mailbox (formerly mailbox.org) vs Mailfence

Compare mailbox (formerly mailbox.org) and Mailfence on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Gmail, Microsoft 365

Logo: mailbox (formerly mailbox.org)

mailbox (formerly mailbox.org)

Germany· Office Productivity Suite

Needs review

Shortlist mailbox when you need a German-operated email-plus-collaboration suite (Mail, Drive, Office, Meet, Admin/API) on dual Berlin sites with published BSI C5 Type 1 and ISO 27001 claims. Skip when you require free forever mail or default zero-knowledge for all messages—consider Proton Mail or Tuta instead.

German-operatedBerlin dual-site hostingPGP + S/MIMEBSI C5 Type 1 (claimed)ISO 27001 (claimed)Mail + Drive + Meet + Office
Logo: Mailfence

Mailfence

Belgium· Email Services

Needs review

Shortlist Mailfence when you want Belgian-operated webmail with interoperable OpenPGP, digital signatures, and a light calendar/documents suite—plus optional business private-label or on-prem license. Skip when you need automatic closed E2EE without key management (consider Tuta), a large Swiss privacy ecosystem (Proton Mail), or a minimalist German mailbox (Posteo / mailbox.org).

EU-operated (Belgium)OpenPGP E2EEDigital signaturesMail + calendar + docsCustom domains (paid)B2B DPA available
mailbox (formerly mailbox.org) vs Mailfence: Snapshot
FeatureLogo: mailbox (formerly mailbox.org)mailbox (formerly mailbox.org)Logo: MailfenceMailfence
Country of originGermanyBelgium
CategoryOffice Productivity SuiteEmail Services
Open sourceNoNo
Self-hostedNoNo
HeadquartersGermanyBelgium
Legal entityHeinlein Hosting GmbH (Berlin; CEO Peer Heinlein)ContactOffice Group sa, Avenue Franklin Roosevelt 47b, B-1050 Brussels (BE 0466.241.584)
Governing lawNot listedBelgian law; Brussels courts (Terms of Use)
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)LowLow
Hosting / residencyCore mailbox, Drive, and Meet on Heinlein-operated servers in German data centres in Berlin (two independent locations). Website analytics: self-hosted Matomo. Marketing site may embed Vimeo/YouTube. No public AWS/GCP/Azure product hosting region found for customer mail data.Primary production servers described as located in Belgium under Mailfence operational control (no intermediary managing servers per security page). No public AWS/GCP/Azure subprocessor list found. Backups stored in locations separate from offices/main DC (providers not named). Payment-card processing path not fully published.
Summary

German paid digital workplace from Heinlein Hosting GmbH: secure email with PGP/S/MIME, Drive, browser Office, Meet, and business Admin on dual Berlin data centres.

Belgian secure email suite with browser-side OpenPGP encryption, digital signatures, calendar, documents, and optional custom domains under ContactOffice Group SA.

Tags
At a glance: mailbox (formerly mailbox.org) vs Mailfence
At a glanceLogo: mailbox (formerly mailbox.org)mailbox (formerly mailbox.org)Logo: MailfenceMailfence
HQBerlin, GermanyNot listed
Legal entityHeinlein Hosting GmbHNot listed
HostingOwn servers, dual independent Berlin sitesVendor-operated servers in Belgium (per security page)
ModelPaid subscription SaaS; trial available; no permanent free tierNot listed
Self-hostNo (managed SaaS)SaaS default; Business license for large on-prem deployments
Open standardsIMAP/SMTP, CalDAV/CardDAV, WebDAV, PGP, S/MIMENot listed
HQ / entityNot listedBrussels — ContactOffice Group sa (BE 0466.241.584)
Product launchNot listedMailfence brand ~2013; ContactOffice lineage since 1999
CryptoNot listedOpenPGP E2EE + digital signatures; optional password-encrypted messages
Open sourceNot listedNo (front-end OSS planned; not current)
Commercial modelNot listedFree tier + prepaid paid plans; Business packaging (see vendor site)
Independent auditNot listedNo public audit PDF found
Key capabilities: mailbox (formerly mailbox.org) vs Mailfence
Key capabilitiesLogo: mailbox (formerly mailbox.org)mailbox (formerly mailbox.org)Logo: MailfenceMailfence
German-operatedYesYes
Berlin dual-site hostingYesNot listed
PGP + S/MIMEYesNot listed
BSI C5 Type 1 (claimed)YesNot listed
ISO 27001 (claimed)YesNot listed
Mail + Drive + Meet + OfficeYesNot listed
OpenPGP E2EENot listedYes
Digital signaturesNot listedYes
Mail + calendar + docsNot listedYes
Custom domains (paid)Not listedYes
B2B DPA availableNot listedYes

mailbox (formerly mailbox.org)

  • PGP Guard, S/MIME, and hardened mail transport

    Webmail Guard for PGP without extra software (or Mailvelope with local keys), S/MIME for sign/encrypt, 2FA and app passwords, multi-stage spam/virus rejection, plus public transport controls (DNSSEC, DANE, MTA-STS, DMARC/DKIM/SPF, TLS checker, @secure.mailbox.org aliases). Benefits security-minded teams that still need interoperable IMAP/SMTP; content is not zero-knowledge by default unless you encrypt.

  • Drive on dual independent Berlin sites

    Cloud files on the provider's own German infrastructure with two independent Berlin locations, WebDAV, mobile apps, guest share links, expandable quota, and optional client-side OpenPGP encryption of stored files. Fits teams replacing consumer cloud drives while keeping residency claims concrete; confirm plan quotas on the official site.

  • Browser Office with CalDAV and CardDAV

    Edit common office formats in the browser, share calendars and contacts via open CalDAV/CardDAV standards, plus tasks, notes, polls, and TLS-secured XMPP chat. Aimed at SMEs and schools that want collaboration without a full Microsoft desktop stack; advanced Excel macros and deep Office add-ins are not the target.

  • Meet video hosted in German data centres

    Browser-based conferencing integrated with calendar and mail: link invites for external guests, breakout rooms, screen share, chat, surveys, and moderator controls. Privacy documentation references the OpenTalk stack; sessions run through mailbox's German data centres. Evaluate E2EE defaults and recording policies against your meeting compliance needs.

  • Business Admin console and automation API

    Central management of domains, mailboxes, quotas, spam/virus settings, IP allowlists, and backups, with an HTTP API for larger orgs and resellers (api.mailbox.org). Supports onboarding help and partner-assisted migration. Better for multi-seat German operations than pure consumer inboxes; not a full IdP replacement without SSO design work.

Mailfence

  • Browser-side OpenPGP end-to-end encryption

    Encrypt outbound mail in the browser with the OpenPGP standard so intermediaries—including Mailfence when messages are properly E2EE—cannot read ciphertext. Fully interoperable with other OpenPGP tools (e.g. Thunderbird/GnuPG). Optional password-encrypted messages cover recipients who do not use PGP. Unencrypted mail still sits on servers in the normal webmail model.

  • Digital signatures and multi-key OpenPGP keystore

    Sign messages for authenticity and integrity, and manage keys in-product: generate, import, export, publish, and hold multiple key pairs without browser plug-ins. Default generated keys are 4096-bit per the threat-model page. Passphrase protection of private keys limits crypto operations if only the account password is compromised.

  • Mail, calendar, documents, and groups in one account

    Beyond inbox: shareable calendars, online document storage/editing, and contact groups for collaboration without bolting on a separate US suite. Storage and alias limits scale by plan; free accounts remain suitable only for light personal use.

  • Custom domains, aliases, and mail protocols on paid tiers

    Higher plans add custom domains with SPF/DKIM/DMARC-oriented setup, larger alias counts, and classic client access (POP, IMAP, SMTP) plus ActiveSync where listed. Entry-level free accounts focus on web/PWA/apps rather than full protocol parity—verify the live plan matrix before procurement.

  • Business admin: API, SSO, private label, optional on-prem license

    Mailfence for Business offers control-panel and XML-RPC API user provisioning, SSO and directory hooks (LDAP/AD/CAS), branding, and Belgian cloud hosting with SLA language—or a license to run on customer Linux servers for large deployments. Fit for orgs that need Belgian hosting with admin automation, not a consumer-only mailbox.

Assurance & compliance: mailbox (formerly mailbox.org) vs Mailfence
Assurance & complianceLogo: mailbox (formerly mailbox.org)mailbox (formerly mailbox.org)Logo: MailfenceMailfence
Independent security / no-logs audit
Not found

No public independent no-logs audit PDF found; operational transparency reports and BSI/ISO artefacts instead

Not found

No public third-party audit PDF found. Vendor mentions security specialists, bug bounty activity, and inspection openness—not a substitute for a published audit. Privacy policy documents operational metadata collection (not zero-logs).

ISO 27001
Vendor claimed

Vendor states ISO/IEC 27001:2022 on certified-quality and press pages; request current certificate in diligence

Not found

No Mailfence ISO 27001 certificate claim found on primary security/GDPR/company pages.

SOC 2 / SOC 3
Not found

No SOC 2/3 claim found on primary security/cert pages

Not found
BSI C5
Vendor claimed

Vendor press (7 Jan 2026): BSI C5 Type 1 attestation for mailbox; confirm type, scope, and period

Not listed
GDPR / EU data protection
Vendor claimed

German controller Heinlein Hosting GmbH; DE hosting; detailed privacy notice; DPO privacy@mailbox.org

Vendor claimed

Belgian controller/processor materials; dedicated GDPR page and technical/organisational measures overview. Confirm roles in your DPA.

US CLOUD Act exposure (indicative)
Partial

EU/German entity, no known US parent, self-operated Berlin hosting for core data—no AWS/GCP/Azure product region found. Residual: marketing embeds (Vimeo/YouTube) and possible external payment services. Indicative assessment only, not legal advice.

Partial

EU entity (ContactOffice Group sa), no known US parent; servers claimed self-operated in Belgium without named US hyperscaler hosts. No formal public subprocessor inventory; payment processors not named. Assessment residual: partial transparency on data path. Not legal advice.

Data processing agreement (B2B)
Vendor claimed

Business knowledge base: customers can conclude a DPA online; historic AVV portal for business accounts

Vendor claimed

Downloadable DPA linked from the GDPR page for organisational customers.

EU AI Act
Not applicable

Email/collaboration suite, not an AI product core

Not applicable

Email/collaboration suite; not an AI system under typical procurement framing.

Considerations & known limitations: mailbox (formerly mailbox.org) vs Mailfence
Considerations & known limitationsLogo: mailbox (formerly mailbox.org)mailbox (formerly mailbox.org)Logo: MailfenceMailfence
Mail is not zero-knowledge by default
Medium

Without PGP/S/MIME, stored message content remains operator-accessible under legal process. Practical impact: train users or mandate Guard/S/MIME for confidential traffic.

Not listed
C5 Type 1 is point-in-time
Low

Type 1 attestations describe design/implementation at a point in time. Re-check type (1 vs 2), scope, and renewal dates for public-sector RFPs.

Not listed
Payment and edge processors need confirmation
Low

Core hosting is self-operated DE, but privacy text references external payment services; marketing embeds US video hosts. Ask for the current processor list with the DPA.

Not listed
Not a full Microsoft 365 ecosystem substitute
Medium

Browser Office and Meet cover common collaboration; deep desktop macros, Graph automations, and third-party M365 marketplaces will not map 1:1.

Not listed
No customer self-host option
Low

Organisations that must operate mail on their own iron need another stack; mailbox is multi-tenant SaaS.

Not listed
No public independent security auditNot listed
Medium

If vendor risk requires a published audit letter, ISO 27001, or SOC 2, treat Mailfence as incomplete until evidence is obtained offline or under NDA.

Closed-source SaaSNot listed
Medium

Cannot independently review server code or default-self-host like some FOSS mail stacks. Business on-prem license is a commercial path, not community self-host docs.

E2EE is opt-in OpenPGP, not automaticNot listed
Medium

Clear-text messages are operator-readable at rest. Users must encrypt/sign deliberately; training and policy matter for regulated content.

Operational metadata retentionNot listed
Low

Privacy policy lists IP, message-IDs, addresses, subjects, and related fields for operations, abuse control, and legal process—not a zero-logs design.

Limited public subprocessor inventoryNot listed
Low

Strong first-party claims of internal hosting, but no AWS-style public subprocessor table; confirm payment and support tooling in procurement.

US CLOUD Act (indicative)Not listed
Low

No known US parent; Belgian self-operated hosting narrative. Residual unknown payment/SaaS paths. Not a legal safe harbour guarantee.

Fit

mailbox (formerly mailbox.org)

Best fit when

  • German or EU orgs replacing Gmail/Microsoft 365 for mail and light collaboration under German law
  • Teams that need IMAP/SMTP plus CalDAV/CardDAV and optional custom domains
  • Buyers that will use PGP Guard or S/MIME deliberately for sensitive mail
  • SMEs and schools wanting Drive, browser Office, and Meet without a US hyperscaler
  • Organisations that need multi-seat Admin, DPA, and an automation API

Poor fit when

  • Users who need a permanent free tier
  • Buyers requiring default zero-knowledge mail for every user without crypto setup
  • Teams that must self-host the full stack on their own infrastructure
  • Enterprises whose workflows depend on deep Microsoft Graph or Google Workspace add-ons

Consider instead when

  • When: You need default end-to-end encrypted mail as the primary product

    Consider: Proton Mail or Tuta

    Stronger E2EE-first posture; lighter full workplace suite than mailbox

  • When: You want minimal German privacy email without Drive/Office/Meet

    Consider: Posteo

    Leaner mailbox; fewer collaboration modules

  • When: You need full desktop Office parity and global SaaS integrations

    Consider: Microsoft 365 (incumbent) with separate residency controls

    Different risk and ecosystem tradeoff—not an EU peer

Mailfence

Best fit when

  • You need OpenPGP interoperability and digital signatures from a European webmail, not only proprietary E2EE
  • Belgian legal entity and self-described self-operated Belgian hosting are procurement requirements
  • Teams want mail plus calendar/documents/groups without moving to Microsoft 365 or Google Workspace
  • You need custom domains, aliases, and classic clients (IMAP/POP/ActiveSync) on paid tiers
  • Business buyers evaluating private-label, API provisioning, SSO/directory integration, or large-scale on-prem license

Poor fit when

  • Security policy requires a published independent security audit, ISO 27001, or SOC 2 from the email vendor
  • You want fully open-source server/client stacks you can fork and self-host as default
  • Every message must be automatically E2EE with no OpenPGP key UX (Tuta-style)
  • You need Microsoft-class DLP, eDiscovery, compliance archives, and deep SaaS integrations
  • Zero-logs marketing is a hard requirement (Mailfence documents operational metadata collection)

Consider instead when

  • When: You want automatic encryption for all messages with minimal key management

    Consider: Tuta

    Different crypto model; less OpenPGP interop emphasis than Mailfence.

  • When: You want a larger Swiss privacy suite brand and ecosystem apps

    Consider: Proton Mail

    Trade Belgian ContactOffice ownership and PGP-centric UX for Proton’s broader product family.

  • When: You want a lean German ad-free mailbox without suite features

    Consider: Posteo or mailbox.org

    Simpler mailbox posture; different admin/domain/crypto tradeoffs.

  • When: You need full Google/Microsoft productivity and compliance tooling

    Consider: Microsoft 365 or Google Workspace (accept US-cloud risk) or EU office suites if residency is the driver

    Mailfence is not a drop-in M365 replacement.

Open questions for due diligence

mailbox (formerly mailbox.org)

  • What is the exact current BSI C5 scope, type, and validity period on the attestation document?
  • Which payment processors and any other subprocessors appear in the live AVV annex?
  • What is the default Meet encryption mode (TLS-only vs optional E2EE) for your plan, and is recording available?
  • Which SSO/IdP integrations are supported for your business tier beyond generic SSO mentions?

Mailfence

  • Will Mailfence provide a current written subprocessor list (including payment processors and any backup locations) for a company account?
  • Is any independent security assessment available under NDA for regulated buyers?
  • For Business on-prem license: exact minimum scale, support model, update cadence, and cryptographic feature parity vs SaaS?
  • Which plan tiers currently include IMAP/POP/ActiveSync and custom-domain limits for our user count?
  • How are disaster-recovery backup sites jurisdictions documented in the signed DPA annex?