A staged DNS connection
Verify ownership first, publish DKIM, SPF and DMARC, optionally publish WKD for compatible encrypted inbound mail, create every mailbox and address, then move MX when the domain is ready.
Connect a domain you own, create every recipient first, and let Thelemail operate the mail infrastructure.
Custom-domain email keeps your identity attached to a domain you control. Thelemail hosts the mailboxes and operates receiving, sending, spam classification, authentication and sender-reputation work. Unencrypted inbound mail is classified in memory and encrypted to the recipient key before storage.
Your administrator adds the domain, prepares every recipient and changes MX only when setup is complete. Household members and teammates use regular private inboxes after that.

The domain stays yours. Thelemail supplies the mailboxes, routing, privacy model and delivery infrastructure around it.
Verify ownership first, publish DKIM, SPF and DMARC, optionally publish WKD for compatible encrypted inbound mail, create every mailbox and address, then move MX when the domain is ready.
Thelemail runs receiving, queues, sending infrastructure, reputation controls, DNS checks and spam classification.
Mailbox content is encrypted for storage. OPAQUE lets the password unlock a wrapped random account key on the user device. Mail between Thelemail accounts is end-to-end encrypted.
Create private mailboxes, shared addresses and unlimited aliases on the same domain. A workspace anti-abuse guardrail applies. Route each address to the person or group responsible for it.
The connection flow delays the receiving change until every address and sending record is prepared.
Add the ownership TXT record while your current mail provider keeps receiving messages.
Publish the generated DKIM, SPF and DMARC records before any incoming-mail change. WKD is optional and lets compatible external senders discover your public key.
Add mailboxes, shared addresses and aliases so every active address has a destination.
Switch incoming mail after the recipients exist. The wizard keeps watching the records for drift.
Your domain stays with its registrar. Thelemail needs administrator access to the DNS records that verify ownership, authenticate sending and route incoming mail.
One administrator handles the connection wizard and DNS records. Other household members or teammates use their mailbox without touching the domain setup.
Addresses on a domain you own stay under your control. Export the mail in standard formats with the open-source export tool, choose another provider and change the domain MX records.
Read the export tool sourceStored mailbox content uses zero-access encryption at rest, and messages between Thelemail accounts are end-to-end encrypted. Outbound external mail uses WKD/OpenPGP when a compatible key exists and standard SMTP with TLS where supported otherwise. Optional WKD lets compatible external senders encrypt inbound mail to you. External subject headers remain visible; unencrypted inbound content is classified in memory and encrypted before storage.
Fay ce que vouldras. The only rule of the Abbey of Thélème. Rabelais, Gargantua, 1534.
The threat model spells out what is encrypted, what is not, and what a server compromise would and would not expose. The gaps we haven't closed yet are listed with it.