Repo: dhcgn/age-web-gateway · Live: age.hdev.io
Problem
I wanted an easy way for people to share encrypted files with me — easy to use but also very secure. I liked age-encryption and wanted to build a browser-based app for it. It is also post-quantum safe.
Tech Overview
| Aspect | Choice |
|---|---|
| Backend | Go (agemail), config file + env vars, Docker via GHCR |
| Frontend | JS, built with node build.mjs, encryption in the browser |
| Format | age (age1…) + hybrid post-quantum (age1pq1…) |
| Key discovery | DNS TXT at _age.domain (DNSSEC optional) or HTTPS well-known file |
| Relay | Encrypted SMTP or Cloudflare Email API over TLS, plus proof-of-work |
Message body, file names, and contents are encrypted in the browser before upload — the backend never sees plaintext. Metadata (recipient, timing) remains visible to mail infrastructure.
Solution
Recipients publish only an age public key:
domain.de;catchall_age@domain.de;age1a3xsw5j5d27k4zmp5wzr7kp49m7gvgt87f32gq3he7da0r4jne6qyk4mmy
Senders open the page, enter a recipient, see a trust level per key source (HTTPS well-known > DNSSEC > basic DNS TXT), type a message, attach files, and send. The browser encrypts to the recipient keys and uploads only ciphertext. Limits: 5 MiB via Cloudflare Email API, 25 MB via SMTP.

I also run a small directory service where people can create an entry with their domain (link to follow). For incoming mail, age-imap-decryptor decrypts attachments automatically after delivery.
Outlook
Next: document the directory onboarding and keep PQ key guidance (use HTTPS well-known — PQ keys are too large for DNS TXT). This is a relay, not a mailbox; try it at the live instance above.