The bureau · Email
No-KYC email, audited.
The highest-rated private email provider we audit is Posteo (9.0/10) - but a no-phone signup and encryption are two different promises, and neither guarantees the third: that it won't be compelled to hand over your metadata. We read the signup flow, the encryption model and the jurisdiction, log every documented disclosure or termination, and score how genuinely anonymous each provider is - and how likely it is to be forced to give you up. Ranked below; every card links to the full case file.
- Providers audited
- 9
- Genuinely no-KYC
- 5
- Disclosure incidents
- 8
- Avg score
- 6.6/10
- Paid listings
- 0
The directory
Every no-KYC email provider, ranked.
Posteo
The benchmark for how it should be done: sign up with no name, phone or alternate email; pay by cash sent in the post; and an audit by the German federal data-protection regulator confirmed it holds no customer-linkable IP logs. No documented handover on record.
- 1KYC
- No phone
- Zero-access
- Anon. pay
Tuta
The strongest zero-access model in the category - it encrypts the subject line, attachments, contacts and calendar, not just the body, so it cannot read your stored mail. Genuinely no-KYC. A 2020 German court order forced monitoring of named accounts going forward, but even then it could not decrypt existing end-to-end-encrypted mail.
- 1KYC
- No phone
- Zero-access
Proton Mail
The market leader, and the clearest lesson that private is not the same as anonymous. Signup needs no phone, and stored message bodies are zero-access encrypted - but documented cases show that IP, payment and recovery data are reachable under a Swiss court order, and subject lines are not encrypted.
- 2KYC
- Zero-access
Mailbox.org
A German, privacy-first provider that allows anonymous signup and anonymous cash payment by post, with PGP and an optional encrypted "Guard" mailbox. No prominent disclosure incident on record. Encryption is opt-in rather than default, like Posteo.
- 1KYC
- No phone
- Anon. pay
Riseup
A no-KYC, invite-based activist mail collective that moved to encrypted storage after being served two sealed FBI warrants under a gag order in 2016 - which it complied with rather than face contempt, and its warrant canary lapsed. Mission-trusted, but US jurisdiction is the structural weakness.
- 1KYC
- No phone
StartMail
A competent PGP-friendly provider from the makers of Startpage, but weaker on the no-KYC axis: it is paid-only after a short trial and typically takes an alternate email at signup, so the account is tied to a card and a contact address. No prominent disclosure incident on record.
- 3KYC
- Zero-access
Mailfence
The deliberate contrast to the German providers: a capable OpenPGP mailbox that, by its own privacy policy, logs your IP address, subjects, sender/recipient and timestamps to comply with Belgian data-retention law - and its transparency report shows it complies with valid Belgian court orders.
- 2KYC
- Zero-access
Skiff Mail
A cautionary tale, now shut down. Skiff was an end-to-end-encrypted mail/calendar/drive suite - until Notion acquired it in February 2024 and sunset all services that August, forcing users to migrate their data out within a window. Its successor, Notion Mail, is itself now closing.
- 1KYC
- No phone
- Zero-access
cock.li
The most no-KYC mailbox there is - no information at all, Tor-reachable - and the clearest reason no-KYC is not the same as safe. It has no default encryption, had a server disk seized in 2015, and in 2025 a webmail SQL-injection breach exposed more than a million user records. A throwaway inbox, not a secure one.
- 0KYC
- No phone
- Zero-access
Compare at a glance
Side by side.
- PosteoThe benchmark for how it should be done: sign up with no name, phone or alternate email; pay by cash sent in the post; and an audit by the German federal data-protection regulator confirmed it holds no customer-linkable IP logs. No documented handover on record. Verified 1 92 88 0 9.0
- TutaThe strongest zero-access model in the category - it encrypts the subject line, attachments, contacts and calendar, not just the body, so it cannot read your stored mail. Genuinely no-KYC. A 2020 German court order forced monitoring of named accounts going forward, but even then it could not decrypt existing end-to-end-encrypted mail. Verified 1 90 85 1 8.7
- Proton MailThe market leader, and the clearest lesson that private is not the same as anonymous. Signup needs no phone, and stored message bodies are zero-access encrypted - but documented cases show that IP, payment and recovery data are reachable under a Swiss court order, and subject lines are not encrypted. Verified 2 80 86 2 8.0
- Mailbox.orgA German, privacy-first provider that allows anonymous signup and anonymous cash payment by post, with PGP and an optional encrypted "Guard" mailbox. No prominent disclosure incident on record. Encryption is opt-in rather than default, like Posteo. No-KYC 1 82 76 0 8.0
- RiseupA no-KYC, invite-based activist mail collective that moved to encrypted storage after being served two sealed FBI warrants under a gag order in 2016 - which it complied with rather than face contempt, and its warrant canary lapsed. Mission-trusted, but US jurisdiction is the structural weakness. No-KYC 1 72 72 1 6.9
- StartMailA competent PGP-friendly provider from the makers of Startpage, but weaker on the no-KYC axis: it is paid-only after a short trial and typically takes an alternate email at signup, so the account is tied to a card and a contact address. No prominent disclosure incident on record. On-trigger 3 55 68 0 6.1
- MailfenceThe deliberate contrast to the German providers: a capable OpenPGP mailbox that, by its own privacy policy, logs your IP address, subjects, sender/recipient and timestamps to comply with Belgian data-retention law - and its transparency report shows it complies with valid Belgian court orders. On-trigger 2 56 66 1 5.9
- Skiff MailA cautionary tale, now shut down. Skiff was an end-to-end-encrypted mail/calendar/drive suite - until Notion acquired it in February 2024 and sunset all services that August, forcing users to migrate their data out within a window. Its successor, Notion Mail, is itself now closing. Defunct 1 55 22 1 3.7
- cock.liThe most no-KYC mailbox there is - no information at all, Tor-reachable - and the clearest reason no-KYC is not the same as safe. It has no default encryption, had a server disk seized in 2015, and in 2025 a webmail SQL-injection breach exposed more than a million user records. A throwaway inbox, not a secure one. Never KYC 0 78 28 2 3.0
Scores follow the published methodology - Privacy×50% + Trust×30% + Reliability×20%, then hard-capped when we find a documented deanonymization, data handover, or a shutdown that stranded users. Nothing here is paid placement.
Ask the bureau
No-KYC email — common questions
What is the most private no-KYC email provider?
By our scoring the highest-rated is Posteo (9.0/10). But "no-KYC" and "private" are two different tests: some providers let you sign up with no phone or ID yet can still read your mail or log your IP, while others encrypt your mailbox but sit in a jurisdiction that has compelled disclosure. We score sign-up anonymity, encryption and track record separately - read each dossier.
Can you get an email account with no phone number?
Yes - 5 of the 9 providers we audit let you register with no phone number and no identifying detail. The catch to watch for is a phone demand that only appears later - on a Tor connection, for a second account, or "on suspicion" - which several mainstream "private" providers do.
Can a private email provider read my email?
It depends on the encryption model. Providers with zero-access (end-to-end-at-rest) encryption store your mailbox encrypted to a key only you hold, so they cannot read stored mail or hand it over readable. Providers without it can read your mail on their servers - and can be compelled to disclose it. Either way, metadata (your IP, who you email, timing) is usually still visible to the provider.
Has any private email provider handed over user data?
Yes, and it is the most important thing to understand before trusting one. Even encrypted providers can be legally compelled to log and disclose metadata like IP addresses - there are documented cases of exactly that. Encryption of content is not the same as anonymity of usage. We log each documented disclosure or account-termination incident per provider and factor it into the reliability score.
Have a provider we haven’t covered? Ask the bureau.