Hello, Thelemail
Thelemail is private email hosting for people who want control of their address and a managed mail service. It is built around a simple division of responsibility: you own the domain and decide who gets each address; Thelemail operates delivery, receiving, abuse controls, spam classification and the DNS checks that keep mail working.
You can start with a free mailbox for yourself or bring your family together without a domain. If you have your own domain, one person handles its setup while everyone else signs in to a separate private inbox.
Why build another email host
Owning a domain gives an email address continuity. A household can keep the same addresses when a provider changes. A small company can move its mail while customers continue writing to the same place. That control is valuable, but operating a dependable mail server is an ongoing responsibility.
Sending reputation, blocklists, bounce handling, spam filtering, queues, backups, DNS authentication and abuse response continue long after the first successful message. Thelemail handles that operational work while keeping the domain portable.
The privacy model matters just as much. OPAQUE unlocks a wrapped account key on the user’s device without sending the password to Thelemail, and stored mailbox content remains ciphertext to the service. Mail between Thelemail accounts is end-to-end encrypted. For outbound external mail, the web client discovers compatible recipient keys through WKD and encrypts with OpenPGP. Thelemail publishes user keys through WKD so compatible outside senders can encrypt inbound mail. Without a usable key, external mail uses standard SMTP with TLS where supported. Envelope metadata still has to remain visible for routing. These boundaries are documented on the security and threat model page.
One administrator, separate members
A household administrator can connect a family domain, create a private mailbox for every member and route shared addresses such as bills@ or school@ to the people who handle them. Members keep separate passwords and inboxes.
A founder can do the same for a small team. Individual mailboxes belong to individual people. Role addresses such as hello@, invoices@ or support@ can reach selected members without a shared password. When someone joins or leaves, the administrator changes the routing and mailbox access from one place.
Paid plans include unlimited aliases, subject to a workspace anti-abuse guardrail. The personal Free plan has no aliases. Free Family includes one shared @thelemail.com alias. They can separate services, identities and responsibilities without consuming another mailbox for every address. The email aliases guide explains the difference between an alias, a mailbox and a shared address.
A domain is the main path
Custom-domain email is the clearest expression of Thelemail because the address remains yours. Setup is staged: verify ownership, prepare sending records, create every recipient, import existing messages and change MX when the domain is ready. The current provider continues receiving mail until that final cutover. The domain setup guide shows the sequence.
A domain is optional for an individual account. People who do not own one can start with an @thelemail.com address and connect a domain later. Free Family supports up to six @thelemail.com accounts without a custom domain. Paid Family and Business member mailboxes use a connected custom domain.
What is published
The production browser client, key transparency log and local export tool are published under AGPL-3.0. The public browser client is the code that creates keys, encrypts messages and decrypts stored mail. The transparency log records the public keys the directory serves. The export tool authenticates with OPAQUE and decrypts mailbox data into standard formats on the user’s computer. The open-source macOS desktop client keeps cryptographic operations in its Rust core and supports encrypted offline mail and search. Mobile client source remains private. The transparency log’s current witness and enforcement status is documented openly.
You can inspect the published source and deployment path, the key transparency status, and the precise encryption boundaries. Thelemail has not completed an independent security audit or formal compliance certification, so it does not claim either.
What you’ll see on this blog
- Practical guides for hosting family or small-team email on a custom domain.
- Migration notes covering MX cutovers, imports, exports, SPF, DKIM and DMARC.
- Plain-language explanations of zero-access storage, end-to-end encryption and email metadata.
- Product and engineering updates, also collected in the changelog.
The goal is to make the administrator’s work understandable before signup. Start with how Thelemail hosts a custom domain, compare plans and capacity, or read the complete threat model.