Zero knowledge by construction

Email the server
cannot read.

One Mail seals every message to your key the moment it arrives, before anything reaches disk. There is no decryption path on the server, no plaintext in the database and no operator who can be asked to hand one over.

X25519
Sealed to your key
Argon2id
Passphrase in-browser
0
Plaintext bytes stored
Sign in to One Mail
onemail.aml.one
Sealed
Match code
47
Expires in 58s
Single use
No public sign-upNo IMAP or SMTP surfaceCustom MTA, no PostfixAdmin edge behind mutual TLS
How it works

Encrypted before it is ever stored

Most providers encrypt at rest with a key they also hold, which protects you from a stolen disk and from nothing else. One Mail encrypts to a key that only your devices have.

1

Mail arrives

Our own MTA answers on port 25, checks SPF, DKIM, DMARC and reputation, and refuses anything addressed to a domain that is not active.

2

It is sealed on receipt

A fresh content key encrypts the message with AES-256-GCM and is itself sealed to your X25519 public key. The plaintext is discarded before the write.

3

Only you open it

Your device unwraps the seed and unseals the content key. The server relays ciphertext it has no way of reading, on any device you own.

Security

Guarantees, not promises

Every claim below is a property of the design rather than a policy we could quietly change. The parts that matter are enforced by cryptography or by the shape of the API.

Sign in by scanning

The browser mints a throwaway keypair and shows it as a circular code. Your phone displays the origin that opened the session plus a two-digit match code, so a proxying attacker gives itself away.

Recovery needs a quorum

A lost passphrase takes your OneAuth share, one administrator's share and any password you have ever used. Administrators alone recover nothing.

Our own mail transfer agent

Written in TypeScript, not bolted onto Postfix. Greylisting, RBLs, per-connection rate limits and spam scoring run before a message is ever accepted.

Delivery that insists on TLS

Outbound mail honours MTA-STS and DANE, signs with a per-domain DKIM key, and retries with exponential backoff rather than falling back to plaintext.

Many domains, one mailbox

Addresses across any hosted domain deliver into the same mailbox and seal to the same key, because keys belong to people rather than to domains.

Administration behind three walls

The admin surface needs a client certificate at the edge, that certificate bound to the account, and a OneAuth code from the last five minutes.

Everywhere you work

One mailbox, five platforms

The same client, the same encrypted local store and the same update pipeline on every device. Mail is cached sealed and searched on your machine, because a server that cannot read your mail cannot search it either.

See downloads
  • Android
  • Windows
  • macOS Silicon
  • Linux
  • Ubuntu Touch

Already have an account?

Sign in by scanning a circular code with your phone. If your phone is not to hand, your passphrase and a OneAuth code still work.