home / email
Proton Mail
No encryption outside of Proton
Emails sent to non-Proton users are not encrypted.
Proton can decrypt emails
Since web apps are dynamic and code integrity is virtually impossible to verify, Proton can easily serve a malicious frontend to target users that steals their PGP private keys upon login, enabling the decryption of all their emails. Audits cannot prevent this dynamic attack because they only confirm past states.
No onion sign up
The service has onion addresses for both login and registration, but attempts to create a new account via onion usually result in errors like "too many usernames tested recently". Registration over Tor via a clearnet address works fine, but requires linking another email address or phone number.
Tor sign up
Creating a new account over Tor via a clearnet address requires a confirmation code from another email address or phone number. Popular temporary email services with static domains are usually rejected, but a few services with dynamic domains are often accepted, essentially allowing you to create a new Proton account over Tor without linking any other identities.
Honeypot
Every email service provider is a honeypot because it's an account based centralized service controlled by one officially registered compliant entity that either already fully leaked its database or will leak it soon due to coercion and hacks. You should never use emails for anything important. If you must use a centralized email service, then minimize your metadata leakage with Tor and encrypt messages with PGP.
Get started:
Useful:
A list of Tor-friendly temporary email services you can try to get a code:
Optional hardening:
Disable writing assistant
Disable in "Security and privacy":
Account monitor
Collect usage diagnostics
Send crash reports
Blog:
File encryption done right - stop trusting web-based scams and learn how to encrypt anything with GPG.