Great answers

…to all your questions. Please also check our How-to to learn everything you need to know about Tutanota.

Table of contents

General questions

Apakah Tutanota gratis?

Ya, klien [Tutanota webmail] (https://app.tutanota.com/#register) selamanya gratis dengan penyimpanan 1 GB gratis untuk pengguna pribadi.

Apa maksud nama "Tutanota"?

Tutanota berasal dari bahasa Latin dan berisi kata-kata "tuta" dan "nota" yang berarti "pesan aman".

Is Tutanota open source?

Yes, all Tutanota clients are published as open source under GPLv3. Check out our GitHub repository. We welcome you to review the code, to give us feedback or to contribute!

Is Tutanota certified?

Tutanota was subject to an extensive penetration test by the SySS GmbH in November 2013. During the tests the experts were not able to access the system or to retrieve any confidential data.

Can I use Tutanota for my business?

Yes, Tutanota offers a whitelabel version for businesses, which includes customizations of the logo and design. You can also place the login for your employees directly on a subdomain of your website.

Learn here how to whitelabel Tutanota for your business.

I can't access my account. What can I do?
password lost login

If you can't access your account, this has been caused by one of the following reasons:

  • You forgot your password or lost your second factor: Please read the howto entry on How do I reset my password or second factor?.
  • Your account got suspended due to unpaid invoices: Your account may be suspended if you don't pay your open bills for a long time. Just contact us if you want to continue using your account and include the email address of your suspended Tutanota account.
  • Your account was disabled due to another reason: Some accounts get disabled due to a violation of our Terms of Service. You can contact us if you think that we made a mistake. Please include the email address of your suspended Tutanota account.

Your Tutanota Password

Tutanota secures my private key with my password. Can you access my password?
recovery reset password

No. When a password is used for authentication (login), it is not necessary that it is known to the server you want to authenticate with. The server only needs a fingerprint (hash) of your password. With Tutanota your hash for authentication is calculated by your browser and only the hash is being sent. Your password never travels the Internet in plain text and it is never seen by our server. As hashes are non-invertible, the server is unable to reconstruct your password from the hash. The server is not able to decrypt your message, but still able to log you in.

Recommended for further reading: Learn how Tutanota automates the encryption process while leaving you in full control of your encrypted data.

What hashing function is used for the password?

Your password is salted and hashed with Bcrypt on your device before being transmitted to Tutanota. Bcrypt is the most reliable method because brute-force attacks need much more time in comparison to conventional methods such as MD5 or SHA. With this method we guarantee an integrated confidentiality and we allow you to access and decrypt your emails from desktops and mobile devices instantly.

How do I choose a strong password?

Tutanota uses a password strength indicator that takes several aspects of a password into consideration to make it secure. You can find additional tips on how to choose a strong password here.

Tutanota has no limitations in regard to the password length or used characters; all unicode characters are respected.

Does Tutanota support two-factor authentication (2FA)?

Yes, Tutanota supports two-factor authentication with U2F and TOTP. Here are details on how to set up your second factor in Tutanota.

Please note: U2F is currently not working in Firefox.

Security and Privacy

Where does the encryption process take place?

Enkripsi dan dekripsi data selalu terjadi secara lokal pada perangkat Anda saat login. Semua data dienkripsi ujung-ke-ujung dan hanya Anda yang dapat mengakses data dengan kata sandi Anda.

What is encrypted and what can you read?
encryption

Kami mengenkripsi semua data Anda (kontak, surel). Kami mengenkripsi subjek, isi, dan lampiran.

Kita hanya bisa membaca (metadata):

  • pengirim
  • penerima
  • tanggal surel tersebut

Kami mencoba menyembunyikan metadata di masa mendatang.

Where are my keys generated and how is my private key secured?

Your private and your public keys are generated locally within your browser upon registration. Your private key is encrypted with your password. This way your login password receives the status of the private key. The key is encrypted so strong that only you can use the key for encrypting and decrypting data. This is why a strong password is essential. An automatic password check on the client makes sure that you use a strong password. Your password is never transmitted to the server in plain text. It is salted and then hashed with bcrypt locally on your device so that neither the server nor we have access to your password. With this innovative design you can access your encrypted inbox from any device (desktop, mobile) easily.

Algoritma enkripsi apa yang digunakan Tutanota?

For the email encryption between users, Tutanota uses a standardized, hybrid method consisting of a symmetrical and an asymmetrical algorithm. Tutanota uses AES with a length of 128 bit and RSA with 2048 bit. Emails to external recipients are encrypted symmetrically with AES 128 bit.

Bagaimana email saya terenkripsi dengan Tutanota?

The system automatically encrypts all emails stored in Tutanota. Emails between Tutanota users are automatically encrypted end-to-end, emails to external users can be secured with the help of a password. Here we explain the differences between a confidential (end-to-end encrypted) and a non-confidential email.

Independent of the end-to-end encryption, the transport between client and Tutanota servers is secured with SSL and DANE to maximize security.

Where are the Tutanota servers located?

The Tutanota servers are located in secure data centers in Germany. All saved data are subject to the strict German privacy protection laws. Independent of that all data is end-to-end encrypted and cannot be read by the Tutao GmbH as the provider or by any third party.

### Dapatkah saya menggunakan Tutanota secara anonim?

We do not log IP addresses when you login or when you send an email. The IP addresses of sent and received emails are also stripped so that your location remains unknown.

Learn on our blog how Tutanota makes sure to provide an anonymous email service. Upon registration you do not need to provide any personal data (e.g. no phone number required). We will also make it possible to pay for Premium and Pro with Bitcoin.

Is my address book within Tutanota encrypted?

Yes, all data within Tutanota is end-to-end encrypted and only accessible with your password. Scanning and profiling of your data is not possible.

Mencatat: Apa yang Tutanota catat dan berapa lama catatan disimpan?

In an error case, Tutanota clients display an error message and provide a function to send the error details to our support. These error details never contain any personal data and are used by our support for tracking down the error that occurred on a client.

We also log technical info, warning and error messages on the server side. These messages never contain any personal data and are also used for improving Tutanota. These logs are kept for 14 days.

Can I disable sessions remotely (session handling)?
ip address log logging security

Yes. You can view and remotely close active sessions under Settings -> Login.

Check our How-to to learn how to enable storing of closed sessions to monitor whether someone else has access to your account. To guarantee the users' privacy, we have implemented the feature as follows:

  • The IP address is stored encrypted, and only the user can decrypt this information. No one else - not even we at Tutanota - can access this information.
  • IP addresses are only stored for one week and then automatically deleted.
Do you delete inactive accounts / recycle email addresses?

Free of charge accounts are deleted if they were not used for at least six months. Your deleted email address (also if it is an alias) will not be recycled for security reasons. There must be no possibility that someone else is able to register your previously used email address, and then, by accident, receive a confidential email that was meant for you.

App, client, instructions

Bagaimana cara menggunakan Tutanota?
How to How-to settings instructions help support

Tutanota is very easy to use. From the start we focused on usability and kept the encryption process in the background. You do not have to install anything or worry about key handling. Tutanota is as easy to use as Gmail or any other webmail service.

You can start with Tutanota right away. If any questions remain, check our detailed how-to.

This describes all Settings of Tutanota. It also answers common usability questions such as:

How to send an encrypted email?
How to switch to not confidential?
How are contacts sorted?
How to add / rename / delete a folder?
How to use multi-select and shortcuts?
How to upgrade to Premium?
How to set up an alias?
How to send an email from an alias?
How to manage passwords for my Premium users?
How to send emails with my own domain?
How to add an encrypted contact form to my website?

Dimana saya bisa mendapatkan aplikasi Tutanota?

You can download the Tutanota app from the following stores:

In addition to that, you can also directly download and install the APK for Android. Keep in mind that you will not get updates automatically if you install the app manually instead of using an app store. You can add our blog to your RSS-reader with this link to get notified about updates: {rssFeedLinkText}

Push notifications on my Android phone are being delayed. What can I do?

Please check the app settings on your phone. As we do not use Google's push notifications service, battery optimization must be disabled for Tutanota to receive push notifications instantly.

This is necessary to offer you an open source email service free from any links to Google.

Is it possible to merge several Tutanota email addresses in one account?

Yes, you can add existing email addresses (e.g. Alice2, Alice3) as aliases to a Premium account (Alice1). Before you can add the aliases, you need to delete the other accounts (Alice2, Alice3) and specify the Premium account (Alice1) as the take over account upon deletion. We explain here how to take over the email addresses.

Please note: You are only transferring the email addresses. Emails and contacts stored in the deleted accounts (Alice2, Alice3) are being deleted. Please export important emails before deleting the accounts.

Is there a dark theme in Tutanota?

Yes. Before logging in, click on 'More' and 'Switch color theme' to switch to the dark theme. This works in all Tutanota clients (web, desktop, apps).

Mengapa Tutanota tidak menggunakan pgp?

Current encryption standards like pgp and S/MIME have several issue that we plan to address with Tutanota. These standards do not support forward secrecy and are not resistant to attacks from quantum computers.

In addition, it is important to us that the subject line in emails is also encrypted. That's why we have developed a solution that is also based on recognized algorithms (RSA and AES) and that automatically encrypts the subject, the content and the attachments. In the future, we plan to upgrade these algorithms to quantum-resistant ones that also support forward secrecy. You can find more information on Tutanota's encryption design on our blog.

We also see the importance that Tutanota needs to be interoperable with other encryption solutions. We will develop an API so that Tutanota users can communicate with users of other secure services confidentially in the future.

Browser mana yang didukung oleh Tutanota?

Tutanota supports the current version of the following browsers:

  • Firefox (desktop)
  • Opera (desktop, Android)
  • Chrome (desktop, Android)
  • Safari from version 11.0 (desktop, iOS)
  • Microsoft Edge (desktop)

    Tutanota also works in Internet Explorer 11, but this browser is not officially supported.

Perkembangan terus berlanjut. Apa selanjutnya?
roadmap

Please have a look here and here.

What is the maximum size for emails and attachments?

The size of emails with attachments sent via Tutanota is limited to 25 MB at the moment.

Dapatkah saya mengambil email Tutanota saya melalui IMAP ke klien surel yang lainnya?
gmail outlook yahoo thunderbird redirect

Ini tidak mungkin karena kami tidak dapat menjamin enkripsi ujung-ke-ujung untuk data Anda.

As an external recipient, can I re-access my emails later?

Yes, you can always access the emails sent via Tutanota through the link from your latest notification email. Old notification links from the same sender are de-activated for security reasons. Your exchanged password, however, stays unchanged as long as the sender does not change it. If you have saved the password upon accessing your confidential emails in your browser, you do not have to re-enter it.

Are emails to other Tutanota users always encrypted?

Yes, when sending emails from Tutanota to Tutanota, all emails are encrypted automatically end-to-end on your device. You do not have to enter any passwords.

Bagaimana cara saya mengirim email terenkripsi ke penerima eksternal?

Yes. Tutanota uses a preshared password for sending an encrypted message to an external recipient, to someone who does not use Tutanota. Please check our how-to to learn how to send encrypted emails to external recipients.

Can I add alias email addresses to Tutanota?

Email aliases are additional email addresses that you can use with the same mailbox without having to switch accounts. Aliases are a Premium feature. If you upgrade to Premium (€1 per month), you can add up to 5 aliases.

Find out more about Tutanota aliases in our How-to.

Can I use a custom (own) domain with Tutanota?

Yes, Tutanota Premium and Pro come with custom domain support. Once upgraded, you can add as many domains as you like.

Please refer to our how-to to learn how to add your own domains to your Tutanota account, how to activate/deactive catch-all and more.

Does Tutanota use a spam filter?
false spam block legit newsletter

Yes, Tutanota uses a spam filter to keep your mailbox free from spam. We are improving this filter continuously. Should you receive spam emails in your inbox, you can also configure your own spam rules here.

In paid accounts, only admins can create spam rules that are being applied across all users.

Are there email limits to protect Tutanota from being abused by spammers?

Yes, Tutanota uses different variables to calculate email limits for individual accounts. This is necessary to protect our free and anonymous email service from spammers who try to abuse Tutanota. If spammers were able to abuse Tutanota, it would harm all Tutanota users - ie Tutanota domains could end up on email blacklists, which we have to prevent under all circumstances.

If you receive the following message in your Tutanota account "It looks like you exceeded the number of allowed emails. Please try again later.", the anti-spam protection method has stopped your account temporarily from sending new emails. Please wait a day or two to send new emails again.

If you need to send more emails immediately, please upgrade to our affordable Premium version (1 Euro per month) as limits for Premium users are much higher. Simply click on 'Premium' in your top menu bar of Tutanota.

Please note that Tutanota is not meant for sending out mass mailings such as newsletters. Please read our Terms & Conditions for details

Other

If I upgrade to Premium, can I downgrade to free again?
Premium Free subscribe unsubscribe

Yes, you can downgrade back to free anytime. Before this, you need to disable all extra bookings (aliases, storage, additional users). You can keep your main Tutanota email address as a free account.

Check here how you can upgrade and downgrade.

My newly created account has been put on hold for 48 hours. What should I do?

Some accounts are automatically marked for approval to prevent abuse and to enable you to sign up for a 100% anonymous email service.

During these 48 hours emails cannot be sent or received. Please do not share your new email address before the blocking has been lifted.

I have received an abusive email (spam, phishing) from one of your domains. How do I report abuse?
fraud stalker threat abuse abusive phishing

If you would like to inform us about abusive usage of one of our domains (tutanota.com, tutanota.de, tutamail.com, tuta.io, keemail.me), please contact us at abuse@tutao.de. Please forward the abusive message to us if appropiate.

If you would like to report abusive usage originating from another provider's email address, you can find contact addresses at abuse.net.

Special offers for non-profit organizations
for free non-profit NGO NPO

For non-profit organizations (NPOs) we have the following special offers:

  1. If you are located in Austria, Canada, France, Germany, Italy, Netherlands, or in Switzerland you can get Tutanota Premium as a donation in cooperation with our partners Stifter-helfen and tech-soup. Please find details on how non-profits can get Tutanota for free on our blog.
  2. Coming soon: If you are located in Poland, you can get Tutanota Premium as a donation in cooperation with our partner tech-soup.
  3. For all other countries we offer a discount of 50%. Get in touch with us directly.

Conditions:

  • If you make use of Tutanota Premium as a donation, our partners collects a small administration fee to cover their expenses for offering the software donations.
  • The free or discounted Tutanota Premium offer is limited to users. Additional upgrades, e.g. storage packages, have to be paid at the standard price.
  • Only up to 50 users are included in the donation. If you need more users, you cannot apply for the donations above. But of course you will get the 50% discount offered by us. Simply get in touch with us directly.