DMCN is private and trustworthy because of how it’s built — not because we ask you to take our word for it. Here’s exactly how your mail is protected, and where the limits are.
Between DMCN inboxes, your mail is locked on your device and opened only by the person you send it to. We only ever handle the encrypted version.
We never store the keys to your mail — not even encrypted copies. There’s nothing on our servers that could be used to read it.
Between DMCN inboxes the network verifies who sent a message before it is accepted, and your client re-checks that sender against the public directory. If the two disagree you are warned and the message stays sealed.
Mail to and from regular email is secured in transit. Like all standard email, it isn’t end-to-end encrypted once it leaves the DMCN network — and we’re upfront about that.
We make money from subscriptions, not from your data. Nothing is scanned, profiled, or sold — ever.
Our security claims are meant to be checked, not taken on faith. The DMCNP protocol spec and an Apache-2.0 reference implementation are published in full, so anyone can read the wire format, audit it, or run their own server.
Your message is encrypted before it ever leaves your device, using keys only you hold.
It travels as a sealed, unreadable packet — relayed by the network, never opened by it.
Only your recipient can unlock it. Between DMCN inboxes, no one in the middle can read a word.
Mail to and from regular email. It is decrypted at the bridge and protected in transit (TLS), like all standard email — so it is not end-to-end encrypted the way DMCN-to-DMCN mail is. End-to-end encryption applies between DMCN inboxes.
Delivery metadata. A relay carries your mail sealed, but it does see who a message is from and which mailbox it is for. Stronger protection for that delivery metadata — onion-routed transport — is built but not yet switched on by default. It is on the roadmap, and we will say so here when it changes.
Adding a new device. This is the one moment key material crosses the network. Your keys travel sealed to that device alone, you confirm a matching code on both screens, and the copy is deleted the moment it arrives. It is a short window, and we would rather name it than leave it out.
Security is a process, not a promise. If you believe you’ve found a vulnerability, tell us privately and we’ll work with you to fix it quickly — and credit you if you’d like.