Skip to content

Security

Security should be quiet.

Practical controls for a mail service operated by Zentrix Data in Dubai, United Arab Emirates. No unverifiable absolutes.
  1. 01

    Transport

    The website and mail connections use TLS. Mail between ZanonMail and other providers uses TLS where the other side supports it.

  2. 02

    Authentication

    Sign-in uses your ZanonMail address and password against the mail server with OAuth (PKCE). No social login. Tokens stay in HttpOnly cookies.

  3. 03

    Password handling

    Passwords are verified server-side and are not stored in browser storage or application source. We will never ask for a password by email.

  4. 04

    Sending authenticity

    SPF, DKIM, and DMARC are published for @zanonmail.com so other providers can verify origin.

  5. 05

    Spam and abuse

    Unsolicited and abusive mail is filtered. Signup, sign-in, and recovery run a self-hosted proof-of-work check — no Google or Cloudflare widget. We rate-limit signup and enforce address caps on the server. Reports go to abuse@zanonmail.com.

  6. 06

    JMAP access

    The webmail client talks to the mail server over JMAP with your session — not with a shared admin identity reading your mail.

  7. 07

    App passwords and external clients

    Optional IMAPS (993) and SMTPS (465) use a separate app password, not your primary password. Third-party clients can store mail on that device. POP3 is not offered.

  8. 08

    Recovery key

    On signup you receive a one-time recovery key. We store only a verifier. Lose both password and key, and recovery may be impossible.

ZanonMail is operated by Zentrix Data in Dubai, United Arab Emirates. Last updated 19 August 2026. These pages describe how the product works today. They are not a substitute for counsel and should be reviewed by a lawyer before they are treated as final.