Mailfence vs RAIDBOXES Emails

Compare Mailfence and RAIDBOXES Emails on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Gmail, Microsoft 365

Logo: Mailfence

Mailfence

Belgium· Email Services

Needs review

Shortlist Mailfence when you want Belgian-operated webmail with interoperable OpenPGP, digital signatures, and a light calendar/documents suite—plus optional business private-label or on-prem license. Skip when you need automatic closed E2EE without key management (consider Tuta), a large Swiss privacy ecosystem (Proton Mail), or a minimalist German mailbox (Posteo / mailbox.org).

EU-operated (Belgium)OpenPGP E2EEDigital signaturesMail + calendar + docsCustom domains (paid)B2B DPA available
Logo: RAIDBOXES Emails

RAIDBOXES Emails

Germany· Email Services

Needs review

Shortlist when you already (or will) host the domain and WordPress stack at RAIDBOXES and need practical multi-mailbox domain email under a German operator with an online DPA. Skip when you need multi-domain density, default E2EE, or email fully independent of a hoster—consider Migadu, Tuta, Posteo, or mailbox.org instead.

German operatorIMAP / SMTPMail Hosting 2.0Online DPAWordPress-adjacentOptional PGP
Mailfence vs RAIDBOXES Emails: Snapshot
FeatureLogo: MailfenceMailfenceLogo: RAIDBOXES EmailsRAIDBOXES Emails
Country of originBelgiumGermany
CategoryEmail ServicesEmail Services
Open sourceNoNo
Self-hostedNoNo
HeadquartersBelgiumGermany
Legal entityContactOffice Group sa, Avenue Franklin Roosevelt 47b, B-1050 Brussels (BE 0466.241.584)Raidboxes GmbH, Hafenstraße 32, 48153 Münster (Amtsgericht Münster HRB 16184)
Governing lawBelgian law; Brussels courts (Terms of Use)German law (company domicile Münster)
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)LowMedium
Hosting / residencyPrimary production servers described as located in Belgium under Mailfence operational control (no intermediary managing servers per security page). No public AWS/GCP/Azure subprocessor list found. Backups stored in locations separate from offices/main DC (providers not named). Payment-card processing path not fully published.Email: vendor claims exclusive German data centres and first-party Mail Hosting 2.0 infrastructure (IMAP/SMTP on securemail.pro hostnames); privacy policy still names Heinlein Hosting/mailbox.org under paid email boxes (possible legacy lag). Platform/website: AWS EMEA SARL and DigitalOcean listed for web hosting of the online offer; US-group SaaS includes Intercom, Calendly, Chargebee, Sentry, Google analytics/ads, Mailgun, and others for support, billing, and marketing.
Summary

Belgian secure email suite with browser-side OpenPGP encryption, digital signatures, calendar, documents, and optional custom domains under ContactOffice Group SA.

German domain email hosting from Raidboxes GmbH (Münster): Mail Hosting 2.0 with IMAP/SMTP, multi-mailbox plans, optional PGP, and dashboard fit for WordPress agencies—domain must be hosted at RAIDBOXES.

Tags
At a glance: Mailfence vs RAIDBOXES Emails
At a glanceLogo: MailfenceMailfenceLogo: RAIDBOXES EmailsRAIDBOXES Emails
HQ / entityBrussels — ContactOffice Group sa (BE 0466.241.584)Not listed
Product launchMailfence brand ~2013; ContactOffice lineage since 1999Not listed
CryptoOpenPGP E2EE + digital signatures; optional password-encrypted messagesNot listed
HostingVendor-operated servers in Belgium (per security page)Not listed
Open sourceNo (front-end OSS planned; not current)No
Self-hostSaaS default; Business license for large on-prem deploymentsNot listed
Commercial modelFree tier + prepaid paid plans; Business packaging (see vendor site)Not listed
Independent auditNo public audit PDF foundNot listed
HQNot listedMünster, Germany
Legal entityNot listedRaidboxes GmbH (HRB 16184)
GroupNot listedteam.blue (Belgium) since 2022
ProductNot listedMail Hosting 2.0 domain email
AccessNot listedIMAP / SMTP + webmail
Domain constraintNot listedDomain hosted at RAIDBOXES for new mailboxes
Self-hostedNot listedNo
Key capabilities: Mailfence vs RAIDBOXES Emails
Key capabilitiesLogo: MailfenceMailfenceLogo: RAIDBOXES EmailsRAIDBOXES Emails
EU-operated (Belgium)YesNot listed
OpenPGP E2EEYesNot listed
Digital signaturesYesNot listed
Mail + calendar + docsYesNot listed
Custom domains (paid)YesNot listed
B2B DPA availableYesNot listed
German operatorNot listedYes
IMAP / SMTPNot listedYes
Mail Hosting 2.0Not listedYes
Online DPANot listedYes
WordPress-adjacentNot listedYes
Optional PGPNot listedYes

Mailfence

  • Browser-side OpenPGP end-to-end encryption

    Encrypt outbound mail in the browser with the OpenPGP standard so intermediaries—including Mailfence when messages are properly E2EE—cannot read ciphertext. Fully interoperable with other OpenPGP tools (e.g. Thunderbird/GnuPG). Optional password-encrypted messages cover recipients who do not use PGP. Unencrypted mail still sits on servers in the normal webmail model.

  • Digital signatures and multi-key OpenPGP keystore

    Sign messages for authenticity and integrity, and manage keys in-product: generate, import, export, publish, and hold multiple key pairs without browser plug-ins. Default generated keys are 4096-bit per the threat-model page. Passphrase protection of private keys limits crypto operations if only the account password is compromised.

  • Mail, calendar, documents, and groups in one account

    Beyond inbox: shareable calendars, online document storage/editing, and contact groups for collaboration without bolting on a separate US suite. Storage and alias limits scale by plan; free accounts remain suitable only for light personal use.

  • Custom domains, aliases, and mail protocols on paid tiers

    Higher plans add custom domains with SPF/DKIM/DMARC-oriented setup, larger alias counts, and classic client access (POP, IMAP, SMTP) plus ActiveSync where listed. Entry-level free accounts focus on web/PWA/apps rather than full protocol parity—verify the live plan matrix before procurement.

  • Business admin: API, SSO, private label, optional on-prem license

    Mailfence for Business offers control-panel and XML-RPC API user provisioning, SSO and directory hooks (LDAP/AD/CAS), branding, and Belgian cloud hosting with SLA language—or a license to run on customer Linux servers for large deployments. Fit for orgs that need Belgian hosting with admin automation, not a consumer-only mailbox.

RAIDBOXES Emails

  • Mail Hosting 2.0 on RAIDBOXES infrastructure

    IMAP/SMTP mailboxes on dedicated hostnames (mail-rb.securemail.pro / smtp-rb.securemail.pro) after the move off the prior mailbox.org cooperation. Vendor claims German data-centre locations and triple-redundant mail servers. Best for teams that want domain mail under the same German WordPress host rather than a separate privacy-mail brand.

  • Multi-mailbox plans with aliases, forwards, and catch-all

    Tiered plans allocate a fixed number of mailboxes and a shared storage pool, plus per-mailbox alias and forwarding quotas, autoresponders, and catch-all (requires a dedicated catch-all mailbox). One connected domain per plan—confirm multi-domain needs before shortlisting.

  • Spam/virus filters, TLS, optional PGP, ad-free inboxes

    All plans include spam and virus filtering, SSL/TLS for transfer, a blacklist checker, webmail, and ad-free inboxes. PGP is optional rather than default end-to-end encryption for every message—teams that need mandatory E2EE workflows should evaluate Tuta or a full mailbox.org stack instead.

  • Dashboard-adjacent domain and WordPress ops

    Mailboxes are ordered from the RAIDBOXES dashboard and are intended to sit next to WordPress hosting and domain management. New RAIDBOXES mailboxes require the domain to be hosted with RAIDBOXES; legacy mailbox.org-linked domains follow a separate migration path documented in the help centre.

  • Online B2B DPA and German operator

    Raidboxes GmbH (Münster) offers an online data processing agreement (AV contract) with technical-organisational measures. Useful for agencies that already sign a DPA for WordPress hosting and want the same counterparty for domain email—still review TOMs and subprocessor scope for mailbox vs platform tooling.

Assurance & compliance: Mailfence vs RAIDBOXES Emails
Assurance & complianceLogo: MailfenceMailfenceLogo: RAIDBOXES EmailsRAIDBOXES Emails
Independent security / no-logs audit
Not found

No public third-party audit PDF found. Vendor mentions security specialists, bug bounty activity, and inspection openness—not a substitute for a published audit. Privacy policy documents operational metadata collection (not zero-logs).

Not found

No public third-party security or no-logs audit report found for RAIDBOXES Emails on primary pages.

ISO 27001
Not found

No Mailfence ISO 27001 certificate claim found on primary security/GDPR/company pages.

Not found

No company-wide ISO 27001 certificate for Raidboxes GmbH found on product/security pages; AWS region ISO mentions are not RAIDBOXES certs.

SOC 2 / SOC 3
Not found
Not found

No public SOC 2/3 report located for RAIDBOXES Emails.

GDPR / EU data protection
Vendor claimed

Belgian controller/processor materials; dedicated GDPR page and technical/organisational measures overview. Confirm roles in your DPA.

Vendor claimed

German controller (Raidboxes GmbH); product claims DE server locations and GDPR-aligned deletion; online DPA available. Confirm active mail stack vs privacy-policy mailbox.org listing.

US CLOUD Act exposure (indicative)
Partial

EU entity (ContactOffice Group sa), no known US parent; servers claimed self-operated in Belgium without named US hyperscaler hosts. No formal public subprocessor inventory; payment processors not named. Assessment residual: partial transparency on data path. Not legal advice.

Partial

EU/German entity, no known US parent (team.blue BE group). Medium residual exposure via US-group platform subprocessors (AWS/DigitalOcean for online offer hosting; Intercom, Chargebee, Google tooling, Mailgun, etc.). Mail content path claimed DE-only. Not legal advice.

Data processing agreement (B2B)
Vendor claimed

Downloadable DPA linked from the GDPR page for organisational customers.

Vendor claimed

Online AV/DPA flow at raidboxes.io/en/dpa/ and DocuSign TOM path documented in help centre.

EU AI Act
Not applicable

Email/collaboration suite; not an AI system under typical procurement framing.

Not applicable

Domain email hosting product, not an AI system offering.

B Corp certificationNot listed
Vendor claimed

Raidboxes GmbH listed as Certified B Corporation on B Lab directory; impact certification, not an information-security audit.

Considerations & known limitations: Mailfence vs RAIDBOXES Emails
Considerations & known limitationsLogo: MailfenceMailfenceLogo: RAIDBOXES EmailsRAIDBOXES Emails
No public independent security audit
Medium

If vendor risk requires a published audit letter, ISO 27001, or SOC 2, treat Mailfence as incomplete until evidence is obtained offline or under NDA.

Not listed
Closed-source SaaS
Medium

Cannot independently review server code or default-self-host like some FOSS mail stacks. Business on-prem license is a commercial path, not community self-host docs.

Not listed
E2EE is opt-in OpenPGP, not automatic
Medium

Clear-text messages are operator-readable at rest. Users must encrypt/sign deliberately; training and policy matter for regulated content.

Not listed
Operational metadata retention
Low

Privacy policy lists IP, message-IDs, addresses, subjects, and related fields for operations, abuse control, and legal process—not a zero-logs design.

Not listed
Limited public subprocessor inventory
Low

Strong first-party claims of internal hosting, but no AWS-style public subprocessor table; confirm payment and support tooling in procurement.

Not listed
US CLOUD Act (indicative)
Low

No known US parent; Belgian self-operated hosting narrative. Residual unknown payment/SaaS paths. Not a legal safe harbour guarantee.

Not listed
Domain must be hosted at RAIDBOXESNot listed
Medium

New mailboxes require the domain on RAIDBOXES. That is convenient for WP customers and a lock-in factor if you only wanted independent mail.

One connected domain per planNot listed
Medium

Multi-domain operators need multiple plans or another provider; not a Migadu-style multi-domain account model.

PGP optional, not default E2EENot listed
Medium

Threat models that assume provider-side unreadability by default are a better fit for Tuta or similar products.

US-group platform subprocessorsNot listed
Medium

Privacy policy discloses AWS EMEA, DigitalOcean, Intercom, Chargebee, Google tools, Mailgun, and others for website/support/billing/marketing—even while email marketing claims German mail servers. Scope diligence to mailbox vs platform data paths.

Privacy policy may lag Mail Hosting 2.0Not listed
Low

§Email box still lists mailbox.org/Heinlein while marketing claims first-party hosting—confirm live stack and subprocessor annex for your contract.

No public ISO/SOC/mail auditNot listed
Medium

B Corp is not a security certification. Enterprise security questionnaires may need NDA materials or alternative providers with published audits.

Fit

Mailfence

Best fit when

  • You need OpenPGP interoperability and digital signatures from a European webmail, not only proprietary E2EE
  • Belgian legal entity and self-described self-operated Belgian hosting are procurement requirements
  • Teams want mail plus calendar/documents/groups without moving to Microsoft 365 or Google Workspace
  • You need custom domains, aliases, and classic clients (IMAP/POP/ActiveSync) on paid tiers
  • Business buyers evaluating private-label, API provisioning, SSO/directory integration, or large-scale on-prem license

Poor fit when

  • Security policy requires a published independent security audit, ISO 27001, or SOC 2 from the email vendor
  • You want fully open-source server/client stacks you can fork and self-host as default
  • Every message must be automatically E2EE with no OpenPGP key UX (Tuta-style)
  • You need Microsoft-class DLP, eDiscovery, compliance archives, and deep SaaS integrations
  • Zero-logs marketing is a hard requirement (Mailfence documents operational metadata collection)

Consider instead when

  • When: You want automatic encryption for all messages with minimal key management

    Consider: Tuta

    Different crypto model; less OpenPGP interop emphasis than Mailfence.

  • When: You want a larger Swiss privacy suite brand and ecosystem apps

    Consider: Proton Mail

    Trade Belgian ContactOffice ownership and PGP-centric UX for Proton’s broader product family.

  • When: You want a lean German ad-free mailbox without suite features

    Consider: Posteo or mailbox.org

    Simpler mailbox posture; different admin/domain/crypto tradeoffs.

  • When: You need full Google/Microsoft productivity and compliance tooling

    Consider: Microsoft 365 or Google Workspace (accept US-cloud risk) or EU office suites if residency is the driver

    Mailfence is not a drop-in M365 replacement.

RAIDBOXES Emails

Best fit when

  • WordPress agencies and freelancers standardising on RAIDBOXES for sites, domains, and mail admin
  • SMEs wanting professional multi-mailbox domain email with standard IMAP clients—not a full Google/Microsoft suite
  • Teams that need catch-all, aliases, forwards, autoresponders, and ad-free inboxes on one domain
  • Buyers who require a German legal counterparty and an online B2B DPA for processor agreements
  • Operators migrating off legacy mailbox.org-linked RAIDBOXES mail toward first-party Mail Hosting 2.0

Poor fit when

  • Multi-domain mail estates that need many domains under one contract (one connected domain per plan)
  • Policies requiring default end-to-end encryption for all mail (PGP is optional only)
  • Buyers who refuse any coupling between mailbox service and domain/WordPress hosting
  • Teams seeking a full office suite (Drive, collaborative docs, built-in video) rather than domain mail
  • Procurement that demands public ISO 27001/SOC 2 or independent no-logs audit reports for the mail product

Consider instead when

  • When: You need multi-domain, usage-based professional mail without WordPress host lock-in

    Consider: Migadu

    Swiss-operated, standards-based hosting priced by quotas rather than per-domain WordPress adjacency

  • When: You need default E2EE and a privacy-first client model

    Consider: Tuta

    Different threat model; less IMAP flexibility than RAIDBOXES

  • When: You want privacy-oriented German personal/business mail without hosting coupling

    Consider: Posteo or mailbox (formerly mailbox.org)

    mailbox is also the former RAIDBOXES mail partner and a deeper digital-workplace option

  • When: You need Google/Microsoft suite collaboration, not just domain mailboxes

    Consider: Google Workspace or Microsoft 365

    US Big Tech residency and CLOUD Act profile differ sharply—use only if suite features dominate

Open questions for due diligence

Mailfence

  • Will Mailfence provide a current written subprocessor list (including payment processors and any backup locations) for a company account?
  • Is any independent security assessment available under NDA for regulated buyers?
  • For Business on-prem license: exact minimum scale, support model, update cadence, and cryptographic feature parity vs SaaS?
  • Which plan tiers currently include IMAP/POP/ActiveSync and custom-domain limits for our user count?
  • How are disaster-recovery backup sites jurisdictions documented in the signed DPA annex?

RAIDBOXES Emails

  • For a new Mail Hosting 2.0 mailbox, is mailbox.org/Heinlein still a subprocessor for mailbox content, or only a legacy path?
  • Which German data-centre operators and exact regions host mail storage and backups (primary + DR)?
  • Does the standard DPA/TOM annex explicitly cover email hosting subprocessors separately from WordPress hosting?
  • What are published RPO/RTO and restore procedures for mailbox backups?
  • Are there any upcoming multi-domain plan options or reseller mail SKUs?