Proton Mail

freemium · open source
Rung 2 · Custody/ Data & Devices Trust-minimized

An encrypted email service from Switzerland where messages are stored in a way Proton itself cannot read. It pairs well with a custom domain, which keeps your address portable if you ever want to leave. Email to outside providers is still exposed in transit by nature, and Proton can be legally compelled to log IP addresses.

Trust shape

Trust-minimized

Proton holds your mailbox and can be legally compelled to log connection data or capture future unencrypted inbound mail.

Facts

Build or maintain Proton Mail? Claim this listing to keep its facts current.

Related in Private Communication

SimpleX Chat

A private messenger with no user identifiers at all: no phone number, no username, not even a persistent ID linking your conversations together. Message routing is split across relays so no single server sees both ends of a chat. The cost is convenience, since contact discovery is manual and the network is younger and smaller than Signal's.

Rung 2 · Custody/ Data & Devices Trust-minimized

Tuta

A German encrypted email provider that encrypts message bodies, subject lines, calendars, and contacts, going further than most rivals. The free tier is enough for a real mailbox. Because it uses its own encryption scheme rather than standard protocols, you cannot connect third-party mail apps, and search inside encrypted mail is limited.

Rung 2 · Custody/ Data & Devices Trust-minimized

Element / Matrix

A messaging app built on Matrix, an open protocol where anyone can run a server, somewhat like email for chat. You can join an existing homeserver or run your own and keep your conversations on hardware you control. Encryption is solid, but metadata visibility and your real sovereignty depend on whose homeserver you use.

Rung 3 · Verify/ Data & Devices Hybrid

GnuPG

The long-standing open-source implementation of OpenPGP encryption: sign, verify, and encrypt files and email using keys that only you hold. It runs entirely on your machine and underpins how software releases are verified across the open-source world. It is famously unfriendly to use, with key management that trips up newcomers, but there is no operator to trust.

Rung 3 · Verify/ Data & Devices Trustless