Security and scale

Serverless and encrypted,
with nothing for you to set up.

OpenEmail runs on a global serverless network, uses SSL on every connection and encrypts what it stores. Here is how it works, in plain words, with the numbers we measured.

Architecture

Serverless,
from the first request.

There is no app server behind OpenEmail. The parts that answer you start when they are needed and scale on their own.

Functions, not machines

The web app, the API and every background job run as serverless functions on a global network. There is no app server for us to size, patch or restart.

Capacity that follows traffic

Capacity grows and shrinks with demand by itself, so a launch-day spike is handled like a quiet afternoon.

Connections made close to you

Every connection is accepted at the nearest point of a global network, which keeps the secure handshake short wherever your visitors are.

Releases that never half-land

Each part ships on its own, and only after its checks pass. A release that fails leaves the previous version serving.

Speed

Measured on
real mail.

These figures come from production traffic, not a benchmark. Sending is queued and paced, and a message that is asked to wait is retried rather than dropped.

5s

Half of all incoming mail is filed into its inbox within about five seconds of reaching OpenEmail.

1min

95% of incoming mail is filed within a minute.

2s

95% of delivery updates, such as delivered or bounced, are recorded within about two seconds.

Measured over two weeks of production mail, September to October 2026.

SSL

The padlock,
on your domain too.

SSL, the S in HTTPS, is what puts the padlock in the address bar. People see it on every OpenEmail address and on yours, and you never handle a certificate.

  • HTTPS on every page and callThe app, the API, tracked links and file links all use HTTPS. Anyone who types http:// is sent to the secure address.
  • A certificate for your domainWhen you serve the app, tracked links or file links from your own domain, OpenEmail requests the certificate for you. There is nothing to buy or upload.
  • Renewed before it expiresCertificates renew automatically, so the padlock never lapses on a busy weekend.
  • Encrypted between mail serversMail travels between servers over TLS whenever the other side supports it, which the large mail providers all do.

Protection

Private
by default.

Encrypted at rest

Message content, attachments and stored files are encrypted before they are written to storage.

Scanned on arrival

Every incoming message is checked for spam and viruses before it reaches an inbox.

Proof the mail is yours

SPF, DKIM and DMARC records for your domain let receiving servers confirm your mail really came from you.

Two-factor sign-in

Accounts can require an authenticator app, with ten single-use recovery codes. Sensitive changes, such as billing, ask for a fresh code.

Keys with limits

API keys belong to one workspace and can be narrowed to the scopes a job needs.

Signed webhooks

Every webhook carries a signature and a timestamp, so your server can prove it came from OpenEmail.

In detail

How each piece
works.

Transport encryption

Mail moves over TLS on the hops we run, and transport alone never turns the padlock green, because nothing on this backend can read the transport off a delivery.

readable where it lands

Wire transfer approved, details attached.

youtlsopenemail.ukstarttls?them
Encryption at rest

Bodies, attachments and what you write are sealed before they are stored, so a copy of the database is ciphertext rather than mail.

readable where it lands

Wire transfer approved, details attached.

youtlsopenemail.ukstarttls?them
Account security

A code from your authenticator app, on top of your password.

Phishing & spam filtering

Mail the sending domain itself disowns lands in Spam rather than the inbox.

receipts@stripe.com
SPFDKIMDMARC
verified sender
DMARC policy

A starter p=none record, printed to copy or written by a sync, never tightened for you.

TXT_dmarc.acme.com

v=DMARC1; p=none; rua=…

Optionalwatch only
Webhooks

Tell your endpoint when mail arrives, instead of making you poll.

/threads?query=invoice
{ "threads": 12 }
Same mailbox, whether a person or a program is holding it.

Questions

Security and scale,
answered.

See it running
in production.

Five products already send and receive email through OpenEmail. Read how each one built it.