{
  "slug": "forward-email",
  "category": "email-providers",
  "name": "Forward Email",
  "description": "Open-source email service with encrypted mailboxes, custom domains, and IMAP, POP3, SMTP, CalDAV and CardDAV on every paid plan.",
  "website": "https://forwardemail.net",
  "source": "https://github.com/forwardemail/forwardemail.net",
  "license": "BUSL-1.1 AND MPL-2.0",
  "platforms": [
    "web",
    "windows",
    "macos",
    "linux",
    "android",
    "ios"
  ],
  "jurisdiction": {
    "code": "US",
    "name": "United States",
    "eyes": "Five Eyes",
    "eu": false,
    "gdpr": false,
    "cloud_act": "provider"
  },
  "pick": true,
  "pick_reason": "The whole service is published on GitHub, server code included. Each mailbox is a separately encrypted SQLite file, IMAP, POP3, SMTP, CalDAV and CardDAV work with any app, and custom domains are included on low-cost plans.",
  "disclosure": "Privacy Ratings is maintained by the team behind Forward Email. This entry is scored by the same criteria as every other email provider, and changes to it are reviewed under the published conflict-of-interest rules.",
  "grade": "A",
  "score": 93,
  "coverage": 100,
  "summary": "Forward Email scores 93 out of 100 (grade A) on the email providers criteria. It meets 17 of 19 criteria: open source, no ads or data sales, independent audit, tells users about requests, TLS configuration, security headers, end-to-end encryption, encrypted mailbox storage, open protocols, custom domains, sign up without personal data, IMAP support, POP3 support, SMTP submission, mail transport security, Sender Rewriting Scheme and ARC sealing. It partly meets no trackers or telemetry and transparency report. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade A+.",
  "url": "https://privacyratings.com/email-providers/forward-email/",
  "markdown": "https://privacyratings.com/email-providers/forward-email/index.md",
  "answers": {
    "open_source": {
      "title": "Open source",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://github.com/forwardemail/forwardemail.net/blob/master/LICENSE.md",
      "note": "All code is public, including the web, API, IMAP, POP3, SMTP, MX, CalDAV and CardDAV servers that run the service. Core mail storage and protocol code is MPL-2.0 and the rest is under the source-available Business Source License 1.1 (BUSL-1.1), which becomes MPL-2.0 four years after each release."
    },
    "no_trackers": {
      "title": "No trackers or telemetry",
      "weight": 3,
      "answer": "partial",
      "evidence": "https://forwardemail.net/en/privacy#analytics",
      "note": "No third-party analytics or telemetry. First-party page statistics keep no IP addresses, cookies or identifiers and are deleted after 30 days. Cloudflare Turnstile loads only on sign-in and sign-up forms to stop bots."
    },
    "no_ads": {
      "title": "No ads or data sales",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://forwardemail.net/en/private-business-email",
      "note": "Funded by paid plans. No ads."
    },
    "independent_audit": {
      "title": "Independent audit",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://cure53.de/pentest-report_forward-email.pdf",
      "note": "Two independent Cure53 audits of the code and infrastructure, published by Cure53 and on forwardemail.net."
    },
    "transparency_report": {
      "title": "Transparency report",
      "weight": 2,
      "answer": "partial",
      "evidence": "https://forwardemail.net/technical-whitepaper.pdf",
      "note": "The technical whitepaper (section 9.3) publishes the government request policy and commits to regular transparency reports with request counts. A report with counts is not published yet."
    },
    "user_notice": {
      "title": "Tells users about requests",
      "weight": 1,
      "answer": "yes",
      "evidence": "https://forwardemail.net/technical-whitepaper.pdf",
      "note": "Users are notified of requests when legally allowed, with notice after disclosure when advance notice is prohibited."
    },
    "tls": {
      "title": "TLS configuration",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=forwardemail.net&hideResults=on",
      "note": "Grade A+"
    },
    "security_headers": {
      "title": "Security headers",
      "weight": 1,
      "answer": "yes",
      "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=forwardemail.net",
      "note": "Grade A+ (125/100+)"
    },
    "web_standards": {
      "title": "Modern web standards",
      "weight": 1,
      "answer": "pending",
      "evidence": null,
      "note": "Not tested yet."
    },
    "e2ee": {
      "title": "End-to-end encryption",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://forwardemail.net/en/faq#do-you-support-openpgpmime-end-to-end-encryption-e2ee-and-web-key-directory-wkd",
      "note": "Mail is automatically encrypted with OpenPGP when the recipient publishes a key through Web Key Directory. OpenPGP/MIME and S/MIME work with any app."
    },
    "encrypted_storage": {
      "title": "Encrypted mailbox storage",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://forwardemail.net/technical-whitepaper.pdf",
      "note": "Each mailbox is a separately encrypted SQLite file (ChaCha20-Poly1305). The technical whitepaper states Forward Email cannot access mailbox contents."
    },
    "open_protocols": {
      "title": "Open protocols",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://forwardemail.net/en/faq#do-you-support-receiving-email-with-imap",
      "note": "IMAP, POP3, SMTP, CalDAV and CardDAV on every paid plan, with no bridge app."
    },
    "custom_domains": {
      "title": "Custom domains",
      "weight": 1,
      "answer": "yes",
      "evidence": "https://forwardemail.net/en/private-business-email",
      "note": "Unlimited domains on every plan."
    },
    "anonymous_signup": {
      "title": "Sign up without personal data",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://forwardemail.net/en/faq#how-do-i-get-started-and-set-up-email-forwarding",
      "note": "Free forwarding is set up entirely with DNS records, with no account at all. Paid mailboxes need only an email address and password, never a phone number."
    },
    "mail_standards": {
      "title": "Email security standards",
      "weight": 2,
      "answer": "pending",
      "evidence": null,
      "note": "Not tested yet."
    },
    "imap_standards": {
      "title": "IMAP support",
      "weight": 2,
      "answer": "yes",
      "evidence": null,
      "note": "imap.forwardemail.net:993 (implicit TLS). IMAP4rev1 advertised with IDLE."
    },
    "pop3_standards": {
      "title": "POP3 support",
      "weight": 1,
      "answer": "yes",
      "evidence": null,
      "note": "pop3.forwardemail.net:995 (implicit TLS). CAPA: TOP, UIDL, USER, RESP-CODES, SASL, PIPELINING."
    },
    "smtp_standards": {
      "title": "SMTP submission",
      "weight": 2,
      "answer": "yes",
      "evidence": null,
      "note": "smtp.forwardemail.net:465 (implicit TLS). SMTPUTF8, 8BITMIME, PIPELINING and AUTH advertised."
    },
    "transport_security": {
      "title": "Mail transport security",
      "weight": 3,
      "answer": "yes",
      "evidence": null,
      "note": "Passes: SPF, DMARC reject, MTA-STS enforce, TLS-RPT, DNSSEC, DANE all."
    },
    "srs": {
      "title": "Sender Rewriting Scheme",
      "weight": 1,
      "answer": "yes",
      "evidence": "https://forwardemail.net/en/faq#how-do-i-set-up-srs-for-forward-email",
      "note": "Applied automatically to all forwarded mail."
    },
    "arc": {
      "title": "ARC sealing",
      "weight": 1,
      "answer": "yes",
      "evidence": "https://forwardemail.net/en/faq#do-you-support-email-best-practices",
      "note": "ARC chains are validated (RFC 8617) and forwarded mail is ARC-sealed."
    }
  },
  "tests": {
    "ssllabs": "A+",
    "observatory": "A+",
    "internetnl_web": null,
    "internetnl_mail": null,
    "trackers": [],
    "tested_at": "2026-10-01T07:46:47.512Z"
  },
  "last_modified": "2026-10-01T07:47:04Z"
}