Logo: Posteo

Posteo

Independent Berlin email provider with self-operated German servers, data-minimising signup, open-standard clients, and layered optional encryption—not a free-tier ad network.

Open source

Posteo is an independent, prepaid email service operated by Posteo e.K. in Berlin. Since 2009 it has offered ad-free mailboxes with calendar (CalDAV), contacts (CardDAV), and notes, financed only by users according to the company: no ads, no tracking, and no outside investors.

It exists for people who want German-operated mail with data economy rather than a free-tier advertising inbox or a proprietary E2EE silo. Signup does not require a name or address. Payment data is deliberately unlinked from the mailbox. Posteo says it operates its own servers in German data centres.

The concrete differentiator is open-standard access (IMAP, POP3, SMTP, plus webmail) combined with optional whole-mailbox crypto storage and inbound PGP or S/MIME encryption. It is not a self-host product.

Self-operated DE serversData-minimising signupIMAP / CalDAV / CardDAVBSI TR-03108 (verified)Optional crypto mail storageAd-free, user-funded

Shortlist when you want a paid German mailbox on self-operated servers, open protocols (IMAP/CalDAV), and extreme data minimisation (no inventory data, unlinked payments). Skip when you need custom domains, default E2EE without setup, multi-seat enterprise admin, or an Art. 28 DPA—consider Proton Mail, Tuta, mailbox.org, or Mailfence instead.

Key capabilities

Accounts can be created without name, address, or phone. Posteo's payment system (bank transfer codes, cash, card, PayPal) is designed so payment identifiers are not stored against the mailbox. Practical limit: recovery options you add yourself and how you fund the prepaid balance still affect anonymity in the real world.

One setting encrypts stored messages—including metadata—with a key protected by the account password (RSA/AES/HMAC/bcrypt design; Dovecot plugin). Posteo states it cannot disable crypto storage once enabled and cites a Cure53 review. Limit: this is server-side encryption at rest after delivery, not sender-to-recipient E2EE, and losing the password can mean losing access to encrypted data.

Access is TLS-only with PFS, HSTS, and DANE/TLSA. Optional TLS-sending/receiving guarantees refuse delivery over cleartext peer links. Posteo holds BSI TR-03108 v2 Secure Email Transport certification (BSI-K-TR-0745-2025). Transport quality still depends on the remote provider's stack.

Calendars and contacts sync via open standards and can be AES-encrypted in Posteo's database so the provider cannot read them when the feature is on. Trade-off: encrypted calendars cannot be shared the same way, and password reset without the old secret can lock you out of encrypted PIM data.

Posteo's own migration tool pulls mail (and often contacts/calendars) over encrypted links from previous providers without routing through a third-party migration SaaS. Quota: a limited number of migrations per account, with an optional collector for ongoing fetch from the old box.

At a glance

HQ
Berlin, Germany
Legal entity
Posteo e.K. (HRA 47592 B)
Hosting
Self-operated servers in Germany
Commercial model
Prepaid paid service; no free tier
Protocols
IMAP, POP3, SMTP, CalDAV, CardDAV
Self-host
No (hosted service)
Founded
2009
Energy
100% green energy (Green Planet Energy, claimed)

Best fit when

  • Individuals and small teams who want German jurisdiction and open-standard clients without Google or Microsoft mail
  • Users prioritising anonymous or low-identity signup and prepaid funding without linking payments to the mailbox
  • Organisations that accept posteo.* addresses and value no ads, no tracking, and published transparency reports
  • Operators who want optional full-mailbox encryption at rest (crypto mail storage) plus PGP/S/MIME tooling
  • Buyers who need BSI-aligned secure email transport certification rather than US SOC 2 paperwork

Poor fit when

  • Anyone requiring custom domains or branded organisational addresses
  • Teams that need default zero-access E2EE for every message without enabling optional layers
  • Procurement processes that mandate a signed Art. 28 DPA, SOC 2, or ISO 27001 from the vendor
  • Large enterprises needing multi-seat admin, shared domain policies, or deep Microsoft/Google workspace integration

Consider instead when

  • When: You need default end-to-end encryption and a broader encrypted suite

    Consider: Proton Mail or Tuta

    Posteo is IMAP-first with optional crypto layers; Proton/Tuta lead with zero-access defaults.

  • When: You need custom domains or richer business mail hosting

    Consider: mailbox.org or Mailfence

    Posteo deliberately refuses own domains to avoid inventory-data obligations.

  • When: You need free-tier consumer mail tightly integrated with docs and chat

    Consider: Gmail or Outlook.com

    Trade privacy posture and EU self-operation for ecosystem convenience.

Jurisdiction & ownership

Legal entity
Posteo e.K., Methfesselstr. 38, 10965 Berlin
Governing law
German / EU law (GDPR, BDSG, telecom secrecy / TTDSG as applicable)
US parent / control
No known US parent
CLOUD Act exposure (indicative)
Low
Hosting / residency
Self-operated infrastructure; stored mail and backups in Germany (Frankfurt, Bielefeld, Berlin DCs per privacy materials). No AWS/GCP/Azure listed for mailbox hosting. Payment top-ups may use PayPal/card networks (unlinked from accounts per Posteo).

No known US parent; public privacy policy asserts no voluntary transfer of personal data to third-party companies for the service. Indicative CLOUD Act exposure is low relative to US-parent or hyperscaler-hosted mail, but not zero: German court orders can compel content; payment processors are separate commercial rails. Not legal advice.

  • Independent security / no-logs auditPartial
  • ISO 27001Not found
  • SOC 2 / SOC 3Not found
  • GDPR / EU data protectionVendor claimed
  • +4

Considerations & known limitations

  • HighNo custom domains

    Posteo will not host your own domain. Organisations needing brand continuity or provider portability via DNS must pick another host or self-host.

  • MediumEncryption is layered, not default E2EE

    Without crypto mail storage, inbound encryption, or client-side PGP/S/MIME, Posteo can process mailbox content like a normal provider. Lawful intercept (TKU) and seizures remain possible under German process; transparency reports show content releases do occur under court order.

  • MediumNo customer Art. 28 DPA

    Procurement checklists that require a signed processor agreement will stall. Posteo argues telecom special law applies instead; validate with legal counsel for your use case.

  • MediumPassword loss risk with crypto features

    Crypto mail storage and encrypted calendars/contacts depend on the account password; Posteo cannot recover plaintext if that secret is lost after encryption is enabled.

  • LowPayment processors outside pure DE mail path

    Optional PayPal/card top-ups involve non-German commercial processors even though Posteo says it does not link payment identity to the mailbox. Cash/bank-code paths reduce that linkage further.

Open questions for due diligence

  • Does your counsel accept Posteo's position that no Art. 28 DPA is required for occupational use?
  • Will posteo.de / .net / .com addresses meet your brand, deliverability, and anti-spoofing requirements without custom domains?
  • Which encryption layers (crypto mail storage, inbound PGP/S/MIME, client E2EE) will your users actually enable and support?
  • Do you need ISO 27001/SOC 2 artefacts that Posteo does not publish?
  • Is BSI TR-03108 transport certification sufficient for your sector's secure-email checklist?

Frequently Asked Questions

No. Posteo's FAQ states that custom domains are incompatible with its data-economy model: domain registration creates inventory data that German rules can force providers to retain and disclose. Choose mailbox.org, Mailfence, or a self-hosted stack if branded domains are mandatory.

No. Default operation is a conventional mailbox with strong transport encryption and disk encryption. Users can layer optional crypto mail storage, inbound PGP/S/MIME encryption, webmail Mailvelope (OpenPGP), and the Posteo S/MIME add-on. For zero-access defaults without setup, evaluate Proton Mail or Tuta instead.

Posteo publishes legal analysis that it is a publicly available electronic communications service under German telecom law, not an Art. 28 processor, and therefore does not offer customer DPAs—even for occupational use. Confirm with counsel whether that stance fits your controller/processor map; peers that sell business DPAs may fit procurement checklists better.

Privacy and encryption pages state that Posteo operates its own server infrastructure with all stored data in Germany (data centres in Frankfurt, Bielefeld, and Berlin) and does not hand personal data to third-party companies for the mail service. Daily backups are retained seven days. No AWS/GCP/Azure tenancy is listed on those primary pages; payment processors used for prepaid top-ups are separate from mailbox content paths.

Yes. IMAP, POP3, and SMTP (TLS required) work with Thunderbird, Outlook, Apple Mail, and mobile apps; calendars and contacts use CalDAV/CardDAV. App passwords support clients when 2FA is enabled. There is also a webmail interface and progressive web app.