Mailfence vs Mailo

Compare Mailfence and Mailo on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Gmail, Microsoft 365, Outlook.com

Logo: Mailfence

Mailfence

Belgium· Email Services

Needs review

Shortlist Mailfence when you want Belgian-operated webmail with interoperable OpenPGP, digital signatures, and a light calendar/documents suite—plus optional business private-label or on-prem license. Skip when you need automatic closed E2EE without key management (consider Tuta), a large Swiss privacy ecosystem (Proton Mail), or a minimalist German mailbox (Posteo / mailbox.org).

EU-operated (Belgium)OpenPGP E2EEDigital signaturesMail + calendar + docsCustom domains (paid)B2B DPA available
Logo: Mailo

Mailo

France· Email Services

Needs review

Shortlist Mailo when you want French-entity freemium webmail with classic IMAP/EAS clients, integrated calendar/cloud, supervised Mailo Junior for kids, or Pro custom domains for SMEs—without US Big Tech accounts. Skip when you need default zero-knowledge E2EE, open-source/self-host, or a full Workspace-class suite; consider Tuta, Proton Mail, or Infomaniak kMail instead.

France-hosted (claimed)Freemium webmailMailo JuniorIMAP / ActiveSyncPro custom domainsOptional PGP (server-side)
Mailfence vs Mailo: Snapshot
FeatureLogo: MailfenceMailfenceLogo: MailoMailo
Country of originBelgiumFrance
CategoryEmail ServicesEmail Services
Open sourceNoNo
Self-hostedNoNo
HeadquartersBelgiumFrance
Legal entityContactOffice Group sa, Avenue Franklin Roosevelt 47b, B-1050 Brussels (BE 0466.241.584)MAILO SAS (capital €75,000; RCS Créteil 851585547; VAT FR44851585547)
Governing lawBelgian law; Brussels courts (Terms of Use)French law (terms of use)
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)LowMedium
Hosting / residencyPrimary production servers described as located in Belgium under Mailfence operational control (no intermediary managing servers per security page). No public AWS/GCP/Azure subprocessor list found. Backups stored in locations separate from offices/main DC (providers not named). Payment-card processing path not fully published.Vendor states user personal data and content are stored/processed on servers in France; specialised French host centre (who-we-are); website hosted by Ecritel, Arradon, France. Named third parties: Verifone/Paybox (payment email), PayPal option, Gandi/Netim (domains), Sirdata + ad agencies (free-tier ads), optional Rainbow video and OnlyOffice. Full mail DC/backup subprocessor list not published.
Summary

Belgian secure email suite with browser-side OpenPGP encryption, digital signatures, calendar, documents, and optional custom domains under ContactOffice Group SA.

French freemium webmail and Mail&Cloud suite (MAILO SAS): email, calendar, cloud disk, Mailo Junior for children, and Pro custom domains—hosted in France, proprietary SaaS.

Tags
At a glance: Mailfence vs Mailo
At a glanceLogo: MailfenceMailfenceLogo: MailoMailo
HQ / entityBrussels — ContactOffice Group sa (BE 0466.241.584)MAILO SAS, France (RCS Créteil 851585547)
Product launchMailfence brand ~2013; ContactOffice lineage since 1999Not listed
CryptoOpenPGP E2EE + digital signatures; optional password-encrypted messagesNot listed
HostingVendor-operated servers in Belgium (per security page)Not listed
Open sourceNo (front-end OSS planned; not current)No (proprietary MailObject®)
Self-hostSaaS default; Business license for large on-prem deploymentsNo
Commercial modelFree tier + prepaid paid plans; Business packaging (see vendor site)Not listed
Independent auditNo public audit PDF foundNot listed
Hosting (claimed)Not listedServers in France; website host Ecritel (FR)
ModelNot listedFreemium SaaS (Free / Premium / Pro / Junior / Edu)
Encryption defaultNot listedTLS + optional server-side PGP (not ZK E2EE)
Key capabilities: Mailfence vs Mailo
Key capabilitiesLogo: MailfenceMailfenceLogo: MailoMailo
EU-operated (Belgium)YesNot listed
OpenPGP E2EEYesNot listed
Digital signaturesYesNot listed
Mail + calendar + docsYesNot listed
Custom domains (paid)YesNot listed
B2B DPA availableYesNot listed
France-hosted (claimed)Not listedYes
Freemium webmailNot listedYes
Mailo JuniorNot listedYes
IMAP / ActiveSyncNot listedYes
Pro custom domainsNot listedYes
Optional PGP (server-side)Not listedYes

Mailfence

  • Browser-side OpenPGP end-to-end encryption

    Encrypt outbound mail in the browser with the OpenPGP standard so intermediaries—including Mailfence when messages are properly E2EE—cannot read ciphertext. Fully interoperable with other OpenPGP tools (e.g. Thunderbird/GnuPG). Optional password-encrypted messages cover recipients who do not use PGP. Unencrypted mail still sits on servers in the normal webmail model.

  • Digital signatures and multi-key OpenPGP keystore

    Sign messages for authenticity and integrity, and manage keys in-product: generate, import, export, publish, and hold multiple key pairs without browser plug-ins. Default generated keys are 4096-bit per the threat-model page. Passphrase protection of private keys limits crypto operations if only the account password is compromised.

  • Mail, calendar, documents, and groups in one account

    Beyond inbox: shareable calendars, online document storage/editing, and contact groups for collaboration without bolting on a separate US suite. Storage and alias limits scale by plan; free accounts remain suitable only for light personal use.

  • Custom domains, aliases, and mail protocols on paid tiers

    Higher plans add custom domains with SPF/DKIM/DMARC-oriented setup, larger alias counts, and classic client access (POP, IMAP, SMTP) plus ActiveSync where listed. Entry-level free accounts focus on web/PWA/apps rather than full protocol parity—verify the live plan matrix before procurement.

  • Business admin: API, SSO, private label, optional on-prem license

    Mailfence for Business offers control-panel and XML-RPC API user provisioning, SSO and directory hooks (LDAP/AD/CAS), branding, and Belgian cloud hosting with SLA language—or a license to run on customer Linux servers for large deployments. Fit for orgs that need Belgian hosting with admin automation, not a consumer-only mailbox.

Mailo

  • French-hosted webmail with IMAP, EAS, and classic protocols

    Webmail plus IMAP4 for clients, Exchange ActiveSync for mobile sync, and POP3 on paid tiers; SMTP relay with account credentials. Vendor states mail and content stay on servers in France. Free tier is ad-supported with lower quotas; Premium unlocks POP3, more aliases, and larger mail/cloud caps. Suits teams that need standard desktop/mobile clients rather than a closed proprietary app only.

  • Mailo Junior supervised email for children

    Child accounts (about ages 6–14) only exchange mail with contacts a parent or teacher validates. Age-adapted mini/junior UIs, no ads on Junior, optional promotion to a standard account while keeping the address. Separate Junior mobile apps. Unique fit for families and schools versus generic consumer mail.

  • Calendar, virtual disk, and open sync protocols

    Shared calendars and tasks, address book, photo albums, and a virtual disk for files with WebDAV/FTP access. CalDAV and CardDAV for external clients. Premium+ can unlock OnlyOffice in-browser editing. Better as an all-in-one Mail&Cloud for SMEs/families than bare IMAP-only privacy mail.

  • Mailo Pro spaces: custom domains and mutualised storage

    Pro Start/5/Modulo style plans share mail+cloud quota across accounts, support custom domains (register, transfer, or declare external), distribution lists, mailbox sharing, resource calendars, and manager tooling. Priority Pro hotline with documented acknowledgement and restoration targets for Pro subscriptions. Aimed at TPE/PME, associations, and municipalities—not a full Google Workspace clone.

  • Optional server-side PGP and account security controls

    Built-in PGP/MIME encrypt and sign in the webmail as a trusted third party (keys managed on Mailo for multi-device convenience). Two-factor authentication, application passwords, connection history, and guardianship-style access options. Not zero-knowledge E2EE by default—use external client crypto if the provider must never hold keys.

Assurance & compliance: Mailfence vs Mailo
Assurance & complianceLogo: MailfenceMailfenceLogo: MailoMailo
Independent security / no-logs audit
Not found

No public third-party audit PDF found. Vendor mentions security specialists, bug bounty activity, and inspection openness—not a substitute for a published audit. Privacy policy documents operational metadata collection (not zero-logs).

Not found

Charter claims no commercial reading of messages; automated AV/spam scanning on servers. No public third-party audit PDF found.

ISO 27001
Not found

No Mailfence ISO 27001 certificate claim found on primary security/GDPR/company pages.

Not found

No ISO 27001 claim found on legal/security/primary pages researched.

SOC 2 / SOC 3
Not found
Not found

No SOC 2/3 report referenced on public product pages.

GDPR / EU data protection
Vendor claimed

Belgian controller/processor materials; dedicated GDPR page and technical/organisational measures overview. Confirm roles in your DPA.

Vendor claimed

French controller; privacy rules cite GDPR and French correspondence secrecy; DPO at dpo@mailo.com; France storage claim.

US CLOUD Act exposure (indicative)
Partial

EU entity (ContactOffice Group sa), no known US parent; servers claimed self-operated in Belgium without named US hyperscaler hosts. No formal public subprocessor inventory; payment processors not named. Assessment residual: partial transparency on data path. Not legal advice.

Partial

EU entity / no known US parent / France-claimed mail hosting, but Verifone and PayPal (US-group) on payment path; full infra subprocessors unpublished. Assessment only—not legal advice.

Data processing agreement (B2B)
Vendor claimed

Downloadable DPA linked from the GDPR page for organisational customers.

Not found

Privacy rules and terms cover processing; no standalone public B2B DPA download found—request via DPO or Pro channel.

EU AI Act
Not applicable

Email/collaboration suite; not an AI system under typical procurement framing.

Not applicable

Traditional email/cloud suite; not marketed as an AI system product.

Considerations & known limitations: Mailfence vs Mailo
Considerations & known limitationsLogo: MailfenceMailfenceLogo: MailoMailo
No public independent security audit
Medium

If vendor risk requires a published audit letter, ISO 27001, or SOC 2, treat Mailfence as incomplete until evidence is obtained offline or under NDA.

Not listed
Closed-source SaaS
Medium

Cannot independently review server code or default-self-host like some FOSS mail stacks. Business on-prem license is a commercial path, not community self-host docs.

Not listed
E2EE is opt-in OpenPGP, not automatic
Medium

Clear-text messages are operator-readable at rest. Users must encrypt/sign deliberately; training and policy matter for regulated content.

Not listed
Operational metadata retention
Low

Privacy policy lists IP, message-IDs, addresses, subjects, and related fields for operations, abuse control, and legal process—not a zero-logs design.

Not listed
Limited public subprocessor inventory
Low

Strong first-party claims of internal hosting, but no AWS-style public subprocessor table; confirm payment and support tooling in procurement.

Not listed
US CLOUD Act (indicative)
Low

No known US parent; Belgian self-operated hosting narrative. Residual unknown payment/SaaS paths. Not a legal safe harbour guarantee.

Not listed
PGP is server-side trusted third partyNot listed
Medium

Webmail PGP holds keys on Mailo for multi-device use. Provider-access risk differs from zero-knowledge E2EE defaults at Tuta/Proton. Use external crypto if that is a hard requirement.

Incomplete public subprocessor inventoryNot listed
Medium

Privacy rules name payments, domains, and free-tier ads, but not a full list of mail storage, backup, or anti-spam infrastructure vendors. Request annex for B2B risk review.

US-group payment processorsNot listed
Low

Checkout shares email with Verifone/Paybox; PayPal is also offered. Limited to billing path per privacy rules, but relevant to CLOUD Act diligence.

Free tier third-party advertisingNot listed
Low

Mailo Free shows ad banners via agencies under IAB TCF consent (Sirdata CMP). Premium removes ads. Ad cookies stated as not tied to Mailo profile.

No public ISO/SOC or independent security auditNot listed
Medium

Security posture relies on first-party statements and internal measures. Procurement teams may need questionnaires or NDA evidence.

Free accounts deleted after inactivityNot listed
Low

Mailo Free unused for 365 days can be deleted with content loss. Premium/Pro have different retention rules—plan backups and renewals.

Fit

Mailfence

Best fit when

  • You need OpenPGP interoperability and digital signatures from a European webmail, not only proprietary E2EE
  • Belgian legal entity and self-described self-operated Belgian hosting are procurement requirements
  • Teams want mail plus calendar/documents/groups without moving to Microsoft 365 or Google Workspace
  • You need custom domains, aliases, and classic clients (IMAP/POP/ActiveSync) on paid tiers
  • Business buyers evaluating private-label, API provisioning, SSO/directory integration, or large-scale on-prem license

Poor fit when

  • Security policy requires a published independent security audit, ISO 27001, or SOC 2 from the email vendor
  • You want fully open-source server/client stacks you can fork and self-host as default
  • Every message must be automatically E2EE with no OpenPGP key UX (Tuta-style)
  • You need Microsoft-class DLP, eDiscovery, compliance archives, and deep SaaS integrations
  • Zero-logs marketing is a hard requirement (Mailfence documents operational metadata collection)

Consider instead when

  • When: You want automatic encryption for all messages with minimal key management

    Consider: Tuta

    Different crypto model; less OpenPGP interop emphasis than Mailfence.

  • When: You want a larger Swiss privacy suite brand and ecosystem apps

    Consider: Proton Mail

    Trade Belgian ContactOffice ownership and PGP-centric UX for Proton’s broader product family.

  • When: You want a lean German ad-free mailbox without suite features

    Consider: Posteo or mailbox.org

    Simpler mailbox posture; different admin/domain/crypto tradeoffs.

  • When: You need full Google/Microsoft productivity and compliance tooling

    Consider: Microsoft 365 or Google Workspace (accept US-cloud risk) or EU office suites if residency is the driver

    Mailfence is not a drop-in M365 replacement.

Mailo

Best fit when

  • EU individuals and families wanting French-hosted mail with calendar and cloud disk in one account
  • Parents/schools needing supervised child email (Mailo Junior) with contact allow-lists
  • French SMEs, associations, and municipalities needing custom domains and mutualised Pro storage
  • Teams that depend on IMAP, EAS, CalDAV, CardDAV, or WebDAV rather than a locked-in app
  • Buyers who accept freemium ads on free tier or low-cost Premium rather than pure prepaid anonymity mail

Poor fit when

  • Orgs that require default end-to-end encryption with zero-access provider architecture
  • Buyers that need open-source server code or official self-hosting
  • Enterprises needing SOC 2 / ISO 27001 evidence already published on a trust centre
  • Heavy Google Workspace / Microsoft 365 collaboration suites (docs/drive ecosystem depth)

Consider instead when

  • When: You need zero-knowledge / default E2EE webmail

    Consider: Tuta or Proton Mail

    Mailo PGP is optional and server-side trusted third party

  • When: You want German privacy mail with different encryption/product posture

    Consider: Posteo or mailbox.org

    Compare protocols, storage bundles, and business features side by side

  • When: You need Swiss multi-product cloud with mail plus broader suite

    Consider: Infomaniak kMail

    Different country stack and product breadth

  • When: You need US Big Tech ecosystem integration at any cost

    Consider: Gmail or Microsoft 365 / Outlook.com

    Trade EU entity and France residency claims for ecosystem depth

Open questions for due diligence

Mailfence

  • Will Mailfence provide a current written subprocessor list (including payment processors and any backup locations) for a company account?
  • Is any independent security assessment available under NDA for regulated buyers?
  • For Business on-prem license: exact minimum scale, support model, update cadence, and cryptographic feature parity vs SaaS?
  • Which plan tiers currently include IMAP/POP/ActiveSync and custom-domain limits for our user count?
  • How are disaster-recovery backup sites jurisdictions documented in the signed DPA annex?

Mailo

  • Will Mailo sign a GDPR Article 28 DPA with a full subprocessor and transfer annex for Pro customers?
  • What is the named primary data-centre operator and backup/DR location beyond the France and Ecritel website-host statements?
  • Is there an independent penetration test, ISO 27001 roadmap, or customer-available security whitepaper?
  • Where is Rainbow (video) and OnlyOffice data processed relative to the France mail claim?
  • Current UGAP / public procurement listing status for French public buyers?