A fast, familiar mail client on top of a protocol that knows who everyone is. Your team composes, replies and searches like they always have; the identity, encryption and custody guarantees live underneath, where nobody has to think about them.
Compose, reply, search, folders, labels — the inbox your team already knows. Every message between DMCN inboxes is encrypted on the sender's device and opened only by the recipient.
Mail from a verified-but-unknown sender waits in a pending queue showing who's writing — identity and subject, never the body — until someone chooses to trust them. Content-based manipulation never gets to render.
The search index lives on the device, not on our servers. We couldn't read your team's search terms if we wanted to.
Device pairing brings an account to a new machine with a short verification code — the keys travel sealed, and nothing about the process is visible to us.
Mint each mailbox on your domain before anyone squats it. Role addresses — admin@, billing@, support@ — are reserved and can't be claimed by self-service.
Pairing doubles as identity proofing: your admin reads a short code with the employee, and the account lands on their devices. No passwords to distribute, no email-a-link ceremony to phish.
A lost or stolen device is re-paired by your admin the same way, in minutes. Recovery never routes through us and never weakens the encryption — there is no back door to abuse, including ours.
Rotation-as-lockout: the departed employee's key is tombstoned first, so every device they hold goes dark immediately — then the mailbox is re-keyed and work continues. Provable, not procedural.
During the design-partner phase these operations run with us as your managed service; a self-serve web admin console is on the roadmap, and design partners are shaping it.
Legacy mail is checked against real SPF, DKIM and DMARC at the bridge, and delivered with a signed verdict — Verified, Unverified or Suspicious legacy sender — that your team's client verifies before showing a trust badge.
Outbound legacy mail is DKIM-signed with SPF, DKIM and DMARC fully aligned — the reputation work your IT team currently babysits, done for you. Replies thread correctly on the other side.
Mail between DMCN inboxes goes point to point, end-to-end encrypted, and never crosses the bridge. Every supplier or customer who adopts DMCN upgrades that channel automatically.
Being honest about the edges: mail crossing the bridge to or from legacy email is decrypted at the bridge and protected in transit (TLS), like all standard email today — it is not end-to-end encrypted. End-to-end encryption applies between DMCN inboxes — and if you want the bridge out of our hands entirely, you can run your own.