Email forwarding and aliases
Addy privacy rating
Open-source email alias service that forwards mail from unlimited aliases to real mailboxes, with optional OpenPGP encryption. Has a free plan and can be self-hosted.
Summary
Addy scores 58 out of 100 (grade D) on the email forwarding and aliases criteria. It meets 7 of 16 criteria: open source, no trackers or telemetry, no ads or data sales, security headers, no stored mail, custom domains and mail transport security. It partly meets TLS configuration, end-to-end encryption and ARC sealing. It does not meet independent audit, transparency report, tells users about requests, open protocols, sign up without personal data and Sender Rewriting Scheme. It is based in the United Kingdom: Five Eyes member; GDPR-style data protection law; CLOUD Act data access agreement with the US. Automated tests: SSL Labs grade A- and Mozilla HTTP Observatory grade A+.
Score 58 out of 100. How scoring works
Criteria
- Yes
-
Yes
No trackers or telemetry Weight 3 of 3
Are the website and apps free of third-party trackers, with any analytics anonymous and any telemetry off by default?
No analytics or trackers, only server access logs, and no third-party content.
-
Yes
No ads or data sales Weight 2 of 3
Is the product funded without advertising, ad targeting or selling user data?
Funded by paid plans. No ads, and personal information is never sold or shared.
-
No
Independent audit Weight 2 of 3
Has an independent security or privacy audit been published within the last three years?
No independent audit is published.
-
No
Transparency report Weight 2 of 3
Does the provider regularly publish how many government and legal requests it receives and how it responds?
No transparency report or government request policy is published.
-
No
Tells users about requests Weight 1 of 3
Does the provider promise to tell users about requests for their data, unless a court forbids it?
No published policy on notifying users about data requests.
-
Partial
End-to-end encryption Weight 2 of 3
Can mail be end-to-end encrypted so that the provider cannot read message contents?
Forwarded mail can be encrypted with the user's own OpenPGP key. Not on by default.
-
Yes
No stored mail Weight 3 of 3
Is forwarded mail passed through without being written to disk?
Mail is not stored. Failed deliveries are kept only if the user turns that option on.
-
No
Open protocols Weight 2 of 3
Can any standard app connect over IMAP, POP3, SMTP, CalDAV or CardDAV, without extra software?
No IMAP or SMTP access. Mail is forwarded to an existing mailbox and replies go through the alias.
-
Yes
Custom domains Weight 1 of 3
Can mail be sent and received with your own domain?
From the Lite plan up.
-
No
Sign up without personal data Weight 2 of 3
Can an account be created without a phone number or another email address?
An existing email address is required to create an account and receive forwarded mail.
-
No
Sender Rewriting Scheme Weight 2 of 3
Is the envelope sender rewritten with SRS when mail is forwarded, so forwarded mail keeps passing SPF?
No SRS. Forwarded mail is re-sent with a VERP return address on addy.io's domain.
-
Partial
ARC sealing Weight 1 of 3
Does the provider validate and add ARC (RFC 8617) signatures, so authentication results survive forwarding?
The documented setup adds ARC signatures with Rspamd. Validation of inbound ARC chains is not documented.
Automated tests
-
Partial
TLS configuration Weight 2 of 3
Does the website pass the Qualys SSL Labs test with a grade of A or better?
Grade A-
-
Yes
Security headers Weight 1 of 3
Does the website pass the Mozilla HTTP Observatory test with a grade of A or better?
Grade A+ (120/100+)
-
Not tested yet
Modern web standards Weight 1 of 3
Does the website score 90% or higher on the Internet.nl website test?
Not tested yet.
-
Not tested yet
Email security standards Weight 2 of 3
Does the mail domain score 90% or higher on the Internet.nl email test?
Not tested yet.
-
Yes
Mail transport security Weight 3 of 3
Does the mail domain enforce encrypted, authenticated delivery with MTA-STS, DANE, DNSSEC, TLS-RPT and an enforced DMARC policy?
Passes: SPF, DMARC reject, MTA-STS enforce, TLS-RPT, DNSSEC, DANE all.
Email standards
- Yes: Mail serversMXmx1.addy.io, mx2.addy.io
- Yes: RFC 7208 sender policySPFpublished
- Yes: RFC 7489. Quarantine or reject counts as enforcedDMARCp=reject
- Yes: RFC 8461 strict transport securityMTA-STSenforce
- Yes: RFC 8460 TLS failure reportsTLS-RPTpublished
- Yes: RFC 4033 signed DNSDNSSECsigned and validated
- Yes: RFC 7672 TLSA records on MX hostsDANEall
- No: Brand logo record (not scored)BIMInone
- No: RFC 6186 and RFC 8314 service records (not scored)SRVnone
IMAP
Could not test: No server found (set a host in the rating file or publish RFC 6186 SRV records)
POP3
Could not test: No server found (set a host in the rating file or publish RFC 6186 SRV records)
SMTP submission
Could not test: No server found (set a host in the rating file or publish RFC 6186 SRV records)
Capabilities are what each server advertises before login. How these tests work