I am trying to choose an email provider, to use with my identifying accounts (like banks, gov ids, etc.). I feel that emails for such cases do not need to be end-to-end encrypted, since most information would already be present with banks, gov, etc.
So I was looking at non-E2EE emails - Mailbox and Posteo.
- Between Posteo and Mailbox - which one do you use / is better in terms of privacy?
I noticed that both of these are hosted in Germany. With rise in popularity of right wing party, a bunch of stuff around chat control and verification, and even normal German government support for Israel, I was wondering whether I should look for other solutions hosted elsewhere. Or use Proton / Tuta instead?
Also, I am not sure if any of these companies support right-wing or Israel themselves?
Do you have any suggestions regarding this?
Tl;Dr: I used Proton and Tuta, both work well and respect privacy. I will encourage E2EE though.
My suggestion is largely dependent on your use case. I’m switching from Proton to Tuta actively, but not necessarily due to a slight to Proton. I simply used to use their VPN + Email combo, but recently wanted to switch to Mullvad VPN, so Tuta then became cheaper.
As far as E2EE discussions go, I dont feel E2EE/PGP is ever a bad thing to have. Namely, encrypted communications have a smaller threat surface. I’d advocate in the modern day, all respectable services should offer it anyways. With how easy PGP is to setup, any company that doesnt do E2EE by default is likely motivated against it, which speaks ill of their privacy practices.
For services in general, most privacy respecting services are hosted in Europe. Switzerland and Germany for Proton and Tuta respectively, which what might ease your stress a bit is that they do still need to follow the GDPR, but all good providers I’m familiar with are European based.
Watever you do, you can use https://unbox.at/ to get free, unlimited aliases in front of any mail account you’d like. It’s a hosted version of addy.io
I’ve given up on encrypted email because they can read whatever you receive or send anyway: they have to. It’s a question of who you trust. I’ve seen posteo and mailbox recommended often enough that I don’t even think it matters which one you pick.
The government isn’t the only threat e2ee protects against. When a non-e2ee service is hacked, the data is free for the taking, if the service is e2ee the data is only available from that moment forward. I’m not going to speak for which provider you should use, but you should reconsider needing e2ee.
I use Posteo and Tuta and I’m pretty sure - but not 100% - that my (german) government will attack homeless, disabled and trans people live on tv before actually starting to invade things like emails publicly.
Tuta has been under some fire for the encryption if I remember correctly but they couldn’t hand out any data so things were left where they are. That’s a plus imho
None.



