Mailo vs Posteo

Compare Mailo and Posteo on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Gmail, Outlook.com

Logo: Mailo

Mailo

France· Email Services

Needs review

Shortlist Mailo when you want French-entity freemium webmail with classic IMAP/EAS clients, integrated calendar/cloud, supervised Mailo Junior for kids, or Pro custom domains for SMEs—without US Big Tech accounts. Skip when you need default zero-knowledge E2EE, open-source/self-host, or a full Workspace-class suite; consider Tuta, Proton Mail, or Infomaniak kMail instead.

France-hosted (claimed)Freemium webmailMailo JuniorIMAP / ActiveSyncPro custom domainsOptional PGP (server-side)
Logo: Posteo

Posteo

Germany· Email Services

Needs review

Shortlist when you want a paid German mailbox on self-operated servers, open protocols (IMAP/CalDAV), and extreme data minimisation (no inventory data, unlinked payments). Skip when you need custom domains, default E2EE without setup, multi-seat enterprise admin, or an Art. 28 DPA—consider Proton Mail, Tuta, mailbox.org, or Mailfence instead.

Self-operated DE serversData-minimising signupIMAP / CalDAV / CardDAVBSI TR-03108 (verified)Optional crypto mail storageAd-free, user-funded
Mailo vs Posteo: Snapshot
FeatureLogo: MailoMailoLogo: PosteoPosteo
Country of originFranceGermany
CategoryEmail ServicesEmail Services
Open sourceNoYes
Self-hostedNoNo
HeadquartersFranceGermany
Legal entityMAILO SAS (capital €75,000; RCS Créteil 851585547; VAT FR44851585547)Posteo e.K., Methfesselstr. 38, 10965 Berlin
Governing lawFrench law (terms of use)German / EU law (GDPR, BDSG, telecom secrecy / TTDSG as applicable)
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)MediumLow
Hosting / residencyVendor states user personal data and content are stored/processed on servers in France; specialised French host centre (who-we-are); website hosted by Ecritel, Arradon, France. Named third parties: Verifone/Paybox (payment email), PayPal option, Gandi/Netim (domains), Sirdata + ad agencies (free-tier ads), optional Rainbow video and OnlyOffice. Full mail DC/backup subprocessor list not published.Self-operated infrastructure; stored mail and backups in Germany (Frankfurt, Bielefeld, Berlin DCs per privacy materials). No AWS/GCP/Azure listed for mailbox hosting. Payment top-ups may use PayPal/card networks (unlinked from accounts per Posteo).
Summary

French freemium webmail and Mail&Cloud suite (MAILO SAS): email, calendar, cloud disk, Mailo Junior for children, and Pro custom domains—hosted in France, proprietary SaaS.

Independent Berlin email provider with self-operated German servers, data-minimising signup, open-standard clients, and layered optional encryption—not a free-tier ad network.

Tags
At a glance: Mailo vs Posteo
At a glanceLogo: MailoMailoLogo: PosteoPosteo
HQ / entityMAILO SAS, France (RCS Créteil 851585547)Not listed
Hosting (claimed)Servers in France; website host Ecritel (FR)Not listed
ModelFreemium SaaS (Free / Premium / Pro / Junior / Edu)Not listed
Open sourceNo (proprietary MailObject®)Not listed
Self-hostNoNo (hosted service)
Encryption defaultTLS + optional server-side PGP (not ZK E2EE)Not listed
HQNot listedBerlin, Germany
Legal entityNot listedPosteo e.K. (HRA 47592 B)
HostingNot listedSelf-operated servers in Germany
Commercial modelNot listedPrepaid paid service; no free tier
ProtocolsNot listedIMAP, POP3, SMTP, CalDAV, CardDAV
FoundedNot listed2009
EnergyNot listed100% green energy (Green Planet Energy, claimed)
Key capabilities: Mailo vs Posteo
Key capabilitiesLogo: MailoMailoLogo: PosteoPosteo
France-hosted (claimed)YesNot listed
Freemium webmailYesNot listed
Mailo JuniorYesNot listed
IMAP / ActiveSyncYesNot listed
Pro custom domainsYesNot listed
Optional PGP (server-side)YesNot listed
Self-operated DE serversNot listedYes
Data-minimising signupNot listedYes
IMAP / CalDAV / CardDAVNot listedYes
BSI TR-03108 (verified)Not listedYes
Optional crypto mail storageNot listedYes
Ad-free, user-fundedNot listedYes

Mailo

  • French-hosted webmail with IMAP, EAS, and classic protocols

    Webmail plus IMAP4 for clients, Exchange ActiveSync for mobile sync, and POP3 on paid tiers; SMTP relay with account credentials. Vendor states mail and content stay on servers in France. Free tier is ad-supported with lower quotas; Premium unlocks POP3, more aliases, and larger mail/cloud caps. Suits teams that need standard desktop/mobile clients rather than a closed proprietary app only.

  • Mailo Junior supervised email for children

    Child accounts (about ages 6–14) only exchange mail with contacts a parent or teacher validates. Age-adapted mini/junior UIs, no ads on Junior, optional promotion to a standard account while keeping the address. Separate Junior mobile apps. Unique fit for families and schools versus generic consumer mail.

  • Calendar, virtual disk, and open sync protocols

    Shared calendars and tasks, address book, photo albums, and a virtual disk for files with WebDAV/FTP access. CalDAV and CardDAV for external clients. Premium+ can unlock OnlyOffice in-browser editing. Better as an all-in-one Mail&Cloud for SMEs/families than bare IMAP-only privacy mail.

  • Mailo Pro spaces: custom domains and mutualised storage

    Pro Start/5/Modulo style plans share mail+cloud quota across accounts, support custom domains (register, transfer, or declare external), distribution lists, mailbox sharing, resource calendars, and manager tooling. Priority Pro hotline with documented acknowledgement and restoration targets for Pro subscriptions. Aimed at TPE/PME, associations, and municipalities—not a full Google Workspace clone.

  • Optional server-side PGP and account security controls

    Built-in PGP/MIME encrypt and sign in the webmail as a trusted third party (keys managed on Mailo for multi-device convenience). Two-factor authentication, application passwords, connection history, and guardianship-style access options. Not zero-knowledge E2EE by default—use external client crypto if the provider must never hold keys.

Posteo

  • Signup without identity data; payments unlinked

    Accounts can be created without name, address, or phone. Posteo's payment system (bank transfer codes, cash, card, PayPal) is designed so payment identifiers are not stored against the mailbox. Practical limit: recovery options you add yourself and how you fund the prepaid balance still affect anonymity in the real world.

  • Optional crypto mail storage for the whole mailbox

    One setting encrypts stored messages—including metadata—with a key protected by the account password (RSA/AES/HMAC/bcrypt design; Dovecot plugin). Posteo states it cannot disable crypto storage once enabled and cites a Cure53 review. Limit: this is server-side encryption at rest after delivery, not sender-to-recipient E2EE, and losing the password can mean losing access to encrypted data.

  • TLS, DANE, and BSI-certified secure transport

    Access is TLS-only with PFS, HSTS, and DANE/TLSA. Optional TLS-sending/receiving guarantees refuse delivery over cleartext peer links. Posteo holds BSI TR-03108 v2 Secure Email Transport certification (BSI-K-TR-0745-2025). Transport quality still depends on the remote provider's stack.

  • CalDAV/CardDAV with optional password encryption

    Calendars and contacts sync via open standards and can be AES-encrypted in Posteo's database so the provider cannot read them when the feature is on. Trade-off: encrypted calendars cannot be shared the same way, and password reset without the old secret can lock you out of encrypted PIM data.

  • In-house migration without third-party movers

    Posteo's own migration tool pulls mail (and often contacts/calendars) over encrypted links from previous providers without routing through a third-party migration SaaS. Quota: a limited number of migrations per account, with an optional collector for ongoing fetch from the old box.

Assurance & compliance: Mailo vs Posteo
Assurance & complianceLogo: MailoMailoLogo: PosteoPosteo
Independent security / no-logs audit
Not found

Charter claims no commercial reading of messages; automated AV/spam scanning on servers. No public third-party audit PDF found.

Partial

BfDI on-site privacy inspection (2016) confirmed data-minimisation / no inventory IP model (public PDF). Crypto mail storage: vendor cites Cure53 multi-level audit; full public report not located. Not a continuous independent no-logs certification programme.

ISO 27001
Not found

No ISO 27001 claim found on legal/security/primary pages researched.

Not found

No ISO 27001 claim found on primary Posteo security/privacy pages.

SOC 2 / SOC 3
Not found

No SOC 2/3 report referenced on public product pages.

Not found

No SOC 2/3 report advertised on primary pages.

GDPR / EU data protection
Vendor claimed

French controller; privacy rules cite GDPR and French correspondence secrecy; DPO at dpo@mailo.com; France storage claim.

Vendor claimed

German entity; privacy policy cites GDPR/BDSG/telecom secrecy; DPO published; BfDI inspection history.

US CLOUD Act exposure (indicative)
Partial

EU entity / no known US parent / France-claimed mail hosting, but Verifone and PayPal (US-group) on payment path; full infra subprocessors unpublished. Assessment only—not legal advice.

Partial

EuropeanStack assessment: German e.K., no known US parent, self-operated DE hosting with no public US-cloud mailbox subprocessors → indicative exposure low. Status is partial (not a clean bill): payment rails and lawful German disclosure remain. Not legal advice.

Data processing agreement (B2B)
Not found

Privacy rules and terms cover processing; no standalone public B2B DPA download found—request via DPO or Pro channel.

Not found

Vendor states it is not an Art. 28 processor as a public electronic communications service and does not offer customer DPAs.

EU AI Act
Not applicable

Traditional email/cloud suite; not marketed as an AI system product.

Not applicable

Conventional email/PIM service; not an AI product.

BSI TR-03108 Secure Email TransportNot listed
Verified

BSI certificate BSI-K-TR-0745-2025 (OpenSource Security GmbH audit; valid through 2030 per BSI listing).

Considerations & known limitations: Mailo vs Posteo
Considerations & known limitationsLogo: MailoMailoLogo: PosteoPosteo
PGP is server-side trusted third party
Medium

Webmail PGP holds keys on Mailo for multi-device use. Provider-access risk differs from zero-knowledge E2EE defaults at Tuta/Proton. Use external crypto if that is a hard requirement.

Not listed
Incomplete public subprocessor inventory
Medium

Privacy rules name payments, domains, and free-tier ads, but not a full list of mail storage, backup, or anti-spam infrastructure vendors. Request annex for B2B risk review.

Not listed
US-group payment processors
Low

Checkout shares email with Verifone/Paybox; PayPal is also offered. Limited to billing path per privacy rules, but relevant to CLOUD Act diligence.

Not listed
Free tier third-party advertising
Low

Mailo Free shows ad banners via agencies under IAB TCF consent (Sirdata CMP). Premium removes ads. Ad cookies stated as not tied to Mailo profile.

Not listed
No public ISO/SOC or independent security audit
Medium

Security posture relies on first-party statements and internal measures. Procurement teams may need questionnaires or NDA evidence.

Not listed
Free accounts deleted after inactivity
Low

Mailo Free unused for 365 days can be deleted with content loss. Premium/Pro have different retention rules—plan backups and renewals.

Not listed
No custom domainsNot listed
High

Posteo will not host your own domain. Organisations needing brand continuity or provider portability via DNS must pick another host or self-host.

Encryption is layered, not default E2EENot listed
Medium

Without crypto mail storage, inbound encryption, or client-side PGP/S/MIME, Posteo can process mailbox content like a normal provider. Lawful intercept (TKU) and seizures remain possible under German process; transparency reports show content releases do occur under court order.

No customer Art. 28 DPANot listed
Medium

Procurement checklists that require a signed processor agreement will stall. Posteo argues telecom special law applies instead; validate with legal counsel for your use case.

Password loss risk with crypto featuresNot listed
Medium

Crypto mail storage and encrypted calendars/contacts depend on the account password; Posteo cannot recover plaintext if that secret is lost after encryption is enabled.

Payment processors outside pure DE mail pathNot listed
Low

Optional PayPal/card top-ups involve non-German commercial processors even though Posteo says it does not link payment identity to the mailbox. Cash/bank-code paths reduce that linkage further.

Fit

Mailo

Best fit when

  • EU individuals and families wanting French-hosted mail with calendar and cloud disk in one account
  • Parents/schools needing supervised child email (Mailo Junior) with contact allow-lists
  • French SMEs, associations, and municipalities needing custom domains and mutualised Pro storage
  • Teams that depend on IMAP, EAS, CalDAV, CardDAV, or WebDAV rather than a locked-in app
  • Buyers who accept freemium ads on free tier or low-cost Premium rather than pure prepaid anonymity mail

Poor fit when

  • Orgs that require default end-to-end encryption with zero-access provider architecture
  • Buyers that need open-source server code or official self-hosting
  • Enterprises needing SOC 2 / ISO 27001 evidence already published on a trust centre
  • Heavy Google Workspace / Microsoft 365 collaboration suites (docs/drive ecosystem depth)

Consider instead when

  • When: You need zero-knowledge / default E2EE webmail

    Consider: Tuta or Proton Mail

    Mailo PGP is optional and server-side trusted third party

  • When: You want German privacy mail with different encryption/product posture

    Consider: Posteo or mailbox.org

    Compare protocols, storage bundles, and business features side by side

  • When: You need Swiss multi-product cloud with mail plus broader suite

    Consider: Infomaniak kMail

    Different country stack and product breadth

  • When: You need US Big Tech ecosystem integration at any cost

    Consider: Gmail or Microsoft 365 / Outlook.com

    Trade EU entity and France residency claims for ecosystem depth

Posteo

Best fit when

  • Individuals and small teams who want German jurisdiction and open-standard clients without Google or Microsoft mail
  • Users prioritising anonymous or low-identity signup and prepaid funding without linking payments to the mailbox
  • Organisations that accept posteo.* addresses and value no ads, no tracking, and published transparency reports
  • Operators who want optional full-mailbox encryption at rest (crypto mail storage) plus PGP/S/MIME tooling
  • Buyers who need BSI-aligned secure email transport certification rather than US SOC 2 paperwork

Poor fit when

  • Anyone requiring custom domains or branded organisational addresses
  • Teams that need default zero-access E2EE for every message without enabling optional layers
  • Procurement processes that mandate a signed Art. 28 DPA, SOC 2, or ISO 27001 from the vendor
  • Large enterprises needing multi-seat admin, shared domain policies, or deep Microsoft/Google workspace integration

Consider instead when

  • When: You need default end-to-end encryption and a broader encrypted suite

    Consider: Proton Mail or Tuta

    Posteo is IMAP-first with optional crypto layers; Proton/Tuta lead with zero-access defaults.

  • When: You need custom domains or richer business mail hosting

    Consider: mailbox.org or Mailfence

    Posteo deliberately refuses own domains to avoid inventory-data obligations.

  • When: You need free-tier consumer mail tightly integrated with docs and chat

    Consider: Gmail or Outlook.com

    Trade privacy posture and EU self-operation for ecosystem convenience.

Open questions for due diligence

Mailo

  • Will Mailo sign a GDPR Article 28 DPA with a full subprocessor and transfer annex for Pro customers?
  • What is the named primary data-centre operator and backup/DR location beyond the France and Ecritel website-host statements?
  • Is there an independent penetration test, ISO 27001 roadmap, or customer-available security whitepaper?
  • Where is Rainbow (video) and OnlyOffice data processed relative to the France mail claim?
  • Current UGAP / public procurement listing status for French public buyers?

Posteo

  • Does your counsel accept Posteo's position that no Art. 28 DPA is required for occupational use?
  • Will posteo.de / .net / .com addresses meet your brand, deliverability, and anti-spoofing requirements without custom domains?
  • Which encryption layers (crypto mail storage, inbound PGP/S/MIME, client E2EE) will your users actually enable and support?
  • Do you need ISO 27001/SOC 2 artefacts that Posteo does not publish?
  • Is BSI TR-03108 transport certification sufficient for your sector's secure-email checklist?