Most comparisons rank providers on encryption features that all of them now have. The things that actually differ are jurisdiction, what metadata is retained, whether aliases are included, and how easily you can leave. That last one gets almost no attention and matters most over a decade โ because switching provider costs you nothing if your addresses are on your own domain, and costs you a re-addressing project if they aren't.
The axis nobody compares on
Encryption at rest, TLS in transit, and some form of zero-access storage are close to table stakes among privacy-focused providers now. Comparing on them mostly produces a list of ticks.
Four things genuinely separate providers:
1. Jurisdiction
Where the company is incorporated and where the servers sit determines which legal processes can compel disclosure, and what a company must do when served. Worth understanding rather than treating as marketing โ but also worth keeping in proportion: for most people this matters less than it's presented to.
2. Metadata retention
Contents may be encrypted; who mailed whom, when, and with what subject line often isn't. Metadata is frequently more revealing than content, and retention policies vary far more between providers than encryption does. This is the question worth asking directly.
3. Whether aliases are included
The practical differentiator for most people, because it's the feature that addresses the problem they actually have. A provider bundling unlimited aliases with custom domain support is solving something an encrypted mailbox alone doesn't touch. Why these are different problems
4. Exit cost
If your addresses are @provider.com, leaving means re-addressing every account you own. If they're on a domain you control, leaving is a DNS change. Nothing else on this list compounds the way this does. The trade-off
Why we're not ranking them
Ranking providers on privacy means assessing claims about internal practice โ what's retained, what's logged, what happens under legal process. Those are largely unverifiable from outside without an audit, and repeating each vendor's own claims as though they were findings would be dressing up marketing as research.
What we can do is tell you which questions produce a meaningful answer, which is what this article is. Where we do quote figures โ pricing, alias limits โ they come from the provider's own current pages with a check date. The alias comparison, where the facts are checkable
The questions to ask
- What metadata do you retain, and for how long?
- What's your process when served with a legal demand, and do you publish a transparency report?
- Can I use my own domain, and on what plan?
- Are aliases included, how many, and can they use my domain?
- What happens to my data if I stop paying?
- Can I export everything in a standard format?
Answers to 3, 4 and 6 are checkable from the outside. Answers to 1, 2 and 5 you're taking largely on trust โ which is itself informative, since some providers answer specifically and others don't.
The pragmatic position
For most people, the provider matters less than the two layers around it: which address each organisation gets, and what you disclose alongside it. You can run those on any provider, including the one you already use, and they address the problem people usually mean when they say they want private email.
If message contents genuinely are your concern, then provider choice matters and the questions above are the ones to ask. How the layers fit together