{
  "slug": "addy",
  "category": "email-forwarding",
  "name": "Addy",
  "description": "Open-source email alias service that forwards mail from unlimited aliases to real mailboxes, with optional OpenPGP encryption. Has a free plan and can be self-hosted.",
  "website": "https://addy.io",
  "source": "https://github.com/anonaddy/anonaddy",
  "license": "AGPL-3.0",
  "platforms": [],
  "jurisdiction": {
    "code": "GB",
    "name": "United Kingdom",
    "eyes": "Five Eyes",
    "eu": false,
    "gdpr": true,
    "cloud_act": "agreement"
  },
  "pick": false,
  "pick_reason": null,
  "disclosure": null,
  "grade": "D",
  "score": 58,
  "coverage": 100,
  "summary": "Addy scores 58 out of 100 (grade D) on the email forwarding and aliases criteria. It meets 7 of 16 criteria: open source, no trackers or telemetry, no ads or data sales, security headers, no stored mail, custom domains and mail transport security. It partly meets TLS configuration, end-to-end encryption and ARC sealing. It does not meet independent audit, transparency report, tells users about requests, open protocols, sign up without personal data and Sender Rewriting Scheme. It is based in the United Kingdom: Five Eyes member; GDPR-style data protection law; CLOUD Act data access agreement with the US. Automated tests: SSL Labs grade A- and Mozilla HTTP Observatory grade A+.",
  "url": "https://privacyratings.com/email-forwarding/addy/",
  "markdown": "https://privacyratings.com/email-forwarding/addy/index.md",
  "answers": {
    "open_source": {
      "title": "Open source",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://github.com/anonaddy/anonaddy/blob/master/LICENSE.md",
      "note": "AGPL-3.0."
    },
    "no_trackers": {
      "title": "No trackers or telemetry",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://addy.io/faq/#why-should-i-use-this-instead-of-a-similar-service",
      "note": "No analytics or trackers, only server access logs, and no third-party content."
    },
    "no_ads": {
      "title": "No ads or data sales",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://addy.io/privacy/",
      "note": "Funded by paid plans. No ads, and personal information is never sold or shared."
    },
    "independent_audit": {
      "title": "Independent audit",
      "weight": 2,
      "answer": "no",
      "evidence": null,
      "note": "No independent audit is published."
    },
    "transparency_report": {
      "title": "Transparency report",
      "weight": 2,
      "answer": "no",
      "evidence": null,
      "note": "No transparency report or government request policy is published."
    },
    "user_notice": {
      "title": "Tells users about requests",
      "weight": 1,
      "answer": "no",
      "evidence": null,
      "note": "No published policy on notifying users about data requests."
    },
    "tls": {
      "title": "TLS configuration",
      "weight": 2,
      "answer": "partial",
      "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=addy.io&hideResults=on",
      "note": "Grade A-"
    },
    "security_headers": {
      "title": "Security headers",
      "weight": 1,
      "answer": "yes",
      "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=addy.io",
      "note": "Grade A+ (120/100+)"
    },
    "web_standards": {
      "title": "Modern web standards",
      "weight": 1,
      "answer": "pending",
      "evidence": null,
      "note": "Not tested yet."
    },
    "e2ee": {
      "title": "End-to-end encryption",
      "weight": 2,
      "answer": "partial",
      "evidence": "https://addy.io/faq/#are-forwarded-emails-signed-when-encryption-is-enabled",
      "note": "Forwarded mail can be encrypted with the user's own OpenPGP key. Not on by default."
    },
    "no_mail_storage": {
      "title": "No stored mail",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://addy.io/faq/#do-you-store-emails",
      "note": "Mail is not stored. Failed deliveries are kept only if the user turns that option on."
    },
    "open_protocols": {
      "title": "Open protocols",
      "weight": 2,
      "answer": "no",
      "evidence": "https://addy.io/faq/#do-you-provide-smtp-credentials-for-aliases",
      "note": "No IMAP or SMTP access. Mail is forwarded to an existing mailbox and replies go through the alias."
    },
    "custom_domains": {
      "title": "Custom domains",
      "weight": 1,
      "answer": "yes",
      "evidence": "https://addy.io/#pricing",
      "note": "From the Lite plan up."
    },
    "anonymous_signup": {
      "title": "Sign up without personal data",
      "weight": 2,
      "answer": "no",
      "evidence": null,
      "note": "An existing email address is required to create an account and receive forwarded mail."
    },
    "mail_standards": {
      "title": "Email security standards",
      "weight": 2,
      "answer": "pending",
      "evidence": null,
      "note": "Not tested yet."
    },
    "transport_security": {
      "title": "Mail transport security",
      "weight": 3,
      "answer": "yes",
      "evidence": null,
      "note": "Passes: SPF, DMARC reject, MTA-STS enforce, TLS-RPT, DNSSEC, DANE all."
    },
    "srs": {
      "title": "Sender Rewriting Scheme",
      "weight": 2,
      "answer": "no",
      "evidence": "https://github.com/anonaddy/anonaddy/blob/master/app/Mail/ForwardEmail.php",
      "note": "No SRS. Forwarded mail is re-sent with a VERP return address on addy.io's domain."
    },
    "arc": {
      "title": "ARC sealing",
      "weight": 1,
      "answer": "partial",
      "evidence": "https://github.com/anonaddy/anonaddy/blob/master/SELF-HOSTING.md",
      "note": "The documented setup adds ARC signatures with Rspamd. Validation of inbound ARC chains is not documented."
    }
  },
  "tests": {
    "ssllabs": "A-",
    "observatory": "A+",
    "internetnl_web": null,
    "internetnl_mail": null,
    "trackers": [],
    "tested_at": "2026-10-01T11:00:24.478Z"
  },
  "last_modified": "2026-10-01T11:14:42Z"
}