Home / Guides / Email and Messaging
Why Private Email Matters and What "End-to-End Encrypted" Means
Email was designed in an era of trust, not privacy. Understanding what regular email exposes, and what private email services do differently, helps you decide how much protection you need.
What ordinary email exposes
- Your provider can usually read your messages. With most free email services, your emails are stored on the provider's servers in a form the provider can read, for spam filtering, features and sometimes advertising or analytics, depending on the provider's policies.
- Messages travel through several servers. Most servers now use encryption between each other (TLS), but this protects mail in transit, not in storage, and it depends on both sides supporting it.
- Metadata is exposed. Who you wrote to, when and how often is often visible even when the content is protected.
- Accounts are a single point of failure. Your email address is the key to password resets for most other accounts.
What "end-to-end encrypted" means
End-to-end encryption means a message is encrypted on the sender's device and can only be decrypted by the recipient's device. The service in the middle, including the email provider, cannot read the content.
Some caveats matter:
- Both sides usually need to use a compatible system. Many private email services encrypt automatically between their own users. Emails to other providers may not be end-to-end encrypted unless you use extra tools or password-protected messages.
- Not everything is encrypted. Depending on the service, subject lines, sender and recipient addresses, and timestamps may or may not be protected. Read the provider's documentation.
- Encryption does not protect a compromised device or a stolen password.
What "zero-access" or "encrypted at rest" means
Some providers encrypt your stored mailbox in a way that the provider itself cannot open it. This is different from ordinary "encrypted at rest" storage, where the provider holds the keys. If this matters to you, check who holds the keys.
What to look for in a private email service
- A clear explanation of what is encrypted, and what is not.
- Open documentation and, ideally, open-source apps or independent audits.
- A business model you can see. A paid plan or a limited free tier is usually more trustworthy than a service with no clear income.
- Two-factor authentication and recovery options that do not undermine the encryption.
- Import tools and custom domain support, if you are switching from another provider. See how to switch from Gmail.
- A jurisdiction and legal-request policy that you understand.
Who needs it
- People who handle sensitive information by email, such as lawyers, journalists, health workers and small business owners.
- People who want their messages not to be scanned by their provider.
- Anyone who wants to reduce the damage if their provider is breached.
For everyone else, protecting your email account with a strong password, two-factor authentication and phishing awareness may bring a bigger benefit than switching. See how to spot a phishing email.