Private Email Migration with Proton and SimpleLogin
The alias hides the mailbox, not the routing relationship. SimpleLogin keeps the Proton address from the sender and supports replies through a reverse alias, but it must process the routing relationship and normal email metadata remains visible.
Data behind this diagram
| Stage | Verify condition |
|---|---|
| Create Proton account | Fresh private-window sign-in works with the stored credential |
| Secure recovery | Authenticator, offline recovery code, recovery phrase, and an independent recovery method are tested |
| Attach SimpleLogin | Proton mailbox is verified and a test alias receives mail |
| Create aliases | Each first account class has a distinct alias that forwards only to Proton |
| Test reverse alias | Recipient sees the alias, not the Proton address, and a reply returns through SimpleLogin |
| Import old mailbox | Inbox, Sent, custom-folder samples, contacts count, and import errors are recorded |
| Forward and update | Mail to the old inbox arrives once and each critical account can deliver to its alias |
| Thirty-day cutover | Every old-address-only message is classified and no critical recovery path remains untested |
This procedure moves an existing inbox to Proton Mail, places SimpleLogin aliases in front of it, and keeps the old address available long enough to catch missed accounts. It is for a reader who wants to stop exposing one permanent address to every shop, newsletter, recovery flow, and personal contact. It does not make ordinary email anonymous or end-to-end encrypted with every recipient.
- FOR
- Existing inbox
- Proton and SimpleLogin docs
- THREAT
- Address reuse
- SimpleLogin docs
- TIME
- 2-4 hours
- Cunicula estimate
- STARTING COST
- $0
- Provider plan pages
COST SOURCES: Proton plan limits (retrieved 10 August 2026); SimpleLogin pricing (retrieved 10 August 2026).
Before you start
- Access to the old inbox, its password, and its current recovery methods.
- A password manager and an authenticator app. Do not plan to use the new mailbox as its own only recovery method.
- A list of the 10 most important accounts that currently use the old address.
- One independent mailbox that can send and receive test messages.
The zero-cost route uses Proton Free and SimpleLogin Free, which includes 10 aliases. SimpleLogin Premium is listed at $36 USD per year and adds unlimited aliases and custom domains. Domain registration, Proton paid storage, and extra addresses are separate. Confirm current prices before paying.
STOP CONDITION: do not delete, close, or stop paying for the old mailbox during this procedure. The migration passes only after imports, forwarding, aliases, replies, and account recovery have each been tested.
1. Create the Proton account without reusing credentials
Open the Proton Mail provider page and continue to the official signup. Choose a mailbox name that does not reproduce a public username unless the account is deliberately public. Generate a unique password in the password manager. Complete any anti-abuse challenge Proton presents; do not add a recovery phone only because the form offers it.
Sign out, open a private browser window, and sign back in using the password-manager entry. This check happens before any import so a credential mistake cannot lock the only copy of migrated mail behind an untested login.
VERIFY: A private window can sign in at account.proton.me with the stored username and password, and the password manager entry has the correct Proton domain.
SOURCES: Proton account and plan documentation (retrieved 10 August 2026); Proton account creation (retrieved 10 August 2026).
2. Add two-factor authentication and recovery
These menu names are for the Proton Mail web interface retrieved on 10 August 2026. Open Settings → All settings → Account and password → Two-factor authentication. Turn on Authenticator app, scan the code with the authenticator, enter one generated code, and save Proton's recovery codes offline.
Then open Settings → All settings → Recovery. Enable the recovery phrase and store its 12 words offline. Add at least one other password-reset or data-recovery method that is not the new Proton inbox itself. If you use the old email as a temporary recovery address, mark it for replacement after cutover rather than silently leaving the dependency.
VERIFY: A fresh sign-in requires the authenticator code, one recovery code is stored offline, and Settings → All settings → Recovery shows a recovery phrase plus at least one separate password-reset or data-recovery method.
SOURCES: Proton two-factor authentication (retrieved 10 August 2026); Proton account recovery (retrieved 10 August 2026).
3. Attach SimpleLogin to the new mailbox
Open the SimpleLogin provider page and sign in with Proton, or create a separate SimpleLogin credential in the password manager. In SimpleLogin open Mailboxes → Add mailbox, enter the new Proton address, and send the verification message. Open that message in Proton and approve the mailbox.
Create one random test alias. From the independent mailbox, send a message with a unique subject such as ALIAS TEST 2026-08-10. Wait for it to reach Proton. If it does not arrive, inspect the SimpleLogin alias activity before changing spam controls or creating more aliases.
VERIFY: SimpleLogin lists the Proton address as a verified mailbox and a message sent to the test alias arrives in Proton with the alias shown as the recipient.
SOURCES: SimpleLogin registration (retrieved 10 August 2026); SimpleLogin mailbox verification (retrieved 10 August 2026).
4. Create one alias per account class
In SimpleLogin create separate aliases for the first accounts on the migration list. Use a random alias for shopping, newsletters, forums, or sites likely to share addresses. A named alias is acceptable for a public role when you want a human-readable address. Record four fields in the password manager entry for each account: account name, login URL, alias, and migration date.
Do not forward an alias to the old inbox. All aliases should resolve to the verified Proton mailbox so a disabled old account cannot break new mail later. On the free plan, stop at 10 aliases. If the list needs more, either migrate in priority order or knowingly choose the paid plan before creating a custom domain.
VERIFY: The alias register contains a distinct enabled alias for each of the first accounts to migrate, and no alias forwards to the old mailbox.
SOURCES: SimpleLogin alias creation (retrieved 10 August 2026); SimpleLogin free and premium limits (retrieved 10 August 2026).
5. Test replies without exposing the mailbox
Open the alias test message in Proton and press Reply. SimpleLogin supplies a reverse-alias recipient, so the external sender should see the alias as the From address. Send a sentence that contains no identifying signature. From the independent mailbox, inspect the visible From address and reply again.
To start a new conversation from an alias, create the recipient's reverse alias in SimpleLogin, then send from Proton to that generated address. Do not type the external recipient directly in Proton and assume SimpleLogin will replace the From address. Test this flow before using an alias for support or account recovery.
VERIFY: The independent mailbox receives the reply from the alias, not the Proton address, and a second reply to that thread returns to Proton through SimpleLogin.
SOURCES: SimpleLogin reverse aliases (retrieved 10 August 2026); SimpleLogin send-from-alias procedure (retrieved 10 August 2026).
6. Import the existing mailbox
In Proton Mail web open Settings → All settings → Import via Easy Switch. For Gmail, select Google and authorize the requested import. For another provider, select the IMAP route and enter the old provider's server details from its official support page. Choose mail and contacts; include calendars only if the old provider and current plan offer that import.
Start the import and leave the old mailbox unchanged. When Proton reports completion, record the imported counts and any errors. Search Proton for three known messages: one old Inbox message, one Sent message, and one message from a custom folder. Export or manually recreate any filter, label, signature, or calendar item that Easy Switch does not carry.
VERIFY: The Easy Switch report is complete or lists explicit errors, Proton contains test samples from old Inbox, Sent, and one custom folder, and the contacts count is recorded.
SOURCES: Proton Easy Switch (retrieved 10 August 2026); Proton Gmail migration (retrieved 10 August 2026).
7. Forward new mail and update important accounts
Enable forwarding from the old provider to Proton using that provider's current official instructions. For Gmail, Easy Switch can establish forwarding from the Proton flow. Send one new message to the old address and confirm it appears once in Proton. A duplicate suggests both import polling and forwarding are active; resolve that before continuing.
Change the login email on the password manager, primary financial account, mobile account, government account, domain registrar, and other recovery-critical services first. Give each one its own SimpleLogin alias. After saving each change, request a security notice, receipt, or password-reset email and mark that account passed only when it reaches Proton.
VERIFY: A new message addressed to the old inbox arrives in Proton once, and each migrated account can send a security or receipt message to its unique alias.
SOURCES: Proton Gmail forwarding and transition (retrieved 10 August 2026); SimpleLogin alias operation (retrieved 10 August 2026).
8. Run a 30-day cutover
Keep the old mailbox active for a Cunicula-controlled 30-day observation period. Each day, review messages still addressed only to the old account. Update useful senders, unsubscribe unwanted mail, and record any service that refuses an alias. Do not forward spam into a new alias just to preserve it.
At day 30, export a final local backup from the old provider if it offers one. Remove the old address from Proton recovery if it was temporary. If any critical sender or recovery path remains untested, extend the observation period. Close the old mailbox only after its retention, billing, and address-reuse consequences are understood.
VERIFY: For 30 consecutive days, every message arriving only at the old address is assigned to update, unsubscribe, archive, or retain; no critical account remains untested.
SOURCES: Proton migration controls (retrieved 10 August 2026); SimpleLogin alias controls (retrieved 10 August 2026).
What this setup does not protect
- Messages between Proton users are end-to-end encrypted, but mail sent to an ordinary external provider is not end-to-end encrypted by default. Use Proton's password-protected mail or compatible PGP when content needs that protection.
- Subject lines and sender and recipient addressing are not end-to-end encrypted. Email still creates relationship and timing metadata.
- SimpleLogin must process alias routing. It can see the routing relationship needed to forward mail even when the final mailbox address is hidden from the sender.
- A custom domain gives portability but can also join aliases through one public domain. WHOIS privacy does not remove DNS, payment, or hosting records.
- The old provider may retain historical mail, logs, backups, and forwarding records according to its terms.
- A compromised browser, device, password manager, recovery method, or recipient still exposes messages after decryption.
LIMITATION SOURCES: Proton external-recipient encryption (retrieved 10 August 2026); Proton encryption scope (retrieved 10 August 2026); SimpleLogin mailbox routing (retrieved 10 August 2026).
Maintenance
Review disabled or blocked aliases monthly. Test the recovery phrase and offline recovery-code location every six months without consuming a code. Before changing the Proton mailbox or SimpleLogin plan, export the alias register and identify which recovery-critical accounts depend on it. A working migration is a maintained routing map, not a one-time import.
Sources
- Proton Mail official site · first-party source
- Proton account creation, retrieved 2026-08-10
- Proton migration controls, retrieved 2026-08-10
- Proton account and plan documentation, retrieved 2026-08-10
- Proton external-recipient encryption
- Proton account recovery, retrieved 2026-08-10
- Proton Gmail forwarding and transition, retrieved 2026-08-10
- Proton two-factor authentication, retrieved 2026-08-10
- Proton encryption scope
- SimpleLogin official site · first-party source
- SimpleLogin alias operation, retrieved 2026-08-10
- SimpleLogin registration, retrieved 2026-08-10
- SimpleLogin reverse aliases, retrieved 2026-08-10
- SimpleLogin send-from-alias procedure, retrieved 2026-08-10
- SimpleLogin mailbox verification, retrieved 2026-08-10
- SimpleLogin free and premium limits, retrieved 2026-08-10