The bureau · Email
Zero-access encrypted email providers
6 providers here encrypt your mailbox so they cannot read it at rest. Posteo rates highest. Zero-access (end-to-end-at-rest) encryption means the provider stores your mail encrypted to a key only you hold, so it cannot read it - and cannot hand readable mail to anyone who asks. It does not cover metadata (who emailed whom, when), which most providers can still see and disclose.
6 matches, ranked
Which email providers cannot read your stored mail?
Posteo
The benchmark for how it should be done: sign up with no name, phone or alternate email; pay by cash sent in the post; and an audit by the German federal data-protection regulator confirmed it holds no customer-linkable IP logs. No documented handover on record.
- 1KYC
- No phone
- Zero-access
- Anon. pay
Tuta
The strongest zero-access model in the category - it encrypts the subject line, attachments, contacts and calendar, not just the body, so it cannot read your stored mail. Genuinely no-KYC. A 2020 German court order forced monitoring of named accounts going forward, but even then it could not decrypt existing end-to-end-encrypted mail.
- 1KYC
- No phone
- Zero-access
Proton Mail
The market leader, and the clearest lesson that private is not the same as anonymous. Signup needs no phone, and stored message bodies are zero-access encrypted - but documented cases show that IP, payment and recovery data are reachable under a Swiss court order, and subject lines are not encrypted.
- 2KYC
- Zero-access
StartMail
A competent PGP-friendly provider from the makers of Startpage, but weaker on the no-KYC axis: it is paid-only after a short trial and typically takes an alternate email at signup, so the account is tied to a card and a contact address. No prominent disclosure incident on record.
- 3KYC
- Zero-access
Mailfence
The deliberate contrast to the German providers: a capable OpenPGP mailbox that, by its own privacy policy, logs your IP address, subjects, sender/recipient and timestamps to comply with Belgian data-retention law - and its transparency report shows it complies with valid Belgian court orders.
- 2KYC
- Zero-access
cock.li
The most no-KYC mailbox there is - no information at all, Tor-reachable - and the clearest reason no-KYC is not the same as safe. It has no default encryption, had a server disk seized in 2015, and in 2025 a webmail SQL-injection breach exposed more than a million user records. A throwaway inbox, not a secure one.
- 0KYC
- No phone
- Zero-access
Ask the bureau
Zero-access encryption — questions
Does zero-access encryption mean my email is fully private?
Not fully. Zero-access encryption protects the CONTENT of stored mail from the provider, which is a major protection. But metadata - your IP, who you email, subject lines in some cases, and timing - is often still visible to the provider and can be logged or disclosed. And mail to and from non-encrypted providers is only as private as the other side.
Browse the full email directory or read the methodology.