Cloud Mail vs Posteo

Compare Cloud Mail and Posteo on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Gmail, Outlook.com

Logo: Cloud Mail

Cloud Mail

Italy· Email Services

Needs review

Shortlist Cloud Mail when you need Italian-operated, managed domain email with Plesk, Roundcube, CalDAV/CardDAV, and pre-delivery antispam on Seeweb infrastructure. Skip when you need end-to-end encrypted / zero-access mail (consider Proton Mail or Tuta) or a full Workspace/365 productivity suite (Google Workspace / Microsoft 365).

Managed domain emailPlesk administrationCalDAV / CardDAVISO 27001 (claimed)CISPE CoC (claimed)Italian / EU operator
Logo: Posteo

Posteo

Germany· Email Services

Needs review

Shortlist when you want a paid German mailbox on self-operated servers, open protocols (IMAP/CalDAV), and extreme data minimisation (no inventory data, unlinked payments). Skip when you need custom domains, default E2EE without setup, multi-seat enterprise admin, or an Art. 28 DPA—consider Proton Mail, Tuta, mailbox.org, or Mailfence instead.

Self-operated DE serversData-minimising signupIMAP / CalDAV / CardDAVBSI TR-03108 (verified)Optional crypto mail storageAd-free, user-funded
Cloud Mail vs Posteo: Snapshot
FeatureLogo: Cloud MailCloud MailLogo: PosteoPosteo
Country of originItalyGermany
CategoryEmail ServicesEmail Services
Open sourceNoYes
Self-hostedNoNo
HeadquartersItalyGermany
Legal entitySeeweb S.r.l. (VAT IT02043220603), Via Armando Vona 66, 03100 FrosinonePosteo e.K., Methfesselstr. 38, 10965 Berlin
Governing lawItaly / EU (forum of Frosinone referenced in general conditions)German / EU law (GDPR, BDSG, telecom secrecy / TTDSG as applicable)
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)LowLow
Hosting / residencySeeweb-operated European infrastructure (proprietary DCs in Milan and Frosinone; group facilities also listed in Lugano, Zurich, Sofia). Cloud Mail backups: daily off-site to another Seeweb data center using IBM Spectrum Protect software. CISPE materials claim European territorial storage for covered cloud services. No public AWS/GCP/Azure hosting path found for this product.Self-operated infrastructure; stored mail and backups in Germany (Frankfurt, Bielefeld, Berlin DCs per privacy materials). No AWS/GCP/Azure listed for mailbox hosting. Payment top-ups may use PayPal/card networks (unlinked from accounts per Posteo).
Summary

Seeweb’s managed professional domain email: Plesk admin, Roundcube webmail, CalDAV/CardDAV, pre-delivery antispam, and daily off-site backups on Italian/EU infrastructure.

Independent Berlin email provider with self-operated German servers, data-minimising signup, open-standard clients, and layered optional encryption—not a free-tier ad network.

Tags
At a glance: Cloud Mail vs Posteo
At a glanceLogo: Cloud MailCloud MailLogo: PosteoPosteo
HQFrosinone, Italy (Seeweb S.r.l.)Berlin, Germany
GroupDHH (Euronext Growth Milan) since 2020Not listed
Product typeManaged domain email hostingNot listed
Admin / webmailPlesk + RoundcubeNot listed
ProtocolsIMAP, POP3, SMTP, CalDAV, CardDAVIMAP, POP3, SMTP, CalDAV, CardDAV
Open source productNo (managed service; Roundcube is the webmail UI)Not listed
Self-hosted productNoNot listed
Commercial modelPaid storage/mailbox packs; domain required; WhiteLabel availablePrepaid paid service; no free tier
Legal entityNot listedPosteo e.K. (HRA 47592 B)
HostingNot listedSelf-operated servers in Germany
Self-hostNot listedNo (hosted service)
FoundedNot listed2009
EnergyNot listed100% green energy (Green Planet Energy, claimed)
Key capabilities: Cloud Mail vs Posteo
Key capabilitiesLogo: Cloud MailCloud MailLogo: PosteoPosteo
Managed domain emailYesNot listed
Plesk administrationYesNot listed
CalDAV / CardDAVYesNot listed
ISO 27001 (claimed)YesNot listed
CISPE CoC (claimed)YesNot listed
Italian / EU operatorYesNot listed
Self-operated DE serversNot listedYes
Data-minimising signupNot listedYes
IMAP / CalDAV / CardDAVNot listedYes
BSI TR-03108 (verified)Not listedYes
Optional crypto mail storageNot listedYes
Ad-free, user-fundedNot listedYes

Cloud Mail

  • Plesk domain mail admin (mailboxes, aliases, forwards)

    One admin account manages mailboxes, passwords, aliases, forwards, and auto-replies in Plesk, with quota/usage visibility per account. Suited to SMEs and resellers who want classic hosting-style control without running their own MTA.

  • Roundcube webmail + IMAP/POP3/SMTP on mail.truemail.it

    Users access mail via Roundcube (webmail.truemail.it) or standard clients. Docs publish IMAP/POP3/SMTP endpoints with STARTTLS and SSL port options for Outlook, Thunderbird, Apple Mail, and mobile. CalDAV and CardDAV cover calendar and contacts sync.

  • Managed pre-delivery antispam/antivirus (no default spam folder)

    Centralized filters check sender IP/domain behaviour and content before the message is accepted. Rejected spam is returned to the sender rather than filed in a default spam mailbox; false positives are handled via ticket or report@postmaster.seeweb.it. Accuracy is not claimed to be 100%.

  • Daily off-site backups (IBM Spectrum Protect, 30-day history)

    Incremental daily backups run to a remote Seeweb data center using IBM Spectrum Protect software. Deleted mail can be requested for recovery within about 30 days; restores recover the backed-up set rather than individual selected messages, so IMAP is recommended.

  • Scalable domain packs + WhiteLabel resale

    Plans scale from small 5 GB / 5-mailbox packs through large multi-hundred-GB packs with matching mailbox counts (up to on the order of 1,280 mailboxes). A domain is required at activation. WhiteLabel supports partners who resell branded mail on Seeweb’s managed stack.

Posteo

  • Signup without identity data; payments unlinked

    Accounts can be created without name, address, or phone. Posteo's payment system (bank transfer codes, cash, card, PayPal) is designed so payment identifiers are not stored against the mailbox. Practical limit: recovery options you add yourself and how you fund the prepaid balance still affect anonymity in the real world.

  • Optional crypto mail storage for the whole mailbox

    One setting encrypts stored messages—including metadata—with a key protected by the account password (RSA/AES/HMAC/bcrypt design; Dovecot plugin). Posteo states it cannot disable crypto storage once enabled and cites a Cure53 review. Limit: this is server-side encryption at rest after delivery, not sender-to-recipient E2EE, and losing the password can mean losing access to encrypted data.

  • TLS, DANE, and BSI-certified secure transport

    Access is TLS-only with PFS, HSTS, and DANE/TLSA. Optional TLS-sending/receiving guarantees refuse delivery over cleartext peer links. Posteo holds BSI TR-03108 v2 Secure Email Transport certification (BSI-K-TR-0745-2025). Transport quality still depends on the remote provider's stack.

  • CalDAV/CardDAV with optional password encryption

    Calendars and contacts sync via open standards and can be AES-encrypted in Posteo's database so the provider cannot read them when the feature is on. Trade-off: encrypted calendars cannot be shared the same way, and password reset without the old secret can lock you out of encrypted PIM data.

  • In-house migration without third-party movers

    Posteo's own migration tool pulls mail (and often contacts/calendars) over encrypted links from previous providers without routing through a third-party migration SaaS. Quota: a limited number of migrations per account, with an optional collector for ongoing fetch from the old box.

Assurance & compliance: Cloud Mail vs Posteo
Assurance & complianceLogo: Cloud MailCloud MailLogo: PosteoPosteo
Independent security / no-logs audit
Not found

No public third-party no-logs or mail-specific penetration audit PDF found for Cloud Mail; ISO ISMS certs are separate.

Partial

BfDI on-site privacy inspection (2016) confirmed data-minimisation / no inventory IP model (public PDF). Crypto mail storage: vendor cites Cure53 multi-level audit; full public report not located. Not a continuous independent no-logs certification programme.

ISO 27001
Vendor claimed

Vendor certifications page: ISO/IEC 27001:2022, scope includes mail services; AXE REGISTER cert IT18-27702D (listed valid until 28 Nov 2027). Not independently re-verified in a public registry by this draft.

Not found

No ISO 27001 claim found on primary Posteo security/privacy pages.

ISO 27017 / 27018 (cloud)
Vendor claimed

Published on certifications page as appendices to the ISO 27001 certificate; mail services in process scope.

Not listed
SOC 2 / SOC 3
Not found

Not listed on the public certifications page.

Not found

No SOC 2/3 report advertised on primary pages.

GDPR / EU data protection
Vendor claimed

Italian controller entity, named DPO, privacy policy under GDPR; product marketed as GDPR-oriented; CISPE CoC adherence claimed.

Vendor claimed

German entity; privacy policy cites GDPR/BDSG/telecom secrecy; DPO published; BfDI inspection history.

CISPE Code of Conduct
Vendor claimed

Certifications page: Seeweb cloud services adhere to CISPE; claims storage exclusively within European territories for covered services.

Not listed
US CLOUD Act exposure (indicative)
Partial

EuropeanStack assessment: EU entity, DHH European group, no known US parent; public hosting story is Seeweb EU DCs and CISPE EU territory claim; backups on Seeweb off-site DCs (Spectrum Protect software, not described as US cloud mailbox SaaS). Residual gaps: no full public subprocessor list; antispam uses external reputation services not named on the docs page. Not legal advice.

Partial

EuropeanStack assessment: German e.K., no known US parent, self-operated DE hosting with no public US-cloud mailbox subprocessors → indicative exposure low. Status is partial (not a clean bill): payment rails and lawful German disclosure remain. Not legal advice.

Data processing agreement (B2B)
Not found

No downloadable product DPA found on the marketing site; general conditions reference GDPR processing and the privacy notice. Request Art. 28 terms for mail content before go-live.

Not found

Vendor states it is not an Art. 28 processor as a public electronic communications service and does not offer customer DPAs.

EU AI Act
Not applicable

Cloud Mail is conventional email hosting, not an AI product.

Not applicable

Conventional email/PIM service; not an AI product.

BSI TR-03108 Secure Email TransportNot listed
Verified

BSI certificate BSI-K-TR-0745-2025 (OpenSource Security GmbH audit; valid through 2030 per BSI listing).

Considerations & known limitations: Cloud Mail vs Posteo
Considerations & known limitationsLogo: Cloud MailCloud MailLogo: PosteoPosteo
Subprocessor / antispam feed list not public
Medium

Docs mention reputation services for antispam but do not publish a complete subprocessor table. Procurement should request the current list and transfer safeguards.

Not listed
Backup restore is set-based, not single-message
Low

30-day off-site history is useful, but restores recover the backed-up set; plan operational recovery expectations and prefer IMAP.

Not listed
Pre-delivery reject without default spam folder
Low

Strong filtering can block legitimate senders; there is no user-visible spam quarantine by default—use tickets/reporting workflows.

Not listed
Not zero-access / E2EE-first mail
Medium

Provider-managed conventional mail. Choose encrypted peers if the threat model assumes a compromised host provider.

Not listed
B2B DPA not prominent on site
Medium

Treat contract/DPA negotiation as a gate for regulated workloads until Art. 28 terms and roles (controller/processor for mailbox content) are signed.

Not listed
No custom domainsNot listed
High

Posteo will not host your own domain. Organisations needing brand continuity or provider portability via DNS must pick another host or self-host.

Encryption is layered, not default E2EENot listed
Medium

Without crypto mail storage, inbound encryption, or client-side PGP/S/MIME, Posteo can process mailbox content like a normal provider. Lawful intercept (TKU) and seizures remain possible under German process; transparency reports show content releases do occur under court order.

No customer Art. 28 DPANot listed
Medium

Procurement checklists that require a signed processor agreement will stall. Posteo argues telecom special law applies instead; validate with legal counsel for your use case.

Password loss risk with crypto featuresNot listed
Medium

Crypto mail storage and encrypted calendars/contacts depend on the account password; Posteo cannot recover plaintext if that secret is lost after encryption is enabled.

Payment processors outside pure DE mail pathNot listed
Low

Optional PayPal/card top-ups involve non-German commercial processors even though Posteo says it does not link payment identity to the mailbox. Cash/bank-code paths reduce that linkage further.

Fit

Cloud Mail

Best fit when

  • SMEs and freelancers needing custom-domain business mail without a full Google/Microsoft suite
  • Teams that want classic IMAP/SMTP clients plus Roundcube webmail and CalDAV/CardDAV
  • Resellers seeking WhiteLabel managed mail on a European host
  • Organizations already using Seeweb compute/hosting that want mail in the same vendor relationship
  • Buyers prioritizing Italian legal entity, published ISO scopes that include mail, and CISPE-oriented residency messaging

Poor fit when

  • Threat models that require default end-to-end encryption or zero-access provider architecture
  • Need for full collaborative office suites, deep directory SSO, or Graph/Workspace app ecosystems
  • Teams that must self-host the MTA stack rather than buy managed mail
  • Procurement that requires a public SOC 2 report or a fully published subprocessor list before first contact

Consider instead when

  • When: You need zero-access / end-to-end encrypted mailboxes as the primary control

    Consider: Proton Mail or Tuta

    Different product class: E2EE-first vs conventional managed IMAP hosting

  • When: You need mail plus full productivity suite and global enterprise ecosystem

    Consider: Google Workspace or Microsoft 365

    Trade EU-operator focus for suite breadth and US-jurisdiction diligence

  • When: You want another European professional domain-mail host for comparison

    Consider: Migadu, Mailfence, or Combell E-mail

    Compare admin model, spam handling, restore RPO, and contract artifacts

Posteo

Best fit when

  • Individuals and small teams who want German jurisdiction and open-standard clients without Google or Microsoft mail
  • Users prioritising anonymous or low-identity signup and prepaid funding without linking payments to the mailbox
  • Organisations that accept posteo.* addresses and value no ads, no tracking, and published transparency reports
  • Operators who want optional full-mailbox encryption at rest (crypto mail storage) plus PGP/S/MIME tooling
  • Buyers who need BSI-aligned secure email transport certification rather than US SOC 2 paperwork

Poor fit when

  • Anyone requiring custom domains or branded organisational addresses
  • Teams that need default zero-access E2EE for every message without enabling optional layers
  • Procurement processes that mandate a signed Art. 28 DPA, SOC 2, or ISO 27001 from the vendor
  • Large enterprises needing multi-seat admin, shared domain policies, or deep Microsoft/Google workspace integration

Consider instead when

  • When: You need default end-to-end encryption and a broader encrypted suite

    Consider: Proton Mail or Tuta

    Posteo is IMAP-first with optional crypto layers; Proton/Tuta lead with zero-access defaults.

  • When: You need custom domains or richer business mail hosting

    Consider: mailbox.org or Mailfence

    Posteo deliberately refuses own domains to avoid inventory-data obligations.

  • When: You need free-tier consumer mail tightly integrated with docs and chat

    Consider: Gmail or Outlook.com

    Trade privacy posture and EU self-operation for ecosystem convenience.

Open questions for due diligence

Cloud Mail

  • Will Seeweb provide a signed Art. 28 DPA and current subprocessor list for Cloud Mail content?
  • Which data center hosts a given Cloud Mail instance (Italy vs other European Seeweb/group sites), and can residency be constrained contractually?
  • Which external reputation / antispam intelligence providers are used, and where do they process metadata?
  • Is there a SOC 2, independent penetration test summary, or customer-available audit package under NDA?
  • What are exact SLA credits, RPO/RTO for mail, and support tier inclusions for pure Cloud Mail (vs Global Support for servers)?

Posteo

  • Does your counsel accept Posteo's position that no Art. 28 DPA is required for occupational use?
  • Will posteo.de / .net / .com addresses meet your brand, deliverability, and anti-spoofing requirements without custom domains?
  • Which encryption layers (crypto mail storage, inbound PGP/S/MIME, client E2EE) will your users actually enable and support?
  • Do you need ISO 27001/SOC 2 artefacts that Posteo does not publish?
  • Is BSI TR-03108 transport certification sufficient for your sector's secure-email checklist?