Registered keys.
Webmail encrypts the subject and body for a recipient with a registered @voidmail.ai key before sending.
Set up the identity ↗Voidmail / setup guide
Set up browser webmail. Keep the backup that lets you return.
Your account signs you in. Your matching key opens encrypted mail.
Know the route
Webmail encrypts the subject and body for a recipient with a registered @voidmail.ai key before sending.
Set up the identity ↗External mail reaches the email service in readable form. Forwarding and an encrypted webmail copy depend on your account setup.
Understand forwarding ↗The secure-link flow exists, but complete delivery and decryption are not verified. Use another trusted channel for essential messages.
Secure-link limits ↗Set up once. Keep the backup.
Your account, alias and browser encryption identity are separate. Work through each step in the real account and mail pages.
If the account form offers a master-password option, keep that password separately. It does not replace the browser keypair backup described below. If activation remains pending, contact support.
That loaded indicator confirms local keys are present. It does not confirm that public-key registration or delivery succeeded. If a sender sees “Recipient has no encryption key registered,” check the recipient account and contact support if setup does not resolve it.
For internal messages, both subject and body are encrypted in the sender’s browser using TweetNaCl: X25519 with XSalsa20-Poly1305 and fresh nonces. The recipient needs the matching private key. Addresses, timing and routing metadata are separate from encrypted content.
voidmail-keypair.json in a secure place you control, such as an encrypted drive or a password manager that supports file storage.If the new browser already has a different identity and no import prompt appears, do not erase either set of keys to force it. Export the current identity too and ask support for a safe recovery path.
The browser stores its active keypair in local storage. Clearing site data or losing the device can remove it. Without the matching backup or another device holding those keys, messages encrypted to that identity cannot be recovered by creating a new account password. Forwarded copies already in another inbox are separate.
An alias is a separate @voidmail.ai address that you can give to services or newsletters. It reduces exposure of the other address you use; it does not make you anonymous or hide network metadata.
Webmail’s Aliases view has its own mailbox controls. Deleting one there and regenerating the account alias are different actions. Check the exact address before changing it.
Mail from Gmail, Outlook and other external senders is received by the email service in readable form. The service attempts to forward it to your registered external email address and, when your public key is available, encrypt a copy for webmail storage. This is not end-to-end encryption from the external sender.
Forwarding depends on account settings, a usable registered email address and successful delivery. The inbound system also has recovery forwarding paths; do not assume a forwarding preference proves every failure path stays inside webmail.
You can read a successfully forwarded copy in the ordinary mail client for that destination inbox. This does not configure an IMAP or SMTP connection to Voidmail. If mail is missing, check the registered inbox and spam folder, webmail, the alias spelling and any bounce received by the sender.
Webmail offers a secure-link route for recipients outside Voidmail. Its intended design encrypts the message in the browser with a fresh symmetric key and puts the key in the URL fragment, #key=…. A URL fragment is not part of an ordinary HTTP request.
The current sender, notification and reader flows have not been verified together. A “Sent” notice or a reader’s “decrypted” label alone is not proof the recipient received and decrypted the intended message. Do not rely on this route for essential or sensitive delivery until it is verified.
Anyone with a functioning full link can read its message. Do not send the full URL, key fragment or message content to support. Expiry or one-time access cannot revoke a copy someone already saved. If the page is blank, garbled, expired or reports an error, contact the sender through another trusted channel; a replacement link may be needed after the underlying issue is resolved.
Native IMAP/SMTP setup has not been verified. This guide provides no working-server promise for Apple Mail, Thunderbird or other clients. If older account screens show native-client credentials, check with support before relying on them. Your normal mail client can still read copies that successfully arrive at your registered forwarding inbox.
For the browser keypair flow, only the public key is submitted for registration. The private key stays in browser storage unless you export it. A backup contains that private key. Keep your device and browser secure, and never upload the backup to a public page or support ticket.
Client-encrypted subject and body, externally received email and secure-link access are different cases. There is no blanket “the service cannot read any mail” claim here. Account identifiers, addressing and delivery metadata are not made anonymous by encryption or an alias. Older stored messages may use legacy formats.
A clear next step
Tell support the device, time, action and error message. Leave out private keys, passwords, backup files, message content and full secure links.