Why the forty-four-year-old protocol behind email cannot be secured by patching — and how QMail replaces it with mail that has no passwords to steal, no server that can read it, and a price on spam.
Written for investors and strategic partners evaluating the secure-communications market. No technical background is assumed.
Nearly every email sent today travels over SMTP, a protocol designed in 1982 for a few hundred researchers who all trusted one another. It has no built-in way to verify who sent a message, it exposes the envelope — and often the contents — to every server that handles it, and it makes sending free, which is why roughly half of all email traffic is spam. Four decades of add-ons (spam filters, sender-verification records, transport encryption) treat the symptoms; the flaws are architectural, and a protocol that must stay compatible with 1982 can never require what security demands.
QMail is a replacement, not a patch. It is an open-standard mail protocol built on RAIDA — a network of 25 independent servers that has operated continuously since 2016. In QMail, your address is a cryptographic certificate rather than an account, so there is no password to phish and a sender's identity is proven rather than claimed. Each message is encrypted and split into fragments stored on separate, independently operated servers, so no company — and no single subpoena or breach — can read your mail. Recipients set a price that strangers must pay to reach their inbox, which turns spam from a filtering problem into an arithmetic problem. And because the system uses no public-key cryptography at all, the mathematics that quantum computers are expected to break simply is not there to attack.
QMail is running software, not a proposal: client applications ship today for Windows, macOS, Linux, and Android; the protocol is published as a royalty-free open standard in draft; and the underlying network has nine years of continuous operation behind it. This paper explains the problem, the mechanism, and the business built on it — including the open questions a diligence team would ask.
Email's underlying protocol, SMTP, was standardized in 1982 — before the web, before commercial internet access, before the idea that a stranger might ever email you. It was built for a small academic community and assumes every participant is honest. That assumption is now the foundation of a criminal economy: in 2023 the FBI's Internet Crime Complaint Center logged $12.5 billion in reported cybercrime losses, with business-email compromise alone accounting for $2.9 billion.1 Five structural flaws explain why.
The "From" line of an email is ordinary text that the sender types. SMTP has no mechanism to check it. Retrofits exist — SPF, DKIM, DMARC — but they are optional, frequently misconfigured, and at best verify a domain, never a person. Every phishing attack ever sent depends on this single omission: the protocol cannot tell your bank from a forgery of your bank.
A sent email is never one copy. It lands on your device, your provider's servers, every relay along the route, the recipient's provider, and the recipient's device — and the protocol delivers it in readable form to each of them. Providers scan mail for advertising; governments collect it in bulk, as the 2013 PRISM disclosures documented.2 Even when the words are encrypted, the envelope is not: who wrote to whom, when, how often, and how much — metadata that by itself maps a person's relationships and routines.3
The encryption protecting email in transit rests on public-key mathematics — problems that are hard for today's computers and, per Shor's algorithm, easy for a sufficiently large quantum computer. Adversaries do not need to wait: U.S. cybersecurity agencies warn of "harvest now, decrypt later" campaigns that record encrypted traffic today to unlock it tomorrow.4 The response is a massive migration to new algorithms — NIST published its first post-quantum standards in August 2024,5 and the U.S. government estimates $7.1 billion to migrate federal systems alone6 — which replaces one mathematical bet with a newer, less-tested one.
Sending ten million emails costs about as much as sending one. As long as that is true, a response rate of one in a hundred thousand is a profitable business, and filters are locked in a permanent arms race they cannot win — spammers adapt faster than filters, and every false positive blocks mail that mattered. Computer scientists identified the fix in 1992: make sending cost something.7 Email has never been able to implement it, because email has no payment rail.
Your mail archive — and your identity, since your address doubles as your login everywhere — lives on servers owned by a handful of companies. Those companies can read it, can be compelled to hand it over, can suspend your account without appeal, and concentrate billions of users' mail into single targets: Yahoo's breach exposed all three billion of its accounts; the 2021 Microsoft Exchange attack compromised tens of thousands of organizations at once. Centralization is not a policy choice a provider can reverse. It is how SMTP-era email is built.
Each of these is a design decision, not a bug. A protocol that must remain compatible with every mail server built since 1982 can bolt security on, but can never require it — and attackers simply use the door that must stay open.
QMail is an open-standard, quantum-safe mail protocol developed under the Distributed Mail System project. It runs on RAIDA — the Redundant Array of Independent Detection Agents — a network of 25 independently operated servers, distributed globally, that has run continuously since 2016 as the authentication network behind the CloudCoin digital currency. QMail was designed against a simple standard: assume every intermediary is hostile, and make the mail safe anyway.
When you press Send, your QMail client — not any server — does the work:
Contrast this with SMTP, where a complete, readable message sits on the sender's provider, the recipient's provider, and every relay in between. In QMail there is no point in the network where the whole message — or even its subject line — exists in readable form.
Answers flaw 1 · anyone can claim to be anyone
A QMail address is not an account; it is a cryptographic certificate — a digital token whose ownership is verified by the RAIDA network. Each token carries 25 separate secrets, one per server, and no server ever holds another's. There is no username, no password, and no login page, which means there is nothing for a phishing site to steal: authentication is a proof your software performs, not a secret you type. The same mechanism makes the "From" line trustworthy for the first time — a sender's identity is cryptographically proven with every message, so a forged sender is not filtered out, it is structurally impossible.
Answers flaw 2 · the mail is a postcard
Because every message is encrypted and striped across independently operated servers, there is no provider that can scan your mail, no central archive to breach, and no single company to subpoena. Subject lines, attachment names, and previews — the fields SMTP exposes to every relay — travel as encrypted data that only the recipient's device can open.
Stated plainly: the recipient's chosen beacon server does see that a delivery occurred — sender, recipient, time, and size — which is a small fraction of what every SMTP relay sees, but not zero. Eliminating this residual visibility is on the protocol's roadmap, and the specification is candid about the boundary.
Answers flaw 3 · encryption with a shelf life
QMail's quantum safety does not come from new, exotic mathematics. It comes from an absence: the protocol uses no public-key cryptography at all. Keys are pre-distributed secrets shared between your token and each server, and all encryption is symmetric AES — the cipher NIST states will remain secure against quantum attack for decades, since Grover's algorithm offers "little or no advantage" against it.8 Shor's algorithm breaks the public-key handshakes in TLS, RSA, and conventional encrypted email; in QMail, that handshake never happens. While the rest of the industry migrates from one mathematical assumption to another, QMail removed the assumption. Wire encryption is AES-128 today, with AES-256 authenticated encryption specified in the standard and deployable to meet U.S. CNSA 2.0 requirements.
Answers flaw 4 · sending is free
Every QMail user publishes an inbox fee in the network's directory. People on your whitelist — friends, family, colleagues — write to you free. A stranger must attach postage, paid in CloudCoin, the zero-fee instant-settlement currency native to the network; the payment rail email never had is built in. A spammer who targets ten million inboxes must pay ten million fees before sending: junk mail stops being a filtering problem and becomes an arithmetic problem. The economics also invert who profits — a rejected phishing attempt still pays you its fee, a routine user might charge a cent, and a public figure can price their inbox at whatever their attention is worth, refunding senders whose messages they welcome. A free allowance keeps ordinary correspondence costless.
Answers flaw 5 · the rented room
QMail is an open standard, not a service. The protocol specifications are published under open licenses with a royalty-free patent grant, anyone may run a server, and your address is a bearer certificate you hold — not an entry in a company's database. No provider can suspend you, mine your archive, or hold your identity hostage, because there is no provider in that sense at all. The model is the one piece of internet infrastructure that has never had a catastrophic central failure: like the DNS root, QMail's trust is spread across independent operators rather than concentrated in any one of them.
QMail messages are encoded in the Compact Binary Document Format rather than HTML. Page layouts, fonts, and colors are referenced as two-byte codes into shared catalogues instead of being spelled out in verbose markup, so a styled message can be on the order of one percent of the size of its HTML equivalent, and a short note is a few dozen bytes. Two consequences matter commercially: servers handle an order of magnitude more mail per dollar of hardware, and — because CBDF documents are data, not code — tracking pixels, hidden scripts, and the entire class of malicious-email rendering attacks are technically impossible, not merely filtered.
Email caps attachments at whatever the smallest provider in the chain allows — usually about 25 megabytes, a limit inherited from the era when a whole message had to fit on one server, and the reason so much "email" actually travels as links to Dropbox or Google Drive. The QMail standard imposes no attachment limit at all. Because a message is already striped across many servers, a large file is simply more stripes: the format addresses objects with 64-bit sizes (beyond 4 gigabytes), total capacity is the sum of what the storage servers offer rather than any one machine's ceiling, and striping works in the sender's favor — a file spread across ten servers uploads and downloads roughly ten times faster than a single connection. Storage is metered in postage, so heavy users pay their way instead of being refused.
| SMTP email | QMail | |
|---|---|---|
| Sender identity | Typed text; forgeable | Cryptographically proven per message |
| Credentials to steal | Password + reset flows | None — no password exists |
| Where mail lives | Complete copies on providers' servers | Encrypted fragments across independent servers |
| Subject & attachment names | Readable by every relay | Encrypted; decrypted only on the recipient's device |
| Cost to spam | ≈ $0 per million messages | Recipient-set postage on every message |
| Quantum exposure | Public-key handshakes; harvestable today | No public-key cryptography to attack |
| Message size (styled) | Typically tens of kilobytes of HTML | On the order of 1% of the HTML equivalent |
| Attachment limit | ≈ 25 MB cap | None in the standard — striped in parallel across servers |
| Who can lock you out | Your provider, at its discretion | No one — the address is a bearer certificate |
Most quantum-safe communication projects are papers. QMail's unusual property is that its foundation predates its pitch:
Development is staged in public phases: Phase I (core striped mail) is complete; Phase II (quantum-safe key exchange, custom addresses, striping across up to 32 servers) is largely deployed; Phase III (full rich-document format and financial services) is targeted for 2027.
Email's business model is surveillance: the user is the product. QMail's business model is postage: attention and storage are priced, payments settle instantly at zero fee in the network's native currency, and the operating company earns revenue at several points of that flow. The streams are deliberately staged by maturity rather than projected as one hockey stick.
The streams reinforce one another: every address sale, subscription, and postage payment settles in CloudCoin, so each product line deepens demand for the currency that the same company issues — a flywheel in which the payment rail, unlike a card network's, costs the users nothing per transaction.
An investor education paper that hides its risks educates no one. Four points deserve scrutiny:
Email's five great problems — phishing, surveillance, quantum exposure, spam, and centralized control — are not failures of effort. They are the direct consequences of a 1982 design that no amount of patching can reach, which is why forty years and billions of dollars of add-ons have not fixed them. QMail is the first working system to attack all five at the root: identity as a certificate instead of a password, mail as encrypted fragments instead of stored copies, symmetric cryptography instead of quantum-vulnerable handshakes, postage instead of filters, and an open standard instead of a landlord — running on a network with nine years of continuous operation, with software you can download today.
To explore further: distributedmailsystem.com for the product and beta downloads, cloudcoin.org for the full protocol specifications, and raidagroup.com for the company behind the network.