Mailfence vs web.de

Compare Mailfence and web.de on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Gmail, Outlook.com

Logo: Mailfence

Mailfence

Belgium· Email Services

Needs review

Shortlist Mailfence when you want Belgian-operated webmail with interoperable OpenPGP, digital signatures, and a light calendar/documents suite—plus optional business private-label or on-prem license. Skip when you need automatic closed E2EE without key management (consider Tuta), a large Swiss privacy ecosystem (Proton Mail), or a minimalist German mailbox (Posteo / mailbox.org).

EU-operated (Belgium)OpenPGP E2EEDigital signaturesMail + calendar + docsCustom domains (paid)B2B DPA available
Logo: web.de

web.de

Germany· Email Services

Needs review

Shortlist web.de when you need mass-market German freemail with DE-sited mail/cloud, E-Mail made in Germany TLS alliance markers, optional PGP/2FA, and a familiar DACH portal. Skip when you need default E2EE, no advertising data path, self-host, or enterprise admin—consider Posteo, mailbox.org, Tuta, or Proton Mail instead.

DE-operated freemailE-Mail made in GermanyGermany data centers (claimed)Optional PGPFreeMail + paid upgradesSaaS only
Mailfence vs web.de: Snapshot
FeatureLogo: MailfenceMailfenceLogo: web.deweb.de
Country of originBelgiumGermany
CategoryEmail ServicesEmail Services
Open sourceNoNo
Self-hostedNoNo
HeadquartersBelgiumGermany
Legal entityContactOffice Group sa, Avenue Franklin Roosevelt 47b, B-1050 Brussels (BE 0466.241.584)1&1 Mail & Media GmbH (United Internet AG group)
Governing lawBelgian law; Brussels courts (Terms of Use)Germany / EU GDPR
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)LowLow
Hosting / residencyPrimary production servers described as located in Belgium under Mailfence operational control (no intermediary managing servers per security page). No public AWS/GCP/Azure subprocessor list found. Backups stored in locations separate from offices/main DC (providers not named). Payment-card processing path not fully published.Vendor claims email and Online-Speicher stored exclusively in Germany in company-owned data centers (E-Mail/Cloud made in Germany). FreeMail monetized via advertising and IAB TCF consent partners; privacy notice allows EEA third-country transfers with Chapter V safeguards. Portal/optional features use additional processors (e.g. search partners, embeds, homepage builder DUDA Inc., ID vendors). No exhaustive public mail-stack subprocessor list found.
Summary

Belgian secure email suite with browser-side OpenPGP encryption, digital signatures, calendar, documents, and optional custom domains under ContactOffice Group SA.

German freemail and portal from United Internet’s 1&1 Mail & Media GmbH: FreeMail with DE-sited mail and cloud, E-Mail made in Germany TLS alliance, optional PGP—consumer SaaS, not default-E2EE privacy mail.

Tags
At a glance: Mailfence vs web.de
At a glanceLogo: MailfenceMailfenceLogo: web.deweb.de
HQ / entityBrussels — ContactOffice Group sa (BE 0466.241.584)Not listed
Product launchMailfence brand ~2013; ContactOffice lineage since 1999Not listed
CryptoOpenPGP E2EE + digital signatures; optional password-encrypted messagesNot listed
HostingVendor-operated servers in Belgium (per security page)Not listed
Open sourceNo (front-end OSS planned; not current)No
Self-hostSaaS default; Business license for large on-prem deploymentsNo
Commercial modelFree tier + prepaid paid plans; Business packaging (see vendor site)Ad-supported FreeMail; paid mailbox/cloud upgrades; Consent or Pay
Independent auditNo public audit PDF foundNot listed
HQ / operatorNot listed1&1 Mail & Media GmbH, Montabaur/Karlsruhe, Germany
Parent groupNot listedUnited Internet AG (Germany)
Product typeNot listedConsumer freemail + portal + cloud (SaaS)
Hosting (vendor claim)Not listedCompany-owned data centers in Germany
Key capabilities: Mailfence vs web.de
Key capabilitiesLogo: MailfenceMailfenceLogo: web.deweb.de
EU-operated (Belgium)YesYes
OpenPGP E2EEYesNot listed
Digital signaturesYesNot listed
Mail + calendar + docsYesNot listed
Custom domains (paid)YesNot listed
B2B DPA availableYesNot listed
E-Mail made in GermanyNot listedYes
Germany data centers (claimed)Not listedYes
Optional PGPNot listedYes
FreeMail + paid upgradesNot listedYes
SaaS onlyNot listedYes

Mailfence

  • Browser-side OpenPGP end-to-end encryption

    Encrypt outbound mail in the browser with the OpenPGP standard so intermediaries—including Mailfence when messages are properly E2EE—cannot read ciphertext. Fully interoperable with other OpenPGP tools (e.g. Thunderbird/GnuPG). Optional password-encrypted messages cover recipients who do not use PGP. Unencrypted mail still sits on servers in the normal webmail model.

  • Digital signatures and multi-key OpenPGP keystore

    Sign messages for authenticity and integrity, and manage keys in-product: generate, import, export, publish, and hold multiple key pairs without browser plug-ins. Default generated keys are 4096-bit per the threat-model page. Passphrase protection of private keys limits crypto operations if only the account password is compromised.

  • Mail, calendar, documents, and groups in one account

    Beyond inbox: shareable calendars, online document storage/editing, and contact groups for collaboration without bolting on a separate US suite. Storage and alias limits scale by plan; free accounts remain suitable only for light personal use.

  • Custom domains, aliases, and mail protocols on paid tiers

    Higher plans add custom domains with SPF/DKIM/DMARC-oriented setup, larger alias counts, and classic client access (POP, IMAP, SMTP) plus ActiveSync where listed. Entry-level free accounts focus on web/PWA/apps rather than full protocol parity—verify the live plan matrix before procurement.

  • Business admin: API, SSO, private label, optional on-prem license

    Mailfence for Business offers control-panel and XML-RPC API user provisioning, SSO and directory hooks (LDAP/AD/CAS), branding, and Belgian cloud hosting with SLA language—or a license to run on customer Linux servers for large deployments. Fit for orgs that need Belgian hosting with admin automation, not a consumer-only mailbox.

web.de

  • E-Mail made in Germany alliance transport

    Founding member of the German provider alliance (WEB.DE, GMX, 1&1, STRATO, T-Online, freenet). TLS on paths inside the alliance, mail stored in Germany, and green checkmarks on alliance addresses in the compose UI. Does not encrypt content to non-alliance or non-PGP recipients end-to-end by default.

  • FreeMail + paid upgrades with intelligent inbox

    Ad-supported FreeMail with integrated calendar, contacts, and Online-Speicher. Intelligent inbox categorizes newsletters, orders, social, and contracts/subscriptions without duplicating messages; optional package tracking via DHL, DPD, and GLS when consented. Paid tiers expand quotas and reduce ad/tracking friction under Consent or Pay.

  • Optional PGP and free 2FA

    Optional PGP end-to-end encryption for sensitive mail (both parties need keys/compatible clients). Optional free two-factor authentication for account login. Baseline mailbox protection relies on account credentials, spam/virus filters, and TLS—not default E2EE for every message.

  • Cloud made in Germany Online-Speicher

    Mailbox-integrated cloud with browser, app, and desktop access; link sharing and Online Office for documents. Vendor claims exclusive German data-center storage and TLS in transit under Cloud made in Germany. Free tier includes a starter cloud quota; larger capacities are paid add-ons. Not a full Google Drive/OneDrive collab suite.

  • German consumer portal on the same identity

    News, services, WEB.Cent cashback, and optional Deutsche Post letter preview sit beside mail. Useful for personal DACH users; increases advertising and partner surface versus a pure mailbox product. Portal embeds and partners are consent-gated where required.

Assurance & compliance: Mailfence vs web.de
Assurance & complianceLogo: MailfenceMailfenceLogo: web.deweb.de
Independent security / no-logs audit
Not found

No public third-party audit PDF found. Vendor mentions security specialists, bug bounty activity, and inspection openness—not a substitute for a published audit. Privacy policy documents operational metadata collection (not zero-logs).

Not found

No public independent no-logs or full security audit package found for FreeMail; alliance pages claim oversight by data-protection function and independent Prüfstellen at a high level only.

ISO 27001
Not found

No Mailfence ISO 27001 certificate claim found on primary security/GDPR/company pages.

Not found

No public ISO 27001 certificate page located for the web.de freemail product during research.

SOC 2 / SOC 3
Not found
Not found

No public SOC 2/3 report found for web.de FreeMail.

GDPR / EU data protection
Vendor claimed

Belgian controller/processor materials; dedicated GDPR page and technical/organisational measures overview. Confirm roles in your DPA.

Vendor claimed

German controller (1&1 Mail & Media GmbH); detailed GDPR privacy notice; DE storage claims for mail/cloud. Not a legal certification.

US CLOUD Act exposure (indicative)
Partial

EU entity (ContactOffice Group sa), no known US parent; servers claimed self-operated in Belgium without named US hyperscaler hosts. No formal public subprocessor inventory; payment processors not named. Assessment residual: partial transparency on data path. Not legal advice.

Partial

EU/German entity and parent; no known US parent; mail/cloud claimed on company-owned DE data centers. Partial because privacy notice allows third-country transfers with safeguards, FreeMail uses ad/TCF partners, and no exhaustive public subprocessor inventory. Not legal advice.

Data processing agreement (B2B)
Vendor claimed

Downloadable DPA linked from the GDPR page for organisational customers.

Not found

Consumer freemail focus; no clear self-serve public B2B DPA for FreeMail found. Request under contract if treating as processor for an organization.

EU AI Act
Not applicable

Email/collaboration suite; not an AI system under typical procurement framing.

Not applicable

Consumer mail/portal with limited in-product assistants; not an AI-centric product for this checklist.

Considerations & known limitations: Mailfence vs web.de
Considerations & known limitationsLogo: MailfenceMailfenceLogo: web.deweb.de
No public independent security audit
Medium

If vendor risk requires a published audit letter, ISO 27001, or SOC 2, treat Mailfence as incomplete until evidence is obtained offline or under NDA.

Medium

ISO 27001, SOC 2, and independent no-logs audits not found on public product pages. Trust rests on German entity, DE hosting claims, and first-party security copy.

Closed-source SaaS
Medium

Cannot independently review server code or default-self-host like some FOSS mail stacks. Business on-prem license is a commercial path, not community self-host docs.

Not listed
E2EE is opt-in OpenPGP, not automatic
Medium

Clear-text messages are operator-readable at rest. Users must encrypt/sign deliberately; training and policy matter for regulated content.

Not listed
Operational metadata retention
Low

Privacy policy lists IP, message-IDs, addresses, subjects, and related fields for operations, abuse control, and legal process—not a zero-logs design.

Not listed
Limited public subprocessor inventory
Low

Strong first-party claims of internal hosting, but no AWS-style public subprocessor table; confirm payment and support tooling in procurement.

Not listed
US CLOUD Act (indicative)
Low

No known US parent; Belgian self-operated hosting narrative. Residual unknown payment/SaaS paths. Not a legal safe harbour guarantee.

Not listed
Ad-financed FreeMail and consent surfaceNot listed
Medium

FreeMail uses advertising and Consent or Pay. With consent, content may feed interest profiles; FreeMail users cannot drop WEB.DE informiert like paid tiers. Unsuitable where ad-tech processors are banned.

No default end-to-end encryptionNot listed
Medium

TLS and alliance transport protection are not content E2EE. Optional PGP only covers willing counterparties. Operator can process plaintext for spam, intelligent inbox, and consented ad analysis.

Third-country transfers and portal partnersNot listed
Low

Privacy notice contemplates non-EEA recipients under Chapter V safeguards. Portal/search/ID/ad features introduce extra processors beyond the mailbox DC story—review consent layer and purpose before sensitive use.

FreeMail inactivity content deletionNot listed
Low

Privacy notice: FreeMail email content may be deleted after more than 180 days without login. Not a durable archive without activity or export.

Fit

Mailfence

Best fit when

  • You need OpenPGP interoperability and digital signatures from a European webmail, not only proprietary E2EE
  • Belgian legal entity and self-described self-operated Belgian hosting are procurement requirements
  • Teams want mail plus calendar/documents/groups without moving to Microsoft 365 or Google Workspace
  • You need custom domains, aliases, and classic clients (IMAP/POP/ActiveSync) on paid tiers
  • Business buyers evaluating private-label, API provisioning, SSO/directory integration, or large-scale on-prem license

Poor fit when

  • Security policy requires a published independent security audit, ISO 27001, or SOC 2 from the email vendor
  • You want fully open-source server/client stacks you can fork and self-host as default
  • Every message must be automatically E2EE with no OpenPGP key UX (Tuta-style)
  • You need Microsoft-class DLP, eDiscovery, compliance archives, and deep SaaS integrations
  • Zero-logs marketing is a hard requirement (Mailfence documents operational metadata collection)

Consider instead when

  • When: You want automatic encryption for all messages with minimal key management

    Consider: Tuta

    Different crypto model; less OpenPGP interop emphasis than Mailfence.

  • When: You want a larger Swiss privacy suite brand and ecosystem apps

    Consider: Proton Mail

    Trade Belgian ContactOffice ownership and PGP-centric UX for Proton’s broader product family.

  • When: You want a lean German ad-free mailbox without suite features

    Consider: Posteo or mailbox.org

    Simpler mailbox posture; different admin/domain/crypto tradeoffs.

  • When: You need full Google/Microsoft productivity and compliance tooling

    Consider: Microsoft 365 or Google Workspace (accept US-cloud risk) or EU office suites if residency is the driver

    Mailfence is not a drop-in M365 replacement.

web.de

Best fit when

  • German consumers who want a familiar .de freemail address with portal news and everyday cloud storage
  • Secondary personal or family mail where DE operator and DE storage matter more than default E2EE
  • Users who value intelligent inbox sorting, package tracking, and mobile/desktop access over privacy-maximalist design
  • Teams comparing Gmail/Outlook.com alternatives on jurisdiction while accepting consumer freemail trade-offs
  • Buyers already in the United Internet ecosystem (WEB.DE / GMX) who need a consistent DACH brand

Poor fit when

  • Organizations needing primary business mail with admin console, SSO, and signed B2B DPA as standard
  • Hard requirements for default end-to-end encryption or zero advertising/tracking surface
  • Self-hosted or open-source mail stacks you operate yourself
  • Long-term cold archives on FreeMail (inactivity deletion policy)
  • Procurement policies that forbid ad-tech partners or third-country transfer language without contract exhibits

Consider instead when

  • When: You need default E2EE and a privacy-first paid mailbox

    Consider: Tuta or Proton Mail

    web.de PGP is optional and counterpart-dependent; FreeMail is ad-financed.

  • When: You want ad-free German/EU mail with strong consumer privacy posture and paid model only

    Consider: Posteo or mailbox.org

    Less portal monetization; clearer privacy-first product framing than mass freemail.

  • When: You prefer the same United Internet Mail & Media stack under another brand

    Consider: GMX Mail

    Nearly aligned trust and capability story; brand and portal mix differ.

  • When: You need Google/Microsoft-class workspace collab and enterprise compliance packs

    Consider: Gmail (Google Workspace) or Outlook.com / Microsoft 365

    Trade DE freemail residency story for US-group platforms and deeper admin tooling.

Open questions for due diligence

Mailfence

  • Will Mailfence provide a current written subprocessor list (including payment processors and any backup locations) for a company account?
  • Is any independent security assessment available under NDA for regulated buyers?
  • For Business on-prem license: exact minimum scale, support model, update cadence, and cryptographic feature parity vs SaaS?
  • Which plan tiers currently include IMAP/POP/ActiveSync and custom-domain limits for our user count?
  • How are disaster-recovery backup sites jurisdictions documented in the signed DPA annex?

web.de

  • Will 1&1 Mail & Media sign a B2B DPA and provide a current subprocessor list for mailbox and cloud processing?
  • Are there ISO 27001, C5, or independent penetration-test summaries available under NDA for Mail & Media freemail infrastructure?
  • For your use case, is FreeMail with ads acceptable, or must you force paid TrackFree/premium paths and refuse intelligent-inbox/ad consents?
  • Confirm whether any non-DE backup, support, or analytics processors touch mailbox content beyond the public privacy notice.