Skip to content

Privacy & Protections

SingleSign Mail is built to protect you by default. Most mail services filter the bad stuff after it reaches you; SingleSign Mail is structured so most of it never gets near you — and what does get through is defused before you see it.

The Screener: strangers wait outside

The strongest protection is structural. Mail from anyone who has never written to you before waits in the Screener until you approve them — so a phisher's message doesn't just get flagged, it never reaches your inbox at all unless you let the sender in.

Links are where email attacks actually happen — the text says one thing, the destination is another. In SingleSign Mail, clicking any link in a message first opens a "Check this link" panel instead of the destination:

  • The panel shows where the link really goes — the destination's domain, large and in lowercase so lookalike characters have nowhere to hide, plus the full address.
  • If something is off, you get a clear warning — for example when the domain uses lookalike characters from another alphabet, or when the link's visible text doesn't match where it actually points.
  • You choose: "Open link", "Cancel", or "Trust ⟨host⟩ & open" — trusting a site skips the check for that site next time (as long as nothing suspicious is detected).

You can review and remove trusted sites anytime under Settings → Security, in the trusted link hosts list — removing one brings the safety check back for its links.

Tracking pixels are flagged

Many senders embed an invisible one-pixel image that reports back when (and roughly where) you opened their message. SingleSign Mail detects these:

  • In your message list, tracked messages carry a small eye icon ("Contains a tracking pixel").
  • The message itself shows a banner: "This email contains tracking. The sender will know you opened it if you load remote images."

The tracker only works if the image loads — which brings us to the next protection.

Remote images ask first

By default, remote images stay blocked until you choose to load them. Nothing is fetched from the sender's servers — so tracking pixels stay blind — until you decide:

  • "Load remote images" on a message loads them for that message only.
  • "Always load" next to it turns on automatic loading for all mail.
  • You can change your mind anytime in Settings → Security: choose "Ask before loading (recommended)" or "Always load images".

Inline images always display. Pictures embedded inside the message itself (like a photo someone attached inline) are part of the message, not remote content — they show normally and reveal nothing to the sender.

Sender authenticity is verified

Every incoming message is checked with the standard email authentication protocols — SPF, DKIM, and DMARC — to verify it really comes from where it claims to. Messages that fail these checks are treated with suspicion rather than delivered as if nothing were wrong, and messages that look like phishing or impersonation are clearly flagged.

Your phone gets protected copies

If you connect your phone's mail app, the same protections travel with your mail: only Screener-approved messages sync, tracking pixels are stripped, and links still go through Link Guard. See SingleSign Mail on Your Phone.

Sending limits protect deliverability

Limits on outbound mail keep SingleSign Mail a bad place to run spam from — which keeps your legitimate mail landing in inboxes instead of spam folders:

  • From the web app: up to 30 messages per hour, 50 recipients per message, and 200 recipients per day (tighter during a mailbox's first week).
  • From connected mail apps (IMAP/SMTP): up to 50 recipients per hour and 100 recipients per day.
  • Repeated limit hits escalate: hitting the cap again and again brings temporary sending blocks that grow longer each time (from an hour up to a day).
  • High bounce or spam rates pause sending. If an unusual number of your messages bounce, are blocked, or are reported as spam, sending is locked to protect the domain — and you'll be asked to verify via a link emailed to your account's outside email address before sending resumes.

None of this should ever be visible in normal personal use. If sending is paused, your drafts are safe and nothing is lost.

Last updated: 2026-09-02

Related articles