Only allow login with single/main address/username
Do not allow that you can log into the account with every address.
If my account name is john.smith then only allow login with john.smith or john.smith@protonmail.com. Not with finance.john.smith@protonmail.com or any other address.
Perfect would be if you would have the choice what address can be used in order to log into your account.
With the current way you have to give away your login username in order to send emails. Hiding the username from the public would be an advantage, since they would have to guess your username and the password. Not only one of them.
-
Woof9906
commented
Wow guys, just took a paid plan. This is basic feature I'm surprised it's not implemented yet. I want to keep my login secret
-
Rob
commented
This is possible on Outlook, why can't we get this option on ProtonMail?
-
uservoice22
commented
It would be really important to be able to choose which addresses can be used to log in.
Aliases should only be used to send and receive emails, not to become additional access points to my account. This way, I can use different aliases without the risk of someone exploiting them to try to gain access.
With the current system, I am forced to “reveal” my login username every time I send an email, because anyone can try to use it to authenticate themselves. If, on the other hand, I could keep my main address hidden, security would be increased: an attacker would have to guess both the correct username and password, not just one of the two.
-
Lucas
commented
Not even recognizing that this issue exists and just ignoring it altogether is out of my mind. Maybe Proton is not that private after all? I mean, why would a service with such wide privacy claims even be allowed to grow to such a large extent and maintain their users online safety at the same time? I doubt the US would allow that tbf. If Proton really mean that they are taking the privacy of their users seriously, I believe that the possibility to limit which email addresses can log into their users' accounts is not unfair to demand.
-
anon
commented
Perfect would be if you would have the choice what address can be used in order to log into your account -> this should be the solution to prioritize please
it could be a great way to keep the account secure, even in the case of someone accidentally leaking you email address, you may actually need to create an address just for a specific service. As i learned the hard way that a governmental service that the online registration was forced on to us and we actually need, blockes the registration with the protonmail aliases.
So in this case if you create an email for that purpose you do not want that address to be used for login in proton ecosystem. So you can have you login address always private even if you communicate the other addresses you used.
-
Jeffery Boyle
commented
This feature should definitely be a top priority for the product. After upgrading to the Proton Unlimited plan, I felt somewhat misled by the mention of "15 email addresses." It gave the impression that these emails are meant solely for email exchange and sign-ups, without the ability to log in to your main account, thus keeping it anonymous and adding a layer of security. Additionally, there’s an indicator for a default email address, but its purpose remains unclear, especially if all other email addresses can be used for logging in to your account.
-
JosefKainz
commented
This is the number one feature I want added to proton. It will essentially make the account impenetrable as it will allow us to hide entirely the login address. Yes we could do that by only using aliases but there are several websites, accounts and institutions that don't allow aliases (or where it's less appropriate to use one) such as with your bank, or a professional association. Being able to designate which address can be used to login would allow us to never expose that credential.
-
AC commented
I found out about this right after paying for unlimited.
This is such a big limitation, i may cancel it within the 30 days.... -
prj29
commented
It seems strange that there cannot be a single login option for a Proton account. Even if it simply meant a checkbox against each address that was "Allow for Login" and you could simply select which email or set of email addresses would be allowed for login. I imagine in the background it would do all the normal checks as it does not, but just reject a successful login depending on which accounts are currently approved. It would allow every paid user to create a single-purpose login-only email regardless of how they use their signup email
-
Sophie Lophie commented
Critical! Was considering upgrading to get more addresses, but won’t after I became aware that they can all be used to log in.
-
Lucas
commented
I have seriously started to wonder if the neglect of this issue is intentional and why this would be the case. This is an old issue and I cannot see that Proton has responded to this earlier in this thread or in the other, similar one here: https://protonmail.uservoice.com/forums/284483-proton-mail-calendar/suggestions/47611028-choose-which-alias-can-log-in-to-proton. Why?
-
Bobo
commented
Proton, please implement this immediately. You're increasing the attack surface exponentially for EACH user - thus increasing the RISK exponentially for each user. There's no reason that each alias should allow login permissions; this ought to be a technically easy fix. Please, do this ASAP, to protect your users AND your reputation!
-
DZFr
commented
This suggestion should be merged with that one (https://protonmail.uservoice.com/forums/284483-proton-mail-calendar/suggestions/47611028-choose-which-alias-can-log-in-to-proton). That’s more than 1000 votes altogether…
-
D
commented
I like how you can create multiple custom emails for one account. I would like an option to toggle off being able to log in with those active custom emails.
For Example
Account is xyz@proton.mecustom email: johndoe@pm.me
I don't want the custom email johndoe@pm.me being able to log into my xyz@proton.me account.
That way would feel more comfortable giving out custom email without someone trying to hack the account because they never got the real login username/email.
As of right now I have a free account to give out email without compromising my main account.
-
Dorothy commented
I have about 40 email addresses (amazon, paypal, youtube, etc.). I currently have chosen this approach over aliases. But now I have a bunch of different ways a person can login to my account, when I'd rather it be limited to one or two (me or my wife, for example). It would be nice to have a checkbox next to every address saying whether a person can use it to login or not. Set them all 'on' by default, and turning them off gives a scary warning - and of course you can never turn off the master account address.
-
cristian
commented
+1
-
Spiff
commented
Critical. Obvious. I feel stupid for not knowing this, and Proton has now lost a lot of my respect. You must allow users to choose which email addresses can be used to log in, or only allow log in with the primary/original. Otherwise this “don’t let anyone know my ‘real’ email address” is a load of ****, because they are all our “real” email addresses.
-
MS
commented
I have just voted on 3 very similar requests across this forum. Please tally up the numbers and see how highly requested this feature is. Why isn't it at least UNDER REVIEW? Please, please, please review this or advise why it isn't possible. Thank you.
-
Rob
commented
This is literally the fourth most highly requested feature in the accounts/payments category (if you lump requests for various different crypto into one) and yet no response from Proton. Please implement this ASAP! It can't possibly be that difficult to do so!
-
Leo
commented
I'm just transitioning to Proton and I'm glad I discovered that the extra emails can be used to log in before I put them in the wild! My goal is to keep my main account email hidden, but I would much prefer being able to use my additional addresses (without the ability to use them to log in) than use random aliases. ONLY being able to log in with the primary account email seems ideal!!