Whether the server itself runs non-free software is a different issue. Non-free software running on the server infringes the freedom of the server operator, but not yours; therefore, it is a secondary issue. We note here that some server operators say they run exclusively free software; you might choose one of them to reward their support for the community.
We don’t know of any surefire way to evaluate a mail service for privacy, since any such service could be handing mail data massively to some government, and there is no way to detect this from outside.
We do know that specific companies providing webmail services were named as part of the PRISM NSA spying revelations: Google, Yahoo, Microsoft, Apple, and AOL.
We also know that some smaller companies, like Lavabit, were pressured to turn over information.
With these caveats, here are some recommendations:
- Pick a mail service located in a country that won’t cooperate with governments that you’re particularly concerned about privacy from.
- Avoid using LinkedIn, which fishes for people’s email contact lists.
- If your mail service and your search engine are run by companies that don’t cooperate, neither of them can correlate your searches with your mail contents. (A spy agency could still do so, if the two companies are in the same country or in countries that cooperate in massive surveillance.) Thus, don’t use both Gmail and other Google services such as web search.
Some of these services are gratis, but that’s a separate issue. Recall that “free software” refers to freedom, not price.
- https://posteo.de: Fully compliant with LibreJS’s standards, but a bug in LibreJS causes the site to not work when the plugin is enabled. Does not work without JS.
- OpenMailBox: Runs explicitly on free software. Service started in June 2013.
- https://riseup.net: Geared more toward activists – they have a manual screening process. Signup works with LibreJS. SquirrelMail (works without JS) can be used to access webmail, POP/IMAP clients can also be used. To access Squirrel mail, access the online mail client page, and select the “old webmail(squirrelmail only)” link.
- https://www.mailoo.org: Explicitly states it runs on free software. Currently French only – would appreciate help translating(registrations were closed as of 2017/01/25).
To ask about a mail service not listed here, or request corrections and updates, please send a mail to: monoverde at riseup dot net : with “Webmail System” in the subject line.
Not Recommended Services
Systems we’ve investigated and found wanting.
- Fastmail: Sign up, sign in, and webmail all work smoothly. This is a paid service with a 60-day free trial. – UPDATE: was notified that this is not the case.
- yahoo: works without JS apparently, but you need JS enabled to create a yahoo account
- Mail.ru: Sign up, sign in, and webmail all work smoothly. BEWARE though – it is almost certainly under governmental surveillance, and likely does not respect privacy.
Under Review Services
These are systems either currently under review, or undergoing a status change.
- https://mailbox.org JS needed to register or use system.
- https://protonmail.ch JS needed to register or use system.
- http://www.autistici.org: Sign up needs JS. They are working on becoming LibreJS compliant, but no ETA on this yet.
- https://www.unseen.is: Site doesn’t load without JS.
- https://www.hushmail.com: Site doesn’t load without JS.
- https://tutanota.de: Looks promising – they’re working on becoming LibreJS Compliant.
Systems that don’t fit conveniently into any category, but we’ve reviewed or processed them.
Vedova Foundation is a UK charity operating worldwide to advance software freedom — learn about our history and work.