Storage encryption
All emails, contacts and notes live in a local database on your machine. Storage encryption makes that file unreadable without its key. Whoever pulls the drive or copies the file holds nothing but noise.
It is enabled by default. The decision is made once, in the setup wizard, and cannot be changed later. On Linux it needs a keyring such as GNOME Keyring or KWallet. Without one, the database stays unencrypted, and the settings page reports Encryption unavailable on this system.
How it works
Section titled “How it works”The database is encrypted with a randomly generated 64-character key
(SQLCipher, AES-256). YouniqMail stores this key sealed in its
settings file config.json. The seal is held by the operating
system: the Keychain on macOS, the Windows data protection interface
(bound to your user account), the desktop environment’s keyring on
Linux.
Day to day you notice nothing: at launch, YouniqMail unseals the key with the help of your system login. No extra password, no extra step.
The same seal also protects the passwords of your email accounts and the sign-ins to connected services, that is tokens, CalDAV passwords and webhook addresses. They are each sealed individually, even when storage encryption is off. Only on Linux without a keyring do they stay unencrypted.
The recovery key
Section titled “The recovery key”The chain has two weak links: the keychain and the config.json
file. Reinstall the operating system, reset the user account or delete
config.json, and the sealed key can no longer be opened, and with it
the access to the database.
That is what the recovery key is for: the same 64 characters, shown once during setup for safekeeping. If the key is missing at launch, YouniqMail shows the Database Key Missing dialog. Via Enter Key… you open the database again with the recovery key, without downloading anything again.
Never saved it? As long as the app runs normally, nothing is lost: under Settings → Security → Encrypt Storage, Show Recovery Key displays it again at any time, and Save as PDF stores it. On a Mac with Touch ID you confirm that with your fingerprint; on other computers it appears without any further prompt. So lock your computer when you walk away from it.
Opening Local Folders without the app
Section titled “Opening Local Folders without the app”Emails in Local Folders exist only on your device, as one file per
email in the local_mail folder of your profile. They are protected
exactly like the database:
- Storage encryption off: they are ordinary
.emlfiles that any mail program opens with a double click. - Storage encryption on: the files end in
.ymrawand are encrypted with the database key. Without it they are as unreadable as the database itself.
Day to day you never need the files directly. File → Export saves
Local Folders as mbox or as single .eml files, and the
full backup takes them along.
If YouniqMail no longer starts, the recovery key and a small emergency program get the emails back:
-
Install Node.js, version 18 or newer.
-
Download the emergency program: youniqmail-local-mail-decrypt.mjs.
-
Open a terminal (on Windows the Command Prompt) and run it with the
local_mailfolder and a target folder:node youniqmail-local-mail-decrypt.mjs <local_mail folder> <target folder> -
Enter the recovery key when asked. What you type stays hidden.
Every email then sits in the target folder as an .eml file, named
after its date and subject. The program reports a damaged file and
leaves it out, and a second run overwrites nothing. It needs no
internet connection and sends nothing anywhere. How the files are built
is described in plain text at the top of the program.
The local_mail folder is in your profile:
~/Library/Application Support/YouniqMail/local_mail/%APPDATA%\YouniqMail\local_mail\~/.config/YouniqMail/local_mail/If you want to reset local data, rescue Local Folders beforehand
with the emergency program: after the reset, YouniqMail cleans up the
files in local_mail that are no longer needed after three days.
What lives outside the database
Section titled “What lives outside the database”YouniqMail keeps some files next to the database, and these are not encrypted:
- Cached attachments you have opened or viewed (folder
attachment_cache, at most 500 MB), - attachments of drafts and of mail in the outbox (folders
draft_attachmentsandoutbox_attachments), - mail currently being sent, until its copy has arrived in the
Sent folder (folder
sent_pending), - the log (folder
logs), from which addresses and content are filtered out, - the settings in
config.json, including the master password hint.
All of them live in the same profile folder as local_mail. To
protect the computer against outside access to the disk, also switch
on the system’s disk encryption (FileVault, BitLocker, LUKS).
What it protects and what it does not
Section titled “What it protects and what it does not”Storage encryption protects the file on disk: against a stolen machine, against copying the database, against curious eyes on a backup drive.
It does not protect against someone sitting at your unlocked computer. There, the database is readable by design. For that there is the master password. And it does not encrypt the transport to the other side. That is what PGP and S/MIME are for.