Security
Security should be quiet.
- 01
Transport
The website and mail connections use TLS. Mail between ZanonMail and other providers uses TLS where the other side supports it.
- 02
Authentication
Sign-in uses your ZanonMail address and password against the mail server with OAuth (PKCE). No social login. Tokens stay in HttpOnly cookies.
- 03
Password handling
Passwords are verified server-side and are not stored in browser storage or application source. We will never ask for a password by email.
- 04
Sending authenticity
SPF, DKIM, and DMARC are published for @zanonmail.com so other providers can verify origin.
- 05
Spam and abuse
Unsolicited and abusive mail is filtered. Signup, sign-in, and recovery run a self-hosted proof-of-work check — no Google or Cloudflare widget. We rate-limit signup and enforce address caps on the server. Reports go to abuse@zanonmail.com.
- 06
JMAP access
The webmail client talks to the mail server over JMAP with your session — not with a shared admin identity reading your mail.
- 07
App passwords and external clients
Optional IMAPS (993) and SMTPS (465) use a separate app password, not your primary password. Third-party clients can store mail on that device. POP3 is not offered.
- 08
Recovery key
On signup you receive a one-time recovery key. We store only a verifier. Lose both password and key, and recovery may be impossible.
ZanonMail is operated by Zentrix Data in Dubai, United Arab Emirates. Last updated 19 August 2026. These pages describe how the product works today. They are not a substitute for counsel and should be reviewed by a lawyer before they are treated as final.