Encrypted email
Meil supports OpenPGP and S/MIME in compatible email applications. You choose whether to sign, encrypt or do both for a message. Publishing a key does not make ordinary email end-to-end encrypted.
What do you need?
| Feature | What it does |
|---|---|
| OpenPGP | Uses a key pair you create or import in your email application. |
| WKD | Lets compatible clients discover a published public OpenPGP key using an email address. |
| S/MIME | Uses your own email certificate, for example from your employer or a certificate issuer. |
Choose the same standard as your correspondents. An OpenPGP key cannot be used as an S/MIME certificate.
Signing is not encryption
A digital signature lets the recipient's application verify the signature and detect changes to signed content. Signing alone does not hide the content. Encryption needs the recipient's public key or certificate; decryption needs the corresponding private key. Sender, recipient and other email headers may remain visible.
TLS protects the connection to the mail server. That is different from end-to-end encryption.
What does Meil do?
Under Settings → Login & Security, you can publish a public OpenPGP key and check an S/MIME setup. Signing and encryption happen in the email application, not in Meil webmail. The setup check does not decrypt ordinary messages in webmail.
Backup and a new device
Keep your private key, any passphrase and a protected backup yourself. Test that the backup can be imported on a trusted device. Retain old decryption keys for as long as you need to read older email.
Account recovery and password changes do not recover lost encryption keys. Never send private keys, passphrases or certificate files containing private keys to support.