This might come out as a bit of a rant, but I just wanted to post it here anyway since it’s the only social media I use.
Recently, I’ve been making some steps to improve my privacy. GrapheneOS, Linux on my PC, open source software, moving away from Google stuff. So, next logical step was for me to switch away from Gmail. I went with Tutanota, since they’re based in EU, their mobile app is on F-Droid and doesn’t require Google Play Services. So I made an account, switched a bunch of my private account e-mails from Gmail to Tuta, and was basically done. Two days later, I wake up to a “invalid credentials” message. I checked the option to remember my password on my PC, so I thought it was weird. I checked my phone, and it turns out I was logged out of the app too. I tried changing my password with recovery code, thinking something went wrong (though unlikely since I used a password manager), but I got an error on that one too. So I contacted Tutanota, almost a week ago. No response.
I tried looking on various sites to check if people had a similar issue. I found a few reports on Reddit. The moderator of Tuta says to contact the e-mail address that I sent a message to already, but people complained that they haven’t gotten a response either. I found out that similar reports were happening for a while now, accounts being flagged for seemingly no reason. I found one post from October, 2024, from a frustrated user. He said he was in the same situation, and when he finally got the reply, Tutanota said they can’t do anything. When I found that post, I was really disheartened. I’ve already went back on a bunch of accounts to @gmail.com account, for safety, but there is still a few that I’m not even able to access because they use e-mail 2fa. Some of them being accounts for various government public services.
So this one gave me a pause on my privacy journey. I never encountered problems like this one before. A service blocking my account without any message or warning. No contact from support. Being locked out of my accounts. I’ve lost a lot of enthusiasm to replace a few proprietary services that I have left.
Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.
In this community everyone is welcome to post links and discuss topics related to privacy.
much thanks to @gary_host_laptop for the logo design :)
Yeah same here, they deleted my old addr for inactivity, fine, so I made a new one. “Flagged for review, cannot send/receive emails at this addr yet” 2d go by, “flagged harder, reach out, using the email that can’t send email, to tuta support and explain why you need this acct.” Tried to send the email, perhaps unsurprisingly, to no success.
So I created a Disroot acct instead. They also flagged me for review (but then approved me, and I did it twice so I have two disroot accts which I need for different reasons), and their sign up site is pretty bad (it says “weak password” until you get enough chars in the prompt, coulda just told me that instead of making me insane rolling 30 different passwords in keepass…) but still, much better now, I have IMAP and disroot doesn’t delete for inactivity, so, woohoo!
That’s why I switched to my own mailserver. Sure this isn’t something for everyone. But getting a vps with a reputable and static IP to setup stalwart and use their manual for building up all the DNS querys wasn’t that hard.
Sorry to hear this, what a nightmare.
If your old Gmail account lives, my thought is to carry on using that with auto forwarding to a fresh Tuta account and see how that goes, using the fresh Tuta and copying to old Gmail for redundancy / fallback. Thats what I did
This is what I hate about all email and why I say every so often I would like citizens public email. I mean this could happen with google. We need to have a right to an email address.
I bet the US will be your full name + the last 4 digits of your social.
fulllegalnameyearemailactivated@street.city.state.us
Use duck dot com email proxies, ya noob.
Buying a domain and using that is a good idea, and you can also do a catch-all so you can give each service their own address and see which ones leak your data
I think it’s safe to say you went too fast (id always start with email forwarding and slowly moving services over in ascending order of importance, and make sure you avoid email 2fa if at all possible), but that does suck.
Tuta is definitely the least reputable of the privacy email services, I still don’t know why they get recommended. I’ve made and lost several accounts with them and treat them like a burner.
Protons a bit risky to me because they’re very aggressive about immediately locking you out if you don’t pay right away (in this case a trial expired, they charged me with no credit card on the account and threatened to block me from accessing my account if I didn’t pay up even though I immediately contacted them and tried to cancel as soon as I saw the trial expired). To me that level of inflexibility is, while maybe acceptable in Europe, not for me. I keep a few email addresses and as soon as the above happened immediately moved everything out of proton.
But really what I’d recommend is the more traditional services that you pay a small amount for. Posteo has been good for me for several years. I’ve read similar things about similar services which aren’t marketed as “privacy” services but instead they just aren’t Google.
+1 for Posteo
A lot of these “privacy sensitive” service providers are actually quite user-hostile.
Find a middle ground - get your own domain (pick a good registrar) and find a respectable mail host that has a support team with accountability who don’t treat you like a burden on this planet when you attempt to contact them (i.e not Tuta, not Mailbox-org - nope!!!, not Proton etc.). Do not go overboard with DMARC/etc in the beginning. Go about it slowly.
Also - make sure you use a service that lets you connect via an IMAP/POP client. It pains me to say that, but if you start avoiding services based on “five eyes” and “14 eyes” and “195 eyes”, I’m pretty sure we will be looking at pigeons and corked bottles in the sea. So, if you need E2EE over email - please use E2EE in the email using GPG on your own. I’d highly recommend not falling for the privacy theatre of the likes of Proton.
I understand the tuta and proton hate, but what’s wrong with the mailbox dot org?
I think they have some sort of critical security flaw regarding spoofing that hasn’t been resolved in years and they had a forum thread about it
I found some really old leddit and HN threads with similar warnings but nothing conclusive –Please send links if anyone finds anything convincing
Did we read the same post?
+1 for Proton as a security theatre.
Proton is not safe, the Swiss government can (and did, in fact) ask Proton for users’ IP addresses and metadata.
Plus, Proton forces you to use their client instead of standard IMAP.
What metadata?
Proton stores senders and subjects in clear text. Only the content of the email is encrypted.
That means that the Swiss government can easily force them to handle out that data.
Fastmail is what i use for this. $50/year. Not gmail. Catch-all email boxes. So i use a new address for everything. It’s not proton. So not sure if it’s even encrypted at rest. But they are not selling my email to advertisers like gmail. And if I want to move I own my domian so its easy.
I’ve been using tuta for more than 3 years now, paid, and even though it has its drawbacks, it’s a good secure alternative to most providers nowadays.
I’ve had to deal with support a while back and even though they were not the fastest, they replied on a fairly timely manner.
I’m sorry to hear you’ve had a bad experience with them.
Lol ya here’s how I use tuta. It’s 90% of the time just a recovery option for other emails that require another email so nothing gets linked. You don’t want to use their app even if its on fdroid its going to make it easy for them to keep track of what you’re up to. Use rethink or foxyproxy to rotate proxies on a mobile browser or tab and open it there, don’t stay logged in. Set reminders on your organization system to periodically login to free blob datacenter emails and clouds. Euros can suck my eggs im not giving them money bc they used the bourgeois state to present a facade of respecting privacy.
Ive lost several tuta accounts, mostly for being inactive in them for 6 months, I find their service pretty annoying, but i think it’s a good idea to write down a password for these kinds of things, and keep it hidden somewhere physically
i dont like the password manager random character youll never recall it nonsense
also setting up a recovery email for a new secure email is important but i understand that doesnt help you now
having to use an email for govt accounts is really annoying ive just had to recreate everything after using the same account for 10 plus years
best of luck op
Wat?
Annoying experience you’ve had there.
I have never had any problem. I have my own domain names, I host them privately and on a webhotel. And then I use Thunderbird - and it just works.
I went through a similar situation with openmailbox dot org, though of course in their case the entire service suddenly shut down. Terrible position to be in. I eventually recovered most, but not all, accounts using that email address. Huge PITA.
Just curious was this a Tuta paid account, or a free one?
Tuta is very strict with the free accounts and flag them for all sorts of reasons. They take their time to “approve” free accounts just to be able to use them. And on top of that they might nuke your account anyway if they think it is being used for spam/illegal activity/whatever or they think it’s not being used.
But I thought those are just issues with their free accounts, presumably their paid accounts don’t get flagged for those things… or so I thought.
Also to echo the other comments - best to buy and own your own domain for your email, that way it doesn’t matter where the email is being hosted in case you need to switch email providers.
I’m really sorry this happened to you OP.
I would really recommend that you consider getting a custom domain for your email. many are not that expensive and if you do, then you can just point that domain at whatever email provider you want without changing your email on the services.
in this scenario, it would let you setup that domain on another provider and at least get access to any emails going forward.
A good and super cheap hosting provider for emails is PurelyMail, albeit it’s based in the US