Signal Sealed Sender: What It Hides, and From Whom

Published: October 7, 2026 · Updated: October 8, 2026

Sealed sender hides who sent a message from Signal’s own servers. A normal messaging server sees both ends of every message: who sent it and who received it. With sealed sender, the sender’s identity travels inside the encrypted envelope, so the server can deliver your message to the right person without learning who you are. The recipient still sees exactly who messaged them. This guide explains how it works in plain terms, when it switches on by itself, and where its limits are.

Download Signal APK

from Signal’s official site — file hosted by Signal, not by us

What problem does sealed sender solve?

End-to-end encryption solved the content problem: nobody in the middle can read your messages. But it left a metadata problem standing. In a normal encrypted messenger, the server cannot read what you said, yet it sees the envelope: this account sent a message to that account at this time. Over months, those envelopes paint a detailed picture of who talks to whom, when, and how often. For many threat models, that picture is the sensitive part.

Signal’s answer was to ask an unusual question: does the server really need to know the sender at all? To deliver a message, the server needs the destination. The sender’s identity is not required for delivery. It was only there because nobody had engineered a way to remove it. Sealed sender is that engineering: it takes the sender’s identity off the outside of the envelope and seals it inside, where only the recipient can open it.

The result is a messaging system where the service operator is cut out of the loop on purpose. Signal’s own description of the goal was simple: the service always needs to know where a message should be delivered, but ideally it should not need to know who the sender is.

How does it work, in plain terms?

The mechanism has three moving parts, and none of them requires a cryptography degree to follow.

Diagram of sealed sender: encrypted message, sender sealed, server relays knowing only the recipient
Like an envelope with no return address.
  1. First, the sender certificate. Your app proves to Signal’s server that it is a real, registered Signal account, and in return the server issues it a short-lived certificate. Think of it as a temporary ID badge stamped by the server: it confirms “this message comes from a genuine Signal user” and it carries an expiry time so it cannot be reused forever. Your app renews it regularly in the background.
  2. Second, the sealed envelope. When you send a message with sealed sender, your app puts the sender certificate and the message together inside an encrypted envelope addressed to the recipient. The “from” line that would normally sit on the outside of the envelope is gone. Instead, the whole package is encrypted again, so the certificate is hidden inside.
  3. Third, delivery without knowledge. The server receives the package, checks that it carries a valid certificate from a genuine account, this stops spam and abuse without identifying anyone, and delivers it to the recipient. The recipient’s phone opens the envelope, validates the certificate, and shows you the message with the sender’s name attached, exactly as normal. From your side and the recipient’s side, nothing looks different. The difference exists only at the server: it delivered a message without learning who sent it.

A useful way to picture it: a courier hands a locked briefcase to a mailroom. The mailroom can verify the courier’s badge is real and read the address label, but the sender’s name is inside the locked briefcase. The mailroom delivers it. Only the person at the address can open it and see who it is from.

Illustration: a sealed envelope addressed to a recipient, with the sender line hidden inside, passing a server that only sees the destination

When is sealed sender on automatically?

Sealed sender is not a toggle you hunt for. It switches on by itself when the conditions are right. In practice, your messages go out sealed automatically when the sender is in the recipient’s contacts or has access to the recipient’s Signal profile. That covers the overwhelming majority of real conversations: people you know, messaging each other normally.

There is also a setting for the receiving side. You can choose to accept sealed-sender messages from people who are not in your contacts and do not have your profile. Widening this increases your metadata protection, more of your incoming messages arrive with the sender hidden from the server, at the cost of making it slightly easier for strangers to reach you. Most people leave the default, which is a sensible middle ground.

One practical note: because sealed sender needs the recipient’s profile information to build the sealed envelope, it works best between people who have exchanged at least some profile data. For brand-new contacts with no profile exchange, messages may go out unsealed. This is a graceful fallback, not a failure.

What does the server still know?

Sealed sender is a big step, not a magic cloak. Honesty about the remainder matters, so here is what the server can still observe.

Checklist of what the Signal server still knows with sealed sender on
Sealed sender hides the "from", not the "to".
Hidden from the serverStill visible to the server
Which account sent the messageWhich account receives the message
The sender’s identity inside the envelopeThat a message was sent, and roughly when
Any link between sender and recipientMessage size and delivery timing at the network level
Sender identity in stored recordsYour account’s connection to the server (IP-level)

The recipient side of the table is the important one to internalize. Sealed sender hides the sender. Somebody has to receive the message, and the server must know who that is to deliver it. A server that knows every recipient and the timing of every delivery still holds meaningful metadata, just much less than before.

The honest limits of sealed sender

Four limits deserve plain statements, because each one is a misunderstanding waiting to happen.

The recipient always knows who you are. Sealed sender hides the sender from the server, not from the person you message. Your name and identity arrive with the message exactly as before. If your threat is the other person, sealed sender does nothing for you.

IP-level observation is still possible. Your internet provider can see that your device connected to Signal’s servers at a certain time. If someone can watch both the network and the server, a sophisticated adversary with access to both, timing correlation can suggest who sent what. Signal’s own documentation has always acknowledged this: a contemporaneous observation of the device and the server can reveal that an IP address reached a Signal server at a given moment.

It does not hide the fact that you use Signal. Sealed sender is about the sender field on messages, not about concealing your Signal usage from your network. If you need your provider not to know you use Signal at all, that is a different tool. A VPN or proxy changes what the network sees, while sealed sender changes what Signal’s server learns.

Group conversations are a harder case. Sealed sender’s cleanest guarantees apply to one-to-one messages. Group messaging involves more moving parts, group membership, sender keys, delivery to many recipients, and while Signal has extended sealed-sender protections toward groups, the metadata picture there is inherently richer. Treat group metadata as reduced, not eliminated.

Why does it matter?

The deepest reason sealed sender matters has nothing to do with daily convenience. It is about what happens when someone with power comes asking. A company can only hand over data it actually holds. By engineering the server so it never learns the sender, Signal removed an entire category of information from the reach of subpoenas, warrants, and breaches.

This is not theoretical. When US law enforcement demanded user data from Signal, the company was able to turn over almost nothing: the account’s creation date and its last-connection date. There was no log of who messaged whom to surrender, partly because sealed sender means the server was never told. An attacker who breaks into the server finds the same absence. You cannot leak or be compelled to share what you never collected.

There is a second, quieter benefit: it changes the company’s incentives. A business that holds rich metadata will eventually face pressure, legal, commercial, or internal, to use it. A business that engineered itself not to hold it has nothing to be pressured about. Sealed sender is as much an institutional safeguard as a technical one.

How other apps handle this

Most encrypted messengers never attempted this. Their servers see the full envelope: sender, recipient, timestamp. Some collect and store that envelope data for months or years. A few publish transparency reports showing how much messaging metadata they hand to authorities, which tells you how much they held in the first place.

That contrast is the point of this guide. Encryption of content is now table stakes among serious messengers. Hiding the sender from your own infrastructure is rare, and it is one of the clearest technical differences between Signal and apps that merely encrypt message bodies. If you want the full accounting of the little Signal does retain, the metadata guide lists it item by item.

Frequently asked questions

Is sealed sender turned on by default?

Effectively yes for normal conversations. Messages are sent sealed automatically when the sender is in the recipient’s contacts or has their Signal profile. There is also a setting to accept sealed messages from non-contacts.

Does sealed sender hide me from the person I message?

No. The recipient always sees exactly who sent the message. Sealed sender hides the sender from Signal’s servers only.

Does sealed sender slow down my messages?

No noticeable difference. The certificate handling happens in the background, and sending and receiving feel exactly the same.

Does sealed sender work in group chats?

Its cleanest guarantees apply to one-to-one messages. Signal has extended the protections toward groups, but group messaging inherently involves more metadata, so treat it as reduced rather than eliminated.

Can the police still tell I sent a message with sealed sender on?

Signal’s server would not have a record of you as the sender, so there is nothing to hand over. A sophisticated adversary watching the network itself could still use timing correlation, which is a network-level observation, not a Signal record.

Keep reading