Website online. Mail service in development; launch follows security reviews.Current status

Mail apps and open standards

Which open standards we plan for lettron.eu and how your usual mail app is meant to work with them.

Status: The mail service is in development and not yet available. This page describes our plans. It is neither a set-up guide nor a list of tested apps.

Keep your mail app

lettron.eu is meant to work with the apps you already use. Rather than our own protocol island, we plan a service that speaks open standards for mail, filters, calendars and contacts. In the default mode, Compatible, native IMAP access is planned, with no extra program between app and mailbox.

Planned standards

StandardUsed forPlanning status
IMAPFetching mail and keeping devices in syncIntended for launch: IMAP4rev1 with extensions such as IDLE and QRESYNC. IMAP4rev2 only once Dovecot, the server software, supports it.
SMTP submission, POP3Sending (SMTP) and simple retrieval (POP3)Intended for launch.
JMAPNewer mail protocol, the intended basis for webmailAn aim, not a commitment. The chosen server software lacks it; the route is open.
Sieve, ManageSieveFilter rules on the serverIntended for launch.
CalDAV, CardDAVSynchronising calendars and contactsIntended for launch; needs additional server software.
OpenPGP (RFC 9580)Encrypting Sealed foldersPlanned with Sealed. Sealed is an aim for launch, not a commitment.
WKD, AutocryptPublishing (WKD) and exchanging (Autocrypt) public OpenPGP keysPlanned alongside Sealed.

IMAP and POP3 are planned over TLS only. The roadmap shows the order of steps, the Open source page the software.

What it should work with

Through these standards, lettron.eu is meant to work with Thunderbird, Apple Mail, Outlook and any other IMAP and SMTP app. As there is no service yet, we call no app tested or supported.

Automatic configuration is planned for set-up: Thunderbird autoconfig, Apple configuration profiles and SRV records (RFC 6186). Webmail is also planned. Our own Android and iOS apps are planned for later; the timing is open. For your own domain, see Domain Autopilot.

Signing in from mail apps

To sign in over IMAP, SMTP, CalDAV or CardDAV, an app sends a secret to the server, protected by TLS. Your main password should therefore never be stored in a mail app. Separate app passwords are planned: one per device, each individually revocable.

Where an app supports it, OAuth 2.1 is intended instead. We are still checking which widely used apps do.

Two levels of protection

Two levels of protection are planned, chosen per folder.

Compatible (default)

Mail is to be stored encrypted with a separate key per account. When your mail app signs in, the server is to decrypt and deliver over TLS, so any IMAP app works without extra software. The price: the server temporarily processes plain text, for example while your app is signed in. Compatible is therefore neither zero access nor end-to-end encryption.

Sealed

These folders are to be encrypted with OpenPGP; decryption then lies with your device, not the server. An ordinary mail app will therefore not open them directly. Access is intended through our own apps or a local bridge, a helper program on your device. The bridge comes later; for now only a concept is planned.

The Security page covers encryption, sign-in and the limits.

Moving and export

Open standards also apply to the way out. We call this exit by design: every plan is meant to include a complete, free export of mail, contacts, calendars and keys in open formats. The data format is to be documented; the export tool is to use standard protocols such as IMAP. For context, see the comparison.