Proton Mail - Private & Add-free Mail

Published

March 25, 2025

Modified

March 25, 2025

Why Proton Mail?

Free mail services (like Gmail, etc.)…

  • Commercialization of user data (you are the product)
    • …messages & attachments indexed by mail providers
    • …tracking of users for behavioral analysis
  • Enables data marketing with advertisement industry…
    • …advertisement is personalized to increase consumer spending
    • concerns over targeted ads and invasion of privacy

Mail is the anchor of a user profile.

What information is typically derived by online user tracking?

  • identity, address, email, phone, gender
  • age, income, spending budget
  • relationship to others
  • behavioral patterns, location
  • political beliefs
  • health conditions

For many people decision between convenience or prioritizes privacy and security in communication.

Questions to ask?

Switch to a privacy-focused, secure, ad-free email service like Proton Mail1˒2

Alternatives to Proton Mail:

User Protection

Thread Model3 …provide ‘good privacy’ for individuals

  • …protects messages from mass surveillance & data breaches
  • …respects data privacy …follows regulations (like GDPR4)
  • Does not protect against…
    • …compromised client devices
    • …man-in-the-middle attacks (for example by government organisations)
  • For reference …controversy around Proton Mail5

Tracking protection6 …remove email trackers by default

Phishing filters7

  • Proton Mail’s PhishGuard8 tries to prevent phishing attempts using…
  • …notifies the user to examine a mail more closely

Encryption9 — Mail body encrypted with PGP by default…

  • …offers no protection for users’ metadata (like mail subject, addresses, etc)
  • …private key is generated on the client side10 (protected by password)
  • …users are always end-to-end encrypted (only send/receiver can read a mail)
  • …exchange encrypted e-mails with off-site users11 …with pre-shared password)
  • …zero-access encryption12 on servers …therefore inaccessible to host

SPAM filter

Todo

Jurisdiction & Infrastructure

Jurisdiction13

  • …for-profit Swiss corporation Proton AG14
  • …owned by nonprofit Proton Foundation15
  • …neutral location outside of US, EU, and NATO jurisdiction
  • Proton Policy16 …describes data collected per user

Data-centers

  • …all infrastructure build by Proton (non cloud-based!)
  • …replication between Switzerland, Germany, Norway
  • …all data-centers run on green energy

Open Source — Proton uses open-source cryptography

  • …encryption methods transparent to the public
  • …experts can review/verify security strength of Proton system
  • Proton mail client application available on GitHub17
  • Deploy involved in OpenPGP18 standardisation & development

Prices & payment

  • Free (single address, minimal storage)
  • Payed tiers …family & business plans
  • Payment methods (…unpaid invoices within 14 days)
    • credit cards, PayPal, Bitcoin
    • bank transfer with IBAN
    • cash (physical mail to Switzerland)

Authentication & Recovery

No support for PassKeys19 (yet)

Two-factor authentication…

  • …six-digit code generated by a 2FA authenticator app
  • …registered smartphone
  • …physical security key

Account recovery

  • …password is linked to your encryption key (reset prevents access to old data)
  • 12-word recovery phrase
  • recovery mail address, phone number
  • recovery file or backup encryption key
  • trusted device-based recovery

Email Addresses

Mail aliases

  • …users can create unlimited extra addresses
  • …additional free personal addresses (up to 10)
  • …unlimited +aliases (sub-email address) …automatically created on use
  • …hide-my-email aliases …randomly-generated email address that forwards emails to your main inbox

Ecosystem

Additional Features — Address book, calender, file storage

  • ProtonVPN20

Footnotes

  1. The CEO of PROTON answers YOUR questions!, YoutTube
    https://www.youtube.com/watch?v=Dp7ght2fMR4↩︎

  2. Proton Mail
    https://proton.me/mail
    https://www.reddit.com/r/ProtonMail↩︎

  3. The Proton Mail Threat Model, Proton Blog
    https://proton.me/blog/protonmail-threat-model↩︎

  4. GDPR compliance is easier with encrypted email, Proton https://proton.me/business/gdpr↩︎

  5. References about a Proton Mail controversy
    https://proton.me/blog/cryptographic-architecture-response
    https://www.youtube.com/watch?v=AhdJzjC7Leo
    https://encryp.ch/blog/disturbing-facts-about-protonmail
    https://brian.carnell.com/articles/2021/the-truth-about-the-truth-about-protonmail/↩︎

  6. Tracking protection, Proton Documentation
    https://proton.me/support/email-tracker-protection↩︎

  7. What is phishing and how to prevent phishing attacks?, Proton Blog
    https://proton.me/blog/what-is-phishing↩︎

  8. What are DMARC, DKIM, and SPF?, Cloudflare Documentation
    https://www.cloudflare.com/learning/email-security/dmarc-dkim-spf↩︎

  9. What is end-to-end encryption and how does it work?, Proton Blog
    https://proton.me/blog/what-is-end-to-end-encryption↩︎

  10. How is the private key stored?, Proton Documentation
    https://proton.me/support/how-is-the-private-key-stored↩︎

  11. How to send Password-protected Emails in Proton Mail, Proton Documentation
    https://proton.me/support/password-protected-emails↩︎

  12. What is zero-access encryption and why is it important for security?, Proton Blog
    https://proton.me/blog/zero-access-encryption↩︎

  13. Five Eyes, Nine Eyes, 14 Eyes, 2025/01
    https://cyberinsider.com/5-eyes-9-eyes-14-eyes↩︎

  14. Proton AG, Wikipedia
    https://en.wikipedia.org/wiki/Proton_AG↩︎

  15. Proton Foundation
    https://proton.me/blog/proton-non-profit-foundation↩︎

  16. Privacy Policy, Proton Documentation
    https://proton.me/legal/privacy↩︎

  17. Proton Mail, GitHub
    https://github.com/ProtonMail↩︎

  18. OpenPGP Project
    https://www.openpgp.org↩︎

  19. Passkeys, FIDO Alliance
    https://fidoalliance.org/passkeys/↩︎

  20. Proton VPN
    https://en.wikipedia.org/wiki/Proton_VPN
    https://github.com/ProtonVPN
    https://protonvpn.com/↩︎