email is postcards with forty years of legacy. sender, recipient, subject and timestamps travel in clear text by design, relayed and stored by machines you do not control. this guide is about taking back what can be taken back, in order of leverage: own the address, pick a provider that is not an ad company, and encrypt with pgp wherever the other side can. and it is honest about the ceiling, because a false sense of safety is worse than none.
the single most sovereign email move is not a provider, it is your own domain. addresses on someone else's domain belong, in practice, to that someone. lose the account, get banned, or watch the provider fold, and every login tied to that address goes with it. addresses on your domain move with you. change provider tomorrow, keep every address, and nobody can take them away. a domain also gives you a catch-all, so anything@yourdomain just works. one throwaway address per site, invented on the spot, and when one starts drawing spam you know exactly who leaked it and you kill it.
the practical checklist: register at a registrar that includes whois privacy (you did exactly this for the domain serving this page), point mx records at your provider, and set spf, dkim and dmarc so your mail authenticates properly. one honest caveat carries over from opsec. a personal domain is one very linkable identifier. it is right for your durable, real-name identity, and exactly wrong for a pseudonymous one, which should live on a provider's shared domain, hidden in the crowd.
pick one whose business model is not reading your mail, then know precisely what each choice trades.
the honest limit stands for all three. the moment you write to someone on gmail without encryption, a copy of that message lives on google's servers anyway. an encrypted mailbox protects your archive and your profile, not the wire.
for email itself, pgp (openpgp, gpg) is the only end-to-end encryption that works across providers, and on a site called paranoiaprivacy it deserves a real setup, not a footnote. the modern path is far less painful than its reputation:
gpg if you prefer the command line, and for real rigor keep the private key on a hardware token (yubikey, nitrokey) so no malware can copy it.keys.openpgp.org, or wkd on your own domain so mail clients discover it automatically, which pairs beautifully with the domain section above.and the limits, because they shape how you use it. pgp encrypts the body and attachments only. subject lines, sender, recipient and timing stay in clear, so the social graph leaks even when the content is sealed. there is no forward secrecy. one long-lived private key protects your whole archive, and a key compromised in 2030 decrypts everything ever sent to it. and it only works when both sides play, which outside security-minded circles is rare. hence the working rule this wiki stands by: mail that must be mail gets pgp. conversations that matter move to a messenger built with forward secrecy and metadata protection. that split is not a downgrade of pgp, it is using each tool for the job it is actually good at.
running your own mail server is the logical endpoint of sovereignty, and stacks like mailcow or mail-in-a-box make the setup itself manageable. the hard part is not installation, it is deliverability. the big providers distrust small ips, reputation takes months to build and one blocklist entry to lose, and you become your own 24/7 postmaster. do it if the ops appeal to you and your threat model justifies holding the mailbox yourself. for most people, own domain plus a privacy provider captures nearly all the sovereignty at a fraction of the cost. both are legitimate answers, as long as the choice is conscious.
if you skip the domain, dedicated aliasing services give you the per-site address trick anyway. simplelogin (owned by proton) or addy.io generate unlimited forwarding addresses, killable one by one. same benefits, one more party in the loop.

.:: eof ::.