Skip to content
← Back to BlogPrivacy

Why end-to-end encryption is not enough: the case for zero-knowledge email

Airfree Mail Team2 min read

When people compare private email services, the first thing they look for is "end-to-end encryption" (E2EE). It is a genuinely important property — but on its own it does not describe how safe your mailbox actually is. The harder question is what the provider can read when your messages are simply sitting on disk.

What end-to-end encryption actually covers

E2EE means a message is encrypted on the sender’s device and only decrypted on the recipient’s. Nobody in between — including the mail provider — can read it while it travels. That closes the interception problem, which is why it gets so much attention.

The gap is that most email is not sent between two users of the same encrypted service. You receive newsletters, receipts, and replies from Gmail and Outlook users. Those messages arrive in plaintext and then have to be stored somewhere.

The data-at-rest problem

Once a message lands in your mailbox, the real question is who holds the keys to it on the server. If the provider can decrypt your stored mail — to index it, to scan it, or because a court compels them — then "encrypted" describes the pipe, not the vault.

  • Transport encryption (TLS): protects the connection, not storage.
  • End-to-end encryption: protects same-service messages in transit.
  • Zero-knowledge at rest: the provider cannot decrypt what it stores, full stop.

How zero-knowledge works

In a zero-knowledge design, your mailbox is encrypted with a key derived from your password, which the server never sees in a usable form. Incoming plaintext mail is encrypted to your public key the moment it is received, so even data that arrived unencrypted is sealed before it is stored.

The trade-off is honest: because we cannot read your mailbox, we cannot recover it if you lose your password and your recovery key. That is the price of a provider that genuinely cannot access your mail — and we think it is the right one.

Keep your recovery key somewhere safe. In a zero-knowledge system it is the only way back into your mailbox if you forget your password.

What to ask any private email provider

The marketing word is always "encrypted". The useful questions are sharper: Can you read my stored mail? Can you index the contents for search on the server, or only on my device? What happens to plaintext messages that arrive from outside your service?

Airfree Mail answers all three the same way: your mailbox is encrypted at rest with keys we never hold in the clear, search runs against an encrypted index, and inbound plaintext is sealed on arrival.

Ready for a private inbox?

Airfree Mail is zero-knowledge email on sovereign infrastructure. Import from Gmail in minutes.

Create your free account →