Skip to content

Call securityNew

How calls are encrypted end to end, and how to check that nobody is in the middle.

Calls are end-to-end encrypted. When someone joins, your device and theirs make new keys for that call, and the messages that set the call up are sealed with them. Our servers pass the call along but can't hear or see it, and we never record calls. The one exception is a connection with someone on an older version of Viremail, which is encrypted but can't be checked (see the labels below).

To see how each connection is protected, choose the label at the top of the call window, such as End-to-end encrypted. It opens Call security.

Check that nobody is in the middle

Each person's name has a small shield. Choose it, or Compare in Call security, to see a security code of 5 emoji.

  1. Ask the other person to open Call security and read their emoji out, or hold them up to the camera.
  2. If you both see the same five in the same order, choose They match. Their name then says Verified for this call.
  3. If they're different, choose They don't match. We close your connection with that person and tell them why.

The code is new for every call. If someone reloads the page, their keys change and you'll see that their connection was reset. Compare the code again.

People with encrypted chats set up

When you and the other person are both signed in and have encrypted chats set up in Settings, Encryption, your devices use those keys to prove who you are, so there's nothing to compare. If the codes match in a call like this, that person is also marked as verified in your security settings.

After a call like this, we expect those keys every time you call that person. If their browser is locked, the call can't connect, and you'll see that we couldn't confirm who they are. Ask them to open Settings, Encryption and unlock that browser, then call again.

What the labels mean

  • Securing… New keys are being made. It takes a moment.
  • Not verified. The call is encrypted, but you haven't compared the code with that person.
  • Verified for this call. You compared the code and it matched.
  • Guest, not verified. Guests have no account keys, so compare the code to be sure who they are.
  • Not verified: they're using an older version of Viremail. That connection is still encrypted, but we can't check that nobody is in the middle. Ask them to reload Viremail.
  • Not connected securely. We couldn't make keys with that person. In a group call, choose Try again in Call security. If it doesn't help, you may both need to choose it, or one of you can reload the page.

In a call with one person, if the call can't be kept private it ends with Call ended to keep it private rather than carrying on without protection. Call again, and if it keeps happening, ask them to reload Viremail.

Was this helpful?

All guides

Getting started

Mail

Security & privacy

Encryption

Vire & calls

Calendar & tasks

Notes & contacts

Drive and office apps

Account

Troubleshooting