In comparison
We compare FOLD only on properties that can be verified, and we link a source per column. Competitor columns as of June 2026; if a vendor changes something, this table changes with it.
| Property | FOLD | Apple Mail | Mimestream | Spark | Thunderbird | Outlook (new) |
|---|---|---|---|---|---|---|
| No extra cloud backend | Yes | Yes | Yes direct to Gmail | No Readdle cloud | Yes | No MS cloud |
| App Sandbox active | Yes | Yes | Yes | Yes | Limited standard install is not sandboxed | Yes |
| OpenPGP native | Yes Ed25519, Curve25519 + RSA | No | No | No | Yes | No |
| S/MIME native | Yes | Yes | No | No | Yes | Yes |
| DKIM verified in the client | Yes | No | No | No | Add-on not in core | No |
| Any IMAP provider | Yes | Yes | No Gmail only | Yes | Yes | Limited forced through MS cloud |
| Open source | No | No | No | No | Yes MPL 2.0 | No |
Sources: Apple Platform Security · Mimestream supported accounts · Spark privacy explained · Thunderbird · New Outlook cloud sync (Cybernews, 2023).
The DKIM row means independent client-side verification (recomputing body hash and signature), not merely displaying the server's Authentication-Results header. As of 06/2026.
Dependency policy
A third-party dependency is accepted only when all four criteria hold: it provides a primitive we cannot build correctly ourselves · it comes from a trustworthy source · it is auditable · it is listed in the table below.
Engine and interface use Apple system frameworks only. The direct download adds one updater to the app shell.
| Allowed | |
|---|---|
Foundation | Apple SDK. Streams with TLS carry IMAP and SMTP, including STARTTLS on the live connection. |
CryptoKit | Ed25519, X25519, AES-GCM, SHA-2, HKDF. |
Security | Keychain, SecTrust, RSA, CMS for S/MIME on macOS. |
CommonCrypto | AES block cipher for OCB and CFB modes. |
AuthenticationServices | ASWebAuthenticationSession for OAuth. |
SQLite3 | System SQLite through a thin Swift wrapper. No GRDB, no SQLite.swift. |
WebKit | Hardened mail rendering with JavaScript off and a strict content policy. |
os.Logger | Apple SDK. |
| Sparkle | Direct download only, in the app shell: signed updates. Not part of engine or interface. |
| Excluded | |
|---|---|
swift-crypto | Cross-platform twin of CryptoKit, not needed on Apple platforms. |
libetpan, MailCore | C wrappers; we want auditable Swift. |
| OpenPGP libraries | Our own modern-first implementation instead of a large legacy surface. |
SwiftData, CoreData | Not built for 500,000 messages per mailbox; direct SQLite instead. |
| Third-party JSON, logging, networking | Foundation and os are enough. |
Crypto strategy
Asymmetric cryptography, AES-GCM, HKDF, SHA-2 and Curve25519 come from CryptoKit and Security.framework, block ciphers from CommonCrypto. Where Apple offers no primitive, FOLD implements it and verifies it byte for byte against reference implementations: Argon2id and BLAKE2b for Fortress Mode, AES-OCB for OpenPGP, PBKDF2 for SCRAM. Authentication tags and SCRAM server signatures are compared in constant time.
OpenPGP: modern by default, legacy contained
Two-part doctrine. Producing: version 4 keys with Ed25519 signatures and Curve25519 key agreement (ECDH), AES-256 with an integrity check (SEIPD v1 with MDC), SHA-256/512. Reading and writing to existing recipients: additionally RSA in Security.framework, and for reading GnuPG's OCB mode; encrypted data is accepted only with a valid integrity check, otherwise the message is rejected (EFAIL). Not supported yet: version 6 keys and AEAD encryption (SEIPD v2) from RFC 9580. Permanently rejected: CAST5, IDEA, Blowfish, 3DES, MD5 and SHA-1 signatures, and encrypted data without integrity protection. Private keys rest S2K-protected (AES-256) in a keychain vault bound to the device. Checked against real GnuPG.
S/MIME
On macOS through the CMS interfaces of Security.framework, on iOS through a platform-neutral CMS implementation on SecKey and SecTrust: sign, verify, encrypt and decrypt. A .p12 identity and recipient certificates (.cer, .pem, .der) can be imported, certificates from verified signed mail are collected, trust runs through SecTrust. A valid signature whose certificate address does not match the sender is shown as untrusted. On iOS, recipient certificates are collected from verified signed mail; importing them by hand follows. Checked against openssl-signed fixtures.
TLS defaults
Strict certificate and hostname validation with no override path. TLS versions follow Apple's platform defaults. STARTTLS: FOLD connects, requests the upgrade and aborts if the server refuses or fails; bytes buffered before the upgrade are treated as a man in the middle and end the connection. Unencrypted IMAP and SMTP are refused outright. Certificate pinning per account is planned, not available yet.
Authentication
Passwords and OAuth tokens live only in the Keychain with kSecAttrAccessibleWhenUnlockedThisDeviceOnly, never in UserDefaults or plists. OAuth runs through ASWebAuthenticationSession with mandatory PKCE (S256) as a public client: no client secret in the binary, concurrent token refreshes are coalesced. SMTP prefers SCRAM-SHA-256 with server signature check, then CRAM-MD5, PLAIN and LOGIN; OAuth accounts use XOAUTH2. Optionally, after a separate consent, IMAP and SMTP passwords can be mirrored through the end-to-end encrypted iCloud Keychain. OAuth tokens, Fortress and PGP secrets never leave the device.
Logging policy
No personal data, message content, subjects, addresses, tokens or cookies in logs, also in debug builds, enforced by lint rules that fail the build. Allowed: connection events (host, port, TLS version, latency), protocol state, error categories. The activity window on the Mac, with sync steps and the SMTP transcript, is kept in memory, capped at 300 entries and never written to disk.
Sandbox and Hardened Runtime
macOS: App Sandbox and Hardened Runtime. Entitlements: outgoing network connections, user-selected files, one keychain access group and the iCloud container for the optional sync; incoming connections are disabled. No library-validation bypass. iOS: system sandbox, keychain group and iCloud container, no App Groups. The direct download, not yet public, adds a single exception so that its updater can install updates. Distribution through Developer ID on macOS and the App Store.
Fortress Mode
Opt-in per account for application-level encryption. Argon2id over your passphrase and a 32-byte salt kept in the Keychain (m = 64 MiB, t = 3, p = 4) derives a 256-bit master key that lives in memory only; each account gets its own key via HKDF-SHA-256. AES-256-GCM seals the text columns of the header database and the message cache; full-text search is limited for Fortress accounts. Auto-lock wipes the key after inactivity, and when the app goes to the background if the app lock is on. Argon2id and BLAKE2b are our own implementations, verified against RFC 9106 and the reference tool.
What Fortress is not
Not a replacement for OpenPGP or S/MIME: those protect mail on the wire, Fortress protects the local copy. No defence against a compromised kernel or operating system. Not an anonymising mode: IMAP metadata still tells the server who you write with.
Threat model
Defences are mapped against MITRE ATT&CK (26 techniques) and MITRE D3FEND. For every technique the FOLD mitigation is named; for input handling and rendering (spear-phishing attachments, MIME bombs, polyglot files, EFAIL-style exfiltration) also the test that covers it.
Test strategy
Swift 6 strict concurrency and ExistentialAny at compile time. More than 3,000 automated tests as of 2026-09-22. Address, Thread and Undefined Behavior sanitizers run as local release gates before every push and release; there is no hosted CI, by decision. A regression suite replays historic mail-client CVEs (EFAIL, BadWinmail, iOS Mail heap overflows). Five libFuzzer targets cover MIME, encoded words, addresses, header blocks and CMS, and every test run replays the corpus with 3,000 mutations.
Coordinated disclosure
Found a flaw? Write to security@datargo.com. We confirm within 72 hours and ship fixes with credit. PGP key on request; the contact is also published in /.well-known/security.txt (RFC 9116).