File 007 · Open Questions

Questions you actually have.

Straight answers, including the ones marketing departments usually soften. If yours isn't here, email a human: contact@adamanture.com.

Last updated: August 2026 · Written by humans, checked against the code.

§ 01 · Basics

The address, the mailbox, the apps, the name.

No — and that isn’t a feature we happen to have, it’s the whole shape of the product. Unlike Mail works with the address you already use: Google and Workspace, Microsoft and Office 365, Zoho, or any mailbox that speaks IMAP. Your contacts don’t change, your signature stays, your decade of archive stays. We add a vault inside the house you already live in; we don’t ask you to move.

Almost certainly. Google, Microsoft and Zoho sign in with one click, everywhere. Everything else — Fastmail, iCloud, mailbox.org, your company’s server, the mailbox that came with your domain, the one you run yourself — connects over IMAP from the Windows desktop app. Type your address and it works out the settings; it only asks for server details if your host is unusual. You’ll want an app password from your provider, which takes about thirty seconds.

The boundary, stated plainly: IMAP mailboxes connect through the desktop app, not the web app. Next question explains why, because the reason is the interesting part.

Because an IMAP login is a permanent password to your entire mailbox — not a token you can revoke from a settings page. A credential like that belongs on your machine. Accepting it in a browser would mean it passes through, or rests on, our servers, and then we would be holding the keys to your mail: the exact arrangement this product exists to avoid.

So the desktop app opens the connection itself. Our servers never learn your mail host, your port, or your password. It costs us a feature and an extra step at signup, and we’d rather explain that than quietly take the easy path.

Honestly, this is the wrong question to be asking us. If you’re on Proton or Tuta you already have end-to-end encryption, and you already paid for it with a new address. We exist for people who don’t want to pay that price. There’s no real reason to run us on top of what you’ve got.

For completeness: Proton can technically connect, through Proton Bridge, on a paid plan, from the desktop app — Bridge serves your mailbox locally and we treat it like any other IMAP server. Tuta can’t, at all: it offers no IMAP by design, so there’s nothing to connect to.

Yes. Unlike Mail adds a layer — it doesn’t replace anything. Your regular mail keeps working in Gmail, Outlook, your provider’s webmail, Thunderbird, Apple Mail, whatever you like. Sealing only kicks in between Unlike Mail users; everything else is exactly the email you know.

You can invite them. They get a free month — no card, no catch — and from the moment they join, every message between you seals itself automatically. No shared passwords, no portal links, no homework.

If they don’t join, your email goes through as normal email. Nothing bounces, nothing breaks, nobody has to know you tried to upgrade them.

Because every other service is basically the same thing with a different coat of paint — same protocols, same server-side reading, same “trust us.” We looked at the whole category and built something actually unlike it: seals on your device, keys we never hold, an address you keep. The name is a mission statement, not a typo.

§ 02 · Security

The claims, and their fine print.

Not the sealed mail. Messages between Unlike Mail users are encrypted on your device before your provider ever touches them — what they store and relay is mathematical noise. They can carry it; they can’t read it.

Mail you exchange with people not on Unlike Mail is ordinary email, and your provider sees it like any other. Sealing needs both ends — we say this everywhere, because pretending otherwise is how “secure email” got its reputation.

No — and not in the “we pinky promise” sense. Our servers store wrapped keys and ciphertext; the keys that open them exist only on your devices. If someone subpoenas us, we hand over noise and wish them luck. Mathematics has an excellent legal department.

Yes. Sealing uses ML-KEM-1024 — the NIST-standardized, lattice-based key-encapsulation mechanism (FIPS 203) — hybridized with AES-256-GCM. The point isn’t sci-fi; it’s “harvest now, decrypt later”: encrypted traffic recorded today should still be unreadable when quantum computers arrive. We’d rather future-proof now than apologize later.

That the server holds no key to what it stores. Your passphrase and KEK never leave your device; every key we persist is wrapped under keys we don’t have; working session state lives in RAM and evaporates. A full database dump — stolen, leaked, subpoenaed — is useless to whoever holds it. The full guarantee ladder is on the architecture page.

Three honest residuals. First: mail with people who aren’t on Unlike Mail is ordinary email at your provider. The other two are web-only: while you’re signed in on the web, your live session necessarily exists in server RAM (a browser is no place for API credentials, so the web client calls your provider through our server), and a compromised open tab can act as you in that tab — though it can’t steal keys or persist.

The native apps have neither problem: they keep keys in the device keystore and call your provider directly, so nothing of yours ever sits in server RAM — nothing to dump, even on a zero-day. Full list with plans and reasons: “What we can’t protect” on the architecture page.

§ 03 · Devices & Keys

Losing things, trusting things.

Nothing dramatic. Your wrapped keys live server-side as ciphertext, so any other enrolled device — or your passphrase — brings everything back. Losing one phone doesn’t lose a single email. Then you revoke the lost device’s passkey and carry on.

Two ways, both one-time. Enter your passphrase once — the new device derives the same key (same salt, same Argon2id), registers its own passkey, and never asks again.

Or skip typing entirely: approve the new device with an authorization QR / code from any device you already trust. Hardware vouches for hardware; no secret crosses anyone’s keyboard. Passkey-first, passwordless thereafter.

Then your sealed history is gone, and we can’t bring it back — there is no master key, no recovery desk, no backdoor. That’s not a support gap; it’s the design working. You reconnect your mailbox and start fresh. A recovery path for you would be a recovery path for anyone who isn’t you.

§ 04 · Billing & Practical

The money part, minus the maze.

No catch. We run lean, we can’t mine data we can’t read, and we don’t buy Super Bowl ads. $1.5 a month covers servers, team, and coffee. Privacy priced like a utility, because it should be one.

30 days free, no card, no phone number. After that it’s $1.5/month or $15/year. No permanent free tier — free tiers are subsidized by data mining or investor cash, and we do neither. You are the customer, which is the whole point.

$15 a year is two months free versus monthly. Same features, same support, just cheaper because you committed. We like commitment.

You click a button. No retention team, no “here’s 20% off” call, no guilt. Stay if we earn it. Leave if we don’t.

Yes — per-user pricing at the same rate, with an admin dashboard, user management, and team policies. Google Workspace, Microsoft 365, Zoho, and custom domains all included; if your company runs its own mail server, the desktop app connects to that over IMAP. 100+ seats, SSO, or on-premise: email contact@adamanture.com and a human replies, usually same day. No 45-minute discovery call.

Tell us — contact@adamanture.com. Security findings are paid (we run a bounty); UI glitches are appreciated loudly. Don’t leave a bad review, leave a detailed bug report. We read every single one.

Still curious?

The blueprint has the diagrams; the trust page has the receipts.