{
  "slug": "countermail",
  "category": "email-providers",
  "name": "CounterMail",
  "description": "Paid email service in Sweden that encrypts mail with OpenPGP and stores it encrypted. New registrations are closed.",
  "website": "https://countermail.com",
  "license": null,
  "platforms": [],
  "jurisdiction": {
    "code": "SE",
    "name": "Sweden",
    "eyes": "Fourteen Eyes",
    "eu": true,
    "gdpr": true,
    "cloud_act": null
  },
  "pick": false,
  "pick_reason": null,
  "disclosure": null,
  "grade": "C",
  "score": 62,
  "coverage": 100,
  "summary": "CounterMail scores 62 out of 100 (grade C) on the email providers criteria. It meets 9 of 19 criteria: no trackers or telemetry, no ads or data sales, TLS configuration, end-to-end encryption, encrypted mailbox storage, open protocols, custom domains, sign up without personal data and IMAP support. It partly meets security headers, SMTP submission and mail transport security. It does not meet open source, independent audit, transparency report, tells users about requests, POP3 support, Sender Rewriting Scheme and ARC sealing. It is based in Sweden: Fourteen Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
  "url": "https://privacyratings.com/email-providers/countermail/",
  "markdown": "https://privacyratings.com/email-providers/countermail/index.md",
  "answers": {
    "open_source": {
      "title": "Open source",
      "weight": 3,
      "answer": "no",
      "evidence": null,
      "note": "Closed source."
    },
    "no_trackers": {
      "title": "No trackers or telemetry",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://countermail.com/?p=privacy",
      "note": "No cookies and no IP logging, and the website loads no third-party trackers."
    },
    "no_ads": {
      "title": "No ads or data sales",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://countermail.com/?p=privacy",
      "note": "Funded by paid accounts. Account data is never shared or sold."
    },
    "independent_audit": {
      "title": "Independent audit",
      "weight": 2,
      "answer": "no",
      "evidence": null,
      "note": "No independent audit is published."
    },
    "transparency_report": {
      "title": "Transparency report",
      "weight": 2,
      "answer": "no",
      "evidence": null,
      "note": "No transparency report or government request policy is published."
    },
    "user_notice": {
      "title": "Tells users about requests",
      "weight": 1,
      "answer": "no",
      "evidence": null,
      "note": "No published policy on notifying users about data requests."
    },
    "tls": {
      "title": "TLS configuration",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=countermail.com&hideResults=on",
      "note": "Grade A+"
    },
    "security_headers": {
      "title": "Security headers",
      "weight": 1,
      "answer": "partial",
      "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=countermail.com",
      "note": "Grade B (75/100+)"
    },
    "web_standards": {
      "title": "Modern web standards",
      "weight": 1,
      "answer": "pending",
      "evidence": null,
      "note": "Not tested yet."
    },
    "e2ee": {
      "title": "End-to-end encryption",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://countermail.com/?p=services",
      "note": "OpenPGP encryption is built in and automatic between users, and works with any OpenPGP user outside CounterMail."
    },
    "encrypted_storage": {
      "title": "Encrypted mailbox storage",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://countermail.com/?p=server",
      "note": "Mail is stored encrypted with the user's OpenPGP key, and incoming unencrypted mail is encrypted on arrival."
    },
    "open_protocols": {
      "title": "Open protocols",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://support.countermail.com/kb/faq.php?id=14",
      "note": "IMAP and SMTP work with any client on premium accounts, with a PGP plugin needed to read mail."
    },
    "custom_domains": {
      "title": "Custom domains",
      "weight": 1,
      "answer": "yes",
      "evidence": "https://countermail.com/?p=services",
      "note": "Available for a one-time setup fee."
    },
    "anonymous_signup": {
      "title": "Sign up without personal data",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://webmail.countermail.com/register/index.php",
      "note": "Registration asks only for a username, password and invitation code, but it is closed to new users."
    },
    "mail_standards": {
      "title": "Email security standards",
      "weight": 2,
      "answer": "pending",
      "evidence": null,
      "note": "Not tested yet."
    },
    "imap_standards": {
      "title": "IMAP support",
      "weight": 2,
      "answer": "yes",
      "evidence": null,
      "note": "imap1.countermail.com:993 (implicit TLS). IMAP4rev1 advertised with IDLE."
    },
    "pop3_standards": {
      "title": "POP3 support",
      "weight": 1,
      "answer": "no",
      "evidence": null,
      "note": "Not offered."
    },
    "smtp_standards": {
      "title": "SMTP submission",
      "weight": 2,
      "answer": "partial",
      "evidence": null,
      "note": "imap1.countermail.com:465 (implicit TLS). Missing: SMTPUTF8."
    },
    "transport_security": {
      "title": "Mail transport security",
      "weight": 3,
      "answer": "partial",
      "evidence": null,
      "note": "Passes: SPF, DMARC quarantine, DNSSEC, DANE all. Missing: MTA-STS missing, TLS-RPT."
    },
    "srs": {
      "title": "Sender Rewriting Scheme",
      "weight": 1,
      "answer": "no",
      "evidence": null,
      "note": "No published documentation on SRS for forwarded mail."
    },
    "arc": {
      "title": "ARC sealing",
      "weight": 1,
      "answer": "no",
      "evidence": null,
      "note": "No published documentation on ARC signing or validation."
    }
  },
  "tests": {
    "ssllabs": "A+",
    "observatory": "B",
    "internetnl_web": null,
    "internetnl_mail": null,
    "trackers": [],
    "tested_at": "2026-10-01T07:46:02.187Z"
  },
  "last_modified": "2026-10-01T07:47:04Z"
}