Secure Mail Guide
Flat isometric illustration of a blue envelope holding a shield with a padlock, on a magenta pad of linked glowing nodes with small floating app cards.
guides

How to Create a Secure Email Account: Step by Step

This guide explains how to choose a secure email provider, limit signup identifiers, protect recovery, enable 2FA, use aliases, and verify encryption.

By Secure Mail Guide Editorial · ·Updated August 22, 2026 · 8 min read

“Secure email account” is a phrase that hides a decision tree. It can mean an account nobody can read in transit, an account nobody can link to your legal name, an account that survives a stolen password, or an account whose provider cannot hand over the contents when asked. Those are four different jobs, and the setup that does one well can be indifferent to the others.

This is the order the steps actually have to happen in. Get them out of order and you end up re-creating the account, because the two decisions that are permanent, the address itself and the identifiers you seed it with, both happen in the first ten minutes.

Step 1: Decide what the account is defending against

The provider choice follows from this and not the other way round. An account meant to keep a marketing platform out of your correspondence has different requirements from one meant to survive a subpoena, and only the second one makes jurisdiction worth arguing about.

Work through the email security threat model before you open a signup page. It lays out who can realistically reach your mail, under what circumstances, and which of those threats a provider change fixes at all. Some of them, notably anything reaching your device or your recipient’s device, no provider can fix.

Write down the answer in one sentence. It is the only input the rest of the steps need.

Step 2: Pick a provider that matches that sentence

Two things separate providers meaningfully: what is encrypted such that the provider cannot read it, and which legal system the provider answers to. Everything else is user interface.

  • If you want the shortest path to a working encrypted mailbox with a full app ecosystem, the ProtonMail setup guide covers Swiss-jurisdiction Proton Mail end to end.
  • If encryption coverage matters more to you than ecosystem breadth, Tuta encrypts subject lines and the whole mailbox index, which Proton does not. The Tuta setup guide walks through its tradeoffs.
  • If you have not narrowed it down, the ProtonMail vs Tuta comparison is the head-to-head, and the encrypted email provider matcher turns hard requirements into a ranked shortlist by treating each requirement as a knockout filter rather than a preference.
  • If the budget is zero, the best free encrypted email accounts piece covers what each free tier actually gives you before the paywall.

One warning worth internalising: an encrypted mailbox does not make mail to outside recipients end-to-end encrypted. Read how email encryption actually works if that distinction is not already clear, because it changes what you should expect from the account you are about to create.

Step 3: Sign up without seeding the account with identifiers

Everything you hand the provider during signup becomes a permanent link between the account and you. This is the step people regret.

The address is forever. You can add aliases later on paid plans, but the primary local part typically cannot be changed. If unlinkability matters, do not use your name, initials plus birth year, or a handle you already use publicly. If unlinkability does not matter, use something you will still want on a business card in five years.

Verification. Providers ask for a phone number or a secondary email to stop bulk account creation. A phone number is the strongest identifier you can hand over. Prefer the secondary-email option where it is offered, and prefer a secondary address that is itself not tied to your name. Verification requirements often vary by signup pattern rather than being fixed, so an account created from a residential connection may not be asked at all.

Payment. Paying by card links the account to a name and a bank. Providers that accept cash or cryptocurrency exist for exactly this reason. If your threat model is “my email provider should not profile me for advertising,” a card is fine. If it is “this account should not be linkable to me,” it is not.

Network. The provider records the IP address the account was created from unless you take steps otherwise. Whether that matters is, again, a threat-model question rather than a universal rule.

Step 4: Set a password you cannot lose and a recovery path you control

Encrypted mailboxes derive your keys from your password. That has a consequence most services do not have: the provider genuinely cannot reset it for you and keep the encryption honest. Lose the password with no recovery method configured and the mailbox is gone, permanently, including everything already in it.

So the password rule here is not the usual one. It is:

  1. Generate a long random passphrase in a password manager. NIST SP 800-63B has been explicit since 2017 that length beats forced complexity and that mandatory periodic rotation makes things worse, and EFF’s diceware method produces something memorable and strong if you need to type it from memory.
  2. Store it somewhere that survives the loss of the device you created it on.
  3. Set the provider’s recovery phrase or recovery file during setup, and store that separately from the password. A recovery phrase is a second copy of your key material, not a password reset.
  4. Understand what a recovery email buys you versus a recovery phrase. On some providers a recovery email restores account access but not the encrypted mail already in it. Read the provider’s own wording before you rely on it.

Step 5: Turn on the right kind of two-factor authentication

Enable it before you send the first message, and pick the method deliberately:

  • Hardware security key (FIDO2/WebAuthn): strongest, because the key checks the site’s origin and therefore cannot be phished by a lookalike login page.
  • Authenticator app (TOTP): strong, and universally supported. Aegis on Android and Raivo or Ente Auth on iOS are the usual picks.
  • SMS: better than nothing, and the weakest of the three, because SIM-swap attacks move your number to someone else’s device without touching your password.

Save the backup codes into the same password manager entry as the password. Losing 2FA on an encrypted mailbox is the second most common way people lock themselves out permanently.

Step 6: Configure the account before you hand out the address

Three settings are worth changing on day one, and the labels are broadly similar across providers:

  • Block remote content and tracking pixels. Marketing mail embeds invisible images that report when and where you opened a message. Blocking them by default removes a read-receipt channel you never agreed to.
  • Link confirmation. A confirmation step before opening external links costs a click and catches the phishing links that get through.
  • Active sessions. Review the session list and sign out anything you do not recognise. Do this again after any device you lose.

Step 7: Give out aliases, not the address

The address you just created should be seen by as few parties as possible. Every service you sign up to gets its own alias that forwards to it, so a leak is attributable and killable at the source rather than a permanent spam subscription.

The mechanics, and the difference between provider-native aliases and dedicated services like SimpleLogin or Addy.io, are in email aliases for privacy. This is the single habit with the best ratio of effort to result on this whole page.

Step 8: Verify the encryption is actually on

Do not assume. Send a message to a second account you control on the same provider and confirm the interface marks it as end-to-end encrypted. Then send one to a Gmail or Outlook address and observe that it is not marked the same way, because it is not: it is TLS in transit and stored in plaintext at the far end.

If you need real end-to-end encryption to recipients outside your provider, you need PGP or a password-protected message. What PGP encryption is and how it works covers the model, how to set up PGP for email covers key generation and client setup, and if the other side is on Gmail, PGP encryption in Gmail covers the browser-extension route.

Step 9: If you own a domain, authenticate it

Using your own domain makes the address portable between providers, which is the one thing a provider-hosted address can never be. It also makes you responsible for three DNS records: SPF, DKIM and DMARC. Without them your mail lands in spam folders and anyone can forge your address.

SPF, DKIM, and DMARC setup for a custom domain covers what each record does and how to confirm it is working rather than merely present.

What this account still will not do

Be clear-eyed about the boundary:

  • Metadata stays visible. Who you mailed, when, and the subject line on most providers. Encrypted bodies do not hide the envelope.
  • The recipient’s copy is out of your control. Mail to a Gmail address sits in Google’s systems, subject to Google’s policies, regardless of where it was sent from.
  • Device compromise defeats everything. Keys live on endpoints. Malware on your laptop reads plaintext.
  • Legal process still exists. A provider that cannot read message bodies can still be compelled to hand over what it does hold, and to start logging what it does not.

If your requirements go past what a mailbox can do, that is a signal to move the conversation to a messenger with forward secrecy, not to buy a bigger email plan.

The ten-minute version

  1. Write one sentence describing what you are defending against.
  2. Choose the provider that matches it; use the matcher if unsure.
  3. Sign up with an address you can live with and the fewest identifiers you can get away with.
  4. Random passphrase in a password manager, recovery phrase stored separately.
  5. Two-factor authentication on, hardware key or TOTP, backup codes saved.
  6. Block remote content, enable link confirmation, review sessions.
  7. Hand out aliases from here on, never the address itself.
  8. Send two test messages and confirm what is encrypted and what is not.

Steps 3 and 4 are the ones you cannot redo later. Everything else is adjustable.

Sources

  1. NIST SP 800-63B: Digital Identity Guidelines, Authentication and Lifecycle Management
  2. Creating Strong Passwords - EFF Surveillance Self-Defense
  3. Proton Mail plans and pricing
  4. Tuta pricing and plan limits

Related