Email providers
Mailfence privacy rating
Email service from Belgium with built-in OpenPGP encryption and signing, plus calendar, contacts and document storage.
Summary
Mailfence scores 54 out of 100 (grade D) on the email providers criteria. It meets 8 of 19 criteria: no trackers or telemetry, no ads or data sales, transparency report, TLS configuration, custom domains, IMAP support, POP3 support and mail transport security. It partly meets security headers, end-to-end encryption, open protocols and SMTP submission. It does not meet open source, independent audit, tells users about requests, encrypted mailbox storage, sign up without personal data, Sender Rewriting Scheme and ARC sealing. It is based in Belgium: Fourteen Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B+.
Score 54 out of 100. How scoring works
Criteria
- No
-
Yes
No trackers or telemetry Weight 3 of 3
Are the website and apps free of third-party trackers, with any analytics anonymous and any telemetry off by default?
The privacy policy states that only authentication cookies are used and no Google Analytics or other trackers.
-
Yes
No ads or data sales Weight 2 of 3
Is the product funded without advertising, ad targeting or selling user data?
Funded by paid plans. No ads, and user data is not sold or shared.
-
No
Independent audit Weight 2 of 3
Has an independent security or privacy audit been published within the last three years?
No independent audit is published.
-
Yes
Transparency report Weight 2 of 3
Does the provider regularly publish how many government and legal requests it receives and how it responds?
Publishes counts of legal requests and disclosures every six months, with a warrant canary.
-
No
Tells users about requests Weight 1 of 3
Does the provider promise to tell users about requests for their data, unless a court forbids it?
No published policy on notifying users about data requests.
-
Partial
End-to-end encryption Weight 3 of 3
Can mail be end-to-end encrypted so that the provider cannot read message contents?
OpenPGP and password-protected messages are built into the webmail, but encryption is not on by default.
-
No
Encrypted mailbox storage Weight 3 of 3
Is stored mail encrypted with a key the provider does not hold?
Only messages encrypted with OpenPGP stay unreadable on the server. Encryption of other stored mail is not documented.
-
Partial
Open protocols Weight 2 of 3
Can any standard app connect over IMAP, POP3, SMTP, CalDAV or CardDAV, without extra software?
IMAP, POP3 and SMTP need the Entry plan or higher. The free and Base plans are webmail and app only.
-
Yes
Custom domains Weight 1 of 3
Can mail be sent and received with your own domain?
Available from the Entry plan up.
-
No
Sign up without personal data Weight 2 of 3
Can an account be created without a phone number or another email address?
An existing external email address is required to receive the activation code.
-
No
Sender Rewriting Scheme Weight 1 of 3
Is the envelope sender rewritten with SRS when mail is forwarded, so forwarded mail keeps passing SPF?
No published documentation on SRS for forwarded mail.
-
No
ARC sealing Weight 1 of 3
Does the provider validate and add ARC (RFC 8617) signatures, so authentication results survive forwarding?
No published documentation on ARC signing or validation.
Automated tests
-
Yes
TLS configuration Weight 2 of 3
Does the website pass the Qualys SSL Labs test with a grade of A or better?
Grade A+
-
Partial
Security headers Weight 1 of 3
Does the website pass the Mozilla HTTP Observatory test with a grade of A or better?
Grade B+ (80/100+)
-
Not tested yet
Modern web standards Weight 1 of 3
Does the website score 90% or higher on the Internet.nl website test?
Not tested yet.
-
Not tested yet
Email security standards Weight 2 of 3
Does the mail domain score 90% or higher on the Internet.nl email test?
Not tested yet.
-
Yes
IMAP support Weight 2 of 3
Does the IMAP server accept connections over implicit TLS on port 993 and advertise IMAP4rev1 or IMAP4rev2 with IDLE push?
imap.mailfence.com:993 (implicit TLS). IMAP4rev1 advertised with IDLE.
-
Yes
POP3 support Weight 1 of 3
Does the POP3 server accept connections over implicit TLS on port 995 and answer CAPA with UIDL?
pop.mailfence.com:995 (implicit TLS). CAPA: USER, EXPIRE, TOP, UIDL, PIPELINING, RESP-CODES, SASL.
-
Partial
SMTP submission Weight 2 of 3
Does mail submission work over implicit TLS on port 465 with SMTPUTF8, 8BITMIME, PIPELINING and AUTH?
smtp.mailfence.com:465 (implicit TLS). Missing: SMTPUTF8, PIPELINING.
-
Yes
Mail transport security Weight 3 of 3
Does the mail domain enforce encrypted, authenticated delivery with MTA-STS, DANE, DNSSEC, TLS-RPT and an enforced DMARC policy?
Passes: SPF, DMARC reject, MTA-STS enforce, TLS-RPT, DNSSEC, DANE all.
Email standards
- Yes: Mail serversMXsmtp1.mailfence.com, smtp2.mailfence.com
- Yes: RFC 7208 sender policySPFpublished
- Yes: RFC 7489. Quarantine or reject counts as enforcedDMARCp=reject
- Yes: RFC 8461 strict transport securityMTA-STSenforce
- Yes: RFC 8460 TLS failure reportsTLS-RPTpublished
- Yes: RFC 4033 signed DNSDNSSECsigned and validated
- Yes: RFC 7672 TLSA records on MX hostsDANEall
- No: Brand logo record (not scored)BIMInone
- No: RFC 6186 and RFC 8314 service records (not scored)SRVnone
IMAP imap.mailfence.com:993 · implicit TLS
- IMAP4
- IMAP4REV1
- NAMESPACE
- QUOTA
- MOVE
- UIDPLUS
- UNSELECT
- IDLE
- AUTH=PLAIN
- SASL-IR
- CLIENTID
POP3 pop.mailfence.com:995 · implicit TLS
- USER
- EXPIRE
- TOP
- UIDL
- PIPELINING
- RESP-CODES
- SASL
SMTP submission smtp.mailfence.com:465 · implicit TLS
- AUTH
- SIZE
- 8BITMIME
Capabilities are what each server advertises before login. How these tests work