Nearly 10 years ago, I used Proton Mail for my email. At the time, it was the new kid on the block, but promised unrivalled privacy and security - 2 things I care greatly about. Fast forward, and that all still holds true. If, for whatever reason, I was doing sketchy things, and needed a secure email, it's where I'd go.
<aside
Proton CEO Andy Yen gave a great TED Talk on starting Proton Mail and why it was necessary.
</aside>
For the last few years, I've been a pretty happy Fastmail user - I've used them personally and professionally on and off for a decade. As security and privacy go, they do the best they can. Emails are encrypted at rest on their servers, but it's not end-to-end - that's a trade-off they make for features (hopefully). However, I care about my security and privacy. Fastmail are open that their staff can read emails due to the nature of their job, and that they have to comply with Australian law enforcement (and in some cases, US). Proton on the other hand, can't. The second emails are received on their servers, they're encrypted with a key only I hold, and only decrypted on my devices - there's no way for them, or anyone else, to access my emails.
Given most of my other service choices are done in the interest of security and privacy, I'd like to do the same for my email. At the end of November was Black Friday - a week (yes, a week long Friday) of discounts. Proton had a Black Friday sale offering between 50% - 70% off their "Proton Ultimate" subscription. So, after spending a week doing research, I committed and clicked buy.
However, before I even moved my email or domains over, I contacted support and requested a refund. Not because there was anything wrong with Proton Mail, but because on reflection it wasn't for me. That might sound confusing and surprising for some, so I want to explain why.
#Does email privacy matter any more?
The protocols behind email (SMTP, IMAP and POP) were designed in the 80s - when security wasn't considered through the same lens it is now. Nowadays, we can use the above protocols over TLS to gain encryption, but each hop can still read the content. The closest we have to proper email security is PGP, but it doesn't scale very well, and puts a lot of burden on the user.
To many, email security may not seem like a big deal. Nowadays, most people don't use email to communicate with other people, they use it to receive messages from services: Order confirmations, newsletters, password resets and more.
Take the following example:
Here, a "service" wants to send an email to a user (me). The service creates an email, passes it to the Mail Transfer Agent (MTA) (eg Mailgun) to send the email to the user's email server (eg Fastmail), who can then download it and read it. In this situation, all 4 parties have complete access to the message. Even though the links between each are fully encrypted, as too probably is any persistent storage, the data is still decrypted to be processed by each party.
Let's contrast with Proton Mail, which should be doing everything it can to secure my emails, right? Proton Mail is fully encrypted - the only person who can see your emails is me, right? Let's consider the above example, but with us using Proton Mail instead:
Well, the service and MTA can still see it, since that's unchanged, and not infrastructure we control. Once the email hits Proton Mail, it's encrypted, and passed encrypted to us to decrypt and read. Sure, it's better - it means Proton Mail can't read the email, but everything else in the chain still knows what it said. Really this is a limitation of the email protocols - they just weren't designed for content to be encrypted by the sender and decrypted by the recipient on-device.
Unfortunately, the same is true when sending email. My email is nice and securely encrypted on my device, and within Proton Mail, but the second it leaves Proton it needs to be decrypted so another service can read it.
The benefits come from when the entire chain is aware of end-to-end encrypted email, and can handle it. But that's rare:
- You and your recipient need to be using PGP (or compatible service, like Proton Mail) or another more obscure protocol
- If your sending email to a group or mailing list, everyone needs to be using PGP
- Any service you want to receive email from needs to know to encrypt email sent to you
<fact
Facebook, of all companies, used to support exactly this - PGP encrypting your email before sending it to you. This would have played perfectly with Proton Mail, as it would mean the email could only be read by you and Facebook - as end-to-end should be. Sadly though, they discontinued this in 2023.
</fact>
Most of the time, I don't send a huge amount of email. Before joining Django's security team (which does almost everything by email), I only sent a handful of emails per year from my personal accounts.
#Privacy in aggregate
Email is more than just a single message through. People receive many emails a day, from many different sources. If your email server (eg Gmail) can see all your emails, it can aggregate that knowledge and start to build a profile on you, even if you never sent any email. Proton Mail not only wouldn't do that, but it can't - the second the email is encrypted it's useless to Proton Mail.
If the MTA a service use is shared by others (eg they're using AWS SES), then the MTA can still see everything being sent to us, and can easily aggregate that knowledge, perhaps even across services. Unfortunately the likes of Proton Mail can't help us there.
#Trade-offs
Proton Mail is objectively more secure and private than the vast majority of other email servers. Even though the protocols are limited, encrypting as soon as it's received, and only decrypting it on my device mitigates a number of potential security and privacy concerns. Proton Mail can't build a profile if they don't have any data to build it off.
But those benefits that comes at a cost. Sure, Proton isn't cheap, but even finances aside there's a cost: usability - as is always the case with security. Much of that isn't Proton's fault - it's hard taking complex security processes and wrapping them in a UI which my parents could use, and yet they have. However, because Proton requires you use their mobile apps (or run their Bridge somewhere), they don't quite hold up in terms of polish to the likes of other email apps.
<aside
Yes, I'm aware Proton just released new mobile apps, and they're definitely nicer. But they're not quite as nice as Fastmail's
</aside>
Because Proton requires the decryption process to happen on your device, they can't use standard protocols like SMTP to let you access your emails. If you do want to use SMTP, for example to use a different email client, you can use their Bridge. I tried bulk moving emails using Thunderbird, and the bridge crawled - processing an email per second or so.
#Aliases
The biggest trade off for me though was in aliases and domains. The Proton Unlimited tier supports up to 3 custom domains, and a total of 15 aliases. You can setup catch-all aliases to receive any incoming email, and disable aliases you don't need to send from immediately, but it's a hassle to manage. If you need more domains however, or don't want to faff with disabling aliases, there's always the included SimpleLogin subscription.
However, SimpleLogin feels to me, whilst a clever, an unnecessary solution and a bit of a bodge. For receiving email, SimpleLogin is completely transparent - there's no way to tell it's sitting in the middle. However to send from an alias or domains managed by SimpleLogin, it requires you use a custom recipient address, which proxies it through SimpleLogin to rewrite it. This means searching emails by recipient won't work, since the recipient address won't be correct.
I assume the reason for Proton to limit plans this way is because unlike other providers, where aliases and domains are just a few pieces of configuration, Proton needs to handle encryption keys alongside them, which adds complexity on their side. I asked support whether it was possible to buy more domains or aliases, and their only response was the business tier (at 50% more expensive), which allows 10 domains and 20 aliases. Better, for sure, but doesn't quite solve my problems.
#Alternatives
After deciding Proton wasn't for me, I was left with a dilemma: Do I stick with Fastmail for a bit longer, or keep shopping around the quickly-expiring Black Friday deals for a different provider?
Mailbox.org kept coming up as recommended, with many of the features of Proton Mail without some of the limitations. Mailbox.org do what they can around security, whilst keeping SMTP support. The most interesting feature of Mailbox.org is their Encrypted Mailbox feature, which does almost exactly what Proton Mail does - encrypt emails using PGP the second they're received. This requires setting up PGP on my clients, but means my emails are fully encrypted when stored. Unfortunately, this falls over quite fast when you have multiple aliases configured, since you'd need to be managing a key per alias, which becomes overwhelming after more than a handful.
Another alternative is Startmail, from the creators of Startpage. Startmail aren't quite as popular, but they seem to do as much as they can privacy wise without sacrificing usability. According to their whitepaper, emails are stored in a LUKS encrypted vault per user, and only decrypted when I need to access them (using a key only I have). If email comes in whilst the vault is locked, it's encrypted with a public key outside, and decrypted and copied in the next time the vault is opened. It's not perfect, since there's still opportunities for Startmail to see the full email, but it's an interesting approach. Startmail also support unlimited aliases and domains, and their home country of the Netherlands is anti chat control.
The final popular choice for secure email is Tuta (formerly Tutanota). Tuta are clearly trying to hit the same niches as Proton Mail, however with a simpler offering. For every day email, Tuta is a non-starter for me, simply because it has no 3rd-party client support. Your options are either their webmail or mobile apps - there's no SMTP or bridge like interface. However, if you're looking for a secondary email for backup purposes, their free tier could be useful.
<warning
If you do use Tuta's free tier, make sure to keep logging in every once in a while. Tuta deletes accounts after 6 months, and will happily let paid plans reuse aliases for previously-deleted accounts.
</warning>
Another option is to just accept Proton Mail as it is. Since I don't send that much email, the SimpleLogin hacks wouldn't be front and centre, annoying me every day. With Proton Ultimate, I'd be getting more than just mail, but I don't really need it. Proton VPN has some interesting features, but the apps aren't as polished as Mullvad, especially on Linux (where I already found a bug). I don't need a password manager, Bitwarden (well, Vaultwarden) is serving me fine for now (when passkeys work). Whilst I could see some value in cloud storage for quick file sharing, it's not that important.
And then of course, there's sticking with Fastmail - the lazy option. Fastmail take privacy and security seriously - it's front and centre on their website. As I've mentioned though, it's not end-to-end encrypted, and Australia are a five-eyes country, but they're as transparent about all this as they can be. The feature-set and the level of polish which comes with Fastmail is unparalleled - the mobile apps are excellent, fast, and completely devoid of AI or other anti-privacy measures. As email providers go, there's little reason for most people to use anyone else. Oh, and there's no limits on domains or aliases, which is another huge plus for me.
#Self-hosting?
When people discuss email providers, there's always someone who says "why not self host your email?". That person is wrong. The technical process behind self-hosting email isn't too complex - I tried it a decade ago without too much headache. The big problems with self-hosting email are everybody else. Deliverability is a nightmare, your server host might block the required ports, and it's a matter of time before your end up on a block list.
Email is one of the few (only?) places I can't recommend self-hosting.
With that said, since I don't send much email, I could route outbound email elsewhere, and keep the inbound email locally. The majority of the downsides of self-hosting email relate to the sending process. Given most of what I do is receiving, I could offload the sending to an MTA, much like most applications do. An MTA would handle the complexities and deliverability concerns of sending email, rather than me. Having to route outbound email via someone else trades the complexity for privacy, which also defeats some of the point.
#What now?
For now, I'm sticking with Fastmail, at least for a little while longer. My annual subscription only renewed in late October, so I still have a lot of time to use and plenty of time to research. Sure, Proton Mail is going to be better for privacy and security, but right now I need 50% more features than I need 5% more privacy.
Does this mean I'll never go back to Proton Mail, absolutely not. My needs will change, and Proton will get better. I sadly can't imagine them changing the alias and domain costs, but I may need them less, or find SimpleLogin less of a bodge.
Come late October, when my Fastmail subscription is up again, I'll be actively looking into alternatives again (or at least switching to monthly to tide me over until Black Friday again). This time next year, I doubt I'll still be with Fastmail. For now, Fastmail's privacy isn't as good as Proton's, but it's good enough for me.
Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.