Proton

UPDATE 11 October 2021: We are now using Let’s Encrypt(new window) as the Certificate Authority that verifies the SSL certificates used to secure the Proton Mail and Proton VPN web sites. For more information on this, and for instructions on how to check the validity of our certificate, please see Proton Mail’s TLS/SSL Certificate.

Last week, we underwent the process of fortifying our SSL certificates. As part of our effort to provide the highest level of security and privacy to our users, we have upgraded every single certificate that we use.

The new SSL certificates have several marked improvements over the previous ones.

  • All certificates now use the highest strength 4096-bit RSA
  • proton.me now uses an Extended Validation certificate
  • All certificates are now hashed using the stronger SHA256 algorithm


These changes can already be seen when you visit Proton Mail by the presence of a green bar in the URL.

SSLCertBar(new window)

Our new certificates are issued by SwissSign(new window) which is a wholly owned by Swiss Post, a public institution owned by the Swiss Confederation and not under US or EU control.

In addition to the new certificates, we have also implemented much stronger SSL encryption. The SSL encryption algorithms we support now provide Perfect Forward Secrecy(new window) and our servers are now configured to always use the strongest possible encryption for client connections. As a result, Proton Mail is graded A+ on our SSL report.

sslgrade(new window)

To learn how to manually verify your connection to Proton Mail to avoid a MITM attack, you can view our knowledge base article on this topic here.

We are committed to your security and privacy online and in the future you can look forward to further improvements.

Related articles

Family photos linked by AI, suggesting that your family photos may be used for training AI
en
Learn how Big Tech uses family photos to train AI, how it affects you, and how to protect your privacy to keep your memories out of datasets.
Microsoft has announced that, starting in June, you’ll no longer be able to save new passwords in the Microsoft Authenticator app.
en
If you want to use Microsoft’s password management features, you now need to step deeper into Microsoft’s walled garden. There's another way.
An illustration of a photo containing a parent and their child, overlayed on a cloud and an open padlock
en
Is your family’s photo collection safe? We surveyed 2,000 UK parents to uncover the truth about cloud storage risks, data breaches, and protecting precious memories.
en
Albums in Proton Drive makes it easier than ever to store and manage photos and videos while protecting your memories with end-to-end encryption.
What is SSO and why is it useful for businesses?
en
SSO allows employees to securely access all their work apps with just one login. Here's how SSO works and why businesses should consider it.
adolescence and the internet we handed to kids
en
Adolescence shows how platforms shape kids in harmful ways. Here's why transparent, open digital education must lead the change.