---
title: "Security and scale: serverless email with SSL everywhere"
description: "How OpenEmail runs: serverless on a global network, HTTPS and automatic certificates on your own domain, encrypted storage, and incoming mail filed in seconds."
url: "https://openemail.uk/security"
---

Security and scale

# Serverless and encrypted, with nothing for you to set up.

OpenEmail runs on a global serverless network, uses SSL on every connection and encrypts what it stores. Here is how it works, in plain words, with the numbers we measured.

[Open mail](https://openemail.uk/mail/inbox) [Get Started](https://openemail.uk/signup.md)[See who runs on it](https://openemail.uk/integrations.md)

Architecture

## Serverless, from the first request.

There is no app server behind OpenEmail. The parts that answer you start when they are needed and scale on their own.

Functions, not machines

The web app, the API and every background job run as serverless functions on a global network. There is no app server for us to size, patch or restart.

Capacity that follows traffic

Capacity grows and shrinks with demand by itself, so a launch-day spike is handled like a quiet afternoon.

Connections made close to you

Every connection is accepted at the nearest point of a global network, which keeps the secure handshake short wherever your visitors are.

Releases that never half-land

Each part ships on its own, and only after its checks pass. A release that fails leaves the previous version serving.

Speed

## Measured on real mail.

These figures come from production traffic, not a benchmark. Sending is queued and paced, and a message that is asked to wait is retried rather than dropped.

5 s

Half of all incoming mail is filed into its inbox within about five seconds of reaching OpenEmail.

1 min

95% of incoming mail is filed within a minute.

2 s

95% of delivery updates, such as delivered or bounced, are recorded within about two seconds.

Measured over two weeks of production mail, September to October 2026.

SSL

## The padlock, on your domain too.

SSL, the S in HTTPS, is what puts the padlock in the address bar. People see it on every OpenEmail address and on yours, and you never handle a certificate.

- HTTPS on every page and call The app, the API, tracked links and file links all use HTTPS. Anyone who types http:// is sent to the secure address.
- A certificate for your domain When you serve the app, tracked links or file links from your own domain, OpenEmail requests the certificate for you. There is nothing to buy or upload.
- Renewed before it expires Certificates renew automatically, so the padlock never lapses on a busy weekend.
- Encrypted between mail servers Mail travels between servers over TLS whenever the other side supports it, which the large mail providers all do.

Protection

## Private by default.

Encrypted at rest

Message content, attachments and stored files are encrypted before they are written to storage.

Scanned on arrival

Every incoming message is checked for spam and viruses before it reaches an inbox.

Proof the mail is yours

SPF, DKIM and DMARC records for your domain let receiving servers confirm your mail really came from you.

Two-factor sign-in

Accounts can require an authenticator app, with ten single-use recovery codes. Sensitive changes, such as billing, ask for a fresh code.

Keys with limits

API keys belong to one workspace and can be narrowed to the scopes a job needs.

Signed webhooks

Every webhook carries a signature and a timestamp, so your server can prove it came from OpenEmail.

In detail

## How each piece works.

Transport encryption

Mail moves over TLS on the hops we run, and transport alone never turns the padlock green, because nothing on this backend can read the transport off a delivery.

readable where it lands

Wire transfer approved, details attached.

you tls openemail.uk starttls? them

Encryption at rest

Bodies, attachments and what you write are sealed before they are stored, so a copy of the database is ciphertext rather than mail.

readable where it lands

Wire transfer approved, details attached.

you tls openemail.uk starttls? them

Account security

A code from your authenticator app, on top of your password.

Phishing & spam filtering

Mail the sending domain itself disowns lands in Spam rather than the inbox.

receipts@ stripe.com

SPF DKIM DMARC

verified sender

DMARC policy

A starter p=none record, printed to copy or written by a sync, never tightened for you.

TXT \_dmarc.acme.com

v=DMARC1; p= none; rua=…

Optional watch only

Webhooks

Tell your endpoint when mail arrives, instead of making you poll.

/threads?query=invoice

{ "threads": 12 }

Same mailbox, whether a person or a program is holding it.

Questions

## Security and scale, answered.

## See it running in production.

Five products already send and receive email through OpenEmail. Read how each one built it.

[Open mail](https://openemail.uk/mail/inbox) [Get Started](https://openemail.uk/signup.md)[See who runs on it](https://openemail.uk/integrations.md)
