PrivacyPick
In This Article
ComparisonsEmail

Proton Mail vs Mailfence: Always-On or On-Demand Encryption

Proton Mail encrypts every inbox by default. Mailfence makes you choose per message but can't be gagged in Belgian court. Here's the real trade-off.

Published September 28, 2026By Juan Martinez

proton-mail
VS
mailfence
Proton MailMailfence
Rating8.57.0
JurisdictionSwitzerlandBelgium
Price (individual, renewal)$4.99/mo (Mail Plus, 15 GB)$3.50/mo (Entry, 40 GB, steady-state — no intro-rate gap)
Zero-Access Encryption✅❌
Custom Domain✅✅
Aliasesunlimitedunlimited
PlatformsWindows, macOS, Linux, Android, iOSAndroid, iOS
Est.20141999

Proton Mail and Mailfence both sell you an encrypted mailbox, and the ratings are not close — 8.5 against 7.0. The gap is not about cipher quality. It is about who decides when encryption happens, and where each company’s trustworthiness actually comes from. At Proton Mail, encryption is a property of the mailbox: every message that arrives, including mail from strangers on ordinary email services, is encrypted on the server the moment it lands, with nobody pressing a button. At Mailfence, encryption is a tool sitting in the compose window, and nothing is encrypted until you choose it for that specific message. And where Proton backs its claims with two published independent audits and fully open client code, Mailfence backs its claims with a jurisdiction in which a gag order is not legally possible — while publishing no audit and no source code at all.

Encryption as a default state, or as a tool you pick up

Proton Mail’s zero-access encryption covers all incoming mail, including messages from senders with no encryption of their own, applied automatically on receipt. The reader makes no decision and can make no mistake. Mailfence’s own security documentation describes the opposite arrangement: encryption is invoked per message through an OpenPGP keystore built into the browser, generating 4096-bit keys by default, and two Mailfence accounts writing to each other get no automatic end-to-end layer simply by both being Mailfence accounts. A Mailfence mailbox where nobody ever turns encryption on has none of the protection the marketing describes. That is the single largest difference between these two products, and it is not a matter of degree.

Mailfence is also more exposed in storage, and says so itself. Its storage table lists message headers on the web server as not encrypted — even for a message whose body and attachments the server genuinely cannot read, the envelope around it sits there in the clear: who wrote to whom, when, under what subject. Proton’s zero-access model is a claim about message content rather than a claim that nothing about your correspondence is visible; routing metadata is inherent to email at any provider. But there is a real difference between metadata that the protocol forces into the open and subject lines that a provider explicitly declines to encrypt in its own database, and Mailfence’s documentation is candid that it is the latter.

Mailfence earns a genuine point back on the standard it chose. Its keystore is plain OpenPGP, so correspondence interoperates with any other OpenPGP service and the keys remain yours if you leave. Proton’s own external PGP support is where its always-on story stops: writing encrypted mail to a non-Proton recipient requires a manual key exchange, and Proton’s documentation describes setting that up as not simple and not for the faint of heart. Inside Proton, encryption is invisible. Outside it, the work looks a lot like the work Mailfence asks of you for every message — except Mailfence asks it in a form that any PGP user anywhere can already receive. Proton does contribute to the standard’s ecosystem rather than working around it, maintaining OpenPGPjs and GopenPGP, libraries used well outside Proton’s own products.

Verification: audits and open code, or a jurisdiction that cannot be gagged

Proton Mail has two public independent reports: Securitum on the redesigned web client and Calendar in 2021, and Ruben Santamarta on the Windows and macOS desktop clients in February 2024. Every client is open source — web, desktop and mobile. That combination has a specific consequence visible in Proton’s own history: the one cross-site scripting flaw disclosed in its web client, published in 2023, was found by outside researchers at Sonar and not by Proton. That is uncomfortable, and it is also the mechanism working. Publishing your code means people with no stake in your company read it and tell you what they found.

Mailfence has neither half of that. Its knowledge base, asked directly whether the service is open source, answers “Not yet,” with a plan to eventually open the front end and no commitment on the back end. There is no published penetration test and no named auditing firm. What the knowledge base offers instead is that the back end is “always open to inspections by recognized auditing teams, academic researchers, and other reputed bodies” — a standing invitation, not a report anyone can read. Twenty-six years of operation and an unusually honest published threat model, which names what the service does not defend against, are real signals. They are not the same kind of evidence as a dated report with a scope and a methodology.

What Mailfence has instead is structural, and it is the strongest single item either provider brings to this comparison. ContactOffice Group sa is a Brussels company, and Belgian law provides no gag-order mechanism — compliance with a data demand cannot be bundled with secrecy about it, so the affected user can be told. Mailfence publishes a warrant canary anyway, stating it has never received a US National Security Letter or a FISA order and has never been asked to install a backdoor, and its transparency report carries counted figures rather than assurances: 21 identification requests in the second half of 2025 with 9 complied with under valid Belgian court order, and 228 requests against 105 complied with cumulatively from launch through June 2025. Roughly half of all requests in the service’s lifetime were refused, and the numbers are itemised enough to be checked over time. Proton, for its part, is a Swiss company whose majority shareholder since June 2024 is the non-profit Proton Foundation, which removes the usual acquisition endgame but is a statement about ownership, not about what a court can secretly compel.

These are different kinds of assurance and neither substitutes for the other. Proton lets you verify that the encryption does what it says. Mailfence lets you verify that pressure applied to the company cannot be kept secret from you — while asking you to take the encryption itself on faith.

Recovery: two ways to lose everything

Neither provider can reset what matters, and both are direct about it. The difference is how the secret is split.

Mailfence keeps two. The account password is stored server-side as a salted bcrypt hash and can be reset through a pre-configured reset address — an ordinary recovery flow. The OpenPGP passphrase never leaves the client and cannot be reset, recovered or changed without the existing passphrase. Lose it and the documented remedy is a revocation certificate you generated in advance, which only lets you disown the key going forward; mail already encrypted under it stays unreadable permanently. That split is a real security benefit in the other direction: a stolen login alone unlocks no cryptographic operation, because the passphrase still stands in front of the keystore.

Proton runs one secret across both problems. A recovery phrase covers regaining the account and regaining the encrypted data at once, where other methods cover only one. Set nothing up and the outcome matches Mailfence’s worst case exactly: permanent loss, no support path.

So the failure mode is identical and neither provider is safer here in the abstract. Proton gives you one thing to protect that handles everything, which is simpler to get right and worse if you lose it. Mailfence gives you two, one of which is forgiving and one of which is absolute, and expects you to know which is which.

Platforms, features and price

Desktop is where Proton is plainly ahead. It has native applications for Windows, macOS and Linux, though only since 2024, alongside Android and iOS. Mailfence has no desktop application on any operating system: desktop use is webmail, or standard POP, IMAP and SMTP through a client you already run. Mobile is closer than that gap suggests — Mailfence ships genuine native apps on the App Store and Google Play plus an installable progressive web app, which is better coverage than a webmail-first provider usually manages. Proton’s IMAP story has its own catch: it runs through Bridge, which is a paid feature.

On plan contents the two lead in different places. Proton Mail Plus is 15 GB, one custom domain and ten hide-my-email aliases; Proton Unlimited is 500 GB, three custom domains, unlimited aliases and the whole VPN, Drive and Pass suite. Mailfence’s Entry gives two custom domains with DKIM, SPF and DMARC plus a catch-all address, 50 aliases and the full protocol set including ActiveSync; Base below it has 10 aliases and no custom domain at all. Free tiers are tight on both sides — Proton at 1 GB, one address and 150 messages a day, Mailfence at 1 GB split between mail and documents with no custom domain, keeping the keystore intact.

Mailfence is cheaper, and cheaper honestly. Base is $2.50 a month billed yearly and Entry is $3.50, both steady-state rates rather than first-year pricing. Proton Mail Plus renews at $4.99 after a $3.99 first year, so the number you see at signup is not the number you pay. At $3.50 for a custom-domain mailbox with catch-all, a calendar and a document store, Mailfence sits near the bottom of this category on price — which is exactly why its Price & Value score is the highest number on its own card while its overall rating is the lower of the two here.

What we didn’t compare, and why

Absolute cryptographic strength. Both providers implement OpenPGP, a standard with decades of scrutiny behind it, and declaring a winner on cipher choice or key length would be theatre. What separates them is when encryption is applied and which fields it covers, which is above.

The rest of the Proton suite. VPN, Drive and Pass are a large part of why Proton Unlimited costs $12.99 a month and a large part of why people pick Proton — but they are not email features, and Mailfence has no comparable bundle to weigh them against. Its own extras, Calendars, Documents and Groups, are counted in the plan comparison and left there.

Bottom line

Read the full Proton Mail review if you want encryption to be a property of the mailbox rather than a decision you make message by message, want a native desktop client, and want the claims backed by two published audits and fully open source code — accepting that PGP with anyone outside Proton is manual work the company itself calls difficult, and that you pay $4.99 rather than $3.99 from year two.

Read the full Mailfence review if your priority is a provider that cannot be secretly compelled — Belgian law with no gag-order mechanism, a warrant canary and counted transparency figures — with standards-plain OpenPGP keys you can carry to any other service, at $2.50 or $3.50 a month with no renewal jump. That choice means accepting closed source with no published audit, encryption that protects nothing until you invoke it, message headers stored unencrypted even on messages whose bodies are not, and no desktop application anywhere.