Email sending services
Forward Email privacy rating
Email service whose paid plans include outbound SMTP and an email API for sending from apps and websites with a custom domain. Message bodies are purged after delivery by default.
Summary
Forward Email scores 85 out of 100 (grade B) on the email sending services criteria. It meets 9 of 12 criteria: open source, no ads or data sales, independent audit, tells users about requests, TLS configuration, security headers, message content deleted after delivery, open and click tracking off by default and encrypted delivery can be enforced. It partly meets no trackers or telemetry and transparency report. It does not meet EU data location. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade A+.
Score 85 out of 100. How scoring works
Criteria
-
Yes
Open source Weight 3 of 3 Source-available
Is all the source code needed to run the product public?
All code is public, including the outbound SMTP servers that run the service. Core mail storage and protocol code is MPL-2.0 and the rest is under the source-available Business Source License 1.1 (BUSL-1.1), which becomes MPL-2.0 four years after each release.
-
Partial
No trackers or telemetry Weight 3 of 3
Are the website and apps free of third-party trackers, with any analytics anonymous and any telemetry off by default?
No third-party analytics. First-party anonymized analytics of page views and service usage is on by default, and Cloudflare Turnstile loads on sign-in and sign-up forms.
-
Yes
No ads or data sales Weight 2 of 3
Is the product funded without advertising, ad targeting or selling user data?
Funded by paid plans. No ads, and the privacy policy states user data is not shared with third parties.
-
Yes
Independent audit Weight 2 of 3
Has an independent security or privacy audit been published within the last three years?
Two independent Cure53 audits of the code and the infrastructure are published.
-
Partial
Transparency report Weight 2 of 3
Does the provider regularly publish how many government and legal requests it receives and how it responds?
The technical whitepaper (section 9.3) publishes the government request policy and commits to transparency reports with request counts. A report with counts is not published yet.
-
Yes
Tells users about requests Weight 1 of 3
Does the provider promise to tell users about requests for their data, unless a court forbids it?
Users are notified of requests when legally allowed, with notice after disclosure when advance notice is prohibited.
-
Yes
Message content deleted after delivery Weight 3 of 3
Is the content of sent mail deleted once it has been delivered?
Outbound mail is queued for up to about 30 days until it is delivered or fails permanently. The body is then purged by default, and can be kept for up to 30 days if the sender turns this on.
-
Yes
Open and click tracking off by default Weight 2 of 3
Are open tracking pixels and click tracking links off unless the sender turns them on?
The email API and SMTP documentation describe no open or click tracking.
-
Yes
Encrypted delivery can be enforced Weight 2 of 3
Can outbound mail be kept from being delivered without TLS?
Outbound delivery enforces the recipient domain's MTA-STS policy and retries later instead of sending without TLS.
-
No
EU data location Weight 1 of 3
Can message content and delivery logs be processed and stored only in the European Union?
All processing and storage, including outbound SMTP, is in the United States. An EU location is not available.
Automated tests
-
Yes
TLS configuration Weight 2 of 3
Does the website pass the Qualys SSL Labs test with a grade of A or better?
Grade A+
-
Yes
Security headers Weight 1 of 3
Does the website pass the Mozilla HTTP Observatory test with a grade of A or better?
Grade A+ (125/100+)
-
Not tested yet
Modern web standards Weight 1 of 3
Does the website score 90% or higher on the Internet.nl website test?
Not tested yet.