Email security

How secure is the email? What should I do if I don’t want my email to be out of reach of even Administrators who are in the ACL as managers?

Thanks

Subject: email security

In general Notes email is very secure…

And now a corporate response from management…most companies should have a policy stating that your work email is not your own and shouldn’t be treated as “personal”. Your mail file and the contents of it are property of the company. If your company doesn’t have a policy like this, they should. Trying to restrict access to your mail file could very well get you in trouble.

I’ve had users do a number of things to “restrict” access to their mail, each time they did it, I would undo it. Or if they removed the Admin group from the ACL, I would re add it (The fact that they had Manager access is another can of worms). Full Access Administration is such a nice feature of D6, wish this existed in R4/R5.

Whatever you do, don’t delete ALL your mail before you leave a company. You could find yourself in a legal mess.

I’m sure there are a lot of differing opinions on this matter. I prefer to take this approach. At least it will make an employee think twice about receiving personal email at work or allowing their friends to send pr0n. It’s unbelievable what some people have in their mail files of a personal nature.

Subject: email security

The way you posed that question is a little odd, so I’m not sure that’s quite what you meant. Notes/Domino is as secure a mail system as anybody could ask for, which means that it’s very safe from intrusion by people who are not allowed to get into it by the system’s administrators. Typically, administrators will be able to access your mail as a matter of course, which is as it should be in most organizations, and can even read encrypted mail if they’ve taken appropriate steps to retain a copy of your ID file.

If you want to keep admins from reading specific messages, you could create private encryption keys to share with specific people within your organization or use third party tools like PGP to exchange secure mail with anybody whether or not they’re in your organization. Of course, most organizations don’t allow their employees to send information that they don’t at least theoretically have access to, so sending encrypted mail without specific permission could get you fired.

Subject: email security

Encrypt all documents using a private key that you create.

Since the administrators could “recreate” your ID file, there’s really no other way to protect documents on the server.