GMX Mail vs Mailfence

Compare GMX Mail and Mailfence on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Gmail, Outlook.com

Logo: GMX Mail

GMX Mail

Germany· Email Services

Needs review

Shortlist GMX Mail for consumer or light-professional freemail when you want a German United Internet operator, claimed German mailbox data centers, large free storage, and standard IMAP/POP—with optional OpenPGP. Skip when you need zero-access encryption by default, enterprise DPA/audit packs, or an ad-free architecture as the baseline; consider Proton Mail instead.

German operatorMailbox in DE (claimed)IMAP / POP3 / SMTPOptional OpenPGPFree ad-supportedSaaS only
Logo: Mailfence

Mailfence

Belgium· Email Services

Needs review

Shortlist Mailfence when you want Belgian-operated webmail with interoperable OpenPGP, digital signatures, and a light calendar/documents suite—plus optional business private-label or on-prem license. Skip when you need automatic closed E2EE without key management (consider Tuta), a large Swiss privacy ecosystem (Proton Mail), or a minimalist German mailbox (Posteo / mailbox.org).

EU-operated (Belgium)OpenPGP E2EEDigital signaturesMail + calendar + docsCustom domains (paid)B2B DPA available
GMX Mail vs Mailfence: Snapshot
FeatureLogo: GMX MailGMX MailLogo: MailfenceMailfence
Country of originGermanyBelgium
CategoryEmail ServicesEmail Services
Open sourceNoNo
Self-hostedNoNo
HeadquartersGermanyBelgium
Legal entity1&1 Mail & Media GmbH (Zweigniederlassung Karlsruhe; Hauptsitz Montabaur)ContactOffice Group sa, Avenue Franklin Roosevelt 47b, B-1050 Brussels (BE 0466.241.584)
Governing lawGerman law (international T&Cs); GDPR applies as EU controllerBelgian law; Brussels courts (Terms of Use)
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)MediumLow
Hosting / residencyVendor privacy (EN): FreeMail emails, address book, and calendar processed in secure data centers in Germany. Product security pages: European data centers for stored mail. Group United Internet AG (DE). Named non-mail paths: Google Analytics/GTM on portal; Google/Yahoo search partnership; international ad partners under consent; DE privacy allows third-country transfers with Chapter V safeguards when used. No public exhaustive mail-infra subprocessor list found.Primary production servers described as located in Belgium under Mailfence operational control (no intermediary managing servers per security page). No public AWS/GCP/Azure subprocessor list found. Backups stored in locations separate from offices/main DC (providers not named). Payment-card processing path not fully published.
Summary

German FreeMail from 1&1 Mail & Media GmbH (United Internet): large free storage, IMAP/POP/SMTP, optional OpenPGP and 2FA, ad-supported consumer webmail.

Belgian secure email suite with browser-side OpenPGP encryption, digital signatures, calendar, documents, and optional custom domains under ContactOffice Group SA.

Tags
At a glance: GMX Mail vs Mailfence
At a glanceLogo: GMX MailGMX MailLogo: MailfenceMailfence
HQ / entity1&1 Mail & Media GmbH, Montabaur (DE)Brussels — ContactOffice Group sa (BE 0466.241.584)
Parent groupUnited Internet AG (DE)Not listed
Product typeConsumer FreeMail + optional paid tiersNot listed
Hosting (claimed)Mailbox/calendar data in German data centersNot listed
ProtocolsWebmail; POP3/IMAP/SMTP (opt-in)Not listed
Open sourceNoNo (front-end OSS planned; not current)
Self-hostedNoNot listed
Product launchNot listedMailfence brand ~2013; ContactOffice lineage since 1999
CryptoNot listedOpenPGP E2EE + digital signatures; optional password-encrypted messages
HostingNot listedVendor-operated servers in Belgium (per security page)
Self-hostNot listedSaaS default; Business license for large on-prem deployments
Commercial modelNot listedFree tier + prepaid paid plans; Business packaging (see vendor site)
Independent auditNot listedNo public audit PDF found
Key capabilities: GMX Mail vs Mailfence
Key capabilitiesLogo: GMX MailGMX MailLogo: MailfenceMailfence
German operatorYesNot listed
Mailbox in DE (claimed)YesNot listed
IMAP / POP3 / SMTPYesNot listed
Optional OpenPGPYesNot listed
Free ad-supportedYesNot listed
SaaS onlyYesNot listed
EU-operated (Belgium)Not listedYes
OpenPGP E2EENot listedYes
Digital signaturesNot listedYes
Mail + calendar + docsNot listedYes
Custom domains (paid)Not listedYes
B2B DPA availableNot listedYes

GMX Mail

  • Large free mailbox storage with open protocols

    gmx.com free accounts advertise up to 65 GB email storage and 50 MB attachments. POP3, IMAP, and SMTP are supported after you enable them in settings (TLS 1.2+; imap.gmx.com / mail.gmx.com). Suits users who want client choice (Thunderbird, Outlook, mobile) without Google or Microsoft as the mailbox host.

  • Optional OpenPGP end-to-end encryption (Mailvelope)

    GMX offers free OpenPGP messaging via the Mailvelope browser extension: key generation, local key storage, key directory, and mobile recovery. Encryption is opt-in per message after setup—not whole-mailbox zero-access by default. Best for occasional sensitive threads when both parties can use OpenPGP.

  • Aliases, Mail Collector, and multi-account inbox

    Create up to 10 alias addresses (including other GMX domains) managed in one inbox, and pull up to 10 external accounts via Mail Collector. Useful for freelancers and project mail without juggling multiple passwords or providers day-to-day.

  • Spam filtering, antivirus, and optional TOTP 2FA

    Free accounts include automated spam filtering (user blacklist and optional improved detection) and antivirus scanning of mail and cloud files. Optional two-factor authentication uses an authenticator app (TOTP); third-party clients use app-specific passwords when 2FA is on.

  • Bundled Cloud, calendar, contacts, and Online Office

    Accounts include contacts, calendar/organizer, about 2 GB GMX Cloud with share links, and Online Office for common document formats—enough for light personal productivity without a separate suite subscription.

Mailfence

  • Browser-side OpenPGP end-to-end encryption

    Encrypt outbound mail in the browser with the OpenPGP standard so intermediaries—including Mailfence when messages are properly E2EE—cannot read ciphertext. Fully interoperable with other OpenPGP tools (e.g. Thunderbird/GnuPG). Optional password-encrypted messages cover recipients who do not use PGP. Unencrypted mail still sits on servers in the normal webmail model.

  • Digital signatures and multi-key OpenPGP keystore

    Sign messages for authenticity and integrity, and manage keys in-product: generate, import, export, publish, and hold multiple key pairs without browser plug-ins. Default generated keys are 4096-bit per the threat-model page. Passphrase protection of private keys limits crypto operations if only the account password is compromised.

  • Mail, calendar, documents, and groups in one account

    Beyond inbox: shareable calendars, online document storage/editing, and contact groups for collaboration without bolting on a separate US suite. Storage and alias limits scale by plan; free accounts remain suitable only for light personal use.

  • Custom domains, aliases, and mail protocols on paid tiers

    Higher plans add custom domains with SPF/DKIM/DMARC-oriented setup, larger alias counts, and classic client access (POP, IMAP, SMTP) plus ActiveSync where listed. Entry-level free accounts focus on web/PWA/apps rather than full protocol parity—verify the live plan matrix before procurement.

  • Business admin: API, SSO, private label, optional on-prem license

    Mailfence for Business offers control-panel and XML-RPC API user provisioning, SSO and directory hooks (LDAP/AD/CAS), branding, and Belgian cloud hosting with SLA language—or a license to run on customer Linux servers for large deployments. Fit for orgs that need Belgian hosting with admin automation, not a consumer-only mailbox.

Assurance & compliance: GMX Mail vs Mailfence
Assurance & complianceLogo: GMX MailGMX MailLogo: MailfenceMailfence
Independent security / no-logs audit
Not found

OpenPGP/Mailvelope path described as externally reviewed; no public independent no-logs audit for FreeMail mailbox access found on product pages.

Not found

No public third-party audit PDF found. Vendor mentions security specialists, bug bounty activity, and inspection openness—not a substitute for a published audit. Privacy policy documents operational metadata collection (not zero-logs).

ISO 27001
Not found

No GMX FreeMail-branded ISO 27001 certificate located on security/privacy pages in this research pass (group companies may hold certs under other brands).

Not found

No Mailfence ISO 27001 certificate claim found on primary security/GDPR/company pages.

SOC 2 / SOC 3
Not found

No SOC 2/3 report found on GMX public security pages.

Not found
GDPR / EU data protection
Vendor claimed

EU/German controller; public privacy notices under GDPR; DPO published; supervisory authorities named (BfDI / LfDI RLP).

Vendor claimed

Belgian controller/processor materials; dedicated GDPR page and technical/organisational measures overview. Confirm roles in your DPA.

US CLOUD Act exposure (indicative)
Partial

German entity and parent (United Internet AG); mailbox data claimed in German DCs. Partial/medium because portal analytics include Google LLC tools, freemail ads involve international partners, and no full public mail-infra subprocessor list. Not legal advice.

Partial

EU entity (ContactOffice Group sa), no known US parent; servers claimed self-operated in Belgium without named US hyperscaler hosts. No formal public subprocessor inventory; payment processors not named. Assessment residual: partial transparency on data path. Not legal advice.

Data processing agreement (B2B)
Not found

Product is primarily consumer FreeMail under GTCs/privacy policy; no public self-serve B2B DPA flow found for FreeMail shortlisting.

Vendor claimed

Downloadable DPA linked from the GDPR page for organisational customers.

EU AI Act
Not applicable

Not an AI-centric product; optional assistive features may appear in product privacy text but FreeMail is not marketed as an AI system.

Not applicable

Email/collaboration suite; not an AI system under typical procurement framing.

Considerations & known limitations: GMX Mail vs Mailfence
Considerations & known limitationsLogo: GMX MailGMX MailLogo: MailfenceMailfence
Advertising-funded free tier
Medium

FreeMail depends on ads and (with consent) interest-based targeting and partner sharing. Privacy posture differs from paid privacy mail. Practical impact: expect consent UX, ad surfaces, and partner lists—not a zero-ads default.

Not listed
E2E encryption is optional, not default
Medium

Without OpenPGP setup, mailbox content is accessible to the provider like conventional hosted mail. Practical impact: do not treat GMX FreeMail as zero-access encryption architecture.

Not listed
Incomplete public infrastructure subprocessors
Medium

Residency for mail is claimed (Germany/EU), but there is no enterprise-style published subprocessor inventory for core mail infrastructure. Portal paths name Google Analytics and global ad partners. Practical impact: extra questionnaire work for high-assurance buyers.

Low

Strong first-party claims of internal hosting, but no AWS-style public subprocessor table; confirm payment and support tooling in procurement.

Inactivity and freemail operational policies
Low

Terms/privacy allow deletion of free mailbox content after prolonged inactivity (about 180 days without login on FreeMail privacy text). Practical impact: inactive project addresses can disappear if not maintained.

Not listed
No public ISO/SOC package for FreeMail
Low

Security pages emphasize product features (spam, AV, 2FA, PGP) rather than downloadable ISO/SOC evidence for FreeMail. Practical impact: may fail enterprise vendor security questionnaires without further vendor dialogue.

Not listed
No public independent security auditNot listed
Medium

If vendor risk requires a published audit letter, ISO 27001, or SOC 2, treat Mailfence as incomplete until evidence is obtained offline or under NDA.

Closed-source SaaSNot listed
Medium

Cannot independently review server code or default-self-host like some FOSS mail stacks. Business on-prem license is a commercial path, not community self-host docs.

E2EE is opt-in OpenPGP, not automaticNot listed
Medium

Clear-text messages are operator-readable at rest. Users must encrypt/sign deliberately; training and policy matter for regulated content.

Operational metadata retentionNot listed
Low

Privacy policy lists IP, message-IDs, addresses, subjects, and related fields for operations, abuse control, and legal process—not a zero-logs design.

US CLOUD Act (indicative)Not listed
Low

No known US parent; Belgian self-operated hosting narrative. Residual unknown payment/SaaS paths. Not a legal safe harbour guarantee.

Fit

GMX Mail

Best fit when

  • Individuals and freelancers who want a European freemail address with large free storage and IMAP client freedom
  • Users consolidating multiple addresses via aliases (up to 10) and Mail Collector
  • Buyers who prefer a German legal controller (1&1 Mail & Media GmbH / United Internet) over US Big Tech freemail
  • Teams that only need optional OpenPGP for specific sensitive threads, not zero-access by default
  • Users already familiar with GMX/WEB.DE in German-speaking markets who need international domains (e.g. gmx.com)

Poor fit when

  • Organizations that require default end-to-end / zero-access encryption for all mail
  • Procurement that needs a published independent security audit pack, ISO/SOC evidence, and a B2B DPA as standard shortlist inputs
  • Teams that cannot accept advertising-funded freemail economics or interest-based ad consent UX
  • Custom-domain corporate mail and admin controls at Microsoft 365 / Google Workspace depth
  • Self-hosted or open-source mail stack requirements

Consider instead when

  • When: You need zero-access encryption by default and a privacy-first paid model without ad-funded freemail as the core product

    Consider: Proton Mail

    Proton is the stronger shortlist peer in this catalog for E2E-first evaluation.

  • When: You need Google Workspace-class collaboration and are willing to accept US Big Tech jurisdiction

    Consider: Gmail / Google Workspace

    Richer suite integration; different sovereignty and ad/ecosystem tradeoffs.

  • When: You need Microsoft ecosystem mail, calendar, and compliance tooling

    Consider: Outlook.com / Microsoft 365

    Strong enterprise admin story; US parent and CLOUD Act path differ from GMX.

Mailfence

Best fit when

  • You need OpenPGP interoperability and digital signatures from a European webmail, not only proprietary E2EE
  • Belgian legal entity and self-described self-operated Belgian hosting are procurement requirements
  • Teams want mail plus calendar/documents/groups without moving to Microsoft 365 or Google Workspace
  • You need custom domains, aliases, and classic clients (IMAP/POP/ActiveSync) on paid tiers
  • Business buyers evaluating private-label, API provisioning, SSO/directory integration, or large-scale on-prem license

Poor fit when

  • Security policy requires a published independent security audit, ISO 27001, or SOC 2 from the email vendor
  • You want fully open-source server/client stacks you can fork and self-host as default
  • Every message must be automatically E2EE with no OpenPGP key UX (Tuta-style)
  • You need Microsoft-class DLP, eDiscovery, compliance archives, and deep SaaS integrations
  • Zero-logs marketing is a hard requirement (Mailfence documents operational metadata collection)

Consider instead when

  • When: You want automatic encryption for all messages with minimal key management

    Consider: Tuta

    Different crypto model; less OpenPGP interop emphasis than Mailfence.

  • When: You want a larger Swiss privacy suite brand and ecosystem apps

    Consider: Proton Mail

    Trade Belgian ContactOffice ownership and PGP-centric UX for Proton’s broader product family.

  • When: You want a lean German ad-free mailbox without suite features

    Consider: Posteo or mailbox.org

    Simpler mailbox posture; different admin/domain/crypto tradeoffs.

  • When: You need full Google/Microsoft productivity and compliance tooling

    Consider: Microsoft 365 or Google Workspace (accept US-cloud risk) or EU office suites if residency is the driver

    Mailfence is not a drop-in M365 replacement.

Open questions for due diligence

GMX Mail

  • Will 1&1 Mail & Media sign a B2B DPA and publish a current mail-infrastructure subprocessor list for our use case?
  • Are FreeMail mailbox systems solely on United Internet / 1&1 operated German DCs, or are any US-group cloud providers used for primary storage, backup, or DR?
  • What independent audits or certifications (if any) cover the FreeMail platform beyond the Mailvelope/OpenPGP path?
  • For paid/premium mailboxes: which advertising and tracking paths remain, and what contractual residency language is available?

Mailfence

  • Will Mailfence provide a current written subprocessor list (including payment processors and any backup locations) for a company account?
  • Is any independent security assessment available under NDA for regulated buyers?
  • For Business on-prem license: exact minimum scale, support model, update cadence, and cryptographic feature parity vs SaaS?
  • Which plan tiers currently include IMAP/POP/ActiveSync and custom-domain limits for our user count?
  • How are disaster-recovery backup sites jurisdictions documented in the signed DPA annex?