noKYCme

Case file · Email

Posteo

The benchmark for how it should be done: sign up with no name, phone or alternate email; pay by cash sent in the post; and an audit by the German federal data-protection regulator confirmed it holds no customer-linkable IP logs. No documented handover on record.

Verified Verified by German Federal Commissioner for Data Protection audit (no customer-identifiable IP logs)
Based
Posteo e.K., Berlin, Germany
Price
EUR1/month, no free tier; pay anonymously by cash, decoupled from the account
Reviewed
2026-07-21
Audited by
The noKYCme Bureau

The systematized overview

The bureau vs the internet.

What the bureau found

9.0/10 · No identity required

Posteo is the closest thing to a gold standard in this category. You register with only a username and password - no name, phone or alternate email - and you can pay the EUR1/month fee in cash sent by post, through a system Posteo deliberately built to dissociate payment from the account. An audit by the German Federal Commissioner for Data Protection confirmed it does not store customer-identifiable IP addresses, and we found no documented data-handover or deanonymization incident. It is not zero-access by default (mailbox encryption is opt-in), which is the one asterisk.

What the internet says

3 recurring praises · 2 recurring gripes

Most praised: genuinely anonymous signup and cash payment. Most cited downside: no free tier.

We track our editorial score and community sentiment separately — neither moves the other. Read together, they're the systematized overview.


The facts

Jurisdiction, sign-up & encryption.

Jurisdiction
Posteo e.K., Berlin, Germany
Sign-up needs
Username + password only; no name, phone or alternate email
KYC trigger
None documented; no phone step reported even for anonymous signups
Encryption
TLS + DANE in transit, encrypted disks; opt-in zero-access mailbox encryption (not default); PGP/S-MIME in webmail
Provider access
Can access stored mail unless you enable mailbox encryption; no customer-linkable IP logs
Anon. payment
Cash by post, decoupled from the account; card/PayPal/bank also; no crypto
Logging
No customer-identifiable IP addresses (DPA-audited)
Open source
No (uses open standards)
Audited
Yes - German Federal Commissioner for Data Protection
Custom domain
Aliases included; custom domains not the focus
Free tier
No (EUR1/month)
Since
2009

The full read

Our analysis, in plain words.

Posteo is what the rest of this category is measured against. It strips identity out of the process at every step: you sign up with nothing but a username and password, and you can pay the EUR1 monthly fee in cash sent through the post, using a payment system Posteo built specifically so a payment can never be tied back to the mailbox it funds. Most "private" providers get one of those right; Posteo gets both.

The claim that would normally require faith here has been externally checked. The German Federal Commissioner for Data Protection audited Posteo and confirmed it does not store customer-identifiable IP addresses - the kind of independent verification that turns a marketing line into a fact. Combined with a strong German jurisdiction, annual transparency reporting, and no documented handover or deanonymization on record, that is why Posteo tops our email scoring.

The one honest caveat is that zero-access mailbox encryption is opt-in rather than default, so out of the box Posteo can technically read stored mail (as most providers can) until you enable it. Turn it on and the profile is close to ideal. There is no free tier, which some will count against it, but a EUR1 anonymous cash payment is a small price for a genuinely identity-free, audited mailbox.


The score, broken down

How the 9.0 is built.

Privacy 4.6Trust 2.6Reliability 1.8 Headroom 1.0

Privacy

weight 50%

What identity, data and metadata the service can demand or collect.

92/100

92 × 50% = 4.6 of 10

Trust

weight 30%

Whether it can technically deliver what it claims — code, audits, age.

88/100

88 × 30% = 2.6 of 10

Reliability

weight 20%

Whether the no-KYC claim holds under real-world pressure.

90/100

90 × 20% = 1.8 of 10

Weighted total 9.0 / 10 · no reliability rule triggered, so the score stands. See the rubric →


Every point, sourced

What earned the score.

Privacy

  • +8Registers with no name, phone or alternate email - just username + password
  • +6Anonymous cash-by-post payment, deliberately decoupled from the account
  • +6No customer-identifiable IP logging (confirmed by the German DPA audit)
  • +-3Zero-access mailbox encryption is opt-in, not default

Trust

  • +6Audited by the German Federal Commissioner for Data Protection
  • +4Publishes annual transparency reports; German (strong-privacy) jurisdiction
  • +4Operating since 2009 with a consistent privacy record
  • +-2Not fully open source

The fine print, read for you

Terms reviewed — no trapdoor found.

Verbatim — the honest version
“Posteo does not save the IP addresses of its customers and dissociates payments from account data, as confirmed in an audit by the German Federal Commissioner for Data Protection.”

What it meansThis is the honest version of a privacy promise: an external regulator checked and confirmed there are no customer-linkable IP logs, and the payment system is built so a cash payment cannot be tied back to the mailbox. It is the structural opposite of a provider that logs metadata by default. The only caveat is that end-to-end mailbox encryption is opt-in, so enable it if you want the provider unable to read stored mail.

Read the source →
KYC trigger threshold

None for identity. You can open a Posteo account with only a username and password - no name, phone or alternate email - and pay the EUR1/month fee anonymously in cash by post. There is no free tier, so payment is required, but the payment system is designed so it cannot be linked to the account. We rate it KYC level 1: identity-free in practice, one step short of a hard "never" guarantee.

Policy review — point by point

  • Audited no-IP-logging

    The German federal data-protection regulator audited and confirmed Posteo stores no customer-identifiable IP addresses.

  • Payment decoupled from account

    Posteo built a payment system that dissociates payment (including anonymous cash) from account data.

  • Encryption is opt-in

    Zero-access mailbox encryption must be enabled by the user; it is not on by default.

Jurisdiction analysis

Posteo operates under German law, one of the strongest data-protection regimes, and has an externally audited no-IP-log posture. German providers can still be served valid German court orders for data they hold - but Posteo is structured to hold as little as possible, which is the point. Its own payment and transparency pages are the primary sources here.


We keep watching

Incident & policy timeline.

  1. 2009

    Launched with an anonymous, payment-decoupled model

    Posteo launched in Berlin offering identity-free signup and a payment system deliberately separated from account data, with cash-by-post accepted.

    source ↗
  2. 2016

    German data-protection regulator audit confirms no IP logging

    An audit by the German Federal Commissioner for Data Protection confirmed Posteo does not store customer-identifiable IP addresses - independent verification of the no-logs claim rather than a marketing assertion.

    source ↗

The verdict

Where it stands.

Strengths

  • Identity-free signup (no name, phone or alternate email)
  • Anonymous cash-by-post payment, decoupled from the account
  • Independently audited no-IP-logging by the German DPA
  • German jurisdiction with strong data-protection law

Trade-offs

  • No free tier (EUR1/month) - payment always required
  • Zero-access mailbox encryption is opt-in, not default
  • Not fully open source
Visit Posteo No affiliate relationship. We link to the official site directly.

Across the internet

What reviewers report.

Consistently praised

  • Genuinely anonymous signup and cash payment
  • Independently audited no-logging
  • Clean privacy track record since 2009

Recurring complaints

  • No free tier
  • Encryption not on by default

Posteo is consistently cited by privacy communities (Privacy Guides and others) as a top-tier private provider, praised for anonymous payment and audited no-logging. The main gripes are the lack of a free tier and opt-in encryption. Synthesized from privacy-community reviews and Posteo primary sources.


Keep exploring

Related lists & categories.


Ask the bureau

Posteo, common questions.

Is Posteo no-KYC?

Yes, on identity. You register with only a username and password - no name, phone or alternate email - and can pay anonymously in cash by post through a system built to keep payment separate from the account. There is no free tier, so a EUR1/month payment is required, but it cannot be linked to the mailbox. We rate it KYC level 1.

Does Posteo log my IP address?

No customer-identifiable IP logging - and this is not just a claim: the German Federal Commissioner for Data Protection audited Posteo and confirmed it. That external verification is why Posteo is our benchmark for the category.

Can Posteo read my email?

By default it can access stored mail on its servers, like most providers. Posteo offers opt-in mailbox encryption that stores inbound mail encrypted to your key - enable it if you want the provider unable to read your stored mail. Metadata and mail in transit follow the usual limits.

Your exact case not covered? The live Ask the bureau answers it and turns it into a public FAQ.