This website is an independent informational resource and is not affiliated with, endorsed by, or operated by Tuta (formerly Tutanota) or Tutao GmbH.
Basics

Encryption Basics: How Tuta's Approach Generally Works

"End-to-end encrypted email" gets used a lot without much explanation. Here's a general walkthrough of the concepts, based on how Tuta's documentation describes its approach.

1

Data is encrypted before it leaves your device

With end-to-end encryption, content is generally encrypted locally, before being sent to the provider's servers, so the provider itself typically can't read it in plain text.

2

Tuta uses its own protocol, not PGP

Rather than PGP (a common older standard), Tuta's documentation states it developed a custom encryption approach, which it says also allows subject-line encryption — not just the message body and attachments.

3

Post-quantum encryption is being layered in

Tuta has also discussed developing post-quantum-resistant encryption (referred to as TutaCrypt in its own materials), aimed at protecting data against future, more powerful decryption techniques.

4

Encryption doesn't erase all metadata

Encrypting content doesn't necessarily hide everything about a message — some metadata (like who's emailing whom, roughly when) can still exist at the infrastructure level, depending on the specific service and setup.

FAQ

Common questions

Are emails encrypted even if the recipient doesn't use Tuta?

Encryption between two Tuta accounts is generally seamless. For a recipient outside Tuta, encrypted providers commonly offer a password-protected email option instead, where the recipient enters a shared password to read the message through a web link.

What does it mean that Tuta doesn't use PGP?

PGP (Pretty Good Privacy) is a widely used, older encryption standard for email. Tuta has developed its own encryption protocol instead of using PGP, which its documentation states allows it to also encrypt the subject line — something traditional PGP setups typically leave unencrypted.