mailbox (formerly mailbox.org) vs Posteo

Compare mailbox (formerly mailbox.org) and Posteo on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Gmail

Logo: mailbox (formerly mailbox.org)

mailbox (formerly mailbox.org)

Germany· Office Productivity Suite

Needs review

Shortlist mailbox when you need a German-operated email-plus-collaboration suite (Mail, Drive, Office, Meet, Admin/API) on dual Berlin sites with published BSI C5 Type 1 and ISO 27001 claims. Skip when you require free forever mail or default zero-knowledge for all messages—consider Proton Mail or Tuta instead.

German-operatedBerlin dual-site hostingPGP + S/MIMEBSI C5 Type 1 (claimed)ISO 27001 (claimed)Mail + Drive + Meet + Office
Logo: Posteo

Posteo

Germany· Email Services

Needs review

Shortlist when you want a paid German mailbox on self-operated servers, open protocols (IMAP/CalDAV), and extreme data minimisation (no inventory data, unlinked payments). Skip when you need custom domains, default E2EE without setup, multi-seat enterprise admin, or an Art. 28 DPA—consider Proton Mail, Tuta, mailbox.org, or Mailfence instead.

Self-operated DE serversData-minimising signupIMAP / CalDAV / CardDAVBSI TR-03108 (verified)Optional crypto mail storageAd-free, user-funded
mailbox (formerly mailbox.org) vs Posteo: Snapshot
FeatureLogo: mailbox (formerly mailbox.org)mailbox (formerly mailbox.org)Logo: PosteoPosteo
Country of originGermanyGermany
CategoryOffice Productivity SuiteEmail Services
Open sourceNoYes
Self-hostedNoNo
HeadquartersGermanyGermany
Legal entityHeinlein Hosting GmbH (Berlin; CEO Peer Heinlein)Posteo e.K., Methfesselstr. 38, 10965 Berlin
Governing lawNot listedGerman / EU law (GDPR, BDSG, telecom secrecy / TTDSG as applicable)
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)LowLow
Hosting / residencyCore mailbox, Drive, and Meet on Heinlein-operated servers in German data centres in Berlin (two independent locations). Website analytics: self-hosted Matomo. Marketing site may embed Vimeo/YouTube. No public AWS/GCP/Azure product hosting region found for customer mail data.Self-operated infrastructure; stored mail and backups in Germany (Frankfurt, Bielefeld, Berlin DCs per privacy materials). No AWS/GCP/Azure listed for mailbox hosting. Payment top-ups may use PayPal/card networks (unlinked from accounts per Posteo).
Summary

German paid digital workplace from Heinlein Hosting GmbH: secure email with PGP/S/MIME, Drive, browser Office, Meet, and business Admin on dual Berlin data centres.

Independent Berlin email provider with self-operated German servers, data-minimising signup, open-standard clients, and layered optional encryption—not a free-tier ad network.

Tags
At a glance: mailbox (formerly mailbox.org) vs Posteo
At a glanceLogo: mailbox (formerly mailbox.org)mailbox (formerly mailbox.org)Logo: PosteoPosteo
HQBerlin, GermanyBerlin, Germany
Legal entityHeinlein Hosting GmbHPosteo e.K. (HRA 47592 B)
HostingOwn servers, dual independent Berlin sitesSelf-operated servers in Germany
ModelPaid subscription SaaS; trial available; no permanent free tierNot listed
Self-hostNo (managed SaaS)No (hosted service)
Open standardsIMAP/SMTP, CalDAV/CardDAV, WebDAV, PGP, S/MIMENot listed
Commercial modelNot listedPrepaid paid service; no free tier
ProtocolsNot listedIMAP, POP3, SMTP, CalDAV, CardDAV
FoundedNot listed2009
EnergyNot listed100% green energy (Green Planet Energy, claimed)
Key capabilities: mailbox (formerly mailbox.org) vs Posteo
Key capabilitiesLogo: mailbox (formerly mailbox.org)mailbox (formerly mailbox.org)Logo: PosteoPosteo
German-operatedYesNot listed
Berlin dual-site hostingYesNot listed
PGP + S/MIMEYesNot listed
BSI C5 Type 1 (claimed)YesNot listed
ISO 27001 (claimed)YesNot listed
Mail + Drive + Meet + OfficeYesNot listed
Self-operated DE serversNot listedYes
Data-minimising signupNot listedYes
IMAP / CalDAV / CardDAVNot listedYes
BSI TR-03108 (verified)Not listedYes
Optional crypto mail storageNot listedYes
Ad-free, user-fundedNot listedYes

mailbox (formerly mailbox.org)

  • PGP Guard, S/MIME, and hardened mail transport

    Webmail Guard for PGP without extra software (or Mailvelope with local keys), S/MIME for sign/encrypt, 2FA and app passwords, multi-stage spam/virus rejection, plus public transport controls (DNSSEC, DANE, MTA-STS, DMARC/DKIM/SPF, TLS checker, @secure.mailbox.org aliases). Benefits security-minded teams that still need interoperable IMAP/SMTP; content is not zero-knowledge by default unless you encrypt.

  • Drive on dual independent Berlin sites

    Cloud files on the provider's own German infrastructure with two independent Berlin locations, WebDAV, mobile apps, guest share links, expandable quota, and optional client-side OpenPGP encryption of stored files. Fits teams replacing consumer cloud drives while keeping residency claims concrete; confirm plan quotas on the official site.

  • Browser Office with CalDAV and CardDAV

    Edit common office formats in the browser, share calendars and contacts via open CalDAV/CardDAV standards, plus tasks, notes, polls, and TLS-secured XMPP chat. Aimed at SMEs and schools that want collaboration without a full Microsoft desktop stack; advanced Excel macros and deep Office add-ins are not the target.

  • Meet video hosted in German data centres

    Browser-based conferencing integrated with calendar and mail: link invites for external guests, breakout rooms, screen share, chat, surveys, and moderator controls. Privacy documentation references the OpenTalk stack; sessions run through mailbox's German data centres. Evaluate E2EE defaults and recording policies against your meeting compliance needs.

  • Business Admin console and automation API

    Central management of domains, mailboxes, quotas, spam/virus settings, IP allowlists, and backups, with an HTTP API for larger orgs and resellers (api.mailbox.org). Supports onboarding help and partner-assisted migration. Better for multi-seat German operations than pure consumer inboxes; not a full IdP replacement without SSO design work.

Posteo

  • Signup without identity data; payments unlinked

    Accounts can be created without name, address, or phone. Posteo's payment system (bank transfer codes, cash, card, PayPal) is designed so payment identifiers are not stored against the mailbox. Practical limit: recovery options you add yourself and how you fund the prepaid balance still affect anonymity in the real world.

  • Optional crypto mail storage for the whole mailbox

    One setting encrypts stored messages—including metadata—with a key protected by the account password (RSA/AES/HMAC/bcrypt design; Dovecot plugin). Posteo states it cannot disable crypto storage once enabled and cites a Cure53 review. Limit: this is server-side encryption at rest after delivery, not sender-to-recipient E2EE, and losing the password can mean losing access to encrypted data.

  • TLS, DANE, and BSI-certified secure transport

    Access is TLS-only with PFS, HSTS, and DANE/TLSA. Optional TLS-sending/receiving guarantees refuse delivery over cleartext peer links. Posteo holds BSI TR-03108 v2 Secure Email Transport certification (BSI-K-TR-0745-2025). Transport quality still depends on the remote provider's stack.

  • CalDAV/CardDAV with optional password encryption

    Calendars and contacts sync via open standards and can be AES-encrypted in Posteo's database so the provider cannot read them when the feature is on. Trade-off: encrypted calendars cannot be shared the same way, and password reset without the old secret can lock you out of encrypted PIM data.

  • In-house migration without third-party movers

    Posteo's own migration tool pulls mail (and often contacts/calendars) over encrypted links from previous providers without routing through a third-party migration SaaS. Quota: a limited number of migrations per account, with an optional collector for ongoing fetch from the old box.

Assurance & compliance: mailbox (formerly mailbox.org) vs Posteo
Assurance & complianceLogo: mailbox (formerly mailbox.org)mailbox (formerly mailbox.org)Logo: PosteoPosteo
Independent security / no-logs audit
Not found

No public independent no-logs audit PDF found; operational transparency reports and BSI/ISO artefacts instead

Partial

BfDI on-site privacy inspection (2016) confirmed data-minimisation / no inventory IP model (public PDF). Crypto mail storage: vendor cites Cure53 multi-level audit; full public report not located. Not a continuous independent no-logs certification programme.

ISO 27001
Vendor claimed

Vendor states ISO/IEC 27001:2022 on certified-quality and press pages; request current certificate in diligence

Not found

No ISO 27001 claim found on primary Posteo security/privacy pages.

SOC 2 / SOC 3
Not found

No SOC 2/3 claim found on primary security/cert pages

Not found

No SOC 2/3 report advertised on primary pages.

BSI C5
Vendor claimed

Vendor press (7 Jan 2026): BSI C5 Type 1 attestation for mailbox; confirm type, scope, and period

Not listed
GDPR / EU data protection
Vendor claimed

German controller Heinlein Hosting GmbH; DE hosting; detailed privacy notice; DPO privacy@mailbox.org

Vendor claimed

German entity; privacy policy cites GDPR/BDSG/telecom secrecy; DPO published; BfDI inspection history.

US CLOUD Act exposure (indicative)
Partial

EU/German entity, no known US parent, self-operated Berlin hosting for core data—no AWS/GCP/Azure product region found. Residual: marketing embeds (Vimeo/YouTube) and possible external payment services. Indicative assessment only, not legal advice.

Partial

EuropeanStack assessment: German e.K., no known US parent, self-operated DE hosting with no public US-cloud mailbox subprocessors → indicative exposure low. Status is partial (not a clean bill): payment rails and lawful German disclosure remain. Not legal advice.

Data processing agreement (B2B)
Vendor claimed

Business knowledge base: customers can conclude a DPA online; historic AVV portal for business accounts

Not found

Vendor states it is not an Art. 28 processor as a public electronic communications service and does not offer customer DPAs.

EU AI Act
Not applicable

Email/collaboration suite, not an AI product core

Not applicable

Conventional email/PIM service; not an AI product.

BSI TR-03108 Secure Email TransportNot listed
Verified

BSI certificate BSI-K-TR-0745-2025 (OpenSource Security GmbH audit; valid through 2030 per BSI listing).

Considerations & known limitations: mailbox (formerly mailbox.org) vs Posteo
Considerations & known limitationsLogo: mailbox (formerly mailbox.org)mailbox (formerly mailbox.org)Logo: PosteoPosteo
Mail is not zero-knowledge by default
Medium

Without PGP/S/MIME, stored message content remains operator-accessible under legal process. Practical impact: train users or mandate Guard/S/MIME for confidential traffic.

Not listed
C5 Type 1 is point-in-time
Low

Type 1 attestations describe design/implementation at a point in time. Re-check type (1 vs 2), scope, and renewal dates for public-sector RFPs.

Not listed
Payment and edge processors need confirmation
Low

Core hosting is self-operated DE, but privacy text references external payment services; marketing embeds US video hosts. Ask for the current processor list with the DPA.

Not listed
Not a full Microsoft 365 ecosystem substitute
Medium

Browser Office and Meet cover common collaboration; deep desktop macros, Graph automations, and third-party M365 marketplaces will not map 1:1.

Not listed
No customer self-host option
Low

Organisations that must operate mail on their own iron need another stack; mailbox is multi-tenant SaaS.

Not listed
No custom domainsNot listed
High

Posteo will not host your own domain. Organisations needing brand continuity or provider portability via DNS must pick another host or self-host.

Encryption is layered, not default E2EENot listed
Medium

Without crypto mail storage, inbound encryption, or client-side PGP/S/MIME, Posteo can process mailbox content like a normal provider. Lawful intercept (TKU) and seizures remain possible under German process; transparency reports show content releases do occur under court order.

No customer Art. 28 DPANot listed
Medium

Procurement checklists that require a signed processor agreement will stall. Posteo argues telecom special law applies instead; validate with legal counsel for your use case.

Password loss risk with crypto featuresNot listed
Medium

Crypto mail storage and encrypted calendars/contacts depend on the account password; Posteo cannot recover plaintext if that secret is lost after encryption is enabled.

Payment processors outside pure DE mail pathNot listed
Low

Optional PayPal/card top-ups involve non-German commercial processors even though Posteo says it does not link payment identity to the mailbox. Cash/bank-code paths reduce that linkage further.

Fit

mailbox (formerly mailbox.org)

Best fit when

  • German or EU orgs replacing Gmail/Microsoft 365 for mail and light collaboration under German law
  • Teams that need IMAP/SMTP plus CalDAV/CardDAV and optional custom domains
  • Buyers that will use PGP Guard or S/MIME deliberately for sensitive mail
  • SMEs and schools wanting Drive, browser Office, and Meet without a US hyperscaler
  • Organisations that need multi-seat Admin, DPA, and an automation API

Poor fit when

  • Users who need a permanent free tier
  • Buyers requiring default zero-knowledge mail for every user without crypto setup
  • Teams that must self-host the full stack on their own infrastructure
  • Enterprises whose workflows depend on deep Microsoft Graph or Google Workspace add-ons

Consider instead when

  • When: You need default end-to-end encrypted mail as the primary product

    Consider: Proton Mail or Tuta

    Stronger E2EE-first posture; lighter full workplace suite than mailbox

  • When: You want minimal German privacy email without Drive/Office/Meet

    Consider: Posteo

    Leaner mailbox; fewer collaboration modules

  • When: You need full desktop Office parity and global SaaS integrations

    Consider: Microsoft 365 (incumbent) with separate residency controls

    Different risk and ecosystem tradeoff—not an EU peer

Posteo

Best fit when

  • Individuals and small teams who want German jurisdiction and open-standard clients without Google or Microsoft mail
  • Users prioritising anonymous or low-identity signup and prepaid funding without linking payments to the mailbox
  • Organisations that accept posteo.* addresses and value no ads, no tracking, and published transparency reports
  • Operators who want optional full-mailbox encryption at rest (crypto mail storage) plus PGP/S/MIME tooling
  • Buyers who need BSI-aligned secure email transport certification rather than US SOC 2 paperwork

Poor fit when

  • Anyone requiring custom domains or branded organisational addresses
  • Teams that need default zero-access E2EE for every message without enabling optional layers
  • Procurement processes that mandate a signed Art. 28 DPA, SOC 2, or ISO 27001 from the vendor
  • Large enterprises needing multi-seat admin, shared domain policies, or deep Microsoft/Google workspace integration

Consider instead when

  • When: You need default end-to-end encryption and a broader encrypted suite

    Consider: Proton Mail or Tuta

    Posteo is IMAP-first with optional crypto layers; Proton/Tuta lead with zero-access defaults.

  • When: You need custom domains or richer business mail hosting

    Consider: mailbox.org or Mailfence

    Posteo deliberately refuses own domains to avoid inventory-data obligations.

  • When: You need free-tier consumer mail tightly integrated with docs and chat

    Consider: Gmail or Outlook.com

    Trade privacy posture and EU self-operation for ecosystem convenience.

Open questions for due diligence

mailbox (formerly mailbox.org)

  • What is the exact current BSI C5 scope, type, and validity period on the attestation document?
  • Which payment processors and any other subprocessors appear in the live AVV annex?
  • What is the default Meet encryption mode (TLS-only vs optional E2EE) for your plan, and is recording available?
  • Which SSO/IdP integrations are supported for your business tier beyond generic SSO mentions?

Posteo

  • Does your counsel accept Posteo's position that no Art. 28 DPA is required for occupational use?
  • Will posteo.de / .net / .com addresses meet your brand, deliverability, and anti-spoofing requirements without custom domains?
  • Which encryption layers (crypto mail storage, inbound PGP/S/MIME, client E2EE) will your users actually enable and support?
  • Do you need ISO 27001/SOC 2 artefacts that Posteo does not publish?
  • Is BSI TR-03108 transport certification sufficient for your sector's secure-email checklist?