Mailfence is based in Belgium, a country with strict privacy laws and no record of co-operation with the US National Security Agency or the UK Government Intelligence Directorate, where ISPs are required to implement extensive and comprehensive data retention, but access to this data is strictly regulated and requires a warrant.
Mailfence uses simple ‘one-click’ OpenPGP encryption to protect emails. Emails sent to other Mailfence users are automatically encrypted (and do not leave Mailfence's servers), and emails sent to non-members can be transmitted either encrypted or unencrypted using PGP. Email sent to non-members can be transmitted unencrypted but digitally signed using a PGP key, and alternatively symmetrically encrypted email can be sent to non-PGP users using a shared key to ensure its security. Since Mailfence uses a standard implementation of OpenPGP with full key management capabilities, the service is interoperable with ‘normal’ PGP users, where mailboxes run their own key servers and PGP keys are generated in the browser and stored on Mailfence's servers using AES-256 ciphers. PGP keys are generated in the browser and stored on Mailfence's servers using AES-256 ciphers.
Browser-based PGP encryption is open-source, but most of the back-end environment is closed-source, and deleted messages are kept for a fortnight for backup. More worryingly Mailfence records all email metadata including ‘IP address, email ID, sender and recipient addresses, subject, browser version, country and timestamp’.Other first class features offered by Mailfence include security, exportable calendars and secure document storage. While mail can be synced to iOS and Android devices via Microsoft Exchange ActiveSync, and support for POP and IMAP means you can use third-party apps (paid subscribers only), it also offers a simplified web interface designed specifically for mobile devices.





















