eclipso Mail Europe vs Mailfence

Compare eclipso Mail Europe and Mailfence on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Gmail, Microsoft 365, Outlook.com

Logo: eclipso Mail Europe

eclipso Mail Europe

Germany· Email Services

Needs review

Shortlist when you want German-hosted mail with direct IMAP/SMTP, optional OpenPGP/S/MIME free on all tiers, prepaid freemium cost control, and a small business suite (drive, calendar, hybrid SMS/fax/post). Skip when you need zero-access defaults, published ISO/SOC audits, or large-enterprise identity—consider Posteo, Tuta, Proton Mail, or mailbox.org instead.

Germany-hosted (claimed)OpenPGP + S/MIMEIMAP/SMTP nativePrepaid freemiumOwner-operated DEBusiness DPA (Art. 28)
Logo: Mailfence

Mailfence

Belgium· Email Services

Needs review

Shortlist Mailfence when you want Belgian-operated webmail with interoperable OpenPGP, digital signatures, and a light calendar/documents suite—plus optional business private-label or on-prem license. Skip when you need automatic closed E2EE without key management (consider Tuta), a large Swiss privacy ecosystem (Proton Mail), or a minimalist German mailbox (Posteo / mailbox.org).

EU-operated (Belgium)OpenPGP E2EEDigital signaturesMail + calendar + docsCustom domains (paid)B2B DPA available
eclipso Mail Europe vs Mailfence: Snapshot
FeatureLogo: eclipso Mail Europeeclipso Mail EuropeLogo: MailfenceMailfence
Country of originGermanyBelgium
CategoryEmail ServicesEmail Services
Open sourceNoNo
Self-hostedNoNo
HeadquartersGermanyBelgium
Legal entityClaus-Peter Beringer (eclipso Mail Europe), Grubstr. 9b, 95445 BayreuthContactOffice Group sa, Avenue Franklin Roosevelt 47b, B-1050 Brussels (BE 0466.241.584)
Governing lawGerman / EU law (GDPR, BDSG); BayLDA supervisory authority named in privacy noticeBelgian law; Brussels courts (Terms of Use)
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)MediumLow
Hosting / residencyPrimary hosting claimed exclusively in Germany; privacy policy names Speedloc Datacenter (Görlitz) with AVV. Optional SMS/fax/post: Commify Germany, CM.com Germany, letterei.de (all DE). Payments: Stripe Payments Europe and PayPal (Europe). Site: Google reCAPTCHA; marketing ad partners documented; Matomo self-hosted analytics.Primary production servers described as located in Belgium under Mailfence operational control (no intermediary managing servers per security page). No public AWS/GCP/Azure subprocessor list found. Backups stored in locations separate from offices/main DC (providers not named). Payment-card processing path not fully published.
Summary

Owner-operated German email and cloud suite with IMAP, optional OpenPGP/S/MIME, prepaid freemium, Drive/organizer, and hybrid SMS/fax/post—hosted in Germany.

Belgian secure email suite with browser-side OpenPGP encryption, digital signatures, calendar, documents, and optional custom domains under ContactOffice Group SA.

Tags
At a glance: eclipso Mail Europe vs Mailfence
At a glanceLogo: eclipso Mail Europeeclipso Mail EuropeLogo: MailfenceMailfence
HQBayreuth, GermanyNot listed
Legal entityClaus-Peter Beringer (owner-operated)Not listed
Founded2003 (vendor)Not listed
HostingGermany; Speedloc Datacenter (Görlitz) named in privacy policyVendor-operated servers in Belgium (per security page)
Open sourceNoNo (front-end OSS planned; not current)
Self-hostedNo (SaaS)Not listed
Commercial modelFreemail (ad-supported) + prepaid paid tiersFree tier + prepaid paid plans; Business packaging (see vendor site)
EncryptionOptional OpenPGP + S/MIME; TLS in transitNot listed
HQ / entityNot listedBrussels — ContactOffice Group sa (BE 0466.241.584)
Product launchNot listedMailfence brand ~2013; ContactOffice lineage since 1999
CryptoNot listedOpenPGP E2EE + digital signatures; optional password-encrypted messages
Self-hostNot listedSaaS default; Business license for large on-prem deployments
Independent auditNot listedNo public audit PDF found
Key capabilities: eclipso Mail Europe vs Mailfence
Key capabilitiesLogo: eclipso Mail Europeeclipso Mail EuropeLogo: MailfenceMailfence
Germany-hosted (claimed)YesNot listed
OpenPGP + S/MIMEYesNot listed
IMAP/SMTP nativeYesNot listed
Prepaid freemiumYesNot listed
Owner-operated DEYesNot listed
Business DPA (Art. 28)YesNot listed
EU-operated (Belgium)Not listedYes
OpenPGP E2EENot listedYes
Digital signaturesNot listedYes
Mail + calendar + docsNot listedYes
Custom domains (paid)Not listedYes
B2B DPA availableNot listedYes

eclipso Mail Europe

  • Native OpenPGP and S/MIME in every plan

    OpenPGP (RFC 4880/9580) key wizard and import work in webmail and apps, free from Freemail upward; S/MIME accepts user-supplied X.509 certificates for business clients. E2EE only applies when both sides use it—plain IMAP mail is not zero-access by default. Private keys for webmail PGP are held in the account under a passphrase for multi-device use.

  • Standard IMAP, POP3, SMTP plus CalDAV/CardDAV

    Direct protocol access for Thunderbird, Outlook, Apple Mail, and mobile clients without a bridge product. Calendar and contacts sync via CalDAV/CardDAV; Premium and Business add WebDAV for the cloud drive. Suits teams that refuse locked-in web-only mail.

  • German-hosted suite: mail, drive, organizer

    One account covers webmail, eclipso Drive file storage with link sharing, Media Center, calendar, address book, notes, and tasks. Vendor claims exclusive Germany data centres (privacy policy names Speedloc Datacenter, Görlitz). Storage and address limits scale by prepaid tariff; WebDAV and higher quotas need paid tiers.

  • Prepaid freemium with optional hybrid channels

    Freemail signs up without credit card or phone number and is ad-supported; paid Connect/Premium/Business terms are prepaid and end automatically after a reminder. Credits enable SMS, fax, and hybrid physical post through named German gateways—useful for crafts and SMEs still on those channels.

  • Business domain and Art. 28 DPA on Business plan

    Business includes a custom mail domain option, higher alias counts, daily send limits suitable for small campaigns, and an in-product Art. 28 GDPR DPA download per vendor docs. Not a full enterprise workspace: no public SCIM/SSO pack or multi-org admin model documented.

Mailfence

  • Browser-side OpenPGP end-to-end encryption

    Encrypt outbound mail in the browser with the OpenPGP standard so intermediaries—including Mailfence when messages are properly E2EE—cannot read ciphertext. Fully interoperable with other OpenPGP tools (e.g. Thunderbird/GnuPG). Optional password-encrypted messages cover recipients who do not use PGP. Unencrypted mail still sits on servers in the normal webmail model.

  • Digital signatures and multi-key OpenPGP keystore

    Sign messages for authenticity and integrity, and manage keys in-product: generate, import, export, publish, and hold multiple key pairs without browser plug-ins. Default generated keys are 4096-bit per the threat-model page. Passphrase protection of private keys limits crypto operations if only the account password is compromised.

  • Mail, calendar, documents, and groups in one account

    Beyond inbox: shareable calendars, online document storage/editing, and contact groups for collaboration without bolting on a separate US suite. Storage and alias limits scale by plan; free accounts remain suitable only for light personal use.

  • Custom domains, aliases, and mail protocols on paid tiers

    Higher plans add custom domains with SPF/DKIM/DMARC-oriented setup, larger alias counts, and classic client access (POP, IMAP, SMTP) plus ActiveSync where listed. Entry-level free accounts focus on web/PWA/apps rather than full protocol parity—verify the live plan matrix before procurement.

  • Business admin: API, SSO, private label, optional on-prem license

    Mailfence for Business offers control-panel and XML-RPC API user provisioning, SSO and directory hooks (LDAP/AD/CAS), branding, and Belgian cloud hosting with SLA language—or a license to run on customer Linux servers for large deployments. Fit for orgs that need Belgian hosting with admin automation, not a consumer-only mailbox.

Assurance & compliance: eclipso Mail Europe vs Mailfence
Assurance & complianceLogo: eclipso Mail Europeeclipso Mail EuropeLogo: MailfenceMailfence
Independent security / no-logs audit
Not found

No public third-party security or no-logs audit PDF located on official pages

Not found

No public third-party audit PDF found. Vendor mentions security specialists, bug bounty activity, and inspection openness—not a substitute for a published audit. Privacy policy documents operational metadata collection (not zero-logs).

ISO 27001
Not found

No ISO 27001 claim found on official security/about pages at research time

Not found

No Mailfence ISO 27001 certificate claim found on primary security/GDPR/company pages.

SOC 2 / SOC 3
Not found

No SOC 2/3 report referenced on official site

Not found
GDPR / EU data protection
Vendor claimed

German controller, DPO contact, BayLDA authority, GDPR rights language in privacy policy; servers claimed in Germany

Vendor claimed

Belgian controller/processor materials; dedicated GDPR page and technical/organisational measures overview. Confirm roles in your DPA.

US CLOUD Act exposure (indicative)
Partial

EU/DE owner-operated entity with DE hosting (Speedloc), but Stripe, PayPal, and Google reCAPTCHA/ad tooling introduce US-group processing paths for payment and website data. Not legal advice.

Partial

EU entity (ContactOffice Group sa), no known US parent; servers claimed self-operated in Belgium without named US hyperscaler hosts. No formal public subprocessor inventory; payment processors not named. Assessment residual: partial transparency on data path. Not legal advice.

Data processing agreement (B2B)
Vendor claimed

Art. 28 DPA described as included and downloadable on Business plan; confirm for lower tiers

Vendor claimed

Downloadable DPA linked from the GDPR page for organisational customers.

EU AI Act
Not applicable

Email/cloud suite; not an AI system product

Not applicable

Email/collaboration suite; not an AI system under typical procurement framing.

Considerations & known limitations: eclipso Mail Europe vs Mailfence
Considerations & known limitationsLogo: eclipso Mail Europeeclipso Mail EuropeLogo: MailfenceMailfence
Not zero-access by default
Medium

Without OpenPGP/S/MIME, mailbox content is accessible to the operator like traditional IMAP hosts. Webmail PGP private keys are stored in-account under a passphrase—review threat model vs pure local keys.

Not listed
US-group payment and site tooling
Medium

Stripe, PayPal, Google reCAPTCHA, and documented ad partners process personal data outside pure DE mailbox hosting. Material for CLOUD Act and transfer diligence even if mail servers stay in Germany.

Not listed
No public ISO/SOC or independent audit
Medium

Security assurance is first-party documentation only. Regulated buyers will need questionnaires, AVVs, and possibly on-request evidence.

Medium

If vendor risk requires a published audit letter, ISO 27001, or SOC 2, treat Mailfence as incomplete until evidence is obtained offline or under NDA.

Freemail is ad-supported
Low

Free tier includes advertising as a service component. Paid tiers are marketed as ad-free; verify current footer/banner behaviour on the live product.

Not listed
Owner-operated scale limits
Low

Independent DE operator (not VC-backed hyperscale). Expect SME-grade support hours and product depth rather than global enterprise SLAs.

Not listed
Closed-source SaaSNot listed
Medium

Cannot independently review server code or default-self-host like some FOSS mail stacks. Business on-prem license is a commercial path, not community self-host docs.

E2EE is opt-in OpenPGP, not automaticNot listed
Medium

Clear-text messages are operator-readable at rest. Users must encrypt/sign deliberately; training and policy matter for regulated content.

Operational metadata retentionNot listed
Low

Privacy policy lists IP, message-IDs, addresses, subjects, and related fields for operations, abuse control, and legal process—not a zero-logs design.

Limited public subprocessor inventoryNot listed
Low

Strong first-party claims of internal hosting, but no AWS-style public subprocessor table; confirm payment and support tooling in procurement.

US CLOUD Act (indicative)Not listed
Low

No known US parent; Belgian self-operated hosting narrative. Residual unknown payment/SaaS paths. Not a legal safe harbour guarantee.

Fit

eclipso Mail Europe

Best fit when

  • Individuals and freelancers who want German mail with Thunderbird/Outlook IMAP and optional OpenPGP without a bridge
  • SMEs needing a custom domain, German server claims, and an Art. 28 DPA on the Business plan
  • Buyers who prefer prepaid terms that end automatically over auto-renewing Big Tech suites
  • Users who still send SMS, fax, or hybrid physical post from the same account
  • Teams migrating from Gmail/Outlook that value CalDAV/CardDAV and a bundled drive/organizer

Poor fit when

  • Orgs that require zero-access architecture where the provider never stores decryptable mailbox keys by default
  • Enterprises needing public ISO 27001/SOC 2 reports, SCIM/SSO, or multi-tenant admin
  • Buyers who refuse any US-group payment or website tooling (Stripe, PayPal, Google reCAPTCHA/ads)
  • Users seeking open-source or self-hosted mail only

Consider instead when

  • When: You want a simple paid-only German privacy mailbox without freemium advertising

    Consider: Posteo

    Posteo is ad-free paid; eclipso differentiates with freemail and hybrid channels

  • When: You prioritise always-on encryption over standard IMAP clients

    Consider: Tuta or Proton Mail

    Tuta uses proprietary E2EE clients; Proton needs Bridge for full IMAP-style access

  • When: You need a broader paid German workplace suite with stronger enterprise packaging

    Consider: mailbox (formerly mailbox.org)

    Compare admin, audit, and collaboration depth on current vendor docs

  • When: You need Google/Microsoft collaboration depth more than EU operator control

    Consider: Gmail or Microsoft 365

    Different jurisdiction and data-use models

Mailfence

Best fit when

  • You need OpenPGP interoperability and digital signatures from a European webmail, not only proprietary E2EE
  • Belgian legal entity and self-described self-operated Belgian hosting are procurement requirements
  • Teams want mail plus calendar/documents/groups without moving to Microsoft 365 or Google Workspace
  • You need custom domains, aliases, and classic clients (IMAP/POP/ActiveSync) on paid tiers
  • Business buyers evaluating private-label, API provisioning, SSO/directory integration, or large-scale on-prem license

Poor fit when

  • Security policy requires a published independent security audit, ISO 27001, or SOC 2 from the email vendor
  • You want fully open-source server/client stacks you can fork and self-host as default
  • Every message must be automatically E2EE with no OpenPGP key UX (Tuta-style)
  • You need Microsoft-class DLP, eDiscovery, compliance archives, and deep SaaS integrations
  • Zero-logs marketing is a hard requirement (Mailfence documents operational metadata collection)

Consider instead when

  • When: You want automatic encryption for all messages with minimal key management

    Consider: Tuta

    Different crypto model; less OpenPGP interop emphasis than Mailfence.

  • When: You want a larger Swiss privacy suite brand and ecosystem apps

    Consider: Proton Mail

    Trade Belgian ContactOffice ownership and PGP-centric UX for Proton’s broader product family.

  • When: You want a lean German ad-free mailbox without suite features

    Consider: Posteo or mailbox.org

    Simpler mailbox posture; different admin/domain/crypto tradeoffs.

  • When: You need full Google/Microsoft productivity and compliance tooling

    Consider: Microsoft 365 or Google Workspace (accept US-cloud risk) or EU office suites if residency is the driver

    Mailfence is not a drop-in M365 replacement.

Open questions for due diligence

eclipso Mail Europe

  • Can non-Business tariffs obtain a signed Art. 28 DPA and full subprocessor list on request?
  • Is Speedloc the sole host for mailbox content (not only the marketing site), and are backup/DR locations exclusively in Germany?
  • Are independent penetration tests or ISO plans available under NDA for enterprise buyers?
  • What exact data minimisation applies to freemail advertising versus paid ad-free tiers (inbox content vs account metadata)?
  • How are OpenPGP private keys encrypted at rest in the account store, and is export/deletion documented for offboarding?

Mailfence

  • Will Mailfence provide a current written subprocessor list (including payment processors and any backup locations) for a company account?
  • Is any independent security assessment available under NDA for regulated buyers?
  • For Business on-prem license: exact minimum scale, support model, update cadence, and cryptographic feature parity vs SaaS?
  • Which plan tiers currently include IMAP/POP/ActiveSync and custom-domain limits for our user count?
  • How are disaster-recovery backup sites jurisdictions documented in the signed DPA annex?