Comparing email provider privacy
Which email provider actually keeps your mail private? It’s easy to pick on cost or storage and then discover the host sits in a Five Eyes jurisdiction, holds the only key to your messages, never publishes a transparency report, and quietly turns over data on request. This article compares mainstream and privacy-focused email providers under a single Privacy Impact score. Every claim is sourced from the provider’s own legal terms with a verbatim quote — and a reusable prompt lets you score any provider not listed here.
Functionality (custom domains, catch-all, IMAP, storage) and pricing are kept in a separate appendix — they matter for picking a provider but they aren’t privacy.
Free Big Tech webmail — Gmail, Outlook.com / Hotmail, Yahoo Mail, AOL Mail, iCloud Mail — is structurally excluded from the per-provider scoring rather than given a low numeric rank. These services are worst-in-class on every axis of the rubric simultaneously — see Out of scope for the sourced detail.
Acronym glossary
- E2EE — End-to-end encryption. Only sender and recipient can read the message; the provider cannot.
- Zero-access encryption. Provider stores ciphertext only and holds no key that can decrypt it.
- PGP / S/MIME. Standards for encrypting individual messages with user-managed keys.
- 5 / 9 / 14 Eyes. Intelligence-sharing alliances. 5 Eyes: USA, UK, Canada, Australia, New Zealand. 9 Eyes adds Denmark, France, Netherlands, Norway. 14 Eyes adds Germany, Belgium, Italy, Spain, Sweden.
- CLOUD Act. US statute compelling US-incorporated providers to produce data stored anywhere globally.
- DPA — Data Processing Agreement. GDPR contract naming the provider as processor acting on customer’s instructions.
- GDPR. EU General Data Protection Regulation.
- DSA. EU Digital Services Act — transparency-reporting obligations.
- Catch-all. Mailbox that receives mail for any address at a custom domain, including ones that don’t exist.
- IMAP / SMTP / POP3. Open protocols for receiving (IMAP/POP3) and sending (SMTP) mail — required to use a third-party client and avoid lock-in.
Contents
Ranking
See the detailed comparison for per-attribute breakdown, or the scoring framework at the end. Click any column header to re-sort.
| Provider | Privacy Impact |
|---|---|
| Proton Mail | LOW1 |
| Mailbox.org | MEDIUM4 |
| Mailfence | MEDIUM4 |
| Tuta | MEDIUM4 |
| Infomaniak kMail | MEDIUM5 |
| Kolab Now | MEDIUM5 |
| Posteo | MEDIUM5 |
| CounterMail | MEDIUM6 |
| StartMail | MEDIUM6 |
| Eclipso | MEDIUM7 |
| Murena Mail | MEDIUM7 |
| Vivaldi Mail | MEDIUM7 |
| Hostpoint | MEDIUM8 |
| Inbox.eu | MEDIUM8 |
| Migadu | MEDIUM8 |
| Runbox | MEDIUM8 |
| GMX | HIGH9 |
| Mailo | HIGH9 |
| Riseup | HIGH9 |
| Seeweb | HIGH9 |
| WEB.DE | HIGH9 |
| Disroot | HIGH10 |
| Gandi Mail | HIGH11 |
| Iroco | HIGH11 |
| Combell | HIGH12 |
| Raidboxes | HIGH12 |
| Soverin | HIGH12 |
| Fastmail | HIGH13 |
| Hushmail | HIGH13 |
| Lavabit | HIGH13 |
| MXroute | HIGH14 |
| Namecheap Private Email | HIGH14 |
| Zoho Mail | HIGH14 |
Out of scope (discontinued or otherwise excluded from scoring):
- Free Big Tech webmail — Gmail, Outlook.com / Hotmail, Yahoo Mail, AOL Mail, iCloud Mail, and their non-US peers, worst-in-class on every axis at once.
- Skiff — built-in E2EE provider acquired by Notion and sunset entirely in 2024.
- CTemplar — Iceland-hosted OpenPGP provider that shut down on 2022-05-26 (founder cited the inability to “guarantee our security claims”).
- Alias and relay services — SimpleLogin, addy.io, Firefox Relay, DuckDuckGo Email Protection: a complement to a mailbox host, not a replacement for one.
To score a provider not listed here, use the audit prompt at the end of the article.
Comparison
Lower score = less the provider’s policy authorises them to do with your mail. The full scoring rubric is at the end of the article. Click any column header to re-sort.
| Provider | HQ | Hosting | Zero-access encryption | Gov-access posture | Anon signup | Privacy Impact |
|---|---|---|---|---|---|---|
| Proton Mail | Switzerland | Switzerland + Germany + Norway | Built-in E2EE + zero-access (body, subject, attachments, calendar, contacts) | Transparency report + Swiss-law user notification | Tor onion + Bitcoin + cash + bank transfer | LOW1 |
| Mailbox.org | Germany | Germany | Built-in PGP/S/MIME via Guard | Transparency report | Tor + anonymous payment + cash | MEDIUM4 |
| Mailfence | Belgium | Belgium (Mailfence-operated, “no intermediary or subcontractor”) | Integrated webclient OpenPGP; server holds passphrase-encrypted private keys (4096-bit default) | Biannual transparency report + warrant canary (“never received any US National Security Letters or FISA court orders”); no notification commitment | Tor supported (no .onion); Bitcoin + Litecoin + PayPal + wire; no real-name verification | MEDIUM4 |
| Tuta | Germany | Germany | Built-in E2EE incl. subject lines | Transparency report + warrant canary | Tor signup; no anon payment | MEDIUM4 |
| Infomaniak kMail | Switzerland | Switzerland (Infomaniak-owned data centres) | Opt-in per-message OpenPGP; private keys stored on Infomaniak infrastructure (“Private keys never leave Infomaniak’s infrastructure”) | Notification-with-carve-out commitment, but no transparency report and no warrant canary | Real name + valid mobile + verifiable info required; no Tor; cards/PayPal/PostFinance/Twint only | MEDIUM5 |
| Kolab Now | Switzerland | Switzerland (Bern data centre, IBM hardware-encrypted storage) | Webclient OpenPGP with server-stored keys — provider explicitly admits “Providing true end-to-end encryption can only really be achieved by client encryption” | Annual transparency report (irregular cadence — “we have missed a few of those reports”); no warrant canary; no notification commitment | Tor not stated; Bitcoin suspended; PayPal/cards/bank transfer only; name + address required for billing | MEDIUM5 |
| Posteo | Germany | Germany | Built-in opt-in Krypto-Mailspeicher (incl. subject + header) | Transparency report only | Cash by mail + no signup data | MEDIUM5 |
| CounterMail | Sweden (14 Eyes) | Sweden | Built-in OpenPGP zero-access for message body + attachments (RSA-4096; private PGP key stored anonymously and encrypted with user password via zero-knowledge proof); subject + From/To/Date headers + folder names remain plaintext | Posture statement only — “will not accept an order from any organization or investigative agency that is outside Sweden”; no published transparency-report numbers, no warrant canary, no user-notification commitment | No .onion; cash wire transfer + prepaid Visa/Mastercard accepted; Bitcoin disabled for new accounts since 2024-06-18; invite-only since 2020-11-01 with the homepage stating “Service is closed for new registrations!” | MEDIUM6 |
| StartMail | Netherlands | Netherlands | Vault at-rest + opt-in PGP (server-stored key) | Transparency report only | Bitcoin (annual plans only); Tor not stated | MEDIUM6 |
| Eclipso | Germany | Germany | Native OpenPGP + S/MIME with server-stored private key (passphrase-encrypted) | Annual transparency report only | Anonymous signup allowed; no Tor; PayPal/Klarna/prepay only | MEDIUM7 |
| Murena Mail | France | Finland (Hetzner Helsinki HEL1, off-site backups in Falkenstein DE) — Finland sits outside 5/9/14 Eyes | None native — opt-in OpenPGP via SnappyMail webmail + Mailvelope browser extension (third-party); document vault is E2EE via Cryptpad but mail itself is not zero-access | Nothing published; no warrant canary; no user-notification commitment | hCaptcha at signup; mandatory non-Murena recovery email; Bitcoin via BitPay accepted on the shop; Tor not stated; no real-name required (username + recovery email only) | MEDIUM7 |
| Vivaldi Mail | Norway | Iceland (Hringdu data centers per Vivaldi Sync policy; mail-specific server location not stated in any Vivaldi policy doc) | None native — opt-in OpenPGP via Roundcube + Mailvelope (key sits on Vivaldi’s webmail server per staff statement); not zero-access; messages stored unencrypted at rest by default | Nothing published; no warrant canary; no user-notification commitment; “with exceptions only requested by law or court order” | Tor not stated; no paid tier so no anonymous-payment path; mandatory non-Vivaldi recovery email; reputation-gated signup since May 2023 (criteria “not shared publicly”) | MEDIUM7 |
| Hostpoint | Switzerland | Switzerland (Digital Realty Glattbrugg) | None — TLS in transit + generic “encrypted where possible” at rest; no PGP | Nothing published; broad disclosure clauses | Real ID required, document verification possible; no crypto/cash; no Tor stated | MEDIUM8 |
| Inbox.eu | Latvia (outside 5/9/14 Eyes) | Latvia (Inbokss-owned, Riga data centre) | None — marketing claims “End-to-end encryption” but the help-center article defines it as TLS in transit only; no PGP / S/MIME | Nothing published; ToS §4.6 explicitly authorises disclosure to “subpoenas, court orders or requests from official bodies”; marketing-vs-ToS conflict on government sharing | Real name + birth date + gender required; phone validation effectively mandatory; cards/PayPal/SEPA/bank transfer only — no crypto/cash; Tor not stated | MEDIUM8 |
| Migadu | Switzerland | France | None — explicitly refuses | Nothing published | Bitcoin off-site only | MEDIUM8 |
| Runbox | Norway | Norway (Runbox-owned servers, DigiPlex Oslo) | None built-in (hardware SSD encryption + opt-in third-party PGP) | Transparency report + Norwegian-court-order disclosure policy; no canary, no notification clause | Bitcoin + Coinbase Commerce + cash by mail; Tor not officially documented but not blocked | MEDIUM8 |
| GMX | Germany | Germany (1&1 Mail & Media GmbH data centres, “E-Mail made in Germany” alliance) | Opt-in via third-party Mailvelope browser extension (Chrome/Firefox only); WEB.DE/GMX webmail itself has no native PGP — subjects/metadata stay plaintext | Annual Jahresbericht hosted only at the WEB.DE-branded URL, not on any GMX-branded property (same legal entity, 46.32M total mailboxes); no notification commitment; no canary | Mobile-phone-number-style verification + real name + address required; “Consent or Pay” tracking model on free tier; cards/SEPA/PayPal only — no crypto/cash; Tor not stated; paid tiers offered only to DE/CH/AT residents on gmx.net | HIGH9 |
| Mailo | France | France | Server-side PGP (provider stores keypair) | Nothing published | Card/PayPal only; real names asked | HIGH9 |
| Riseup | USA (5 Eyes, 501(c)(4) nonprofit) | Not stated (US assumed) | Personally-encrypted storage for new accounts (StartMail-style; server unwraps key per session) | Active warrant canary; no published request stats | Tor onion + invite signup + Monero/Zcash/Bitcoin/cash | HIGH9 |
| Seeweb | Italy | Italy (Seeweb-owned data centres in Milan + Frosinone; partner facilities in Lugano/Zurich/Sofia) | Server-side plaintext — provider performs content-level antispam/AV inspection and full daily backups via IBM Spectrum Protect; opt-in client-side PGP in Roundcube webmail | Nothing published; no notification commitment; no warrant canary; no public DPA template | Full business data required at signup; PayPal/SEPA/RID/bank transfer only — no credit cards, no crypto, no cash; Tor not stated | HIGH9 |
| WEB.DE | Germany | Germany (1&1 Mail & Media GmbH data centres, “E-Mail made in Germany” alliance) | Opt-in via third-party Mailvelope browser extension (Chrome/Firefox only); WEB.DE webmail itself has no native PGP — subjects/metadata stay plaintext | Annual Jahresbericht 2025 (608 content disclosures + 1,681 G10/§100a interception orders against 46.32M mailboxes); no notification commitment; no canary | Working mobile phone number mandatory at signup; real name + address required; ad-financed FreeMail with non-cancellable weekly newsletter; cards/SEPA/PayPal only — no crypto/cash; Tor not stated | HIGH9 |
| Disroot | Netherlands | Netherlands | None — “emails… are stored unencrypted on our servers”; opt-in user-managed PGP only | Nothing published | Minimal signup data, but no Tor or anon payment documented | HIGH10 |
| Gandi Mail | France | France + Luxembourg | None (customer responsibility) | DSA transparency report | Not stated | HIGH11 |
| Iroco | France | France (OVH Roubaix) | None — Postfix/Cyrus stack; only the user password is “stored in encrypted form”; no PGP integration | Nothing published; no canary; no notification commitment | Tor explicitly blocked at signup; SEPA via GoCardless only — no cards/PayPal/crypto/cash; real name + address required | HIGH11 |
| Combell | Belgium | Belgium + Netherlands (team.blue group) | None — “hard disk encryption software” generically; provider-side telecommunications-secrecy claim only | Nothing published; explicit confidential cooperation with authorities | Real ID required; no crypto/cash; no Tor stated | HIGH12 |
| Raidboxes | Germany | Marketed as Germany — actual IMAP/SMTP on *.securemail.pro (Register S.p.A. cert, Italy) | None — PGP listed only as “Optional”, key custody not disclosed | Nothing published | SEPA + cards (GoCardless/checkout.com) only — no crypto, no cash, no PayPal; no Tor stated | HIGH12 |
| Soverin | Netherlands | Netherlands | None for live mailbox (TLS + disc encryption only); per-user backup encryption is narrow | Nothing published | Phone required at signup; Mollie (cards/iDeal) only — no crypto/cash | HIGH12 |
| Fastmail | Australia (5 Eyes) | USA (5 Eyes, CLOUD Act) | None in own apps; opt-in PGP/S-MIME via 3rd-party clients | Transparency report + user notification | Cards/PayPal only | HIGH13 |
| Hushmail | Canada (5 Eyes) | Canada (5 Eyes) | Server-side PGP for webmail (key decrypted on server) | Explicit non-notification | Not stated | HIGH13 |
| Lavabit | USA (5 Eyes) | Not stated (US ISP) | Opt-in “secure” mode only; DIME products still “in development” | Nothing published (transparency report planned only) | Not stated; pricing/payment methods not on public site | HIGH13 |
| MXroute | USA (5 Eyes) | USA (5 Eyes, CLOUD Act) | None | Nothing published | Not stated | HIGH14 |
| Namecheap Private Email | USA (5 Eyes, CLOUD Act) | USA (default; “may transfer Customer Data to the United States”) | None | Nothing published | Bitcoin via BitPay/BTCPay; Tor not stated | HIGH14 |
| Zoho Mail | USA + Netherlands + India | User-selected: US / EU / CN / IN / AU / JP | None default; opt-in PGP scope undocumented | Nothing published | Not stated | HIGH14 |
Proton Mail wins outright: Swiss jurisdiction with no Five-Eyes treaty exposure, hosting only in Switzerland/Germany/Norway, built-in E2EE + zero-access for body, subject, attachments, calendars and contacts, a Tor onion site for signup, cash and crypto payments, and a non-profit foundation as primary shareholder ruling out a future acquisition. Mailbox.org, Mailfence and Tuta tie for second on MEDIUM 4 — Mailbox.org has the broadest anonymous-signup story (Tor exit node + cash), Mailfence pairs biannual transparency reporting and an actively-resigned warrant canary (“never received any US National Security Letters or FISA court orders”) with Tor + Bitcoin/Litecoin signup and a 27-year operating history under Belgian ContactOffice Group SA, and Tuta is the only mainstream provider that encrypts subject lines server-side. Posteo and StartMail sit in the upper MEDIUM band — Posteo loses points for no canary or notification commitment but is the only provider that refuses custom domains as a privacy-by-data-minimisation choice; StartMail (Netherlands) pairs Dutch hosting with annual Bitcoin payments and a transparency report but no warrant canary, no Tor mention, and only server-side OpenPGP. CounterMail also ties StartMail at 6 — the only provider in this comparison that ships built-in zero-access OpenPGP for message bodies and attachments by default (RSA-4096; private key stored anonymously, decryptable only by the user’s zero-knowledge-proof password) and the only one whose own docs claim “we NEVER logged any user IP-addresses during our 15 year history” (subject + From/To/Date headers and folder names still remain plaintext by CounterMail’s own admission). The trade-off is severe: no transparency-report numbers, no warrant canary, no notification commitment, no DPA, no GDPR documentation, a 214-word privacy policy, signup has been invite-only since 2020-11-01 with the homepage literally saying “Service is closed for new registrations!”, and Bitcoin payments were disabled for new accounts on 2024-06-18 with the changelog warning “All types of Crypto payments will be stopped before the end of this year”. Infomaniak kMail and Kolab Now both match Posteo at 5 with Swiss jurisdiction and Swiss-only hosting but with different weaknesses: Infomaniak loses ground on real-name + valid-mobile-phone signup, no published transparency report, and an opt-in-per-message PGP feature where “Private keys never leave Infomaniak’s infrastructure” — the May 2026 Infomaniak Foundation governance change (permanent blocking shares) is a structural plus, though founder Boris Siegenthaler’s June 2025 LinkedIn statements “opposing online anonymity” and criticising free privacy services are an out-of-band signal worth weighing. Kolab Now is unusually candid that its webclient OpenPGP “is not end-to-end encryption” because the server holds the keys, publishes an annual-but-irregular transparency report (Jan 2026 report covering 2025: 5 administrative requests, 1 rejected; 0 metadata/data/wiretap requests), has no warrant canary, and currently has no anonymous-payment route (Bitcoin was suspended pending the new billing platform) — its biggest functional pain is that enabling TOTP 2FA disables IMAP/POP/DAV/ActiveSync entirely (“will only be able to use the web client”). Eclipso (Germany) bridges MEDIUM and HIGH: native OpenPGP and S/MIME with a server-stored private key plus an annual transparency report, but no Tor and no anonymous payment. Murena Mail and Vivaldi Mail also tie Eclipso at 7 — both are community-perk webmails attached to a larger ecosystem (Murena to the /e/OS degoogled-Android project run by the French non-profit e Foundation, Vivaldi to the Vivaldi browser run by Vivaldi Technologies AS in Oslo) and both inherit good jurisdictional hygiene without ever rising to a privacy-grade provider in the Proton/Tuta sense. Murena hosts on Hetzner Helsinki HEL1 (Finland sits outside 5/9/14 Eyes) with off-site backups in Falkenstein DE, accepts Bitcoin via BitPay on the paid Workspace tiers (1,99€/mo for 20 GB), and offers a built-in Google migration tool — but mail itself is not zero-access (opt-in OpenPGP via SnappyMail + Mailvelope, with Murena’s own roadmap saying “True end-to-end encryption … for mails is in our plans as long-term features”) and the 2024 Crowdcube equity raise (€786k from 545 investors) is the only thing keeping it out of the >10-year-bootstrapped band. Vivaldi Mail is free and gated by a deliberately opaque reputation system (“details about how the reputation system works are not shared publicly”) — IP addresses are logged for up to three months for incoming mail, mail bodies are not encrypted at rest by default (per Vivaldi staff on the Vivaldi-hosted forum: “the key is on the webmail server, so someone with access to both could theoretically decrypt it”), and the Vivaldi-owned mail-specific docs do not name a server location (the Iceland/Hringdu attribution comes from the Sync privacy policy and SMTP network-level evidence, not from any mail-specific Vivaldi document). Both publish no transparency report, no warrant canary, and no notification commitment — and Vivaldi’s own email-signup page openly recommends two competitors (“Proton Mail — From €3/month” and “Fastmail — From $5/month”) alongside its free option, which is itself a useful editorial signal. Hostpoint lands at 8 — a 25-year-old Swiss owner-operated host with Swiss-only data residency, but the email product offers nothing beyond TLS in transit and a generic “encrypted where possible” claim at rest, no transparency report, no warrant canary, no anonymous payment, and catch-all is explicitly disclaimed (“Hostpoint does not offer catch-all addresses”). Migadu sits at the bottom of MEDIUM: Swiss company but hosted in France, no built-in encryption, no government-access posture. Runbox also ties at 8 — Norwegian-court-order disclosure policy, a transparency report updated as of 2026-05-12, employee ownership (77.54% in 2024), and Bitcoin / Coinbase Commerce / cash-by-mail payment claw back ground that the lack of native zero-access (Runbox 7’s promised PGP and FIDO2 still unshipped 7+ years on) and lack of warrant canary lose. Inbox.eu also ties at 8 — the lowest-scoring Latvian/Baltic provider in the comparison, helped by Latvia being outside 5/9/14 Eyes and by Inbokss being bootstrapped since 1998, but its marketing page advertises “End-to-end encryption” while the help-center article titled “End-to-end encryption” defines it as TLS in transit only (no PGP, no S/MIME, no zero-access). Two surfacing conflicts: the marketing FAQ says deletion completes “within 7 days” but the Privacy Policy §5.1 commits to “within one year”, and the marketing privacy page promises “we do not store or share your personal information with third parties – neither government agencies nor advertisers” while ToS §4.6 explicitly authorises disclosure to “subpoenas, court orders or requests from official bodies”. The HIGH band groups providers with at least one of: 5-Eyes hosting, no zero-access encryption, or opaque government-access posture. Mailo (France) lands at the top of HIGH — French hosting and law, server-side PGP, but no transparency report, no anonymous payment, and identifying data asked at signup. Riseup ties Mailo at 9 — the US jurisdiction and US-based servers cost it 6 points, but personally-encrypted storage, an active warrant canary, Tor onion services, and donation routes via Monero/Zcash/cash claw most of that back; the 2017 sealed-warrant compliance is documented openly in their canary statement. WEB.DE and GMX also tie at 9 — both are operated by the same German legal entity (1&1 Mail & Media GmbH, indirect subsidiary of publicly-listed United Internet AG on the Frankfurt Xetra ticker UTDI). Servers are stated to live exclusively in Germany, the parent publishes a single entity-level annual Jahresbericht (608 content disclosures + 1,681 G10/§100a interception orders against 46.32M mailboxes in 2025), and the only PGP path is opt-in via the third-party Mailvelope browser extension (Chrome/Firefox only — subjects and metadata stay plaintext). Both require real identifying details + working mobile number at signup and are funded by an ad + tracking model the parent calls “Consent or Pay” — free FreeMail comes with a non-cancellable weekly newsletter that “finances FreeMail”. Seeweb also ties at 9 — an Italian SMB host operating since 1998 (rolled into publicly-listed DHH S.p.A. on Euronext Growth Milan in 2020), Cloud Mail is server-side plaintext with content-level antispam/AV inspection and a Roundcube opt-in PGP feature, no transparency report, no canary, no public DPA template, payment is PayPal/SEPA/bank transfer only (no credit cards, no crypto, no cash), and adherence to the CISPE Code of Conduct (positive EDPB opinion 2021-05-19, CNIL approval 2021-06-03) is its strongest formal compliance signal. Disroot is the lone non-profit in mid-HIGH: Dutch foundation, Dutch hosting, minimal signup data — but “emails… are stored unencrypted on our servers” unless the user runs their own PGP, no transparency report, and no anonymous payment documented. Iroco (France) ties Gandi at 11 — a 2020-founded SAS with OVH-Roubaix hosting and a 2 000 € share capital, no PGP integration on the Cyrus/Postfix stack, no transparency report, no warrant canary, and uniquely in this comparison Tor is explicitly blocked at signup (“we do not allow signup from a TOR address”) — the January 2025 Russian spam-abuse incident also led Iroco to drop its free trial and accept SEPA-only payment via GoCardless (no cards, no PayPal, no crypto, no cash), so anonymous signup is structurally impossible. Combell and Raidboxes both tie Soverin at 12 as the team.blue group’s three entries in this comparison. Combell (Belgium / Netherlands hosting, ISO 27001 since 2011) backstops nothing technical between a court order and your mailbox — an explicit “Combell will fully cooperate with law enforcement authorities” AUP clause, no zero-access, no transparency report, and team.blue PE ownership (Hg + CPP Investments + Sofina at a €4.8bn 2024 valuation). Raidboxes markets “Server location Germany” and “Own infrastructure, no third-party providers”, but the actual IMAP/SMTP endpoints run on *.securemail.pro whose TLS certificate is issued to Register S.p.A. in Florence — a fellow team.blue subsidiary acquired alongside Raidboxes via the June 2022 HTGF exit — one connected domain per mail plan, and TOTP/email/SMS 2FA only. Soverin (Netherlands) rounds out the trio at 12 — Dutch hosting helps but there is no native E2EE, no transparency report, no warrant canary, a phone number is required at signup, and a 2024 “joining The Sharing Group” move adds parent-portfolio risk to a previously independent provider. Lavabit ties Fastmail and Hushmail at 13 despite its principled 2013 shutdown (Ladar Levison refused to surrender TLS keys to US authorities): the present-day service has US jurisdiction, no published transparency report, no documented pricing, and most fields are literally “Not stated” in its own docs. Namecheap Private Email ties MXroute and Zoho at the bottom — US registrar with US-default hosting, no transparency report, no E2EE, though it does accept Bitcoin via BitPay/BTCPay. Skiff would have scored well on technical posture (built-in E2EE for body and subject) but was acquired by Notion and sunset entirely in 2024; CTemplar had an equally strong on-paper posture (Iceland-hosted, RSA-4096 OpenPGP, anonymous BTC/XMR, Tor onion, explicit warrant canary) but shut down on 2022-05-26 after a July 2021 catastrophic data-loss incident, with founder citing the inability to “guarantee our security claims to our users”. Both are included as
out-of-scope cautionary cases rather than ranked — different acquisition paths to the same outcome.
Provider profiles
Proton Mail
Privacy Impact: LOW1 — Strongest privacy posture of the providers compared.
- Name: Proton Mail — operated by Proton AG, Geneva, Switzerland; primary shareholder is the non-profit Proton Foundation
- URL:
proton.me/mail - HQ jurisdiction: Switzerland (outside 14 Eyes) GOOD0
- Hosting jurisdiction: Switzerland, Germany, Norway GOOD0
- Zero-access encryption: Built-in E2EE + zero-access for body, attachments, subject lines, calendars, contacts; sender/recipient and IP metadata exposed for SMTP delivery GOOD0
- Government-access posture: Annual transparency report; Swiss law requires authorities (not Proton) to notify subjects of judicial procedures; no explicit warrant canary OK+1
- Anonymous signup: Tor onion site for signup; no personal data required; Bitcoin, bank transfer, and cash all accepted GOOD0
- Funding stability: Non-profit foundation as primary shareholder; operating since 2014; explicitly “no VC, no exit” structure GOOD0
Sources (Legal Framework)
Operated by Proton AG at Route de la Galaise 32, 1228 Plan-les-Ouates, Geneva, Switzerland. Privacy policy: “The Services are operated by Proton AG (the ‘Company’, ‘We’), domiciled at Route de la Galaise 32, 1228 Plan-les-Ouates, Geneva, Switzerland.” Source: Privacy Policy .
Multi-jurisdiction EU hosting. Mail privacy policy: “Data is always stored in encrypted format on our servers, which are exclusively located in Switzerland, Germany or Norway, under the protection of some of the world’s strongest privacy laws.” Source: Mail Privacy Policy .
Built-in zero-access encryption. “Proton Mail uses end-to-end encryption and zero-access encryption to protect emails at all times. We cannot access users’ encrypted emails because we do not have access to users’ private encryption keys or passwords.” Source: Is Proton Mail GDPR compliant . Encryption covers email body, attachments, subject lines, calendars and contacts; sender/recipient addresses and IP remain unencrypted for SMTP delivery: “Due to limitations of the SMTP protocol, we have access to the following email metadata: sender and recipient email addresses, the IP address incoming messages originated from, attachment name, message subject…” (Subject is listed as metadata they have access to in transit for SMTP but Proton’s own client-side encryption applies before storage — read alongside the zero-access claim above.)
Transparency report. Updated annually at proton.me/legal/transparency ; FY2025 reports 9,301 legal orders, 988 contested. Swiss-law notification: “Under Swiss law, subjects of judicial procedures have to be notified of such procedures, although such notification has to come from the authorities and not from the Company.” Foreign requests rejected: “Under Article 271 of the Swiss Criminal Code, Proton may not transmit any data to foreign authorities directly, and we therefore reject all requests from foreign authorities.” No explicit warrant canary.
Tor + anonymous signup. Privacy policy: “It is not necessary to provide personal information in order to create an Account.” Onion signup: “you can now sign up for your Proton account directly on our onion site, making it even easier for anyone to use Tor to bypass censorship and set up a Proton account.” Source: Updated Tor site . Payments — “Aside from Payment card and PayPal, you can pay for a Proton subscription with Bitcoin, Bank transfer, and even Cash.” Source: Manage payment methods .
IP logs minimised. “By default, we do not keep permanent IP logs in relation with your Account.” Kept temporarily for spam/abuse, or permanently if user opts in to authentication logging. Backups retained max 30 days. Account deletion: “Your account and all its data will be permanently deleted from our systems.”
DPA available; GDPR compliant. “Proton Mail has a Data Processing Agreement (DPA) with business users detailing the specific rights and obligations of each party, as required for GDPR compliance.” GDPR Article 27 representative: Proton Europe sàrl, Luxembourg. Source: Business GDPR .
Non-profit foundation structure. “Proton services are operated by Proton AG, a Swiss corporation whose primary shareholder is the non-profit Proton Foundation based in Geneva, Switzerland.” Founded 2014 after a public crowdfund of $500k+ from 10,000 backers; “We do not have venture capital investors, and our non-profit structure requires us to permanently put people before profits while protecting against takeover attempts.” Source: About and Foundation .
Mailbox.org
Privacy Impact: MEDIUM4 — Strongest privacy posture of the providers compared.
- Name: mailbox.org — operated by Heinlein Hosting GmbH, Berlin, Germany
- URL:
mailbox.org - HQ jurisdiction: Germany (14 Eyes, strong GDPR) OK+1
- Hosting jurisdiction: Germany (Berlin data centres) OK+1
- Zero-access encryption: Built-in PGP + S/MIME with Mailbox.org Guard; provider holds no key GOOD0
- Government-access posture: Public transparency report (annual, since 2021); no explicit user-notification commitment found; no warrant canary BAD+2
- Anonymous signup: Operator-run Tor exit node + Tor hidden service; pseudonyms accepted at signup; cash-by-post, SEPA, PayPal, bank transfer GOOD0
- Funding stability: Family business, self-funded since 1992, no acquisition history GOOD0
Sources (Legal Framework)
Operated by Heinlein Hosting GmbH at Schwedter Straße 8/9B, 10119 Berlin, Germany (per the Data Protection Notice and imprint ).
German hosting, no foreign transfers. Pricing page: “Server location in Germany … We operate our services exclusively in redundant data centres in Berlin”. Source: mailbox.org/en/prices/ .
Built-in zero-access encryption via Guard. KB: “We, the team at mailbox, do not possess any replacement or secondary keys. Even if you have stored your private key in Guard, we cannot decrypt your encrypted emails … We have no way whatsoever to restore the plain text of your emails.” Source: kb.mailbox.org/…/backup-pgp-key/ .
Tor + anonymous signup. KB: “To open a mailbox account, we require you to provide a first and last name. However, since we do not verify this information at any point, you may choose any pseudonym.” Source: kb.mailbox.org/…/anonymous-new-registration/ . Plus: “To support anonymous Internet usage … we operate our own Tor exit node in our data center” and a v3 onion service for SMTP/POP3/IMAP/XMPP. Source: kb.mailbox.org/…/using-the-tor-exit-node-from-mailbox/ .
Cash payment accepted. Pricing FAQ: “Cash by post (By letter and EURO banknotes only - no cheques)” and “Cash deposit into our bank account”. Source: mailbox.org/en/prices/ . Crypto: not stated.
Transparency report published annually. 2025 report: “In 2025, a total of 74 official requests for information were sent to mailbox”, with rejection statistics. Source: mailbox.org/en/news/transparency-report-2025/ . Notification policy and warrant canary: not stated.
Tight log retention. Privacy notice: web server / IMAP / Suite logs erased after 4 days; SMTP / spam-filter logs erased after 7 days. Source: mailbox.org/en/data-protection/ .
German law, Berlin courts. ToS §15: “The law of the Federal Republic of Germany … shall apply”. Source: mailbox.org/en/t-cs-cancellation-policy/ .
Family-owned, self-funded since 1992. Company page: “mailbox.org is operated by the family business Heinlein Support GmbH … whose origins go back to the year 1992” and “launched under the new brand mailbox.org in 2014, entirely self-funded”. Source: mailbox.org/en/company .
Mailfence
Privacy Impact: MEDIUM4 — Belgian provider with self-operated Belgian servers, biannual transparency reporting, an actively re-signed warrant canary, Tor + Bitcoin/Litecoin signup, and 27 years of bootstrapped operation under ContactOffice Group SA — but the integrated OpenPGP is in-webclient with the server holding the (passphrase-encrypted) private key, and there is no explicit user-notification commitment.
- Name: Mailfence — operated by Mailfence - ContactOffice Group sa, Brussels, Belgium (BE 0466.241.584)
- URL:
mailfence.com - HQ jurisdiction: Belgium (14 Eyes, strong GDPR) OK+1
- Hosting jurisdiction: Belgium — “Our servers are located in Belgium (Europe) and we have full control over them. We do not use an intermediary or subcontractor to manage them and we do not allow any third-party access.” OK+1
- Zero-access encryption: Integrated in-webclient OpenPGP (4096-bit default key length); private keys stored in the user’s account, passphrase-encrypted before storage — structurally equivalent to Eclipso’s / Mailo’s / Infomaniak’s server-stored-key model. Scope is body + attachments only; “messages subjects” explicitly listed as metadata visible to the provider. OK+1
- Government-access posture: Biannual transparency report at transparency-report-and-warrant-canary (Jan 2026 update covering H2 2025: 21 user-identification requests, 9 disclosed per valid Belgian court orders; 249/114 cumulative since launch); explicit warrant canary (“Mailfence being a Belgian company, cannot receive and has never received any US National Security Letters or FISA court orders … We have never placed any backdoors in our hardware or software”, last updated April 9 2026); no explicit written commitment to notify users when legally allowed — only the observation that “Belgium does not have any equivalent to the US NSL (National Security Letter) and gag order”. Two of three → OK+1
- Anonymous signup: Tor explicitly supported (“Can I use Tor browser to access Mailfence webmail? Yes.”) but no .onion service (a 2017 plan stated “we do plan to provide a Tor hidden service. However, this currently is not in our priority list.” — still not shipped 9 years later); Bitcoin + Litecoin + PayPal + wire transfer accepted (no cash); external recovery email + chosen username required, no real-name verification (“do not use your first name or last name for your username or email address” is the provider’s own anonymity guidance). GOOD0
- Funding stability: ContactOffice Group SA founded 1999, Mailfence product launched November 2013; bootstrapped — “We are not a traditional startup with a high burn rate. Nor do we have third-party financial investors that want to make profit by forcing us to sell our company”; dual revenue (Mailfence subscriptions + white-label licensing to “more than 600.000 accounts” at universities and corporations); 15% of Ultra-tier revenue donated to EFF and European Digital Rights. GOOD0
Sources (Legal Framework)
Operated by Mailfence - ContactOffice Group sa, Avenue Franklin Roosevelt 47b, B-1050 Brussels, Belgium (BE 0466.241.584). ToS: “the secure email service Mailfence, referred to as the ‘Service’, provided by: Mailfence - ContactOffice Group sa Avenue Franklin Roosevelt 47b B-1050 Brussels - Belgium BE 0466.241.584”. Privacy policy: “Mailfence is a service provided by the Belgian company ContactOffice Group SA and as such it is subject to Belgian law.” Sources: Terms and Privacy .
Belgian servers, fully self-operated. Secure-email page: “Locally hosted and total control over our servers — Our servers are located in Belgium (Europe) and we have full control over them. We do not use an intermediary or subcontractor to manage them and we do not allow any third-party access.” Source: Secure email .
Belgian law, Brussels courts. ToS: “This agreement is governed by Belgian law. The courts located in Brussels, Belgium shall have exclusive jurisdiction over any dispute that may arise.” Source: Terms .
Encryption-at-rest model and OpenPGP scope. Encryption-at-rest blog (Feb 4 2025): “While lots of applications implemented block-level encryption (or full-disk encryption), we opted for store-level encryption. … even when mounting (i.e. turning on) the server hard drive, all user data remains encrypted. It is only when a user calls an email (or file.) that that specific data is decrypted; store-level encryption allows for advanced key management with more control (multiple keys for multiple stores).” Threat model: “to prevent a strong adversary from cracking-down a private key, the default length of every generated key pair has been set to 4096 bits (generated with strong entropy).” Homepage: “Encryption happens in the browser. It is impossible for anyone (including us) to read your emails along the line. Fully inter-operable with any OpenPGP service.” But the metadata gap is explicit: “your email provider and Mailfence know when the emails were sent to or from you, as well as other meta-data (to/from email addresses, messages subjects and sizes, IP addresses, etc.).” Sources: Encryption at rest , Threat model , Mailfence , FAQ .
Biannual transparency report; warrant canary. Transparency post: “this information will be updated every half year” and Jan 2026 latest update: “Between the 1st of July 2025 and 31st of December 2025, Mailfence has: 1. received requests for user identification in 21 cases. 2. provided user identification because of a valid Belgium court order in 9 case.” Cumulative through 30 June 2025: “received requests for user identification in 228 cases. provided user identification because of a valid Belgium court order in 105 cases.” Warrant canary on the same page: “Although a gag order is legally not possible in Belgium, we still publish a warrant canary. Mailfence being a Belgian company, cannot receive and has never received any US National Security Letters or FISA court orders. We also have not been subject to any gag order by a FISA court. Finally, we have never placed any backdoors in our hardware or software and have not received any requests to do so.” (last updated April 9, 2026). Source: Transparency report and warrant canary . No standalone user-notification commitment — the ToS only states: “The Service will not monitor, edit or disclose any personal information about you (including your credit card information) or your use of the Service, including its contents, without your prior permission unless required by the Belgian laws.”
Tor + crypto + minimal-identity signup. FAQ: “Can I use Tor browser to access Mailfence webmail? Yes.” Anonymous-email blog: “you can easily access your Mailfence account through Tor … Emails sent using Mailfence webmail do not include the source IP address (X-Originating-IP) for privacy reasons. When you sign up and/or log in via Tor, Mailfence (or other intermediaries) will only see your Tor exit node (the last point in the anonymous communication chain). Your real IP address will not be exposed.” And: “When creating your email account, do not use any personal information. Do not use your first name or last name for your username or email address. Also, avoid using a recovery address that can be linked back to you.” Sources: FAQ and Send email anonymously . Payment methods: “Credit card (Visa and Eurocard/Mastercard) … Bitcoin. Litecoin. PayPal. Wire transfer: contact support for more information.” Cash is not accepted. No .onion hidden service exists — a 2017 staff reply (preserved on tor-talk mailing list, 2018-08): “Yes, we do plan to provide a Tor hidden service. However, this currently is not in our priority list.”
IP logging without published retention. Privacy policy: “We collect IP addresses, message-ID’s, sender and recipient addresses, subjects, browser versions, countries and timestamps.” No specific IP-log retention period is published — the only dated retention is the 45-day deleted-message backup: “We retain backups of deleted messages and documents for 45 days. … After 45 days, data will be permanently deleted from all our systems.” Source: Privacy .
Account-deletion data retention. Privacy policy: “Account deletion — Should you close your account, all data will be permanently deleted 30 days after the legal expiration date (i.e. the Belgian law imposes 365 days after account closing). … We do not delete your account before the legal expiration date because users often ask to reopen their account after having closed it themselves.” Effective deletion timeline ~395 days. Inactivity rule: “Free accounts are suspended after 7 months of inactivity and totally deleted 5 months later. Paid accounts are not deleted as long as payments are received.”
Catch-all on custom domains; alias caps shared across domains. KB: “8. Optional: To set up a catch-all address for your domain, select any of the existing addresses in the catch-all column.” Catch-all is implemented by designating an existing user/alias as the destination for unmatched mail (not a wildcard alias entry). Domain caps: 2 custom domains on Entry, 7 on Pro, 10 on Ultra. Per-account alias caps: Base 10, Entry 50, Pro 100, Ultra 200. Sender-only configuration is supported: “After validation of DNS SPF and DKIM entries, if you prefer to use addresses based on your domain exclusively for sending emails, not for receiving, please go to your account Settings → Account → Personal Data → Edit and add the desired sender addresses.” Receive is all-or-nothing per domain: “All e-mails sent to any address of your domain name arrive on our servers: it’s not possible to transfer only certain selected addresses.” Sources: Custom-domain KB , Custom-domain how-to .
IMAP / SMTP / POP3 supported on paid tiers (Entry+). FAQ: “Paid accounts have POPS, IMAPS and SMTPS access. The settings are: POPS server: pop.mailfence.com … port: 995 (SSL); IMAPS server: imap.mailfence.com … port: 993 (SSL); Please note that simultaneous IMAP connections are limited to 20; SMTPS server: smtp.mailfence.com … port: 465 (SSL)”. Free and Base do not include IMAP/POP/SMTP. ActiveSync is supported on Entry, Pro, Ultra.
2FA: TOTP only. “The technical term is Time-based One-Time Password (TOTP).” Backup codes are generated at setup. WebAuthn/FIDO2 hardware-key support and SMS 2FA are not documented. Source: 2FA .
Native mobile app (PWA). Launch blog (Jan 14 2021, Patrick De Schutter): “We are incredibly thrilled to announce that the Mailfence mobile app is officially going out of beta. Our mobile app was developed as a progressive web application (PWA).” Published in both the iOS App Store (id1628808776) and Google Play (com.contactoffice.mailfence).
DPA available; sub-processors not used. GDPR page: “Mailfence Data Processing Agreement — In order for your organization to comply with GDPR, we provide a Data Processing Agreement.” And: “Mailfence has a strong policy to keep user data internally. We do not disclose any information to outside parties and do not use Google Analytics trackers.” Sources: GDPR and Secure email .
ContactOffice Group since 1999; Mailfence since November 2013; bootstrapped. Company page: “We launched the company in 1999 and are among the pioneers of cloud software in Europe.” KB: “Mailfence is a service operated by ContactOffice Group sa. We are not a traditional startup with a high burn rate. Nor do we have third-party financial investors that want to make profit by forcing us to sell our company. We are in it for the long run.” Dual revenue stream: “To pay our bills, the team sells private label versions of its software to universities, service providers and corporations all over the world.” And: “we pledge to donate 15% of all income of the Ultra plan to foundations like the Electronic Frontier Foundation and the European Digital Rights Foundation.” Sources: Company , Who are we KB , FAQ .
One disclosed regional incident. March 2020 Russian SMTP block: “Mailfence SMTP servers are gradually being blocked by Russian based email services. … Some weeks ago, we received an official request to Submit a Notice of Commencement of Collaboration with Roskomnadzor’s … Acknowledging their request would oblige us to provide information about our users, violating our Terms of Rule and the federal Belgian laws. We, therefore, did not respond to their request.” Source: Email servers blocked Russia . No customer-data breach documented.
Tuta
Privacy Impact: MEDIUM4 — Widest encrypted-content scope of any provider (subject lines included); missing user-notification commitment and anonymous payment keep it out of LOW.
- Name: Tuta (formerly Tutanota) — operated by Tutao GmbH, Hanover, Germany
- URL:
tuta.com - HQ jurisdiction: Germany (14 Eyes, strong GDPR) OK+1
- Hosting jurisdiction: Germany (ISO 27001 data centres) OK+1
- Zero-access encryption: Built-in E2EE for body, attachments, subject lines, calendars, and contacts; sender/recipient addresses exposed for SMTP delivery; only mainstream provider that encrypts subject lines server-side GOOD0
- Government-access posture: Bi-annual transparency report; explicit warrant canary (never received NSL/FISA/gag order); no explicit user-notification commitment OK+1
- Anonymous signup: Tor explicitly supported for registration; payment via card (Braintree), PayPal, SEPA only — no cash or crypto OK+1
- Funding stability: Founded 2011; “wholly owned by Matthias and Arne” (the founders); no outside investors GOOD0
Sources (Legal Framework)
Operated by Tutao GmbH at Deisterstr. 17a, 30449 Hanover, Germany — German GmbH, register HRB 208014 Hanover. Source: Imprint .
German hosting. “All data in Tuta is stored end-to-end encrypted on our own servers in ISO 27001 certified data centers in Germany.” Source: GDPR-compliant email .
Subject lines encrypted too. Business page: “Our encryption protects your emails, attachments, and subject lines as well as calendars and contacts.” Privacy policy: “All user data is stored end-to-end encrypted in Tuta (except for email addresses of users as well as senders and recipients of emails).” Source: Privacy Policy .
Bi-annual transparency report + warrant canary. “Tuta (formerly Tutanota) has never received any National Security Letters or FISA court orders, and we have not been subject to any gag order by a FISA court. We have never placed any backdoors to our encryption and have not received any requests to do so.” And: “The Transparency Report is updated every six months. The warrant canary is always up to date. If there was any request stated above, we would immediately take down the canary.” Source: Transparency report . No explicit user-notification clause found.
Minimal IP logging. “By default, Tuta does not log IP addresses when you login or when you send an email.” Mail-server logs retained 7 days but contain “no customer IP addresses”.
Tor signup; no anonymous payment. “Upon registration you do not need to provide any personal data (e.g. no phone number is required), even when you register via the Tor browser.” Source: Privacy Policy . Payment data per privacy policy: bank details (SEPA), credit card (Braintree), PayPal — no cash or crypto documented.
No IMAP/POP — explicit choice. “We do not offer IMAP as it would only work if we sent decrypted data to your device. Instead we have built our own open source desktop clients, which store your data encrypted.” Source: Security .
TOTP + U2F hardware key. “Yes, Tuta supports two-factor authentication with U2F and TOTP.” No SMS 2FA documented.
DPA available. “Tuta provides an Order Processing Agreement with legally binding data protection guarantees to help you demonstrate your compliance with GDPR.” Source: Privacy Policy .
Founder-owned, bootstrapped since 2011. “Tutao GmbH, the company behind Tuta, was founded in 2011 by Arne Möhle and Matthias Pfau who knew each other from studying together at FHWD university in Hanover, Germany. To this day, the company is wholly owned by Matthias and Arne, and is not liable to anyone else.” Source: Tutanota not a honeypot .
Infomaniak kMail
Privacy Impact: MEDIUM5 — Swiss jurisdiction with Swiss-owned data centres and (since May 2026) an Infomaniak Foundation governance lock — but encryption is opt-in per outbound message with the private key kept on Infomaniak servers, no published transparency report or warrant canary, and the ToS requires real first/last name + physical address + a valid mobile phone at signup.
- Name: Infomaniak kMail / Mail Service — operated by Infomaniak Network SA, Les Acacias (Geneva), Switzerland; majority-owned (voting rights) by the Infomaniak Foundation since 13 May 2026
- URL:
infomaniak.com/en/ksuite/service-mail - HQ jurisdiction: Switzerland (outside 14 Eyes) GOOD0
- Hosting jurisdiction: Switzerland — “All data transmitted by the Customer to Infomaniak is stored and hosted exclusively in data centres in Switzerland which are the property of Infomaniak” GOOD0
- Zero-access encryption: Opt-in per-message OpenPGP — encryption happens server-side on a single click; “Private keys never leave Infomaniak’s infrastructure” and “Encryption is not natively integrated at Infomaniak”; structurally equivalent to Mailo’s / Eclipso’s server-stored-key model, not Mailbox.org’s Guard OK+1
- Government-access posture: No published transparency report; ToS commits to “Inform the Client of said request, unless the law expressly prohibits us from doing so”; no warrant canary BAD+2
- Anonymous signup: ToS requires real first/last name, physical address, and a valid mobile phone — and may demand Infomaniak Check identity verification (passport / ID / driver’s licence / selfie); no Tor support documented; PayPal/cards/PostFinance/Twint/prepaid only — no crypto, no cash BAD+2
- Funding stability: Founded 1994 in Geneva; bootstrapped, employee-owned for 30+ years; on 13 May 2026 majority voting rights transferred to the Infomaniak Foundation in “special shares … that can never be transferred”; no external investors GOOD0
Sources (Legal Framework)
Operated by Infomaniak Network SA, Rue Eugène-Marziano 25, 1227 Les Acacias (Geneva), Switzerland (Commercial Register CH-660.0.059.996-1, CHE-103.167.648). Source: Legal notice .
Swiss data centres, owned by Infomaniak. Special Conditions Article 7.1: “All data transmitted by the Customer to Infomaniak is stored and hosted exclusively in data centres in Switzerland which are the property of Infomaniak.” Product page: “data is exclusively located in Switzerland” and “The email infrastructure is replicated in several data centers located in Switzerland and managed exclusively by Infomaniak.” Sources: Mail Service Special Conditions and Service Mail .
Swiss law, Geneva courts. TCU Article 22.3: “Any dispute relating to this contract … shall be governed exclusively by Swiss law, the exclusive place of jurisdiction being Geneva, subject to recourse to the Federal Court in Lausanne.” Source: General Terms . Note: TCU 1.2 makes the French versions of the contracts authoritative; the English wording is “indicative”.
Opt-in encryption, server-managed keys — explicitly not zero-access. Service Mail FAQ: “Encryption is not natively integrated at Infomaniak. This function blocks certain essential professional functions such as email indexing (and thus searches). It is nevertheless possible to encrypt your messages via an email client (such as Thunderbird) and the Mail Service using OpenPGP.” Encryption announcement: “Infomaniak has developed an encryption system based on recognised standards (OpenPGP, ECC, AES-256-GCM)… Encryption is activated in a single click when writing an email.” And: “Unlike end-to-end encryption systems that can lead to loss of access to data, Infomaniak strikes the right balance between robust security and continuity of access. Private keys never leave Infomaniak’s infrastructure. Passphrases that protect keys are never stored in clear text and are only decoded on the fly during an authenticated session.” The feature applies to outbound mail; inbound and previously-stored mail are not retroactively encrypted by it. Sources: Service Mail and Email encryption news .
User-notification commitment with carve-out; no transparency report; no warrant canary. TCU Article 18.5: “In the event that Infomaniak receives a request from a competent authority (judicial, administrative or law enforcement) … Infomaniak undertakes to: Inform the Client of said request, unless the law expressly prohibits us from doing so; Limit the disclosure of data strictly to what the authority has expressly requested.” DPA Article 2.1.13 mirrors the same wording. No numeric transparency report is published anywhere on infomaniak.com or in the 2024 Impact Report. No warrant canary in any document reviewed.
Real identifying details + valid mobile required. TCU Article 2.1: “the Customer must create an Organization on the Infomaniak Site and provide certain information allowing him to be identified, namely at least: his first and last name, his e-mail address, his physical address and a valid mobile phone number on which he can be reached … the Customer undertakes to provide true, accurate and complete information.” Article 2.2: “Infomaniak reserves the right to block access to the Organization in the event of incomplete or erroneous information or to immediately terminate the Contract if Infomaniak deems, on its own initiative and in good faith, that the Information is fraudulent.” Identity verification: Infomaniak Check (passport / ID card / driver’s licence / selfie) may be required at Infomaniak’s discretion per the Confidentiality Policy. Free “my kSuite” also requires a “valid mobile phone number to confirm registration” per FAQ 2485 .
Payment methods exclude crypto and cash. “credit card Visa, MasterCard, CB Carte Bleue; card PostFinance (if the currency is in CHF); IBAN transfer; PayPal; Twint; the prepaid account.” Source: Pay or renew manually FAQ . Tor support, cryptocurrency and cash are not mentioned in any of Infomaniak’s own documents.
2FA: TOTP + kAuth push + YubiKey + geo-restricted SMS. “kAuth app for iOS / Android devices … any OTP application (such as Authy for example) … YubiKey (from Yubico) … SMS (only for CH / FR / BE / DE countries).” Source: Two-factor authentication FAQ . Generic WebAuthn / FIDO2 beyond YubiKey is not stated.
IP logging. Confidentiality Policy: “We store your IP address to give you an overview of the IP addresses used to connect to your account and to verify the origin of any changes.” Retention for mail-server IP logs is not stated; the closest dated figure is “The logs of your email addresses are available free of charge for the last 19 days” per FAQ 2630 .
Account-deletion retention. “In the absence of a specific request on your part, Infomaniak will automatically delete all your data six months after the termination of your account.” Mail Service Special Conditions Article 7.4 adds a six-day post-deletion grace.
DPA + GDPR. Formal DPA published at Data Processing Agreement (PDF) . Article 14.1: “This Agreement is governed by Swiss law.” For customer-uploaded mail content, the customer is controller and Infomaniak is processor.
Foundation-controlled since 13 May 2026. Press release: “The Infomaniak Foundation now holds the majority of voting rights in Infomaniak Group SA, in the form of special shares: a category that gives the Foundation a permanent blocking power and that can never be transferred. Boris Siegenthaler and the 36 employee-shareholders have all unanimously approved this transfer, accepting that the voting rights attached to their shares decrease accordingly. To date, Infomaniak has no external investors.” Founded 1994; group revenue CHF 56 million in 2025, 340+ employees. Source: Infomaniak Foundation .
Caveat on privacy stance. Externally documented (Wikipedia citing Tom’s Guide, 4 June 2025): a June 2025 LinkedIn post by founder Boris Siegenthaler “opposed online anonymity, criticized free privacy services, and argued that requiring ID to use online services and mass metadata collection is acceptable”, with Communications Manager Thomas Jacobsen telling broadcasters that privacy-advocate companies “prevent justice from doing its work”. Not from Infomaniak’s own legal pages, but an on-the-record statement from the founder that conflicts with Infomaniak’s marketing of “sovereign cloud” privacy.
Kolab Now
Privacy Impact: MEDIUM5 — Swiss-jurisdiction, fully-open-source groupware suite operated from Bern by Apheleia IT AG (renamed from Kolab Systems AG in 2019); at-rest disk encryption on IBM hardware and webclient OpenPGP — but the provider explicitly admits the webclient PGP is not true E2EE (the server holds the keys), the transparency report is published as irregular blog posts (not on a /transparency URL), no warrant canary, no anonymous-payment route today (Bitcoin suspended), no native mobile app, and enabling TOTP 2FA blocks IMAP/POP/DAV/ActiveSync entirely.
- Name: Kolab Now — operated by Apheleia IT AG (renamed from Kolab Systems AG on 2019-12-05), Bern, Switzerland (Trade register CH-036.3.053.227-3)
- URL:
kolabnow.com - HQ jurisdiction: Switzerland (outside 14 Eyes) GOOD0
- Hosting jurisdiction: Switzerland — “The servers live in a rack in Bern, Switzerland, behind 3 sets of locks to which only Kolab Now employees has the key” GOOD0
- Zero-access encryption: Hardware-level at-rest encryption (“heavy set of hardware encrypted IBM storage canisters … this means that data at rest is encrypted”); webclient OpenPGP with server-stored keys, explicitly acknowledged as not true E2EE: “the webclient is letting the server hold a copy of the public / private keys … Providing true end-to-end encryption can only really be achieved by client encryption”. Structurally equivalent to Mailfence’s / Eclipso’s / Infomaniak’s server-stored-key model. OK+1
- Government-access posture: Transparency report published as annual blog posts (cadence irregular — “For the sake of transparency we used to report on our interactions with authorities every year. Unfortunately we have missed a few of those reports”); Jan 13 2026 post covering 2025: “Administrative Requests: 5 … In 2025, we have received 5 such requests of which we rejected 1. Retroactive Metadata Requests: 0 … All Data Requests: 0 … Live Interception Requests: 0”; ToS clause “there will be no access to your data by third parties without a duly authorized warrant issued by a Swiss judge”; no warrant canary; no written notification commitment. One of three (just an irregular TR) → BAD+2
- Anonymous signup: Tor support / blocking not stated anywhere on Kolab Now’s docs; Bitcoin suspended (“We suspended the possibility to pay via bitcoin a while ago and are still working on re-enabling it”) — current payment is PayPal / credit card / bank transfer only; KB requires “name and optionally an address” for billing. BAD+2
- Funding stability: Operating since 2013 (“Operated in Switzerland since 2013”); corporate parent renamed from Kolab Systems AG to Apheleia IT AG on 2019-12-05; bootstrapped — ToS: “You are our customer. All of the Service is paid for by your monthly fee. There are no third party revenue streams, no selling of advertising or personal data” and KB: “The roadmap of kolab Now is laid out by the team. No venture capital investments.” GOOD0
Sources (Legal Framework)
Swiss entity. ToS: “Welcome to Kolab Now, provided by Apheleia IT AG (‘we’), a software freedom company from Bern, Switzerland that is focused on the development of Open Source technologies for collaboration.” KB footer (every page): "© Apheleia IT AG 2019 - 2026 © Kolab Systems AG 2013 - 2019." Trade register listing on the open-source community site: “Apheleia IT AG Trade register CH-036.3.053.227-3”. Sources: Terms of Service , FAQ , kolab.org .
Bern data centre, Apheleia-controlled. KB: “Kolab Now is running on high-end equipment located in a data-center in Bern, Switzerland.” And: “The servers live in a rack in Bern, Switzerland, behind 3 sets of locks to which only Kolab Now employees has the key.” Homepage marketing: “Not in the ‘cloud’, but on our infrastructure, hosted right here in Switzerland.” Sources: What does Kolab Now run , Kolab Now main page .
Swiss law, Zurich courts. ToS: “These terms are subject and governed by the substantial laws of Switzerland with the exclusion of the Vienna Convention on the International Sale of Goods dated April 11, 1980. Disputes arising under or in connection with this Agreement shall be exclusively subject to the jurisdiction of the courts of Zurich, Switzerland. Mandatory legal venue for consumer contracts is reserved.” Source: Terms .
At-rest encryption + explicit non-E2EE admission for webclient PGP. KB: “These hypervisors are ‘fat’ in that they each have quite a few CPU sockets with multi-core CPUs, and are fully stuffed with RAM. These are some enterprise-grade systems — they even come with a chassis, and they are connected to a heavy set of hardware encrypted IBM storage canisters (this means that data at rest is encrypted).” And the encryption KB summary: “Kolab Now has configured Perfect Forward Secrecy (PFS), data in transport is encrypted with SSL/TLS, and all systems are HMS encrypted.” On the webclient OpenPGP: “The web client provides the option of encrypting emails through PGP asymmetric keys. As other similar solutions, e.g. the use of browser add-ons like Mailvelope, the webclient is letting the server hold a copy of the public / private keys, which brings another level of security considerations into play. Providing true end-to-end encryption can only really be achieved by client encryption.” Specific symmetric-cipher / key-length details are not stated by Kolab Now’s primary pages. Sources: What does Kolab Now run , Encryption KB , Onboarding KB .
IP-log retention. 2018 GDPR blog post: “we keep the following logs for up to six months (but no more) — think of this information as the same type of metadata a telecommunications provider would be required to retain. — Successful and unsuccessful login attempts, including source IP address, — Mail submissions, including source IP address, — Mail received, including sender address.” ToS reinforces: “We will only keep the minimum of logs and debug information necessary to ensure that we can improve the service and resolve issues that may have occurred.” Sources: Short-form GDPR compliance , Terms .
Account-deletion retention. GDPR blog post: “When data is deleted it can not be recovered. Please make sure that you have saved all data (messages, contacts, etc..) that you need before pressing the red button.” Residual record post-termination: “This data is reduced to a customer number and an anonymous version of the transaction (customer number and a UUID) at the point of termination of the account.” Specific retention window for the residual customer-number/UUID record is not stated.
Transparency report (annual blog posts, irregular cadence). Latest: “Administrative Requests: 5 … In 2025, we have received 5 such requests of which we rejected 1. Retroactive Metadata Requests: 0 … All Data Requests: 0 … Live Interception Requests: 0 … In 2025 we received zero such requests.” Cadence caveat: “For the sake of transparency we used to report on our interactions with authorities every year. Unfortunately we have missed a few of those reports.” No dedicated /transparency URL — reports live on the blog. Source:
Transparency reporting 2026-01-13 .
No notification commitment in writing; ToS narrower than blog claim. Blog reassurance: “Our terms of service state there’s basically no way for anyone to get any access to your data without us also being able to talk about the fact it happened.” But what the ToS actually says is narrower: “there will be no access to your data by third parties without a duly authorized warrant issued by a Swiss judge” — i.e. a Swiss-warrant requirement, not a user-notification commitment. No clause explicitly commits Kolab Now to notify users when legally allowed. No warrant canary on the site.
Tor: not stated. Bitcoin: suspended. No statement about Tor support or blocking on Kolab Now’s pages. KB Payment System: “you can make payments to Kolab Now using PayPal, Credit Card and Bank transfers.” Blog (2020): “We suspended the possibility to pay via bitcoin a while ago and are still working on re-enabling it. The first iteration of the new HKCCP will not include support for bitcoin payments but it lays the technical foundation to do so with a reasonable investment of development resources.” Cash not mentioned. Sources: Payment system , Future of Kolab Now Part II .
Signup identifying data. Blog (2018): “this typically still leaves your record of purchase, in the form of the account information you provided such as your name and optionally an address.” Onboarding KB: “In the Personal information tab the external email address needs to be set what is important in case you ever forget your password.” Whether truthful-name verification is enforced is not stated.
Custom domains + catch-all. Pricing KB: “As it was before with the group accounts, the first private domain in the new, unified account type is free. For each extra added domain, there is a fee of CHF 0.50 pr. domain/month.” MX takeover required: “MX records contain information about the receiving email servers for the domain. Since your groupware is hosted with Kolab Now, the following MX records should be considered for your domains: MX 10 mx01.kolabnow.com. MX 10 mx02.kolabnow.com.” External-domain aliases forbidden: “Kolab Now supports the use of multiple aliases and identities, however we do not allow external aliases from domains that are not linked to our servers, or domains that are not under our users’ control (e.g. gmail.com, hotmail.com or yahoo.com).” Catch-all is a per-domain manual single-address alias: “If you are using your private domain, you can create a catch-all yourself by logging in to the Cockpit. Create an alias for the desired user account that you want to receive all mails with. Use catchall@yourdomain.tld and repeat for any additional domains you may have associated with your Kolab Now account.” Sources: Pricing FAQ , DNS settings , Aliases , Catch-all .
IMAP / SMTP / POP3 + DAV + ActiveSync. KB: “Yes, Kolab Now provide POP3 access, although we advice users to connect via IMAP.” ToS: “The standard package includes SSL secured access via HTTP, POP, IMAP, CalDAV, CardDAV, and WebDAV. Optionally, users can also connect their mobile devices via ActiveSync.” Source: Does Kolab Now provide POP3 .
2FA is TOTP-only AND disables all non-web clients. “2FA at Kolab Now involves the password prompt and a Time-based One-Time Password (TOTP) algorithm. The preferred provider of the TOTP is Aegis Authenticator … For iOS users … TOTP Authenticator.” And the gotcha: “User accounts that have 2FA enabled in the subscription will only be able to use the web client. All other clients will be blocked at the IMAP, POP, ActiveSync, CalDAV, CardDAV and WebDAV level.” WebAuthn/FIDO2 hardware-key support not documented; SMS is referenced only as a possible future per-action confirmation, not as a 2FA factor. Source: Two-factor authentication .
Migration via Audriga partner. KB: “Moving your current emails and data to Kolab Now can be done with the help of our partner, Audriga. … The prices for the migration are as follows: 8 CHF per box/user for email migration only (fully automatic) 15 CHF per box/user for full groupware migration (assisted, timing depends on availability). Alternatively, you could move all your existing mail to Kolab Now yourself using the IMAP protocol.” Source: Migration KB .
Pricing (May 2026, post-March-2025 unification). Per KB pricing table: “User Mailbox (incl. 5 GB storage) – 5.00 CHF/month; Groupware features add-on – 4.90 CHF/month; ActiveSync add-on – Free; Added storage (per 1 GB) – 0.25 CHF/month; Shared folder – 1.00 CHF/month; Distribution list – 1.00 CHF/month; Extra domain (first domain free) – 0.50 CHF/month”. Trial only: “All Kolab Now accounts are free for the first month.” Wallet-based billing: “When a payment is due, the amount of the payment due will be deducted from your account balance.” Sources: Pricing FAQ , Future of Kolab Now Part II .
No native mobile app — standards-based. Homepage: “Synchronize Email, Contacts, Calendars and Tasks with Android & iPhone · Use third party clients such as Thunderbird, Outlook, eM-Client, Apple Mail, Apple Calendar”. ActiveSync + CalDAV + CardDAV + IMAP only.
Operating since 2013; subscriber-funded; no VC. ToS effective-date footer: “Since: 2013-07-25 — Updated to replace MyKolab.com by Kolab Now on 2015-01-26 — Updated to replace Kolab Systems AG with Apheleia IT AG on 2019-12-05”. Funding posture: “You are our customer. All of the Service is paid for by your monthly fee. There are no third party revenue streams, no selling of advertising or personal data.” And: “The roadmap of kolab Now is laid out by the team. No venture capital investments.” Recent operational events disclosed publicly: March 2026 hardware migration to new Bern servers (completed Mar 24 2026 with minor cert/DNS issues); March 3 2026 outbound-spam incident from compromised user accounts; Nov 6 2024 hypervisor reboot; Jan 17 2022 four-hour CalDAV/CardDAV/WebDAV outage from misconfigured log rotation. No customer-data breach disclosed; no shutdowns. Sources: Migration day , What’s going on .
Posteo
Privacy Impact: MEDIUM5 — Outstanding data-minimisation posture but no custom-domain support at all by design, and only a transparency report (no canary, no notification commitment).
- Name: Posteo — operated by Posteo e.K., Berlin, Germany
- URL:
posteo.de - HQ jurisdiction: Germany OK+1
- Hosting jurisdiction: Germany (own infrastructure, all servers + stored data in Germany) OK+1
- Zero-access encryption: Built-in opt-in “Krypto-Mailspeicher” — AES-encrypts emails (content, attachments, subject lines, headers), calendars, contacts, notes with the account password; Posteo cannot decrypt once enabled GOOD0
- Government-access posture: Annual transparency report (since 2014 — first German email provider to publish one); no explicit user-notification commitment; no warrant canary BAD+2
- Anonymous signup: Zero inventory data at signup; cash-by-letter accepted; Tor not explicitly documented; no crypto OK+1
- Funding stability: Customer-financed, “no advertising partners or investors”; in operation since 2009 GOOD0
Sources (Legal Framework)
Operated by Posteo e.K., Methfesselstraße 38, 10965 Berlin, Germany — registered as HRA 47592 B at Charlottenburg (Berlin).
German hosting on own infrastructure. Privacy policy: “We operate and maintain our own server infrastructure. All of our servers and stored data are located in Germany.” Content data is “saved on encrypted hard drives to protect them from physical access”. Source: Posteo Privacy Policy .
Built-in encrypted mailbox covers subject and headers. Krypto-Mailspeicher announcement: “Die Verschlüsselung umfasst sowohl die Inhalte und Anhänge aller bei Posteo gespeicherten E-Mails als auch die dazugehörigen Metadaten (wie z.B. die Betreffzeile oder der E-Mail-Header).” (The encryption covers both the contents and attachments of all emails stored at Posteo as well as the associated metadata such as the subject line or the email header.) And: “Die verschlüsselten Daten in Ihrem Krypto-Mailspeicher sind auch für uns nicht mehr lesbar. Posteo kann die Verschlüsselung auch nicht deaktivieren; dies können nur Sie selbst tun.”
No IP logging. “We also do not collect or save your IP address if you use an external client to retrieve your emails via IMAP or POP3 or to transmit messages via SMTP to be delivered by us.” And: “we strictly do not save any IP addresses that could be traced back to customers.”
No inventory data at signup. “As a matter of principle, we do not collect and save any inventory data (such as names, addresses, etc.) from you. When registering, you do not enter any inventory data and we do not collect any other personally related data.” Payment data is decoupled from the account.
Anonymous cash by post. “Even anonymous payment of the service can be made in cash by letter.” Cards, SEPA, PayPal also accepted; no crypto.
Transparency report since 2014 at posteo.de/en/site/transparency_report — Posteo was the first German email provider to publish one. No explicit user-notification commitment found; no warrant canary documented.
No custom domains — explicit privacy choice. Help: “No. We are an email provider with a particular, privacy-oriented model – and this is not compatible with incorporating own domains… One of our emphases is data economy: we do not collect any user information… If you were able to use own domains with us, this would affect the entire concept of Posteo: we would need to start saving user information for all customers who use their own domains with us – and to provide these to the Federal Network Agency to be provided on request to the authorities.” External addresses can be configured as sender identities (with forwarding) but Posteo does not host your domain.
Founded 2009; customer-financed. Privacy policy: “Posteo is financed by our customers: There are no advertising partners or investors.” In 2019 the German Bundesverfassungsgericht rejected Posteo’s constitutional complaint and ordered them to support targeted real-time interception (TKÜ) on valid German court order — Posteo complies per their transparency reports but cannot decrypt encrypted mailboxes or content sent encrypted.
CounterMail
Privacy Impact: MEDIUM6 — Swedish OpenPGP-built-in webmail (RSA-4096) with a 15-year operating history, anonymous private-key storage, full-disk encryption, and an explicit refusal of foreign court orders — but the corporate identity is opaque (no legal entity name, address, or organisationsnummer published in any policy/terms/about footer), there is no published transparency-report numerical data, no warrant canary, no notification commitment, no DPA, no GDPR documentation, and signup has been invite-only since 2020-11-01 with the homepage literally stating “Service is closed for new registrations!”.
- Name: CounterMail — operated by an undisclosed Swedish entity (no legal name, organisationsnummer, or registered address published on the site; founder publicly named as Simon Persson in third-party press only)
- URL:
countermail.com - HQ jurisdiction: Sweden (14 Eyes member, strong GDPR) — “Our company is based in Sweden, we have our jurisdiction here in Sweden and we follow the Swedish laws” OK+1
- Hosting jurisdiction: Sweden — “CounterMail’s secure servers are located in Sweden” OK+1
- Zero-access encryption: Built-in OpenPGP for body + attachments (RSA-4096); private key stored anonymously on the server and encrypted with the user’s password via zero-knowledge proof (“We do not know your password. We are not capable of accessing your account with the password hash we possess”); full-disk encryption on mail servers — but headers (From/To/Subject/Date) and folder names are stored unencrypted by CounterMail’s own admission GOOD0
- Government-access posture: Posture statement only — “Countermail will not accept an order from any organization or investigative agency that is outside Sweden”; no published transparency-report numbers (the FAQ-titled “Transparency Report?” is a posture statement without numerical request counts); no warrant canary; no user-notification commitment BAD+3
- Anonymous signup: No .onion address; Bitcoin disabled for new accounts since 2024-06-18 (“All types of Crypto payments will be stopped before the end of this year”); cash wire transfer + prepaid Visa/Mastercard still accepted (one anonymous-payment route survives); invite-only since 2020-11-01; payment data deleted after 14 days; no real-name requirement; Tor not blocked but no .onion service OK+1
- Funding stability: Self-described independent / no investors / no government funding (“we don’t want to get dependent of any third party company for funds”); public launch 2009–2010 per provider’s own changelog; 15+ years operating GOOD0
Sources (Legal Framework)
No legal entity disclosed. Every footer on countermail.com reads only "©2021 CounterMail.com. All rights reserved." — no organisationsnummer, no registered address, no VAT number is published on the Privacy / Terms / About / Contact pages. The founder is publicly named in third-party press only: “My name is Simon Persson, and I am the founder of Countermail. I’m 40 years old, I live in Stockholm, Sweden.” —
Unfinishedman.com interview . A direct Bolagsverket näringslivsregister lookup would be required for definitive entity confirmation. Sources:
Privacy ,
Terms ,
About ,
Contact .
Swedish servers + Swedish jurisdiction. About page: “CounterMail’s secure servers are located in Sweden.” Source: About . Changelog 2020-02-15: “Our main server is located in Sweden.” Source: Changelog . FAQ #74: “Our company is based in Sweden, we have our jurisdiction here in Sweden and we follow the Swedish laws. We will never take orders from anyone outside Sweden, if we began to violate our promise to our users, our users would leave us and our company would go bankrupt.” Source: FAQ #74 .
Built-in OpenPGP zero-access for body + attachments — but headers and folder names plaintext. Privacy policy: “Email data (body & attachments) are always stored in encrypted form.” Source: Privacy . FAQ #56 scope statement: “The following data is not encrypted (in stored emails): Header-fields like From, To, Subject, Date, and Folder names. The reason for this is that the SMTP & IMAP protocols can not handle encrypted headers or foldernames” and “The private PGP keys are stored anonymously, this means that we are unable to determine which private key belongs to a specific user… This means that we can’t give out any private key even if someone forced us.” Source: FAQ #56 . Algorithm: “We are using a strong encryption protocol called OpenPGP, with 4096 bits encryption keys to protect your data.” (Homepage) and “All emails that you send via CounterMail are encrypted on the client-side using the RSA 4096-bit encryption and the OpenPGP standard.” Source: PGP encryption . Full-disk encryption on the mail server: “Our server have full disk encryption, which uses extra CPU and harddrive resources” — Source: Services .
No IP logging — restated repeatedly. Privacy: “No IP-logging, our server does not log IP-addresses.” FAQ #56: “We do not log IP-addresses by ourselves, so we can not provide IP-addresses for any of our email accounts.” Changelog 2025-11-06: “we NEVER logged any user IP-addresses during our 15 year history and NEVER been able to give anyone any user IP-addresses, because it’s NOT possible to do in our system.”
Posture statement, not a transparency report. FAQ #56: “Countermail will not accept an order from any organization or investigative agency that is outside Sweden. If we get a valid court order from the Swedish police and a Swedish prosecutor we can only provide them with meta-data, at maximum.” No periodic report with numerical request counts is published. No user-notification clause. No warrant canary.
Account-deletion retention. FAQ #58: "(1)=removed within 24h, this include emails and contacts and all other info we have in our database for your account." Free Trial accounts cannot be deleted on demand: “If you have a free Trial account, it will be deleted automatically after 12 months. You can NOT delete a free Trial account on demand.” Payment-record retention: “Countermail store your payment information for 14 days, after this period they are automatically deleted.” — Source: Terms §6 .
Bitcoin disabled for new accounts since 2024-06-18. Changelog 2024-06-19 entry: “We have disabled Bitcoin payments for new accounts because of new more complicated laws in our country… All types of Crypto payments will be stopped before the end of this year.” Source: Changelog . Cash wire transfer + prepaid Visa/Mastercard remain documented in FAQ #7 (“ALT 1: Buy a prepaid VISA/Mastercard… ALT 2: Use Bitcoin… ALT 3: Do a cash wire transfer (bank transfer)” — Source: FAQ #7 ). Stripe credit card + bank transfer also listed on the Services page.
Service is closed for new registrations. Pricing page header carries the literal text “IMPORTANT! Service is closed for new registrations!” Source: Services . Registration has been invite-only since 2020-11-01: “The registration now requires an invitation code.” — Source: FAQ #258 . FAQ #258 also caps user count: “We will not take on more than 20k users. So we have a queue for the invites.”
No catch-all on any tier. FAQ #25: “We do not allow catch-all addresses, due to abuse. Using a catch-all address is never good, because you will receive much more spam emails. If you need multiple incoming forwarders, you can create identities for your domain instead of using a catch-all.” Custom domains are a $15 one-time bolt-on, MX-takeover only: “The DNS MX-record must point to our server, otherwise you are violating our terms of use and the domain will be deleted from your account.” Source: FAQ #25 .
2FA: TOTP + proprietary USB keyfile. Changelog 2018-06-12: “Added support for Two Factor Authentication (our own mobile app for iOS and Android) and support for TOTP Two Factor (Google Authenticator).” USB-key webmail-only: “Use it as a keyfile … The keyfile consists of 512 random bits” — Source: USB key . WebAuthn/FIDO2: not stated. SMS 2FA: not stated in CounterMail’s own materials (a Cloudwards review claim is uncorroborated).
Independent funding; no investors. FAQ #258: “we don’t want to get dependent of any third party company for funds… we are not required to hire people from any big fund raiser, and we are not required to follow some special requirements created by a fund raiser.” Changelog 2021-02-23: “we have never get paid or sponsored by any authorities/government.”
Operating since 2009–2010. Homepage news sidebar lists “2009-11-21 Open website for Beta-testers” and “2010-05-24 Opened up for all !”. FAQ #250 (2019): “we started our service between 2009-2010, so it’s more than 10 years.” Changelog 2025-11-06 references “our 15 year history.” Third-party reviews give 2008 (domain-registration year); CounterMail’s own statement is treated as primary.
Documented incidents. Changelog 2021-02-23 (“Its hard for smaller companies to withstand a full blown government attack combined with a bug from the server manufacturer” — SuperMicro firmware bug + DDoS); 2021-10-24 large DDoS; 2023-03-31 datacenter relocation; 2025-11-03 corrupt-filesystem incident (“First time this happened in our 15 year history”). No user-data compromise has been disclosed in CounterMail’s own materials. Source: Changelog .
StartMail
Privacy Impact: MEDIUM6 — Dutch jurisdiction with a transparency report and Bitcoin payments, but server-side PGP only and no warrant canary, no Tor, no user-notification commitment.
- Name: StartMail — operated by StartMail B.V., Zeist, Netherlands
- URL:
startmail.com - HQ jurisdiction: Netherlands (9 Eyes / 14 Eyes member, strong GDPR) OK+1
- Hosting jurisdiction: Netherlands OK+1
- Zero-access encryption: User vault encrypted when logged out; opt-in OpenPGP with server-stored private key (passphrase-protected); provider has plaintext access during user sessions for non-PGP messages OK+1
- Government-access posture: Annual transparency report; refuses non-Dutch authority requests; no explicit user-notification commitment; no warrant canary BAD+2
- Anonymous signup: Bitcoin accepted on annual plans only; pseudonyms allowed at signup; Tor not stated OK+1
- Funding stability: Operating since 2013; describes itself as “independent from any commercial third parties or governments” GOOD0
Sources (Legal Framework)
Operated by StartMail B.V. at Boulevard 11, 3707 BK Zeist, Netherlands. ToS: “The StartMail Service is offered by StartMail B.V. (‘StartMail’), a company established under Dutch law with its registered office in the city of Zeist…” Source: Terms of Service .
Dutch hosting, Dutch law. Privacy policy: “The StartMail databases (containing customer emails which are stored in encrypted user vaults) are located in data centers in the Netherlands.” Source: Privacy Policy . ToS: “The Agreement shall be governed by Dutch law… The court of the Hague, the Netherlands, shall have exclusive jurisdiction…”
User vault + opt-in PGP, but not zero-access. “All of your email messages are stored in a secure User Vault on our servers. All information in the vault is encrypted… Your User Vault is only opened when you login. Without the account password or a recovery key the vault is inaccessible when it is closed.” OpenPGP: “Users can encrypt emails via OpenPGP. The users’ key-pair is stored in the User Vault. Additionally, the private key is encrypted by means of the passphrase.” During an active session, “When you are logged in, your unencrypted emails are unencrypted” — so the vault model protects mailbox-at-rest but does not keep the provider out of message bodies during user sessions.
Transparency report annually. startmail.com/transparency ; 2025 report shows 3 legal requests, all from Dutch authorities. Privacy policy: “ONLY if we receive a request from Dutch judicial authorities to hand over information about one of our Users, we will have our lawyers check the validity of the request… We will NOT comply with requests from any authorities other than Dutch authorities.” PRISM/US support article: “StartMail has never provided a single byte of user data to the US government, or any other government or agency.” No explicit user-notification commitment; no warrant canary.
Tight log retention. Privacy policy: “In our weblogs we store the browser user agent, pages visited, IP address and timestamp for a maximum of 7 days after which they are deleted.” SMTP/IMAP service logs also retained 7 days. “We do not keep a record of the IP addresses used to access our services” beyond those logs. Outbound email headers omit the user’s IP. Deleted emails purged immediately; backups retained max 3 days.
Account deletion. ToS: “When an Agreement is fully terminated, all data contained in the Account, including all e-mails, is immediately deleted permanently. Only the backup will remain for the maximum retention period of three days…”
Partial anonymous signup. Pseudonyms allowed: “A name that you choose (optional and may be an alias or pseudonym, but see also our Terms of Service…”. Anonymous Bitcoin payments: “If you choose to pay annually, you can do so anonymously with Bitcoin.” — but not on monthly plans or group subscriptions. Tor: not stated anywhere in StartMail’s own docs.
DPA / GDPR. StartMail names itself as GDPR controller: “clearly state our identity as a ‘controller’ of your personal data…” Source: Privacy Policy . No standalone customer DPA template is published; sub-processors (Stripe, PayPal, Chargebee) are listed as processors under separate DPAs.
Independence claim. About page: “StartMail is independent from any commercial third parties or governments.” Launched 2013. (Worth flagging out-of-band: StartMail has historically shared ownership with Startpage; StartMail’s own docs do not disclose ownership structure beyond StartMail B.V.)
Eclipso
Privacy Impact: MEDIUM7 — German owner-operated provider with native OpenPGP/S/MIME integration and a published annual transparency report, but the OpenPGP private key is stored server-side and no Tor or anonymous payment is documented.
- Name: Eclipso Mail Europe — operated by eclipso.net – Claus-Peter Beringer (sole proprietorship), Bayreuth, Germany
- URL:
eclipso.eu - HQ jurisdiction: Germany (14 Eyes, strong GDPR) OK+1
- Hosting jurisdiction: Germany (“All servers are located exclusively in Germany”) OK+1
- Zero-access encryption: Native OpenPGP and S/MIME integration; private key stored in the account, passphrase-encrypted (“Ihr privater Schlüssel wird sicher in Ihrem Konto gespeichert” / “Ihr privater Schlüssel verlässt Ihr Konto nie unverschlüsselt”) — equivalent to StartMail’s server-stored key model, not Mailbox.org’s Guard model OK+1
- Government-access posture: Annual transparency report (“Der eclipso Transparenzbericht erscheint jährlich”); foreign-authority requests refused on jurisdictional grounds; no user-notification commitment; no warrant canary BAD+2
- Anonymous signup: Anonymous registration explicitly offered (“sich auf unseren Internetseiten anonym … zu registrieren”) and Freemail tier requires no phone number — but no Tor support documented, and payment is PayPal / Klarna-Sofort / prepayment only (no cash, no crypto) BAD+2
- Funding stability: Owner-managed sole proprietorship since 2003 (Claus-Peter Beringer); “independent, owner-managed German internet company”; no investors, no acquisitions documented GOOD0
Sources (Legal Framework)
Operated by eclipso.net – Claus-Peter Beringer, Grubstr. 9b, 95445 Bayreuth, Germany. AGB: “eclipso Mail Europe ist ein Dienst von eclipso.net - Claus-Peter Beringer, Grubstr. 9b, 95445 Bayreuth, Deutschland”. Source: AGB .
German servers, no foreign transfers. About: “Owner-managed, based in Germany. All servers are located exclusively in Germany - under German law and EU-GDPR.” And: “Your emails, contacts, and files are stored exclusively on servers located in Germany. No transatlantic data transfers, no copies in foreign data centers.” Source: About . Business page: “Your data is stored exclusively in German high-security data centers. No US servers, no Cloud Act risks.” Source: Business .
German law, Bayreuth jurisdiction. AGB: “Für die von eclipso Mail Europe … abgeschlossenen Verträge … gilt ausschließlich das Recht der Bundesrepublik Deutschland” and “Ausschließlicher Gerichtsstand … ist … 95445 Bayreuth”. Source: AGB .
Native OpenPGP and S/MIME — but server-side private key. OpenPGP page: “eclipso Mail Europe integriert OpenPGP Ende-zu-Ende-Verschlüsselung nativ in Ihr Postfach - ohne Erweiterungen, ohne Fremdsoftware, ohne Zusatzkosten.” And: “Ihre E-Mails werden verschlüsselt, bevor sie Ihr Gerät verlassen … Nicht einmal eclipso hat Zugriff auf den Inhalt.” But the key custody is server-side: “Ihr privater Schlüssel wird sicher in Ihrem Konto gespeichert” — the private key lives on Eclipso’s infrastructure, encrypted with the user passphrase. Source: PGP . No claim of encryption-at-rest for the wider mailbox in the docs reviewed; the OpenPGP statement covers the body of PGP-encrypted messages, scope for subject lines and metadata is not stated.
Annual transparency report. “Der eclipso Transparenzbericht erscheint jährlich” and “Anfragen von ausländischen Polizeidiensten und Behörden lehnen wir mit Hinweis auf die geltenden Gesetze ebenfalls ab und verweisen prinzipipiell an deutsche Behörden.” And: “Auskünfte zu Verkehrs- und Metadaten werden ausschließlich auf Basis richterlicher oder staatsanwaltlicher Anordnung erteilt.” Source: Transparenzbericht . No user-notification commitment and no warrant canary in the documents reviewed.
Anonymous registration allowed; no anonymous payment. Privacy notice: “Die betroffene, nach dem Gesetz volljährige Person hat die Möglichkeit, sich auf unseren Internetseiten anonym oder unter Angabe von personenbezogenen Daten zu registrieren.” Free-email page: “Free email address with 4 GB email & cloud storage. Secure, convenient and usable without providing personal information. No phone number required.” Sources: Datenschutz and Free email . Payment methods (per product comparison): “PayPal, Klarna/Sofort.com, Prepayment” — no crypto, no cash, no Tor support documented.
Account inactivity retention; AGB/privacy disagree on window. Privacy notice (Pkt. 8): “Wird ein Benutzerkonto für die Dauer von 365 Tagen nicht genutzt, erfolgt eine automatische Sperrung des Benutzerkontos. Nach Ablauf der Frist von insgesamt längstens 455 Tagen nach dem letzten Login wird das Benutzerkonto aufgelöst.” User-initiated deletion: “nach Ablauf der Frist von insgesamt längstens 90 Tagen nach Deaktivierung das Benutzerkonto aufgelöst, sämtliche Daten zu diesem Benutzerkonto werden endgültig gelöscht.” The older AGB sets the inactivity window at “insgesamt längstens 395 Tagen nach dem letzten Login” — a documented inconsistency between the two contracts. Sources: Datenschutz and AGB .
2FA: TOTP only. 2FA page: “Two-factor authentication (2FA) ensures that only you can log in - even if your password is ever compromised.” And: “Use any TOTP-compatible app: Google Authenticator, Microsoft Authenticator, Authy, FreeOTP and many more. Free to choose - works on iOS and Android.” No WebAuthn/FIDO2 hardware key, no SMS 2FA documented. Source: Two-factor authentication .
DPA included with Business tier. Business page: “DPA according to Art. 28 GDPR included, German servers, highest security standards.” And: “the DPA is mandatory and automatically included. You can view and download your copy of the DPA in the central settings at any time.” Source: Business . The DPA text itself is not publicly published outside of the customer account.
Owner-managed since 2003. About: “We are an independent, owner-managed German internet company with one clear goal: secure, private communication for everyone. Founded in 2003 by Claus-Peter Beringer - because no existing email provider met his privacy standards, so he built one himself.” Source: About . No outside capital, no acquisitions documented.
Murena Mail
Privacy Impact: MEDIUM7 — French-controller webmail attached to the /e/OS degoogled-Android ecosystem (operated by the commercial subsidiary Murena Retail SAS in Paris on behalf of the non-profit e Foundation), mail data hosted at Hetzner Helsinki (Finland sits outside 5/9/14 Eyes) with off-site backups in Falkenstein DE, Nextcloud-style server-side encryption for files and an E2EE document vault (Cryptpad-based) but mail itself is not zero-access (opt-in OpenPGP via SnappyMail + Mailvelope), BitPay/Bitcoin accepted on paid Workspace tiers — but no transparency report, no warrant canary, no notification commitment, and the 2024 Crowdcube equity raise (€786k from 545 investors) prevents the funding axis from scoring 0.
- Name: Murena Mail — operated by Murena Retail SAS, 31 Avenue de Ségur, 75007 Paris, France (Caen RCS no. 883 789 398, Siret 883 789 398 00012, VAT FR82883789398); the e Foundation (French association loi 1901 registered 2018-04-26) publishes the account/mail policies via
e.foundation - URL:
murena.com(Workspace product),murena.io(webmail),@e.email/@murena.iouser addresses - HQ jurisdiction: France (14 Eyes / 9 Eyes member, strong GDPR) OK+1
- Hosting jurisdiction: Finland — “Murena Workspace user data is stored in a replicated storage cluster at Hetzner’s data center in Helsinki, Finland (code named - HEL1)”; off-site backups “to Hetzner’s data center in Falkenstein, Germany (code named - FSN1)”; Finland sits outside 5/9/14 Eyes GOOD0
- Zero-access encryption: None native for mail — “Only a few team members can read your emails, unless some encryption mechanism is used like PGP”; opt-in OpenPGP via the SnappyMail webmail + Mailvelope browser-extension integration; files have Nextcloud server-side encryption with keys “only available in the servers”; document E2EE only exists in the separate Murena Vault (Cryptpad-based); Murena’s own roadmap acknowledges “True end-to-end encryption for Murena Workspace files, full database encryption, and encryption for mails is in our plans as long-term features” OK+1
- Government-access posture: No transparency report on murena.com, e.foundation, or doc.e.foundation; no warrant canary; no explicit user-notification commitment — only “We will only disclose the limited user data we possess if legally obliged to do so”; “Decryption is only authorized as part of a disaster recovery procedure, initiated by a user request submitted using this contact form or as part of a legal obligation to answer a binding request coming from legal authorities in the European Union” BAD+3
- Anonymous signup: Tor not stated; hCaptcha required at signup; mandatory non-Murena recovery email (“After 30 days without setting and verifying a recovery email address your account will be disabled and then deleted”); Bitcoin accepted on the paid Workspace tiers via BitPay (“We use Stripe, PayPal and Bitpay to process payments on this website”); username only — no real-name required OK+1
- Funding stability: e Foundation is a non-profit registered 2018-04-26; commercial sister Murena Retail SAS (formerly ESolutions SAS); 2018 Kickstarter (≥€71k), 2024 Crowdcube equity raise (€786,398 from 545 investors on top of a previously-secured €343,652) — privately held with crowdfunded equity history, operating <10 years OK+1
Sources (Legal Framework)
Commercial entity / non-profit split. Murena Retail SAS publisher block: “Publisher: Murena Retail SAS / Nº Siret: 883 789 398 00012 / VAT Number: FR82883789398 / Code APE: 5829C / Headquarters: 31 Avenue de Ségur – 75007 Paris, France.” Source:
Legal notice . T&Cs lead: “MURENA RETAIL SAS, whose registered office is located 31 Avenue de Ségur, Paris (75007), France, registered in the Caen Trade and Companies Register under number 883 789 398.” Source:
Terms & Conditions . The non-profit publisher of e.foundation: “Publisher: e Foundation / Non-profit organization under the French law for association 1901 registered on April 26th 2018.” Source:
e Foundation legal notice/privacy . Murena’s mail privacy policy directs users to e.foundation for @e.email account policies: “For more information regarding the privacy policies of the following services: /e/OS and apps, @e.email account…” Source:
Murena privacy policy .
Mail data in Finland; off-site backups in Germany. Workspace product page: “All Murena servers are hosted in the European Union. More precisely, our email and cloud servers are located in Finland.” Source: Workspace . Service documentation: “Murena Workspace user data is stored in a replicated storage cluster at Hetzner’s data center in Helsinki, Finland (code named - HEL1) with server side encryption provided by Nextcloud server application.” And: “Additionally, we create a second copy of these snapshots and synchronize them every day to Hetzner’s data center in Falkenstein, Germany (code named - FSN1). These incremental cold backups are kept for up to three months.” Source: doc.e.foundation services . Hosting provider: “Hosting: Hetzner Online GmbH” (Murena legal notice).
French law, French courts (shop / cloud subscription side). T&Cs: “These general terms and conditions of sale shall be governed by French law. We offer You to settle all disputes concerning the validity, interpretation, execution, termination and consequences and follow-up of the contract through an internal mediation procedure. Failing this, if You do not wish to follow a mediation procedure or if the mediation is not successful, the dispute will be submitted to the exclusive jurisdiction of the competent French courts.” Source:
Terms & Conditions . The product-side Workspace ToS at https://murena.io/apps/terms_of_service/en_GB/termsandconditions is referenced at signup; its specific governing-law clause is not reproduced here.
Files: Nextcloud server-side encryption; Mail: not zero-access. “All Murena Workspace files are encrypted by server-side encryption. This means the keys to decrypt the data are only available in the servers hosting the application. Only a handful of senior administrators and lead developers have access to those servers to perform maintenance and troubleshooting.” And: “All backups are encrypted with a different key, not stored on the application servers.” Mail specifically: “Only a few team members can read your emails, unless some encryption mechanism is used like PGP. This is the case on any e-mail provider except custom non-standard solutions… For now, you can already configure PGP on /e/OS Mail and on Murena Workspace webmail.” Source: doc.e.foundation services . Forward-looking: “True end-to-end encryption for Murena Workspace files, full database encryption, and encryption for mails is in our plans as long-term features.” The Mailvelope integration page: “Murena’s SnappyMail integration with the Mailvelope extension allows you to encrypt/decrypt/sign your emails, as well as create/manage PGP keys right in the browser.” Source: Mailvelope setup . /e/OS Mail app PGP: “Our Mail app is integrated with Open Keychain to provide the possibility to send end to end encrypted e-mails from your device.” Source: What’s /e/ . Murena Vault: “Murena Vault is a secure document management service integrated into the Murena Workspace. It is powered by Cryptpad, providing you with a secure environment to create, store, edit, and manage documents.” Source: Workspace .
IP-log retention: “minimum legal duration” — no number stated. e.foundation legal notice (Spot search-engine section): “IP addresses are logged for the minimum legal duration.” For OS-update connections: “When you connect to our servers to update /e/OS, we collect some visitors statistics such as your IP address, only for our internal use… These statistics are not providing us any personal identifiable information. This information is not disclosed unless legally obliged to do so.” Source: e Foundation legal notice/privacy . Specific numeric retention for mail/IMAP/webmail logins: not stated.
No transparency report; no warrant canary. No transparency-report URL exists on murena.com, e.foundation, or doc.e.foundation. The only government-access language is: “All data on your ‘own’ /e/ server is encrypted and never shared, sold or traded to any third party. We will only disclose the limited user data we possess if legally obliged to do so.” Source:
e Foundation legal notice/privacy . And: “Decryption is only authorized as part of a disaster recovery procedure, initiated by a user request submitted using this contact form or as part of a legal obligation to answer a binding request coming from legal authorities in the European Union.” Source:
doc.e.foundation services . No user-notification commitment.
Signup: hCaptcha + mandatory non-Murena recovery email. Account-creation doc: “Ensure you add a valid recovery email address to your Murena Workspace account. The recovery email is important in case you lose access to your Murena Workspace account for any reason. This email address cannot be a murena.io address.” And: “After 30 days without setting and verifying a recovery email address your account will be disabled and then deleted.” And: “Your username may contain Latin letters (a-z), digits (0-9) and special characters (- . _) Your username must be at least 3 characters long and at most 30 characters long.” Source: Create a Murena cloud account . hCaptcha disclosure: “We use the hCaptcha security service (hereinafter ‘hCaptcha’) on murena.io/signup… hCaptcha evaluates various information (e.g. IP address, how long the visitor has been on the website or app, or mouse movements made by the user).” Source: Privacy policy .
No catch-all / no custom-domain consumer tier yet. Workspace plans page (https://murena.com/cloud-subscriptions/) lists 20 GB → 2 TB tiers — no custom-domain attachment, no catch-all on any consumer tier. Custom domains are announced as a roadmap / Business-tier feature only: “You can now manage and host your email and drive for your family or business, using a single identity on your own custom domain, and connect it with your /e/OS smartphone.” Source:
e Foundation eCloud page . Catch-all under any terminology (“catch-all”, “wildcard alias”, *@) is not documented anywhere in primary Murena docs.
Free-tier hide-my-email + every account gets both @e.email and @murena.io. Murena Workspace murena.io alias: “Murena Workspace users now have the choice to use murena.io domain for emails. For example, a user called ‘jane.doe’ is now able to use both
jane.doe@e.email and
jane.doe@murena.io email addresses.” Source:
Murena.io alias address . Hide-My-Email count: “5 Hide My Email” on paid 20 GB and 64 GB tiers per
Workspace ; historically “there is one alias available” on free per
edevelopers-blog.medium.com/murena-cloud — current free count is not stated explicitly on the pricing page.
IMAP / SMTP supported; POP3 not documented. “SMTP/IMAP server: mail.ecloud.global / SMTP/IMAP username: your Murena Workspace email address in full (example: john.doe@e.email or john.doe@murena.io) / SMTP port: 587, plain password, STARTTLS, requires authentication / IMAP port: 993, SSL/TLS.” Sources: Create a Murena cloud account , Configure email . POP3 is not stated as supported.
Pricing (EUR, monthly / yearly). Source: Cloud subscriptions . 20 GB “1,99€ / month” or “19,90€ / year”; 64 GB “3,99€ / month” or “39,90€ / year”; 128 GB “5,99€ / month” or “59,90€ / year”; 256 GB “7,99€ / month” or “79,90€ / year”; 1 TB “12,99€ / month” or “129,90€ / year”; 2 TB “24,99€ / month” or “249,90€ / year”. Free tier: “FREE ACCOUNT” with “1 GB FREE” of storage, supported “by donations”. Source: Workspace and Create a Murena cloud account .
Payment methods. “We use Stripe, PayPal and Bitpay to process payments on this website.” Source: Privacy policy . T&Cs: “We give You the choice to pay by debit card, credit card, or with Your PayPal account if You have one.” Source: Terms & Conditions . Card, PayPal, and Bitcoin (via BitPay): supported. SEPA direct debit + cash: not stated.
2FA: TOTP only documented; no WebAuthn/FIDO2; SMS not stated. TOTP: “To enable a TOTP Password you will need a compatible client.” Source: Two-factor authentication . Murena maintains a fork of the Nextcloud TOTP app at Murena-SAS/twofactor_totp . WebAuthn / FIDO2: not stated in primary Murena docs.
DPA: not stated; DPO contact only. “How can I contact Murena Workspace Data Protection Officer (DPO)? Please write your inquiry to dpo@murena.com and the person currently performing this role will coordinate the necessary action and reply in the shortest delay.” Source: doc.e.foundation services . General GDPR posture: “All of our online services are GDPR compliant for the protection of your data.” Source: Workspace .
Built-in Google migration tool. “During migration, Murena Workspace will access the content of the following apps to migrate it to the matching Murena Workspace app: Gmail: all your Gmail e-mails will be imported in a dedicated folder in Murena Workspace’s Mail; Google Drive: all the files stored on your Google Drive will be imported into Murena Workspace’s Files; Google Photos…; Google Contacts…; Google Calendar…” And: “The content is imported into Murena Workspace at your explicit request while using the Google data migration tool available in Settings > Migration.” Source: Privacy policy . Generic IMAP import wizard: not stated.
Native Android Mail app, no native iOS app. /e/OS Mail is “a fork of the open source K9-mail application” (per the /e/OS community forum announcement at community.e.foundation/t/e-os-mail-application-and-gmail/18390; the source repo at gitlab.e.foundation/e/os/mail README also states it is “Forked from
https://github.com/k9mail/k-9" ), pre-installed on /e/OS smartphones, available via F-Droid / App Lounge — Source:
What’s /e/ . For iOS, only Apple Mail autoconfig is documented: “If you are using a current Apple Mail version (both on macOS or iOS) you can visit
https://autoconfig.murena.io/ and fill in your details to download a configuration package that automatically configures your client.” Source:
Configure email .
Funding: non-profit registered 2018-04-26; 2018 Kickstarter; 2024 Crowdcube equity raise. e Foundation: “Our non-profit organization ’e Foundation’ was incorporated in May 2018.” Source: About /e/ . e Foundation donations: “We use PayPal and Patreon to process donations to the e Foundation.” Source: e Foundation legal notice/privacy . 2018 Kickstarter raise (Eelo): “Duval launched a Kickstarter crowdfunding campaign with an initial goal of €25,000, and received at least €71,000 from contributors” — Source: Wikipedia /e/ . 2024 Crowdcube raise: “This opportunity was approved as a crowdfunding offer by Crowdcube Europe S.L. on 19/06/2024” — and per Technology Reseller, “achieved its funding target of €400,000 in less than 24-hours, raising a total of €786,398 (£650,000) from 545 investors” on top of a previously-secured €343,652. Sources: Crowdcube pitch , Technology Reseller .
Brand history: Eelo → /e/ → Murena. Per Wikipedia /e/ : “Eelo was renamed to /e/ in July 2018 due to a conflict with the ’eelloo’ trademark” and “ESolutions SAS was re-named Murena Retail” concurrent with the launch of Murena-branded phones (per The Register’s May 2022 reporting).
Vivaldi Mail
Privacy Impact: MEDIUM7 — Free community-perk webmail run by Vivaldi Technologies AS in Oslo, Norway as a benefit for active Vivaldi-browser community members, with Iceland-hosted infrastructure (Hringdu data centers, per Vivaldi’s Sync privacy policy and SMTP-host network attribution — the mail-specific Vivaldi docs do not state a server location), Roundcube webmail with opt-in Mailvelope PGP, 10 GB storage, TOTP + security-key 2FA, and an explicit “0 outside investors” claim — but mail is not encrypted at rest by default (per Vivaldi staff post on the Vivaldi-hosted forum: “the key is on the webmail server, so someone with access to both could theoretically decrypt it”), IP logs are kept for up to three months, signup is gated by a deliberately opaque reputation system (“details about how the reputation system works are not shared publicly”), there is no transparency report, no warrant canary, no notification commitment, no DPA, no custom domains, no real aliases (only plus-addressing), no native mobile app, and no paid tier.
- Name: Vivaldi Mail / Vivaldi Webmail — operated by Vivaldi Technologies AS, Mølleparken 6, 0459 Oslo, Norway
- URL:
vivaldi.com/features/mail/(product page),webmail.vivaldi.net(Roundcube webmail) - HQ jurisdiction: Norway (14 Eyes / 9 Eyes member, GDPR via EEA) OK+1
- Hosting jurisdiction: Iceland — Sync privacy policy states “Vivaldi’s servers are hosted at the Hringdu data centers in Iceland”; SMTP host
smtp.vivaldi.netresolves to a Hringdu ehf (AS51896) IP range; mail-specific Vivaldi policy/help documents do not contain a verbatim mail-server location statement — treated as Iceland (outside 5/9/14 Eyes) per the Sync statement and network attribution GOOD0 - Zero-access encryption: None native — mail body is not encrypted at rest by default. Opt-in OpenPGP via the Roundcube Mailvelope plugin in webmail (Vivaldi staff post: “It provides encryption in transport and when at rest on the IMAP server, but the key is on the webmail server, so someone with access to both could theoretically decrypt it”) OK+1
- Government-access posture: No published transparency report; no warrant canary; no commitment to notify users of lawful requests — only generic “We do not share or sell your personal data with any third party. We protect user data from disclosure, with exceptions only requested by law or court order” BAD+3
- Anonymous signup: Tor not stated (no published Tor policy); no paid tier so no anonymous-payment path; mandatory non-Vivaldi recovery email; minimum age 16; reputation-gated signup since May 2023 — “To start using your webmail account, you first need to be an active community member and build up some reputation” and “details about how the reputation system works are not shared publicly”; IP-log retention “up to three months” BAD+2
- Funding stability: Founded 2013 by Jon von Tetzchner; explicit “0 Outside investors”; “Having no external investors gives us the freedom to listen to our users” — independent, employee-owned, operating >10 years GOOD0
Sources (Legal Framework)
Norwegian entity. Community privacy policy: “At Vivaldi Technologies AS (“Vivaldi”), protecting your privacy is one of our top priorities.” Contact block: “Vivaldi Technologies AS / Mølleparken 6 / 0459 Oslo / Norway.” Source: Community privacy policy .
EULA governing law: Norway / Oslo City Court. EULA: “Vivaldi’s headquarters are based in the beautiful city of Oslo, Norway. This EULA is therefore governed by the laws of Norway, except its conflict of laws rules and regulations. All disputes, actions or proceedings arising under or related to this EULA shall exclusively be referred and resolved by the Oslo City Court.” Source: EULA . The Community Terms of Use (which expressly cover Webmail) at community-terms-of-use is silent on governing law; the EULA’s Norway clause applies via the “ancillary services” wording.
Iceland hosting (stated for Sync, network-attributable for Mail). Sync policy: “Vivaldi’s servers are hosted at the Hringdu data centers in Iceland.” Source:
Sync privacy . Support-form page: “We use Jira Software hosted on our servers in Iceland to manage messages sent to us via this form.” Source:
Create a new account . The mail-specific Vivaldi policy/help documents do not contain a verbatim mail-server location statement — the Iceland attribution for mail itself comes from the Sync policy + SMTP-host network-level evidence (smtp.vivaldi.net on Hringdu ehf / AS51896, per discussion on the Vivaldi-hosted forum at
forum.vivaldi.net/topic/72494 ).
Mail metadata logged for up to three months. Community privacy policy: “In order to provide you our mail service, Vivaldi Webmail, we process the following email metadata: sender and recipient email addresses, the IP address from which incoming messages originated, and message sent and received times. Email messages are scanned by automated systems that allow us to detect malicious activity.” And: “Email logs are stored for up to three months.” Source: Community privacy policy .
Mail is not encrypted at rest by default. Community privacy policy contains only generic security language and no at-rest encryption claim for mail. A Vivaldi staff post on the official Vivaldi-hosted forum confirms: “Vivaldi Webmail uses Roundcube for the webmail interface and emails can be encrypted using a PGP encryption plugin provided by Roundcube that we’ve added as an option for webmail users to use. It provides encryption in transport and when at rest on the IMAP server, but the key is on the webmail server, so someone with access to both could theoretically decrypt it.” Source: forum.vivaldi.net/topic/57870 . PGP is opt-in via Roundcube Mailvelope plugin.
Deletion on account close. Privacy policy: “When you close your Vivaldi account, your data is immediately deleted from our production servers.” Source: Community privacy policy . Terms of Use: “You can choose to end the agreement at any time, for any reason, by deleting your Vivaldi account and discontinuing your use of the services. When doing so, your data is permanently deleted from all our servers, and your username can never be re-used.” Source: Community Terms of Use .
No transparency report, no warrant canary, no notification commitment. Targeted gap-search across vivaldi.com, vivaldi.net, help.vivaldi.com returned no transparency report and no canary. The only government-access language: “We do not share or sell your personal data with any third party. We protect user data from disclosure, with exceptions only requested by law or court order” and “Vivaldi will not transfer any personal data to third parties except as required by law or law enforcement.” Source:
Community privacy policy .
Signup data and age gate. Terms of Use: “Provide true, accurate, current and complete information about yourself as prompted by the sign-up process.” And: “You affirm that you are at least 16 years of age when signing up to Vivaldi’s services.” Source: Community Terms of Use . Required signup fields per Create a new account are “Username … Recovery email … Password … Profile Picture” — recovery email is mandatory; no government ID, real name, or phone number.
Reputation-gated Webmail access since May 2023. Help: “Vivaldi Webmail is a free and private email service we offer only to our active community members to cover their personal emailing needs.” And: “To start using your webmail account, you first need to be an active community member and build up some reputation by using the following services: Vivaldi Forum, Vivaldi Social, Vivaldi Themes, Community Blogs, Sync.” And: “To guarantee the efficiency of this method, details about how the reputation system works are not shared publicly. How long it will take to get access to Vivaldi Webmail will also vary.” Source: Webmail access and reputation system .
No custom domains; aliases via plus-addressing only. Help: “In Vivaldi Mail all emails need to be delivered to and sent from username@vivaldi.net. This means that different aliases, unfortunately, can’t be used. But, if you have set your Vivaldi Mail up in a mail client, you may use plus addressing (also known as sub-addressing). With plus addressing you can add a keyword to your email address ( username+keyword@vivaldi.net) which allows you to create different variations of the email address.” Source: Webmail settings . Vivaldi staff confirmation: “Vivaldi.net webmail accounts don’t support custom domains so you’d have to use some forwarding account for that.” Source: forum.vivaldi.net/topic/114683 .
IMAP / POP3 / SMTP supported. Server settings: “IMAPs (recommended): Server: imap.vivaldi.net Port: 993 … POP3s: Server: pop3.vivaldi.net Port: 995 … SMTPs (recommended): Server: smtp.vivaldi.net Port: 465.” Source: Setting up Vivaldi Mail in a mail client .
Storage: 10 GB free. Help: “In Vivaldi mail each account gets 10GB of storage space.” Source: Webmail settings . ToU: “Please note that the email quota is of 10GB. As soon as your account reaches critical size, Vivaldi will send you a warning message. An account that has exceeded the quota limit will be blocked from receiving mail and from storing new messages.” Source: Community Terms of Use .
2FA: TOTP + security key; no SMS. “For your Vivaldi account, the second verification can be done either with app based authentication or with a security key.” And: “An alternative to an authenticator app is a physical security key or device. You can add as many security keys to your account as you want.” Source: Two-factor authentication . WebAuthn/FIDO2 via security keys is supported. Recovery codes and app-passwords also documented.
No native mobile mail app. Vivaldi staff confirmation: “The mobile versions of Vivaldi on Android and iOS do not include the mail client and we don’t have separate client apps for mobile.” Source:
forum.vivaldi.net/topic/103640 . Mobile users access via webmail.vivaldi.net or via a third-party IMAP/POP client.
Free, gated, no paid tier. Email signup page: “Free / Available for active Vivaldi Community members.” The same page actively recommends two paid competitors alongside its own free option — “Proton Mail — From €3/month” and “Fastmail — From $5/month.” Source: Email signup . No payment methods — the mail service does not accept payment. (Stripe is named in the Community privacy policy only for donations, not for mail.)
DPA: not stated; controller-stance only. Privacy policy: “The purpose of this policy is to inform you of how Vivaldi will process your personal data as data controllers and the measures and processes we have put in place to ensure its adequate protection.” And: “The legal basis for the processing is the fulfilment of your request (contract) and the legitimate interest Vivaldi has in providing you with a good experience when using our email service.” Source: Community privacy policy . No customer DPA template is published.
Funding: 0 outside investors; founded 2013. Vivaldi Mail product page: “Having no external investors gives us the freedom to listen to our users and, together with them, build the browser they deserve. 4 000 000+ Active users. 2 500 000+ Community members. 0 Outside investors.” Source: Vivaldi Mail features . Founding year (2013, founders Jon von Tetzchner + Tatsuki Tomita) is not stated on Vivaldi’s own privacy/policy pages; documented externally on Wikipedia and not contradicted by Vivaldi.
Vivaldi Mail product timeline. Per the official Vivaldi blog post by Jon von Tetzchner (2022-06-09): “Launching today, your new mail client Vivaldi Mail 1.0 is built right into the Vivaldi browser.” Source: Vivaldi Mail launch . Earlier milestones (Nov 2020 technical preview, June 2021 beta) per Wikipedia. The May 2023 reputation-gate + 2FA rollout: Two-factor authentication blog .
Hostpoint
Privacy Impact: MEDIUM8 — Owner-operated Swiss host with 25 years of independent operation and Swiss-only data residency, but the email product offers no zero-access encryption, no transparency report, no warrant canary, no anonymous signup or payment — and the docs explicitly state “Hostpoint does not offer catch-all addresses”, so it’s a poor identity-compartmentalization fit on top of the weak privacy posture.
- Name: Hostpoint Cloud Office — operated by Hostpoint AG, Rapperswil-Jona SG, Switzerland (CH-320.4.049.510-4)
- URL:
hostpoint.ch/en/email - HQ jurisdiction: Switzerland (outside 14 Eyes) GOOD0
- Hosting jurisdiction: Switzerland — “Hostpoint stores all web, e-mail and database data on servers in the Swiss data center of Digital Realty (formerly Interxion) in Glattbrugg” GOOD0
- Zero-access encryption: None — “For e-mails, at least line encryption (TLS) is offered and used where supported”; storage is described only as “encrypted where possible”; no built-in PGP, no S/MIME, no zero-access vault BAD+3
- Government-access posture: No transparency report; no user-notification commitment; no warrant canary; the GTC reserves broad disclosure rights to courts and authorities (Cl. 3.2.3-3.2.4) BAD+3
- Anonymous signup: Tor not stated; payment via invoice / credit card / PayPal / SEPA LSV / prepayment — no crypto, no cash; GTC 3.1.2 requires “truthful and verifiable information” and lets Hostpoint demand supporting documents at any time BAD+2
- Funding stability: Founded 2001 by Markus Gebert, Sandro Bertschinger and Claudius Röllin; ~130 employees in 2026; CEO statement (April 2026): “While various providers have been taken over by international groups, Hostpoint remains independent” — no external investors, no acquisitions disclosed GOOD0
Sources (Legal Framework)
Operated by Hostpoint AG, Neue Jonastrasse 60, 8640 Rapperswil, Switzerland (CH-320.4.049.510-4, UID CHE-101.974.997). Source: Privacy Policy .
Swiss-only hosting. Company page: “Hostpoint stores all web, e-mail and database data on servers in the Swiss data center of Digital Realty (formerly Interxion) in Glattbrugg.” Email product page: “At Hostpoint, data is stored in a highly secure data center in Switzerland.” Company statement: “With the exception of a few components of rankingCoach, all data relating to our products and services are stored on our servers in Switzerland.” Sources: Company and Email . An EU representative (Hostpoint Limited, Malta) exists for GDPR Art. 27 only.
Swiss law, Hostpoint’s seat as exclusive forum. GTC 13.3: “These GTC and any disputes arising under or in connection with the contractual relationship between Hostpoint and the Customer shall be subject exclusively to Swiss law, excluding its conflict of laws rules and the provisions of the UN Convention on Contracts for the International Sale of Goods (CISG).” And 13.4: “The ordinary courts at the registered office of Hostpoint shall have exclusive jurisdiction.” Source: GTC Web hosting (PDF) .
No zero-access encryption. Annex 2 TOM Addendum A: “Data stored in the Data Centre is protected against physical access (see paragraph G) and encrypted where possible.” And: “For e-mails, at least line encryption (TLS) is offered and used where supported.” The privacy policy makes no provider-side PGP / S/MIME / zero-access claim. DANE was added in 2020 for inter-server TLS only.
Broad disclosure clauses; no transparency report; no canary. Privacy Policy §7: “To the extent that courts or authorities request and we are legally required, we will pass on your personal data to them or other third parties.” GTC 3.2.3: “Hostpoint reserves the right to inspect contents made accessible by the Customer by means of using the hosting services upon receipt of a Notice pursuant to the Code of Conduct – Hosting … or at the request of courts or authorities.” GTC 3.2.4: “Hostpoint still has the right to inform third parties of the identity of the Customer at the request of courts or authorities.” GTC 3.2.6 lets Hostpoint suspend the service “if … a court or authority has requested Hostpoint to do so.” No clause commits to notify affected users when legally permitted. No transparency report or canary is published anywhere on hostpoint.ch.
Truthful identifying details required. GTC 3.1.2: “When ordering and registering and in the context of using the services, the Customer is obligated to provide truthful and verifiable information. Hostpoint may at any time and without providing reasons request that the Customer subsequently provides documents or information which enable Hostpoint to verify the accuracy of the information provided by the Customer. Hostpoint is entitled to defer the acceptance of an order or registration, to suspend services or to terminate the contract with the Customer with immediate effect in the event that the Customer fails to provide the requested documents or information within the deadline set by Hostpoint.”
Payment methods exclude crypto and cash. Right to cancel §B: “You can choose to pay by invoice, credit card, PayPal, direct debit (LSV) or prepayment.” GTC Annex 1 §2.3 even prohibits running “Crypto-mining software” on the servers. Cryptocurrency and cash are not mentioned. Tor support / blocking is not stated in any Hostpoint document.
Catch-all explicitly not supported. Support KB: “Info: Note: Hostpoint does not offer catch-all addresses.” Source: Alternative e-mail address KB . Hostpoint’s official Twitter on 13 February 2015: “Nein, Catch-All E-Mail Accounts bieten wir nicht an.”
Account-deletion grace. “Temporarily delete e-mail address: This option deletes your e-mail and Cloud Office data, but you can restore it yourself within 30 days free of charge. Once this period has elapsed, the data is permanently deleted.” Backup retention by tier: 30 / 90 / 180 days (Basic / Plus / Business).
Log retention. Privacy Policy §6 only gives a general retention rule (“five, ten or more years” after end of contract). For web hosting access/error logs, support article states: “Access and error logs are kept for at least 7 days.” IP-log retention for mail-server connections specifically is not stated.
2FA: TOTP authenticator app only. “If two-factor authentication is activated, you first have to enter your Hostpoint ID password and then a code generated via an authenticator app (e.g. Authy, Google Authenticator, Aegis) on your smartphone.” WebAuthn/FIDO2 hardware keys and SMS are not documented. The 2FA also only protects the Hostpoint ID / Control Panel — it is not described as protecting individual IMAP/SMTP mailbox sessions. Source: 2FA general questions .
DPA via Annex 2 of the Web-hosting GTC. Annex 2 Cl. 5.1: “The client therefore assumes the role of controller.” And Cl. 5.3: “Hostpoint takes on the role of the processor in terms of the processing of personal data.” No standalone E-mail / Cloud Office DPA document.
Owner-operated, independent since 2001. 25th-anniversary press release (30 April 2026): “around 130 people at its Rapperswil-Jona SG site … In the last five years alone, the workforce has grown by almost 70 percent.” CEO Markus Gebert: “The Swiss hosting market has changed significantly and become increasingly consolidated in recent years. While various providers have been taken over by international groups, Hostpoint remains independent. We want to continue on our path … and continue to focus on quality, proximity to customers and reliable Swiss infrastructure in the future.” Source: 25-year press release . Hostpoint also acquired ~SWITCH retail .ch domains in 2014–2015 (“450,000 customers … 1.2 million domain names”) — an inbound acquisition, not an exit.
Inbox.eu
Privacy Impact: MEDIUM8 — Latvian webmail operated by Inbokss Ltd (reg. no. LV40003560720, Riga; founded 1998, Inbox.eu product line launched 2011) with data centres in Latvia and processing governed by Latvian law — kept out of the HIGH band by Latvia sitting outside 5/9/14 Eyes and by Inbokss being bootstrapped/owner-operated for 27 years, but with no zero-access encryption (the help-center article titled “End-to-end encryption” defines it as TLS in transit only), no transparency report, no warrant canary, no notification commitment, ToS §4.6 explicitly authorising disclosure to “subpoenas, court orders or requests from official bodies”, real name + birth date + gender required at signup, phone validation effectively mandatory, and no anonymous payment route (Visa/Mastercard/PayPal/bank transfer/SEPA only — no crypto, no cash).
- Name: Inbox.eu — operated by SIA “INBOKSS” (LLC INBOKSS), reg. no. LV40003560720, headquartered at 15 Matrožu Iela, Rīga, LV-1048; sister consumer products on the same platform are inbox.lv (Latvia), inbox.lt (Lithuania), mail.ee (Estonia)
- URL:
inbox.eu - HQ jurisdiction: Latvia (EU/GDPR, outside 5/9/14 Eyes) GOOD0
- Hosting jurisdiction: Latvia — “INBOX processes personal information in its servers, which are located in Latvia”; data centre in Riga “built in accordance with European security standards (EN 50600-3)” GOOD0
- Zero-access encryption: None — marketing advertises “End-to-end encryption” as a Premium feature but the help-center article of the same name defines it as TLS-in-transit only: “Our service supports encryption in transit using TLS (Transport Layer Security) by default”; no PGP, no S/MIME, no zero-access vault; provider explicitly retains the ability to inspect content (“Any potential access is handled exclusively by our Security Department and only in response to a valid legal request”) BAD+3
- Government-access posture: No transparency report; no warrant canary; no user-notification commitment; ToS §4.6 explicitly authorises disclosure: "«Inbox.eu» can send personally identifiable information provided by you at registration to other companies or people when: … c) We respond to subpoenas, court orders or requests from official bodies”; ToS §7.6.14 widens to “good faith belief” preservation/disclosure — directly conflicts with the marketing privacy page that asserts “We do not store or share your personal information with third parties – neither government agencies nor advertisers … And we never will” BAD+3
- Anonymous signup: Real name + surname + birth date + gender required (“When registering, you must provide information about yourself: 1.1.1 Name 1.1.2 Surname 1.1.3 Birth date 1.1.4 Gender”); to send mail (not just receive), mobile-phone validation is required (“in the Trial mode, you can receive emails as well, however, to send new ones, you must validate your mobile phone number”); payment is Visa/Mastercard/PayPal/Swedbank/SEB/invoice only — “Payment card information is not collected or processed” — no crypto, no cash; Tor not stated BAD+2
- Funding stability: “Inbokss Ltd was established in 1998” — 27 years operating; self-described bootstrapped (“our service is shaped by real user needs — not venture capital pressure or data monetization”); no parent / shareholders disclosed in primary documents (treat as independent based on self-description) GOOD0
Sources (Legal Framework)
Latvian SIA. Terms of Service: “LLC INBOKSS, reg.no. LV40003560720, hereinafter referred to as «Inbox.eu»”. Privacy Policy: “SIA "INBOKSS" reg. No. 40003560720”. Footer: “Inbokss Ltd. 15 Matrožu Iela, Rīga, LV-1048”. Sources: Terms of Service , Privacy Policy , Inbox.eu .
Servers in Latvia; EU-only processing. Privacy Policy §2: “INBOX processes personal information in its servers, which are located in Latvia.” Marketing: “All data is hosted on our own servers in Latvia and handled in full compliance with the EU General Data Protection Regulation (GDPR)”; “Our headquarters and robust servers are located in Latvia, at the heart of the Baltics”; “Our servers are hosted in one of the largest data centers in Northern Europe — a secure and modern facility in Riga, built in accordance with European security standards (EN 50600-3).” Sources: Privacy Policy , Our story , Email privacy features .
Latvian governing law; PTAC consumer ADR. ToS §7.6.11 references “any applicable laws of the Republic of Latvia or any international laws”. ToS §4.10: “Your personal data will be processed in accordance with the "Personal Data Protection Law" requirements, and will be based on personal data processing systems of Latvian Republic Data State Inspectorate.” Complaints route via Latvia’s Consumer Rights Protection Centre (PTAC, Patērētāju tiesību aizsardzības centrs) at ptac.gov.lv/lv/content/stridu-risinasanas-process. No explicit choice-of-law clause for non-consumer commercial disputes. Source:
Terms of Service .
“End-to-end encryption” claim is TLS in transit only. Pricing page markets “End-to-end encryption” as a Premium feature, but the help-center article titled “End-to-end encryption” defines it as: “Our service supports encryption in transit using TLS (Transport Layer Security) by default across all our products and subscriptions. This ensures that emails are encrypted while being transmitted between servers, provided the recipient’s email server also supports TLS.” No PGP, no S/MIME, no zero-access at rest. Privacy Policy §6.1.1 mentions only “Encryption using a standard SSL” — algorithm/keying details for at-rest storage are not disclosed. Marketing security page describes transit encryption only: “every email you send is automatically encrypted using TLS 1.2+ protocol”. Server-side plaintext access is confirmed: “Any potential access is handled exclusively by our Security Department and only in response to a valid legal request submitted through the appropriate international legal channels, including Interpol where applicable.” Sources: Pricing , End-to-end encryption help article , Privacy Policy , Email security .
ToS authorises government disclosure; marketing claims the opposite. ToS §4.6.c: "«Inbox.eu» can send personally identifiable information provided by you at registration to other companies or people when: … c) We respond to subpoenas, court orders or requests from official bodies according to the procedure provided for by laws of the Republic of Latvia". ToS §7.6.14: “you acknowledge and agree that «Inbox.eu» may preserve the Content and may also disclose the Content if required to do so by law or in the good faith belief that such preservation or disclose is reasonably necessary to: a) comply with legal process; b) enforce the TOS; c) respond to claims that any Content violates the rights of third-parties; d) protect the rights, property of «Inbox.eu», or personal safety of «Inbox.eu», its users, and the public.” Marketing privacy page (directly conflicts): “We do not store or share your personal information with third parties – neither government agencies nor advertisers or advertising networks. And we never will.” No transparency report, no warrant canary, no user-notification commitment is published anywhere on inbox.eu. Sources:
ToS ,
Email privacy features .
IP logging; no retention period stated. Privacy Policy §1.2 logs login IP + date/time. §1.3: “When you use INBOX services, we can collect and process information on your physical location. INBOX uses location determination technologies based on your IP address.” The INBOX FILES ToS adds: “INBOX also automatically receives and records information on our server logs from your browser including your IP address, INBOX cookie information, and the page you requested.” No explicit IP-log retention period.
Conflicting deletion windows: 7 days (marketing) vs. one year (binding Privacy Policy). Privacy Policy §5.1: “The user has the right to delete their own personal data by deleting their profile in the "User Profile" section; access to the profile will be blocked and information about the user will be deleted from the INBOX servers within one year.” Marketing FAQ (directly conflicts): “When you request account deletion, we permanently remove all emails, contacts, files, and personal information from our servers within 7 days.” The Privacy Policy is the controlling document. ToS §2.9.2: “Inbox.eu service validity period to inactive (not validated) domain user (including domain registration date) is 270 days from day when account status change from "active" to "inactive". After these 270 days all domain account content and information about domain user will be permanently deleted from inbox.eu mail system.” ToS §2.10.1: “Inbox automatically deletes messages(permanently), located in the Trash folder 30 days after messages are moved or delivered to these folders.” Sources: Privacy Policy , Email privacy features , ToS .
Real identifying details required; phone validation gates outbound mail. Privacy Policy §1.1: “When registering, you must provide information about yourself: 1.1.1 Name 1.1.2 Surname 1.1.3 Birth date 1.1.4 Gender.” §4.2: “Providing personal identifying information is a prerequisite of using INBOX services.” Phone validation required to send (not just receive) mail: “In the Trial mode, you can receive emails as well, however, to send new ones, you must validate your mobile phone number”; “after the end of the 30-day trial period, TRIAL email addresses without validated mobile phone number will be deleted.” Sources: Privacy Policy , Trial validation , Trial deletion .
Payment: bank-linked rails only; no card data stored by Inbox.eu. Pricing page: “We also accept payment via bank transfers (Swedbank, SEB) and invoice payment via online banking.” Help center adds: “Credit card VISA and MasterCard users will be forwarded to First Data website for the purchase … Clients of payment system PayPal will be forwarded to Pay Pal website for the purchase.” Privacy Policy §1.4 confirms: “Payment card information is not collected or processed.” No cryptocurrency, no cash, no Monero/Bitcoin acceptance documented anywhere.
Business Premium is the only tier with custom domains. Pricing page: “Custom domain name addresses | Unlimited” in the Business column only. Business management model: “Use one Inbox.eu account to manage all your domain mailboxes. After registration add other domain in admin section.” Custom-domain attachment requires full DNS-level proof of control: “Verify domain ownership via DNS/MX records. To activate your domain, verify ownership using one of four methods (DNS, MX, TXT, or HTML).” Sources: Pricing , Mail for business , Business admin help .
Same-domain aliases only; 5 per mailbox. Pricing comparison: “5 email aliases” on Business Premium. Business help: “You can pay only for one mailbox, but use 5 more aliases for free. All mails sent to the specified aliases will go to your main mailbox. Aliases works without any time limits.” Alias scope is same-domain only: “Aliases - a way to create an additional names for any your email account without paying for another email, e.g. info@yourdomain.com, sales@yourdomain.com”. Sources: Pricing , Business help , Inbox.eu business info .
Catch-all is supported on paid custom-domain plans only. Help: “Catch-all feature is available for domain email users on the Inbox.eu platform. A Catch-all address allows you to receive emails sent to any non-existent address in your domain. … The Catch-all feature is available only for domains with a paid subscription.” Important precedence: “If an existing address matches the recipient, the email will go to that account instead of the catch-all.” No documentation of “wildcard alias” or *@domain as a sending identity. Source:
Catch-all feature .
IMAP / POP3 / SMTP supported; disabled by default. Pricing comparison: “IMAP/POP3/APOP/SMTPs access”. Server data: “POP3 server: mail.inbox.eu - IMAP server - mail.inbox.eu - SMTP server: mail.inbox.eu”; ports 995/POP3s, 993/IMAPs, 587 or 25 SMTPs. Caveat: “In order to ensure users’ safety, default access to mailbox using POP3/SMTP/IMAP protocol is denied. To enable this option, go to "Options", click "Email forwarding, mail programs, SMS alerts" and choose "Enable external POP3/IMAP and SMTP access".” Source: Mail program help .
2FA: TOTP authenticator app only; WebAuthn/SMS not stated. Help: “2-step verification (known also as two-factor authentication) is an extra layer of your account security … It can be implemented using mobile application for code generation, installed on your mobile device and set exactly for your account.” WebAuthn/FIDO2 not stated; no separate SMS 2FA login flow documented. Source: 2FA help .
No standalone DPA; one-clause processor stance. ToS §9.3: “If third-party personal data is stored on the INBOX platform, you are the data controller, and INBOX as the data repository is the processor, storing data in accordance with applicable Latvian legislation and GDPR requirements.” Source: ToS .
Trial is time-limited, no free tier. Marketing: “Yes, Inbox.eu provides a free 30 day trial version with essential features, as well as premium plans for users who require additional capabilities and advanced functionalities.” Trial outgoing-mail cap: “Send up to 3 emails per day”; phone validation required to send. Source: Inbox.eu .
Founded 1998; Inbox.eu product line launched 2011; bootstrapped. Our story: “Inbokss Ltd was established in 1998 as a European email provider with a clear vision: to deliver simple, secure, and private email services that respect user privacy.” And: “In 2011, we started a new project called Inbox.eu, which provides functional custom email addresses for the owners of registered domains.” Self-described funding: “our service is shaped by real user needs — not venture capital pressure or data monetization.” No external funding round, no acquirer, no parent disclosed. Source: Our story .
2024 Baltcom customer migration; 2022 DDoS on sister product inbox.lv. Inbokss company site: “In May 2024, LLC "Baltcom" and LLC "Inbokss" signed an agreement according to which LLC "Inbokss" will provide email services for LLC "Baltcom" clients on the inbox.eu platform”; “In June 2024, the company LLC "Baltcom," which became part of the mobile operator "Bite," migrated to the domain mail technical platform Inbox.eu.” (Baltcom was fully merged into Bite Latvija on 2024-07-01 per LSM and pricer.lt — a customer-acquisition event for Inbokss, not an acquisition of Inbokss.) The 2022 DDoS was on sister product inbox.lv and is documented only by external press (The Baltic Times, 2022-05-16): chairman Andris Grikis said inbox.lv had “faced the largest cyber attack in its history”; CERT.LV preliminarily attributed it to “cyberhooligan group Killent who supports Russia’s aggressive regime” (widely transliterated as “Killnet”). Source: Inbokss company page .
Migadu
Privacy Impact: MEDIUM8 — Bootstrapped Swiss company hosted in France with no built-in encryption, no transparency, and no published government-access posture.
- Name: Migadu — operated by Migadu-Mail GmbH, CH-9414 Schachen, Switzerland
- URL:
migadu.com - HQ jurisdiction: Switzerland (outside 14 Eyes) GOOD0
- Hosting jurisdiction: France (14 Eyes / 9 Eyes) — Swiss company but explicitly does not host in Switzerland OK+1
- Zero-access encryption: None — explicitly argues encryption-at-rest is just “encoding” if the keys live on the same infrastructure, and points users to external GPG instead BAD+3
- Government-access posture: No transparency report; no user-notification commitment; no warrant canary BAD+3
- Anonymous signup: Tor not stated; cash not accepted; Bitcoin only off-site via direct wallet on request (no on-site crypto checkout); minimal signup data OK+1
- Funding stability: Profitable, bootstrapped Swiss company since 2014; founders explicitly state “We have not taken any outside capital nor plan to ever do so. We are not interested in ’exiting’ our company.” GOOD0
Sources (Legal Framework)
Operated by Migadu-Mail GmbH, Rohnen 587, CH-9414 Schachen, Switzerland. Source: Privacy/DPA and Contact .
Swiss company, French servers. Pros/cons page: “In Switzerland, but servers are not… This may come as a surprise, but we do not host our servers in Switzerland. Current data centers are located in France.” Source: Pros & cons . This is the largest jurisdiction-vs-hosting mismatch in this comparison.
No built-in encryption — explicit refusal. “Email as we know it and encryption are incompatible. If someone is telling you otherwise, they are not to be trusted… If we were to roll out encryption at rest, we would have to keep the encryption keys ourselves. That means we would be encrypting and decrypting messages on the fly using a key which is available on the same storage where your data is. That is not encryption but rather encoding.” Recommends external GPG end-to-end instead. Source: Pros & cons .
Privacy doc serves as DPA. “The processing of personal data takes place in compliance with the EU General Data Protection Regulation (GDPR) and the local Swiss Federal Data Protection Act (DPA). This document serves both as our Privacy Policy and as our Data Processing Agreement (DPA).” Stripe and PayPal listed as sub-processors. Source: Privacy/DPA .
Minimal signup data, no anonymous payment. Signup requires only an existing email address (used as login + for confirmation). Card via Stripe, PayPal prepayment; “We do not offer on-site payments with BitCoins. However, if this is your preferred payment method, you can reach out to support and we will give you our wallet address.” No cash. Source: Pricing FAQ .
No mailbox 2FA. Pros/cons: “No mailbox 2FA (yet!)… IMAP protocol as well email clients do not support second factor authentication for the mailboxes… We do offer so called App-specific passwords via mailbox identities though. These are commonly touted by email providers as 2FA. They are not.”
No provider domain. “We do not offer email at our domains. Our whole service was built around the premise of giving email liberties back to the users, not taking them away.” Migadu is custom-domain-only — the inverse of Posteo’s policy.
Bootstrapped, profitable, family-style since 2014. About: “Behind Migadu stands a small bootstrapped, independent Swiss company… We have not taken any outside capital nor plan to ever do so.” “Profitable shortly after founding in 2014.” Source: About .
Runbox
Privacy Impact: MEDIUM8 — Employee-owned Norwegian host with a Norwegian-court-order disclosure policy that explicitly rejects CLOUD Act compulsion, a published transparency report (updated 2026-05-12), and crypto payment via Bitcoin and Coinbase Commerce — but no built-in zero-access encryption, no warrant canary, no user-notification commitment, and Runbox 7’s promised native PGP and FIDO2/WebAuthn 2FA have remained unshipped for seven-plus years.
- Name: Runbox — operated by Runbox Solutions AS, Oslo, Norway
- URL:
runbox.com - HQ jurisdiction: Norway (14 Eyes / 9 Eyes member, strong privacy laws; EEA member, outside EU but inside GDPR via local Personal Data Act) OK+1
- Hosting jurisdiction: Norway — “Runbox owns and operates its own servers, which are physically located in Oslo, Norway” (DigiPlex data centre) OK+1
- Zero-access encryption: None built in — “encrypted SSD storage” (hardware-level only, protects against physical theft) plus opt-in client-side PGP via third-party clients (Mailvelope, Thunderbird, GPGTools); Runbox itself notes “the only way to truly ensure that your email can’t be read by anyone you don’t intend it to be read by is to use end-to-end encryption” BAD+3
- Government-access posture: Public transparency report (“This page is up to date as of 2026-05-12”); Norwegian-court-order requirement (“Runbox will by principle respond by requesting a Norwegian court order pursuant to the Norwegian Criminal Procedure Act before disclosing any information”); no explicit user-notification commitment; no warrant canary BAD+2
- Anonymous signup: Tor not officially documented but not blocked (Runbox Support on the tor-talk mailing list, March 2017: “Using Tor is no problem at all”); Bitcoin (direct wallet) + Coinbase Commerce + cash by mail (“sent via regular mail at your own risk, and is not recommended”); ToS requires first/last name + country + alternative email at signup (phone optional, real-name not technically verified) OK+1
- Funding stability: Email service launched 12 October 2000; current operating entity Runbox Solutions AS formed March 2011 (employee buyout from Runbox AS); “Runbox is owned by employees and board members (77.54% in 2024) and close associates”; no external investors; partial Runbox 7 R&D funding from The Research Council of Norway GOOD0
Sources (Legal Framework)
Operated by Runbox Solutions AS, Oslo, Norway. Privacy policy: “Runbox Solutions AS (‘Runbox Solutions’), a company incorporated and located in Norway, provides users with email, web, and domain hosting services.” Source: Privacy Policy . About: “Founded in 2000 and based in Norway, Runbox Solutions is an independent, limited liability company with headquarters in Oslo.” Source: About .
Owned-server hosting in Norway; CLOUD Act inapplicable. Blog: “Runbox owns and operates its own servers, which are physically located in Oslo, Norway. While the facility housing our servers is managed by a third party, the servers—and all the data on them—are fully owned and controlled by Runbox.” And: “The CLOUD Act applies only to data—not the physical facility where servers are housed. Because Runbox owns and controls the servers, your data remains under Norwegian jurisdiction.” Source: Runbox vs the CLOUD Act .
Norwegian law, Oslo city court. ToS: “The Agreement shall be governed by the laws of Norway. You agree that the Norwegian courts shall have exclusive jurisdiction to resolve any and all disputes related to the Agreement. Oslo city court shall be the agreed legal venue.” Source: Terms of Service .
Hardware-encrypted SSDs; no built-in zero-access. 2022 board annual message: “All email account data processed through the Runbox email service is stored on our own physical servers in Norway on encrypted SSD storage.” But Runbox itself acknowledges this is not zero-access: “Although Runbox always tries to encrypt your email during transfer … the only way to truly ensure that your email can’t be read by anyone you don’t intend it to be read by is to use end-to-end encryption.” Runbox 7 native PGP has been on the roadmap since at least November 2018 (“Runbox 7 Webmail beta test is now open to the public!”) but is not shipped as of May 2026 — over 7.5 years in public beta. CyberInsider’s 2026 round-up summarises the architectural limit: “Runbox doesn’t provide end-to-end encryption. This means that your emails aren’t encrypted on Runbox servers, so technically their staff can access all of your sensitive data.” Sources: Annual Message 2022 and the Encryption help FAQ.
Norwegian-court-order disclosure policy. Blog: “If an entity requests access to any user data, Runbox will by principle respond by requesting a Norwegian court order pursuant to the Norwegian Criminal Procedure Act before disclosing any information.” Source: Why we require a Norwegian court order . Privacy policy: “Runbox Solutions will not disclose your Account Information, or access or disclose your Account Content, except with your written permission or unless acting under good faith that such action is necessary to: conform to legal requirements or comply with legal process pursuant to Norwegian law; protect or defend the rights or property of Runbox Solutions.”
Transparency report published; no warrant canary, no notification commitment. Live report: “On this page you will find statistics on requests for disclosure of individual customer data that Runbox Solutions AS has received directly from authorities and others (law firms, individuals, etc) … This page is up to date as of 2026-05-12.” Update cadence is irregular rather than scheduled. Source: Transparency Report . Historical Runbox MD statement: “To date Runbox have received a total of 4 requests for information from Norwegian or foreign authorities, and complied with 1 request from Norwegian authorities after having been presented a Norwegian court order.” No warrant canary; no commitment to notify users when legally permitted.
Log retention. “Server logs relating to email delivery are stored for 10 days, while server logs relating to usage of the web interface are stored for 1 month.” IP stripping on outbound: “When sending email with the Runbox 6 Webmail, your IP address is no longer included in the message headers.” Source: Runbox email privacy 2013-06 .
Account-deletion + backup retention. Privacy Policy: “Email service content … is stored in main storage on servers located in Norway for as long as your account is active and: up to 3 months after closure of trial accounts; or up to 6 months after closure of subscribed accounts.” Backups: “Backup of Account Content is stored on secure servers separate from the Runbox system for up to 6 months, even after the content has been deleted from the main storage, except for accounts that have activated the ‘No backup’ feature more than 6 months prior to this.” Account-Information records retained up to 5 years post-closure per Norwegian bookkeeping law.
Signup data + anonymous payment. Privacy policy: “You consent to providing us with the following personal data when you register an account: First name, last name, company name (where applicable), mobile phone number (where applicable), country, and alternative email address.” Phone is optional; first/last/country/alt-email required. Real-name accuracy is not technically verified. Tor: only a March 2017 Runbox Support mailing-list reply confirms “Using Tor is no problem at all”; no formal Tor policy in primary docs. Crypto: “Runbox supports Coinbase payments via Coinbase Commerce and direct transfers to our Coinbase wallet” and “After selecting the desired products, select ‘Pay with Bitcoin’ as the payment method.” Cash: “Cash is sent via regular mail at your own risk, and is not recommended.” Cheques and money orders no longer accepted. Sources: Coinbase payments help , Bitcoin payments blog , Payment methods .
2FA: TOTP + OTP only. Blog (June 2017): “Runbox 2FA currently supports Timed One-Time Passwords (TOTP) and One-Time Passwords (OTP) as additional factors. We are planning to expand this with Yubikey or U2F support.” WebAuthn / FIDO2 / YubiKey remained “planned” as of May 2026 — over eight years on. Source: Runbox 2FA .
No native mobile app. Runbox 7 webmail is delivered as a Progressive Web App (PWA), installable on iOS via Safari “Add to Home Screen” and on Android via the browser prompt. Standard IMAP clients work normally. Source: Runbox 7 features .
Custom domains + catch-all + unlimited aliases. “To host your domain’s mail with Runbox, you can add it from the Account » Email Hosting screen. You must change your domain’s MX records to mx.runbox.com” (MX takeover, all-or-nothing per domain). “The number of email aliases you can create on your own domain name is unlimited.” Catch-all on hosted domains: “Runbox supports a so-called ‘catch all’ function for email hosting. This means that you will receive mail on any valid address for your domain without having to setup an explicit alias. All mail will automatically be received by your main Runbox account.” Sources: FAQs , Quotas , Catch-all .
Bootstrapped, employee-owned since 2011. About: “Runbox is owned by employees and board members (77.54% in 2024) and close associates. The company in its current form was founded in March 2011.” Recent operational incident publicly documented: Post-Event Analysis of Email Service Incident March 4th, 2026 — hardware failure remediated by rebuild and added redundancy, “No user data was lost.”
GMX
Privacy Impact: HIGH9 — Free, ad-financed German webmail operated by 1&1 Mail & Media GmbH (Karlsruhe branch / Montabaur HQ, HRB 7666; indirect subsidiary of publicly-listed United Internet AG, Frankfurt Xetra ticker UTDI). Servers stated to be exclusively in Germany under the “E-Mail made in Germany” alliance, but the only PGP path is opt-in via the third-party Mailvelope browser extension (Chrome/Firefox only — subjects/metadata stay plaintext), no GMX-branded transparency report exists (the entity-level Jahresbericht is published only at the WEB.DE-branded URL), no warrant canary, no notification commitment, and the “Consent or Pay” model conditions free service on accepting personalised ad tracking. Distinct gotcha vs WEB.DE: paid tiers (ProMail / TopMail) are offered only to DE/CH/AT residents on the German gmx.net site — the English gmx.com markets only FreeMail with no upgrade path.
- Name: GMX — operated by 1&1 Mail & Media GmbH, Brauerstr. 48, 76135 Karlsruhe (Zweigniederlassung); Hauptsitz Montabaur (Amtsgericht Montabaur HRB 7666; VAT DE243413002); managing directors Alexander Charles, Dr. Michael Hagenau, Thomas Ludwig, Dr. Verena Patzelt
- URL:
gmx.com(English) /gmx.net(German) - HQ jurisdiction: Germany (14 Eyes / SSEUR, strong GDPR) OK+1
- Hosting jurisdiction: Germany — “We process all personal data in secure data centers in Germany”; “Your personal data never leaves GMX; it is saved in our secure computer centers in accordance with European data protection laws” OK+1
- Zero-access encryption: Opt-in via the third-party Mailvelope browser extension (Chrome/Firefox only): “GMX has optimized the OpenPGP procedure to make it user-friendly. This was achieved in cooperation with the Mailvelope open source project from Heidelberg, Germany”; PGP key + passphrase live in the browser (“all important data is stored by the user. Neither government agencies, nor GMX, nor Mailvelope have access to the encrypted email content”); but without Mailvelope enabled GMX has full plaintext access — and the “Encrypted communication … makes the sender, recipient, subject (metadata) and content inaccessible” claim applies only to Mailvelope-encrypted messages between PGP-using counterparties OK+1
- Government-access posture: No GMX-branded transparency report (no URL on
gmx.com,gmx.net,mail-and-media.com, orunited-internet.depublishes one; the entity-level Jahresbericht lives only at the WEB.DE-branded URL); Privacy Policy authorises disclosure (“To work with law enforcement agencies. For example, to respond to inquiries or orders from law enforcement agencies or to provide information that we believe is important”) without committing to user notification; no warrant canary BAD+2 - Anonymous signup: Required signup fields are “gender, name, country, state, and date of birth” plus “mobile phone number and/or a secondary email address” for password recovery; Google reCAPTCHA at signup; payment via SEPA-Lastschrift / PayPal / Visa / Mastercard / Amex — no crypto, no cash; Tor neither documented nor blocked; paid tiers offered only to DE/CH/AT residents (“GMX ProMail ist nur für Kunden mit Wohnsitz in Deutschland, Schweiz oder Österreich bestellbar”); ad-funded free tier requires personalised tracking unless paid TrackFree opt-out is purchased on the German side BAD+2
- Funding stability: Publicly-listed parent United Internet AG (Frankfurt Xetra ticker UTDI, ISIN DE0005089031); 1&1 Mail & Media Applications SE is the group’s Consumer Applications segment (1,115 employees as of 2025-06-30 per the H1 2025 Interim Report; 10,824 group-wide); GMX launched 1997 by Michael and Matthias Greve, acquired into the 1&1 / United Internet group by 2001 and consolidated into 1&1 Mail & Media in 2005, mail.com acquired 2010 — “Acquired into corporate ad-funded group” category BAD+2
Sources (Legal Framework)
German legal entity; Montabaur jurisdiction. GMX Terms: “This Agreement is governed by, and shall be interpreted in accordance with, German law. If the customer is a consumer with habitual residence in the EU, the customer shall also enjoy the protection of the mandatory provisions of the law of his state of residence.” About GMX: “District court: Montabaur Commercial register number: 7666 VAT ID: DE243413002”. Sources: GMX Terms , About GMX .
Servers in Germany; “E-Mail made in Germany” alliance. Privacy Policy: “We process all personal data in secure data centers in Germany.” Mail-client data-collection page: “Your personal data never leaves GMX; it is saved in our secure computer centers in accordance with European data protection laws.” Security page: “within the network, transmission paths are automatically encrypted and your emails are only stored in secure European data centers”; “Encrypted communication complements transport encryption and offers protection even if the email leaves the secure email made within the European network.” TLS minimum: “You can only use a TLS protocol if your email program uses TLS versions 1.2 or 1.3. For security reasons, we no longer support the older TLS versions 1.0 and 1.1.” Sources: Privacy Policy , Mail client data , Encryption , Outlook setup .
Mailvelope third-party PGP; encryption-at-rest details Not stated. Encryption page: “GMX has optimized the OpenPGP procedure to make it user-friendly. This was achieved in cooperation with the Mailvelope open source project from Heidelberg, Germany”; “Yes, email attachments like pictures and other files are also encrypted with OpenPGP.” And: “Browser-based storage means that all important data is stored by the user. Neither government agencies, nor GMX, nor Mailvelope have access to the encrypted email content. Even court decisions on data delivery will remain ineffective because of this.” Encryption-at-rest algorithm/keying details: not stated. The English Terms say only: “Once GMX have received your information, GMX will use strict procedures and security features to try to prevent unauthorized access.” Sources: GMX Encryption , GMX Terms .
IP and traffic-data logging; 7-day Verkehrsdaten retention; 21-day deactivation; 6-month inactivity deletion. English Privacy Policy: “date and time of access or delivery or IP address of the device used to access your inbox … Traffic data are deleted after the expiry of the legal retention period.” German Datenschutzhinweise: “Verkehrsdaten werden entsprechend der rechtlichen Anforderungen grundsätzlich innerhalb von sieben Tagen gelöscht” and “Falls du deinen Account löschen möchtest, deaktivieren wir zunächst deinen Account, überprüfen deinen Löschanspruch und löschen diesen in der Regel nach 21 Tagen.” Terms: “GMX is entitled to delete the messages saved in the customer’s account and other files after a period of 6 months of inactivity … without warning. After a period of 1 year of inactivity, GMX shall also be entitled to release the customer’s GMX email addresses (‘aliases’) and make them available to other customers.” KB confirms 1-year address block: “For security reasons, your email address will be blocked for 1 year. This means that no one can register with your old email address in this time period.” Sources: Privacy Policy , Datenschutzhinweise , Terms , Account deletion .
Government-access disclosure authorised; no transparency report at any GMX URL; no canary. Privacy Policy: “To work with law enforcement agencies. For example, to respond to inquiries or orders from law enforcement agencies or to provide information that we believe is important” and “To comply with applicable laws and regulations. This may include laws outside of your country of residence.” German Datenschutzhinweise: “Überdies können Daten an andere Verantwortliche weitergegeben werden, wenn wir gesetzlich dazu verpflichtet sind oder eine behördliche oder gerichtliche Anordnung vorliegt.” No transparency report is hosted on gmx.com, gmx.net, mail-and-media.com, or united-internet.de. The entity-level Jahresbericht hosted at the WEB.DE-branded URL covers all 1&1 Mail & Media German portals at the entity level (46.32M total mailboxes), but is not surfaced from any GMX property. Sources:
Privacy Policy ,
Datenschutzhinweise .
Required signup data + Google reCAPTCHA. FAQ: “Enter your gender, name, country, state, and date of birth” and “Pick a backup recovery option by including your mobile phone number and/or a secondary email address. These are used in order to reset your password in the event you forget it. Your details remain secure and will only be used for password recovery” and “Prove you’re not a robot by entering the Google security captcha form.” No Tor support/block statement. Source: GMX FAQ .
Paid tiers DE/CH/AT only. “Preise: GMX ProMail kostet 3,99 € pro Monat, GMX TopMail 6,49 € pro Monat und das Bundle ProMail + 500 GB Cloud 8,48 € pro Monat. Die Abrechnung erfolgt bei ProMail und TopMail jeweils halbjährlich im Voraus.” “Hinweis: GMX ProMail ist nur für Kunden mit Wohnsitz in Deutschland, Schweiz oder Österreich bestellbar.” English gmx.com markets only FreeMail with no Premium/Upgrade link in the footer. Sources:
GMX Premium DE ,
ProMail ,
TopMail .
FreeMail is ad-funded. Privacy Policy: “To ensure that we can continue to provide you with these services free of charge, we show advertising.” Storage: “Plenty of storage space with 65GB; Send attachments up to 50MB in size; Bonus features like Online Office and Organizer.” “TrackFree” anti-tracking add-on (German market only) is a paid opt-out: “Es ermöglicht die Nutzung aller GMX Seiten und Dienste ohne personalisiertes Tracking und personalisierte Werbung.” Sources: GMX FAQ , GMX Premium FAQ DE .
10-alias allowance on GMX-owned TLDs only; no custom domain on gmx.com. Alias help: “Your GMX account comes with the option of creating and using up to 10 different sender addresses, even allowing you to select other email domains for your alias addresses as well. … you also have the option of switching the email domain for another one of GMX’s available options – such as gmx.us, gmx.co.uk, or gmx.ca.” Custom-domain product (German market only): “Preise: Mit GMX FreeMail ab 1,99 € mtl. je nach gewählter Domain-Endung. Mit GMX Premium erhalten Sie exklusive Preisvorteile ab 0,97 € mtl. je nach gewählter Domain-Endung. … Die Vertragslaufzeit beträgt 12 Monate.” Per registered domain: “Zu jeder Domain erhalten Sie 500 E-Mail-Adressen”. Custom-domain attachment via forwarding-into-GMX: “Sie können eine Weiterleitung auf eine eigene E-Mail-Adresse einrichten oder auf das GMX Postfach einer anderen Person”. Sources:
Alias addresses ,
Homepage & Mail DE ,
Persönliche Domains .
Catch-all: Not stated in any English help-center page reviewed. Searches across the English gmx.com help center for “catch-all” and “wildcard alias” return nothing.
IMAP / POP3 / SMTP supported, off by default. Help: “POP3/IMAP sync is deactivated by default. If you wish to use third party applications or mobile apps to sync your email, you need to activate this feature in your settings.” Server data: “Incoming mail: Server imap.gmx.com with port 993 … Outgoing mail: Server mail.gmx.com with port 587 and the encryption method STARTTLS.” Sources: POP/IMAP toggle , Outlook setup .
2FA: TOTP only; app-specific password required for IMAP after 2FA. Help: “After 2FA is enabled, you will be prompted not only for your password but also for a 6-digit one-time password (OTP), which you generate on your smartphone using an authentication app” and “the six-digit code is also known as a ’time-based one-time password’ (TOTP).” App-specific passwords: “You can have the app-specific password created during the activation of two-factor authentication. You need it if you retrieve your emails via POP3/IMAP and use an external email program such as Outlook or Thunderbird.” SMS used only at enrollment, not as a login factor: “During setup, you must enter a confirmation code, which you will receive by text message to your mobile phone number.” WebAuthn/FIDO2/hardware-key support: not stated. Source: 2FA help .
GDPR controller; no standalone DPA. Privacy Policy: “We are the ‘data controller’ for all data processing that results from your use of these functions. As per the GDPR, you are assigned the role of the ‘data subject’ and therefore benefit from the rights listed in Section 1.3 above.” DPO: “Data Protection Officer of 1&1 Mail & Media GmbH … Elgendorfer Str. 57, 56410 Montabaur, Germany … e-mail: dataprivacy@corp.gmx.com.” CCPA: “In accordance with CCPA, California residents have the right to have access to and delete their data, as well as to opt-out of the sale (broadly interpreted) of their personal data. In order to guarantee and facilitate the exercise of these rights, we have provided the page ‘Do not sell my personal Information’.” Source: Privacy Policy .
Group context: United Internet AG; 42M users. 1&1 Mail & Media corporate page: “in March 1997, GMX (Global Message Exchange) was launched in Munich as one of Germany’s first e-mail providers”; “Our GMX, WEB.DE & mail.com brands have 42 million active users around the world.” United Internet H1 2025 Interim Report: “As of June 30, 2025, the United Internet Group employed 10,824 people” with “1,115 in the Consumer Applications segment (prior year: 1,070).” SLA: “GMX guarantees an annual average server accessibility of 99%.” Sources: 1&1 Mail & Media , United Internet H1 2025 , GMX Terms .
Mailo
Privacy Impact: HIGH9 — French jurisdiction and hosting, but server-side PGP only, no transparency report, no anonymous payment, and identifying data asked at signup.
- Name: Mailo — operated by MAILO SAS, France; technology by Mail Object
- URL:
mailo.com - HQ jurisdiction: France (9 Eyes / 14 Eyes, strong GDPR) OK+1
- Hosting jurisdiction: France OK+1
- Zero-access encryption: None for default mailbox; opt-in OpenPGP with server-stored keypair (Mailo holds both public and private keys, the private key encrypted by passphrase); no encryption-at-rest claim OK+1
- Government-access posture: No transparency report; no user-notification commitment; no warrant canary; states it may provide data only on French magistrate authorisation BAD+3
- Anonymous signup: First/last name + DOB asked at signup; payment via card / PayPal / surcharged phone only — no crypto, no cash; Tor not stated BAD+2
- Funding stability: Privately held French SAS; mixed business model (ad-supported free + paid subscriptions); MAILO SAS registered 2019, technology by Mail Object since the late 1990s OK+1
Sources (Legal Framework)
Operated by MAILO SAS (RCS 851585547), France; service edited by Mail Object. “Le service Mailo (anciennement NetCourrier) est édité par la société française Mail Object et en utilise la technologie.” Source: About Mailo (press) .
French hosting, French law. “Mailo is hosted in France in a specialized host center with 24-hour supervision.” Source: Who we are . ToU: “This contract… is governed by French law. Any dispute concerning the validity, interpretation or execution of these Terms of Use will, after failure of any conciliation, be submitted to the competent courts.”
Server-side PGP, not zero-access. “Pour vous permettre d’utiliser PGP en toute facilité, Mailo stocke votre paire de clés (clé privée + clé publique) et les clés publiques de vos correspondants.” (Mailo stores your keypair — private key + public key — and your contacts’ public keys.) Source: Blog: encrypt with PGP . And: “Net-C propose une intégration de PGP côté serveur, avec tiers de confiance.” (Net-C offers server-side PGP integration as a trusted third party.) No encryption-at-rest claim in Mailo’s own docs.
No transparency report, no canary. Privacy rules: “Mailo may be required to provide data to the police, gendarmerie and justice authorities in a strict legal framework with the authorization of a magistrate.” Source: Privacy rules . The charter adds: “The users’ data is confidential: no backdoor is open for anyone, even authorities requesting access outside a specific legal framework.” No published transparency report; no warrant canary; no explicit user-notification clause.
Identifying data at signup. “you provide personal information that you explicitly fill in such as your first and last name, your e-mail address, your date of birth or your language.” DOB is mandatory to verify the user is 16+. Source: Privacy rules .
No anonymous payment. FAQ: “Mailo vous permet de régler en ligne de façon totalement sécurisée par carte bancaire (CB, Visa, Mastercard) ou par PayPal.” Source: Payment methods . ToU adds “a surcharged phone number” as an option. No crypto, no cash. Tor not mentioned anywhere in Mailo’s own docs.
2FA: TOTP only. “Pour renforcer la sécurité de votre compte, vous pouvez activer la double authentification (2FA).” Provider response on FIDO2/U2F hardware keys: “Bonjour, ce n’est pas prévu aujourd’hui.” (Not planned today.) SMS 2FA explicitly rejected as insecure. Source: 2FA FAQ .
Logs. Detailed connection history (with IP) retained 30 days and exposed in the user panel for self-audit. A broader IP-log retention policy is not stated.
Account deletion. Free accounts inactive for 12 months are auto-deleted; ToU: “All their data will then be permanently deleted.” No grace-period window stated for user-initiated deletion.
Mixed funding model. “Pour assurer ses équilibres financiers et sa pérennité, Mailo dispose de deux modèles économiques : – des boîtes aux lettres gratuites avec des bannières publicitaires dans le webmail – des packs…” Source: About Mailo (press) . Per French government registry, MAILO SAS was registered 15 May 2019; Mail Object (the underlying tech company) is older. No outside investors mentioned.
Riseup
Privacy Impact: HIGH9 — Activist non-profit with built-in personally-encrypted storage, Tor onion services, anonymous payment via Monero/Zcash/cash, and an active warrant canary — but US jurisdiction, US-based collective, complied with two sealed FBI warrants in 2017 under gag order, and no native account 2FA, no automatic migration tool, no custom-domain hosting.
- Name: Riseup Networks — registered 501(c)(4) nonprofit; PO Box 3027, Lacey, WA 98509 USA; “The Riseup Collective is an autonomous body based in Seattle with collective members world wide”
- URL:
riseup.net - HQ jurisdiction: USA (5 Eyes, CLOUD Act); “Riseup is a registered nonprofit under section 501(c)(4) of the US Internal Revenue Code” BAD+3
- Hosting jurisdiction: Not stated in provider docs (only that they have “physical control of our servers, they are not hosted ‘in the cloud’”); Riseup is US-based and operates from Seattle — assume US BAD+3
- Zero-access encryption: Personally-encrypted storage for new accounts since March 2017 — Riseup unwraps the user key during a session (“With Riseup’s new system, you still put faith in the server while you are logged in”); structurally equivalent to StartMail’s vault model; “the email ‘subject’ and routing information regarding the message ‘from’ and ’to’ are seen by our servers in the clear when the email initially arrives” OK+1
- Government-access posture: Active warrant canary re-signed quarterly (Feb 1 / May 1 / Aug 1 / Nov 1); no published government-request statistics (“transparency report”); no explicit user-notification commitment (in 2017 a sealed gag order prevented disclosure of two FBI warrants) BAD+2
- Anonymous signup: Tor onion services for IMAP/POP3/SMTP and web (“5gdvpfoh6kb2iqbizb37lzk2ddzrwa47m6rpdueg2m656fovmbhoptqd.onion”); invite-code signup with no phone or personal info; cash by post and crypto (Monero, Zcash, Bitcoin) accepted for donations GOOD0
- Funding stability: 501(c)(4) nonprofit, operating since around 1999 (described in a 2024 newsletter as “almost 25 years ago”); donation-funded with no advertisers or investors; “all financial decisions by the Riseup Collective are made using the consensus process” GOOD0
Sources (Legal Framework)
US nonprofit collective. Donate page: “Riseup is a registered nonprofit under section 501(c)(4) of the US Internal Revenue Code.” Legal address: “Riseup Networks, PO Box 3027, Lacey, WA 98509 USA”. The collective is described as “an autonomous body based in Seattle with collective members world wide”. Sources: Donate , Contact , About .
Washington-state law, King County courts. ToS: “You agree that these Terms of Service and your use of riseup’s services is governed by the law of the State of Washington and any claim or dispute shall be resolved in the Superior Court for King County, Washington.” Source: Terms of Service .
Personally-encrypted storage since March 2017 — but not E2EE. Privacy policy: “All of your data is stored in an encrypted format, and only Riseup has the keys to decrypt the data. Additionally, as of March 2017, the storage for all new accounts is personally encrypted. Riseup is unable to read any of the stored content for these accounts.” Canary statement: “We have taken action to ensure that Riseup never again has access to a user’s stored email in plaintext.” But the same statement clarifies the model: “To be absolutely clear, this type of encryption is not end-to-end message encryption. With Riseup’s new system, you still put faith in the server while you are logged in. For full end-to-end email encryption, as before, you must use a client that supports OpenPGP (and is not web-based).” And the metadata gap: “Even when using end-to-end OpenPGP encryption for email messages, the email ‘subject’ and routing information regarding the message ‘from’ and ’to’ are seen by our servers in the clear when the email initially arrives. This is due to inherent limitations in the email protocol and in OpenPGP.” Sources: Privacy Policy and Canary Statement .
No IP retention. “No IP addresses of any user for any service are retained.” And: “Unlike corporate providers, we do not log internet addresses of anyone using riseup.net services, including email.” From/To metadata logged for abuse-prevention: “In order to detect when our servers are under attack from a ‘spam bomb’ or when a spammer is using our system, we keep a log of the ‘from’ or ’to’ information for every message relayed. These logs are purged on a daily basis.” Source: Privacy Policy .
Warrant canary, no published transparency report. Canary page: “Riseup positively confirms that the integrity of our system is sound: all our infrastructure is in our control, we have not been compromised or suffered a data breach, we have not disclosed any private encryption keys, and we have not been forced to modify our system to allow access or information leakage to a third party.” Re-signing schedule: “This canary will be re-signed on the following dates: February 1, May 1, August 1, November 1.” Source: Canary . General posture: “We will do everything in our power to protect the data of social movements and activists, short of extended incarceration. We would rather pull the plug than submit to repressive surveillance by our government, or any government.” Source: Recent email provider closures . No periodic government-request statistics page.
Tor onion services for IMAP / POP3 / SMTP. “We provide Tor Onion Services (Hidden Services) in case you need to increase your anonymity or circumvent possible blocks to our services.” And: “mail.riseup.net: 5gdvpfoh6kb2iqbizb37lzk2ddzrwa47m6rpdueg2m656fovmbhoptqd.onion (ports 25, 80, 110, 143, 465, 587, 993, 995).” Sources: Email and Tor .
Invite-code signup, no phone. “In order to create an account you will need an invite: 1. Obtain an Invite Code from a friend who trusts you … 2. Use the Invite Code by visiting account.riseup.net to create your account.” And: “Because we do not require a phone number or billing information, we need some alternate way to prevent abuse.” And: “We do not require you to sign up with a phone number or personal information. Instead, we rely on invite codes.” Sources: Mail accounts and Email .
Anonymous payment paths for donations. “You can send us cash in any currency in the mail to our PO Box. People do this all the time.” And: “Or use a cryptocurrency. Monero and Zcash are anonymous. For Bitcoin, you need to do a bit of work if you want to ensure strong anonymity with Bitcoin.” No paid email tiers — donations are “asked” but not required. Source: Donate .
No webmail 2FA; no account-level 2FA documented. “We are not currently offering two-factor authentication for Roundcube, as the plugin had a lot of problems. Sorry.” Source: Roundcube 2FA . Account-level 2FA mechanisms (TOTP, WebAuthn/FIDO2, SMS) for the wider Riseup account are not documented in the help pages reviewed.
Small storage; no migration tool. “For different reasons we can only provide 1 GB of storage space for e-mail.” Source: Email . No automated import/migration tool from Gmail or generic IMAP is documented.
Custom domains and catch-all not offered. Riseup documents alias addresses on riseup.net and forwarding rules. A third-party-domain feature exists but is sender-only and discouraged: “Riseup also allows registering aliases for other 3rd party domains. This is an advanced usage and we don’t recommend you try to do it if you are not familiar with advanced email internals.” And: “If you add an alias for a domain other than riseup.net, mails sent to that address will not automatically arrive in your riseup account.” No catch-all / wildcard alias support is documented. Source:
Aliases .
2017 sealed-warrant compliance. Canary statement: “After exhausting our legal options, Riseup recently chose to comply with two sealed warrants from the FBI, rather than facing contempt of court (which would have resulted in jail time for Riseup birds and/or termination of the Riseup organization). There was a ‘gag order’ that prevented us from disclosing even the existence of these warrants until now. This was also the reason why we could not update our ‘Canary’.” The personally-encrypted storage rollout was the technical response: “We have taken action to ensure that Riseup never again has access to a user’s stored email in plaintext. Starting today, all new Riseup email accounts will feature personally encrypted storage on our servers, only accessible by you.” Source: Canary statement . Unusual transparency — most providers under US gag orders never retroactively disclose.
Seeweb
Privacy Impact: HIGH9 — Italian SMB cloud-hosting provider operating since 1998 (rolled into publicly-listed DHH S.p.A. on Euronext Growth Milan in 2020), Cloud Mail (legacy brand TrueMail) is GDPR-aligned and EU-only with data and backups in Italian/EU Seeweb data centres — but customer mail is server-side plaintext (the provider performs content-level antispam/AV inspection and full daily backups via IBM Spectrum Protect), the only PGP is opt-in client-side in the Roundcube webmail, no transparency report, no warrant canary, no notification commitment, no standalone DPA template, no documented 2FA on the customer area, no native mobile app, custom domain is mandatory at every tier (no free tier), and payment is restricted to PayPal / SEPA-RID / bank transfer (no credit card, no crypto, no cash). Adherence to the CISPE Code of Conduct (GDPR Art. 40/42 code; EDPB positive opinion 2021-05-19; CNIL approval 2021-06-03) is its strongest formal compliance signal.
- Name: Cloud Mail (legacy TrueMail; mail and webmail endpoints still on
mail.truemail.it/webmail.truemail.it) — operated by SEEWEB srl, Via Armando Vona 66, 03100 Frosinone, Italy (P.IVA 02043220603; capitale sociale €103,000; CCIAA 17793/98; REA 126233) - URL:
seeweb.it/prodotti/cloud-mail - HQ jurisdiction: Italy (14 Eyes / SSEUR, EU/GDPR) OK+1
- Hosting jurisdiction: Italy — “Tale backup avviene sempre off-site (su Data Center Seeweb distante da quello dove viene gestito il servizio di posta)”; “L’aderenza al CISPE e quindi anche al GDPR garantisce inoltre che i dati siano gestiti e conservati esclusivamente all’interno del territorio europeo”; data centres in Milan (2), Frosinone (1), partner facilities in Lugano / Zurich / Sofia OK+1
- Zero-access encryption: Cloud Mail is server-side plaintext (the provider performs “filtri basati su un elevato numero di controlli locali e servizi di reputazione … esaminandone il contenuto” and full daily backups via IBM Spectrum Protect); opt-in client-side PGP is offered in the Roundcube webmail (“chiavi PGP (Pretty Good Privacy)”, user procedure: “basta accedere alla webmail; aprire le impostazioni; creare la tua chiave; inviare email in modo crittografato”); no PGP-encrypted-by-default model and no server-side encryption-at-rest claim for message bodies OK+1
- Government-access posture: No transparency report on any Seeweb-owned domain; no warrant canary; no user-notification commitment (CGV Art. 14 merely refers to the Privacy Policy and does not contain Art. 28 GDPR notification clauses); no public DPA template — DPAs are signed bilaterally on request to
dpo@seeweb.it(DPO Tamara Arduini named); “transparency” in marketing copy refers to pricing predictability, not government requests BAD+3 - Anonymous signup: Full business data and contract acceptance required (“All’interno di quest’area riservata ci devono essere tutti i dati aziendali e il contratto (le condizioni generali) caricato”); payment limited to “PayPal, Paypal Preautorizzato Automatico, Bonifico Bancario, Sepa/Rid” — credit cards are not listed in either the Italian or English FAQ; no cryptocurrency, no cash; Tor not stated BAD+2
- Funding stability: Founded 1998 (“Siamo un Cloud Computing Provider italiano che offre soluzioni IT dal 1998”); Seeweb founded the DHH (Dominion Hosting Holding) holdco in 2015 and was rolled into it in 2020; DHH S.p.A. is publicly listed on Euronext Growth Milan (ticker DHH.MI, ISIN IT0005203622; IPO 2016-07-27 at EUR 10.00/share raising EUR 4.2M); founder-aligned listing structure (“ecosistema di aziende indipendenti … in cui i vari partner mantengono il proprio marchio”) OK+1
Sources (Legal Framework)
Italian Srl; Foro di Frosinone. Condizioni Generali: “il soggetto erogatore dei servizi di cui all’accordo, giuridicamente individuato nella SEEWEB srl proponente il presente accordo di fornitura di servizi.” Privacy Policy: “Il Titolare del Trattamento dei suoi dati personali è Seeweb Srl, P.IVA 02043220603 - Via Armando Vona, 66 - 03100 Frosinone – Italia.” Footer: “Seeweb © srl 1998-2026 – c.s. 103.000 EURO - CCIAA 17793/98 - REA 126233 - p.iva e c/f 02043220603.” Art. 11 Condizioni Generali: “Il rapporto di fornitura è regolato dalle leggi dello Stato Italiano. Per tutte le controversie relative al presente accordo le parti riconoscono la competenza esclusiva e sussidiaria del foro di Frosinone; in via principale sarà competente un arbitro, il quale seguirà le procedure stabilite dal regolamento depositato presso la CCIAA di Milano.” Sources: Condizioni Generali , Privacy Policy .
DHH publicly-listed parent. “Seeweb, dopo aver fondato - nel 2015 - DHH (Dominion Hosting Holding), nel 2020 è entrata a far parte del gruppo. … DHH è una società per azioni quotata in Borsa, sul mercato Euronext Growth Milan.” DHH S.p.A. trades on Euronext Growth Milan under ticker DHH.MI (ISIN IT0005203622); IPO priced at EUR 10.00/share on 2016-07-27 raising EUR 4.2M (Euronext IPO showcase). Sources: DHH group page .
EU-only data; Italian + EU data centres. “L’aderenza al CISPE e quindi anche al GDPR garantisce inoltre che i dati siano gestiti e conservati esclusivamente all’interno del territorio europeo.” Sysadmin Giovanni Metitieri (quoted in CWI/DigitalWorld Italia): “il backup giornaliero remoto, allocato in modalità off-site nei datacenter italiani di Seeweb … Nessun rischio di data profiling, quindi, né di dati al di fuori dei confini dell’Italia.” Data-centre footprint: “Le nostre sedi di Milano, Frosinone e Lugano sono dotate, ognuna, di risorse di rete IP indipendenti.” Privacy Policy: “Il Titolare informa che effettuerà il trattamento dei dati conferiti, prevalentemente in via diretta o attraverso incarico ad altro soggetto comunque in ambito Europeo.” Sources: Cloud Mail docs , Truemail guide , Data centers , Privacy Policy .
TLS in transit; encryption-at-rest details Not stated. “Posta in ingresso Imap: Server: mail.truemail.it Porta: 143 Protocollo: STARTTLS … POP3: … Porta: 110 Protocollo: STARTTLS … Posta in uscita SMTP: Server: mail.truemail.it Porta: 587 Protocollo: STARTTLS” (with alternatives 993/SSL, 995/STARTTLS, 465/SSL). No at-rest algorithm disclosed on seeweb.it, docs.seeweb.it, or blog.seeweb.it. Source:
Cloud Mail docs .
Server-side plaintext + opt-in Roundcube PGP. Truemail guide: “chiavi PGP (Pretty Good Privacy)”; user procedure: “basta accedere alla webmail; aprire le impostazioni; creare la tua chiave; inviare email in modo crittografato (il destinatario deve usare lo stesso sistema).” Content-level inspection is documented: “filtri basati su un elevato numero di controlli locali e servizi di reputazione. Questi controlli avvengono sia prima della ricezione del messaggio (valutando l’IP, il dominio del mittente e il comportamento del suo mail server) che esaminandone il contenuto per individuare eventuali segnali tipici di spam o virus.” Metitieri in datamanager.it: “un filtro antispam che è in grado di restituire il 99% di messaggi genuini”. Sources: Truemail guide , Cloud Mail docs .
IP logging aggregated; 24-month post-contract removal; 30-day mail backup retention; 15-day account-termination grace. Privacy Policy: “Dati derivanti da implicita trasmissione nell’uso dei protocolli di comunicazione di Internet … indirizzi IP o i nomi a dominio dei computer utilizzati dagli utenti … Questi dati vengono raccolti in forma esclusivamente aggregata … per ragioni tecniche di corretto funzionamento.” Retention: “Dichiariamo che, trascorsi 24 mesi dal termine delle obbligazioni contrattuali o dalle attività di presales e commerciali richieste, rimuoveremo i dati personali non diversamente necessari per normative cogenti.” Art. 10 Condizioni Generali: “La ‘sospensione’ o ‘cessazione’ del servizio non comporterà la distruzione immediata del materiale … decorso il termine di giorni 15 dalla data di sospensione e/o cessazione del servizio – si intende autorizzata la rimozione dai server di proprietà del FORNITORE e la relativa distruzione.” Cloud Mail backup: “in caso di cancellazione di una email, garantisce il mantenimento dello storico per un massimo di 30 giorni.” Sources: Privacy Policy , Condizioni Generali , Cloud Mail docs .
No transparency report; CISPE Code of Conduct adherence. Privacy Policy: “Il Titolare dichiara di aver aderito ad un codice di condotta vincolante e certificativo in tema di trattamento di dati personali come istituito agli artt. 40 e 42 GDPR.” English Cloud Mail page: “the Seeweb Cloud Mail service is built on CISPE certified Cloud platforms, the European Code of Conduct in line with the GDPR policies on data protection.” Seeweb stance: “SEEWEB srl … shall act as Data Controller for the data collection, processing and management phases that are necessary for providing the services requested.” DPO Tamara Arduini named publicly: “il Titolare … ai sensi dell’art. 37 GDPR ha nominato Tamara Arduini Responsabile della Protezione dei Dati - Data Protection Officer … mail: dpo@seeweb.it.” The CISPE Code of Conduct received a positive EDPB opinion on 2021-05-19 and CNIL approval on 2021-06-03. No transparency report, no warrant canary, no user-notification commitment is published on any Seeweb-owned domain. Sources: Privacy Policy , Cloud Mail EN .
Custom domain mandatory; per-customer AOP aggregates all instances. Order form requires domain: “Nome del dominio (obbligatorio) … Inserisci il nome del dominio da associare al tuo hosting.” Cloud Mail docs: “per ogni cliente viene generato un solo account con cui è possibile gestire tutti i prodotti Cloud Mail attivati con il relativo account AOP.” Blog: “Il cliente che acquista un account Cloud Mail potrà creare più servizi per tutti i domini che vuole e rivenderli a terzi.” Plesk scope is per-domain: “dal menù di sinistra cliccare su Siti web e domini –> dominio.tld –> account di posta”. Cross-domain workaround is mailbox forwarding (“inoltro”); aliases are same-domain by default. Custom-domain attachment is MX-only, not a full DNS takeover: “Non è necessario che quest’ultimo sia gestito da Seeweb. In caso il dominio del cliente sia registrato presso un altro provider, sarà possibile modificarne solo i record mail.” Sources: Cloud Mail product page , Cloud Mail docs , Email-hosting blog .
Catch-all: Not stated on any Seeweb-owned page. Searches across seeweb.it, docs.seeweb.it, and blog.seeweb.it for “catch-all”, “wildcard” and "*@dominio" return nothing. The Cloud Mail documentation enumerates “Alias, inoltri e risposte automatiche” but never uses the term catch-all.
IMAP / POP3 / SMTP supported. “Configurazione in IMAP la posta viene salvata sul server … Configurazione in POP3 la posta viene scaricata sul client”. Source: Cloud Mail docs .
Storage 5 GB → 1,280 GB. Product page: “5 GB + 5 Caselle” (entry) up to “1280 GB + 1280 Caselle” (max). Migration is paid-only: “Migrazione da mail server esterno | 63,50 €/10 Caselle”. WhiteLabel reseller add-on: “Cloud Mail WhiteLabel … Sì - 45,50 €/mese”. Billing: “Fatturazione mensile a partire dal piano da 80GB. Durata contrattuale 12 mesi.” Source: Cloud Mail product page .
Entry price 10 €/year + VAT. Seeweb’s product page renders prices via JavaScript (static HTML carries only the placeholder “Totale Annuale 0,00 €”). The numeric entry price is sourced from Seeweb sysadmin Giovanni Metitieri quoted in CWI/DigitalWorld Italia (Quine Srl, Tribunale di Milano n. 295 del 28-11-2018): “L’offerta Cloud Mail parte da soli 10 euro all’anno più IVA per un pacchetto da 5 GB di spazio disco e un massimo di 5 caselle email e arriva fino a 1.280 GB e altrettante caselle.” Cooling-off: “Il termine per l’esercizio di tale diritto è di giorni 10 dalla data di attivazione del servizio.” Source: CWI / Cloud Mail , Condizioni Generali Art. 13 .
Payment: PayPal / SEPA-RID / bank transfer only — no credit card listed. Italian FAQ: “si potrà pagare direttamente dal proprio centro contabile online con vari metodi: Paypal, Paypal Preautorizzato Automatico, Bonifico Bancario, Sepa/Rid.” English FAQ confirms: “Payments can be made directly from your online billing center using various methods: PayPal, Automatic Pre-Authorized PayPal, Bank Transfer, and SEPA/RID.” No card, no crypto, no cash. Sources: FAQ IT , FAQ EN .
No native mobile app; no documented 2FA on customer area. “Puoi configurarlo su Android e iOS, usando Outlook o Thunderbird.” The Cloud Mail product page references multi-factor authentication only abstractly: “Sofisticati sistemi criptati e autenticazioni a più fattori possono proteggere i tuoi messaggi e i dati in essi contenuti.” aop.seeweb.it (customer area) is blocked by robots.txt — the absence of 2FA documentation does not prove absence of the feature, only that it is undocumented on Seeweb-owned domains.
WEB.DE
Privacy Impact: HIGH9 — Free, ad-financed German webmail operated by 1&1 Mail & Media GmbH (Karlsruhe branch / Montabaur HQ, HRB 7666) — same legal entity as GMX, same indirect subsidiary of publicly-listed United Internet AG (Frankfurt Xetra ticker UTDI). Servers stated to be exclusively in Germany under the “E-Mail made in Germany” alliance, an entity-level annual Jahresbericht is published at the WEB.DE-branded URL (2025: 37,174 subscriber-data requests, 2,816 traffic-data requests, 608 content-data disclosures, 1,681 G10/§100a interception orders against 46.32M mailboxes), but the only PGP path is opt-in via the third-party Mailvelope browser extension (Chrome/Firefox only — subjects/metadata stay plaintext), no warrant canary, no notification commitment, a working mobile-phone number is mandatory at signup, and FreeMail’s “Consent or Pay” model couples ad financing with a “non-cancellable” mandatory weekly newsletter.
- Name: WEB.DE — operated by 1&1 Mail & Media GmbH, Zweigniederlassung Karlsruhe, Brauerstr. 48, 76135 Karlsruhe; Hauptsitz Montabaur (Amtsgericht Montabaur HRB 7666; VAT DE243413002); managing directors Alexander Charles, Dr. Michael Hagenau, Thomas Ludwig, Dr. Verena Patzelt
- URL:
web.de - HQ jurisdiction: Germany (14 Eyes / SSEUR, strong GDPR) OK+1
- Hosting jurisdiction: Germany — “Innerhalb unseres Sicherheitsverbunds sind alle Verbindungswege für Ihre E-Mails automatisch verschlüsselt und Ihre Mails werden in unseren Rechenzentren ausschließlich in Deutschland gespeichert”; “Der E-Mail-Austausch innerhalb des ‘E-Mail made in Germany’-Verbunds erfolgt ausnahmslos über Server in deutschen Hochleistungsrechenzentren” OK+1
- Zero-access encryption: Opt-in via third-party Mailvelope browser extension (Chrome/Firefox only): “Ende-zu-Ende-Verschlüsselung macht nur dann Sinn, wenn die Rechenoperationen zur Verschlüsselung auf Ihrem Rechner (und nicht auf einem Server von WEB.DE) ausgeführt werden. Dazu wird die Software Mailvelope als Erweiterung für die Browser Chrome und Firefox eingesetzt”; provider scope statement: “Durch die Kooperation mit Mailvelope wird zudem sichergestellt, dass alle sicherheitsrelevanten Daten wie Schlüssel oder zugehöriges Passwort außerhalb des Einflussbereichs von WEB.DE liegen”; WEB.DE webmail itself has no native PGP; subjects/metadata stay plaintext unless both correspondents run Mailvelope OK+1
- Government-access posture: Annual entity-level Jahresbericht published at the WEB.DE-branded URL (2025 figures: 37,174 subscriber-data / 2,816 traffic-data / 608 content-data disclosures / 1,681 G10/§100a interception orders against 46.32M mailboxes; “Die Sicherheitsbehörden haben keinen direkten Zugriff auf die Postfachinhalte”); no user-notification commitment (the Datenschutzhinweise say only “Überdies können Daten an andere Verantwortliche weitergegeben werden, wenn wir gesetzlich dazu verpflichtet sind oder eine behördliche oder gerichtliche Anordnung vorliegt”); no warrant canary BAD+2
- Anonymous signup: Mobile-phone number mandatory at signup (“Geben Sie Ihre aktuelle Mobilfunknummer an … Ohne gültige Mobilfunknummer ist eine Registrierung nicht möglich”); gender + name + full postal address collected (“Wählen Sie als Geschlecht weiblich, männlich oder neutral aus und geben Sie Ihre Anschrift ein. Diese Angaben dienen der Absicherung Ihres Accounts”); account-recovery uses IDnow Autoidentverfahren or eID with the German Personalausweis; payment via SEPA-Lastschrift / PayPal / Visa / Amex / Mastercard — no crypto, no cash; Tor not stated; FreeMail’s “Consent or Pay” model couples ad financing with a non-cancellable weekly newsletter (“Der Newsletter kann nicht abbestellt werden, da er den FreeMail Dienst mitfinanziert”) BAD+2
- Funding stability: Founded 1995 by Michael and Matthias Greve (per Media Ownership Monitor Germany); 2005 reorganisation into the United Internet group (WEB.DE GmbH carve-out; combots AG portal split; ultimate consolidation into 1&1 Mail & Media GmbH); indirect subsidiary of publicly-listed United Internet AG (Frankfurt Xetra ticker UTDI, ISIN DE0005089031, WKN 508903); ad-funded FreeMail business model is the structural privacy concern beyond corporate stability BAD+2
Sources (Legal Framework)
German legal entity; Montabaur jurisdiction. Impressum: “1&1 Mail & Media GmbH, Zweigniederlassung Karlsruhe, Brauerstr. 48, 76135 Karlsruhe, Deutschland … Hauptsitz Montabaur, Amtsgericht Montabaur, HRB 7666, UST-Id. DE243413002.” Managing directors: “Alexander Charles, Dr. Michael Hagenau, Thomas Ludwig, Dr. Verena Patzelt”. AGB §17: “17.1 Ausschließlicher Gerichtsstand für alle Streitigkeiten aus diesem Vertrag ist, wenn auch der Nutzer Kaufmann ist, Montabaur. 17.2 Für die von WEB.DE auf der Grundlage dieser Allgemeinen Geschäftsbedingungen abgeschlossenen Verträge und für aus ihnen folgende Ansprüche gleich welcher [Art gilt deutsches Recht].” Parent entity: 1&1 Mail & Media Applications SE, Elgendorfer Straße 57, 56410 Montabaur, HRB 24401. Sources: Impressum , AGB , Mail & Media imprint .
Publicly-listed parent United Internet AG. Bundestag-Lobbyregister entry for 1&1 Mail & Media Applications SE: “Die 1&1 Mail & Media GmbH gehört zur United Internet AG, Europas führendem Internetspezialist.” United Internet AG trades on Frankfurt Stock Exchange’s Xetra under ticker UTDI (ISIN DE0005089031, WKN 508903). Source: Lobbyregister R001925 .
Servers in Germany; “E-Mail made in Germany” alliance. Email landing page: “Innerhalb unseres Sicherheitsverbunds sind alle Verbindungswege für Ihre E-Mails automatisch verschlüsselt und Ihre Mails werden in unseren Rechenzentren ausschließlich in Deutschland gespeichert.” E-Mail made in Germany page: “Der E-Mail-Austausch innerhalb des ‘E-Mail made in Germany’-Verbunds erfolgt ausnahmslos über Server in deutschen Hochleistungsrechenzentren. Dadurch unterliegt die Speicherung und Verarbeitung Ihrer Daten dem deutschen bzw. europäischen Datenschutzgesetz.” Encryption-at-rest details: not stated. Sources: Email , E-Mail made in Germany .
Mailvelope third-party PGP only. Help: “Ende-zu-Ende-Verschlüsselung macht nur dann Sinn, wenn die Rechenoperationen zur Verschlüsselung auf Ihrem Rechner (und nicht auf einem Server von WEB.DE) ausgeführt werden. Dazu wird die Software Mailvelope als Erweiterung für die Browser Chrome und Firefox eingesetzt.” And: “Durch die Kooperation mit Mailvelope wird zudem sichergestellt, dass alle sicherheitsrelevanten Daten wie Schlüssel oder zugehöriges Passwort außerhalb des Einflussbereichs von WEB.DE liegen.” Sources: PGP help , PGP security .
Annual Jahresbericht at WEB.DE-branded URL; no canary. Privacy Policy: “Überdies können Daten an andere Verantwortliche weitergegeben werden, wenn wir gesetzlich dazu verpflichtet sind oder eine behördliche oder gerichtliche Anordnung vorliegt.” The 2025 Jahresbericht ( https://web.de/impressum/erteilte-auskuenfte-sicherheitsbehoerden-jahresbericht-2025-41806120 ) covers the entire 1&1 Mail & Media entity: “Als in Deutschland ansässiges Unternehmen ist die 1&1 Mail & Media GmbH verpflichtet, unter Einhaltung strenger gesetzlicher Voraussetzungen ausschließlich deutschen Sicherheitsbehörden Auskünfte zu erteilen.” 2025 figures: “Anfragen … zu Teilnehmerbestandsdaten … 1&1 Mail & Media GmbH – deutsche Portale: 37.174”; “Anfragen … zu Verkehrsdaten … 2.816”; “Übermittlung von Inhaltsdaten an die Sicherheitsbehörden … 608”; “Anordnungen nach Artikel-10-Gesetz und §100a StPO … 1.681”; mailbox base “46,32 Millionen”. Separate DSA Art. 15 transparency at https://s.uicdn.com/pih/legal/2025TransparencyReport.xlsx . No user-notification commitment in any document; no warrant canary. Sources: Privacy Policy , Jahresbericht 2025 , Impressum .
IP and traffic-data logging; 7-day Verkehrsdaten retention; 21-day deactivation; 6-month / 1-year inactivity rules. Privacy Policy: “In den Log-Dateien werden beispielsweise folgende Informationen gespeichert: IP-Adresse, Name der abgerufenen Dateien bzw. Informationen, Datum und Uhrzeit des Abrufs, Informationen zum verwendeten Endgerät.” And: “Verkehrsdaten werden entsprechend der rechtlichen Anforderungen grundsätzlich innerhalb von sieben Tagen gelöscht.” Account deletion: “Falls du deinen Account löschen möchtest, deaktivieren wir zunächst deinen Account, überprüfen deinen Löschanspruch und löschen diesen in der Regel nach 21 Tagen.” Inactivity: “E-Mail-Inhalte von FreeMail-Postfächern, welche mehr als 180 Tage keine Logins verzeichnen (über Web, App oder IMAP/POP), können von uns ohne vorherigen Hinweis gelöscht werden.” AGB §5.3: “WEB.DE ist berechtigt, die im Account des Nutzers gespeicherten Nachrichten und sonstige Dateien nach einem Zeitraum von sechs Monaten der Inaktivität … ohne Rückfrage zu löschen. Nach einem Zeitraum von einem Jahr der Inaktivität ist WEB.DE darüber hinaus berechtigt, die vom Nutzer bei WEB.DE registrierten E-Mail-Adressen freizugeben und anderen Nutzern zur Verfügung zu stellen.” Sources: Privacy Policy , AGB .
Mobile number mandatory + IDnow / eID for recovery. Registrierung help: “Geben Sie Ihre aktuelle Mobilfunknummer an. Sie können dafür die Ländervorwahl von Deutschland oder der Schweiz auswählen. Ohne gültige Mobilfunknummer ist eine Registrierung nicht möglich.” And: “Wählen Sie als Geschlecht weiblich, männlich oder neutral aus und geben Sie Ihre Anschrift ein. Diese Angaben dienen der Absicherung Ihres Accounts.” Account-recovery via IDnow Autoidentverfahren or eID with the German Personalausweis (Privacy Policy sections “Autoidentverfahren” and “eID”). Source: Registrierung .
FreeMail ad-funded; non-cancellable newsletter; “Consent or Pay”. AGB §2.4.2: “Der Newsletter kann nicht abbestellt werden, da er den FreeMail Dienst mitfinanziert.” Privacy Policy: “Um dir unsere FreeMail-Dienste ohne Entgelt zur Verfügung stellen zu können, sind Werbeeinblendungen Bestandteil unseres digitalen Angebots (Vertragserfüllung)”; “FreeMail Kunden können das WEB.DE Magazin nicht abbestellen, da dieses als fester Leistungsbestandteil des WEB.DE E-Mail-Dienstes ausgestaltet ist”; “Wir betreiben unser Angebot mit einem sogenannten ‘Consent or Pay’ Modell.” Sources: AGB , Privacy Policy .
WEB.DE MailPlus paid tiers (DE residents). Tarifvergleich: “3,99 € monatlich” (MailPlus), “6,49 € monatlich” (Club), “7,99 € monatlich” (Club 100); “Die Vertragslaufzeit inkl. Testphase beträgt 13 Monate. Danach setzt sich Ihr Vertrag ohne Laufzeitbegrenzung fort. Eine Kündigung ist 4 Wochen zum Ende der jeweiligen Vertragslaufzeit und im Zeitraum danach möglich.” AGB §11.3: “Die Begleichung des WEB.DE PremiumMail-Beitrags … erfolgt je nach Wahl des WEB.DE PremiumMail-Nutzers per Rechnung, Lastschrifteinzug oder Kreditkartenabbuchung.” Premium signup lists SEPA-Lastschrift / PayPal / Visa / Amex / Mastercard — no crypto, no cash. Sources: Premium , AGB .
Custom domains as separate SKU. “Schon ab 0,97 € mtl. Kurz und knackig, einprägsam und persönlich, authentisch und seriös: Durch klassische oder neue Top-Level-Domains wie .de, .info, .cool, .shopping oder .club werden Ihre E-Mail-Adressen noch aussagekräftiger.” And: “Preise: Mit WEB.DE FreeMail ab 1,99 € mtl. je nach gewählter Domain-Endung. Mit WEB.DE Premium erhalten Sie exklusive Preisvorteile ab 0,97 € mtl. je nach gewählter Domain-Endung.” Per-domain alias caps conflict between sources: 50 (help page) vs. 500 (marketing page). Sources: Persönliche Domains , Homepage & Mail , Adressen help .
Catch-all: Not stated. Neither “Catch-all” nor “wildcard alias” / "*@domain" is documented anywhere on web.de help or product pages.
Aliases on @email.de are MailPlus / Club only; count not stated. Help: “Als WEB.DE FreeMail Nutzer erhalten Sie eine Standardadresse. Als WEB.DE MailPlus-Mitglied erhalten Sie weitere E-Mail-Adressen mit der exklusiven Endung @email.de und zusätzliche E-Mail-Adressen mit originellen Endungen.” And: “Diese Funktion steht Ihnen nur im WEB.DE Club oder WEB.DE MailPlus zu Verfügung.” WEB.DE never publishes a number — the 10-address cap is documented only on the GMX side of the same 1&1 Mail & Media platform. Deleted aliases blocked: “eine gelöschte Absenderadresse [bleibt] für mindestens fünf Jahre gesperrt.” Sources: Absenderadressen , Verwalten .
IMAP / POP3 / SMTP supported, opt-in. “Um POP3 oder IMAP nutzen zu können, müssen Sie diese Funktion in den WEB.DE Einstellungen einschalten.” Server data: pop3.web.de:995, imap.web.de:993, smtp.web.de:587 STARTTLS / 465 SSL. Sources: POP/IMAP toggle , IMAP server data .
2FA: TOTP only; WebAuthn / FIDO2 not stated. Help: “Zur Einrichtung der Zwei-Faktor-Authentifizierung wird eine sogenannte Authentifzierungs-App benötigt. Diese generiert für jeden Anmeldevorgang einen individuellen, temporär gültigen Zugangscode.” SMS is not offered as a login factor — the mobile number serves password recovery: “wird eine verifizierte Mobilfunknummer zur Passwort-Wiederherstellung benötigt”. Once 2FA is on, IMAP/SMTP need an “anwendungsspezifisches Passwort”. WebAuthn/FIDO2/hardware-key support is not documented. Sources: 2FA help , POP/IMAP toggle .
Native mobile apps (Android + iOS). “WEB.DE Mail & Cloud (Android) … WEB.DE Mail, Cloud & News (iOS) … WEB.DE Cloud (Android)”. Source: Privacy Policy app listing .
GDPR controller; no standalone DPA. “Verantwortlich für die Verarbeitung deiner persönlichen Daten ist die 1&1 Mail & Media GmbH (Zweigniederlassung Karlsruhe, Brauerstr. 48, 76135 Karlsruhe; Hauptsitz Montabaur, Elgendorfer Str. 57, 56410 Montabaur).” DPO: “Datenschutzbeauftragter der 1&1 Mail & Media GmbH, Elgendorfer Str. 57, 56410 Montabaur, datenschutz@webde.de.” No standalone Art. 28 GDPR DPA published for consumer FreeMail/PremiumMail. Source: Privacy Policy .
1995 founding; 2005 reorganisation into 1&1 / United Internet. Impressum: “WEB.DE wurde 1995 gegründet, im Februar 1998 startete das redaktionelle Angebot.” Handelsregister context (HRB 7666 Montabaur via online-handelsregister.de): the WEB.DE AG carve-out into Combots AG and the 1&1 Internet AG / WEB.DE GmbH consolidation are documented in the entity’s historical filings. Founders Michael and Matthias Greve per Media Ownership Monitor Germany (germany.mom-gmr.org/en/media/online/outlet/web-de-113669). Sources: Impressum , Handelsregister WEB.DE .
Disroot
Privacy Impact: HIGH10 — Non-profit Dutch foundation with minimal signup data, but email content is stored unencrypted on the server, no built-in zero-access encryption, and no transparency report or warrant canary.
- Name: Disroot — operated by Stichting Disroot.org, a Dutch non-profit foundation (KVK 69988099)
- URL:
disroot.org - HQ jurisdiction: Netherlands (9 Eyes / 14 Eyes, strong GDPR) OK+1
- Hosting jurisdiction: Netherlands (“our own servers, located in a data center in the Netherlands”) OK+1
- Zero-access encryption: None — disk encryption against physical seizure only; “all emails, unless encrypted by the user (with GnuPG/PGP, for example) are stored unencrypted on our servers”; no provider-managed PGP integration BAD+3
- Government-access posture: No public periodic transparency report; no user-notification commitment; no warrant canary BAD+3
- Anonymous signup: No real-name / phone / address required at signup; signup email used for confirmation and then deleted unless user opts to keep it for password recovery; Tor not stated; donation routes are SEPA / PayPal / Patreon / Liberapay (no crypto, no cash) BAD+2
- Funding stability: Non-profit foundation since 2015; volunteer-run, donation-supported; “all revenues from the Disroot platform are invested back into the project” GOOD0
Sources (Legal Framework)
Operated by Stichting Disroot.org (Dutch foundation, KVK 69988099), Amsterdam, Netherlands. Privacy policy: “For the purposes of the GDPR, Disroot.org is the ‘data controller’. This means that Disroot determines the purposes for which and the manner which your data is processed.” Source: Privacy Policy .
Dutch hosting, Dutch law. “We store all data in our own servers, located in a data center in the Netherlands.” And: “Disroot.org is hosted in the Netherlands and therefore is subject to Dutch laws and jurisdiction.” Source: ToS and Privacy Policy .
No zero-access on email content. “We use disk encryption on all servers to prevent data leak in case the servers are stolen, confiscated or in any way physically tampered with.” But on emails specifically: “All emails, unless encrypted by the user (with GnuPG/PGP, for example) are stored unencrypted on our servers.” Source: Privacy Policy . Disk encryption protects against physical seizure but not against the provider or against compelled disclosure of data at rest while servers are running.
Tight log retention. “We store logs of your activity for a period no longer than 24 hours (unless specified otherwise per service).” Email-specific: “IP addresses of currently logged in users via IMAP/POP3 protocols are stored as long as the device is logged in the server (per each device logged in).” Server logs “are stored for a period of 24 hours after which they are deleted from the server. No backup of log files is created.”
Minimal signup data. “A valid email address: required for account creation. This email address is deleted from our database after the account has been approved/denied, unless the user chooses during the registration process, to keep it for password reset process.” And: “We do not require any additional information that is not crucial for the operation of the service (we do not ask for phone numbers, private personal data, home address).” Tor: not stated.
Account deletion. FAQ: “To delete your Disroot account log in to https://user.disroot.org and select ‘Delete My Account’. … Accounts and their data are wiped on daily.” Source: FAQ .
No transparency report, no canary, no notification commitment. Provider docs do not publish a periodic government-request transparency report. The only “transparency report” reference in the privacy policy is per-user, addressed to the account holder “under suspicion of breaking our Terms Of Services” — not a government-request disclosure mechanism.
Donation-funded, no anonymous payment. “Bank transfer (SEPA countries only): Stichting Disroot.org IBAN: NL19 TRIO 0338 7622 05” and via third-party processors “such as PayPal, Patreon or Liberapay”. No crypto, no cash by post documented. Source: Donate . Storage upgrades are priced “annually only”, in EUR (e.g., 11€/5GB, 20€/10GB).
Non-profit foundation, volunteer-run since 2015. “Disroot.org is a non-profit foundation and all revenues from the Disroot platform are invested back into the project, the maintenance of services and into free software development.” And: “The project is based in Amsterdam, was founded by Muppeth and Antilopa in 2015, it is maintained by volunteers and relies on the support of its community.” Sources: Mission statement and About .
Documentation gaps for custom domains. Disroot offers custom-domain linking as a donation perk (“It allows you to use your own domain to be able to send and receive emails. It is a lifetime reward.” — email service page ) but does not document the per-account domain cap, whether aliases can span domains, catch-all support, or whether full-domain MX takeover is required. Plus-addressing is supported on the disroot.org domain.
Gandi Mail
Privacy Impact: HIGH11 — EU jurisdiction helps; no zero-access encryption and recent acquisition hurt.
- Name: GandiMail — operated by GANDI SAS, Paris, France; owned by Total Webhosting Solutions B.V. (Netherlands), ultimate parent Stichting Carbonara
- URL:
gandi.net - HQ jurisdiction: France (14 Eyes / 9 Eyes, strong GDPR) OK+1
- Hosting jurisdiction: France (Equinix PA3, Saint-Denis) + Luxembourg (LuxConnect DC2) OK+1
- Zero-access encryption: None — Trust Center explicitly places this on the customer BAD+3
- Government-access posture: DSA transparency report published; no notification commitment; no warrant canary BAD+2
- Anonymous signup: Not stated — Tor, crypto, cash not documented BAD+2
- Funding stability: Acquired by Total Webhosting Solutions B.V. (Your.Online group) BAD+2
Sources (Legal Framework)
Operated by GANDI SAS, registered in Paris, France (RCS Paris 423 093 459). Privacy Policy names “Gandi SAS” as data controller. Owned by Total Webhosting Solutions B.V. with ultimate parent Stichting Carbonara — per Terms of Use .
EU hosting. Trust Center: data centres in “France: Saint-Denis Equinix PA3” and “Luxembourg: Bissen LuxConnect DC2”. Source: gandi.net trust center .
No provider-side message encryption. Trust Center: “Note: Encryption of customer information such as emails or data stored on our hosting services remains the responsibility of the customer.” Source: same.
DSA transparency report. Gandi: “As per article 15 of the EU Digital Services Act … Gandi is required to publish a transparency report”. Source: gandi.net DSA report . User notification: not stated. Warrant canary: not stated.
Personal data collection includes IP + location with general “no longer than necessary” retention. No concrete IP-log retention period stated. Source: Privacy Policy .
Ownership / funding. ToU: “Gandi SAS is owned by Total Webhosting Solutions B.V., a Dutch corporation … Total Webhosting Solutions B.V.’s ultimate parent company is Stichting Carbonara”. Source: Terms of Use .
Iroco
Privacy Impact: HIGH11 — Tiny French SAS (2 000 € capital, 2-10 employees, OVH-Roubaix hosting), explicitly ad-free and open-source-oriented under French jurisdiction — but no built-in encryption beyond the user password being “stored in encrypted form”, no transparency report, no warrant canary, no notification commitment, custom domains only on the organisation tier, no catch-all documented, no native mobile app, no migration tools, and uniquely in this comparison Tor signup is explicitly blocked following a January 2025 spam-abuse incident.
- Name: Iroco — operated by IROCO SAS, Vanves (Hauts-de-Seine), France (RCS Paris 889 424 255; SIRET 88942425500012); co-directors Adeline AGUT (President) and Bruno THOMAS
- URL:
iroco.co - HQ jurisdiction: France (14 Eyes / 9 Eyes, strong GDPR) OK+1
- Hosting jurisdiction: France — “Nos services sont hébergés dans un data center situé à Roubaix et opéré par OVH” (OVH SAS, Roubaix); contractual no-transfer clause: “IROCO s’interdit de transférer ses données en dehors de France sans l’accord préalable de l’acheteur” OK+1
- Zero-access encryption: None — Iroco runs a Postfix + Cyrus stack with no PGP / S/MIME / zero-access vault; the only “encrypted” claim is for the user password: “Nous stockons également votre mot de passe sous forme cryptée: nous n’y avons donc pas accès en clair”; no provider-side encryption-at-rest claim for message bodies; users may opt into PGP via third-party clients BAD+3
- Government-access posture: No transparency report; no warrant canary; no user-notification commitment — only the boilerplate “si la loi l’exige, IROCO peut effectuer la transmission de données pour donner suite aux réclamations présentées contre la Plateforme et se conformer aux procédures administratives et judiciaires” BAD+3
- Anonymous signup: Tor explicitly blocked at signup (“nous n’autorisons pas l’inscription avec une adresse TOR” — “Pour éviter ces désagréments, nous avons désactivé l’inscription avec TOR”); payment is SEPA via GoCardless only — no cards, no PayPal, no crypto, no cash; signup requires first/last name + billing address; CGV §15.1.1: “Lors de la création du compte de l’utilisateur, ses nom, prénom, adresse électronique” BAD+2
- Funding stability: SAS incorporated 29 September 2020 in Vanves; service launched 2021; share capital only 2 000 €; bootstrapped + one BPIFrance Innov’Up Faisabilité grant; LinkedIn lists 2-10 employees; January 2025 Russian-spam abuse incident led to the removal of the free trial and tightened payment controls OK+1
Sources (Legal Framework)
French SAS. Legal notice: “Raison sociale: IROCO SAS”; “Adresse du siège social: 3 rue Aristide Briand, 92170 VANVES”; “SIRET: 88942425500012”; “Nom du directeur et/ou co-directeur: Adeline AGUT, Bruno THOMAS”; “Montant du capital social: 2 000 euros”. CGV Article 2.5: “IROCO, Société par Actions Simplifiée, immatriculée au Registre du Commerce et des Sociétés de Paris sous le numéro 889 424255, représentée par sa Présidente, Adeline AGUT … son numéro de TVA intracommunautaire: FR 75889424255.” Sources:
Mentions légales ,
CGV . Externally corroborated incorporation date (29 September 2020) on societe.com.
OVH Roubaix hosting. FAQ: “Nos services sont hébergés dans un data center situé à Roubaix et opéré par OVH, une société française. Le data center est sécurisé, certifié ISO27001 et engagé dans une démarche d’éco-responsabilité. Les données présentes sur nos serveurs sont soumises à la règlementation française, notamment concernant la protection de la vie privée.” Documentation: “deux serveurs de production chez OVH à Roubaix. Un serveur pour le mail et un serveur pour le web. un serveur de préproduction (VPS) chez OVH également.” Legal notice (hébergeur): “OVH SAS, 2 rue Kellermann, 59100 Roubaix.” CGV §15.4: “IROCO s’interdit de transférer ses données en dehors de France sans l’accord préalable de l’acheteur.” Sources: FAQ hosting , Doc , Legal . (A third-party listing on european-alternatives.eu incorrectly states Grenoble — Iroco’s own docs are explicit about Roubaix.)
French law, Vanves jurisdiction. CGV Article 12: “Tous les litiges auxquels les opérations d’achat et de vente conclues en application des présentes conditions générales de vente pourraient donner lieu … seront soumis aux tribunaux compétents dans les conditions de droit commun. Pour la définition de la juridiction compétente, le vendeur élit domicile à son siège social.” Article 13: “Les présentes conditions générales de vente sont rédigées en langue française. Dans le cas où elles seraient traduites en une ou plusieurs langues étrangères, seul le texte français ferait foi en cas de litige.” Source: CGV .
No zero-access; only the user password is “encrypted”. FAQ data section: “Nous stockons également votre mot de passe sous forme cryptée: nous n’y avons donc pas accès en clair.” About page: “Bien évidemment, nous n’accédons pas non plus au contenu de vos mails: vous avez la certitude que vos données stockées sur nos serveurs resteront confidentielles.” — a policy/access statement, not a cryptographic guarantee. Documentation: “Serveur SMTP: Postfix; Serveur IMAP, calendriers/contacts: Cyrus” — no PGP/S-MIME integration anywhere in iroco.co, the FAQ, the blog, or the Doc page. CGV §15.5 admits the limitation: “il est à signaler qu’internet n’est pas un environnement complètement sécurisé et IROCO ne peut pas garantir la sécurité de la transmission ou du stockage des informations sur internet.” Sources:
FAQ data ,
About ,
Doc ,
CGV .
IP-logging via AbuseIPDB at signup. CGV §15.3: “vérifications par IROCO, par ses propres moyens ou en ayant recours à des prestataires externes, que l’adresse IP de l’utilisateur n’est pas référencée auprès de AbuseIPDB (Marathon Studios, Inc) comme étant une adresse à l’origine d’utilisations abusives de services en ligne”. Doc: “Le serveur de mail est protégé par le détecteur d’intrusion fail2ban. Fail2ban est relié au site AbuseIPDB qui sert à indiquer les adresses IP malveillantes sur internet. Nos serveurs téléchargent ensuite la liste pour mettre à jour nos pare-feux.” IP-log retention period not stated. (AbuseIPDB is operated by Marathon Studios Inc., East Stroudsburg, Pennsylvania, USA — a third-party processor.)
Account-deletion mechanism; retention not stated. CGV §9bis: “L’acheteur peut mettre un terme au contrat à tout moment, par lettre recommandée avec accusé de réception adressée au siège social d’IROCO, ou bien par l’interface utilisateur de l’application iroco, ou bien par courriel envoyé à l’adresse suivante: unsubscribe@iroco.fr, le contrat prenant alors fin au dernier jour du mois en cours suivant la date de réception de la demande de résiliation.” Restitution: “téléchargement d’archive. modalités financières: aucune.” No specific retention window for backups or residual data is published.
No transparency report, no canary, no notification commitment. Searches of iroco.co and blog.iroco.co return nothing. The only government-access reference is the standard CGV §15.3 “si la loi l’exige, IROCO peut effectuer la transmission de données pour donner suite aux réclamations présentées contre la Plateforme et se conformer aux procédures administratives et judiciaires” clause.
Tor explicitly blocked at signup. FAQ: “Pourquoi j’ai cette erreur: ’nous n’autorisons pas l’inscription avec une adresse TOR’ à l’inscription? … Pour éviter ces désagréments, nous avons désactivé l’inscription avec TOR.” Source: FAQ Tor . This is the only provider in this comparison that documents blocking (rather than not supporting) Tor signup.
SEPA-only payment via GoCardless. Signup app: “Lorsque vous aurez complété l’intégralité du formulaire, vous serez redirigé vers le site de GoCardless, notre prestataire de paiement, afin de procéder à la mise en place de la souscription d’abonnement par mandat SEPA.” CGV §2.4: “prestataire de paiement (GoCardless)”. Iroco does not accept cards, PayPal, crypto or cash. (GoCardless Ltd, UK Companies House no. 07495895, incorporated 17 January 2011, is a UK-based payment processor — a 14 Eyes / 5 Eyes data-flow consideration for what is otherwise a French-jurisdiction setup.)
Real identifying details at signup. CGV §15.1.1: “Lors de la création du compte de l’utilisateur, ses nom, prénom, adresse électronique”. §15.1.4: “Dans le cadre du paiement … celle-ci enregistre des données financières relatives au compte bancaire ou à la carte de crédit de l’utilisateur, ainsi qu’une adresse et un numéro de téléphone.” FAQ: “Via notre prestataire de paiement (la société GoCardless), nous collectons vos nom, prénom et adresse de facturation.”
Custom domains: organisation tier only; Individual is @iroco.co / @iroco.io. Collective signup page: “Vous amenez votre nom de domaine. À partir de 3,60 € TTC par mois — Vos boîtes mail sur votre nom de domaine — Autant de boîtes mail que nécessaires — Autant d’alias que nécessaires”. FAQ (outdated answer for individuals, still on the page): “Cela sera très bientôt possible! Nous ne proposons pour le moment que les noms de domaine iroco.io et iroco.co” — the Collective tier now delivers custom domains, but the Individual tier still does not. Iroco is not a domain registrar: “Iroco n’est pas un ‘registraire’ de nom de domaine: nous n’hébergeons pas les noms de domaines. Il vous faut prendre un nom de domaine auprès d’un registraire.” Per-domain cap on Collective is unstated; CGV speaks only of “usage raisonné”. Sources:
Collective signup ,
FAQ domain .
Catch-all not documented. Searches of iroco.co, the FAQ, the blog and the Doc page for “catch-all”, “fourre-tout”, “wildcard” and *@ all return nothing. The only alias mechanism described in detail is the +suffix plus-addressing scheme: “Chez Iroco, nous vous permettons de créer facilement jusqu’à 50 alias de messagerie directement depuis notre webapp … Normalement, il devrait prendre la forme suivante:
votrenom+votrealias@iroco.co ou
votrenom+votrealias@iroco.io”. Source:
Blog alias .
Aliases: 50 on Individual, “as needed” on Collective. Individual signup: “50 alias e-mail”. FAQ: “50 alias, c’est-à-dire des adresses mails secondaires composées sur la base de votre adresse principale. Les messages envoyés à ces alias arriveront dans votre boîte de réception principale.”
IMAP + SMTP supported; POP3 not documented. FAQ configuration: “Il faut préciser les deux adresses du serveur d’envoi de mail (SMTP), de réception de mail (IMAP) … imap.iroco.io si votre mail est sur iroco.io, imap.iroco.co si votre mail est sur iroco.co. La sécurité de connexion est SSL/TLS. smtp.iroco.io si votre mail est sur iroco.io, smtp.iroco.co si votre mail est sur iroco.co. La sécurité de connexion est SSL/TLS”. CGV §2.4: “protocoles mail IMAP (courrier entrant) et SMTP (courrier sortant)”. CalDAV + CardDAV also supported.
2FA: TOTP only. Login interstitial: “Code de vérification (OTP) — Si vous avez activé le code de vérification, merci de saisir ci-dessus ce code à 6 chiffres généré par votre outil d’authentification”. WebAuthn/FIDO2 and SMS 2FA not documented.
No native mobile app. Homepage: “Compatible avec votre client de messagerie préféré, sur ordinateur et sur mobile.” — third-party clients only; no iOS or Android Iroco-branded app exists in either store.
No migration tools. No mention of a Gmail import wizard, IMAP migration assistant, or “import from another provider” on iroco.co or blog.iroco.co. Users self-migrate via IMAP using any standard client.
No free tier. FAQ: “Pourquoi avez-vous supprimé la période d’essai gratuite d’un mois? Nous avions ajouté cette fonctionnalité pour permettre de tester nos services. Malheureusement, la grande majorité des utilisateurs de cette période d’essai ont créé des boites mail pour envoyer des messages non sollicités ou d’hameçonnage.” Individual subscription: 3,60 € TTC / month (3,00 € HT). All published prices are monthly; CGV §9bis describes the contract as “contrat dont la durée est indéterminée” with month-to-month cancellation. Sources: FAQ free trial , Individual signup .
DPA is embedded in the CGV, not a standalone document. CGV Article 15 contains the GDPR clauses (controller, sub-processors, DSAR mechanism). No B2B-style standalone DPA template is published. Sub-processors named: OVH (hosting), GoCardless (payments), AbuseIPDB (IP reputation), Matomo (self-hosted analytics, per Doc).
Founded 2020; bootstrapped + one BPIFrance grant. About: “Dans le cadre du dispositif Innov’Up Faisabilité, nous avons bénéficié d’une aide financière de BPIFrance pour le développement de notre projet.” SAS incorporation date (29 September 2020) and 2 000 € share capital per the Mentions légales and external registries (societe.com). 2021 INSEE filing qualified IROCO SAS for full statutory confidentiality under Article L.232-25 of the French Commercial Code (balance-sheet < 350 000 €; revenue < 700 000 €; < 10 employees). LinkedIn lists 2-10 employees.
January 2025 abuse incident. Blog (2 January 2025): “Il y a à peu près un mois, nous avons subi une attaque d’un groupe de spam, probablement localisé en Russie … Ils ont utilisé notre plateforme pour envoyer des messages d’hameçonnage (phishing).” This led to (a) removing the free trial, (b) introducing an initial payment check, and (c) the Tor signup block. No customer-data exfiltration was reported. Follow-up policy update (March 2025): “Suite à des tentatives de fraude nous avions mis en place un paiement initial avec la technologie instant bank pay … nous allons supprimer cette étape et n’utiliser que des prélèvements SEPA standards, en activant les comptes uniquement lorsque le premier paiement est passé.” Sources: Blog incident , Blog signup .
Combell
Privacy Impact: HIGH12 — Belgian / Dutch mass hoster owned by team.blue (PE-backed: Hg + CPP Investments + Sofina at a €4.8bn 2024 valuation), ISO 27001 certified since 2011 — but no zero-access encryption, no transparency report, no warrant canary, no anonymous signup, and an explicit “Combell will fully cooperate with law enforcement authorities” AUP clause.
- Name: Combell Email — operated by Combell nv, Ghent, Belgium (CBE 0541.977.701); part of team.blue (parallel NL entity contracts under Dutch law)
- URL:
combell.com/en/email-hosting - HQ jurisdiction: Belgium (14 Eyes, strong GDPR) OK+1
- Hosting jurisdiction: Belgium + Netherlands — “Our own fibre-optic network connects all our data centres in Belgium and the Netherlands into one logical network” (both 14 Eyes / 9 Eyes) OK+1
- Zero-access encryption: None — Privacy Policy invokes “telecommunications secrecy” (a legal-not-technical protection) and lists “hard disk encryption software” generically; no PGP, no S/MIME, no built-in E2EE in any KB or product page BAD+3
- Government-access posture: No transparency report (only a forward-looking DSA clause in the AUP, “Combell may publish reports”, with no actual report located); no user-notification commitment; explicit confidential cooperation (“Combell can be obligated to communicate certain data to the requisite authorities in a confidential manner”); no warrant canary BAD+3
- Anonymous signup: Real identifying details required (“name, address, telephone number, e-mail address and customer number”); ID-card copy required to exercise GDPR rights; Tor not stated; payment methods not enumerated in primary docs; cryptocurrency and cash not mentioned anywhere BAD+2
- Funding stability: Founded 1999 by Jonas Dhaenens (then 16); merged into team.blue in 2019 alongside TransIP Group and Register Group; team.blue lead investor Hg (since 2019), CPP Investments committed ~€550M for ~20% in July 2024, Sofina minority stake at a €4.8bn valuation; multi-rotation PE ownership BAD+2
Sources (Legal Framework)
Operated by Combell nv, Skaldenstraat 121, 9042 Ghent, Belgium (CBE 0541.977.701). Source: Privacy Policy §1 .
Owned by team.blue group. About: “Combell is part of team.blue, a European group of hosting companies headquartered in our Ghent office.” Source: About Combell . team.blue press release: “Combell Group and TransIP Group today announce the creation of team.blue, one of the latest European tech companies to exceed a $1 billion valuation.” Source: team.blue press . Investor history per team.blue’s own corporate page: Hg (lead investor since 2019), CPP Investments (~€550M for ~20% in July 2024), Sofina (minority in 2024) at a €4.8bn valuation; founder Jonas Dhaenens retains an interest.
Belgian / Dutch hosting. Network page: “Our own fibre-optic network connects all our data centres in Belgium and the Netherlands into one logical network.” And: “since Combell only uses the best data centres in Belgium and the Netherlands, your e-mails are safe from spying eyes.” And: “71% of Belgium’s internet is located in one of our data centres.” Sources: Network , Exchange hosting , Datacenters .
Belgian law (BE entity) or Dutch law (NL entity). Combell nv General Conditions: “This Agreement concluded with Combell is subject to Belgian law.” Source: General Conditions . NL counterpart Article 14: “This Agreement concluded with Combell is subject to Dutch law. Insofar as the rules of mandatory law do not describe otherwise, all disputes as a result of the Agreement will be settled by the authorised Dutch Court in the district where Combell is established.” Source: combell.nl General Conditions . Customers contracting via combell.com are subject to Belgian law; combell.nl customers to Dutch law.
No zero-access encryption; legal-not-technical secrecy. Privacy Policy: “The existence and content of the personal communication that takes place via the Combell network (for example: email traffic, hosting…) is protected by the provisions for telecommunications secrecy. This means that Combell and its employees may not have any knowledge of the existence or content of such communication, outside of the exceptions enumerated by the law.” Generic stack: “Combell uses a variety of technical measures to protect personal data, such as: password protection, hard disk encryption software, firewalls, antivirus software, intrusion and anomaly detection system and access control systems for employees.” No PGP, S/MIME or built-in E2EE.
No transparency report, no canary; explicit confidential cooperation. AUP (forward-looking, no actual report located): “To enhance transparency and in compliance with the DSA, Combell may publish reports outlining its content moderation practices, including the number and nature of content removals and user accounts suspended or terminated.” Privacy Policy: “In the context of a police or judicial investigation, Combell can be obligated to communicate certain data to the requisite authorities in a confidential manner.” AUP: “Combell will fully cooperate with law enforcement authorities in their investigations of suspected criminal violations, violation of systems or network security.” AUP §6 disclosure trigger: “if Combell is obliged to comply with an order, instruction or request of a competent law enforcement authority.” Sources: Privacy Policy and AUP . No warrant canary.
Real identifying details at signup; ID required to exercise GDPR rights. Privacy Policy: “Combell will ask you for a number of personal details, such as name, address, telephone number, e-mail address and customer number.” And: “you must provide us with proof of your identity. We therefore ask that you preferably attach a copy of the front of your identity card to your application.”
Custom domains mandatory; no provider-domain free addresses. “Note: all our mailboxes work with your own domain name. No more @telenet.be, @gmail.com, etc.” Source: Compare email hosting . “With your domain name, you also get a free mailbox to send and receive e-mails.”
Same-domain aliases only; catch-all supported per domain. Exchange aliases KB: “You can link multiple, alternative e-mail addresses with the same domain name to your Exchange mailbox. These are internal e-mail aliases, internal because the referral takes place within the same domain name.” Cross-domain workaround via per-alias forwarding to a different mailbox. Quantity: “Combell allows you to create an unlimited number of e-mail aliases and to decide to which mailbox these e-mails have to be forwarded.” Catch-all: “A catch-all mailbox will receive all e-mails that are sent to mail addresses on your domain name, even if they have not been created.” Sources: Exchange aliases , Basic mail catch-all , Creating an address .
IMAP / POP3 / SMTP supported. Server hostnames: “IMAP: imap.mailprotect.be – port: 993 – Security: SSL · POP3: pop3.mailprotect.be – port: 995 – Security: SSL · … SMTP: smtp-auth.mailprotect.be – port 465 – Security: SSL” ( https://www.combell.com/en/help/kb/how-to-configure-my-basic-mailbox-on-android-basic-mail/) .
2FA: TOTP via authenticator only. “Enable two-factor authentication with software token for your Combell control panel.” Setup uses Duo Mobile or any TOTP app. WebAuthn/FIDO2/SMS for the Combell control panel are not documented. (Microsoft 365 mailboxes inherit Microsoft’s MFA separately.) Source: Two-factor authentication blog .
ISO 27001 since 2011. Privacy Policy: “Combell’s information security policy, requirements and management standards are in fact fully modelled on the international ISO 27001 standard, for which Combell has been certified since 2011.”
Retention. “Combell is obliged to keep records for up to 7 years” (accounting / fiscal) and “the legal necessity to provide certain data as evidence in case of disputes for up to a maximum of 10 years after termination of your contract.” IP-log-specific retention is not stated.
DPA stance. GTC Article 10: “If the Customer as ‘controller’ within the meaning of the General Data Protection Regulation (GDPR) processes personal data with the use of the services, products or goods from Combell, the Customer must conclude a ‘data processing agreement’ with Combell.” For natural-person customers Combell is controller: “Combell acts as the responsible party for processing the personal data of its customers.”
Founder origin story. “Everything started back in 1999, when Jonas Dhaenens (who was then only 16) registered the domain name combell.com using the money his father gave him for his excellent school grades.” Source: Combell 17th-anniversary blog . Footer: "© 1999 – 2026 Combell nv."
Entry-tier pricing conflicts between Combell’s own pages. The home and comparison pages advertise Basic Professional at “Normal price € 4.49/month · Now € 2.99/month”, while the standalone product page shows “1st year 43% discount · 6.99 /month · 3.99 /month” for the same tier. The figures used here are the home-page ones. Sources: Home , Basic email hosting .
Raidboxes
Privacy Impact: HIGH12 — German WordPress host that markets the email product as “Server location Germany” and “Own infrastructure, no third-party providers”, but the actual IMAP/SMTP endpoints (mail-rb.securemail.pro / smtp-rb.securemail.pro) carry a TLS certificate issued to Register S.p.A. of Florence, Italy — a fellow team.blue subsidiary acquired alongside Raidboxes via the June 2022 HTGF exit. No zero-access encryption, no transparency report, no warrant canary, TOTP/email/SMS 2FA only, and one connected custom domain per mail plan kills identity compartmentalization.
- Name: Raidboxes Email Hosting 2.0 — operated by Raidboxes GmbH, Münster, Germany (HRB 16184); part of team.blue
- URL:
raidboxes.io/en/email-hosting - HQ jurisdiction: Germany (14 Eyes, strong GDPR) OK+1
- Hosting jurisdiction: Marketed as Germany (“Server location Germany”), but the actual IMAP/SMTP endpoints
mail-rb.securemail.pro/smtp-rb.securemail.procarry a TLS certificate issued to “Register S.p.A., VIALE GIOVINE ITALIA 17” (Florence, Italy — also a team.blue subsidiary; both Italy and Germany are 14 Eyes); physical mail-server country is not unambiguously stated in Raidboxes’ own docs OK+1 - Zero-access encryption: None — product page conflates transport and storage (“Your emails are fully encrypted—not just during transfer via SSL/TLS, but the entire email including attachments”, no algorithm given); PGP listed only as “Optional” in the plan comparison with no statement on key custody (server-side vs. client-side) and no dedicated help article in the “Mail Hosting 2.0” collection BAD+3
- Government-access posture: No transparency report (only a DSA contact point in the Imprint); no user-notification commitment; no warrant canary BAD+3
- Anonymous signup: No Tor support stated; payment via SEPA (GoCardless), credit card (checkout.com), or invoice only — no crypto, no cash, no PayPal mentioned; ToS §7(2): “The Customer is obligated to provide their contract data correctly and completely” BAD+2
- Funding stability: Founded 2014 by Torben Simon Meier and Johannes Benz; seed-funded by HTGF in 2016 (€600k); acquired by team.blue on 28 June 2022 (HTGF exit); since August 2025 the mail backend was migrated off Mailbox.org onto team.blue’s own
securemail.proinfrastructure BAD+2
Sources (Legal Framework)
Operated by Raidboxes GmbH, Hafenstraße 32, 48153 Münster, Germany (HRB 16184; VAT DE306895091). Authorised representatives: Christian Klapka, Johannes Bernardus Nijholt. Source: Legal notice .
Acquired by team.blue on 28 June 2022. About page: “2022 Growth to 50 team members, over 16,500 customers and more than 35,000 websites hosted by us. Another milestone: Raidboxes joins forces with team.blue in order to expand further.” Source: About us . HTGF exit announcement: “Bonn, 28 June 2022 – team.blue … announced that the High-Tech Gründerfonds (HTGF) portfolio company Raidboxes … is joining its growing group of companies. HTGF is selling its stake after having closely supported the team led by Johannes Benz and Torben Simon Meier since 2016.” Source: HTGF exit . Privacy Policy further names “team.blue N.V., Skaldenstraat 121, 9042 Gent, Belgium”, “iubenda s.r.l.”, “LeadInfo B.V.”, “Hypernode B.V.” as joint controllers for advertising data.
German law, Münster as place of jurisdiction. GTC §15: “The law of the Federal Republic of Germany applies. The version of the contract in the original German language is binding. If the Customer is a consumer, the mandatory provisions of the law in the state of his habitual residence shall remain unaffected. If the Customer is a business person, a legal entity under public law or a special fund under public law, the place of jurisdiction is the registered office of Raidboxes.” GTC §15(4): “Raidboxes is not willing and is not obliged to participate in a dispute resolution procedure before a consumer arbitration board.” Source: General Terms .
Mailservers run on team.blue sibling infrastructure. Marketing copy claims “Server location Germany” and “Full control: Own infrastructure, no third-party providers” (
https://raidboxes.io/en/email-hosting/) . The Help Center documents the actual server hostnames: “Posteingang (IMAP) … mail-rb.securemail.pro … Port 993 … Encryption SSL / TLS” and “Postausgang (SMTP) … smtp-rb.securemail.pro … Port 587 … Encryption TLS / STARTTLS” (
https://helpcenter.raidboxes.de/en/articles/11851526-email-hosting-2-0-everything-you-need-to-know) . The *.securemail.pro TLS certificate is issued to “O=Register S.p.A., VIALE GIOVINE ITALIA 17” — Register S.p.A.’s own corporate page states “The ultimate parent entity of Register S.p.a. is team.blue EquityCo S.a.r.l.” (
https://www.register.it/company/?lang=en) . Raidboxes does not disclose this Register.it backend relationship on any primary-source page — a material gap relative to the “own infrastructure” claim.
Encryption claims conflate transport with storage; no zero-access. Product page: “Your emails are fully encrypted—not just during transfer via SSL/TLS, but the entire email including attachments.” The Privacy Policy describes only generic “https://” TLS encryption: “For security reasons and to protect the transmission of your personal data and other confidential content, we use encryption on our domain. You can recognize this in the browser line by the string ‘https://’ and the lock symbol.” No algorithm or key-management is specified for at-rest encryption. PGP appears only as “PGP encryption | Optional | Optional | Optional” in the plan comparison ( https://raidboxes.io/en/email-hosting/ ) with no statement on key custody. The German migration article describes “die neuen Mailserver bieten Spam- und Virenfilter, SSL-Verschlüsselung, einen Blacklist-Checker und optional eine PGP-Verschlüsselung” ( https://helpcenter.raidboxes.de/de/articles/13224505) . No dedicated PGP help article exists in the post-Mailbox.org “Mail Hosting 2.0” collection.
No transparency report, no canary, no notification commitment. The only “transparency”-related disclosure is the Imprint’s DSA contact: “Contact point for authorities pursuant to Art. 11 of the Digital Service Act of the European Parliament and Council … This e-mail address is intended exclusively for enquiries pursuant to Art. 11 DSA. Other enquiries will not be processed and answered.” No transparency report exists on raidboxes.io, blog.raidboxes.io, or helpcenter.raidboxes.de. No warrant canary. Privacy Policy contains only a generic recipients clause at §9 — no user-notification commitment, no explicit non-notification clause.
1 connected domain per mail plan. Email-hosting comparison table: “Maximum number of connected domains | 1 | 1 | 1” — across all three tiers (Mini, Starter, Pro). Same-domain aliases only (5 / 10 / 15 per mailbox); cross-domain delivery requires external forwarding. Help Center: “Please note that creating a mailbox is only possible if the corresponding domain is already hosted with Raidboxes.”
Catch-all supported on the one connected domain. “With the catch-all feature, all emails sent to non-existent email addresses of your domain can be automatically forwarded to a specific mailbox.” And: “To use the catch-all function, you need a mailbox with the same name, e.g., catchall@yourdomain.de.” Source: Email Hosting 2.0 help .
2FA: TOTP, email or SMS — no WebAuthn/FIDO2. “Our 2FA feature allows you to receive authentication codes via app, email or SMS.” And: “To activate two-factor authentication via app, select the option Authenticator App (TOTP) and click on Activate 2FA to confirm. … We recommend the app Authy.” SMS provider Twilio Ireland Limited is named in the Privacy Policy. WebAuthn/FIDO2 hardware-key support is not documented. Source: 2FA help .
Payment methods exclude crypto, cash, and PayPal. Subscription management blog: “We work with GoCardless for SEPA payments and checkout.com for credit card payments.” Source: New subscription management 2022 . Cryptocurrency, cash, and PayPal are not mentioned anywhere in payment-related primary sources. Discount on prepayment: “5 or 10 percent discount” for semi-annual / annual.
Migration via paid Audriga only on the new platform. “If you want to migrate the data of a mailbox from an external provider to Raidboxes, you can use the paid migration service from audriga.” A free self-service Gmail/IMAP importer for the Email Hosting 2.0 stack is not documented.
Real identifying details at signup. Privacy Policy: “As part of the registration or order process, it is necessary for you to create a customer account so that you can use our services.” GTC §7(2): “The Customer is obligated to provide their contract data correctly and completely and to inform Raidboxes immediately about any changes.”
DPA available via the customer dashboard. Privacy Policy §22: “If you intend to transfer personal data to us when using our products, enable you to conclude a contract for order processing (AVV) online with us.” Dedicated DPA page: “Do you need our DPA? No problem! Simply fill out the form below with your account details to conclude the data processing agreement with us online. A copy of the contract will then be sent directly to your e-mail address.” Source: DPA .
Backend migration off Mailbox.org on 26 August 2025. Help Center: “Please note: Starting August 26, 2025, mailbox.org mailboxes will only be available for domains that are already connected to mailbox.org and obtain mailboxes through this cooperation partner.” Source: Raidboxes Email + Mailbox.org . Some old marketing copy referencing Mailbox.org is still partially visible on the product page even though the partnership has ended.
Soverin
Privacy Impact: HIGH12 — Dutch operator with Dutch hosting, but no built-in encryption for live mail, no transparency report, no warrant canary, a phone number required at signup, no anonymous payment — and a 2024 corporate move “joining The Sharing Group” adds parent-portfolio risk to a previously independent provider.
- Name: Soverin — operated by Soverin B.V., Vijzelstraat 68, 1017HL Amsterdam, Netherlands (KvK 61552275)
- URL:
soverin.com - HQ jurisdiction: Netherlands (9 Eyes / 14 Eyes, strong GDPR) OK+1
- Hosting jurisdiction: Netherlands (“All data stays in the Netherlands”); broader claim is “servers that are separately located within Europe” OK+1
- Zero-access encryption: None for the live mailbox — TLS in transit and “disc encryption” on servers (against physical seizure) only; backups are encrypted with a per-user key (“these backups are encrypted with Your personally generated key”) but no E2EE or zero-access claim for stored mail; no native PGP/S-MIME integration BAD+3
- Government-access posture: No published transparency report; no user-notification commitment; no warrant canary; ToS reserves the right to “hand over any information We have about You … if a competent authority requests Soverin to hand over such information” BAD+3
- Anonymous signup: Tor not stated; payment via Mollie (“credit cards, iDeal and others”) — no crypto, no cash documented; signup requires “a mobile phone number” (stated to be used only for password reset) BAD+2
- Funding stability: Founded around 2014 (10-year anniversary press release in 2024); described in 2024 as “joining The Sharing Group, a collective of companies that use technology to empower people and society” — a recent corporate-group affiliation that introduces parent-portfolio exposure even with the statement “Our name, our team, and our commitment to privacy and independence remain unchanged” BAD+2
Sources (Legal Framework)
Dutch entity, Dutch law. Terms (July 2025 PDF): “Soverin, We, Our or Us: Soverin B.V., registered at Vijzelstraat 68 (1017HL) Amsterdam, registered at the chamber of commerce under number 61552275.” And: “All rights and obligations arising out of or in connection to these Terms and the Agreement are construed, governed, interpreted and enforced according to the laws of the Netherlands.” And: “The exclusive jurisdiction and venue of any action with respect to any subject matter relating to these Terms will be the court’s located in Amsterdam, the Netherlands.” Source: Terms and Privacy Statement (PDF, July 2025) .
Dutch hosting, EU-only processing. Privacy Statement: “Soverin only Processes Personal Data in countries within the European Union.” FAQ: “All data stays in the Netherlands, protected by EU law — no U.S. Cloud Act exposure.” And: “Everything is hosted in servers that are separately located within Europe, with secured infrastructure and disc encryption in case our hardware is ever confiscated.” Sources: Privacy Statement and FAQ .
TLS + disc encryption only; no native E2EE. Privacy Statement: “The security of Your data is extremely important to Soverin … We encrypt all data connections from and to our email servers.” Terms (5.2): “Soverin treats all emails between You and Your designated recipients confidentially. Soverin does not check, open or view the contents of Your emails, including attachments, calendars and contact entries.” The provider does not claim built-in zero-access or end-to-end encryption for mailbox content; the only stored-data encryption claim is “disc encryption in case our hardware is ever confiscated” — i.e. physical-seizure protection only. No native PGP / S-MIME integration is documented.
Per-user backup encryption — narrow scope. Privacy Statement (6.2): “The backups of Our servers do contain copies of Your data, amongst which including email. However, these backups are encrypted with Your personally generated key, granting You exclusive access to Your data. This key will be erased when You delete Your account, so no one will be able to access Your backup. So to be extra clear; Soverin cannot access Your backup.” This is unusual and useful — but it covers backups only, not live mailbox storage during user sessions.
IP removed from outbound headers; server-side logging not stated. FAQ: “We remove your personal IP address from the headers of your email. Nobody needs to know your location when you send an email.” No statement on whether (or how long) Soverin logs client IPs at the mail-server level.
Account-deletion retention. Terms (6.6): “Upon termination of Your Account or Your optional custom domain, it is, including Your emails, calendar and contact entries and all other data therein, is directly, automatically and permanently deleted.” FAQ: “If you leave Soverin, your data is removed from our systems, including backups, in line with our data retention policies.” No fixed retention window stated for backups.
No transparency report, no canary, no notification commitment. Soverin publishes no government-request statistics page. Terms (5.6): “Soverin is entitled to report and hand over any information We have about You and relating to You and Your use of the Service to the police if We have reason to assume the Service is used for criminal activities and also if a competent authority requests Soverin to hand over such information.” No commitment to notify users when legally allowed; no warrant canary.
Phone number required at signup; no anonymous payment. FAQ: “Signing up is easy … All you will need is a mobile phone number to sign up. And don’t worry, we only use it to reset your password.” About: “Signing up is a breeze. All you need is a phone number. We are not interested in acquiring personal data or building user profiles. Your mobile phone number is all you need to sign up, it is only used to reset your password.” Sources: FAQ and About . Terms (6.2): “We use trusted payment provider Mollie ( www.mollie.com ), which supports credit cards, iDeal and others, when charging You for any kind of fees.” No crypto, no cash, no Tor documented.
TOTP only; no FIDO2 / WebAuthn / SMS 2FA. Help: “Soverin uses Time-based One-Time Passwords (TOTP). This means a unique, one time passcode is generated by an authenticator app on your phone. Without this code, logging in with just your password isn’t possible.” Source: Two-factor authentication .
No POP3. Help page documents only IMAP (993 / 143) and SMTP (465 / 587); POP3 is not described. Source: Mail app setup .
DPA via Privacy Statement; processor stance. Privacy Statement: “This Privacy Statement qualifies as a processing agreement as referred to in Article 28 AVG. The applicability of any other processing agreements is expressly rejected.” And: “Soverin and You agree that with respect to the processing of Your personal data supplied by You to Soverin for enabling You to use the Service, Soverin is ‘processor’ within the meaning of the General Data Protection Regulation and complies with the Privacy Statement.” Source: Privacy Statement . No customer-signable DPA template is separately published.
Founded around 2014; 2024 group affiliation. About: “Soverin is an independent private company based in Amsterdam, run by a team of internet enthusiasts who want to create great products that are safe, beautiful and easy to use.” Source: About . 2024 announcement: “Today, we are taking an important step in that mission: Soverin is joining The Sharing Group, a collective of companies that use technology to empower people and society.” And the reassurance: “Our name, our team, and our commitment to privacy and independence remain unchanged.” Source: Soverin joins The Sharing Group . The provider docs do not disclose the full ownership chain inside The Sharing Group — Soverin previously presented as fully independent, so the group affiliation is the structural risk to flag.
Fastmail
Privacy Impact: HIGH13 — Best government-access posture of the 5 Eyes providers, but US hosting + Australian jurisdiction stack badly.
- Name: Fastmail Pty Ltd, ABN 31 142 646 580, Victoria, Australia
- URL:
fastmail.com - HQ jurisdiction: Australia (5 Eyes; CLOUD Act agreement with US active since Jan 2024) BAD+3
- Hosting jurisdiction: USA (primary: Philadelphia, PA; secondary: St. Louis, MO) BAD+3
- Zero-access encryption: None in own apps; opt-in PGP/S/MIME possible via third-party clients; disk-level encryption only BAD+3
- Government-access posture: Annual transparency report + explicit user-notification commitment (with stated exceptions); no warrant canary OK+1
- Anonymous signup: Cards / PayPal / Apple Pay / Google Pay only; no cash, cheques, bank transfers, money orders; Tor not stated; crypto not stated BAD+2
- Funding stability: Privately held; was acquired by Opera Software and bought back by employees; no recent ownership change OK+1
Sources (Legal Framework)
US server location. Help: “Our main servers are located in Philadelphia, Pennsylvania, USA … Our secondary site is in St. Louis, Missouri, USA.” Source: How Fastmail provides a secure service .
Australian law applies. ToS: “These Terms are governed by the laws of the State of Victoria Australia … The courts sitting in the State of Victoria, Australia shall have exclusive jurisdiction”. Source: Terms of Service .
No E2EE in their own apps — explicit choice. Fastmail: “We don’t offer end-to-end encryption in our own apps, as we don’t believe it provides a meaningful increase in security for most users, while the trade-offs are significant.” Source: Fastmail vs Proton and features/security . Disk-level: “All your data is stored on encrypted disk volumes, including backups.”
User-notification commitment. Law-enforcement page: “Fastmail notifies a user if an authority has made a legal request for their information, giving them the opportunity to challenge the request.” With exceptions for harm, Australian-law prohibitions, or already-closed accounts. Source: Information for law enforcement .
Transparency report. Annual report published since 2021. 2024 onwards includes CLOUD Act request statistics: “In 2021 this was amended by the Cloud Act agreement between Australian and the USA, however the processes only came into force in January 2024, so we received our first requests under the Cloud Act in that year.” Source: Data Transparency Report .
Payment methods limit anonymity. Pricing FAQ: “We currently accept most major credit and debit cards, plus PayPal, Apple Pay, and Google Pay. We are unable to accept cash, cheques, bank transfers, or money orders.” Source: Pricing . Crypto: previously accepted, now discontinued (not documented on current site).
Founded 1999; Opera acquisition + employee buyback. Blog: “FastMail has been around for 15 years now, via a short detour as part of Opera Software and then back to being our own company again.” Source: Working at FastMail .
Hushmail
Privacy Impact: HIGH13 — Server-side PGP is not zero-access; explicit non-notification policy is unusual.
- Name: Hush Communications Canada Inc. (servers); parent Hush Communications Corporation (Delaware, USA); HQ Vancouver, BC, Canada
- URL:
hushmail.com - HQ jurisdiction: Canada (5 Eyes) with US parent corporation BAD+3
- Hosting jurisdiction: Canada — Vancouver, BC + Calgary, AB BAD+3
- Zero-access encryption: Server-side OpenPGP for webmail — private key is decrypted on the web server during user sessions, exposing message body to the server briefly; client-side PGP only in the iPhone app OK+1
- Government-access posture: Explicit non-notification: “we will not disclose to any user the existence, or nonexistence, of any order we may have received”; no public transparency report; no warrant canary BAD+3
- Anonymous signup: Card payments only; IP recorded at signup and purchase; Tor not stated; crypto not stated BAD+2
- Funding stability: Privately held Delaware corporation; founded 1998–1999; long operational history OK+1
Sources (Legal Framework)
Corporate identity. Privacy Policy: “Our servers where user data is stored are located in Vancouver, British Columbia and Calgary, Alberta, Canada, and operated by Hush Communications Canada Inc., a wholly owned subsidiary of Hush Communications Corporation, a private Delaware, USA company.” Source: Privacy Policy .
Server-side PGP is not zero-access. Security analysis: “Message body known to web server: Yes, after the message emerges from SSL encryption, the body is temporarily exposed to the server before the PGP encryption takes effect.” And “Private key decrypted and used on server for decrypting and signing messages (for the duration of your session).” Source: Security Analysis .
Non-notification of legal orders. Privacy Policy: “Because such orders generally state that we are not permitted to disclose the existence of the order to a user, we will not disclose to any user the existence, or nonexistence, of any order we may have received.” Source: Privacy Policy .
British Columbia law for orders. Court-orders article: “Hushmail will not accept an order from any authority or investigative agency that is not enforceable under the laws of British Columbia, Canada.” Source: How we handle court orders .
IP logging at signup and purchase. Privacy Policy: “As part of the account creation process your IP address will be recorded … we will record the IP address from where the payment is made.” Retention: “The records we keep of your activities are permanently deleted after approximately 18 months.”
Founded 1998–1999. About: “Hush Communications was founded in 1998, and in May 1999 we launched Hushmail.” Source: About . “Hush Communications is a profitable, privately held Delaware corporation.”
Known prior compliance case (external): In 2007 Hushmail handed over decrypted email content to US authorities in a steroid investigation — not documented on the provider’s own site but extensively reported externally. Worth flagging in any privacy assessment.
Lavabit
Privacy Impact: HIGH13 — US jurisdiction, almost no operational documentation on the public site, and a 2013 forced shutdown make this a niche/historical choice despite the founder’s principled posture.
- Name: Lavabit LLC, Dallas, Texas, USA; founded by Ladar Levison
- URL:
lavabit.com - HQ jurisdiction: USA (5 Eyes, CLOUD Act; jurisdiction stated as Dallas, Texas) BAD+3
- Hosting jurisdiction: Not stated in Lavabit’s docs (primary ISP is Cogent — assume US) BAD+3
- Zero-access encryption: Opt-in “secure” mode uses passphrase-derived asymmetric encryption at rest; default (“Trustful”) mode has none; DIME’s zero-access modes (Cautious / Paranoid) and the Volcano client are documented as protocols/products still “in development” OK+1
- Government-access posture: No transparency report (stated as planned, not published); no warrant canary; no user-notification commitment BAD+3
- Anonymous signup: Tor not stated; payment methods not enumerated on the public site; signup identity requirements not stated BAD+2
- Funding stability: Founded 2004; voluntarily shut down in 2013 when US authorities demanded its TLS private keys; relaunched 2017; sole-founder operation; no investors disclosed OK+1
Sources (Legal Framework)
US entity, Texas jurisdiction. ToS: “The services provided by Lavabit LLC (hereafter referred to as Lavabit) are subject to the following Terms of Use.” And: “Should a need for legal action arise, Lavabit reserves the right to have said action occur within the jurisdiction of Dallas, Texas.” Source: Terms of Use .
Encryption only on opt-in “secure” mode. Privacy policy: “For premium users who have elected to use our ‘secure’ service, incoming e-mail is stored using an asynchronous encryption process that guarantees that it can’t be accessed by anyone except the holder of the account password. For these accounts, only the encrypted version of the message is ever saved to disk.” Default (Trustful) mode is not encrypted at rest. DIME’s Cautious/Paranoid modes and the Volcano client remain prospective: “Volcano is Lavabit’s own propriety mail client… Now in development for iOS, Android, and webmail.” Source: Enterprise page .
Strong non-disclosure baseline; no transparency report. Privacy policy: “Lavabit will not release any information related to an individual user unless legally compelled to do so.” On transparency: “We plan to conform to the Transparency Reporting Toolkit” (planned, not published). No warrant canary; no user-notification clause in any current document.
Limited logging. “We do not keep a record of the IP addresses used to access our services (except in the web server logs), and we not keep a record of what information was accessed during a particular session.” Web log IP retention: “typically deleted within seven days”. Mail is retained only until delivered/deleted/account-terminated.
IMAP/POP/SMTP supported in Trustful mode: “Accounts operating in Trustful mode send messages using the Simple Mail Transfer Protocol—SMTP—and receive messages using the Post Office Protocol—POP—or the Internet Mail Access Protocol—IMAP.” Source: Security .
Custom domains: contact-based setup. FAQ: “Contact us using the form below, with the address you want associated with your account, and we’ll provide you with requisite DNS entries, along with instructions for providing domain ownership.” Source: Questions .
2013 shutdown, 2017 relaunch. About: “In 2013, we suspended service to protect our global customers when the U.S. government ordered us to release our Transport Layer Security private keys. To protect your digital privacy and freedom, we said no.” Source: About . This is the single most prominent privacy-positive operator move on public record — and also a major operational red flag for anyone relying on Lavabit to remain online under US legal pressure.
Documentation gaps. Lavabit’s public site does not publish pricing, plan tiers, storage quotas, alias counts, catch-all support, 2FA methods, Tor support, anonymous payment options, or a customer DPA. Most comparison-relevant fields are explicitly “Not stated” in the provider’s primary documents.
MXroute
Privacy Impact: HIGH14 — Bulk email hosting under US jurisdiction with minimal privacy posture.
- Name: MXroute LLC, registered in Texas, USA
- URL:
mxroute.com - HQ jurisdiction: USA (5 Eyes, CLOUD Act) BAD+3
- Hosting jurisdiction: Not explicitly stated in provider docs; “We operate under U.S. federal and Texas state laws” — assume US BAD+3
- Zero-access encryption: None claimed; “As an email service provider, we transmit and store email data as part of our core service”; no E2EE feature BAD+3
- Government-access posture: No transparency report, no notification commitment, no warrant canary; “we may also release your information when we believe release is appropriate” (forum policy) BAD+3
- Anonymous signup: PayPal + cards only via Stripe; “Crypto payments are not supported at this time”; cash not accepted; Tor not stated BAD+2
- Funding stability: “Independent and operator-run since 2013, with no exit plan.” “No private equity, no investor decks” — bootstrapped GOOD0
Sources (Legal Framework)
US entity, US-only law cited. GDPR note: “MXroute is a company based in the United States with no operations (employees, incorporation, or physical presence) inside the European Union” and “We operate under U.S. federal and Texas state laws”. Source: docs.mxroute.com/…/gdpr.html .
No published encryption-at-rest claim for email content. GDPR note: “We implement standard security measures to protect this data from unauthorized access” — no algorithm, no key-holder statement, no E2EE claim.
No published government-access policy. Forum privacy policy (note: applies only to forum, per MXroute): “We may also release your information when we believe release is appropriate to comply with the law, enforce our site policies, or protect ours or others rights, property, or safety.” No transparency report or canary anywhere on the site.
No GDPR DPA. GDPR note: “While we respect the importance of data privacy, we maintain a neutral position regarding specific GDPR compliance measures.”
Bootstrapped since 2013. Homepage: “EST. 2013 · NO-NONSENSE EMAIL HOSTING”, “Independent and operator-run since 2013, with no exit plan”, “No private equity, no investor decks, no AI summaries”. Source: mxroute.com .
Payment limits anonymity. Billing docs: “MXroute accepts payments through: PayPal Stripe” and “Crypto payments are not supported at this time”. Source: docs.mxroute.com/…/billing.html .
Namecheap Private Email
Privacy Impact: HIGH14 — Long-running US registrar selling a domain-attached mailbox; CLOUD Act exposure, no E2EE, no transparency report. Bitcoin acceptance is the only material privacy plus.
- Name: Namecheap Private Email — operated by Namecheap, Inc., Phoenix, Arizona, USA
- URL:
namecheap.com/hosting/email - HQ jurisdiction: USA (5 Eyes, CLOUD Act) BAD+3
- Hosting jurisdiction: Default USA — DPA: “Namecheap may transfer Customer Data to the United States for processing.” Specific data-centre locations for Private Email mail servers are not stated BAD+3
- Zero-access encryption: None — no encryption-at-rest or E2EE claim for Private Email in any legal or KB document; privacy policy is silent on encryption of mailbox content BAD+3
- Government-access posture: No transparency report on government requests; no user-notification commitment; no warrant canary. DPA states “Namecheap does not voluntarily provide governments with access to any data about users for surveillance purposes” and rejects/challenges overbroad requests — non-binding posture without a transparency report to back it up BAD+3
- Anonymous signup: Bitcoin accepted (via BitPay and BTCPay); credit balance up to $100,000 fundable in BTC; Tor not stated; signup requires “accurate, current and complete” account info OK+1
- Funding stability: Founded 2000; “remained a private company, and has grown consistently and organically”; no acquisition history; CEO Richard Kirkendall OK+1
Sources (Legal Framework)
Operated by Namecheap, Inc. at 4600 East Washington Street, Suite 300, Phoenix, AZ 85034, USA. Per Hosting Privacy Policy: “Namecheap Inc, dba Namecheap”. Source: Web Hosting Privacy Policy .
US-defaulted data processing. DPA: “Customer agrees that, except where specifically noted in the Terms of Service, Namecheap may transfer Customer Data to the United States for processing.” Source: Data Processing Addendum . No mail-server location is published for Private Email specifically.
No documented E2EE or zero-access encryption. Private Email’s KB and ToS do not describe encryption-at-rest or end-to-end encryption for mailbox content; protocol-level encryption (SMTPS port 465, IMAP SSL 993, POP3 SSL 995, SMTP STARTTLS 587) is documented for client connections.
Account-deletion retention. Hosting Privacy Policy: “When Your Namecheap account is cancelled (either voluntarily or involuntarily) all of Your personally identifiable information is placed in ‘deactivated’ status within Our corresponding databases.” And: “deactivation of Your account does not mean Your personally identifiable information has been deleted from Our database entirely. We will retain and use Your personally identifiable information if necessary in order to resolve disputes or enforce Our agreements.” No fixed retention window stated.
Government-access posture without a transparency report. DPA: “Namecheap does not voluntarily provide governments with access to any data about users for surveillance purposes, and Namecheap will not disclose Customer Data to any government or any other third party, except as necessary to comply with the law or a valid and binding order of a law enforcement agency (such as a subpoena or court order).” And: “Namecheap interprets legal process as narrowly as possible. Namecheap rejects or challenges any requests that have no legal basis or are unclear, overbroad or otherwise inappropriate.” No periodic government-request statistics published; no warrant canary; no user-notification commitment. Hosting Privacy Policy reserves the right to disclose “when We are required by law … in the good-faith belief that such action is necessary in order to conform to the edicts of the law…”
DPA / GDPR. Universal ToS Section 4: “Namecheap’s Controller to Processor Data Processing Addendum (‘DPA’), which is hereby incorporated by reference and applicable to Covered Services…” Customer is the “Data Controller/Data Exporter”; Namecheap is the Data Processor for Private Email. Source: Universal ToS and DPA .
Bitcoin accepted; PayPal + Visa / Mastercard / Amex. Press release: “We’re delighted to inform you that we now accept the Bitcoin payment method, in addition to PayPal, Visa, Mastercard, and American Express.” And: “Namecheap will also continue to accept payment through BitPay, and customers looking to purchase Namecheap products and services with Bitcoin will now have the option to do so through BTCPay or BitPay.” “With BTCPay, Namecheap customers can now add any amount of money (up to $100,000) to their Namecheap account balance…” Source: BTCPay press release . SEPA / cash: not stated. Tor: not stated.
2FA: TOTP + U2F (Yubikey-style). “Choose from some of the most rock-solid 2FA methods in the market now, including the world-leading U2F (Universal 2nd Factor) service and TOTP (Time-based One-Time Password).” And: “With U2F (Universal 2nd factor) you don’t need to type in codes from an app on your smartphone. Instead, this technology uses a small, specialized USB or NFC device like Yubikey…” SMS 2FA: not mentioned. Source: 2FA page .
Aliases per mailbox, plan-gated. KB: “with Starter email plan – 10 aliases per mailbox / with Pro email plan – 50 aliases per mailbox / with Ultimate email plan – Unlimited number of aliases per mailbox.” Catch-all is supported via DNS (Email Forwarding, one catch-all per domain) and inside Private Email by designating a mailbox as the domain’s catch-all. Sources: Aliases KB and Catch-all KB .
Founded 2000; privately held. “Namecheap® is an ICANN-accredited domain registrar and technology company founded in 2000 by CEO Richard Kirkendall.” And: “Since its launch in 2000, Namecheap has remained a private company, and has grown consistently and organically without Super Bowl-sized marketing budgets.” No outside investors, acquisitions, or prior shutdowns documented in provider materials.
Zoho Mail
Privacy Impact: HIGH14 — US-headquartered SaaS group with multi-jurisdiction hosting, no E2EE by default, no transparency posture; ties MXroute at the bottom.
- Name: Zoho Mail — operated by the Zoho Group: Zoho Corporation (Pleasanton, CA, USA), Zoho Corporation B.V. (Utrecht, Netherlands), Zoho Corporation Pvt. Ltd. (India, sub-processor)
- URL:
zoho.com/mail/ - HQ jurisdiction: USA primary contracting entity + Netherlands EU entity + India sub-processor; CLOUD Act exposure via US group BAD+3
- Hosting jurisdiction: User-selected at signup from US, EU, CN, IN, AU, JP — but the group entities span 5 Eyes (US, AU) and high-surveillance (CN); worst case applied BAD+3
- Zero-access encryption: None default; opt-in PGP/S/MIME advertised but technical scope and zero-access status not stated; spam filtering implies server-side plaintext access BAD+3
- Government-access posture: No transparency report; no warrant canary; no explicit user-notification commitment BAD+3
- Anonymous signup: Tor not stated; no crypto, no cash; only card / PayPal / NEFT / cheque; signup requires “true, accurate, current and complete” information BAD+2
- Funding stability: Privately held, founder-controlled (Sridhar Vembu); operating since 1996; never acquired; never taken venture capital GOOD0
Sources (Legal Framework)
Multi-entity group. Global privacy policy: “This Privacy Policy statement is made by the Zoho Group consisting of all the entities listed here (collectively, ‘Zoho’, ‘we’, ‘us’ or ‘our’).” Entities include Zoho Corporation (Pleasanton CA, USA — data centers in the US), Zoho Corporation B.V. (Utrecht, Netherlands — data centers in the EU), Zoho Corporation Pvt. Ltd. (India — sub-processor). Source: Zoho Group entities and Privacy Policy .
Governing law depends on customer location. ToS: “The governing law and jurisdiction that will apply in case of any dispute or lawsuit arising out of or in connection with this Agreement, will depend on your billing address if you are a paid customer and your state or country of domicile in all other cases.” Source: Terms of Service .
User-selected data centre, multi-region group reach. “Zoho servers are located in most secure data centers in US, EU, CN, IN and AU.” Mail domain maps to data centre: mail.zoho.com → US, mail.zoho.eu → EU, mail.zoho.com.cn → CN, mail.zoho.in → IN, mail.zoho.com.au → AU, mail.zoho.jp → JP. Source:
Mail GDPR .
Encryption at rest, no zero-access. “The service data stored in Zoho Mail is Encrypted At Rest(EAR). All the data are encrypted in transit also.” Source: Mail GDPR . PGP is advertised — “PGP Encryption – Secure email communication with end-to-end encryption” — but technical scope undocumented; and “Processes like spam filtering and virus detection are automated in order to not give any employees access to view your emails” clearly implies server-side plaintext processing. Source: Mail privacy .
No transparency report, no canary, no notification commitment. No published transparency report on Zoho’s own properties. Privacy policy: “We may be required by law to preserve or disclose your personal information and service data to comply with any applicable law, regulation, legal process or governmental request, including to meet national security requirements.” No explicit user-notification clause either way.
Account-deletion retention. “When a personal Zoho Mail account is closed by the user or when an account is manually deleted by a Super Administrator/Administrator, the data from the deleted account is retained on Zoho Mail servers for 30 days, after which it is permanently purged.” Inactive free personal mailboxes are cleared after 300 days. Source: Data deletion policy .
Identifying data required at signup. ToS: “You agree to: (i) provide true, accurate, current and complete information about yourself as prompted by the sign up process; and (ii) maintain and promptly update the information provided during sign up to keep it true, accurate, current, and complete.” No Tor support documented.
Payments — no anonymity. Pricing FAQ: “We accept payment via Visa, MasterCard, American Express, and PayPal. We also accept payment via NEFT bank transfers and cheque transfers for yearly subscriptions.” No crypto, no cash.
DPA available on request. “To enable you to be compliant with your data protection obligations, we are prepared to sign an appropriate Data Processing Addendum (DPA).” Source: Privacy Policy .
Founder-controlled, bootstrapped (external). Provider docs don’t state founding year or funding model. Externally well-documented: Zoho Corp was founded 1996 by Sridhar Vembu, has never taken venture capital, is family-controlled, and has never been acquired — strong stability signal that partially offsets the jurisdictional weakness above.
Out of scope
Providers that don’t get a Privacy Impact score — either discontinued, sub-scale, or otherwise unscorable — kept here so the lesson isn’t lost. Extend this section by adding more entries below; no new ## headers required.
Free Big Tech webmail (Gmail, Outlook.com / Hotmail, Yahoo Mail, AOL Mail, iCloud Mail — and analogous non-U.S. peers Yandex Mail, QQ Mail, NetEase 163.com, mail.com). Worst-in-class on every axis of the rubric simultaneously: U.S. incorporation under Five Eyes membership, direct CLOUD Act exposure (18 U.S.C. § 2713 compels disclosure of stored content “regardless of whether such communication, record, or other information is located within or outside of the United States”), no zero-access or end-to-end encryption in their own apps (Apple’s own
iCloud data security overview states verbatim “iCloud Mail does not use end-to-end encryption because of the need to interoperate with the global email system”), systematic content scanning (Microsoft’s
Privacy Statement : “some of our products, such as Outlook.com or OneDrive, systematically scan content in an automated manner to identify suspected spam, viruses, abusive actions, or URLs that have been flagged as fraud, phishing, or malware links”), real-name + phone-required signup, and advertising-driven business models (Alphabet’s
FY2024 10-K : “We generated more than 75% of total revenues from online advertising in 2024”). Compressing their score onto a 0–14 scale alongside Proton or Tuta misleads the reader about the magnitude of the gap. The non-U.S. peers are excluded for analogous worst-in-class reasons under their own jurisdictions — Russian FSB-mandated retention + decryption keys under Federal Law 374-FZ (“Yarovaya law”), PRC Cybersecurity / Data Security / Personal Information Protection Law data-localization + warrantless state-security access, and German BND-Gesetz compelled-disclosure for 1&1 Mail & Media’s mail.com.
Why free Big Tech webmail is structurally excluded
All five U.S. providers were named in the NSA’s PRISM/US-984XN slide deck disclosed by Edward Snowden in June 2013 — “Collection directly from the servers of these U.S. Service Providers: Microsoft, Yahoo, Google, Facebook, PalTalk, AOL, Skype, YouTube, Apple”, with per-provider onboarding dates Microsoft (Hotmail) 9/11/2007, Yahoo 3/12/2008, Google 1/14/2009, AOL 3/31/2011, and Apple October 2012 (the last of the five). Sources: Washington Post — PRISM collection documents (Gellman & Poitras, 2013-06-06); The Guardian — NSA Prism program taps in to user data of Apple, Google and others (Greenwald & MacAskill, 2013-06-06).
Statutory CLOUD Act exposure (2018). United States v. Microsoft Corp., 584 U.S. ___ (2018) — the “Microsoft Ireland” case — was mooted by Congress’s enactment of the CLOUD Act, which added 18 U.S.C. § 2713 requiring U.S. ECS providers to disclose communications regardless of storage location. Google LLC, Microsoft Corporation, Yahoo Inc., Apple Inc., and the Apollo-owned Yahoo entity that now operates AOL Mail are all directly compellable under that statute.
Scale of compelled disclosure (most recent H1 2024 reports). Apple’s H1 2024 transparency report discloses U.S. National Security Requests — “FISA Non-Content Requests: 500–999 / Users-or-Accounts: 53,000–53,499” and “FISA Content Requests: 500–999 / Users-or-Accounts: 65,500–65,999”, with Apple’s own note that “Apple responds to National Security FISA content requests with information obtained from iCloud”. Microsoft’s H1 2024 transparency report records roughly 27,242 consumer-services law-enforcement requests worldwide. Google’s transparency-report user-data overview shows that in H1 2024 Google received over 82,000 requests for disclosure of user information from U.S. federal agencies and other government entities. FISA and NSL counts are published in bands of 500 with a six-month statutory delay under the USA FREEDOM Act of 2015.
No zero-access encryption in any of the five. Apple’s Advanced Data Protection for iCloud overview is explicit: “Because of the need to interoperate with the global email, contacts, and calendar systems, iCloud Calendar, Contacts, and Mail aren’t end-to-end encrypted.” — iCloud Mail keystorage remains “Apple” under both Standard data protection and Advanced Data Protection. Microsoft’s Privacy Statement states “If you receive an email using Outlook.com, we need to collect the content of that email to deliver it to your inbox, display it to you, enable you to reply to it, and store it for you until you choose to delete it” and confirms automated scanning at the system level. Microsoft also invokes the EU CSAM derogation: “In accordance with European Union Regulation (EU) 2021/1232, we have invoked the derogation permitted by that Regulation from Articles 5(1) and 6(1) of EU Directive 2002/58/EC. We use scanning technologies to create digital signatures (known as ‘hashes’) of certain images and video content on our systems.” Google retains scanning carve-outs for spam, phishing, malware, and contextual features (Diane Greene, SVP Google Cloud, 2017-06-23 Google blog : “Consumer Gmail content will not be used or scanned for any ads personalization after this change” — but “A flight confirmation email you receive may be used to create a ‘check-in’ button that appears in your Gmail” per the current Privacy Policy , and the consumer-Gmail ML-training carve-out for Smart Compose / Smart Reply / Gemini-for-Gmail is not separately disclosed). Yahoo / AOL Mail are TLS-in-transit only; Yahoo’s previous “End-to-End” PGP plug-in initiative was abandoned in 2017.
Yahoo’s 2016 custom government scanner (Reuters disclosure). Joseph Menn, Reuters, 2016-10-04 — Yahoo secretly scanned customer emails for U.S. intelligence — verbatim: “Yahoo Inc last year secretly built a custom software program to search all of its customers’ incoming emails for specific information provided by U.S. intelligence officials… The company complied with a classified U.S. government demand, scanning hundreds of millions of Yahoo Mail accounts at the behest of the National Security Agency or FBI.” The same article carries Google’s response (“We’ve never received such a request, but if we did, our response would be simple: ‘No way.’”) and Microsoft’s (“We have never engaged in the secret scanning of email traffic like what has been reported today about Yahoo.”).
Yahoo’s 2013 and 2014 mega-breaches. SEC settled enforcement In the Matter of Altaba Inc., f/d/b/a Yahoo! Inc. (Admin. Proc. No. 3-18448, 2018-04-24) — the first SEC settlement of a public company for cybersecurity disclosure failure: “Yahoo! to pay a $35 million civil monetary penalty” for failing to disclose the 2014 breach (~500M accounts) under Sections 17(a)(2)/(3) of the Securities Act. The 2013 breach was later revised in October 2017 to all ~3 billion Yahoo accounts; the Verizon–Yahoo 8-K of 2017-02-21 confirmed “Verizon and Yahoo have agreed to reduce the price Verizon will pay to acquire Yahoo’s operating business by $350 million” — reducing the acquisition value from ~$4.83 billion to $4,475,800,000.
Microsoft’s 2023 Storm-0558 / Exchange Online compromise. The U.S. Cyber Safety Review Board’s Review of the Summer 2023 Microsoft Exchange Online Intrusion (CISA, 2024-03-20) concluded — verbatim: “The Board concludes that this intrusion should never have happened. Storm-0558 was able to succeed because of a cascade of security failures at Microsoft, as outlined in this report”; “Microsoft’s security culture was inadequate and requires an overhaul”; Microsoft “failed to detect the compromise of its cryptographic crown jewels on its own, relying instead of a customer”. Scope: “In May and June 2023, a threat actor compromised the Microsoft Exchange Online mailboxes of 22 organizations and over 500 individuals around the world” — including the U.S. Department of State, Department of Commerce (Secretary Gina Raimondo), and U.S. House of Representatives.
Funding model is structurally hostile to privacy. Alphabet’s FY2024 10-K states verbatim “We generated more than 75% of total revenues from online advertising in 2024”; consumer Gmail is the largest acquisition surface for the Google Account → cross-product ID graph → Google Workspace upsell funnel. Yahoo Inc. is privately held by Apollo Global Management since 2021 (NYSE: APO; Apollo’s press release of 2021-09-01 confirmed the $5.0 billion transaction with Verizon retaining a 10% stake) and remains primarily advertising-funded; AOL Mail is operationally consolidated onto Yahoo’s mail backend since the 2021 transfer from Verizon. Apple is not advertising-funded at the corporate level, but its iCloud+ Mail has no zero-access architecture and serves as a device-ecosystem retention surface within Services. Microsoft is licensing/subscription-funded, but Outlook.com remains a Microsoft 365 acquisition funnel and the New Outlook client routes third-party-provider mail through Microsoft 365 servers — “a copy of your email, calendar, and contacts will be synchronized between your email provider and Microsoft data centers”.
Post-2018 GDPR enforcement against Google. CNIL, 2019-01-21 — €50 million against Google LLC — “The CNIL’s restricted committee imposes a financial penalty of 50 Million euros against the company GOOGLE LLC, in accordance with the General Data Protection Regulation (GDPR), for lack of transparency, inadequate information and lack of valid consent regarding the ads personalization”; upheld by Conseil d’État, 2020-06-19. CNIL, 2021-12-31 — €150 million against Google LLC and Google Ireland Limited for cookie-banner design failures.
Worst-in-class non-U.S. free webmail (same structural exclusion). Yandex Mail (Russia) is subject to Federal Law 374-FZ (“Yarovaya law”) — six-month retention of message content + provision of decryption keys to the FSB on demand; SORM lawful-interception integration is mandatory. Yandex N.V. divested its Russian operations to a Russian consortium in 2024, removing the previous Dutch corporate-veil mitigation. QQ Mail (Tencent) and NetEase 163.com are subject to the PRC Cybersecurity Law (2017), Data Security Law (2021), and Personal Information Protection Law (2021); data localization is mandatory and state-security access does not require a judicial warrant; Citizen Lab and Cisco Talos have separately documented keyword-based message filtering on both platforms. mail.com is operated by 1&1 Mail & Media GmbH (the same German legal entity covered in this article’s WEB.DE and GMX entries — both rank HIGH 9), advertising-funded with no E2EE and no built-in PGP, and subject to the German BND-Gesetz compelled-disclosure regime.
Bottom line. Against any per-axis rubric scoring jurisdiction, zero-access encryption, anonymous signup, and funding model, these providers score worst-in-class on every axis simultaneously. The appropriate disposition is structural exclusion with a footnote, not a low numeric score — ranking them on the 0–14 scale alongside privacy-focused providers like Proton, Tuta, Mailbox.org, Posteo, or Disroot would compress the scale and misrepresent the magnitude of the gap.
Skiff (sunset 2024-08-09, acquired by Notion 2024-02-09). Skiff was a US-based provider with one of the strongest technical postures on this list: built-in zero-access encryption that covered email body and subject lines (matching Tuta’s scope), unlimited aliases per custom domain, and explicit anonymous Bitcoin upgrades. It would have scored credibly against the EU-based providers despite US jurisdiction. None of that mattered. Migration page: “All Skiff services, including Mail, Pages, Calendar and Drive, were sunset on August 9, 2024, as part of Skiff’s acquisition by Notion.” Source: skiff.com/data-migration . Mail forwarding terminated 2025-02-09. The takeaway for this article: strong cryptography does not protect against acquisition risk. A privately-held US provider can be acquired and shut down on the buyer’s timetable — the same way Lavabit’s principled posture in 2013 did not keep its service online. Funding-stability weight in the rubric (non-profit foundation or owner-locked structure scoring GOOD0, VC-backed / acquisition-exposed structure scoring BAD+2) exists precisely to surface this risk before it materialises. Proton’s non-profit-foundation primary shareholder and Tuta’s “wholly owned by Matthias and Arne” statements are the structural answer to the Skiff outcome.
CTemplar (shut down 2022-05-26). CTemplar — operated by Templar Software Systems Ltd. (Seychelles LLC per the 2021 footer; the present-day 2026 footer reads only "©2026 Templar Software Systems") — was an Icelandic-hosted OpenPGP provider whose on-paper posture matched the strongest entries in this comparison: physical servers in Iceland (“We host our users’ data on servers in Iceland because this offers the strongest legal protection”), Seychelles-incorporated parent, RSA-4096 OpenPGP zero-access encryption of body / subject / attachments, 7-day anonymous IP retention, instant deletion on account closure (except a 1-year username hold), explicit refusal to comply with anything other than Icelandic court orders (“CTemplar will only comply with valid Icelandic court orders”), anonymous Bitcoin + Monero payment, a Tor onion service, and an explicit warrant canary (“No law enforcement agencies have been here. Watch for this statement’s removal or change”). It nevertheless shut down on 2022-05-26, per the provider’s own announcement (preserved verbatim on multiple mirrors of https://ctemplar.com/ctemplar-is-shutting-down/): “CTemplar is closing and the last day of operation for this email service will be on May 26 of 2022.” A follow-up customer email reproduced at
cyberinsider.com/ctemplar-email-shutting-down-alternatives carried the founder’s reasoning: “When we created this service, we made a promise to ourselves that we would shut down the email service if we couldn’t guarantee our security claims to our users. That day has come, and we would rather shut this service down than make security changes that would have been harmful to you.” The marketing site at ctemplar.com is reachable again in 2026 but the email service is non-functional: the Tor mirror page now shows the onion as “Offline”, the knowledge-base topic pages all read “Nothing found…”, and the original transparency-report URL (https://ctemplar.com/transparency-report-ctemplar/) returns HTTP 404 — a textbook canary-removal-by-disappearance scenario. A separate operational caveat: on 2021-07-09, CTemplar’s own customer email (reproduced at
cyber-privacy.net/ctemplar-catastrophic-incident-with-complete-data-loss-july-2021 ) admitted “a catastrophic technical failure that caused partial data loss, in one way or another, to most customers” — minimal retention turned out to be both a privacy feature and the root cause of the incident. The CTemplar lesson is distinct from Skiff’s: where Skiff illustrates acquisition risk for VC-backed crypto-strong providers, CTemplar illustrates Lavabit-style exit risk for principled solo-operator providers — the founder’s quoted statement is the most direct post-Lavabit echo on this list and arguably more comparable to Lavabit’s 2013 shutdown than to Proton or Tuta, who chose lawful compliance under their respective European frameworks.
Alias and relay services (SimpleLogin, addy.io, Firefox Relay, DuckDuckGo Email Protection). These hand out a throwaway address per site and forward whatever arrives to a mailbox you already own. That makes them a complement to the providers scored above rather than an alternative: a relay controls who learns your real address, while your mailbox host still controls who can read the message. The rubric doesn’t transfer cleanly either, because a service that holds mail only in transit answers different questions than one storing it for years. Relays also move the trust problem rather than removing it. Every forwarded message crosses the relay’s servers, and the category has consolidated toward the same companies scored above: Proton owns SimpleLogin, and Firefox Relay is Mozilla’s. Run one on top of a provider from the ranking. Don’t run one instead of picking a provider, which is why this comparison scores mailbox hosts only.
Functionality & pricing appendix
Functionality and pricing are decision factors but not privacy signals — kept separate so the comparison above stays honest. Click any column header to re-sort.
| Provider | Custom domain tier | Domains per mailbox | Catch-all | Aliases (per domain) | IMAP/SMTP | E2EE | Hardware-key 2FA | Storage (entry) | Price (entry) |
|---|---|---|---|---|---|---|---|---|---|
| Proton Mail | Mail Plus | 1 (Mail Plus) / 3 (Unlimited) / up to 15 (Business) | ✅ (paid plans only) | 10 addresses (Mail Plus) / 15 extra (Unlimited) | ✅ via Bridge only (no POP3) | Built-in E2EE incl. subject | ✅ (FIDO2/U2F) | 15 GB (Mail Plus) | $3.99/mo yearly (Mail Plus) |
| Mailbox.org | Standard (Light in family/team) | No published cap (alias quota is the constraint) | ✅ | 50 (Standard) / 250 (Premium) across all custom domains | ✅ | Built-in (Guard) | YubiKey OTP (not WebAuthn) | 2 GB (Light) | €1/mo (Light) |
| Mailfence | Entry (3.5 EUR/mo, billed yearly) | 2 (Entry) / 7 (Pro) / 10 (Ultra); receive is all-or-nothing per domain | ✅ (per custom domain — designate an existing alias as the catch-all) | Account-wide alias caps shared across domains: 10 / 50 / 100 / 200 (Base / Entry / Pro / Ultra); @mailfence.com alias is non-deletable | ✅ (incl. POP3) on Entry+ (Free + Base have no IMAP/POP/SMTP) | Integrated webclient OpenPGP (server-stored passphrase-encrypted key; 4096-bit default) | ❌ (TOTP + backup codes only) | 1 GB Free / 11 GB Base / 40 GB Entry / 78 GB Pro / 225 GB Ultra | Free; €2.5/mo Base; €3.5/mo Entry (~42 €/yr); €9.5/mo Pro; €29/mo Ultra |
| Tuta | Revolutionary | 3 (Revolutionary) / 10 (Legend) / Unlimited (Business Unlimited) | ✅ | Unlimited on custom domain (15 extra on Tuta domain) | ❌ (by design — own clients only) | Built-in E2EE incl. subject lines | ✅ (U2F/FIDO2) | 20 GB (Revolutionary) | €3/mo yearly (Revolutionary) |
| Infomaniak kMail | Mail Service (paid Service Mail, single address from CHF 2.29/mo) | Multiple via “linked domain” / “alias domain” mechanism (no hard numeric cap stated); MX takeover is per-Mail-Service | ✅ on paid Service Mail (except Starter) and all paid kSuite tiers | 50 per address on kSuite Standard/Business/Enterprise and Mail Service Premium; 1 on Starter and kSuite free; "+ addressing" wildcard works in addition | ✅ (incl. POP3) | Opt-in per-message OpenPGP (server-side, Infomaniak holds keys) | ✅ — YubiKey explicitly named; kAuth push + TOTP + SMS (CH/FR/BE/DE only) | Unlimited on all paid plans; 20 GB on my kSuite free | CHF 2.29/mo Mail Service single-address; CHF 1.76/user/mo kSuite Standard annual; prices ex-VAT |
| Kolab Now | Just Email (CHF 5.00/mo) — custom domain free; full groupware at CHF 9.90/mo (5 + 4.90 add-on) | First private domain free; each additional CHF 0.50/mo (no published numeric cap); full MX takeover required (mx0{1,2}.kolabnow.com); external-domain aliases forbidden | ✅ (per domain — manual catchall@yourdomain.tld alias, repeated for each domain) | Per-domain alias cap not stated | ✅ (incl. POP3) + CalDAV / CardDAV / WebDAV / ActiveSync — but enabling 2FA disables all of them (web-client-only) | Webclient OpenPGP with server-stored keys; provider explicitly admits “Providing true end-to-end encryption can only really be achieved by client encryption” | ❌ (TOTP only — and enabling it disables IMAP/POP/DAV/ActiveSync entirely) | 5 GB (Just Email); +1 GB per CHF 0.25/mo | CHF 5.00/mo (Just Email) / CHF 9.90/mo (full groupware); 30-day trial, no free tier; wallet-based billing |
| Posteo | ❌ — refuses by design | GOOD0 — no custom domains, ever | N/A | 2 free + 18 paid @ €0.10/mo each on Posteo domain (cap 20) | ✅ (incl. POP3) | Built-in opt-in (Krypto-Mailspeicher) | Not stated (TOTP confirmed) | 2 GB (default, expandable) | €1/mo flat |
| CounterMail | Premium (custom domain via $15 one-time bolt-on; no separate “with custom domain” tier) | Multiple per premium ($15 one-time per domain, MX-takeover required; “You can purchase multiple domains to a single premium account”) | ❌ — explicitly forbidden (“We do not allow catch-all addresses, due to abuse”; FAQ #25); only forced exception is abuse@yourdomain.com | 10 aliases at provider domain (“up to 10 different aliases (@cmail.nu copies will be automatically added), which gives you a total of 20 aliases”); domain aliases “unlimited on their own domain” but same-domain only — no cross-domain alias span | ✅ IMAP + SMTP (port 993 SSL / 465 SSL on imap1.countermail.com); POP3 not stated in any CounterMail document | Built-in OpenPGP zero-access for body + attachments (RSA-4096); full-disk encryption on mail server; subject + From/To/Date headers + folder names plaintext | TOTP + proprietary USB keyfile (webmail-only); WebAuthn/FIDO2 not stated; SMS not stated in provider’s own docs | 4 GB (sole premium tier — “Premium subscriptions includes 4 GB of encrypted storage data for emails”); extra storage one-time $19 / 250 MB ↗ $89 / 1750 MB | 6 mo: $29 ( |
| StartMail | Personal ($4.99/mo) | 1 (Personal) / Unlimited (Business) | ✅ | Unlimited domain aliases per custom domain | ✅ (no POP3) | Vault at-rest + opt-in OpenPGP (server-stored key) | ❌ (TOTP only) | 20 GB (Personal) / 30 GB (Business) | $4.99/mo, $59.88/yr (Personal); $6.99/mo, $83.88/yr (Business) |
| Eclipso | Business (€4.99/mo) | 1 mail domain included; additional domains not documented | Not stated | 0 / 10 / 24 / 50 aliases per account (Freemail / Connect / Premium / Business) | ✅ (incl. POP3) | Server-side OpenPGP + S/MIME (natively integrated; private key passphrase-encrypted in the account) | ❌ (TOTP only) | 4 GB Freemail / 20 GB Connect / 40 GB Premium / 100 GB Business | Free; €0.99/mo Connect; €1.99/mo Premium; €4.99/mo Business (paid in advance, 12-month minimum on Connect/Premium, 6-month on Business) |
| Murena Mail | ❌ — no consumer custom-domain tier yet (Workspace plans page lists 20 GB → 2 TB without custom domains); announced only as Business-tier roadmap “if desired” | GOOD0 today on consumer tiers; announced as Business-tier feature | ❌ (not documented under “catch-all” / “wildcard alias” / *@ — no custom-domain support to attach catch-all to) | Every account gets both @e.email and @murena.io form of username (free); paid 20 GB / 64 GB tiers list 5 Hide My Email aliases each; free tier historical “1” alias (current count not stated explicitly on pricing page) | ✅ IMAP + SMTP (mail.ecloud.global, 587 STARTTLS + 993 SSL); POP3 not stated | None native — opt-in OpenPGP via SnappyMail + Mailvelope in webmail and OpenKeychain in the /e/OS Mail app; Nextcloud server-side encryption on files; Murena Vault E2EE via Cryptpad (documents only) | ❌ TOTP only (per doc.e.foundation/support-topics/two-factor-authentication ); WebAuthn / FIDO2 / SMS not stated | 1 GB free (“FREE ACCOUNT”); 20 GB “1,99€ / month” or “19,90€ / year”; 64 GB at €3.99/mo; up to 2 TB at €24.99/mo | Free 1 GB (donation-supported, mandatory non-Murena recovery email + hCaptcha); 20 GB € 1.99/mo or €19.90/yr; payment via Stripe / PayPal / BitPay (Bitcoin) — “We use Stripe, PayPal and Bitpay to process payments on this website”; SEPA + cash not stated; built-in Google migration tool (Gmail / Drive / Photos / Contacts / Calendar) |
| Vivaldi Mail | ❌ — no custom-domain support (“Vivaldi.net webmail accounts don’t support custom domains” per Vivaldi staff) | GOOD0 | ❌ (not stated as supported; no custom-domain support to attach catch-all to) | 0 real aliases — “different aliases, unfortunately, can’t be used. But… you may use plus addressing (also known as sub-addressing)” (username+keyword@vivaldi.net); 10 GB single mailbox at @vivaldi.net | ✅ IMAP + POP3 + SMTP (imap.vivaldi.net 993 SSL / pop3.vivaldi.net 995 SSL / smtp.vivaldi.net 465 SSL) | None native (mail body not encrypted at rest by default per Vivaldi staff post; opt-in OpenPGP via Roundcube + Mailvelope, key on Vivaldi’s webmail server — “someone with access to both could theoretically decrypt it”) | ✅ TOTP + security key (WebAuthn/FIDO2) + recovery codes + app passwords; SMS not offered | 10 GB free mailbox (“In Vivaldi mail each account gets 10GB of storage space”) | Free for “active Vivaldi Community members” — gated by an opaque reputation system since May 2023 (“details about how the reputation system works are not shared publicly”); no paid tier; the email-signup page actively recommends “Proton Mail — From €3/month” and “Fastmail — From $5/month” as paid alternatives |
| Hostpoint | Cloud Office Basic | Multiple per Cloud Office group (no published cap); aliases stay same-domain | ❌ — “Hostpoint does not offer catch-all addresses” | Same-domain aliases only; no published numeric cap; alternative email addresses inside the same domain | ✅ (incl. POP3) | None — TLS in transit + generic “encrypted where possible” at rest | ❌ (TOTP only, control-panel only — not per-mailbox) | 15 GB (Basic) / 50 GB (Plus) / 100 GB (Business) — extendable to 500 GB | CHF 2.00/mo 1st-year promo (Basic), CHF 3.00/mo thereafter; prices incl. VAT |
| Inbox.eu | Business Premium (€9.99/user/year) | One AOP account manages all domains via admin panel (“Use one Inbox.eu account to manage all your domain mailboxes”); no published numeric ceiling; full DNS/MX takeover required (4 verification methods) | ✅ — but paid Business custom-domain plans only (“The Catch-all feature is available only for domains with a paid subscription”); existing addresses take precedence over the catch-all | 5 email aliases per Business Premium mailbox (1 on Trial); same-domain only — cross-domain alias use not documented | ✅ (incl. POP3 + APOP) — disabled by default, opt-in toggle in “Email forwarding, mail programs, SMS alerts” | None — “E2E encryption” in marketing = TLS in transit only per the help-center article; no PGP / S/MIME | ❌ (TOTP via authenticator app only; WebAuthn/SMS not documented) | 100 GB (Personal Premium + Business Premium); Business adds 100 GB shared/domain | €9.99/user/year Business Premium (€0.83/mo equiv.); €9.99/year Personal Premium; 30-day trial outgoing-mail-capped (3/day); Visa/Mastercard via First Data + PayPal + Swedbank/SEB bank transfer/invoice — no card data stored, no crypto, no cash |
| Migadu | All paid plans | Unlimited per account | ✅ | Unlimited within plan quotas | ✅ (incl. POP3) | None | ❌ (no mailbox 2FA at all) | Soft limits (no hard cap) | $19/yr Micro (~$1.58/mo) |
| Runbox | Micro (€19.95/yr) | 1 (Micro) / 5 (Mini) / 10 (Medium) / 25 (Max) | ✅ (per hosted custom domain; full MX takeover required) | Unlimited aliases on user-owned domains; 100 free aliases on @runbox.com regardless of plan | ✅ (incl. POP3); FTP for Files; CalDAV/CardDAV | None built-in (encrypted-SSD hardware + opt-in 3rd-party PGP) | ❌ (TOTP + OTP only; YubiKey/U2F “planned” since June 2017) | 2 GB email (Micro) | €19.95/yr Micro (~€1.66/mo); annual only — no monthly billing |
| GMX | Free FreeMail (ad-financed) — paid ProMail / TopMail offered only to DE/CH/AT residents on gmx.net | 1 (FreeMail itself, no custom domain on gmx.com); German-market “GMX Domain & Mail” sold as forwarding into FreeMail, “500 E-Mail-Adressen” per registered domain | Not stated — searches across gmx.com for “catch-all” / “wildcard alias” return nothing | Up to 10 GMX-TLD aliases per account (“gmx.us / gmx.co.uk / gmx.ca …”); cross-domain selection within GMX’s own TLDs only — no other-domain aliases | ✅ (incl. POP3) — disabled by default, opt-in toggle required; app-specific password mandatory after 2FA | None — opt-in via third-party Mailvelope browser extension (Chrome/Firefox only) | ❌ (TOTP only — “the six-digit code is also known as a ’time-based one-time password’ (TOTP)”; WebAuthn/FIDO2 not stated; SMS at enrollment only) | 65 GB (FreeMail) | Free FreeMail + 50 MB attachment cap; ProMail €3.99/mo (DE/CH/AT only); TopMail €6.49/mo; ProMail + 500 GB Cloud bundle €8.48/mo; payment SEPA-Lastschrift / PayPal / Visa / Mastercard / Amex — no crypto, no cash |
| Mailo | Any paid Mailo space (Pro/Family/Asso/Edu) | “Several” per space — no numeric cap stated | ✅ | 5 Free / 100 paid per mailbox (no per-domain cap stated) | ✅ (POP3 on Premium only) | Opt-in OpenPGP (server-stored keypair) | ❌ (TOTP only; FIDO2/SMS not offered) | 1 GB Free / 20 GB Premium | Free; €1/mo Premium; €3/mo HT Pro Start |
| Riseup | ❌ — no custom-domain hosting; third-party-domain aliases are sender-only and discouraged | GOOD0 — no custom-domain hosting | ❌ (not documented) | Riseup-domain aliases unlimited (no numeric cap stated); cap shared with username pool | ✅ (incl. POP3) — also reachable via Tor onion service | Personally-encrypted storage for new accounts since March 2017 (server unwraps key per session) | ❌ (no Roundcube 2FA; account-level not documented) | 1 GB (quota-increase by ticket) | Free — donations “asked” via card / PayPal / Liberapay / cash / Monero / Zcash / Bitcoin |
| Seeweb | Entry Cloud Mail (5 GB + 5 caselle, 10 €/year + VAT per Seeweb sysadmin quoted in CWI) — custom domain mandatory at every tier | One AOP customer login aggregates “più servizi per tutti i domini che vuole”; entry SKU attaches to one domain (MX-only takeover, “sarà possibile modificarne solo i record mail”); no published per-account ceiling | ❌ (not documented — no “catch-all” / “wildcard” / "*@dominio" reference on seeweb.it, docs.seeweb.it or blog.seeweb.it) | Per-domain alias cap not stated; documented cross-domain workaround is mailbox forwarding (“inoltro”) | ✅ (incl. POP3) — STARTTLS on 143/110/587 + SSL on 993/995/465 | Server-side plaintext (content-level antispam/AV inspection + IBM Spectrum Protect daily backups); opt-in client-side PGP in Roundcube | ❌ (Not stated — aop.seeweb.it blocked by robots.txt; 2FA referenced abstractly in marketing only) | 5 GB (entry) → 1,280 GB (max); mailbox count scales with storage | 10 €/yr + VAT (5 GB / 5 caselle) per Seeweb sysadmin via CWI; product page shows only JS placeholder “Totale Annuale 0,00 €”; monthly billing only from 80 GB; 12-month minimum; payment PayPal / SEPA-RID / bank transfer only — no credit cards, no crypto, no cash; paid migration 63.50 €/10 mailboxes; WhiteLabel 45.50 €/mo |
| WEB.DE | Free FreeMail (ad-financed, mandatory weekly newsletter) — paid MailPlus / Club / Club 100 only via German market | 1 (FreeMail itself, no custom domain by default); separate “WEB.DE Homepage & Mail” SKU registers and forwards into FreeMail; per-domain alias cap conflict (50 on help page vs. 500 on marketing page) | Not stated — searches for “Catch-all” / “wildcard alias” / "*@domain" return nothing | Extra @email.de addresses + bonus TLDs on MailPlus / Club only, count never published on web.de (FreeMail = 1 standard address); deleted aliases blocked 5 years | ✅ (incl. POP3) — opt-in toggle required; app-specific password mandatory after 2FA | None — opt-in via third-party Mailvelope browser extension (Chrome/Firefox only) | ❌ (TOTP only via “Authentifzierungs-App”; WebAuthn/FIDO2 not stated; mobile-number used for recovery, not as login factor) | 1 GB mail + 4 GB cloud (FreeMail); 5 GB mail + 5 GB cloud (MailPlus) | Free FreeMail + 20 MB attachment cap; MailPlus €3.99/mo + 100 MB attachments; Club €6.49/mo; Club 100 €7.99/mo; 13-month minimum incl. one-month trial; payment via Rechnung / Lastschrifteinzug / Kreditkarte (SEPA + PayPal + Visa/Amex/Mastercard) — no crypto, no cash; account-recovery via IDnow Autoidentverfahren or eID |
| Disroot | Donation perk (“lifetime reward”) | Not stated | Not stated | Plus-addressing on @disroot.org (e.g. user+tag@disroot.org); discrete aliases not documented | ✅ (incl. POP3) | None — user-managed PGP only | Not stated (no 2FA documented for email) | 1 GB free email (+2 GB cloud, 500 MB CryptPad) | Free; storage upgrades 11€/yr (5 GB) up to 110€/yr (60 GB), split between mail and cloud |
| Gandi Mail | Any paid mailbox (domain must be at Gandi) | 1 — aliases are same-domain only; cross-domain requires forwarders | ✅ (via wildcard alias) | Unlimited aliases / 1000 forwards per domain | ✅ | Customer responsibility | Not stated | 10 GB (Standard) | €4.99/mo (Standard) |
| Iroco | Collective (organisation) tier only — from 3,60 € TTC/mo; Individual is @iroco.co / @iroco.io only | Collective: “Autant de boîtes mail que nécessaires” with “usage raisonné”; per-domain cap not stated | ❌ (not documented — no “catch-all” / “fourre-tout” / “wildcard” / *@ reference anywhere on iroco.co) | 50 on Individual (via +suffix plus-addressing); “as needed” on Collective | IMAP + SMTP ✅; POP3 not documented; CalDAV + CardDAV ✅ | None — only the user password is “stored in encrypted form”; no PGP / S-MIME integration | ❌ (TOTP only) | 5 GB (Individual); 5–100 GB configurable (Collective) | 3,60 € TTC/mo Individual; Collective from 3,60 € TTC/mo; SEPA via GoCardless only — no cards/PayPal/crypto/cash; no free tier (trial removed Jan 2025) |
| Combell | Basic Professional | Multiple domains attachable, but aliases are same-domain only (cross-domain only via per-alias forwarding to another mailbox) | ✅ (per domain) | Unlimited aliases (per domain) — “Combell allows you to create an unlimited number of e-mail aliases” | ✅ (incl. POP3) — servers on mailprotect.be | None — TLS + generic “hard disk encryption software”; no PGP / S/MIME | ❌ (TOTP via Duo Mobile or any TOTP app — Combell control panel only) | 5 GB (Basic Professional) / 50 GB (Expert+) / 100 GB (Ultimate) | €2.99/mo 1st-year promo Basic Professional, €4.49/mo thereafter; ex-VAT; annual term; 90-day money-back |
| Raidboxes | Mail Mini | 1 — “Maximum number of connected domains: 1” on all three tiers; aliases are same-domain only | ✅ (on the one connected domain) | 5 / 10 / 15 aliases per mailbox (Mini / Starter / Pro); 50 / 100 / 150 redirects to external addresses | ✅ — mail-rb.securemail.pro / smtp-rb.securemail.pro; POP3 not stated on the new platform | None — *“PGP encryption | Optional”* (key custody undisclosed); no zero-access claim | ❌ (TOTP via Authy / email / SMS via Twilio; no WebAuthn/FIDO2) | 3 GB / 10 GB / 25 GB (Mini / Starter / Pro) shared across 3 / 10 / 25 mailboxes |
| Soverin | Single tier (mailbox + custom domain available on the standard paid product) | Not stated (numeric cap absent; “Multiple domains” marketed but no ceiling) | ✅ (domain-level, mailbox-routed) | “as many aliases as you’d like, free of charge” per owned domain | IMAP + SMTP ✅; POP3 not documented | None — TLS + disc encryption only; per-user encrypted backups | ❌ (TOTP only; no WebAuthn/FIDO2/SMS) | 25 GB | €3.25/mo billed annually (~€39/yr mailbox alone; ~€52/yr with .nl domain bundled) |
| Fastmail | Standard+ | 100 (freely create users/aliases across all) | ✅ (wildcard alias) | 600 total aliases (across all domains) | ✅ | None in own apps | ✅ (security keys) | 6 GB (Basic) / 60 GB (Individual) | $4/mo (Basic), $6/mo (Individual) |
| Hushmail | Healthcare / Small Business / Law plans | 1 — docs refer to “your domain” singular; all-or-nothing MX takeover | ✅ | Unlimited | ✅ | Server-side PGP (webmail) | ❌ (SMS / TOTP / email backup only) | 10–15 GB | $5.99/mo (Personal) / $11.99/mo (Healthcare Starter) |
| Lavabit | Contact-based setup (no tier disclosed) | Not stated | Not stated | Not stated | ✅ (IMAP / POP / SMTP in Trustful mode) | Opt-in “secure” mode (at-rest, passphrase); DIME zero-access modes still “in development” | Not stated | Not stated | Not stated on public site |
| MXroute | All plans | Unlimited | ✅ (discouraged) | Unlimited | ✅ | None | Not stated | 10 GB | $59/yr ($4.92/mo) |
| Namecheap Private Email | All paid Private Email plans (Starter / Pro / Ultimate) | Not stated | ✅ (per Private Email mailbox + DNS-level catch-all on Email Forwarding) | 10 / 50 / Unlimited aliases per mailbox (Starter / Pro / Ultimate) | ✅ (incl. POP3) | None | ✅ (U2F — Yubikey-style; TOTP also supported) | Starter: 5 GB email + 2 GB files | $14.88/yr Starter (~$1.24/mo); $35.88/yr Pro; $55.88/yr Ultimate |
| Zoho Mail | Free (1 domain, web-only) / Mail Lite (multi-domain + IMAP) | Up to 30 per organization | ✅ | 30 aliases per primary mailbox | ✅ (incl. POP3) on paid; ❌ on Free | None default; opt-in PGP (Premium); S/MIME (Premium) | Not stated (TOTP + SMS via OneAuth) | 5 GB (Free) / 5–10 GB (Mail Lite) | Free tier exists; $1/user/mo annual (Mail Lite) |
Notes:
- Domains per mailbox is the key axis for identity compartmentalization: how many separate custom domains can land in one inbox. Gandi and Hushmail effectively force one-mailbox-per-domain (workable only via forwarding, which breaks outbound sending). MXroute, Fastmail, Migadu, Mailbox.org and Zoho all consolidate cleanly. Posteo is the only provider that refuses custom domains entirely as a privacy-by-data-minimisation choice.
- Mailbox.org’s entry tier (Light, €1/mo) does not include custom domains except in family/team accounts; first standalone tier with custom-domain support is Standard at €3/mo.
- Hushmail Personal does NOT support custom domains; cheapest plan with custom domain + catch-all is Hushmail for Healthcare Starter at $11.99/mo.
- Tuta has no IMAP, POP3, or SMTP for third-party clients — they argue these protocols would force decrypting on the server side and would break their E2EE model. You must use Tuta’s own web, desktop, or mobile apps.
- Migadu does not host email on its own domains — custom-domain-only by policy. The inverse of Posteo.
- Zoho Mail Free is unique in offering custom-domain hosting (1 domain, up to 5 users) at no cost, but without IMAP/POP/ActiveSync — locking you to web + mobile apps until you upgrade to Mail Lite ($1/user/mo annual).
- StartMail Personal caps custom domains at 1; you need the Business plan ($6.99/mo, $83.88/yr) for unlimited domains. Bitcoin payment is only available on annual plans, not monthly or group subscriptions.
- Mailo’s alias limits (5 Free / 100 paid) are per-mailbox totals across all domains, not per-domain. Mailo also asks for first/last name + DOB at signup (DOB is verified for 16+); these aren’t validated against documents but the signup flow does not support pseudonyms the way Mailbox.org’s does.
- Lavabit’s public docs leave most comparison fields blank — no pricing tier, no storage, no alias counts, no catch-all confirmation, no 2FA documentation. The “secure” tier offers at-rest encryption only; DIME’s stronger zero-access modes (Cautious / Paranoid) and the Volcano client have been “in development” since 2017.
- Disroot’s custom-domain feature is intentionally lightly documented — it’s offered as a donation perk (“lifetime reward”) rather than a tiered plan. The provider docs do not state the per-account domain cap, whether aliases can span domains, catch-all support, or whether full-domain MX takeover is required. Disroot also does not document any account-level 2FA for the email service; users wanting hardware-key MFA need to look elsewhere.
- Namecheap’s alias caps are per-mailbox, not per-domain — 10 / 50 / Unlimited on Starter / Pro / Ultimate. The maximum number of separate custom domains per account is not stated. Catch-all is available two ways: via the free DNS-level Email Forwarding (one catch-all per domain, forwards to a single destination) and inside Private Email itself (one mailbox designated as the domain’s catch-all). Namecheap is the cheapest provider in this comparison ($14.88/yr Starter) — and the only US registrar-bundled mailbox that accepts Bitcoin.
- Eclipso gates custom domains behind the Business tier — “Important: eclipso Business tariff is required to use your own mail domain with your eclipso Account”; “1 Mail domain included” on Business with no documented cap on additional domains. Aliases are counted per account, not per domain (0/10/24/50 across Freemail/Connect/Premium/Business). Catch-all is not mentioned anywhere in Eclipso’s docs (searching for “catch-all”, “wildcard alias”, and
*@domainall return nothing) — assume unsupported until proven otherwise. Custom-domain setup uses full MX delegation tomail.eclipso.de; per-address hosting without changing the MX is not documented. Paid plans bill in advance for the booked period (no monthly subscription; cancellation possible in advance of renewal). - Riseup is the only provider in the comparison that refuses to be a paid service — donations are “asked” but accounts are free, including the 1 GB mailbox. There is no custom-domain hosting, no catch-all, no automated migration tool, and no documented account-level 2FA (Roundcube’s plugin was explicitly removed). Mail is reachable via clearnet IMAP/POP/SMTP and via a Tor onion service on the same ports — useful if your local network blocks Riseup or you want to access mail without revealing your IP. Signup is invite-only (codes generated from existing accounts at
account.riseup.net). - Soverin treats custom-domain support as a baseline feature, not a tier upgrade — every paid account can attach a custom domain (~€52/yr with a
.nlbundled). The provider explicitly documents catch-all per domain in the dashboard (“Choose the catchall mailbox or select ‘reject (bounce) such mail’ to disable this feature”). Aliases on owned domains are “as many … as you’d like, free of charge”; there is also a free anonymous alias on the shared@sinenomine.emaildomain (“a free randomly generated alias for your mailbox on our @sinenomine.email domain that can not be tracked back to your real email address”). Soverin does not ship a mobile app (“Soverin doesn’t have an own app”) and does not document POP3 — IMAP / SMTP only. - Infomaniak kMail is the only provider in this comparison whose paid entry tier ships unlimited mail storage — every paid plan (Mail Service single-address from CHF 2.29/mo, kSuite Standard CHF 1.76/user/mo annual) lists “Email storage mail unlimited”. The free “my kSuite” gives 20 GB email + 15 GB kDrive “for life” but is restricted to a published list of 37 countries and “requires a valid European mobile number”. Custom-domain mail consolidation is via “linked / alias domain” — a single Mail Service can host many owned domains, but all share one MX takeover. Native YubiKey support (alongside Infomaniak’s own kAuth push, TOTP, and geo-restricted SMS) is unusual for a non-privacy-first provider. 2FA scope: the documented 2FA protects the Infomaniak Manager / Control Panel login, not individual IMAP/SMTP mailbox sessions.
- Hostpoint is the only Swiss-jurisdiction provider in this comparison that refuses catch-all — “Info: Note: Hostpoint does not offer catch-all addresses”, repeated since at least 2015 on the company’s official Twitter. Bundled with web hosting, “Cloud Office Limited” gives unlimited mailboxes (5 GB each) but excludes Hostpoint Drive and Cloud Office Documents. Backup retention scales with the tier: 30 / 90 / 180 days (Basic / Plus / Business), with self-restore for 30 days after deletion before permanent purge. Cloud Office Plus and Business are required for catch-all of any kind — “UNAVAILABLE with kSuite free, my kSuite / my kSuite+, Service Mail Starter” applies to Hostpoint’s product analogues. No native first-party Hostpoint mail app — the Cloud Office UI is delivered as a PWA plus Exchange ActiveSync into device-native clients. 2FA is TOTP-only and protects the Control Panel login, not per-mailbox IMAP/SMTP.
- Runbox is the only paid provider in this comparison that bills annual-only — there is no monthly subscription; Micro (€19.95/yr ≈ €1.66/mo) is already cheaper than the entry tier of every other custom-domain-capable provider here. Per-domain mailbox quotas scale with the plan: 1 / 5 / 10 / 25 custom domains across Micro / Mini / Medium / Max, each with unlimited aliases on the owned domain. Plus-addressing works on the provider domain without setup (“if your username is zorro, you can already receive email sent to
zorro+whatever@runbox.com”). All paid plans get 100 free aliases on
@runbox.com. Bitcoin (direct wallet) and Coinbase Commerce are both accepted; cash by mail is documented but discouraged. The “Runbox 7 webmail” remains in public beta as of May 2026 (over 7.5 years since its November 2018 launch); native PGP and FIDO2 are both still “planned”. - Combell forces same-domain aliases despite supporting multiple domains per account — Exchange aliases are “internal because the referral takes place within the same domain name”. Cross-domain delivery is possible only via per-alias forwarders to another mailbox (with a different MX). All Combell mailboxes require a customer-owned domain (“No more @telenet.be, @gmail.com, etc.”); there is no provider-domain free address. Catch-all is documented per domain, and aliases are “unlimited” per Combell’s own blog. The mailservers are on
*.mailprotect.be(Belgium) rather than oncombell.com. The Combell NL entity (combell.nl) contracts under Dutch law; combell.com under Belgian law — same product, two governing-law clauses depending on which storefront you signed up via. - Raidboxes’ “Server location Germany” claim is contradicted by its own Help Center — IMAP/SMTP endpoints are
mail-rb.securemail.proandsmtp-rb.securemail.pro, whose TLS certificate is issued to “O=Register S.p.A., VIALE GIOVINE ITALIA 17” (Florence, Italy — a team.blue sibling). The 26 August 2025 migration off Mailbox.org moved customers onto this team.blue-internalsecuremail.proinfrastructure. Plan caps are aggressive for identity compartmentalization: 1 connected domain across all three tiers, same-domain aliases only, 5/10/15 aliases per mailbox, and 50/100/150 forwardings (redirects to external addresses) per mailbox. No native mobile app, no PayPal, no crypto, no cash; payment is SEPA (GoCardless) or credit card (checkout.com) only. 2FA tops out at TOTP, email, or SMS (Twilio Ireland) — no WebAuthn/FIDO2. Migration to Raidboxes Email 2.0 from external providers is via the paid Audriga service; no free self-service Gmail/IMAP import is documented for the new platform. - Mailfence shares one account-wide alias pool across all custom domains — the Entry plan’s 50 aliases are not per-domain, they’re per-account, and the same number applies whether you’ve configured one custom domain or seven. Catch-all is implemented by designating an existing user/alias as the destination for a given domain rather than via a wildcard syntax (
*@example.comdoes not exist as a Mailfence concept). Receive is all-or-nothing per domain — the whole domain’s MX must point to Mailfence — but Mailfence does support sender-only configurations (“if you prefer to use addresses based on your domain exclusively for sending emails, not for receiving”). The@mailfence.comalias (and its short@mf.mevariant) cannot be deleted: “To protect our users from identity impersonation attacks, and our service from abuse, we have decided to forbid deletion of Mailfence domain name based alias addresses.” - Kolab Now’s TOTP 2FA disables IMAP, POP, ActiveSync, CalDAV, CardDAV and WebDAV entirely — “User accounts that have 2FA enabled in the subscription will only be able to use the web client. All other clients will be blocked at the IMAP, POP, ActiveSync, CalDAV, CardDAV and WebDAV level.” This is the largest functional regression of any provider in this comparison: you can have 2FA or you can have third-party email clients, but not both. Bitcoin payment has been “suspended” since at least 2020 with no current re-enable date, so anonymous payment is structurally unavailable; PayPal / credit card / bank transfer are the only options. There is no native iOS/Android Kolab Now app — sync is via ActiveSync + CalDAV + CardDAV + IMAP through third-party clients. Catch-all exists per-domain but as a “create an alias named
catchall@yourdomain.tld” manual configuration, not a wildcard. External-domain aliases are explicitly forbidden: “we do not allow external aliases from domains that are not linked to our servers, or domains that are not under our users’ control (e.g. gmail.com, hotmail.com or yahoo.com).” - Iroco is the only provider in this comparison that explicitly blocks Tor at signup — “nous n’autorisons pas l’inscription avec une adresse TOR”. Block is the result of the January 2025 Russian-spam abuse incident, which also led Iroco to drop its free trial and switch to SEPA-direct-debit-only billing via GoCardless (UK Companies House no. 07495895). Custom domains are restricted to the Collective (organisation) tier; the Individual tier is permanently
@iroco.co/@iroco.io. The catch-all feature is not documented anywhere oniroco.co, the FAQ, the blog, or the Doc page (no “catch-all” / “fourre-tout” / “wildcard” /*@reference) —+suffixplus-addressing is the only documented alias mechanism. No native mobile app, no migration tools, no POP3 documentation, no transparency report, no warrant canary. The provider is small (2-10 employees, 2 000 € share capital) — funding is bootstrapped + one BPIFrance Innov’Up Faisabilité grant. - Inbox.eu publishes “End-to-end encryption” as a Premium feature but defines it as TLS in transit only. The help-center article of that name reads: “Our service supports encryption in transit using TLS (Transport Layer Security) by default.” There is no PGP, no S/MIME, no zero-access vault; the provider explicitly retains the ability to inspect content “in response to a valid legal request submitted through the appropriate international legal channels, including Interpol where applicable”. Two further marketing-vs-binding-docs conflicts to surface: the marketing FAQ promises deletion “within 7 days” but Privacy Policy §5.1 binds “within one year”; and the marketing privacy page asserts “we do not store or share your personal information with third parties – neither government agencies nor advertisers … And we never will” while ToS §4.6 expressly authorises disclosure to “subpoenas, court orders or requests from official bodies”. Aliases are same-domain only (5 per Business Premium mailbox); custom domains require full DNS/MX takeover (4 verification methods); catch-all is the one feature gated to paid Business plans only. No transparency report. No standalone DPA — only the one-clause processor stance in ToS §9.3 (“INBOX as the data repository is the processor”). Inbokss owns sister consumer products
inbox.lv,inbox.lt,mail.eeon the same platform — and the 2024 Baltcom→Inbokss customer migration brought additional Latvian/Bite-Latvija mailboxes onto Inbox.eu’s infrastructure. - GMX and WEB.DE are the same legal entity (1&1 Mail & Media GmbH) but the entity-level Jahresbericht lives only at the WEB.DE-branded URL. Searches across
gmx.com,gmx.net,mail-and-media.com, andunited-internet.defor a transparency report return nothing — the 2025 figures (37,174 subscriber-data / 2,816 traffic-data / 608 content-data / 1,681 G10/§100a orders against 46.32M mailboxes) are accessible only viaweb.de/impressum/. Both products rely on opt-in third-party Mailvelope (Chrome/Firefox only) for any encryption — the webmails themselves have no native PGP. Both require a working mobile-phone number at signup; account recovery uses IDnow Autoidentverfahren or the German Personalausweis eID. Free FreeMail (WEB.DE) and GMX FreeMail are both ad-financed under a “Consent or Pay” model — WEB.DE bundles a “non-cancellable” weekly newsletter into the free tier (“Der Newsletter kann nicht abbestellt werden, da er den FreeMail Dienst mitfinanziert”). Paid tiers exist only on the German-languagegmx.netandweb.deproperties — and GMX’s paid tiers (ProMail / TopMail) are restricted to DE/CH/AT residents, leaving English-languagegmx.comusers with no upgrade path. Custom domains are a separate SKU (WEB.DE / GMX Domain & Mail) sold as forwarding-into-FreeMail, not a true BYO-domain MX takeover for end consumers. Per-domain alias caps conflict between WEB.DE’s own help page (50) and its marketing page (500). 2FA tops out at TOTP — no WebAuthn/FIDO2. - CounterMail is the strongest built-in OpenPGP product in this comparison, but its corporate identity is opaque and it is effectively unpurchasable in 2026. RSA-4096 zero-access encryption of message body and attachments is the default for every premium account — the private PGP key is stored anonymously on the server and decrypted only by the user’s zero-knowledge-proof password (“This means that we can’t give out any private key even if someone forced us”). Full-disk encryption on the mail server. But: the footer reads only "©2021 CounterMail.com. All rights reserved." with no legal entity name, organisationsnummer, or registered address published anywhere on
countermail.com; a Swedish open-registry search did not surface a matching company. Signup has been invite-only since 2020-11-01 and the homepage reads “Service is closed for new registrations!”; Bitcoin was disabled for new accounts on 2024-06-18 with the changelog warning “All types of Crypto payments will be stopped before the end of this year”. Cash wire transfer + prepaid VISA/Mastercard remain documented but are an awkward workaround. Catch-all is explicitly forbidden on every tier (“We do not allow catch-all addresses, due to abuse”); only forced exception is theabuse@yourdomain.comaddress. Headers (From / To / Subject / Date) and folder names remain plaintext by CounterMail’s own admission — “The reason for this is that the SMTP & IMAP protocols can not handle encrypted headers or foldernames.” No transparency-report numbers (only an FAQ-titled posture statement), no warrant canary, no notification commitment, no DPA, ~214-word privacy policy. POP3 not documented; only IMAP/SMTP listed in the email-client FAQ. No native mobile mail app. The 2025-11-03 corrupt-filesystem incident (“First time this happened in our 15 year history”) followed years of documented DDoS/firmware/datacenter outages on the changelog. - Murena Mail is a community-tier webmail attached to the /e/OS degoogled-Android ecosystem, hosted at Hetzner Helsinki HEL1 (Finland sits outside 5/9/14 Eyes) — but mail itself is not zero-access. Files have Nextcloud server-side encryption with off-site backups in Falkenstein DE (“every copy is kept for seven days” same-DC, “up to three months” off-site); the separate Murena Vault provides Cryptpad-based E2EE for documents only. Mail is opt-in OpenPGP via SnappyMail webmail + Mailvelope (or OpenKeychain in the /e/OS Mail app) — Murena’s own roadmap acknowledges “True end-to-end encryption … for mails is in our plans as long-term features.” Every account gets both
@e.emailand@murena.ioforms of the username; paid 20 GB / 64 GB tiers list 5 Hide My Email aliases each. No consumer custom-domain tier yet (announced only as a Business-tier roadmap feature). Catch-all not documented under any terminology. Bitcoin payment via BitPay is one of three documented payment processors (“We use Stripe, PayPal and Bitpay to process payments on this website”) — but no transparency report, no warrant canary, no notification commitment, no DPA URL (onlydpo@murena.com). Mandatory non-Murena recovery email at signup (“After 30 days without setting and verifying a recovery email address your account will be disabled and then deleted”). 2FA is TOTP only (no WebAuthn/FIDO2 documented). Built-in Google migration tool (Gmail / Drive / Photos / Contacts / Calendar). Native /e/OS Mail app on Android (forked from K-9 Mail per the project’s own GitLab README); no native iOS app — Apple Mail via theautoconfig.murena.ioprofile. The 2018 Eelo→/e/ rename, the 2022 ESolutions SAS→Murena Retail rename, and the 2024 Crowdcube equity raise (€786,398 from 545 investors) keep the funding-axis from scoring GOOD0 despite the non-profit e Foundation publisher ofe.foundation. - Vivaldi Mail is a free community-perk webmail tied to the Vivaldi-browser ecosystem — useful but not a privacy-grade option. Vivaldi acts as a data controller (not a processor or zero-knowledge custodian); mail is not encrypted at rest by default per a Vivaldi staff post on the official Vivaldi-hosted forum (“the key is on the webmail server, so someone with access to both could theoretically decrypt it”). The community privacy policy states verbatim: “In order to provide you our mail service, Vivaldi Webmail, we process the following email metadata: sender and recipient email addresses, the IP address from which incoming messages originated, and message sent and received times. Email messages are scanned by automated systems that allow us to detect malicious activity” — and “Email logs are stored for up to three months.” Mail-specific Vivaldi policy/help documents do not name a server location; the Iceland / Hringdu attribution comes from the Sync policy (“Vivaldi’s servers are hosted at the Hringdu data centers in Iceland”) and SMTP-host network-level evidence (
smtp.vivaldi.neton AS51896). Reputation-gated signup since May 2023 with the criteria deliberately undisclosed (“details about how the reputation system works are not shared publicly. How long it will take to get access to Vivaldi Webmail will also vary”); mandatory non-Vivaldi recovery email; mail body not encrypted at rest by default. No custom domains, no catch-all, no real aliases (only plus-addressing), no native mobile app, no paid tier, no DPA, no transparency report, no warrant canary, no notification commitment, no documented Tor posture. On the positive side: TOTP + security-key (WebAuthn/FIDO2) 2FA, app passwords + recovery codes, 10 GB quota, immediate deletion on account close, full IMAP/POP3/SMTP support, explicit “0 Outside investors” posture. Vivaldi’s own email-signup page actively recommends two paid competitors alongside its own free option — “Proton Mail — From €3/month” and “Fastmail — From $5/month” — itself a notable editorial transparency signal. - Seeweb Cloud Mail bundles every tier with mandatory custom-domain attachment, but excludes credit cards and lists no per-domain alias / catch-all cap. Order form requires a domain name; there is no free tier. Payment is restricted to PayPal / Automatic Pre-Authorized PayPal / Bonifico Bancario / SEPA-RID — Seeweb’s own FAQ does not list credit cards, and crypto/cash are nowhere mentioned. Catch-all is not documented under any terminology (“catch-all” / “wildcard” / "*@dominio"). Per-domain alias caps and per-account domain ceilings are unstated; the documented cross-domain workaround is mailbox forwarding (“inoltro”). No native mobile app — Seeweb directs users to “Outlook o Thunderbird” on Android/iOS. Custom-domain attachment is MX-only (“sarà possibile modificarne solo i record mail”), so existing registrars can stay. Cloud Mail is server-side plaintext: the provider runs content-level antispam/AV inspection (“esaminandone il contenuto”) and IBM Spectrum Protect daily backups “off-site (su Data Center Seeweb distante da quello dove viene gestito il servizio di posta)”. Opt-in PGP is available via the Roundcube webmail. The brand was renamed from TrueMail to Cloud Mail but the legacy hostnames still surface (
mail.truemail.it,webmail.truemail.it). Adherence to the CISPE Code of Conduct (EDPB positive opinion 2021-05-19, CNIL approval 2021-06-03) is its strongest formal compliance signal in lieu of a transparency report.aop.seeweb.it(customer area) is blocked by robots.txt, so 2FA availability is undocumented on Seeweb-owned domains rather than confirmed absent.
Privacy Impact Framework
Lower score = less the provider’s policy authorises them to do with your mail.
- HQ jurisdiction: Outside 14 Eyes (e.g. Switzerland, Iceland) (0); 14-Eyes member with strong GDPR enforcement (FR, DE) (+1); 5-Eyes member (US, UK, CA, AU, NZ) (+3); High-surveillance jurisdiction (China, Russia) (+3)
- Hosting jurisdiction: Same scale as HQ — hosting matters more for legal seizure than HQ alone
- Zero-access encryption: Built-in, provider holds no key for at least the message body (0); Opt-in via third-party PGP/S-MIME clients only (+1); Server-side PGP where provider can briefly access plaintext (+1); None (+3)
- Government-access posture: Published transparency report + user-notification commitment + warrant canary (0); two of three (+1); one of three (typically just a transparency report) (+2); none (+3). Add OK+1 more for an explicit non-notification policy.
- Anonymous signup: Tor explicitly supported and anonymous payment (cash or crypto) accepted (0); one of the two (+1); neither stated (+2)
- Funding stability: Independent / family-owned / non-profit operating >10 years (0); Privately held, stable ownership (+1); VC-backed or recently acquired (+2)
Bands: LOW0–3; MEDIUM4–8; HIGH9–14; CRITICAL 15+.
Audit a provider yourself
Paste this prompt into your research AI of choice (Perplexity, ChatGPT with web search, Claude with web search, etc.) to score any provider not listed here against the same rubric. The prompt is self-contained. Swap <PROVIDER NAME> and <URL>; extra research fields can be appended to the end of its field list without disturbing the rest.
Folding a scored provider back into this article takes four edits, each ordered ascending by Privacy Impact score: a row in
Ranking, a row in
Comparison, a ### section under
Provider profiles, and a row in the
functionality appendix. The six attribute deltas in the profile must sum to the score shown in all three tables. A provider that can’t be scored at all belongs in
Out of scope, where entries simply append.
Prompt
You are researching an email provider for a privacy + functionality comparison
article. The provider is: <PROVIDER NAME>. Their website is: <URL>.
Produce a structured report with verbatim quotes from the provider's own
Privacy Policy, Terms of Service, DPA, transparency reports, knowledge base,
and pricing pages — no paraphrasing for factual claims. For every claim,
include the source URL and the exact quoted sentence(s). If a fact is not
stated in the provider's own documents, say "Not stated" rather than
inferring. Resolve conflicts between umbrella ToS and product-specific ToS by
quoting both.
Cover these fields:
## Identity & jurisdiction
- Legal entity name and country of incorporation
- Parent company / ownership chain if disclosed
- Country/countries where mail servers physically reside (cite their docs)
- Governing law and dispute jurisdiction (from ToS)
(Five/Nine/Fourteen Eyes membership is derived externally — do not research it.)
## Privacy posture
- Encryption at rest: yes/no (algorithm details rarely stated, skip if not)
- Zero-access / end-to-end encryption: none / opt-in via 3rd-party PGP/S-MIME /
server-side PGP (provider has plaintext during session) / built-in zero-access.
State the scope: body only, subject, metadata.
- IP address logging policy + retention period
- Account-deletion data retention period
- Government-access posture, scored as three independent attributes:
(a) published transparency report (yes/no, URL, frequency)
(b) commitment to notify users of lawful requests when legally allowed
(yes/no, quote the commitment OR the non-notification clause)
(c) warrant canary (yes/no)
- Anonymous signup:
(a) Tor explicitly supported / blocked / not stated
(b) Anonymous payment methods: cash, crypto (state which)
(c) Whether real identifying details are required at signup
- DPA available? GDPR controller/processor stance?
## Functionality
- Custom domains:
(a) supported at which tier;
(b) max number of *separate* custom domains that can be attached to a single
mailbox/account (this is the "domains per mailbox" question — critical
for identity compartmentalization). Specifically check:
- Can aliases span domains, or are aliases same-domain only?
- If aliases are same-domain only, is there a forwarding-address
workaround? What's its limit?
- Does setting up a custom domain require taking over the entire
domain's MX (all-or-nothing) or can individual addresses be hosted?
Also search for "wildcard alias" if "catch-all" returns no results.
(c) max aliases per domain.
- Catch-all addresses: supported yes/no, on custom domain only?
(Search for "wildcard alias" / `*@domain` if "catch-all" returns nothing.)
- Aliases at provider domain: how many, free or paid
- IMAP / SMTP / POP3: supported yes/no
- Storage quota at the entry paid tier AND at the first tier with custom domains
- Migration tools (import from Gmail/IMAP)
- 2FA methods: specifically separate TOTP, WebAuthn/FIDO2 hardware key, SMS
- Native mobile app: iOS/Android (skip open-source question unless stated)
## Pricing
- Lowest paid tier that includes BOTH custom domain AND catch-all
- Monthly and yearly price (state currency: EUR, USD, etc.)
- Free tier exists? what's included? (distinguish from time-limited trial)
- Payment methods accepted: card, SEPA, PayPal, crypto, cash
## Stability signals
- Year founded
- Funding model: bootstrapped, VC-backed, non-profit, family-owned, acquired
- Any prior shutdowns, acquisitions, or major incidents
(provider docs only — supplement with external sources after if needed)
For each privacy-relevant claim, prefer quoting the Privacy Policy or ToS
directly. If the provider has multiple documents (umbrella ToS + product
ToS), read all of them and resolve conflicts by citing both.
End with a "Gaps" section listing anything you could not determine from
primary sources.
