Temporary mailbox for external users
Through the temporary mailbox, we enable you to communicate securely via mail with any contact worldwide. This prevents your mails from being sent unencrypted and from being read or altered in transit. If you send your communication partner an encrypted mail for the first time and the Guard cannot assign a PGP key to this mail address, we will provide a temporary mailbox for the recipient – a helpful feature for secure communication with partners who cannot or do not want to use encryption.
mailbox automatically creates a temporary mailbox for this recipient as soon as you send this contact an encrypted mail.
Setup
The recipient receives a mail containing the link to a temporary mailbox:
Figure 1: The recipient receives a link to the encrypted mailbox.
The recipient can then open the link received with the first mail in the browser. Since this mail with the link to the temporary mailbox is sent in an unencrypted mail, it could of course be intercepted and read. You should therefore additionally secure access to the temporary mailbox with a PIN – which we explain in the following section.
Figure 2: A personal message can easily be added.
Figure 3: Note down the PIN and share it with your communication partner.
Figure 4: The communication partner receives a mail message with a link.
Figure 5: First-time use of mailbox Guard security.
It may happen that you are asked to enter the new password again later on.
Figure 6: The recipient can now view the encrypted message without having stored a public key.
Optional: Two-way authentication
When you send your contact the first encrypted message, you also have the option to protect your communication with two-factor authentication, ideally with a PIN number assigned when creating the temporary mailbox. Provide this number to your contact via a third, preferably secure, channel (e.g. personal meeting, phone call, chat, SMS, letter, ...). The recipient needs both the link from the mail and the PIN in order to log in (Figure 3):
In this temporary mailbox, which is equipped with all our security features, your communication partner can read and reply to the encrypted mail. Their replies are also automatically encrypted. Once a temporary mailbox has been set up, all encrypted mails sent from a mailbox address to the corresponding address will be delivered to the temporary mailbox. Mails sent from the temporary mailbox are stored in the "Sent" folder. As soon as the recipient opens the link (and verifies with the PIN), they must create a password for their temporary mailbox (which cannot be changed later). This password cannot be changed, as this is the only way we can ensure that no attacker could misuse a potential reset mechanism. Temporary mailboxes are deleted after 90 days of inactivity.
Alternatively, you can also view the source code of this mail. There you will find the following line in the header:
X-OxGuard-PIN:
Note: This line is inserted when saving the sent copy and is not part of the sent mail.