noKYCme

The bureau · Email

Zero-access encrypted email providers

6 providers here encrypt your mailbox so they cannot read it at rest. Posteo rates highest. Zero-access (end-to-end-at-rest) encryption means the provider stores your mail encrypted to a key only you hold, so it cannot read it - and cannot hand readable mail to anyone who asks. It does not cover metadata (who emailed whom, when), which most providers can still see and disclose.


6 matches, ranked

Which email providers cannot read your stored mail?

Verified
#1

Posteo

9.0 /10

The benchmark for how it should be done: sign up with no name, phone or alternate email; pay by cash sent in the post; and an audit by the German federal data-protection regulator confirmed it holds no customer-linkable IP logs. No documented handover on record.

Privacy 92
Trust 88
Reliab. 90
  • 1KYC
  • No phone
  • Zero-access
  • Anon. pay
Posteo e.K., Berlin, Germany 0 disclosures 3↑ 2↓ Read →
Verified
#2

Tuta

8.7 /10

The strongest zero-access model in the category - it encrypts the subject line, attachments, contacts and calendar, not just the body, so it cannot read your stored mail. Genuinely no-KYC. A 2020 German court order forced monitoring of named accounts going forward, but even then it could not decrypt existing end-to-end-encrypted mail.

Privacy 90
Trust 85
Reliab. 82
  • 1KYC
  • No phone
  • Zero-access
Tutao GmbH, Hanover, Germany 1 disclosures 3↑ 2↓ Read →
Verified
#3

Proton Mail

8.0 /10

The market leader, and the clearest lesson that private is not the same as anonymous. Signup needs no phone, and stored message bodies are zero-access encrypted - but documented cases show that IP, payment and recovery data are reachable under a Swiss court order, and subject lines are not encrypted.

Privacy 80
Trust 86
Reliab. 70
  • 2KYC
  • Zero-access
Proton AG, Geneva, Switzerland 2 disclosures 3↑ 2↓ Read →
KYC-on-trigger · Level 3
#4

StartMail

6.1 /10

A competent PGP-friendly provider from the makers of Startpage, but weaker on the no-KYC axis: it is paid-only after a short trial and typically takes an alternate email at signup, so the account is tied to a card and a contact address. No prominent disclosure incident on record.

Privacy 55
Trust 68
Reliab. 66
  • 3KYC
  • Zero-access
Surfboard Holding BV, Netherlands 0 disclosures 2↑ 2↓ Read →
KYC-on-trigger · Level 2
#5

Mailfence

5.9 /10

The deliberate contrast to the German providers: a capable OpenPGP mailbox that, by its own privacy policy, logs your IP address, subjects, sender/recipient and timestamps to comply with Belgian data-retention law - and its transparency report shows it complies with valid Belgian court orders.

Privacy 56
Trust 66
Reliab. 55
  • 2KYC
  • Zero-access
ContactOffice Group SA, Belgium 1 disclosures 2↑ 2↓ Read →
Never KYC
#6

cock.li

3.0 /10

The most no-KYC mailbox there is - no information at all, Tor-reachable - and the clearest reason no-KYC is not the same as safe. It has no default encryption, had a server disk seized in 2015, and in 2025 a webmail SQL-injection breach exposed more than a million user records. A throwaway inbox, not a secure one.

Privacy 78
Trust 28
Reliab. 20
  • 0KYC
  • No phone
  • Zero-access
Sole operator (Vincent Canfield); hosting jurisdiction has shifted 2 disclosures 2↑ 2↓ Read →

Ask the bureau

Zero-access encryption — questions

Does zero-access encryption mean my email is fully private?

Not fully. Zero-access encryption protects the CONTENT of stored mail from the provider, which is a major protection. But metadata - your IP, who you email, subject lines in some cases, and timing - is often still visible to the provider and can be logged or disclosed. And mail to and from non-encrypted providers is only as private as the other side.

Browse the full email directory or read the methodology.