Hi! We're building Flectar Mail, an open-source, local-first email client written in Rust.
One of the main goals is to keep the architecture small, native and understandable rather than embedding a browser runtime. Flectar Mail uses no WebViews at all, including for rendering HTML email. Email HTML/CSS is rendered through a Rust-native pipeline, scripts inside emails are not executed, and remote images are blocked by default to reduce tracking.
Some of the privacy/security-related features already available:
- Local-first mail and calendar storage with offline access
- No WebViews or embedded browser engine
- No execution of email scripts
- Remote images blocked by default
- Desktop OpenPGP/MIME signing and encryption using GnuPG 2.x
- Required encryption can block sending when recipient keys are missing or invalid
- Protected drafts remain local until Send
- Credentials stored through the platform’s secure credential storage
- IMAP / SMTP / JMAP, CalDAV and CardDAV
- Gmail, Outlook and Microsoft 365 support
- Account-specific signatures, including separate defaults for new messages and replies
- AGPLv3 open source
- SHA256 checksums and signed build-provenance attestations for releases
- As little as ~20 MB RAM in lighter workloads
The HTML renderer is probably the most unusual part. We use Blitz rather than Chromium/WebKit, which keeps the application fully native and gives us a considerably smaller browser-related attack surface by design. It is also currently the most experimental part of Flectar Mail, so compatibility with particularly complex email HTML is still improving.
OpenPGP currently works on desktop through an installed GnuPG 2.x. S/MIME and mobile OpenPGP are not implemented yet.
The project is still alpha, and our official Google and Microsoft OAuth applications are going through verification. Preview builds therefore currently require your own OAuth registration for those providers, while regular IMAP/JMAP accounts can be used directly.
We'd be especially interested in feedback from this community on the security/privacy model and anything you think we should be considering as the project develops.
GitHub: https://github.com/flectar/mail
https://www.reddit.com/gallery/1wgnx9d
Source: r/PrivacySoftware · by /u/flectar
