Posteo vs Proton Mail

Compare Posteo and Proton Mail on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Gmail, Outlook.com

Logo: Posteo

Posteo

Germany· Email Services

Needs review

Shortlist when you want a paid German mailbox on self-operated servers, open protocols (IMAP/CalDAV), and extreme data minimisation (no inventory data, unlinked payments). Skip when you need custom domains, default E2EE without setup, multi-seat enterprise admin, or an Art. 28 DPA—consider Proton Mail, Tuta, mailbox.org, or Mailfence instead.

Self-operated DE serversData-minimising signupIMAP / CalDAV / CardDAVBSI TR-03108 (verified)Optional crypto mail storageAd-free, user-funded
Logo: Proton Mail

Proton Mail

Switzerland· Email Services

Needs review

Shortlist Proton Mail when you want Swiss-jurisdiction, zero-access encrypted email with open-source clients, custom domains, Bridge for desktop mailers, and a public DPA. Skip when you need free-tier IMAP Bridge, fully self-hosted FOSS mail on your own servers, or Workspace-class collaboration depth—consider Tuta, Posteo, or Mailfence among EU peers, or stay on Google/Microsoft if suite lock-in wins.

E2EE + zero-accessSwiss-operatedBridge (IMAP/SMTP)Open-source clientsISO 27001 & SOC 2 (claimed)Public B2B DPA
Posteo vs Proton Mail: Snapshot
FeatureLogo: PosteoPosteoLogo: Proton MailProton Mail
Country of originGermanySwitzerland
CategoryEmail ServicesEmail Services
Open sourceYesNo
Self-hostedNoNo
HeadquartersGermanySwitzerland
Legal entityPosteo e.K., Methfesselstr. 38, 10965 BerlinProton AG, Route de la Galaise 32, 1228 Plan-les-Ouates, Geneva, Switzerland (EU representative: Proton Europe sàrl, Luxembourg)
Governing lawGerman / EU law (GDPR, BDSG, telecom secrecy / TTDSG as applicable)Swiss law (Terms; Geneva courts for business/non-US consumer disputes as stated in Terms)
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)LowMedium
Hosting / residencySelf-operated infrastructure; stored mail and backups in Germany (Frankfurt, Bielefeld, Berlin DCs per privacy materials). No AWS/GCP/Azure listed for mailbox hosting. Payment top-ups may use PayPal/card networks (unlinked from accounts per Posteo).Primary mail storage on Proton-owned servers in Switzerland (vendor security pages). Not marketed as AWS/GCP/Azure inbox hosting. Public privacy policy lists US-group processors for support and payments (Zendesk; Chargebee, Stripe, PayPal) and group support processing in North Macedonia and Taiwan; HubSpot noted for business sales inquiries.
Summary

Independent Berlin email provider with self-operated German servers, data-minimising signup, open-standard clients, and layered optional encryption—not a free-tier ad network.

Swiss end-to-end encrypted email from Proton AG: zero-access inbox storage, open-source clients, custom domains, and Bridge for desktop IMAP clients.

Tags
At a glance: Posteo vs Proton Mail
At a glanceLogo: PosteoPosteoLogo: Proton MailProton Mail
HQBerlin, GermanyPlan-les-Ouates (Geneva), Switzerland
Legal entityPosteo e.K. (HRA 47592 B)Proton AG (CHE-354.686.492); Proton Foundation supervision
HostingSelf-operated servers in GermanyNot listed
Commercial modelPrepaid paid service; no free tierFreemium + paid consumer and business seats
ProtocolsIMAP, POP3, SMTP, CalDAV, CardDAVNot listed
Self-hostNo (hosted service)No (SaaS); clients open source
Founded2009Not listed
Energy100% green energy (Green Planet Energy, claimed)Not listed
Hosting modelNot listedProton-owned hardware in Switzerland (vendor claim)
BridgeNot listedPaid plans that include Mail
Key capabilities: Posteo vs Proton Mail
Key capabilitiesLogo: PosteoPosteoLogo: Proton MailProton Mail
Self-operated DE serversYesNot listed
Data-minimising signupYesNot listed
IMAP / CalDAV / CardDAVYesNot listed
BSI TR-03108 (verified)YesNot listed
Optional crypto mail storageYesNot listed
Ad-free, user-fundedYesNot listed
E2EE + zero-accessNot listedYes
Swiss-operatedNot listedYes
Bridge (IMAP/SMTP)Not listedYes
Open-source clientsNot listedYes
ISO 27001 & SOC 2 (claimed)Not listedYes
Public B2B DPANot listedYes

Posteo

  • Signup without identity data; payments unlinked

    Accounts can be created without name, address, or phone. Posteo's payment system (bank transfer codes, cash, card, PayPal) is designed so payment identifiers are not stored against the mailbox. Practical limit: recovery options you add yourself and how you fund the prepaid balance still affect anonymity in the real world.

  • Optional crypto mail storage for the whole mailbox

    One setting encrypts stored messages—including metadata—with a key protected by the account password (RSA/AES/HMAC/bcrypt design; Dovecot plugin). Posteo states it cannot disable crypto storage once enabled and cites a Cure53 review. Limit: this is server-side encryption at rest after delivery, not sender-to-recipient E2EE, and losing the password can mean losing access to encrypted data.

  • TLS, DANE, and BSI-certified secure transport

    Access is TLS-only with PFS, HSTS, and DANE/TLSA. Optional TLS-sending/receiving guarantees refuse delivery over cleartext peer links. Posteo holds BSI TR-03108 v2 Secure Email Transport certification (BSI-K-TR-0745-2025). Transport quality still depends on the remote provider's stack.

  • CalDAV/CardDAV with optional password encryption

    Calendars and contacts sync via open standards and can be AES-encrypted in Posteo's database so the provider cannot read them when the feature is on. Trade-off: encrypted calendars cannot be shared the same way, and password reset without the old secret can lock you out of encrypted PIM data.

  • In-house migration without third-party movers

    Posteo's own migration tool pulls mail (and often contacts/calendars) over encrypted links from previous providers without routing through a third-party migration SaaS. Quota: a limited number of migrations per account, with an optional collector for ongoing fetch from the old box.

Proton Mail

  • Zero-access inbox encryption by default

    Bodies and attachments are encrypted so Proton states it lacks keys to read stored mail. Proton-to-Proton traffic is end-to-end encrypted automatically; external recipients need password-protected messages or PGP/WKD for comparable content protection. Subject lines are not fully E2EE under OpenPGP header rules.

  • Proton Mail Bridge for desktop IMAP clients

    Paid plans that include Mail can run Bridge locally to connect Outlook, Thunderbird, or Apple Mail over IMAP/SMTP while encrypting and decrypting on the device. Free accounts use official web/mobile/desktop apps instead of Bridge.

  • Custom domains, aliases, and business admin

    Paid and business tiers support custom domains, extra addresses, catch-all and groups, hide-my-email aliases, and org admin for seats, storage, and retention policies. Suits teams leaving Google/Microsoft who still need branded addresses.

  • Open-source clients with published audits

    Web, mobile, and desktop clients are published on GitHub with third-party audit reports linked from Proton’s open-source page. The hosted mail backend is not offered as self-hosted FOSS—audit client trust, not full server reproducibility.

  • Tracker blocking, PhishGuard, and Sentinel

    Built-in tracker protection, phishing heuristics, link confirmation, SPF/DKIM/DMARC for custom domains, hardware-key 2FA, and optional Proton Sentinel monitoring for high-risk accounts. Complements encryption with everyday abuse defenses.

Assurance & compliance: Posteo vs Proton Mail
Assurance & complianceLogo: PosteoPosteoLogo: Proton MailProton Mail
Independent security / no-logs audit
Partial

BfDI on-site privacy inspection (2016) confirmed data-minimisation / no inventory IP model (public PDF). Crypto mail storage: vendor cites Cure53 multi-level audit; full public report not located. Not a continuous independent no-logs certification programme.

Vendor claimed

Open-source clients with published third-party audit reports (web/desktop links on open-source page). Not a classic VPN no-logs court test; transparency report covers legal orders for accessible account data.

ISO 27001
Not found

No ISO 27001 claim found on primary Posteo security/privacy pages.

Vendor claimed

Vendor announces ISO 27001 certification after external audit completed 2 May 2024; Trust Center links a certificate download. Confirm scope and validity at procurement time.

SOC 2 / SOC 3
Not found

No SOC 2/3 report advertised on primary pages.

Vendor claimed

Vendor announces first SOC 2 Type II attestation (July 2025 blog). Report typically under NDA—request from vendor for diligence files.

GDPR / EU data protection
Vendor claimed

German entity; privacy policy cites GDPR/BDSG/telecom secrecy; DPO published; BfDI inspection history.

Vendor claimed

Swiss controller/processor with EU representative; public DPA; GDPR materials for business. Adequacy/transfer mechanisms documented for non-adequate destinations.

US CLOUD Act exposure (indicative)
Partial

EuropeanStack assessment: German e.K., no known US parent, self-operated DE hosting with no public US-cloud mailbox subprocessors → indicative exposure low. Status is partial (not a clean bill): payment rails and lawful German disclosure remain. Not legal advice.

Partial

Swiss entity / no known US parent; inbox content on Proton-owned Swiss hardware with zero-access design. Partial exposure remains via US SaaS subprocessors (Zendesk support; Stripe/Chargebee/PayPal payments) and any account metadata Proton can access under Swiss process. Not legal advice.

Data processing agreement (B2B)
Not found

Vendor states it is not an Art. 28 processor as a public electronic communications service and does not offer customer DPAs.

Vendor claimed

Public DPA at proton.me/legal/dpa forms part of terms when Proton acts as processor; Swiss law, Geneva jurisdiction; general authorization for listed subprocessors.

EU AI Act
Not applicable

Conventional email/PIM service; not an AI product.

Not applicable

Core product is encrypted email. Optional Scribe assistant is ancillary; not an AI-centric offering for this catalog entry.

BSI TR-03108 Secure Email Transport
Verified

BSI certificate BSI-K-TR-0745-2025 (OpenSource Security GmbH audit; valid through 2030 per BSI listing).

Not listed
Considerations & known limitations: Posteo vs Proton Mail
Considerations & known limitationsLogo: PosteoPosteoLogo: Proton MailProton Mail
No custom domains
High

Posteo will not host your own domain. Organisations needing brand continuity or provider portability via DNS must pick another host or self-host.

Not listed
Encryption is layered, not default E2EE
Medium

Without crypto mail storage, inbound encryption, or client-side PGP/S/MIME, Posteo can process mailbox content like a normal provider. Lawful intercept (TKU) and seizures remain possible under German process; transparency reports show content releases do occur under court order.

Not listed
No customer Art. 28 DPA
Medium

Procurement checklists that require a signed processor agreement will stall. Posteo argues telecom special law applies instead; validate with legal counsel for your use case.

Not listed
Password loss risk with crypto features
Medium

Crypto mail storage and encrypted calendars/contacts depend on the account password; Posteo cannot recover plaintext if that secret is lost after encryption is enabled.

Not listed
Payment processors outside pure DE mail path
Low

Optional PayPal/card top-ups involve non-German commercial processors even though Posteo says it does not link payment identity to the mailbox. Cash/bank-code paths reduce that linkage further.

Not listed
Weaker defaults outside ProtonNot listed
Medium

Mail to Gmail/Outlook/others is not E2EE unless password-protected or PGP/WKD is used. Subject lines are not fully E2EE. Train users or you only protect the Proton-stored copy.

US support and payment processorsNot listed
Medium

Zendesk, Chargebee, Stripe, and PayPal appear in the public processor list. They should not see zero-access message bodies, but support content and billing data can touch US-group services—document this in DPIAs.

Bridge requires paid MailNot listed
Low

Desktop IMAP/SMTP via Bridge is not available on free accounts. Budget seats for users who refuse the official apps.

Hosted service, not self-hosted FOSS mailNot listed
Medium

Open-source clients improve inspectability but you still depend on Proton’s operated backend, uptime, and Swiss legal process. Unsuitable if policy mandates customer-operated mail servers.

Swiss legal orders on accessible dataNot listed
Low

Transparency reports show thousands of yearly legal orders for Mail with many complied. Bodies stay encrypted; recovery emails, IPs (when retained for abuse), and similar metadata may still be in scope. Align expectations with counsel.

Fit

Posteo

Best fit when

  • Individuals and small teams who want German jurisdiction and open-standard clients without Google or Microsoft mail
  • Users prioritising anonymous or low-identity signup and prepaid funding without linking payments to the mailbox
  • Organisations that accept posteo.* addresses and value no ads, no tracking, and published transparency reports
  • Operators who want optional full-mailbox encryption at rest (crypto mail storage) plus PGP/S/MIME tooling
  • Buyers who need BSI-aligned secure email transport certification rather than US SOC 2 paperwork

Poor fit when

  • Anyone requiring custom domains or branded organisational addresses
  • Teams that need default zero-access E2EE for every message without enabling optional layers
  • Procurement processes that mandate a signed Art. 28 DPA, SOC 2, or ISO 27001 from the vendor
  • Large enterprises needing multi-seat admin, shared domain policies, or deep Microsoft/Google workspace integration

Consider instead when

  • When: You need default end-to-end encryption and a broader encrypted suite

    Consider: Proton Mail or Tuta

    Posteo is IMAP-first with optional crypto layers; Proton/Tuta lead with zero-access defaults.

  • When: You need custom domains or richer business mail hosting

    Consider: mailbox.org or Mailfence

    Posteo deliberately refuses own domains to avoid inventory-data obligations.

  • When: You need free-tier consumer mail tightly integrated with docs and chat

    Consider: Gmail or Outlook.com

    Trade privacy posture and EU self-operation for ecosystem convenience.

Proton Mail

Best fit when

  • Teams that need default end-to-end / zero-access encryption without running their own mail stack
  • Orgs that want Swiss legal venue and documented resistance to direct foreign data demands
  • Businesses migrating branded domains off Gmail/Outlook with Easy Switch and Bridge for desktop holdouts
  • Security-conscious professionals who value open-source clients, published audits, and hardware-key 2FA
  • Buyers who need a public DPA plus vendor-claimed ISO 27001 / SOC 2 Type II for questionnaires

Poor fit when

  • Fully self-hosted requirements (Proton Mail is SaaS; clients are open source, not a full on-prem mail server)
  • Desktop IMAP on free accounts only—Bridge needs a paid plan that includes Mail
  • Workflows that depend on unencrypted-looking mail to external parties who will not use password links or PGP
  • Teams that primarily need full Microsoft 365 / Google Workspace collaboration depth rather than encrypted mail first

Consider instead when

  • When: You want German E2EE email with a different crypto product surface and may not need Proton’s full ecosystem

    Consider: Tuta

    Compare desktop interoperability and business admin maturity side by side.

  • When: You want ad-free European mail with strong transport privacy but do not require zero-access E2EE for all stored content

    Consider: Posteo

    Different threat model: Posteo is privacy-forward without Proton’s zero-access default.

  • When: You need OpenPGP-centric mail with classic collaboration extras under Belgian operation

    Consider: Mailfence

    Weigh automatic Proton-to-Proton E2EE UX versus Mailfence’s model.

  • When: Collaboration suite depth and ecosystem lock-in outweigh encryption defaults

    Consider: Google Workspace or Microsoft 365

    Accept US-provider jurisdiction and scanning/processing models as tradeoffs.

Open questions for due diligence

Posteo

  • Does your counsel accept Posteo's position that no Art. 28 DPA is required for occupational use?
  • Will posteo.de / .net / .com addresses meet your brand, deliverability, and anti-spoofing requirements without custom domains?
  • Which encryption layers (crypto mail storage, inbound PGP/S/MIME, client E2EE) will your users actually enable and support?
  • Do you need ISO 27001/SOC 2 artefacts that Posteo does not publish?
  • Is BSI TR-03108 transport certification sufficient for your sector's secure-email checklist?

Proton Mail

  • What exact data-center sites and any non-Swiss regions apply to your tenant’s mailbox replicas today?
  • Will Proton provide the full SOC 2 Type II report under NDA and confirm ISO 27001 certificate scope/expiry for your questionnaire?
  • For business orgs: which users will be private vs non-private, and how will admin recovery work with zero-access constraints?
  • Which external partners must receive E2EE content, and will they accept password-protected messages or PGP?