PrivacyPick
In This Article
ComparisonsEmail

Proton Mail vs Tuta: Compatible or Fully Encrypted

Proton Mail keeps IMAP and PGP. Tuta drops both to encrypt everything, including subject lines. Here's the real trade-off.

Published September 27, 2026By Juan Martinez

proton-mail
VS
tuta

Proton Mail and Tuta both encrypt your stored mail so that the provider cannot read it, both publish all their client code, and neither has taken venture capital. The ratings are close — 8.5 against 7.9. What separates them is a design decision each made early and has stuck to since: Proton Mail encrypts what it can while still behaving like ordinary email, and Tuta encrypts everything in the mailbox while refusing the two standards that would make ordinary email possible. Proton gives you IMAP through a paid bridge and manual PGP for outside correspondents. Tuta has neither, will never have either, and encrypts subject lines, calendar reminders and your search index in exchange.

Proton MailTuta
Rating8.57.9
JurisdictionSwitzerlandGermany
Price (individual, renewal)$4.99/mo (Mail Plus, 15 GB)€3/mo (Revolutionary, 20 GB, no intro-rate gap)
Zero-Access Encryption✅✅
Custom Domain✅✅
Aliasesunlimitedlimited
PlatformsWindows, macOS, Linux, Android, iOSWindows, macOS, Linux, Android, iOS
Est.20142011

Compatibility or coverage: the decision behind everything else

Tuta encrypts more of your mailbox than Proton Mail does. Mail bodies and attachments are encrypted at rest at both providers, including mail that arrives from outside senders, but Tuta extends that to subject lines, the address book, inbox rules, calendar events down to their reminders and push notifications, and the search index. The only thing left readable is the routing metadata the email protocol itself requires — addresses and timestamps. Proton Mail encrypts the content of an incoming external message on arrival with your public key, which covers the body and attachments; the subject line of mail from outside senders is not part of that.

The reason Tuta can encrypt subject lines is the same reason it cannot talk to anyone using PGP: it does not implement PGP at all. Its stated objections are technical — PGP cannot encrypt the subject line, its algorithms cannot be swapped quickly for post-quantum replacements, and it has no Perfect Forward Secrecy option. S/MIME is rejected on the same grounds. So correspondence with a non-Tuta recipient runs on a password you agree with that person once through some other channel, which then covers the whole thread with them. Someone who already runs PGP and expects a PGP-encrypted message either accepts that flow or receives plaintext.

Proton Mail takes the opposite side. PGP with an external recipient works, but only after a manual key exchange: the contact sends you a signed message with their key attached and you accept it, or you upload their key yourself under Contacts. Proton’s own documentation calls setting this up not simple and not for the faint-hearted. Once done for a specific address, encryption to that person is automatic from then on. For recipients who will never handle a key, Proton has password-protected emails — a password on a single message, no account or software needed at the other end — which is closer to Tuta’s model than to PGP, but scoped per message rather than per thread.

IMAP is the sharper version of the same split. Proton Mail Bridge gives Thunderbird, Outlook or Apple Mail real IMAP and SMTP access, and it is a paid feature. Tuta states plainly that IMAP would require sending decrypted data out to the device, so there is no IMAP, no bridge, and no workaround — your mail lives inside Tuta’s own apps, on the way in and on the way out. If a standard desktop client is part of how you work, that single line settles the comparison before any other row matters.

Cryptography and what has actually been checked

Tuta is ahead on the protocol itself. TutaCrypt combines AES-256, x25519 and Kyber/ML-KEM, has been rolling out to all accounts since March 2024, and made Tuta the first provider to run a post-quantum email protocol in production. It also has scrutiny of a kind almost no mail provider has: a peer-reviewed paper in IACR Communications in Cryptology defining Bellare–Rogaway-style security models for the protocol and giving reduction-based proofs of the assumptions it holds under. Proton Mail’s cryptography is elliptic curve on OpenPGP with post-quantum support in place, and Proton maintains OpenPGPjs and GopenPGP — libraries used far outside its own products, and therefore read by people with no stake in the company.

The audit trails run the other way round. Proton Mail has two public reports with full text available: Securitum on the redesigned web client and Calendar in July 2021, and Ruben Santamarta on the Windows and macOS desktop clients in February 2024. There is also a public bug bounty. Tuta names one penetration test — SySS GmbH, before the public release, which puts it somewhere in the 2011 to 2014 window — with no date given and no report published, so its scope and methodology cannot be checked, and nothing more recent has appeared.

These two forms of review are not interchangeable. A formal proof establishes that the protocol design is sound under stated assumptions. A penetration test establishes that the deployed service, as actually built and configured, resists attack. Tuta has the first and not a current version of the second; Proton has the second twice over and relies on a widely used library ecosystem rather than an academic proof for the first. Neither gap is filled by the other side’s strength.

What happened when each one had a bug

Both have had exactly one cross-site scripting flaw disclosed, both patched, neither exploited, and neither counts as a data breach — but the circumstances differ in a way that says something.

Proton’s was in the open-source web client, found by Sonar’s research team, disclosed privately in June 2022 and published in September 2023. In theory it would have let an attacker read decrypted mail and impersonate the victim, bypassing the end-to-end encryption entirely; exploiting it required the target to open two crafted emails and, in most scenarios, click a link in the second. Proton patched shortly after disclosure and Sonar states users were not at risk once patches were applied. The uncomfortable part is that Proton did not find it — outside researchers did, in code Proton publishes.

Tuta’s was narrower and caught in-house. An XSS flaw was introduced on 20 January 2021 on a payment subpage used for Braintree 3D-Secure card verification — not the webmail, and never the desktop or mobile apps. A crafted link to that page, clicked while it was live, could have exposed a browser-stored password or an active session. Tuta’s own routine security review found it and fixed it the same day, 25 February 2021, after 36 days live. No payment data was exposed and no exploitation attempts are known.

Read together: Proton’s bug sat in the security-critical path and needed outsiders to surface it, which is the cost of a larger web client. Tuta’s sat on a secondary page and its internal review caught it, which is the behaviour you want — though 36 days shows how long a regression can go unnoticed when it is off the main product.

Jurisdiction and who owns the company

Proton AG is in Plan-les-Ouates near Geneva, and since June 2024 its majority shareholder has been the non-profit Proton Foundation, after the founders transferred their shares in what they describe as an irreversible move. That structure removes the usual endgame where an acquisition quietly rewrites the terms. Tutao GmbH has been in Hanover since 2011, same entity, registered at the District Court of Hanover, with no venture backing and no ownership change to describe. Tuta’s specific claim about German law is the more checkable one in this pair: that no German law permits gag orders or backdoor mandates. Switzerland and Germany are both defensible places to keep a mailbox, so this is not the axis that decides between them.

The architectural difference underneath is more interesting than the flags. Tuta writes essentially the whole stack itself — web, desktop, Android, iOS — specifically to avoid inheriting the security and tracking behaviour of components like Dovecot, Roundcube or Google Push, and publishes all of it under GPLv3 with verifiable signed desktop builds. That is slow, and it shows in the feature pace. Proton builds more conventionally, on its own hardware in Swiss data centers with biometric access and encrypted disks, and is also fully open source across web, desktop and mobile. Tuta reports no telemetry at all and no IP logging by default, including at signup and over Tor; Proton runs locally hosted, anonymized analytics without retaining IP addresses for it.

Neither can filter spam by reading your mail, so both work around it. Proton’s PhishGuard checks SPF, DKIM and DMARC plus metadata — headers, sender, link URLs, attachment hashes — and retrains on your own spam and not-spam actions, with a 24/7 deliverability team behind it. Tuta hardens the protocol layer with SPF, DKIM, DMARC and MTA-STS, blocks external images and video by default until you allow them, and warns when the technical sender does not match the visible From address. Proton’s approach is the more active of the two; both are less aggressive than a content-scanning filter, which is the direct price of encryption.

Recovery: both can lock you out, one has two ways not to

Neither provider can reset your password, and both say so directly. The difference is how many ways there are to prepare.

Tuta has one: a recovery code, generated at signup or on demand, that decrypts the private key independently of the password. You store it yourself. Lose the password and the code together and the account is gone — no support path, no identity check.

Proton splits the problem in two — regaining the account, and regaining the encrypted data — and a recovery phrase covers both at once, while other methods cover only one. Set nothing up and the outcome is identical to Tuta’s: permanent loss. So the failure mode is the same at both providers; Proton simply gives you more than one configuration to get wrong, and one option that handles both halves.

Features and price

Tuta is cheaper and there is no renewal trap. Revolutionary is €3 a month billed yearly, taxes included, for 20 GB, unlimited calendars and labels, 15 extra addresses and three custom domains — and that figure is the steady-state price, not an introductory rate. Legend is €8 a month for 500 GB, 30 extra addresses and ten custom domains. Proton Mail Plus renews at $4.99 a month for 15 GB, one custom domain and ten extra addresses, after a $3.99 first year. Proton Unlimited renews at $12.99 a month, and at that price it stops being a mail plan: 500 GB shared across services, three custom domains, unlimited hide-my-email aliases, Dark Web Monitoring, Sentinel, plus the full VPN, Drive and Pass. Judged on mail alone that is poor value; judged as a replacement for three or four subscriptions it is the plan most Mail Plus users eventually look at. Tuta bundles Calendar and Drive and has no VPN — deliberately, since as your mail provider it already sees your real IP and says routing your traffic through its own VPN would remove nothing while doubling what one company observes.

On the plan details the two lead in different places. Tuta gives ten custom domains at the top tier against Proton’s three. Proton gives ten hide-my-email aliases even on the free plan and unlimited ones on Unlimited; Tuta’s equivalent is extra addresses, capped at 15 or 30 by plan, which are full addresses on the account rather than throwaway aliases — not the same thing. Free tiers are tight at both: 1 GB each, with Proton adding a 150-message daily cap and one address, and Tuta limiting you to one calendar, three labels and no extra addresses. Proton’s desktop app is a 14-day trial on free, and both Bridge and custom domains are paid-only.

What we didn’t compare, and why

The rest of the Proton suite. Calendar, Drive, VPN and Pass are what makes Proton Unlimited worth $12.99 a month, and they are part of why people choose Proton — but they are not email features, and Tuta has no comparable bundle to weigh them against. The price row treats Unlimited as a suite subscription and leaves it there.

Absolute encryption strength. Both use modern, well-regarded cryptography, and picking a winner on cipher choice would be theatre. What separates them is coverage — which fields are encrypted — and post-quantum readiness, both of which are above. Neither review scores one AES-256 implementation against another.

Migration effort. Moving an existing mailbox into either service is real work, and for Tuta it is one-directional in a way the no-IMAP row already makes clear. How long an import takes depends entirely on where you are coming from, so it is not a row either review could fill with a fact.

Bottom line

Read the full Proton Mail review if you need your encrypted mailbox to coexist with the rest of how email works — a real mail client over IMAP, PGP with correspondents who already use it, a suite you can consolidate other subscriptions into — and you accept that the subject lines of incoming external mail stay readable to the provider and that PGP setup is manual work Proton itself calls difficult.

Read the full Tuta review if you want the provider to hold nothing readable at all — subject lines, calendar reminders and search index included — at the lowest steady-state price in this category, and you can live inside Tuta’s own apps permanently, with no PGP for the people who insist on it and no current published penetration-test report to point at.