Cloud Mail vs Mailfence

Compare Cloud Mail and Mailfence on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Gmail, Microsoft 365, Outlook.com

Logo: Cloud Mail

Cloud Mail

Italy· Email Services

Needs review

Shortlist Cloud Mail when you need Italian-operated, managed domain email with Plesk, Roundcube, CalDAV/CardDAV, and pre-delivery antispam on Seeweb infrastructure. Skip when you need end-to-end encrypted / zero-access mail (consider Proton Mail or Tuta) or a full Workspace/365 productivity suite (Google Workspace / Microsoft 365).

Managed domain emailPlesk administrationCalDAV / CardDAVISO 27001 (claimed)CISPE CoC (claimed)Italian / EU operator
Logo: Mailfence

Mailfence

Belgium· Email Services

Needs review

Shortlist Mailfence when you want Belgian-operated webmail with interoperable OpenPGP, digital signatures, and a light calendar/documents suite—plus optional business private-label or on-prem license. Skip when you need automatic closed E2EE without key management (consider Tuta), a large Swiss privacy ecosystem (Proton Mail), or a minimalist German mailbox (Posteo / mailbox.org).

EU-operated (Belgium)OpenPGP E2EEDigital signaturesMail + calendar + docsCustom domains (paid)B2B DPA available
Cloud Mail vs Mailfence: Snapshot
FeatureLogo: Cloud MailCloud MailLogo: MailfenceMailfence
Country of originItalyBelgium
CategoryEmail ServicesEmail Services
Open sourceNoNo
Self-hostedNoNo
HeadquartersItalyBelgium
Legal entitySeeweb S.r.l. (VAT IT02043220603), Via Armando Vona 66, 03100 FrosinoneContactOffice Group sa, Avenue Franklin Roosevelt 47b, B-1050 Brussels (BE 0466.241.584)
Governing lawItaly / EU (forum of Frosinone referenced in general conditions)Belgian law; Brussels courts (Terms of Use)
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)LowLow
Hosting / residencySeeweb-operated European infrastructure (proprietary DCs in Milan and Frosinone; group facilities also listed in Lugano, Zurich, Sofia). Cloud Mail backups: daily off-site to another Seeweb data center using IBM Spectrum Protect software. CISPE materials claim European territorial storage for covered cloud services. No public AWS/GCP/Azure hosting path found for this product.Primary production servers described as located in Belgium under Mailfence operational control (no intermediary managing servers per security page). No public AWS/GCP/Azure subprocessor list found. Backups stored in locations separate from offices/main DC (providers not named). Payment-card processing path not fully published.
Summary

Seeweb’s managed professional domain email: Plesk admin, Roundcube webmail, CalDAV/CardDAV, pre-delivery antispam, and daily off-site backups on Italian/EU infrastructure.

Belgian secure email suite with browser-side OpenPGP encryption, digital signatures, calendar, documents, and optional custom domains under ContactOffice Group SA.

Tags
At a glance: Cloud Mail vs Mailfence
At a glanceLogo: Cloud MailCloud MailLogo: MailfenceMailfence
HQFrosinone, Italy (Seeweb S.r.l.)Not listed
GroupDHH (Euronext Growth Milan) since 2020Not listed
Product typeManaged domain email hostingNot listed
Admin / webmailPlesk + RoundcubeNot listed
ProtocolsIMAP, POP3, SMTP, CalDAV, CardDAVNot listed
Open source productNo (managed service; Roundcube is the webmail UI)Not listed
Self-hosted productNoNot listed
Commercial modelPaid storage/mailbox packs; domain required; WhiteLabel availableFree tier + prepaid paid plans; Business packaging (see vendor site)
HQ / entityNot listedBrussels — ContactOffice Group sa (BE 0466.241.584)
Product launchNot listedMailfence brand ~2013; ContactOffice lineage since 1999
CryptoNot listedOpenPGP E2EE + digital signatures; optional password-encrypted messages
HostingNot listedVendor-operated servers in Belgium (per security page)
Open sourceNot listedNo (front-end OSS planned; not current)
Self-hostNot listedSaaS default; Business license for large on-prem deployments
Independent auditNot listedNo public audit PDF found
Key capabilities: Cloud Mail vs Mailfence
Key capabilitiesLogo: Cloud MailCloud MailLogo: MailfenceMailfence
Managed domain emailYesNot listed
Plesk administrationYesNot listed
CalDAV / CardDAVYesNot listed
ISO 27001 (claimed)YesNot listed
CISPE CoC (claimed)YesNot listed
Italian / EU operatorYesNot listed
EU-operated (Belgium)Not listedYes
OpenPGP E2EENot listedYes
Digital signaturesNot listedYes
Mail + calendar + docsNot listedYes
Custom domains (paid)Not listedYes
B2B DPA availableNot listedYes

Cloud Mail

  • Plesk domain mail admin (mailboxes, aliases, forwards)

    One admin account manages mailboxes, passwords, aliases, forwards, and auto-replies in Plesk, with quota/usage visibility per account. Suited to SMEs and resellers who want classic hosting-style control without running their own MTA.

  • Roundcube webmail + IMAP/POP3/SMTP on mail.truemail.it

    Users access mail via Roundcube (webmail.truemail.it) or standard clients. Docs publish IMAP/POP3/SMTP endpoints with STARTTLS and SSL port options for Outlook, Thunderbird, Apple Mail, and mobile. CalDAV and CardDAV cover calendar and contacts sync.

  • Managed pre-delivery antispam/antivirus (no default spam folder)

    Centralized filters check sender IP/domain behaviour and content before the message is accepted. Rejected spam is returned to the sender rather than filed in a default spam mailbox; false positives are handled via ticket or report@postmaster.seeweb.it. Accuracy is not claimed to be 100%.

  • Daily off-site backups (IBM Spectrum Protect, 30-day history)

    Incremental daily backups run to a remote Seeweb data center using IBM Spectrum Protect software. Deleted mail can be requested for recovery within about 30 days; restores recover the backed-up set rather than individual selected messages, so IMAP is recommended.

  • Scalable domain packs + WhiteLabel resale

    Plans scale from small 5 GB / 5-mailbox packs through large multi-hundred-GB packs with matching mailbox counts (up to on the order of 1,280 mailboxes). A domain is required at activation. WhiteLabel supports partners who resell branded mail on Seeweb’s managed stack.

Mailfence

  • Browser-side OpenPGP end-to-end encryption

    Encrypt outbound mail in the browser with the OpenPGP standard so intermediaries—including Mailfence when messages are properly E2EE—cannot read ciphertext. Fully interoperable with other OpenPGP tools (e.g. Thunderbird/GnuPG). Optional password-encrypted messages cover recipients who do not use PGP. Unencrypted mail still sits on servers in the normal webmail model.

  • Digital signatures and multi-key OpenPGP keystore

    Sign messages for authenticity and integrity, and manage keys in-product: generate, import, export, publish, and hold multiple key pairs without browser plug-ins. Default generated keys are 4096-bit per the threat-model page. Passphrase protection of private keys limits crypto operations if only the account password is compromised.

  • Mail, calendar, documents, and groups in one account

    Beyond inbox: shareable calendars, online document storage/editing, and contact groups for collaboration without bolting on a separate US suite. Storage and alias limits scale by plan; free accounts remain suitable only for light personal use.

  • Custom domains, aliases, and mail protocols on paid tiers

    Higher plans add custom domains with SPF/DKIM/DMARC-oriented setup, larger alias counts, and classic client access (POP, IMAP, SMTP) plus ActiveSync where listed. Entry-level free accounts focus on web/PWA/apps rather than full protocol parity—verify the live plan matrix before procurement.

  • Business admin: API, SSO, private label, optional on-prem license

    Mailfence for Business offers control-panel and XML-RPC API user provisioning, SSO and directory hooks (LDAP/AD/CAS), branding, and Belgian cloud hosting with SLA language—or a license to run on customer Linux servers for large deployments. Fit for orgs that need Belgian hosting with admin automation, not a consumer-only mailbox.

Assurance & compliance: Cloud Mail vs Mailfence
Assurance & complianceLogo: Cloud MailCloud MailLogo: MailfenceMailfence
Independent security / no-logs audit
Not found

No public third-party no-logs or mail-specific penetration audit PDF found for Cloud Mail; ISO ISMS certs are separate.

Not found

No public third-party audit PDF found. Vendor mentions security specialists, bug bounty activity, and inspection openness—not a substitute for a published audit. Privacy policy documents operational metadata collection (not zero-logs).

ISO 27001
Vendor claimed

Vendor certifications page: ISO/IEC 27001:2022, scope includes mail services; AXE REGISTER cert IT18-27702D (listed valid until 28 Nov 2027). Not independently re-verified in a public registry by this draft.

Not found

No Mailfence ISO 27001 certificate claim found on primary security/GDPR/company pages.

ISO 27017 / 27018 (cloud)
Vendor claimed

Published on certifications page as appendices to the ISO 27001 certificate; mail services in process scope.

Not listed
SOC 2 / SOC 3
Not found

Not listed on the public certifications page.

Not found
GDPR / EU data protection
Vendor claimed

Italian controller entity, named DPO, privacy policy under GDPR; product marketed as GDPR-oriented; CISPE CoC adherence claimed.

Vendor claimed

Belgian controller/processor materials; dedicated GDPR page and technical/organisational measures overview. Confirm roles in your DPA.

CISPE Code of Conduct
Vendor claimed

Certifications page: Seeweb cloud services adhere to CISPE; claims storage exclusively within European territories for covered services.

Not listed
US CLOUD Act exposure (indicative)
Partial

EuropeanStack assessment: EU entity, DHH European group, no known US parent; public hosting story is Seeweb EU DCs and CISPE EU territory claim; backups on Seeweb off-site DCs (Spectrum Protect software, not described as US cloud mailbox SaaS). Residual gaps: no full public subprocessor list; antispam uses external reputation services not named on the docs page. Not legal advice.

Partial

EU entity (ContactOffice Group sa), no known US parent; servers claimed self-operated in Belgium without named US hyperscaler hosts. No formal public subprocessor inventory; payment processors not named. Assessment residual: partial transparency on data path. Not legal advice.

Data processing agreement (B2B)
Not found

No downloadable product DPA found on the marketing site; general conditions reference GDPR processing and the privacy notice. Request Art. 28 terms for mail content before go-live.

Vendor claimed

Downloadable DPA linked from the GDPR page for organisational customers.

EU AI Act
Not applicable

Cloud Mail is conventional email hosting, not an AI product.

Not applicable

Email/collaboration suite; not an AI system under typical procurement framing.

Considerations & known limitations: Cloud Mail vs Mailfence
Considerations & known limitationsLogo: Cloud MailCloud MailLogo: MailfenceMailfence
Subprocessor / antispam feed list not public
Medium

Docs mention reputation services for antispam but do not publish a complete subprocessor table. Procurement should request the current list and transfer safeguards.

Not listed
Backup restore is set-based, not single-message
Low

30-day off-site history is useful, but restores recover the backed-up set; plan operational recovery expectations and prefer IMAP.

Not listed
Pre-delivery reject without default spam folder
Low

Strong filtering can block legitimate senders; there is no user-visible spam quarantine by default—use tickets/reporting workflows.

Not listed
Not zero-access / E2EE-first mail
Medium

Provider-managed conventional mail. Choose encrypted peers if the threat model assumes a compromised host provider.

Not listed
B2B DPA not prominent on site
Medium

Treat contract/DPA negotiation as a gate for regulated workloads until Art. 28 terms and roles (controller/processor for mailbox content) are signed.

Not listed
No public independent security auditNot listed
Medium

If vendor risk requires a published audit letter, ISO 27001, or SOC 2, treat Mailfence as incomplete until evidence is obtained offline or under NDA.

Closed-source SaaSNot listed
Medium

Cannot independently review server code or default-self-host like some FOSS mail stacks. Business on-prem license is a commercial path, not community self-host docs.

E2EE is opt-in OpenPGP, not automaticNot listed
Medium

Clear-text messages are operator-readable at rest. Users must encrypt/sign deliberately; training and policy matter for regulated content.

Operational metadata retentionNot listed
Low

Privacy policy lists IP, message-IDs, addresses, subjects, and related fields for operations, abuse control, and legal process—not a zero-logs design.

Limited public subprocessor inventoryNot listed
Low

Strong first-party claims of internal hosting, but no AWS-style public subprocessor table; confirm payment and support tooling in procurement.

US CLOUD Act (indicative)Not listed
Low

No known US parent; Belgian self-operated hosting narrative. Residual unknown payment/SaaS paths. Not a legal safe harbour guarantee.

Fit

Cloud Mail

Best fit when

  • SMEs and freelancers needing custom-domain business mail without a full Google/Microsoft suite
  • Teams that want classic IMAP/SMTP clients plus Roundcube webmail and CalDAV/CardDAV
  • Resellers seeking WhiteLabel managed mail on a European host
  • Organizations already using Seeweb compute/hosting that want mail in the same vendor relationship
  • Buyers prioritizing Italian legal entity, published ISO scopes that include mail, and CISPE-oriented residency messaging

Poor fit when

  • Threat models that require default end-to-end encryption or zero-access provider architecture
  • Need for full collaborative office suites, deep directory SSO, or Graph/Workspace app ecosystems
  • Teams that must self-host the MTA stack rather than buy managed mail
  • Procurement that requires a public SOC 2 report or a fully published subprocessor list before first contact

Consider instead when

  • When: You need zero-access / end-to-end encrypted mailboxes as the primary control

    Consider: Proton Mail or Tuta

    Different product class: E2EE-first vs conventional managed IMAP hosting

  • When: You need mail plus full productivity suite and global enterprise ecosystem

    Consider: Google Workspace or Microsoft 365

    Trade EU-operator focus for suite breadth and US-jurisdiction diligence

  • When: You want another European professional domain-mail host for comparison

    Consider: Migadu, Mailfence, or Combell E-mail

    Compare admin model, spam handling, restore RPO, and contract artifacts

Mailfence

Best fit when

  • You need OpenPGP interoperability and digital signatures from a European webmail, not only proprietary E2EE
  • Belgian legal entity and self-described self-operated Belgian hosting are procurement requirements
  • Teams want mail plus calendar/documents/groups without moving to Microsoft 365 or Google Workspace
  • You need custom domains, aliases, and classic clients (IMAP/POP/ActiveSync) on paid tiers
  • Business buyers evaluating private-label, API provisioning, SSO/directory integration, or large-scale on-prem license

Poor fit when

  • Security policy requires a published independent security audit, ISO 27001, or SOC 2 from the email vendor
  • You want fully open-source server/client stacks you can fork and self-host as default
  • Every message must be automatically E2EE with no OpenPGP key UX (Tuta-style)
  • You need Microsoft-class DLP, eDiscovery, compliance archives, and deep SaaS integrations
  • Zero-logs marketing is a hard requirement (Mailfence documents operational metadata collection)

Consider instead when

  • When: You want automatic encryption for all messages with minimal key management

    Consider: Tuta

    Different crypto model; less OpenPGP interop emphasis than Mailfence.

  • When: You want a larger Swiss privacy suite brand and ecosystem apps

    Consider: Proton Mail

    Trade Belgian ContactOffice ownership and PGP-centric UX for Proton’s broader product family.

  • When: You want a lean German ad-free mailbox without suite features

    Consider: Posteo or mailbox.org

    Simpler mailbox posture; different admin/domain/crypto tradeoffs.

  • When: You need full Google/Microsoft productivity and compliance tooling

    Consider: Microsoft 365 or Google Workspace (accept US-cloud risk) or EU office suites if residency is the driver

    Mailfence is not a drop-in M365 replacement.

Open questions for due diligence

Cloud Mail

  • Will Seeweb provide a signed Art. 28 DPA and current subprocessor list for Cloud Mail content?
  • Which data center hosts a given Cloud Mail instance (Italy vs other European Seeweb/group sites), and can residency be constrained contractually?
  • Which external reputation / antispam intelligence providers are used, and where do they process metadata?
  • Is there a SOC 2, independent penetration test summary, or customer-available audit package under NDA?
  • What are exact SLA credits, RPO/RTO for mail, and support tier inclusions for pure Cloud Mail (vs Global Support for servers)?

Mailfence

  • Will Mailfence provide a current written subprocessor list (including payment processors and any backup locations) for a company account?
  • Is any independent security assessment available under NDA for regulated buyers?
  • For Business on-prem license: exact minimum scale, support model, update cadence, and cryptographic feature parity vs SaaS?
  • Which plan tiers currently include IMAP/POP/ActiveSync and custom-domain limits for our user count?
  • How are disaster-recovery backup sites jurisdictions documented in the signed DPA annex?