Skip to content

Security

Your company’s email, protected at every step.

Security is built into how mail is delivered, how people sign in and how organizations are kept apart.

Mail in transit

Protection for the messages you send and receive.

Encrypted connections

Webmail, the console and every mail protocol (IMAP, POP3, SMTP submission and ManageSieve) run over TLS.

SPF, DKIM and DMARC

Outgoing mail is DKIM-signed with both Ed25519 and RSA keys, and the console checks your SPF and DMARC records.

Spam and spoofing filters

Incoming mail is scored by a spam filter and checked for forged senders before it reaches an inbox.

No sending as someone else

A signed-in mailbox can only send from its own addresses. Open relaying is refused.

Accounts and sign-in

Keeping the wrong people out of your console.

Strong password storage

Console passwords are hashed with Argon2id. We never store or display them in plain text.

Two-factor sign-in

Authenticator-app codes with one-time recovery codes for every console account.

Rate limits and lockout

Sign-in, sign-up, password reset and domain checks are rate limited, and repeated failures lock an account progressively.

Hardened sessions

Short-lived HttpOnly, Secure session cookies, rotating refresh tokens and CSRF protection on every change.

Platform

How the service itself is run.

Tenant isolation

Each organization sees only its own data. Mailbox users cannot look up addresses belonging to other companies.

Locked-down administration

Server administration is reachable only from the server itself, never from the internet.

Audit trail

Every change made in the console is logged with the person, time and IP address, and visible to owners and admins.

Daily backups

Databases and message storage are backed up every night and kept for 14 days.

Report a vulnerability

If you believe you have found a security issue in Shwastik Mail, please email security@shwastik.com with the details and steps to reproduce it. We will acknowledge your report, keep you updated while we investigate, and credit you if you wish.

Please do not access other customers’ data, degrade the service, or send spam while testing, and give us a reasonable time to fix the issue before disclosing it publicly.

To report spam or phishing sent from our servers, write to abuse@shwastik.com.

Put your team on email that looks like your business.

Start a 14-day free trial. Add your domain and create mailboxes in minutes.