Posteo vs web.de

Compare Posteo and web.de on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Gmail, Outlook.com

Logo: Posteo

Posteo

Germany· Email Services

Needs review

Shortlist when you want a paid German mailbox on self-operated servers, open protocols (IMAP/CalDAV), and extreme data minimisation (no inventory data, unlinked payments). Skip when you need custom domains, default E2EE without setup, multi-seat enterprise admin, or an Art. 28 DPA—consider Proton Mail, Tuta, mailbox.org, or Mailfence instead.

Self-operated DE serversData-minimising signupIMAP / CalDAV / CardDAVBSI TR-03108 (verified)Optional crypto mail storageAd-free, user-funded
Logo: web.de

web.de

Germany· Email Services

Needs review

Shortlist web.de when you need mass-market German freemail with DE-sited mail/cloud, E-Mail made in Germany TLS alliance markers, optional PGP/2FA, and a familiar DACH portal. Skip when you need default E2EE, no advertising data path, self-host, or enterprise admin—consider Posteo, mailbox.org, Tuta, or Proton Mail instead.

DE-operated freemailE-Mail made in GermanyGermany data centers (claimed)Optional PGPFreeMail + paid upgradesSaaS only
Posteo vs web.de: Snapshot
FeatureLogo: PosteoPosteoLogo: web.deweb.de
Country of originGermanyGermany
CategoryEmail ServicesEmail Services
Open sourceYesNo
Self-hostedNoNo
HeadquartersGermanyGermany
Legal entityPosteo e.K., Methfesselstr. 38, 10965 Berlin1&1 Mail & Media GmbH (United Internet AG group)
Governing lawGerman / EU law (GDPR, BDSG, telecom secrecy / TTDSG as applicable)Germany / EU GDPR
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)LowLow
Hosting / residencySelf-operated infrastructure; stored mail and backups in Germany (Frankfurt, Bielefeld, Berlin DCs per privacy materials). No AWS/GCP/Azure listed for mailbox hosting. Payment top-ups may use PayPal/card networks (unlinked from accounts per Posteo).Vendor claims email and Online-Speicher stored exclusively in Germany in company-owned data centers (E-Mail/Cloud made in Germany). FreeMail monetized via advertising and IAB TCF consent partners; privacy notice allows EEA third-country transfers with Chapter V safeguards. Portal/optional features use additional processors (e.g. search partners, embeds, homepage builder DUDA Inc., ID vendors). No exhaustive public mail-stack subprocessor list found.
Summary

Independent Berlin email provider with self-operated German servers, data-minimising signup, open-standard clients, and layered optional encryption—not a free-tier ad network.

German freemail and portal from United Internet’s 1&1 Mail & Media GmbH: FreeMail with DE-sited mail and cloud, E-Mail made in Germany TLS alliance, optional PGP—consumer SaaS, not default-E2EE privacy mail.

Tags
At a glance: Posteo vs web.de
At a glanceLogo: PosteoPosteoLogo: web.deweb.de
HQBerlin, GermanyNot listed
Legal entityPosteo e.K. (HRA 47592 B)Not listed
HostingSelf-operated servers in GermanyNot listed
Commercial modelPrepaid paid service; no free tierAd-supported FreeMail; paid mailbox/cloud upgrades; Consent or Pay
ProtocolsIMAP, POP3, SMTP, CalDAV, CardDAVNot listed
Self-hostNo (hosted service)No
Founded2009Not listed
Energy100% green energy (Green Planet Energy, claimed)Not listed
HQ / operatorNot listed1&1 Mail & Media GmbH, Montabaur/Karlsruhe, Germany
Parent groupNot listedUnited Internet AG (Germany)
Product typeNot listedConsumer freemail + portal + cloud (SaaS)
Hosting (vendor claim)Not listedCompany-owned data centers in Germany
Open sourceNot listedNo
Key capabilities: Posteo vs web.de
Key capabilitiesLogo: PosteoPosteoLogo: web.deweb.de
Self-operated DE serversYesNot listed
Data-minimising signupYesNot listed
IMAP / CalDAV / CardDAVYesNot listed
BSI TR-03108 (verified)YesNot listed
Optional crypto mail storageYesNot listed
Ad-free, user-fundedYesNot listed
DE-operated freemailNot listedYes
E-Mail made in GermanyNot listedYes
Germany data centers (claimed)Not listedYes
Optional PGPNot listedYes
FreeMail + paid upgradesNot listedYes
SaaS onlyNot listedYes

Posteo

  • Signup without identity data; payments unlinked

    Accounts can be created without name, address, or phone. Posteo's payment system (bank transfer codes, cash, card, PayPal) is designed so payment identifiers are not stored against the mailbox. Practical limit: recovery options you add yourself and how you fund the prepaid balance still affect anonymity in the real world.

  • Optional crypto mail storage for the whole mailbox

    One setting encrypts stored messages—including metadata—with a key protected by the account password (RSA/AES/HMAC/bcrypt design; Dovecot plugin). Posteo states it cannot disable crypto storage once enabled and cites a Cure53 review. Limit: this is server-side encryption at rest after delivery, not sender-to-recipient E2EE, and losing the password can mean losing access to encrypted data.

  • TLS, DANE, and BSI-certified secure transport

    Access is TLS-only with PFS, HSTS, and DANE/TLSA. Optional TLS-sending/receiving guarantees refuse delivery over cleartext peer links. Posteo holds BSI TR-03108 v2 Secure Email Transport certification (BSI-K-TR-0745-2025). Transport quality still depends on the remote provider's stack.

  • CalDAV/CardDAV with optional password encryption

    Calendars and contacts sync via open standards and can be AES-encrypted in Posteo's database so the provider cannot read them when the feature is on. Trade-off: encrypted calendars cannot be shared the same way, and password reset without the old secret can lock you out of encrypted PIM data.

  • In-house migration without third-party movers

    Posteo's own migration tool pulls mail (and often contacts/calendars) over encrypted links from previous providers without routing through a third-party migration SaaS. Quota: a limited number of migrations per account, with an optional collector for ongoing fetch from the old box.

web.de

  • E-Mail made in Germany alliance transport

    Founding member of the German provider alliance (WEB.DE, GMX, 1&1, STRATO, T-Online, freenet). TLS on paths inside the alliance, mail stored in Germany, and green checkmarks on alliance addresses in the compose UI. Does not encrypt content to non-alliance or non-PGP recipients end-to-end by default.

  • FreeMail + paid upgrades with intelligent inbox

    Ad-supported FreeMail with integrated calendar, contacts, and Online-Speicher. Intelligent inbox categorizes newsletters, orders, social, and contracts/subscriptions without duplicating messages; optional package tracking via DHL, DPD, and GLS when consented. Paid tiers expand quotas and reduce ad/tracking friction under Consent or Pay.

  • Optional PGP and free 2FA

    Optional PGP end-to-end encryption for sensitive mail (both parties need keys/compatible clients). Optional free two-factor authentication for account login. Baseline mailbox protection relies on account credentials, spam/virus filters, and TLS—not default E2EE for every message.

  • Cloud made in Germany Online-Speicher

    Mailbox-integrated cloud with browser, app, and desktop access; link sharing and Online Office for documents. Vendor claims exclusive German data-center storage and TLS in transit under Cloud made in Germany. Free tier includes a starter cloud quota; larger capacities are paid add-ons. Not a full Google Drive/OneDrive collab suite.

  • German consumer portal on the same identity

    News, services, WEB.Cent cashback, and optional Deutsche Post letter preview sit beside mail. Useful for personal DACH users; increases advertising and partner surface versus a pure mailbox product. Portal embeds and partners are consent-gated where required.

Assurance & compliance: Posteo vs web.de
Assurance & complianceLogo: PosteoPosteoLogo: web.deweb.de
Independent security / no-logs audit
Partial

BfDI on-site privacy inspection (2016) confirmed data-minimisation / no inventory IP model (public PDF). Crypto mail storage: vendor cites Cure53 multi-level audit; full public report not located. Not a continuous independent no-logs certification programme.

Not found

No public independent no-logs or full security audit package found for FreeMail; alliance pages claim oversight by data-protection function and independent Prüfstellen at a high level only.

ISO 27001
Not found

No ISO 27001 claim found on primary Posteo security/privacy pages.

Not found

No public ISO 27001 certificate page located for the web.de freemail product during research.

SOC 2 / SOC 3
Not found

No SOC 2/3 report advertised on primary pages.

Not found

No public SOC 2/3 report found for web.de FreeMail.

GDPR / EU data protection
Vendor claimed

German entity; privacy policy cites GDPR/BDSG/telecom secrecy; DPO published; BfDI inspection history.

Vendor claimed

German controller (1&1 Mail & Media GmbH); detailed GDPR privacy notice; DE storage claims for mail/cloud. Not a legal certification.

US CLOUD Act exposure (indicative)
Partial

EuropeanStack assessment: German e.K., no known US parent, self-operated DE hosting with no public US-cloud mailbox subprocessors → indicative exposure low. Status is partial (not a clean bill): payment rails and lawful German disclosure remain. Not legal advice.

Partial

EU/German entity and parent; no known US parent; mail/cloud claimed on company-owned DE data centers. Partial because privacy notice allows third-country transfers with safeguards, FreeMail uses ad/TCF partners, and no exhaustive public subprocessor inventory. Not legal advice.

Data processing agreement (B2B)
Not found

Vendor states it is not an Art. 28 processor as a public electronic communications service and does not offer customer DPAs.

Not found

Consumer freemail focus; no clear self-serve public B2B DPA for FreeMail found. Request under contract if treating as processor for an organization.

EU AI Act
Not applicable

Conventional email/PIM service; not an AI product.

Not applicable

Consumer mail/portal with limited in-product assistants; not an AI-centric product for this checklist.

BSI TR-03108 Secure Email Transport
Verified

BSI certificate BSI-K-TR-0745-2025 (OpenSource Security GmbH audit; valid through 2030 per BSI listing).

Not listed
Considerations & known limitations: Posteo vs web.de
Considerations & known limitationsLogo: PosteoPosteoLogo: web.deweb.de
No custom domains
High

Posteo will not host your own domain. Organisations needing brand continuity or provider portability via DNS must pick another host or self-host.

Not listed
Encryption is layered, not default E2EE
Medium

Without crypto mail storage, inbound encryption, or client-side PGP/S/MIME, Posteo can process mailbox content like a normal provider. Lawful intercept (TKU) and seizures remain possible under German process; transparency reports show content releases do occur under court order.

Not listed
No customer Art. 28 DPA
Medium

Procurement checklists that require a signed processor agreement will stall. Posteo argues telecom special law applies instead; validate with legal counsel for your use case.

Not listed
Password loss risk with crypto features
Medium

Crypto mail storage and encrypted calendars/contacts depend on the account password; Posteo cannot recover plaintext if that secret is lost after encryption is enabled.

Not listed
Payment processors outside pure DE mail path
Low

Optional PayPal/card top-ups involve non-German commercial processors even though Posteo says it does not link payment identity to the mailbox. Cash/bank-code paths reduce that linkage further.

Not listed
Ad-financed FreeMail and consent surfaceNot listed
Medium

FreeMail uses advertising and Consent or Pay. With consent, content may feed interest profiles; FreeMail users cannot drop WEB.DE informiert like paid tiers. Unsuitable where ad-tech processors are banned.

No default end-to-end encryptionNot listed
Medium

TLS and alliance transport protection are not content E2EE. Optional PGP only covers willing counterparties. Operator can process plaintext for spam, intelligent inbox, and consented ad analysis.

Limited public audit/cert artifactsNot listed
Medium

ISO 27001, SOC 2, and independent no-logs audits not found on public product pages. Trust rests on German entity, DE hosting claims, and first-party security copy.

Third-country transfers and portal partnersNot listed
Low

Privacy notice contemplates non-EEA recipients under Chapter V safeguards. Portal/search/ID/ad features introduce extra processors beyond the mailbox DC story—review consent layer and purpose before sensitive use.

FreeMail inactivity content deletionNot listed
Low

Privacy notice: FreeMail email content may be deleted after more than 180 days without login. Not a durable archive without activity or export.

Fit

Posteo

Best fit when

  • Individuals and small teams who want German jurisdiction and open-standard clients without Google or Microsoft mail
  • Users prioritising anonymous or low-identity signup and prepaid funding without linking payments to the mailbox
  • Organisations that accept posteo.* addresses and value no ads, no tracking, and published transparency reports
  • Operators who want optional full-mailbox encryption at rest (crypto mail storage) plus PGP/S/MIME tooling
  • Buyers who need BSI-aligned secure email transport certification rather than US SOC 2 paperwork

Poor fit when

  • Anyone requiring custom domains or branded organisational addresses
  • Teams that need default zero-access E2EE for every message without enabling optional layers
  • Procurement processes that mandate a signed Art. 28 DPA, SOC 2, or ISO 27001 from the vendor
  • Large enterprises needing multi-seat admin, shared domain policies, or deep Microsoft/Google workspace integration

Consider instead when

  • When: You need default end-to-end encryption and a broader encrypted suite

    Consider: Proton Mail or Tuta

    Posteo is IMAP-first with optional crypto layers; Proton/Tuta lead with zero-access defaults.

  • When: You need custom domains or richer business mail hosting

    Consider: mailbox.org or Mailfence

    Posteo deliberately refuses own domains to avoid inventory-data obligations.

  • When: You need free-tier consumer mail tightly integrated with docs and chat

    Consider: Gmail or Outlook.com

    Trade privacy posture and EU self-operation for ecosystem convenience.

web.de

Best fit when

  • German consumers who want a familiar .de freemail address with portal news and everyday cloud storage
  • Secondary personal or family mail where DE operator and DE storage matter more than default E2EE
  • Users who value intelligent inbox sorting, package tracking, and mobile/desktop access over privacy-maximalist design
  • Teams comparing Gmail/Outlook.com alternatives on jurisdiction while accepting consumer freemail trade-offs
  • Buyers already in the United Internet ecosystem (WEB.DE / GMX) who need a consistent DACH brand

Poor fit when

  • Organizations needing primary business mail with admin console, SSO, and signed B2B DPA as standard
  • Hard requirements for default end-to-end encryption or zero advertising/tracking surface
  • Self-hosted or open-source mail stacks you operate yourself
  • Long-term cold archives on FreeMail (inactivity deletion policy)
  • Procurement policies that forbid ad-tech partners or third-country transfer language without contract exhibits

Consider instead when

  • When: You need default E2EE and a privacy-first paid mailbox

    Consider: Tuta or Proton Mail

    web.de PGP is optional and counterpart-dependent; FreeMail is ad-financed.

  • When: You want ad-free German/EU mail with strong consumer privacy posture and paid model only

    Consider: Posteo or mailbox.org

    Less portal monetization; clearer privacy-first product framing than mass freemail.

  • When: You prefer the same United Internet Mail & Media stack under another brand

    Consider: GMX Mail

    Nearly aligned trust and capability story; brand and portal mix differ.

  • When: You need Google/Microsoft-class workspace collab and enterprise compliance packs

    Consider: Gmail (Google Workspace) or Outlook.com / Microsoft 365

    Trade DE freemail residency story for US-group platforms and deeper admin tooling.

Open questions for due diligence

Posteo

  • Does your counsel accept Posteo's position that no Art. 28 DPA is required for occupational use?
  • Will posteo.de / .net / .com addresses meet your brand, deliverability, and anti-spoofing requirements without custom domains?
  • Which encryption layers (crypto mail storage, inbound PGP/S/MIME, client E2EE) will your users actually enable and support?
  • Do you need ISO 27001/SOC 2 artefacts that Posteo does not publish?
  • Is BSI TR-03108 transport certification sufficient for your sector's secure-email checklist?

web.de

  • Will 1&1 Mail & Media sign a B2B DPA and provide a current subprocessor list for mailbox and cloud processing?
  • Are there ISO 27001, C5, or independent penetration-test summaries available under NDA for Mail & Media freemail infrastructure?
  • For your use case, is FreeMail with ads acceptable, or must you force paid TrackFree/premium paths and refuse intelligent-inbox/ad consents?
  • Confirm whether any non-DE backup, support, or analytics processors touch mailbox content beyond the public privacy notice.