Two modes, and why neither one is the upgrade
Ruber has two mailbox modes and no opinion about which one you should pick. Here is the trade-off, including the parts that do not flatter us.
Every mailbox Ruber runs today is a Smart mailbox. The mail plane can read message contents, and that is not an oversight — it is the thing that makes server-side search work, that lets a filter act on a message body, that allows an integration to be handed something other than ciphertext. Standards-compatible email is readable email. Any provider telling you otherwise has either changed what the word means or is describing a client rather than a mailbox.
Private is the other answer to the same question. It is being built so that protected contents are encrypted for the account holder rather than available to our servers, which means we cannot search them, cannot filter on their contents, and cannot hand them to anything. That is the same property doing its job, viewed from two sides.
Neither one is the upgrade
The temptation, once you have built two modes, is to sell one as the serious choice and the other as the convenient one. We are trying hard not to. A shared support inbox that four people search every day is not doing security wrong by being Smart — it is doing exactly what a shared inbox is for, and moving it to Private would break it while protecting nothing that matters.
The reverse holds too. A mailbox carrying contracts does not need full-text search across three years of history more than it needs the property that we cannot read it.
So mode is set per mailbox rather than per account or per domain. One company runs both, because the addresses do different jobs.
What encryption does not do
Two things get claimed for encrypted mailboxes that are not true of any of them, and they are worth saying plainly because we would rather you heard them from us.
- Mail arriving from outside cannot become end-to-end encrypted after the fact. A message from Gmail crossed the internet as ordinary SMTP before it reached us. Encrypting it on receipt protects it from that point onward and is worth doing — it is not end-to-end, and calling it that would be a lie about where the message has already been.
- Encryption covers content, not metadata. Sender, recipient, timestamps and approximate size stay visible in both modes, because SMTP needs them to route a message at all. No mailbox design removes them.