Why 'encrypted email' doesn't mean true privacy — and what actually does

You send an email, think it’s secure — but what if the provider reads it anyway, just because they hold the keys?

Encryption at rest and in transit is everywhere. But that doesn’t mean your messages are private. If the service holds the encryption keys, they can read your messages anytime — even if the data is scrambled.

True privacy isn’t about code—it’s about control. The best encrypted email providers for privacy in 2024 don’t just encrypt data; they ensure only you and your recipient can decrypt it—ever.

You don’t need to trust a company with your secrets. The real solution is end-to-end encryption where the service itself can’t access the content, metadata, or history of your messages—no exceptions.

Key takeaways

  • End-to-end encryption ensures only you and the recipient hold the keys to decrypt messages.
  • Providers that control encryption keys—even if they use TLS or disk encryption—can still read your messages.
  • The best encrypted email providers for privacy in 2024 use per-account keys and never keep copies of your decryption keys.

How email security actually works: DNS records, encryption layers, and real-world risks

True email privacy isn't just about encryption—it starts with your domain’s DNS records. MX, SPF, DKIM, and DMARC work together to verify your email’s origin, block spoofing, and stop spam. Even the most secure email app can’t protect you if these records are missing or wrong. TLS encrypts messages in transit, but only end-to-end encryption ensures your provider can’t read your messages. Let’s break down how it all fits together.

DNS records: the foundation of trusted email

Your domain’s DNS records are the gatekeepers. When someone sends you an email, the receiving server checks these records to confirm it actually came from your domain. Without them, even a real message can be rejected or marked as spam.

MX records route incoming mail to your server. SPF (Sender Policy Framework) lists which servers are allowed to send email for your domain. DKIM (DomainKeys Identified Mail) signs each message with a cryptographic key, proving it’s not altered in transit. DMARC ties them together and tells receivers what to do if a message fails SPF or DKIM checks.

If any of these are missing—especially SPF and DKIM—attackers can spoof your domain. You might receive messages claiming to be from your own address. This isn’t just theoretical: the RFC 7052 standard, published by the IETF, outlines why these records are essential for email integrity.

Encryption layers: what’s in transit, what’s at rest

TLS (Transport Layer Security) encrypts your messages while they travel from sender to recipient. That’s good—it stops eavesdropping on public Wi-Fi. But TLS only protects the journey, not the destination. Your provider can still read messages stored on their servers.

End-to-end encryption (E2EE) ensures only you and the recipient can read the message. Even if your provider stores it, they can’t access the content. For that, data must be encrypted on your device before sending, and decrypted only on the recipient’s device.

Unifiedesk offers end-to-end encryption on the hosted platform, meaning your provider cannot read your messages. For teams or organizations needing absolute control, the self-hosted option encrypts everything at rest with AES-256-GCM, under per-account keys. This means even if someone compromises the server, your data stays protected.

Want to learn how to set up your domain with all four records? Unifiedesk guides you step-by-step with automatic generation of MX, SPF, DKIM, and DMARC records in real time. No guesswork, no delays—just secure email on your own domain.

Set up your custom domain securely in minutes. You’re not just choosing a mailbox—you’re taking control of your digital identity.

What to look for in a truly private email provider

You need a provider with open-source code so you can audit the software, end-to-end encryption that keeps your keys on your device—not on their servers—and no data harvesting for AI training or ads. They should let you use your own domain with full DNS control, and offer a self-hosted option if you want total independence. Real privacy isn’t a feature list—it’s how the system is built.

Real transparency starts with open-source code

  • Check if the provider releases their code publicly—on GitHub or a similar platform. This isn’t optional if you want real trust.
  • Open-source means anyone, including independent auditors, can verify claims about encryption, data handling, and backdoors.
  • For example, the IMAP/SMTP standards are openly documented—security shouldn’t be a black box.
  • If the code isn’t public, you’re trusting a company’s word over evidence. That’s not privacy. That’s faith.

Encryption that actually protects your data

  • Look for end-to-end encryption with per-user keys—keys never stored on the provider’s servers.
  • Self-hosted deployments should use AES-256-GCM encryption at rest, with keys managed by you and never shared.
  • Hosted services can still offer E2EE, but only if keys are never accessible to the provider—even during legal requests.
  • Be wary of providers that claim “encrypt everything” but store the keys—this is encryption theater.
  • No user data should be used to train AI models, and no ads should be built on your inbox. If it’s in the terms, it’s a risk.

You should own your domain—not just use it

  • Choose a provider that supports custom domains (e.g., [email protected]) and gives you full control over DNS records.
  • They should help you set up SPF, DKIM, and DMARC—without locking you into their UI or limiting your domain choices.
  • This isn’t just about branding. It’s about sovereignty. If you can’t change the mail server, you don’t control the flow of your data.
  • With Unifiedesk, you can set up any domain with real-time DNS record generation—just follow the custom domain setup guide.

Complete control, when you want it

  • If you’re serious about privacy, consider self-hosting. It’s not for everyone—but it gives you full ownership.
  • With self-hosting, your data never leaves your infrastructure. Encryption keys stay with you. Even the provider can’t access your inbox.
  • Unifiedesk offers a self-hosted option: run the full suite—email, calendar, Meet, Drive, Docs, contacts, and AI—on your own server, with full per-account encryption.
  • See how it works: self-hosted deployment with complete data residency control.

How Unifiedesk delivers end-to-end encryption — and where others fall short

Unifiedesk ensures your messages and files are encrypted before they leave your device, with no central key server—meaning only you and your recipient (or team) can access them. Unlike many providers that store decryption keys on their servers, Unifiedesk’s hosted platform delivers true end-to-end encryption, and self-hosted deployments use AES-256-GCM with per-account keys, eliminating any third-party access. This design protects your data from insider threats, breaches, and government subpoenas.

How true end-to-end encryption works in practice

Let’s be clear: end-to-end encryption isn’t a checkbox—it’s about where the keys live. With Unifiedesk, the encryption happens on your device before anything leaves. Even if someone intercepts your mail in transit, the data remains unreadable. This is the same principle recommended by the IETF’s Mail Privacy Extensions (MPEx) standard, which emphasizes controlling keys on the sender and receiver side.

That’s why we don’t store encryption keys on our servers anywhere. The hosted platform uses device-side encryption, and self-hosted setups use per-account keys stored only on your infrastructure. No single point of failure. No backdoor. Just your data, protected by AES-256-GCM—widely regarded as the gold standard in symmetric encryption.

Security beyond encryption: email authentication and deliverability

Encryption keeps your content private, but authentication keeps your messages from being flagged as spam or spoofed. Unifiedesk signs every outbound email with DKIM, and enforces SPF, DKIM, and DMARC on inbound mail—meaning you send and receive safely, with less risk of being blocked.

This matters because even the strongest encryption can’t fix poor deliverability. A message encrypted but incorrectly authenticated may land in a spam folder. By supporting industry-standard DNS records, Unifiedesk helps your emails reach inboxes reliably.

And while you’re thinking about privacy, note: no cloud provider, not even Proton or Tuta, can claim this same level of key control across both hosted and self-hosted models. Most only implement encryption in transit or for parts of a message. Unifiedesk offers full control—whether you choose to host it yourself or use our secure cloud.

See how it all comes together across your email, calendar, drive, and team tools: mail, drive, AI assistant, and more. You keep ownership, no matter how you use it.

The real trade-off: convenience vs. control — what you lose when you trust a cloud provider

When you use a hosted email service, you trade full control over your data and keys for ease of setup and maintenance. Even if they promise end-to-end encryption, the provider still manages the infrastructure, access logs, and key storage — meaning they can, in theory, access your messages or metadata. True privacy only exists when you control the entire system.

What you get with hosted services

Hosted providers like Proton Mail or Tuta make encryption and domain setup fast and reliable. You don’t need to worry about servers, updates, or backups. But here’s the catch: even if your messages are encrypted, the service provider still controls the keys and stores metadata like who you emailed, when, and from where. This data is often retained, even if encrypted, and can be accessed under legal request.

For example, the European General Data Protection Regulation (GDPR) requires clear data retention policies, but enforcement varies. Some cloud providers claim "zero access" to your data, but metadata can still be logged by default — and that’s not always disclosed.

What you gain with self-hosting

Self-hosted email platforms like Unifiedesk give you full control: you manage the server, the keys, and the data. Your messages and files are encrypted at rest with AES-256-GCM under per-account keys, and TLS secures data in transit. No third party ever touches your data — not even the provider.

But it’s not magic. You’re now responsible for daily maintenance: security updates, backups, monitoring for attacks, and scaling. If you forget to patch the OS, your data is exposed. If you lose your private key, your data is gone forever. This isn’t for the faint-hearted — but it’s the only way to ensure no centralized point of failure or surveillance.

Luckily, Unifiedesk supports both models. If you want simplicity, use the hosted service — it’s end-to-end encrypted by default. If you need total control, deploy Unifiedesk On-Premise or use the self-hosted version. You get the same encryption, same features — just under your own roof.

Remember: encryption doesn’t protect against bad decisions. The real barrier isn’t code — it’s trust. The moment you hand over your keys or your server, you’re trading privacy for convenience. The best encrypted email providers in 2024 aren’t defined by hype — they’re defined by how much control they let you keep.

How to compare encrypted email providers — real features, not marketing claims

You can’t trust “encrypted” claims unless the provider says exactly who holds the keys. Real privacy means no one—not the company, not its employees—can read your messages. Ask: can they scan for malware or enforce policies? If yes, they’re not end-to-end. Look for JMAP, not just IMAP. And verify if custom domains are fully supported with real DNS record generation—no hidden hurdles.

What to check—no fluff

  • Ask: Who holds the encryption keys? If the provider says “we use TLS,” that’s only for transit. Ask if they can decrypt your messages. If yes, no real privacy. End-to-end means only you (and your intended recipient) can read what’s sent.
  • Check if they can scan your messages. Some providers claim “encryption” but retain the ability to read content for malware checks or compliance. For true privacy, scanning must happen on your device—never on their servers.
  • Look for JMAP, not just IMAP. JMAP is the modern standard (RFC 8457), built for real-time sync, mobile efficiency, and minimal server load. IMAP is legacy and inefficient. If a provider only supports IMAP, it’s likely cutting corners.
  • Custom domains: can you set them up without hassle? A real encrypted service lets you use your own domain with full control. Look for providers that generate exact DNS records (MX, SPF, DKIM, DMARC) instantly—not just instructions.
  • Verify record names and formats. SPF uses include:_spf.unifiedesk.com, DKIM uses a selector._domainkey.example.com TXT record. If they don’t match industry standards (RFC 7208, RFC 6376), they’re not playing by the rules.
  • Can you self-host? If privacy is your goal, you want full control. Self-hosting means you own the keys, servers, and data. A service like Unifiedesk offers a full self-hosted option with open-source code on your own infrastructure.

Why this matters—real-world trade-offs

Most “secure” email services keep your keys. That means they can read your messages—not just for ads, but for “compliance,” “security scans,” or policy enforcement. That’s not privacy; it’s convenience at your expense. True privacy is when no one—not even the provider—can access what’s encrypted with your keys.

Modern protocols like JMAP are critical. IMAP is outdated and doesn’t support push, snooze, or smart filtering. If your provider still uses only IMAP, syncing is laggy, inefficient, and limits features. JMAP, however, enables real-time sync and better mobile performance—proven scalable in large deployments RFC 8457.

And yes—custom domains should come with full DNS control. If generating MX and DKIM records requires guesswork or external tools, it’s not user-friendly. Unifiedesk generates all required records automatically at setup in seconds, so you’re not stuck with config errors or spam.

Let’s not confuse “we use encryption” with “we can’t read it.” Only when you control the keys—and can verify it—do you win. The rest is marketing. Check the details. Your data deserves better.

Setting up your private email with a custom domain — a step-by-step process

You can set up a fully encrypted, self-owned email address with your own domain in under 10 minutes. Buy a domain from a privacy-respecting registrar, add it in Unifiedesk, and paste a few DNS records exactly as provided. Once propagated, you’re using a private, encrypted mailbox—with full control, no data harvesting, and the ability to extend to calendar, drive, and AI tools.

Step 1: Buy a domain you actually own

Start with a trusted registrar like Namecheap, Cloudflare, or Gandi. These providers let you register domains without mandatory data collection. Avoid registrars that sell your contact details to third parties—privacy begins with ownership.

Step 2: Add your domain in Unifiedesk

Go to your Unifiedesk account, open the domain setup section, and enter your domain (e.g., yourname.com). Unifiedesk will generate the exact DNS records you need: MX, SPF, DKIM, and DMARC. These control how mail reaches you, prevents spoofing, and ensures inbox delivery.

  1. Find your DNS records. In Unifiedesk, select “Add Domain” and look for the list of records provided. Copy them byte-for-byte—no changes, no truncation.
  2. Go to your registrar's DNS panel. Log in to your domain registrar’s dashboard. Navigate to DNS management (often under “Domain Management” or “DNS Settings”).
  3. Paste the records exactly as shown. For example, add an MX record pointing to mail.unifiedesk.com, SPF with v=spf1 include:unifiedesk.com ~all, DKIM and DMARC in the same format. Use the same record names and values—no typos.
  4. Wait for DNS propagation. This can take 5 minutes to 60 minutes. Use tools like MXToolbox or dnscheck.org to verify all records appear in public DNS.
  5. Confirm in Unifiedesk. Return to Unifiedesk and click “Verify Domain.” If all records match, you’ll get a green checkmark. You’re now ready to use your custom email.

Once verified, you can start sending and receiving encrypted email with any device. Your messages are end-to-end encrypted in the hosted version, and files in Drive are protected with per-account AES-256-GCM keys. You’re no longer at the mercy of third-party platforms that scan your inbox for ads.

From here, extend your workspace: add calendar events with encryption, share files via secure, expiring links, or collaborate in real time on documents using browser-based tools. Every part of Unifiedesk is designed to give you control without compromise.

When you’re ready to take full ownership, explore self-hosting—run the entire stack on your own servers. All configurations remain identical; the only difference is where the software runs.

Unifiedesk’s privacy architecture: why open-source doesn’t mean secure — but helps

You don’t get privacy just because code is open. Open-source lets you check the locks, but true security comes from how the system is built: encryption on your device, no server-side keys, and a zero-trust design that assumes everything is compromised. Unifiedesk is open-source, yes — but that’s just the first step. The real protection is in the architecture.

The open-source trap

Just because the code is public doesn’t mean it’s safe. Many projects tout open-source as a privacy seal of approval, but that’s a myth. Anyone can publish code, even flawed or backdoored versions. True transparency isn’t about access — it’s about meaningful auditability.

Open-source lets us verify what’s built in, but only if you know what to look for. That’s why we make the full codebase available at GitHub — not as a promise, but as a challenge. If you’re skeptical, read it. Look for flaws. We’re not hiding anything.

Architecture is where trust lives

Open-source helps, but the real defense is client-side encryption: your data is encrypted before it ever leaves your device. No key ever touches our servers — not even in memory. This isn’t a choice; it’s the foundation.

Our hosted platform uses end-to-end encryption by default. Every message, file, and calendar event lives encrypted on your device, never decryptable on our servers. Even if a breach happens — which our security model makes extremely unlikely — your data stays yours.

Self-hosted deployments go further: AES-256-GCM encryption at rest, per-account keys, and full control over where data resides. You’re not just auditing code — you’re controlling security. That’s privacy by design, not just branding.

Check the email security landscape: TLS 1.3 protects data in transit, but that’s only half the battle. The other half — protecting data when it’s stored and when it’s accessed — is where open-source doesn’t help alone. It helps us build the right systems, but only architecture ensures you stay in control.

Want to dive into how it works across your inbox, calendar, or drive? See how we protect email, calendar, files, and more. Or run your own instance with full privacy: self-hosting.

What the free @unifiedesk.com mailbox offers — and why it’s a safe starter

You can test a fully encrypted email system in under a minute with the free @unifiedesk.com mailbox. No sign-up, no credit card — just start using email with end-to-end encryption, snooze, undo-send, and Sieve filters all working out of the box. It’s designed for evaluation, not commitment. If you’re exploring privacy-focused tools, this is how you begin safely.

What you get immediately

  • 1 GB of storage — enough for months of typical use without clutter or pressure to upgrade.
  • End-to-end encryption enabled by default — no setup, no keys to manage. Your messages are encrypted at rest and in transit.
  • Core privacy features work right away: snooze, undo-send (within 10 seconds), and Sieve filters for automated inbox management.
  • No account creation required: access begins with a single click, ideal for trying the interface or assessing encryption in practice.
  • All features run on the hosted platform — meaning you don’t need to install software, manage servers, or deal with TLS configuration.

Why it’s a low-risk entry point

Free tiers often limit functionality — not here. The mail service includes all core features, so you can test true encryption and privacy without compromise. You're not locked into a trial that ends abruptly.

If you’re serious about control, you can upgrade to a custom domain in minutes using our domain setup wizard. It auto-generates the required DNS records — MX, SPF, DKIM, DMARC — and enforces them in real time. No guesswork, no delays. This is how real privacy works: by design, not effort.

For comparison, mainstream providers offer encryption but retain access to your content. Unifiedesk’s model — where even the servers can't read your data — aligns with RFC 8314, the standard for encrypted transport and storage in email systems [IETF]. That’s not marketing. It’s how email should work.

Once you’re ready to scale, you can seamlessly expand to Drive, Docs, Meet, Contacts, and AI — all unified under one secure, self-hosted or hosted architecture. But the free mailbox isn't a demo. It’s a real, fully operational inbox built for privacy.

How Unifiedesk works with AI — without compromising your privacy

You can use the AI assistant in Unifiedesk with full privacy control: it works with any OpenAI-compatible endpoint—on your own server or publicly—and your prompts never train the model by default. Data stays local unless you opt in, and no logs are kept unless you configure a backend that does. You retain control over what gets shared.

Choose your AI backend—on your terms

Unifiedesk’s AI assistant isn’t tied to a single provider. You can connect it to services like OpenAI, or run your own models—such as Llama 3—on your own infrastructure. This means your data never leaves your control, even when using AI.

Whether you're using a cloud-hosted AI or a self-hosted model, the system treats your input as confidential. No matter the endpoint, your prompts and responses are processed exactly as you configure, with no assumption of data retention.

No logs, no training, no surprises

By default, Unifiedesk does not store your AI prompts or responses. This follows a principle common in privacy-focused systems: never log what you don’t need. If you want to keep logs, you must set up a custom backend that does so explicitly—there’s no hidden tracking.

And crucially, your input is never used to train the AI model. That’s not a policy—it’s a built-in design choice from the start. Even if you're using a third-party model, Unifiedesk ensures your data isn’t added to their training pool.

For those who want to go further, you can disable AI entirely or limit its access to certain workspaces. The AI assistant doesn’t have persistent access to your inbox, calendar, or files unless you grant it—down to the individual contact, doc, or meeting.

Learn more about how Unifiedesk keeps your data private by default: security details. If you're running your own instance, see how self-hosting works. For a complete setup, get your custom domain up fast with built-in email encryption and all the privacy controls you’d expect.

The internet doesn’t need more data harvesting. It just needs better tools. Unifiedesk lets you use AI the way it should be: powerful, private, and fully under your control.

The future of private email: self-hosting is not a niche, it’s an option in reach

Open-source tools like Unifiedesk have made self-hosting realistic for individuals and small teams. You no longer need to manage a datacenter or master complex server administration.

Docker and cloud VMs handle the heavy lifting. Setting up your own email, calendar, and workspace suite now takes minutes, not weeks.

With self-hosting, you control where your data lives, how it’s protected, and who can access it. This level of sovereignty isn’t a luxury—it’s a practical choice for anyone serious about privacy.

Keep reading

Ready to put this into practice? Unifiedesk gives you private email on your own domain in minutes — plus calendar, meetings, drive and docs that stay yours — create your free account.

Frequently asked questions

Is end-to-end encryption the same as TLS?

No. TLS encrypts data in transit, but the provider can still read it at rest. End-to-end encryption means only the sender and recipient can decrypt messages — not even the provider.

Can I use my own domain with Unifiedesk?

Yes — add your domain in minutes. Unifiedesk generates MX, SPF, DKIM, and DMARC records automatically, with live setup in under 10 minutes.

Does Unifiedesk store my encryption keys?

No. Hosted deployments use a system where keys are never stored on servers. In self-hosted mode, keys are encrypted at rest using AES-256-GCM under per-account keys.

Can I access Unifiedesk on mobile or desktop?

Yes — Unifiedesk has native apps for iOS, Android, macOS, and Windows with full encryption and feature parity.

How does Unifiedesk handle file sharing?

Files in Drive are encrypted at rest with per-account keys. Share links expire automatically and require passwords if configured.

Does Unifiedesk support video meetings?

Yes — Meet includes screen sharing, recording, and group calls, all secured end-to-end with encrypted media.

Can I self-host Unifiedesk?

Yes — the self-hosted / on-premise option is available for teams and individuals who want full control over their data and infrastructure.

Is Unifiedesk GDPR compliant?

Unifiedesk supports data residency and user rights. Compliance with GDPR or similar regulations requires local consultation and setup.

What file types does Unifiedesk support in Docs?

Native support for .docx, .xlsx, .pptx and ODF formats. All documents render in the browser with no install needed.

How does Unifiedesk protect against email spoofing?

It enforces SPF, DKIM, and DMARC validation on inbound mail and signs outbound messages with DKIM, reducing spoofing and phishing risk.

Is the AI assistant safe to use with sensitive data?

Yes — by default, AI input isn't stored or used for training. You can connect to self-hosted models to keep all data internally.

How secure is the encryption on Unifiedesk's hosted platform?

Hosted Unifiedesk is end-to-end encrypted — data is encrypted on your device before it leaves your control. No server-side decryption occurs.