Glossary
Email words, without the RFC.
24 terms that come up when you run mail on your own domain. Each one says what it is and why it matters to you, which is the half a dictionary leaves out.
DNS and authentication
The records in DNS that decide where your mail goes and who is allowed to send as you.
- MX recordMail Exchanger
- The DNS record that says which server receives mail for your domain. It is the single record that moves a domain from one provider to another, which is also why leaving any provider is a DNS change rather than a negotiation. Change it and new mail arrives somewhere else within the record's TTL.
- SPFSender Policy Framework
- A DNS record listing which servers are allowed to send mail using your domain. Receiving providers check it and treat mail from anywhere else with suspicion. If it is missing or wrong, your legitimate mail starts landing in spam folders.
- DKIMDomainKeys Identified Mail
- A cryptographic signature added to every message you send, checked against a public key published in your DNS. It proves the message really came from your domain and was not altered on the way. SPF says who may send; DKIM proves who did.
- DMARCDomain-based Message Authentication, Reporting and Conformance
- A policy telling receiving providers what to do when SPF and DKIM fail — nothing, quarantine, or reject — and where to send reports about it. It is the record that turns the other two from signals into enforcement.
- TTLTime To Live
- How long other systems are allowed to cache a DNS record before checking again. Lower it a day before you change an MX record and the switch takes effect in minutes rather than hours.
Protocols
How mail actually moves, and what your mail client is speaking when it connects.
- SMTPSimple Mail Transfer Protocol
- The protocol that carries a message from one server to another, and from your mail client when you press send. It is old, it is plain text underneath, and every design decision in email inherits from it — including the fact that sender and recipient cannot be hidden.
- IMAPInternet Message Access Protocol
- The protocol a mail client uses to read a mailbox that lives on a server. Messages stay on the server, so the same mailbox looks the same on your laptop and your phone. This is what makes a mailbox portable between clients.
- POP3Post Office Protocol
- An older way of reading mail that downloads messages to one device and usually deletes the server copy. If you use more than one device, IMAP is what you want.
- Submission
- The port a mail client uses to hand a message to your provider for sending, as opposed to the port servers use to talk to each other. It requires authentication — your provider is doing this on your behalf, so it needs to know it is you.
- TLS and STARTTLS
- Two ways of encrypting a mail connection. Implicit TLS is encrypted from the first byte; STARTTLS begins in plain text and upgrades. Both are fine when enforced, and implicit TLS has fewer ways to go wrong.
Encryption and privacy
Words that get used loosely in marketing and mean specific things here.
- E2EEEnd-to-end encryption
- Encryption where neither provider can read the message, because only the two ends hold keys. It requires both ends to support it — which means mail arriving from an ordinary provider cannot be end-to-end encrypted, no matter what happens to it after it arrives.
- Zero-access storage
- Storage where the provider cannot read the contents because it does not hold the keys. It is a real property with a real cost: a server that cannot read a message also cannot search it, filter on it, or hand it to an integration. Ruber does this for Private mailboxes: the keys are derived on your device and the server never holds them. The cost is the one above — a Private mailbox cannot be searched on the server, and although IMAP still reaches it, no third-party client can decrypt what it fetches.
- Metadata
- Everything about a message that is not its contents: who sent it, who received it, when, and roughly how big it was. SMTP needs these to route mail, so no amount of encryption removes them. Any product implying otherwise is describing something that is not email.
- MTA-STSSMTP MTA Strict Transport Security
- A standard that lets a domain tell sending providers to refuse delivery unless the connection is properly encrypted and the certificate matches. It closes a downgrade attack that opportunistic TLS leaves open.
- TLS-RPT
- A record that asks other providers to send you reports when TLS connections to your servers fail. Without it, a downgrade or a broken certificate is invisible until somebody complains.
Delivery
Why a message that was definitely sent does not always turn up.
- Deliverability
- Whether your mail reaches the inbox rather than the spam folder. It is decided by the receiving provider using their own signals, so no sending provider can guarantee it — the honest promise is correct authentication and a clean sending reputation, not placement.
- Sending reputation
- The score a receiving provider keeps on the IP address and domain your mail comes from. It is shared: one account sending badly from a given IP affects everyone else sending from it, which is why bulk sending belongs on separate infrastructure.
- Bounce
- A message returned as undeliverable. A hard bounce means the address does not exist; a soft bounce means try later. Repeatedly sending to addresses that hard bounce is one of the fastest ways to damage a reputation.
- Greylisting
- A deliberate temporary rejection of a message from an unknown sender, on the theory that real mail servers retry and a lot of spam does not. It delays first messages from new senders by minutes.
Mailboxes and addresses
Terms that mean something specific in the context of an account here.
- Mailbox
- A real, separate account with its own storage, password and login. Distinct from an alias, which is why a mailbox counts against your plan and an alias does not.
- Alias
- An additional address that delivers into an existing mailbox. Useful for role addresses and for giving out a throwaway address you can retire, and it does not need its own login.
- Catch-all
- A rule that accepts mail sent to any address at your domain, including addresses that do not exist. Convenient, and it collects a great deal of spam, because a spammer guessing addresses always succeeds. Pointing it at a subdomain rather than the whole domain is what makes it usable — see wildcard identity.
- Wildcard identity
- A catch-all on a subdomain used deliberately: turn one on for shop.yourdomain and you can invent ikea@shop.yourdomain at the counter without configuring anything first. One address per company means a leak identifies who leaked it, and you can cut off that address alone. The wildcard works today; the part that offers to keep or block each new address as its first message arrives is being built.
- Smart and Private
- The two modes a Ruber mailbox can be in. Smart is standards-first and lets the server work on message contents; Private is built so it cannot. Mode is set per mailbox, not per account or per domain, and both are available. Search inside a Private mailbox and Private mail on the mobile app are still being built.