{
  "slug": "aol-mail",
  "category": "email-providers",
  "name": "AOL Mail",
  "description": "Free, ad-supported email service from AOL, owned by Bending Spoons, with webmail and mobile apps. A paid subscription removes ads.",
  "website": "https://mail.aol.com",
  "license": null,
  "platforms": [],
  "jurisdiction": {
    "code": "US",
    "name": "United States",
    "eyes": "Five Eyes",
    "eu": false,
    "gdpr": false,
    "cloud_act": "provider"
  },
  "pick": false,
  "pick_reason": null,
  "disclosure": null,
  "grade": "F",
  "score": 22,
  "coverage": 100,
  "summary": "AOL Mail scores 22 out of 100 (grade F) on the email providers criteria. It meets 3 of 19 criteria: TLS configuration, open protocols and IMAP support. It partly meets security headers, POP3 support and SMTP submission. It does not meet open source, no trackers or telemetry, no ads or data sales, independent audit, transparency report, tells users about requests, end-to-end encryption, encrypted mailbox storage, custom domains, sign up without personal data, mail transport security, Sender Rewriting Scheme and ARC sealing. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
  "url": "https://privacyratings.com/email-providers/aol-mail/",
  "markdown": "https://privacyratings.com/email-providers/aol-mail/index.md",
  "answers": {
    "open_source": {
      "title": "Open source",
      "weight": 3,
      "answer": "no",
      "evidence": null,
      "note": "Closed source."
    },
    "no_trackers": {
      "title": "No trackers or telemetry",
      "weight": 3,
      "answer": "no",
      "evidence": "https://legal.aol.com/privacy/index.html",
      "note": "The AOL website loads New Relic, Heap and Google tags, and the privacy policy allows third-party tracking technologies for advertising."
    },
    "no_ads": {
      "title": "No ads or data sales",
      "weight": 2,
      "answer": "no",
      "evidence": "https://help.aol.com/articles/ad-free-aol-mail",
      "note": "The free service is funded by ads, and the privacy policy allows sharing data with advertising networks. A paid subscription removes ads."
    },
    "independent_audit": {
      "title": "Independent audit",
      "weight": 2,
      "answer": "no",
      "evidence": null,
      "note": "No independent audit is published."
    },
    "transparency_report": {
      "title": "Transparency report",
      "weight": 2,
      "answer": "no",
      "evidence": null,
      "note": "No transparency report or government request policy is published."
    },
    "user_notice": {
      "title": "Tells users about requests",
      "weight": 1,
      "answer": "no",
      "evidence": null,
      "note": "No published policy on notifying users about data requests."
    },
    "tls": {
      "title": "TLS configuration",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=mail.aol.com&hideResults=on",
      "note": "Grade A+"
    },
    "security_headers": {
      "title": "Security headers",
      "weight": 1,
      "answer": "partial",
      "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=mail.aol.com",
      "note": "Grade B (70/100+)"
    },
    "web_standards": {
      "title": "Modern web standards",
      "weight": 1,
      "answer": "pending",
      "evidence": null,
      "note": "Not tested yet."
    },
    "e2ee": {
      "title": "End-to-end encryption",
      "weight": 3,
      "answer": "no",
      "evidence": null,
      "note": "Not supported."
    },
    "encrypted_storage": {
      "title": "Encrypted mailbox storage",
      "weight": 3,
      "answer": "no",
      "evidence": null,
      "note": "Encryption at rest for stored mail is not documented."
    },
    "open_protocols": {
      "title": "Open protocols",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://help.aol.com/articles/how-do-i-use-other-email-applications-to-send-and-receive-my-aol-mail",
      "note": "IMAP, POP3 and SMTP work with other apps."
    },
    "custom_domains": {
      "title": "Custom domains",
      "weight": 1,
      "answer": "no",
      "evidence": null,
      "note": "Not supported. Addresses use AOL domains."
    },
    "anonymous_signup": {
      "title": "Sign up without personal data",
      "weight": 2,
      "answer": "no",
      "evidence": "https://help.aol.com/articles/use-whatsapp-to-verify-your-aol-account",
      "note": "Registration requires a mobile phone number to receive a verification code."
    },
    "mail_standards": {
      "title": "Email security standards",
      "weight": 2,
      "answer": "pending",
      "evidence": null,
      "note": "Not tested yet."
    },
    "imap_standards": {
      "title": "IMAP support",
      "weight": 2,
      "answer": "yes",
      "evidence": null,
      "note": "imap.aol.com:993 (implicit TLS). IMAP4rev1 advertised with IDLE."
    },
    "pop3_standards": {
      "title": "POP3 support",
      "weight": 1,
      "answer": "partial",
      "evidence": null,
      "note": "pop.aol.com:995 (implicit TLS). CAPA: IMPLEMENTATION, TOP, USER, SASL."
    },
    "smtp_standards": {
      "title": "SMTP submission",
      "weight": 2,
      "answer": "partial",
      "evidence": null,
      "note": "smtp.aol.com:465 (implicit TLS). Missing: SMTPUTF8."
    },
    "transport_security": {
      "title": "Mail transport security",
      "weight": 3,
      "answer": "no",
      "evidence": null,
      "note": "Passes: SPF, DMARC reject. Missing: MTA-STS missing, TLS-RPT, DNSSEC, DANE none."
    },
    "srs": {
      "title": "Sender Rewriting Scheme",
      "weight": 1,
      "answer": "no",
      "evidence": null,
      "note": "No published documentation on SRS for forwarded mail."
    },
    "arc": {
      "title": "ARC sealing",
      "weight": 1,
      "answer": "no",
      "evidence": null,
      "note": "No published documentation on ARC signing or validation."
    }
  },
  "tests": {
    "ssllabs": "A+",
    "observatory": "B",
    "internetnl_web": null,
    "internetnl_mail": null,
    "trackers": [],
    "tested_at": "2026-10-01T10:59:37.553Z"
  },
  "last_modified": "2026-10-01T11:14:42Z"
}