A wish or some feedback about tunnl.? We would love to hear your echo.

Write an echo
New message
Settings
Appearance
Language
DEEN
Admin cockpit

In brief

Sending confidential documents by email

Email is a postcard that gets copied. Confidential things need an envelope.

Email is usually encrypted in transit, but readable at every stop, and afterwards it stays everywhere. Whoever sends confidential things encrypts the content itself – with S/MIME or PGP if both sides have set that up, otherwise via a link whose key is not held by the provider.

What actually happens on the way

Between your device and your mail server the connection is encrypted, and usually between servers too. That is transport encryption, and it protects against reading on the wire. What it does not do is protect the content from the stops themselves. Every server on the way holds the mail in clear text. And whether the far end even accepts encryption is not your decision.

The bigger problem comes after delivery: the mail stays. In your sent folder, in the recipient’s mailbox, in backups, in archives, on a phone that is later sold.

The routes that exist

S/MIME or PGP. Technically the right thing: end-to-end encrypted, right in the mail client. In practice it fails because both sides must set up certificates or keys. For a customer receiving one quote, that is a non-starter.

Encrypted ZIP. Works if the password comes separately and is long enough. Many mail filters block encrypted archives, though, because malware hides in them.

Portals and secure mailboxes. Reliable, but the other side needs an account. Good for regular traffic with the same partners, cumbersome for one-off deliveries.

A link with a key. The attachment is stored encrypted and the recipient opens a link. The one question that decides everything: does the provider hold the key? If so, it is only relocated trust.

And with tunnl.

With tunnl. the key sits in the link, behind the # – and a browser never sends anything after that character to the server. So we only ever hold ciphertext, even if someone steals our database. The other side needs no account, no app and no setup; they click and read.

What tunnl. cannot do here: Whoever holds the link can read. So do not send it together with the password over the same channel – and for particularly sensitive things, send the link by mail and the password by phone.

How tunnl. encrypts · And how to pass on the password · The comparison in detail

We cannot read your messages. We do not store IP addresses.

What for?Help & questionsEcho usPrivacyLegal notice

Beta

xoox ag · bluematic ag · cloud services ag