{
  "slug": "amazon-workmail",
  "category": "email-providers",
  "name": "Amazon WorkMail",
  "description": "Paid business email and calendar service on AWS for custom domains, billed per user. AWS has announced the end of support for WorkMail and no longer accepts new customers.",
  "website": "https://aws.amazon.com/workmail/",
  "license": null,
  "platforms": [
    "web"
  ],
  "jurisdiction": {
    "code": "US",
    "name": "United States",
    "eyes": "Five Eyes",
    "eu": false,
    "gdpr": false,
    "cloud_act": "provider"
  },
  "pick": false,
  "pick_reason": null,
  "disclosure": null,
  "grade": "D",
  "score": 48,
  "coverage": 93,
  "summary": "Amazon WorkMail scores 48 out of 100 (grade D) on the email providers criteria. It meets 6 of 15 criteria: transparency report, tells users about requests, TLS configuration, security headers, open protocols and custom domains. It partly meets no ads or data sales, independent audit, end-to-end encryption and encrypted mailbox storage. It does not meet open source, no trackers or telemetry and sign up without personal data. Still needing evidence: Sender Rewriting Scheme and ARC sealing. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade A.",
  "url": "https://privacyratings.com/email-providers/amazon-workmail/",
  "markdown": "https://privacyratings.com/email-providers/amazon-workmail/index.md",
  "answers": {
    "open_source": {
      "title": "Open source",
      "weight": 3,
      "answer": "no",
      "evidence": null,
      "note": "Closed source."
    },
    "no_trackers": {
      "title": "No trackers or telemetry",
      "weight": 3,
      "answer": "no",
      "evidence": "https://aws.amazon.com/legal/cookies/",
      "note": "AWS websites allow cookies from third parties including Google, LinkedIn and The Trade Desk for ads and reporting."
    },
    "no_ads": {
      "title": "No ads or data sales",
      "weight": 2,
      "answer": "partial",
      "evidence": "https://aws.amazon.com/compliance/data-privacy-faq/",
      "note": "Funded by per-user fees, and customer content is not used for marketing or advertising. The AWS website uses third-party cookies to show AWS ads on other sites."
    },
    "independent_audit": {
      "title": "Independent audit",
      "weight": 2,
      "answer": "partial",
      "evidence": "https://d1.awsstatic.com/onedam/marketing-channels/website/aws/en_US/whitepapers/compliance/AWS_SOC3_Report.pdf",
      "note": "WorkMail is in scope of AWS SOC audits. Only the SOC 3 summary report is public. The full SOC 2 report is only available to customers."
    },
    "transparency_report": {
      "title": "Transparency report",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://d1.awsstatic.com/onedam/marketing-channels/website/aws/en_US/security/pdfs/Amazon_Government_Request_Report_H1_2026.pdf",
      "note": "Semi-annual reports with counts of government requests to Amazon and AWS and how they were answered."
    },
    "user_notice": {
      "title": "Tells users about requests",
      "weight": 1,
      "answer": "yes",
      "evidence": "https://aws.amazon.com/compliance/data-privacy-faq/",
      "note": "AWS gives customers notice of demands for their content unless legally prohibited."
    },
    "tls": {
      "title": "TLS configuration",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=aws.amazon.com&hideResults=on",
      "note": "Grade A+"
    },
    "security_headers": {
      "title": "Security headers",
      "weight": 1,
      "answer": "yes",
      "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=aws.amazon.com",
      "note": "Grade A (95/100+)"
    },
    "web_standards": {
      "title": "Modern web standards",
      "weight": 1,
      "answer": "pending",
      "evidence": null,
      "note": "Not tested yet."
    },
    "e2ee": {
      "title": "End-to-end encryption",
      "weight": 3,
      "answer": "partial",
      "evidence": "https://docs.aws.amazon.com/workmail/latest/userguide/send_encrypted_email.html",
      "note": "S/MIME works in Outlook and some mobile mail apps with a certificate from a third party. Not in the web app and not on by default."
    },
    "encrypted_storage": {
      "title": "Encrypted mailbox storage",
      "weight": 3,
      "answer": "partial",
      "evidence": "https://docs.aws.amazon.com/workmail/latest/adminguide/data-protection.html",
      "note": "Mailboxes are encrypted at rest with AWS KMS keys. The organization can choose its own KMS key, but AWS decrypts mail when users access it."
    },
    "open_protocols": {
      "title": "Open protocols",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://docs.aws.amazon.com/workmail/latest/userguide/using_IMAP.html",
      "note": "IMAP and SMTP work with other apps over implicit TLS. POP3 is not supported."
    },
    "custom_domains": {
      "title": "Custom domains",
      "weight": 1,
      "answer": "yes",
      "evidence": "https://aws.amazon.com/workmail/faqs/",
      "note": "Existing domains can be added after ownership is verified."
    },
    "anonymous_signup": {
      "title": "Sign up without personal data",
      "weight": 2,
      "answer": "no",
      "evidence": "https://docs.aws.amazon.com/accounts/latest/reference/manage-acct-creating.html",
      "note": "An AWS account requires an email address, a phone number that receives a PIN and a valid payment method."
    },
    "mail_standards": {
      "title": "Email security standards",
      "weight": 2,
      "answer": "n/a",
      "evidence": null,
      "note": "No mail domain to test."
    },
    "imap_standards": {
      "title": "IMAP support",
      "weight": 2,
      "answer": "pending",
      "evidence": null,
      "note": "Not tested yet."
    },
    "pop3_standards": {
      "title": "POP3 support",
      "weight": 1,
      "answer": "pending",
      "evidence": null,
      "note": "Not tested yet."
    },
    "smtp_standards": {
      "title": "SMTP submission",
      "weight": 2,
      "answer": "pending",
      "evidence": null,
      "note": "Not tested yet."
    },
    "transport_security": {
      "title": "Mail transport security",
      "weight": 3,
      "answer": "pending",
      "evidence": null,
      "note": "Not tested yet."
    },
    "srs": {
      "title": "Sender Rewriting Scheme",
      "weight": 1,
      "answer": "unknown",
      "evidence": null,
      "note": null
    },
    "arc": {
      "title": "ARC sealing",
      "weight": 1,
      "answer": "unknown",
      "evidence": null,
      "note": null
    }
  },
  "tests": {
    "ssllabs": "A+",
    "observatory": "A",
    "internetnl_web": null,
    "internetnl_mail": null,
    "trackers": [],
    "tested_at": "2026-10-03T09:53:54.712Z"
  },
  "last_modified": "2026-10-03T10:27:12Z"
}