DRIVUNO Mail

Forward your mail to an inbox that cannot read it.

Every inbound message is encrypted to your key at ingestion. The stored archive is ciphertext — searchable by you, unreadable by us.

The last hop of your mail should be the one that stops reading.

For anyone consolidating several addresses, and professionals who want signup mail kept away from the address their clients use.

Built for confidentiality

Sealed at ingestion

Subjects, bodies, HTML formatting and attachments are encrypted to your public key the moment the message arrives.

Search your archive privately

Blind-index tags for senders, subjects and words are computed on your device; matching happens on opaque tags.

Per-purpose addresses

Create separate addresses for signups, clients and public forms, each with its own display name and signature.

Domain separation

Keep high-exposure signup mail on a public-facing domain so your professional address keeps a clean reputation.

Attachments into your vault

Open attachments in a local viewer and save them straight into your encrypted drive in one click.

Your archive, exportable

Export in the clear from your own device at any time. Zero-knowledge should never mean lock-in.

What forwarding actually does

A forwarded message is delivered to one server and re-sent to another; each hop holds a readable copy while it processes the mail. Forwarding adds a reader — so what matters is where the chain ends.

The honest boundary

Mail sent from a standard provider crosses the internet under transport encryption and arrives readable. No provider can change SMTP. What we can do is seal it before storage, so the readable copy stops existing at ingestion.

Between DRIVUNO accounts

Messages exchanged inside the platform never leave the sealed model at all: encrypted by the sender, delivered as per-recipient key envelopes, with no readable intermediate copy.

Frequently asked questions

Does forwarding to DRIVUNO make the whole path encrypted?

+

No, and any provider claiming otherwise is overselling. The path uses transport encryption; what changes is that the final stored archive is sealed to a key only you hold.

Should I use a catch-all address?

+

Usually not. A catch-all turns every guessed alias into a valid target, which is how address harvesting starts. Per-purpose addresses can be retired individually.

Can spam on my public address damage my professional one?

+

That is exactly why the two live on separate domains. Volume, complaints and reputation issues stay on the public-facing side.

Can DRIVUNO read this content?

+

No. Everything is encrypted on your device with XChaCha20-Poly1305, using keys derived locally from your password with Argon2id and wrapped per member with X25519. Servers store ciphertext and sealed key envelopes only.

Is there a free plan?

+

Yes. The free plan includes 1 GB with exactly the same zero-knowledge architecture as paid plans.

What happens if I lose my password?

+

Because we cannot read your data, we cannot reset it for you. Create a Recovery Kit — a printable PDF with a QR code — and store it offline. That is the same property that stops anyone else from reading your account.

Related

Your sensitive files deserve more than a traditional cloud.

Start free with 1 GB. Zero-knowledge encryption from the first upload — no admin override, no AI scanning, no plaintext on the server.

1 GBfree vault
Encrypted on your device · upload in 1 click
Upload