Mailfence Explained

Mailfence
Logo Alt:Logo of Mailfence
Commercial:Yes
Type:Webmail
Registration:Required
Language:English, Spanish, French, German, Dutch, Italian, Portuguese and Russian
Content License:Proprietary
Owner:ContactOffice Group
Current Status:Online

Mailfence is secure encrypted email service that offers OpenPGP based end-to-end encryption and digital signatures.[1] [2] It was launched in November 2013 by Belgium-based company ContactOffice Group that has been operating an online collaboration suite since 1999.[3]

History

Development

In the midst of 2013, the Mailfence project was started by the founders of ContactOffice.

In March 2016, a beta version of end-to-end encryption and digital signatures for emails was released.[4]

Mobile interface

In January 2021, Mailfence released progressive web application for mobile devices.[5]

Block in Russia

On 5 March 2020, Mailfence reported that their SMTP servers are blocked by Russian-based email services. This was in response to their refusal to submit a Notice of Commencement of Collaboration with Roskomnadzor's (the Federal Supervision Agency for Communications, Information Technology, and Mass Communication) of the Russian government. Mailfence did not respond to this request, citing obligation to provide information about users, violating its Terms and the federal Belgian laws.[6]

Features

Mailfence provides secure email features, with other functions such as Calendar, Contacts, Documents and Collaboration.[7]

Mailfence Email

The service supports POP/IMAP and Exchange ActiveSync[8] as well as vanity domains with SPF, DKIM, DMARC[9] and catch-all address support.[10] Users can send both plain and rich text emails, organize messages in folders and/or categorize them with tags, take notes by setting comment on each message and create default message signatures for every sender address. Different identities can also be managed using aliases and filters for incoming emails.

The email application is based on the ContactOffice collaboration suite that supports POP/IMAP and Exchange ActiveSync as well as vanity domains with SPF, DKIM, DMARC and catch-all address support.  It was enriched with security and privacy features in 2016 at the launch of the Mailfence service with features: managing access or generating specific password for web and non-web services, two-factor authentication, spam protection alongside of plus addressing, sender address blacklist and whitelist,

Mailfence Contacts

The contacts support (CSV, vCard, LDIF) import, (vCard, PDF) export and can be accessed using CardDAV.[11] Users may organize them with tags and can also create contact lists.

Mailfence Calendar

The calendar supports vCal/iCal import, export and can be accessed by using CalDAV.[12] Users can share their calendars with group members and can also create polls.[13]

Mailfence Documents

The documents can be accessed using WebDAV or edited online. Users can drag and drop files in folders, categorize them with tags take notes by setting comment on each file.[14]

Mailfence Groups

Groups allow users to share mailboxes, documents, contacts, calendars and perform instant chatting with group members in a secure way. A group administrator manages the access rights of group members and can also set another group member as co-admin or the main admin of the group.[15]

Mailfence Polls

Mailfence Polls is a meeting scheduler that claims to be secure and private.

Mailfence Chat

Jabber/XMPP protocol is the base of Mailfence chat functionality. First named Jabber, then XMPP (Extensible Messaging and Presence Protocol), this open-source protocol has been created for instant messaging.

Web-based clients

The web-interface comes with an embedded IMAP, POP3, CalDAV, and WebDAV client. Users can add external accounts and manage them centrally in the web-interface.[16] [17]

User management

Account owners can create and manage user accounts using the admin console.[18]

Server location

Since their servers are located in Belgium,[19] they are legally outside of US jurisdiction. Mailfence is therefore not subjected to US gag orders and NSLs, notwithstanding extradition treaties with the US.[20] [21] Under Belgian law, all national and international surveillance requests must go through a Belgian court.[22]

Security and privacy

Mailfence claims to be secure and private on their website,[23] offering most conventional security and privacy features, but they also claim to support some less-common privacy and security enhancing features:

Transport security

Like most major e-mail services, the service claims to use TLS with ephemeral key exchange to encrypt all internet traffic between users and Mailfence servers. HSTS, MTA-STS and DANE standards are also supported.[24] [25] [26]

End-to-end encryption

The service uses an open-source implementation of OpenPGP (RFC 4880) for emails. OpenPGP keypair is generated in client-browser, encrypted (via AES256) with the user's passphrase, and then stored on Mailfence server. Since December 2018, the service also supports end-to-end encryption for emails using a shared password.[27]

OpenPGP signatures

The service gives the choice between "signing", or "signing and encrypting" an email message with or without attachments.[28]

Integrated Keystore

Since its launch in 2017, the service provides an integrated keystore to manage OpenPGP keys,.[29] OpenPGP keypairs can be generated, imported or exported.[30] Public keys of other users can be imported through file or in-line text. Mailfence also supports Web Key Directory besides key discovery via Public key servers.[31] [32]

Full OpenPGP interoperability

Users can communicate with any OpenPGP compatible service provider.[33]

Warrant Canary and Transparency Report

The service maintains an up-to-date transparency report and warrant canary.[34] [35]

Reception

In an article Kim Komando of Fox News wrote about Mailfence, "It's a great option for small business owners and ordinary users alike."[36] Lifehacker wrote, "Mailfence is a solid choice with office apps, it's more email- and calendar-focused compared to the comprehensive app suite of Kolab Now."[37] The ProPrivacy's Ray Walsh mentions in his article “Mailfence is a solid and easy-to-use email provider that is ideal for beginners."[38] Restore privacy's Sven Taylor wrote, “Mailfence has all the features and options that you are likely to need, whether you are looking to manage the mail for an entire organization, or just want great service for personal use”[39] Lifewire writes in a review of five encrypted email providers: “Mailfence is a security-centric email service that features end-to-end encryption to ensure nobody but you and your intended recipient can read your messages."[40] In an open guide about secure emails, maintained by Open Technology Fund appreciates Mailfence by saying:  "The project came into existence after snowden revelations and holds a strong online privacy-oriented philosophy."

See also

Notes and References

  1. Web site: Johnson . Dave . The 7 best secure email providers . 2024-04-07 . Business Insider . en-US.
  2. Web site: The 5 Best Secure Email Services for 2024 . 2024-04-07 . Lifewire . en.
  3. Web site: 29 December 2016 . ContactOffice launch and users .
  4. Web site: BETA launch of a pure end-to-end encrypted email solution that gives you full control. 10 March 2016 . 25 May 2016.
  5. Web site: Mailfence mobile app goes out of beta. 14 January 2021 . 14 January 2021.
  6. Web site: Mailfence email servers blocked in Russia. 5 March 2020 . 5 March 2020.
  7. Web site: Leonard. John. Escape from Yahoo: Nine encrypted email alternatives. 11 October 2016.
  8. Web site: Skjefstad. Vegard. Secure and Private E-mail: A Provider Overview.. 1 August 2015. 21 September 2015. https://web.archive.org/web/20150921160401/https://www.vegard.net/archives/11906/. dead.
  9. Web site: Spoofing defense for Custom domains: SPF, DKIM, DMARC. 8 January 2018 . 8 January 2018.
  10. Web site: Mailfence Release Notes Dec 2017.. 5 December 2017 . 5 December 2017.
  11. Web site: Mailfence Contacts: a secure contact management software. 28 February 2018 . 27 June 2018.
  12. Web site: Mailfence Calendar: a secure online calendar to schedule, manage and track meetings & events. 31 October 2017 . 9 March 2018.
  13. Web site: Mailfence Polls: simple and secure meeting scheduler. 28 November 2017 . 28 November 2017.
  14. Web site: Mailfence Documents: secure file sharing, storage and collaboration. 9 November 2017 . 9 November 2017.
  15. Web site: Mailfence Groups: secure group collaboration. 5 September 2017 . 5 September 2017.
  16. Web site: How to encrypt email with Gmail and Outlook.com or any other provider. 11 October 2017.
  17. Web site: POP3 vs IMAP vs Exchange ActiveSync. What's the difference?. 22 September 2017.
  18. Web site: Manage your users with the mailfence admin console. 21 March 2019 . 21 March 2019.
  19. Web site: The Mailfence SSL/TLS Certificate. 10 June 2016 . 10 June 2016.
  20. Web site: United States Extradition Treaty with Belgium.
  21. Web site: United States Supplemental Extradition Treaty with Belgium.
  22. Web site: Mailfence privacy policy. 12 November 2013. dead. https://web.archive.org/web/20140718012716/http://www.mailfence.com/c/mailfence/more/privacy.jsp. 18 July 2014. dmy-all.
  23. Web site: Mailfence . Secure and private email Mailfence encrypted email service . 2024-03-19 . Mailfence . en.
  24. Web site: SSL Report: mailfence.com. 10 June 2016. Qualys SSL Labs. 14 Jan 2021.
  25. Web site: MTA-STS validator - Mail Hardener tools. 27 July 2022.
  26. Web site: DANE SMTP Validator. 14 January 2021.
  27. Web site: 2024-01-22 . Email Encryption . 2024-04-07 . OpenPGP . en.
  28. Web site: Thomas. Mike. A (mostly) In Depth Review of Mailfence. 1 September 2016. https://web.archive.org/web/20161220161728/https://www.disobeyers.com/2016/09/01/in-depth-review-mailfence/. 20 December 2016. dead.
  29. Web site: Schürmann. Dominik. OpenPGP Email encryption. For all operating systems. Standing the test of time.. 1 September 2016.
  30. Web site: Tschabitscher. Heinz. Encrypted email services keep your messages private. 3 June 2018.
  31. Web site: Mailfence's OpenPGP keystore gives full control over key management. 17 May 2017 . 17 May 2017.
  32. Web site: Mailfence keeps on improving security for its users. 22 December 2021 . 22 December 2021.
  33. Web site: Encrypted email service providers. v. 25 May 2016. dead. https://web.archive.org/web/20160518094904/http://www.emailquestions.com/encrypted-email-service-providers/. 18 May 2016. dmy-all.
  34. Web site: Transparency Report and Warrant Canary. 29 April 2016 . 29 April 2016.
  35. Web site: Service review. 20 February 2019.
  36. Web site: 2020-05-13 . Sick of being tracked? Use these Google alternatives . 2024-04-07 . The Kim Komando Show . en-US.
  37. Web site: Hesse . Brendan . 2018-11-08 . The Comprehensive Guide to Quitting Google . 2024-04-07 . Lifehacker . en.
  38. Web site: Mailfence Review 2024 Test Results - Worth the Price? . 2024-04-07 . RestorePrivacy . en-US.
  39. Web site: Mailfence Review 2024 Test Results - Worth the Price? . 2024-04-07 . RestorePrivacy . en-US.
  40. Web site: The 5 Best Secure Email Services for 2024 . 2024-04-07 . Lifewire . en.