Skip to content

Storage encryption

All emails, contacts and notes live in a local database on your machine. Storage encryption makes that file unreadable without its key. Whoever pulls the drive or copies the file holds nothing but noise.

It is enabled by default. The decision is made once, in the setup wizard, and cannot be changed later. On Linux it needs a keyring such as GNOME Keyring or KWallet. Without one, the database stays unencrypted, and the settings page reports Encryption unavailable on this system.

The database is encrypted with a randomly generated 64-character key (SQLCipher, AES-256). YouniqMail stores this key sealed in its settings file config.json. The seal is held by the operating system: the Keychain on macOS, the Windows data protection interface (bound to your user account), the desktop environment’s keyring on Linux.

Day to day you notice nothing: at launch, YouniqMail unseals the key with the help of your system login. No extra password, no extra step.

The same seal also protects the passwords of your email accounts and the sign-ins to connected services, that is tokens, CalDAV passwords and webhook addresses. They are each sealed individually, even when storage encryption is off. Only on Linux without a keyring do they stay unencrypted.

The chain has two weak links: the keychain and the config.json file. Reinstall the operating system, reset the user account or delete config.json, and the sealed key can no longer be opened, and with it the access to the database.

That is what the recovery key is for: the same 64 characters, shown once during setup for safekeeping. If the key is missing at launch, YouniqMail shows the Database Key Missing dialog. Via Enter Key… you open the database again with the recovery key, without downloading anything again.

Never saved it? As long as the app runs normally, nothing is lost: under Settings → Security → Encrypt Storage, Show Recovery Key displays it again at any time, and Save as PDF stores it. On a Mac with Touch ID you confirm that with your fingerprint; on other computers it appears without any further prompt. So lock your computer when you walk away from it.

Emails in Local Folders exist only on your device, as one file per email in the local_mail folder of your profile. They are protected exactly like the database:

  • Storage encryption off: they are ordinary .eml files that any mail program opens with a double click.
  • Storage encryption on: the files end in .ymraw and are encrypted with the database key. Without it they are as unreadable as the database itself.

Day to day you never need the files directly. File → Export saves Local Folders as mbox or as single .eml files, and the full backup takes them along.

If YouniqMail no longer starts, the recovery key and a small emergency program get the emails back:

  1. Install Node.js, version 18 or newer.

  2. Download the emergency program: youniqmail-local-mail-decrypt.mjs.

  3. Open a terminal (on Windows the Command Prompt) and run it with the local_mail folder and a target folder:

    node youniqmail-local-mail-decrypt.mjs <local_mail folder> <target folder>
  4. Enter the recovery key when asked. What you type stays hidden.

Every email then sits in the target folder as an .eml file, named after its date and subject. The program reports a damaged file and leaves it out, and a second run overwrites nothing. It needs no internet connection and sends nothing anywhere. How the files are built is described in plain text at the top of the program.

The local_mail folder is in your profile:

Operating system:
~/Library/Application Support/YouniqMail/local_mail/
%APPDATA%\YouniqMail\local_mail\
~/.config/YouniqMail/local_mail/

If you want to reset local data, rescue Local Folders beforehand with the emergency program: after the reset, YouniqMail cleans up the files in local_mail that are no longer needed after three days.

YouniqMail keeps some files next to the database, and these are not encrypted:

  • Cached attachments you have opened or viewed (folder attachment_cache, at most 500 MB),
  • attachments of drafts and of mail in the outbox (folders draft_attachments and outbox_attachments),
  • mail currently being sent, until its copy has arrived in the Sent folder (folder sent_pending),
  • the log (folder logs), from which addresses and content are filtered out,
  • the settings in config.json, including the master password hint.

All of them live in the same profile folder as local_mail. To protect the computer against outside access to the disk, also switch on the system’s disk encryption (FileVault, BitLocker, LUKS).

Storage encryption protects the file on disk: against a stolen machine, against copying the database, against curious eyes on a backup drive.

It does not protect against someone sitting at your unlocked computer. There, the database is readable by design. For that there is the master password. And it does not encrypt the transport to the other side. That is what PGP and S/MIME are for.