# Mailfence privacy rating

Email service from Belgium with built-in OpenPGP encryption and signing, plus calendar, contacts and document storage.

## Summary

Mailfence scores 54 out of 100 (grade D) on the email providers criteria. It meets 8 of 19 criteria: no trackers or telemetry, no ads or data sales, transparency report, TLS configuration, custom domains, IMAP support, POP3 support and mail transport security. It partly meets security headers, end-to-end encryption, open protocols and SMTP submission. It does not meet open source, independent audit, tells users about requests, encrypted mailbox storage, sign up without personal data, Sender Rewriting Scheme and ARC sealing. It is based in Belgium: Fourteen Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B+.

- Website: https://mailfence.com
- Jurisdiction: Belgium. Fourteen Eyes member. EU member (GDPR).
- Home page trackers: none found
- Category: [Email providers](https://privacyratings.com/email-providers/)
- Grade: D (54/100)

## Criteria

| Criterion | Answer | Note | Evidence |
| --- | --- | --- | --- |
| Open source | No | Closed source. |  |
| No trackers or telemetry | Yes | The privacy policy states that only authentication cookies are used and no Google Analytics or other trackers. | https://mailfence.com/en/privacy.jsp |
| No ads or data sales | Yes | Funded by paid plans. No ads, and user data is not sold or shared. | https://mailfence.com/en/privacy.jsp |
| Independent audit | No | No independent audit is published. |  |
| Transparency report | Yes | Publishes counts of legal requests and disclosures every six months, with a warrant canary. | https://blog.mailfence.com/transparency-report-and-warrant-canary/ |
| Tells users about requests | No | No published policy on notifying users about data requests. |  |
| TLS configuration | Yes | Grade A+ | https://www.ssllabs.com/ssltest/analyze.html?d=mailfence.com&hideResults=on |
| Security headers | Partial | Grade B+ (80/100+) | https://developer.mozilla.org/en-US/observatory/analyze?host=mailfence.com |
| Modern web standards | Not tested yet | Not tested yet. |  |
| End-to-end encryption | Partial | OpenPGP and password-protected messages are built into the webmail, but encryption is not on by default. | https://mailfence.com/en/end-to-end-encryption.jsp |
| Encrypted mailbox storage | No | Only messages encrypted with OpenPGP stay unreadable on the server. Encryption of other stored mail is not documented. | https://mailfence.com/en/threat-model.jsp |
| Open protocols | Partial | IMAP, POP3 and SMTP need the Entry plan or higher. The free and Base plans are webmail and app only. | https://mailfence.com/en/faq.jsp |
| Custom domains | Yes | Available from the Entry plan up. | https://mailfence.com/en/faq.jsp |
| Sign up without personal data | No | An existing external email address is required to receive the activation code. | https://mailfence.com/en/privacy.jsp |
| Email security standards | Not tested yet | Not tested yet. |  |
| IMAP support | Yes | imap.mailfence.com:993 (implicit TLS). IMAP4rev1 advertised with IDLE. |  |
| POP3 support | Yes | pop.mailfence.com:995 (implicit TLS). CAPA: USER, EXPIRE, TOP, UIDL, PIPELINING, RESP-CODES, SASL. |  |
| SMTP submission | Partial | smtp.mailfence.com:465 (implicit TLS). Missing: SMTPUTF8, PIPELINING. |  |
| Mail transport security | Yes | Passes: SPF, DMARC reject, MTA-STS enforce, TLS-RPT, DNSSEC, DANE all. |  |
| Sender Rewriting Scheme | No | No published documentation on SRS for forwarded mail. |  |
| ARC sealing | No | No published documentation on ARC signing or validation. |  |

Source: https://privacyratings.com/email-providers/mailfence/
Edit: https://github.com/privacyratings/privacyratings.com/edit/main/ratings/email-providers/mailfence.md
