I think you are misreading my comment: they are the threat actor themselves, tricking users in believing they are better off via Proton.
SMTP does not encrypt messages and they arrive at Proton's inbound relays unencrypted, are scanned in plaintext for spam etc. At this point they can Bcc anything to another relay/account and keep a copy of all inbound messages BEFORE anything gets encrypted.
Access to historical messages? One line of code for logging, and let's not forget GPG does not encrypt the metadata which is readily available. How about FTS indexes, are they also decrypted on the fly in the browser?
Email is complex and not many have the patience to understand the monster behind, but lying about it, as Proton does - I find it just insulting to our profession.
Also "Swiss neutral", this is even more offending. Swiss execute US orders regularly.
end-to-end encryption? yes, if both users are on Proton - but don't call it email then.
Storing encrypted makes only sense when keys are not in their hands. Plaintext password enters their system on each login which means they can have your decryption key at any point if needed.
just forwarding is great if you can afford losing mail. Gmail will drop your messages occasionally.
You can use gmail's own relay for sending but it won't DKIM sign which is a must even for Gmail itself.
for a more reliable solution use forwarding AND POP3 fetching with some provoder OR use https://gmailify.com which offers own relays too for ~$7 a year.
I think you're reading that wrong. It's an issue with the protocol. IMAP/SMTP as implemented in most clients do not support 2FA. You can add 2FA on your own on the webmail, but you could still circumvent it by using the protocol directly. It's not a Migadu-specific thing.
You could also stick with free Gmail accounts and add on top all addresses and domains you need via gmailify.com[1] for flat $6 per year. It's custom domains extensions for Gmail with own dedicated relays.
If you are just doing cold mailing on one-to-one basis, you can use migadu.com for it. Everyone has to do that at some point and it is not spam. 500 mails is not a lot. Just cap it daily to e.g. 50-100 or you could hurt your own domain reputation.
> Email spam, also known as junk email, refers to unsolicited email messages, usually sent in bulk to a large list of recipients.
It is Gmailify serving the "unlimited", not Google. No ToS violation - not using Google's APIs. Gmailify is an extension of existing features of Gmail.
Many Gmail users already do this, but through a complete service like Fastmail, Migadu etc. Gmailify provides a thinner layer made for this purpose specifically.
Thank you for the comment and typo correction! Fixed.
> Allowing multiple customers to send mail from the same IP seemed too risky.
There are two sides of this problem. Sending very little traffic from an IP can also have negative effects as it will often be seen as "new". Using a shared range to send out mails of all customers could keep all IP addresses warm. The benefit is also that if there is one bad apple, it is statistically very low.
When we started, we were unsure how to cover the costs of the free tier which were becoming steep. One of the ideas was to allow internal advertising of paid users towards the free users for their products and services through text banners on incoming messages. We did not like that after all and preferred to drop the free plan all together.
Btw. When you register a company, you want to give it the widest possible scope, to avoid later paperwork. The purpose in the Handelsregister is completely irrelevant to actual operations, as long as it is larger in scope.
Our infrastructure is split among several datacenters. We utilize also multliple datacenters within individual regions. In case of a complete datacenter disaster as it has happened in Strasbourg, we'd be minimally affected with possible data loss of 15 - 60minutes of the most recent data.
That said, chances another OVH datacenter will burn down are significantly lower now compared to other datacenter providers.
That is not quite fair; even though we did raise prices, we informed twice in an announcement to all users months before it happened giving opportunity to act upon it. We have also grandfathered old pricing for an additional year to all users that asked for it.
Nevertheless, glad you found MXRoute fits your needs and budget!
We could all bake our own bread at home, but very few do. It boils down to convenience and time best spent.
By all means, I would recommend [5] if you have the technical knowledge to run it. This will give you more insight and appreciation for email as well [2] & [1] and humbly... [0].
Unfortunately, running an email service is a very underappreciated task; after Gmail - it is taken for granted. Cheers to Postmasters at MXRoute and Postale.io!
>Hate speech, racism, calls for violence, Nazism as well any other immoral, unethical or socially unacceptable activity will be denied service. If illegal, we will report such to the authorities.
That is not referring to the content of messages but rather general usage of our email service. We never look at the messages except when asked to. If you use our email service for things such as "hate speech, racism, calls for violence", all being illegal and punishable by law, we would know about it only once we receive a harassment complaint. With a valid proof we would act upon it, first level being asking you politely not to do it because it involves us then.
That is rather common sense, and we speak here from experience and past cases.
SMTP does not encrypt messages and they arrive at Proton's inbound relays unencrypted, are scanned in plaintext for spam etc. At this point they can Bcc anything to another relay/account and keep a copy of all inbound messages BEFORE anything gets encrypted.
Access to historical messages? One line of code for logging, and let's not forget GPG does not encrypt the metadata which is readily available. How about FTS indexes, are they also decrypted on the fly in the browser?
Email is complex and not many have the patience to understand the monster behind, but lying about it, as Proton does - I find it just insulting to our profession.
Also "Swiss neutral", this is even more offending. Swiss execute US orders regularly.
Translated: https://daslamm-ch.translate.goog/ueberwachungsoase-statt-da...
Original: https://daslamm.ch/ueberwachungsoase-statt-datenschutzparadi...
What we really need instead of such shams is a new mail system that does not depend on trusting providers and especially not a SINGLE provider.