{
  "slug": "tuta",
  "category": "email-providers",
  "name": "Tuta",
  "description": "End-to-end encrypted email and calendar service from Germany, with open-source apps for web, desktop and mobile.",
  "website": "https://tuta.com",
  "source": "https://github.com/tutao/tutanota",
  "license": "GPL-3.0",
  "platforms": [],
  "jurisdiction": {
    "code": "DE",
    "name": "Germany",
    "eyes": "Fourteen Eyes",
    "eu": true,
    "gdpr": true,
    "cloud_act": null
  },
  "pick": false,
  "pick_reason": null,
  "disclosure": null,
  "grade": "C",
  "score": 61,
  "coverage": 100,
  "summary": "Tuta scores 61 out of 100 (grade C) on the email providers criteria. It meets 9 of 18 criteria: no trackers or telemetry, no ads or data sales, transparency report, security headers, end-to-end encryption, encrypted mailbox storage, custom domains, sign up without personal data and mail transport security. It partly meets open source. It does not meet independent audit, tells users about requests, open protocols, IMAP support, POP3 support, SMTP submission, Sender Rewriting Scheme and ARC sealing. It is based in Germany: Fourteen Eyes member; EU member (GDPR). Automated tests: Mozilla HTTP Observatory grade A+.",
  "url": "https://privacyratings.com/email-providers/tuta/",
  "markdown": "https://privacyratings.com/email-providers/tuta/index.md",
  "answers": {
    "open_source": {
      "title": "Open source",
      "weight": 3,
      "answer": "partial",
      "evidence": "https://github.com/tutao/tutanota/blob/master/LICENSE.txt",
      "note": "Apps are open source under GPL-3.0. The server is not."
    },
    "no_trackers": {
      "title": "No trackers or telemetry",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://tuta.com/privacy-policy",
      "note": "No Google Analytics or other third-party analysis tools. Anonymized usage statistics are collected only with prior consent."
    },
    "no_ads": {
      "title": "No ads or data sales",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://tuta.com/pricing",
      "note": "Funded by paid plans. No ads on any plan, including the free plan."
    },
    "independent_audit": {
      "title": "Independent audit",
      "weight": 2,
      "answer": "no",
      "evidence": null,
      "note": "No independent audit is published."
    },
    "transparency_report": {
      "title": "Transparency report",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://tuta.com/blog/transparency-report",
      "note": "Publishes counts of requests by type and how many led to data being released."
    },
    "user_notice": {
      "title": "Tells users about requests",
      "weight": 1,
      "answer": "no",
      "evidence": null,
      "note": "No published policy on notifying users about data requests."
    },
    "tls": {
      "title": "TLS configuration",
      "weight": 2,
      "answer": "pending",
      "evidence": null,
      "note": "Could not test: No endpoint could be graded"
    },
    "security_headers": {
      "title": "Security headers",
      "weight": 1,
      "answer": "yes",
      "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=tuta.com",
      "note": "Grade A+ (105/100+)"
    },
    "web_standards": {
      "title": "Modern web standards",
      "weight": 1,
      "answer": "pending",
      "evidence": null,
      "note": "Not tested yet."
    },
    "e2ee": {
      "title": "End-to-end encryption",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://tuta.com/encryption",
      "note": "Mail between Tuta users is always end-to-end encrypted, including subject lines. Password-protected mail is available for other recipients."
    },
    "encrypted_storage": {
      "title": "Encrypted mailbox storage",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://tuta.com/encryption",
      "note": "The whole mailbox, including the search index, is encrypted with keys only the user holds."
    },
    "open_protocols": {
      "title": "Open protocols",
      "weight": 2,
      "answer": "no",
      "evidence": "https://tuta.com/blog/desktop-clients-tutanota#security-first-approach-no-imap-no-compromises",
      "note": "No IMAP, POP3 or SMTP access. Mail can only be used in Tuta's own apps."
    },
    "custom_domains": {
      "title": "Custom domains",
      "weight": 1,
      "answer": "yes",
      "evidence": "https://tuta.com/pricing",
      "note": "Available on paid plans from Revolutionary up."
    },
    "anonymous_signup": {
      "title": "Sign up without personal data",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://tuta.com/blog/anonymous-email",
      "note": "No phone number or other email address is needed to register."
    },
    "mail_standards": {
      "title": "Email security standards",
      "weight": 2,
      "answer": "pending",
      "evidence": null,
      "note": "Not tested yet."
    },
    "imap_standards": {
      "title": "IMAP support",
      "weight": 2,
      "answer": "no",
      "evidence": null,
      "note": "Not offered."
    },
    "pop3_standards": {
      "title": "POP3 support",
      "weight": 1,
      "answer": "no",
      "evidence": null,
      "note": "Not offered."
    },
    "smtp_standards": {
      "title": "SMTP submission",
      "weight": 2,
      "answer": "no",
      "evidence": null,
      "note": "Not offered."
    },
    "transport_security": {
      "title": "Mail transport security",
      "weight": 3,
      "answer": "yes",
      "evidence": null,
      "note": "Passes: SPF, DMARC quarantine, MTA-STS enforce, TLS-RPT, DNSSEC, DANE all."
    },
    "srs": {
      "title": "Sender Rewriting Scheme",
      "weight": 1,
      "answer": "no",
      "evidence": null,
      "note": "No published documentation on SRS for forwarded mail."
    },
    "arc": {
      "title": "ARC sealing",
      "weight": 1,
      "answer": "no",
      "evidence": null,
      "note": "No published documentation on ARC signing or validation."
    }
  },
  "tests": {
    "ssllabs": null,
    "observatory": "A+",
    "internetnl_web": null,
    "internetnl_mail": null,
    "trackers": [],
    "tested_at": "2026-10-01T11:00:20.819Z"
  },
  "last_modified": "2026-10-01T11:14:42Z"
}