Email forwarding and aliases
Forward Email privacy rating
Email forwarding and alias service for custom domains. Mail is forwarded in memory to existing mailboxes or webhooks, with optional OpenPGP encryption, and paid plans add SMTP sending and encrypted IMAP mailboxes.
Summary
Forward Email scores 86 out of 100 (grade B) on the email forwarding and aliases criteria. It meets 12 of 16 criteria: open source, no ads or data sales, independent audit, tells users about requests, TLS configuration, security headers, no stored mail, open protocols, custom domains, mail transport security, Sender Rewriting Scheme and ARC sealing. It partly meets no trackers or telemetry, transparency report, end-to-end encryption and sign up without personal data. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade A+.
Score 86 out of 100. How scoring works
Criteria
-
Yes
Open source Weight 3 of 3 Source-available
Is all the source code needed to run the product public?
All code is public, including the MX forwarding servers that run the service. Core mail storage and protocol code is MPL-2.0 and the rest is under the source-available Business Source License 1.1 (BUSL-1.1), which becomes MPL-2.0 four years after each release.
-
Partial
No trackers or telemetry Weight 3 of 3
Are the website and apps free of third-party trackers, with any analytics anonymous and any telemetry off by default?
No third-party analytics. First-party anonymized analytics of page views and service usage is on by default, and Cloudflare Turnstile loads on sign-in and sign-up forms.
-
Yes
No ads or data sales Weight 2 of 3
Is the product funded without advertising, ad targeting or selling user data?
Funded by paid plans. No ads, and the privacy policy states user data is not shared with third parties.
-
Yes
Independent audit Weight 2 of 3
Has an independent security or privacy audit been published within the last three years?
Two independent Cure53 audits of the code, including the MX servers, and the infrastructure are published.
-
Partial
Transparency report Weight 2 of 3
Does the provider regularly publish how many government and legal requests it receives and how it responds?
The technical whitepaper (section 9.3) publishes the government request policy and commits to transparency reports with request counts. A report with counts is not published yet.
-
Yes
Tells users about requests Weight 1 of 3
Does the provider promise to tell users about requests for their data, unless a court forbids it?
Users are notified of requests when legally allowed, with notice after disclosure when advance notice is prohibited.
-
Partial
End-to-end encryption Weight 2 of 3
Can mail be end-to-end encrypted so that the provider cannot read message contents?
Forwarded mail is encrypted with OpenPGP when the recipient has an uploaded key or publishes one through Web Key Directory. Mail to webhooks and mail from senders with a DMARC reject policy is not encrypted.
-
Yes
No stored mail Weight 3 of 3
Is forwarded mail passed through without being written to disk?
Forwarded mail is processed in memory and never written to disk. SMTP error logs keep the envelope and headers, not the body, for 7 days.
-
Yes
Open protocols Weight 2 of 3
Can any standard app connect over IMAP, POP3, SMTP, CalDAV or CardDAV, without extra software?
IMAP, POP3 and SMTP work with any client on every paid plan, with no bridge app.
-
Yes
Custom domains Weight 1 of 3
Can mail be sent and received with your own domain?
Custom domains are supported on every plan, including the free plan.
-
Partial
Sign up without personal data Weight 2 of 3
Can an account be created without a phone number or another email address?
The free plan needs no account. Forwarding is set up with MX and TXT records on the domain, and the destination address in the TXT record is public unless encrypted. Paid plans need an account with an existing email address. No phone number is asked for.
-
Yes
Sender Rewriting Scheme Weight 2 of 3
Is the envelope sender rewritten with SRS when mail is forwarded, so forwarded mail keeps passing SPF?
Applied automatically to all forwarded mail.
-
Yes
ARC sealing Weight 1 of 3
Does the provider validate and add ARC (RFC 8617) signatures, so authentication results survive forwarding?
ARC is supported on all plans, with inbound chains validated and forwarded mail ARC-sealed.
Automated tests
-
Yes
TLS configuration Weight 2 of 3
Does the website pass the Qualys SSL Labs test with a grade of A or better?
Grade A+
-
Yes
Security headers Weight 1 of 3
Does the website pass the Mozilla HTTP Observatory test with a grade of A or better?
Grade A+ (125/100+)
-
Not tested yet
Modern web standards Weight 1 of 3
Does the website score 90% or higher on the Internet.nl website test?
Not tested yet.
-
Not tested yet
Email security standards Weight 2 of 3
Does the mail domain score 90% or higher on the Internet.nl email test?
Not tested yet.
-
Yes
Mail transport security Weight 3 of 3
Does the mail domain enforce encrypted, authenticated delivery with MTA-STS, DANE, DNSSEC, TLS-RPT and an enforced DMARC policy?
Passes: SPF, DMARC reject, MTA-STS enforce, TLS-RPT, DNSSEC, DANE all.
Email standards
- Yes: Mail serversMXmx1.forwardemail.net, mx2.forwardemail.net
- Yes: RFC 7208 sender policySPFpublished
- Yes: RFC 7489. Quarantine or reject counts as enforcedDMARCp=reject
- Yes: RFC 8461 strict transport securityMTA-STSenforce
- Yes: RFC 8460 TLS failure reportsTLS-RPTpublished
- Yes: RFC 4033 signed DNSDNSSECsigned and validated
- Yes: RFC 7672 TLSA records on MX hostsDANEall
- No: Brand logo record (not scored)BIMInone
- Yes: RFC 6186 and RFC 8314 service records (not scored)SRVclient autoconfiguration published
IMAP imap.forwardemail.net:993 · implicit TLS
- XAPPLEPUSHSERVICE
- IMAP4REV1
- APPENDLIMIT=52428800
- AUTH=PLAIN
- AUTH=PLAIN-CLIENTTOKEN
- CHILDREN
- CONDSTORE
- ENABLE
- ID
- IDLE
- MOVE
- NAMESPACE
- QUOTA
- SASL-IR
- SPECIAL-USE
- UIDPLUS
- UNSELECT
- UTF8=ACCEPT
- XLIST
POP3 pop3.forwardemail.net:995 · implicit TLS
- TOP
- UIDL
- USER
- RESP-CODES
- SASL
- PIPELINING
SMTP submission smtp.forwardemail.net:465 · implicit TLS
- PIPELINING
- 8BITMIME
- SMTPUTF8
- ENHANCEDSTATUSCODES
- DSN
- AUTH
- REQUIRETLS
- SIZE
Capabilities are what each server advertises before login. How these tests work