Posteo vs Swissnode

Compare Posteo and Swissnode on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Gmail

Logo: Posteo

Posteo

Germany· Email Services

Needs review

Shortlist when you want a paid German mailbox on self-operated servers, open protocols (IMAP/CalDAV), and extreme data minimisation (no inventory data, unlinked payments). Skip when you need custom domains, default E2EE without setup, multi-seat enterprise admin, or an Art. 28 DPA—consider Proton Mail, Tuta, mailbox.org, or Mailfence instead.

Self-operated DE serversData-minimising signupIMAP / CalDAV / CardDAVBSI TR-03108 (verified)Optional crypto mail storageAd-free, user-funded
Logo: Swissnode

Swissnode

Switzerland· Email Services

Needs review

Shortlist Swissnode for lean European cPanel domain email plus shared web or KVM VPS when Spain/EU residency is acceptable and you do not need enterprise compliance packs. Skip when you require live Swiss territorial hosting, E2EE mail, or published DPA/subprocessor inventories—consider Hostpoint, Infomaniak, or Proton Mail instead.

cPanel domain emailKVM VPSSpain data center (vendor)Optional Cloudflare CDNSMB hosting packages
Posteo vs Swissnode: Snapshot
FeatureLogo: PosteoPosteoLogo: SwissnodeSwissnode
Country of originGermanySwitzerland
CategoryEmail ServicesEmail Services
Open sourceYesNo
Self-hostedNoNo
HeadquartersGermanySwitzerland
Legal entityPosteo e.K., Methfesselstr. 38, 10965 BerlinSwissnode (legal form/registry name not clearly published on marketing site)
Governing lawGerman / EU law (GDPR, BDSG, telecom secrecy / TTDSG as applicable)Not clearly stated on marketing pages; confirm in contract (CH contact vs ES ops)
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)LowMedium
Hosting / residencySelf-operated infrastructure; stored mail and backups in Germany (Frankfurt, Bielefeld, Berlin DCs per privacy materials). No AWS/GCP/Azure listed for mailbox hosting. Payment top-ups may use PayPal/card networks (unlinked from accounts per Posteo).Vendor states primary hosting moved to a Spain data center after Swiss DC closure; homepage cites Spanish privacy laws. Site IP geolocates to Spain (Ipcore Datacenters). Optional Cloudflare CDN on web plans (US-group). Off-site backup provider not named. No public subprocessor inventory.
Summary

Independent Berlin email provider with self-operated German servers, data-minimising signup, open-standard clients, and layered optional encryption—not a free-tier ad network.

European cPanel email, shared web hosting, and KVM VPS under the Swissnode brand—vendor-stated Spain data center after Swiss DC closure, with optional Cloudflare CDN on web plans.

Tags
At a glance: Posteo vs Swissnode
At a glanceLogo: PosteoPosteoLogo: SwissnodeSwissnode
HQBerlin, GermanyNot listed
Legal entityPosteo e.K. (HRA 47592 B)Not listed
HostingSelf-operated servers in GermanyNot listed
Commercial modelPrepaid paid service; no free tierPackage tiers (monthly/yearly); optional antispam add-on
ProtocolsIMAP, POP3, SMTP, CalDAV, CardDAVNot listed
Self-hostNo (hosted service)Not listed
Founded2009Not listed
Energy100% green energy (Green Planet Energy, claimed)Not listed
Contact addressNot listedBinzallee 6, 8055 Zurich, CH (public contact page)
Footer / ops addressNot listedMutilva Baja, Navarra, Spain
Primary hosting (vendor)Not listedSpain data center after Swiss DC closure
Core productsNot listedDomain email, cPanel web hosting, KVM VPS
Control panelsNot listedcPanel (shared); Virtualizor (VPS)
Open sourceNot listedNo
Self-hosted productNot listedNo (provider-hosted; VPS gives root on rented VM)
Key capabilities: Posteo vs Swissnode
Key capabilitiesLogo: PosteoPosteoLogo: SwissnodeSwissnode
Self-operated DE serversYesNot listed
Data-minimising signupYesNot listed
IMAP / CalDAV / CardDAVYesNot listed
BSI TR-03108 (verified)YesNot listed
Optional crypto mail storageYesNot listed
Ad-free, user-fundedYesNot listed
cPanel domain emailNot listedYes
KVM VPSNot listedYes
Spain data center (vendor)Not listedYes
Optional Cloudflare CDNNot listedYes
SMB hosting packagesNot listedYes

Posteo

  • Signup without identity data; payments unlinked

    Accounts can be created without name, address, or phone. Posteo's payment system (bank transfer codes, cash, card, PayPal) is designed so payment identifiers are not stored against the mailbox. Practical limit: recovery options you add yourself and how you fund the prepaid balance still affect anonymity in the real world.

  • Optional crypto mail storage for the whole mailbox

    One setting encrypts stored messages—including metadata—with a key protected by the account password (RSA/AES/HMAC/bcrypt design; Dovecot plugin). Posteo states it cannot disable crypto storage once enabled and cites a Cure53 review. Limit: this is server-side encryption at rest after delivery, not sender-to-recipient E2EE, and losing the password can mean losing access to encrypted data.

  • TLS, DANE, and BSI-certified secure transport

    Access is TLS-only with PFS, HSTS, and DANE/TLSA. Optional TLS-sending/receiving guarantees refuse delivery over cleartext peer links. Posteo holds BSI TR-03108 v2 Secure Email Transport certification (BSI-K-TR-0745-2025). Transport quality still depends on the remote provider's stack.

  • CalDAV/CardDAV with optional password encryption

    Calendars and contacts sync via open standards and can be AES-encrypted in Posteo's database so the provider cannot read them when the feature is on. Trade-off: encrypted calendars cannot be shared the same way, and password reset without the old secret can lock you out of encrypted PIM data.

  • In-house migration without third-party movers

    Posteo's own migration tool pulls mail (and often contacts/calendars) over encrypted links from previous providers without routing through a third-party migration SaaS. Quota: a limited number of migrations per account, with an optional collector for ongoing fetch from the old box.

Swissnode

  • Domain email on cPanel (IMAP/POP/SMTP)

    Business mailboxes on your domain with secure webmail, SpamAssassin-style spam control, virus filtering, DKIM, calendars/contacts, autoresponders, forwarders, filters, and mailing lists on mid-tier plans—protocol-compatible with Outlook, Apple Mail, and mobile clients.

  • cPanel web hosting with Softaculous and LiteSpeed PHP

    Shared and reseller web plans with datacenter SSDs, free panel SSL, multi-PHP, SSH above entry tiers, and Softaculous one-click apps—aimed at brochure sites, WordPress, and small PHP apps rather than container platforms.

  • KVM VPS with RAID-10 enterprise SSDs

    Root-level Linux VPS via KVM, enterprise SSDs, RAID-10 arrays, fixed per-VPS network allotments, and Virtualizor-style management for teams that outgrow shared hosting but still want package SKUs.

  • Optional Cloudflare CDN from the control panel

    Web plans advertise easy Cloudflare integration to cache static assets near visitors—useful for performance, with the tradeoff that enabled CDN traffic can traverse a US-group network path.

  • Backup cadence for VPS (vendor-stated)

    Marketing states daily on-site and weekly off-site VPS backups with rebuilds measured in minutes to an hour after failure—restore SLAs and off-site provider identity should be confirmed in the contract.

Assurance & compliance: Posteo vs Swissnode
Assurance & complianceLogo: PosteoPosteoLogo: SwissnodeSwissnode
Independent security / no-logs audit
Partial

BfDI on-site privacy inspection (2016) confirmed data-minimisation / no inventory IP model (public PDF). Crypto mail storage: vendor cites Cure53 multi-level audit; full public report not located. Not a continuous independent no-logs certification programme.

Not found

No public independent audit report found on swissnode.ch.

ISO 27001
Not found

No ISO 27001 claim found on primary Posteo security/privacy pages.

Not found

No ISO 27001 claim located on official product/security pages.

SOC 2 / SOC 3
Not found

No SOC 2/3 report advertised on primary pages.

Not found

No SOC 2/3 claim found.

GDPR / EU data protection
Vendor claimed

German entity; privacy policy cites GDPR/BDSG/telecom secrecy; DPO published; BfDI inspection history.

Partial

Spain/EU hosting supports EU data-protection analysis, and homepage references Spanish privacy laws; usable privacy policy/DPA text not published on site. Customer remains controller for lawful basis.

US CLOUD Act exposure (indicative)
Partial

EuropeanStack assessment: German e.K., no known US parent, self-operated DE hosting with no public US-cloud mailbox subprocessors → indicative exposure low. Status is partial (not a clean bill): payment rails and lawful German disclosure remain. Not legal advice.

Partial

No known US parent; primary host Spain/EU. Optional Cloudflare CDN is a US-group subprocessor for web static delivery; off-site backups and other SaaS paths not published. Not a clean low-exposure bill; not legal advice.

Data processing agreement (B2B)
Not found

Vendor states it is not an Art. 28 processor as a public electronic communications service and does not offer customer DPAs.

Not found

No public DPA download or B2B processing terms found; request in writing.

EU AI Act
Not applicable

Conventional email/PIM service; not an AI product.

Not applicable

Commodity hosting/email/VPS, not an AI product.

BSI TR-03108 Secure Email Transport
Verified

BSI certificate BSI-K-TR-0745-2025 (OpenSource Security GmbH audit; valid through 2030 per BSI listing).

Not listed
Swiss territorial hostingNot listed
Partial

Vendor discloses Swiss DC closed; operations from Spain DC. Contact still Zurich. Do not treat as CH-only residency.

Considerations & known limitations: Posteo vs Swissnode
Considerations & known limitationsLogo: PosteoPosteoLogo: SwissnodeSwissnode
No custom domains
High

Posteo will not host your own domain. Organisations needing brand continuity or provider portability via DNS must pick another host or self-host.

Not listed
Encryption is layered, not default E2EE
Medium

Without crypto mail storage, inbound encryption, or client-side PGP/S/MIME, Posteo can process mailbox content like a normal provider. Lawful intercept (TKU) and seizures remain possible under German process; transparency reports show content releases do occur under court order.

Not listed
No customer Art. 28 DPA
Medium

Procurement checklists that require a signed processor agreement will stall. Posteo argues telecom special law applies instead; validate with legal counsel for your use case.

Not listed
Password loss risk with crypto features
Medium

Crypto mail storage and encrypted calendars/contacts depend on the account password; Posteo cannot recover plaintext if that secret is lost after encryption is enabled.

Not listed
Payment processors outside pure DE mail path
Low

Optional PayPal/card top-ups involve non-German commercial processors even though Posteo says it does not link payment identity to the mailbox. Cash/bank-code paths reduce that linkage further.

Not listed
Swiss brand vs Spain hostingNot listed
High

Product pages state the Swiss data center closed and services run in Spain; homepage cites Spanish privacy laws. Buyers assuming Zurich colocation from the brand or older materials will mis-classify risk and contractual residency.

Empty privacy pages / no public DPA or certsNot listed
High

Privacy and cookie URLs do not present substantive policy text; ISO/SOC and DPA artifacts were not found. Regulated or enterprise buyers face a heavy offline diligence burden.

Optional Cloudflare CDN (US-group)Not listed
Medium

Web hosting markets Cloudflare integration from cPanel. Enabling CDN can place static content on a US-group network path even when origin is Spain—document this in transfer assessments.

Off-site backup provider not namedNot listed
Medium

Daily on-site and weekly off-site backups are claimed for VPS, but the off-site location/provider is not published—ask before trusting disaster-recovery or residency narratives.

Aging marketing surfaceNot listed
Low

Public site still shows 2013–2018 copyright and sparse modern trust pages; may signal limited investment in public assurance UX even if infrastructure remains operational.

Fit

Posteo

Best fit when

  • Individuals and small teams who want German jurisdiction and open-standard clients without Google or Microsoft mail
  • Users prioritising anonymous or low-identity signup and prepaid funding without linking payments to the mailbox
  • Organisations that accept posteo.* addresses and value no ads, no tracking, and published transparency reports
  • Operators who want optional full-mailbox encryption at rest (crypto mail storage) plus PGP/S/MIME tooling
  • Buyers who need BSI-aligned secure email transport certification rather than US SOC 2 paperwork

Poor fit when

  • Anyone requiring custom domains or branded organisational addresses
  • Teams that need default zero-access E2EE for every message without enabling optional layers
  • Procurement processes that mandate a signed Art. 28 DPA, SOC 2, or ISO 27001 from the vendor
  • Large enterprises needing multi-seat admin, shared domain policies, or deep Microsoft/Google workspace integration

Consider instead when

  • When: You need default end-to-end encryption and a broader encrypted suite

    Consider: Proton Mail or Tuta

    Posteo is IMAP-first with optional crypto layers; Proton/Tuta lead with zero-access defaults.

  • When: You need custom domains or richer business mail hosting

    Consider: mailbox.org or Mailfence

    Posteo deliberately refuses own domains to avoid inventory-data obligations.

  • When: You need free-tier consumer mail tightly integrated with docs and chat

    Consider: Gmail or Outlook.com

    Trade privacy posture and EU self-operation for ecosystem convenience.

Swissnode

Best fit when

  • Freelancers and micro-SMBs wanting domain IMAP/POP mail with spam filtering and webmail on cPanel
  • Agencies/resellers needing simple shared web packages (Softaculous, multi-PHP, free panel SSL) plus optional VPS upgrade path
  • Teams that prefer standard mail protocols over migrating into Microsoft 365 or Google Workspace
  • Buyers comfortable with Spain/EU hosting under a .ch brand and Swiss contact details
  • Workloads where package-tier hosting and KVM root access matter more than published ISO/SOC packs

Poor fit when

  • Organizations that hard-require Swiss (CH) server residency or nFADP narratives assuming Zurich colocation
  • Procurement needing public DPA, full subprocessor lists, ISO 27001, or SOC 2 on the vendor site
  • Teams needing end-to-end encrypted mail or zero-access webmail (choose Proton-class products)
  • Enterprises expecting Microsoft 365-class collaboration, compliance archives, and admin tooling
  • Buyers who shortlisted the brand solely for “Swiss data center” marketing that product pages no longer support

Consider instead when

  • When: You need Swiss-resident email/office with a broader product catalog and clearer CH hosting claims

    Consider: Hostpoint E-Mail & Cloud Office or Infomaniak kMail

    Fuller Swiss platforms; better when territorial Switzerland is non-negotiable.

  • When: You need end-to-end encrypted mail and open-source clients rather than cPanel hosting

    Consider: Proton Mail

    Different product class: E2EE vs classic hosted IMAP.

  • When: You need full collaboration suites, admin compliance tooling, and ecosystem apps

    Consider: Microsoft 365 or Google Workspace (US-group control planes)

    Richer features; different jurisdiction/CLOUD Act profile.

  • When: You want a larger EU hosting group with broader cloud SKUs

    Consider: IONOS or OVHcloud

    Scale and catalog depth over niche Swissnode packaging.

Open questions for due diligence

Posteo

  • Does your counsel accept Posteo's position that no Art. 28 DPA is required for occupational use?
  • Will posteo.de / .net / .com addresses meet your brand, deliverability, and anti-spoofing requirements without custom domains?
  • Which encryption layers (crypto mail storage, inbound PGP/S/MIME, client E2EE) will your users actually enable and support?
  • Do you need ISO 27001/SOC 2 artefacts that Posteo does not publish?
  • Is BSI TR-03108 transport certification sufficient for your sector's secure-email checklist?

Swissnode

  • What is the exact legal entity (registry name, UID/CHE or Spanish NIF) and governing law on the customer contract?
  • Will Swissnode sign a B2B DPA and publish a current subprocessor list (spam filter, backups, payment, support tools)?
  • Exact Spain facility (Ipcore or other) and whether any secondary regions exist for mail, web, and VPS separately?
  • Where are weekly off-site backups stored, and under which provider’s control?
  • Is Cloudflare mandatory, optional, or default for web plans, and can customers disable it for pure Spain origin delivery?
  • What uptime SLA, restore RPO/RTO, and support hours are contractual vs marketing (99.5% backbone claim on homepage)?