End-to-end encryption
sealed before it leaves the tab

Your private key is made in your browser and never sent to us. Mail to OpenEmail addresses with a published key is sealed in the tab, and mail sealed to you opens there too.

In short

What is end-to-end encrypted email?

The sender encrypts with the recipient's public key, and only the matching private key can open it. Servers in between carry unreadable text. OpenPGP seals only the body, so the subject and addresses stay readable.

15min

idle before an unlocked key locks again

8h

the longest a key stays unlocked

3MB

of files, roughly, fit one sealed message

How it works

Sealed in your tab before sending

When every recipient has a key in the OpenEmail directory, the body and files are encrypted in your browser and reach us as ciphertext.

Green only when it really opens

Mail sealed to a key in this browser opens in the reading pane, whichever PGP client sent it. The Privacy check goes green only after decrypting.

Your passphrase is the only way in

Setup will not finish until you download the backup, and a forgotten passphrase leaves sealed mail unreadable, to us too.

Formats it recognises

Identified on arrival, whoever sent it.

multipart/encryptedPGP/MIME, opens hereBEGIN PGP MESSAGEinline PGP, opens hereapplication/pkcs7-mimeS/MIME, cannot openmultipart/signedsigned, not checked

What you get

In the product today

Subject stays visible

The addresses and date do too. Only the body and files are sealed.

Out of search

Rules, search and AI skip sealed bodies, even ones you have opened.

Scheduled sends stay sealed

They wait as ciphertext, sealed to the keys recipients hold when you write.

Good practice

Getting the most out of it

  1. 01

    Guard the backup file

    Keep it in a password manager. It is your only way back without this browser.

  2. 02

    Import on each device

    A phone or second laptop has no key until you import the backup.

  3. 03

    Rotate after a leak

    Suspect someone saw your passphrase or device? Replace the key. Old sealed mail still opens.

Where it stands

Good to know

Sending beyond OpenEmail
No keyserver, Web Key Directory or Autocrypt lookup. Your public key leaves only inside a workspace export.
Replies, forwards, templates
Cannot be sealed: the quoted thread would sit outside the seal, and templates render on the server.

Questions

Asked often

Keep going

Works well with

Transport encryption

Mail moves over TLS on the hops we run, and transport alone never turns the padlock green, because nothing on this backend can read the transport off a delivery.

Encryption at rest
Soon

Every field of a message sealed before it is written down (body, subject, addresses and attachment bytes), so a copy of the database is ciphertext rather than mail.

Account security

A code from your authenticator app, on top of your password.

Start

Your domain,
your mail.

Point a domain at OpenEmail and read it in a mailbox built around it. The free plan covers one domain.

Your inbox,
on your own terms.

Email infrastructure for businesses, AI, agents and personal email. Built for scale, privacy and control. Everything email should have had from day one.

OpenEmail

Email infrastructure for businesses, AI, agents and personal email. Built for scale, privacy and control. Everything email should have had from day one.

© 2026 OpenEmail. All rights reserved.