Privacy Ratings

Email forwarding and aliases

Addy privacy rating

Open-source email alias service that forwards mail from unlimited aliases to real mailboxes, with optional OpenPGP encryption. Has a free plan and can be self-hosted.

United Kingdom Five EyesLicense: AGPL-3.0

Summary

Addy scores 58 out of 100 (grade D) on the email forwarding and aliases criteria. It meets 7 of 16 criteria: open source, no trackers or telemetry, no ads or data sales, security headers, no stored mail, custom domains and mail transport security. It partly meets TLS configuration, end-to-end encryption and ARC sealing. It does not meet independent audit, transparency report, tells users about requests, open protocols, sign up without personal data and Sender Rewriting Scheme. It is based in the United Kingdom: Five Eyes member; GDPR-style data protection law; CLOUD Act data access agreement with the US. Automated tests: SSL Labs grade A- and Mozilla HTTP Observatory grade A+.

Score 58 out of 100. How scoring works

Criteria

  • Yes

    Open source Weight 3 of 3

    Is all the source code needed to run the product public?

    AGPL-3.0.

    github.com

  • Yes

    No trackers or telemetry Weight 3 of 3

    Are the website and apps free of third-party trackers, with any analytics anonymous and any telemetry off by default?

    No analytics or trackers, only server access logs, and no third-party content.

    addy.io

  • Yes

    No ads or data sales Weight 2 of 3

    Is the product funded without advertising, ad targeting or selling user data?

    Funded by paid plans. No ads, and personal information is never sold or shared.

    addy.io

  • No

    Independent audit Weight 2 of 3

    Has an independent security or privacy audit been published within the last three years?

    No independent audit is published.

  • No

    Transparency report Weight 2 of 3

    Does the provider regularly publish how many government and legal requests it receives and how it responds?

    No transparency report or government request policy is published.

  • No

    Tells users about requests Weight 1 of 3

    Does the provider promise to tell users about requests for their data, unless a court forbids it?

    No published policy on notifying users about data requests.

  • Partial

    End-to-end encryption Weight 2 of 3

    Can mail be end-to-end encrypted so that the provider cannot read message contents?

    Forwarded mail can be encrypted with the user's own OpenPGP key. Not on by default.

    addy.io

  • Yes

    No stored mail Weight 3 of 3

    Is forwarded mail passed through without being written to disk?

    Mail is not stored. Failed deliveries are kept only if the user turns that option on.

    addy.io

  • No

    Open protocols Weight 2 of 3

    Can any standard app connect over IMAP, POP3, SMTP, CalDAV or CardDAV, without extra software?

    No IMAP or SMTP access. Mail is forwarded to an existing mailbox and replies go through the alias.

    addy.io

  • Yes

    Custom domains Weight 1 of 3

    Can mail be sent and received with your own domain?

    From the Lite plan up.

    addy.io

  • No

    Sign up without personal data Weight 2 of 3

    Can an account be created without a phone number or another email address?

    An existing email address is required to create an account and receive forwarded mail.

  • No

    Sender Rewriting Scheme Weight 2 of 3

    Is the envelope sender rewritten with SRS when mail is forwarded, so forwarded mail keeps passing SPF?

    No SRS. Forwarded mail is re-sent with a VERP return address on addy.io's domain.

    github.com

  • Partial

    ARC sealing Weight 1 of 3

    Does the provider validate and add ARC (RFC 8617) signatures, so authentication results survive forwarding?

    The documented setup adds ARC signatures with Rspamd. Validation of inbound ARC chains is not documented.

    github.com

Automated tests

  • Partial

    TLS configuration Weight 2 of 3

    Does the website pass the Qualys SSL Labs test with a grade of A or better?

    Grade A-

    ssllabs.com

  • Yes

    Security headers Weight 1 of 3

    Does the website pass the Mozilla HTTP Observatory test with a grade of A or better?

    Grade A+ (120/100+)

    developer.mozilla.org

  • Not tested yet

    Modern web standards Weight 1 of 3

    Does the website score 90% or higher on the Internet.nl website test?

    Not tested yet.

  • Not tested yet

    Email security standards Weight 2 of 3

    Does the mail domain score 90% or higher on the Internet.nl email test?

    Not tested yet.

  • Yes

    Mail transport security Weight 3 of 3

    Does the mail domain enforce encrypted, authenticated delivery with MTA-STS, DANE, DNSSEC, TLS-RPT and an enforced DMARC policy?

    Passes: SPF, DMARC reject, MTA-STS enforce, TLS-RPT, DNSSEC, DANE all.

Email standards

  • Yes: Mail serversMXmx1.addy.io, mx2.addy.io
  • Yes: RFC 7208 sender policySPFpublished
  • Yes: RFC 7489. Quarantine or reject counts as enforcedDMARCp=reject
  • Yes: RFC 8461 strict transport securityMTA-STSenforce
  • Yes: RFC 8460 TLS failure reportsTLS-RPTpublished
  • Yes: RFC 4033 signed DNSDNSSECsigned and validated
  • Yes: RFC 7672 TLSA records on MX hostsDANEall
  • No: Brand logo record (not scored)BIMInone
  • No: RFC 6186 and RFC 8314 service records (not scored)SRVnone

IMAP

Could not test: No server found (set a host in the rating file or publish RFC 6186 SRV records)

POP3

Could not test: No server found (set a host in the rating file or publish RFC 6186 SRV records)

SMTP submission

Could not test: No server found (set a host in the rating file or publish RFC 6186 SRV records)

Capabilities are what each server advertises before login. How these tests work

Other email forwarding and aliases

All 9 email forwarding and aliases