Email Security Fundamentals

Email was designed in the 1970s with zero security in mind. Despite decades of improvements, email remains one of the most vulnerable communication channels. Understanding its limitations is key to using it safely.

What email doesn't protect against by default: • Interception in transit (mitigated by TLS, but not guaranteed) • Server-side access by your provider • Metadata exposure (who emailed whom, when, and subject lines) • Attachment scanning and indexing • Forwarding without your knowledge

What secure email providers add: • End-to-end encryption between users of the same provider • Zero-access encryption for stored emails • Stripped metadata • No advertising or data mining

Practical Email Security

1. Choose a Secure Provider: ProtonMail or Tutanota for maximum privacy. Gmail with Advanced Protection for strong security within the Google ecosystem.

2. Use Strong Authentication: Enable MFA on your email account. Use a hardware security key if possible — email is too critical for SMS-based MFA.

3. Use Email Aliases: Services like SimpleLogin, AnonAddy, or Apple Hide My Email create unique aliases for each service you sign up for. If one is compromised, you disable it without affecting other accounts.

4. Handle Attachments Carefully: Never open unexpected attachments. Scan attachments with antivirus before opening. Be especially wary of Office documents with macros, ZIP files, and executable files.

5. Verify Before Acting: Any email requesting urgent action (password reset, payment, account verification) should be verified through a separate channel before responding.

6. Encrypt Sensitive Emails: When sending sensitive information via email, use PGP encryption or share via a secure service like ZeroLatch instead. Email was not designed for sensitive data transfer.

Email and Dead Man's Switches

Email plays a critical role in dead man's switch systems:

Heartbeat reminders: You'll receive email reminders to check in. Ensure you recognize these as legitimate (bookmark the sender address). • Warning notifications: If you miss a check-in, warning emails are sent. These are time-sensitive — missing them means your vault may be released. • Release notifications: Recipients receive emails when a vault is released.

To ensure the dead man's switch works reliably: • Whitelist the service's email addresses • Don't filter heartbeat reminders to a folder you rarely check • Verify the sender domain matches exactly • If using email-based heartbeat confirmation, click only links from the verified sender