Mailfence vs Migadu

Compare Mailfence and Migadu on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Gmail, Microsoft 365

Logo: Mailfence

Mailfence

Belgium· Email Services

Needs review

Shortlist Mailfence when you want Belgian-operated webmail with interoperable OpenPGP, digital signatures, and a light calendar/documents suite—plus optional business private-label or on-prem license. Skip when you need automatic closed E2EE without key management (consider Tuta), a large Swiss privacy ecosystem (Proton Mail), or a minimalist German mailbox (Posteo / mailbox.org).

EU-operated (Belgium)OpenPGP E2EEDigital signaturesMail + calendar + docsCustom domains (paid)B2B DPA available
Logo: Migadu

Migadu

Switzerland· Email Services

Needs review

Shortlist Migadu when you need Swiss-operated, standards IMAP/SMTP hosting with unlimited addresses across many domains under flat account quotas—especially agencies and multi-domain SMEs. Skip when you need provider E2EE defaults, contractual SLA on the default offer, mailbox 2FA, or bulk/transactional sending; consider Proton Mail/Tuta for E2EE, or mailbox.org/Mailfence/Posteo/Runbox for other European professional-mail tradeoffs.

Swiss operatorUsage-priced multi-domainSMTP/IMAP/POP3Mail hosted in FranceMulti-admin + APINo ads / no tracking
Mailfence vs Migadu: Snapshot
FeatureLogo: MailfenceMailfenceLogo: MigaduMigadu
Country of originBelgiumSwitzerland
CategoryEmail ServicesEmail Services
Open sourceNoNo
Self-hostedNoNo
HeadquartersBelgiumSwitzerland
Legal entityContactOffice Group sa, Avenue Franklin Roosevelt 47b, B-1050 Brussels (BE 0466.241.584)Migadu-Mail GmbH
Governing lawBelgian law; Brussels courts (Terms of Use)Canton of Appenzell Ausserrhoden, Swiss Confederation (terms)
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)LowMedium
Hosting / residencyPrimary production servers described as located in Belgium under Mailfence operational control (no intermediary managing servers per security page). No public AWS/GCP/Azure subprocessor list found. Backups stored in locations separate from offices/main DC (providers not named). Payment-card processing path not fully published.Mail servers stated in France (EU). Payment subprocessors Stripe and PayPal (US) for billing data. Full mail infrastructure/backup subprocessor list not published by name on primary pages.
Summary

Belgian secure email suite with browser-side OpenPGP encryption, digital signatures, calendar, documents, and optional custom domains under ContactOffice Group SA.

Swiss-operated, standards-based email hosting for custom domains: unlimited addresses and multi-domain accounts priced by usage quotas, not per mailbox.

Tags
At a glance: Mailfence vs Migadu
At a glanceLogo: MailfenceMailfenceLogo: MigaduMigadu
HQ / entityBrussels — ContactOffice Group sa (BE 0466.241.584)Migadu-Mail GmbH, Switzerland
Product launchMailfence brand ~2013; ContactOffice lineage since 1999Not listed
CryptoOpenPGP E2EE + digital signatures; optional password-encrypted messagesNot listed
HostingVendor-operated servers in Belgium (per security page)Not listed
Open sourceNo (front-end OSS planned; not current)Not listed
Self-hostSaaS default; Business license for large on-prem deploymentsNo
Commercial modelFree tier + prepaid paid plans; Business packaging (see vendor site)Flat per-account plans by daily message quotas + soft storage
Independent auditNo public audit PDF foundNot listed
FoundedNot listed2014 (vendor About)
Mail hostingNot listedData centers in France (vendor Pro/Cons)
Open source product?Not listedNo — built on open-source stack; service is proprietary SaaS
OwnershipNot listedBootstrapped; no outside capital (vendor claim)
Key capabilities: Mailfence vs Migadu
Key capabilitiesLogo: MailfenceMailfenceLogo: MigaduMigadu
EU-operated (Belgium)YesNot listed
OpenPGP E2EEYesNot listed
Digital signaturesYesNot listed
Mail + calendar + docsYesNot listed
Custom domains (paid)YesNot listed
B2B DPA availableYesNot listed
Swiss operatorNot listedYes
Usage-priced multi-domainNot listedYes
SMTP/IMAP/POP3Not listedYes
Mail hosted in FranceNot listedYes
Multi-admin + APINot listedYes
No ads / no trackingNot listedYes

Mailfence

  • Browser-side OpenPGP end-to-end encryption

    Encrypt outbound mail in the browser with the OpenPGP standard so intermediaries—including Mailfence when messages are properly E2EE—cannot read ciphertext. Fully interoperable with other OpenPGP tools (e.g. Thunderbird/GnuPG). Optional password-encrypted messages cover recipients who do not use PGP. Unencrypted mail still sits on servers in the normal webmail model.

  • Digital signatures and multi-key OpenPGP keystore

    Sign messages for authenticity and integrity, and manage keys in-product: generate, import, export, publish, and hold multiple key pairs without browser plug-ins. Default generated keys are 4096-bit per the threat-model page. Passphrase protection of private keys limits crypto operations if only the account password is compromised.

  • Mail, calendar, documents, and groups in one account

    Beyond inbox: shareable calendars, online document storage/editing, and contact groups for collaboration without bolting on a separate US suite. Storage and alias limits scale by plan; free accounts remain suitable only for light personal use.

  • Custom domains, aliases, and mail protocols on paid tiers

    Higher plans add custom domains with SPF/DKIM/DMARC-oriented setup, larger alias counts, and classic client access (POP, IMAP, SMTP) plus ActiveSync where listed. Entry-level free accounts focus on web/PWA/apps rather than full protocol parity—verify the live plan matrix before procurement.

  • Business admin: API, SSO, private label, optional on-prem license

    Mailfence for Business offers control-panel and XML-RPC API user provisioning, SSO and directory hooks (LDAP/AD/CAS), branding, and Belgian cloud hosting with SLA language—or a license to run on customer Linux servers for large deployments. Fit for orgs that need Belgian hosting with admin automation, not a consumer-only mailbox.

Migadu

  • Usage-metered accounts with unlimited addresses

    Plans are flat per Migadu account. Within daily in/out quotas and soft storage guidance, create large numbers of mailboxes and host many domains without per-address fees—useful for agencies and multi-project teams. Soft storage does not hard-bounce mail; sustained over-quota use can force upgrades or limits.

  • Standards SMTP, IMAP4, POP3, and webmail

    No proprietary client protocol. Connect Thunderbird, Apple Mail, Outlook, mutt, and others over TLS (typical endpoints imap.migadu.com:993, smtp.migadu.com:465, pop.migadu.com:995). ManageSieve filtering, aliases, pattern rewrites, identities, footers, auto-responders, and optional catch-alls cover classic postmaster needs. Data remains portable via standard protocols.

  • Multi-domain admin, multi-admin, and beta API

    Agencies can hold many client domains under one roof, open multiple administrators (domain-scoped on higher plans), set per-domain/mailbox limits, and monitor traffic. A REST API (documented as early beta) manages domains, mailboxes, identities, forwardings, aliases, and rewrites for automation. Domain deletion stays UI-only as a safety measure.

  • DNS helpers and postmaster-style support

    Optional built-in DNS ships mail records preconfigured; Migadu also offers DNS setup help at no extra fee and publishes diagnostics/activation flows. Support is ticket-based from people who operate the mail stack—not outsourced chat—with plan-dependent urgency outside office hours.

  • No ads, no product analytics cookies

    Vendor policy states no advertising, no tracking of mailbox content for ads, and no website analytics cookies beyond session needs. Processing is framed for service delivery, abuse prevention, and legal obligations. Payment data still goes to Stripe and PayPal under separate processor terms.

Assurance & compliance: Mailfence vs Migadu
Assurance & complianceLogo: MailfenceMailfenceLogo: MigaduMigadu
Independent security / no-logs audit
Not found

No public third-party audit PDF found. Vendor mentions security specialists, bug bounty activity, and inspection openness—not a substitute for a published audit. Privacy policy documents operational metadata collection (not zero-logs).

Not found

Vendor claims no ad scanning/sharing of mail content; no public third-party audit PDF located.

ISO 27001
Not found

No Mailfence ISO 27001 certificate claim found on primary security/GDPR/company pages.

Not found

Data centers described as internationally certified; no Migadu-organization ISO 27001 certificate found on primary pages.

SOC 2 / SOC 3
Not found
Not found
GDPR / EU data protection
Vendor claimed

Belgian controller/processor materials; dedicated GDPR page and technical/organisational measures overview. Confirm roles in your DPA.

Vendor claimed

Privacy policy asserts GDPR and Swiss DPA compliance; mail hosted in France per vendor.

US CLOUD Act exposure (indicative)
Partial

EU entity (ContactOffice Group sa), no known US parent; servers claimed self-operated in Belgium without named US hyperscaler hosts. No formal public subprocessor inventory; payment processors not named. Assessment residual: partial transparency on data path. Not legal advice.

Partial

Swiss entity, no known US parent, mail in France; Stripe and PayPal process payments with US transfers. Infrastructure subprocessors not fully named. EuropeanStack assessment—not a vendor certification. Not legal advice.

Data processing agreement (B2B)
Vendor claimed

Downloadable DPA linked from the GDPR page for organisational customers.

Vendor claimed

Privacy page states it serves as privacy policy and DPA; confirm suitability with counsel.

EU AI Act
Not applicable

Email/collaboration suite; not an AI system under typical procurement framing.

Not applicable

Email hosting product; not an AI system offering.

Considerations & known limitations: Mailfence vs Migadu
Considerations & known limitationsLogo: MailfenceMailfenceLogo: MigaduMigadu
No public independent security audit
Medium

If vendor risk requires a published audit letter, ISO 27001, or SOC 2, treat Mailfence as incomplete until evidence is obtained offline or under NDA.

Medium

Privacy and no-ad-scanning claims are first-party. No independent audit report found for no-logs or security controls.

Closed-source SaaS
Medium

Cannot independently review server code or default-self-host like some FOSS mail stacks. Business on-prem license is a commercial path, not community self-host docs.

Not listed
E2EE is opt-in OpenPGP, not automatic
Medium

Clear-text messages are operator-readable at rest. Users must encrypt/sign deliberately; training and policy matter for regulated content.

Not listed
Operational metadata retention
Low

Privacy policy lists IP, message-IDs, addresses, subjects, and related fields for operations, abuse control, and legal process—not a zero-logs design.

Not listed
Limited public subprocessor inventory
Low

Strong first-party claims of internal hosting, but no AWS-style public subprocessor table; confirm payment and support tooling in procurement.

Not listed
US CLOUD Act (indicative)
Low

No known US parent; Belgian self-operated hosting narrative. Residual unknown payment/SaaS paths. Not a legal safe harbour guarantee.

Not listed
US payment subprocessors (Stripe, PayPal)Not listed
Medium

Billing-related personal data can transfer to US processors under Migadu’s privacy policy. Mail content path is France/EU per vendor, but payment data is a separate CLOUD Act / transfer surface.

Incomplete public infrastructure subprocessor listNot listed
Medium

Primary pages name France hosting and certified DCs without a full vendor inventory for compute, storage, and backups. Procurement should request the current list and regions in writing.

No E2EE product default; no classic mailbox 2FANot listed
Medium

Standards mail with TLS; vendor recommends user-side OpenPGP for strong content secrecy. IMAP 2FA is not offered; app-specific-style identities are not second-factor MFA.

Daily quotas and human-mail policyNot listed
Medium

Account-wide daily in/out caps and anti-bulk rules make Migadu unsuitable as a transactional/marketing ESP. Over-limit mail can be deferred or rejected after tolerance.

No default SLA on standard plansNot listed
Low

Vendor states standard offers lack SLAs; email is treated as asynchronous and occasionally disrupted. Enterprise SLA only via separate commercial discussion.

Fit

Mailfence

Best fit when

  • You need OpenPGP interoperability and digital signatures from a European webmail, not only proprietary E2EE
  • Belgian legal entity and self-described self-operated Belgian hosting are procurement requirements
  • Teams want mail plus calendar/documents/groups without moving to Microsoft 365 or Google Workspace
  • You need custom domains, aliases, and classic clients (IMAP/POP/ActiveSync) on paid tiers
  • Business buyers evaluating private-label, API provisioning, SSO/directory integration, or large-scale on-prem license

Poor fit when

  • Security policy requires a published independent security audit, ISO 27001, or SOC 2 from the email vendor
  • You want fully open-source server/client stacks you can fork and self-host as default
  • Every message must be automatically E2EE with no OpenPGP key UX (Tuta-style)
  • You need Microsoft-class DLP, eDiscovery, compliance archives, and deep SaaS integrations
  • Zero-logs marketing is a hard requirement (Mailfence documents operational metadata collection)

Consider instead when

  • When: You want automatic encryption for all messages with minimal key management

    Consider: Tuta

    Different crypto model; less OpenPGP interop emphasis than Mailfence.

  • When: You want a larger Swiss privacy suite brand and ecosystem apps

    Consider: Proton Mail

    Trade Belgian ContactOffice ownership and PGP-centric UX for Proton’s broader product family.

  • When: You want a lean German ad-free mailbox without suite features

    Consider: Posteo or mailbox.org

    Simpler mailbox posture; different admin/domain/crypto tradeoffs.

  • When: You need full Google/Microsoft productivity and compliance tooling

    Consider: Microsoft 365 or Google Workspace (accept US-cloud risk) or EU office suites if residency is the driver

    Mailfence is not a drop-in M365 replacement.

Migadu

Best fit when

  • Agencies and freelancers hosting many client domains under one account with multi-admin or API provisioning
  • Organizations that want custom-domain mail with standard clients and portable IMAP—not a proprietary suite lock-in
  • Teams tired of per-seat pricing for large address spaces with modest real traffic
  • Buyers who value a small bootstrapped Swiss operator that publishes blunt product limits
  • Setups that need aliases, rewrites, identities, SIEVE, and postmaster-style controls more than collab apps

Poor fit when

  • Primary need is end-to-end encrypted mail by default (Proton Mail, Tuta, or user-side OpenPGP workflows)
  • High-volume transactional, marketing, or bulk outbound mail
  • Requirement for default contractual SLA, phone support, or multi-language admin UI
  • Mandatory mailbox 2FA on every IMAP login
  • Want a free long-term plan or Migadu-branded @provider addresses without owning a domain

Consider instead when

  • When: You need provider-managed end-to-end encryption as the default product promise

    Consider: Proton Mail or Tuta

    Migadu is standards hosting with TLS; content secrecy against the operator is not the design center.

  • When: You want another European professional host with a different admin/encryption/residency package

    Consider: mailbox.org, Mailfence, Posteo, or Runbox

    Compare DPA detail, audit packaging, and whether multi-domain usage pricing still wins for your address sprawl.

  • When: You need full workspace suite (docs, meet, identity) rather than email hosting alone

    Consider: Google Workspace, Microsoft 365, or Infomaniak-style European suites

    Migadu deliberately stays postmaster-focused.

  • When: You need bulk or high-rate application email

    Consider: A dedicated ESP (not Migadu); Amazon SES is the common Big Tech baseline—pair with EU ESPs if residency matters

    Migadu rate-limits and bans intentional bulk use.

Open questions for due diligence

Mailfence

  • Will Mailfence provide a current written subprocessor list (including payment processors and any backup locations) for a company account?
  • Is any independent security assessment available under NDA for regulated buyers?
  • For Business on-prem license: exact minimum scale, support model, update cadence, and cryptographic feature parity vs SaaS?
  • Which plan tiers currently include IMAP/POP/ActiveSync and custom-domain limits for our user count?
  • How are disaster-recovery backup sites jurisdictions documented in the signed DPA annex?

Migadu

  • What are the current named mail hosting, backup, and ancillary subprocessors and their countries?
  • Can Migadu provide ISO/SOC evidence for the organization or only DC-level certifications?
  • Is an independent security or penetration-test summary available under NDA?
  • Does the privacy-page DPA meet your controller’s mandatory clauses without a separate signed agreement?
  • What encryption-at-rest and key-management practices apply today versus the older public pro/con narrative?