Secure email (CORA encryption)

In the app: Compose › Secure

A secure email is encrypted with CORA before it leaves your device. Your email provider, and anyone else who gets a copy of the message, sees only a short notice and a block of scrambled text. Each secure email gets its own brand-new key.

Important: a PIN reset gives you 3 months to recover your secure emails. The keys of the secure emails you send are protected by your multi-device PIN. If you ever reset the PIN, goCORA keeps your old security key for 3 months only. During those 3 months you can make your older secure emails readable again (often automatically — see After a PIN reset). After 3 months the old key is deleted for good, and secure emails that weren't recovered can never be read again — by you or anyone else.

Before you start

Sending a secure email

  1. Start a new message, a reply or a forward (Compose).
  2. Tap Secure in the toolbar. It is off for every new message. When it's on, a lock appears, the banner "This message will be encrypted with CORA" shows above the message, and the Send button becomes Send Secure. Tap Secure again to turn it off.
  3. Write your message as usual and tap Send Secure.

What the recipient sees

The message starts with this notice, followed by the encrypted block:

This is an encrypted email that requires the goCORA app to decrypt.
-----------------------------------------------------------------------------

-----BEGIN CORA MESSAGE-----
Key-Id: …
(encrypted text)
-----END CORA MESSAGE-----
Coming soon: recipients who use goCORA will be able to ask your goCORA for the key and read the message. Today, a secure email can be read only on the device that sent it. Recipients who open it in goCORA see "Its key isn't on this device yet; requesting it from the sender is coming soon."

Reading a secure email

Open the message (for example in your Sent folder). goCORA recognizes the encrypted block, decrypts it and shows the banner Encrypted with CORA above the text. To decrypt, goCORA needs:

The key of each secure email is protected twice: by this device and by your multi-device PIN. Someone who copies the device's files without your PIN, or who learns your PIN without the device, still can't read the message. A backup account uses the same PIN, so it can read them too.

After a PIN reset: recovering older secure emails

Changing your PIN keeps everything readable. Resetting it (when you've forgotten it) creates a new security key, so secure emails sent before the reset can't be read until goCORA moves their keys to the new one. Before you reset, goCORA tells you how many secure emails on that device depend on the current key.

There are two ways to recover them, both within 3 months of the reset:

  1. Automatically. If the PIN was reset on another device, a device that still remembered the old PIN recovers its own secure emails by itself as soon as you enter the new PIN there. goCORA says "goCORA recovered N secure email(s)…". So after a reset, open goCORA and enter the new PIN on each of your devices — the sooner the better.
  2. With your old PIN. When automatic recovery isn't possible, the goCORA account page shows, in orange, how many secure emails are still protected with the old key, the last day you can recover them and how many days are left. Tap Recover older secure emails and type the old PIN.

Opening such a message before it's recovered shows: "This secure message is protected with your old security key… Recover it on your goCORA account page with your old PIN." After the 3 months, the account page says they can't be read any more.

Changed your PIN, then forgot the new one? When you change the PIN, the old PIN keeps working for recovery for only about 4 hours. If you then reset the PIN before a device has been opened with the changed PIN, that device's secure emails can be recovered only with the changed PIN. That's why goCORA asks you, after a change, to open goCORA on your other devices soon.

Coming soon: keeping a received secure email

When recipients can read secure emails, goCORA will also let a recipient save a received secure email in one of two ways:

This page will be updated when that's available.