{
  "slug": "migadu",
  "category": "email-providers",
  "name": "Migadu",
  "description": "Swiss email hosting service for custom domains, priced by usage rather than per mailbox, with standard IMAP, POP3 and SMTP access.",
  "website": "https://migadu.com",
  "license": null,
  "platforms": [],
  "jurisdiction": {
    "code": "CH",
    "name": "Switzerland",
    "eyes": null,
    "eu": false,
    "gdpr": true,
    "cloud_act": null
  },
  "pick": false,
  "pick_reason": null,
  "disclosure": null,
  "grade": "F",
  "score": 35,
  "coverage": 100,
  "summary": "Migadu scores 35 out of 100 (grade F) on the email providers criteria. It meets 6 of 19 criteria: no trackers or telemetry, no ads or data sales, TLS configuration, open protocols, custom domains and POP3 support. It partly meets IMAP support and SMTP submission. It does not meet open source, independent audit, transparency report, tells users about requests, security headers, end-to-end encryption, encrypted mailbox storage, sign up without personal data, mail transport security, Sender Rewriting Scheme and ARC sealing. It is based in Switzerland: Not in the Five, Nine or Fourteen Eyes; GDPR-style data protection law. Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade D.",
  "url": "https://privacyratings.com/email-providers/migadu/",
  "markdown": "https://privacyratings.com/email-providers/migadu/index.md",
  "answers": {
    "open_source": {
      "title": "Open source",
      "weight": 3,
      "answer": "no",
      "evidence": null,
      "note": "Closed source."
    },
    "no_trackers": {
      "title": "No trackers or telemetry",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://migadu.com/privacy/",
      "note": "No tracking or analytics cookies, and no website analytics."
    },
    "no_ads": {
      "title": "No ads or data sales",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://migadu.com/about/",
      "note": "Funded by paid plans. No ads and no outside investors."
    },
    "independent_audit": {
      "title": "Independent audit",
      "weight": 2,
      "answer": "no",
      "evidence": null,
      "note": "No independent audit is published."
    },
    "transparency_report": {
      "title": "Transparency report",
      "weight": 2,
      "answer": "no",
      "evidence": null,
      "note": "No transparency report or government request policy is published."
    },
    "user_notice": {
      "title": "Tells users about requests",
      "weight": 1,
      "answer": "no",
      "evidence": null,
      "note": "No published policy on notifying users about data requests."
    },
    "tls": {
      "title": "TLS configuration",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=migadu.com&hideResults=on",
      "note": "Grade A"
    },
    "security_headers": {
      "title": "Security headers",
      "weight": 1,
      "answer": "no",
      "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=migadu.com",
      "note": "Grade D (30/100+)"
    },
    "web_standards": {
      "title": "Modern web standards",
      "weight": 1,
      "answer": "pending",
      "evidence": null,
      "note": "Not tested yet."
    },
    "e2ee": {
      "title": "End-to-end encryption",
      "weight": 3,
      "answer": "no",
      "evidence": "https://migadu.com/procon/",
      "note": "Not supported. Migadu recommends OpenPGP tools in the mail client."
    },
    "encrypted_storage": {
      "title": "Encrypted mailbox storage",
      "weight": 3,
      "answer": "no",
      "evidence": "https://migadu.com/procon/",
      "note": "Stored mail is not encrypted. Data is split across disks instead."
    },
    "open_protocols": {
      "title": "Open protocols",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://migadu.com/guides/thunderbird/",
      "note": "IMAP, POP3 and SMTP work with any client."
    },
    "custom_domains": {
      "title": "Custom domains",
      "weight": 1,
      "answer": "yes",
      "evidence": "https://migadu.com/pricing/",
      "note": "The service is built for custom domains on every plan."
    },
    "anonymous_signup": {
      "title": "Sign up without personal data",
      "weight": 2,
      "answer": "no",
      "evidence": "https://admin.migadu.com/public/signup",
      "note": "An existing email address is needed to verify the account."
    },
    "mail_standards": {
      "title": "Email security standards",
      "weight": 2,
      "answer": "pending",
      "evidence": null,
      "note": "Not tested yet."
    },
    "imap_standards": {
      "title": "IMAP support",
      "weight": 2,
      "answer": "partial",
      "evidence": null,
      "note": "imap.migadu.com:993 (implicit TLS). IMAP4rev2 advertised, no IDLE before login."
    },
    "pop3_standards": {
      "title": "POP3 support",
      "weight": 1,
      "answer": "yes",
      "evidence": null,
      "note": "pop.migadu.com:995 (implicit TLS). CAPA: TOP, UIDL, USER, RESP-CODES, PIPELINING, SASL, AUTH-RESP-CODE, IMPLEMENTATION."
    },
    "smtp_standards": {
      "title": "SMTP submission",
      "weight": 2,
      "answer": "partial",
      "evidence": null,
      "note": "smtp.migadu.com:587 (STARTTLS). SMTPUTF8, 8BITMIME, PIPELINING and AUTH advertised."
    },
    "transport_security": {
      "title": "Mail transport security",
      "weight": 3,
      "answer": "no",
      "evidence": null,
      "note": "Passes: SPF, DNSSEC. Missing: DMARC missing, MTA-STS missing, TLS-RPT, DANE none."
    },
    "srs": {
      "title": "Sender Rewriting Scheme",
      "weight": 1,
      "answer": "no",
      "evidence": null,
      "note": "No published documentation on SRS for forwarded mail."
    },
    "arc": {
      "title": "ARC sealing",
      "weight": 1,
      "answer": "no",
      "evidence": null,
      "note": "No published documentation on ARC signing or validation."
    }
  },
  "tests": {
    "ssllabs": "A",
    "observatory": "D",
    "internetnl_web": null,
    "internetnl_mail": null,
    "trackers": [],
    "tested_at": "2026-10-01T11:00:18.651Z"
  },
  "last_modified": "2026-10-01T11:14:42Z"
}