Watch how it all works — Overview Video.
Your recipients' email servers must support TLS for this mode of easy encryption to work (Not many do) — LuxSci determines this automatically for you and falls back to other mechanisms as needed. See also: SMTP TLS: All About Secure Email Delivery over TLS
SecureLine users (WebMail and SMTP) can disable TLS-Only sending on a per-message basis (e.g. if you like TLS Only in general, but would like to use Opportunistic TLS + something more secure (Escrow, PGP, or S/MIME) for particular messages).
More Details — SecureLine TLS
More Details — SecureLine Escrow
More Details — SecureLine PKI
SecureLine integrates all of these methods, using the best choice for each recipient based on your sending preferences. In general:
| Security | TLS | Escrow | PKI |
|---|---|---|---|
* Use of Escrow with "Question and Answer" recipient verification protects the messages if you use well chosen questions and answers. Use of "SecureSend Login" recipient verification allows the recipient's password to be easily reset by anyone with access to the user's email account. This is why "Question and Answer" authentication can be more secure.
** Escrow with "Message Center" enabled technically allows LuxSci operations staff to unlock saved messages, as the system needs to be able to open any saved messages for the user. Escrow with Message Center off (the default) eliminates the possibility of anyone for except the individual recipients themselves to unlock their messages.
*** PKI-encrypted messages can never be opened by LuxSci operations staff unless you have "Escrowed" the password to your private key with LuxSci for auto-decryption or password-recovery purposes.
| Feature | TLS | Escrow | PKI |
|---|---|---|---|
SecureLine selects the encryption method to use separately for each recipient of each message. As a result, a single message to multiple people can employ many different encryption methods. SecureLine takes care of this all behind the scenes — in general, little or no sender interaction is needed.
For every recipient, SecureLine goes through the following list of possible encryption options, in order, and uses the first one available for that recipient.
| Encryption Option | Discussion | |
|---|---|---|
| SMTP TLS Only | TLS Only for delivery is used if:
a. TLS Only delivery is enabled account-wide or domain-wide
b. The recipient's email servers support TLS
c. The recipient is not excluded from TLS delivery by your administrator
d. The sender has not opted this message out of TLS Only use |
|
| PKI | PGP or S/MIME will be used for
delivery if the recipient is an active LuxSci user with a PGP and/or S/MIME certificate in his/her
LuxSci profile. Getting the public key and determining use of S/MIME vs PGP will be taken care of by SecureLine and the recipient's personal LuxSci preferences. |
|
| PKI or Escrow Question and Answer from Address Book data | SecureLine will look in the sender's address
books for pre-configured encryption information for the recipient. This could be a PGP or S/MIME
public key or an Escrow Question and Answer. The first entry with encryption information found is used. User Address Books are searched in the following order: a. Preferred address book for SecureLine data, if specified
b. All subscribed address books, if there are any
b. Default address book, if none are subscribed
|
|
| Escrow with SecureSend Login | If the 'SecureSend Login' mode of Escrow recipient verification is enabled for your account, this will be used. | |
| Escrow with SecureSend Login | If the recipient already has a SecureSend account, then the 'SecureSend Login' mode of Escrow recipient verification will be used. | |
| Escrow with Default Question and Answer | If there is a default Escrow Question and Answer configured on the per-account, per-domain, or per-user level for this recipient, then that will be used. | |
| Escrow prompts sender for a Question and Answer | When using LuxSci WebMail or Windows Outlook with the SecureLine Plugin, SecureLine can ask the sender to provide Questions and Answers as needed for new recipients. These can be auto-saved to the sender's address books for easy re-use. |
In cases where none of the first 6 options work and SecureLine cannot interact with the sender, SecureLine cannot send the message securely. The message will fail to send to this recipient and the preferred action to take in this case is followed (e.g. Send insecurely or send a bounce notice to the sender indicating the failure).
As long as "Escrow with SecureSend Login verification" or a default Question and Answer are provided, messages will always be able to be sent securely to anyone without sender input.
Book 1 in the LuxSci Internet Security Series.
Created by Erik Kangas, PhD
Get the HIPAA eBook
The servers are super fast, the WebMail responds quickly, and everything is secure - I couldn't be happier."
I am extremely satisfied with your security features and with the extent of knowledge of your support staff. You provide a solid, reliable service and also manage to continue to add more thoughtful features -- all at a reasonable price."
I just wanted to say that LuxSci is DEFINITELY the best hosting company I've ever used for email. They have real features, not glitz, especially in terms of security and unbelievable support! That is what I like here; keep it up!"
LuxSci is an exemplary choice...I'm paying for confidence and security a free email service can't provide."
Every time I needed support with LuxSci's Secure Email solution the technical staff at LuxSci found the solution very quickly. They always get to work on a ticket immediately. They always give a status update in the ticket system which also notifies via email. Opening and updating a support ticket is very easy. We are very pleased with the Secure Email product and the support team."
![]()
Tom W.
![]()
Kevin Rasmussen, Co-owner, Keo Scientific Ltd., http://keoscientific.com
![]()
Adam Kanis
![]()
John R.
![]()
Andy Groll, USAmeriBank




