Transport encryption
A padlock that never guesses.

The hops OpenEmail runs use HTTPS. STARTTLS between mail servers is optional and never reported to us, so transport never turns the lock green.

In short

What is TLS encryption for email?

SMTP carries mail between servers, and STARTTLS upgrades a connection to TLS when both ends support it. It protects the hop, not the message: every server on the route can still read it. If either side declines, mail usually goes in plain text.

How it works

STARTTLS offered, plain text accepted

The servers that receive for you offer STARTTLS and still take plain SMTP, so a sender that skips it gets through.

Nothing says how it travelled

A delivery arrives with its authentication and spam verdicts, and nothing about transport. Not checked is not the same as not encrypted.

Only a decrypt turns it green

On ordinary mail, the Privacy check in a message’s Details tab reads Not sealed, dimmed, however the message travelled.

The words on the wire

What each one covers.

SMTPHow servers hand mail onSTARTTLSUpgrades SMTP to TLS, if both agreeHTTPSTLS on the hops OpenEmail runsMXNames the servers that receive for you

What you get

In the product today

HTTPS on our hops

Outbound leaves over HTTPS, and inbound reaches us over HTTPS too.

STARTTLS, best effort

Between servers that are not ours it is offered, never required.

Dimmed, not flagged

Not sealed is a muted note, never a warning.

Green means decrypted

The only green lock is an end-to-end message opened in this browser.

Good practice

Getting the most out of it

  1. 01

    Seal what matters

    Seal anything a server should not read in a new message to an OpenEmail address with a published key.

  2. 02

    Mind the subject line

    Keep sensitive detail out of the subject, which travels in the clear even on a sealed message.

  3. 03

    Read dimmed as unknown

    A dimmed lock means transport went unmeasured, not that the mail crossed in plain text.

Where it stands

Good to know

Required TLS
Receiving servers accept plain SMTP too, and no setting refuses it.

Questions

Asked often

Keep going

Works well with

End-to-end encryption

OpenPGP keys made in your browser. Mail you send to another OpenEmail address can be sealed before it leaves the tab, and sealed mail addressed to you opens in the reading pane, decrypted on your machine. The keys are never ours to hand over.

Encryption at rest
Soon

Every field of a message sealed before it is written down (body, subject, addresses and attachment bytes), so a copy of the database is ciphertext rather than mail.

Verified sender

A mark beside the sender when the sending domain’s published records line up.

Start

Your domain,
your mail.

Point a domain at OpenEmail and read it in a mailbox built around it. The free plan covers one domain.

Your inbox,
on your own terms.

Email infrastructure for businesses, AI, agents and personal email. Built for scale, privacy and control. Everything email should have had from day one.

OpenEmail

Email infrastructure for businesses, AI, agents and personal email. Built for scale, privacy and control. Everything email should have had from day one.

© 2026 OpenEmail. All rights reserved.