Proton Mail switches to post-quantum encryption (and it's free)

Proton Mail offers a quantum-resistant encryption option, available on all plans including the free one. Must be enabled manually, but don't get your hopes up.

Proton Mail has just activated an option that protects your new emails against decryption by a future quantum computer. It’s available on all plans, including the free one, and you can enable it yourself. And it’s not just marketing. \

The Fact

On May 5, 2026, Proton pushed a new option into Proton Mail’s settings: « Enable post-quantum protection ». Once enabled, new emails you send are encrypted with a combination of classical plus post-quantum algorithm, a type of cryptography designed to resist even a quantum computer of tomorrow. Available on all plans, including free, which is rare enough in the industry to warrant mention.

The option is not enabled by default. You go to Settings, Encryption and keys, and check it yourself. Proton justifies this caution due to the still-experimental status in the external ecosystem.

The idea behind it is to counter what’s called « harvest now, decrypt later ». In plain terms: an attacker could intercept and store your encrypted emails today, unable to read them, hoping to decrypt them in ten or twenty years when a powerful enough quantum computer exists. Today’s classical encryption (RSA, elliptic curves) would crumble like a house of cards. Post-quantum is the insurance that even this scenario yields nothing to the attacker.

Why It Matters to You

Several things to know before you rush to enable it.

The protection applies only to new emails. Anything already in your mailbox, sent or received before enabling, remains encrypted as before. Proton says so: « Post-quantum protection applies to new encrypted emails going forward. It does not retroactively re-encrypt emails that are already in your mailbox, for now. » If your old emails have already been intercepted by someone, this option doesn’t change anything for them. The « for now » suggests a retroactive re-encryption is on the roadmap, but it’s not delivered yet.

The recipient matters. The best scenario is Proton to Proton, where both sides have post-quantum keys. If your correspondent is elsewhere (Gmail, a classic OpenPGP client, etc.), Proton falls back on the usual encryption for that send, which is the only reasonable thing to do while waiting for others to adopt the same standard.

Some friction. If you’re using Proton’s end-to-end encrypted forwarding, it’s temporarily incompatible with the new option. You choose one or the other for now. There’s also a slight performance impact on sending, barely noticeable on recent hardware according to Proton.

The Game-Changer Angle: Open Standard vs Silos

Proton isn’t the first email service to offer post-quantum. Tuta (ex-Tutanota) did so since 2024, with its own proprietary scheme. Apple deployed PQ3 on iMessage in February 2024. Signal did the same with PQXDH in September 2023.

Proton’s difference is that it does so on OpenPGP, the open standard others can adopt. Apple PQ3 remains locked in the Apple ecosystem, Signal PQXDH doesn’t leave Signal, and Tuta’s scheme is proprietary to Tuta. Proton, meanwhile, bets on standardization, announced collaboration with the Thunderbird project, so tomorrow your sovereign email client (Thunderbird, GnuPG, or another) can read and write post-quantum emails compatible with Proton without going through the Proton app itself.

That’s the sovereignty angle. An open standard is what prevents your communication security from depending on the whim of a single provider. Today in practice, interop is still largely Proton-to-Proton, the external ecosystem isn’t there yet. But the direction is set, and that’s what distinguishes this announcement from mere marketing.

What You Do Now

1. Go to Proton Mail, Settings, Encryption and keys, and enable « Enable post-quantum protection ». Read the warning banner (forwarding, etc.) before validating.

2. Keep in mind that it only protects your new sends. If you have sensitive conversations archived, consider sorting them out. Retroactive re-encryption is coming later, but for now, it’s pure conditional.

3. If your correspondent is also on Proton, encourage them to enable it on their end. Until both ends are equipped, the benefit remains partial.

4. If you’re using Proton Bridge with Apple Mail (see the dedicated article), ensure your Bridge is up-to-date, or new post-quantum emails might not be readable on the local client side.

Also See

Sources