Gmail used to be good alright, but then it started to ask for my phone number all the time. I've switched to Tutanota recently, much better IMO, particularly the new client: https://mail.tutanota.com/
Why can't these services use something like OpenPGP's Web Key Discovery [0] fetching key from https://domain.com/.well-known/openpgp/hu/hash-for-localpart and avoid links altogether?
[0]: https://www.gnupg.org/blog/20160830-web-key-service.html
As far as I know self-destruct emails in Gmail are not end-to-end encrypted.
Is there an issue tracker or a mailing list where one can subscribe and see when this would be available?
Devs say they want to publish the app on F-Droid. https://tutanota.com/blog/posts/secure-mail-open-source
How is that for protonmail?
So I register bob@tutanota.com but forget to register bob@tutanota.de and anybody can squat it and impersonate me from the same service?
Not to mention they blocked my IP after registering 3 of the 5 available domains.
When I wake up on the second morning after I've registered an email account, it was impossible for me to remember whether the domain was tunanota, notatuna, nonanuta or tutanote...
I'm so tempted now.. YMMD :)
How about the UX? Can anyone comment on how they like the over all experience of Protonmail as compared to Fastmail? I realize I could sign up a Protonmail account and compare, but I’m not sure I’d get a good picture of the service through casual use.
I like Fastmail quite a lot so far, but I’m open to reevaluating in a year’s time.
How would encrypted emails work in a client like Thunderbird? Would it normally be handled correctly if POP/IMAP was available?
But... those aren’t particularly friendly and thus aren’t widely used. The main usability issue is a fundamental one, namely that management of crypto keys is hard.
Hearing that Protonmail requires their own client suggests to me that they’ve given up on the standards due to usability issues, and have instead adopted a managed key model like Apple’s iMessage.
iMessage is end-to-end encrypted, but Apple manages keys on your behalf. It’s not a bad compromise between privacy and usability depending on your threat model.
But, at this point I’m deeply suspicious of anything that isn’t standards based or that locks me into a particular vendor’s software. I’m therefore skeptical that we’ll satisfactorily solve email privacy for a majority of people in my lifetime.
EDIT: Thunderbird would work with Fastmail for encryption using PGP or SMIME (at least I think Thunderbird supports SMIME). Protonmail wouldn’t work, I’d guess.
Thunderbird supports SMIME natively, just like most of email clients. But of course there are some usability issues, like you need to enable encryption each time per email, or require it for all emails, there is no middle ground like "encrypt if I have keys, do not encrypt otherwise".
I also like the [anything]@alias.domainname.com feature. Lets you separate out user accounts into unique email addresses, and you skip the username+[unique]@gmail.com filter that a lot of places have now.
And the fact you can host a simple static website on your domain is useful.