When something looks wrong
The problems people actually hit, what causes each, and how to tell a fault from a real warning.
No banner appears at all
In the browser plugin. Reload the page. The plugin attaches to Gmail and
Outlook on the web only, and only on the mail view — not on a printed message or a pop-out
window. Check the plugin icon is not showing as locked: it forgets your key when the browser
closes, and asks for your passphrase again.
In the desktop application. It tags messages in your mail program rather
than drawing banners. Look for the ProtectMyMail tags or labels on the message. If nothing is
tagged, the inbox watcher may not be running — it only starts after you unlock the app,
because it needs your mail password to connect.
Everything says "signed, but the address is unconfirmed"
Two different causes, and it is worth knowing which:
- The sender has not confirmed their mailbox. Common, and their side to
fix — it takes two minutes.
- Your plugin cannot reach the network. Then it cannot check who is
allowed to confirm mailboxes, and it deliberately shows less rather than guessing. A
badge it cannot justify is worse than no badge.
To tell them apart: if every sender is suddenly unconfirmed, including ones that
were verified yesterday, it is the connection, not them.
My own message is reported as altered
If you send something and the recipient is told it was altered, the usual causes are:
- A mailing list. Lists rewrite messages as they pass through — adding a
footer, changing the subject. That genuinely alters the text, and the check is
correctly reporting it. Signing is not much use for list traffic.
- A gateway that "improves" mail. Some corporate filters rewrite links
or append disclaimers. Same story: the message really did change.
- An old plugin on one side. If one side is several versions behind, the
two may disagree about what exactly is signed.
A message altered by a mailing list and a message altered by an attacker look identical
from the outside, which is why the warning does not try to distinguish them.
It says my message has no plain-text part
Your mail program is sending HTML only. What gets signed is the plain-text version, because
that is the one every reader can reproduce — so with no such version, no signature can be
made that anyone could check, and the message is sent unprotected rather than mis-signed.
The fix: set your mail program to send plain text alongside HTML. In
Outlook and Thunderbird this is the default; if it has been changed, it is under the message
format settings.
Automatic protection stopped working
- The app is locked. It forgets your mail password when locked, so it
cannot reconnect. Unlock it.
- Your provider needs an app password. Gmail, iCloud, Yahoo and Fastmail
do not accept your normal password from another program. The app warns about this when
you set it up; if you skipped past it, generate an app password in your provider's
security settings.
- Your mail program was updated and reset its outgoing server. Check it
still points at the local address the app shows.
Note that mail keeps going out regardless. If protection fails, the message is relayed
unchanged rather than held — you may lose the protection on a message, never the message.
I get a "new key" warning from someone I know
Not a fault. It means what it says: they are writing with a different key than before. New
laptop, restored phrase — or a taken-over account. Ask them, through some channel that is not
that mailbox. The warning lasts thirty days.
Windows or macOS refuses to open the download
The files are not code-signed yet. On Windows: More info → Run anyway. On
macOS: right-click → Open. Do this only if you are confident where the file came
from — the warning exists for good reasons and we would rather not talk you out of it.
Nothing here matches
Open an issue on GitHub with what you
did, what you saw and what you expected. There is no telemetry in any of the clients, so a
problem nobody reports is a problem nobody knows about.
← All documentation