Blog/ Head-to-head comparisons

Tuta vs Mailfence for Encrypted Email: Proprietary or OpenPGP?

Nafiul HasanNafiul Hasan· 14 min read
Tuta vs Mailfence for encrypted email — a closed proprietary encryption protocol on one side and an interoperable OpenPGP keystore on the other

The short answer

Neither is universally better. Tuta's own protocol encrypts more of each message, including subject lines, but end-to-end encryption only works Tuta-to-Tuta. Mailfence's OpenPGP works with any PGP user anywhere and keeps IMAP access, at the cost of an unencrypted subject line and manual key work.

Tuta vs Mailfence for encrypted email: proprietary post-quantum crypto with no IMAP, or OpenPGP that talks to everyone. Which wins, by dimension.

On this page
  1. 01The verdict up front
  2. 02At-a-glance comparison table
  3. 03The axis most comparisons skip: who can actually receive it
  4. 04Where Tuta wins
  5. 05Where Mailfence wins
  6. 06Key management: managed for you, or yours to hold
  7. 07Jurisdiction: Germany vs Belgium, and what that actually buys
  8. 08Client access: IMAP is the quiet dealbreaker
  9. 09Pricing model, and why there are no numbers here
  10. 10Who each one is genuinely for
  11. 11A third option, honestly — and where AI Emaily does not fit

Tuta vs Mailfence for encrypted email is really a question about protocol philosophy, not feature counts. Tuta built its own encryption and controls the whole stack. Mailfence implements OpenPGP, the standard defined in RFC 4880, and keeps the mailbox interoperable with the rest of the internet.

That single decision cascades into everything else: who you can exchange encrypted mail with, whether the subject line is protected, whether you can use a desktop client over IMAP, and how much key management lands on you.

This post compares them dimension by dimension and names a winner on each. Capabilities were checked against each vendor's own live pages in September 2026 — both products change, so verify anything decision-critical on their sites before you pay.

The verdict up front#

Pick Mailfence if you need to exchange encrypted mail with people who are not your provider's customers, or if you want a mailbox a real desktop client can open. OpenPGP is the only encryption in either product that works with strangers, and Mailfence documents IMAP, POP, SMTP and Exchange ActiveSync on its paid tiers.

Pick Tuta if your threat model is about metadata inside the mailbox rather than interoperability outside it. Tuta encrypts subject lines, contacts and calendar entries — OpenPGP does not encrypt subject lines, and Tuta's own encryption page names that as one of the reasons it rejected PGP.

The honest concession, by name: Tuta wins the depth-of-encryption dimension outright. Mailfence leaves subject lines, and therefore a readable summary of who is talking to whom about what, outside the encrypted envelope. That is not a small gap and no amount of standards purity closes it.

Mailfence wins the reach dimension just as cleanly. A Tuta user emailing a non-Tuta recipient falls back to a password-protected message the recipient opens on Tuta's servers — a workable mechanism, but it is not standards-based encrypted mail, and it requires you to get a shared password to the other person somehow.

Scope of this verdict

This compares two encrypted mailbox providers on encryption architecture, client access, jurisdiction and key handling. It is not a general email-client comparison, and neither product is being judged on AI, search or triage features it does not claim to have.

At-a-glance comparison table#

DimensionTutaMailfenceEdge
Encryption approachProprietary — AES-256 plus RSA-2048 or ECC x25519, and TutaCrypt with Kyber-1024 for post-quantum protectionOpenPGP (RFC 4880), implemented in an in-browser keystoreDepends on goal
Encrypted to non-customersPassword-protected message opened on Tuta's serversReal OpenPGP to any PGP user, anywhereMailfence
Subject line encryptedYes — Tuta states subjects and sender/recipient names are encryptedNo — OpenPGP encrypts the body, not the headerTuta
IMAP / POP / SMTPNot offered — Tuta's own apps onlyDocumented on paid tiersMailfence
Exchange ActiveSyncNoDocumented on paid tiersMailfence
Key managementHandled for you; nothing to import or exportGenerate or import your own key pairs; multiple pairs supportedDepends on goal
Encrypted calendar and contactsYes — events, attendees and address books encryptedCalendar, documents and groups included; encryption scope differs per featureTuta
JurisdictionGermany, EU — GDPRBelgium, EU — the company stresses that only local judges can compel disclosure, with a court orderTie
PlatformsAndroid, iPhone, iPad, Linux, Windows, macOS, browserWeb and mobile, plus any client you connect over IMAP or ActiveSyncDepends on goal
Packaging shapeFree tier plus paid personal tiers (Revolutionary, Legend) and business plansFree tier plus several paid tiers; protocol access sits on the paid onesTie

The axis most comparisons skip: who can actually receive it#

Most Tuta vs Mailfence write-ups compare storage, apps and interface. That misses the thing that decides whether encryption does anything for you: encryption is a property of a pair of people, not of a mailbox.

A mailbox advertised as end-to-end encrypted can still send nearly all of its mail in the clear, because the other side is on Gmail. What matters is the size and shape of the set of people you can reach with the encryption switched on.

For Tuta, that set is other Tuta users, plus anyone you can hand a password to out of band. For Mailfence, it is every OpenPGP user on the internet whose public key you can obtain — including people on Proton Mail, Thunderbird with an OpenPGP setup, or a self-hosted server.

  • Tuta to Tuta: end-to-end encrypted automatically, subject line included.
  • Tuta to anyone else: a password-protected message the recipient opens in a browser session, with the password exchanged once and reused for that contact.
  • Mailfence to any OpenPGP user: standard encrypted mail, body encrypted, subject header in the clear.
  • Mailfence to a non-PGP user: a password-encrypted message where the recipient receives a link to decrypt it on Mailfence's servers.
  • Either provider to a plain Gmail user with no setup: not end-to-end encrypted at all.
Diagram of encrypted email routing paths: same-provider end-to-end encryption, standards-based OpenPGP to any key holder, and a password-protected fallback link for everyone else
The fallback path is where most encrypted mail actually travels. Both products have one; only one of them also has a standards path.

Where Tuta wins#

Tuta's advantage is that it did not have to stay compatible with a 1990s message format, so it encrypted things OpenPGP structurally cannot.

Tuta's encryption page states that email bodies, subjects and sender and recipient names are encrypted, along with all attachments, whole address books, and calendar events including descriptions, times, locations and attendees. The unencrypted remainder is the email addresses themselves and the send and receive dates, which the delivery protocol needs.

That is a materially different metadata posture from a PGP mailbox, where an observer with server access reads every subject line in the archive.

  • Encrypted subject lines — the single clearest technical win in this comparison.
  • Post-quantum protection: TutaCrypt, introduced in March 2024, combines conventional algorithms with Kyber-1024. Whether you need that today depends on whether you believe harvest-now-decrypt-later applies to your mail.
  • Encrypted calendar and contacts, not just mail — the surrounding data is inside the same envelope.
  • Nothing to configure. There is no key to generate, back up, publish or lose, because Tuta manages the key material for you.
  • Algorithm upgrades ship centrally. Tuta cites PGP's difficulty updating algorithms and its lack of forward secrecy as reasons it built its own protocol.

Where Mailfence wins#

Mailfence's advantage is that it bet on a standard, and standards outlive vendors. An OpenPGP key pair you generated in Mailfence's keystore still works if you leave Mailfence, because the ciphertext and the key are both defined by a public specification rather than by one company's client.

Mailfence describes itself as fully interoperable with any OpenPGP service and ships an integrated keystore where you can generate a key pair or import an existing one, with support for multiple key pairs.

The second win is duller and matters more day to day: Mailfence keeps standard protocol access. IMAP, POP, SMTP and Exchange ActiveSync are documented on its paid tiers, with the free plan limited to web and mobile.

  • Encrypted mail with people who will never sign up for your provider — the only route either product offers that does not require a shared secret.
  • Digital signatures, so a recipient can verify a message really came from your key rather than from someone who compromised the account.
  • Portability: keys you control can be exported and reused elsewhere, which is the practical definition of no lock-in.
  • IMAP access, which means a desktop client, a backup tool, or a migration script can all read the mailbox.
  • A broader suite in the same account — calendar, document storage and contact groups — aimed at small teams rather than only at individual mail.

OpenPGP does not hide the subject line

This is a property of the format, not a Mailfence shortcoming. RFC 4880 encrypts message bodies; the subject lives in the RFC 5322 header outside that envelope. If a readable subject line is unacceptable in your threat model, that rules out every PGP-based provider, not just this one.

Key management: managed for you, or yours to hold#

This is where the two philosophies stop being abstract. Tuta generates and rotates key material invisibly. You never see a key, never export one, and never have to think about a keyserver. The cost is that the keys only mean something inside Tuta's own ecosystem.

Mailfence puts a keystore in front of you. You can generate a pair or import one you already trust, and hold more than one — useful if you already have a long-lived identity key from Thunderbird or GnuPG that your contacts have signed.

Neither model is strictly safer. Managed keys remove the biggest real-world failure mode, which is a user losing or mishandling a private key. User-held keys remove a different one, which is being unable to verify or move your own identity.

QuestionTutaMailfence
Can you import an existing key?NoYes
Can you hold multiple key pairs?NoYes, documented
Can you lose access by losing a key?No separate key to loseYes — key and passphrase discipline is on you
Does your identity survive leaving?No — the protocol is Tuta'sYes — the key pair is standard
Can a recipient verify a signature?Within Tuta's own modelYes, via standard OpenPGP signatures

Jurisdiction: Germany vs Belgium, and what that actually buys#

Both providers sit inside the EU and both lean on it in their marketing. Tuta is made in Germany and cites GDPR. Mailfence's servers are in Belgium, and the company's pitch is specifically about legal process: only local judges can request information, and they must have a court order.

Treat that as a real but narrow protection. Jurisdiction governs who can compel a provider to hand something over and through what process. It does not change what the provider is technically able to hand over.

That is why the encryption question ranks above the jurisdiction question. Content a provider genuinely cannot read is safe from a court order in any country; content it can read is only as safe as the local process. On this dimension the two are close enough that it should rarely be the tiebreaker.

Verify the legal claims yourself if they are load-bearing

Provider marketing pages summarise national law in a sentence, and law changes faster than marketing copy. If a specific legal protection is the reason you are choosing one of these, read the provider's current transparency and legal pages rather than a comparison post — including this one.

Client access: IMAP is the quiet dealbreaker#

Tuta does not offer IMAP, POP or SMTP. That is a deliberate consequence of its design: if a standard client could read the mailbox, the mailbox would have to hand that client decrypted content over a standard protocol, which is the thing Tuta built its own apps to avoid.

So Tuta ships its own clients instead, across Android, iPhone, iPad, Linux, Windows, macOS and the browser. That is broad coverage, and if you are happy inside those apps you may never notice the restriction.

You notice it the moment you want something else: a third-party client, a local archive, a search tool, a backup script, a shared-inbox product, or any automation. On Mailfence, those all work through IMAP on a paid tier. On Tuta, none of them do.

  • Want to keep one desktop client for six accounts? Mailfence connects; Tuta does not.
  • Want an automated local backup of the whole mailbox? IMAP is the usual route, so Mailfence again.
  • Want the strongest possible guarantee that no third-party software ever touches plaintext? Then Tuta's refusal is the feature, not the bug.
Decision fork between a closed encrypted mailbox with vendor-only apps and an OpenPGP mailbox that keeps IMAP access for third-party clients
The IMAP question usually settles this comparison faster than the cryptography does.

Pricing model, and why there are no numbers here#

Both providers use the same packaging shape: a limited free tier plus paid tiers that unlock capacity and capability. Tuta publishes personal tiers named Revolutionary and Legend above its free plan, plus business plans. Mailfence publishes a free plan plus several paid tiers, and puts protocol access — IMAP, POP, SMTP, ActiveSync — on the paid side.

We do not print competitor prices. Email pricing changes without announcement, currency and region change what you actually pay, and a stale figure in a comparison post is worse than no figure, because readers act on it.

What is worth knowing is the shape of the gate rather than the number. On Mailfence, the free plan is a web-and-mobile mailbox; the thing most people eventually want from it, standard protocol access, is paid. On Tuta, the free plan is a genuinely usable encrypted mailbox with tight storage and no custom domain or aliases.

Check both pricing pages on the day you buy

Tier names, storage and which features sit behind which gate have all moved on both products in the past. The vendor's own pricing page is the only source worth trusting for what you will be charged.

Who each one is genuinely for#

The choice is decided by who you send to and what else has to read the mailbox. Everything else is detail.

If this describes youChooseWhy
You need encrypted mail with people outside your organisation who already use PGPMailfenceOpenPGP is the only interoperable path either product offers
Your subject lines leak as much as your bodies wouldTutaSubjects, contacts and calendar entries are inside the encrypted envelope
You want a desktop client, a backup tool or any automation on the mailboxMailfenceIMAP, POP, SMTP and ActiveSync on paid tiers
You want encryption with nothing to configure and no key to loseTutaKey material is managed; there is no keystore to learn
You already hold a long-lived PGP identity your contacts trustMailfenceImport existing key pairs, and hold more than one
Post-quantum protection matters to you todayTutaTutaCrypt combines conventional algorithms with Kyber-1024
You want a small-team suite — shared documents, groups, calendar — in one accountMailfenceDocuments, groups and calendar ship alongside mail

A third option, honestly — and where AI Emaily does not fit#

We build AI Emaily, an AI email client, so treat this section as an interested party being specific about its own limits. AI Emaily is not an encrypted mailbox provider and is not a replacement for either product on this page. If end-to-end encrypted mail is the requirement, the honest ranking above stands and we are not in it.

Two limits are worth stating plainly. AI Emaily connects accounts over Gmail, Microsoft and IMAP — which means it can connect a Mailfence mailbox on a tier that includes IMAP, and cannot connect Tuta at all, because Tuta offers no IMAP by design. And an AI assistant has to read message content to triage or draft, so end-to-end encryption and AI assistance are genuinely in tension: content only your recipient can read is content our agent cannot read either.

Where we are a reasonable third position is the common case where the encrypted mailbox is one of several accounts rather than all of them. If your PGP mail lives in Mailfence and the rest of your working day is in Gmail or Outlook, a client that unifies those and triages the non-sensitive ones is a different job from encryption, not a competitor to it. Our voice matching comes from a Personal Context brain you fill in plus per-client profiles you set, not from scanning your past mail, and we do not train models on user mail.

If that combination is what you are actually solving for, the product is at aiemaily.com with plans on the pricing page; there is a 7-day free trial with a card required and nothing charged if you cancel before day seven. If it is not, stay with the verdict above — a comparison page that recommends its own publisher on a question it does not answer is worth nothing to you.

Frequently asked

Nafiul Hasan

Written by

Nafiul Hasan

Nafiul Hasan is an entrepreneur and AI automation system builder with 10+ years of experience turning messy, manual workflows into reliable automated systems. He designs and ships AI enterprise solutions end-to-end — the agent logic, the data plumbing, and the product people actually use — and founded AI Emaily to give busy professionals their attention back. He writes here from the builder's seat: what works, what breaks, and how to put AI to work without giving up control.

EntrepreneurAI Automation System BuilderAI EnthusiastBuilds AI Enterprise Solutions10+ years experience
More from Nafiul
Ready when you are

Encrypted mailbox in one place, everything else in another?

AI Emaily unifies Gmail, Outlook and IMAP accounts and triages the mail that is not end-to-end encrypted. We build it — 7-day free trial, card required, nothing charged if you cancel before day seven.

  • 7-day free trial
  • Cancel anytime
  • Every provider