Skip to content

Your inbox is yours. We keep it that way.

Lettera needs access to your mailbox to send as you. This is exactly how that access is protected.

Six safeguards, working together.

Mail passwords, encrypted

Sealed with AES-256-GCM and a fresh random IV. Each secret is bound to your account, so it cannot be lifted into another one. The key lives in the server environment, never in the database.

Your password, hashed

Your Lettera password is hashed with Argon2id. It cannot be read back, by us or by anyone holding the database.

Sessions scripts cannot read

You stay signed in with an HTTP-only cookie. Resetting your password signs out every other session at once.

Previews that cannot run code

Email HTML is cleaned on the server before it is stored or sent, then shown in a sandboxed frame with scripts switched off.

Limits on guessing

Log-in, sign-up and password reset are rate limited, which slows down anyone trying passwords in bulk.

A record without the content

Sign-ins and sends are logged with their outcome and time. Passwords and message bodies are never written to that log.

Things Lettera never does.

Reply checks only look for messages that answer an email you sent through Lettera, and only when you ask.

  • Store your mail password in plain text
  • Show your mail password back to anyone, including you
  • Add tracking pixels to your emails
  • Search your inbox beyond replies to emails you sent with Lettera

Send with confidence, from your own address.

Start your free trial

2 months free. No card needed.