{
  "slug": "forward-email",
  "category": "email-sending",
  "name": "Forward Email",
  "description": "Email service whose paid plans include outbound SMTP and an email API for sending from apps and websites with a custom domain. Message bodies are purged after delivery by default.",
  "website": "https://forwardemail.net",
  "source": "https://github.com/forwardemail/forwardemail.net",
  "license": null,
  "platforms": [
    "web"
  ],
  "jurisdiction": {
    "code": "US",
    "name": "United States",
    "eyes": "Five Eyes",
    "eu": false,
    "gdpr": false,
    "cloud_act": "provider"
  },
  "pick": false,
  "pick_reason": null,
  "disclosure": "Privacy Ratings is maintained by the team behind Forward Email. This entry is scored by the same criteria as every other entry in this category, and changes to it are reviewed under the published conflict-of-interest rules.",
  "grade": "B",
  "score": 85,
  "coverage": 100,
  "summary": "Forward Email scores 85 out of 100 (grade B) on the email sending services criteria. It meets 9 of 12 criteria: open source, no ads or data sales, independent audit, tells users about requests, TLS configuration, security headers, message content deleted after delivery, open and click tracking off by default and encrypted delivery can be enforced. It partly meets no trackers or telemetry and transparency report. It does not meet EU data location. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade A+.",
  "url": "https://privacyratings.com/email-sending/forward-email/",
  "markdown": "https://privacyratings.com/email-sending/forward-email/index.md",
  "answers": {
    "open_source": {
      "title": "Open source",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://github.com/forwardemail/forwardemail.net/blob/master/LICENSE.md",
      "note": "All code is public, including the outbound SMTP servers that run the service. Core mail storage and protocol code is MPL-2.0 and the rest is under the source-available Business Source License 1.1 (BUSL-1.1), which becomes MPL-2.0 four years after each release."
    },
    "no_trackers": {
      "title": "No trackers or telemetry",
      "weight": 3,
      "answer": "partial",
      "evidence": "https://forwardemail.net/en/privacy#analytics",
      "note": "No third-party analytics. First-party anonymized analytics of page views and service usage is on by default, and Cloudflare Turnstile loads on sign-in and sign-up forms."
    },
    "no_ads": {
      "title": "No ads or data sales",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://forwardemail.net/en/private-business-email",
      "note": "Funded by paid plans. No ads, and the privacy policy states user data is not shared with third parties."
    },
    "independent_audit": {
      "title": "Independent audit",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://cure53.de/pentest-report_forward-email.pdf",
      "note": "Two independent Cure53 audits of the code and the infrastructure are published."
    },
    "transparency_report": {
      "title": "Transparency report",
      "weight": 2,
      "answer": "partial",
      "evidence": "https://forwardemail.net/technical-whitepaper.pdf",
      "note": "The technical whitepaper (section 9.3) publishes the government request policy and commits to transparency reports with request counts. A report with counts is not published yet."
    },
    "user_notice": {
      "title": "Tells users about requests",
      "weight": 1,
      "answer": "yes",
      "evidence": "https://forwardemail.net/technical-whitepaper.pdf",
      "note": "Users are notified of requests when legally allowed, with notice after disclosure when advance notice is prohibited."
    },
    "tls": {
      "title": "TLS configuration",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=forwardemail.net&hideResults=on",
      "note": "Grade A+"
    },
    "security_headers": {
      "title": "Security headers",
      "weight": 1,
      "answer": "yes",
      "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=forwardemail.net",
      "note": "Grade A+ (125/100+)"
    },
    "web_standards": {
      "title": "Modern web standards",
      "weight": 1,
      "answer": "pending",
      "evidence": null,
      "note": "Not tested yet."
    },
    "content_retention": {
      "title": "Message content deleted after delivery",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://forwardemail.net/en/privacy#outbound-smtp-emails",
      "note": "Outbound mail is queued for up to about 30 days until it is delivered or fails permanently. The body is then purged by default, and can be kept for up to 30 days if the sender turns this on."
    },
    "tracking_off_by_default": {
      "title": "Open and click tracking off by default",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://forwardemail.net/en/email-api#outbound-emails",
      "note": "The email API and SMTP documentation describe no open or click tracking."
    },
    "enforced_tls": {
      "title": "Encrypted delivery can be enforced",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://forwardemail.net/en/faq#do-you-use-tls-encryption-for-email-forwarding",
      "note": "Outbound delivery enforces the recipient domain's MTA-STS policy and retries later instead of sending without TLS."
    },
    "eu_data_location": {
      "title": "EU data location",
      "weight": 1,
      "answer": "no",
      "evidence": "https://forwardemail.net/en/faq#can-i-keep-my-email-processing-and-storage-in-the-eu-data-residency",
      "note": "All processing and storage, including outbound SMTP, is in the United States. An EU location is not available."
    }
  },
  "tests": {
    "ssllabs": "A+",
    "observatory": "A+",
    "internetnl_web": null,
    "internetnl_mail": null,
    "trackers": [],
    "tested_at": "2026-10-01T07:26:05.785Z"
  },
  "last_modified": "2026-10-01T07:44:20Z"
}