{
  "slug": "disroot",
  "category": "email-providers",
  "name": "Disroot",
  "description": "Volunteer-run platform from the Netherlands offering email and other open services.",
  "website": "https://disroot.org",
  "source": "https://git.disroot.org/Disroot-Ansible",
  "license": null,
  "platforms": [],
  "jurisdiction": {
    "code": "NL",
    "name": "Netherlands",
    "eyes": "Nine Eyes",
    "eu": true,
    "gdpr": true,
    "cloud_act": null
  },
  "pick": false,
  "pick_reason": null,
  "disclosure": null,
  "grade": "D",
  "score": 59,
  "coverage": 100,
  "summary": "Disroot scores 59 out of 100 (grade D) on the email providers criteria. It meets 9 of 19 criteria: open source, no trackers or telemetry, no ads or data sales, TLS configuration, open protocols, custom domains, IMAP support, POP3 support and mail transport security. It partly meets security headers, end-to-end encryption and SMTP submission. It does not meet independent audit, transparency report, tells users about requests, encrypted mailbox storage, sign up without personal data, Sender Rewriting Scheme and ARC sealing. It is based in the Netherlands: Nine Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
  "url": "https://privacyratings.com/email-providers/disroot/",
  "markdown": "https://privacyratings.com/email-providers/disroot/index.md",
  "answers": {
    "open_source": {
      "title": "Open source",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://disroot.org/about",
      "note": "Runs only free and open-source software such as Postfix, Dovecot and Roundcube. Deployment roles are published at git.disroot.org."
    },
    "no_trackers": {
      "title": "No trackers or telemetry",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://disroot.org/privacy_policy",
      "note": "The privacy policy states that user behavior is not analyzed or profiled and that there are no advertisers."
    },
    "no_ads": {
      "title": "No ads or data sales",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://disroot.org/privacy_policy",
      "note": "Funded by donations. No ads and no data sales."
    },
    "independent_audit": {
      "title": "Independent audit",
      "weight": 2,
      "answer": "no",
      "evidence": null,
      "note": "No independent audit is published."
    },
    "transparency_report": {
      "title": "Transparency report",
      "weight": 2,
      "answer": "no",
      "evidence": null,
      "note": "No transparency report or government request policy is published."
    },
    "user_notice": {
      "title": "Tells users about requests",
      "weight": 1,
      "answer": "no",
      "evidence": null,
      "note": "No published policy on notifying users about data requests."
    },
    "tls": {
      "title": "TLS configuration",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=disroot.org&hideResults=on",
      "note": "Grade A+"
    },
    "security_headers": {
      "title": "Security headers",
      "weight": 1,
      "answer": "partial",
      "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=disroot.org",
      "note": "Grade B (75/100+)"
    },
    "web_standards": {
      "title": "Modern web standards",
      "weight": 1,
      "answer": "pending",
      "evidence": null,
      "note": "Not tested yet."
    },
    "e2ee": {
      "title": "End-to-end encryption",
      "weight": 3,
      "answer": "partial",
      "evidence": "https://disroot.org/services/email",
      "note": "OpenPGP is possible with the Mailvelope browser extension or a desktop client. Not on by default."
    },
    "encrypted_storage": {
      "title": "Encrypted mailbox storage",
      "weight": 3,
      "answer": "no",
      "evidence": "https://disroot.org/privacy_policy",
      "note": "Mail is stored unencrypted unless the user encrypts it. An opt-in Lacre beta encrypts incoming mail with the user's own PGP key for a limited group of users."
    },
    "open_protocols": {
      "title": "Open protocols",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://disroot.org/services/email",
      "note": "IMAP, POP3 and SMTP work with any client."
    },
    "custom_domains": {
      "title": "Custom domains",
      "weight": 1,
      "answer": "yes",
      "evidence": "https://disroot.org/perks",
      "note": "Available as a lifetime feature after a donation of the suggested amount."
    },
    "anonymous_signup": {
      "title": "Sign up without personal data",
      "weight": 2,
      "answer": "no",
      "evidence": "https://user.disroot.org/pwm/public/newuser",
      "note": "An existing email address is required for verification during sign-up."
    },
    "mail_standards": {
      "title": "Email security standards",
      "weight": 2,
      "answer": "pending",
      "evidence": null,
      "note": "Not tested yet."
    },
    "imap_standards": {
      "title": "IMAP support",
      "weight": 2,
      "answer": "yes",
      "evidence": null,
      "note": "disroot.org:993 (implicit TLS). IMAP4rev1 advertised with IDLE."
    },
    "pop3_standards": {
      "title": "POP3 support",
      "weight": 1,
      "answer": "yes",
      "evidence": null,
      "note": "disroot.org:995 (implicit TLS). CAPA: CAPA, TOP, UIDL, RESP-CODES, PIPELINING, AUTH-RESP-CODE, USER, SASL."
    },
    "smtp_standards": {
      "title": "SMTP submission",
      "weight": 2,
      "answer": "partial",
      "evidence": null,
      "note": "disroot.org:465 (implicit TLS). Missing: SMTPUTF8."
    },
    "transport_security": {
      "title": "Mail transport security",
      "weight": 3,
      "answer": "yes",
      "evidence": null,
      "note": "Passes: SPF, DMARC reject, MTA-STS enforce, TLS-RPT, DNSSEC, DANE all."
    },
    "srs": {
      "title": "Sender Rewriting Scheme",
      "weight": 1,
      "answer": "no",
      "evidence": null,
      "note": "No published documentation on SRS for forwarded mail."
    },
    "arc": {
      "title": "ARC sealing",
      "weight": 1,
      "answer": "no",
      "evidence": null,
      "note": "No published documentation on ARC signing or validation."
    }
  },
  "tests": {
    "ssllabs": "A+",
    "observatory": "B",
    "internetnl_web": null,
    "internetnl_mail": null,
    "trackers": [],
    "tested_at": "2026-10-01T07:46:20.833Z"
  },
  "last_modified": "2026-10-01T07:47:04Z"
}