{
  "slug": "forward-email",
  "category": "email-forwarding",
  "name": "Forward Email",
  "description": "Email forwarding and alias service for custom domains. Mail is forwarded in memory to existing mailboxes or webhooks, with optional OpenPGP encryption, and paid plans add SMTP sending and encrypted IMAP mailboxes.",
  "website": "https://forwardemail.net",
  "source": "https://github.com/forwardemail/forwardemail.net",
  "license": null,
  "platforms": [
    "web"
  ],
  "jurisdiction": {
    "code": "US",
    "name": "United States",
    "eyes": "Five Eyes",
    "eu": false,
    "gdpr": false,
    "cloud_act": "provider"
  },
  "pick": false,
  "pick_reason": null,
  "disclosure": "Privacy Ratings is maintained by the team behind Forward Email. This entry is scored by the same criteria as every other entry in this category, and changes to it are reviewed under the published conflict-of-interest rules.",
  "grade": "B",
  "score": 86,
  "coverage": 100,
  "summary": "Forward Email scores 86 out of 100 (grade B) on the email forwarding and aliases criteria. It meets 12 of 16 criteria: open source, no ads or data sales, independent audit, tells users about requests, TLS configuration, security headers, no stored mail, open protocols, custom domains, mail transport security, Sender Rewriting Scheme and ARC sealing. It partly meets no trackers or telemetry, transparency report, end-to-end encryption and sign up without personal data. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade A+.",
  "url": "https://privacyratings.com/email-forwarding/forward-email/",
  "markdown": "https://privacyratings.com/email-forwarding/forward-email/index.md",
  "answers": {
    "open_source": {
      "title": "Open source",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://github.com/forwardemail/forwardemail.net/blob/master/LICENSE.md",
      "note": "All code is public, including the MX forwarding servers that run the service. Core mail storage and protocol code is MPL-2.0 and the rest is under the source-available Business Source License 1.1 (BUSL-1.1), which becomes MPL-2.0 four years after each release."
    },
    "no_trackers": {
      "title": "No trackers or telemetry",
      "weight": 3,
      "answer": "partial",
      "evidence": "https://forwardemail.net/en/privacy#analytics",
      "note": "No third-party analytics. First-party anonymized analytics of page views and service usage is on by default, and Cloudflare Turnstile loads on sign-in and sign-up forms."
    },
    "no_ads": {
      "title": "No ads or data sales",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://forwardemail.net/en/private-business-email",
      "note": "Funded by paid plans. No ads, and the privacy policy states user data is not shared with third parties."
    },
    "independent_audit": {
      "title": "Independent audit",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://cure53.de/pentest-report_forward-email.pdf",
      "note": "Two independent Cure53 audits of the code, including the MX servers, and the infrastructure are published."
    },
    "transparency_report": {
      "title": "Transparency report",
      "weight": 2,
      "answer": "partial",
      "evidence": "https://forwardemail.net/technical-whitepaper.pdf",
      "note": "The technical whitepaper (section 9.3) publishes the government request policy and commits to transparency reports with request counts. A report with counts is not published yet."
    },
    "user_notice": {
      "title": "Tells users about requests",
      "weight": 1,
      "answer": "yes",
      "evidence": "https://forwardemail.net/technical-whitepaper.pdf",
      "note": "Users are notified of requests when legally allowed, with notice after disclosure when advance notice is prohibited."
    },
    "tls": {
      "title": "TLS configuration",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=forwardemail.net&hideResults=on",
      "note": "Grade A+"
    },
    "security_headers": {
      "title": "Security headers",
      "weight": 1,
      "answer": "yes",
      "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=forwardemail.net",
      "note": "Grade A+ (125/100+)"
    },
    "web_standards": {
      "title": "Modern web standards",
      "weight": 1,
      "answer": "pending",
      "evidence": null,
      "note": "Not tested yet."
    },
    "e2ee": {
      "title": "End-to-end encryption",
      "weight": 2,
      "answer": "partial",
      "evidence": "https://forwardemail.net/en/faq#do-you-support-openpgpmime-end-to-end-encryption-e2ee-and-web-key-directory-wkd",
      "note": "Forwarded mail is encrypted with OpenPGP when the recipient has an uploaded key or publishes one through Web Key Directory. Mail to webhooks and mail from senders with a DMARC reject policy is not encrypted."
    },
    "no_mail_storage": {
      "title": "No stored mail",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://forwardemail.net/en/faq#where-is-inbound-email-for-my-domain-processed-and-stored-and-for-how-long",
      "note": "Forwarded mail is processed in memory and never written to disk. SMTP error logs keep the envelope and headers, not the body, for 7 days."
    },
    "open_protocols": {
      "title": "Open protocols",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://forwardemail.net/en/faq#do-you-support-receiving-email-with-imap",
      "note": "IMAP, POP3 and SMTP work with any client on every paid plan, with no bridge app."
    },
    "custom_domains": {
      "title": "Custom domains",
      "weight": 1,
      "answer": "yes",
      "evidence": "https://forwardemail.net/en/private-business-email",
      "note": "Custom domains are supported on every plan, including the free plan."
    },
    "anonymous_signup": {
      "title": "Sign up without personal data",
      "weight": 2,
      "answer": "partial",
      "evidence": "https://forwardemail.net/en/faq#how-do-i-get-started-and-set-up-email-forwarding",
      "note": "The free plan needs no account. Forwarding is set up with MX and TXT records on the domain, and the destination address in the TXT record is public unless encrypted. Paid plans need an account with an existing email address. No phone number is asked for."
    },
    "mail_standards": {
      "title": "Email security standards",
      "weight": 2,
      "answer": "pending",
      "evidence": null,
      "note": "Not tested yet."
    },
    "transport_security": {
      "title": "Mail transport security",
      "weight": 3,
      "answer": "yes",
      "evidence": null,
      "note": "Passes: SPF, DMARC reject, MTA-STS enforce, TLS-RPT, DNSSEC, DANE all."
    },
    "srs": {
      "title": "Sender Rewriting Scheme",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://forwardemail.net/en/faq#how-do-i-set-up-srs-for-forward-email",
      "note": "Applied automatically to all forwarded mail."
    },
    "arc": {
      "title": "ARC sealing",
      "weight": 1,
      "answer": "yes",
      "evidence": "https://forwardemail.net/en/faq#do-you-support-email-best-practices",
      "note": "ARC is supported on all plans, with inbound chains validated and forwarded mail ARC-sealed."
    }
  },
  "tests": {
    "ssllabs": "A+",
    "observatory": "A+",
    "internetnl_web": null,
    "internetnl_mail": null,
    "trackers": [],
    "tested_at": "2026-10-01T07:46:52.313Z"
  },
  "last_modified": "2026-10-01T07:47:04Z"
}