Your recovery phrase
Twelve words. They are not a password you can reset — they are the identity itself.
What it is
When you first set this up, you are shown twelve ordinary words in a specific order. Every
key you have is calculated from those words: the key that signs your mail, and the key that
opens mail sealed to you.
The words are not stored anywhere except by you. Not on our servers, not on the network,
not in your mail account. That is the point — but it also means the responsibility genuinely
sits with you.
Nobody can reset it. There is no "forgot my phrase" link and there
cannot be one. If we could recover your identity, so could anyone who convinced us they
were you, and the badge would be worth nothing. Lose the phrase and you lose the identity.
What to do with it, right now
- Write it on paper. Not a photo, not a note in your mail account — the
one place it must not be is inside the thing it protects.
- Put it where you keep important documents. A drawer at home is fine.
A safe is better.
- Consider a second copy somewhere else — with a lawyer, in another
building. A phrase that exists in exactly one place is one flood away from gone.
- A password manager is acceptable if you already use one seriously,
with its own strong master password and a recovery route you have tested.
What not to do
- Do not e-mail it to yourself.
- Do not photograph it with a phone that backs up to a cloud you have not thought about.
- Do not type it into any website. No legitimate page will ever ask for it, including
this one. If a page asks, it is stealing it.
The passphrase is a different thing
The application also asks for a passphrase. That is a lock on the settings file on
this computer — the mail server details and, if you use automatic protection, your
mail password. It is local, and it is not your identity.
| Recovery phrase | Passphrase |
| What it is | Twelve words, shown once | Something you choose |
| What it protects | Your identity and your keys | The settings on one computer |
| If you lose it | Identity gone; start again with a new one | Re-enter your recovery phrase and set it up again |
| Can it be changed | No | Yes |
A new computer, or a second one
Install ProtectMyMail, choose "I already have a recovery phrase", and type in the twelve
words. That device now has the same identity: it signs as you, and it can open mail sealed to
you. Nothing needs to be transferred and there is nothing to sync.
If you lose the phrase
Two things happen, and it is worth being clear about both.
- Mail sealed to your old key cannot be opened again. Not by us, not by
the network. The mathematics does not have a back door and we did not build one.
- Your outgoing mail can be re-established. Create a new identity and
confirm your mailbox again. Everyone who writes to you will see the
new key warning for thirty days — which is correct, because from the outside a
new laptop and a stolen account look identical, and they deserve to be told.
If you think someone else has it
Create a new identity immediately and confirm your mailbox again. The key change is
published, and everyone you correspond with is warned for thirty days that your key changed.
Then tell the people who matter, through a channel that is not e-mail.
Be aware of the honest limit here: anything already sealed to the old key stays readable
by whoever holds it. Rotating the key protects the future, not the past.
← All documentation