A few days ago, the U.S. government sanctioned A/I for supporting “extreme far-left antifa terrorists”. If you didn’t know, A/I is an antifascist and anticapitalist group based in Italy, and they host a lot of services (like email, website hosting, etc.) run through donations. Their policy states that they are against racism, sexism, militarism, homophobia, and transphobia, and you have to agree to those principles to use their services. Their website and mailing server has been taken down, and unfortunately, that also means my email no longer works. It’s kind of insane how quickly the American government can take down internet services they don’t like. A/I has denied all of the allegations by the Trump admin, and rightfully so, they’re just a digital services provider who respect your privacy and are against fascism and bigotry.
relevant link if you want to read more about this: https://cavallette.noblogs.org/2026/08/10076
I still need to use email, so what’s a good alternative email provider that doesn’t profit off of my data? I have used Disroot in the past and had good experiences with their services, so they are currently my fallback. I have ruled out Proton and Tuta, as neither support IMAP properly.
edit: It appears that it’s only the autistici.org domain that has been blocked (the registrar for the .org TLD is American), the services are still running (though my email is unable to receive mail, I can only read existing mail). A/I is working towards providing users with a new mail address. If that doesn’t pan out, I’ll probably go with Disroot.


I’ve been happy with mailbox.org so far. They offer full mailbox encryption, but unlike proton still support regular imap and smtp. You just need a mail client that supports pgp en/decryption (thunderbird does, both desktop and android).
Hmmm, how? For me, it sounds like they are either talking about OpenPGP which everyone can use OR it’s, sniff, bs.
It is openpgp, but I’m not aware of another mail provider that allows you to encrypt every mail when it arrives. Mailbox.org does have to manage this key though of course, but it can be a separate one from what you use to sign / encrypt sent emails.
The way it works is that it’s encrypted at rest on the server with your password.
If the server isn’t infected, they can’t read your email. If the webmail server is infected, they could store your password on auth (instead of just hashing it immediately) and decrypt your email.
The mitigation to this risk of server integrity compromise is PGP
Okay. New mail arrives. Plaintext, SMTP. You have not logged in today. To store it, it needs to know your password…
About as good as a gate in the middle of a field. Better just use POP3.
No, that’s not how it works. If you set up mailbox encryption (mailbox guard), you set up (or let mailbox.org generate) a pgp keypair. Any time you want to read an email, you have to unlock the key first. This way you can use regular imap, the body of emails will just arrive encrypted (and optionally the subjects as well I believe), you only need a pgp decryption tool to read the mails (which Thunderbird/K9 supports out of the box (with OpenKeychain on Android)).
Right. A user from another server sends you mail. The mail is unencrypted on their side because they don’t know your key yet, or they don’t know how to use OpenPGP, or it’s automated.
Servers talk SMTP between each other, not just a client sending mail.
The round trip time in this protocol is fucking insane, but that’s what the people in the year 1980 thought of. They never thought this would be used outside of universities.
Anyways, inevitably,
mail.mailbox.orggets the message, unencrypted. It can encrypt it later. Though I don’t see how this is any safer than just getting the mail out with POP3.Yes I know how mail encryption works. The point is that mails get encrypted as soon as they enter mailbox’ servers, so mailbox can never know any contents, so they have nothing to hand over to authorities if they come asking. They do have to know the private key used for this though, that is a risk to consider. Of course, if you want fully secure mail, you need both parties agreeing on encrypting/decrypting the mail. Or just don’t use email, use a secure protocol instead.
I will look at mailbox then, it seems pretty neat!
Proton does support IMAP, though it is through a desktop app. IMAP is weak security since it uses basic authentication, so I’m not sure why you think integrated support for IMAP makes a service better or more secure. A product is only as secure as its weakest link.
There has been a lot of Proton hate recently, much of it being highly misinformed or just looking for reasons to shit on them. I’d love if people could give me real reasons they dislike Proton.
And that’s the problem, the requirement for “Proton Bridge” isn’t the greatest. I would rather have proper IMAP support, as the protocol supports PGP encryption if you do need secure communication, which will be intercompatible with other mail services.
I don’t like how they are pushing people to adopt the Proton “ecosystem” of services that is all tied to a single account, I would rather not have everything in one basket. They also don’t have a Linux client for Proton Drive, so that service is ruled out for me.
Their CEO is also super pro-Trump and pro-GOP, which is always a red flag. The company now states that they are “politically neutral”, but it doesn’t seem like it from some of the comments that Proton (the company) has made, where they are basically saying that “Trump/the Republicans is the great hero against Big Tech that we needed”
How do you feel about Gail Slater?
Well I’m not American, so I have no idea who that is. Just skimming Wikipedia, looks like she served as the Assistant Attorney General of the antitrust division during the second Trump admin, but resigned earlier this year. Dunno anything about her though, so can’t place any assumptions.
She is known for trying to break up monopolies in tech, which is why people were surprised when she was selected by Trump who has tech giant friends. That’s what the proton ceo was praising, Gail Slater being picked. She didn’t last long, presumably because she indeed tried to break up big tech. He was also saying that the Democrats had done very little when they had the chance, because some Democrats are on the side of big tech. This was the controversy, and soon people called proton fascist and what not, and I don’t think it’s entirely fair.
His language of how Trump and the Republicans are their “only chance” to fight Big Tech isn’t great though. People were rightfully pretty mad about this, and Proton (the company) tried to position itself as “apolitical” and distanced themselves from the CEO. Being super pro-Trump is not a great image, especially given how he is financing big tech, promoting whatever makes them the most money, warmongering, and threatening political freedom.
I agree that his language wasn’t great. The appropriate language should have been to either not say anything or at least also criticize Trumps generally corrupt ways. It sounds to me similar to praising the strict animal welfare laws in Germany under the Nazis. I am all for banning vivisection and making animal cruelty illegal. That was a good thing, done by horrible people. If I say those laws were good, it doesn’t mean I’m a Nazi. But still, it wouldn’t look good.
Show me a CEO who isn’t pro-GOP. If you protest every company that has a GOP CEO, you would have to live an Amish lifestyle. It is a fine enough reason to avoid a company, but that in itself does not make their services bad.
Not having all your eggs in one basket is a personal choice, not an objective reason why the company itself or their services are bad. I will acknowledge that if things go sour, it would be a huge PITA to migrate to another service.
Not offering services you need does not make the company bad, though it is a valid reason to seek an alternative that fits your needs. Proton has been working on Linux clients (with ProtonVPN being their latest offering). They will get there one day, I’m sure.
I do agree that Proton Bridge is not the best solution, but it is a solution. I also agree that some solutions aren’t worth the effort or pain, so if Proton Bridge does not work for you, then that is a valid reason to seek something else.
I appreciate you taking the time to actually reply back with your grievances. While it may not appear so in my post, it did give me something to think about.
Well, there are plenty of email services that are not super pro-GOP and pro-Trump. Yes, it is ideal to avoid big corporations, but in many cases you simply don’t have an option (see computers, printers, etc.)
I’d rather not give them my money though, and I’d rather not use their services if given alternatives
You keep repeating that their services are not bad, but I don’t think that is true. Everything being tied to one account has an objective downside. The requirement of Proton Bridge for IMAP support is a downside. Somebody else has already mentioned how it won’t work for mobile, meaning you’re forced to use the official client. The lack of a Linux client for Proton Drive is a clear downside for it.
Judging by your last statement, I feel like you didn’t really read my comment and just cherry-picked parts to comment on. I ultimately agreed with your points in some form, and you…challenge me anyway? You once again say putting everything in one basket is bad as a matter of fact, saying it has an objective downside, and don’t even bother to say what that downside is or expand on why.
I’m sure you are not invested in this discussion, but you should at least act in good faith if you are going to engage anyway.
Edit: Also NOWHERE in my post did I say their services were good (not bad). I am now convinced you were acting in bad faith.
You have already mentioned it, it makes it more difficult to switch away to an alternative and it locks you down to Proton’s services. One of the main reasons why it’s so difficult to switch away from Google is due to their vast “ecosystem” of software services, though of course, this is an extreme example. Proton is a much smaller company, but my point remains that it is more difficult to go from Proton to another email service (like Disroot or mailbox) than it is to do the reverse.
I can think of another too. If one account is compromised, the whole “ecosystem” with email, drive, VPN, and maybe passwords/2FA (depending on how bad it is) could also be accessed or blocked. There’s a higher chance for one company to be bought out by Big Tech, banned in your country, sanctioned by the U.S., etc., than many simultaneously.
It doesn’t look like you have. You negated how Proton is licking the boots of Trump by saying “every CEO is pro-GOP”. You emphasised how they were “not bad”, all of my points were “personal decisions” of some sort.
No, you said they were not bad. Distinctly different from good. You said my points does not make Proton “objectively bad”, that they were all “personal choices”. I said that a lack of a Linux client for Proton Drive is bad. The lack of proper IMAP support (that is, without the use of Proton Bridge, since it only works on desktop) in Proton Mail is bad. Tying everything to one account is bad.
Personally I don’t like how they do marketing, it feels scammy. the naming, calling “unlimited” something that isnt, highlighting the more expensive option, playing with text sizes to make the lower number that is less truthful larger, the alwaus visible banner with distracting background color that advertises some timed discount. also the newsletters, I mean in my mailbox its fine, but when I register someone on protonmail, go out of my way to disable the promotional emails, and later they are automatically subscribed to them for new proton products… what do I say with straight face if someone asks me about any of these?
Proton supports Trump
I won’t comment on the Proton thing as the other replies already explained it well.
IMAP does not make it more secure, it makes it so that you can use any email client and aren’t tied in to their proprietary apps, like you are with Proton. You either need their desktop app or their bridge.
IMAP having weak security is not an issue (also I’m not aware that it has, you can use imap with plenty of authentication options), because all of your emails are encrypted if you set it up correctly. Someone could steal my every single transaction with mailbox.org and not be able to do anything with the data.
how do you use that on an email client on ypur phone?
why is that such a big issue when everything is transferred over an encrypted connection? sure, not optimal, but email providers don’t want to adopt more modern standards for some reason.