Nicholas TongProton Mail
08 / 46
Proton Mail: what encrypted email actually encrypts
The notification arrived at 6:12pm on a Tuesday: someone had signed into my father's email from a country he has never visited. His password was our old street number plus the year the Astros won the World Series, a combination I had been telling him to change since roughly 2019, and the credential stuffing run found it in about eleven seconds. Nobody phished him. The password was simply a puzzle that millions of leaked passwords had already solved.
He got the account back that night, with my help over speakerphone and one trip to his house. Two years later I run my own sensitive mail on Proton Mail, and this post is the honest version of why, because the reason is narrower than the marketing implies.
the part everyone gets wrong
"Encrypted email" sounds like the message is unreadable from end to end. Email was built in an era when nobody imagined passive surveillance of the wire, and the protocol exposes metadata by design: who you write, who writes you, when, how often, from which addresses. Proton Mail encrypts message bodies and attachments, encrypts your mailbox at rest, and still routes mail through the same SMTP plumbing as everyone else. Your subject lines are encrypted at rest on their servers, which is better than Gmail, and the routing metadata of a message sent to the outside world is not encrypted in any way that matters, because the receiving server needs it.
CVE numbers are boring on purpose. Metadata is boring the same way, and it is where the real picture of your life gets assembled: a feed of every clinic, lawyer, and bank you correspond with, readable without breaking a single cipher. No email product on earth fixes that, including this one. What it does fix is which companies can read the content at rest, and how much they can be made to hand over.
the mechanics
Proton's design is zero-access: mail sitting on their servers is encrypted with keys derived from your password, so a database dump or a rogue insider reading the mail store gets ciphertext. Between two Proton accounts, encryption is automatic end-to-end via PGP underneath. For mail to a Gmail address, they offer password-protected messages, where the recipient opens an encrypted page with a shared secret you exchange out of band. The apps are open source, and the company is Proton AG in Geneva, which publishes a transparency report itemizing the legal requests it receives.
The tiers are Proton Free, 1 GB of storage and one address; Mail Plus, 15 GB, ten addresses, one custom domain, and IMAP support through their Bridge app; and Proton Unlimited, 500 GB, three custom domains, and the whole suite including VPN and Pass. I'm on Unlimited for the VPN and aliases, and I'd have been fine on Mail Plus if I wasn't reviewing the bundle. Annual pricing is the only one I'd recommend either way.
Proton Sentinel, on Unlimited, is their high-security account protection program, extra review of anomalous logins. It's the tier for people who expect to be targets, and I am not one.
where it breaks
Swiss law reaches Proton, and 2021 proved it. A court order tied to a French climate activist case forced Proton to log the IP address the activist used on login, and they disclosed it afterward. It was Proton Mail, not the VPN, and the lesson isn't that they're bad, it's that no jurisdiction is a wall. Legal process compelled a privacy company to collect a piece of data it normally doesn't touch, and the disclosure mattered more than the promise.
The Bridge is the daily annoyance. IMAP support for desktop clients like Thunderbird runs through a local proxy app that re-encrypts on the fly, and it is clunky, occasionally logs out, and only exists on paid plans. If your mail life lives in a native client, budget an evening for it and expect to redo it after an update.
Search is slower than Gmail because searching encrypted mail means decrypting on your device first. Spam filtering is weaker, genuinely weaker, and my aunt's pharmacy newsletter lands in my junk folder about once a week, and I've just accepted it. Deliverability from proton.me to strict corporate filters is occasionally rocky, which I noticed when a resume of a mentee I sent along bounced back twice from a bank's mail gateway.
And the free tier's 1 GB fills up in about three months of attachments, which is by design.
what to do
- Don't migrate everything. Move the sensitive mail: banking, medical, legal, government. That inbox is where content actually matters, and it's maybe fifty messages a month.
- Turn on 2FA on the account before you move anything, and set a recovery contact you actually trust.
- Use hide-my-email aliases for everything new, so the real address never leaks into a breach dump.
- Keep Gmail or whatever you use for newsletters, logistics, and coupons. Spam filtering is a feature, and Gmail is still the best at it.
- If you're migrating a parent, do the password manager first. The email provider matters less than the password reuse, and that's the order I got wrong with my dad.
I wrote half of this between pho courses at the place on Bellaire that opens at seven, over a number 27 with extra onions, and the wifi there logs your MAC address like everywhere else, which is exactly the kind of thing encrypted email does nothing about.
Move the sensitive mail first. The coupons can wait.