Tuta Mail
German encrypted email that hides the subject line as well as the body.
TL;DR verdict
Tuta is the mailbox for people who read the Proton Mail small print and decided that unencrypted subject lines were the deal-breaker. It encrypts more of the message, uses its own client-side search, and pays for that with a rougher day-to-day feel than Proton.
What we like
- Encrypts subject lines, not just message bodies
- Encrypted address book and calendar built into the same account
- Free tier is usable, if narrow, and does not require a phone number
- Post-quantum key exchange rolled out ahead of most competitors
Where it falls short
- No PGP support, so external interop is password-protected messages or plaintext
- Sync UX is rougher than Proton, especially on iOS push
- Search is entirely client-side, which is more private but slower
- No IMAP bridge, so third-party mail clients are not an option
TL;DR verdict
Tuta is the encrypted mailbox that takes the "encrypted" part further than anyone else and pays for it in convenience. Subject lines, contacts and calendar entries all sit inside the encrypted vault; interop with the rest of the email world happens through password-protected web messages. Worth the friction for a specific kind of user.
What it does well
The scope of what gets encrypted is the pitch. Message bodies, attachments, subject lines, contact entries and calendar events are all stored end-to-end encrypted, with the keys derived from the login password. Proton stores subject lines encrypted at rest but has to expose them to make standard mail work; Tuta does not, because it does not try to make standard mail work.
Search runs entirely client-side against a local encrypted index. This is slower than Gmail-scale server search and takes a first-time indexing pass to warm up, but nothing about your queries leaves the device. The calendar and contacts are built in and behave the same way — no separate app, no separate encryption story.
The post-quantum key exchange work is real and shipped, which is more than most of the market can say. If a slice of your threat model involves an adversary storing traffic today to decrypt in a decade, having a hybrid classical-plus-lattice key exchange on by default is a genuine upgrade.
Where it strains
No PGP is a real limitation. Sending an encrypted message to someone outside Tuta means either a password-protected web message the recipient opens through a link, or plaintext. There is no bridging into the wider PGP ecosystem, which makes Tuta less useful as a cross-provider tool than Proton.
There is also no IMAP bridge. You use Tuta's own clients — web, desktop wrapper, iOS, Android — or you do not use Tuta. This is a coherent security choice; it is also a real limitation if you want to run mutt against your mail.
Day to day, the sync feels a step behind. iOS push notifications occasionally arrive late. The desktop client is functional but plainer than Proton's. None of this affects the encryption story, but it is what you notice after the first week.
Who it's for
Journalists and activists who want the encryption boundary drawn further out than Proton draws it, and who mostly correspond with people already on Tuta or willing to click a password-protected link. Remote workers who want an encrypted calendar and contacts under the same login. Anyone who has read enough about post-quantum threats to want a mailbox that is already dealing with them.
Frequently asked
How is Tuta different from Proton Mail in practice?
Tuta encrypts more — subject lines, contacts, calendar — and gives that up on interoperability, since it does not speak PGP or expose an IMAP bridge. Proton encrypts less at rest but plays better with the rest of the email world. If everyone you email is already on Tuta, or you are happy to send password-protected web messages to outsiders, Tuta is the stricter choice. If you need to email a lawyer on Gmail every day, Proton is calmer.
Is Tuta based in Germany a problem?
Germany has strong privacy law and a court system that has actually pushed back on surveillance overreach. It is also inside the EU and reachable by European legal process. Tuta has been compelled in past cases to log metadata for specific accounts under court order, and has said so publicly, which is honest and worth knowing. Content stays encrypted; the fact of who is emailing whom is not always hidden.
What is post-quantum email and do I care yet?
Tuta has rolled out a hybrid key exchange that combines classical elliptic-curve crypto with a lattice-based algorithm believed to resist quantum attacks. For most threat models this is future-proofing rather than an immediate need. For people whose adversaries might store encrypted mail today and decrypt it in a decade, it is worth having on by default.