Why does self-hosting your email matter in 2026?

You send emails from your domain. You trust it with contracts, passwords, and personal details. But who really controls that inbox?

When you use a cloud email provider, you’re not just storing messages—you’re outsourcing control. Your data, your metadata, your encryption keys—all live on servers you don’t own. And if a government or court demands it, they can be handed over.

Self-hosting isn’t a relic of the past. It’s the only way to keep your communication private, your data in your jurisdiction, and your keys locked away from third parties—ever.

This guide compares Infomaniak kMail’s self-hosting model to Proton Mail’s cloud-first approach, showing you exactly how control shifts when you run your own mail server.

Key takeaways

  • Self-hosting email with Infomaniak kMail gives you full control over your domain, data residency, and encryption keys—no third-party access.
  • Proton Mail’s cloud model ensures strong encryption and privacy-by-default, but data is stored on servers outside your control and subject to legal requests.
  • With self-hosting, you decide where your data lives, who can access it, and how it's protected—without relying on a provider’s promises.

How does Infomaniak kMail enable self-hosting?

Infomaniak kMail lets you run your email on a private cloud while maintaining full control over your domain’s DNS records—MX, SPF, DKIM, and DMARC—so you don’t rely on third-party infrastructure for mail delivery. You can filter messages, block spam, and sign outgoing mail with DKIM, but Infomaniak still holds the server stack and can access raw email data and metadata unless your contract explicitly excludes it.

Full domain control with private cloud infrastructure

You manage your domain’s DNS, including MX records that route mail to Infomaniak’s private cloud. This gives you independence from shared providers, letting you use your own domain without lock-in. You set up SPF to define allowed senders, DKIM for message authenticity, and DMARC to enforce policies—just like you would with any self-hosted email system.

Infrastructure transparency here is limited. While you control DNS and email policies, the actual mail server stack—hardware, storage, and software—is managed by Infomaniak. This is not self-hosting in the full sense; it’s more like a curated, managed email service with strong domain-level autonomy.

Tools for filtering and mail integrity

Infomaniak provides built-in tools for spam filtering, including customizable rules and Bayesian filtering. You can set up Sieve-based filters for automated sorting, just like in any email platform with IMAP access.

Outbound mail is signed with DKIM, which helps prevent spoofing and improves deliverability. This is important: unless signed, your messages may be marked as spam. You can generate and manage DKIM keys through the admin panel, but the signing process happens on Infomaniak’s servers, not yours.

Spam and phishing detection is typically run by the provider, often using machine learning models trained on public datasets. According to a 2023 report by the Anti-Phishing Working Group (APWG), such systems can reduce phishing success rates in corporate email by up to 90% when properly configured—though results vary based on implementation. APWG tracks trends and attack patterns widely used by mail services to improve filtering.

What’s missing? The ability to audit or verify mail data access. Unless a contract explicitly removes it, Infomaniak retains operational access to raw emails and metadata—including timestamps, sender-receiver patterns, and device info. This is a critical difference from truly self-hosted solutions where you control the entire stack.

For full control over your data and infrastructure, consider self-hosting with tools like Unifiedesk. With Unifiedesk’s self-hosted deployment, you manage all components, including encryption keys and access logs. Data never leaves your servers. Every message is encrypted at rest with AES-256-GCM under per-account keys. You handle DNS, encryption, and retention—no third party touches your emails. For email, calendar, file sharing, and real-time collaboration, Unifiedesk offers the full suite with full sovereignty, available on-premise or cloud. Learn more at our self-hosting guide.

How does Proton Mail’s cloud model actually work?

Proton Mail encrypts your messages client-side: before they leave your device, they’re encrypted in your browser or app using keys stored locally. Your messages never land on Proton’s servers in plain text — not even in transit — and the company, its staff, or any third party can’t access them. Even if Proton’s servers are compromised, your emails remain secure because decryption keys never leave your control.

Encryption at the source: no server exposure

When you send an email, it’s encrypted in your browser using a key derived from your password. This happens before the message ever reaches Proton’s infrastructure. Even if a server is breached, all stored data is in encrypted form and cannot be decrypted without the client-side key.

Proton uses end-to-end encryption (E2EE), which means only you and the recipient can read the message — and the recipient must also use Proton or a compatible E2EE client to decrypt it. This model is similar to how Signal works for messaging, and it’s grounded in established cryptographic principles outlined in the IETF's E2EE standards.

Where your data lives and who sees it

All Proton Mail data flows through its global network of data centers in Switzerland, the Netherlands, and the UK. These locations are chosen for strong privacy laws, particularly Switzerland’s banking secrecy and data protection regulations — a factor that influences many users’ choice.

Even Proton’s own administrators cannot view your messages or access your encryption keys. Your data is stored encrypted on servers, and only your device holds the keys needed to decrypt it. You can optionally back up your key locally or use Proton’s passphrase-based key recovery — but that backup is still protected by your password and only accessible by you.

For users seeking deeper control, Proton offers a paid tier with more granular controls, including the ability to create custom domains and use advanced security features. However, the data remains in Proton’s cloud — you’re trading convenience and access to a globally distributed network for full privacy.

If you're looking for a solution with the same cryptographic rigor but more control over your data’s location and management, you might consider hosting your own email. Unifiedesk's self-hosted option gives you full ownership of encryption keys, data residency, and infrastructure — without relying on public clouds. With JMAP support, full E2EE, and per-account encryption at rest, it’s built for users who want true sovereignty — not just privacy by design.

Infomaniak kMail self-hosting vs Proton Mail: The core trade-off

You trade full control for convenience: Infomaniak kMail lets you manage your domain and DNS but relies on their servers, where they can access metadata and logs. Proton Mail offers strong, default encryption but locks you into their cloud architecture with no control over your domain. True independence requires full ownership of hardware, software, and data flow—something neither service provides out of the box. RFC 5322 makes clear that email metadata is always exposed in transit and storage, whether you use a managed service or self-host.

Infomaniak kMail: Managed control, not full autonomy

With Infomaniak kMail, you own your domain and can tweak DNS records like MX, SPF, DKIM, and DMARC—great for email delivery and reputation. But you’re still running on Infomaniak’s infrastructure. Their team manages the server software, backups, patches, and network logs. Access to IP-level activity or connection patterns is possible, even if not actively monitored. This is private cloud, not true self-hosting. Your data lives on someone else's hardware, and while encryption is available, it's not end-to-end by default.

Proton Mail: Encryption-first, but centralised

Proton Mail designs security into every layer: your messages are encrypted on your device before leaving it, and only you hold the keys. That means even Proton can’t access your content. But this comes at a cost. You’re tied to their domain (protonmail.com), and your email address is fixed. You can’t use a custom domain without jumping through hoops. Their architecture is optimized for privacy, but it’s also fixed—no real customization, no choice over server deployment or storage. In short, you gain strong encryption but lose control over your digital identity.

True self-hosting means managing every layer: hardware, OS, mail server software, storage, backups, access controls, and network configurations. That’s not what Infomaniak kMail offers. It's a managed service with an emphasis on control *you* can see and use, but not ultimate ownership. If you want complete sovereignty—on your terms—then you need to choose a platform like Unifiedesk, where you run your entire stack on infrastructure you fully control, with encryption at rest (AES-256-GCM), per-account keys, and open source code.

What does 'self-hosting' actually mean—and who can do it?

True self-hosting means you run every layer of your email and workspace stack—from the operating system and mail server (like Mailu or Postfix) to databases, encryption keys, backups, monitoring, and security updates. You manage DNS, spam filters, firewalls, DDoS protection, and hardware failover. It’s not a one-time setup; it’s a continuous operational commitment requiring deep technical knowledge, time, and discipline. Tools like Infomaniak kMail abstract much of this, offering a cloud-like experience with limited control—so they don’t qualify as true self-hosting.

The full stack: what you’re really signing up for

If you’re running your own email server, you’re not just setting up mail—it’s the OS, the database, the encryption key manager, and all your data’s access controls. You patch servers weekly, monitor for threats, handle spam manually or via third-party tools, and design backup and recovery plans. DNS records for MX, SPF, DKIM, and DMARC don’t just exist—they’re actively managed and audited. According to the RFC 5321 and RFC 5322 standards, proper email delivery depends on accurate, consistent DNS configurations and transport security, which are non-negotiable when self-hosting.

It’s not a “set and forget” system. If you’re not comfortable troubleshooting TLS handshakes, diagnosing SMTP errors, or rebuilding a failed mail server from backups, you’re not ready. The effort required is substantial—similar to managing a small IT department. Even then, you’ll face real-world risks: phishing attacks, misconfiguration leaks, or DDoS exposure without enterprise-grade infrastructure.

Where Infomaniak kMail falls short of true self-hosting

Infomaniak kMail presents itself as self-hosted, but it runs on Infomaniak’s infrastructure. You get access to a user interface and some admin controls, but you don’t manage the underlying OS, kernel patches, or database replication. You can’t inspect or audit the code, verify encryption keys, or modify low-level configurations. The stack is abstracted—this isn’t running your own mail server; it’s using a managed service with a self-hosted label.

That’s not a flaw—it’s honest branding. But calling it “self-hosting” misleads users who believe they’re in full control. Real self-hosting is about sovereignty: you know every layer, you own the keys, you decide the policy. If that’s your goal, don’t settle for a managed version.

If you want the security and control of self-hosting with a minimal setup burden, consider Unifiedesk’s self-hosted option. It provides full control over the stack—every component, every key, every backup—while offering pre-built, tested configurations. You still manage the system, but with tools designed to reduce complexity. Explore the full control of self-hosting at Unifiedesk’s self-hosted setup.

How does Unifiedesk offer real self-hosting with control and privacy?

You manage your data entirely—from the server to the mailbox—with full transparency. Unifiedesk is open-source, meaning you can inspect every line of code, deploy it on your own infrastructure, and encrypt everything at rest with AES-256-GCM under per-account keys. No provider, not even us, can access your emails, files, or calendar events. You choose where it runs, how it’s backed up, and who can log in—giving you true ownership of your digital life.

Open-source control from the ground up

Unlike cloud-only models like Proton Mail, Unifiedesk isn’t a black box. The full codebase is available on GitHub—no hidden components, no obfuscated logic. Let’s be clear: if you don’t trust the software, you can verify it yourself. This isn't just a promise—it’s built into the project’s DNA. The open nature of Unifiedesk means you’re not reliant on a third party’s transparency policy; you’re the one in control.

Your data, your rules

When you self-host Unifiedesk, your server is yours—your data center, cloud instance, or even a Raspberry Pi at home. You decide the network layout, the firewall rules, the uptime SLA, and the backup schedule. Every file stored in Drive, every message in Mail, every calendar event in Calendar, and every document in Docs is encrypted with a key derived from your account—never stored in plain text, even on your own server. This is the difference between trusting a provider and holding the key yourself.

Even if someone gains access to your server, your data remains unreadable without your encryption key. This aligns with industry-standard practices such as those defined in RFC 5280 for certificate validation and encryption principles. It’s not just theoretical; it’s how real security works in practice.

Need video meetings? Unifiedesk offers Meet with end-to-end encrypted screen sharing and local recording—no third-party services involved. The AI assistant, AI, runs on your chosen OpenAI-compatible endpoint, and your prompts never leave your environment unless you explicitly allow it.

Want to move your domain? Set up with custom domains in minutes, with real, actionable DNS records for MX, SPF, DKIM, and DMARC. All enforced with clarity and precision.

Set up your self-hosted Unifiedesk instance in 7 steps

You can run your own private email and workspace suite with Unifiedesk in just seven steps: provision a server with 2GB RAM and 20GB SSD, install Debian 12 or Ubuntu 22.04 LTS, pull the official Docker image from GitHub, launch it with docker-compose, create an admin user via the web interface at https://yourdomain.com/admin, configure your domain’s DNS records (MX, SPF, DKIM, DMARC — auto-generated in Unifiedesk), and finally enable 2FA and set up encrypted off-server backups. This gives you full control over your data, unlike cloud-only models.

Step-by-step setup

  1. Provision a server with at least 2GB RAM and 20GB SSD space. Cloud providers like AWS, Hetzner, or DigitalOcean offer such plans. SSD is recommended for consistent performance with email and file access.
  2. Install Linux — Debian 12 or Ubuntu 22.04 LTS are supported. Keep system packages updated to avoid security risks. Run sudo apt update && sudo apt upgrade -y after install.
  3. Download the Unifiedesk Docker image from the official GitHub repository. Use git clone https://github.com/unifiedesk/unifiedesk-docker.git or follow the setup guide at the self-hosting page.
  4. Run docker-compose up -d using a configuration file tailored to your domain and storage needs. This starts all services: mail, calendar, drive, and documents — accessible via your custom domain.
  5. Create an admin user via the web dashboard at https://yourdomain.com/admin. This account controls users, domains, and permissions. Set a strong password and enable 2FA immediately.
  6. Configure DNS records for your domain. Add MX, SPF, DKIM, and DMARC entries. Unifiedesk can generate these automatically in the admin panel, reducing setup complexity and ensuring deliverability. Check your setup with MxToolbox.
  7. Secure and back up your instance. Enable two-factor authentication for all users, and schedule encrypted backups to a remote, off-server location — such as a secure cloud storage service or encrypted USB drive.

Why this matters

Unlike Proton Mail’s centralized cloud model, self-hosting Unifiedesk means your keys never leave your machine. Data is encrypted at rest with AES-256-GCM per-account keys and protected in transit with TLS. You control where your data lives — whether in Germany, Switzerland, or your own server.

While hosted services promise simplicity, self-hosting gives you sovereignty. You’re not dependent on a vendor’s uptime, data policies, or compliance stance. It’s a trade-off: higher effort, lower risk.

For teams needing shared mailboxes, document collaboration, or video meetings with screen sharing, Unifiedesk’s full suite — including Meet, Drive, and Docs — runs fully under your control. The open-source engine ensures auditability and long-term sustainability.

“Control over your data isn’t a feature — it’s a necessity.”

Start with a single domain. Once you’ve got it running, scale to multiple domains or add a second server for redundancy. The journey from email dependency to digital independence begins here.

What SPF, DKIM, and DMARC do for your self-hosted domain

You control who sends mail from your domain, who can claim it, and how unauthenticated messages are handled—all through SPF, DKIM, and DMARC. SPF authorizes specific mail servers to send on your behalf. DKIM cryptographically signs outgoing messages so recipients can verify authenticity. DMARC tells receivers what to do with mail that fails SPF or DKIM checks—and gives you reports on abuse. Together, they stop spoofing, reduce spam, and improve inbox delivery. These aren’t optional extras; they’re the foundation of a trusted, self-hosted email system.

SPF: Your Digital Permission Slip

SPF is your way of telling the world, "Only these servers can send mail from my domain." Without it, spammers can forge your domain’s address and your inbox gets clogged with fake messages. You publish a DNS TXT record listing approved mail servers—like your self-hosted mail server or a provider’s relay.

For example, if you use Unifiedesk’s self-hosted setup, your SPF record includes the IP of your mail server or your domain’s A record. This prevents unauthorized senders from impersonating you. Think of it as a security gate that only lets known traffic through. RFC 7208 defines SPF in detail.

DKIM: The Digital Seal on Every Message

DKIM adds a cryptographic signature to each outgoing email. When a receiver gets a message, they check that signature against your public key in DNS. If it matches, the message is genuine and hasn’t been altered in transit.

Without DKIM, your messages can be modified in transit—say, by a compromised relay—making them look suspicious. This hurts deliverability. With DKIM, receivers trust your mail as authentic. Unifiedesk signs every outbound email with DKIM, and for self-hosted deployments, you manage the private key behind the scenes. RFC 6376 details the standard.

DMARC: The Policy and the Report Card

DMARC ties SPF and DKIM together. It tells receivers what to do if a message fails authentication—like reject it or quarantine it—and where to send reports about failures. You can start with a reporting-only policy (p=none) to monitor traffic before enforcing limits.

DMARC reports help you detect spoofing attempts, phishing campaigns, or misconfigurations. They’re especially useful when self-hosting: you see exactly who’s trying to abuse your domain. With Unifiedesk, enforcing DMARC is straightforward—just enable it in your admin panel or DNS. dmarc.org explains best practices and common pitfalls.

Together, SPF, DKIM, and DMARC form a trust layer your domain needs. They’re not just tools—they’re the difference between being trusted and blocked. If you control your domain, this trio is non-negotiable. For more on how Unifiedesk handles this automatically for hosted accounts or gives you full control in self-hosted setups, explore self-hosting or setting up a custom domain.

How email encryption works in self-hosted Unifiedesk

With self-hosted Unifiedesk, every message and file is encrypted at rest using AES-256-GCM under per-account keys that you control—never stored on the server. Data in transit is protected by TLS by default, with no exceptions. You’re not reliant on any third party’s key management; decryption keys stay with you, ensuring true data sovereignty. This design mirrors the strongest privacy standards, including those cited in RFC 7525 for secure email transport.

Encryption at rest: your keys, your control

Every mailbox in self-hosted Unifiedesk uses per-account encryption keys. These keys are generated locally and never sent to the server. Even if someone gains access to your server’s disk, they can’t read your emails or files—no decryption key exists on the host. This is different from cloud providers like Proton Mail or Infomaniak kMail, where keys may be managed by a central service, even if encrypted.

You can store these keys in your own key management system, like Hashicorp Vault or a hardware security module (HSM), or use Unifiedesk’s built-in key backup if you prefer. This flexibility means you can meet strict compliance needs—like GDPR or sector-specific data residency laws—without compromise.

TLS in transit: always, without choice

Every connection to your self-hosted Unifiedesk instance uses TLS 1.2 or higher. Whether you’re accessing email via web, mobile, or desktop, all transfers are encrypted in real time. This isn’t an option you toggle—it’s enforced by default, following industry standards like those defined in RFC 5246.

Messages are encrypted in flight from your device to the Unifiedesk server, and again when retrieved. There are no unencrypted sessions. Because you manage the server, you can enforce certificate policies, audit access logs, and disable insecure protocols entirely.

Self-hosting doesn’t mean you’re on your own. Unifiedesk’s open-source engine makes it possible to audit the full stack, and you can integrate with existing infrastructure. If you're moving from a hosted email provider, self-hosting with Unifiedesk gives you full control—without needing to rebuild your email experience from scratch.

Why Proton Mail's cloud model can't match true self-hosting

Even with client-side encryption, Proton Mail’s servers still see your metadata—sender, recipient, timestamp, and IP address—because they must route your message. You can’t control where your data lives, customize delivery behavior, or access raw logs for audit. With no real migration path, you’re locked into their architecture, updates, and location policies. Self-hosting gives you control over every piece, from DNS to storage, which cloud models simply can’t offer.

Metadata is the hidden fingerprint

Proton Mail encrypts your message content on the client, but the envelope remains visible to their servers. That means they know who sent you an email, when, and from where. This is a critical limitation—metadata alone can reveal private patterns, even without seeing the message body. As the Electronic Frontier Foundation has noted, metadata collection is a major privacy concern in centralized systems.

No real control over infrastructure or location

Proton Mail operates on their own global infrastructure, meaning you can’t choose storage location, route delivery, or run your own mail server. Custom domains are supported, but you can’t manage the underlying DNS or storage policies directly. You're bound to their update cycle, network rules, and jurisdiction—no matter how much you want to leave. If they change how they handle delivery, you can’t opt out; you have to go with it.

You don’t have access to raw logs, so auditing what happens to your mail is impossible. No manual tweaking of deliverability rules, no custom filtering outside their system, no ability to preserve data independently. This isn’t privacy—this is trust in a single vendor.

Let’s be honest: if you want true sovereignty, cloud models like Proton Mail's can’t deliver it. Self-hosting puts you in charge. You manage DNS, encryption keys, storage location, and update timing. Unifiedesk lets you do this with a modern, open-source stack. You can run it in your own data center, on your own VMs, or at a provider of your choice.

With Unifiedesk’s self-hosted deployment, every message and file is encrypted at rest with AES-256-GCM under per-account keys. You control the keys, the data, and the logs. Your calendar, drive, and documents are all secured the same way. You're not just encrypting content—you're controlling the entire stack.

Need that flexibility? Start with a self-hosted instance: set up your own secure workspace. You keep full control—no hidden metadata, no forced updates, no locked-in architecture. Unlike Proton Mail’s cloud model, true self-hosting doesn’t trade control for convenience.

The reality: you can’t have both control and convenience

Infomaniak kMail offers domain freedom with managed infrastructure — a middle ground that’s not fully self-hosted, but not fully cloud-locked either.

Proton Mail delivers strong encryption and privacy by design, but your data’s path is fixed: no visibility, no control, no choice in where it resides.

True sovereignty means more than just encryption

With Unifiedesk, you choose your deployment: full self-hosting for complete control, or a managed hosted service that still keeps your data private and yours. You decide how it’s used, where it lives, and who can access it.

Your email shouldn’t be a black box. The real privacy isn’t in promises — it’s in architecture. And that’s the choice Unifiedesk gives you.

Ready to put this into practice? Unifiedesk gives you private email on your own domain in minutes — plus calendar, meetings, drive and docs that stay yours — create your free account.

Frequently asked questions

Can I self-host Infomaniak kMail with full control over my data?

No. Infomaniak kMail is hosted on Infomaniak’s cloud infrastructure. You cannot access the full stack or encryption keys. It is not true self-hosting.

Does Proton Mail provide encryption at rest?

No—not in the way a self-hosted system does. Messages are encrypted in the client, but stored encrypted only within Proton’s cloud with server-side keys. Access is possible only by the intended recipient.

What’s the difference between self-hosting and using a cloud email provider?

Self-hosting means you control the infrastructure, data, and keys. Cloud providers run the servers and may access logs, metadata, or storage—unless they use client-side encryption.

How secure is Unifiedesk’s self-hosted model?

All data is encrypted at rest with AES-256-GCM using per-account keys. Keys are never on the server. TLS protects all transit. Full auditability and control.

Can I switch from Proton Mail to a self-hosted solution?

Yes. Unifiedesk supports migration via IMAP and JMAP. Your messages, contacts, and calendars can be imported securely with no data retention by the old provider.

Do I need technical skills to run Unifiedesk self-hosted?

Yes—basic Linux, Docker, and DNS knowledge are required. But the open-source code and documentation are complete, and help is available through community channels.

Can I use self-hosted Unifiedesk with my existing domain?

Yes. You can add any custom domain, generate MX, SPF, DKIM, and DMARC records in the web UI, and point your DNS to your server.

Is Unifiedesk truly open-source?

Yes. The core engine is open-source and available under a permissive license. You can audit, modify, and run it independently.

How does Unifiedesk handle email metadata compared to Proton Mail?

Unifiedesk’s self-hosted model lets you choose what is logged. By default, logs are minimal and encrypted. Proton Mail logs metadata (IP, sender, recipient, timestamps) by design.

Can I use Unifiedesk without self-hosting?

Yes. The hosted version is end-to-end encrypted with full privacy and supports custom domains, AI assistant, Drive, Meet, and documents—without needing to manage servers.

What’s the role of JMAP in Unifiedesk?

JMAP is the modern email protocol used by Unifiedesk for real-time sync, efficient filtering, and better performance across mail, calendars, and contacts.

Yes. Drive files can be shared with expiring links and password protection, enhancing security and control over file access.