Remove Mailbox.org

I don’t know the answer to this, but separately it’s worth noting that they’ve begun to roll out a more normal two-factor authentication (2FA), which I’m looking forward to.

Idk how relevant this is to this thread, but mailbox.org is also used by the German Federal Criminal Police Office or “Bundeskriminalamt” using their mail-Services.

This may indicate positive or negative thoughts - depends on how you see it.

Yes. Make an MX lookup for cyber.bka[.]de .
They may not only use mailbox.org as a provider tho. They also gave other urls as mail addresses such as bka.bund[.]de .

So this basically means that if I use mailbox.org I can have an email arriving in my inbox where the sender is listed as apple.com but in reality it’s not with no warning whatsoever?

And if you were tempted to tinker with the spam protection level, they say:

Whenever an e-mail has been flagged as spam by our systems, it will be rejected. That means our server will deny accepting the e-mail message and the system at the other end (the client) will issue a delivery failure notice to the sender (the message „bounces“).

Source

I understand their point about false positives but that’s why the spam folder exists…

Or at least display a warning in the interface.

Do these issues still apply? Without proper anti-spoofing, nothing else matters.

No, this is not possible (anymore), see here:

The only issue is them not respecting DMARC and SPF fully, but as I was never hit with spam mails in all these years it seems to me neglectable.

also the stuff about their 2FA implementation is no longer relevant.

I was looking at them to De-Google a year ago and their lack of real 2FA and questionable custom domain issues were a dealbreaker. I just can’t believe it took them SO long to implement normal 2FA. April of 2025? It was “in testing and almost roll out” last summer IIRC.

It was a whole SSO solution, and tbh it’s not unsurprising that they wanted to test that thoroughly before making it generally available.

I didn’t have any issues during beta, so yeah.

I’m hoping the next bunch of tests will be something like google’s XOAuth, allowing for FIDO2/TOTP auth on IMAP. A proper SSO solution was needed first though no doubt.

This blog post caught my eye because it seems contrary to much of the security concerns shared in this post. It is hard for me to understand the scope of impact of the concerns shared here.

They only seem to check if there’s a valid DMARC policy but not if it’s enabled, because Posteo also got gold status and it doesn’t even have a strict DMARC. Unless the policy is set to reject or quarantine it’s useless.

Why should this tool be removed?

Mailbox.org has several security issues and should be considered for removal as it is advertised to be a secure mailbox solution.

Issues:

  • Mailbox announced that the user now has the option to deactivate the password reset (and 2FA reset) via IMAP. However, the default setting is that a reset via IMAP is enabled and will reset the password and 2FA. Based on the Support it will stay that way
  • They don‘t have any security notification or dashboard where you can see sessions, failed logins, recent actions like password changes. No notification when 2FA was activated, when password was changed, when IMAP password has been created etc. unlike Tuta, Fastmail, Proton, etc.
  • No OAuth or YubiKey support for 2FA
  • No recovery codes possible for 2FA TOTP
  • No SPAM/Rejection-Log
  • Increase of vulnerabilities and minimal response provided by Mailbox team
  • No roadmap or timeline to implement anti-spoofing for custom domains

Related Thread:
https://discuss.privacyguides.net/t/mailbox-org-with-severe-authentication-vulnerability-through-password-reset/31846/16

Refreshing this post I made in the other thread:

I’ve also been dissatisfied with Mailbox for the reasons you’ve listed but I’m still on Mailbox because I’m not aware of any other privacy-friendly email provider that:

  • Is reputable / not brand new

  • Supports IMAP in some form

  • Supports CardDAV (or otherwise syncs with phone contacts)

  • Supports custom domains

Tuta, Proton, and Posteo all fail at least one of the above. Mailfence made a topic a few months ago but then disappeared when asked for specifics on their privacy claims. IMAP is the only one I could possibly flex on, but Proton and Tuta don’t support CardDAV so it’s a moot point anyways.

If we remove Mailbox (which I’d be okay with) we need to figure out what the next best option is. Proton, Tuta, and Posteo are great but are not ‘plug and play’ for many general use cases due to missing at least one of the common, widely used, often necessary features listed above.

Mailbox announced that the user now has the option to deactivate the password reset (and 2FA reset) via IMAP. However, the default setting is that a reset via IMAP is enabled and will reset the password and 2FA. Based on the Support it will stay that way

So the user can still use 2FA if they want.

Far behind competitors regarding features

Cry about it. Not a good reason to remove mailbox.

They don‘t have any security notification or dashboard where you can see sessions, failed logins, recent actions like password changes. No notification when 2FA was activated, when password was changed, when IMAP password has been created etc. unlike Tuta, Fastmail, Proton, etc.

You can view which devices are logged in in the dashboard settings.

No OAuth or YubiKey support for 2FA
No recovery codes possible for 2FA 

Not really anti-privacy features.

No SPAM/Rejection-Log

Not really an anti-privacy feature so moot point.

Increase of vulnerabilities and minimal response provided by Mailbox team
No roadmap or timeline to implement anti-spoofing for custom domains

I believe the anti-spoofing is handled by the domain host with dmarc records. There are a series of records one needs to add and if you don’t know the process, then one shouldn’t be messing with a custom domain. Also, a custom domain is not private at all. I thought this was a privacy forum?

So far you’ve just whined about their security measures. What about Proton requiring a backup email which has been used in one instance by the authorities to break into a user’s mailbox (user used a gmail)?

Mailbox is still the best email provider that supports third party email clients. Proton still doesn’t have a linux app. No carddav or caldav. For all these reasons, Mailbox is the best in its class. If one wants to commit crimes, then yeah use Proton. But how many people in your inner circle use Proton? Its like the same debate on whether to use Signal. If you’re sending emails to other gmail users you’re not getting much benefit from Proton. If you’re not emailing other proton users, you’re not getting that e2ee anyways. Still, Mailbox is the best for the average user.

I would like to remind folks of PrivacyGuides’ goal to find a “balance of privacy, security, and convenience” when it comes to recommended tools.

Mailbox.org and services like Proton Mail serve two different types of users. I agree with you on how my concerns are security related (although the “whining” is a bit immature to assume) rather than privacy related. I believe an argument could be made either way based on the facts.

  1. Prioritizing Open Standards & Privacy: As person looking for a private, non-advertising email provider and with open standards, Mailbox.org is one of the best in this specific class.

  2. Prioritizing Maximum Security: A person looking for end-to-end encryption (E2EE) and the most robust, phishing-resistant security, and is willing to sacrifice convenience and open protocols to get it, should choose a service like Proton.

I myself fall into the later group and prefer to have stronger security over privacy. Ideally it is not an either or, but a both focused on security. Finding the sweet spot has been an enduring effort for me and I have been a Mailbox.org user for a couple of years now. I continue to strive to find that sweet spot product and it is one of the reasons I moved away from Proton and over to Mailbox. I believe we could do better or lobby the providers more to achieve these goals.

At a minimum the PrivacyGuides listing for Mailbox.org should be updated to clearly feature these caveats so the user could make their own educated decision:

  • Security Weakness: “Lacks support for hardware-based 2FA (U2F/YubiKey). Only TOTP (authenticator apps) is supported.”

  • Security Weakness: “Enables password reset via IMAP by default. Users must manually disable this feature in their security settings for proper account protection.”

References:

The other two PG-recommended email providers (Proton & Tuta) don’t even have IMAP, so if anything it’s the opposite.

Proton does

Great, then lets hear what features they offer despite the ONE point you made. No Apps, No Push notifications, No Spam logs, No Yubikey Support, No Recovery Codes, and the list goes on…

>No Apps, No Push notifications,

Usecase? Just use any email client

>No Spam logs,

Not sure what you mean but it seems that you can change a setting so that it doesn’t reject spam mails but puts them in a spam folder instead

>No Yubikey Support, No Recovery Codes,

TOTP is good enough for most people

Curious if you belong to mailbox or if you are just an ultra-fanboy that doesn‘t allow any critisism of his favorite service. But alright lets go into detail:

„So the user can still use 2FA if they want“

Yes, but the big problem is that they only backpaddled after some users made posts and critized this feature heavily. It was not by mistake, instead the mailbox team decided on purpose that its ok to bypass 2FA with an IMAP Application password.

„Cry about it. Not a good reason to remove mailbox“

Lol what an attitude. The fact that they are far behind the other competitors is of course not the only reason to remove the service but instead the cherry on top why it should be removed. If they would offer any meaningful advantage over the competitors or even be on-par with them would make this vulnerability (and the other security issues) maybe more tolerable, but they have worse security while also being behind with other topics → a dealbreaker

„You can view which devices are logged in in the dashboard settings.“

Great, so they now fullfill 1 out of 6 points I mentioned. Not really a good argument. They still don‘t have failed logins, recent actions like password changes. No notification when 2FA was activated, when password was changed, when IMAP password has been created.

„Not really anti-privacy features.“

„Not really an anti-privacy feature so moot point.“

Looks like somebody does not understand that security and privacy are often depended on each other. But ok, if you want to hear how bad they can be regarding privacy:

A few months back for about 9 hours emails from a catch all accounts were displayed in other mailboxes withing the same domain.

Very private to have your emails visible in another accounts…

„Mailbox is still the best email provider that supports third party email clients“

„Mailbox is the best in its class“

„Still, Mailbox is the best for the average user.“

How can you seriously still claim something like that after all those arguments?