noKYCme

The bureau · Email

Open-source private email providers

6 providers here publish open-source code you can inspect. Tuta rates highest. Open-source clients (and ideally servers) let independent researchers verify that the encryption works as claimed, rather than taking the provider’s word for it. It is a trust signal, not a privacy guarantee on its own.


6 matches, ranked

Which private email providers are open source?

✓ Verified
#1

Tuta

8.7 /10

The strongest zero-access model in the category - it encrypts the subject line, attachments, contacts and calendar, not just the body, so it cannot read your stored mail. Genuinely no-KYC. A 2020 German court order forced monitoring of named accounts going forward, but even then it could not decrypt existing end-to-end-encrypted mail.

Privacy 90
Trust 85
Reliab. 82
  • 1KYC
  • No phone
  • Zero-access
Tutao GmbH, Hanover, Germany 1 disclosures 3↑ 2↓ Read →
✓ Verified
#2

Proton Mail

8.0 /10

The market leader, and the clearest lesson that private is not the same as anonymous. Signup needs no phone, and stored message bodies are zero-access encrypted - but documented cases show that IP, payment and recovery data are reachable under a Swiss court order, and subject lines are not encrypted.

Privacy 80
Trust 86
Reliab. 70
  • 2KYC
  • Zero-access
Proton AG, Geneva, Switzerland 2 disclosures 3↑ 2↓ Read →
No-KYC · Level 1
#3

addy.io

7.9 /10

An open-source email aliasing relay (not a mailbox): it hands out throwaway aliases that forward to your real inbox, can PGP-encrypt the forwarded mail, takes no ID, and accepts Monero. But it holds your real destination address, logs IPs for 3 days, and will disclose your identity to law enforcement on abuse - so it is pseudonymous, not anonymous.

Privacy 76
Trust 83
Reliab. 80
  • 1KYC
  • No phone
Will Browning (sole operator), United Kingdom (Five/Nine-Eyes); governing law England and Wales 0 disclosures 2↑ 3↓ Read →
No-KYC · Level 1
#4

Autistici/Inventati

7.7 /10

A 24-year-old Italian activist email collective that requires no identity - you write why you share their anti-fascist/anti-commercial principles, a human approves it, and the request is deleted 15 days later. It holds almost no data by design - a posture forged after Italian police covertly backdoored its server in 2004-05.

Privacy 85
Trust 82
Reliab. 52
  • 1KYC
  • No phone
Associazione AI-ODV, Italy (14-Eyes); EU/GDPR; mirror inventati.org 2 disclosures 2↑ 3↓ Read →
No-KYC · Level 1
#5

Disroot

7.2 /10

A Netherlands-based, donation-funded community collective (since 2015) running a fully open-source stack. Sign up with just a username and a deletable verification email - no phone, name or ID - on GDPR soil, with 24-hour logs and Monero accepted. The trade-off is volunteer-run reliability, not privacy.

Privacy 76
Trust 74
Reliab. 63
  • 1KYC
  • No phone
Stichting Disroot.org, Amsterdam, Netherlands (EU/GDPR) 0 disclosures 2↑ 3↓ Read →
No-KYC · Level 1
#6

Riseup

6.9 /10

A no-KYC, invite-based activist mail collective that moved to encrypted storage after being served two sealed FBI warrants under a gag order in 2016 - which it complied with rather than face contempt, and its warrant canary lapsed. Mission-trusted, but US jurisdiction is the structural weakness.

Privacy 72
Trust 72
Reliab. 55
  • 1KYC
  • No phone
Riseup Networks, Seattle, USA 1 disclosures 3↑ 2↓ Read →

Ask the bureau

Open source — questions

Does open source make email more private?

Indirectly. Open code lets researchers audit whether the encryption and no-logging claims hold, which is why the strongest providers publish theirs. But open source alone does not stop a provider from logging metadata or handing it over - judge it alongside jurisdiction and track record.

Browse the full email directory or read the methodology.