Migadu vs Tuta

Compare Migadu and Tuta on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Gmail, Google Workspace, Microsoft 365

Logo: Migadu

Migadu

Switzerland· Email Services

Needs review

Shortlist Migadu when you need Swiss-operated, standards IMAP/SMTP hosting with unlimited addresses across many domains under flat account quotas—especially agencies and multi-domain SMEs. Skip when you need provider E2EE defaults, contractual SLA on the default offer, mailbox 2FA, or bulk/transactional sending; consider Proton Mail/Tuta for E2EE, or mailbox.org/Mailfence/Posteo/Runbox for other European professional-mail tradeoffs.

Swiss operatorUsage-priced multi-domainSMTP/IMAP/POP3Mail hosted in FranceMulti-admin + APINo ads / no tracking
Logo: Tuta

Tuta

Germany· Email Services

Needs review

Shortlist when you need default end-to-end encrypted mail, calendar, and contacts under German law with post-quantum TutaCrypt and official multi-platform apps. Skip when teams must keep Outlook/Thunderbird via IMAP or need a full M365/Workspace suite—consider Proton Mail (Bridge) or mailbox.org instead.

Default mailbox E2EETutaCrypt post-quantumEU-operated (Germany)Open-source clientsDE data centers (claimed)No IMAP (by design)
Migadu vs Tuta: Snapshot
FeatureLogo: MigaduMigaduLogo: TutaTuta
Country of originSwitzerlandGermany
CategoryEmail ServicesEmail Services
Open sourceNoYes
Self-hostedNoNo
HeadquartersSwitzerlandGermany
Legal entityMigadu-Mail GmbHTutao GmbH (HRB 208014, Hanover)
Governing lawCanton of Appenzell Ausserrhoden, Swiss Confederation (terms)German law / GDPR
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)MediumLow
Hosting / residencyMail servers stated in France (EU). Payment subprocessors Stripe and PayPal (US) for billing data. Full mail infrastructure/backup subprocessor list not published by name on primary pages.Vendor states mailbox data is stored end-to-end encrypted on Tutao-operated servers in ISO 27001-certified data centers in Germany. No AWS/GCP/Azure primary hosting named on official security/privacy pages. Privacy statement discloses payment processing via PayPal (Europe) and banks for card/SEPA; no comprehensive public subprocessor list found for ops tools.
Summary

Swiss-operated, standards-based email hosting for custom domains: unlimited addresses and multi-domain accounts priced by usage quotas, not per mailbox.

German end-to-end encrypted email, calendar, and contacts from Tutao GmbH in Hanover—with post-quantum TutaCrypt, open-source clients, and freemium personal plus business plans.

Tags
At a glance: Migadu vs Tuta
At a glanceLogo: MigaduMigaduLogo: TutaTuta
HQ / entityMigadu-Mail GmbH, SwitzerlandNot listed
Founded2014 (vendor About)Not listed
Mail hostingData centers in France (vendor Pro/Cons)Not listed
Commercial modelFlat per-account plans by daily message quotas + soft storageFreemium personal + paid personal/business (no ads)
Open source product?No — built on open-source stack; service is proprietary SaaSNot listed
Self-hostNoNot listed
OwnershipBootstrapped; no outside capital (vendor claim)Not listed
HQNot listedHanover, Germany (Tutao GmbH)
ProductNot listedEncrypted email, calendar, contacts (SaaS)
HostingNot listedOwn servers in ISO 27001 data centers in Germany (vendor claim)
Open sourceNot listedClients GPLv3 on GitHub; no productized self-host
ProtocolsNot listedNo IMAP/SMTP client access; official apps only
CryptoNot listedTutaCrypt hybrid (Kyber-1024 + X25519 + AES-256) for new accounts
Key capabilities: Migadu vs Tuta
Key capabilitiesLogo: MigaduMigaduLogo: TutaTuta
Swiss operatorYesNot listed
Usage-priced multi-domainYesNot listed
SMTP/IMAP/POP3YesNot listed
Mail hosted in FranceYesNot listed
Multi-admin + APIYesNot listed
No ads / no trackingYesNot listed
Default mailbox E2EENot listedYes
TutaCrypt post-quantumNot listedYes
EU-operated (Germany)Not listedYes
Open-source clientsNot listedYes
DE data centers (claimed)Not listedYes
No IMAP (by design)Not listedYes

Migadu

  • Usage-metered accounts with unlimited addresses

    Plans are flat per Migadu account. Within daily in/out quotas and soft storage guidance, create large numbers of mailboxes and host many domains without per-address fees—useful for agencies and multi-project teams. Soft storage does not hard-bounce mail; sustained over-quota use can force upgrades or limits.

  • Standards SMTP, IMAP4, POP3, and webmail

    No proprietary client protocol. Connect Thunderbird, Apple Mail, Outlook, mutt, and others over TLS (typical endpoints imap.migadu.com:993, smtp.migadu.com:465, pop.migadu.com:995). ManageSieve filtering, aliases, pattern rewrites, identities, footers, auto-responders, and optional catch-alls cover classic postmaster needs. Data remains portable via standard protocols.

  • Multi-domain admin, multi-admin, and beta API

    Agencies can hold many client domains under one roof, open multiple administrators (domain-scoped on higher plans), set per-domain/mailbox limits, and monitor traffic. A REST API (documented as early beta) manages domains, mailboxes, identities, forwardings, aliases, and rewrites for automation. Domain deletion stays UI-only as a safety measure.

  • DNS helpers and postmaster-style support

    Optional built-in DNS ships mail records preconfigured; Migadu also offers DNS setup help at no extra fee and publishes diagnostics/activation flows. Support is ticket-based from people who operate the mail stack—not outsourced chat—with plan-dependent urgency outside office hours.

  • No ads, no product analytics cookies

    Vendor policy states no advertising, no tracking of mailbox content for ads, and no website analytics cookies beyond session needs. Processing is framed for service delivery, abuse prevention, and legal obligations. Payment data still goes to Stripe and PayPal under separate processor terms.

Tuta

  • Default E2EE for mail, subjects, and attachments

    Between Tuta users, messages encrypt automatically including subject lines, bodies, and attachments. External recipients can use a shared password for end-to-end threads without installing software. Contacts and calendars use the same zero-access model; only delivery metadata (addresses, timestamps) stays readable by design.

  • TutaCrypt post-quantum hybrid cryptography

    New accounts use TutaCrypt: Kyber-1024 KEM plus X25519 ECDH with AES-256, targeting harvest-now-decrypt-later risks. Protocol details are published; existing accounts migrate as key rotation rolls out. Tuta intentionally avoids PGP so subjects and non-mail features can stay encrypted and algorithms can be upgraded in-product.

  • Zero-knowledge calendar with private reminders

    Calendar events—including times, titles, locations, and attendees—are end-to-end encrypted. Reminders are pushed as encrypted payloads and fired locally so servers are not told when an event starts. Sharing stays encrypted; invites can go out via mail, optionally password-protected for externals.

  • Open-source multi-platform clients (no IMAP)

    Web, Android (Play and F-Droid), iOS, Windows, macOS, and Linux clients are published under GPLv3 on GitHub. Desktop builds are signed for verification. There is no IMAP/SMTP bridge: third-party mail apps cannot connect, which preserves encryption at rest but forces a client switch for Outlook/Thunderbird holdouts.

  • Business domains, admin console, and whitelabel

    Paid business plans add custom domains, aliases, shared mailboxes, multi-admin roles, password/2FA resets, catch-all, templates, and optional branding/login on your own site. Vendor-stated uptime SLA and a GDPR order-processing agreement support B2B procurement—confirm current plan matrix on tuta.com.

Assurance & compliance: Migadu vs Tuta
Assurance & complianceLogo: MigaduMigaduLogo: TutaTuta
Independent security / no-logs audit
Not found

Vendor claims no ad scanning/sharing of mail content; no public third-party audit PDF located.

Vendor claimed

Vendor states SySS GmbH penetration testing before public release; not a continuously published annual no-logs audit PDF on the marketing site.

ISO 27001
Not found

Data centers described as internationally certified; no Migadu-organization ISO 27001 certificate found on primary pages.

Partial

Official pages claim data centers are ISO 27001 certified; does not clearly establish a public Tutao GmbH organizational ISO 27001 certificate.

SOC 2 / SOC 3
Not found
Not found

No SOC 2/3 report located on security, business, or privacy pages.

GDPR / EU data protection
Vendor claimed

Privacy policy asserts GDPR and Swiss DPA compliance; mail hosted in France per vendor.

Vendor claimed

German controller Tutao GmbH; privacy statement cites GDPR; DPO published; DE storage claimed.

US CLOUD Act exposure (indicative)
Partial

Swiss entity, no known US parent, mail in France; Stripe and PayPal process payments with US transfers. Infrastructure subprocessors not fully named. EuropeanStack assessment—not a vendor certification. Not legal advice.

Partial

EU entity, no known US parent, primary mailbox hosting claimed as own DE servers—not AWS/GCP/Azure. Payment may use PayPal (Europe). Assessment is low exposure for content with residual billing/processor unknowns; not a vendor 'safe' claim. Not legal advice.

Data processing agreement (B2B)
Vendor claimed

Privacy page states it serves as privacy policy and DPA; confirm suitability with counsel.

Vendor claimed

Security/business materials state an Order Processing Agreement (Auftragsverarbeitung) is provided for GDPR; obtain signed version via sales—no public self-serve DPA URL confirmed.

EU AI Act
Not applicable

Email hosting product; not an AI system offering.

Not applicable

Encrypted email/calendar product; vendor states it does not plan AI that processes user communications for model training.

Considerations & known limitations: Migadu vs Tuta
Considerations & known limitationsLogo: MigaduMigaduLogo: TutaTuta
US payment subprocessors (Stripe, PayPal)
Medium

Billing-related personal data can transfer to US processors under Migadu’s privacy policy. Mail content path is France/EU per vendor, but payment data is a separate CLOUD Act / transfer surface.

Not listed
Incomplete public infrastructure subprocessor list
Medium

Primary pages name France hosting and certified DCs without a full vendor inventory for compute, storage, and backups. Procurement should request the current list and regions in writing.

Not listed
No E2EE product default; no classic mailbox 2FA
Medium

Standards mail with TLS; vendor recommends user-side OpenPGP for strong content secrecy. IMAP 2FA is not offered; app-specific-style identities are not second-factor MFA.

Not listed
Daily quotas and human-mail policy
Medium

Account-wide daily in/out caps and anti-bulk rules make Migadu unsuitable as a transactional/marketing ESP. Over-limit mail can be deferred or rejected after tolerance.

Not listed
No default SLA on standard plans
Low

Vendor states standard offers lack SLAs; email is treated as asynchronous and occasionally disrupted. Enterprise SLA only via separate commercial discussion.

Not listed
No public independent security audit
Medium

Privacy and no-ad-scanning claims are first-party. No independent audit report found for no-logs or security controls.

Not listed
No IMAP/SMTP third-party clientsNot listed
High

Desktop and mobile holdouts cannot stay on Outlook/Thunderbird/Apple Mail. Plan full client migration or pick a standards-based alternative.

Weaker protection to non-Tuta recipientsNot listed
Medium

Without a shared password, external mail is ordinary SMTP (TLS in transit). Only Tuta-to-Tuta and password-protected external threads are true E2EE.

Hosted service, not on-prem mailNot listed
Medium

Open-source clients help inspectability, but mailboxes still depend on Tutao's German SaaS backend, uptime, and German legal process.

Data-center ISO vs company ISMSNot listed
Low

ISO 27001 wording refers to data centers. Do not tick 'vendor ISO 27001 certified' on questionnaires without the actual Tutao certificate.

Limited public subprocessor inventoryNot listed
Medium

Privacy policy covers payments (e.g. PayPal Europe) but lacks a detailed live subprocessor register. Request the DPA annex for DPIA completeness.

German court orders on accessible dataNot listed
Low

Transparency reports show regular German requests. Stored E2EE content stays undecryptable by Tutao; real-time monitoring can expose newly arriving unencrypted SMTP mail. Align expectations with counsel.

Fit

Migadu

Best fit when

  • Agencies and freelancers hosting many client domains under one account with multi-admin or API provisioning
  • Organizations that want custom-domain mail with standard clients and portable IMAP—not a proprietary suite lock-in
  • Teams tired of per-seat pricing for large address spaces with modest real traffic
  • Buyers who value a small bootstrapped Swiss operator that publishes blunt product limits
  • Setups that need aliases, rewrites, identities, SIEVE, and postmaster-style controls more than collab apps

Poor fit when

  • Primary need is end-to-end encrypted mail by default (Proton Mail, Tuta, or user-side OpenPGP workflows)
  • High-volume transactional, marketing, or bulk outbound mail
  • Requirement for default contractual SLA, phone support, or multi-language admin UI
  • Mandatory mailbox 2FA on every IMAP login
  • Want a free long-term plan or Migadu-branded @provider addresses without owning a domain

Consider instead when

  • When: You need provider-managed end-to-end encryption as the default product promise

    Consider: Proton Mail or Tuta

    Migadu is standards hosting with TLS; content secrecy against the operator is not the design center.

  • When: You want another European professional host with a different admin/encryption/residency package

    Consider: mailbox.org, Mailfence, Posteo, or Runbox

    Compare DPA detail, audit packaging, and whether multi-domain usage pricing still wins for your address sprawl.

  • When: You need full workspace suite (docs, meet, identity) rather than email hosting alone

    Consider: Google Workspace, Microsoft 365, or Infomaniak-style European suites

    Migadu deliberately stays postmaster-focused.

  • When: You need bulk or high-rate application email

    Consider: A dedicated ESP (not Migadu); Amazon SES is the common Big Tech baseline—pair with EU ESPs if residency matters

    Migadu rate-limits and bans intentional bulk use.

Tuta

Best fit when

  • Teams that will standardize on Tuta's official web/mobile/desktop clients for default zero-access email
  • Orgs prioritizing subject-line encryption, encrypted calendar, and post-quantum hybrid crypto under German jurisdiction
  • SMEs needing custom domains, aliases, shared mailboxes, and multi-admin controls without running their own mail servers
  • Journalists, NGOs, and privacy-led departments that value F-Droid builds, no Google Push dependency, and ad-free operation
  • Buyers who want open-source client auditability plus a freemium path for personal trial before business seats

Poor fit when

  • Hard requirement for IMAP/SMTP in Outlook, Thunderbird, Apple Mail, or third-party automation
  • On-prem / customer-operated mail server mandates (no productized self-host for the backend)
  • Workflows that depend on first-class PGP or S/MIME interoperability with external partners
  • Primary need is full Google Workspace or Microsoft 365 collaboration (Drive, Meet, deep Outlook) rather than encrypted mail first

Consider instead when

  • When: Users must keep desktop IMAP clients or need Bridge-style Outlook integration

    Consider: Proton Mail (Bridge on paid plans) or mailbox.org / Posteo / Soverin

    Those options trade Tuta's automatic subject E2EE model for standards-based access

  • When: You need a broader German digital workplace (Drive, Office, video) with optional PGP

    Consider: mailbox.org

    Stronger suite breadth; different default encryption depth than Tuta's full zero-access mailbox

  • When: Swiss jurisdiction and multi-product privacy suite (VPN, drive, pass) matter more than German HQ

    Consider: Proton Mail

    Compare Bridge, ecosystem lock-in, and published cert posture side by side

  • When: Belgian OpenPGP-centric suite with browser crypto and classic protocols is preferred

    Consider: Mailfence

    Different encryption UX (PGP-oriented) versus Tuta's automatic proprietary stack

Open questions for due diligence

Migadu

  • What are the current named mail hosting, backup, and ancillary subprocessors and their countries?
  • Can Migadu provide ISO/SOC evidence for the organization or only DC-level certifications?
  • Is an independent security or penetration-test summary available under NDA?
  • Does the privacy-page DPA meet your controller’s mandatory clauses without a separate signed agreement?
  • What encryption-at-rest and key-management practices apply today versus the older public pro/con narrative?

Tuta

  • Will Tutao provide a current signed AVV/DPA with a full subprocessor list (DNS, billing, support, CDN if any)?
  • Is there a current organizational ISO 27001 or SOC 2 report for Tutao GmbH, or only facility-level data-center certification?
  • What is the documented status of TutaCrypt key rotation for all legacy accounts in your tenant?
  • Are any US-group cloud services used for backups, DNS, or support tooling beyond payment processors named in the privacy statement?
  • For business rollout: migration tooling limits (EML/MBOX import on desktop) and dual-running period with legacy IMAP hosts?