PrivacyPick
Mailbox.org logo

Mailbox.org

Germany-based encrypted email provider

6.8
out of 10
Visit Mailbox.org →
JurisdictionGermany
HostingCloud
Free TierPaid only
External PGPNative
AliasesLimited
Telemetryopt-out
Open SourceNoIntra-Provider E2EENoZero-Access EncryptionNoCustom Domain SupportYesPast Data BreachNo
CalendarDriveOfficeMeet
Light (individual, annual)
$1.00/mo
Standard (individual, annual)
$3.00/mo
Premium (individual, annual)
$9.00/mo

Published September 17, 2026By Juan Martinez

In This Article

Mailbox.org is the mail service of Heinlein Hosting GmbH, a Berlin company that has been running mail infrastructure under the Heinlein Group name since 1989 and launched this consumer product in 2014. It takes the opposite route from providers that build their own end-to-end protocol: the encryption here is PGP, implemented natively in the webmail client rather than through a separate protocol of the provider’s own design, and it is something you switch on rather than something that is on the moment you sign up. What you get in exchange is a mailbox that speaks the open standards the rest of email speaks, sitting on German infrastructure, with a productivity bundle attached.

Security

The encryption model is the first thing to understand, because it is not the model most privacy-focused mail services use. There is no proprietary protocol that encrypts every account automatically. PGP is built into the webmail client, so you can generate a key pair, sign and encrypt in the browser, and never install a separate plugin. Key exchange with outside contacts is handled better than most PGP setups manage: mailbox.org runs its own HKPS keyserver for automatic public-key lookup, and it took part in the Keys4All work that became the WKS/WKD standard for providers to exchange public keys automatically. That is real engineering on the hardest part of PGP, which has always been getting the other person’s key.

What it is not is automatic end-to-end encryption between two accounts on the same service. Two mailbox.org users do not get an encrypted conversation by default — both of them have to configure PGP first. The company’s own documentation is explicit that users choose between automatic encryption and manual control, which is another way of saying neither is the out-of-the-box state.

There is a feature that narrows the gap, and it is opt-in. Under mail encryption settings you can tick PGP encryption for incoming mail, and from then on anything arriving unencrypted is PGP-encrypted on the server with your own public key before storage. Private keys are held on German servers, encrypted under your account password, so once this is enabled the provider cannot read the stored mail. That is a genuinely useful design. It is also off until you find the setting and turn it on, which is a different proposition from a mailbox that is encrypted the instant it exists.

Transport and account security are conventional and adequate: TLS with DigiCert certificates, TOTP-style two-factor authentication, and multi-stage malware and spam scanning applied to arriving mail at transport time — that is, before any optional encryption is applied to it, which is how content filtering and stored-mail encryption are made to coexist.

The gap in the security picture is verification. Mailbox.org publishes ISO 27001 certification and a BSI C5 attestation, plus the BSI IT-Security Label on its plans. Those are infrastructure and process certifications — they say the company manages security in a structured, audited way, and they are worth more than nothing. They are not an independent penetration test of the running service, and they are not a third-party review of the cryptographic implementation. No such report is published anywhere on the site. For a service whose positioning is encryption, that absence is the single biggest reason the Security score sits in the middle of the range rather than higher.

One incident is on the public record and deserves stating accurately. On 21 and 22 October 2021 mailbox.org was hit by distributed denial-of-service attacks using roughly 147,000 compromised machines, causing 30 to 60 minutes of login and access disruption on the first day and about an hour of IPv6-specific trouble on the second. The attackers demanded a Bitcoin ransom; the company refused to pay and said so publicly. Customer data was not involved — the attackers never had access to the network, only the ability to flood it. This was an availability failure, not a breach, and the disclosure was prompt and specific.

Privacy & Trust

Heinlein Hosting GmbH is registered at Schwedter Strasse 8/9A in Berlin, at the District Court of Berlin-Charlottenburg under HRB 220010 B, with Peer Heinlein as managing director and also head of the parent group. Servers are in Berlin data centres. German jurisdiction means GDPR plus the Federal Data Protection Act, and an owner who has been in the same business for over three decades rather than a venture-funded company on its way to an exit.

The transparency reporting is the strongest part of the case, because it is numbers rather than posture. In 2025 mailbox.org received 74 official information requests and rejected 18 of them. The reasons are itemised: of the 63 requests that arrived by email, 27 were sent unencrypted and had to be corrected by the requesting authority before they would be processed, and 6 were unlawful on other grounds. The company requires authority requests to be transmitted encrypted, and states that a lawyer and its data protection officer review every request before it is answered or refused. Refusing more than a fifth of requests, and publishing why, is a materially different thing from a report that gives a single total.

Two facts pull the other way. The code is only partly open. The mail transport layer is Postfix and Dovecot, and the webmail and *DAV servers come from Open-Xchange — all open source, all inspectable. But the CEO has stated directly on the company’s own user forum that the internal backend infrastructure, the glue code, the internal API servers, backup and maintenance scripts, anti-abuse detection and the process logic are developed in-house and not published. That is a candid answer, and it is more than most providers will say, but it means the layer that actually connects the open components is closed to inspection.

The second is that the strongest privacy feature is opt-in, as described above. A default-encrypted mailbox and an encrypted-on-request mailbox produce very different outcomes across a user base, because most people never change a default.

Product analytics are self-hosted Matomo, without cookies and with IP addresses anonymised, and you can opt out. That is a defensible middle position — not the zero-telemetry stance some providers take, but nothing leaving for a third party either.

Features

The paid plans bundle Calendar, Drive, Office and Meet alongside mail, which puts a working document and video-call setup in the same subscription. Custom domains are supported on Standard and Premium, not on the entry-level Light plan.

Aliases are capped rather than unlimited, and the caps are worth checking against how you actually use them: Standard gives 25 @mailbox.org aliases plus 50 on your custom domain, Premium gives 25 plus 250. No catch-all option appears on the plan comparison. For per-service throwaway addresses at scale, those ceilings are real.

Spam and malware handling gets to be more thorough here than at services that cannot read stored mail, precisely because scanning happens at delivery, before any optional encryption is applied. Arriving mail is scanned multiple times with different methods. The protocol layer is hardened about as far as it goes: SPF, DKIM, DMARC, DNSSEC with full implementation, DANE and MTA-STS.

For encrypted delivery to someone who does not use PGP, the Guard feature sends the message to a temporary secure mailbox the recipient opens instead of receiving it directly. The provider also generates key pairs automatically, manages them in the background and publishes them to a searchable directory — convenient, and also a reminder that key generation is on the provider’s side unless you bring your own.

Account recovery is the part to plan for before you need it. The documentation covers replacing an expired key; it does not describe any recovery path if you lose the private key or the passphrase protecting it. Encrypted mail you can no longer decrypt is encrypted mail you have lost.

Usability

There are no native mailbox.org applications. Not on Windows, macOS or Linux, not on Android or iOS. Access is the webmail client, or standard IMAP and POP3 through whatever mail, calendar and contacts apps your operating system already has. A separate OX Drive application handles file sync.

Whether that is a problem depends entirely on how you work. If you already live in Thunderbird, Outlook or Apple Mail, this is arguably better than a provider that forbids IMAP — your existing client works, your existing workflow survives, and setup is the standard server-settings dialogue. If you expect a polished first-party mobile app with push notifications and a support channel that assumes you are using it, there is nothing here to install, and the mobile experience becomes whatever your phone’s built-in mail app offers.

The PGP side adds its own learning curve. Native webmail PGP and automatic keyserver lookup remove the plugin step, but you are still managing keys, deciding on the encrypted-mailbox setting, and explaining to correspondents why they got a link to a temporary mailbox instead of an email. That is more setup than a service where encryption simply happens.

Price & Value

Light is €1 per month, billed annually at €12 a year, for 2 GB of mail and three aliases, with no custom domain. It is the cheapest way in and is best read as a starter mailbox rather than a full account.

Standard is €3 per month billed annually — €36 a year — or €4 billed monthly, for 20 GB of mail plus 10 GB of Drive, 25 aliases on the service domain and 50 on your own, custom-domain support, and Calendar, Office and Meet.

Premium is €9 per month billed annually at €108 a year, or €12 monthly, for 50 GB of mail plus 100 GB of Drive and 250 custom-domain aliases.

The annual discount is framed as twelve months for the price of ten, and it is a recurring structure rather than a first-year promotion: there is no introductory rate that jumps at renewal, so €3 a month is what Standard costs in year one and in year five. For a paid mailbox with a custom domain, a calendar, file storage, an office suite and video calls, that sits at the low end of this category.

There is no free plan — only a 30-day trial. That rules out keeping a permanent zero-cost secondary address here, which is how a lot of people first try a privacy-focused mail service.

Pros and Cons

  • PGP is native in the webmail client — no plugin, no separate desktop software, and key pairs can be generated in the browser
  • Self-operated HKPS keyserver plus participation in the Keys4All work that became the WKS/WKD standard, so public keys of outside contacts are looked up automatically
  • Standard IMAP and POP3 access, so Thunderbird, Outlook and Apple Mail all work without a bridge
  • The 2025 transparency report gives itemised numbers — 74 authority requests, 18 rejected — and requires encrypted transmission of every request, with a lawyer and the data protection officer reviewing each one
  • German company under GDPR, registered in Berlin since 2014 with servers in Berlin, owned by a mail-infrastructure group operating since 1989
  • Malware and spam scanning runs multiple passes at delivery time, before any optional encryption, alongside SPF, DKIM, DMARC, full DNSSEC, DANE and MTA-STS
  • Standard costs €3/month billed annually with a custom domain, 20 GB of mail, 10 GB of Drive, plus Calendar, Office and Meet — a recurring annual discount, not a first-year rate that jumps at renewal
  • The October 2021 DDoS attack was disclosed publicly with specifics, the Bitcoin ransom was refused, and no customer data was accessible
  • No independent penetration test or third-party review of the cryptography is published — ISO 27001 and BSI C5 are infrastructure and process certifications, not an audit of the encryption
  • No automatic end-to-end encryption between two mailbox.org accounts: both users must configure PGP themselves first
  • The encrypted mailbox that PGP-encrypts incoming mail with your own key is opt-in, buried in mail-encryption settings, and off until you find it
  • No native applications on any platform — Windows, macOS, Linux, Android and iOS all rely on webmail or the operating system's own mail app
  • Backend infrastructure, internal API servers, glue code and anti-abuse logic are proprietary; only the Postfix/Dovecot transport layer and the Open-Xchange webmail are open source
  • Aliases are capped — 25 plus 50 custom-domain on Standard, 25 plus 250 on Premium — with no catch-all option
  • No free plan at all, only a 30-day trial, and the €1 Light plan has 2 GB, three aliases and no custom domain
  • No documented recovery path if the private key or its passphrase is lost — encrypted stored mail becomes unreadable

Our Rating

Mailbox.org suits people who want a German-hosted mailbox that works with the mail client they already use, with PGP available natively and a custom domain, a calendar, file storage and an office suite in one €3-a-month subscription. The transparency reporting is unusually specific, and the keyserver work makes PGP with outside contacts less painful than it usually is. It suits you less if you want encryption that is simply on by default rather than something you configure, if you want a polished first-party mobile app, or if you want a published independent audit of the cryptography to point at — the last of those is the clearest gap in an otherwise carefully documented service.

  • Security6.5/10

    PGP-based rather than a proprietary end-to-end protocol, native key management and transport security are solid, but no independent penetration-test report or third-party cryptographic audit is published — only infrastructure certifications (ISO 27001, BSI C5)

  • Privacy & Trust7.5/10

    German jurisdiction with a detailed, numbers-backed yearly transparency report and a legal review process for every authority request, but the client/backend stack is only partially open source and the strongest encryption feature is opt-in rather than the default

  • Features6.5/10

    Custom domains and a productivity bundle (Calendar, Drive, Office, Meet) are solid, but aliases are capped rather than unlimited and there is no automatic end-to-end encryption between two mailbox.org accounts out of the box

  • Usability6.0/10

    No native mailbox.org desktop or mobile apps — access is webmail plus standard IMAP/POP3 through the operating system's own mail, calendar and contacts apps

  • Price & Value7.5/10

    Standard renews at EUR 3/month and Premium at EUR 9/month billed annually, both including a custom domain and the full productivity bundle, at the low end of this category

Overall6.8/10

Security 30% · Privacy & Trust 30% · Features 15% · Usability 15% · Price & Value 10%

See our rating methodology →

Ready to try Mailbox.org?

Visit Mailbox.org →

Last updated: September 17, 2026By Juan Martinez