V1.0.0 // ZERO-KNOWLEDGE CORE
SYSTEM: OFFLINE
ZERO-KNOWLEDGE TERMINAL

[ZERO-KNOWLEDGE SMTP DIRECTIVE]

Secure, surveillance-free email, encrypted completely inside the browser. No password recovery. Hard 48-hour storage limits. Absolute cryptographic isolation.

[ SYSTEM CONFIGURATION LOGS ]
SEC-01 //

Browser Key Derivation

Your master passphrase is run through client-side PBKDF2 stretching with a unique salt. The resulting keys are kept in your browser's RAM, ensuring your decryption secrets never touch our server.

SEC-02 //

Hybrid Envelope Cryptography

Emails are secured with AES-256-GCM payloads. Ephemeral symmetric keys are wrapped client-side using RSA-4096. No backdoor, no administrative bypass, no corporate recovery key.

SEC-03 //

SMTP Encryption on Arrival

Plaintext emails from standard servers (e.g. Gmail) are intercepted at our SMTP server and immediately encrypted on-the-fly using your public RSA key. Stored only as ciphertext.

SEC-04 //

48-Hour Purge Mandate

To prevent target accumulation, all emails are hard-scheduled for permanent server-side deletion exactly 48 hours after they are read, backed by our server daemon.

[ ACCESS CONTROL GATEWAY ]

SYSTEM PROTOCOL POLICY STATEMENT

0dMail operates a zero-knowledge architecture. Your password is used browser-side to encrypt your private keys. No password recovery, recovery email, or administration backdoor exists. If you lose this password, your account and all associated emails are lost forever. You assume 100% responsibility for your credentials.

Loading gateway challenge...

INBOX

Syncing secure vault...

COMPOSE TRANSMISSION

Encrypted Mode: Message will be encrypted client-side using RSA-4096 before sending. Only the target local account can decrypt it. The server operators cannot read it.

Loading Secure Payload...

EPHEMERAL POLICIES
[ SECURE PAYLOAD LOGS ]
Decrypting block cipher...

DECRYPT EXTERNAL FILE

LOCAL DECRYPTION ENGINE

Upload a raw encrypted email file (JSON format downloaded via "Export Cipher"). The browser will attempt to decrypt it client-side using your active private keys in RAM. The server will not see the decrypted content until you choose to temporarily import it to your vault.

[ DECRYPTED OUTPUT PREVIEW ]
Select a file to parse...