Voidly

Voidmail / setup guide

Your inbox.
Your key.

Set up browser webmail. Keep the backup that lets you return.

Browser-held identitySeparate backup

Your account signs you in. Your matching key opens encrypted mail.

Know the route

Three different paths.

Inside Voidmail

Registered keys.

Webmail encrypts the subject and body for a recipient with a registered @voidmail.ai key before sending.

Set up the identity ↗
Incoming from outside

Forwarded email.

External mail reaches the email service in readable form. Forwarding and an encrypted webmail copy depend on your account setup.

Understand forwarding ↗
Outgoing to outside

Needs verification.

The secure-link flow exists, but complete delivery and decryption are not verified. Use another trusted channel for essential messages.

Secure-link limits ↗

Set up once. Keep the backup.

The browser setup.

Your account, alias and browser encryption identity are separate. Work through each step in the real account and mail pages.

01 / Your accountSign in, then check the mailbox
  1. Go to your account and use one of the sign-in methods currently shown.
  2. In the Voidmail section, choose Create Mail Account if you do not already have one. Follow the actual account form and its result.
  3. Keep your assigned address and anonymous alias distinct. Copy the alias from your account when you want to share that address.
  4. If creation fails, remains pending or no mailbox appears in webmail, stop and contact support. An account screen alone does not confirm mail delivery.

If the account form offers a master-password option, keep that password separately. It does not replace the browser keypair backup described below. If activation remains pending, contact support.

02 / Your encryption identityGenerate once, or import your existing backup
  1. Open Voidmail webmail while signed in. A new browser should show Set Up Encryption Identity.
  2. If this is your first identity, choose Generate New Keys. Webmail generates an X25519 keypair locally and attempts to register the public key.
  3. If you already have an identity, choose Import Keypair and select your own saved JSON backup. Generating a new pair cannot unlock messages encrypted to the old pair.
  4. Look for Encryption identity loaded — keys stored in this browser, then export a backup before changing browsers or devices.

That loaded indicator confirms local keys are present. It does not confirm that public-key registration or delivery succeeded. If a sender sees “Recipient has no encryption key registered,” check the recipient account and contact support if setup does not resolve it.

For internal messages, both subject and body are encrypted in the sender’s browser using TweetNaCl: X25519 with XSalsa20-Poly1305 and fresh nonces. The recipient needs the matching private key. Addresses, timing and routing metadata are separate from encrypted content.

03 / Your backupThe step that makes another device possible

Export on the device that has your keys

  1. In webmail, select Export backup beside the identity-loaded indicator.
  2. Save voidmail-keypair.json in a secure place you control, such as an encrypted drive or a password manager that supports file storage.
  3. Treat this JSON file as a secret. It contains the private key and is not itself password-encrypted by the export.

Restore in a new browser or device

  1. Sign in to the same account and open webmail.
  2. At the identity setup prompt, select Import Keypair and choose your saved JSON.
  3. Check that the correct identity loads and can decrypt your existing messages before removing the old device or its browser data.

If the new browser already has a different identity and no import prompt appears, do not erase either set of keys to force it. Export the current identity too and ask support for a safe recovery path.

The browser stores its active keypair in local storage. Clearing site data or losing the device can remove it. Without the matching backup or another device holding those keys, messages encrypted to that identity cannot be recovered by creating a new account password. Forwarded copies already in another inbox are separate.

04 / Your shared addressUse an alias, keep track of changes

An alias is a separate @voidmail.ai address that you can give to services or newsletters. It reduces exposure of the other address you use; it does not make you anonymous or hide network metadata.

  1. Copy your actual assigned alias from your account. Example addresses in a guide are not your mailbox.
  2. If you choose Regenerate Anonymous Alias, read the account confirmation before proceeding.
  3. Update services and contacts to use the new address. The old alias is intended to stop receiving after the change; do not rely on immediate revocation or continued delivery to it.

Webmail’s Aliases view has its own mailbox controls. Deleting one there and regenerating the account alias are different actions. Check the exact address before changing it.

Incoming mail & forwardingExternal mail has a different privacy boundary

Mail from Gmail, Outlook and other external senders is received by the email service in readable form. The service attempts to forward it to your registered external email address and, when your public key is available, encrypt a copy for webmail storage. This is not end-to-end encryption from the external sender.

Forwarding depends on account settings, a usable registered email address and successful delivery. The inbound system also has recovery forwarding paths; do not assume a forwarding preference proves every failure path stays inside webmail.

You can read a successfully forwarded copy in the ordinary mail client for that destination inbox. This does not configure an IMAP or SMTP connection to Voidmail. If mail is missing, check the registered inbox and spam folder, webmail, the alias spelling and any bounce received by the sender.

External secure linksDelivery and decryption still need verification

Webmail offers a secure-link route for recipients outside Voidmail. Its intended design encrypts the message in the browser with a fresh symmetric key and puts the key in the URL fragment, #key=…. A URL fragment is not part of an ordinary HTTP request.

The current sender, notification and reader flows have not been verified together. A “Sent” notice or a reader’s “decrypted” label alone is not proof the recipient received and decrypted the intended message. Do not rely on this route for essential or sensitive delivery until it is verified.

Anyone with a functioning full link can read its message. Do not send the full URL, key fragment or message content to support. Expiry or one-time access cannot revoke a copy someone already saved. If the page is blank, garbled, expired or reports an error, contact the sender through another trusted channel; a replacement link may be needed after the underlying issue is resolved.

Something went wrongFind the safest next step
Mailbox creation is pending or failed
Check account status and service status. Keep the error text and contact support. Do not assume a promised activation window.
Invalid keypair file
Use your own exported JSON file, not a configuration, password or public key alone. Do not paste its contents into a support message.
Encrypted message will not open
Check you are in the correct account and browser. Restore the matching keypair from backup; do not generate a replacement to recover old messages.
Recipient has no registered key
Ask the recipient to check their webmail identity setup. If registration still fails, contact support with the error, without keys.
Forwarded mail is missing
Check the registered inbox and spam folder, alias spelling, webmail and any sender bounce. A wallet-only account may have no external forwarding destination.
Secure link is missing or cannot be read
Use another trusted channel to reach the sender. Do not repeatedly open a one-time link to troubleshoot it, and do not treat a blank “decrypted” view as success.
Security & mail clientsWhat this setup does, and what it does not

Use webmail for browser-encrypted messages

Native IMAP/SMTP setup has not been verified. This guide provides no working-server promise for Apple Mail, Thunderbird or other clients. If older account screens show native-client credentials, check with support before relying on them. Your normal mail client can still read copies that successfully arrive at your registered forwarding inbox.

Protect the key, and the browser holding it

For the browser keypair flow, only the public key is submitted for registration. The private key stays in browser storage unless you export it. A backup contains that private key. Keep your device and browser secure, and never upload the backup to a public page or support ticket.

Encryption has a scope

Client-encrypted subject and body, externally received email and secure-link access are different cases. There is no blanket “the service cannot read any mail” claim here. Account identifiers, addressing and delivery metadata are not made anonymous by encryption or an alias. Older stored messages may use legacy formats.

A clear next step

Keep the key.
Send the error.

Tell support the device, time, action and error message. Leave out private keys, passwords, backup files, message content and full secure links.

Email support ↗Voidly on Telegram ↗

Use public channels only for non-sensitive questions.