Encrypted Email
Summary
The practice of protecting email content and credentials from interception, account compromise, and metadata exposure. The 2026 choice is between provider-side encryption (Proton Mail, Tuta) and self-managed PGP/GPG, with the operational rule that the right answer depends on the user’s threat model and on the cost of key management they can absorb.
Body
Encrypted email is the asynchronous companion to secure-messaging and the channel activists most often misuse. The canonical framing distinguishes two paths: a hosted encrypted-email service (Proton Mail, Tuta) that handles key management on the user’s behalf, and self-managed PGP/GPG where the user generates, publishes, and signs their own keys [source: digitale-gesellschaft-email-krypto]. The Digitale Gesellschaft primer — published by an independent Swiss civil-society association — argues that for most activists a reputable provider-side encrypted service gives 80% of the security benefit at 5% of the operational cost, and reserves PGP/GPG for the threat model that genuinely needs it (a high-risk defender targeted by state-level adversaries who can absorb the key-management cost) [source: digitale-gesellschaft-email-krypto]. This trade-off framing is unusual in the encrypted-email literature, which tends either to insist on PGP or to ignore it; the Digitale Gesellschaft primer names the trade-off explicitly.
For users who do proceed to PGP, the standard sequence is key generation with a reputable client (Thunderbird’s built-in OpenPGP, or the older Enigmail pathway), key publication to a keyserver, signing and verification of incoming messages, and the recovery question — what happens to my encrypted email if I lose my device [source: digitale-gesellschaft-email-krypto][source: digitalcourage-digitale-selbstverteidigung]. Each step is paired with a short rationale — why OpenPGP, why a long key, why publish a public key at all — so a reader can adapt the recipe rather than copying it [source: digitale-gesellschaft-email-krypto].
The non-English-language canon supplies set-up guides that account for the local service-provider ecosystem. Digitalcourage’s Digitale Selbstverteidigung covers PGP/GPG and increasingly simpler protocols, with set-up instructions that explicitly call out German mail providers and legal context (Telekommunikationsgesetz, Datenschutz-Grundverordnung) [source: digitalcourage-digitale-selbstverteidigung]. Nothing2Hide’s French-language guide covers email provider choice, jurisdiction, two-factor authentication, and the PGP-versus-provider-side trade-off [source: nothing2hide-guide-numerique]. The guide.boum.org Guide d’autodéfense numérique (Tome 2) goes deeper on encrypted email and metadata than the shorter zines, with worked examples and command-line recipes for the defender willing to learn about cipher suites [source: guide-survie-securite-numerique-activistes]. EFF’s Surveillance Self-Defense covers the operational habits that keep email protection intact — lock-screen passcodes, account-recovery hygiene, the choice between “at-rest” and “in-transit” encryption [source: ssd-eff].
The Holistic Security Manual adds the meta-discipline: encrypted email is one of three interlocking security dimensions (digital, psychosocial, organisational) that must be planned together, and a defender who adopts encrypted email without first agreeing on what may be written down at all creates new vulnerabilities in the act of fixing old ones [source: holistic-security-tactical-tech].
Encrypted email is closely related to secure-messaging (the synchronous channel), digital-security (the broader discipline), and digital-first-aid (the incident-response discipline when an email account is compromised).
Use it for
Choosing between provider-side encrypted email and self-managed PGP/GPG for a campaign; running an email-security training as part of a digital-security onboarding; setting up encrypted email for a board, coalition, or volunteer cohort; recovering from an email-account compromise.
Worked examples
- belarusian-citizens-protest-presidential-election-2006 — opposition channels required encrypted email to protect communication content and identities from state surveillance.
- committee-of-soldiers-mothers-of-russia-campaign-against-the — whistle-blowers and source-data handlers relied on encrypted email to prevent retaliation.
- indigenous-peoples-in-bangladesh-protest-to-stop-open-pit-coal — community organisers needed secure communications against state surveillance over multi-year resistance.
Learn more
- On Wikipedia: Email encryption — CC BY-SA 4.0
Related
- digital-security
- secure-messaging
- digital-first-aid
- ssd-eff
- holistic-security-tactical-tech
- digitale-gesellschaft-email-krypto
- digitalcourage-digitale-selbstverteidigung
- nothing2hide-guide-numerique
- guide-survie-securite-numerique-activistes
Open Questions
(none)
FAQ
What is encrypted email?
Encrypted email is the practice of protecting email content and credentials from interception, account compromise, and metadata exposure. The current choice is between provider-side encryption, such as Proton Mail or Tuta, and self-managed PGP/GPG. The appropriate answer depends on the user’s threat model and the operational cost of key management they can absorb [source: digitale-gesellschaft-email-krypto].
What is the difference between provider-side encryption and PGP/GPG?
A hosted encrypted-email service such as Proton Mail or Tuta handles key management on the user’s behalf, while self-managed PGP/GPG requires the user to generate, publish, and sign their own keys. The Digitale Gesellschaft primer says a reputable provider-side service gives most activists 80% of the security benefit at 5% of the operational cost, reserving PGP/GPG for genuinely high-risk threat models [source: digitale-gesellschaft-email-krypto].
How do you set up self-managed PGP email?
The standard sequence is generating keys with a reputable client such as Thunderbird’s built-in OpenPGP or the older Enigmail pathway, publishing a key to a keyserver, signing and verifying incoming messages, and planning recovery if the device is lost. Each step has a rationale so the reader can adapt the recipe rather than simply copy it [source: digitale-gesellschaft-email-krypto] [source: digitalcourage-digitale-selbstverteidigung].
Why should encrypted email be planned with holistic security?
Encrypted email is one of three interlocking security dimensions—digital, psychosocial, and organisational—that must be planned together. A defender who adopts encrypted email without first agreeing on what may be written down can create new vulnerabilities while fixing old ones [source: holistic-security-tactical-tech].
Sources & verification
- sources/ssd-eff — grounding: primary — Terminal T4 (2026-07-01)
- sources/holistic-security-tactical-tech — grounding: primary — Terminal T4 (2026-07-01)
- sources/digitale-gesellschaft-email-krypto — grounding: primary — Terminal T4 (2026-07-01)
- sources/digitalcourage-digitale-selbstverteidigung — grounding: primary — Terminal T4 (2026-07-01)
- sources/nothing2hide-guide-numerique — grounding: primary — Terminal T4 (2026-07-01)
- sources/guide-survie-securite-numerique-activistes — grounding: primary — Terminal T4 (2026-07-01)
