Email providers
HEY privacy rating
Paid email service from 37signals with a screening-based inbox and its own apps. Works only through the HEY apps, without IMAP or POP3.
Summary
HEY scores 32 out of 100 (grade F) on the email providers criteria. It meets 5 of 19 criteria: no ads or data sales, tells users about requests, TLS configuration, security headers and custom domains. It partly meets independent audit, transparency report, encrypted mailbox storage and mail transport security. It does not meet open source, no trackers or telemetry, end-to-end encryption, open protocols, sign up without personal data, IMAP support, POP3 support, SMTP submission, Sender Rewriting Scheme and ARC sealing. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade A+.
Score 32 out of 100. How scoring works
Criteria
- No
-
No
No trackers or telemetry Weight 3 of 3
Are the website and apps free of third-party trackers, with any analytics anonymous and any telemetry off by default?
The privacy policy describes web analytics and some third-party cookies for analytics and ad measurement.
-
Yes
No ads or data sales Weight 2 of 3
Is the product funded without advertising, ad targeting or selling user data?
Funded by subscriptions. No ads, and data is not sold.
-
Partial
Independent audit Weight 2 of 3
Has an independent security or privacy audit been published within the last three years?
Trail of Bits and Doyensec reviewed HEY before launch and the full reports are public, but they are more than three years old.
-
Partial
Transparency report Weight 2 of 3
Does the provider regularly publish how many government and legal requests it receives and how it responds?
Publishes a policy for government data requests, but no request counts.
-
Yes
Tells users about requests Weight 1 of 3
Does the provider promise to tell users about requests for their data, unless a court forbids it?
Affected users are notified before data is disclosed, unless legally prohibited or in some emergencies.
-
No
End-to-end encryption Weight 3 of 3
Can mail be end-to-end encrypted so that the provider cannot read message contents?
Not supported.
-
Partial
Encrypted mailbox storage Weight 3 of 3
Is stored mail encrypted with a key the provider does not hold?
Content is encrypted at rest and per field in the database, with keys HEY holds.
-
No
Open protocols Weight 2 of 3
Can any standard app connect over IMAP, POP3, SMTP, CalDAV or CardDAV, without extra software?
Only the HEY apps work. IMAP and POP3 are not supported.
-
Yes
Custom domains Weight 1 of 3
Can mail be sent and received with your own domain?
Available with HEY for Domains.
-
No
Sign up without personal data Weight 2 of 3
Can an account be created without a phone number or another email address?
A backup email address is required at sign-up.
-
No
Sender Rewriting Scheme Weight 1 of 3
Is the envelope sender rewritten with SRS when mail is forwarded, so forwarded mail keeps passing SPF?
No published documentation on SRS for forwarded mail.
-
No
ARC sealing Weight 1 of 3
Does the provider validate and add ARC (RFC 8617) signatures, so authentication results survive forwarding?
No published documentation on ARC signing or validation.
Automated tests
-
Yes
TLS configuration Weight 2 of 3
Does the website pass the Qualys SSL Labs test with a grade of A or better?
Grade A+
-
Yes
Security headers Weight 1 of 3
Does the website pass the Mozilla HTTP Observatory test with a grade of A or better?
Grade A+ (120/100+)
-
Not tested yet
Modern web standards Weight 1 of 3
Does the website score 90% or higher on the Internet.nl website test?
Not tested yet.
-
Not tested yet
Email security standards Weight 2 of 3
Does the mail domain score 90% or higher on the Internet.nl email test?
Not tested yet.
-
No
IMAP support Weight 2 of 3
Does the IMAP server accept connections over implicit TLS on port 993 and advertise IMAP4rev1 or IMAP4rev2 with IDLE push?
Not offered.
-
No
POP3 support Weight 1 of 3
Does the POP3 server accept connections over implicit TLS on port 995 and answer CAPA with UIDL?
Not offered.
-
No
SMTP submission Weight 2 of 3
Does mail submission work over implicit TLS on port 465 with SMTPUTF8, 8BITMIME, PIPELINING and AUTH?
Not offered.
-
Partial
Mail transport security Weight 3 of 3
Does the mail domain enforce encrypted, authenticated delivery with MTA-STS, DANE, DNSSEC, TLS-RPT and an enforced DMARC policy?
Passes: SPF, DMARC quarantine, MTA-STS enforce, TLS-RPT. Missing: DNSSEC, DANE none.
Email standards
- Yes: Mail serversMXhome-mx.app.hey.com
- Yes: RFC 7208 sender policySPFpublished
- Yes: RFC 7489. Quarantine or reject counts as enforcedDMARCp=quarantine
- Yes: RFC 8461 strict transport securityMTA-STSenforce
- Yes: RFC 8460 TLS failure reportsTLS-RPTpublished
- No: RFC 4033 signed DNSDNSSECnot validated
- No: RFC 7672 TLSA records on MX hostsDANEnone
- No: Brand logo record (not scored)BIMInone
- No: RFC 6186 and RFC 8314 service records (not scored)SRVnone
IMAP
Not offered.
POP3
Not offered.
SMTP submission
Not offered.
Capabilities are what each server advertises before login. How these tests work