# Mullvad Using Gmail

**URL:** https://discuss.privacyguides.net/t/mullvad-using-gmail/16258
**Category:** Site Development
**Tags:** rejected
**Created:** 2024-01-15T22:07:56Z
**Posts:** 46

## Post 1 by @HardenedSteel — 2024-01-15T22:07:56Z

There’s full text on Nostr: [SimplifiedPrivacy.com](https://primal.net/e/note1hekrtdrtnfk40xuktjaw8y06um9eyf6seh7gckae0aqcddmnc8qsyhxmsn)

Mullvad using gmail for their email, my points are:

- Google has access to all Mullvad’s emails and their customers’ information.
- Even they’re encrypted Google can [Harvest now, decrypt later](https://en.wikipedia.org/wiki/Harvest_now,_decrypt_later).
- 
  - Which also means they’re indirectly lying about no logs policy.

- Even someone never e-mails the Mullvad its ridiculous a privacy company using gmail, they can just self host or use better e-mail services.

would like to hear other opinions and correct me if I am wrong.

---

## Post 2 by @exaCORE — 2024-01-15T22:17:09Z

Hmmm… I dont know what the implications are for this, but they probably use Enterprise Gmail which might have better privacy guarantees (I’m not sure however if this is the case)???

---

## Post 3 by @Satoshi — 2024-01-15T22:26:46Z

It’s not great that they’re using gmail, but according to one of the users on primal they said they are working on their own email server. If this is true and not just hearsay, I’m willing to give them a pass on it given they don’t require an email address for registration to begin with and you can just use PGP with an email address specifically created for the Mullvad account, e.g. [Cock.li](https://cock.li) (Tor: [http://rurcblzhmdk22kttfkel2zduhyu3r6to7knyc7wiorzrx5gw4c3lftad.onion/](http://rurcblzhmdk22kttfkel2zduhyu3r6to7knyc7wiorzrx5gw4c3lftad.onion/)) or [Cyberfear](https://cyberfear.com) (Tor: [http://cyberfe3gvh7cvq2nhuqtaghjxebhcnqafnfvalwvq6mxrinep7m7xqd.onion/](http://cyberfe3gvh7cvq2nhuqtaghjxebhcnqafnfvalwvq6mxrinep7m7xqd.onion/)).

As long as they abide by their VPN no-log policy and provide a good VPN service, that’s all I really care about. You should always browse the web as if you are being watched, especially if you are using a VPN, but I like a VPN provider that isn’t really in the picture. I don’t want to constantly think about the fact that I’m using a VPN and I just want it to work as intended.

Overall, this is a nothing burger for the most part.

---

## Post 4 by @HardenedSteel — 2024-01-15T22:30:30Z

Mullvad’s customer support response:

> Currently our email is being hosted on Gmail this is correct.  
> We are working on a self-hosted version based on our STBOOT (  
> [Mullvad VPN | Privacy is a universal right](https://mullvad.net/en/blog/tag/system-transparency) ) project.  
> It’s in the final phase and being tested internally and the goal is to  
> move over email to this platform this year if the testing phase is going  
> smoothly.
> 
> We strongly suggest using pgp regardless of what email server is being  
> used, as any other means is basically unencrypted and not considered safe.

---

## Post 5 by @wojciechxtx — 2024-01-15T22:45:35Z

Another provider that wannabe taken seriously, but is caught lying.

---

## Post 6 by @overdrawn98901 — 2024-01-15T23:40:02Z

> [@Satoshi](#):
>
> It’s not great that they’re using gmail, but according to one of the users on primal they said they are working on their own email server. If this is true and not just hearsay, I’m willing to give them a pass on it…

I’d agree. At the end of the day, Mullvad is a business, and running their own hosted e-mail server was probably not at their highest priority. Truth be told, I can’t imagine many business would even consider owning their own e-mail server in this day in age, so the fact that Mullvad is migrating to their own server (if they follow through) is at least some level of commitment to privacy. I think they likely omitted this fact as it clearly isn’t optimal, and its not particularly great it wasn’t more publicly disclosed, but pick and choose battles I suppose.

Not trying to be super pro Mullvad, but if anyone’s threat model is to be penetrated by sending an encrypted support e-mail to Mullvad that is hosted on a Gmail server, I just think there are bigger fish to fry.

---

## Post 7 by @anon73250778 — 2024-01-16T04:46:58Z

I think using enterprise gmail isnt necessarily a bad thing.

I dont think they’ll be sending messages containing keys and personally identifying info?

I think its a responsible thing to do if you are not completely competent to do email yourself. I think its only fair because Mullvad never claimed theyre an email company.

---

## Post 8 by @jonah — 2024-01-16T04:57:57Z

This is an interesting point. We don’t really evaluate much outside the VPN product itself when evaluating VPN providers, but maybe we should look at and factor in things like this?

Using Google Workspace is obviously pretty questionable :thinking:

On the other hand, this isn’t something a customer would _have_ to interact with.

---

## Post 9 by @abstract — 2024-01-16T09:50:26Z

That social media post is so gaslighting I have a hard time taking it seriously, even though it is pointing out a simple fact. The reality is that most people are not using privacy-preserving email services, and are most likely communicating with Mullvad support using a Gmail address anyway. Yes, it’s not a good lookout for Mullvad, but as a customer I am personally satisfied with their reply.

---

## Post 10 by @anon29374801 — 2024-01-16T14:16:23Z

This is silly, PG already has decently strict criteria on what can even be considered for recommendations when it comes to VPNs. PG would look ridiculous not recommending Mullvad over something like this.

What would be the point of audits as a criteria, if they can still be removed due to their email provider?

---

## Post 11 by @anon85295620 — 2024-01-16T15:02:34Z

When I check [Mullvad VPN - Free the internet](https://mullvad.net/en) I see [support@mullvad.net](mailto:support@mullvad.net)

---

## Post 12 by @anon21489307 — 2024-01-16T15:08:51Z

> [@anon85295620](#):
>
> I see [support@mullvad.net](mailto:support@mullvad.net)

It seems the domain is registered in Google Workspace email, thus used Gmail to operate.

---

## Post 13 by @anon85295620 — 2024-01-16T15:13:34Z

Doesn’t look like it to me.

> **[Whois mullvad.net](https://www.whois.com/whois/mullvad.net)**
>
> Whois Lookup for mullvad.net

---

## Post 14 by @anon21489307 — 2024-01-16T15:40:47Z

The domain can be purchased from any provider, anyone can register the domain in Google Workspace as a business email, which will be using Gmail to operate.

See: [What is Google Workspace & Other FAQs | Google Workspace](https://workspace.google.com/faq/)

 ![Screenshot](//forum-uploads.privacyguidesusercontent.com/original/2X/b/b4551819949e657c0955e729d37cd3e974ef99cb.jpeg)

---

## Post 15 by @exaCORE — 2024-01-16T17:25:27Z

Many email providers provide an option to use a custom domain name. It helps with portability (switching services is easy because your email doesn’t change). This feature is also one that PG requires that recommended email providers have.

---

## Post 16 by @anon80779245 — 2024-01-17T06:43:34Z

The original post is **misleading** at best. They assert that the **government can identify you** based on this. The author lies by saying customer service will ask for account number and then the gov can see your IP by loging as you and hijacking Wireguard to see your ip or something like that . Mullvad support will not ask account number - except if you ask for a refund, in which case you will not use the service anymore. Furthermore anyone which a high threat model will not e-mail their VPN provider because that put them in a niche position, regardless of wheter the mail is private or not.

That being said, I did ask them why they wouldn’t swicth to something like Session and they say the mail workflow is more convenient. I overall which Mail was dumped for customers services, but it is still the most widely used communication. Every single country use mail.

I also think they should have been more transparent about this, but it remains overall a low key concern.

---

## Post 17 by @anon86552080 — 2024-01-17T08:03:00Z

That is indeed interesting, but as long as you don’t send them any emails there shouldn’t be a problem.  
If you really have to send them an email use an email alias, pay for it every month separately and replace your account from time to time.

---

## Post 18 by @PrivacyAintReal — 2024-01-17T10:02:36Z

Google enterprise != free gmail

Is everyone here IT resistant?

---

## Post 19 by @ph00lt0 — 2024-01-17T11:09:32Z

Well I obviously agree with this. Proton uses Zendesk, I am not sure if that is any better than Google Workspace.

---

## Post 20 by @wojciechxtx — 2024-01-17T11:31:47Z

> [@PrivacyAintReal](#):
>
> Is everyone here IT resistant?

what do you mnean by this?

---

## Post 21 by @dngray — 2024-01-17T13:01:33Z

From what I’ve seen that Simplified Privacy spams a lot, in fact I’ve deleted a few of their posts on our lemmy sub because they were prolific with the blogspam posts.

There isn’t really anything extraordinary about using Google Workspaces, it’s not GMail and has a entirely [different privacy policy](https://cloud.google.com/privacy) to [gmail](https://support.google.com/mail/answer/10434152?hl=en). Neither product “scan” your emails to serve you advertising.

Proton uses Zendesk for their support, and that isn’t E2EE. These emails are likely not used for anything particularly sensitive.

There are totally legitimate reasons for businesses to use Workspace, or MS 365 (like the ones we recommend), as there are fine grained access control options that “privacy providers” simply do not have.

In particular PGP encryption per mailbox, would be completely inappropriate in an organization where a manager might need to review what employees have been saying to customers, ie things like [Google Vault](https://workspace.google.com/products/vault/). Another reason would be transfer of data when an employee leaves, or if they are fired etc.

> [@HardenedSteel](#):
>
> Which also means they’re indirectly lying about no logs policy.

That in itself is completely untrue, the logging policy relates to logging of what you’re browsing over the VPN, not if you’re asking support for help with payment processing, or to get connected or whatever.

> [@anon85295620](#):
>
> Doesn’t look like it to me.

That doesn’t prove anything, it’s just a whois record for the domain.

In this case they’re talking about the MX (Mail Exchange) records for the [mullvad.net](http://mullvad.net) domain which indeed are the ones used with workspace.

TLDR: nothing to worry about, this is just more degoogling nonsense. If they were using salesforce or some other platform nobody would bat an eye lid. (Like proton doesn’t get strife for using Zendesk) or some other SaSS platform.

---

## Post 22 by @anon36658780 — 2024-01-17T15:52:23Z

I don’t think they are lying you could always make an MX lookup to see what provider they used. Some of privacy services use Gmail because it’s the best product for managing business email.  
But I still think they of course should have used their own email servers.

---

## Post 23 by @dngray — 2024-01-17T15:54:10Z

> [@anon36658780](#):
>
> But I still think they of course should have used their own email servers.

Which in practice means they’d have to charge more, to manage, that, also if you want high availability, it makes sense to just use Google for this. Self hosting would not provide all of the infrastructure around management around it, so they’d need to find a product to do that as well.

---

## Post 25 by @dngray — 2024-01-17T17:21:50Z

There is really no way to know, they could just have proxy in front.

---

## Post 26 by @whoami4 — 2024-01-19T09:26:38Z

I think Proton has email solution for businesses, but I also kinda understand that they (Mullvad) doesn’t want to be seen using services of their competition (even if its a little bit different space - vpns). But it is a pity that they have to compete so hard.  
Maybe Mullvad is even preparing its own private email service. Who knows.

---

## Post 27 by @anon32876053 — 2024-01-19T10:54:34Z

Individuals who advocate for Gmail must comprehend that Google is primarily an advertising company, and the rest of the business revolves around the advertising business. Using their services or any degree/part there of, is handing over a fist full of data to this company, you become part of the marketing product. Make no mistake that this is their main purposes, Apple is now doing a similar thing, ad revenues are skyrocketing.

---

## Post 28 by @Bhaelros — 2024-01-20T22:49:38Z

Mullvad is using Google Workspace, aimed to businesses, which has totally different architecture, security and privacy policies compared to Google Mail, which is a personal product. There are lots of privacy laws in place, forced by many governments and agencies, checked frequently and audited, and also used by a lot of companies.

Please educate yourselfs before attacking companies with torches and pitchforks.

> **[Trust Center - Security and Compliance](https://cloud.google.com/trust-center)**
>
> Get the latest information on Google Cloud's security, privacy, compliance, and operational health at our Trust Center.

> **[How Google protects your data - Google Workspace](https://workspace.google.com/intl/en_us/learn-more/security/security-whitepaper/page-1/)**
>
> Learn more about Google’s approach to security and compliance for Google Workspace, our cloud-based productivity suite

---

## Post 29 by @dngray — 2024-01-21T05:37:11Z

> [@whoami4](#):
>
> has email solution for businesses

It doesn’t compete with Google, nor does it offer anywhere near the functionality required. In part this can largely be because it is difficult if not impossible to implement with E2EE. A manager should always be able to see email on the company server. Google Workspace also has a wide variety of other routing rule options, ability to have your own DKIM keys (not protons) etc.

**TLDR: Workspace is not gmail**

> [@anon32876053](#):
>
> Individuals who advocate for Gmail must comprehend that Google is primarily an advertising company, and the rest of the business revolves around the advertising business

None of the rest of your post makes any sense, GCP is very clearly a different policy to consumer products. The reality is companies like Google and Microsoft have a very large array of products and services aimed at different audiences, and as such they have different goals.

---

## Post 30 by @anon89321548 — 2024-02-08T10:30:50Z

Mullvad blog:

> Our support emails are now moving to self-hosted and Mullvad-owned hardware.

> From now on, our Support Team can be reached at a **new email address** : [support@mullvadvpn.net](mailto:support@mullvadvpn.net)

> Emails sent to the **old address:** [support@mullvad.net](mailto:support@mullvad.net), will still continue to function until we announce the shut-down of that email address.

> **[We now self-host our support email | Mullvad VPN](https://mullvad.net/en/blog/2024/2/8/we-now-self-host-our-support-email)**
>
> Our support emails are now moving to self-hosted and Mullvad-owned hardware.

---

## Post 31 by @anonymous127 — 2024-02-08T12:43:31Z

This seems a bit fast… I hope they didn’t rush this out because of the backlash

---

## Post 32 by @anon29374801 — 2024-02-08T13:32:18Z

> [@anonymous127](#):
>
> This seems a bit fast… I hope they didn’t rush this out because of the backlash

In the blog they say their email server was audited pre-production which is probably a good sign that they did not rush it.

---

## Post 33 by @abstract — 2024-02-08T19:09:41Z

Let us hope this is a solution that is deemed stable in the future. And not so costly as to having to raise their prices to an uncomfortable level.

---

## Post 34 by @FlipSid — 2024-02-09T05:28:23Z

Honestly I have enough to worry about thinking about what I am doing online and what services I am using.  
Expanding it to what the service I am using is doing online and what services the service is using that I am using :wink: (my opinion) is just pure brainfu.k.  
Might aswell stay off the internet all together then.

Aviods all possible problems.

---

## Post 35 by @dngray — 2024-02-09T12:32:33Z

> [@anon89321548](#):
>
> Mullvad blog:

No doubt they did this to get ahead of some other VPN company using it as adversarial marketing material to an overly paranoid clientele that generally doesn’t understand the concept of a threat model.

TLDR it’s Mullvad’s attempt to get ahead of an already nothing burger.

---

## Post 36 by @anon89321548 — 2024-02-09T12:38:40Z

Eh. I applaud the change. Glad to see it and was surprised when the news came out.

---

## Post 37 by @anon80779245 — 2024-02-10T08:50:52Z

When the simplified privacy piece came out, someone in the comment reached out to Mullvad and they already said that were testing their new in-house email service

---

## Post 38 by @wojciechxtx — 2024-02-10T22:51:24Z

> [@FlipSid](#):
>
> Might aswell stay off the internet all together then.

Yeah, good luck with this :slight_smile:

Truth is that, in modern times, you, sooner or later, will connect/be connected to internet one way or the other. This is unavoidable.

---

## Post 39 by @FlipSid — 2024-02-11T18:42:53Z

Irony my friend, very much of irony :slight_smile:  
I was getting at something else:  
If one (which is not me) will worry about what services the specific service he wants to use uses (in this case Mullvad), maby just stay off the internet. (Sarcasm as well)  
No offence in this statement at all to anyone its just that:  
The internet is a place where one in short has fun and productivity.  
Don’t take it to the paranoid level :slight_smile:  
Do what you can and then use it.

---

## Post 40 by @Stiffly2505 — 2024-02-11T18:55:24Z

> None of the rest of your post makes any sense, GCP is very clearly a different policy to consumer products. The reality is companies like Google and Microsoft have a very large array of products and services aimed at different audiences, and as such they have different goals.

Reminded me of how Microsoft has its clone of Azure for the US government. Don’t… live in the US I guess? I mean that’s a pretty solid advice, but certainly not for the Microsoft reason.

---

## Post 41 by @dngray — 2024-02-11T19:16:10Z

> [@Stiffly2505](#):
>
> Azure for the US government

These are mostly [compliance things](https://learn.microsoft.com/en-us/azure/azure-government/documentation-government-overview-dod) and this agreement would also cost a lot of money. A support address for a VPN provider is mostly going to be dealing with people who are having trouble with getting connected, or asking about billing queries perhaps.

In any case Mullvad has always had a PGP key.

---

## Post 42 by @jonah — 2024-02-12T06:10:37Z

Marking as #rejected, since we are not making any changes to the site as a result of this.

---

## Post 43 by @aspirin6993 — 2024-02-12T06:49:55Z

My 2 cents.

- Email is an inherently insecure mode of communication and it is expected that a privacy conscious person would know that.
- You can just use PGP to become platform agnostic w.r.t security for email.
- Finally - You do not need to email Mullvad to use their service so it’s not really a security concern.

---

## Post 44 by @ph00lt0 — 2024-02-12T19:56:17Z

> **[We now self-host our support email | Mullvad VPN](https://mullvad.net/en/blog/we-now-self-host-our-support-email)**
>
> Our support emails are now moving to self-hosted and Mullvad-owned hardware.

Seems they actually listened also and the issue has been solved.

---

## Post 45 by @Tuta_Official — 2024-02-20T11:22:39Z

While we can’t be exactly sure what kind of account the team is using, it is worth noting that [Google did introduce end-to-end encryption](https://tuta.com/blog/posts/gmail-end-to-end-encryption-is-dead) for _some_ Google Workspace key users. Again, we don’t know if this is the case for them or not, but it is worth acknowledging.

It would be great to see them drop Google.

---

## Post 46 by @ph00lt0 — 2024-02-20T16:40:59Z

Off topic and irrelevant. GSE would not be e2ee in any way for people who reach out to mullvad given they aren’t Google workspace users.  
And again, they already ditched google…
