Security is about who can read the message. Privacy is about who knows the address and what they do with it. They're solved by different tools and confusing them is why people move to an encrypted provider and are baffled when the spam follows them. Encryption protects contents in transit and at rest; it has no effect whatsoever on the three hundred companies holding your address.
The distinction
| Secure email | Private email | |
|---|---|---|
| Question it answers | Who can read this message? | Who knows my address, and what do they do with it? |
| Threat | Interception, provider access, server compromise | Sharing, selling, breaches, aggregation, spam |
| Tools | TLS, end-to-end encryption, PGP, zero-access storage | Per-service addresses, not publishing your address, minimal disclosure |
| Protects | Message contents | The address itself, and who can reach you |
| Doesn't touch | Who has your address | Whether messages can be read in transit |
| Typical purchase | An encrypted mail provider | An alias service, or a domain |
Why people conflate them
Both get marketed as "privacy". An encrypted provider's pitch โ nobody can read your mail, not even us โ sounds like it addresses the general unease people have about email, and it genuinely addresses part of it. It just isn't the part most people are actually experiencing.
The felt problem for most people is volume and loss of control: too much unwanted mail, from companies they can't identify, that they can't stop. That's entirely an address problem. Encryption is orthogonal to it.
What each actually gets you
Security, done well
- Your provider can't read the contents of stored mail.
- A server breach exposes ciphertext rather than your correspondence.
- End-to-end encrypted exchanges with people using compatible tools are private between you.
Real benefits. Note the limit: mail to and from people not using encryption is still ordinary email at the other end, and metadata โ who mailed whom, when, with what subject โ is largely not protected regardless.
Privacy, done well
- Each organisation holds a different address, so a breach exposes something nobody else has.
- Unwanted mail identifies its own source.
- You can revoke any single company's route to you without their cooperation.
- Your address stops being the join key that links your records across datasets. Why that matters
The test
Ask what specifically worries you.
- "I don't want my provider or an interceptor reading my mail." Security problem. An encrypted provider is the right answer.
- "I get too much unwanted mail and can't tell where it came from." Privacy problem. Encryption will change nothing.
- "My details are published on people-search sites." Neither โ that's a removal problem. Different tool again
- "All of the above." Common, and they stack fine: an encrypted provider as the destination, per-service addresses in front of it.
They combine well
Nothing about the two is in tension. Aliases forward into whatever inbox you choose, including an encrypted one โ and that's arguably the strongest setup available: the contents protected at rest, and each organisation holding a different, revocable address.
What doesn't work is buying one and expecting it to do the other's job. How the layers fit together