{
  "slug": "protonmail",
  "category": "email-providers",
  "name": "Proton Mail",
  "description": "End-to-end encrypted email service from Switzerland, with apps for web, Android, iOS and desktop.",
  "website": "https://proton.me/mail",
  "source": "https://github.com/ProtonMail/WebClients",
  "license": "GPL-3.0",
  "platforms": [],
  "jurisdiction": {
    "code": "CH",
    "name": "Switzerland",
    "eyes": null,
    "eu": false,
    "gdpr": true,
    "cloud_act": null
  },
  "pick": false,
  "pick_reason": null,
  "disclosure": null,
  "grade": "C",
  "score": 64,
  "coverage": 100,
  "summary": "Proton Mail scores 64 out of 100 (grade C) on the email providers criteria. It meets 8 of 19 criteria: no ads or data sales, transparency report, tells users about requests, TLS configuration, end-to-end encryption, encrypted mailbox storage, custom domains and mail transport security. It partly meets open source, no trackers or telemetry, independent audit, security headers, open protocols and sign up without personal data. It does not meet IMAP support, POP3 support, SMTP submission, Sender Rewriting Scheme and ARC sealing. It is based in Switzerland: Not in the Five, Nine or Fourteen Eyes; GDPR-style data protection law. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B+.",
  "url": "https://privacyratings.com/email-providers/protonmail/",
  "markdown": "https://privacyratings.com/email-providers/protonmail/index.md",
  "answers": {
    "open_source": {
      "title": "Open source",
      "weight": 3,
      "answer": "partial",
      "evidence": "https://github.com/ProtonMail/WebClients/blob/main/LICENSE",
      "note": "Apps are open source under GPL-3.0. The server is not."
    },
    "no_trackers": {
      "title": "No trackers or telemetry",
      "weight": 3,
      "answer": "partial",
      "evidence": "https://proton.me/legal/privacy",
      "note": "Website analytics are self-hosted. The apps include crash reporting and usage statistics, which are on by default and can be turned off."
    },
    "no_ads": {
      "title": "No ads or data sales",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://proton.me/mail/pricing",
      "note": "No ads on any plan, including the free plan."
    },
    "independent_audit": {
      "title": "Independent audit",
      "weight": 2,
      "answer": "partial",
      "evidence": "https://proton.me/blog/soc-2",
      "note": "Proton completed a SOC 2 Type II audit, but the report is not public."
    },
    "transparency_report": {
      "title": "Transparency report",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://proton.me/legal/transparency",
      "note": "Publishes yearly counts of legal orders received, complied with and contested."
    },
    "user_notice": {
      "title": "Tells users about requests",
      "weight": 1,
      "answer": "yes",
      "evidence": "https://proton.me/legal/law-enforcement",
      "note": "Targeted users are notified of data requests, with delays only when Swiss law, a court order or a risk to life requires it."
    },
    "tls": {
      "title": "TLS configuration",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=proton.me&hideResults=on",
      "note": "Grade A+"
    },
    "security_headers": {
      "title": "Security headers",
      "weight": 1,
      "answer": "partial",
      "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=proton.me",
      "note": "Grade B+ (80/100+)"
    },
    "web_standards": {
      "title": "Modern web standards",
      "weight": 1,
      "answer": "pending",
      "evidence": null,
      "note": "Not tested yet."
    },
    "e2ee": {
      "title": "End-to-end encryption",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://proton.me/support/proton-mail-encryption-explained",
      "note": "Always end-to-end encrypted between Proton users. Password-protected messages or PGP for other recipients. Subject lines are not end-to-end encrypted."
    },
    "encrypted_storage": {
      "title": "Encrypted mailbox storage",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://proton.me/support/proton-mail-encryption-explained",
      "note": "Stored mail uses zero-access encryption that Proton cannot read."
    },
    "open_protocols": {
      "title": "Open protocols",
      "weight": 2,
      "answer": "partial",
      "evidence": "https://proton.me/support/imap-smtp-and-pop3-setup",
      "note": "IMAP and SMTP need the Proton Mail Bridge app on a paid plan. POP3 is not supported."
    },
    "custom_domains": {
      "title": "Custom domains",
      "weight": 1,
      "answer": "yes",
      "evidence": "https://proton.me/mail/pricing",
      "note": "From the Mail Plus plan up. Not on the free plan."
    },
    "anonymous_signup": {
      "title": "Sign up without personal data",
      "weight": 2,
      "answer": "partial",
      "evidence": "https://proton.me/legal/privacy",
      "note": "No personal data is needed by default, but some sign-ups must be verified by email or SMS."
    },
    "mail_standards": {
      "title": "Email security standards",
      "weight": 2,
      "answer": "pending",
      "evidence": null,
      "note": "Not tested yet."
    },
    "imap_standards": {
      "title": "IMAP support",
      "weight": 2,
      "answer": "no",
      "evidence": null,
      "note": "Not offered."
    },
    "pop3_standards": {
      "title": "POP3 support",
      "weight": 1,
      "answer": "no",
      "evidence": null,
      "note": "Not offered."
    },
    "smtp_standards": {
      "title": "SMTP submission",
      "weight": 2,
      "answer": "no",
      "evidence": null,
      "note": "Not offered."
    },
    "transport_security": {
      "title": "Mail transport security",
      "weight": 3,
      "answer": "yes",
      "evidence": null,
      "note": "Passes: SPF, DMARC quarantine, MTA-STS enforce, TLS-RPT, DNSSEC, DANE all."
    },
    "srs": {
      "title": "Sender Rewriting Scheme",
      "weight": 1,
      "answer": "no",
      "evidence": null,
      "note": "No published documentation on SRS for forwarded mail."
    },
    "arc": {
      "title": "ARC sealing",
      "weight": 1,
      "answer": "no",
      "evidence": null,
      "note": "No published documentation on ARC signing or validation."
    }
  },
  "tests": {
    "ssllabs": "A+",
    "observatory": "B+",
    "internetnl_web": null,
    "internetnl_mail": null,
    "trackers": [],
    "tested_at": "2026-10-01T07:46:21.987Z"
  },
  "last_modified": "2026-10-01T07:47:04Z"
}