Case file · Email
Posteo
The benchmark for how it should be done: sign up with no name, phone or alternate email; pay by cash sent in the post; and an audit by the German federal data-protection regulator confirmed it holds no customer-linkable IP logs. No documented handover on record.
The systematized overview
The bureau vs the internet.
9.0/10 · No identity required
Posteo is the closest thing to a gold standard in this category. You register with only a username and password - no name, phone or alternate email - and you can pay the EUR1/month fee in cash sent by post, through a system Posteo deliberately built to dissociate payment from the account. An audit by the German Federal Commissioner for Data Protection confirmed it does not store customer-identifiable IP addresses, and we found no documented data-handover or deanonymization incident. It is not zero-access by default (mailbox encryption is opt-in), which is the one asterisk.
3 recurring praises · 2 recurring gripes
Most praised: genuinely anonymous signup and cash payment. Most cited downside: no free tier.
We track our editorial score and community sentiment separately — neither moves the other. Read together, they're the systematized overview.
The facts
Jurisdiction, sign-up & encryption.
- Jurisdiction
- Posteo e.K., Berlin, Germany
- Sign-up needs
- Username + password only; no name, phone or alternate email
- KYC trigger
- None documented; no phone step reported even for anonymous signups
- Encryption
- TLS + DANE in transit, encrypted disks; opt-in zero-access mailbox encryption (not default); PGP/S-MIME in webmail
- Provider access
- Can access stored mail unless you enable mailbox encryption; no customer-linkable IP logs
- Anon. payment
- Cash by post, decoupled from the account; card/PayPal/bank also; no crypto
- Logging
- No customer-identifiable IP addresses (DPA-audited)
- Open source
- No (uses open standards)
- Audited
- Yes - German Federal Commissioner for Data Protection
- Custom domain
- Aliases included; custom domains not the focus
- Free tier
- No (EUR1/month)
- Since
- 2009
The full read
Our analysis, in plain words.
Posteo is what the rest of this category is measured against. It strips identity out of the process at every step: you sign up with nothing but a username and password, and you can pay the EUR1 monthly fee in cash sent through the post, using a payment system Posteo built specifically so a payment can never be tied back to the mailbox it funds. Most "private" providers get one of those right; Posteo gets both.
The claim that would normally require faith here has been externally checked. The German Federal Commissioner for Data Protection audited Posteo and confirmed it does not store customer-identifiable IP addresses - the kind of independent verification that turns a marketing line into a fact. Combined with a strong German jurisdiction, annual transparency reporting, and no documented handover or deanonymization on record, that is why Posteo tops our email scoring.
The one honest caveat is that zero-access mailbox encryption is opt-in rather than default, so out of the box Posteo can technically read stored mail (as most providers can) until you enable it. Turn it on and the profile is close to ideal. There is no free tier, which some will count against it, but a EUR1 anonymous cash payment is a small price for a genuinely identity-free, audited mailbox.
The score, broken down
How the 9.0 is built.
Privacy
weight 50%What identity, data and metadata the service can demand or collect.
92 × 50% = 4.6 of 10
Trust
weight 30%Whether it can technically deliver what it claims — code, audits, age.
88 × 30% = 2.6 of 10
Reliability
weight 20%Whether the no-KYC claim holds under real-world pressure.
90 × 20% = 1.8 of 10
Weighted total 9.0 / 10 · no reliability rule triggered, so the score stands. See the rubric →
Every point, sourced
What earned the score.
Privacy
The fine print, read for you
Terms reviewed — no trapdoor found.
“Posteo does not save the IP addresses of its customers and dissociates payments from account data, as confirmed in an audit by the German Federal Commissioner for Data Protection.”
What it meansThis is the honest version of a privacy promise: an external regulator checked and confirmed there are no customer-linkable IP logs, and the payment system is built so a cash payment cannot be tied back to the mailbox. It is the structural opposite of a provider that logs metadata by default. The only caveat is that end-to-end mailbox encryption is opt-in, so enable it if you want the provider unable to read stored mail.
Read the source →None for identity. You can open a Posteo account with only a username and password - no name, phone or alternate email - and pay the EUR1/month fee anonymously in cash by post. There is no free tier, so payment is required, but the payment system is designed so it cannot be linked to the account. We rate it KYC level 1: identity-free in practice, one step short of a hard "never" guarantee.
Policy review — point by point
-
Audited no-IP-logging
The German federal data-protection regulator audited and confirmed Posteo stores no customer-identifiable IP addresses. ↗
-
Payment decoupled from account
Posteo built a payment system that dissociates payment (including anonymous cash) from account data. ↗
-
Encryption is opt-in
Zero-access mailbox encryption must be enabled by the user; it is not on by default. ↗
Posteo operates under German law, one of the strongest data-protection regimes, and has an externally audited no-IP-log posture. German providers can still be served valid German court orders for data they hold - but Posteo is structured to hold as little as possible, which is the point. Its own payment and transparency pages are the primary sources here.
We keep watching
Incident & policy timeline.
- 2009
Launched with an anonymous, payment-decoupled model
Posteo launched in Berlin offering identity-free signup and a payment system deliberately separated from account data, with cash-by-post accepted.
source ↗ - 2016
German data-protection regulator audit confirms no IP logging
An audit by the German Federal Commissioner for Data Protection confirmed Posteo does not store customer-identifiable IP addresses - independent verification of the no-logs claim rather than a marketing assertion.
source ↗
The verdict
Where it stands.
Strengths
- Identity-free signup (no name, phone or alternate email)
- Anonymous cash-by-post payment, decoupled from the account
- Independently audited no-IP-logging by the German DPA
- German jurisdiction with strong data-protection law
Trade-offs
- No free tier (EUR1/month) - payment always required
- Zero-access mailbox encryption is opt-in, not default
- Not fully open source
Across the internet
What reviewers report.
Consistently praised
- Genuinely anonymous signup and cash payment
- Independently audited no-logging
- Clean privacy track record since 2009
Recurring complaints
- No free tier
- Encryption not on by default
Posteo is consistently cited by privacy communities (Privacy Guides and others) as a top-tier private provider, praised for anonymous payment and audited no-logging. The main gripes are the lack of a free tier and opt-in encryption. Synthesized from privacy-community reviews and Posteo primary sources.
Keep exploring
Related lists & categories.
Ask the bureau
Posteo, common questions.
Is Posteo no-KYC?
Yes, on identity. You register with only a username and password - no name, phone or alternate email - and can pay anonymously in cash by post through a system built to keep payment separate from the account. There is no free tier, so a EUR1/month payment is required, but it cannot be linked to the mailbox. We rate it KYC level 1.
Does Posteo log my IP address?
No customer-identifiable IP logging - and this is not just a claim: the German Federal Commissioner for Data Protection audited Posteo and confirmed it. That external verification is why Posteo is our benchmark for the category.
Can Posteo read my email?
By default it can access stored mail on its servers, like most providers. Posteo offers opt-in mailbox encryption that stores inbound mail encrypted to your key - enable it if you want the provider unable to read your stored mail. Metadata and mail in transit follow the usual limits.
Your exact case not covered? The live Ask the bureau answers it and turns it into a public FAQ.