RAIDBOXES Emails vs Tuta

Compare RAIDBOXES Emails and Tuta on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Gmail, Google Workspace, Microsoft 365

Logo: RAIDBOXES Emails

RAIDBOXES Emails

Germany· Email Services

Needs review

Shortlist when you already (or will) host the domain and WordPress stack at RAIDBOXES and need practical multi-mailbox domain email under a German operator with an online DPA. Skip when you need multi-domain density, default E2EE, or email fully independent of a hoster—consider Migadu, Tuta, Posteo, or mailbox.org instead.

German operatorIMAP / SMTPMail Hosting 2.0Online DPAWordPress-adjacentOptional PGP
Logo: Tuta

Tuta

Germany· Email Services

Needs review

Shortlist when you need default end-to-end encrypted mail, calendar, and contacts under German law with post-quantum TutaCrypt and official multi-platform apps. Skip when teams must keep Outlook/Thunderbird via IMAP or need a full M365/Workspace suite—consider Proton Mail (Bridge) or mailbox.org instead.

Default mailbox E2EETutaCrypt post-quantumEU-operated (Germany)Open-source clientsDE data centers (claimed)No IMAP (by design)
RAIDBOXES Emails vs Tuta: Snapshot
FeatureLogo: RAIDBOXES EmailsRAIDBOXES EmailsLogo: TutaTuta
Country of originGermanyGermany
CategoryEmail ServicesEmail Services
Open sourceNoYes
Self-hostedNoNo
HeadquartersGermanyGermany
Legal entityRaidboxes GmbH, Hafenstraße 32, 48153 Münster (Amtsgericht Münster HRB 16184)Tutao GmbH (HRB 208014, Hanover)
Governing lawGerman law (company domicile Münster)German law / GDPR
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)MediumLow
Hosting / residencyEmail: vendor claims exclusive German data centres and first-party Mail Hosting 2.0 infrastructure (IMAP/SMTP on securemail.pro hostnames); privacy policy still names Heinlein Hosting/mailbox.org under paid email boxes (possible legacy lag). Platform/website: AWS EMEA SARL and DigitalOcean listed for web hosting of the online offer; US-group SaaS includes Intercom, Calendly, Chargebee, Sentry, Google analytics/ads, Mailgun, and others for support, billing, and marketing.Vendor states mailbox data is stored end-to-end encrypted on Tutao-operated servers in ISO 27001-certified data centers in Germany. No AWS/GCP/Azure primary hosting named on official security/privacy pages. Privacy statement discloses payment processing via PayPal (Europe) and banks for card/SEPA; no comprehensive public subprocessor list found for ops tools.
Summary

German domain email hosting from Raidboxes GmbH (Münster): Mail Hosting 2.0 with IMAP/SMTP, multi-mailbox plans, optional PGP, and dashboard fit for WordPress agencies—domain must be hosted at RAIDBOXES.

German end-to-end encrypted email, calendar, and contacts from Tutao GmbH in Hanover—with post-quantum TutaCrypt, open-source clients, and freemium personal plus business plans.

Tags
At a glance: RAIDBOXES Emails vs Tuta
At a glanceLogo: RAIDBOXES EmailsRAIDBOXES EmailsLogo: TutaTuta
HQMünster, GermanyHanover, Germany (Tutao GmbH)
Legal entityRaidboxes GmbH (HRB 16184)Not listed
Groupteam.blue (Belgium) since 2022Not listed
ProductMail Hosting 2.0 domain emailEncrypted email, calendar, contacts (SaaS)
AccessIMAP / SMTP + webmailNot listed
Domain constraintDomain hosted at RAIDBOXES for new mailboxesNot listed
Open sourceNoClients GPLv3 on GitHub; no productized self-host
Self-hostedNoNot listed
HostingNot listedOwn servers in ISO 27001 data centers in Germany (vendor claim)
ProtocolsNot listedNo IMAP/SMTP client access; official apps only
CryptoNot listedTutaCrypt hybrid (Kyber-1024 + X25519 + AES-256) for new accounts
Commercial modelNot listedFreemium personal + paid personal/business (no ads)
Key capabilities: RAIDBOXES Emails vs Tuta
Key capabilitiesLogo: RAIDBOXES EmailsRAIDBOXES EmailsLogo: TutaTuta
German operatorYesNot listed
IMAP / SMTPYesNot listed
Mail Hosting 2.0YesNot listed
Online DPAYesNot listed
WordPress-adjacentYesNot listed
Optional PGPYesNot listed
Default mailbox E2EENot listedYes
TutaCrypt post-quantumNot listedYes
EU-operated (Germany)Not listedYes
Open-source clientsNot listedYes
DE data centers (claimed)Not listedYes
No IMAP (by design)Not listedYes

RAIDBOXES Emails

  • Mail Hosting 2.0 on RAIDBOXES infrastructure

    IMAP/SMTP mailboxes on dedicated hostnames (mail-rb.securemail.pro / smtp-rb.securemail.pro) after the move off the prior mailbox.org cooperation. Vendor claims German data-centre locations and triple-redundant mail servers. Best for teams that want domain mail under the same German WordPress host rather than a separate privacy-mail brand.

  • Multi-mailbox plans with aliases, forwards, and catch-all

    Tiered plans allocate a fixed number of mailboxes and a shared storage pool, plus per-mailbox alias and forwarding quotas, autoresponders, and catch-all (requires a dedicated catch-all mailbox). One connected domain per plan—confirm multi-domain needs before shortlisting.

  • Spam/virus filters, TLS, optional PGP, ad-free inboxes

    All plans include spam and virus filtering, SSL/TLS for transfer, a blacklist checker, webmail, and ad-free inboxes. PGP is optional rather than default end-to-end encryption for every message—teams that need mandatory E2EE workflows should evaluate Tuta or a full mailbox.org stack instead.

  • Dashboard-adjacent domain and WordPress ops

    Mailboxes are ordered from the RAIDBOXES dashboard and are intended to sit next to WordPress hosting and domain management. New RAIDBOXES mailboxes require the domain to be hosted with RAIDBOXES; legacy mailbox.org-linked domains follow a separate migration path documented in the help centre.

  • Online B2B DPA and German operator

    Raidboxes GmbH (Münster) offers an online data processing agreement (AV contract) with technical-organisational measures. Useful for agencies that already sign a DPA for WordPress hosting and want the same counterparty for domain email—still review TOMs and subprocessor scope for mailbox vs platform tooling.

Tuta

  • Default E2EE for mail, subjects, and attachments

    Between Tuta users, messages encrypt automatically including subject lines, bodies, and attachments. External recipients can use a shared password for end-to-end threads without installing software. Contacts and calendars use the same zero-access model; only delivery metadata (addresses, timestamps) stays readable by design.

  • TutaCrypt post-quantum hybrid cryptography

    New accounts use TutaCrypt: Kyber-1024 KEM plus X25519 ECDH with AES-256, targeting harvest-now-decrypt-later risks. Protocol details are published; existing accounts migrate as key rotation rolls out. Tuta intentionally avoids PGP so subjects and non-mail features can stay encrypted and algorithms can be upgraded in-product.

  • Zero-knowledge calendar with private reminders

    Calendar events—including times, titles, locations, and attendees—are end-to-end encrypted. Reminders are pushed as encrypted payloads and fired locally so servers are not told when an event starts. Sharing stays encrypted; invites can go out via mail, optionally password-protected for externals.

  • Open-source multi-platform clients (no IMAP)

    Web, Android (Play and F-Droid), iOS, Windows, macOS, and Linux clients are published under GPLv3 on GitHub. Desktop builds are signed for verification. There is no IMAP/SMTP bridge: third-party mail apps cannot connect, which preserves encryption at rest but forces a client switch for Outlook/Thunderbird holdouts.

  • Business domains, admin console, and whitelabel

    Paid business plans add custom domains, aliases, shared mailboxes, multi-admin roles, password/2FA resets, catch-all, templates, and optional branding/login on your own site. Vendor-stated uptime SLA and a GDPR order-processing agreement support B2B procurement—confirm current plan matrix on tuta.com.

Assurance & compliance: RAIDBOXES Emails vs Tuta
Assurance & complianceLogo: RAIDBOXES EmailsRAIDBOXES EmailsLogo: TutaTuta
Independent security / no-logs audit
Not found

No public third-party security or no-logs audit report found for RAIDBOXES Emails on primary pages.

Vendor claimed

Vendor states SySS GmbH penetration testing before public release; not a continuously published annual no-logs audit PDF on the marketing site.

ISO 27001
Not found

No company-wide ISO 27001 certificate for Raidboxes GmbH found on product/security pages; AWS region ISO mentions are not RAIDBOXES certs.

Partial

Official pages claim data centers are ISO 27001 certified; does not clearly establish a public Tutao GmbH organizational ISO 27001 certificate.

SOC 2 / SOC 3
Not found

No public SOC 2/3 report located for RAIDBOXES Emails.

Not found

No SOC 2/3 report located on security, business, or privacy pages.

GDPR / EU data protection
Vendor claimed

German controller (Raidboxes GmbH); product claims DE server locations and GDPR-aligned deletion; online DPA available. Confirm active mail stack vs privacy-policy mailbox.org listing.

Vendor claimed

German controller Tutao GmbH; privacy statement cites GDPR; DPO published; DE storage claimed.

US CLOUD Act exposure (indicative)
Partial

EU/German entity, no known US parent (team.blue BE group). Medium residual exposure via US-group platform subprocessors (AWS/DigitalOcean for online offer hosting; Intercom, Chargebee, Google tooling, Mailgun, etc.). Mail content path claimed DE-only. Not legal advice.

Partial

EU entity, no known US parent, primary mailbox hosting claimed as own DE servers—not AWS/GCP/Azure. Payment may use PayPal (Europe). Assessment is low exposure for content with residual billing/processor unknowns; not a vendor 'safe' claim. Not legal advice.

Data processing agreement (B2B)
Vendor claimed

Online AV/DPA flow at raidboxes.io/en/dpa/ and DocuSign TOM path documented in help centre.

Vendor claimed

Security/business materials state an Order Processing Agreement (Auftragsverarbeitung) is provided for GDPR; obtain signed version via sales—no public self-serve DPA URL confirmed.

EU AI Act
Not applicable

Domain email hosting product, not an AI system offering.

Not applicable

Encrypted email/calendar product; vendor states it does not plan AI that processes user communications for model training.

B Corp certification
Vendor claimed

Raidboxes GmbH listed as Certified B Corporation on B Lab directory; impact certification, not an information-security audit.

Not listed
Considerations & known limitations: RAIDBOXES Emails vs Tuta
Considerations & known limitationsLogo: RAIDBOXES EmailsRAIDBOXES EmailsLogo: TutaTuta
Domain must be hosted at RAIDBOXES
Medium

New mailboxes require the domain on RAIDBOXES. That is convenient for WP customers and a lock-in factor if you only wanted independent mail.

Not listed
One connected domain per plan
Medium

Multi-domain operators need multiple plans or another provider; not a Migadu-style multi-domain account model.

Not listed
PGP optional, not default E2EE
Medium

Threat models that assume provider-side unreadability by default are a better fit for Tuta or similar products.

Not listed
US-group platform subprocessors
Medium

Privacy policy discloses AWS EMEA, DigitalOcean, Intercom, Chargebee, Google tools, Mailgun, and others for website/support/billing/marketing—even while email marketing claims German mail servers. Scope diligence to mailbox vs platform data paths.

Not listed
Privacy policy may lag Mail Hosting 2.0
Low

§Email box still lists mailbox.org/Heinlein while marketing claims first-party hosting—confirm live stack and subprocessor annex for your contract.

Not listed
No public ISO/SOC/mail audit
Medium

B Corp is not a security certification. Enterprise security questionnaires may need NDA materials or alternative providers with published audits.

Not listed
No IMAP/SMTP third-party clientsNot listed
High

Desktop and mobile holdouts cannot stay on Outlook/Thunderbird/Apple Mail. Plan full client migration or pick a standards-based alternative.

Weaker protection to non-Tuta recipientsNot listed
Medium

Without a shared password, external mail is ordinary SMTP (TLS in transit). Only Tuta-to-Tuta and password-protected external threads are true E2EE.

Hosted service, not on-prem mailNot listed
Medium

Open-source clients help inspectability, but mailboxes still depend on Tutao's German SaaS backend, uptime, and German legal process.

Data-center ISO vs company ISMSNot listed
Low

ISO 27001 wording refers to data centers. Do not tick 'vendor ISO 27001 certified' on questionnaires without the actual Tutao certificate.

Limited public subprocessor inventoryNot listed
Medium

Privacy policy covers payments (e.g. PayPal Europe) but lacks a detailed live subprocessor register. Request the DPA annex for DPIA completeness.

German court orders on accessible dataNot listed
Low

Transparency reports show regular German requests. Stored E2EE content stays undecryptable by Tutao; real-time monitoring can expose newly arriving unencrypted SMTP mail. Align expectations with counsel.

Fit

RAIDBOXES Emails

Best fit when

  • WordPress agencies and freelancers standardising on RAIDBOXES for sites, domains, and mail admin
  • SMEs wanting professional multi-mailbox domain email with standard IMAP clients—not a full Google/Microsoft suite
  • Teams that need catch-all, aliases, forwards, autoresponders, and ad-free inboxes on one domain
  • Buyers who require a German legal counterparty and an online B2B DPA for processor agreements
  • Operators migrating off legacy mailbox.org-linked RAIDBOXES mail toward first-party Mail Hosting 2.0

Poor fit when

  • Multi-domain mail estates that need many domains under one contract (one connected domain per plan)
  • Policies requiring default end-to-end encryption for all mail (PGP is optional only)
  • Buyers who refuse any coupling between mailbox service and domain/WordPress hosting
  • Teams seeking a full office suite (Drive, collaborative docs, built-in video) rather than domain mail
  • Procurement that demands public ISO 27001/SOC 2 or independent no-logs audit reports for the mail product

Consider instead when

  • When: You need multi-domain, usage-based professional mail without WordPress host lock-in

    Consider: Migadu

    Swiss-operated, standards-based hosting priced by quotas rather than per-domain WordPress adjacency

  • When: You need default E2EE and a privacy-first client model

    Consider: Tuta

    Different threat model; less IMAP flexibility than RAIDBOXES

  • When: You want privacy-oriented German personal/business mail without hosting coupling

    Consider: Posteo or mailbox (formerly mailbox.org)

    mailbox is also the former RAIDBOXES mail partner and a deeper digital-workplace option

  • When: You need Google/Microsoft suite collaboration, not just domain mailboxes

    Consider: Google Workspace or Microsoft 365

    US Big Tech residency and CLOUD Act profile differ sharply—use only if suite features dominate

Tuta

Best fit when

  • Teams that will standardize on Tuta's official web/mobile/desktop clients for default zero-access email
  • Orgs prioritizing subject-line encryption, encrypted calendar, and post-quantum hybrid crypto under German jurisdiction
  • SMEs needing custom domains, aliases, shared mailboxes, and multi-admin controls without running their own mail servers
  • Journalists, NGOs, and privacy-led departments that value F-Droid builds, no Google Push dependency, and ad-free operation
  • Buyers who want open-source client auditability plus a freemium path for personal trial before business seats

Poor fit when

  • Hard requirement for IMAP/SMTP in Outlook, Thunderbird, Apple Mail, or third-party automation
  • On-prem / customer-operated mail server mandates (no productized self-host for the backend)
  • Workflows that depend on first-class PGP or S/MIME interoperability with external partners
  • Primary need is full Google Workspace or Microsoft 365 collaboration (Drive, Meet, deep Outlook) rather than encrypted mail first

Consider instead when

  • When: Users must keep desktop IMAP clients or need Bridge-style Outlook integration

    Consider: Proton Mail (Bridge on paid plans) or mailbox.org / Posteo / Soverin

    Those options trade Tuta's automatic subject E2EE model for standards-based access

  • When: You need a broader German digital workplace (Drive, Office, video) with optional PGP

    Consider: mailbox.org

    Stronger suite breadth; different default encryption depth than Tuta's full zero-access mailbox

  • When: Swiss jurisdiction and multi-product privacy suite (VPN, drive, pass) matter more than German HQ

    Consider: Proton Mail

    Compare Bridge, ecosystem lock-in, and published cert posture side by side

  • When: Belgian OpenPGP-centric suite with browser crypto and classic protocols is preferred

    Consider: Mailfence

    Different encryption UX (PGP-oriented) versus Tuta's automatic proprietary stack

Open questions for due diligence

RAIDBOXES Emails

  • For a new Mail Hosting 2.0 mailbox, is mailbox.org/Heinlein still a subprocessor for mailbox content, or only a legacy path?
  • Which German data-centre operators and exact regions host mail storage and backups (primary + DR)?
  • Does the standard DPA/TOM annex explicitly cover email hosting subprocessors separately from WordPress hosting?
  • What are published RPO/RTO and restore procedures for mailbox backups?
  • Are there any upcoming multi-domain plan options or reseller mail SKUs?

Tuta

  • Will Tutao provide a current signed AVV/DPA with a full subprocessor list (DNS, billing, support, CDN if any)?
  • Is there a current organizational ISO 27001 or SOC 2 report for Tutao GmbH, or only facility-level data-center certification?
  • What is the documented status of TutaCrypt key rotation for all legacy accounts in your tenant?
  • Are any US-group cloud services used for backups, DNS, or support tooling beyond payment processors named in the privacy statement?
  • For business rollout: migration tooling limits (EML/MBOX import on desktop) and dual-running period with legacy IMAP hosts?