电子邮件服务商
Forward Email 隐私评级
编辑推荐
开源电子邮件服务,提供加密邮箱和自定义域名,所有付费套餐均支持 IMAP、POP3、SMTP、CalDAV 和 CardDAV。
摘要
按电子邮件服务商的标准,Forward Email 得分 93/100(等级 A)。 它满足 19 项标准中的 17 项:开源、无广告或数据出售、独立审计、告知用户有关请求、TLS 配置、安全标头、端到端加密、加密邮箱存储、开放协议、自定义域名、注册无需个人数据、IMAP 支持、POP3 支持、SMTP 提交、邮件传输安全、发件人重写方案(SRS)和ARC 签封。 它部分满足无跟踪器或遥测和透明度报告。 它的总部位于美国:五眼联盟成员; 受美国 CLOUD Act 约束。 自动测试:SSL Labs 等级 A+和Mozilla HTTP Observatory 等级 A+。
分数 93/100。 评分方式
标准
-
是
开源 权重 3/3 源码可见
运行产品所需的全部源代码是否都已公开?
All code is public, including the web, API, IMAP, POP3, SMTP, MX, CalDAV and CardDAV servers that run the service. Core mail storage and protocol code is MPL-2.0 and the rest is under the source-available Business Source License 1.1 (BUSL-1.1), which becomes MPL-2.0 four years after each release.
-
部分
无跟踪器或遥测 权重 3/3
网站和应用是否没有第三方跟踪器,任何统计分析均为匿名,且任何遥测默认关闭?
No third-party analytics or telemetry. First-party page statistics keep no IP addresses, cookies or identifiers and are deleted after 30 days. Cloudflare Turnstile loads only on sign-in and sign-up forms to stop bots.
- 是
- 是
-
部分
透明度报告 权重 2/3
服务商是否定期公布收到的政府和法律请求数量及其处理方式?
The technical whitepaper (section 9.3) publishes the government request policy and commits to regular transparency reports with request counts. A report with counts is not published yet.
-
是
告知用户有关请求 权重 1/3
除非法院禁止,服务商是否承诺将针对用户数据的请求告知用户?
Users are notified of requests when legally allowed, with notice after disclosure when advance notice is prohibited.
-
是
端到端加密 权重 3/3
邮件能否进行端到端加密,使服务商无法读取邮件内容?
Mail is automatically encrypted with OpenPGP when the recipient publishes a key through Web Key Directory. OpenPGP/MIME and S/MIME work with any app.
-
是
加密邮箱存储 权重 3/3
存储的邮件是否使用服务商不持有的密钥加密?
Each mailbox is a separately encrypted SQLite file (ChaCha20-Poly1305). The technical whitepaper states Forward Email cannot access mailbox contents.
-
是
开放协议 权重 2/3
任何标准应用能否通过 IMAP、POP3、SMTP、CalDAV 或 CardDAV 连接,而无需额外软件?
IMAP, POP3, SMTP, CalDAV and CardDAV on every paid plan, with no bridge app.
- 是
-
是
注册无需个人数据 权重 2/3
能否在不提供电话号码或其他电子邮件地址的情况下创建账户?
Free forwarding is set up entirely with DNS records, with no account at all. Paid mailboxes need only an email address and password, never a phone number.
-
是
发件人重写方案(SRS) 权重 1/3
转发邮件时是否使用 SRS 重写信封发件人,使转发的邮件仍能通过 SPF?
Applied automatically to all forwarded mail.
-
是
ARC 签封 权重 1/3
服务商是否验证并添加 ARC(RFC 8617)签名,使认证结果在转发后仍然有效?
ARC chains are validated (RFC 8617) and forwarded mail is ARC-sealed.
自动测试
- 是
- 是
- 尚未测试
- 尚未测试
-
是
IMAP 支持 权重 2/3
IMAP 服务器是否接受 993 端口上的隐式 TLS 连接,并声明支持带 IDLE 推送的 IMAP4rev1 或 IMAP4rev2?
imap.forwardemail.net:993 (implicit TLS). IMAP4rev1 advertised with IDLE.
-
是
POP3 支持 权重 1/3
POP3 服务器是否接受 995 端口上的隐式 TLS 连接,并在响应 CAPA 时包含 UIDL?
pop3.forwardemail.net:995 (implicit TLS). CAPA: TOP, UIDL, USER, RESP-CODES, SASL, PIPELINING.
-
是
SMTP 提交 权重 2/3
邮件提交是否支持 465 端口上的隐式 TLS,并支持 SMTPUTF8、8BITMIME、PIPELINING 和 AUTH?
smtp.forwardemail.net:465 (implicit TLS). SMTPUTF8, 8BITMIME, PIPELINING and AUTH advertised.
-
是
邮件传输安全 权重 3/3
邮件域名是否通过 MTA-STS、DANE、DNSSEC、TLS-RPT 和强制执行的 DMARC 策略,确保加密且经过认证的投递?
Passes: SPF, DMARC reject, MTA-STS enforce, TLS-RPT, DNSSEC, DANE all.
电子邮件标准
- 是: 邮件服务器MXmx1.forwardemail.net, mx2.forwardemail.net
- 是: RFC 7208 发件人策略SPF已发布
- 是: RFC 7489。quarantine 或 reject 视为已强制执行DMARCp=reject
- 是: RFC 8461 严格传输安全MTA-STSenforce
- 是: RFC 8460 TLS 故障报告TLS-RPT已发布
- 是: RFC 4033 签名 DNSDNSSEC已签名并验证
- 是: MX 主机上的 RFC 7672 TLSA 记录DANEall
- 否: 品牌标志记录(不计分)BIMI无
- 是: RFC 6186 和 RFC 8314 服务记录(不计分)SRV已发布客户端自动配置
IMAP imap.forwardemail.net:993 · 隐式 TLS
- XAPPLEPUSHSERVICE
- IMAP4REV1
- APPENDLIMIT=52428800
- AUTH=PLAIN
- AUTH=PLAIN-CLIENTTOKEN
- CHILDREN
- CONDSTORE
- ENABLE
- ID
- IDLE
- MOVE
- NAMESPACE
- QUOTA
- SASL-IR
- SPECIAL-USE
- UIDPLUS
- UNSELECT
- UTF8=ACCEPT
- XLIST
POP3 pop3.forwardemail.net:995 · 隐式 TLS
- TOP
- UIDL
- USER
- RESP-CODES
- SASL
- PIPELINING
SMTP 提交 smtp.forwardemail.net:465 · 隐式 TLS
- PIPELINING
- 8BITMIME
- SMTPUTF8
- ENHANCEDSTATUSCODES
- DSN
- AUTH
- REQUIRETLS
- SIZE
功能是指各服务器在登录前公布的能力。 这些测试的工作方式
Jurisdiction and the CLOUD Act
Forward Email is based in the United States, a Five Eyes country, and is subject to the CLOUD Act. Its technical whitepaper describes how the design limits what any legal request could reach:
- Mailboxes are individually encrypted SQLite files that Forward Email cannot read.
- Email content and metadata are not logged to disk.
- Data that could be disclosed is limited to basic account details (such as the account email, sign-up date and payment information) and limited IP address logs that may be kept temporarily for security and abuse prevention.
- Requests need valid US legal process (subpoena, court order or search warrant). Foreign requests must come through a US court, a mutual legal assistance treaty or a CLOUD Act agreement. Overbroad requests are challenged.
Independent audits
Notes
Forward Email also publishes Awesome Mail Server Providers, a comparison of hosts for running a mail server.