The dirty secret of digital time capsules is that they mostly fail.
Not the writing part. The writing goes fine. Millions of people, every year, sit down and pour something honest into a form on a website, hit send, and feel the little rush of having done a small good thing for a future stranger. That part works.
What fails is the arriving.
Here are three cases from the last twenty-five years, in order of scale.
Forbes E-Mail Time Capsule (2000, ~140,000 letters)
In 2000, Forbes ran a project called the E-Mail Time Capsule. The pitch was simple: write a letter, pick a delivery date, and Forbes would send it to you in one, three, five, ten, or twenty years. Around 140,000 people participated. Twenty years was the longest window offered.
The letters were meant to start arriving in 2005. Many of them didn't.
The technical partner Forbes chose had layoffs in the first few months. The delivery system they built didn't work — a lot of the earliest emails were, according to later reporting, never actually sent. Forbes itself was sold, changed hands more than once, and the team that had originally run the project was long gone by the time the 2020 letters were due.
Some 2020 letters did arrive. The ones that did were widely written about because they were unusual. Twenty years is a long time, and by the end of that window, the original setup — the company, the technical stack, the people who knew where the letters were stored — had all been through so many transformations that the fact that anything came out the other end at all was surprising.
The lesson wasn't that Forbes did anything malicious. They did what most companies do: they ran a marketing project, ownership changed, priorities shifted, and something that had a twenty-year commitment attached to it ended up being maintained by no one in particular.
OhLife (shut down 2014)
OhLife wasn't strictly a time capsule service. It was a personal journal — you'd get an email every evening asking how your day went, and your reply would be stored as an entry. But the shape of it, especially the ten-year subscription many users signed up for, meant a lot of people were treating it as one.
In October 2014, the company announced it was shutting down. Users had a few weeks to export their data. If you missed that window — because you were out of town, because the email went to spam, because you'd stopped checking that inbox and were counting on the service to hold your writing until you were ready to come back — your entries were deleted.
There was no promised delivery date for OhLife journals. There was no ceremony of a letter arriving. But the emotional weight was similar: years of small, honest daily writing, stored on someone else's servers, gone.
The dozens of smaller ones nobody wrote about
For every OhLife and every Forbes project, there were dozens of small services with names like "MailToFuture" or "Emailyourselflater.com" that quietly stopped responding. Most of them didn't announce a shutdown. The domain expired, or the founder graduated and got a job, or the server bill stopped getting paid.
There's no scandal in any individual case. Someone built a thing, they moved on, life happened. That's normal. What's not normal is that the letters people entrusted to those services stopped being letters — they became rows in an abandoned database, and then bits on a hard drive somewhere, and then nothing.
What actually goes wrong
Boiled down, there are four failure modes. Every service that lost letters lost them to one or more of these.
1. The company changes. Ownership sells, priorities move, the person who understood the delivery system leaves and takes their knowledge with them. Even without shutting down, a company can quietly stop being able to keep an old promise.
2. The tech partner changes. In the Forbes case, the delivery mechanism itself was outsourced, and the outsourced vendor had its own turbulence. If your letter's arrival depends on a chain of three vendors and one of them goes down at the wrong moment, the letter doesn't arrive.
3. The recipient changes. Ten years is long enough for people to change jobs, change providers, get hacked, lose access to their old email, or die. Even a perfectly reliable service can send a letter to an address that no longer receives mail. Then it bounces, is retried some number of times, and disappears.
4. The service disappears without notice. No email, no export window, just a domain that stops resolving. Everything stored there is gone.
What to check before trusting a service with a ten-year letter
You can't verify all of these from the outside. But you can check some of them, and even asking the questions gets you further than most people go.
Read the terms of service. Specifically look for what happens if the company shuts down. Most services don't mention it. Silence in this section is a real answer — it means whoever wrote the terms didn't want to promise anything about that scenario.
Read the privacy policy for retention. How long does the service hold your letter after delivery? Some services archive or delete content within thirty days of arriving. If you were hoping to have the letter to reread later, that's a nasty surprise.
Ask what happens if the delivery bounces. How many retries. Over what period. What happens after that. "We'll try five times and give up" is a very common answer. Ten years is a long time; a lot can bounce.
Give a backup address, if they'll let you. The number of services that only accept one email address for a decade-long letter is embarrassing. If a service can't hold two addresses, they're not really taking the ten-year part seriously.
Look for evidence of a dead man's switch. This is the one thing that would actually save your letter if the service shuts down: some mechanism where, if the company ends, every unopened letter is delivered early instead of destroyed. Vanishingly few services have this. Ask.
Why we built this the way we did
Full disclosure: I built the service you're reading this on. So this section is going to sound like marketing. It is, and it isn't — the whole reason the service exists is that the four failure modes above pissed me off.
The letters you seal here go through a multi-channel delivery chain — not just one email, and not just five retries. If the primary address fails, we try the backup. If that fails, we hold the letter in a claim queue for at least three years and keep trying. And if the service itself ever ends — because I do, or because it stops being viable — a scheduled task delivers every unopened letter early, before the servers go dark. That's a real switch, wired in from day one, and it's in the terms of service, not just this blog post.
None of that guarantees anything. Nothing does. But it's the difference between a service that hopes you'll never notice and one that treats "actually arriving" as the whole point.
The graveyard of dead time capsule services is bigger than most people realize. Whichever service you use, ask the questions in the section above. Yours might be one of the good ones. But you should find out on purpose, not by accident, ten years from now.