Email providers
Disroot privacy rating
Volunteer-run platform from the Netherlands offering email and other open services.
Summary
Disroot scores 59 out of 100 (grade D) on the email providers criteria. It meets 9 of 19 criteria: open source, no trackers or telemetry, no ads or data sales, TLS configuration, open protocols, custom domains, IMAP support, POP3 support and mail transport security. It partly meets security headers, end-to-end encryption and SMTP submission. It does not meet independent audit, transparency report, tells users about requests, encrypted mailbox storage, sign up without personal data, Sender Rewriting Scheme and ARC sealing. It is based in the Netherlands: Nine Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.
Score 59 out of 100. How scoring works
Criteria
-
Yes
Open source Weight 3 of 3
Is all the source code needed to run the product public?
Runs only free and open-source software such as Postfix, Dovecot and Roundcube. Deployment roles are published at git.disroot.org.
-
Yes
No trackers or telemetry Weight 3 of 3
Are the website and apps free of third-party trackers, with any analytics anonymous and any telemetry off by default?
The privacy policy states that user behavior is not analyzed or profiled and that there are no advertisers.
-
Yes
No ads or data sales Weight 2 of 3
Is the product funded without advertising, ad targeting or selling user data?
Funded by donations. No ads and no data sales.
-
No
Independent audit Weight 2 of 3
Has an independent security or privacy audit been published within the last three years?
No independent audit is published.
-
No
Transparency report Weight 2 of 3
Does the provider regularly publish how many government and legal requests it receives and how it responds?
No transparency report or government request policy is published.
-
No
Tells users about requests Weight 1 of 3
Does the provider promise to tell users about requests for their data, unless a court forbids it?
No published policy on notifying users about data requests.
-
Partial
End-to-end encryption Weight 3 of 3
Can mail be end-to-end encrypted so that the provider cannot read message contents?
OpenPGP is possible with the Mailvelope browser extension or a desktop client. Not on by default.
-
No
Encrypted mailbox storage Weight 3 of 3
Is stored mail encrypted with a key the provider does not hold?
Mail is stored unencrypted unless the user encrypts it. An opt-in Lacre beta encrypts incoming mail with the user's own PGP key for a limited group of users.
-
Yes
Open protocols Weight 2 of 3
Can any standard app connect over IMAP, POP3, SMTP, CalDAV or CardDAV, without extra software?
IMAP, POP3 and SMTP work with any client.
-
Yes
Custom domains Weight 1 of 3
Can mail be sent and received with your own domain?
Available as a lifetime feature after a donation of the suggested amount.
-
No
Sign up without personal data Weight 2 of 3
Can an account be created without a phone number or another email address?
An existing email address is required for verification during sign-up.
-
No
Sender Rewriting Scheme Weight 1 of 3
Is the envelope sender rewritten with SRS when mail is forwarded, so forwarded mail keeps passing SPF?
No published documentation on SRS for forwarded mail.
-
No
ARC sealing Weight 1 of 3
Does the provider validate and add ARC (RFC 8617) signatures, so authentication results survive forwarding?
No published documentation on ARC signing or validation.
Automated tests
-
Yes
TLS configuration Weight 2 of 3
Does the website pass the Qualys SSL Labs test with a grade of A or better?
Grade A+
-
Partial
Security headers Weight 1 of 3
Does the website pass the Mozilla HTTP Observatory test with a grade of A or better?
Grade B (75/100+)
-
Not tested yet
Modern web standards Weight 1 of 3
Does the website score 90% or higher on the Internet.nl website test?
Not tested yet.
-
Not tested yet
Email security standards Weight 2 of 3
Does the mail domain score 90% or higher on the Internet.nl email test?
Not tested yet.
-
Yes
IMAP support Weight 2 of 3
Does the IMAP server accept connections over implicit TLS on port 993 and advertise IMAP4rev1 or IMAP4rev2 with IDLE push?
disroot.org:993 (implicit TLS). IMAP4rev1 advertised with IDLE.
-
Yes
POP3 support Weight 1 of 3
Does the POP3 server accept connections over implicit TLS on port 995 and answer CAPA with UIDL?
disroot.org:995 (implicit TLS). CAPA: CAPA, TOP, UIDL, RESP-CODES, PIPELINING, AUTH-RESP-CODE, USER, SASL.
-
Partial
SMTP submission Weight 2 of 3
Does mail submission work over implicit TLS on port 465 with SMTPUTF8, 8BITMIME, PIPELINING and AUTH?
disroot.org:465 (implicit TLS). Missing: SMTPUTF8.
-
Yes
Mail transport security Weight 3 of 3
Does the mail domain enforce encrypted, authenticated delivery with MTA-STS, DANE, DNSSEC, TLS-RPT and an enforced DMARC policy?
Passes: SPF, DMARC reject, MTA-STS enforce, TLS-RPT, DNSSEC, DANE all.
Email standards
- Yes: Mail serversMXdisroot.org
- Yes: RFC 7208 sender policySPFpublished
- Yes: RFC 7489. Quarantine or reject counts as enforcedDMARCp=reject
- Yes: RFC 8461 strict transport securityMTA-STSenforce
- Yes: RFC 8460 TLS failure reportsTLS-RPTpublished
- Yes: RFC 4033 signed DNSDNSSECsigned and validated
- Yes: RFC 7672 TLSA records on MX hostsDANEall
- No: Brand logo record (not scored)BIMInone
- Yes: RFC 6186 and RFC 8314 service records (not scored)SRVclient autoconfiguration published
IMAP disroot.org:993 · implicit TLS
- IMAP4REV1
- LOGIN-REFERRALS
- ID
- ENABLE
- IDLE
- SASL-IR
- LITERAL+
- AUTH=PLAIN
- AUTH=LOGIN
POP3 disroot.org:995 · implicit TLS
- CAPA
- TOP
- UIDL
- RESP-CODES
- PIPELINING
- AUTH-RESP-CODE
- USER
- SASL
SMTP submission disroot.org:465 · implicit TLS
- PIPELINING
- SIZE
- VRFY
- ETRN
- AUTH
- ENHANCEDSTATUSCODES
- 8BITMIME
- CHUNKING
Capabilities are what each server advertises before login. How these tests work