Who else reads your email? Meet Eon Phoenix: post-quantum email on the address you already have. Eon Phoenix. Post-quantum mail. Same address.
Your email provider can read your email.
Your messages are protected while they travel, but once they arrive, they're stored in a form your provider can open. That's what makes features like spam filters and AI assistants possible.
It also means others can get in. US-based providers can be legally required to hand over data, even when it's stored in Europe. And providers get breached: in 2023, attackers used a stolen Microsoft key to read government mailboxes in Microsoft's cloud.
Most providers handle that access with care. You just have no way to check.
Email encryption is too complicated for regular users
Secure email has existed for decades. Hardly anyone uses it, because it has always been a hassle:
- You need a new address. Most secure services only protect your mail if you move to them. That means a new address, and telling everyone you work with.
- You need to swap keys. With tools like PGP, you first exchange keys with every person you want to write to. Most people give up at that step.
- It's easy to slip. Write to someone outside your secure service, and your message often goes out less protected than you think.
This is why people who care about privacy still end up using regular email.
Why we built Eon Phoenix
We believe privacy shouldn't be a premium feature, or a technical project. So we built Eon Phoenix: a free, open-source mail client that protects your messages without asking you to change how you work.
It works with Microsoft 365, Google Workspace and any regular mail provider. Your regular email keeps working as it always has. Protected messages land in the same inbox, and you open them in Phoenix.
On top of today's encryption, Phoenix adds a post-quantum layer.
Choose how private each message is
Not every email needs the same protection. Phoenix gives you four options, in one inbox:
- Email. Your regular mail, protected whenever the recipient can receive it. Phoenix always shows whether it was.
- D-Mail (Direct Mail). An encrypted conversation that feels like chat but runs on your email address.
- C-Mail (Confidential Mail). Always encrypted, never stored as readable text. If it can't be sent securely, it isn't sent at all.
- B-Mail (Burner Mail). A message designed to be read once.
Why a quantum layer?
Quantum computers will be able to break much of the encryption we use today. You don't have to wait for that moment to be at risk. Attackers can collect encrypted messages now, store them, and open them later, once the technology is there. This is called harvest now, decrypt later.
If your mail has to stay private for years, it needs protection that holds up against a quantum computer.
Phoenix uses both today's proven encryption and new post-quantum encryption. Both would have to be broken before anyone could read your message.
How it works
You keep your address and your provider. Phoenix connects to the account you already use, whether that's Gmail, Outlook or another provider, so there's no new address and no moving your mail.
Encrypted email has always failed at the same point: getting the right key from the recipient. Phoenix removes that step. It finds the key automatically and seals the message, so there's nothing for you or your team to get wrong.
Keys are published through Codex: one keyserver per domain, run by that domain for its own addresses. No central registry, and no swapping keys by hand.
The person you write to needs Phoenix too. Want the technical details? See how Phoenix works.
Try it, or build with us
Phoenix is in beta, free, and open source. Everyone can read the code, check it and challenge it.
Want to try it? Download Phoenix from GitLab for macOS, Windows or Linux. Found a bug, or missing something? Tell us on GitLab.
Want to offer it to others? We're looking for partners: mail and hosting providers, IT service providers, software companies and packagers. Learn more.
Like what we're building?
Phoenix is just the start. At Eoncore, we build post-quantum cryptography and security tools for people and organisations. Next up are our core products for organisations: Eon Insights, which shows what cryptography runs in your systems, and Eon Path, which adds post-quantum protection to your existing applications. Follow us on LinkedIn to stay in the loop.
Mail provider can read your mail.
Mail protected while travel. Once arrive, stored so provider can open. That how spam filter and AI assistant work.
Others get in too. US provider can be forced to hand over data, even data stored in Europe. Provider get breached: 2023, stolen Microsoft key, government mailboxes read. You no way to check.
Secure mail too hard
- New address. Most secure services only protect mail if you move there.
- Swap keys. PGP want key exchange with every person first. Most people quit here.
- Easy slip. Write outside secure service, mail go out less protected than you think.
So privacy people still use regular mail.
Why Phoenix
Eon Phoenix: free, open-source mail client. Work with Microsoft 365, Google Workspace, any regular provider. Same inbox. Protected mail open in Phoenix. Post-quantum layer on top of today's crypto.
Four kind of message
- Email — protected when recipient can take it. Phoenix show if it was.
- D-Mail — encrypted chat, on your mail address.
- C-Mail — always encrypted. Cannot send safe? Not sent.
- B-Mail — read once.
Why quantum layer
Quantum break today's crypto. Attacker store your mail now, open later. Harvest now, decrypt later. Phoenix use classic and post-quantum both. Attacker must break both.
How work
Keep address, keep provider. Phoenix find recipient key itself and seal message. Keys live in Codex: one keyserver per domain, run by that domain. No central registry. Recipient need Phoenix too. Detail: docs.
Get it
Beta. Free. Source open. Download for macOS, Windows, Linux. Bug? Tell us on GitLab. Want to offer it? Partner.
Next: Eon Insights find crypto in your systems. Eon Path add post-quantum to your apps.
TL;DR — Eon Phoenix is a free, open-source (beta) desktop mail client that adds hybrid classical + post-quantum encryption on top of an existing mailbox (Microsoft 365, Google Workspace, any IMAP/SMTP provider). No new address, no manual key exchange.
- Problem: providers store mail in a form they can open; exposure via legal compulsion (US jurisdiction over EU-stored data) and breaches (2023 stolen Microsoft signing key, government mailboxes read).
- Why existing secure mail fails: new address required, manual key exchange (PGP), silent downgrade when writing outside the service.
- Message kinds: Email (opportunistic, protection status shown), D-Mail (encrypted chat-style on the mail address), C-Mail (always sealed, refused rather than downgraded), B-Mail (read once).
- Crypto: hybrid classical + post-quantum; both must be broken to read a message. Threat model includes harvest now, decrypt later.
- Key discovery: Codex, one keyserver per domain, operated by that domain for its own addresses. No central registry. Recipient needs Phoenix.
- Platforms: macOS, Windows, Linux. Releases: gitlab.com/eoncore/phoenix/-/releases.
- Partners sought: mail and hosting providers, IT service providers, software companies, packagers — eoncore.eu/phoenix.html.
Documentation: docs.eoncore.eu/eon-phoenix/.