{
  "slug": "forward-email-webmail",
  "category": "webmail",
  "name": "Forward Email Webmail",
  "description": "Hosted webmail for Forward Email accounts, with mail, calendar and contacts, built-in OpenPGP and optional encryption of locally cached data. It shares one source-available codebase with the Forward Email desktop and mobile apps.",
  "website": "https://mail.forwardemail.net",
  "source": "https://github.com/forwardemail/mail.forwardemail.net",
  "license": null,
  "platforms": [
    "web"
  ],
  "jurisdiction": {
    "code": "US",
    "name": "United States",
    "eyes": "Five Eyes",
    "eu": false,
    "gdpr": false,
    "cloud_act": "provider"
  },
  "pick": true,
  "pick_reason": "Source-available webmail with built-in OpenPGP and no third-party analytics, covered by Cure53's audit. It works only with Forward Email accounts, not other IMAP and SMTP providers.",
  "disclosure": "Privacy Ratings is maintained by the team behind Forward Email. This entry is scored by the same criteria as every other entry in this category, and changes to it are reviewed under the published conflict-of-interest rules.",
  "grade": "C",
  "score": 74,
  "coverage": 100,
  "summary": "Forward Email Webmail scores 74 out of 100 (grade C) on the webmail criteria. It meets 6 of 13 criteria: open source, no ads or data sales, independent audit, tells users about requests, OpenPGP support and connects directly. It partly meets no trackers or telemetry, transparency report, TLS configuration, security headers, blocks remote content and self-hostable. It does not meet works with any provider. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade B and Mozilla HTTP Observatory grade B+.",
  "url": "https://privacyratings.com/webmail/forward-email-webmail/",
  "markdown": "https://privacyratings.com/webmail/forward-email-webmail/index.md",
  "answers": {
    "open_source": {
      "title": "Open source",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://github.com/forwardemail/mail.forwardemail.net/blob/main/LICENSE.md",
      "note": "All code is public. The webmail app is under the source-available Business Source License 1.1, which becomes MPL-2.0 four years after each release, and the Forward Email service behind it is published under MPL-2.0 and BUSL-1.1."
    },
    "no_trackers": {
      "title": "No trackers or telemetry",
      "weight": 3,
      "answer": "partial",
      "evidence": "https://forwardemail.net/en/privacy#analytics",
      "note": "No third-party analytics in the webmail. The privacy policy describes first-party anonymized analytics of page views and service usage, including API use, that is on by default."
    },
    "no_ads": {
      "title": "No ads or data sales",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://forwardemail.net/en/privacy",
      "note": "Funded by paid plans. No ads, and user data is not shared with third parties."
    },
    "independent_audit": {
      "title": "Independent audit",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://cure53.de/pentest-report_forward-email.pdf",
      "note": "Cure53 audited the webmail source code, including its client-side logic, together with the Forward Email service."
    },
    "transparency_report": {
      "title": "Transparency report",
      "weight": 2,
      "answer": "partial",
      "evidence": "https://forwardemail.net/technical-whitepaper.pdf",
      "note": "The technical whitepaper (section 9.3) publishes the government request policy and commits to transparency reports with request counts. A report with counts is not published yet."
    },
    "user_notice": {
      "title": "Tells users about requests",
      "weight": 1,
      "answer": "yes",
      "evidence": "https://forwardemail.net/technical-whitepaper.pdf",
      "note": "Users are notified of requests when legally allowed, with notice after disclosure when advance notice is prohibited."
    },
    "tls": {
      "title": "TLS configuration",
      "weight": 2,
      "answer": "partial",
      "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=mail.forwardemail.net&hideResults=on",
      "note": "Grade B"
    },
    "security_headers": {
      "title": "Security headers",
      "weight": 1,
      "answer": "partial",
      "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=mail.forwardemail.net",
      "note": "Grade B+ (80/100+)"
    },
    "web_standards": {
      "title": "Modern web standards",
      "weight": 1,
      "answer": "pending",
      "evidence": null,
      "note": "Not tested yet."
    },
    "openpgp": {
      "title": "OpenPGP support",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://github.com/forwardemail/mail.forwardemail.net/blob/main/src/utils/pgp-send.ts",
      "note": "OpenPGP encryption and signing are built in."
    },
    "no_cloud_relay": {
      "title": "Connects directly",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://github.com/forwardemail/mail.forwardemail.net/blob/main/README.md",
      "note": "The browser connects directly to the Forward Email API, which is the mail server, with no separate sync service."
    },
    "remote_content_blocked": {
      "title": "Blocks remote content",
      "weight": 2,
      "answer": "partial",
      "evidence": "https://github.com/forwardemail/mail.forwardemail.net/blob/main/src/stores/settingsRegistry.ts",
      "note": "Tracking pixels are blocked by default, but other remote images load unless blocking is turned on in settings."
    },
    "any_provider": {
      "title": "Works with any provider",
      "weight": 1,
      "answer": "no",
      "evidence": "https://forwardemail.net/en/faq#do-you-offer-a-webmail-client",
      "note": "Works only with Forward Email accounts. The maintainers state that a future version is planned to support any IMAP and SMTP provider."
    },
    "self_hostable": {
      "title": "Self-hostable",
      "weight": 1,
      "answer": "partial",
      "evidence": "https://github.com/forwardemail/mail.forwardemail.net/blob/main/README.md",
      "note": "The static web app can be built and served from another server, with a configurable API address, but there is no official self-hosting guide and it only works with the Forward Email API."
    }
  },
  "tests": {
    "ssllabs": "B",
    "observatory": "B+",
    "internetnl_web": null,
    "internetnl_mail": null,
    "trackers": [],
    "tested_at": "2026-10-01T07:06:27.819Z"
  },
  "last_modified": "2026-10-01T07:44:20Z"
}