Logo: Mailfence

Mailfence

Belgian secure email suite with browser-side OpenPGP encryption, digital signatures, calendar, documents, and optional custom domains under ContactOffice Group SA.

Mailfence is a secure webmail and collaboration suite operated by ContactOffice Group SA in Brussels. The Mailfence brand launched as a privacy-focused email product on top of ContactOffice's longer-running European collaboration platform. The core offer is email with browser-side OpenPGP encryption and digital signatures, plus calendar, documents, and contacts.

It exists as a Belgian alternative to Gmail-class inboxes for people who want interoperable OpenPGP rather than a closed encryption format. Recipients on other OpenPGP systems can verify and decrypt. Password-encrypted messages cover recipients who do not use PGP.

The concrete differentiator is that OpenPGP keystore plus optional Mailfence for Business: white-label, directory integrations, and either Belgian cloud hosting or a license to run on customer Linux servers.

EU-operated (Belgium)OpenPGP E2EEDigital signaturesMail + calendar + docsCustom domains (paid)B2B DPA available

Shortlist Mailfence when you want Belgian-operated webmail with interoperable OpenPGP, digital signatures, and a light calendar/documents suite—plus optional business private-label or on-prem license. Skip when you need automatic closed E2EE without key management (consider Tuta), a large Swiss privacy ecosystem (Proton Mail), or a minimalist German mailbox (Posteo / mailbox.org).

Key capabilities

Encrypt outbound mail in the browser with the OpenPGP standard so intermediaries—including Mailfence when messages are properly E2EE—cannot read ciphertext. Fully interoperable with other OpenPGP tools (e.g. Thunderbird/GnuPG). Optional password-encrypted messages cover recipients who do not use PGP. Unencrypted mail still sits on servers in the normal webmail model.

Sign messages for authenticity and integrity, and manage keys in-product: generate, import, export, publish, and hold multiple key pairs without browser plug-ins. Default generated keys are 4096-bit per the threat-model page. Passphrase protection of private keys limits crypto operations if only the account password is compromised.

Beyond inbox: shareable calendars, online document storage/editing, and contact groups for collaboration without bolting on a separate US suite. Storage and alias limits scale by plan; free accounts remain suitable only for light personal use.

Higher plans add custom domains with SPF/DKIM/DMARC-oriented setup, larger alias counts, and classic client access (POP, IMAP, SMTP) plus ActiveSync where listed. Entry-level free accounts focus on web/PWA/apps rather than full protocol parity—verify the live plan matrix before procurement.

Mailfence for Business offers control-panel and XML-RPC API user provisioning, SSO and directory hooks (LDAP/AD/CAS), branding, and Belgian cloud hosting with SLA language—or a license to run on customer Linux servers for large deployments. Fit for orgs that need Belgian hosting with admin automation, not a consumer-only mailbox.

At a glance

HQ / entity
Brussels — ContactOffice Group sa (BE 0466.241.584)
Product launch
Mailfence brand ~2013; ContactOffice lineage since 1999
Crypto
OpenPGP E2EE + digital signatures; optional password-encrypted messages
Hosting
Vendor-operated servers in Belgium (per security page)
Open source
No (front-end OSS planned; not current)
Self-host
SaaS default; Business license for large on-prem deployments
Commercial model
Free tier + prepaid paid plans; Business packaging (see vendor site)
Independent audit
No public audit PDF found

Best fit when

  • You need OpenPGP interoperability and digital signatures from a European webmail, not only proprietary E2EE
  • Belgian legal entity and self-described self-operated Belgian hosting are procurement requirements
  • Teams want mail plus calendar/documents/groups without moving to Microsoft 365 or Google Workspace
  • You need custom domains, aliases, and classic clients (IMAP/POP/ActiveSync) on paid tiers
  • Business buyers evaluating private-label, API provisioning, SSO/directory integration, or large-scale on-prem license

Poor fit when

  • Security policy requires a published independent security audit, ISO 27001, or SOC 2 from the email vendor
  • You want fully open-source server/client stacks you can fork and self-host as default
  • Every message must be automatically E2EE with no OpenPGP key UX (Tuta-style)
  • You need Microsoft-class DLP, eDiscovery, compliance archives, and deep SaaS integrations
  • Zero-logs marketing is a hard requirement (Mailfence documents operational metadata collection)

Consider instead when

  • When: You want automatic encryption for all messages with minimal key management

    Consider: Tuta

    Different crypto model; less OpenPGP interop emphasis than Mailfence.

  • When: You want a larger Swiss privacy suite brand and ecosystem apps

    Consider: Proton Mail

    Trade Belgian ContactOffice ownership and PGP-centric UX for Proton’s broader product family.

  • When: You want a lean German ad-free mailbox without suite features

    Consider: Posteo or mailbox.org

    Simpler mailbox posture; different admin/domain/crypto tradeoffs.

  • When: You need full Google/Microsoft productivity and compliance tooling

    Consider: Microsoft 365 or Google Workspace (accept US-cloud risk) or EU office suites if residency is the driver

    Mailfence is not a drop-in M365 replacement.

Jurisdiction & ownership

Legal entity
ContactOffice Group sa, Avenue Franklin Roosevelt 47b, B-1050 Brussels (BE 0466.241.584)
Governing law
Belgian law; Brussels courts (Terms of Use)
US parent / control
No known US parent
CLOUD Act exposure (indicative)
Low
Hosting / residency
Primary production servers described as located in Belgium under Mailfence operational control (no intermediary managing servers per security page). No public AWS/GCP/Azure subprocessor list found. Backups stored in locations separate from offices/main DC (providers not named). Payment-card processing path not fully published.

No known US parent from public materials. Vendor claims internal data handling and Belgian LE process only. Indicative CLOUD Act exposure via US corporate parent is low relative to US-owned webmail; residual risk remains if any undisclosed US payment/SaaS tooling is used. Not legal advice.

  • Independent security / no-logs auditNot found
  • ISO 27001Not found
  • SOC 2 / SOC 3Not found
  • GDPR / EU data protectionVendor claimed
  • +3

Considerations & known limitations

  • MediumNo public independent security audit

    If vendor risk requires a published audit letter, ISO 27001, or SOC 2, treat Mailfence as incomplete until evidence is obtained offline or under NDA.

  • MediumClosed-source SaaS

    Cannot independently review server code or default-self-host like some FOSS mail stacks. Business on-prem license is a commercial path, not community self-host docs.

  • MediumE2EE is opt-in OpenPGP, not automatic

    Clear-text messages are operator-readable at rest. Users must encrypt/sign deliberately; training and policy matter for regulated content.

  • LowOperational metadata retention

    Privacy policy lists IP, message-IDs, addresses, subjects, and related fields for operations, abuse control, and legal process—not a zero-logs design.

  • LowLimited public subprocessor inventory

    Strong first-party claims of internal hosting, but no AWS-style public subprocessor table; confirm payment and support tooling in procurement.

  • LowUS CLOUD Act (indicative)

    No known US parent; Belgian self-operated hosting narrative. Residual unknown payment/SaaS paths. Not a legal safe harbour guarantee.

Open questions for due diligence

  • Will Mailfence provide a current written subprocessor list (including payment processors and any backup locations) for a company account?
  • Is any independent security assessment available under NDA for regulated buyers?
  • For Business on-prem license: exact minimum scale, support model, update cadence, and cryptographic feature parity vs SaaS?
  • Which plan tiers currently include IMAP/POP/ActiveSync and custom-domain limits for our user count?
  • How are disaster-recovery backup sites jurisdictions documented in the signed DPA annex?

Frequently Asked Questions

No. Mailfence’s headline E2EE path is user-controlled OpenPGP (and password-encrypted messages for non-PGP recipients). Messages you send in clear text are protected in transit with TLS where peers support it, but content remains readable to the service operator in the standard webmail threat model. Choose Mailfence when interoperable OpenPGP and digital signatures matter; choose Tuta when automatic closed encryption with minimal key UX is the requirement.

Public security materials state production servers are in Belgium under Mailfence’s operational control, without a third party managing those servers. Standard consumer and most business cloud seats are SaaS. Mailfence for Business documents a separate license model to host the application on your own Linux servers (vendor guidance points at larger deployments, e.g. on the order of 1,000+ users). Confirm architecture, SLA, and support boundaries in a written proposal.

The product is not open source today; the knowledge base states a future intent to open-source the front-end and that the back-end can be inspected by recognised auditors/researchers. No public third-party security or no-logs audit report or ISO 27001/SOC 2 certificate was found on primary pages during research. Procurement teams that require published audits should request evidence under NDA or shortlist audited peers.

Webmail, progressive web apps, and vendor iOS/Android apps are available across tiers. POP, IMAP, SMTP, and ActiveSync are advertised on higher paid plans (not as unrestricted free-tier features on the public matrix). Combine with OpenPGP-capable desktop clients when you need offline crypto outside the web keystore. Always re-check the current plan comparison on mailfence.com before assuming protocol access.

The privacy policy lists operational data such as IP addresses, message-IDs, sender/recipient addresses, subjects, browser versions, countries, and timestamps, plus anti-spam/virus processing and payment details when you pay by card. It is not a zero-logs service. Jurisdiction is Belgian; transparency reports summarise Belgian court-order identification requests. Non-Belgian agencies are not served directly according to the vendor. Treat transparency figures as first-party disclosures and re-read the latest report before risk review.

Yes. The GDPR page links a Data Processing Agreement document for organisations that need Art. 28-style processor terms. Pair the DPA with your own due diligence on hosting, backups, support access, and any payment subprocessors not listed on the public site.