Email providers
Migadu privacy rating
Swiss email hosting service for custom domains, priced by usage rather than per mailbox, with standard IMAP, POP3 and SMTP access.
Summary
Migadu scores 38 out of 100 (grade F) on the email providers criteria. It meets 7 of 19 criteria: no trackers or telemetry, no ads or data sales, TLS configuration, open protocols, custom domains, POP3 support and SMTP submission. It partly meets IMAP support. It does not meet open source, independent audit, transparency report, tells users about requests, security headers, end-to-end encryption, encrypted mailbox storage, sign up without personal data, mail transport security, Sender Rewriting Scheme and ARC sealing. It is based in Switzerland: Not in the Five, Nine or Fourteen Eyes; GDPR-style data protection law. Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade D.
Score 38 out of 100. How scoring works
Criteria
- No
-
Yes
No trackers or telemetry Weight 3 of 3
Are the website and apps free of third-party trackers, with any analytics anonymous and any telemetry off by default?
No tracking or analytics cookies, and no website analytics.
-
Yes
No ads or data sales Weight 2 of 3
Is the product funded without advertising, ad targeting or selling user data?
Funded by paid plans. No ads and no outside investors.
-
No
Independent audit Weight 2 of 3
Has an independent security or privacy audit been published within the last three years?
No independent audit is published.
-
No
Transparency report Weight 2 of 3
Does the provider regularly publish how many government and legal requests it receives and how it responds?
No transparency report or government request policy is published.
-
No
Tells users about requests Weight 1 of 3
Does the provider promise to tell users about requests for their data, unless a court forbids it?
No published policy on notifying users about data requests.
-
No
End-to-end encryption Weight 3 of 3
Can mail be end-to-end encrypted so that the provider cannot read message contents?
Not supported. Migadu recommends OpenPGP tools in the mail client.
-
No
Encrypted mailbox storage Weight 3 of 3
Is stored mail encrypted with a key the provider does not hold?
Stored mail is not encrypted. Data is split across disks instead.
-
Yes
Open protocols Weight 2 of 3
Can any standard app connect over IMAP, POP3, SMTP, CalDAV or CardDAV, without extra software?
IMAP, POP3 and SMTP work with any client.
-
Yes
Custom domains Weight 1 of 3
Can mail be sent and received with your own domain?
The service is built for custom domains on every plan.
-
No
Sign up without personal data Weight 2 of 3
Can an account be created without a phone number or another email address?
An existing email address is needed to verify the account.
-
No
Sender Rewriting Scheme Weight 1 of 3
Is the envelope sender rewritten with SRS when mail is forwarded, so forwarded mail keeps passing SPF?
No published documentation on SRS for forwarded mail.
-
No
ARC sealing Weight 1 of 3
Does the provider validate and add ARC (RFC 8617) signatures, so authentication results survive forwarding?
No published documentation on ARC signing or validation.
Automated tests
-
Yes
TLS configuration Weight 2 of 3
Does the website pass the Qualys SSL Labs test with a grade of A or better?
Grade A
-
No
Security headers Weight 1 of 3
Does the website pass the Mozilla HTTP Observatory test with a grade of A or better?
Grade D (30/100+)
-
Not tested yet
Modern web standards Weight 1 of 3
Does the website score 90% or higher on the Internet.nl website test?
Not tested yet.
-
Not tested yet
Email security standards Weight 2 of 3
Does the mail domain score 90% or higher on the Internet.nl email test?
Not tested yet.
-
Partial
IMAP support Weight 2 of 3
Does the IMAP server accept connections over implicit TLS on port 993 and advertise IMAP4rev1 or IMAP4rev2 with IDLE push?
imap.migadu.com:993 (implicit TLS). IMAP4rev2 advertised, no IDLE before login.
-
Yes
POP3 support Weight 1 of 3
Does the POP3 server accept connections over implicit TLS on port 995 and answer CAPA with UIDL?
pop.migadu.com:995 (implicit TLS). CAPA: TOP, UIDL, USER, RESP-CODES, PIPELINING, SASL, AUTH-RESP-CODE, IMPLEMENTATION.
-
Yes
SMTP submission Weight 2 of 3
Does mail submission work over implicit TLS on port 465 with SMTPUTF8, 8BITMIME, PIPELINING and AUTH?
smtp.migadu.com:465 (implicit TLS). SMTPUTF8, 8BITMIME, PIPELINING and AUTH advertised.
-
No
Mail transport security Weight 3 of 3
Does the mail domain enforce encrypted, authenticated delivery with MTA-STS, DANE, DNSSEC, TLS-RPT and an enforced DMARC policy?
Passes: SPF, DNSSEC. Missing: DMARC missing, MTA-STS missing, TLS-RPT, DANE none.
Email standards
- Yes: Mail serversMXmx.migadu.com
- Yes: RFC 7208 sender policySPFpublished
- No: RFC 7489. Quarantine or reject counts as enforcedDMARCmissing
- No: RFC 8461 strict transport securityMTA-STSmissing
- No: RFC 8460 TLS failure reportsTLS-RPTmissing
- Yes: RFC 4033 signed DNSDNSSECsigned and validated
- No: RFC 7672 TLSA records on MX hostsDANEnone
- No: Brand logo record (not scored)BIMInone
- Yes: RFC 6186 and RFC 8314 service records (not scored)SRVclient autoconfiguration published
IMAP imap.migadu.com:993 · implicit TLS
- IMAP4REV2
- IMAP4REV1
- SASL-IR
- LITERAL-
- AUTH=PLAIN
POP3 pop.migadu.com:995 · implicit TLS
- TOP
- UIDL
- USER
- RESP-CODES
- PIPELINING
- SASL
- AUTH-RESP-CODE
- IMPLEMENTATION
SMTP submission smtp.migadu.com:465 · implicit TLS
- PIPELINING
- 8BITMIME
- ENHANCEDSTATUSCODES
- CHUNKING
- AUTH
- SMTPUTF8
- SIZE
Capabilities are what each server advertises before login. How these tests work