# Neir

Category: email · Encrypted Mailbox
Grade: C
KYC: no_kyc, no_email, no_account
Highlights: ZERO SIGNUP, E2E BODIES, XMR NATIVE, ONION MIRROR
Features: no_account, no_pii, tor_mirror, e2e_bodies
Fees: Free (100 MB) · Pro $4.25–$4.99/mo · XMR + BTC + 18 other assets
Web: https://neir.io
Tor: http://itlmjjwnpraaxvm5gkjeebwhjy5zycildwyg2u3lyrfigz5e6hntdqqd.onion
Last verified: 2026-07-30
Operating since: 2024 (2y) — ~22 months since Wayback first-snapshot 2024-09-10.

> Zero-signup encrypted mailbox — no email, no phone, no captcha; on-device Account Key + browser-side OpenPGP for message bodies. Full XMR payment support (Monero-network, 6 confs). Onion mirror advertised. Metadata (sender / recipient / subject / timestamp) is stored plaintext — honest limitation vs Proton/Tuta.

## Review

Neir is a **zero-signup encrypted mailbox** where account creation asks for nothing — no email, no phone, no captcha. Signup issues an on-device Account Key + recovery phrase; the server stores only a salted one-way hash of the key. Message bodies are end-to-end encrypted with an OpenPGP key pair generated in the browser; message metadata (sender, recipient, subject, timestamp) is stored plaintext, which the operator discloses openly. Listed at **Grade C** — the entry grade for a new no-KYC email service with genuine anti-KYC posture and two-peer-directory corroboration, before the usual identity/canary/audit-history gaps close.

**What you trust.** Browser-side PGP key generation — private key never leaves the client in plaintext; encrypted before send with a key derived from the Account Key. Message bodies are opaque to the server. Metadata is NOT opaque — treat sender/recipient/subject as visible to Neir. Zero-signup design means recovery hinges on the Account Key + recovery phrase; lose both and the account is unrecoverable (there is no email fallback, no support-side reset).

**TOS quote.** From the Terms page: *"Neir does not and will never require identity verification or know-your-customer (KYC) checks to create or use an account."* The Terms contain no counter-clauses about reserved-right-to-request-ID or law-enforcement cooperation — a clean statement of posture.

**Log policy.** The Privacy Policy states *"We do not log or store your IP address or geographic location against your account."* The claim is self-attested — no third-party audit, no published bug-bounty programme, no open-source client to inspect the browser-side PGP flow.

**Operator identity.** *"Based in Sweden"* per the footer. No named legal entity, no team / about page, no PGP fingerprint published for the operator. Contact via `hello@neir.io` and Telegram `@neir_io`. **Warrant canary** exists at `/canary` with the four standard statements (no NSL, no gag order, no backdoor, no seizure), but the "Last updated" field renders blank and the canary is not PGP-signed. That combination — canary present but neither signed nor dated — is a real gap worth watching.

**Tenure.** Wayback earliest snapshot 2024-09-10 (~22 months). Not an aged-domain re-brand — no evidence of prior unrelated use.

**Onion mirror.** `itlmjjwnpraaxvm5gkjeebwhjy5zycildwyg2u3lyrfigz5e6hntdqqd.onion` — advertised on the clearnet homepage footer, byte-identical response to the clearnet HTML at the same path. Real Tor mirror, not a proxy.

**Peer directories.** kycnot.me lists Neir at 8/10 (Privacy 100 / Trust 62), *"Guaranteed no KYC"*, "Listed, but not yet reviewed by the team" — a community-contributed listing with a positive score, weaker signal than a team-reviewed one. monerica.com lists under the 2026-07-30 additions batch. Privacy Guides does not include it in the recommended-email shortlist (which is Proton / Tuta / Mailbox.org today).

**Pricing.** Free tier at 100 MB storage. Pro tier at $4.99/mo month-to-month, down to $4.25/mo on the 12-month prepay. Payments accepted across 31 currency/network combos including **XMR on the Monero network with a 6-confirmation requirement** — first-class alongside BTC, LTC, ETH, USDT-on-6-networks. Payment surface reads as third-party crypto-processor integration (NOWPayments / CoinPayments style) rather than native XMR wallet; typical for a boutique provider.

**Fees.** Free tier: none. Pro: monthly + prepay pricing above; no per-message fees, no per-alias fees, no storage overage fees disclosed.

**Positioning.** Full-mailbox provider (not alias-only like AnonAddy / SimpleLogin, not classic-IMAP like Cock.li / Disroot). Zero-signup-friction places Neir closer to Cock.li's ethos with Tuta's browser-side E2E approach. The metadata-plaintext limitation puts it below Proton/Tuta on the encrypted-metadata axis. Free tier + XMR-native + no-signup-data is the differentiator.

**Grade C — what it means here.** Acceptable with the caveats above named. Real signup posture, real E2E for bodies, real XMR payment, real onion mirror, honest metadata disclosure. What holds the grade below B: no named legal entity, no operator PGP fingerprint, canary is present but unsigned + undated, no independent audit or open-source client to verify the browser-side PGP claim. The path up needs those gaps closed plus 6+ months of clean operation on the watchlist.

**Useful when.** You want a **full mailbox** with zero identifying data at signup, accept metadata-plaintext as the tradeoff, and pay in **XMR**. You are comfortable with a small operator whose canary + identity surface is thinner than Proton/Tuta. For **PGP-encrypted body correspondence only**, this is genuinely low-friction; recovery discipline (Account Key + recovery phrase) matters more than usual because there is no email-based reset path.

**Caveats.** The unsigned + undated canary is the most-immediate gap — a canary that isn't demonstrably fresh isn't doing canary work. Legal entity + jurisdictional recourse: "Sweden" without a named legal entity is thinner than Proton's Swiss corporate transparency. Metadata plaintext is honest but material — if your threat model treats subject lines as sensitive, a fully-metadata-encrypted alternative (Proton, Tuta) is a closer fit.

Source: https://xmr.club/email/neir