Proton Mail Bridge
Proton AG · A local IMAP/SMTP bridge that connects a paid Proton Mail account to desktop email clients while encrypting and decrypting mail on the computer.
About
Proton Mail Bridge connects Proton Mail to desktop clients such as Apple Mail, Thunderbird and Outlook through local IMAP and SMTP servers. It runs in the background and handles encryption/decryption between your client and Proton. It suits paid Proton Mail users who prefer a desktop client's mailbox, search and workflow tools.
Mail-client workflow
Sign in to a supported paid Proton account in Bridge, then configure your client with the server details and generated mailbox password shown by Bridge. The generated password is separate from your Proton account password. Combined-address mode uses one mailbox; split mode configures addresses separately. Bridge must be running and signed in for new mail to synchronize. Closing its main window does not stop the background process, and startup is enabled by default.
This is not a generic Proton POP3 service or an offline substitute for account authentication. Existing messages in a desktop client can remain after signing out of Bridge. Review synchronization state before changing accounts, repairing caches or removing a client profile.
Installation and requirements
Download the official DMG, install the app and follow its account/client setup wizard, or use brew install --cask proton-mail-bridge. The exact 3.27.0 DMG is 130,955,674 bytes, verified by official-asset HEAD. The current package remains 3.27.0; release history now includes 3.27.1, 3.27.0 and 3.26.0, whose notes are separate from this download-size evidence. Mailbox caches, client copies, logs and updates require additional disk space proportional to your mailbox.
The current official requirements page supports macOS 15 Sequoia and macOS 26 Tahoe. It supports 64-bit systems, including Intel Macs and Apple Silicon, and says Bridge should not use more than 2 GB RAM at any time. This is usage guidance, not an explicitly published numeric minimum RAM requirement. Other OS versions may work but are not equally tested/supported. macOS Keychain is required for credentials; the native distribution contains its launcher and app and does not require a Go/Qt development environment.
Accounts, fees and networking
The code is GPLv3-licensed, while Bridge service access requires an eligible paid Proton Mail plan. Your mail client may have its own license or subscription. A free Proton account alone is not the documented Bridge entitlement. Network access is needed for Proton sign-in, mailbox synchronization, sending and updates; already downloaded client messages may be available offline according to that client's behavior.
The local IMAP/SMTP endpoints are intended for the client on your computer. Port conflicts can prevent setup; use Bridge's displayed configuration rather than exposing those services remotely. Proton accounts with additional security checks or two-factor authentication must complete those checks during sign-in.
Permissions and encryption boundaries
Bridge uses the native Keychain for secrets. Apple Mail setup requires installing Bridge's self-signed local certificate/profile through macOS settings; the official guide explains that this profile appears unsigned. Verify that the prompt is from your own Bridge setup and follow the guide rather than trusting arbitrary certificates. The launcher is installed in a protected location and verifies signed app files for updates. The checked sources do not establish Accessibility or Screen Recording as ordinary prerequisites.
Mail exchanged with other Proton accounts is end-to-end encrypted. Mail to non-Proton accounts is not end-to-end encrypted by default; existing PGP contact settings can apply. Proton's zero-access server encryption does not make every external recipient's copy encrypted. Bridge stores local mail encrypted, but the desktop mail client can store it unencrypted. Protect the workstation, disk, backups and exported attachments accordingly.
Bridge has local logs and Sentry crash-reporting infrastructure documented in the repository; do not assume that all operational telemetry is absent. Review diagnostics before sending them and consult Proton's current privacy controls. Avoid moving the cache onto unreliable/removable media; back up client mail before repair or profile removal. A second local copy, another client or a debug report can expose information even though the server uses encryption.
Sources: Product, Official requirements, Installation and paid accounts, Apple Mail profile setup, Encryption boundaries, README/keychain/background behavior, Official releases.
New What’s new in 3.27.1 Jan 1, 1 · OpenNavo editorial
- FixesRecovers from a corrupted synchronization-state file.