{
  "slug": "kolab-now",
  "category": "email-providers",
  "name": "Kolab Now",
  "description": "Paid email and groupware service from Apheleia IT in Switzerland, built on the open-source Kolab platform, with calendars, contacts, files and video calls.",
  "website": "https://kolabnow.com",
  "source": "https://git.kolab.org/source/kolab/",
  "license": null,
  "platforms": [],
  "jurisdiction": {
    "code": "CH",
    "name": "Switzerland",
    "eyes": null,
    "eu": false,
    "gdpr": true,
    "cloud_act": null
  },
  "pick": false,
  "pick_reason": null,
  "disclosure": null,
  "grade": "C",
  "score": 64,
  "coverage": 100,
  "summary": "Kolab Now scores 64 out of 100 (grade C) on the email providers criteria. It meets 10 of 19 criteria: open source, no trackers or telemetry, no ads or data sales, TLS configuration, open protocols, custom domains, IMAP support, POP3 support, SMTP submission and mail transport security. It partly meets transparency report and end-to-end encryption. It does not meet independent audit, tells users about requests, security headers, encrypted mailbox storage, sign up without personal data, Sender Rewriting Scheme and ARC sealing. It is based in Switzerland: Not in the Five, Nine or Fourteen Eyes; GDPR-style data protection law. Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade D.",
  "url": "https://privacyratings.com/email-providers/kolab-now/",
  "markdown": "https://privacyratings.com/email-providers/kolab-now/index.md",
  "answers": {
    "open_source": {
      "title": "Open source",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://git.kolab.org/source/kolab/",
      "note": "Runs on the open-source Kolab platform, and the terms state that all software used is free software."
    },
    "no_trackers": {
      "title": "No trackers or telemetry",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://kb.kolabnow.com/documentation/why-kolab-now-is-the-right-thing-for-you",
      "note": "User data is not sold or used for statistical analysis, and the website loads no third-party trackers."
    },
    "no_ads": {
      "title": "No ads or data sales",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://kolabnow.com/tos",
      "note": "Funded by subscriptions. No advertising and no sale of personal data."
    },
    "independent_audit": {
      "title": "Independent audit",
      "weight": 2,
      "answer": "no",
      "evidence": null,
      "note": "No independent audit is published."
    },
    "transparency_report": {
      "title": "Transparency report",
      "weight": 2,
      "answer": "partial",
      "evidence": "https://kolabnow.com/tos",
      "note": "The terms state that data is only given to third parties with a warrant from a Swiss judge. No request counts are published."
    },
    "user_notice": {
      "title": "Tells users about requests",
      "weight": 1,
      "answer": "no",
      "evidence": null,
      "note": "No published policy on notifying users about data requests."
    },
    "tls": {
      "title": "TLS configuration",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=kolabnow.com&hideResults=on",
      "note": "Grade A"
    },
    "security_headers": {
      "title": "Security headers",
      "weight": 1,
      "answer": "no",
      "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=kolabnow.com",
      "note": "Grade D (35/100+)"
    },
    "web_standards": {
      "title": "Modern web standards",
      "weight": 1,
      "answer": "pending",
      "evidence": null,
      "note": "Not tested yet."
    },
    "e2ee": {
      "title": "End-to-end encryption",
      "weight": 3,
      "answer": "partial",
      "evidence": "https://kb.kolabnow.com/documentation/kolab-now-a-guide",
      "note": "PGP encryption can be set up in the webmail settings. Not on by default."
    },
    "encrypted_storage": {
      "title": "Encrypted mailbox storage",
      "weight": 3,
      "answer": "no",
      "evidence": null,
      "note": "Encryption at rest for stored mail is not documented."
    },
    "open_protocols": {
      "title": "Open protocols",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://kb.kolabnow.com/documentation/generic-imap-client-setup-guide",
      "note": "IMAP, SMTP, CalDAV and CardDAV work with any client."
    },
    "custom_domains": {
      "title": "Custom domains",
      "weight": 1,
      "answer": "yes",
      "evidence": "https://kb.kolabnow.com/faq/what-is-the-price-for-a-kolab-now-subscription",
      "note": "The first custom domain is free and extra domains cost a small monthly fee."
    },
    "anonymous_signup": {
      "title": "Sign up without personal data",
      "weight": 2,
      "answer": "no",
      "evidence": null,
      "note": "An existing email address is required to verify a new account."
    },
    "mail_standards": {
      "title": "Email security standards",
      "weight": 2,
      "answer": "pending",
      "evidence": null,
      "note": "Not tested yet."
    },
    "imap_standards": {
      "title": "IMAP support",
      "weight": 2,
      "answer": "yes",
      "evidence": null,
      "note": "imap.kolabnow.com:993 (implicit TLS). IMAP4rev1 advertised with IDLE."
    },
    "pop3_standards": {
      "title": "POP3 support",
      "weight": 1,
      "answer": "yes",
      "evidence": null,
      "note": "pop.kolabnow.com:995 (implicit TLS). CAPA: SASL, EXPIRE, LOGIN-DELAY, TOP, UIDL, PIPELINING, RESP-CODES, AUTH-RESP-CODE, USER, IMPLEMENTATION."
    },
    "smtp_standards": {
      "title": "SMTP submission",
      "weight": 2,
      "answer": "yes",
      "evidence": null,
      "note": "smtp.kolabnow.com:465 (implicit TLS). SMTPUTF8, 8BITMIME, PIPELINING and AUTH advertised."
    },
    "transport_security": {
      "title": "Mail transport security",
      "weight": 3,
      "answer": "yes",
      "evidence": null,
      "note": "Passes: SPF, DMARC quarantine, MTA-STS enforce, TLS-RPT, DNSSEC, DANE all."
    },
    "srs": {
      "title": "Sender Rewriting Scheme",
      "weight": 1,
      "answer": "no",
      "evidence": null,
      "note": "No published documentation on SRS for forwarded mail."
    },
    "arc": {
      "title": "ARC sealing",
      "weight": 1,
      "answer": "no",
      "evidence": null,
      "note": "No published documentation on ARC signing or validation."
    }
  },
  "tests": {
    "ssllabs": "A",
    "observatory": "D",
    "internetnl_web": null,
    "internetnl_mail": null,
    "trackers": [],
    "tested_at": "2026-10-01T07:46:09.063Z"
  },
  "last_modified": "2026-10-01T07:47:04Z"
}