Only allow login with single/main address/username
Do not allow that you can log into the account with every address.
If my account name is john.smith then only allow login with john.smith or john.smith@protonmail.com. Not with finance.john.smith@protonmail.com or any other address.
Perfect would be if you would have the choice what address can be used in order to log into your account.
With the current way you have to give away your login username in order to send emails. Hiding the username from the public would be an advantage, since they would have to guess your username and the password. Not only one of them.
-
Steven
commented
This is crucial! It's been 9 years since this suggestion was posted, what is the status?....
-
Zireael
commented
What's the point of allowing me to have 15 email addresses if any of them could be used to login to the entire account? I thought I had one truly private one for logging in, drive, pass, and calendars I will not share, another using my nickname for personal contacts and calendar invites, another using firstname.lastname for professional contacts and calendar invites and then one each for other primary accounts, banking, doctors, shopping, forums, and social media. Yeah its not quite as secure as having a hide-my-email alias for every individual account but there's enough of a buffer to only have to disable and create one new address and change a few accounts at a time.
Now I'm sitting here realizing that doesn't work. All 8 of these email addresses are out there in the world and I need to alter everything to hide-my-email addresses, then disable the proton ones because I don't even want the aliases to filter to them because they're known, so I need to create new email addresses for the aliases to forward to. I'm basically redoing everything I did a year ago when I migrated from gmail. And I'm going to have to get on the phone to change at least 25 of these accounts.My doctor's office is going to look at me like I've lost my mind.
And that still won't correct the problem that inviting people to a calendar event will reveal the email address associated with that calendar and thus a proton login option. It's not that I don't trust my personal and professional contacts, it's that people are stupid and give out your email because they're so used to only using one or two for the last 15-20 years. And the second one is usually a work/school one. I was fine with that risk when I thought those two email addresses, which are variations of my real name anyway, couldn't be used to login to my account.
-
unlimited user
commented
Disregard my last comment:
“Tuta has the exact same problem. Tuta allows login using a Tuta alias, which defeats the value of having the alias. Despite this being a known issue since 2019, it doesn’t appear to be a priority for them to fix. So switching to Tuta doesn’t solve your core grievance. Both services currently share this vulnerability. Keep that front of mind as you read the rest.”
-
BK
commented
Essential feature. Our business requires an address specifically for logging in; one that is never used to send/receive email.
-
unlimited user
commented
Look into Tuta Mail.
-
Mick
commented
Are there any decent alternatives to ProtonMail in case they don't sort this out? I've heard AtomicMail are quite good?
-
Mick
commented
Does anybody at ProtonMail actually read these?
I notice a couple of people on page 2 saying "this is finally under review". Where did you find that? Do you have a link, please?
-
Mick
commented
Does anybody at ProtonMail actually read these?
-
Kappa
commented
This really is a critical feature for security. Please please consider this.
-
Rob
commented
Proton, why do you have to tease us? This (and others like it) have been frequently requested for 9 years, and in January of this year you merged several similar threads into one and said it was "under review" but now it's back to no longer being under review (aka being ignored). This is such an important security feature... It's almost like 3-factor authentication instead of 2 if bad actors don't even know your user name to log in. Please at least consider implementing this or something like it! Please!?!?
-
gilcust-413
commented
I've been a paid user for more than a year. I noticed this missing critical feature when I subscribed to the premium plan. I had mailed the Proton support back then, got no answer whatsoever. If they are this privacy-focused company as they claim to be, having this feature is mandatory. I hope they implement it soon.
-
Liesbeth
commented
I only realised that any alias can be used to login to any part of the Proton suite when I started using it more. I've kept my initial proton address completely safe, but to what end, I'm not sure now.
Even with 2 step authentication this seems odd. -
Professor Tor Coolguy
commented
It's kind of silly this still hasn't been addressed by a potential Google/Outlook alternative. Serious users don't want to have to use a silly SimpleLogin alias for their business emails. I want to be jsmith @ proton.me or johnsmith @ proton.me in my correspondence with clients, not jsmith.420bananastand @ aleeas.com
-
DZFr
commented
For those who support this feature, you can also support : https://protonmail.uservoice.com/forums/284483-proton-mail-calendar/suggestions/47611028-choose-which-alias-can-log-in-to-proton
-
Gevk
commented
With yet another data breach, this is becoming more and more critical
-
ok7258963
commented
Critical feature as pointed out already, which currently prevents me from using protonmail the way that was intended
-
Bad Sensor
commented
Presently, I can login with all my Proton aliases.
This potentially expands the attack surface for unauthorized logins.
When login to Proton account only with primary Proton email, this will be reduced. -
Professor Tor Coolguy
commented
This is such a glaring security issue and it's the only reason I haven't gone for a paid account. I love how smooth and integrated everything is in Proton and would love more features-- but the key one I want is security and I don't want to pay to increase the ease with which my entire account can be compromised if one of my potential alases gets leaked through a hack.
-
Juhis
commented
This would improve account security. Really critical. I use a custom domain address alongside my primary Proton Mail address (you can see Proton stuff in DNS MX record). Every time I give my own professional email address away, I increase a change that it will used to for trying to hack into my Proton account. Same goes with pm.me address. I come from Outlook and in Outlook it was possible to deny login for other mail address. I used to have a policy not to share my login address with anyone, so login account was never used as email address. I would very much like to see that same possibility with Proton. Some kind of proton user ID (not mail) would be the option for logins.
It would be very useful to have a separate “disable login” toggle (or the ability to mark an address as “login‑only off”) so the address can remain fully functional for email while never being usable for authentication. (Proton Unlimited user)
-
DZFr
commented
On January 6th, I received an email from Uservoice saying that this was under review. Is it still the case ? Apparently not…