What Encryption Does Proton Mail Use?

What Encryption Does Proton Mail Use?
Proton Mail encryption stacks three layers to keep your email private. Mail sent between Proton users gets end-to-end encryption through OpenPGP, so it is scrambled on your device before it ever reaches a server. Anything stored in your mailbox sits behind zero-access encryption, which means Proton cannot read it. Messages to the outside world travel over TLS. Underneath sits AES-256 for the content and elliptic-curve keys for the exchange. Strong, though not a cloak of invisibility.
This page is part of the Proton Mail FAQ Hub.
What are the layers of Proton Mail encryption?
Proton Mail encryption is not a single switch but three layers doing different jobs. The first is end-to-end encryption for mail between Proton accounts. The second is zero-access encryption for anything stored on Proton’s servers. The third is TLS, the same transport security your bank uses, for messages heading to non-Proton addresses. Keep them separate in your head and the whole system makes sense.
The unifying idea is simple. Your content is encrypted on your own device before it goes anywhere, so Proton holds ciphertext rather than plain text. That is why the company cannot produce readable emails on demand: it genuinely does not have them. The maths does the work, not a promise.
What does end-to-end encryption mean between Proton users?
Send an email to another Proton user and it is encrypted on your device, then decrypted only on theirs. The servers in between carry a locked box they cannot open. This is the strongest protection on offer, it happens automatically, and you never have to touch a key or wrestle with settings.
Under the bonnet, AES-256 encrypts the message body whilst elliptic-curve public keys handle the secret exchange. That is current, well-regarded cryptography, delivered without a maths degree. The honest catch: both people must be on Proton for this to apply by default. Email one outsider and you drop to a weaker layer.
What is zero-access encryption at rest?
Zero-access encryption protects mail already sitting in your mailbox, including messages that arrived from Gmail, Outlook or anywhere else. Once a message lands, it is re-encrypted with a key only you control. Proton can see that an email exists and roughly when it arrived, but not what it actually says.
This is the quiet workhorse of the design. A server breach, a rogue employee or a court order cannot conjure up your readable inbox, because the readable version only exists once you log in and decrypt it. The limitation worth stating: the sender’s own copy, on their provider’s servers, sits entirely outside Proton’s reach.
What happens with emails to non-Proton addresses?
This is where expectations need managing. Email a Gmail or Outlook account and the end-to-end layer no longer applies by default. Your message travels over TLS, which protects it whilst in transit, but the receiving provider can read it once it arrives. That is not a Proton weakness. It is how standard email has always worked.
You can close the gap with a password-protected message, which encrypts the content for any recipient regardless of their provider. It takes a shared password and a little more effort. For genuinely sensitive mail to outsiders, that extra step is the difference between private and merely in transit.
Is Proton Mail encryption strong enough in practice?
Yes, and the algorithms are rarely the problem. AES-256 and elliptic-curve cryptography are used across banking, government and the wider internet. The realistic weak points are human: a reused password, a convincing phishing page, a laptop left unlocked in a cafe. Encryption cannot save you from handing over the keys yourself.
Here is the honest split of what the encryption does and does not cover:
A free account already includes the full encryption stack, which is the point worth repeating. Upgrading to Proton Mail Plus buys storage, custom domains and more addresses, not better cryptography. The maths is identical whether you pay or not.
- Protected: the content of your emails, both in transit between Proton users and at rest in your mailbox.
- Not end-to-end encrypted: subject lines and routing metadata, such as sender, recipient and timestamps.
- Down to you: a strong unique password, two-factor authentication and a device that locks itself.
Encryption on by default, zero faff.
The free tier already encrypts everything on your device. If you want custom domains and room to grow, Proton Mail Plus adds the extras without changing the maths.
Get Proton Mail Plus for £1 / $1 / €1 for your first month, a saving of 80%. Prefer to lock it in? The annual plan runs £2.40 / $3 / €3 per month, a saving of 40%.
Pricing shown in GBP / USD / EUR. The intro discount applies to your first billing period, then it renews at the standard rate. Affiliate link: BAIZAAR may earn a commission at no extra cost to you.
