Skip to main content
  1. Posts/

How email actually got built: from ARPANET to the modern inbox

··3660 words·18 mins·
Table of Contents
Computer History - This article is part of a series.
Part : This Article

Email is one of those technologies that gets older without seeming to age. The protocols are still mostly the ones written in the 1980s. The user experience has barely changed since Hotmail in 1996. The problem of figuring out who actually sent the message in your inbox is still unsolved in 2026. Yet email is where most of the world’s serious work happens. Legal contracts, recruiting pipelines, authoritative password resets, all of it still goes through this fifty-year-old store-and-forward messaging system that nobody planned but everybody depends on.

What follows is the story of how we got here. Four phases, then the corporate alternatives that ran in parallel for two decades, then a security section, then trivia with the actual dates this time.

Phase one: ARPANET origins (1965 to 1982)
#

Email predates the internet. The first mail programs ran on time-sharing mainframes in the mid-1960s as a way for users sharing the same computer to leave each other notes. MIT’s CTSS (Compatible Time-Sharing System) had a MAIL command by 1965. Berkeley’s SDC had similar facilities. None of this was networked email; it was inter-user file drops on a single machine.

The network era started with ARPANET in 1969, the four-node packet-switching network funded by the U.S. Department of Defense’s Advanced Research Projects Agency (ARPA) and built by Bolt, Beranek, and Newman (BBN). ARPANET initially had file transfer (FTP) and remote login (Telnet) but no native messaging. Ray Tomlinson, a BBN engineer, fixed that in 1971 by hacking together two existing programs: SNDMSG, a single-machine mail program, and CPYNET, an experimental file-copying utility. The result was the first email system that could send messages between different computers on a network.

Tomlinson’s other contribution was the address syntax. He needed a way to separate the user’s name from the host they were on, and he picked @ from the available teletype symbols because it didn’t appear in any username and conveniently read as “at” in English. The convention stuck. Every email address on Earth uses Tomlinson’s punctuation.

The first email message Tomlinson ever sent went to himself, between two PDP-10s sitting next to each other in his office. The popular story is that it said “QWERTYUIOP” (the top row of a keyboard), but Tomlinson said in later interviews that he didn’t actually remember what it said. The QWERTYUIOP claim is plausible folklore that hardened into “fact” through repetition.

The 1970s were the decade of email finding its protocols. The 1972 International Conference on Computer Communication in Washington D.C. featured the first public ARPANET demo with email visible to outside attendees. By 1973 the protocol had crossed the Atlantic: NORSAR in Norway connected to ARPANET in June 1973 via satellite, and University College London joined later that year. That makes the first transatlantic email connections roughly five years older than the often-cited 1978 US-UK date.

Standardization came in stages. Various competing mail formats ran on ARPANET through the 1970s (RFC 561 in 1973 defined an early standardized format; RFC 733 in 1977 standardized message headers). The protocol everyone settled on, Simple Mail Transfer Protocol (SMTP), is RFC 821 by Jon Postel, published August 1982. It’s still what the internet runs email on today, with extensions but no replacement, which is a remarkable run for a forty-plus-year-old design.

Two other firsts from this period are worth knowing. May 3, 1978: Gary Thuerk, a marketer at Digital Equipment Corporation, sent an unsolicited email to roughly 393 ARPANET users advertising a DEC product demonstration. ARPA management formally chastised him, but Thuerk later said he’d do it again because the demo sold $13-14 million worth of equipment. The first spam was profitable, which is essentially the entire story of spam. September 19, 1982: Scott Fahlman, a computer scientist at Carnegie Mellon University, posted to the CMU computer-science bulletin board suggesting :-) to mark jokes and :-( to mark non-jokes after a series of misunderstood satirical posts had derailed a thread. (The post often gets dated to 1979 in older histories. It was 1982. Fahlman’s original message was recovered from CMU backup tapes in 2002.)

Phase two: the internet era (1982 to 1995)
#

SMTP set the standard in 1982; the next decade was about making email accessible to people who weren’t on ARPANET.

The commercial dial-up services built walled gardens around centralized mail systems. CompuServe had email for its subscribers from 1979 onward; MCI Mail launched 1983; GEnie, Prodigy, and eventually AOL (1989 as Quantum Link, renamed AOL in 1991) each ran their own mail systems with their own internal addressing conventions. Users could only mail other users on the same service until inter-service gateways arrived in the late 1980s and early 1990s. AOL’s “You’ve got mail!” sound effect, introduced in 1993, became one of the most-recognized audio cues in 1990s American culture.

DNS arrived in November 1983, when Paul Mockapetris published RFCs 882 and 883. The modern revised version landed as RFCs 1034 and 1035 in November 1987. DNS replaced the central HOSTS.TXT file that ARPANET had been using to map hostnames to addresses; once DNS was in place, anyone with an internet-connected mail server could receive mail at user@domain.example without ARPANET’s blessing.

Mailing lists became the social architecture of academic email in 1986, when Eric Thomas wrote the LISTSERV software for the IBM mainframe-based BITNET network. Before LISTSERV, address lists had to be managed by hand. After it, every research community organized itself around a mailing list, and the conversations that happened on those lists drove a lot of the intellectual collaboration of the era. (Alan Emtage at McGill, who sometimes gets credited with the first listserv, actually created Archie, the FTP search engine, in 1989. The listserv attribution is a misremembering.)

MIME arrived in June 1992 with RFC 1341 from Nathaniel Borenstein and Ned Freed. It solved the fact that pre-MIME SMTP could only carry 7-bit ASCII text. After MIME, email could carry binary attachments (images, audio, video, executables), arbitrary character sets (so the rest of the world could finally send email in their own languages), and the multipart-message structure that’s how every modern email client renders content today.

Encryption arrived in June 1991 when Phil Zimmermann released Pretty Good Privacy (PGP). PGP offered end-to-end encryption using public-key cryptography, which the U.S. government decided was a munition under export-control law. Zimmermann ended up the subject of a federal criminal investigation that ran from 1993 through 1996 before being closed without charges. The export of PGP became one of the early cryptography-policy battles that shaped the modern internet.

Webmail appeared at the very end of the period. Hotmail launched July 4, 1996 with the name stylized “HoTMaiL” specifically to capitalize the H, T, M, L and emphasize that it ran in any web browser as HTML. Sabeer Bhatia and Jack Smith were the founders. Yahoo Mail followed in October 1997 (acquired from Four11’s RocketMail). Webmail was the moment email stopped requiring a special client and became something you accessed from any browser anywhere. The implications for both adoption and security were enormous.

The downside arrived alongside the upside. Spam, which had been an occasional annoyance in the 1980s, became an industrial-scale problem in the 1990s as commercial spammers learned to harvest email addresses from Usenet and the early web. By 1995 spam was a meaningful percentage of internet email traffic. By 2000 it was the majority of email volume worldwide, where it stayed for the next two decades.

Phase three: webmail, BlackBerry, and the spam wars (1995 to 2005)
#

The decade after Hotmail’s launch was when email became infrastructure. By 2000 something like half of American households had an email address. By 2005 the number was nearly everyone. The combination of free webmail (Hotmail, Yahoo, AOL Mail, eventually Gmail) and mobile email (the BlackBerry 850, launched January 1999, the first portable device people could send and receive email on without finding a payphone or a hotel modem jack) made email portable and free at the same time.

Research In Motion, the company that became BlackBerry Limited, built the 850 as a glorified pager with a thumb keyboard, push email, and a tiny screen. Wall Street and Washington adopted it almost overnight. By 2005 the BlackBerry had become the status symbol of senior professionals everywhere, and BlackBerry Messenger (BBM) was the de facto secure-messaging app for executives years before WhatsApp existed. The device shaped corporate email culture for a decade. It’s also why so many email signatures from 2003 through 2010 read “Sent from my BlackBerry, please excuse brevity and typos.”

The spam wars accelerated. Spam volume crossed 50% of email traffic in 2001, hit roughly 90% at its peak in 2008, and stayed at brutal numbers until coordinated takedowns and bayesian filtering pushed it back down. Paul Graham’s August 2002 essay “A Plan for Spam” introduced statistical (Bayesian) filtering as a technique, and it became the foundation of every modern spam filter. The CAN-SPAM Act of 2003 was the U.S. legal response; it had mixed results, largely failing at preventing spam but establishing some norms around unsubscribe handling and required disclosure of advertising. The actual technical wins came from authentication: SPF (RFC 4408, 2006), DKIM (RFC 6376, 2011), and DMARC (RFC 7489, 2015) gave receiving mail servers a way to verify that incoming mail came from the domain it claimed to come from.

Phishing became its own genre during this period. The ILOVEYOU worm, written by Onel de Guzman in the Philippines and released May 4, 2000, was technically a worm rather than phishing (it used VBScript and exploited Microsoft Outlook’s address-book access to propagate), but it taught the world that an email attachment could be a weapon. Roughly 45 million Windows machines were infected globally within 24 hours; the eventual total ran into the tens of millions more. The Philippines had no specific computer-crime law at the time, so de Guzman couldn’t be charged with anything. He later confirmed he wrote the code as a university student trying to use other people’s internet access for free.

Gmail launched April 1, 2004 with 1 GB of free storage at a time when Hotmail offered 4 MB and Yahoo Mail offered 6 MB. The launch date was the actual date, but a lot of people thought it was an April Fools’ joke because 1 GB of free email storage was implausible at the time. It was real. The storage was real. Within five years every major webmail provider had moved to multi-gigabyte free storage.

Phase four: mobile, social, and the slow death of trust (2005 to present)
#

The iPhone launched June 29, 2007 and turned the mobile phone into the primary email-reading device for most people. The transition from BlackBerry to iPhone-and-Android happened fast; BlackBerry’s market share peaked around 20% in 2009 and was effectively zero in mobile by 2016. Email had to adapt to smaller screens, touch input, and the inbox-as-stream user model that Mail.app and Gmail’s mobile clients popularized. The corporate “Sent from my iPhone” signature replaced “Sent from my BlackBerry” as the universal apology for typos.

The protocol layer kept catching up. STARTTLS encryption for SMTP became standard, mostly forced by Google publishing the percentage of inbound mail that arrived over TLS, which shamed the laggard mail providers into upgrading. DMARC adoption accelerated significantly after Yahoo Mail’s 2014 DMARC policy change broke a lot of mailing lists and forced the industry to take authentication seriously. By 2020 most major providers required DMARC alignment. In 2024 Google and Yahoo made DMARC, SPF, and DKIM mandatory for bulk senders.

Encryption at the content layer remained niche. Edward Snowden’s 2013 revelations about NSA surveillance brought attention to ProtonMail (founded 2014 by Andy Yen and team at CERN) and Tutanota (now Tuta, 2011) along with other end-to-end encrypted services, but PGP-style content encryption never went mainstream. The actual privacy improvements that did stick were at the transport layer (TLS) and at the authentication layer (DMARC), not at the contents layer. Encrypted-mail-for-everyone remains an aspiration that hasn’t survived contact with users who want to read their mail on five devices.

The 2010s and 2020s also saw the consolidation of consumer email into a handful of providers. Gmail passed 1.8 billion users by 2020 and is now the dominant consumer service worldwide. Microsoft 365 (with Outlook.com plus Exchange Online for enterprises) is the dominant business service. Apple iCloud Mail, Yahoo Mail, and ProtonMail account for most of the remainder. The independent mail provider became rare; self-hosting email became hard, because delivering reliably to Gmail and Outlook.com without getting marked as spam now requires DMARC, a clean IP reputation, and a working relationship with the receivers’ deliverability teams.

Phishing kept getting more sophisticated. AiTM (adversary-in-the-middle) phishing kits like Evilginx proxy victims through to the real M365 or Google login and steal session cookies after MFA. Helpdesk vishing campaigns (Scattered Spider’s 2023 MGM and Caesars hits being the canonical examples) bypass email entirely. The MFA story matured in painful steps: SMS codes broke in 2016, TOTP and push notifications broke under AiTM kits between 2020 and 2023, and the only phishing-resistant authentication factor that’s actually held up is passkeys and FIDO2 hardware tokens. Most of that story is in the spear phishing post .

The corporate alternatives that ran in parallel
#

SMTP won the public internet, but the corporate world ran its own mail systems for two decades. Three matter to know.

Lotus Notes, written by Ray Ozzie at Iris Associates, shipped 1.0 on December 7, 1989. It was more than mail; Notes was a document database with email built in, replication across servers, and the early-internet equivalent of a wiki plus workflow engine. Lotus acquired Iris in 1994, IBM acquired Lotus in 1995, and the product lived as IBM Notes through 2018 before HCL Technologies bought the line and rebranded it HCL Notes. Still in active use at some financial-services firms and government agencies that built their workflow on top of it twenty-five years ago and can’t migrate.

Novell GroupWise started in 1985 as WordPerfect Office and became GroupWise after Novell acquired WordPerfect in 1994. It combined calendaring, tasks, instant messaging, and mail in one product. The native client-to-server protocol is proprietary, defaulting to TCP port 1677. GroupWise supports IMAP as a supplementary protocol, but IMAP isn’t its native one. (Older histories sometimes claim GroupWise uses “a proprietary protocol called IMAP,” which is confused: IMAP is RFC 3501, an open IETF standard, and GroupWise supports it for compatibility rather than as its primary protocol.)

Microsoft Exchange Server shipped 1.0 in April 1996, and over the next two decades ate every other corporate mail server. Native protocol is MAPI/RPC, now MAPI over HTTP, wrapped in the Microsoft Exchange ecosystem with Active Directory integration. Exchange Online (the cloud version, part of Microsoft 365) is by far the dominant enterprise mail platform in 2026; the on-prem Exchange Server install base has been shrinking since around 2015 and is now mostly governments and specific compliance environments.

The thing that killed the alternative-protocol model was mobile email. Once executives wanted email on their phones, the email had to either run a native client (which BlackBerry then iOS and Android did per platform) or speak IMAP, which most consumer devices supported. Proprietary protocols without a path to mobile got left behind. Exchange survived because Microsoft built ActiveSync, the proprietary protocol that every iOS and Android device implements for syncing email with Exchange Online. Notes and GroupWise built their own mobile clients but never reached the same adoption.

The security side, as a continuing battle
#

Email’s security history is the history of the protocol designers in 1982 not anticipating that strangers would want to lie about who they were on the network. SMTP assumed every server was trustworthy and every user was who they claimed to be, which was approximately correct in 1982 and wildly wrong by 1992.

Generic phishing is still the highest-volume attack against email users: fraudulent mail claiming to be from a bank, shipping company, streaming service, with the goal of getting a click on a malicious link or a credential entered into a fake login page. Modern spam filters catch most of the obvious cases, but enough get through to keep the technique profitable.

Spear phishing and whaling are the targeted versions, customized to a specific individual using OSINT. Whaling targets executives specifically and overlaps heavily with Business Email Compromise (BEC), which is the impersonation of a senior executive (usually the CEO) directed at a subordinate (usually the CFO or an executive assistant) instructing them to wire money or buy gift cards. The FBI’s IC3 has consistently ranked BEC as the highest-dollar category of cybercrime by reported losses, ahead of ransomware in raw dollar terms. The full version of this story is in the spear phishing post .

Malware-via-attachment has shifted vectors as Microsoft tightened defaults. Macro-bearing Office documents were the dominant payload through about 2022; the modern delivery uses ISO and IMG containers (which strip Mark-of-the-Web from their contents when mounted), OneNote attachments, HTML smuggling, or LNK-in-archive. The goal is the same; the wrapper changes.

Spoofing (forging the From: header to make a message look like it came from a trusted sender) has mostly been defeated by DMARC alignment for well-configured senders. It’s still rampant against domains that haven’t deployed DMARC, which in 2026 is fewer organizations than you’d hope.

The defensive layer that actually works combines phishing-resistant MFA (FIDO2/passkeys), strict DMARC alignment, and user training that gets people to pause before clicking. None of these fixes the problem completely; they reduce the failure rate from regular catastrophe to occasional incident.

Trivia
#

The kind of facts that get a party conversation going, with the actual dates instead of the AI-mangled ones that have started showing up:

  1. The first spam was sent May 3, 1978 by Gary Thuerk, a Digital Equipment Corporation marketer, advertising a DEC product demo to roughly 393 ARPANET users. ARPA management formally chastised him; he later said he’d do it again because the demo sold $13-14 million worth of equipment.
  2. The first email attachment was sent in 1992 by Nathaniel Borenstein, one of MIME’s authors, demonstrating the new MIME multipart encoding to fellow researchers. It was a photo of the all-female CERN doo-wop group Les Horribles Cernettes.
  3. Hotmail really was stylized “HoTMaiL” with capital H, T, M, L. The marketing point was that it ran in any web browser using HTML. Launched July 4, 1996 by Sabeer Bhatia and Jack Smith.
  4. “Spam” as a term for unwanted email comes from the 1970 Monty Python sketch where a group of Vikings drown out a restaurant conversation by singing “Spam, spam, spam, spam, lovely spam, wonderful spam” louder and louder. Adopted by MUD and BBS users in the early 1980s to describe annoying repetitive messages.
  5. The first email from space was August 9, 1991 from Space Shuttle Atlantis on STS-43, sent by Shannon Lucid and James Adamson via AppleLink on a Macintosh Portable to Marsha Ivins at Johnson Space Center. Message: “Hello Earth! Greetings from the STS-43 Crew. This is the first AppleLink from space.” (Older histories sometimes claim Tim Kopra sent the first email from space in 2016, which is wrong by twenty-five years.)
  6. Clinton, not Obama, was the first sitting U.S. president to send an email from office. Clinton sent one to John Glenn aboard Space Shuttle Discovery on November 7, 1998. Obama (2009 onward) was the first to use email regularly and keep a BlackBerry in office; the “first ever” claim is folklore.
  7. Gmail launched April 1, 2004 with 1 GB of free storage when Hotmail offered 4 MB and Yahoo Mail offered 6 MB. People thought the announcement was an April Fools’ joke. It wasn’t. Within five years every competitor had matched and exceeded it.
  8. The first emoticon was September 19, 1982, when Scott Fahlman posted to the Carnegie Mellon computer science bulletin board suggesting :-) for jokes and :-( for non-jokes. Fahlman’s original message was recovered from backup tapes in 2002 by Jeff Baird.
  9. Ray Tomlinson picked the @ symbol from the available teletype symbols because it didn’t appear in any username and conveniently read as “at” in English. He sent the first networked email in 1971 between two PDP-10s in his BBN office. The popular “QWERTYUIOP” message-content story is folklore; Tomlinson said he didn’t actually remember what the test message said.
  10. Phil Zimmermann released PGP on June 5-6, 1991, providing the first practical end-to-end email encryption. The U.S. government opened a federal criminal investigation against him in 1993 under arms-export laws, because public-key cryptography was classified as a munition. The case was closed without charges in 1996.

Closing
#

Five decades since Tomlinson typed his test message between two computers in the same room, email is still the medium where most of the world’s serious correspondence happens. The protocols haven’t been replaced. SMTP from 1982 is what every mail server speaks. MIME from 1992 is how attachments work. The IETF email working groups keep producing extensions rather than successors. The user experience hasn’t fundamentally changed since Hotmail in 1996. The security problems have all been there since 1978 when Gary Thuerk sent the first spam.

What has changed is the scale. Roughly 350 billion emails get sent per day worldwide in 2026, and a meaningful share is spam by most estimates. The infrastructure has concentrated into a handful of providers (Gmail, Microsoft 365, Apple, Yahoo, ProtonMail) that handle the vast majority of consumer and business email. The defensive layer has matured into an alphabet soup of authentication standards (DMARC, DKIM, SPF, BIMI, MTA-STS, TLS-RPT) that didn’t exist in the 2010s. The offense has matured faster, with AiTM kits, helpdesk vishing, and deepfake-voice executive impersonation as the current state of the art.

The medium is older than most of the people who use it and more pervasive than any of its designers planned. It’s also, somehow, still the most reliable way to send a stranger a verifiable message. The history isn’t over and the protocol is still mostly the same.

UncleSp1d3r
Author
UncleSp1d3r
As a computer security professional, I’m passionate about building secure systems and exploring new technologies to enhance threat detection and response capabilities. My experience with Rails development has enabled me to create efficient and scalable web applications. At the same time, my passion for learning Rust has allowed me to develop more secure and high-performance software. I’m also interested in Nim and love creating custom security tools.
Computer History - This article is part of a series.
Part : This Article