Tuta, formerly Tutanota,
is an
end-to-end
End-to-end or End to End may refer to:
* End-to-end auditable voting systems, a voting system
* End-to-end delay, the time for a packet to be transmitted across a network from source to destination
* End-to-end encryption, a cryptographic paradigm ...
encrypted email Email encryption is encryption of email messages to protect the content from being read by entities other than the intended recipients. Email encryption may also include authentication.
Email is prone to the disclosure of information. Most emails a ...
app and a
freemium
Freemium, a portmanteau of the words "free" and "premium," is a pricing strategy by which a basic product or service is provided free of charge, but money (a premium) is charged for additional features, services, or virtual (online) or physical ...
secure email service. The service is advertisement-free; it relies on donations and premium subscriptions. As of June 2023, Tutanota's owners claimed to have over 10 million users of the product. The company announced a transition to 100% renewable electricity in March 2019. This decision coincided with employee participation in
Fridays for Future
School Strike for Climate ( sv, Skolstrejk för klimatet), also known variously as Fridays for Future (FFF), Youth for Climate, Climate Strike or Youth Strike for Climate, is an international movement of school students who skip Friday ...
protests. On 1st October 2024, Tuta launched its standalone encrypted calendar app. Tuta Mail has recently integrated post-quantum cryptography features through its new protocol - ''TutaCrypt'' replacing standard encryption methods like
RSA-2048 and
AES-256
The Advanced Encryption Standard (AES), also known by its original name Rijndael (), is a specification for the encryption of electronic data established by the U.S. National Institute of Standards and Technology (NIST) in 2001.
AES is a variant ...
for its newly created accounts after March 2024.
History

Tutanota is derived from Latin and contains the words "
tuta" and "
nota
Nota Sports and Racing Cars is an automobile manufacturer in Australia. The company was founded by Guy Buckingham in 1952. He was an aircraft engineer and used his expertise to build triangulated spaceframed sportscars. Possibly Australia's f ...
" which means "secure message". Tutao GmbH was founded in 2011 in Hanover, Germany.
The goal of the developers for Tuta is to fight for email privacy. Their vision gained even more importance, when
Edward Snowden
Edward Joseph Snowden (born June 21, 1983) is an American and naturalized Russian former computer intelligence consultant who leaked highly classified information from the National Security Agency (NSA) in 2013, when he was an employee and s ...
revealed
NSA
The National Security Agency (NSA) is a national-level intelligence agency of the United States Department of Defense, under the authority of the Director of National Intelligence (DNI). The NSA is responsible for global monitoring, collectio ...
's mass surveillance programs like
XKeyscore
XKeyscore (XKEYSCORE or XKS) is a secret computer system used by the United States National Security Agency (NSA) for searching and analyzing global Internet data, which it collects in real time. The NSA has shared XKeyscore with other intelligen ...
in July 2013.
Since 2014, the software has been open-sourced and can be reviewed by outsiders on
GitHub
GitHub, Inc. () is an Internet hosting service for software development and version control using Git. It provides the distributed version control of Git plus access control, bug tracking, software feature requests, task management, co ...
.
In August 2018, Tuta became the first email service provider to release their app on
F-Droid
F-Droid is an app store and software repository for Android, serving a similar function to the Google Play store. The main repository, hosted by the project, contains only free and open source apps. Applications can be browsed, downloaded and ...
, removing all dependence on proprietary code. This was part of a full remake of the app, which removed dependence on
GCM for notifications by replacing it with
SSE. The new app also enabled search,
2FA
Multi-factor authentication (MFA; encompassing two-factor authentication, or 2FA, along with similar terms) is an electronic authentication method in which a user is granted access to a website or application only after successfully presenting ...
and got a new reworked user interface.
In November 2020, the Cologne court ordered monitoring of a single Tuta account that had been used for an
extortion
Extortion is the practice of obtaining benefit through coercion. In most jurisdictions it is likely to constitute a criminal offence; the bulk of this article deals with such cases. Robbery is the simplest and most common form of extortion, ...
attempt. The monitoring function should only apply to future unencrypted emails this account receives and it will not affect emails previously received.
On 7 November 2023, Tutanota announced it was rebranded to simply 'Tuta'. The former domain name tutanota.com now redirects to the shorter tuta.com.
On 11 November 2023, it was alleged that Tuta was being used as a
honeypot for criminals with a
backdoor
A back door is a door in the rear of a building. Back door may also refer to:
Arts and media
* Back Door (jazz trio), a British group
* Porta dos Fundos (literally “Back Door” in Portuguese) Brazilian comedy YouTube channel.
* Works so titl ...
from authorities. An ex-
RCMP
The Royal Canadian Mounted Police (RCMP; french: Gendarmerie royale du Canada; french: GRC, label=none), commonly known in English as the Mounties (and colloquially in French as ) is the federal and national police service of Canada. As poli ...
officer,
Cameron Ortis, testified that the service was used as a storefront to lure criminals in and gain information on those who fell for it. He stated authorities were monitoring the whole service, feeding it to
Five Eyes
The Five Eyes (FVEY) is an intelligence alliance comprising Australia, Canada, New Zealand, the United Kingdom, and the United States. These countries are parties to the multilateral UKUSA Agreement, a treaty for joint cooperation in si ...
, which would disperse it back to the RCMP in order to gain more knowledge about the criminal underground. However, no evidence was ever presented to back up this statement, and Tuta refuted the claim.
Services
Tuta Mail
"Tuta Mail" is Tuta’s initial and primary service. Tuta Mail is a fully end-to-end encrypted email service available for download on Android (Google, F-Droid, apk) and iOS. Tuta Mail has email clients for Linux, Windows and macOS. It can also be accessed through web browser. In 2024 Tuta introduced quantum-resistant algorithms in a
hybrid protocol similar to
Signal
In signal processing, a signal is a function that conveys information about a phenomenon. Any quantity that can vary over space or time can be used as a signal to share messages between observers. The '' IEEE Transactions on Signal Processing' ...
to protect the data against future attacks from
quantum computers
Quantum computing is a type of computation whose operations can harness the phenomena of quantum mechanics, such as superposition, interference, and entanglement. Devices that perform quantum computations are known as quantum computers. Though ...
.
Tuta Calendar
The "Tuta Calendar" is encrypted with
post-quantum cryptography
In cryptography, post-quantum cryptography (sometimes referred to as quantum-proof, quantum-safe or quantum-resistant) refers to cryptographic algorithms (usually public-key algorithms) that are thought to be secure against a cryptanalytic attack ...
. The Tuta Calendar was first released as an integrated calendar in Tuta Mail. In October 2024, Tuta released it as a stand-alone calendar app available for iOS and Android.
Encryption
When a user registers on Tuta, a
private and public key is generated locally on their device. The private key is encrypted with the user's password before being sent to Tuta’s servers. User passwords are hashed using
Argon2
Argon2 is a key derivation function that was selected as the winner of the 2015 Password Hashing Competition. It was designed by Alex Biryukov, Daniel Dinu, and Dmitry Khovratovich from the University of Luxembourg. The reference implementation ...
and
SHA256
SHA-2 (Secure Hash Algorithm 2) is a set of cryptographic hash functions designed by the United States National Security Agency (NSA) and first published in 2001. They are built using the Merkle–Damgård construction, from a one-way compression ...
.
Emails between Tuta users are automatically encrypted end-to-end. For emails sent to external recipients, a password must be exchanged for
symmetric encryption
Symmetric-key algorithms are algorithms for cryptography that use the same cryptographic keys for both the encryption of plaintext and the decryption of ciphertext. The keys may be identical, or there may be a simple transformation to go between t ...
. Tuta also encrypts subject lines and attachments of emails and calendars with metadata and search indexes. The email addresses of users, as well as those of senders and recipients, are stored in plain text. The
timestamps
A timestamp is a sequence of characters or encoded information identifying when a certain event occurred, usually giving date and time of day, sometimes accurate to a small fraction of a second. Timestamps do not have to be based on some absolut ...
indicating when an email was sent or received are also not encrypted.
Tuta uses a standardized, hybrid method consisting of a symmetrical and an asymmetrical algorithm -
AES
AES may refer to:
Businesses and organizations Companies
* AES Corporation, an American electricity company
* AES Data, former owner of Daisy Systems Holland
* AES Eletropaulo, a former Brazilian electricity company
* AES Andes, formerly AES Gener ...
with a length of 256 bit and
RSA
RSA may refer to:
Organizations Academia and education
* Rabbinical Seminary of America, a yeshiva in New York City
*Regional Science Association International (formerly the Regional Science Association), a US-based learned society
*Renaissance S ...
with 2048 bit. To external recipients who do not use Tuta a notification is sent with a link to a temporary Tuta account. After entering a previously exchanged password, the recipient can read the message and reply end-to-end encrypted.
Tuta Mail uses
post-quantum cryptography
In cryptography, post-quantum cryptography (sometimes referred to as quantum-proof, quantum-safe or quantum-resistant) refers to cryptographic algorithms (usually public-key algorithms) that are thought to be secure against a cryptanalytic attack ...
features through its new protocol, ''TutaCrypt'' for its newly created accounts after March 2024. TutaCrypt combines traditional encryption methods with quantum-resistant algorithms to secure communications. It replaces the previous RSA-2048 keys with two new key pairs:
Elliptic Curve Key Pair: ''Utilizes the X25519 curve for the
Elliptic Curve Diffie-Hellman (ECDH) key exchange.''
Kyber-1024 Key Pair: ''Implements post-quantum key encapsulation using the
CRYSTALS-Kyber algorithm.''
TutaCrypt employs AES-256 in
CBC mode
In cryptography, a block cipher mode of operation is an algorithm that uses a block cipher to provide information security such as confidentiality or authenticity.
A block cipher by itself is only suitable for the secure cryptographic transforma ...
alongside
HMAC-SHA-256
In cryptography, an HMAC (sometimes expanded as either keyed-hash message authentication code or hash-based message authentication code) is a specific type of message authentication code (MAC) involving a cryptographic hash function and a secret ...
for authenticated symmetric encryption. And the transition to TutaCrypt for old existing user accounts created before March 2024, will occur in December 2024. Tuta also stated that it does not use
PGP
PGP or Pgp may refer to:
Science and technology
* P-glycoprotein, a type of protein
* Pelvic girdle pain, a pregnancy discomfort
* Personal Genome Project, to sequence genomes and medical records
* Pretty Good Privacy, a computer program for the ...
due to its limitations in encrypting subject lines and lack of flexibility for algorithm updates.
S/MIME S/MIME (Secure/Multipurpose Internet Mail Extensions) is a standard for public key encryption and signing of MIME data. S/MIME is on an IETF standards track and defined in a number of documents, most importantly . It was originally developed b ...
is also avoided due to critical vulnerabilities identified in 2018.
Reception
Reviews of Tech websites were generally positive for Tuta. In July 2023,
TechRadar
''TechRadar'' is an online publication owned by Future and focused on technology. It has editorial teams in the US, UK and Australia and provides news and reviews of tech products and gadgets. It was launched in 2007 and expanded to the US in ...
praised Tuta Mail as an "Excellent encrypted email platform" focusing on its broad features and intuitive design. However, it criticized the limitations in customer support and the cost of additional storage. In June 2024,
PCMag
''PC Magazine'' (shortened as ''PCMag'') is an American computer magazine published by Ziff Davis. A print edition was published from 1982 to January 2009. Publication of online editions started in late 1994 and have continued to the present d ...
highlighted Tuta for its strong encryption and user-friendly interface with a rating of 4 out 5. CyberNews rated 4.6 overall, but criticized Tuta for its lack of
PGP
PGP or Pgp may refer to:
Science and technology
* P-glycoprotein, a type of protein
* Pelvic girdle pain, a pregnancy discomfort
* Personal Genome Project, to sequence genomes and medical records
* Pretty Good Privacy, a computer program for the ...
and
IMAP
In computing, the Internet Message Access Protocol (IMAP) is an Internet standard protocol used by email clients to retrieve email messages from a mail server over a TCP/IP connection. IMAP is defined by .
IMAP was designed with the goal of pe ...
support. Also it pointed out Tuta's Headquarters -
Germany
Germany, officially the Federal Republic of Germany (FRG),, is a country in Central Europe. It is the most populous member state of the European Union. Germany lies between the Baltic and North Sea to the north and the Alps to the sou ...
as a drawback for being a part in
Fourteen Eyes Alliance.
Future
Tuta is working on a
cloud storage
Cloud storage is a model of computer data storage in which the digital data is stored in logical pools, said to be on "the cloud". The physical storage spans multiple servers (sometimes in multiple locations), and the physical environment is ty ...
platform named "TutaDrive" with a focus on
post-quantum cryptography
In cryptography, post-quantum cryptography (sometimes referred to as quantum-proof, quantum-safe or quantum-resistant) refers to cryptographic algorithms (usually public-key algorithms) that are thought to be secure against a cryptanalytic attack ...
. The project, officially named "PQDrive - Development of a Post-Quantum Encrypted Online Storage," is funded by the
German government's KMU-innovativ program (€1.5 million), which supports
Small and medium-sized enterprises
Small and medium-sized enterprises (SMEs) or small and medium-sized businesses (SMBs) are businesses whose personnel and revenue numbers fall below certain limits. The abbreviation "SME" is used by international organizations such as the World Ba ...
(SMEs) like Tuta. The project receives further support through a €600,000 collaboration with the
University of Wuppertal
The University of Wuppertal (''Universität Wuppertal'') is a German scientific institution, located in Wuppertal, in the state of North Rhine-Westphalia, Germany.
The university's official name in German is ''Bergische Universität Wuppertal'' ...
, which will play a key role in
research and development
Research and development (R&D or R+D), known in Europe as research and technological development (RTD), is the set of innovative activities undertaken by corporations or governments in developing new services or products, and improving existi ...
.
Account deletion
Tuta deletes free accounts that have not been logged into for 6 months. According to Tuta, this happens because of security reasons and for keeping the service free.
Tuta has also been
GDPR
The General Data Protection Regulation (GDPR) is a European Union regulation on data protection and privacy in the EU and the European Economic Area (EEA). The GDPR is an important component of EU privacy law and of human rights law, in partic ...
compliant since 2018.
Censorship
Tuta has been
blocked in Egypt since October 2019, and
blocked in Russia since February 2020 for unknown reasons (although believed to be tied to actions against services operating outside of the country, especially those that involve encrypted communications).
See also
*
Comparison of mail servers
The comparison of mail servers covers mail transfer agents (MTAs), mail delivery agents, and other computer software that provide e-mail services.
Unix-based mail servers are built using a number of components because a Unix-style environment ...
*
Comparison of webmail providers
The following tables compare general and technical information for a number of notable webmail providers who offer a web interface in English.
The list does not include web hosting
A web hosting service is a type of Internet hosting s ...
References
External links
* {{Official website, https://tuta.com
Cross-platform software
Free security software
Free software webmail
Internet properties established in 2011
Secure communication
Software using the GNU General Public License
Free software programmed in TypeScript
Free software programmed in JavaScript