SecureMail is a security-focused email client for Ubuntu Touch.

Mail is read live from your IMAP server. SecureMail does not keep an offline mailbox, local message database or autosaved drafts. If IMAP is unavailable there is no cached email to display.

The idea of SecureMail is that if you loose access to your phone, you can reset your IMAP/SMTP password on the server side. Doing so will render the app useless. Without having to relay on things like a remote device wipe action. Since no email data is stored by SecureMail, no data can be exfiltrated. Remember that Ubuntu Touch does not have full disk encryption. 

This app is not meant to be a perfect rendering email-client, it is meant to get daily stuff done on the road. It also does not support 'modern authentication' via OAuth. If you just want your Gmail/Outlook email to work, use Dekko instead. This app is known to work with Postfix/Dovecot and Stalwart. Expect many updates as making an email client is hard.

* If someone knows how to implement copy/paste so I can select parts of the received emails, please let me know!!!

Your IMAP and SMTP account details are stored in an AES-256-GCM encrypted vault protected by a SecureMail password. Enter that password when SecureMail starts. Suspend, wake and resume do not ask again while the app process remains open. Setup can optionally be imported from a JSON file selected through Content Hub; because that source file contains plaintext secrets, remove or separately protect it after import.

Features:
- IMAP and SMTP with TLS / STARTTLS
- encrypted on-device credential vault
- optional JSON account setup import through Content Hub
- plain-text safe rendering of HTML mail with user-clickable external links
- receive attachments in memory and explicitly save arbitrary types through File Manager via Content Hub
- send attachments without keeping a local draft store
- To, Cc and Bcc recipients
- unread messages grouped at the top with blue marker/bold styling plus manual Mark as read / Mark as unread
- purple attachment indicator in the message list without downloading bodies
- safe UID-specific deletion of the currently open email
- IMAP-backed email search without a local search index
- attached .eml messages rendered inline; multipart alternative plain-text and sanitized HTML representations are both retained
- Contacts-only Content Hub picker and in-memory recipient autocomplete without unrestricted address-book permission
- server-side Sent copy using IMAP APPEND after SMTP send
- dark and light themes
- confined app: networking + Content Hub import/export only
- no tracking, telemetry or ads
- failed IMAP/SMTP connections emit a redacted connection trace to the system log for diagnosis; credentials and mail content are not logged

SecureMail was vibe coded using AI. Source code and security design notes are included in the project README.

License

MIT No Attribution

Copyright 2026 Barry de Graaff

Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.

