{
  "slug": "runbox",
  "category": "email-providers",
  "name": "Runbox",
  "description": "Paid email service from Norway with custom domain hosting, standard protocols and an open-source webmail app.",
  "website": "https://runbox.com",
  "source": "https://github.com/runbox/runbox7",
  "license": null,
  "platforms": [],
  "jurisdiction": {
    "code": "NO",
    "name": "Norway",
    "eyes": "Nine Eyes",
    "eu": false,
    "gdpr": true,
    "cloud_act": null
  },
  "pick": false,
  "pick_reason": null,
  "disclosure": null,
  "grade": "D",
  "score": 49,
  "coverage": 100,
  "summary": "Runbox scores 49 out of 100 (grade D) on the email providers criteria. It meets 7 of 18 criteria: no trackers or telemetry, no ads or data sales, transparency report, open protocols, custom domains, IMAP support and POP3 support. It partly meets open source, end-to-end encryption and SMTP submission. It does not meet independent audit, tells users about requests, security headers, encrypted mailbox storage, sign up without personal data, mail transport security, Sender Rewriting Scheme and ARC sealing. It is based in Norway: Nine Eyes member; EEA member (GDPR). Automated tests: Mozilla HTTP Observatory grade D-.",
  "url": "https://privacyratings.com/email-providers/runbox/",
  "markdown": "https://privacyratings.com/email-providers/runbox/index.md",
  "answers": {
    "open_source": {
      "title": "Open source",
      "weight": 3,
      "answer": "partial",
      "evidence": "https://github.com/runbox/runbox7/blob/master/LICENSE",
      "note": "The Runbox 7 webmail app is open source under GPL-3.0. The server components are not."
    },
    "no_trackers": {
      "title": "No trackers or telemetry",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://runbox.com/about/privacy-policy/",
      "note": "The privacy policy states that no third-party tracking, statistics or web beacons are used."
    },
    "no_ads": {
      "title": "No ads or data sales",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://runbox.com/about/privacy-policy/",
      "note": "Funded by paid plans. No ads, and user data is not sold."
    },
    "independent_audit": {
      "title": "Independent audit",
      "weight": 2,
      "answer": "no",
      "evidence": null,
      "note": "No independent audit is published."
    },
    "transparency_report": {
      "title": "Transparency report",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://runbox.com/features/privacy-security/transparency-report/",
      "note": "Publishes yearly counts of disclosure requests received, complied with and rejected."
    },
    "user_notice": {
      "title": "Tells users about requests",
      "weight": 1,
      "answer": "no",
      "evidence": null,
      "note": "No published policy on notifying users about data requests."
    },
    "tls": {
      "title": "TLS configuration",
      "weight": 2,
      "answer": "pending",
      "evidence": null,
      "note": "Could not test: No endpoint could be graded"
    },
    "security_headers": {
      "title": "Security headers",
      "weight": 1,
      "answer": "no",
      "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=runbox.com",
      "note": "Grade D- (25/100+)"
    },
    "web_standards": {
      "title": "Modern web standards",
      "weight": 1,
      "answer": "pending",
      "evidence": null,
      "note": "Not tested yet."
    },
    "e2ee": {
      "title": "End-to-end encryption",
      "weight": 3,
      "answer": "partial",
      "evidence": "https://help.runbox.com/encrypting-your-runbox-email/",
      "note": "PGP and S/MIME work in desktop clients or in the webmail with browser extensions such as Mailvelope. Not built in."
    },
    "encrypted_storage": {
      "title": "Encrypted mailbox storage",
      "weight": 3,
      "answer": "no",
      "evidence": null,
      "note": "Encryption of stored mail is not documented."
    },
    "open_protocols": {
      "title": "Open protocols",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://help.runbox.com/email-program-settings/",
      "note": "IMAP, POP3 and SMTP work with any client."
    },
    "custom_domains": {
      "title": "Custom domains",
      "weight": 1,
      "answer": "yes",
      "evidence": "https://runbox.com/pricing/",
      "note": "Every plan includes at least one custom domain."
    },
    "anonymous_signup": {
      "title": "Sign up without personal data",
      "weight": 2,
      "answer": "no",
      "evidence": "https://runbox.com/about/privacy-policy/",
      "note": "Registration asks for a name, country and an alternative email address."
    },
    "mail_standards": {
      "title": "Email security standards",
      "weight": 2,
      "answer": "pending",
      "evidence": null,
      "note": "Not tested yet."
    },
    "imap_standards": {
      "title": "IMAP support",
      "weight": 2,
      "answer": "yes",
      "evidence": null,
      "note": "mail.runbox.com:993 (implicit TLS). IMAP4rev1 advertised with IDLE."
    },
    "pop3_standards": {
      "title": "POP3 support",
      "weight": 1,
      "answer": "yes",
      "evidence": null,
      "note": "mail.runbox.com:995 (implicit TLS). CAPA: TOP, USER, UIDL, SASL."
    },
    "smtp_standards": {
      "title": "SMTP submission",
      "weight": 2,
      "answer": "partial",
      "evidence": null,
      "note": "mail.runbox.com:465 (implicit TLS). Missing: SMTPUTF8."
    },
    "transport_security": {
      "title": "Mail transport security",
      "weight": 3,
      "answer": "no",
      "evidence": null,
      "note": "Passes: SPF, DMARC quarantine, TLS-RPT, DNSSEC. Missing: MTA-STS testing, DANE none."
    },
    "srs": {
      "title": "Sender Rewriting Scheme",
      "weight": 1,
      "answer": "no",
      "evidence": null,
      "note": "No published documentation on SRS for forwarded mail."
    },
    "arc": {
      "title": "ARC sealing",
      "weight": 1,
      "answer": "no",
      "evidence": null,
      "note": "No published documentation on ARC signing or validation."
    }
  },
  "tests": {
    "ssllabs": null,
    "observatory": "D-",
    "internetnl_web": null,
    "internetnl_mail": null,
    "trackers": [],
    "tested_at": "2026-10-01T07:46:51.555Z"
  },
  "last_modified": "2026-10-01T07:47:04Z"
}