Introducing ProtonMail Bridge, email encryption for Outlook, Thunderbird, and Apple Mail

综合技术 2017-12-07

Today we are officially launching ProtonMail Bridge, which brings easy-to-use email encryption to desktop email clients.

Ever since the day that we first got the idea to create ProtonMail, one of the most enduring challenges has been how to do email security right while simultaneously making encrypted email easy enough to use for normal people. Since our early days working from the CERN cafeteria , we have been working tirelessly to address this specific problem.

In the years since, we have made many great strides towards creating usable encrypted email, first with ProtonMail’s webmail interface and then with ouraward-winning iOS andAndroid secure email apps. However, one of our goals has always been to bring easy-to-use encrypted email to desktop. The problem is formidable. Desktop systems encompass multiple operating systems with dozens of popular email clients with their own adherents, and virtually none of them natively speak PGP, the email encryption standard upon which ProtonMail is built.

Around two years ago, we created a small task force to tackle this challenge. Today, we are finally ready to presentProtonMail Bridge.

What is the ProtonMail IMAP/SMTP Bridge?

In a single sentence, ProtonMail Bridge is an application that allows you to use your ProtonMail encrypted email account with your favorite desktop email client such as Thunderbird, Apple Mail, or Outlook,while simultaneously retaining the zero-access encryption and end-to-end encryption that ProtonMail provides. The best part is that this does not require modifying your email client or making changes to your existing workflow. Use email like you have always used it, and the Bridge will automatically encrypt and decrypt messages in the background.

How does the ProtonMail Bridge work?

The Bridge is an app that youdownload and install locally on your desktop or laptop computer and it runs automatically in the background.

The Bridge essentially acts like a local email server (using the IMAP and SMTP protocols) and interacts with email clients also installed locally on your desktop computer. As a result, all encryption and decryption occur locally and thus the benefits of end-to-end encryption remain. The Bridge communicates with ProtonMail’s encrypted email server via our API, which supports end-to-end encryption, while email clients can communicate directly with the Bridge via standard IMAP and SMTP. In this way, standard email clients which do not natively support end-to-end encryption can support encryption without modification. Another way to think of it is that the ProtonMail Bridge translates end-to-end encrypted email data into a language that any email client can understand, thus “bridging” the gap between ProtonMail’s end-to-end encryption and your standard email client.

Full-text search, multiple accounts, import/export

One of the powerful benefits of using the Bridge and email apps like Thunderbird, AppleMail, and Outlook is being able to use full-body text search within your encrypted emails . The Bridge decrypts messages as they arrive in your computer and delivers them to your desktop email client. These local copies are stored on your computer, so the search features of your desktop client work normally and you can search within your encrypted emails.

Another powerful benefit of the Bridge is being able to have multiple accounts added to an email client . For example, many users will have both a Gmail account and a ProtonMail account. In this scenario, you could simply drag messages between accounts using Thunderbird (for example). This essentially enables you to drag and drop an existing Gmail account into a new ProtonMail account as a way of doing “Account Import” (a dedicated account import and export tool is currently under development). Similarly, for users who want a backup of their ProtonMail data, most native email clients let you mass export your data and download it. You can also have multiple ProtonMail addresses and accounts in a single email client, and move messages between your ProtonMail accounts.

Threat Model

The Bridge preserves end-to-end email encryption, and also zero-access encryption (meaning that even we cannot read your emails). However, the Bridge does not protect your emails from end-point compromise (e.g. compromised laptop). Since the Bridge decrypts data locally, it’s important to ensure that your computer is safe. If someone breaks into your computer while using the Bridge, the unencrypted data could potentially be viewed as well.

During the installation process, the Bridge will auto-generate a “Bridge Password”. This Bridge Password is used to setup and configure your email clients. In this way you don’t need to trust your email client with your secret ProtonMail password.

JavaScript Cryptography and Open Source

Because the Bridge is locally installed, it is like our mobile apps in that it does not do decryption in a browser. Therefore, the Bridge also guards against the threat vector of somebody compromising the connection between you and ProtonMail in order to send you bad JavaScript code, or ProtonMail getting compromised and serving a malicious webpage to users.

Furthermore, after the technical documentation of the ProtonMail Bridge code is done, we will be releasing the source code of the Bridge, so that you can even compile it yourself instead of getting the binaries from us, so there is even less need to trust us. This is an important step in our work to eliminate ProtonMail itself as a threat vector.

Using the ProtonMail Bridge

The Bridge software is easy to set up and use. The setup process consists of:

  1. Installing the Bridge app
  2. Adding your ProtonMail account to the Bridge
  3. Adding your ProtonMail account to your email client (Thunderbird, Apple Mail, Outlook)
  4. Configuring your email client’s settings (ports, password, etc).

Currently, the officially supported email clients are Thunderbird, Apple Mail, and Outlook, on both Windows and MacOS (Linux is coming in Spring of 2018). However, in theory, any IMAP email client can work with the Bridge, and in our beta testing, many were shown to work. If you are a paid ProtonMail user, you can immediately get started here:

Finally, we would like to thank the thousands of ProtonMail users who participated in the Bridge Beta over the past year. Your support and feedback was invaluable towards bringing the Bridge to fruition, and we look forward to making ProtonMail even better for the community.

Best Regards,

The ProtonMail Team

You can read the ProtonMail Bridge press releasehere.

ProtonMail’s media kit can be foundhere.

ProtonMail Bridge images can be found here .

You can get a free secure email account from ProtonMail here .

We also provide a free VPN service to protect your privacy.

ProtonMail and ProtonVPN are funded by community contributions. If you would like to support our development efforts, you can upgrade to a paid plan or donate . Thank you for your support!

Share This! Get an Encrypted Email Account


Apple’s 2019 iPhones may have 3D laser senso... Apple's front-facing 3D TrueDepth camera system was a big deal for the iPhone X's Face ID package to replace Touch ID. Apparently, the company is ...
Cult of Mac Magazine: Everything Apple unveiled th... Apple’s first ever keynote at the Steve Jobs Theater last Tuesday was one for the ages as the company took the wraps off some of its most innovative p...
苹果不再蛮横 允许微信打赏功能回归!还收30%分成吗?... 苹果多年来稳坐手机市场份额第一,跟手机有关的一切,老大哥都拥有一定话语权。也因此,苹果相当蛮横,能推卸的责任就推卸,冷不丁就怪消费者使用不当。 不知道大家还有没有印象,去年五月份,苹果曾强烈禁止中国用户在各种社交网络上的打赏功能,直接要求微信等应用关闭打赏功能,或者收用户打赏30%分成...
苹果对产品泄密不能忍,要求员工远离三类人... 【Technews科技新报】近日,彭博社曝光的一份苹果内部备忘录显示,苹果在过去一年共抓到29名泄密者,其中12名被逮捕。这些员工包括苹果正式员工、合同工,以及供应链公司员工。 苹果告诫员工,不要心存侥幸,公司正严惩泄密问题……泄密者不仅会丢掉工作,而且会坐牢、面临巨额罚款。 ...
苹果新专利:计划让AirPods成健康追踪器... 实健康追踪器这个词大家并不一定很熟悉,实际上你可以将智能手表、手环或者很多穿戴设备当作健康追踪器,他们可以监控你身体的一部分数据,比如心率、运动记步、汗液检测等等,并不局限于某一方面。 AirPods 最近苹果申请了一项专利,与健康追踪器有关。在专利文件中,苹果指出用户希望能增加...