Back to sift.mx

Security

Security, without vague promises.

sift.mx protects forwarded email with authenticated intake, encrypted quarantine storage, short retention, and strict separation between senders and your private inbox.

Last updated July 30, 2026

Our trust model

sift.mx is a trusted forwarding intermediary. It is not end-to-end encrypted or zero-knowledge. Our mail worker must decrypt a message inside our controlled infrastructure to parse and forward it. Authorized operators with production key access could technically decrypt quarantined mail.

We make that limitation explicit because “we cannot read your email” would not accurately describe how forwarding works today. Our goal is to minimize where content exists, who can reach it, and how long it is retained.

What happens to a message

  1. Cloudflare Email Routing receives the message and passes it to the sift.mx mail worker.
  2. sift.mx checks sender authentication, including SPF, DKIM, and DMARC results, plus loop and rate-limit controls.
  3. The complete message is encrypted with AES-256-GCM before being stored in the private quarantine bucket.
  4. Sender rules determine whether the message is blocked, delivered free, or held until the cover is paid.
  5. For delivery, the mail worker decrypts the message in memory, prepares the private forward, and sends it to the verified destination inbox.
  6. Delivered content is removed from quarantine storage. Unpaid content expires within seven days.

What we protect

Your private destination

Your forwarding address is encrypted in our database and is not disclosed to senders or exposed on payment pages. Replies use opaque sift.mx addresses so normal correspondence can continue without revealing your private inbox.

Quarantined content

Raw message bodies and attachments are encrypted at rest. The member dashboard shows sender and subject metadata for a held message, but it does not expose the quarantined body or attachments.

Sensitive identifiers and tokens

Sender addresses, forwarding addresses, subjects, and contact rules are encrypted where appropriate. Challenge, verification, and reply tokens are stored as one-way digests rather than reusable plaintext tokens.

Retention and deletion

  • Unpaid quarantined message content expires within seven days.
  • Successfully delivered content is removed from quarantine storage as part of delivery.
  • Blocked, deleted, expired, and other terminal content is removed by the scheduled purge, normally within an hour.
  • Delivery metadata, authentication results, financial records, ledger entries, and audit events may remain for security, reconciliation, and legal purposes.
  • Reply tokens expire after 90 days; payment challenge tokens expire after 72 hours.

Accounts and abuse controls

sift.mx supports passwordless magic links, optional Google sign-in, session protections, and two-factor authentication. Changing a forwarding destination requires a two-factor step-up. Message and quarantine actions are scoped to the recipient account.

Inbound mail is screened for authentication failure, loops, backscatter, duplicate messages, invalid aliases, and excessive send rates before it can reach a recipient.

Payments stay separate from content

Stripe receives the purchase amount, credit package, and an internal payment reference. sift.mx does not send Stripe the message body, attachments, private destination inbox, or contact rules. Signed Stripe webhooks—not browser redirects—are the source of truth for settlement.

Infrastructure we rely on

sift.mx uses Cloudflare for email routing, workers, encrypted object storage, queues, and observability; Neon for PostgreSQL; Stripe for card payments; and Google only when a member chooses Google sign-in. These providers operate under their own security and privacy practices.

Report a security concern

If you believe you found a vulnerability or confidential-data issue, email hello@sift.mx with enough detail for us to reproduce it. Please do not include live message content, credentials, or payment data in the report.