This might come out as a bit of a rant, but I just wanted to post it here anyway since it’s the only social media I use.
Recently, I’ve been making some steps to improve my privacy. GrapheneOS, Linux on my PC, open source software, moving away from Google stuff. So, next logical step was for me to switch away from Gmail. I went with Tutanota, since they’re based in EU, their mobile app is on F-Droid and doesn’t require Google Play Services. So I made an account, switched a bunch of my private account e-mails from Gmail to Tuta, and was basically done. Two days later, I wake up to a “invalid credentials” message. I checked the option to remember my password on my PC, so I thought it was weird. I checked my phone, and it turns out I was logged out of the app too. I tried changing my password with recovery code, thinking something went wrong (though unlikely since I used a password manager), but I got an error on that one too. So I contacted Tutanota, almost a week ago. No response.
I tried looking on various sites to check if people had a similar issue. I found a few reports on Reddit. The moderator of Tuta says to contact the e-mail address that I sent a message to already, but people complained that they haven’t gotten a response either. I found out that similar reports were happening for a while now, accounts being flagged for seemingly no reason. I found one post from October, 2024, from a frustrated user. He said he was in the same situation, and when he finally got the reply, Tutanota said they can’t do anything. When I found that post, I was really disheartened. I’ve already went back on a bunch of accounts to @gmail.com account, for safety, but there is still a few that I’m not even able to access because they use e-mail 2fa. Some of them being accounts for various government public services.
So this one gave me a pause on my privacy journey. I never encountered problems like this one before. A service blocking my account without any message or warning. No contact from support. Being locked out of my accounts. I’ve lost a lot of enthusiasm to replace a few proprietary services that I have left.
Thank you first of all OP for actually sharing your experience. I’ve known Tuta was sketchy for a while, yet in every single post anyone talks about switching emails, every other reply is always “Tuta! :)”
And I feel because everyone is so unanimously vouching for Tuta, people who may use other niche services don’t feel as encouraged to share what they may have “Oh, guess everyone likes Tuta.”
Stfu about Tuta. Seriously.
And ftr, no OP you’re not alone. I’ve seen countless other domains engage in the same draconian 2FA shit where they do a better job of locking you out of your own accounts than actually protecting your privacy. It’s unfortunately becoming an industry standard model from the looks of it.
Tuta is very suspect
No clue what you’re talking about at the end with 2fa, though. it sounds very yelling at clouds.
Try posteo. They at least allow third party clients and they have some cool features.
I tried Tudor and proton’s free tier, and I couldn’t deal with how they can’t use a normal email client.
On the other hand, I’ve been trying to use Thunderbird with my next cloud calendar and it keeps hanging for me on Ubuntu. So maybe trying to use Thunderbird is a recipe for disaster as well. I don’t know what to do.
I wished posteo allowed custom domains… They would be perfect then!
Their reasoning seems to be because of potential privacy issues: https://posteo.de/en/site/faq
I had the exact same issue when I created a Tuta email, thankfully they solved my problem in less than 24h after I emailed them about the this.
Just send an e-mail. your account was flagged as bot.
Why would they flag a human as a bot?
I have been disappointed in tuta myself as well. They seem to be too privacy and security focused at the cost of being hard to use.
A lot of these “privacy sensitive” service providers are actually quite user-hostile.
Find a middle ground - get your own domain (pick a good registrar) and find a respectable mail host that has a support team with accountability who don’t treat you like a burden on this planet when you attempt to contact them (i.e not Tuta, not Mailbox-org - nope!!!, not Proton etc.). Do not go overboard with DMARC/etc in the beginning. Go about it slowly.
Also - make sure you use a service that lets you connect via an IMAP/POP client. It pains me to say that, but if you start avoiding services based on “five eyes” and “14 eyes” and “195 eyes”, I’m pretty sure we will be looking at pigeons and corked bottles in the sea. So, if you need E2EE over email - please use E2EE in the email using GPG on your own. I’d highly recommend not falling for the privacy theatre of the likes of Proton.
I understand the tuta and proton hate, but what’s wrong with the mailbox dot org?
I think they have some sort of critical security flaw regarding spoofing that hasn’t been resolved in years and they had a forum thread about it
I found some really old leddit and HN threads with similar warnings but nothing conclusive –Please send links if anyone finds anything convincing
Fastmail is what i use for this. $50/year. Not gmail. Catch-all email boxes. So i use a new address for everything. It’s not proton. So not sure if it’s even encrypted at rest. But they are not selling my email to advertisers like gmail. And if I want to move I own my domian so its easy.
Did we read the same post?
I also had a problem a few years ago with Tutanota and when I emailed for help, no response. I just gave up and accepted that those emails were lost forever. I now have Protonmail and I’ve been happy with them.
If they “can’t do anything” on their own service then how can they be trusted at all?
They’re either lying outright, or are so deeply incompetent that they don’t know how their own software works and can’t touch it to try to resolve a problem for fear of breaking something.
Instead of having your online accounts registered directly to your @tuta.io address (or your gmail address, or any webmail address), buy a domain name and have the accounts registered to that and then set the DNS to forward all mail from that domain to your webmail account of choice. That way, if the webmail service fucks up, the worst-case scenario is that you change the forwarding again and you’ve only lost the contents of the previous emails sent, not access to receive future ones.
(Caveat: when you send an email it’ll by default be coming from your webmail provider address, not your custom domain address, and I’m not sure how to fix that – I’ve only recently started switching to the scheme myself – but if your main issue is receiving 2FA emails and such that’s not a big deal.)
I am following the same path for more privacy, ultimately choosing Posteo, where I am now slowly transferring all my addresses. After 6 months, I have not encountered any problems yet.
I’m really sorry this happened to you OP.
I would really recommend that you consider getting a custom domain for your email. many are not that expensive and if you do, then you can just point that domain at whatever email provider you want without changing your email on the services.
in this scenario, it would let you setup that domain on another provider and at least get access to any emails going forward.
This is horrible, did you try reaching out to them on mastodon? Their account is pretty active there
Buying a domain and using that is a good idea, and you can also do a catch-all so you can give each service their own address and see which ones leak your data
I think it’s safe to say you went too fast (id always start with email forwarding and slowly moving services over in ascending order of importance, and make sure you avoid email 2fa if at all possible), but that does suck.
Tuta is definitely the least reputable of the privacy email services, I still don’t know why they get recommended. I’ve made and lost several accounts with them and treat them like a burner.
Protons a bit risky to me because they’re very aggressive about immediately locking you out if you don’t pay right away (in this case a trial expired, they charged me with no credit card on the account and threatened to block me from accessing my account if I didn’t pay up even though I immediately contacted them and tried to cancel as soon as I saw the trial expired). To me that level of inflexibility is, while maybe acceptable in Europe, not for me. I keep a few email addresses and as soon as the above happened immediately moved everything out of proton.
But really what I’d recommend is the more traditional services that you pay a small amount for. Posteo has been good for me for several years. I’ve read similar things about similar services which aren’t marketed as “privacy” services but instead they just aren’t Google.
Does this happen when you log in via your browser as well as when using a client app?
Browser and android app. Just tried the appimage too, same problem.
I went through a similar situation with openmailbox dot org, though of course in their case the entire service suddenly shut down. Terrible position to be in. I eventually recovered most, but not all, accounts using that email address. Huge PITA.
That’s why I switched to my own mailserver. Sure this isn’t something for everyone. But getting a vps with a reputable and static IP to setup stalwart and use their manual for building up all the DNS querys wasn’t that hard.







