Gravbox is engineered from the ground up to guarantee strict DNS authentication, TLS 1.3 in-transit encryption, zero ad-scanning, and encrypted BYOK API key storage.
Domain spoofing is the #1 vector for email phishing. Gravbox generates unique 2048-bit DKIM cryptographic keys per custom domain, verifies strict SPF policies, and provides automated status monitoring to ensure your emails deliver reliably into the primary inbox.
All webmail sessions, SMTPS client connections, and server-to-server email transmissions are strictly protected using TLS 1.3 transport encryption with modern cipher suites. Unencrypted plaintext mail transit is rejected by default.
When you connect your OpenAI, Gemini, or Groq API keys, your keys are encrypted at rest using AES-256-GCM authenticated encryption. Keys are never logged in plaintext or shared with any third party, and API requests execute directly with your provider.
Unlike free consumer webmail services, Gravbox never scans or indexes your mailbox contents for advertising or behavioral profiling. Your emails, attachments, and user communications remain 100% private and confidential.
Real-time server-side filters analyze sender reputation, spam bot signatures, and malicious attachments before reaching inbox folders.
Mail processing services execute in isolated server containers, limiting lateral threat movement and protecting data boundaries.
We adhere to responsible vulnerability disclosure policies. Security researchers can contact our team at support@gravbox.com.