Privacy Ratings

Email providers

Mailfence privacy rating

Email service from Belgium with built-in OpenPGP encryption and signing, plus calendar, contacts and document storage.

Summary

Mailfence scores 54 out of 100 (grade D) on the email providers criteria. It meets 8 of 19 criteria: no trackers or telemetry, no ads or data sales, transparency report, TLS configuration, custom domains, IMAP support, POP3 support and mail transport security. It partly meets security headers, end-to-end encryption, open protocols and SMTP submission. It does not meet open source, independent audit, tells users about requests, encrypted mailbox storage, sign up without personal data, Sender Rewriting Scheme and ARC sealing. It is based in Belgium: Fourteen Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B+.

Score 54 out of 100. How scoring works

Criteria

  • No

    Open source Weight 3 of 3

    Is all the source code needed to run the product public?

    Closed source.

  • Yes

    No trackers or telemetry Weight 3 of 3

    Are the website and apps free of third-party trackers, with any analytics anonymous and any telemetry off by default?

    The privacy policy states that only authentication cookies are used and no Google Analytics or other trackers.

    mailfence.com

  • Yes

    No ads or data sales Weight 2 of 3

    Is the product funded without advertising, ad targeting or selling user data?

    Funded by paid plans. No ads, and user data is not sold or shared.

    mailfence.com

  • No

    Independent audit Weight 2 of 3

    Has an independent security or privacy audit been published within the last three years?

    No independent audit is published.

  • Yes

    Transparency report Weight 2 of 3

    Does the provider regularly publish how many government and legal requests it receives and how it responds?

    Publishes counts of legal requests and disclosures every six months, with a warrant canary.

    blog.mailfence.com

  • No

    Tells users about requests Weight 1 of 3

    Does the provider promise to tell users about requests for their data, unless a court forbids it?

    No published policy on notifying users about data requests.

  • Partial

    End-to-end encryption Weight 3 of 3

    Can mail be end-to-end encrypted so that the provider cannot read message contents?

    OpenPGP and password-protected messages are built into the webmail, but encryption is not on by default.

    mailfence.com

  • No

    Encrypted mailbox storage Weight 3 of 3

    Is stored mail encrypted with a key the provider does not hold?

    Only messages encrypted with OpenPGP stay unreadable on the server. Encryption of other stored mail is not documented.

    mailfence.com

  • Partial

    Open protocols Weight 2 of 3

    Can any standard app connect over IMAP, POP3, SMTP, CalDAV or CardDAV, without extra software?

    IMAP, POP3 and SMTP need the Entry plan or higher. The free and Base plans are webmail and app only.

    mailfence.com

  • Yes

    Custom domains Weight 1 of 3

    Can mail be sent and received with your own domain?

    Available from the Entry plan up.

    mailfence.com

  • No

    Sign up without personal data Weight 2 of 3

    Can an account be created without a phone number or another email address?

    An existing external email address is required to receive the activation code.

    mailfence.com

  • No

    Sender Rewriting Scheme Weight 1 of 3

    Is the envelope sender rewritten with SRS when mail is forwarded, so forwarded mail keeps passing SPF?

    No published documentation on SRS for forwarded mail.

  • No

    ARC sealing Weight 1 of 3

    Does the provider validate and add ARC (RFC 8617) signatures, so authentication results survive forwarding?

    No published documentation on ARC signing or validation.

Automated tests

  • Yes

    TLS configuration Weight 2 of 3

    Does the website pass the Qualys SSL Labs test with a grade of A or better?

    Grade A+

    ssllabs.com

  • Partial

    Security headers Weight 1 of 3

    Does the website pass the Mozilla HTTP Observatory test with a grade of A or better?

    Grade B+ (80/100+)

    developer.mozilla.org

  • Not tested yet

    Modern web standards Weight 1 of 3

    Does the website score 90% or higher on the Internet.nl website test?

    Not tested yet.

  • Not tested yet

    Email security standards Weight 2 of 3

    Does the mail domain score 90% or higher on the Internet.nl email test?

    Not tested yet.

  • Yes

    IMAP support Weight 2 of 3

    Does the IMAP server accept connections over implicit TLS on port 993 and advertise IMAP4rev1 or IMAP4rev2 with IDLE push?

    imap.mailfence.com:993 (implicit TLS). IMAP4rev1 advertised with IDLE.

  • Yes

    POP3 support Weight 1 of 3

    Does the POP3 server accept connections over implicit TLS on port 995 and answer CAPA with UIDL?

    pop.mailfence.com:995 (implicit TLS). CAPA: USER, EXPIRE, TOP, UIDL, PIPELINING, RESP-CODES, SASL.

  • Partial

    SMTP submission Weight 2 of 3

    Does mail submission work over implicit TLS on port 465 with SMTPUTF8, 8BITMIME, PIPELINING and AUTH?

    smtp.mailfence.com:465 (implicit TLS). Missing: SMTPUTF8, PIPELINING.

  • Yes

    Mail transport security Weight 3 of 3

    Does the mail domain enforce encrypted, authenticated delivery with MTA-STS, DANE, DNSSEC, TLS-RPT and an enforced DMARC policy?

    Passes: SPF, DMARC reject, MTA-STS enforce, TLS-RPT, DNSSEC, DANE all.

Email standards

  • Yes: Mail serversMXsmtp1.mailfence.com, smtp2.mailfence.com
  • Yes: RFC 7208 sender policySPFpublished
  • Yes: RFC 7489. Quarantine or reject counts as enforcedDMARCp=reject
  • Yes: RFC 8461 strict transport securityMTA-STSenforce
  • Yes: RFC 8460 TLS failure reportsTLS-RPTpublished
  • Yes: RFC 4033 signed DNSDNSSECsigned and validated
  • Yes: RFC 7672 TLSA records on MX hostsDANEall
  • No: Brand logo record (not scored)BIMInone
  • No: RFC 6186 and RFC 8314 service records (not scored)SRVnone

IMAP imap.mailfence.com:993 · implicit TLS

  • IMAP4
  • IMAP4REV1
  • NAMESPACE
  • QUOTA
  • MOVE
  • UIDPLUS
  • UNSELECT
  • IDLE
  • AUTH=PLAIN
  • SASL-IR
  • CLIENTID

POP3 pop.mailfence.com:995 · implicit TLS

  • USER
  • EXPIRE
  • TOP
  • UIDL
  • PIPELINING
  • RESP-CODES
  • SASL

SMTP submission smtp.mailfence.com:465 · implicit TLS

  • AUTH
  • SIZE
  • 8BITMIME

Capabilities are what each server advertises before login. How these tests work

Other email providers

All 31 email providers