Mailfence vs Swissnode

Compare Mailfence and Swissnode on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Gmail, Microsoft 365

Logo: Mailfence

Mailfence

Belgium· Email Services

Needs review

Shortlist Mailfence when you want Belgian-operated webmail with interoperable OpenPGP, digital signatures, and a light calendar/documents suite—plus optional business private-label or on-prem license. Skip when you need automatic closed E2EE without key management (consider Tuta), a large Swiss privacy ecosystem (Proton Mail), or a minimalist German mailbox (Posteo / mailbox.org).

EU-operated (Belgium)OpenPGP E2EEDigital signaturesMail + calendar + docsCustom domains (paid)B2B DPA available
Logo: Swissnode

Swissnode

Switzerland· Email Services

Needs review

Shortlist Swissnode for lean European cPanel domain email plus shared web or KVM VPS when Spain/EU residency is acceptable and you do not need enterprise compliance packs. Skip when you require live Swiss territorial hosting, E2EE mail, or published DPA/subprocessor inventories—consider Hostpoint, Infomaniak, or Proton Mail instead.

cPanel domain emailKVM VPSSpain data center (vendor)Optional Cloudflare CDNSMB hosting packages
Mailfence vs Swissnode: Snapshot
FeatureLogo: MailfenceMailfenceLogo: SwissnodeSwissnode
Country of originBelgiumSwitzerland
CategoryEmail ServicesEmail Services
Open sourceNoNo
Self-hostedNoNo
HeadquartersBelgiumSwitzerland
Legal entityContactOffice Group sa, Avenue Franklin Roosevelt 47b, B-1050 Brussels (BE 0466.241.584)Swissnode (legal form/registry name not clearly published on marketing site)
Governing lawBelgian law; Brussels courts (Terms of Use)Not clearly stated on marketing pages; confirm in contract (CH contact vs ES ops)
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)LowMedium
Hosting / residencyPrimary production servers described as located in Belgium under Mailfence operational control (no intermediary managing servers per security page). No public AWS/GCP/Azure subprocessor list found. Backups stored in locations separate from offices/main DC (providers not named). Payment-card processing path not fully published.Vendor states primary hosting moved to a Spain data center after Swiss DC closure; homepage cites Spanish privacy laws. Site IP geolocates to Spain (Ipcore Datacenters). Optional Cloudflare CDN on web plans (US-group). Off-site backup provider not named. No public subprocessor inventory.
Summary

Belgian secure email suite with browser-side OpenPGP encryption, digital signatures, calendar, documents, and optional custom domains under ContactOffice Group SA.

European cPanel email, shared web hosting, and KVM VPS under the Swissnode brand—vendor-stated Spain data center after Swiss DC closure, with optional Cloudflare CDN on web plans.

Tags
At a glance: Mailfence vs Swissnode
At a glanceLogo: MailfenceMailfenceLogo: SwissnodeSwissnode
HQ / entityBrussels — ContactOffice Group sa (BE 0466.241.584)Not listed
Product launchMailfence brand ~2013; ContactOffice lineage since 1999Not listed
CryptoOpenPGP E2EE + digital signatures; optional password-encrypted messagesNot listed
HostingVendor-operated servers in Belgium (per security page)Not listed
Open sourceNo (front-end OSS planned; not current)No
Self-hostSaaS default; Business license for large on-prem deploymentsNot listed
Commercial modelFree tier + prepaid paid plans; Business packaging (see vendor site)Package tiers (monthly/yearly); optional antispam add-on
Independent auditNo public audit PDF foundNot listed
Contact addressNot listedBinzallee 6, 8055 Zurich, CH (public contact page)
Footer / ops addressNot listedMutilva Baja, Navarra, Spain
Primary hosting (vendor)Not listedSpain data center after Swiss DC closure
Core productsNot listedDomain email, cPanel web hosting, KVM VPS
Control panelsNot listedcPanel (shared); Virtualizor (VPS)
Self-hosted productNot listedNo (provider-hosted; VPS gives root on rented VM)
Key capabilities: Mailfence vs Swissnode
Key capabilitiesLogo: MailfenceMailfenceLogo: SwissnodeSwissnode
EU-operated (Belgium)YesNot listed
OpenPGP E2EEYesNot listed
Digital signaturesYesNot listed
Mail + calendar + docsYesNot listed
Custom domains (paid)YesNot listed
B2B DPA availableYesNot listed
cPanel domain emailNot listedYes
KVM VPSNot listedYes
Spain data center (vendor)Not listedYes
Optional Cloudflare CDNNot listedYes
SMB hosting packagesNot listedYes

Mailfence

  • Browser-side OpenPGP end-to-end encryption

    Encrypt outbound mail in the browser with the OpenPGP standard so intermediaries—including Mailfence when messages are properly E2EE—cannot read ciphertext. Fully interoperable with other OpenPGP tools (e.g. Thunderbird/GnuPG). Optional password-encrypted messages cover recipients who do not use PGP. Unencrypted mail still sits on servers in the normal webmail model.

  • Digital signatures and multi-key OpenPGP keystore

    Sign messages for authenticity and integrity, and manage keys in-product: generate, import, export, publish, and hold multiple key pairs without browser plug-ins. Default generated keys are 4096-bit per the threat-model page. Passphrase protection of private keys limits crypto operations if only the account password is compromised.

  • Mail, calendar, documents, and groups in one account

    Beyond inbox: shareable calendars, online document storage/editing, and contact groups for collaboration without bolting on a separate US suite. Storage and alias limits scale by plan; free accounts remain suitable only for light personal use.

  • Custom domains, aliases, and mail protocols on paid tiers

    Higher plans add custom domains with SPF/DKIM/DMARC-oriented setup, larger alias counts, and classic client access (POP, IMAP, SMTP) plus ActiveSync where listed. Entry-level free accounts focus on web/PWA/apps rather than full protocol parity—verify the live plan matrix before procurement.

  • Business admin: API, SSO, private label, optional on-prem license

    Mailfence for Business offers control-panel and XML-RPC API user provisioning, SSO and directory hooks (LDAP/AD/CAS), branding, and Belgian cloud hosting with SLA language—or a license to run on customer Linux servers for large deployments. Fit for orgs that need Belgian hosting with admin automation, not a consumer-only mailbox.

Swissnode

  • Domain email on cPanel (IMAP/POP/SMTP)

    Business mailboxes on your domain with secure webmail, SpamAssassin-style spam control, virus filtering, DKIM, calendars/contacts, autoresponders, forwarders, filters, and mailing lists on mid-tier plans—protocol-compatible with Outlook, Apple Mail, and mobile clients.

  • cPanel web hosting with Softaculous and LiteSpeed PHP

    Shared and reseller web plans with datacenter SSDs, free panel SSL, multi-PHP, SSH above entry tiers, and Softaculous one-click apps—aimed at brochure sites, WordPress, and small PHP apps rather than container platforms.

  • KVM VPS with RAID-10 enterprise SSDs

    Root-level Linux VPS via KVM, enterprise SSDs, RAID-10 arrays, fixed per-VPS network allotments, and Virtualizor-style management for teams that outgrow shared hosting but still want package SKUs.

  • Optional Cloudflare CDN from the control panel

    Web plans advertise easy Cloudflare integration to cache static assets near visitors—useful for performance, with the tradeoff that enabled CDN traffic can traverse a US-group network path.

  • Backup cadence for VPS (vendor-stated)

    Marketing states daily on-site and weekly off-site VPS backups with rebuilds measured in minutes to an hour after failure—restore SLAs and off-site provider identity should be confirmed in the contract.

Assurance & compliance: Mailfence vs Swissnode
Assurance & complianceLogo: MailfenceMailfenceLogo: SwissnodeSwissnode
Independent security / no-logs audit
Not found

No public third-party audit PDF found. Vendor mentions security specialists, bug bounty activity, and inspection openness—not a substitute for a published audit. Privacy policy documents operational metadata collection (not zero-logs).

Not found

No public independent audit report found on swissnode.ch.

ISO 27001
Not found

No Mailfence ISO 27001 certificate claim found on primary security/GDPR/company pages.

Not found

No ISO 27001 claim located on official product/security pages.

SOC 2 / SOC 3
Not found
Not found

No SOC 2/3 claim found.

GDPR / EU data protection
Vendor claimed

Belgian controller/processor materials; dedicated GDPR page and technical/organisational measures overview. Confirm roles in your DPA.

Partial

Spain/EU hosting supports EU data-protection analysis, and homepage references Spanish privacy laws; usable privacy policy/DPA text not published on site. Customer remains controller for lawful basis.

US CLOUD Act exposure (indicative)
Partial

EU entity (ContactOffice Group sa), no known US parent; servers claimed self-operated in Belgium without named US hyperscaler hosts. No formal public subprocessor inventory; payment processors not named. Assessment residual: partial transparency on data path. Not legal advice.

Partial

No known US parent; primary host Spain/EU. Optional Cloudflare CDN is a US-group subprocessor for web static delivery; off-site backups and other SaaS paths not published. Not a clean low-exposure bill; not legal advice.

Data processing agreement (B2B)
Vendor claimed

Downloadable DPA linked from the GDPR page for organisational customers.

Not found

No public DPA download or B2B processing terms found; request in writing.

EU AI Act
Not applicable

Email/collaboration suite; not an AI system under typical procurement framing.

Not applicable

Commodity hosting/email/VPS, not an AI product.

Swiss territorial hostingNot listed
Partial

Vendor discloses Swiss DC closed; operations from Spain DC. Contact still Zurich. Do not treat as CH-only residency.

Considerations & known limitations: Mailfence vs Swissnode
Considerations & known limitationsLogo: MailfenceMailfenceLogo: SwissnodeSwissnode
No public independent security audit
Medium

If vendor risk requires a published audit letter, ISO 27001, or SOC 2, treat Mailfence as incomplete until evidence is obtained offline or under NDA.

Not listed
Closed-source SaaS
Medium

Cannot independently review server code or default-self-host like some FOSS mail stacks. Business on-prem license is a commercial path, not community self-host docs.

Not listed
E2EE is opt-in OpenPGP, not automatic
Medium

Clear-text messages are operator-readable at rest. Users must encrypt/sign deliberately; training and policy matter for regulated content.

Not listed
Operational metadata retention
Low

Privacy policy lists IP, message-IDs, addresses, subjects, and related fields for operations, abuse control, and legal process—not a zero-logs design.

Not listed
Limited public subprocessor inventory
Low

Strong first-party claims of internal hosting, but no AWS-style public subprocessor table; confirm payment and support tooling in procurement.

Not listed
US CLOUD Act (indicative)
Low

No known US parent; Belgian self-operated hosting narrative. Residual unknown payment/SaaS paths. Not a legal safe harbour guarantee.

Not listed
Swiss brand vs Spain hostingNot listed
High

Product pages state the Swiss data center closed and services run in Spain; homepage cites Spanish privacy laws. Buyers assuming Zurich colocation from the brand or older materials will mis-classify risk and contractual residency.

Empty privacy pages / no public DPA or certsNot listed
High

Privacy and cookie URLs do not present substantive policy text; ISO/SOC and DPA artifacts were not found. Regulated or enterprise buyers face a heavy offline diligence burden.

Optional Cloudflare CDN (US-group)Not listed
Medium

Web hosting markets Cloudflare integration from cPanel. Enabling CDN can place static content on a US-group network path even when origin is Spain—document this in transfer assessments.

Off-site backup provider not namedNot listed
Medium

Daily on-site and weekly off-site backups are claimed for VPS, but the off-site location/provider is not published—ask before trusting disaster-recovery or residency narratives.

Aging marketing surfaceNot listed
Low

Public site still shows 2013–2018 copyright and sparse modern trust pages; may signal limited investment in public assurance UX even if infrastructure remains operational.

Fit

Mailfence

Best fit when

  • You need OpenPGP interoperability and digital signatures from a European webmail, not only proprietary E2EE
  • Belgian legal entity and self-described self-operated Belgian hosting are procurement requirements
  • Teams want mail plus calendar/documents/groups without moving to Microsoft 365 or Google Workspace
  • You need custom domains, aliases, and classic clients (IMAP/POP/ActiveSync) on paid tiers
  • Business buyers evaluating private-label, API provisioning, SSO/directory integration, or large-scale on-prem license

Poor fit when

  • Security policy requires a published independent security audit, ISO 27001, or SOC 2 from the email vendor
  • You want fully open-source server/client stacks you can fork and self-host as default
  • Every message must be automatically E2EE with no OpenPGP key UX (Tuta-style)
  • You need Microsoft-class DLP, eDiscovery, compliance archives, and deep SaaS integrations
  • Zero-logs marketing is a hard requirement (Mailfence documents operational metadata collection)

Consider instead when

  • When: You want automatic encryption for all messages with minimal key management

    Consider: Tuta

    Different crypto model; less OpenPGP interop emphasis than Mailfence.

  • When: You want a larger Swiss privacy suite brand and ecosystem apps

    Consider: Proton Mail

    Trade Belgian ContactOffice ownership and PGP-centric UX for Proton’s broader product family.

  • When: You want a lean German ad-free mailbox without suite features

    Consider: Posteo or mailbox.org

    Simpler mailbox posture; different admin/domain/crypto tradeoffs.

  • When: You need full Google/Microsoft productivity and compliance tooling

    Consider: Microsoft 365 or Google Workspace (accept US-cloud risk) or EU office suites if residency is the driver

    Mailfence is not a drop-in M365 replacement.

Swissnode

Best fit when

  • Freelancers and micro-SMBs wanting domain IMAP/POP mail with spam filtering and webmail on cPanel
  • Agencies/resellers needing simple shared web packages (Softaculous, multi-PHP, free panel SSL) plus optional VPS upgrade path
  • Teams that prefer standard mail protocols over migrating into Microsoft 365 or Google Workspace
  • Buyers comfortable with Spain/EU hosting under a .ch brand and Swiss contact details
  • Workloads where package-tier hosting and KVM root access matter more than published ISO/SOC packs

Poor fit when

  • Organizations that hard-require Swiss (CH) server residency or nFADP narratives assuming Zurich colocation
  • Procurement needing public DPA, full subprocessor lists, ISO 27001, or SOC 2 on the vendor site
  • Teams needing end-to-end encrypted mail or zero-access webmail (choose Proton-class products)
  • Enterprises expecting Microsoft 365-class collaboration, compliance archives, and admin tooling
  • Buyers who shortlisted the brand solely for “Swiss data center” marketing that product pages no longer support

Consider instead when

  • When: You need Swiss-resident email/office with a broader product catalog and clearer CH hosting claims

    Consider: Hostpoint E-Mail & Cloud Office or Infomaniak kMail

    Fuller Swiss platforms; better when territorial Switzerland is non-negotiable.

  • When: You need end-to-end encrypted mail and open-source clients rather than cPanel hosting

    Consider: Proton Mail

    Different product class: E2EE vs classic hosted IMAP.

  • When: You need full collaboration suites, admin compliance tooling, and ecosystem apps

    Consider: Microsoft 365 or Google Workspace (US-group control planes)

    Richer features; different jurisdiction/CLOUD Act profile.

  • When: You want a larger EU hosting group with broader cloud SKUs

    Consider: IONOS or OVHcloud

    Scale and catalog depth over niche Swissnode packaging.

Open questions for due diligence

Mailfence

  • Will Mailfence provide a current written subprocessor list (including payment processors and any backup locations) for a company account?
  • Is any independent security assessment available under NDA for regulated buyers?
  • For Business on-prem license: exact minimum scale, support model, update cadence, and cryptographic feature parity vs SaaS?
  • Which plan tiers currently include IMAP/POP/ActiveSync and custom-domain limits for our user count?
  • How are disaster-recovery backup sites jurisdictions documented in the signed DPA annex?

Swissnode

  • What is the exact legal entity (registry name, UID/CHE or Spanish NIF) and governing law on the customer contract?
  • Will Swissnode sign a B2B DPA and publish a current subprocessor list (spam filter, backups, payment, support tools)?
  • Exact Spain facility (Ipcore or other) and whether any secondary regions exist for mail, web, and VPS separately?
  • Where are weekly off-site backups stored, and under which provider’s control?
  • Is Cloudflare mandatory, optional, or default for web plans, and can customers disable it for pure Spain origin delivery?
  • What uptime SLA, restore RPO/RTO, and support hours are contractual vs marketing (99.5% backbone claim on homepage)?