In August 2026, researchers from the University of Wuppertal published a mathematical proof confirming the security of TutaCrypt, the encryption protocol used by Tuta Mail. This proof examined a hybrid encryption method that combines traditional encryption with post-quantum encryption, a strategy cryptographers call "belt and braces." Tuta Mail, Signal, and Proton Mail are all preparing their services for the potential arrival of quantum computers, which could break current encryption methods. However, each service has taken a different approach to integrating post-quantum encryption. Tuta Mail developed its own protocol from scratch, called TutaCrypt. Signal, which already had a well-established encryption protocol, enhanced it by adding post-quantum elements, such as PQXDH and later SPQR. Proton Mail, on the other hand, did not create a new protocol. Instead, it adapted post-quantum algorithms to an existing encryption standard called OpenPGP, using a new technical specification known as RFC 9980. These different approaches reflect varying philosophies on how to best prepare for the future of encryption. Encrypting a message involves transforming it into a string of unreadable characters using a mathematical key. Without the key, the result looks like random noise. With it, the original message can be restored. One major challenge in encrypted communication is securely exchanging keys when the sender and recipient have never met. This is typically addressed in two ways: either the recipient keeps the decryption key private and shares only the encryption key, as in OpenPGP, or the two parties generate a shared secret without directly transmitting it, using methods like Diffie-Hellman or KEM (Key Encapsulation Mechanism). Tuta Mail and Signal both use a similar two-step approach to address this challenge. They combine a classical Diffie-Hellman key exchange with a post-quantum KEM called ML-KEM, which is standardized by the U.S. National Institute of Standards and Technology (NIST). ML-KEM relies on complex mathematical problems involving point lattices, which are currently resistant to quantum attacks. This dual-layer approach ensures that even if a quantum computer could break the classical part, the post-quantum part would still protect the message. The hybrid encryption approach used by TutaCrypt combines eight elements, including three secret values and five public components, to create a unique encryption key. This design ensures that the key is specific to each communication and cannot be reused. However, if an intelligence agency intercepts and stores encrypted messages today, they might be able to decrypt them in the future with a powerful quantum computer. While quantum computers could break the classical part of the encryption, the post-quantum part would still protect the message unless a mathematical weakness in the lattice-based algorithm is discovered. Each service has a distinct approach to authentication, which is crucial for verifying the sender's identity. Signal uses signed pre-keys, which are public keys stored on the server and signed with a dedicated identity key. This allows messages to be sent even if the recipient is offline. TutaCrypt relies on an implicit authentication method, where the sender's secret key is directly involved in generating the session key. This method is secure against classical attacks but may be vulnerable to quantum attacks if the sender's key is compromised. Proton Mail separates encryption and authentication, using different key pairs for each function, which offers a different balance of security and flexibility. The three services also differ in how they handle forward secrecy, which ensures that the compromise of a long-term key does not allow the decryption of past messages. Signal uses a technique called the Double Ratchet, which rotates encryption keys frequently and deletes old ones, ensuring that even if a key is stolen, it only grants access to a limited portion of the conversation. TutaCrypt lacks this level of randomness on the recipient's side, which limits its forward secrecy. Proton Mail, relying on the OpenPGP standard, does not offer forward secrecy at all, meaning that if a private key is stolen, all past messages encrypted with it become readable. In terms of academic validation, each service has taken a different path. TutaCrypt was rigorously reviewed by researchers from the University of Wuppertal with financial support from the German government. Signal's PQXDH protocol also underwent a formal security analysis. Proton Mail, however, based its approach on a previously tested method called X-Wing, reviewed by government cybersecurity agencies. These different approaches reflect the varied ways in which encryption protocols are being scrutinized and validated in the field of mass communication.