This blog explains how privymail.eu works: the technology behind it, what a decision costs and what it does not solve. The posts go into detail, from the protocol down to a single header, and name the limits of a method along with it.
What is in our logs, and what is not
What the server of this website records, which logs the mail service keeps, how long they stay and what never goes into them.
This website can be verified
What the signed inventory of this website contains, how it is rebuilt every day, how to verify the signature and what it does not prove.
A password that never leaves your device
How the OPAQUE method checks your password without our server ever seeing it, what the server stores instead and where the protection ends.
Why we do not use SMS codes
Which second factor privymail.eu uses instead of SMS codes, why it works without a phone number and what it does not protect.
A website without JavaScript and without third-party servers
What this website's security policy allows the browser to do, how the rule is enforced and what the website gives up in return.
MTA-STS and DANE: how mail servers require encryption
Why encryption between mail servers is optional by default, how MTA-STS and DANE change that and what Domain Autopilot sets up for it.
European providers only: the rule and its reasons
Which rule applies to the providers behind the privymail.eu mail service, which services it excludes, what it costs and where it ends.
A computational puzzle instead of a CAPTCHA service
How privymail.eu slows down automatically created accounts without giving visitor data to third parties, and what a puzzle cannot do.
App passwords: your mail app never gets your main password
Why every mail app gets a password of its own, how that password relates to your mailbox key and what it does not prevent.