Encrypt Your Emails¶

You may be aware that mainstream email services compromise privacy, sell data to advertisers and participate in mass surveillance. Despite this, many stick with them due to familiarity and perceived difficulty in changing.
Fear not, transitioning is simpler than it seems! We’ll introduce some reliable, privacy-focused, encrypted email services, like Tutanota and Protonmail. We’ll also guide you on using PGP encryption tools for emails.
Protonmail¶
| Description | |
|---|---|
| Protonmail claims to be the world's largest secure email service, protected by Swiss privacy laws. Depite its apps being open source, the server-side lacks transparency. Funders include US investors Charles River Ventures. The free single-user account provides 500 MB storage. With plans ranging from 4 to 24 EUR/month, you unlock additional users, storage, and an array of features including calendar, contact and email imports, bitcoin payments, VPN, and more. Protonmail provides mobile apps for Android and iOS, aside from webmail access. Desktop users with paid accounts can use Thunderbird with the Protonmail Bridge application. ElectronMail is an alternative free and open source desktop client. |
Step-by-step guide
Simply download the Protonmail app from Google's Play Store or Aurora Store. It contains 0 trackers and requires 14 permissions. By comparison: for Gmail it's 1 tracker and 55 permissions; for Outlook it's 13 trackers and 49 permissions; and for Hotmail it's 4 trackers and 31 permissions.
Step-by-step guide
Simply download the Protonmail app from the App Store.
Step-by-step guide for ElectronMail (no paid account needed)
| Instructions | Description |
|---|---|
| Download ElectronMail | Download and run the ElectronMail installer for Windows. |
| Create a master password | Open ElectronMail and provide a strong, unique master password to protect your emails. |
| Login | Provide your Protonmail credentials, including two-factor authentication if activated. |
| Domain | Choose a domain from the list. There is even an Onion option to use Tor. Then click on Close. |
Step-by-step guide for Thunderbird (paid accounts only)
Install Thunderbird on Windows¶
Navigate to Thunderbird's download page and click on the Free Download button. Once the installer is downloaded, click on the Run button and follow the installation wizard.
Install Protonmail Bridge on Windows¶
Thunderbird integrates nicely with Protonmail, making sure emails stay encrypted when they enter and leave your computer. This is handled by the so-called Bridge application, a software available to paid users only. Download Protonmail Bridge for Windows. Once the installer is downloaded, click on the "Run" button and follow the installation wizard.
Configure Protonmail Bridge on Windows¶
Open the freshly installed Protonmail Bridge application and follow the setup wizard:
| Steps | Description |
|---|---|
| 1 | Log into your Protonmail account. |
| 2 | Click on your account name and then the Mailbox configuration button. |
| 3 | A window with the title Protonmail Bridge Mailbox Configuration should pop up. It displays IMAP and SMTP settings, including a password, needed later on to configure Thunderbird. |
Configure Thunderbird on Windows¶
Now launch Thunderbird, navigate to Menu ‣ New ‣ Existing Email Account and follow the setup wizard:
| Setting | Description |
|---|---|
| Your name | Enter the name you want others to see. |
| Email address | Enter your Protonmail email address. |
| Password | Copy and paste the password from the Protonmail Bridge Mailbox Configuration window (do not enter your Protonmail password, it won't work). |
| Remember password | Check the Remember Password box to avoid re-entering the password each time you fire up Thunderbird. |
| Manual config | Click on the Manual config button, and fill out the IMAP and SMTP settings provided in the Protonmail Bridge Mailbox Configuration window (for Authentication, select Normal password). |
| Re-test | Click on the Re-test button to verify your connection settings. |
| Advanced config | Click on the Advanced config button. A new window appears. Just click on the OK button, do not modify any settings in this window. |
| Add Security Exception | Click on the Confirm Security Exception button in the pop-up window. This confirms that your computer (127.0.0.1) can run the Bridge app. You might have to confirm a second security exception later on, once you send your first email. |
Step-by-step guide for ElectronMail (no paid account needed)
| Instructions | Description |
|---|---|
| Download ElectronMail | Download the ElectronMail disk image, open it and drag the ElectronMail icon on top of the Application folder. For easy access, open the Applications folder and drag the ElectronMail icon to your dock. |
| Create a master password | Open ElectronMail and provide a strong, unique master password to protect your emails. |
| Login | Provide your Protonmail credentials, including two-factor authentication if activated. |
| Domain | Choose a domain from the list. There is even an Onion option to use Tor. Then click on Close. |
Step-by-step guide for Thunderbird (paid accounts only)
Install Thunderbird on macOS¶
Navigate to Thunderbird's download page and click on the Free Download button. Once the installer is downloaded, it should open by itself and mount a new volume containing the Thunderbird application. If not, open the downloaded Thunderbird .dmg file and drag the appearing Thunderbird icon on top of the Application folder. For easy access, open the Applications folder and drag the Thunderbird icon to your dock.
Install Protonmail Bridge on macOS¶
Thunderbird integrates nicely with Protonmail, making sure emails stay encrypted when they enter and leave your computer. This is handled by the so-called Bridge application, available to paid users only. Download Protonmail Bridge for macOS. Once the installer is downloaded, it should start by itself and mount a new volume containing the Protonmail application. If not, open the downloaded Protonmail Bridge .dmg file and drag the Protonmail icon on top of the Application folder. For easy access, open the Applications folder and drag the Protonmail Bridge icon to your dock.
Configure Protonmail Bridge on macOS¶
Open the freshly installed Protonmail Bridge application and follow the setup wizard:
| Steps | Description |
|---|---|
| 1 | Log into your Protonmail account. |
| 2 | Click on your account name and then the Mailbox configuration button. |
| 3 | A window with the title Protonmail Bridge Mailbox Configuration should pop up. It displays IMAP and SMTP settings, including a password, needed later on to configure Thunderbird. |
Configure Thunderbird on macOS¶
Now launch Thunderbird, navigate to Menu ‣ New ‣ Existing Email Account and follow the setup wizard:
| Setting | Description |
|---|---|
| Your name | Enter the name you want others to see. |
| Email address | Enter your Protonmail email address. |
| Password | Copy and paste the password from the Protonmail Bridge Mailbox Configuration window (do not enter your Protonmail password, it won't work). |
| Remember password | Check the Remember Password box to avoid re-entering the password each time you fire up Thunderbird. |
| Manual config | Click on the Manual config button, and fill out the IMAP and SMTP settings provided in the Protonmail Bridge Mailbox Configuration window (for Authentication, select Normal password). |
| Re-test | Click on the Re-test button to verify your connection settings. |
| Advanced config | Click on the Advanced config button. A new window appears. Just click on the OK button, do not modify any settings in this window. |
| Add Security Exception | Click on the Confirm Security Exception button in the pop-up window. This confirms that your computer (127.0.0.1) can run the Bridge app. You might have to confirm a second security exception later on, once you send your first email. |
Step-by-step guide for ElectronMail (no paid account needed)
| Instructions | Description |
|---|---|
| Download ElectronMail | Download the latest ElectronMail .deb package. The file should be named something like electron-mail-X-XX-X-linux-amd64.deb. For the purpose of this tutorial, let's suppose the file was downloaded to the folder /home/gofoss/Downloads. Make sure to adjust these file paths according to your own setup. Now open the terminal with the Ctrl+Alt+T shortcut or click on the Applications button on the top left and search for Terminal. Finally, run the following commands:cd /home/gofoss/Downloads sudo dpkg -i electron-mail-X-XX-X-linux-amd64.deb |
| Create a master password | Open ElectronMail and provide a strong, unique master password to protect your emails. |
| Login | Provide your Protonmail credentials, including two-factor authentication if activated. |
| Domain | Choose a domain from the list. There is even an Onion option to use Tor. Then click on Close. |
Step-by-step guide for Thunderbird (paid accounts only)
Install Thunderbird on Linux¶
If you run a Linux distribution such as Ubuntu, open the terminal with the shortcut CTRL + ALT + T, or click on the Applications button on the top left and search for Terminal. Run the following command to install Thunderbird:
sudo apt install thunderbird
Install Protonmail Bridge Linux¶
Thunderbird integrates nicely with Protonmail, making sure emails stay encrypted when they enter and leave your computer. This is handled by the so-called Bridge application, available to paid users only. Download Protonmail Bridge Linux. The file should be called something similar to protonmail-bridge_X.X.X-X_amd64.deb. Let's assume it has been downloaded to the folder /home/gofoss/Downloads. Open the terminal with the shortcut CTRL + ALT + T, or click on the Applications button on the top left and search for Terminal. Then run the following commands (don't forget to adjust the filename and download folder path accordingly):
sudo apt install gdebi
cd /home/gofoss/Downloads
sudo gdebi protonmail-bridge_X.X.X-X_amd64.deb
Configure Protonmail Bridge Linux¶
Open the Bridge application with the terminal command protonmail-bridge, or click on the Applications button on the top left, and search for ProtonMail Bridge. Follow the setup wizard:
| Steps | Description |
|---|---|
| 1 | Log into your Protonmail account. |
| 2 | Click on your account name and then the Mailbox configuration button. |
| 3 | A window with the title Protonmail Bridge Mailbox Configuration should pop up. It displays the Protonmail server settings, including IMAP, SMTP and a password needed later on to configure Thunderbird. |
Configure Thunderbird on Linux¶
Now launch Thunderbird, navigate to Menu ‣ New ‣ Existing Email Account and follow the setup wizard:
| Setting | Description |
|---|---|
| Your name | Enter the name you want others to see. |
| Email address | Enter your Protonmail email address. |
| Password | Copy and paste the password from the Protonmail Bridge Mailbox Configuration window (do not enter your Protonmail password, it won't work). |
| Remember password | Check the Remember Password box to avoid re-entering the password each time you fire up Thunderbird. |
| Manual config | Click on the Manual config button, and fill out the IMAP and Protonmail SMTP settings provided in the Protonmail Bridge Mailbox Configuration window (for Authentication, select Normal password). |
| Re-test | Click on the Re-test button to verify your connection settings. |
| Advanced config | Click on the Advanced config button. A new window appears. Just click on the OK button, do not modify any settings in this window. |
| Add Security Exception | Click on the Confirm Security Exception button in the pop-up window. This confirms that your computer (127.0.0.1) can run the Bridge app. You might have to confirm a second security exception later on, once you send your first email. |
Some words of advice on encryption
| Encryption | |
|---|---|
| Sent between Protonmail users | Message body and attachments are end-to-end encrypted. Subject lines and recipient/sender addresses are not. |
| Sent from Protonmail users to other providers | Message body and attachments are only end-to-end encrypted if the user selects the Encrypt for Outside option. Otherwise, only TLS encryption is applied if the receiving mail server supports it (which also means that the receiving provider can read the message). In any case, subject lines and recipient/sender addresses are not end-to-end encrypted. |
| Received by Protonmail users from other providers | Message body and attachments are only encrypted with TLS, if the sender's mail server supports it. Subject lines and recipient/sender addresses are not end-to-end encrypted. |
Tutanota¶
| Description | |
|---|---|
| Tutanota, a secure email service based in Germany, operates on a freemium model. All data is end-to-end encrypted, using Tutanota’s own standard instead of PGP. While the apps are open source, the server-side remains proprietary. The free basic account provides 1 GB storage. With plans ranging from 1 to 6 EUR/month, you can unlock custom domains, unlimited search, inbox rules, calendar sharing, and more. However, email imports and anonymous payments are not currently supported. You can access Tutanota through webmail or mobile apps for Android and iOS. For desktop users, a specially designed client by Tutanota is available. |
Step-by-step guide
Simply download the Tutanota app from Google's Play Store or Aurora Store. Tutanota is also available on F-Droid. Alternatively, visit Tutanota's download page or Github repository to download and install the .apk file. The app contains 0 trackers and requires 9 permissions. By comparison: for Gmail it's 1 tracker and 55 permissions; for Outlook it's 13 trackers and 49 permissions; and for Hotmail it's 4 trackers and 31 permissions.
Step-by-step guide
Simply download the Tutanota app from the App Store.
Step-by-step guide
Simply download the installer, then click on the Run button and follow the installation wizard.
Step-by-step guide
Simply download the installer, which should open by itself and mount a new volume containing the Tutanota application. If not, open the downloaded Tutanota .dmg file and drag the appearing Tutanota icon on top of the Application folder. For easy access, open the Applications folder and drag the Tutanota icon to your dock.
Step-by-step guide
Simply download the installer, which should be called something like tutanota-desktop-linux.AppImage. Let's assume it was downloaded to the folder /home/gofoss/Downloads. Open the terminal with the CTRL + ALT + T shortcut, or click on the Applications button on the top left and search for Terminal. Then run the following commands (don't forget to adjust the filename and download folder path accordingly):
cd /home/gofoss/Downloads
chmod +x tutanota-desktop-linux.AppImage
How to pin Tutanota to Ubuntu's dock
It's not straight forward, but Tutanota's launcher can be added to Ubuntu's application menu and pinned to the dock. Open the terminal with the CTRL + ALT + T shortcut, or click on the Applications button on the top left and search for Terminal. Run the following command:
sudo gedit /usr/share/applications/tutanota.desktop
Paste the following content into the newly created file. Make sure to point the Exec path towards the folder containing the downloaded AppImage:
#!/usr/bin/env xdg-open
[Desktop Entry]
Version=1.0
Type=Application
Terminal=false
Exec=/home/gofoss/Downloads/tutanota-desktop-linux.AppImage
Name=Tutanota
Make the file executable:
sudo chmod +x /usr/share/applications/tutanota.desktop
Log off and back into your Ubuntu session. You should now be able to launch Tutanota from the application menu, and pin it to the dock.
Other providers¶
| Info | Description |
|---|---|
| Website | disroot. org |
| Pricing | Basic account is free (1 GB storage); extra storage for 0.15 EUR per GB per month. |
| Features | Platform providing online services based on principles of freedom, privacy, federation and decentralization. Located in the Netherlands. Accepts bitcoin and faircoin. Full disk encryption & email encryption. Mobile app. |
| Anti-features | Can potentially decrypt user data, as emails are reportedly stored in plain text. |
| Info | Description |
|---|---|
| Website | mailbox. org |
| Pricing | 1 EUR/month, 2 GB storage. |
| Features | German open source email provider, with servers located in Berlin. Offers security features such as encryption at rest, PGP, DANE, SPF and DKIM, as well as two-factor authentication, full text search, calendars, address books and task lists, CalDAV and CardDAV synchronisation. |
| Anti-features | No mobile client, need for third party clients. |
| Info | Description |
|---|---|
| Website | posteo.de |
| Pricing | 1 EUR/month, 2 GB storage. |
| Features | German open source email provider, self-financed, encryption at rest, two-factor authentication, calendars and address books, CalDAV and CardDAV synchronisation. |
| Anti-features | No spam folder, no trial or free version. |
| Info | Description |
|---|---|
| Website | kolabnow.com |
| Pricing | 5 USD/month, 2 GB storage. |
| Features | Swiss open source email provider, text search and tagging, filters, address books, calendars, CalDAV and CardDAV synchronisation. |
| Anti-features | No built-in end-to-end encryption, not encryption at rest. |
Transition phase¶
Transitioning to a new email account, like changing messaging apps, takes time. Keep your old accounts active temporarily and forward incoming messages to your new adress. Check Gmail, Outlook, iCloud, and Yahoo documentation for forwarding guidance.
Review your old email accounts, identify active subscriptions and update your new email credentials. Notify your personal and professional contacts, as well as your insurance, bank, or tax office about your new adress. Consider setting up an auto-reply on your old account to keep people informed about the change. As time passes, your old inbox receives fewer emails. Consider terminating it when inactive.