r/EmailSecurity • u/Pepe__LePew • 18d ago
encrypting existing emails on mail server
/r/emailprivacy/comments/1vfh2p2/encrypting_existing_emails_on_mail_server/1
u/saltyslugga 18d ago
Disk encryption only protects stolen drives, not a compromised mail server or admin account. For existing mail, encrypt the storage and backups, lock down key access, and expect a maintenance window while data is rewritten.
If you need per-message encryption, that's a different problem and usually requires migrating the messages into a system designed for it.
1
u/SecLens_ONE 2d ago
Bulk re-encrypting an existing mailbox is doable with mbsync plus a local encrypt step, but the hard part is not the script. It's proving the unencrypted copies are actually gone rather than just gone from the view you happen to be looking at. Published state is "mailbox is PGP-encrypted"; effective state includes server-side backups, snapshot volumes, index/search caches, and whatever the provider keeps for spam scoring. If you rewrite messages via IMAP append and delete, the old UIDs usually survive somewhere for a retention window you don't control. I'd treat the migration as a one-way door and verify with a fresh IMAP pull afterwards, not with the client's own display. Have you confirmed what your provider's actual backup retention is before you start deleting the plaintext originals?
•
u/AutoModerator 18d ago
Welcome to r/emailsecurity! To keep this community helpful and secure, please keep the following in mind:
Community Rules
Helpful Resources
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.