GMX Mail vs Posteo

Compare GMX Mail and Posteo on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Gmail, Outlook.com

Logo: GMX Mail

GMX Mail

Germany· Email Services

Needs review

Shortlist GMX Mail for consumer or light-professional freemail when you want a German United Internet operator, claimed German mailbox data centers, large free storage, and standard IMAP/POP—with optional OpenPGP. Skip when you need zero-access encryption by default, enterprise DPA/audit packs, or an ad-free architecture as the baseline; consider Proton Mail instead.

German operatorMailbox in DE (claimed)IMAP / POP3 / SMTPOptional OpenPGPFree ad-supportedSaaS only
Logo: Posteo

Posteo

Germany· Email Services

Needs review

Shortlist when you want a paid German mailbox on self-operated servers, open protocols (IMAP/CalDAV), and extreme data minimisation (no inventory data, unlinked payments). Skip when you need custom domains, default E2EE without setup, multi-seat enterprise admin, or an Art. 28 DPA—consider Proton Mail, Tuta, mailbox.org, or Mailfence instead.

Self-operated DE serversData-minimising signupIMAP / CalDAV / CardDAVBSI TR-03108 (verified)Optional crypto mail storageAd-free, user-funded
GMX Mail vs Posteo: Snapshot
FeatureLogo: GMX MailGMX MailLogo: PosteoPosteo
Country of originGermanyGermany
CategoryEmail ServicesEmail Services
Open sourceNoYes
Self-hostedNoNo
HeadquartersGermanyGermany
Legal entity1&1 Mail & Media GmbH (Zweigniederlassung Karlsruhe; Hauptsitz Montabaur)Posteo e.K., Methfesselstr. 38, 10965 Berlin
Governing lawGerman law (international T&Cs); GDPR applies as EU controllerGerman / EU law (GDPR, BDSG, telecom secrecy / TTDSG as applicable)
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)MediumLow
Hosting / residencyVendor privacy (EN): FreeMail emails, address book, and calendar processed in secure data centers in Germany. Product security pages: European data centers for stored mail. Group United Internet AG (DE). Named non-mail paths: Google Analytics/GTM on portal; Google/Yahoo search partnership; international ad partners under consent; DE privacy allows third-country transfers with Chapter V safeguards when used. No public exhaustive mail-infra subprocessor list found.Self-operated infrastructure; stored mail and backups in Germany (Frankfurt, Bielefeld, Berlin DCs per privacy materials). No AWS/GCP/Azure listed for mailbox hosting. Payment top-ups may use PayPal/card networks (unlinked from accounts per Posteo).
Summary

German FreeMail from 1&1 Mail & Media GmbH (United Internet): large free storage, IMAP/POP/SMTP, optional OpenPGP and 2FA, ad-supported consumer webmail.

Independent Berlin email provider with self-operated German servers, data-minimising signup, open-standard clients, and layered optional encryption—not a free-tier ad network.

Tags
At a glance: GMX Mail vs Posteo
At a glanceLogo: GMX MailGMX MailLogo: PosteoPosteo
HQ / entity1&1 Mail & Media GmbH, Montabaur (DE)Not listed
Parent groupUnited Internet AG (DE)Not listed
Product typeConsumer FreeMail + optional paid tiersNot listed
Hosting (claimed)Mailbox/calendar data in German data centersNot listed
ProtocolsWebmail; POP3/IMAP/SMTP (opt-in)IMAP, POP3, SMTP, CalDAV, CardDAV
Open sourceNoNot listed
Self-hostedNoNot listed
HQNot listedBerlin, Germany
Legal entityNot listedPosteo e.K. (HRA 47592 B)
HostingNot listedSelf-operated servers in Germany
Commercial modelNot listedPrepaid paid service; no free tier
Self-hostNot listedNo (hosted service)
FoundedNot listed2009
EnergyNot listed100% green energy (Green Planet Energy, claimed)
Key capabilities: GMX Mail vs Posteo
Key capabilitiesLogo: GMX MailGMX MailLogo: PosteoPosteo
German operatorYesYes
Mailbox in DE (claimed)YesNot listed
IMAP / POP3 / SMTPYesNot listed
Optional OpenPGPYesNot listed
Free ad-supportedYesNot listed
SaaS onlyYesNot listed
Data-minimising signupNot listedYes
IMAP / CalDAV / CardDAVNot listedYes
BSI TR-03108 (verified)Not listedYes
Optional crypto mail storageNot listedYes
Ad-free, user-fundedNot listedYes

GMX Mail

  • Large free mailbox storage with open protocols

    gmx.com free accounts advertise up to 65 GB email storage and 50 MB attachments. POP3, IMAP, and SMTP are supported after you enable them in settings (TLS 1.2+; imap.gmx.com / mail.gmx.com). Suits users who want client choice (Thunderbird, Outlook, mobile) without Google or Microsoft as the mailbox host.

  • Optional OpenPGP end-to-end encryption (Mailvelope)

    GMX offers free OpenPGP messaging via the Mailvelope browser extension: key generation, local key storage, key directory, and mobile recovery. Encryption is opt-in per message after setup—not whole-mailbox zero-access by default. Best for occasional sensitive threads when both parties can use OpenPGP.

  • Aliases, Mail Collector, and multi-account inbox

    Create up to 10 alias addresses (including other GMX domains) managed in one inbox, and pull up to 10 external accounts via Mail Collector. Useful for freelancers and project mail without juggling multiple passwords or providers day-to-day.

  • Spam filtering, antivirus, and optional TOTP 2FA

    Free accounts include automated spam filtering (user blacklist and optional improved detection) and antivirus scanning of mail and cloud files. Optional two-factor authentication uses an authenticator app (TOTP); third-party clients use app-specific passwords when 2FA is on.

  • Bundled Cloud, calendar, contacts, and Online Office

    Accounts include contacts, calendar/organizer, about 2 GB GMX Cloud with share links, and Online Office for common document formats—enough for light personal productivity without a separate suite subscription.

Posteo

  • Signup without identity data; payments unlinked

    Accounts can be created without name, address, or phone. Posteo's payment system (bank transfer codes, cash, card, PayPal) is designed so payment identifiers are not stored against the mailbox. Practical limit: recovery options you add yourself and how you fund the prepaid balance still affect anonymity in the real world.

  • Optional crypto mail storage for the whole mailbox

    One setting encrypts stored messages—including metadata—with a key protected by the account password (RSA/AES/HMAC/bcrypt design; Dovecot plugin). Posteo states it cannot disable crypto storage once enabled and cites a Cure53 review. Limit: this is server-side encryption at rest after delivery, not sender-to-recipient E2EE, and losing the password can mean losing access to encrypted data.

  • TLS, DANE, and BSI-certified secure transport

    Access is TLS-only with PFS, HSTS, and DANE/TLSA. Optional TLS-sending/receiving guarantees refuse delivery over cleartext peer links. Posteo holds BSI TR-03108 v2 Secure Email Transport certification (BSI-K-TR-0745-2025). Transport quality still depends on the remote provider's stack.

  • CalDAV/CardDAV with optional password encryption

    Calendars and contacts sync via open standards and can be AES-encrypted in Posteo's database so the provider cannot read them when the feature is on. Trade-off: encrypted calendars cannot be shared the same way, and password reset without the old secret can lock you out of encrypted PIM data.

  • In-house migration without third-party movers

    Posteo's own migration tool pulls mail (and often contacts/calendars) over encrypted links from previous providers without routing through a third-party migration SaaS. Quota: a limited number of migrations per account, with an optional collector for ongoing fetch from the old box.

Assurance & compliance: GMX Mail vs Posteo
Assurance & complianceLogo: GMX MailGMX MailLogo: PosteoPosteo
Independent security / no-logs audit
Not found

OpenPGP/Mailvelope path described as externally reviewed; no public independent no-logs audit for FreeMail mailbox access found on product pages.

Partial

BfDI on-site privacy inspection (2016) confirmed data-minimisation / no inventory IP model (public PDF). Crypto mail storage: vendor cites Cure53 multi-level audit; full public report not located. Not a continuous independent no-logs certification programme.

ISO 27001
Not found

No GMX FreeMail-branded ISO 27001 certificate located on security/privacy pages in this research pass (group companies may hold certs under other brands).

Not found

No ISO 27001 claim found on primary Posteo security/privacy pages.

SOC 2 / SOC 3
Not found

No SOC 2/3 report found on GMX public security pages.

Not found

No SOC 2/3 report advertised on primary pages.

GDPR / EU data protection
Vendor claimed

EU/German controller; public privacy notices under GDPR; DPO published; supervisory authorities named (BfDI / LfDI RLP).

Vendor claimed

German entity; privacy policy cites GDPR/BDSG/telecom secrecy; DPO published; BfDI inspection history.

US CLOUD Act exposure (indicative)
Partial

German entity and parent (United Internet AG); mailbox data claimed in German DCs. Partial/medium because portal analytics include Google LLC tools, freemail ads involve international partners, and no full public mail-infra subprocessor list. Not legal advice.

Partial

EuropeanStack assessment: German e.K., no known US parent, self-operated DE hosting with no public US-cloud mailbox subprocessors → indicative exposure low. Status is partial (not a clean bill): payment rails and lawful German disclosure remain. Not legal advice.

Data processing agreement (B2B)
Not found

Product is primarily consumer FreeMail under GTCs/privacy policy; no public self-serve B2B DPA flow found for FreeMail shortlisting.

Not found

Vendor states it is not an Art. 28 processor as a public electronic communications service and does not offer customer DPAs.

EU AI Act
Not applicable

Not an AI-centric product; optional assistive features may appear in product privacy text but FreeMail is not marketed as an AI system.

Not applicable

Conventional email/PIM service; not an AI product.

BSI TR-03108 Secure Email TransportNot listed
Verified

BSI certificate BSI-K-TR-0745-2025 (OpenSource Security GmbH audit; valid through 2030 per BSI listing).

Considerations & known limitations: GMX Mail vs Posteo
Considerations & known limitationsLogo: GMX MailGMX MailLogo: PosteoPosteo
Advertising-funded free tier
Medium

FreeMail depends on ads and (with consent) interest-based targeting and partner sharing. Privacy posture differs from paid privacy mail. Practical impact: expect consent UX, ad surfaces, and partner lists—not a zero-ads default.

Not listed
E2E encryption is optional, not default
Medium

Without OpenPGP setup, mailbox content is accessible to the provider like conventional hosted mail. Practical impact: do not treat GMX FreeMail as zero-access encryption architecture.

Not listed
Incomplete public infrastructure subprocessors
Medium

Residency for mail is claimed (Germany/EU), but there is no enterprise-style published subprocessor inventory for core mail infrastructure. Portal paths name Google Analytics and global ad partners. Practical impact: extra questionnaire work for high-assurance buyers.

Not listed
Inactivity and freemail operational policies
Low

Terms/privacy allow deletion of free mailbox content after prolonged inactivity (about 180 days without login on FreeMail privacy text). Practical impact: inactive project addresses can disappear if not maintained.

Not listed
No public ISO/SOC package for FreeMail
Low

Security pages emphasize product features (spam, AV, 2FA, PGP) rather than downloadable ISO/SOC evidence for FreeMail. Practical impact: may fail enterprise vendor security questionnaires without further vendor dialogue.

Not listed
No custom domainsNot listed
High

Posteo will not host your own domain. Organisations needing brand continuity or provider portability via DNS must pick another host or self-host.

Encryption is layered, not default E2EENot listed
Medium

Without crypto mail storage, inbound encryption, or client-side PGP/S/MIME, Posteo can process mailbox content like a normal provider. Lawful intercept (TKU) and seizures remain possible under German process; transparency reports show content releases do occur under court order.

No customer Art. 28 DPANot listed
Medium

Procurement checklists that require a signed processor agreement will stall. Posteo argues telecom special law applies instead; validate with legal counsel for your use case.

Password loss risk with crypto featuresNot listed
Medium

Crypto mail storage and encrypted calendars/contacts depend on the account password; Posteo cannot recover plaintext if that secret is lost after encryption is enabled.

Payment processors outside pure DE mail pathNot listed
Low

Optional PayPal/card top-ups involve non-German commercial processors even though Posteo says it does not link payment identity to the mailbox. Cash/bank-code paths reduce that linkage further.

Fit

GMX Mail

Best fit when

  • Individuals and freelancers who want a European freemail address with large free storage and IMAP client freedom
  • Users consolidating multiple addresses via aliases (up to 10) and Mail Collector
  • Buyers who prefer a German legal controller (1&1 Mail & Media GmbH / United Internet) over US Big Tech freemail
  • Teams that only need optional OpenPGP for specific sensitive threads, not zero-access by default
  • Users already familiar with GMX/WEB.DE in German-speaking markets who need international domains (e.g. gmx.com)

Poor fit when

  • Organizations that require default end-to-end / zero-access encryption for all mail
  • Procurement that needs a published independent security audit pack, ISO/SOC evidence, and a B2B DPA as standard shortlist inputs
  • Teams that cannot accept advertising-funded freemail economics or interest-based ad consent UX
  • Custom-domain corporate mail and admin controls at Microsoft 365 / Google Workspace depth
  • Self-hosted or open-source mail stack requirements

Consider instead when

  • When: You need zero-access encryption by default and a privacy-first paid model without ad-funded freemail as the core product

    Consider: Proton Mail

    Proton is the stronger shortlist peer in this catalog for E2E-first evaluation.

  • When: You need Google Workspace-class collaboration and are willing to accept US Big Tech jurisdiction

    Consider: Gmail / Google Workspace

    Richer suite integration; different sovereignty and ad/ecosystem tradeoffs.

  • When: You need Microsoft ecosystem mail, calendar, and compliance tooling

    Consider: Outlook.com / Microsoft 365

    Strong enterprise admin story; US parent and CLOUD Act path differ from GMX.

Posteo

Best fit when

  • Individuals and small teams who want German jurisdiction and open-standard clients without Google or Microsoft mail
  • Users prioritising anonymous or low-identity signup and prepaid funding without linking payments to the mailbox
  • Organisations that accept posteo.* addresses and value no ads, no tracking, and published transparency reports
  • Operators who want optional full-mailbox encryption at rest (crypto mail storage) plus PGP/S/MIME tooling
  • Buyers who need BSI-aligned secure email transport certification rather than US SOC 2 paperwork

Poor fit when

  • Anyone requiring custom domains or branded organisational addresses
  • Teams that need default zero-access E2EE for every message without enabling optional layers
  • Procurement processes that mandate a signed Art. 28 DPA, SOC 2, or ISO 27001 from the vendor
  • Large enterprises needing multi-seat admin, shared domain policies, or deep Microsoft/Google workspace integration

Consider instead when

  • When: You need default end-to-end encryption and a broader encrypted suite

    Consider: Proton Mail or Tuta

    Posteo is IMAP-first with optional crypto layers; Proton/Tuta lead with zero-access defaults.

  • When: You need custom domains or richer business mail hosting

    Consider: mailbox.org or Mailfence

    Posteo deliberately refuses own domains to avoid inventory-data obligations.

  • When: You need free-tier consumer mail tightly integrated with docs and chat

    Consider: Gmail or Outlook.com

    Trade privacy posture and EU self-operation for ecosystem convenience.

Open questions for due diligence

GMX Mail

  • Will 1&1 Mail & Media sign a B2B DPA and publish a current mail-infrastructure subprocessor list for our use case?
  • Are FreeMail mailbox systems solely on United Internet / 1&1 operated German DCs, or are any US-group cloud providers used for primary storage, backup, or DR?
  • What independent audits or certifications (if any) cover the FreeMail platform beyond the Mailvelope/OpenPGP path?
  • For paid/premium mailboxes: which advertising and tracking paths remain, and what contractual residency language is available?

Posteo

  • Does your counsel accept Posteo's position that no Art. 28 DPA is required for occupational use?
  • Will posteo.de / .net / .com addresses meet your brand, deliverability, and anti-spoofing requirements without custom domains?
  • Which encryption layers (crypto mail storage, inbound PGP/S/MIME, client E2EE) will your users actually enable and support?
  • Do you need ISO 27001/SOC 2 artefacts that Posteo does not publish?
  • Is BSI TR-03108 transport certification sufficient for your sector's secure-email checklist?