---
title: "End-to-end encrypted email"
description: "OpenPGP keys made in your browser. Mail to OpenEmail addresses with a published key is sealed in the tab, and sealed mail to you opens on your machine."
url: "https://openemail.uk/features/e2ee"
---

[Privacy & ownership](https://openemail.uk/features.md#trust)

# End-to-end encryption sealed before it leaves the tab

Your private key is made in your browser and never sent to us. Mail to OpenEmail addresses with a published key is sealed in the tab, and mail sealed to you opens there too.

[Open mail](https://openemail.uk/mail/inbox) [Get Started](https://openemail.uk/signup.md)[All features](https://openemail.uk/features.md)

In short

## What is end-to-end encrypted email?

The sender encrypts with the recipient's public key, and only the matching private key can open it. Servers in between carry unreadable text. OpenPGP seals only the body, so the subject and addresses stay readable.

15 min

idle before an unlocked key locks again

8 h

the longest a key stays unlocked

3 MB

of files, roughly, fit one sealed message

How it works

## Sealed in your tab before sending

When every recipient has a key in the OpenEmail directory, the body and files are encrypted in your browser and reach us as ciphertext.

## Green only when it really opens

Mail sealed to a key in this browser opens in the reading pane, whichever PGP client sent it. The Privacy check goes green only after decrypting.

## Your passphrase is the only way in

Setup will not finish until you download the backup, and a forgotten passphrase leaves sealed mail unreadable, to us too.

## Formats it recognises

Identified on arrival, whoever sent it.

multipart/encrypted PGP/MIME, opens here BEGIN PGP MESSAGE inline PGP, opens here application/pkcs7-mime S/MIME, cannot open multipart/signed signed, not checked

What you get

## In the product today

Subject stays visible

The addresses and date do too. Only the body and files are sealed.

Out of search

Rules, search and AI skip sealed bodies, even ones you have opened.

Scheduled sends stay sealed

They wait as ciphertext, sealed to the keys recipients hold when you write.

Good practice

## Getting the most out of it

1. 01
   
   Guard the backup file
   
   Keep it in a password manager. It is your only way back without this browser.
2. 02
   
   Import on each device
   
   A phone or second laptop has no key until you import the backup.
3. 03
   
   Rotate after a leak
   
   Suspect someone saw your passphrase or device? Replace the key. Old sealed mail still opens.

Where it stands

## Good to know

Questions

## Asked often

Keep going

## Works well with

Transport encryption

Mail moves over TLS on the hops we run, and transport alone never turns the padlock green, because nothing on this backend can read the transport off a delivery.

Encryption at rest

Soon

Every field of a message sealed before it is written down (body, subject, addresses and attachment bytes), so a copy of the database is ciphertext rather than mail.

Account security

A code from your authenticator app, on top of your password.

Start

## Your domain, your mail.

Point a domain at OpenEmail and read it in a mailbox built around it. The free plan covers one domain.

[Open mail](https://openemail.uk/mail/inbox) [Get Started](https://openemail.uk/signup.md)[Read the reference](https://openemail.uk/docs/knowledge/trust/e2ee.md)
