Journal logo

How To Secure Is That This Email Client

Secure Email Client

By nick rodasPublished 3 years ago 9 min read
Like

The firm’s base in Norway is usually considered to be good in terms of privacy (the nation doesn't have mandatory data retention laws that apply to email providers). However, it's worth noting that the state is a component of the greater Nine Eyes agreement, which suggests that government intelligence agencies are likely to be performing some surveillance and communicating with the likes of the NSA and GCHQ. In 2011 the firm was completely bought out by employees and therefore the remainder of the board.

How much does Runbox cost?

A subscription to Runbox are often purchased in Micro, Mini, Medium, or Max. The four subscription plans vary in cost but are all yearly subscription plans.

The Micro plan gives users access to 1 GB of email storage with an additional 100 Mb of file space for storing . Micro users don't get access to any custom domain names - these must be purchased as an add on. additionally , the micro account doesn't permit users to connect any existing custom domains they need (previously registered domains from other services) to their account. A Micro plan costs $19.95 per annum .

The Mini plan gives subscribers to five GB of storage and 500 Mb of file storage. Mini users are permitted to use five custom domains they need previously registered with another provider. However, if they need to register a replacement custom domain, they're going to need to purchase it as an add on. The mini-plan costs $34.95 per annum .

The Medium plan gives users access to 10 GB of email storage and 1 Gb of file storage. Users can use the account with up to 10 previously registered custom domains. However, if they need to register a replacement custom domain, they're going to need to purchase it as an add on. The medium plan costs $49.95 per annum .

The Max plan gives users access to 25 GB of email storage and a couple of GB of file storage. Users can use the account with up to 25 previously registered custom domains. like the opposite plans, they're going to got to pay to register a replacement custom domain. The Max plan costs $79.95 per annum .

Anybody eager to purchase extra email aliases (in packs of five), custom domains, or extra space for storing can do so at various bolt-on prices. This pricing structure is sort of complicated compared to other email services. However, it does give users tons of customizability - as long as they're willing to pay.

Users can elect to buy Runbox via credit or open-end credit , PayPal, or Bitcoin for added privacy.

Runbox Features

Based in Norway. Which is usually thought to be an honest location in terms of privacy compared to several EU locations, the UK, and therefore the US

  1. 100 aliases included with every account (for one user’s inbox)
  2. Spam detection
  3. POP and IMAP and SMTPS supported for sending and receiving emails across various clients.
  4. Data storage included
  5. Synchronize with Apple Mail, Mozilla Thunderbird, and Microsoft Outlook.
  6. Drag and drop attachments
  7. Custom domain support
  8. A+ score for security with Qualys SSL Labs

Privacy

The Runbox Terms of Service requires users to register using their real name. Thus, this email provider should be considered private but not anonymous.

Despite this, users can theoretically use a burner email address to subscribe. From that moment on, it's possible to form support requests from within the Runbox account -meaning that you simply don’t necessarily need to hold on thereto burner address, either.

We checked the Runbox privacy policy to ascertain what quite data the firm collects about its users. the great news is that the policy is GDPR compliant. additionally , Runbox doesn't state that it collects user IP addresses, and claims that none of the info collected while using the service is defined as sensitive.

The information provided by subscribers at the time of signing up to the service is retained for the amount that it's necessary to supply the service. However, anybody that pays for a subscription should remember that their data is additionally held for five years after the top of a subscription to suits Norwegian bookkeeping laws.

Email service content (data related to the webmail, Contacts, and Files within the Service) is stored for the duration of an account being held, and for up to three months after the closure of an attempt account or up to six months after the closure of a paid subscription.

Overall, the privacy policy seems strong, and there's no reason we could see to question their dedication to consumer privacy.

Security

All communications with Runbox servers are handled with TLS/SSL encryption. This ensures that data is usually secure in transit between the sender and Runbox’s servers and between Runbox’s servers and therefore the recipient. The service gets a score of A+ with Qualys SSL Labs, meaning that connections to its servers are indeed secure. (SHA256 with RSA 4096 bits.)

Unfortunately, there's no built-in end-to-end encryption within the Runbox webmail interface. For this reason, you'll got to install a third-party extension like Mailvelope to encrypt emails with PGP. this is often slightly trickier than with another providers but will get the work done.

Users even have the choice to encrypt emails using S/MIME as long as they use their Runbox account with a 3rd party standalone email client like Mozilla Thunderbird, Apple Mail, or Microsoft Outlook.

The good news is that Runbox is getting to introduce native PGP encryption to its Runbox 7 client (currently in Beta). So watch this space.

Anybody that does use the webmail interface instead of a stand-alone client must remember that because encryption occurs within their browser (using Mailvelope) - there are some security issues in touch in mind (which apply to all or any JavaScript mail clients and not just Mailfence).

Javascript has vulnerabilities which will permit a man-in-the-middle attack to force compromised encryption keys onto both the sender and recipient’s browsers. Anybody who wants to avoid these JavaScript vulnerabilities will got to use an email provider with a fanatical email client.

One thing worth bearing in mind is that Runbox doesn't currently implement encryption for emails that are at rest on its servers, this might concern any user that doesn't implement strong E2EE using S/MIME or PGP.

Finally, Runbox implements IP stripping from all sent messages. this suggests that your IP address isn't attached to an outgoing email.

Ease of Use

Signing up for a free trial of Runbox is straightforward , but does require you to supply an alternate email address that you simply already own. this is often slightly frustrating for those people that value privacy and don’t want to link their new account to a previous one. While the firm does prefer customers handy over a telephone number , thankfully this is often optional - which is one grace .

Having subscribed, you'll receive a validation email within the inbox that you simply provided. Click on the link therein email to urge started. The link takes you, fully logged in, to the online client where you're able to start taking advantage of the secure email service.

Setting up folders is good and straightforward because of the shape that appears just underneath the directory of inboxes. I went ahead and set a folder up just to ascertain how it works. you'll see the results below.

To import contacts from Google or the other email provider, you merely click on Contacts within the top left of the online mail client then click on import. The feature allows you to import contacts via CSV, which suggests you'll import them from Google Mail or simply about the other email provider. We found the feature to figure without a hitch.

With imports contacted you're able to start sending emails. Clicking on compose opens a separate window, and that we were shocked to seek out that there have been no options for OpenPGP encryption. In fact, initially glance, we could see no options for encrypting emails at all; this confused us because we were under the impression that this was a secure email provider.

We contacted support to urge clear confirmation about now and were informed that Runbox stores all emails on secure servers but doesn't provide any PGP functionality or password encrypted email options.

What’s more, feature-wise Runbox is extremely thin on the ground: it provides email storage and file storage (for uploading documents onto its equivalent of Google Drive) - but no extras like spreadsheets, webchat - and every one those other goodies you discover with numerous other encrypted email providers. However, it's worth noting that the firm does appear to be expanding its feature set (it has already added a calendar to the Runbox 7 beta, for instance ).

All in all, we were a touch disappointed with what's on offer considering the value of even a micro account (other email providers exist that are just 1 Euro a month - and supply more features baked in).

However, to be fair, Runbox is extremely easy to use. And, if you don’t actually want to send encrypted emails - and are just trying to find secure email storage (that isn't being scanned by Google for advertising purposes, which is stored safely to guard it from hacking) - this email provider could be an option for you.

Customer Support

Where customer support cares Runbox may be a bit of a slog. Users must begin the method by sending an email from their account. thereupon done an automatic response will arrive. However, so as to truly open a support ticket, it's necessary to reply thereto initial auto-response to say that you simply haven't been ready to find the answer within the help section of its website. thereupon done, another automated response arrives and following that the particular help.

Overall, the system does work - and that we did get a response within an hour - which isn’t terrible. However, for folks that are forking out for a Max account, i think a live chat feature would be welcomed, and considering what they're charging; probably need to be an available resource.

With that said, both the assistance and blog sections of the web site are useful and can provide users with answers to several commonly asked questions. We found the assistance center easy to use, and that we particularly enjoyed the way that the highest nav bar is split into tabs: Search, How-tos, FAQs, Documentation, and Support.

This allows you to quickly hone in on what you're trying to find - whether it's information about the service, or specific setup guides for IMAP, POP, or fixing aliases, for example.

Runbox email conclusion

Runbox is an email provider that's extremely easy to urge wont to . However, if you would like something that comes with PGP encryption right out of the box - you would possibly be more happy looking elsewhere.

For those people that prefer using their email account with Outlook, Thunderbird, Apple Mail, or another third-party client; the supply of both PGP encryption and S/MIME means you'll be ready to use this email provider to send secure E2EE on your emails.

One thing worth bearing in mind is that because it stands the webmail client isn't open source. this might put diehard privacy and security advocates off the service. However, Runbox 7 which is currently in Beta, goes to possess PGP baked and it's claimed that it'll be open source.

An easy-to-use provider with useful browser-based webmail - as long as you don’t mind following guides to urge PGP encryption up and running with Mail elope or a separate standalone client.

With all that said, Runbox is pricier than a number of its competitors, and, many of these providers accompany tons more features baked in. So, counting on your needs, you'll be more happy looking around for something else.

product review
Like

About the Creator

Reader insights

Be the first to share your insights about this piece.

How does it work?

Add your insights

Comments

There are no comments for this story

Be the first to respond and start the conversation.

Sign in to comment

    Find us on social media

    Miscellaneous links

    • Explore
    • Contact
    • Privacy Policy
    • Terms of Use
    • Support

    © 2024 Creatd, Inc. All Rights Reserved.