---
title: "How a product is made: from the sketch to EMX · Elchi Studios"
description: "How Elchi Studios builds a product, with EMX as the example: the pencil sketch, the diagram it became, the code and the service that runs today."
url: https://elchi.dev/en/entstehung
language: en
---

How a product is made

# From the pencil to a running service.

Every product of Elchi Studios starts on paper. With EMX as the example: the first draft as it lay on the desk, the diagram it became, a piece of the code and the service that runs today.

Step 1

## The sketch

Squared paper and a pencil, in the night before 9 October 2026. This is how Samuel Krauss drew the path of an email through EMX before a single box was digital. We show the draft unchanged, including what was not yet right.

  

[The sketch at full size](https://elchi.dev/img/entstehung/emx-skizze-3200.jpg)

Step 2

## The diagram

It becomes a clean drawing, and on the way the facts are put straight. The draft showed four things differently from how EMX is built:

-   Reading hangs on the storage: your devices read what is kept in Geneva.
-   Outlook and Apple Mail sign in with an app password. EAuth protects the sign-in to the web client and the app.
-   Sealed is not a place of its own but a property of the mailboxes in Geneva, and you decide whether you want it.
-   The copies of the database have names: Nuremberg and Paris.

**The path of an email at EMX.** An email comes from a sender on the internet to mx.emxmail.ch, where SPF, DKIM and DMARC are checked and the spam filter runs. Messages and attachments are stored encrypted in Geneva, sealed if you want; the database is in Frankfurt, with copies in Nuremberg and Paris. Mail is read in the web client and the app with sign-in through EAuth, in Outlook, Apple Mail and on the phone over IMAP with an app password, and by your software through the API with a token. Our own servers deliver outgoing mail, signed with DKIM, to recipients on the internet.

 

The path of an email at EMX. Pointing at an area highlights its path.

Step 3

## The code

Every box is code that runs. A piece of the box mx.emxmail.ch: whether the domain in the From line matches the one SPF or DKIM confirmed. Strict means equal, relaxed means the same organisation. Only then does DMARC count.

```
func aligned(a, b string, mode dmarc.AlignmentMode) bool {
	a, b = strings.ToLower(a), strings.ToLower(b)
	if mode == dmarc.AlignmentStrict {
		return a == b
	}
	return OrgDomain(a) == OrgDomain(b)
}
```

From internal/mailauth in EMX, Go.

Step 4

## The service

What the diagram shows runs today at emxmail.ch. The security page names every exception, and status.elchi.dev measures whether it runs, with every outage at its real length.

[EMX security](https://emxmail.ch/en/security) [status.elchi.dev](https://status.elchi.dev/)

## How every product is made

First on paper, then as a diagram, then as code, then measured in operation. The next sketches will be shown here.
