Migadu vs Posteo

Compare Migadu and Posteo on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Gmail

Logo: Migadu

Migadu

Switzerland· Email Services

Needs review

Shortlist Migadu when you need Swiss-operated, standards IMAP/SMTP hosting with unlimited addresses across many domains under flat account quotas—especially agencies and multi-domain SMEs. Skip when you need provider E2EE defaults, contractual SLA on the default offer, mailbox 2FA, or bulk/transactional sending; consider Proton Mail/Tuta for E2EE, or mailbox.org/Mailfence/Posteo/Runbox for other European professional-mail tradeoffs.

Swiss operatorUsage-priced multi-domainSMTP/IMAP/POP3Mail hosted in FranceMulti-admin + APINo ads / no tracking
Logo: Posteo

Posteo

Germany· Email Services

Needs review

Shortlist when you want a paid German mailbox on self-operated servers, open protocols (IMAP/CalDAV), and extreme data minimisation (no inventory data, unlinked payments). Skip when you need custom domains, default E2EE without setup, multi-seat enterprise admin, or an Art. 28 DPA—consider Proton Mail, Tuta, mailbox.org, or Mailfence instead.

Self-operated DE serversData-minimising signupIMAP / CalDAV / CardDAVBSI TR-03108 (verified)Optional crypto mail storageAd-free, user-funded
Migadu vs Posteo: Snapshot
FeatureLogo: MigaduMigaduLogo: PosteoPosteo
Country of originSwitzerlandGermany
CategoryEmail ServicesEmail Services
Open sourceNoYes
Self-hostedNoNo
HeadquartersSwitzerlandGermany
Legal entityMigadu-Mail GmbHPosteo e.K., Methfesselstr. 38, 10965 Berlin
Governing lawCanton of Appenzell Ausserrhoden, Swiss Confederation (terms)German / EU law (GDPR, BDSG, telecom secrecy / TTDSG as applicable)
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)MediumLow
Hosting / residencyMail servers stated in France (EU). Payment subprocessors Stripe and PayPal (US) for billing data. Full mail infrastructure/backup subprocessor list not published by name on primary pages.Self-operated infrastructure; stored mail and backups in Germany (Frankfurt, Bielefeld, Berlin DCs per privacy materials). No AWS/GCP/Azure listed for mailbox hosting. Payment top-ups may use PayPal/card networks (unlinked from accounts per Posteo).
Summary

Swiss-operated, standards-based email hosting for custom domains: unlimited addresses and multi-domain accounts priced by usage quotas, not per mailbox.

Independent Berlin email provider with self-operated German servers, data-minimising signup, open-standard clients, and layered optional encryption—not a free-tier ad network.

Tags
At a glance: Migadu vs Posteo
At a glanceLogo: MigaduMigaduLogo: PosteoPosteo
HQ / entityMigadu-Mail GmbH, SwitzerlandNot listed
Founded2014 (vendor About)2009
Mail hostingData centers in France (vendor Pro/Cons)Not listed
Commercial modelFlat per-account plans by daily message quotas + soft storagePrepaid paid service; no free tier
Open source product?No — built on open-source stack; service is proprietary SaaSNot listed
Self-hostNoNo (hosted service)
OwnershipBootstrapped; no outside capital (vendor claim)Not listed
HQNot listedBerlin, Germany
Legal entityNot listedPosteo e.K. (HRA 47592 B)
HostingNot listedSelf-operated servers in Germany
ProtocolsNot listedIMAP, POP3, SMTP, CalDAV, CardDAV
EnergyNot listed100% green energy (Green Planet Energy, claimed)
Key capabilities: Migadu vs Posteo
Key capabilitiesLogo: MigaduMigaduLogo: PosteoPosteo
Swiss operatorYesNot listed
Usage-priced multi-domainYesNot listed
SMTP/IMAP/POP3YesNot listed
Mail hosted in FranceYesNot listed
Multi-admin + APIYesNot listed
No ads / no trackingYesNot listed
Self-operated DE serversNot listedYes
Data-minimising signupNot listedYes
IMAP / CalDAV / CardDAVNot listedYes
BSI TR-03108 (verified)Not listedYes
Optional crypto mail storageNot listedYes
Ad-free, user-fundedNot listedYes

Migadu

  • Usage-metered accounts with unlimited addresses

    Plans are flat per Migadu account. Within daily in/out quotas and soft storage guidance, create large numbers of mailboxes and host many domains without per-address fees—useful for agencies and multi-project teams. Soft storage does not hard-bounce mail; sustained over-quota use can force upgrades or limits.

  • Standards SMTP, IMAP4, POP3, and webmail

    No proprietary client protocol. Connect Thunderbird, Apple Mail, Outlook, mutt, and others over TLS (typical endpoints imap.migadu.com:993, smtp.migadu.com:465, pop.migadu.com:995). ManageSieve filtering, aliases, pattern rewrites, identities, footers, auto-responders, and optional catch-alls cover classic postmaster needs. Data remains portable via standard protocols.

  • Multi-domain admin, multi-admin, and beta API

    Agencies can hold many client domains under one roof, open multiple administrators (domain-scoped on higher plans), set per-domain/mailbox limits, and monitor traffic. A REST API (documented as early beta) manages domains, mailboxes, identities, forwardings, aliases, and rewrites for automation. Domain deletion stays UI-only as a safety measure.

  • DNS helpers and postmaster-style support

    Optional built-in DNS ships mail records preconfigured; Migadu also offers DNS setup help at no extra fee and publishes diagnostics/activation flows. Support is ticket-based from people who operate the mail stack—not outsourced chat—with plan-dependent urgency outside office hours.

  • No ads, no product analytics cookies

    Vendor policy states no advertising, no tracking of mailbox content for ads, and no website analytics cookies beyond session needs. Processing is framed for service delivery, abuse prevention, and legal obligations. Payment data still goes to Stripe and PayPal under separate processor terms.

Posteo

  • Signup without identity data; payments unlinked

    Accounts can be created without name, address, or phone. Posteo's payment system (bank transfer codes, cash, card, PayPal) is designed so payment identifiers are not stored against the mailbox. Practical limit: recovery options you add yourself and how you fund the prepaid balance still affect anonymity in the real world.

  • Optional crypto mail storage for the whole mailbox

    One setting encrypts stored messages—including metadata—with a key protected by the account password (RSA/AES/HMAC/bcrypt design; Dovecot plugin). Posteo states it cannot disable crypto storage once enabled and cites a Cure53 review. Limit: this is server-side encryption at rest after delivery, not sender-to-recipient E2EE, and losing the password can mean losing access to encrypted data.

  • TLS, DANE, and BSI-certified secure transport

    Access is TLS-only with PFS, HSTS, and DANE/TLSA. Optional TLS-sending/receiving guarantees refuse delivery over cleartext peer links. Posteo holds BSI TR-03108 v2 Secure Email Transport certification (BSI-K-TR-0745-2025). Transport quality still depends on the remote provider's stack.

  • CalDAV/CardDAV with optional password encryption

    Calendars and contacts sync via open standards and can be AES-encrypted in Posteo's database so the provider cannot read them when the feature is on. Trade-off: encrypted calendars cannot be shared the same way, and password reset without the old secret can lock you out of encrypted PIM data.

  • In-house migration without third-party movers

    Posteo's own migration tool pulls mail (and often contacts/calendars) over encrypted links from previous providers without routing through a third-party migration SaaS. Quota: a limited number of migrations per account, with an optional collector for ongoing fetch from the old box.

Assurance & compliance: Migadu vs Posteo
Assurance & complianceLogo: MigaduMigaduLogo: PosteoPosteo
Independent security / no-logs audit
Not found

Vendor claims no ad scanning/sharing of mail content; no public third-party audit PDF located.

Partial

BfDI on-site privacy inspection (2016) confirmed data-minimisation / no inventory IP model (public PDF). Crypto mail storage: vendor cites Cure53 multi-level audit; full public report not located. Not a continuous independent no-logs certification programme.

ISO 27001
Not found

Data centers described as internationally certified; no Migadu-organization ISO 27001 certificate found on primary pages.

Not found

No ISO 27001 claim found on primary Posteo security/privacy pages.

SOC 2 / SOC 3
Not found
Not found

No SOC 2/3 report advertised on primary pages.

GDPR / EU data protection
Vendor claimed

Privacy policy asserts GDPR and Swiss DPA compliance; mail hosted in France per vendor.

Vendor claimed

German entity; privacy policy cites GDPR/BDSG/telecom secrecy; DPO published; BfDI inspection history.

US CLOUD Act exposure (indicative)
Partial

Swiss entity, no known US parent, mail in France; Stripe and PayPal process payments with US transfers. Infrastructure subprocessors not fully named. EuropeanStack assessment—not a vendor certification. Not legal advice.

Partial

EuropeanStack assessment: German e.K., no known US parent, self-operated DE hosting with no public US-cloud mailbox subprocessors → indicative exposure low. Status is partial (not a clean bill): payment rails and lawful German disclosure remain. Not legal advice.

Data processing agreement (B2B)
Vendor claimed

Privacy page states it serves as privacy policy and DPA; confirm suitability with counsel.

Not found

Vendor states it is not an Art. 28 processor as a public electronic communications service and does not offer customer DPAs.

EU AI Act
Not applicable

Email hosting product; not an AI system offering.

Not applicable

Conventional email/PIM service; not an AI product.

BSI TR-03108 Secure Email TransportNot listed
Verified

BSI certificate BSI-K-TR-0745-2025 (OpenSource Security GmbH audit; valid through 2030 per BSI listing).

Considerations & known limitations: Migadu vs Posteo
Considerations & known limitationsLogo: MigaduMigaduLogo: PosteoPosteo
US payment subprocessors (Stripe, PayPal)
Medium

Billing-related personal data can transfer to US processors under Migadu’s privacy policy. Mail content path is France/EU per vendor, but payment data is a separate CLOUD Act / transfer surface.

Not listed
Incomplete public infrastructure subprocessor list
Medium

Primary pages name France hosting and certified DCs without a full vendor inventory for compute, storage, and backups. Procurement should request the current list and regions in writing.

Not listed
No E2EE product default; no classic mailbox 2FA
Medium

Standards mail with TLS; vendor recommends user-side OpenPGP for strong content secrecy. IMAP 2FA is not offered; app-specific-style identities are not second-factor MFA.

Not listed
Daily quotas and human-mail policy
Medium

Account-wide daily in/out caps and anti-bulk rules make Migadu unsuitable as a transactional/marketing ESP. Over-limit mail can be deferred or rejected after tolerance.

Not listed
No default SLA on standard plans
Low

Vendor states standard offers lack SLAs; email is treated as asynchronous and occasionally disrupted. Enterprise SLA only via separate commercial discussion.

Not listed
No public independent security audit
Medium

Privacy and no-ad-scanning claims are first-party. No independent audit report found for no-logs or security controls.

Not listed
No custom domainsNot listed
High

Posteo will not host your own domain. Organisations needing brand continuity or provider portability via DNS must pick another host or self-host.

Encryption is layered, not default E2EENot listed
Medium

Without crypto mail storage, inbound encryption, or client-side PGP/S/MIME, Posteo can process mailbox content like a normal provider. Lawful intercept (TKU) and seizures remain possible under German process; transparency reports show content releases do occur under court order.

No customer Art. 28 DPANot listed
Medium

Procurement checklists that require a signed processor agreement will stall. Posteo argues telecom special law applies instead; validate with legal counsel for your use case.

Password loss risk with crypto featuresNot listed
Medium

Crypto mail storage and encrypted calendars/contacts depend on the account password; Posteo cannot recover plaintext if that secret is lost after encryption is enabled.

Payment processors outside pure DE mail pathNot listed
Low

Optional PayPal/card top-ups involve non-German commercial processors even though Posteo says it does not link payment identity to the mailbox. Cash/bank-code paths reduce that linkage further.

Fit

Migadu

Best fit when

  • Agencies and freelancers hosting many client domains under one account with multi-admin or API provisioning
  • Organizations that want custom-domain mail with standard clients and portable IMAP—not a proprietary suite lock-in
  • Teams tired of per-seat pricing for large address spaces with modest real traffic
  • Buyers who value a small bootstrapped Swiss operator that publishes blunt product limits
  • Setups that need aliases, rewrites, identities, SIEVE, and postmaster-style controls more than collab apps

Poor fit when

  • Primary need is end-to-end encrypted mail by default (Proton Mail, Tuta, or user-side OpenPGP workflows)
  • High-volume transactional, marketing, or bulk outbound mail
  • Requirement for default contractual SLA, phone support, or multi-language admin UI
  • Mandatory mailbox 2FA on every IMAP login
  • Want a free long-term plan or Migadu-branded @provider addresses without owning a domain

Consider instead when

  • When: You need provider-managed end-to-end encryption as the default product promise

    Consider: Proton Mail or Tuta

    Migadu is standards hosting with TLS; content secrecy against the operator is not the design center.

  • When: You want another European professional host with a different admin/encryption/residency package

    Consider: mailbox.org, Mailfence, Posteo, or Runbox

    Compare DPA detail, audit packaging, and whether multi-domain usage pricing still wins for your address sprawl.

  • When: You need full workspace suite (docs, meet, identity) rather than email hosting alone

    Consider: Google Workspace, Microsoft 365, or Infomaniak-style European suites

    Migadu deliberately stays postmaster-focused.

  • When: You need bulk or high-rate application email

    Consider: A dedicated ESP (not Migadu); Amazon SES is the common Big Tech baseline—pair with EU ESPs if residency matters

    Migadu rate-limits and bans intentional bulk use.

Posteo

Best fit when

  • Individuals and small teams who want German jurisdiction and open-standard clients without Google or Microsoft mail
  • Users prioritising anonymous or low-identity signup and prepaid funding without linking payments to the mailbox
  • Organisations that accept posteo.* addresses and value no ads, no tracking, and published transparency reports
  • Operators who want optional full-mailbox encryption at rest (crypto mail storage) plus PGP/S/MIME tooling
  • Buyers who need BSI-aligned secure email transport certification rather than US SOC 2 paperwork

Poor fit when

  • Anyone requiring custom domains or branded organisational addresses
  • Teams that need default zero-access E2EE for every message without enabling optional layers
  • Procurement processes that mandate a signed Art. 28 DPA, SOC 2, or ISO 27001 from the vendor
  • Large enterprises needing multi-seat admin, shared domain policies, or deep Microsoft/Google workspace integration

Consider instead when

  • When: You need default end-to-end encryption and a broader encrypted suite

    Consider: Proton Mail or Tuta

    Posteo is IMAP-first with optional crypto layers; Proton/Tuta lead with zero-access defaults.

  • When: You need custom domains or richer business mail hosting

    Consider: mailbox.org or Mailfence

    Posteo deliberately refuses own domains to avoid inventory-data obligations.

  • When: You need free-tier consumer mail tightly integrated with docs and chat

    Consider: Gmail or Outlook.com

    Trade privacy posture and EU self-operation for ecosystem convenience.

Open questions for due diligence

Migadu

  • What are the current named mail hosting, backup, and ancillary subprocessors and their countries?
  • Can Migadu provide ISO/SOC evidence for the organization or only DC-level certifications?
  • Is an independent security or penetration-test summary available under NDA?
  • Does the privacy-page DPA meet your controller’s mandatory clauses without a separate signed agreement?
  • What encryption-at-rest and key-management practices apply today versus the older public pro/con narrative?

Posteo

  • Does your counsel accept Posteo's position that no Art. 28 DPA is required for occupational use?
  • Will posteo.de / .net / .com addresses meet your brand, deliverability, and anti-spoofing requirements without custom domains?
  • Which encryption layers (crypto mail storage, inbound PGP/S/MIME, client E2EE) will your users actually enable and support?
  • Do you need ISO 27001/SOC 2 artefacts that Posteo does not publish?
  • Is BSI TR-03108 transport certification sufficient for your sector's secure-email checklist?