Inbox.eu vs Posteo

Compare Inbox.eu and Posteo on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Gmail

Logo: Inbox.eu

Inbox.eu

Latvia· Email Services

Needs review

Shortlist Inbox.eu when you need Latvia-hosted, ad-free SME email with large included storage, custom domains, IMAP clients, and business SSO under an EU operator. Skip when you require zero-knowledge E2E crypto or published ISO/SOC audits—consider Proton Mail, Tuta, Posteo, or mailbox.org instead.

EU-operated (Latvia)100 GB mail + filesCustom domainsIMAP / SMTPSAML / LDAP SSOTLS, not ZK E2E
Logo: Posteo

Posteo

Germany· Email Services

Needs review

Shortlist when you want a paid German mailbox on self-operated servers, open protocols (IMAP/CalDAV), and extreme data minimisation (no inventory data, unlinked payments). Skip when you need custom domains, default E2EE without setup, multi-seat enterprise admin, or an Art. 28 DPA—consider Proton Mail, Tuta, mailbox.org, or Mailfence instead.

Self-operated DE serversData-minimising signupIMAP / CalDAV / CardDAVBSI TR-03108 (verified)Optional crypto mail storageAd-free, user-funded
Inbox.eu vs Posteo: Snapshot
FeatureLogo: Inbox.euInbox.euLogo: PosteoPosteo
Country of originLatviaGermany
CategoryEmail ServicesEmail Services
Open sourceNoYes
Self-hostedNoNo
HeadquartersLatviaGermany
Legal entitySIA INBOKSS (Inbokss Ltd), reg. no. 40003560720, Matrozu street 15-2, Riga, LV-1048Posteo e.K., Methfesselstr. 38, 10965 Berlin
Governing lawRepublic of Latvia / EU GDPRGerman / EU law (GDPR, BDSG, telecom secrecy / TTDSG as applicable)
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)MediumLow
Hosting / residencyMailbox/file data: vendor claims own servers in Latvia (Riga DC, EN 50600-3) with live multi-copy backups and no EU exit. Web property privacy policy lists Google Analytics, Meta Pixel, Gemius, AdBox, InMobi CMP, and hCaptcha—US/global SaaS for analytics, ads, consent, and bot defence. No public full mail-path subprocessor register found.Self-operated infrastructure; stored mail and backups in Germany (Frankfurt, Bielefeld, Berlin DCs per privacy materials). No AWS/GCP/Azure listed for mailbox hosting. Payment top-ups may use PayPal/card networks (unlinked from accounts per Posteo).
Summary

Latvia-based hosted email from SIA INBOKSS with ad-free personal and business mailboxes, custom domains, large integrated file storage, calendar/contacts, and mobile apps.

Independent Berlin email provider with self-operated German servers, data-minimising signup, open-standard clients, and layered optional encryption—not a free-tier ad network.

Tags
At a glance: Inbox.eu vs Posteo
At a glanceLogo: Inbox.euInbox.euLogo: PosteoPosteo
HQRiga, Latvia (EU)Berlin, Germany
Legal entitySIA INBOKSS (reg. 40003560720)Posteo e.K. (HRA 47592 B)
Product sinceInbokss 1998; Inbox.eu brand from 2011Not listed
HostingVendor-claimed own servers in Latvia; multi-server backupsSelf-operated servers in Germany
Open sourceNoNot listed
Self-hostNoNo (hosted service)
Commercial modelPrepaid personal/business premium; time-limited trialPrepaid paid service; no free tier
ProtocolsNot listedIMAP, POP3, SMTP, CalDAV, CardDAV
FoundedNot listed2009
EnergyNot listed100% green energy (Green Planet Energy, claimed)
Key capabilities: Inbox.eu vs Posteo
Key capabilitiesLogo: Inbox.euInbox.euLogo: PosteoPosteo
EU-operated (Latvia)YesNot listed
100 GB mail + filesYesNot listed
Custom domainsYesNot listed
IMAP / SMTPYesNot listed
SAML / LDAP SSOYesNot listed
TLS, not ZK E2EYesNot listed
Self-operated DE serversNot listedYes
Data-minimising signupNot listedYes
IMAP / CalDAV / CardDAVNot listedYes
BSI TR-03108 (verified)Not listedYes
Optional crypto mail storageNot listedYes
Ad-free, user-fundedNot listedYes

Inbox.eu

  • 100 GB mailbox plus integrated Files storage

    Premium accounts include a large combined email-and-files quota (business adds domain-level shared storage). Files supports multi-gigabyte uploads, share links, parallel downloads, and WebDAV mounting on desktop—useful for SMEs that want drive-like sharing without a separate vendor.

  • Custom domains with business admin panel

    Business email lets you host unlimited domain mailboxes after DNS/MX validation, with admin controls for users, aliases, catch-all, and domain settings. A public demo of the admin experience is available for evaluation before signup.

  • Standard protocols plus mobile apps

    Full IMAP, POP3, and SMTP (with TLS) for Thunderbird, Outlook, and other clients; calendar and contacts sync; official apps on iOS and Android. Fits teams that refuse webmail lock-in.

  • TLS, 2FA, spam filtering, and business SSO

    Transport encryption with TLS 1.2+, optional two-factor authentication, multi-filter spam/malware scanning, and Business SSO via SAML 2.0 or LDAP (including common IdPs such as Azure AD and Google Workspace). This is hosted-email security, not zero-knowledge E2E.

  • Migration support and human multilingual help

    Documented IMAP/CSV migration paths from Gmail and other providers, plus real-person support in English and Baltic languages rather than chatbot-only queues—material for SMEs without a dedicated mail ops team.

Posteo

  • Signup without identity data; payments unlinked

    Accounts can be created without name, address, or phone. Posteo's payment system (bank transfer codes, cash, card, PayPal) is designed so payment identifiers are not stored against the mailbox. Practical limit: recovery options you add yourself and how you fund the prepaid balance still affect anonymity in the real world.

  • Optional crypto mail storage for the whole mailbox

    One setting encrypts stored messages—including metadata—with a key protected by the account password (RSA/AES/HMAC/bcrypt design; Dovecot plugin). Posteo states it cannot disable crypto storage once enabled and cites a Cure53 review. Limit: this is server-side encryption at rest after delivery, not sender-to-recipient E2EE, and losing the password can mean losing access to encrypted data.

  • TLS, DANE, and BSI-certified secure transport

    Access is TLS-only with PFS, HSTS, and DANE/TLSA. Optional TLS-sending/receiving guarantees refuse delivery over cleartext peer links. Posteo holds BSI TR-03108 v2 Secure Email Transport certification (BSI-K-TR-0745-2025). Transport quality still depends on the remote provider's stack.

  • CalDAV/CardDAV with optional password encryption

    Calendars and contacts sync via open standards and can be AES-encrypted in Posteo's database so the provider cannot read them when the feature is on. Trade-off: encrypted calendars cannot be shared the same way, and password reset without the old secret can lock you out of encrypted PIM data.

  • In-house migration without third-party movers

    Posteo's own migration tool pulls mail (and often contacts/calendars) over encrypted links from previous providers without routing through a third-party migration SaaS. Quota: a limited number of migrations per account, with an optional collector for ongoing fetch from the old box.

Assurance & compliance: Inbox.eu vs Posteo
Assurance & complianceLogo: Inbox.euInbox.euLogo: PosteoPosteo
Independent security / no-logs audit
Not found

No public third-party audit PDF or no-logs attestation located on security/help pages.

Partial

BfDI on-site privacy inspection (2016) confirmed data-minimisation / no inventory IP model (public PDF). Crypto mail storage: vendor cites Cure53 multi-level audit; full public report not located. Not a continuous independent no-logs certification programme.

ISO 27001
Not found

No ISO 27001 certificate or registry entry found on official site.

Not found

No ISO 27001 claim found on primary Posteo security/privacy pages.

SOC 2 / SOC 3
Not found

No SOC 2/3 report referenced on official site.

Not found

No SOC 2/3 report advertised on primary pages.

GDPR / EU data protection
Vendor claimed

EU (Latvia) controller SIA INBOKSS; vendor states 100% GDPR compliance and Latvia hosting. Confirm DPA and subprocessors for your workload.

Vendor claimed

German entity; privacy policy cites GDPR/BDSG/telecom secrecy; DPO published; BfDI inspection history.

US CLOUD Act exposure (indicative)
Partial

EU entity / no known US parent; mail claimed on own Latvia servers. Residual medium exposure via US-group web SaaS in privacy policy (Google Analytics, Meta Pixel, hCaptcha, InMobi). Not legal advice.

Partial

EuropeanStack assessment: German e.K., no known US parent, self-operated DE hosting with no public US-cloud mailbox subprocessors → indicative exposure low. Status is partial (not a clean bill): payment rails and lawful German disclosure remain. Not legal advice.

Data processing agreement (B2B)
Not found

TOS mentions controller/processor roles under GDPR, but no standalone public DPA download found—request in writing.

Not found

Vendor states it is not an Art. 28 processor as a public electronic communications service and does not offer customer DPAs.

EU AI Act
Not applicable

Conventional email hosting; not an AI-system product.

Not applicable

Conventional email/PIM service; not an AI product.

BSI TR-03108 Secure Email TransportNot listed
Verified

BSI certificate BSI-K-TR-0745-2025 (OpenSource Security GmbH audit; valid through 2030 per BSI listing).

Considerations & known limitations: Inbox.eu vs Posteo
Considerations & known limitationsLogo: Inbox.euInbox.euLogo: PosteoPosteo
No public ISO/SOC or independent audit
Medium

Enterprise RFPs that require cert packs will stall until the vendor supplies private assurance materials.

Not listed
Not zero-knowledge E2E mail
Medium

Operator-controlled storage with TLS in transit; legal-process access is acknowledged. Do not shortlist as a Proton/Tuta crypto peer.

Not listed
US-group tools on website privacy path
Medium

Google Analytics, Meta Pixel, hCaptcha, and InMobi appear in the privacy policy even while mail is marketed as Latvia-only—align transfer assessments and cookies consent with this split.

Not listed
Public DPA / subprocessor list gap
Medium

Processor language exists in TOS, but buyers still need a signed DPA and current subprocessors for regulated personal data.

Not listed
Operator also runs ad-supported portals
Low

Inbokss group products include advertising-supported regional portals; verify contractually that paid Inbox.eu mailboxes stay ad-free and outside portal ad profiling.

Not listed
No custom domainsNot listed
High

Posteo will not host your own domain. Organisations needing brand continuity or provider portability via DNS must pick another host or self-host.

Encryption is layered, not default E2EENot listed
Medium

Without crypto mail storage, inbound encryption, or client-side PGP/S/MIME, Posteo can process mailbox content like a normal provider. Lawful intercept (TKU) and seizures remain possible under German process; transparency reports show content releases do occur under court order.

No customer Art. 28 DPANot listed
Medium

Procurement checklists that require a signed processor agreement will stall. Posteo argues telecom special law applies instead; validate with legal counsel for your use case.

Password loss risk with crypto featuresNot listed
Medium

Crypto mail storage and encrypted calendars/contacts depend on the account password; Posteo cannot recover plaintext if that secret is lost after encryption is enabled.

Payment processors outside pure DE mail pathNot listed
Low

Optional PayPal/card top-ups involve non-German commercial processors even though Posteo says it does not link payment identity to the mailbox. Cash/bank-code paths reduce that linkage further.

Fit

Inbox.eu

Best fit when

  • SMEs wanting branded domain email without Google Workspace or Microsoft 365 suite lock-in
  • Teams that standardise on Thunderbird, Outlook, or other IMAP/SMTP clients
  • Buyers prioritising large included mailbox and file quotas plus WebDAV sharing
  • Organisations that need business SSO (SAML 2.0 or LDAP) without a separate SSO SKU
  • Users seeking an ad-free paid European mailbox with human support in English and Baltic languages

Poor fit when

  • RFPs that require published ISO 27001, SOC 2, or independent security/no-logs audit reports
  • Threat models that assume the provider cannot access plaintext mail (zero-knowledge E2E)
  • Buyers needing a downloadable public DPA and full mail-path subprocessor register before any sales contact
  • Teams that need a full office suite (docs, sheets, meetings) rather than email-plus-files

Consider instead when

  • When: You need open or heavily audited zero-knowledge end-to-end encrypted mail

    Consider: Proton Mail or Tuta

    Different crypto posture than TLS-hosted conventional mail

  • When: You prefer German jurisdiction and a long-standing privacy-host reputation

    Consider: Posteo or mailbox.org

    Often leaner storage; strong EU privacy positioning

  • When: You already depend on Docs/Drive/Meet or full Microsoft 365 collaboration

    Consider: Google Workspace or Microsoft 365

    Inbox.eu is not a suite replacement

  • When: You want Belgian dual-key / open-source-oriented secure mail

    Consider: Mailfence

    Different feature and crypto tradeoffs

Posteo

Best fit when

  • Individuals and small teams who want German jurisdiction and open-standard clients without Google or Microsoft mail
  • Users prioritising anonymous or low-identity signup and prepaid funding without linking payments to the mailbox
  • Organisations that accept posteo.* addresses and value no ads, no tracking, and published transparency reports
  • Operators who want optional full-mailbox encryption at rest (crypto mail storage) plus PGP/S/MIME tooling
  • Buyers who need BSI-aligned secure email transport certification rather than US SOC 2 paperwork

Poor fit when

  • Anyone requiring custom domains or branded organisational addresses
  • Teams that need default zero-access E2EE for every message without enabling optional layers
  • Procurement processes that mandate a signed Art. 28 DPA, SOC 2, or ISO 27001 from the vendor
  • Large enterprises needing multi-seat admin, shared domain policies, or deep Microsoft/Google workspace integration

Consider instead when

  • When: You need default end-to-end encryption and a broader encrypted suite

    Consider: Proton Mail or Tuta

    Posteo is IMAP-first with optional crypto layers; Proton/Tuta lead with zero-access defaults.

  • When: You need custom domains or richer business mail hosting

    Consider: mailbox.org or Mailfence

    Posteo deliberately refuses own domains to avoid inventory-data obligations.

  • When: You need free-tier consumer mail tightly integrated with docs and chat

    Consider: Gmail or Outlook.com

    Trade privacy posture and EU self-operation for ecosystem convenience.

Open questions for due diligence

Inbox.eu

  • Will SIA INBOKSS sign your organisation's DPA and provide a current subprocessor list limited to production mail/file paths?
  • Are there private ISO, SOC, or penetration-test reports available under NDA?
  • Which backup media/locations and any non-EU operational tooling (support remote access, payments) process personal data?
  • Does business SSO support your exact IdP configuration (SAML attributes / LDAP schema) without custom engineering fees?

Posteo

  • Does your counsel accept Posteo's position that no Art. 28 DPA is required for occupational use?
  • Will posteo.de / .net / .com addresses meet your brand, deliverability, and anti-spoofing requirements without custom domains?
  • Which encryption layers (crypto mail storage, inbound PGP/S/MIME, client E2EE) will your users actually enable and support?
  • Do you need ISO 27001/SOC 2 artefacts that Posteo does not publish?
  • Is BSI TR-03108 transport certification sufficient for your sector's secure-email checklist?