Encrypted Email Myths That Steer People to the Wrong Provider
Estimated reading time: 4 minutes
In September 2021, Proton Mail found itself defending a decision that surprised many of its users. Following a request from French police passed through Europol, Swiss authorities ordered the company to record the IP address of a French activist’s account, and Proton complied. Within days it updated its policy to state plainly that it can be legally compelled to log IP addresses during a Swiss criminal investigation.
The messages in that account stayed encrypted throughout. What the case exposed was a gap between what people believed encrypted email does and what it actually does. Clearing up that gap is the best way to choose a provider, so here are the most common misconceptions and what to look for instead.
Myth 1: Encrypted email protects everything about a message
Encryption protects content. It does much less for metadata, meaning who you wrote to, when, and from where. Proton states that subject lines and sender and recipient addresses are encrypted on its servers but not end-to-end encrypted. Tuta, based in Hanover, goes further and encrypts subject lines end to end, yet email addresses and timestamps still have to remain readable for mail to be delivered. Any provider that claims otherwise is overselling.
Myth 2: Every message I send is end-to-end encrypted
Usually only messages between two users of the same service get full end-to-end protection automatically. Send a note from Proton or Tuta to a Gmail address and it travels as ordinary email, normally protected in transit but readable by the recipient’s provider. Both services offer password-protected messages for outside recipients, and Proton supports PGP, but these take a deliberate extra step.
Also Read: The Impact of Quantum Computing on Data Security in 2026
Myth 3: A Swiss or German address puts your data beyond reach
Strong data protection laws help, but no provider is above the law of its own country. The Proton case shows that a lawful order can require new logging from that point on. The realistic question is what a provider can hand over when compelled. A service that stores little about you has little to disclose. LessKYC, an independent directory that rates crypto and online services on how much personal data they collect, is a quick way to compare email providers on exactly that point.
Myth 4: Good encrypted email is expensive
It doesn’t have to be. Posteo, run from Berlin since 2009, costs 1 euro a month, asks for no personal details at signup, runs on green energy and offers payment methods that aren’t linked to your account. Proton and Tuta both have free tiers, with paid plans adding storage, custom domains and more addresses.
How you pay matters too, because a card payment ties your name to the account. Proton accepts Bitcoin on its paid plans, and if you would like to pay for the rest of your online services in Monero, XMRList, a directory of more than 1,400 businesses that accept it, covers VPNs, web hosting, wallets and more.
Also Read: Understanding Homomorphic Encryption for Data Security
Myth 5: Switching means abandoning your old inbox
You can move gradually. Forwarding from your old address buys time, and alias services let you give each website its own address. Proton bought the alias service SimpleLogin in April 2022, and addy.io offers something similar. If one shop leaks its customer list, only that alias is exposed, and you can switch it off.
What to check before you pick a provider
- Which messages are end-to-end encrypted, and which only at rest
- Whether subject lines and contacts are covered
- What signup requires: a phone number, a recovery email or nothing
- How recovery works if you forget your password
- Whether IMAP or PGP is supported (Tuta deliberately supports neither)
- Whether you can export your mail if you leave
- Whether the company publishes a transparency report on legal requests
Signup requirements are where providers quietly differ most. Some ask for a phone number to deter spam, others for a recovery address, others for nothing. LessKYC’s email listings record these details, along with the payment methods each provider accepts, which saves you from creating test accounts to find out.
Choosing with the right expectations
Encrypted email is worth using. It keeps your message content away from advertisers, data brokers and anyone who breaches the provider’s servers. Just choose it for what it does well, protecting content and limiting what is stored, rather than for promises no email system can keep. Pair it with aliases and a provider that collects little at signup, and you will have most of the benefit with none of the illusions.
Note: The article includes external links to third-party services; readers should independently evaluate any referenced platforms before engaging.

