Independent reviews of email providers based on encryption standards, jurisdiction, metadata handling, and actual privacy practices—not affiliate commissions.
| Provider | Jurisdiction | Encryption | Zero-Knowledge | Metadata Logging | Price | Custom Domain | Verdict | Details |
|---|---|---|---|---|---|---|---|---|
| ProtonMail | Switzerland | E2E (PGP) | Yes | Yes | Free / €3.99+/mo | Yes | Recommended | Visit Site |
| Tutanota | Germany | E2E (proprietary) | Yes | No | Free / €3+/mo | Yes | Recommended | Visit Site |
| Mailbox.org | Germany | E2E (PGP) | No | Yes | €1/mo (Light) | Yes | Recommended | Visit Site |
| Skiff Mail | USA | E2E (proprietary) | Yes | No | Free / $8+/mo | Yes | Conditional | Visit Site |
All information verified as of February 2025. Zero-knowledge means the provider cannot read your emails. Metadata logging refers to sender/recipient/timestamp data.
The provider should be technically unable to read your emails. If they hold your encryption keys, they can be compelled to hand over your content. Look for end-to-end encryption where only you hold the keys.
Where the provider is based determines what governments can demand. Switzerland and Iceland have strong privacy laws and are outside intelligence alliances. Germany is reasonable but inside Fourteen Eyes.
Even with encrypted content, who you email and when can reveal a lot. Some providers log sender, recipient, and timestamps. Others minimise or avoid this entirely. Understand what metadata your provider retains.
Open-source apps allow independent verification that the encryption works as claimed. Closed-source implementations require you to trust the provider's word.
Providers supporting standard IMAP/SMTP allow you to use any email client. Proprietary systems lock you into their apps, which may be less flexible or harder to migrate away from.
Has the provider been tested by real legal demands? Do they publish transparency reports? A provider that has resisted government pressure or proven they had no data to hand over is far more credible than one with only marketing claims.
The major free email providers scan your emails for advertising purposes, comply extensively with government requests, and are based in surveillance-friendly jurisdictions. They are not suitable for private communication.
If you send an email from ProtonMail to a Gmail address, the content is not end-to-end encrypted — Google can read it. True private communication requires both parties to use an encrypted provider or PGP.
Even with perfect content encryption, metadata reveals who you communicate with, how often, and when. For high-stakes privacy needs, email is fundamentally limited — consider Signal or other metadata-resistant tools instead.
Some providers encrypt data in transit or at rest but still hold the decryption keys themselves. This means they can read your emails and can be compelled to. Look specifically for end-to-end or zero-knowledge encryption.
For most people: ProtonMail offers the best balance of usability, features, and privacy with a solid free tier.
If metadata privacy is critical: Tutanota logs less metadata than ProtonMail and encrypts subject lines.
If you need standard IMAP support and a full-featured suite: Mailbox.org is the most flexible option.
Use Tor Browser or a VPN when creating your account to avoid linking your real IP to your new email address.
Do not provide a recovery phone number or existing email address if you want anonymity. ProtonMail and Tutanota allow signup without these.
Choose a username that doesn't identify you. Your email address becomes part of your identity.
Don't try to switch everything at once. Start by using your new address for new accounts and sensitive communications.
Update important accounts (banking, healthcare, government) to your new address first.
Keep your old address active for low-sensitivity accounts while you transition over weeks or months.
Encourage contacts to join your encrypted provider, or set up PGP keys for email with people on standard providers.
For truly sensitive conversations, consider Signal instead — email metadata is always exposed regardless of content encryption.
Use email aliases (SimpleLogin, AnonAddy) to protect your real address when signing up for services.
For content privacy, yes — Proton cannot read your emails. However, they do log metadata (who you email, when) and have complied with Swiss legal orders to provide IP addresses in criminal cases. For most people's threat model it's excellent. For high-risk users or activists, treat email as inherently limited.
You can't transfer ownership of a Gmail or Outlook address. However, you can set up email forwarding to your new address and reply from the new one, gradually shifting contacts over. Custom domain support (on paid plans) lets you use your own domain with a privacy-respecting provider.
PGP (Pretty Good Privacy) is an open standard used by ProtonMail and Mailbox.org. It's widely understood, auditable, and interoperable with other PGP users. Tutanota uses their own encryption which encrypts more (including subject lines) but isn't compatible with standard PGP tools. Both are secure, but PGP is more flexible.
ProtonMail and Tutanota both offer decent free tiers. For most personal use, a free account is sufficient. Paid plans get you more storage, custom domains, and additional addresses. Given that free email providers monetise your data, paying a few euros a month is a reasonable trade.
Email alias services like SimpleLogin (now owned by Proton) and AnonAddy let you create throwaway addresses that forward to your real inbox. This protects your actual address from data breaches and spam, and lets you identify which services sell your data. Highly recommended alongside a private email provider.
Email is a legacy protocol with fundamental limitations — metadata is always exposed, and the system wasn't designed with privacy in mind. For casual privacy needs, an encrypted provider is a major improvement over Gmail. For truly sensitive communications — journalism, legal matters, activism — use Signal instead.