Skip to main content

mailbox Guard - FAQ

How is my private key protected?

When you upload a PGP key or create one via the Guard, this key is encrypted with a password known only to you. This password is never stored on our systems and must be entered by you separately when decryption (e.g. to read an encrypted email or edit an encrypted text file) is required. As long as you do not enter the Guard password, the key files remain encrypted on the server – and thus inaccessible (even to us).

Have emails been encrypted by sender or mailbox?

If you have activated our automatic encryption for the completely encrypted mailbox, you can no longer determine whether emails were encrypted by us or by the sender. But it is possible you might like to find out.

You can do this with a simple trick: Generate two GPG keys. The first is your real key. You distribute this key to your contacts and have it signed if necessary. Use the second key for our automatically encrypted mailbox only. Then, based on the key ID, you can determine who encrypted the email – the sender or mailbox.

Is the encrypted mailbox compatible with Guard?

Our encrypted mailbox is 100% compatible with the functionality offered by mailbox Guard.

Until recently, users of the encrypted mailbox could not access their encrypted emails via the web interface but had to use a local email client instead. mailbox Guard presents an appropriate solution at last. With mailbox Guard in place, you can use a web browser to access your encrypted e-mails at any time, on any device.

Which PGP standards does mailbox Guard support?

The email encryption used by mailbox Guard is 100% compatible with the (Open)PGP standard.

PGP/MIME and PGP/Inline encrypted emails can be sent, received, signed, and verified in the mailbox web client. This allows you to communicate securely via email with users of other PGP-compatible email clients or plug-ins without any issues.

mailbox Guard currently supports so-called ECC PGP keys (Elliptic Curve Cryptography) according to RFC 6637.

Does mailbox Guard use the Web of Trust?

In PGP encryption, there is the Web of Trust – a trust network in which PGP users can mutually sign the validity of their keys, thereby establishing trust in the authenticity of a user who is only indirectly known.

In mailbox Guard it is currently not implemented that you can manage and/or evaluate signatures of other users on keys.

Instead, mailbox Guard is based on the fact that you manually import the recipients’ keys into Guard and thereby classify them as valid and trustworthy. Signatures on the keys do not play a role in this process.

Before importing a key, you will be shown the fingerprint of the key, among other things. You should verify this (and possibly other characteristics) with the sender via a secure second channel (e.g., by phone, SMS, chat, verbally, or in writing) before importing the key – as this is how you extend your trust to them.

How do I deactivate mailbox Guard?

If you want to completely deactivate the mailbox Guard, you can contact our Support team via https://support.mailbox.org. Our Support team will then verify your identity as the account holder and can subsequently deactivate the Guard for you.

Attention

When deactivating the Guard, all your stored key pairs on our servers will be deleted. If you have not created a backup of the keys, you will no longer be able to read or open the emails and data encrypted with them afterwards.