Title: age-web-gateway: Send age-Encrypted Files Without Own Keys

URL Source: https://blog.hem.si/blog/2026-09-09-age-web-gateway/

Markdown Content:
---
title: age-web-gateway: Send age-Encrypted Files Without Own Keys
description: Self-hostable gateway with browser-side age encryption, DNS/HTTPS key discovery, SMTP relay. Live at age.hdev.io.
image: https://blog.hem.si/blog-placeholder-1.jpg
---

 09.09.2026 

# age-web-gateway: Send age-Encrypted Files Without Own Keys

[Get Site as Markdown ](https://markdown.new/https://blog.hem.si/blog/2026-09-09-age-web-gateway/) 

---

Repo: [dhcgn/age-web-gateway](https://github.com/dhcgn/age-web-gateway) · Live: [age.hdev.io](https://age.hdev.io/)

## Problem

I wanted an easy way for people to share encrypted files with me — easy to use but also very secure. I liked age-encryption and wanted to build a browser-based app for it. It is also post-quantum safe.

## Tech Overview

| Aspect        | Choice                                                              |
| ------------- | ------------------------------------------------------------------- |
| Backend       | Go (agemail), config file + env vars, Docker via GHCR               |
| Frontend      | JS, built with node build.mjs, encryption in the browser            |
| Format        | age (age1…) + hybrid post-quantum (age1pq1…)                        |
| Key discovery | DNS TXT at \_age.domain (DNSSEC optional) or HTTPS well-known file  |
| Relay         | Encrypted SMTP or Cloudflare Email API over TLS, plus proof-of-work |

Message body, file names, and contents are encrypted in the browser before upload — the backend never sees plaintext. Metadata (recipient, timing) remains visible to mail infrastructure.

## Solution

Recipients publish only an age public key:

```plaintext
domain.de;catchall_age@domain.de;age1a3xsw5j5d27k4zmp5wzr7kp49m7gvgt87f32gq3he7da0r4jne6qyk4mmy
```

Senders open the page, enter a recipient, see a trust level per key source (HTTPS well-known > DNSSEC > basic DNS TXT), type a message, attach files, and send. The browser encrypts to the recipient keys and uploads only ciphertext. Limits: 5 MiB via Cloudflare Email API, 25 MB via SMTP.



I also run a small directory service where people can create an entry with their domain (link to follow). For incoming mail, [age-imap-decryptor](https://github.com/dhcgn/age-imap-decryptor) decrypts attachments automatically after delivery.

## Outlook

Next: document the directory onboarding and keep PQ key guidance (use HTTPS well-known — PQ keys are too large for DNS TXT). This is a relay, not a mailbox; try it at the live instance above.