Encrypted email service Tutanotawas hit by DDoS attacks this week, initially targeting the company's website and then its DNS. The attacks left millions of users without access to the service for hours. The outage was further exacerbated by the fact that different DNS servers continued to cache incorrect entries for the domain.
Tutanota is a German provider of end-to-end encrypted email service, with more than 2 million users. The company is often mentioned together with popular encrypted email providers such as ProtonMail. The Tutanota service is based on open source and exchanges encrypted email messages with anyone, easily and quickly. Thus, all messages and contacts of users are stored encrypted in Tutanota's systems. Decryption of messages and contacts of users is only possible with the password set by each user. No one else knows it and no one has access to a user's data except the user himself. The Tutanota service combines the ease of use of email with security and encryption for everyone. Therefore, it gives users the opportunity to take the security of their messages into their own hands.

The DDoS attacks targeting Tutanota took place on September 12-13, causing problems for hundreds of users. However, the security incidents were quickly fixed by limiting an “overreacting IP-block” responsible for the attack.
Tutanota said in a blog post that continuous DDoS attacks and an infrastructure issue led to downtime for hundreds of users this weekend. The company added that while it had mitigated most of the DDoS, an overreacting IP-block to combat the attacks prevented hundreds of users from accessing Tutanota for several hours this Sunday.
Additionally, the post mentions several anti-DDoS measures and improvements the company has implemented, which are expected to make it easier to recover from any future disruptions that may arise from DDoS attacks. Rather than focusing on “collapsing” Tutanota’s servers directly, the attackers decided to use alternative means.

The second DDoS attack hit the DNS provider that hosts records for Tutanota.
As a result, that provider went down. The company immediately tried to update the DNS records and move them to another provider. This didn’t work at first because the DNS records were locked to one of the DNS hosting providers.
Tutanota co-founder Matthias Pfau told BleepingComputer that this is a direct attack on everyone's freedom and right to privacy. With Tutanota, the company provides a secure tool to millions of users around the world, including activists and journalists. These ongoing attacks against Tutanota seem to have only one goal: to prevent citizens from using encrypted email, according to Pfau.

The company confirmed that service was restored on Thursday, September 17 at 7:30 CET.
Due to the outage, however, several emails sent to Tutanota users may not have been delivered. However, Tutanota assured its users that no data and that the end-to-end encrypted nature of the service makes it impossible for even the company itself to access user data.
Pfau said that as the company improves its system for mitigating DDoS attacks, attackers seem to be looking for other ways to harm it. He also added that since this is a privacy-focused service, using a mitigation service that requires its SSL key for their service is not an option. That is the challenge of creating a secure email service that respects privacy. But the company will succeed, just as it has managed to avoid using Google, such as Google Push for its Android app, Pfau stressed.
