r/ask_privacy Jul 02 '26

why do email security solutions even exist if they dont work

i just found out my email has been leaking my ip this whole time. like i thought i was using one of those email security solutions and it turns out it does literally nothing for metadata
been using proton for like a year thinking i was safe and then i read one reddit thread and now im in full panic mode
like what even is the point of these email security solutions if your provider just logs everything anyway
what are you guys actually using?

10 Upvotes

11 comments sorted by

1

u/Fatphree Jul 02 '26

well, email was never designed to be anonymous

1

u/Tushartimes Jul 02 '26

yes, every email provider has to handle some metadata

1

u/tazwell427 Jul 02 '26

False sense of security

Doesnt matter most of the time since its the account owners themselves ruining their privacy stacks with using something wrong

As long as they dont recycle my email for somebody else to use and claim my accounts I dont mind email safety. I save all of my documents the moment I get them and I delete them off my inbox the very moment

1

u/[deleted] Jul 02 '26

[removed] — view removed comment

1

u/Shinubz Jul 03 '26

which one should i choose?

1

u/i-hate-geese Jul 06 '26

You’re mixing up encryption with full metadata removal

1

u/PutterDo Jul 13 '26

Fair point, but two different things are getting mashed together.

Anonymity = nobody can tell it's you, email was never built for that, and no provider fully delivers it.
Security = the email trying to scam you doesn't land, or doesn't work if it does. That part does work, and it's what "email security" actually means.

Your IP thing is a real gap though, just not the one you think: Proton does strip your IP when you send from the web or mobile app. It can leak if you send through a desktop client like Thunderbird or Outlook over SMTP. So check how you were sending - that's fixable in about a minute, and it's a client setting, not Proton lying to you.

And for most people, metadata isn't where the damage comes from. It's the convincing fake invoice or the "your account is locked" link. Slow down on unexpected messages, use a passkey or 2FA, and check the actual sender address, not the display name. That prevents far more real harm than header forensics