17 karma · joined October 30, 2023
We currently serve UMD, Tufts, Swarthmore, and more.
Also - you should note that we largely operate in-memory and don't store to disk any information or logs (unless essential, e.g. IMAP storage, or if they are error logs). We have all of this in our privacy policy and terms on our website. We are extremely transparent.
[1]: https://github.com/forwardemail/mta-sts.forwardemail.net/blo...
A PGP encrypted email doesn't get "decrypted" when it's being transferred. That's the whole purpose of PGP encryption, to encrypt it before it even gets transferred or stored, which is what we do. If you set up a PGP key, use WKD, then your emails will be stored as encrypted (not only is your database encrypted with your password, but the emails themselves can be PGP encrypted this way), and any sender attempting to send to you will automatically have their message PGP encrypted to you, if it is not already (in case their mail client doesn't use WKD).
https://forwardemail.net/en/faq#do-you-support-openpgpmime-e...
We've considered adding a E2EE comparison column as well (with the issues such as Proton rewriting your emails @ http://jfloren.net/b/2023/7/7/0 highlighted).
Privacy Guides Discussion @ https://discuss.privacyguides.net/t/forward-email-email-prov...
Unlike Skiff, Proton, and Tuta... we're _actually_ 100% open-source. Those providers that advertise as open-source really only open-source the front-end, when the back-end is the most sensitive part of an email service.
We are the *only* email service provider that is 100% open-source. Proton Mail [1], Skiff [2], and Tuta [3] all have closed-source back-ends, despite advertising as closed-source.
RE: Quantum Safe:
ChaCha20-Poly1305 is generally considered to be quantum safe [4] [5].
[1]: https://www.reddit.com/r/ProtonMail/comments/b847n7/comment/...
[2]: https://www.reddit.com/r/Skiff/comments/10yn8a5/comment/j811...
[3]: https://www.reddit.com/r/tutanota/comments/10hghin/comment/j...
[4]: https://crypto.stackexchange.com/questions/79518/is-xchacha2...
[5]: https://old.reddit.com/r/crypto/comments/suk2k7/is_chacha20p...
We support SMTP, POP3, IMAP, API, webhooks, regular expressions, and more.
[1]: https://forwardemail.net/blog/docs/best-quantum-safe-encrypt...
[2]: https://forwardemail.net/faq#do-you-support-openpgpmime-end-...
We built an email service (IMAP support added a month ago) and wrote a WebSocket to SQLite layer to solve our encryption at rest needs for storage.
See our deep dive at https://forwardemail.net/blog/docs/best-quantum-safe-encrypt... for insight.
Edit: It matters because if someone has access to the filesystem, or our MongoDB database, then they still can't read/write to your email mailbox because they don't have your IMAP password (which we only show to you _once_ for 30 seconds and render in-memory). We use ChaCha20-Poly1305 encryption on the SQLite mailboxes (which is generally considered quantum-secure[0]). Passwords are generated[1] via Node.js `crypto.pbkdf2`.
[0]: https://crypto.stackexchange.com/a/90311 [1]: https://github.com/forwardemail/forwardemail.net/blob/d537fc...