EMXby Elchi Studios

Security and data location

Where your mail is, and who can read it.

EMX runs on servers we rent from providers in Switzerland and the EU. Here is what is where, what is encrypted, and the exceptions, by name.

The path of an email

Where an email arrives, where it is kept, who can read it and how it leaves.

The path of an email at EMXAn email comes from a sender on the internet to mx.emxmail.ch, where SPF, DKIM and DMARC are checked and the spam filter runs. Messages and attachments are stored encrypted in Geneva, sealed if you want; the database is in Frankfurt, with copies in Nuremberg and Paris. Mail is read in the web client and the app with sign-in through EAuth, in Outlook, Apple Mail and on the phone over IMAP with an app password, and by your software through the API with a token. Our own servers deliver outgoing mail, signed with DKIM, to recipients on the internet.StoredGenevamessages and attachments,stored encryptedsealed, if you wantFrankfurtdatabaseNurembergcopyPariscopyReceivedSenderanywhere on the internetmx.emxmail.chchecks SPF, DKIM, DMARCspam filterReadWeb client and appsign-in with EAuthOutlook, Apple Mail, phoneIMAP, app passwordYour softwareAPI with a tokenSentOur servers deliversigned with DKIMRecipientanywhere on the internetThe path of an email at EMXAn email comes from a sender on the internet to mx.emxmail.ch, where SPF, DKIM and DMARC are checked and the spam filter runs. Messages and attachments are stored encrypted in Geneva, sealed if you want; the database is in Frankfurt, with copies in Nuremberg and Paris. Mail is read in the web client and the app with sign-in through EAuth, in Outlook, Apple Mail and on the phone over IMAP with an app password, and by your software through the API with a token. Our own servers deliver outgoing mail, signed with DKIM, to recipients on the internet.StoredGenevamessages and attachments,stored encryptedsealed, if you wantFrankfurtdatabaseNurembergcopyPariscopyReceivedSenderanywhere on the internetmx.emxmail.chchecks SPF, DKIM, DMARCspam filterReadWeb client and appsign-in with EAuthOutlook, Apple Mail, phoneIMAP, app passwordYour softwareAPI with a tokenSentOur servers deliversigned with DKIMRecipientanywhere on the internet

What is where

Messages and attachmentsGeneva, Switzerland, stored encrypted
Database (mailboxes, folders, settings)Frankfurt, Germany; copies in Nuremberg and Paris
Outgoing mailour own servers, unless you choose your own Resend account
Payment on TeamStripe; EMX stores no card data
Block lists for the spam filterqueries to Spamhaus, United Kingdom, with the address of the sending server

Every sub-processor with its location and task is in Annex A of the EMX terms. EMX terms

How EMX protects your mail

Stored encrypted

Every message is encrypted in storage; the keys are not with the storage provider.

Sealed mailboxes

Where allowed, EMX encrypts messages, subject, sender and recipients included, to a key the person's passkey unlocks. Then we cannot read them either.

Passkey sign-in

Through EAuth with a passkey or a password and a second factor. Mail apps get app passwords of their own, revoked one by one.

Encrypted on the way

TLS to browsers and mail apps, MTA-STS for your domain, and DKIM signatures on every outgoing message.

Senders checked

SPF, DKIM and DMARC on every incoming message; forgeries of your own domain stand out.

Keeping little

Full IP addresses in logs for 90 days only, then the network alone.

What we do not claim

A mailbox at your own domain, today.

Private is free and starts at once. Switch to Team when more people join.