Marcus moved to Proton Mail two years ago after a breach at a shopping site leaked his old address and password. He did the sensible thing. His mail is now stored encrypted in Switzerland, and he trusts that nobody at the company can read it. Then last month a message arrived that looked like it came from his bank, asked him to confirm a payment, and sat in his Inbox next to a note from his sister. He nearly tapped it. Encryption did what it promised. It just was not built for that.
That is the whole of this comparison. Proton Mail and OptMsg are both private email services for people who are done with the free-inbox trade. They are good at different problems, and the useful question is not “which is more secure” but “which problem do you actually have.”
What Proton Mail does well
Proton is the best-known name in private email, and it has earned that. Its security page describes end-to-end encryption between Proton accounts, so a message from one Proton user to another is encrypted on the sender’s device and decrypted on the recipient’s. Mail that arrives from outside is encrypted on Proton’s servers with your public key, which the company calls zero-access encryption: stored messages are held in a form Proton says it cannot decrypt. If you need to send something encrypted to a Gmail address, you can set a password on the message and share it another way.
Around that core sit the things a security-minded reader looks for: open-source apps that have been independently audited, two-factor sign-in with hardware keys, a phishing warning called PhishGuard that flags spoofed addresses, link confirmation on mobile, and a Swiss legal base. Proton also blocks tracking pixels in its web app, so a marketer cannot see when you opened their email. If the thing keeping you up at night is who can read your stored mail, or whether your provider might hand it over, Proton has a thorough and clearly explained answer.
Where Proton is like every other inbox
Two things about Proton are the same as Gmail, Outlook and nearly every service you could name, and neither is a flaw in Proton. They are how email has worked since it was invented.
First, the front door is open. Anyone who has your address can put a message in your Inbox. Proton’s own support page explains that it sorts incoming mail with machine-learning spam filtering, and that you can add senders to spam, block and allow lists to tune it. That is a good filter. It is still a filter: software guessing, after the fact, which of the messages that already reached you are the ones you wanted. Marcus’s fake bank email got past it because it looked, to a filter, like a bank email.
Second, the account has a password. Proton’s two-factor page says it plainly: with 2FA on, you enter a one-time code in addition to your username and password. Two-factor is a real improvement and everyone should use it. But the password still exists, and a password that exists is a password that can be leaked from somewhere else, guessed, or phished on a convincing page.
What OptMsg does differently
OptMsg starts from the same place as Proton on the trade itself: OptMsg does not scan your emails to sell ads, and we don’t collect your personal data to sell to advertisers. Messages between OptMsg addresses are encrypted at rest and in transit while they stay on OptMsg infrastructure. Mail you send to an outside address is handled by that provider under its rules, as it would be from Proton or anyone else. OptMsg is not an end-to-end encryption product, and this article does not claim it is.
The difference is the front door. OptMsg’s patent-pending opt-in technology reverses the default. Only people you approve can reach your Inbox. Everyone else goes to Trash, where messages sit for 30 days before they are auto-deleted, so you can look through that folder and rescue anything you want. Nothing is guessing on your behalf. A fake bank email from an address you have not approved lands in Trash, not beside your sister’s note, because you did not invite it in. If many other OptMsg users have approved a sender you have not, a Community Recommendation flags the message so it does not slip past you.
The second difference is the account. Your OptMsg account has no password, so a password stolen from another site can’t open your inbox. Sign-in uses passkeys. Credential stuffing needs a password to try; your OptMsg account doesn’t have one. When another company gets breached, the login they leak isn’t the login to your inbox. And because your email is how most accounts get reset, keeping that door shut keeps the rest shut with it.
That is a statement about how one account is designed. It is not a claim that Proton’s security is weak, and it does not cover a lost, unlocked phone or a scam that talks you through a live sign-in. The argument is strong enough at its real size.
Encryption and spam are two different problems
Put the two side by side and the shape is clear.
Proton’s question is: once a message exists, who can read it? Its answer is encryption, and it is a good one.
OptMsg’s question is: who gets to put a message in front of you at all, and what can a stolen login do? Its answer is opt-in delivery and an account with no password.
You can care about both. But most people who type “protonmail vs” into a search box are not choosing between two encryption products. They are trying to work out whether the thing that bothers them is the privacy of what they store, or the daily stream of what arrives and the fear of what a leaked password can open. Marcus had the first problem solved and the second one waiting.
How to choose
If you exchange sensitive documents with people who will also use Proton, or you want stored mail that the provider itself cannot read, Proton is a strong choice and it explains itself well. If what wears you down is deciding, every morning, which messages are real, and you want an inbox where that decision was made once when you approved the sender, create an OptMsg account and forward your existing address into it to see the difference. For the wider field, see Gmail alternatives for people who are done being the product, and for the mechanism itself, what opt-in email means.
Pick the tool for the problem you have. Both are honest about what they do.
Create Your Account. Your Inbox. Your Rules.
Frequently asked questions
Is Proton Mail secure? By its own account, yes: end-to-end encryption between Proton users, zero-access encryption for stored mail, audited open-source apps, and two-factor sign-in including hardware keys. It is designed to protect what you store and send. It still delivers any sender’s mail to your Inbox and sorts it with a spam filter, and the account has a password.
Does OptMsg encrypt email like Proton? Not in the same way. Messages between OptMsg addresses are encrypted at rest and in transit while they stay on OptMsg infrastructure. OptMsg is not an end-to-end encryption product. Its difference is who can reach your Inbox and the absence of a password on the account.
What happens to email from someone I have not approved on OptMsg? Only people you approve can reach your Inbox. Everyone else goes to Trash, where messages are kept for 30 days before being auto-deleted, so you can check the folder and approve a sender you want to hear from.
Can I use OptMsg and Proton at the same time? Yes. Many people keep an encrypted address for specific correspondence and use OptMsg as the everyday inbox they actually read. You can forward mail from an existing address into OptMsg and read it there.
Why does not having a password matter after a breach? When another site is breached, attackers try the leaked address-and-password pairs on email accounts, because the inbox resets everything else. Your OptMsg account has no password, so a password stolen from another site can’t open your inbox.