Privacy & Protections
SingleSign Mail is built to protect you by default. Most mail services filter the bad stuff after it reaches you; SingleSign Mail is structured so most of it never gets near you — and what does get through is defused before you see it.
The Screener: strangers wait outside
The strongest protection is structural. Mail from anyone who has never written to you before waits in the Screener until you approve them — so a phisher's message doesn't just get flagged, it never reaches your inbox at all unless you let the sender in.
Link Guard: every link is checked before it opens
Links are where email attacks actually happen — the text says one thing, the destination is another. In SingleSign Mail, clicking any link in a message first opens a "Check this link" panel instead of the destination:
- The panel shows where the link really goes — the destination's domain, large and in lowercase so lookalike characters have nowhere to hide, plus the full address.
- If something is off, you get a clear warning — for example when the domain uses lookalike characters from another alphabet, or when the link's visible text doesn't match where it actually points.
- You choose: "Open link", "Cancel", or "Trust ⟨host⟩ & open" — trusting a site skips the check for that site next time (as long as nothing suspicious is detected).
You can review and remove trusted sites anytime under Settings → Security, in the trusted link hosts list — removing one brings the safety check back for its links.
Tracking pixels are flagged
Many senders embed an invisible one-pixel image that reports back when (and roughly where) you opened their message. SingleSign Mail detects these:
- In your message list, tracked messages carry a small eye icon ("Contains a tracking pixel").
- The message itself shows a banner: "This email contains tracking. The sender will know you opened it if you load remote images."
The tracker only works if the image loads — which brings us to the next protection.
Remote images ask first
By default, remote images stay blocked until you choose to load them. Nothing is fetched from the sender's servers — so tracking pixels stay blind — until you decide:
- "Load remote images" on a message loads them for that message only.
- "Always load" next to it turns on automatic loading for all mail.
- You can change your mind anytime in Settings → Security: choose "Ask before loading (recommended)" or "Always load images".
Inline images always display. Pictures embedded inside the message itself (like a photo someone attached inline) are part of the message, not remote content — they show normally and reveal nothing to the sender.
Sender authenticity is verified
Every incoming message is checked with the standard email authentication protocols — SPF, DKIM, and DMARC — to verify it really comes from where it claims to. Messages that fail these checks are treated with suspicion rather than delivered as if nothing were wrong, and messages that look like phishing or impersonation are clearly flagged.
Your phone gets protected copies
If you connect your phone's mail app, the same protections travel with your mail: only Screener-approved messages sync, tracking pixels are stripped, and links still go through Link Guard. See SingleSign Mail on Your Phone.
Sending limits protect deliverability
Limits on outbound mail keep SingleSign Mail a bad place to run spam from — which keeps your legitimate mail landing in inboxes instead of spam folders:
- From the web app: up to 30 messages per hour, 50 recipients per message, and 200 recipients per day (tighter during a mailbox's first week).
- From connected mail apps (IMAP/SMTP): up to 50 recipients per hour and 100 recipients per day.
- Repeated limit hits escalate: hitting the cap again and again brings temporary sending blocks that grow longer each time (from an hour up to a day).
- High bounce or spam rates pause sending. If an unusual number of your messages bounce, are blocked, or are reported as spam, sending is locked to protect the domain — and you'll be asked to verify via a link emailed to your account's outside email address before sending resumes.
None of this should ever be visible in normal personal use. If sending is paused, your drafts are safe and nothing is lost.
Last updated: 2026-09-02
Related articles
- Help CenterFind answers about using SingleSign to sign in, manage your privacy, and secure your account.
- The Screener, step by stepHow the Screener works — every first-time sender waits for your approval before anything they send can reach your inbox.
- Google Sign-In alternativeSingleSign vs Google Sign-In: the same one-tap convenience, without an advertising business behind the identity.
- more on Privacy PolicyHow SingleSign collects, uses, and protects your personal information.
- free identity providerSingleSign pricing in one line: sign-in is free, with no monthly-active-user meter. See exactly what is included, and what SingleSign Mail costs for businesses.
- Identity provider alternativesIdentity provider alternatives, by the provider you are leaving: what actually has to change in your code, and what does not.
- SingleSign vs Auth0SingleSign vs Auth0 compared on the difference that matters: who owns the account. A side-by-side table, then the three cases where each one is the right call.
- Okta comparisonSingleSign vs Okta: Okta is built for workforce identity inside a company, SingleSign for consumer sign-in across applications.
- Firebase Auth comparisonSingleSign vs Firebase Authentication on lock-in, portability and consent, plus the cases where staying on Firebase is right.
- Auth0 alternativesAuth0 alternatives compared, plus the part most listicles skip: what migrating off Auth0 actually involves, which code changes, and which does not.
- alternative to OktaOkta alternatives for teams that need customer sign-in rather than workforce identity. The table first, then what changes when you move consumer auth off Okta.
- alternative to Firebase AuthFirebase Authentication alternatives for teams leaving Google Cloud or wanting a standalone OIDC provider. Comparison table, then the real migration path.