Posteo vs RAIDBOXES Emails

Compare Posteo and RAIDBOXES Emails on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Gmail

Logo: Posteo

Posteo

Germany· Email Services

Needs review

Shortlist when you want a paid German mailbox on self-operated servers, open protocols (IMAP/CalDAV), and extreme data minimisation (no inventory data, unlinked payments). Skip when you need custom domains, default E2EE without setup, multi-seat enterprise admin, or an Art. 28 DPA—consider Proton Mail, Tuta, mailbox.org, or Mailfence instead.

Self-operated DE serversData-minimising signupIMAP / CalDAV / CardDAVBSI TR-03108 (verified)Optional crypto mail storageAd-free, user-funded
Logo: RAIDBOXES Emails

RAIDBOXES Emails

Germany· Email Services

Needs review

Shortlist when you already (or will) host the domain and WordPress stack at RAIDBOXES and need practical multi-mailbox domain email under a German operator with an online DPA. Skip when you need multi-domain density, default E2EE, or email fully independent of a hoster—consider Migadu, Tuta, Posteo, or mailbox.org instead.

German operatorIMAP / SMTPMail Hosting 2.0Online DPAWordPress-adjacentOptional PGP
Posteo vs RAIDBOXES Emails: Snapshot
FeatureLogo: PosteoPosteoLogo: RAIDBOXES EmailsRAIDBOXES Emails
Country of originGermanyGermany
CategoryEmail ServicesEmail Services
Open sourceYesNo
Self-hostedNoNo
HeadquartersGermanyGermany
Legal entityPosteo e.K., Methfesselstr. 38, 10965 BerlinRaidboxes GmbH, Hafenstraße 32, 48153 Münster (Amtsgericht Münster HRB 16184)
Governing lawGerman / EU law (GDPR, BDSG, telecom secrecy / TTDSG as applicable)German law (company domicile Münster)
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)LowMedium
Hosting / residencySelf-operated infrastructure; stored mail and backups in Germany (Frankfurt, Bielefeld, Berlin DCs per privacy materials). No AWS/GCP/Azure listed for mailbox hosting. Payment top-ups may use PayPal/card networks (unlinked from accounts per Posteo).Email: vendor claims exclusive German data centres and first-party Mail Hosting 2.0 infrastructure (IMAP/SMTP on securemail.pro hostnames); privacy policy still names Heinlein Hosting/mailbox.org under paid email boxes (possible legacy lag). Platform/website: AWS EMEA SARL and DigitalOcean listed for web hosting of the online offer; US-group SaaS includes Intercom, Calendly, Chargebee, Sentry, Google analytics/ads, Mailgun, and others for support, billing, and marketing.
Summary

Independent Berlin email provider with self-operated German servers, data-minimising signup, open-standard clients, and layered optional encryption—not a free-tier ad network.

German domain email hosting from Raidboxes GmbH (Münster): Mail Hosting 2.0 with IMAP/SMTP, multi-mailbox plans, optional PGP, and dashboard fit for WordPress agencies—domain must be hosted at RAIDBOXES.

Tags
At a glance: Posteo vs RAIDBOXES Emails
At a glanceLogo: PosteoPosteoLogo: RAIDBOXES EmailsRAIDBOXES Emails
HQBerlin, GermanyMünster, Germany
Legal entityPosteo e.K. (HRA 47592 B)Raidboxes GmbH (HRB 16184)
HostingSelf-operated servers in GermanyNot listed
Commercial modelPrepaid paid service; no free tierNot listed
ProtocolsIMAP, POP3, SMTP, CalDAV, CardDAVNot listed
Self-hostNo (hosted service)Not listed
Founded2009Not listed
Energy100% green energy (Green Planet Energy, claimed)Not listed
GroupNot listedteam.blue (Belgium) since 2022
ProductNot listedMail Hosting 2.0 domain email
AccessNot listedIMAP / SMTP + webmail
Domain constraintNot listedDomain hosted at RAIDBOXES for new mailboxes
Open sourceNot listedNo
Self-hostedNot listedNo
Key capabilities: Posteo vs RAIDBOXES Emails
Key capabilitiesLogo: PosteoPosteoLogo: RAIDBOXES EmailsRAIDBOXES Emails
Self-operated DE serversYesYes
Data-minimising signupYesNot listed
IMAP / CalDAV / CardDAVYesNot listed
BSI TR-03108 (verified)YesNot listed
Optional crypto mail storageYesNot listed
Ad-free, user-fundedYesNot listed
IMAP / SMTPNot listedYes
Mail Hosting 2.0Not listedYes
Online DPANot listedYes
WordPress-adjacentNot listedYes
Optional PGPNot listedYes

Posteo

  • Signup without identity data; payments unlinked

    Accounts can be created without name, address, or phone. Posteo's payment system (bank transfer codes, cash, card, PayPal) is designed so payment identifiers are not stored against the mailbox. Practical limit: recovery options you add yourself and how you fund the prepaid balance still affect anonymity in the real world.

  • Optional crypto mail storage for the whole mailbox

    One setting encrypts stored messages—including metadata—with a key protected by the account password (RSA/AES/HMAC/bcrypt design; Dovecot plugin). Posteo states it cannot disable crypto storage once enabled and cites a Cure53 review. Limit: this is server-side encryption at rest after delivery, not sender-to-recipient E2EE, and losing the password can mean losing access to encrypted data.

  • TLS, DANE, and BSI-certified secure transport

    Access is TLS-only with PFS, HSTS, and DANE/TLSA. Optional TLS-sending/receiving guarantees refuse delivery over cleartext peer links. Posteo holds BSI TR-03108 v2 Secure Email Transport certification (BSI-K-TR-0745-2025). Transport quality still depends on the remote provider's stack.

  • CalDAV/CardDAV with optional password encryption

    Calendars and contacts sync via open standards and can be AES-encrypted in Posteo's database so the provider cannot read them when the feature is on. Trade-off: encrypted calendars cannot be shared the same way, and password reset without the old secret can lock you out of encrypted PIM data.

  • In-house migration without third-party movers

    Posteo's own migration tool pulls mail (and often contacts/calendars) over encrypted links from previous providers without routing through a third-party migration SaaS. Quota: a limited number of migrations per account, with an optional collector for ongoing fetch from the old box.

RAIDBOXES Emails

  • Mail Hosting 2.0 on RAIDBOXES infrastructure

    IMAP/SMTP mailboxes on dedicated hostnames (mail-rb.securemail.pro / smtp-rb.securemail.pro) after the move off the prior mailbox.org cooperation. Vendor claims German data-centre locations and triple-redundant mail servers. Best for teams that want domain mail under the same German WordPress host rather than a separate privacy-mail brand.

  • Multi-mailbox plans with aliases, forwards, and catch-all

    Tiered plans allocate a fixed number of mailboxes and a shared storage pool, plus per-mailbox alias and forwarding quotas, autoresponders, and catch-all (requires a dedicated catch-all mailbox). One connected domain per plan—confirm multi-domain needs before shortlisting.

  • Spam/virus filters, TLS, optional PGP, ad-free inboxes

    All plans include spam and virus filtering, SSL/TLS for transfer, a blacklist checker, webmail, and ad-free inboxes. PGP is optional rather than default end-to-end encryption for every message—teams that need mandatory E2EE workflows should evaluate Tuta or a full mailbox.org stack instead.

  • Dashboard-adjacent domain and WordPress ops

    Mailboxes are ordered from the RAIDBOXES dashboard and are intended to sit next to WordPress hosting and domain management. New RAIDBOXES mailboxes require the domain to be hosted with RAIDBOXES; legacy mailbox.org-linked domains follow a separate migration path documented in the help centre.

  • Online B2B DPA and German operator

    Raidboxes GmbH (Münster) offers an online data processing agreement (AV contract) with technical-organisational measures. Useful for agencies that already sign a DPA for WordPress hosting and want the same counterparty for domain email—still review TOMs and subprocessor scope for mailbox vs platform tooling.

Assurance & compliance: Posteo vs RAIDBOXES Emails
Assurance & complianceLogo: PosteoPosteoLogo: RAIDBOXES EmailsRAIDBOXES Emails
Independent security / no-logs audit
Partial

BfDI on-site privacy inspection (2016) confirmed data-minimisation / no inventory IP model (public PDF). Crypto mail storage: vendor cites Cure53 multi-level audit; full public report not located. Not a continuous independent no-logs certification programme.

Not found

No public third-party security or no-logs audit report found for RAIDBOXES Emails on primary pages.

ISO 27001
Not found

No ISO 27001 claim found on primary Posteo security/privacy pages.

Not found

No company-wide ISO 27001 certificate for Raidboxes GmbH found on product/security pages; AWS region ISO mentions are not RAIDBOXES certs.

SOC 2 / SOC 3
Not found

No SOC 2/3 report advertised on primary pages.

Not found

No public SOC 2/3 report located for RAIDBOXES Emails.

GDPR / EU data protection
Vendor claimed

German entity; privacy policy cites GDPR/BDSG/telecom secrecy; DPO published; BfDI inspection history.

Vendor claimed

German controller (Raidboxes GmbH); product claims DE server locations and GDPR-aligned deletion; online DPA available. Confirm active mail stack vs privacy-policy mailbox.org listing.

US CLOUD Act exposure (indicative)
Partial

EuropeanStack assessment: German e.K., no known US parent, self-operated DE hosting with no public US-cloud mailbox subprocessors → indicative exposure low. Status is partial (not a clean bill): payment rails and lawful German disclosure remain. Not legal advice.

Partial

EU/German entity, no known US parent (team.blue BE group). Medium residual exposure via US-group platform subprocessors (AWS/DigitalOcean for online offer hosting; Intercom, Chargebee, Google tooling, Mailgun, etc.). Mail content path claimed DE-only. Not legal advice.

Data processing agreement (B2B)
Not found

Vendor states it is not an Art. 28 processor as a public electronic communications service and does not offer customer DPAs.

Vendor claimed

Online AV/DPA flow at raidboxes.io/en/dpa/ and DocuSign TOM path documented in help centre.

EU AI Act
Not applicable

Conventional email/PIM service; not an AI product.

Not applicable

Domain email hosting product, not an AI system offering.

BSI TR-03108 Secure Email Transport
Verified

BSI certificate BSI-K-TR-0745-2025 (OpenSource Security GmbH audit; valid through 2030 per BSI listing).

Not listed
B Corp certificationNot listed
Vendor claimed

Raidboxes GmbH listed as Certified B Corporation on B Lab directory; impact certification, not an information-security audit.

Considerations & known limitations: Posteo vs RAIDBOXES Emails
Considerations & known limitationsLogo: PosteoPosteoLogo: RAIDBOXES EmailsRAIDBOXES Emails
No custom domains
High

Posteo will not host your own domain. Organisations needing brand continuity or provider portability via DNS must pick another host or self-host.

Not listed
Encryption is layered, not default E2EE
Medium

Without crypto mail storage, inbound encryption, or client-side PGP/S/MIME, Posteo can process mailbox content like a normal provider. Lawful intercept (TKU) and seizures remain possible under German process; transparency reports show content releases do occur under court order.

Not listed
No customer Art. 28 DPA
Medium

Procurement checklists that require a signed processor agreement will stall. Posteo argues telecom special law applies instead; validate with legal counsel for your use case.

Not listed
Password loss risk with crypto features
Medium

Crypto mail storage and encrypted calendars/contacts depend on the account password; Posteo cannot recover plaintext if that secret is lost after encryption is enabled.

Not listed
Payment processors outside pure DE mail path
Low

Optional PayPal/card top-ups involve non-German commercial processors even though Posteo says it does not link payment identity to the mailbox. Cash/bank-code paths reduce that linkage further.

Not listed
Domain must be hosted at RAIDBOXESNot listed
Medium

New mailboxes require the domain on RAIDBOXES. That is convenient for WP customers and a lock-in factor if you only wanted independent mail.

One connected domain per planNot listed
Medium

Multi-domain operators need multiple plans or another provider; not a Migadu-style multi-domain account model.

PGP optional, not default E2EENot listed
Medium

Threat models that assume provider-side unreadability by default are a better fit for Tuta or similar products.

US-group platform subprocessorsNot listed
Medium

Privacy policy discloses AWS EMEA, DigitalOcean, Intercom, Chargebee, Google tools, Mailgun, and others for website/support/billing/marketing—even while email marketing claims German mail servers. Scope diligence to mailbox vs platform data paths.

Privacy policy may lag Mail Hosting 2.0Not listed
Low

§Email box still lists mailbox.org/Heinlein while marketing claims first-party hosting—confirm live stack and subprocessor annex for your contract.

No public ISO/SOC/mail auditNot listed
Medium

B Corp is not a security certification. Enterprise security questionnaires may need NDA materials or alternative providers with published audits.

Fit

Posteo

Best fit when

  • Individuals and small teams who want German jurisdiction and open-standard clients without Google or Microsoft mail
  • Users prioritising anonymous or low-identity signup and prepaid funding without linking payments to the mailbox
  • Organisations that accept posteo.* addresses and value no ads, no tracking, and published transparency reports
  • Operators who want optional full-mailbox encryption at rest (crypto mail storage) plus PGP/S/MIME tooling
  • Buyers who need BSI-aligned secure email transport certification rather than US SOC 2 paperwork

Poor fit when

  • Anyone requiring custom domains or branded organisational addresses
  • Teams that need default zero-access E2EE for every message without enabling optional layers
  • Procurement processes that mandate a signed Art. 28 DPA, SOC 2, or ISO 27001 from the vendor
  • Large enterprises needing multi-seat admin, shared domain policies, or deep Microsoft/Google workspace integration

Consider instead when

  • When: You need default end-to-end encryption and a broader encrypted suite

    Consider: Proton Mail or Tuta

    Posteo is IMAP-first with optional crypto layers; Proton/Tuta lead with zero-access defaults.

  • When: You need custom domains or richer business mail hosting

    Consider: mailbox.org or Mailfence

    Posteo deliberately refuses own domains to avoid inventory-data obligations.

  • When: You need free-tier consumer mail tightly integrated with docs and chat

    Consider: Gmail or Outlook.com

    Trade privacy posture and EU self-operation for ecosystem convenience.

RAIDBOXES Emails

Best fit when

  • WordPress agencies and freelancers standardising on RAIDBOXES for sites, domains, and mail admin
  • SMEs wanting professional multi-mailbox domain email with standard IMAP clients—not a full Google/Microsoft suite
  • Teams that need catch-all, aliases, forwards, autoresponders, and ad-free inboxes on one domain
  • Buyers who require a German legal counterparty and an online B2B DPA for processor agreements
  • Operators migrating off legacy mailbox.org-linked RAIDBOXES mail toward first-party Mail Hosting 2.0

Poor fit when

  • Multi-domain mail estates that need many domains under one contract (one connected domain per plan)
  • Policies requiring default end-to-end encryption for all mail (PGP is optional only)
  • Buyers who refuse any coupling between mailbox service and domain/WordPress hosting
  • Teams seeking a full office suite (Drive, collaborative docs, built-in video) rather than domain mail
  • Procurement that demands public ISO 27001/SOC 2 or independent no-logs audit reports for the mail product

Consider instead when

  • When: You need multi-domain, usage-based professional mail without WordPress host lock-in

    Consider: Migadu

    Swiss-operated, standards-based hosting priced by quotas rather than per-domain WordPress adjacency

  • When: You need default E2EE and a privacy-first client model

    Consider: Tuta

    Different threat model; less IMAP flexibility than RAIDBOXES

  • When: You want privacy-oriented German personal/business mail without hosting coupling

    Consider: Posteo or mailbox (formerly mailbox.org)

    mailbox is also the former RAIDBOXES mail partner and a deeper digital-workplace option

  • When: You need Google/Microsoft suite collaboration, not just domain mailboxes

    Consider: Google Workspace or Microsoft 365

    US Big Tech residency and CLOUD Act profile differ sharply—use only if suite features dominate

Open questions for due diligence

Posteo

  • Does your counsel accept Posteo's position that no Art. 28 DPA is required for occupational use?
  • Will posteo.de / .net / .com addresses meet your brand, deliverability, and anti-spoofing requirements without custom domains?
  • Which encryption layers (crypto mail storage, inbound PGP/S/MIME, client E2EE) will your users actually enable and support?
  • Do you need ISO 27001/SOC 2 artefacts that Posteo does not publish?
  • Is BSI TR-03108 transport certification sufficient for your sector's secure-email checklist?

RAIDBOXES Emails

  • For a new Mail Hosting 2.0 mailbox, is mailbox.org/Heinlein still a subprocessor for mailbox content, or only a legacy path?
  • Which German data-centre operators and exact regions host mail storage and backups (primary + DR)?
  • Does the standard DPA/TOM annex explicitly cover email hosting subprocessors separately from WordPress hosting?
  • What are published RPO/RTO and restore procedures for mailbox backups?
  • Are there any upcoming multi-domain plan options or reseller mail SKUs?