Inbox.eu vs Mailfence

Compare Inbox.eu and Mailfence on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Gmail, Microsoft 365

Logo: Inbox.eu

Inbox.eu

Latvia· Email Services

Needs review

Shortlist Inbox.eu when you need Latvia-hosted, ad-free SME email with large included storage, custom domains, IMAP clients, and business SSO under an EU operator. Skip when you require zero-knowledge E2E crypto or published ISO/SOC audits—consider Proton Mail, Tuta, Posteo, or mailbox.org instead.

EU-operated (Latvia)100 GB mail + filesCustom domainsIMAP / SMTPSAML / LDAP SSOTLS, not ZK E2E
Logo: Mailfence

Mailfence

Belgium· Email Services

Needs review

Shortlist Mailfence when you want Belgian-operated webmail with interoperable OpenPGP, digital signatures, and a light calendar/documents suite—plus optional business private-label or on-prem license. Skip when you need automatic closed E2EE without key management (consider Tuta), a large Swiss privacy ecosystem (Proton Mail), or a minimalist German mailbox (Posteo / mailbox.org).

EU-operated (Belgium)OpenPGP E2EEDigital signaturesMail + calendar + docsCustom domains (paid)B2B DPA available
Inbox.eu vs Mailfence: Snapshot
FeatureLogo: Inbox.euInbox.euLogo: MailfenceMailfence
Country of originLatviaBelgium
CategoryEmail ServicesEmail Services
Open sourceNoNo
Self-hostedNoNo
HeadquartersLatviaBelgium
Legal entitySIA INBOKSS (Inbokss Ltd), reg. no. 40003560720, Matrozu street 15-2, Riga, LV-1048ContactOffice Group sa, Avenue Franklin Roosevelt 47b, B-1050 Brussels (BE 0466.241.584)
Governing lawRepublic of Latvia / EU GDPRBelgian law; Brussels courts (Terms of Use)
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)MediumLow
Hosting / residencyMailbox/file data: vendor claims own servers in Latvia (Riga DC, EN 50600-3) with live multi-copy backups and no EU exit. Web property privacy policy lists Google Analytics, Meta Pixel, Gemius, AdBox, InMobi CMP, and hCaptcha—US/global SaaS for analytics, ads, consent, and bot defence. No public full mail-path subprocessor register found.Primary production servers described as located in Belgium under Mailfence operational control (no intermediary managing servers per security page). No public AWS/GCP/Azure subprocessor list found. Backups stored in locations separate from offices/main DC (providers not named). Payment-card processing path not fully published.
Summary

Latvia-based hosted email from SIA INBOKSS with ad-free personal and business mailboxes, custom domains, large integrated file storage, calendar/contacts, and mobile apps.

Belgian secure email suite with browser-side OpenPGP encryption, digital signatures, calendar, documents, and optional custom domains under ContactOffice Group SA.

Tags
At a glance: Inbox.eu vs Mailfence
At a glanceLogo: Inbox.euInbox.euLogo: MailfenceMailfence
HQRiga, Latvia (EU)Not listed
Legal entitySIA INBOKSS (reg. 40003560720)Not listed
Product sinceInbokss 1998; Inbox.eu brand from 2011Not listed
HostingVendor-claimed own servers in Latvia; multi-server backupsVendor-operated servers in Belgium (per security page)
Open sourceNoNo (front-end OSS planned; not current)
Self-hostNoSaaS default; Business license for large on-prem deployments
Commercial modelPrepaid personal/business premium; time-limited trialFree tier + prepaid paid plans; Business packaging (see vendor site)
HQ / entityNot listedBrussels — ContactOffice Group sa (BE 0466.241.584)
Product launchNot listedMailfence brand ~2013; ContactOffice lineage since 1999
CryptoNot listedOpenPGP E2EE + digital signatures; optional password-encrypted messages
Independent auditNot listedNo public audit PDF found
Key capabilities: Inbox.eu vs Mailfence
Key capabilitiesLogo: Inbox.euInbox.euLogo: MailfenceMailfence
EU-operated (Latvia)YesYes
100 GB mail + filesYesNot listed
Custom domainsYesNot listed
IMAP / SMTPYesNot listed
SAML / LDAP SSOYesNot listed
TLS, not ZK E2EYesNot listed
OpenPGP E2EENot listedYes
Digital signaturesNot listedYes
Mail + calendar + docsNot listedYes
Custom domains (paid)Not listedYes
B2B DPA availableNot listedYes

Inbox.eu

  • 100 GB mailbox plus integrated Files storage

    Premium accounts include a large combined email-and-files quota (business adds domain-level shared storage). Files supports multi-gigabyte uploads, share links, parallel downloads, and WebDAV mounting on desktop—useful for SMEs that want drive-like sharing without a separate vendor.

  • Custom domains with business admin panel

    Business email lets you host unlimited domain mailboxes after DNS/MX validation, with admin controls for users, aliases, catch-all, and domain settings. A public demo of the admin experience is available for evaluation before signup.

  • Standard protocols plus mobile apps

    Full IMAP, POP3, and SMTP (with TLS) for Thunderbird, Outlook, and other clients; calendar and contacts sync; official apps on iOS and Android. Fits teams that refuse webmail lock-in.

  • TLS, 2FA, spam filtering, and business SSO

    Transport encryption with TLS 1.2+, optional two-factor authentication, multi-filter spam/malware scanning, and Business SSO via SAML 2.0 or LDAP (including common IdPs such as Azure AD and Google Workspace). This is hosted-email security, not zero-knowledge E2E.

  • Migration support and human multilingual help

    Documented IMAP/CSV migration paths from Gmail and other providers, plus real-person support in English and Baltic languages rather than chatbot-only queues—material for SMEs without a dedicated mail ops team.

Mailfence

  • Browser-side OpenPGP end-to-end encryption

    Encrypt outbound mail in the browser with the OpenPGP standard so intermediaries—including Mailfence when messages are properly E2EE—cannot read ciphertext. Fully interoperable with other OpenPGP tools (e.g. Thunderbird/GnuPG). Optional password-encrypted messages cover recipients who do not use PGP. Unencrypted mail still sits on servers in the normal webmail model.

  • Digital signatures and multi-key OpenPGP keystore

    Sign messages for authenticity and integrity, and manage keys in-product: generate, import, export, publish, and hold multiple key pairs without browser plug-ins. Default generated keys are 4096-bit per the threat-model page. Passphrase protection of private keys limits crypto operations if only the account password is compromised.

  • Mail, calendar, documents, and groups in one account

    Beyond inbox: shareable calendars, online document storage/editing, and contact groups for collaboration without bolting on a separate US suite. Storage and alias limits scale by plan; free accounts remain suitable only for light personal use.

  • Custom domains, aliases, and mail protocols on paid tiers

    Higher plans add custom domains with SPF/DKIM/DMARC-oriented setup, larger alias counts, and classic client access (POP, IMAP, SMTP) plus ActiveSync where listed. Entry-level free accounts focus on web/PWA/apps rather than full protocol parity—verify the live plan matrix before procurement.

  • Business admin: API, SSO, private label, optional on-prem license

    Mailfence for Business offers control-panel and XML-RPC API user provisioning, SSO and directory hooks (LDAP/AD/CAS), branding, and Belgian cloud hosting with SLA language—or a license to run on customer Linux servers for large deployments. Fit for orgs that need Belgian hosting with admin automation, not a consumer-only mailbox.

Assurance & compliance: Inbox.eu vs Mailfence
Assurance & complianceLogo: Inbox.euInbox.euLogo: MailfenceMailfence
Independent security / no-logs audit
Not found

No public third-party audit PDF or no-logs attestation located on security/help pages.

Not found

No public third-party audit PDF found. Vendor mentions security specialists, bug bounty activity, and inspection openness—not a substitute for a published audit. Privacy policy documents operational metadata collection (not zero-logs).

ISO 27001
Not found

No ISO 27001 certificate or registry entry found on official site.

Not found

No Mailfence ISO 27001 certificate claim found on primary security/GDPR/company pages.

SOC 2 / SOC 3
Not found

No SOC 2/3 report referenced on official site.

Not found
GDPR / EU data protection
Vendor claimed

EU (Latvia) controller SIA INBOKSS; vendor states 100% GDPR compliance and Latvia hosting. Confirm DPA and subprocessors for your workload.

Vendor claimed

Belgian controller/processor materials; dedicated GDPR page and technical/organisational measures overview. Confirm roles in your DPA.

US CLOUD Act exposure (indicative)
Partial

EU entity / no known US parent; mail claimed on own Latvia servers. Residual medium exposure via US-group web SaaS in privacy policy (Google Analytics, Meta Pixel, hCaptcha, InMobi). Not legal advice.

Partial

EU entity (ContactOffice Group sa), no known US parent; servers claimed self-operated in Belgium without named US hyperscaler hosts. No formal public subprocessor inventory; payment processors not named. Assessment residual: partial transparency on data path. Not legal advice.

Data processing agreement (B2B)
Not found

TOS mentions controller/processor roles under GDPR, but no standalone public DPA download found—request in writing.

Vendor claimed

Downloadable DPA linked from the GDPR page for organisational customers.

EU AI Act
Not applicable

Conventional email hosting; not an AI-system product.

Not applicable

Email/collaboration suite; not an AI system under typical procurement framing.

Considerations & known limitations: Inbox.eu vs Mailfence
Considerations & known limitationsLogo: Inbox.euInbox.euLogo: MailfenceMailfence
No public ISO/SOC or independent audit
Medium

Enterprise RFPs that require cert packs will stall until the vendor supplies private assurance materials.

Not listed
Not zero-knowledge E2E mail
Medium

Operator-controlled storage with TLS in transit; legal-process access is acknowledged. Do not shortlist as a Proton/Tuta crypto peer.

Not listed
US-group tools on website privacy path
Medium

Google Analytics, Meta Pixel, hCaptcha, and InMobi appear in the privacy policy even while mail is marketed as Latvia-only—align transfer assessments and cookies consent with this split.

Not listed
Public DPA / subprocessor list gap
Medium

Processor language exists in TOS, but buyers still need a signed DPA and current subprocessors for regulated personal data.

Not listed
Operator also runs ad-supported portals
Low

Inbokss group products include advertising-supported regional portals; verify contractually that paid Inbox.eu mailboxes stay ad-free and outside portal ad profiling.

Not listed
No public independent security auditNot listed
Medium

If vendor risk requires a published audit letter, ISO 27001, or SOC 2, treat Mailfence as incomplete until evidence is obtained offline or under NDA.

Closed-source SaaSNot listed
Medium

Cannot independently review server code or default-self-host like some FOSS mail stacks. Business on-prem license is a commercial path, not community self-host docs.

E2EE is opt-in OpenPGP, not automaticNot listed
Medium

Clear-text messages are operator-readable at rest. Users must encrypt/sign deliberately; training and policy matter for regulated content.

Operational metadata retentionNot listed
Low

Privacy policy lists IP, message-IDs, addresses, subjects, and related fields for operations, abuse control, and legal process—not a zero-logs design.

Limited public subprocessor inventoryNot listed
Low

Strong first-party claims of internal hosting, but no AWS-style public subprocessor table; confirm payment and support tooling in procurement.

US CLOUD Act (indicative)Not listed
Low

No known US parent; Belgian self-operated hosting narrative. Residual unknown payment/SaaS paths. Not a legal safe harbour guarantee.

Fit

Inbox.eu

Best fit when

  • SMEs wanting branded domain email without Google Workspace or Microsoft 365 suite lock-in
  • Teams that standardise on Thunderbird, Outlook, or other IMAP/SMTP clients
  • Buyers prioritising large included mailbox and file quotas plus WebDAV sharing
  • Organisations that need business SSO (SAML 2.0 or LDAP) without a separate SSO SKU
  • Users seeking an ad-free paid European mailbox with human support in English and Baltic languages

Poor fit when

  • RFPs that require published ISO 27001, SOC 2, or independent security/no-logs audit reports
  • Threat models that assume the provider cannot access plaintext mail (zero-knowledge E2E)
  • Buyers needing a downloadable public DPA and full mail-path subprocessor register before any sales contact
  • Teams that need a full office suite (docs, sheets, meetings) rather than email-plus-files

Consider instead when

  • When: You need open or heavily audited zero-knowledge end-to-end encrypted mail

    Consider: Proton Mail or Tuta

    Different crypto posture than TLS-hosted conventional mail

  • When: You prefer German jurisdiction and a long-standing privacy-host reputation

    Consider: Posteo or mailbox.org

    Often leaner storage; strong EU privacy positioning

  • When: You already depend on Docs/Drive/Meet or full Microsoft 365 collaboration

    Consider: Google Workspace or Microsoft 365

    Inbox.eu is not a suite replacement

  • When: You want Belgian dual-key / open-source-oriented secure mail

    Consider: Mailfence

    Different feature and crypto tradeoffs

Mailfence

Best fit when

  • You need OpenPGP interoperability and digital signatures from a European webmail, not only proprietary E2EE
  • Belgian legal entity and self-described self-operated Belgian hosting are procurement requirements
  • Teams want mail plus calendar/documents/groups without moving to Microsoft 365 or Google Workspace
  • You need custom domains, aliases, and classic clients (IMAP/POP/ActiveSync) on paid tiers
  • Business buyers evaluating private-label, API provisioning, SSO/directory integration, or large-scale on-prem license

Poor fit when

  • Security policy requires a published independent security audit, ISO 27001, or SOC 2 from the email vendor
  • You want fully open-source server/client stacks you can fork and self-host as default
  • Every message must be automatically E2EE with no OpenPGP key UX (Tuta-style)
  • You need Microsoft-class DLP, eDiscovery, compliance archives, and deep SaaS integrations
  • Zero-logs marketing is a hard requirement (Mailfence documents operational metadata collection)

Consider instead when

  • When: You want automatic encryption for all messages with minimal key management

    Consider: Tuta

    Different crypto model; less OpenPGP interop emphasis than Mailfence.

  • When: You want a larger Swiss privacy suite brand and ecosystem apps

    Consider: Proton Mail

    Trade Belgian ContactOffice ownership and PGP-centric UX for Proton’s broader product family.

  • When: You want a lean German ad-free mailbox without suite features

    Consider: Posteo or mailbox.org

    Simpler mailbox posture; different admin/domain/crypto tradeoffs.

  • When: You need full Google/Microsoft productivity and compliance tooling

    Consider: Microsoft 365 or Google Workspace (accept US-cloud risk) or EU office suites if residency is the driver

    Mailfence is not a drop-in M365 replacement.

Open questions for due diligence

Inbox.eu

  • Will SIA INBOKSS sign your organisation's DPA and provide a current subprocessor list limited to production mail/file paths?
  • Are there private ISO, SOC, or penetration-test reports available under NDA?
  • Which backup media/locations and any non-EU operational tooling (support remote access, payments) process personal data?
  • Does business SSO support your exact IdP configuration (SAML attributes / LDAP schema) without custom engineering fees?

Mailfence

  • Will Mailfence provide a current written subprocessor list (including payment processors and any backup locations) for a company account?
  • Is any independent security assessment available under NDA for regulated buyers?
  • For Business on-prem license: exact minimum scale, support model, update cadence, and cryptographic feature parity vs SaaS?
  • Which plan tiers currently include IMAP/POP/ActiveSync and custom-domain limits for our user count?
  • How are disaster-recovery backup sites jurisdictions documented in the signed DPA annex?