(A companion to my Proton Mail post, the wider field of privacy email providers, what their controversies actually mean, and which service is the least likely to get you identified.)


If you read my last post, you’ll know I landed on Proton Mail as my email home after finally cutting ties with Gmail and Outlook in 2025. One practical thing worth knowing if you go that route before we get into alternatives: IMAP access, for using Proton with a third party client like Thunderbird or Apple Mail, requires both a paid subscription and Proton’s own Bridge app installed on your machine. The free tier is locked to Proton’s own apps. Not a dealbreaker, but worth knowing before you commit. But writing that piece made me realise I’d glossed over something important: the wider field. Proton gets the headlines, absorbs the controversy, and dominates the privacy email conversation to the point where most people don’t realise there are genuinely strong alternatives, some of which have cleaner track records, and a few of which are better suited to specific use cases that Proton doesn’t quite nail.

So this is the companion post. We’re going to look at the main players, what they actually offer across free and paid tiers, where they’ve stumbled, and then get into the question that the Stop Cop City reporting quietly raised but nobody seems to be answering directly: for activists and whistleblowers, which of these services is actually the least likely to get you identified?

Spoiler: the answer is more nuanced than any single provider’s marketing will tell you.

Before we start, the encryption limitation nobody advertises. End-to-end encryption only applies when both sender and recipient use compatible encryption, either the same service, or manually exchanged PGP keys. If you’re on Proton and you email someone on Gmail, that email is not end-to-end encrypted. It’s encrypted in transit, but it lands in Google’s servers in plaintext. Less obviously: if you’re on Proton and you email someone on Tuta, that’s also not E2E encrypted by default. Proton and Tuta use different encryption systems that aren’t interoperable. The same logic applies across every provider in this comparison. In practice, the majority of emails most people send will fall into this category. Switching to a privacy email provider protects your inbox from your provider. It doesn’t protect the inbox of whoever you’re emailing.

Also worth knowing, the password loss problem. Zero-knowledge encryption means the provider genuinely cannot read your emails. It also means that if you forget your password and lose your recovery key, neither can you. Permanently. Unlike Gmail, where a forgotten password is a minor inconvenience, losing your master password on Proton or Tuta without a valid recovery key means your emails are gone. The encryption is working exactly as designed. Write your recovery key down somewhere physical and keep it somewhere you’ll actually be able to find it, or store it in your encryption vault if you use a password manager, but that does have its own obvious downsides if your password manager gets compromised.

1️⃣ The contenders Link to heading

There are more privacy focused email providers than most people realise. This isn’t an exhaustive list, it’s the ones I think are worth having an opinion on.

Tuta (formerly Tutanota) - Germany Link to heading

Tuta is probably the most serious technical competitor to Proton Mail. Based in Hanover, operating under German law and full GDPR coverage, it’s been in the privacy email space since 2011 and has quietly built a reputation as the provider that takes encryption the most seriously of anyone in this space.

Where it differentiates: Tuta encrypts everything by default. The email body, attachments, subject lines, calendar entries, and contact data. The subject lines matter more than you’d think, as subject lines are metadata, and metadata is routinely what gets handed over in legal requests. Proton Mail doesn’t encrypt subject lines by default. Tuta does. In 2024, Tuta also became the first major provider to implement post-quantum cryptography via their TutaCrypt protocol, which protects data against decryption by future quantum computers. Whether that matters to you right now is a separate question, but it signals seriousness.

Tuta also doesn’t use Google’s push notification infrastructure for Android, having built its own system, which is a small but telling detail about how committed the team is to not having Big Tech fingers in the stack.

Free tier: 1GB storage, one calendar, one email address. Functional but limited, you may hit the ceiling quickly if you’re using it as a primary inbox and not clearing out old content.

Paid tiers: the ‘Revolutionary’ plan starts at €3/month for 20GB, unlimited calendars, and 15 email addresses. The ‘Legend’ plan is €8/month for 500GB and 30 addresses. Business plans from €6 - 12/month.

The controversy: in 2020, a German regional court in Cologne ordered Tuta to monitor an account used in an extortion attempt and hand over unencrypted emails. Tuta fought it, called it “absurd,” and appealed to Germany’s Federal Court of Justice. They lost. The BGH ruled that Tuta qualified as a telecommunications service under German law and was subject to lawful intercept requirements. The part that matters for users: only unencrypted emails were affected, anything already end-to-end encrypted could not be decrypted, and Tuta confirmed the company holds no decryption keys. More recently, in 2023, a former RCMP intelligence officer on trial in Canada alleged that Tuta had operated as a “storefront” for intelligence agencies. Tuta categorically denied it, pointed to their fully open sourced client code, and pushed back publicly. The allegation came from a discredited witness with no supporting evidence, and most of the security community took Tuta’s denial at face value.

The broader picture: Tuta has consistently fought legal orders, been transparent about them, and has never been shown to have handed over encrypted content. Where it has complied, as it legally must, it has been with unencrypted metadata only.

Mailfence - Belgium Link to heading

Mailfence is the quiet one. It doesn’t dominate privacy email discourse, doesn’t chase expansion into other products, and rarely makes headlines, which is, arguably, exactly the kind of company you want handling your email.

Run by ContactOffice Group, a Belgian company with roots going back to 1999, Mailfence operates under Belgian law and EU GDPR. Belgium’s privacy protections are strong, and critically, only a valid Belgian court order can compel the company to release data. It has no foreign parent company, which means it’s not subject to US gag orders or National Security Letters, which is something it states plainly on its website.

The encryption model uses OpenPGP (the same standard Proton uses) but there’s a meaningful difference: Mailfence doesn’t automatically encrypt mail between Mailfence users by default the way Proton does. Both sender and recipient need to have PGP set up and exchange keys for end-to-end encryption to kick in. That’s more friction than most people want, but it keeps the system interoperable with the broader email ecosystem, which some users prefer.

Mailfence also has an uncommonly honest approach to its commercial model: it donates 15% of revenue from its higher tier plans to digital rights organisations including the EFF and European Digital Rights. You can debate whether that matters for trust, but it signals a values commitment that goes beyond marketing.

Free tier: 500MB email storage, 500MB file storage. Limited but functional for light use.

Paid tiers: starting at roughly €2.50/month for 5GB email and 6GB file storage, scaling up through team and business plans.

The controversy: a relatively clean record, which is notable. Mailfence has received legal requests, published them in its transparency reports, and has documented cases where it refused to comply with requests it deemed unlawful or non conformant with Belgian law.

Posteo - Germany Link to heading

Posteo is the odd one out in this space, and deliberately so. No free tier. No custom domains. No IMAP or POP. €1/month, flat, for a no frills private email service with a notably principled stance on privacy.

What makes Posteo stand out is its data minimisation philosophy taken to a logical extreme: it collects essentially none. No name required on signup, no IP address logging, and it explicitly separates payment data from accounts, meaning even if authorities obtain Posteo’s payment records, they can’t link payments to specific email accounts. That’s a structural privacy protection that most providers don’t bother with. They do also accept cash.

Posteo also runs on 100% green energy, is entirely independently owned, and publishes unusually candid transparency reports that list the data requests received alongside open criticism of law enforcement for regularly sending requests that don’t comply with German legal requirements. It’s the kind of thing a company does when it’s genuinely invested in the fight rather than performing it.

The tradeoff is real though. No custom domain means you’re stuck with a @posteo.de address. No IMAP/POP means you use their webmail or their own apps. And end-to-end encryption requires manual setup, Posteo supports it but doesn’t automate it. For non technical users, that’s a significant barrier.

Free tier: none.

Paid tier: €1/month for 2GB, expandable at €0.25/month per GB. Simple, ethical, transparent.

The controversy: very little. Posteo has been the subject of legal requests and has complied only where required under German law. Given that it holds no IP addresses or personal data by design, there’s often nothing to hand over even if compelled. That’s the most honest data protection posture available: not having the data in the first place.

StartMail - Netherlands Link to heading

StartMail was built by the founders of Startpage, the privacy focused search engine. It’s a Netherlands based service operating under Dutch law and EU GDPR, and its primary differentiator is its alias system: unlimited disposable and custom aliases, all forwarding to one inbox. For people managing a lot of online accounts, that’s a genuinely useful privacy tool.

The interface is clean and accessible, PGP encryption is available and simplified to a one click setup, and it supports IMAP, meaning you can use it with Thunderbird, Apple Mail, or any standard client. That interoperability is StartMail’s pitch: you don’t have to change how you use email, just who handles it.

The notable absence: there’s no free tier. StartMail offers a 7 day trial and that’s it. If you want the service, you pay for it, which from a privacy standpoint is actually the correct model, even if it limits accessibility.

Free tier: none (7-day trial only).

Paid tier: approximately $4.99/month, all inclusive.

The controversy: StartMail has a relatively clean record. As a Dutch company it operates under GDPR and the Netherlands’ telecommunications laws. There’s no significant publicly documented case of StartMail handing over data in a way that resulted in user identification. It’s not as widely battle tested as Proton or Tuta, but its track record is uneventful in the way you’d want.

Hushmail - Canada Link to heading

Worth a mention, but not for the reasons its marketing would prefer. Hushmail has long marketed itself as a privacy email provider, and it does offer encryption, but it operates under Canadian jurisdiction, which is a Five Eyes country. That alone should give high risk users pause.

More significantly, there’s a documented historical case: in 2007, Hushmail handed over decrypted emails to US authorities in a drug trafficking investigation after being served a court order in Canada. The mechanism was a Java applet that Hushmail could deploy to a specific user’s session to capture the passphrase. This was not a hack. It was a designed vulnerability in the system, one the company was legally compelled to use, but which demonstrated that “we can’t read your emails” was conditional in ways the marketing hadn’t made clear.

Hushmail has since moved to a fully web based system and updated its disclosures to be clearer about its legal obligations. But for anyone with a high stakes privacy requirement, a Five Eyes jurisdiction with a documented history of state compelled decryption is a hard pass.

Free tier: a limited 25MB option.

Paid tier: from $4.99/month.

2️⃣ Controversies compared Link to heading

A pattern emerges when you look across these providers.

Every privacy email service operating in a real jurisdiction is subject to that jurisdiction’s laws. What separates them is how much data they hold, whether they fight orders, how transparent they are about compliance, and whether their encryption model means content is protected even when metadata isn’t.

Tuta and Proton have both complied with legal orders and been transparent about it. The difference is that Tuta has consistently fought orders in court and structured its service so that even when it must comply, it has no decryption keys to hand over. Proton has done the same on content, but its record on metadata, particularly the payment data and IP address cases, is what’s caused the most damage to its reputation.

Mailfence and Posteo have cleaner public records, partly because they’re smaller and less targeted, and partly because Posteo especially has designed away the most exploitable data points. Hushmail is the cautionary tale: a company that couldn’t protect its users when the legal pressure came, not because of malice but because of architectural choices it made early on.

There’s a third category worth knowing about, even if it’s historical: Lavabit. In 2013, Lavabit, the encrypted email service used by Edward Snowden, received a US government order to hand over its SSL private keys, which would have given the FBI access to all of its users’ communications. The owner, Ladar Levison, chose to shut the entire service down rather than comply. He couldn’t warn users; he was under a gag order. It’s the definitive example of a provider choosing total non compliance, and the cost was the service itself. Lavabit relaunched in 2017 with an architecture specifically designed to make that kind of compelled disclosure technically impossible. It has a small user base today and isn’t in the main comparison, but it’s the reference point the whole “what does a provider do when truly cornered?” conversation is built around.

3️⃣ For activists and whistleblowers - the honest assessment Link to heading

This is where most privacy email guides get vague, and it’s worth being direct.

If your safety genuinely depends on not being identified, email is probably the wrong primary tool. The structural properties of email, sender address, recipient address, timestamps, subject lines, IP metadata, create a trail that even the best providers can’t fully eliminate. The Freedom of the Press Foundation recommends SecureDrop for journalists receiving tips from high risk sources precisely because it’s designed from the ground up for anonymous document transfer in a way that email is not.

That said, if you’re using email, here’s the honest breakdown.

For most activists and journalists doing routine sensitive work, Proton Mail or Tuta are both reasonable choices. Both have fought legal orders, both encrypt content, both are outside Five Eyes jurisdiction. Tuta’s subject line encryption is a genuine advantage. Proton’s usability and wider ecosystem integration makes it more accessible. Pay with cash or Monero. Use Tor when signing up. Don’t attach a recovery email.

For higher risk situations, whistleblowers in particular, Tuta has structural advantages. No IP logging, signup without a phone number, anonymous payment options (Bitcoin and Monero accepted), and the ability to sign up via Tor. The fact that it encrypts subject lines means less metadata is available even if a legal order arrives. Its German jurisdiction requires court orders for any data release, and it has a documented history of challenging those orders.

Posteo deserves an honourable mention for extreme threat models in one specific way: it literally doesn’t have the data to hand over. No IP addresses, no personal information, payment data structurally separated from accounts. If an authority compels Posteo for your account data, they may get email content if it isn’t end-to-end encrypted, but they won’t get an IP address or a name, because Posteo never had them. The manual encryption setup requirement is the friction cost of that protection.

None of these services protect against the failures that actually catch people. A device that’s already compromised, a contact who’s been turned or isn’t using encryption, careless OPSEC (using a credit card, logging in from a home IP, attaching a personal recovery address), or a legal process that targets someone you’ve emailed rather than you directly. The Stop Cop City case was an OPSEC failure, not an encryption failure. The Phrack journalists case was a platform governance failure, not a technical one. Different problems require different solutions.

4️⃣ The comparison at a glance Link to heading

Features:

ProviderJurisdictionFree TierPaid FromSubject EncryptedOpen-Source ClientCustom DomainAnon Signup
Proton MailSwitzerland✅ 1GB~€4/mo✅ (via Tor)
TutaGermany✅ 1GB€3/mo
MailfenceBelgium✅ 500MB~€2.50/mo
PosteoGermany€1/mo
StartMailNetherlands❌ (trial)~$5/moLimited
HushmailCanada 🇨🇦$5/mo

Track record:

ProviderIP LoggingNotable Controversy
Proton MailSometimesMultiple MLAT data disclosures; Phrack suspension
TutaCourt-ordered monitoring (unencrypted only); “storefront” allegation (denied)
MailfenceLimitedClean record; refused some unlawful requests
PosteoNear-clean; structurally minimal data
StartMailLimitedMinimal documented controversy
HushmailYes2007 decryption of user emails via court order

No provider is perfect. The honest version of privacy email is: choose the service whose failure mode you can live with, minimise the data you give them, and understand that your security is ultimately a function of your behaviour more than your choice of provider.

For most people switching away from Gmail or Outlook, Proton Mail or Tuta are both strong choices. For anyone with a meaningful threat model, Tuta’s architecture is harder to compromise, it has less to hand over, encrypts more by default, and has a documented history of fighting rather than quietly complying. For people who want absolute data minimisation and don’t need a free tier, Posteo is the most structurally honest option available.

The bigger lesson from the Stop Cop City case, the Phrack journalists, the French activist, and every other incident in this space is the same one every time: the tool worked. The people using it didn’t.

Operational security isn’t a feature. It’s a practice.

5️⃣ Email aliases - the complementary layer Link to heading

No privacy email guide should end without mentioning alias services, because they solve a different problem from your email provider and work alongside whichever one you choose.

The idea is simple: instead of giving your real address to every website, service, or mailing list you sign up for, you give them a unique alias that forwards to your real inbox. If an alias starts getting spammed, you delete it. If a site’s data gets breached and that alias appears in the dump, your real address is still clean. Each alias can be traced to exactly where it was given, so you know which service leaked or sold your details.

SimpleLogin is the most widely used option and has been owned by Proton since 2022. It integrates directly with Proton Mail, supports custom domains, and has both free and paid tiers. Being Proton owned is either reassuring, same privacy values, tight integration, or a concern, depending on how you feel about concentrating your privacy stack in one company.

Addy.io (formerly AnonAddy) is the open source alternative. Fully auditable, self hostable if you want complete control, and available free with paid tiers for higher alias limits and custom domains. No corporate parent, independently run.

A couple of things worth knowing: alias services protect your address, not the content of your emails. They’re a complement to encrypted email, not a substitute. If the forwarded message eventually lands in an unencrypted Gmail inbox, Google can still read it. You’ve just protected your real address from being linked to it.

Both SimpleLogin and Addy.io allow you to reply from behind an alias, so the recipient never sees your real address even in replies. If you’re on Proton Mail, SimpleLogin is the natural pairing. If you’re on anything else, Addy.io works with any provider.

References Link to heading

The providers:

The controversies:

Reviews and guidance:

Alias services:

  • SimpleLogin, Proton owned email alias service: SimpleLogin
  • Addy.io, open source and independently run email alias service: Addy.io

TL;DR - Private email compared Link to heading

  • Switching provider doesn’t mean all your emails are encrypted. E2E only applies between compatible services, and that includes between privacy providers, Proton to Tuta is not E2E by default, and emailing someone on Gmail is not E2E full stop. And zero-knowledge cuts both ways: lose your password and recovery key on Proton or Tuta and your emails are gone permanently, so write the recovery key down somewhere physical.
  • No provider is immune to legal process. Every service in a real jurisdiction can be compelled to hand over what it holds. What differs is how much they hold, what they’ll fight, and whether their encryption means content is protected even when metadata isn’t.
  • Tuta is the strongest technical choice for high-risk users, and Posteo the most structurally honest. Tuta encrypts subject lines, logs no IPs, takes anonymous payment, and fights orders in court. Posteo simply doesn’t hold the data that gets people identified, at the cost of no custom domain, no IMAP, and manual encryption setup.
  • Proton and Tuta are both fine for most people. If you’re switching from Gmail and just don’t want your inbox monetised, either is a strong choice. Mailfence and StartMail are solid but don’t differentiate strongly enough to be a first recommendation, and Hushmail’s Five Eyes jurisdiction plus its 2007 decryption case make it one to avoid for anything sensitive.
  • Add an alias service on top. SimpleLogin (Proton owned) or Addy.io (open source, independent) protect your real address from breaches and spam, regardless of which provider you use. They solve a different problem and complement rather than replace a good email provider.
  • OPSEC still matters more than your provider. Real credit cards, personal phone numbers, and home IP addresses will undo any privacy stack. The tool works. Make sure you do too.