{
  "slug": "stalwart-mail-server",
  "category": "mail-server-software",
  "name": "Stalwart",
  "description": "Self-hosted mail and collaboration server written in Rust, with JMAP, IMAP, POP3, SMTP, CalDAV, CardDAV and WebDAV support, built-in spam filtering and a web admin interface.",
  "website": "https://stalw.art",
  "source": "https://github.com/stalwartlabs/stalwart",
  "license": null,
  "platforms": [
    "linux",
    "macos",
    "windows"
  ],
  "jurisdiction": {
    "code": "GB",
    "name": "United Kingdom",
    "eyes": "Five Eyes",
    "eu": false,
    "gdpr": true,
    "cloud_act": "agreement"
  },
  "pick": false,
  "pick_reason": null,
  "disclosure": null,
  "grade": "A",
  "score": 100,
  "coverage": 100,
  "summary": "Stalwart scores 100 out of 100 (grade A) on the mail server software criteria. It meets 4 of 4 criteria: open source, no trackers or telemetry, no ads or data sales and independent audit. It is based in the United Kingdom: Five Eyes member; GDPR-style data protection law; CLOUD Act data access agreement with the US.",
  "url": "https://privacyratings.com/mail-server-software/stalwart-mail-server/",
  "markdown": "https://privacyratings.com/mail-server-software/stalwart-mail-server/index.md",
  "answers": {
    "open_source": {
      "title": "Open source",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://github.com/stalwartlabs/stalwart/blob/main/LICENSES/AGPL-3.0-only.txt",
      "note": "All code is public. Most is AGPL-3.0, and enterprise features in the same repository use the source-available Stalwart Enterprise License, which is not open source."
    },
    "no_trackers": {
      "title": "No trackers or telemetry",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://stalw.art/legal/privacy",
      "note": "The websites load no third-party analytics, and the self-hosted server does not send data to Stalwart Labs."
    },
    "no_ads": {
      "title": "No ads or data sales",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://stalw.art/pricing/",
      "note": "Funded by paid enterprise licenses and support. The privacy policy says personal information is not sold."
    },
    "independent_audit": {
      "title": "Independent audit",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://stalw.art/blog/security-audit/ros-report.pdf",
      "note": "Code review and penetration test by Radically Open Security, full report public."
    },
    "transparency_report": {
      "title": "Transparency report",
      "weight": 2,
      "answer": "n/a",
      "evidence": null,
      "note": "Only applies to hosted services with a website to test."
    },
    "user_notice": {
      "title": "Tells users about requests",
      "weight": 1,
      "answer": "n/a",
      "evidence": null,
      "note": "Only applies to hosted services with a website to test."
    },
    "tls": {
      "title": "TLS configuration",
      "weight": 2,
      "answer": "n/a",
      "evidence": null,
      "note": "Only applies to hosted services with a website to test."
    },
    "security_headers": {
      "title": "Security headers",
      "weight": 1,
      "answer": "n/a",
      "evidence": null,
      "note": "Only applies to hosted services with a website to test."
    },
    "web_standards": {
      "title": "Modern web standards",
      "weight": 1,
      "answer": "n/a",
      "evidence": null,
      "note": "Only applies to hosted services with a website to test."
    }
  },
  "tests": {
    "ssllabs": null,
    "observatory": null,
    "internetnl_web": null,
    "internetnl_mail": null,
    "trackers": [
      {
        "name": "Cloudflare Web Analytics",
        "host": "static.cloudflareinsights.com",
        "effect": "partial"
      }
    ],
    "tested_at": "2026-10-01T07:02:36.766Z"
  },
  "last_modified": "2026-10-01T07:44:20Z"
}