Security at Umail
The badges on the homepage (TLS, AES-256, 2FA, DKIM/SPF/DMARC) are a summary — here's what's actually behind each one. Every item below is a real, active control in Umail today, not an aspirational claim.
TLS-encrypted transport
All traffic to and from Umail — web, mobile app, and SMTP/IMAP connections — is encrypted with TLS, so your data never travels the network in plain text.
AES-256 storage encryption
Your messages and attachments are encrypted with AES-256 while stored on our servers.
Two-factor authentication (2FA)
Enable TOTP-based 2FA with any authenticator app; one-time recovery codes get you back in if you ever lose access to your device.
Device & session management
See every device signed into your account and revoke any suspicious or unused session remotely with one click.
Security audit log
Logins, failed 2FA attempts, password changes, and other account-level actions are recorded so you can see exactly what's happened on your account.
SPF, DKIM & DMARC
Every outgoing message is signed with SPF and DKIM, and a DMARC policy is enforced — this stops others from forging mail as your domain and improves deliverability.
Account recovery
Add a verified phone number or recovery email so you can regain access to your account even if you forget your password.
Abuse prevention
Attachments are scanned for malware, and login and sending attempts are rate-limited — protecting both your account and the platform's overall delivery reputation.
Data retention
After you close your account, your data is deleted per our data-retention policy; contact support first if you need an export.
Have a question?
If you have any other security questions, our support team is ready to help.