Case file · Email
Mailfence
The deliberate contrast to the German providers: a capable OpenPGP mailbox that, by its own privacy policy, logs your IP address, subjects, sender/recipient and timestamps to comply with Belgian data-retention law - and its transparency report shows it complies with valid Belgian court orders.
The systematized overview
The bureau vs the internet.
5.9/10 · Logs metadata by law
Mailfence is a competent OpenPGP email service, but it is the category’s honest counter-example: its own privacy policy states it logs IP addresses, message subjects, sender/recipient and timestamps to satisfy Belgian data-retention law, and it is not zero-access by default. Its transparency report shows routine compliance with valid Belgian court orders (one identification honored in H1 2025). Useful and transparent about all this - but it retains and can disclose exactly the metadata the top providers are built not to hold.
2 recurring praises · 2 recurring gripes
Most praised: good pgp implementation and keystore. Most cited downside: logs ip and metadata by design.
We track our editorial score and community sentiment separately — neither moves the other. Read together, they're the systematized overview.
The facts
Jurisdiction, sign-up & encryption.
- Jurisdiction
- ContactOffice Group SA, Belgium
- Sign-up needs
- Registration data collected (typically an alternate email)
- KYC trigger
- IP + metadata logged by default under Belgian retention law
- Encryption
- OpenPGP with built-in keystore (user-managed); NOT zero-access by default
- Provider access
- Can access non-PGP mail; retains IP, subjects, sender/recipient, timestamps
- Anon. payment
- Crypto accepted for paid plans; Monero unverified
- Logging
- Logs IP + message metadata to comply with Belgian data-retention law
- Open source
- No
- Audited
- No prominent public audit found
- Custom domain
- Yes (paid plans)
- Free tier
- Yes (limited)
- Since
- 2013
The full read
Our analysis, in plain words.
Mailfence earns its place in this audit as the honest counter-example. It is a perfectly capable email service with a good OpenPGP implementation and a user-managed keystore, and it is unusually transparent - it publishes a transparency report and a warrant canary, and states plainly which requests it complied with. But transparency about a weakness is still a weakness.
The weakness is structural: Mailfence’s own privacy policy says it logs your IP address, message subjects, sender/recipient and timestamps to comply with Belgian data-retention law, and it is not zero-access by default. That means the metadata identifying who you emailed, when, about what, and from where is retained by design - and its transparency report confirms it discloses that data to valid Belgian court orders (one identification in the first half of 2025). This is exactly the data Posteo was audited to prove it does not hold.
So Mailfence lands mid-table: genuinely useful for encrypted content, genuinely transparent about its compliance, but not an anonymity tool and not in the same class as the German no-log providers on the privacy axis that defines this category. If you choose it, use PGP for content and assume your metadata is logged and disclosable under Belgian law.
The score, broken down
How the 5.9 is built.
Privacy
weight 50%What identity, data and metadata the service can demand or collect.
56 × 50% = 2.8 of 10
Trust
weight 30%Whether it can technically deliver what it claims — code, audits, age.
66 × 30% = 2.0 of 10
Reliability
weight 20%Whether the no-KYC claim holds under real-world pressure.
55 × 20% = 1.1 of 10
Weighted total 5.9 / 10 · no reliability rule triggered, so the score stands. See the rubric →
Every point, sourced
What earned the score.
Privacy
The fine print, read for you
The clause they bury.
“We collect and store your IP address, message headers (sender, recipient, subject), and timestamps, and retain this data in order to comply with applicable Belgian data-retention legislation.”
What it meansThis is the honest disclosure the strongest providers make unnecessary by design. Mailfence, by law and by default, records the metadata that identifies who you emailed, when, about what (subject), and from where (IP). It is transparent about it and only hands it to valid Belgian court orders - but the data exists to be handed over, which is precisely what Posteo’s audited no-IP-logging avoids. Use PGP for content, but assume your metadata is retained.
Read the source →Registration collects some data (typically an alternate email), and Mailfence logs your IP and message metadata by Belgian legal requirement, so it is not an anonymous mailbox in the way Posteo or Tuta are. It complies with valid Belgian court orders. We rate it KYC level 2 - private content via PGP, but retained, disclosable metadata.
Policy review — point by point
-
Logs IP + metadata by law
The privacy policy states Mailfence logs IP, subjects, sender/recipient and timestamps under Belgian data-retention law. ↗
-
Not zero-access
Mailfence can technically access non-PGP mail; encryption depends on the user using OpenPGP. ↗
-
Transparent compliance
Publishes a transparency report + warrant canary; honors only valid Belgian court orders (1 of 7 in H1 2025). ↗
Mailfence operates under Belgian law, which imposes data-retention obligations that Mailfence complies with by logging IP and metadata. It honors valid Belgian court orders and says it refuses direct foreign requests. This is lawful and disclosed, but the retained metadata is the key difference from the audited no-log German providers. Its privacy policy and transparency report are the primary sources.
We keep watching
Incident & policy timeline.
- 2016
Metadata logging to comply with Belgian retention law
Mailfence’s privacy policy documents that it logs IP addresses and message metadata to comply with Belgian data-retention legislation - a deliberate, disclosed design choice.
source ↗ - H1 2025
Transparency report: 1 of 7 requests complied with
Mailfence’s transparency report for the first half of 2025 records 7 user-identification requests received and compliance with 1 valid Belgian court order, alongside a warrant canary. It states it will not honor foreign requests directly.
source ↗
The verdict
Where it stands.
Strengths
- Solid OpenPGP implementation with user-managed keys
- Transparent about its logging and court compliance
- Only honors valid Belgian court orders; publishes a warrant canary
Trade-offs
- Logs IP, subjects, sender/recipient and timestamps by law
- Not zero-access by default - can access non-PGP mail
- Registration collects data; not an anonymous mailbox
- Not open source
Across the internet
What reviewers report.
Consistently praised
- Good PGP implementation and keystore
- Transparent about logging and compliance
Recurring complaints
- Logs IP and metadata by design
- Not zero-access; not anonymous
Reviewers rate Mailfence a competent PGP provider but repeatedly flag its by-design IP/metadata logging as the reason it is not a top-tier privacy choice. Its own transparency is widely (and fairly) credited. Synthesized from Mailfence primary sources and review sites.
Keep exploring
Related lists & categories.
Ask the bureau
Mailfence, common questions.
Is Mailfence private?
For content, if you use its OpenPGP - yes. For metadata, less so: Mailfence’s own privacy policy states it logs your IP address, message subjects, sender/recipient and timestamps to comply with Belgian data-retention law. It is transparent about this, but the metadata is retained and can be disclosed under a Belgian court order.
Does Mailfence hand over data?
Only to valid Belgian court orders, and it publishes the numbers: in the first half of 2025 it received 7 identification requests and complied with 1. It says it will not honor foreign requests directly. That is lawful, transparent compliance - but it is only possible because Mailfence retains the metadata by design, unlike providers audited to hold no IP logs.
Is Mailfence no-KYC?
Not really. Registration collects some data and it logs your IP and metadata by law, so an account is more traceable than an anonymous German mailbox. We rate it KYC level 2. It is a capable PGP provider, just not an anonymity tool.
Your exact case not covered? The live Ask the bureau answers it and turns it into a public FAQ.