<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" version="2.0" xml:base="https://mailbox.org/en/">
  <channel>
    <title>Mailbox</title>
    <link>https://mailbox.org/en/</link>
    <description/>
    <language>en</language>
    <atom:link rel="self" href="https://mailbox.org/en/feed.rss"/>
<lastBuildDate>Thu, 17 Sep 2026 13:23:27 +0200</lastBuildDate>
<sy:updatePeriod>hourly</sy:updatePeriod>
<sy:updateFrequency>1</sy:updateFrequency>
<pubDate>Thu, 03 Sep 26 00:00:00 +0200</pubDate>
<item>
  <title>Stiftung Warentest reviews email providers and recommends mailbox</title>
  <link>https://mailbox.org/en/news/stiftung-warentest-recommends-mailbox-2026/</link>
  <description>&lt;h2&gt;Top marks for privacy&lt;/h2&gt;&lt;p&gt;In Stiftung Warentest’s assessment, mailbox performed particularly well in the privacy category, which accounts for 30 per cent of the overall score. Here, mailbox achieved the top mark of 1.4, earning a ‘very good’ rating for the app’s data transmission behaviour, basic protection of user data and end-to-end encryption options such as &lt;a href="https://mailbox.org/en/blog/pgp-encryption-at-mailboxorg/" data-entity-type="node" data-entity-uuid="5c710490-9276-4b9f-854d-c9c1b4af845b" data-entity-substitution="canonical" title="PGP encryption for maximum email protection"&gt;PGP&lt;/a&gt; and &lt;a href="https://mailbox.org/en/blog/smime-secure-e-mail-encryption-and-signature/" data-entity-type="node" data-entity-uuid="fcb79eca-189f-4b16-af88-c0f2a34ede37" data-entity-substitution="canonical" title="S/MIME: Secure e-mail encryption and signature"&gt;S/MIME&lt;/a&gt;. This category also includes the security of general email traffic, which mailbox has already demonstrated for the &lt;a href="https://mailbox.org/en/security/" data-entity-type="node" data-entity-uuid="2b846140-bfc8-4154-b324-43cee2bd3bfb" data-entity-substitution="canonical" title="Email encryption: Best protection for your data"&gt;BSI IT Security Mark and the BSI Gold Status for email security&lt;/a&gt;. Furthermore, mailbox is &lt;a href="https://mailbox.org/en/certified-quality/" data-entity-type="node" data-entity-uuid="63a24500-5ad6-4ee2-b951-4070d88f2285" data-entity-substitution="canonical" title="Certified quality"&gt;ISO 27001- and BSI C5-certified&lt;/a&gt; – both external audits confirm high information security standards.&lt;/p&gt;&lt;h2&gt;mailbox impresses in terms of set-up and use&lt;/h2&gt;&lt;p&gt;With a test score of 0.8, mailbox stands out from all other providers tested in the ‘Set-up’ category and achieves an excellent result here too. With the Light plan tested, mailbox offers a cost-effective entry point into secure and reliable email communication.&lt;/p&gt;&lt;p&gt;mailbox impresses in the ‘Usage’ category with the top mark of 1.9. This category carries the greatest weighting at 45 per cent. The assessment covered features, usage via the webmail client and the app, as well as &lt;a href="https://mailbox.org/en/blog/what-free-email-really-costs/" data-entity-type="node" data-entity-uuid="fb5babd7-02d2-4162-a473-017ae6c8a678" data-entity-substitution="canonical" title="Free email: What Gmail and the like really cost"&gt;ad-free experience&lt;/a&gt; were tested. mailbox stands out thanks to its support for open standards such as IMAP, POP3 and SMTP, as well as the option to use &lt;a href="https://mailbox.org/en/blog/email-alias-protection-against-spam/" data-entity-type="node" data-entity-uuid="87067ce5-7331-433e-8c51-0618e4be8140" data-entity-substitution="canonical" title="Email alias: How to protect your email address from spam"&gt;email alias addresses&lt;/a&gt;. In the Standard and Premium plans, &lt;a href="https://mailbox.org/en/blog/email-adress-with-your-custom-domain/" data-entity-type="node" data-entity-uuid="b060164d-12d0-4068-ae62-e004982b9fc8" data-entity-substitution="canonical" title="Email address with your custom domain: introduction and tips"&gt;your own domains&lt;/a&gt; can also be used.&lt;/p&gt;&lt;h2&gt;Digital sovereignty starts with your email provider&lt;/h2&gt;&lt;p&gt;In its email provider test, Stiftung Warentest highlights the legal &lt;a href="https://mailbox.org/en/blog/find-european-alternatives-to-google-and-microsoft/" data-entity-type="node" data-entity-uuid="e6fcf9aa-3a3d-40d8-9f95-594258e79050" data-entity-substitution="canonical" title="Moving away from the US cloud: Find European alternatives to Google and Microsoft"&gt;risk factors associated with US companies&lt;/a&gt;. Whether &lt;a href="https://mailbox.org/en/blog/sovereign-cloud-providers/" data-entity-type="node" data-entity-uuid="a24aa792-dac3-41f3-9b36-926010aadbdd" data-entity-substitution="canonical" title="The sovereign cloud: Who really has control over your data?"&gt;the US CLOUD Act,&lt;/a&gt; a ‘kill switch’ or account suspensions due to politically motivated sanctions: Stiftung Warentest advises caution when using US-based providers. In the test, however, mailbox scored highly as a GDPR-compliant German provider with data centres located exclusively in Germany. The top mark of 1.4 in the privacy category shows that mailbox is the right answer to the current challenges in digital policy.&lt;/p&gt;


  
        
        
    
      &lt;p&gt;“Our test results confirm that, as a provider, we stand out for prioritising digital independence and our proven implementation of data protection and information security. The email address is at the heart of our online identity. This makes it a vital building block for digital sovereignty, both in our private and business lives. Secure and sovereign communication begins with a trustworthy email provider that meets the highest security and data protection standards whilst remaining easy to use. We are delighted that Stiftung Warentest has once again recognised this with mailbox.”&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Balint Gyemant, Chief Product Officer at mailbox&lt;/p&gt;
    
      



  
    
      &lt;h2 class="ticket__title"&gt;Give mailbox a go and take back control of your data!&lt;/h2&gt;
              

&lt;a data-track="News Stiftung Warentest 2026" data-component-id="boxy:knob" data-component-variant="tertiary" class="knob knob--tertiary" href="https://mailbox.org/en/prices/"&gt;Try mailbox now&lt;/a&gt;

          
    
          
                  
              
                  &lt;img loading="lazy" height="1202" width="2663" src="https://mailbox.org/sites/default/files/2026-09/mbo_sw_B_2026_img3.jpg" alt="mailbox erhält die Note 1,8 bei Stiftung Warentest"&gt;

  


    
  

</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2026-09/mbo_sw_B_2026_img2.jpg?itok=N_kSIzIe" type="image/jpeg" length="166287"/><guid isPermaLink="false">4da493ca-0ba4-425b-bba0-eaa04309aa24</guid>
    <pubDate>Thu, 03 Sep 2026 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Stiftung Warentest reviews email providers and recommends mailbox</dc:title>
    <dc:identifier>4da493ca-0ba4-425b-bba0-eaa04309aa24</dc:identifier>
    </item>
<item>
  <title>Staying operational when IT systems go down: EVAC at SCCON 2026</title>
  <link>https://mailbox.org/en/news/evac-sccon-2026/</link>
  <description>&lt;h2&gt;IT emergencies in local government bring critical aspects of public life to a standstill&lt;/h2&gt;&lt;p&gt;Whether it be schools, nurseries, water supply or waste management – local authorities provide essential public services and a wide range of facilities for their citizens. Local authorities and public bodies, in particular, must be able to communicate and take action even in the event of a cyberattack.&lt;/p&gt;&lt;p&gt;Yet the reality is still characterised by long periods of downtime and a breakdown in communication. For instance, Germany is still grappling with the cyberattack on parts of Berlin’s administration in August 2026: two Senate departments lost access to external email communication and the internet, forcing staff to improvise as best they could. For citizens, this meant, amongst other things, that the processing of housing benefit applications ground to a halt for several days. It took around ten days before the affected departments were largely operational again. That means ten days in crisis mode.&lt;/p&gt;&lt;h3&gt;Berlin is not an isolated case, but the norm&lt;/h3&gt;&lt;p&gt;According to the Association of German Municipalities and Cities, hackers attack local authorities’ IT systems almost daily. This often results in prolonged downtime in German towns and local authorities. In 2022, for example, the administration of the Rhein-Pfalz district had to switch to emergency operations for several months following a cyberattack, and sensitive data was also published on the dark web. In 2023, a cyberattack in North Rhine-Westphalia rendered the IT infrastructure of 70 local authorities inoperable for months. Local government services were disrupted for several weeks.&lt;/p&gt;&lt;p&gt;These incidents highlight the fundamental importance of resilient IT infrastructures for functioning public institutions. And they make it clear that an organisation’s ability to operate depends on whether it can continue to communicate.&lt;/p&gt;&lt;p&gt;We are delighted to discuss with you at the Smart Country Convention (SCCON) in Berlin how the public sector can remain accessible to staff, citizens, partners and institutions even in the event of an IT emergency.&lt;/p&gt;&lt;h2&gt;EVAC at the Smart Country Convention: 13 to 15 October 2026&lt;/h2&gt;&lt;p&gt;The Smart Country Convention is the leading event on the digitalisation of the public sector. Once again this year, the three-day event will bring together representatives from public administration, politics, the digital economy, associations, start-ups and academia from 13 to 15 October 2026 at the Berlin Exhibition Centre (Berliner Messegelände) to present and discuss visions and solutions for modern public administration, digitised public authorities and connected cities. Finding ways to ensure the public sector remains capable of acting in crisis situations is also a key focus at SCCON: This year’s key topics include resilience, cyber security and digital sovereignty.&lt;/p&gt;&lt;p&gt;More than 23,000 participants are expected this year. You’ll find a packed programme of keynote speeches and workshops, and you’ll have the chance to exchange views with experts on forward-looking topics in digital transformation and make valuable contacts.&lt;/p&gt;&lt;h2&gt;Come and visit us at SCCON 2026!&lt;/h2&gt;&lt;p&gt;At our Stand No. 431 in Hall 26, we’ll show you what’s essential for a robust business continuity strategy, what you should look out for when choosing a secondary communications platform, and how the switch to an emergency platform works.&lt;/p&gt;&lt;h3&gt;Free tickets for SCCON&lt;/h3&gt;&lt;p&gt;Admission to the Smart Country Convention is free of charge. Tickets are available exclusively online via the organiser’s ticket shop; there is no on-site box office. → Secure your &lt;a href="https://www.smartcountry.berlin/en/visit/tickets"&gt;free ticket&lt;/a&gt; for SCCON here!&lt;/p&gt;&lt;h3&gt;Arrange a personal chat at the EVAC stand&lt;/h3&gt;&lt;p&gt;Would you like to have a chat with us in person? We’d be delighted! We recommend you take the opportunity to book an appointment in advance so you can discuss matters with our Sales Manager, Henrik Heigel, at SCCON. → Book an appointment &lt;a href="https://online.smartcountry.berlin/company/mailbox-org--1225976"&gt;here under ‘Request meeting’&lt;/a&gt; to book a meeting!&lt;/p&gt;&lt;h2&gt;We look forward to seeing you at our stand at the Smart Country Convention 2026 in Berlin!&lt;/h2&gt;

  
    
      &lt;h2 class="accordion__headline"&gt;Frequently asked questions about SCCON 2026&lt;/h2&gt;
          
    
    
                        
            
              Where will SCCON 2026 take place, and where is the EVAC stand?
              
                
              
            

            
              
                &lt;p&gt;The Smart Country Convention will take place from 13 to 15 October 2026 at the Berlin Exhibition Centre, Jafféstraße 2, Gate 25, 14055 Berlin. You will find the EVAC stand, number 431, in Hall 26.&lt;/p&gt;
              
            
          
                                
            
              How can I arrange a meeting with the EVAC team at SCCON?
              
                
              
            

            
              
                &lt;p&gt;You can arrange a personal meeting with our Sales Manager, Henrik Heigel, in advance online &lt;a href="https://online.smartcountry.berlin/company/mailbox-org--1225976"&gt;by clicking on ‘Request meeting’ on this page&lt;/a&gt;.&lt;/p&gt;
              
            
          
                                
            
              Will the Heinlein Group’s teams be there as well?
              
                
              
            

            
              
                &lt;p&gt;OpenCloud and OpenTalk are also attending as part of the Heinlein Group. You’ll find them at the Open Source Business Alliance (OSBA) stand: Stand 500 in Hall 25.&lt;/p&gt;
              
            
          
                                
            
              How much will it cost me to attend SCCON 2026?
              
                
              
            

            
              
                &lt;p&gt;Attendance at SCCON is free of charge for visitors.&lt;/p&gt;
              
            
          
                                
            
              Where can I get tickets for SCCON?
              
                
              
            

            
              
                &lt;p&gt;Free tickets are available exclusively online &lt;a href="https://www.smartcountry.berlin/en/visit/tickets"&gt;via the organiser’s ticket shop&lt;/a&gt;.&lt;/p&gt;
              
            
          
                                
            
              What is EVAC?
              
                
              
            

            
              
                &lt;p&gt;EVAC is mailbox’s business continuity solution, a secondary communication and collaboration platform that remains on standby and can be activated at the touch of a button in the event of an emergency. If the primary IT system fails, staff can access emergency email inboxes, calendars, address books, task management, video conferencing, cloud storage and online office tools via their web browser. The infrastructure is completely independent of the primary system, operates in redundant data centres in Germany, and is ISO 27001-certified and BSI C5-tested. With EVAC, you are immediately able to take action in the event of an IT emergency.&lt;/p&gt;
              
            
          
                                
            
              Why is business continuity so important for the public sector?
              
                
              
            

            
              
                &lt;p&gt;For the public sector, a robust business continuity strategy – including a secondary communications platform – is more than just a technical precaution. The BSI 200-4 standard requires that time-critical processes continue to run in emergency mode. Emergency communications are essential for this. For organisations falling within the scope of NIS-2 and the German KRITIS regulation, reporting and documentation obligations also apply.&lt;/p&gt;&lt;p&gt;If there is no way to communicate securely and reliably in an emergency, the risk of shadow IT being used, prolonged downtime and lasting damage to the organisation increases. With a secondary communication platform, however, you can meet reporting deadlines, coordinate the crisis management team, keep staff informed and respond to enquiries from the public.&lt;/p&gt;
              
            
          
                  

  



  
    
      &lt;h2 class="ticket__title"&gt;Find out more about business continuity at the touch of a button!&lt;/h2&gt;
              

&lt;a data-component-id="boxy:knob" data-component-variant="tertiary" class="knob knob--tertiary" href="https://mailbox.org/en/evac/"&gt;Discover EVAC&lt;/a&gt;

          
    
          
                  
              
                  &lt;img loading="lazy" height="1632" width="2944" src="https://mailbox.org/sites/default/files/2025-04/mailbox-evac-button-web-rgb.jpg" alt="Kommunikation auf Knopfdruck"&gt;

  


    
  

</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2026-09/mailbox%20EVAC%20SCCON%202026_eng.jpg?itok=eV8NBsYV" type="image/jpeg" length="446196"/><guid isPermaLink="false">c943a2c7-7cc2-4bef-b93d-c6de04af0726</guid>
    <pubDate>Wed, 02 Sep 2026 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Staying operational when IT systems go down: EVAC at SCCON 2026</dc:title>
    <dc:identifier>c943a2c7-7cc2-4bef-b93d-c6de04af0726</dc:identifier>
    </item>
<item>
  <title>IT security: Why small businesses in particular are targeted by cyberattacks</title>
  <link>https://mailbox.org/en/blog/IT-security-for-small-businesses/</link>
  <description>&lt;p&gt;&lt;em&gt;Reading time: 8 minutes&lt;/em&gt;&lt;/p&gt;&lt;p&gt;As a company that does not generate millions in turnover or manage large volumes of sensitive customer or patient data, one often lulls oneself into a false sense of security and mistakenly believes that cybersecurity is an issue exclusively for large organisations. However, the notion that cybercriminals have nothing to gain from small businesses is a common – and costly – misconception. In fact, small and medium-sized enterprises are not overlooked simply because of their size. On the contrary, their size often makes them a prime target. In our article, you’ll find out how small businesses are targeted and what specific steps you can take to protect yourself.&lt;/p&gt;


      
                  
              
              
              
              
              
              
              
                  &lt;img loading="lazy" height="2160" width="4096" src="https://mailbox.org/sites/default/files/2026-08/mailbox%20EVAC%20Blog%20IT-Sicherheit%20kleine%20Unternehmen.jpeg" alt="mailbox EVAC Blog IT-Sicherheit kleine Unternehmen"&gt;

  


  
          

              


  
    
    
    
    &lt;h2&gt;IT security for small businesses in Germany&lt;/h2&gt;&lt;p&gt;Bitkom, the trade association for the German information and telecommunications sector, estimates the annual cost to the German economy of theft, espionage and sabotage at 289.2 billion euros in its study on economic security 2025. Cyberattacks alone account for 202.4 billion euros of this figure. Around 87 % of the companies surveyed were affected during the study period.&lt;/p&gt;&lt;p&gt;The fact that these attacks are by no means confined to large corporations is made clear by Germany's Federal Office for Information Security’s (BSI) annual report on IT security in Germany for the year 2025. According to the report, around 80 % of the reported attacks were directed against small and medium-sized enterprises. In its 2025 Federal Cybercrime Situation Report, Germany's Federal Criminal Police Office (BKA) also recorded 1,041 reported ransomware attacks, which is 10 % more than in the previous year. At 90 %, small and medium-sized enterprises are once again the group most severely affected.&lt;/p&gt;&lt;p&gt;These figures dispel the myth that small businesses are uninteresting targets. So why are small businesses targeted so frequently?&lt;/p&gt;&lt;h2&gt;What makes small businesses so attractive to cyber-attacks?&lt;/h2&gt;&lt;h3&gt;The vast majority of attacks are automated&lt;/h3&gt;&lt;p&gt;Malware and botnets constantly scan the internet for vulnerable systems, open ports, outdated software or weak login credentials. Whether the target is an international corporation or a small trade business with twelve employees is irrelevant in this initial phase. Anyone who leaves a gap open will be hit. At the same time, there is a shift away from a few elaborate attacks towards a multitude of smaller, easily executable attacks.&lt;/p&gt;&lt;h3&gt;The weakest link in the supply chain&lt;/h3&gt;&lt;p&gt;Small firms often misjudge their own role within the wider structure of the supply chain. Suppliers, service providers or specialist craft businesses are now closely connected to their partners digitally. For attackers, this weakest link becomes a gateway through which they can reach the targets of real interest further up the chain. Your size therefore does not protect you; on the contrary, it can make you a preferred point of entry.&lt;/p&gt;&lt;h3&gt;Cybercrime-as-a-Service lowers the barrier to entry&lt;/h3&gt;&lt;p&gt;In the ‘Cybercrime-as-a-Service’ business model, malware and complete attack services are offered like off-the-shelf products. Attacks therefore require neither in-depth technical knowledge nor significant investment. This significantly lowers the barrier to entry and increases the number of potential attackers, at the expense of those companies that previously considered themselves too insignificant.&lt;/p&gt;&lt;h3&gt;The security gap: perceived vs. actual security&lt;/h3&gt;&lt;p&gt;According to the BSI, small and medium-sized enterprises meet, on average, only around 56 % of the basic IT security requirements and regularly overestimate their own level of protection. Attackers exploit this gap between perceived and actual security. When companies believe themselves to be secure without actually being so, they fail to take the measures needed to ward off cyber risks and ensure their business continuity.&lt;/p&gt;&lt;h2&gt;The most common entry points for cybercrime&lt;/h2&gt;&lt;p&gt;In practice, it is primarily the following recurring patterns that cybercriminals use to cause damage to small businesses:&lt;/p&gt;

          
                                                  
      

    
          
        &lt;h2 class="mosaic__title"&gt;
                    Phishing
        &lt;/h2&gt;
        &lt;p&gt;A deceptively genuine invoice from a long-standing business partner, a purported message from the company’s bank, or an urgent request from a supposed line manager can trick employees into thoughtlessly clicking on links, attachments and the like. Such attacks are aimed directly at people.&lt;/p&gt;
              
          
        &lt;h2 class="mosaic__title"&gt;
                    Ransomware
        &lt;/h2&gt;
        &lt;p&gt;In ransomware attacks, company data is encrypted in order to extort a ransom from the victims. According to Bitkom, 34 % of the companies surveyed suffered damage caused by ransomware within a year, followed by DDoS attacks (25 %) and other malware (24 %).&lt;/p&gt;
              
          
        &lt;h2 class="mosaic__title"&gt;
                    Accesses
        &lt;/h2&gt;
        &lt;p&gt;Weak or reused passwords and the absence of a second factor of authentication leave the door wide open to attackers. This risk is exacerbated by out-of-date software and inadequately secured remote access, for example when working from home or whilst on the move.&lt;/p&gt;
              
      

              


  
    
    
    
    &lt;h2&gt;Why are small businesses hit harder by the damage?&lt;/h2&gt;&lt;p&gt;The fear of ransom demands often overshadows the consequences of cyber-attacks, which cause far greater damage. Following a ransomware attack, in many cases it is not just the IT systems that come to a standstill, but the entire business: Orders cannot be processed, invoices cannot be issued and customers cannot be served. Every day of downtime results in an immediate loss of turnover, and unlike a large corporation, a small business rarely has the reserves to bridge a prolonged interruption.&lt;/p&gt;&lt;p&gt;On top of the downtime come the costs of recovery, potential fines and reporting obligations in the event of a personal data breach under the GDPR, as well as the loss of trust among customers and partners, which is difficult to quantify.&lt;/p&gt;&lt;p&gt;A large corporation can more easily absorb the impact of a successful attack. Small businesses, on the other hand, are hit particularly hard. For them, a serious cyber incident therefore poses an immediate threat to the very foundations of their business. This is precisely where it becomes clear why business continuity – that is, the ability to maintain business operations even in an emergency – is a matter of survival for small businesses.&lt;/p&gt;&lt;h2&gt;Staying operational: communication as an underestimated emergency factor&lt;/h2&gt;&lt;p&gt;Whether an incident turns into a minor disruption or a full-blown crisis is often decided in the first few hours – and thus depends on the ability to communicate.&lt;/p&gt;&lt;p&gt;It is precisely when swift and coordinated action is crucial that the very tools you would normally rely on often fail. If the primary communication channels are compromised, email inboxes and video-conferencing tools are no longer available. If, at that moment, you do not know how to reach your staff, you will lose valuable time. Yet in an emergency, communication must take place in several directions at once:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;The workforce needs clear instructions and new communication channels.&lt;/li&gt;&lt;li&gt;Customers and business partners expect open and reliable information; otherwise, there is a risk of a lasting loss of trust that could threaten the very survival of the business.&lt;/li&gt;&lt;li&gt;There are legal obligations towards the authorities; for example, a data protection incident must be reported to the &lt;a href="https://mailbox.org/en/blog/gdpr-violations-5-costly-traps-companies/" data-entity-type="node" data-entity-uuid="fab139b9-84c0-49ff-bc51-8e17bd6c4f2e" data-entity-substitution="canonical" title="GDPR violations: 5 common mistakes to avoid"&gt;GDPR&lt;/a&gt; within 72 hours.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;For this communication to succeed at all, it must function independently of the affected systems. Contact lists, emergency numbers and a coordinated communication plan must therefore be stored in a single location that remains accessible even when the primary channels are down. A resilient communication capability in an emergency is the cornerstone of business continuity.&lt;/p&gt;

          
                                                  
      


  
    
      &lt;h2 class="ticket__title"&gt;Business continuity for SMEs&lt;/h2&gt;
              

&lt;a data-component-id="boxy:knob" data-component-variant="tertiary" class="knob knob--tertiary" href="https://mailbox.org/en/blog/business-continuity-plan-bsi-200-4-sme/"&gt;Learn about BSI Standard 200-4&lt;/a&gt;

          
    
          
                  
              
                  &lt;img loading="lazy" height="4283" width="6628" src="https://mailbox.org/sites/default/files/2026-04/Blog%20mailbox%20EVAC%20Gescha%CC%88ftsfortfu%CC%88hrungsplan%20nach%20BSI%20Standard%20200-4%20BCM%20fu%CC%88r%20KMU.jpeg" alt="Blog mailbox EVAC Business Continuity Plan according to BSI Standard 200-4 BCM for SMEs"&gt;

  


    
  

              


  
    
    
    
    &lt;h2&gt;IT security for small businesses: Your action plan&lt;/h2&gt;&lt;p&gt;However serious the situation may be, there is little cause for resignation: as most attacks are automated and seek out the easiest opportunity, even a solid level of basic protection shifts the cost-benefit balance against the attackers. A business by no means needs to mobilise the resources of a large corporation to become significantly less vulnerable to attack. Effective IT security for small businesses does not start with expensive specialist solutions, but with the consistent implementation of the basics:&lt;/p&gt;&lt;p&gt;Can be implemented immediately:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Enable multi-factor authentication (MFA) for all key access points: this is one of the most effective measures and is already included in many systems.&lt;/li&gt;&lt;li&gt;Introduce password management: this replaces weak and reused passwords.&lt;/li&gt;&lt;li&gt;Keep your systems up to date: install any outstanding security updates and enable automatic updates to be prepared for new threats.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;In the short term:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Set up regular, off-site backups and test the recovery process in case of an emergency.&lt;/li&gt;&lt;li&gt;Review remote access permissions and consistently revoke access that is no longer required.&lt;/li&gt;&lt;li&gt;Raise your staff’s awareness of &lt;a href="https://mailbox.org/en/blog/phishing-alarm-how-to-spot-fake-mailboxorg-emails/" data-entity-type="node" data-entity-uuid="2db1b30d-ccf2-40fb-bf08-b28a69e166ac" data-entity-substitution="canonical" title="Phishing alert: How to spot fake mailbox.org e-mails"&gt;phishing&lt;/a&gt; and the &lt;a href="https://mailbox.org/en/blog/business-email-compromise-protection-against-email-fraud/" data-entity-type="node" data-entity-uuid="3a9f36b1-3f8a-4f84-8126-95585abf91e8" data-entity-substitution="canonical" title="Business Email Compromise: How to prevent email fraud"&gt;increased risks of email fraud resulting from the use of artificial intelligence&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Embed this in your structure:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Draw up a clear contingency plan and a robust business continuity strategy, and test the measures regularly to ensure you remain capable of acting in the event of a failure. Practical guidance on this is provided by the &lt;a href="https://mailbox.org/en/blog/business-continuity-plan-bsi-200-4-sme/" data-entity-type="node" data-entity-uuid="51b24a68-8b81-49c8-9a03-d3c407f2465d" data-entity-substitution="canonical" title="Business continuity plan in accordance with BSI Standard 200-4: How SMEs ensure their business continuity"&gt;BSI Standard 200-4&lt;/a&gt;, which helps small businesses in particular to develop and establish a robust business continuity management (BCM) system whilst conserving resources.&lt;/li&gt;&lt;li&gt;Prepare &lt;a href="https://mailbox.org/en/evac/" data-entity-type="node" data-entity-uuid="8d62b38c-25b3-4011-a5f2-de2d2e58cc87" data-entity-substitution="canonical" title="EVAC: Business continuity in an emergency"&gt;communication channels independent of the primary system&lt;/a&gt; that are immediately available in an emergency.&lt;/li&gt;&lt;li&gt;View IT security as an ongoing process and as a responsibility of senior management.&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Conclusion&lt;/h2&gt;&lt;p&gt;The situation reports from the BSI, BKA and Bitkom paint a consistent picture: Cybercriminals are not looking for the largest company, but the one that is easiest to target. Smaller companies, in particular, are the main focus. That is why it is so important to consistently implement the fundamentals of IT security for small businesses and to take business continuity seriously.&lt;/p&gt;

          
                                                  
      

    
          
        &lt;h2 class="mosaic__title"&gt;
                    Make sure your business is prepared for an emergency.
        &lt;/h2&gt;
        
                  

&lt;a data-component-id="boxy:knob" data-component-variant="primary" class="knob knob--primary" href="https://mailbox.org/en/evac/"&gt;Discover EVAC&lt;/a&gt;
      
          
        &lt;h2 class="mosaic__title"&gt;
                    Let’s answer your questions about business continuity.
        &lt;/h2&gt;
        
                  

&lt;a data-component-id="boxy:knob" data-component-variant="primary" class="knob knob--primary" href="https://mailbox.org/en/business-request/"&gt;Contact Sales&lt;/a&gt;
      
      



      
      &lt;h2 class="row__intro__title"&gt;            Insights &amp;amp; Trends
      &lt;/h2&gt;
      Discover more articles on the topic of security.
              
            

&lt;a data-component-id="boxy:knob" data-component-variant="secondary" class="knob knob--secondary" href="https://mailbox.org/en/insights/"&gt;All articles&lt;/a&gt;

        
          
    
      
      
  
  
                    
                  
              
                  &lt;img loading="lazy" height="4912" width="7360" src="https://mailbox.org/sites/default/files/2026-07/mailbox%20EVAC%20Blog%20Schatten-IT%20als%20Notfalllo%CC%88sung%20vermeiden.jpeg" alt="mailbox EVAC Blog Schatten-IT als Notfalllösung vermeiden"&gt;

  


      
      
      
      Business Continuitiy, Security
    
    &lt;h3 class="snip__title"&gt;How to avoid shadow IT when your communication tools fail&lt;/h3&gt;
  &lt;a class="snip__arrow" href="https://mailbox.org/en/blog/avoiding-shadow-IT-in-an-emergency/" aria-hidden="true"&gt;→&lt;/a&gt;
  &lt;a class="snip__link" href="https://mailbox.org/en/blog/avoiding-shadow-IT-in-an-emergency/"&gt;Read more about &lt;em class="placeholder"&gt;How to avoid shadow IT when your communication tools fail&lt;/em&gt;&lt;/a&gt;


    
      
      
  
  
                    
                  
              
                  &lt;img loading="lazy" height="4596" width="8688" src="https://mailbox.org/sites/default/files/2026-06/mailbox%20EVAC%20Blog%20Business%20Email%20Compromise.jpeg" alt="mailbox EVAC Blog Business Email Compromise E-Mail-Betrug"&gt;

  


      
      
      
      Business Continuitiy, Security
    
    &lt;h3 class="snip__title"&gt;Business Email Compromise: How to prevent email fraud&lt;/h3&gt;
  &lt;a class="snip__arrow" href="https://mailbox.org/en/blog/business-email-compromise-protection-against-email-fraud/" aria-hidden="true"&gt;→&lt;/a&gt;
  &lt;a class="snip__link" href="https://mailbox.org/en/blog/business-email-compromise-protection-against-email-fraud/"&gt;Read more about &lt;em class="placeholder"&gt;Business Email Compromise: How to prevent email fraud&lt;/em&gt;&lt;/a&gt;


    
  
  


</description>
  <guid isPermaLink="false">b669c55e-7ad7-47b6-bdae-7cbfb91b139d</guid>
    <pubDate>Tue, 25 Aug 2026 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>IT security: Why small businesses in particular are targeted by cyberattacks</dc:title>
    <dc:identifier>b669c55e-7ad7-47b6-bdae-7cbfb91b139d</dc:identifier>
    </item>
<item>
  <title>How to use business continuity as a competitive advantage in the supply chain</title>
  <link>https://mailbox.org/en/blog/business-continuity-supply-chain/</link>
  <description>&lt;p&gt;&lt;em&gt;Reading time: 6 minutes&lt;/em&gt;&lt;/p&gt;&lt;p&gt;Against a backdrop of growing cyber threats and increasingly sophisticated attack scenarios, clients have long since ceased to select their suppliers based solely on quality and price; instead, they now consider their cyber resilience and reliability as key decision-making criteria. As small and medium-sized enterprises in particular are a favourite target for cybercriminals, robust business continuity management (BCM) is thus shifting from an internal security issue to a selling point. In this article, you will learn what role your ability to operate effectively in a crisis plays in the tendering process, what business continuity is, and how you can strengthen and demonstrate your resilience.&lt;/p&gt;


      
                  
              
              
              
              
              
              
              
                  &lt;img loading="lazy" height="2160" width="4096" src="https://mailbox.org/sites/default/files/2026-08/mailbox%20EVAC%20Blog%20Business%20Continuity%20in%20der%20Lieferkette.jpeg" alt="mailbox EVAC Blog Business Continuity in der Lieferkette"&gt;

  


  
          

              


  
    
    
    
    &lt;h2&gt;Reliability as a selection criterion&lt;/h2&gt;&lt;p&gt;Companies are interdependent and digitally connected within the value chain. Supply chains today are global and highly complex and they are only as strong as their weakest link: even a single supplier failing to deliver can bring a production line to a standstill, delay a project or disrupt a service. The damage is not confined to the supplier alone, but ripples through the entire chain. Clients therefore seek to minimise this risk right from the stage of selecting business partners.&lt;/p&gt;&lt;p&gt;This is precisely why the resilience of partners is coming into focus. Today, procurement departments in large companies assess their suppliers not only on the basis of cost and quality, but also according to other criteria:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;How does a partner deal with exceptional situations?&lt;/li&gt;&lt;li&gt;Can they resume operations quickly after an incident?&lt;/li&gt;&lt;li&gt;Do they remain contactable?&lt;/li&gt;&lt;li&gt;Are their processes documented and traceable?&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;A service provider that remains unreachable for a long time following a ransomware attack becomes an incalculable factor and risk for its client. Poorly managed cyber incidents can thus place a lasting strain on business relationships. Furthermore, one of the reasons small and medium-sized enterprises are such popular targets for cyber attacks is that their IT systems – which are often inadequately protected – can be used to reach other, larger targets.&lt;/p&gt;&lt;p&gt;This is another reason why clients are compelled to extend their influence over their suppliers’ security concepts and business continuity strategies. The resulting requirements become a condition of business relationships and are set out in contracts and security questionnaires.&lt;/p&gt;&lt;p&gt;After all, a supplier that remains operational even during a crisis relieves its customers of the burden of disruptions affecting the wider supply chain. That is why companies favour suppliers who can demonstrate that they have their business continuity under control. This development presents well-prepared organisations with an opportunity to stand out positively from their competitors.&lt;/p&gt;&lt;h2&gt;NIS-2 reinforces the trend&lt;/h2&gt;&lt;p&gt;With the &lt;a href="https://mailbox.org/en/blog/nis-2-implementation-act-germany-obligations-business-continuity/" data-entity-type="node" data-entity-uuid="39c7c4b3-4771-4a2d-be32-be147cb897ed" data-entity-substitution="canonical" title="NIS-2 Implementation Act Germany: Obligations &amp;amp; Business Continuity"&gt;NIS-2 Directive and its national implementing acts&lt;/a&gt;, many companies are now required to manage the security of their entire supply chain. As a result, they pass on security and business continuity requirements to their suppliers via contracts. And in our globally interconnected economy, this also applies to those who are not themselves covered by the Directive.&lt;/p&gt;&lt;p&gt;NIS-2, so to speak, formalises the need for reliable partners in business relationships. However, this need exists independently of regulations and laws for both clients and suppliers. Even when dealing with unregulated clients, robust business continuity therefore directly enhances your own appeal as a business partner.&lt;/p&gt;&lt;h2&gt;What does business continuity management (BCM) mean?&lt;/h2&gt;&lt;p&gt;Business continuity describes an organisation’s ability to maintain its most critical processes, or to resume them rapidly, even in the event of disruptions. This includes an analysis of time-critical processes, clear lines of responsibility in the event of a crisis, and defined recovery objectives.&lt;/p&gt;&lt;p&gt;For smaller companies, this can pose a serious challenge: whilst large corporations have well-staffed and technically well-equipped IT departments and dedicated business continuity management (BCM) officers, smaller companies have to make do with significantly fewer resources.&lt;/p&gt;&lt;p&gt;Efficient solutions for business continuity, security and cyber resilience are particularly essential for this type of organisation, if they are to continue to be regarded as attractive business partners under the prevailing conditions. It is precisely through organisational professionalism that you can stand out:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Are there tried-and-tested security policies that also take your own role in the supply chain into account?&lt;/li&gt;&lt;li&gt;Are there documented and robust processes for handling security incidents?&lt;/li&gt;&lt;li&gt;Are there clearly defined and comprehensive responsibilities?&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Small and medium-sized enterprises can prove themselves to be reliable partners by avoiding informal structures and relying on robust business continuity management (BCM). The &lt;a href="https://mailbox.org/en/blog/business-continuity-plan-bsi-200-4-sme/" data-entity-type="node" data-entity-uuid="51b24a68-8b81-49c8-9a03-d3c407f2465d" data-entity-substitution="canonical" title="Business continuity plan in accordance with BSI Standard 200-4: How SMEs ensure their business continuity"&gt;BSI Standard 200-4&lt;/a&gt; provides a practical framework for this.&lt;/p&gt;&lt;h2&gt;Emergency communication is the most visible proof of reliability&lt;/h2&gt;&lt;p&gt;IT security, in particular, is usually thought of in terms of prevention – that is, as a defence against attacks. However, resilience does not end with defence; rather, it is demonstrated by the ability to remain operational following an incident. The ability to communicate is crucial for a company’s public image: if email and collaboration tools fail simultaneously following an attack, even the best data backup is of little use as long as communication is impossible.&lt;/p&gt;&lt;p&gt;A company that remains reachable during a disruption and continues to communicate professionally demonstrates its reliability at the crucial moment. A prerequisite for this is a second communication platform that stands by in the background and can be activated at the touch of a button in an emergency. A robust emergency platform meets a number of clear criteria:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;It is independent of the primary IT infrastructure so as not to fail at the same time.&lt;/li&gt;&lt;li&gt;It is ready for immediate use, because every hour counts in an emergency.&lt;/li&gt;&lt;li&gt;In addition to email, it includes video conferencing and shared file storage to support day-to-day collaborative digital work.&lt;/li&gt;&lt;li&gt;It is secure, GDPR-compliant and digitally sovereign, ensuring that sensitive data does not fall into the wrong hands, even during a crisis.&lt;/li&gt;&lt;/ul&gt;

          
                                                  
      


  
    
      &lt;h2 class="ticket__title"&gt;Business continuity management for SMEs&lt;/h2&gt;
              

&lt;a data-component-id="boxy:knob" data-component-variant="tertiary" class="knob knob--tertiary" href="https://mailbox.org/en/blog/business-continuity-plan-bsi-200-4-sme/"&gt;Learn more about BCM now&lt;/a&gt;

          
    
          
                  
              
                  &lt;img loading="lazy" height="4283" width="6628" src="https://mailbox.org/sites/default/files/2026-04/Blog%20mailbox%20EVAC%20Gescha%CC%88ftsfortfu%CC%88hrungsplan%20nach%20BSI%20Standard%20200-4%20BCM%20fu%CC%88r%20KMU.jpeg" alt="Blog mailbox EVAC Business Continuity Plan according to BSI Standard 200-4 BCM for SMEs"&gt;

  


    
  

              


  
    
    
    
    &lt;h2&gt;Turning resilience into a selling point&lt;/h2&gt;&lt;p&gt;For the investment in contingency planning to pay off, it must be recognisable to potential clients. Three approaches will help you turn your own business continuity from an internal project into a sales advantage:&lt;/p&gt;&lt;ol&gt;&lt;li&gt;&lt;p&gt;Provide evidence:&lt;/p&gt;&lt;p&gt;The actual proof of business continuity is a documented continuity plan, based on relevant standards such as BSI Standard 200-4 or ISO 22301. In addition, recognised information security certifications such as ISO 27001 or a BSI C5 certificate demonstrate a mature security organisation.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Communicate proactively:&lt;/p&gt;&lt;p&gt;Actively highlight your resilience in quotations, on your website and during sales meetings, rather than simply responding to it in a security questionnaire.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Practise for an emergency:&lt;/p&gt;&lt;p&gt;Regular tests, such as tabletop exercises, demonstrate that your plans are not just on paper and will stand up to scrutiny in audits.&lt;/p&gt;&lt;/li&gt;&lt;/ol&gt;&lt;h2&gt;Conclusion: Business continuity is a precaution that pays off&lt;/h2&gt;&lt;p&gt;The pressure to meet security requirements does not stop at organisations affected by NIS-2 and other laws and regulations, but extends throughout the entire supply chain. To ensure the stability of the supply chain, both clients and contractors must take into account the security interests and security risks of their partners.&lt;/p&gt;&lt;p&gt;Business continuity is more than just a safeguard against damage to one’s own company. Driven by regulatory developments such as NIS-2, demonstrable and robust resilience is not only an economic factor but is already a criterion for awarding contracts. For small and medium-sized enterprises, this presents an opportunity, as a well-thought-out business continuity strategy combined with a reliable emergency platform makes the company a preferred partner.&lt;/p&gt;

          
                                                  
      


  
    
      &lt;h2 class="ticket__title"&gt;The emergency platform for business continuity at the touch of a button&lt;/h2&gt;
              

&lt;a data-component-id="boxy:knob" data-component-variant="tertiary" class="knob knob--tertiary" href="https://mailbox.org/en/evac/"&gt;Find out more about EVAC now&lt;/a&gt;

          
    
          
                  
              
                  &lt;img loading="lazy" height="1219" width="2200" src="https://mailbox.org/sites/default/files/2025-05/mailbox_evac_infrastruktur_web_rgb.jpg" alt="EVAC Button"&gt;

  


    
  



      
      &lt;h2 class="row__intro__title"&gt;            Insights &amp;amp; Trends
      &lt;/h2&gt;
      Discover more articles on the topic of business continuity.
              
            

&lt;a data-component-id="boxy:knob" data-component-variant="secondary" class="knob knob--secondary" href="https://mailbox.org/en/insights/"&gt;All articles&lt;/a&gt;

        
          
    
      
      
  
  
                    
                  
              
                  &lt;img loading="lazy" height="2160" width="4096" src="https://mailbox.org/sites/default/files/2026-08/mailbox%20EVAC%20Blog%20IT-Sicherheit%20kleine%20Unternehmen.jpeg" alt="mailbox EVAC Blog IT-Sicherheit kleine Unternehmen"&gt;

  


      
      
      
      Business Continuitiy, Security
    
    &lt;h3 class="snip__title"&gt;IT security: Why small businesses in particular are targeted by cyberattacks&lt;/h3&gt;
  &lt;a class="snip__arrow" href="https://mailbox.org/en/blog/IT-security-for-small-businesses/" aria-hidden="true"&gt;→&lt;/a&gt;
  &lt;a class="snip__link" href="https://mailbox.org/en/blog/IT-security-for-small-businesses/"&gt;Read more about &lt;em class="placeholder"&gt;IT security: Why small businesses in particular are targeted by cyberattacks&lt;/em&gt;&lt;/a&gt;


    
      
      
  
  
                    
                  
              
                  &lt;img loading="lazy" height="4912" width="7360" src="https://mailbox.org/sites/default/files/2026-07/mailbox%20EVAC%20Blog%20Schatten-IT%20als%20Notfalllo%CC%88sung%20vermeiden.jpeg" alt="mailbox EVAC Blog Schatten-IT als Notfalllösung vermeiden"&gt;

  


      
      
      
      Business Continuitiy, Security
    
    &lt;h3 class="snip__title"&gt;How to avoid shadow IT when your communication tools fail&lt;/h3&gt;
  &lt;a class="snip__arrow" href="https://mailbox.org/en/blog/avoiding-shadow-IT-in-an-emergency/" aria-hidden="true"&gt;→&lt;/a&gt;
  &lt;a class="snip__link" href="https://mailbox.org/en/blog/avoiding-shadow-IT-in-an-emergency/"&gt;Read more about &lt;em class="placeholder"&gt;How to avoid shadow IT when your communication tools fail&lt;/em&gt;&lt;/a&gt;


    
  
  


</description>
  <guid isPermaLink="false">56344ac3-26b0-451d-8268-e03064a057f1</guid>
    <pubDate>Thu, 13 Aug 2026 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>How to use business continuity as a competitive advantage in the supply chain</dc:title>
    <dc:identifier>56344ac3-26b0-451d-8268-e03064a057f1</dc:identifier>
    </item>
<item>
  <title>Two new features for your day-to-day business</title>
  <link>https://mailbox.org/en/news/two-new-features-your-day-day-business/</link>
  <description>&lt;p&gt;Two new features are now available to all private and business customers: signature templates and text templates.&lt;/p&gt;&lt;h2&gt;Signature templates&lt;/h2&gt;&lt;p&gt;When making initial contact with new customers, you often need a different signature to the one used for support or internal communication. With signature templates, you can create several versions of your personal signature and select the appropriate one when composing an email.&lt;/p&gt;&lt;p&gt;You can find the new signature templates under Settings → E-mail → Signatures → New from template&lt;/p&gt;&lt;h2&gt;Text templates&lt;/h2&gt;&lt;p&gt;In business correspondence, much of the content is repetitive: confirmation of quotations, proposed dates, standard information. With text templates, you can create these phrases once and insert them into an email with just a few clicks. You can create templates for different scenarios.&lt;/p&gt;&lt;p&gt;You can find the new text templates under Settings → E-mail → Templates&lt;/p&gt;


  
    
      &lt;h2 class="ticket__title"&gt;mailbox Business is the digital workplace for businesses&lt;/h2&gt;
              

&lt;a data-component-id="boxy:knob" data-component-variant="tertiary" class="knob knob--tertiary" href="https://mailbox.org/en/business/"&gt;Discover mailbox Business&lt;/a&gt;

          
    
          
                  
              
                  &lt;img loading="lazy" height="2577" width="3864" src="https://mailbox.org/sites/default/files/2025-06/mailbox-sicherheit-fuer-unternehmen.jpg" alt="A man in a blue blazer holds a tablet, standing outdoors near a modern glass building, with soft evening light filtering through."&gt;

  


    
  

</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-04/mailbox-news-und-updates-produktupdate.jpg?itok=VmAEEH73" type="image/jpeg" length="400284"/><guid isPermaLink="false">672afc0a-00af-4fc2-8bca-925a28a927eb</guid>
    <pubDate>Wed, 12 Aug 2026 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Two new features for your day-to-day business</dc:title>
    <dc:identifier>672afc0a-00af-4fc2-8bca-925a28a927eb</dc:identifier>
    </item>
<item>
  <title>Email alias: How to protect your email address from spam</title>
  <link>https://mailbox.org/en/blog/email-alias-protection-against-spam/</link>
  <description>&lt;p&gt;&lt;em&gt;Reading time: 9 minutes&lt;/em&gt;&lt;/p&gt;&lt;p&gt;An online shop asks for your email address when you place an order, as does an AI tool, and you also provide it to access the Wi-Fi in a café. A few weeks or months later, you’re puzzled by adverts from senders who’ve never contacted you, and at first you can’t work out how they got hold of your address. In our blog, we’ll show you how your email address ends up in the wrong hands and how you can protect yourself against this with a small but effective tool: the email alias.&lt;/p&gt;


      
                  
              
              
              
              
              
              
              
                  &lt;img loading="lazy" height="4065" width="6098" src="https://mailbox.org/sites/default/files/2026-07/mailbox%20Blog%20E-Mail-Alias.jpeg" alt="mailbox Blog E-Mail-Alias"&gt;

  


  
          

              


  
    
    
    
    &lt;h2&gt;Your email address is more than just a way to get in touch&lt;/h2&gt;&lt;p&gt;For most people, their email address has long since become the central key to their digital identity. It serves as a username for dozens of services, is used to reset passwords, and links accounts that, at first glance, appear to have nothing to do with one another.&lt;/p&gt;&lt;p&gt;This is precisely what makes it so interesting to others: Anyone who uses the same address everywhere provides data brokers with an anchor point around which information from a wide variety of sources can be pieced together. From individual fragments – online shops, travel portals, gyms, newsletter subscriptions, etc. – a detailed profile emerges.&lt;/p&gt;&lt;p&gt;For cybercriminals, a widely used email address is a real treat: if it turns up in a data breach along with a password, automated scripts try the same combination on other services. This method is known as credential stuffing.&lt;/p&gt;&lt;h2&gt;How does spam even come about?&lt;/h2&gt;&lt;p&gt;Spam is a business model: advertising emails cost their senders almost nothing, and even if only a tiny fraction of recipients respond, the effort has already paid off. The prerequisite for this, however, is that the senders can actually obtain email addresses in the first place. There is now a whole market dedicated to this, offering reliable methods:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;Email addresses are collected automatically:&lt;/p&gt;&lt;p&gt;Programmes known as ‘harvesters’ scan websites, forums, comments sections and social media round the clock for anything that looks like an email address. If you leave your address in a public place, you run the risk of it being automatically captured.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Addresses are passed on and sold:&lt;/p&gt;&lt;p&gt;Unfortunately, not every service handles your data with care. Some providers pass addresses on to so-called ‘partners’, whilst others sell them to data brokers. Once your email address has been sold, it is passed from list to list.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Addresses end up in circulation due to data breaches:&lt;/p&gt;&lt;p&gt;Frequently, companies fall victim to attacks in which entire customer databases are compromised. These data sets, which often contain email addresses along with passwords, subsequently turn up on specialist forums and are traded. Even if you’ve done everything right yourself, your address can still be made public due to a provider’s negligence. Incidentally, you can check whether you’ve been affected on websites such as &lt;a href="//haveibeenpwned.com/"&gt;Have I Been Pwned&lt;/a&gt; or using the &lt;a href="https://ilc.hpi.de/?lang=en"&gt;Identity Leak Checker from the Hasso Plattner Institute&lt;/a&gt;.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Addresses are guessed:&lt;/p&gt;&lt;p&gt;Some senders generate addresses automatically by combining common first names, words and numbers with well-known domains. Sooner or later, a simple, obvious address will be hit in this way – even if you’ve never provided it anywhere.&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Once an address appears on one of these lists, it’s almost impossible to undo. It gets copied, traded and replicated. If your entire digital life – from online banking and social media to communicating with public authorities – depends on a single email address, this is particularly troublesome. This is exactly where an email alias comes in.&lt;/p&gt;&lt;h2&gt;What is an email alias and how does it work?&lt;/h2&gt;&lt;p&gt;An email alias is an additional email address that points to your existing inbox. Technically speaking, it is an internal server-based forwarding mechanism: A message sent to the alias is received by the mail server and ends up in the same inbox as a message sent to your main address. You don’t need a second account, a second app or another password. An alias is, in a sense, an additional name for the same mailbox.&lt;/p&gt;&lt;p&gt;An example: Your main address is firstname@example.org. Alongside this, you set up alias addresses such as firstname.shopping@example.org or firstname.news@example.org. All three lead to the same mailbox, but you can choose which address to give to whom. A good email alias does not contain any real names: the more neutral it is, the harder it is to trace back to you.&lt;/p&gt;&lt;p&gt;The key difference is that this is not simply a forwarding to someone else’s account: an alias belongs to your mailbox. You can, and indeed should, therefore not only receive emails via the alias, but also reply and send emails using it, without your actual address being visible to the recipient.&lt;/p&gt;

          
                                                  
      

    
          
        &lt;h2 class="mosaic__title"&gt;
                    Uses of an email alias
        &lt;/h2&gt;
        &lt;ul&gt;&lt;li&gt;Online shopping&lt;/li&gt;&lt;li&gt;Newsletters&lt;/li&gt;&lt;li&gt;Social media and forums&lt;/li&gt;&lt;li&gt;Competitions, Wi-Fi hotspots and free downloads&lt;/li&gt;&lt;li&gt;Authorities, banks and insurance companies&lt;/li&gt;&lt;li&gt;Classifieds and sales&lt;/li&gt;&lt;/ul&gt;
              
          
        &lt;h2 class="mosaic__title"&gt;
                    The limitations of an email alias
        &lt;/h2&gt;
        &lt;p&gt;Alias addresses are a useful addition, but not a cure-all.&lt;/p&gt;&lt;p&gt;An email alias controls who knows which of your addresses. However, it does not make you anonymous, does not conceal your IP address, and is no substitute for a strong password or two-factor authentication.&lt;/p&gt;
              
      

              


  
    
    
    
    &lt;h2&gt;How an email alias actually helps&lt;/h2&gt;&lt;p&gt;The basic idea behind an email alias is simple: give each service its own address, rather than using the same one everywhere. This offers several advantages.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;You can identify who is passing on your data:&lt;/p&gt;&lt;p&gt;If you suddenly start receiving adverts at an alias that you’ve only given to a single provider, the source is clear. And you can simply deactivate that alias. The spam goes nowhere, whilst your main address and all your other alias addresses remain unaffected. Instead of moving your entire digital life, you simply close a single door.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;You can spot phishing attempts more quickly:&lt;/p&gt;&lt;p&gt;Let’s say you use a separate email alias for your bank that nobody else knows about. If you then receive an urgent ‘security warning from your bank’ at the address you’ve only ever given to a furniture shop, you can quickly identify the supposed email as &lt;a href="https://mailbox.org/en/blog/phishing-alarm-how-to-spot-fake-mailboxorg-emails/" data-entity-type="node" data-entity-uuid="2db1b30d-ccf2-40fb-bf08-b28a69e166ac" data-entity-substitution="canonical" title="Phishing alert: How to spot fake mailbox.org e-mails"&gt;phishing&lt;/a&gt;. The alias thus acts as an early-warning system for forgeries.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;You make it harder to build a profile:&lt;/p&gt;&lt;p&gt;If each service knows a different address for you, data brokers lack the common denominator that would allow them to link your activities. One large profile is broken down into many small, unconnected fragments. Email aliases are data minimisation in practice.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;They protect your access:&lt;/p&gt;&lt;p&gt;With many providers, the main address is also the login name. By not revealing this in the first place and instead communicating only via alias addresses, you significantly reduce the attack surface of your account. An attacker may then know an alias, but not your actual username.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;You gain a clearer overview:&lt;/p&gt;&lt;p&gt;If you use separate aliases for different areas of your life, you can have incoming messages automatically sorted into the appropriate folders using filter rules. This makes it easier to keep work, personal matters, shopping, etc. separate and to organise your inbox clearly.&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;As well as email aliases, there are other ways to protect your inbox. The aim – to protect your actual address – is the same, and they are often mentioned in the same breath, but they differ technically.&lt;/p&gt;

          
                                                  
      

  
    
      &lt;h2 class="accordion__headline"&gt;Three related tools to protect your main email address&lt;/h2&gt;
          
    
    
                        
            
              The email alias
              
                
              
            

            
              
                &lt;p&gt;This is an alias in the true sense of the word: a permanent additional address that you create deliberately and which is stored as a separate entry in your mailbox for various purposes. It is suitable for anything you intend to use in the long term, and can usually also be used for sending emails.&lt;/p&gt;
              
            
          
                                
            
              The Plus address or email extension
              
                
              
            

            
              
                &lt;p&gt;With a Plus address or &lt;a href="https://kb.mailbox.org/en/private/e-mail/mail-extensions/"&gt;mail extension&lt;/a&gt;, a suffix is appended to your existing address after a plus sign, for example, firstname+shop@example.org. Strictly speaking, this is a form of ‘sub-addressing’: you do not create an alias; instead, the mail server simply ignores everything after the plus sign during delivery, whilst the suffix is retained for filter rules.&lt;/p&gt;&lt;p&gt;Plus addresses are suitable for automatic sorting. However, they offer only limited protection against spam: professional data collectors are familiar with this principle and simply remove the suffix after the plus sign – thereby gaining access to your base address.&lt;/p&gt;
              
            
          
                                
            
              The disposable or one-off address
              
                
              
            

            
              
                &lt;p&gt;Disposable email addresses say it all in their name: a disposable email address is intended for a single occasion, such as signing up for a service where you don’t fully trust the provider.&lt;/p&gt;&lt;p&gt;Caution is advised when using temporary email services online, particularly regarding validity periods, data protection, security and the risk of being blocked by service providers. To find out how to use disposable email addresses with a trusted email provider such as mailbox, &lt;a href="https://mailbox.org/en/blog/how-disposable-addresses-protect-against-digital-threat/" data-entity-type="node" data-entity-uuid="ee09eda0-758d-4a59-bc38-323b7d7b4565" data-entity-substitution="canonical" title="Disposable email addresses: Protection from spam &amp;amp; data misuse"&gt;read our blog&lt;/a&gt;.&lt;/p&gt;
              
            
          
                  

  

              


  
    
    
    
    &lt;h2&gt;Email aliases with your custom domain&lt;/h2&gt;&lt;p&gt;If you take the alias concept to its logical conclusion, you’ll eventually reach the limits of your quota: most providers only allow a certain number of alias addresses. Having your own domain removes this restriction. If, for example, you register surname.de, you can create as many addresses as you like under it and consolidate them all into a single inbox: from firstname@lastname.com to shopping@lastname.com and club@lastname.com.&lt;/p&gt;&lt;p&gt;The benefits go beyond sheer quantity, as having your own domain makes you independent of your provider: if you switch providers one day, you can simply take your addresses with you, rather than having to set them up again everywhere. &lt;a href="https://mailbox.org/en/blog/email-adress-with-your-custom-domain/" data-entity-type="node" data-entity-uuid="b060164d-12d0-4068-ae62-e004982b9fc8" data-entity-substitution="canonical" title="Email address with your custom domain: introduction and tips"&gt;In our blog&lt;/a&gt;, you can find out more about the benefits of having your own email domain and how to set one up.&lt;/p&gt;&lt;h3&gt;Special case: ‘Catch-all alias’&lt;/h3&gt;&lt;p&gt;On your own domain, you can also activate a so-called catch-all address – a catch-all address that accepts every message sent to your domain, even those sent to addresses you’ve never set up. With catch-all enabled, emails sent to wifi@lastname.com end up in your inbox just as they would if sent to magazine@lastname.com, without you having to set up these addresses beforehand. This offers perhaps the most convenient way of handling aliases of all: you can simply come up with a suitable address on the spot for each service, whether at the checkout or on a registration form. If spam arrives at one of these addresses later, the source is immediately identifiable.&lt;/p&gt;&lt;p&gt;However, this convenience has a downside: because mail is delivered to absolutely every conceivable address, catch-all domains are a prime target for spammers who send common addresses such as info@ or contact@ to any domain. To get rid of a single leaked address, you’ll need to set up an exception.&lt;/p&gt;&lt;p&gt;A catch-all alias really comes into its own when you want to make the most of the full flexibility of your own domain. We show you how to set up a catch-all alias in mailbox &lt;a href="https://kb.mailbox.org/en/private/custom-domains/use-your-own-domain-with-catch-all/"&gt;in our Knowledge Base&lt;/a&gt;.&lt;/p&gt;

          
                                                  
      


  
          
        

  💡︎

      
        
    &lt;h2 class="highlight__title"&gt;Creating an email alias: The best way to go about it&lt;/h2&gt;    
    
      &lt;p&gt;Start small, rather than changing everything straight away. First, set up two or three themed alias addresses – for example, for shopping, newsletters and official correspondence – and add appropriate filter rules. You’ll soon notice how much quieter your inbox becomes.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;You don’t need to change every existing account retrospectively either. It makes more sense to start with the most important services and consistently register everything new using an email alias.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Make sure you reply from the correct sender address. If you respond to a message sent to an alias using your main address, you’ll be revealing it.&lt;/p&gt;
    
      

              


  
    
    
    
    &lt;h2&gt;Email alias at mailbox&lt;/h2&gt;&lt;p&gt;Spam is the result of a market in which email addresses are collected, traded and resold. Once your address has ended up in this cycle, it is almost impossible to get it out again. An email alias breaks this very pattern: it reveals who is passing on your data, can be disabled individually in the event of misuse, makes profiling and phishing more difficult, and, as an added bonus, keeps your inbox tidy.&lt;/p&gt;&lt;p&gt;If you use mailbox, all the tools described in this blog are already included. With the Standard and Premium plans, you can create, delete and recreate up to 25 aliases ending in @mailbox.org – not just for receiving, but also for sending emails. If you want maximum flexibility, you can also integrate your own domains and use 50 aliases for your own domains on the Standard plan and 250 on the Premium plan.&lt;/p&gt;

          
                                                  
      


  
    
      &lt;h2 class="ticket__title"&gt;How to set up and use email aliases in mailbox&lt;/h2&gt;
              

&lt;a data-component-id="boxy:knob" data-component-variant="tertiary" class="knob knob--tertiary" href="https://kb.mailbox.org/en/private/e-mail/what-is-an-alias-and-how-do-i-use-it/"&gt;Set up an email alias now&lt;/a&gt;

          
    
          
                  
              
                  &lt;img loading="lazy" height="1632" width="2912" src="https://mailbox.org/sites/default/files/2025-05/news-envelope-1.png" alt="Envelope"&gt;

  


    
  



      
      &lt;h2 class="row__intro__title"&gt;            Insights &amp;amp; Trends
      &lt;/h2&gt;
      Discover more articles on the topic of data protection.
              
            

&lt;a data-component-id="boxy:knob" data-component-variant="secondary" class="knob knob--secondary" href="https://mailbox.org/en/insights/"&gt;All articles&lt;/a&gt;

        
          
    
      
      
  
  
                    
                  
              
                  &lt;img loading="lazy" height="2160" width="4096" src="https://mailbox.org/sites/default/files/2026-08/mailbox%20EVAC%20Blog%20IT-Sicherheit%20kleine%20Unternehmen.jpeg" alt="mailbox EVAC Blog IT-Sicherheit kleine Unternehmen"&gt;

  


      
      
      
      Business Continuitiy, Security
    
    &lt;h3 class="snip__title"&gt;IT security: Why small businesses in particular are targeted by cyberattacks&lt;/h3&gt;
  &lt;a class="snip__arrow" href="https://mailbox.org/en/blog/IT-security-for-small-businesses/" aria-hidden="true"&gt;→&lt;/a&gt;
  &lt;a class="snip__link" href="https://mailbox.org/en/blog/IT-security-for-small-businesses/"&gt;Read more about &lt;em class="placeholder"&gt;IT security: Why small businesses in particular are targeted by cyberattacks&lt;/em&gt;&lt;/a&gt;


    
      
      
  
  
                    
                  
              
                  &lt;img loading="lazy" height="2160" width="4096" src="https://mailbox.org/sites/default/files/2026-08/mailbox%20EVAC%20Blog%20Business%20Continuity%20in%20der%20Lieferkette.jpeg" alt="mailbox EVAC Blog Business Continuity in der Lieferkette"&gt;

  


      
      
      
      Best practice, Business Continuitiy
    
    &lt;h3 class="snip__title"&gt;How to use business continuity as a competitive advantage in the supply chain&lt;/h3&gt;
  &lt;a class="snip__arrow" href="https://mailbox.org/en/blog/business-continuity-supply-chain/" aria-hidden="true"&gt;→&lt;/a&gt;
  &lt;a class="snip__link" href="https://mailbox.org/en/blog/business-continuity-supply-chain/"&gt;Read more about &lt;em class="placeholder"&gt;How to use business continuity as a competitive advantage in the supply chain&lt;/em&gt;&lt;/a&gt;


    
  
  


</description>
  <guid isPermaLink="false">87067ce5-7331-433e-8c51-0618e4be8140</guid>
    <pubDate>Tue, 04 Aug 2026 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Email alias: How to protect your email address from spam</dc:title>
    <dc:identifier>87067ce5-7331-433e-8c51-0618e4be8140</dc:identifier>
    </item>
<item>
  <title>The sovereign cloud: Who really has control over your data?</title>
  <link>https://mailbox.org/en/blog/sovereign-cloud-providers/</link>
  <description>&lt;p&gt;&lt;em&gt;Reading time: 11 minutes&lt;/em&gt;&lt;/p&gt;&lt;p&gt;Three American corporations currently process the majority of European corporate data. The cloud you use determines how much control you retain over your data – and how much you relinquish. This has implications for information security, data protection, compliance and your ability to act. Find out more in our article about how clouds work, the consequences of your choice of cloud provider, and what you can do to identify a sovereign cloud and make independent decisions about your data.&lt;/p&gt;


      
                  
              
              
              
              
              
              
              
                  &lt;img loading="lazy" height="4753" width="7121" src="https://mailbox.org/sites/default/files/2026-07/mailbox%20Blog%20Souvera%CC%88ne%20Cloud.jpeg" alt="mailbox Blog Souveräne Cloud"&gt;

  


  
          

              


  
    
    
    
    &lt;h2&gt;What is the cloud?&lt;/h2&gt;&lt;p&gt;The term ‘cloud’ sounds like something ethereal and hard to grasp. Yet it is actually something very concrete: a network of servers in data centres. When you save a file to the cloud, it is not stored on your local hard drive, but on a cloud provider’s servers.&lt;/p&gt;&lt;p&gt;The cloud allows you to outsource storage space and computing power. The servers used for this are accessible via the internet, and the data can be accessed from anywhere. Clouds also serve as backups or for sharing programmes. This allows flexible access for several people, who can, for example, edit documents together.&lt;/p&gt;&lt;h2&gt;What businesses and public authorities store in the cloud&lt;/h2&gt;&lt;p&gt;Which provider you choose and whether it is a sovereign cloud is crucial, as cloud services now process the majority of a business’s or public authority’s digital content:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Personal data: Sensitive data relating to staff, customers and citizens, e.g. payslips, customer databases or registration and social security data in the public sector&lt;br&gt;&amp;nbsp;&lt;/li&gt;&lt;li&gt;Business and trade secrets: Design plans, research findings, price calculations, draft contracts and similar&lt;br&gt;&amp;nbsp;&lt;/li&gt;&lt;li&gt;Communication data: Email threads, chat logs or video conference recordings, which often provide insights into internal decision-making processes&lt;br&gt;&amp;nbsp;&lt;/li&gt;&lt;li&gt;Identity and access data: Login credentials, certificates and keys&lt;br&gt;&amp;nbsp;&lt;/li&gt;&lt;li&gt;Particularly sensitive data categories: Health data, data held by domestic intelligence and security agencies, or data from judicial and social proceedings, as found primarily in the public sector and strictly regulated industries&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Four cloud models&lt;/h2&gt;&lt;p&gt;There are essentially four ways to use the cloud. Your choice of model and cloud provider has far-reaching consequences for cloud sovereignty and your control over your data:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;On-premises (On-Prem): Here, you use your own hardware on your own premises. As a company, for example, you own the servers, operate them yourself and bear full responsibility – and you have full control. The price you pay for this is a high level of in-house effort for hardware, maintenance, disaster recovery and security updates.&lt;br&gt;&amp;nbsp;&lt;/li&gt;&lt;li&gt;IaaS (Infrastructure as a Service): As an organisation, you rent computing power and storage space, but no longer need to worry about hardware, cooling or power supply. That falls within the remit of the IaaS providers. With this model, you bring in another organisation, which reduces your level of control – particularly if you use one of the US providers such as Amazon Web Services (AWS), Microsoft Azure or Google Cloud Platform.&lt;br&gt;&amp;nbsp;&lt;/li&gt;&lt;li&gt;PaaS (Platform as a Service): Here, the provider supplies an entire development platform, including databases, runtime environments and interfaces. Developers focus on their own application, whilst virtually everything is managed by the provider in the background. If you build your application deeply into provider-specific interfaces, you can only replicate it elsewhere at considerable expense. Control shifts noticeably towards the PaaS provider.&lt;br&gt;&amp;nbsp;&lt;/li&gt;&lt;li&gt;SaaS (Software as a Service): In this model, the provider takes care of everything: software, infrastructure, updates and security. All that remains for the company is to use the ready-made interface. Examples include Microsoft 365 and Google Workspace. This model is very convenient, but you have the least insight into what happens to your data. Users of this model should be particularly discerning when selecting their providers.&lt;/li&gt;&lt;/ul&gt;

          
                                                  
      


  
    
      &lt;h2 class="ticket__title"&gt;mailbox’s digital workplace is the sovereign alternative to Microsoft and Google.&lt;/h2&gt;
              

&lt;a data-component-id="boxy:knob" data-component-variant="tertiary" class="knob knob--tertiary" href="https://mailbox.org/en/business/"&gt;Discover the independent alternative&lt;/a&gt;

          
    
          
                  
              
                  &lt;img loading="lazy" height="1080" width="1440" src="https://mailbox.org/sites/default/files/2025-10/mailbox-drive-show.png" alt="mailbox drive: Alles an einem Ort"&gt;

  


    
  


  
    
      &lt;h2 class="accordion__headline"&gt;Data in focus: Four dimensions and their implications&lt;/h2&gt;
          
    
    
                        
            
              Data protection
              
                
              
            

            
              
                &lt;p&gt;A cloud provider processes large amounts of data and communications. This provides a detailed picture of the organisation: who communicates with whom, when, about what, and at what level in the hierarchy? From a data protection perspective, this increases the significance of every single vulnerability: a single instance of unauthorised access can reveal a coherent picture of the entire organisation.&lt;/p&gt;
              
            
          
                                
            
              Information security
              
                
              
            

            
              
                &lt;p&gt;From an information security perspective, the following applies: the more systems and data are held by a single provider, the greater the damage if something goes wrong. This concentration is exacerbated when a large proportion of the public sector or several industries rely on the same hyperscalers. This gives rise to what is known as a concentration risk.&lt;/p&gt;
              
            
          
                                
            
              Digital sovereignty
              
                
              
            

            
              
                &lt;p&gt;Administrative data in the public sector affects not only individual citizens, but also the very functioning of the state itself. If, for example, data and systems relating to local authority infrastructure are held by a provider subject to a foreign legal system, part of the state’s capacity to act is shifted to a foreign jurisdiction. The same applies to sensitive business data.&lt;/p&gt;
              
            
          
                                
            
              Cyber security
              
                
              
            

            
              
                &lt;p&gt;This concentration makes cloud infrastructures an attractive target for attack. If an attacker gains access to the central identity system of a major cloud provider, they could potentially gain access to the data of thousands of customer organisations simultaneously. This yields a significantly higher return than an attack on a single on-premises system.&lt;/p&gt;
              
            
          
                  

  

              


  
    
    
    
    &lt;h2&gt;Cloud sovereignty: Europe is dependent on the US&lt;/h2&gt;&lt;p&gt;Europe is structurally dependent on US hyperscalers: approximately 70 per cent of the EU market for cloud infrastructure is covered by AWS, Microsoft Azure and Google Cloud. Furthermore, US providers also dominate the productivity software sector, such as Microsoft 365. Microsoft currently has a virtual monopoly in the German public sector: Microsoft’s market share in Germany for Office products stands at over 90 per cent.&lt;/p&gt;&lt;p&gt;When deep-rooted dependence meets a non-transparent pricing model, the risk is exacerbated: Microsoft has, for instance, continuously increased the price of Microsoft 365 in recent years – including for the public sector. Furthermore, this one-sided dependency carries a higher risk of service disruption.&lt;/p&gt;&lt;p&gt;All the signs point to the need for greater digital self-determination. Yet it is precisely this deep-rooted dependency, resulting from the use of an entire IT ecosystem, that makes it so difficult to switch to other providers. This dependence, and the high potential for damage that comes with it, makes these applications – which are used almost universally in the public sector – attractive targets for cyber-attacks and a popular means of exerting pressure in geopolitical conflicts.&lt;/p&gt;

          
                                                  
      


  
          
        

  💡︎

      
        
        
    
      &lt;p&gt;What is a hyperscaler?&lt;br&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Cloud providers with vast resources for computing and storage power, as well as network infrastructure, are known as ‘hyperscalers’. Hyperscalers such as AWS, Google and Microsoft operate large-scale data centres distributed across the globe. Criticism of these corporations often centres on issues of digital sovereignty and data protection, market power and environmental impact.&lt;/p&gt;
    
      

              


  
    
    
    
    &lt;h2&gt;The truly sovereign cloud: distinguishing between server location and jurisdiction&lt;/h2&gt;&lt;p&gt;Cloud providers’ data centres are located in fixed locations and are therefore subject, on the one hand, to the law of the respective country. In addition, the company operating the infrastructure is subject to the law of the country in which it has its headquarters. For international corporations, this means that they are also subject to the law of the parent company, even if the operating subsidiary is formally registered in Europe.&lt;/p&gt;&lt;p&gt;When you save a file to Google Drive, you are storing it on one of the numerous servers that Google operates worldwide – including in Europe. If the file is stored in one of these European data centres, this may seem reassuring at first glance. Furthermore, the contractual partner for European customers is often a European Google subsidiary.&lt;/p&gt;&lt;p&gt;However, this company ultimately belongs to Google LLC, which is registered in the US and is, in turn, part of the US-based Alphabet Inc. The parent company to which you entrust your data is therefore subject to US law. Neither the server location nor even the address of the contracting company alters this overarching control. The same applies to Microsoft and AWS.&lt;/p&gt;

          
                                                  
      


  
          
        

  📍︎

      
        
        
    
      &lt;p&gt;Control over infrastructure therefore depends not primarily on the location of the data centre, but on the corporate structure and the registered office of the parent company with ultimate responsibility.&lt;/p&gt;
    
      

              


  
    
    
    
    &lt;h2&gt;US CLOUD Act: US law determines your data protection&lt;/h2&gt;&lt;p&gt;The US CLOUD Act (Clarifying Lawful Overseas Use of Data Act) has been in force since 2018. Under this law, US tech companies are obliged to grant US authorities access to data they store – even if the companies do not store the data in the US at all, but in Europe, for example. Under the law, IT companies may be prohibited from informing the individuals concerned. Users of these services may therefore not even be aware that they are affected by data access by US authorities.&lt;/p&gt;&lt;p&gt;A request from US authorities to Microsoft may therefore well concern the emails of a German organisation, even if the server is located in Germany and even if this contravenes the GDPR applicable in the EU. This structural dependence on US hyperscalers thus adds a further layer of dependence and poses a threat to Europe’s sovereignty.&lt;/p&gt;&lt;p&gt;In 2025, Microsoft’s then Head of Legal Affairs admitted under oath before the French Senate that the company cannot guarantee that European customer data is protected from access by US authorities – regardless of where the data is stored.&lt;/p&gt;&lt;p&gt;So-called ‘sovereign cloud’ offerings and European data centres do nothing to alter the fact that the US companies behind these services are ultimately subject to US law.&lt;/p&gt;&lt;h2&gt;When the digital plug is pulled, dependence and sovereignty come to light&lt;/h2&gt;&lt;p&gt;Furthermore, the US Supreme Court’s ruling in the ‘Trump v Slaughter’ case in June 2026 destroyed the foundation of transatlantic data protection: The ruling strengthens the powers of the US President and weakens the independence of the Federal Trade Commission (FTC), which is responsible for enforcing data protection principles in the US.&lt;/p&gt;&lt;p&gt;Another event from June 2026 shows that the control exercised by a foreign authority can extend to the very question of whether a service remains available at all: Anthropic, the US company behind the Claude models, was forced to disable access to two of its AI models on the direct orders of the US government. The software, which was already widely used, was subsequently no longer available worldwide.&lt;/p&gt;&lt;p&gt;A company that has built its processes on US IT infrastructure and is dependent on this ecosystem runs the risk of being rendered digitally incapacitated following an official directive from the US.&lt;/p&gt;

          
                                                  
      


  
          
        

  🛡

      
        
        
    
      &lt;p&gt;To eliminate this risk, you should choose a cloud provider based in Germany, which, as a company, is subject exclusively to German and European law.&lt;/p&gt;&lt;p&gt;&lt;br&gt;However, a cloud provider based in Germany does not automatically make a company fully GDPR-compliant. A provider must be able to demonstrate, through an independent audit, that it has the organisational measures in place required for reliable data protection and information security.&lt;/p&gt;
    
      

              


  
    
    
    
    &lt;h2&gt;The choice of cloud provider determines your independence&lt;/h2&gt;&lt;p&gt;If you hand over control of your infrastructure and data, you are giving up more than you might initially realise. Be clear about the areas where your digital sovereignty requires particularly critical decisions:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Technical: The choice of cloud model determines, to a considerable extent, the extent of your control over your data.&lt;br&gt;&amp;nbsp;&lt;/li&gt;&lt;li&gt;In terms of content: Be aware of which (sensitive) data you are entrusting to a cloud provider.&lt;br&gt;&amp;nbsp;&lt;/li&gt;&lt;li&gt;Legal: Check whether the cloud providers under consideration are subject to foreign law, e.g. the US CLOUD Act, and what impact this has on information security and data protection.&lt;br&gt;&amp;nbsp;&lt;/li&gt;&lt;li&gt;Political: When making your choice, bear in mind the consequences of geopolitical changes, the effects of which have long been felt. The Anthropic case illustrates that control affects not only data, but also the availability of a service.&lt;br&gt;&amp;nbsp;&lt;/li&gt;&lt;li&gt;Economic: Check whether your choice of cloud provider is leading you into digital dependency or even vendor lock-in, and take active steps to counteract this.&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Three key questions for identifying a sovereign cloud&lt;/h2&gt;&lt;p&gt;The market for sovereign cloud solutions is growing, and with it the number of providers who use sovereignty as a selling point without structurally delivering on it. European data centres, GDPR certificates and ‘sovereign cloud’ labels are no guarantee that a service is actually free from foreign legal jurisdiction.&lt;/p&gt;&lt;p&gt;Anyone who fails to check carefully runs the risk of falling for so-called ‘sovereignty washing’ – that is, an offering that suggests independence but does not deliver on it. Three key questions help to distinguish genuine sovereignty from supposed sovereignty:&lt;/p&gt;&lt;ol&gt;&lt;li&gt;Where is the parent company legally based?&lt;/li&gt;&lt;li&gt;Where is the data stored – and on whose infrastructure?&lt;/li&gt;&lt;li&gt;Is there verifiable evidence?&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;Make sure that behind the supposedly sovereign cloud lies a genuinely sovereign cloud, and that you do not fall victim to ‘sovereignty washing’. You can find support for this in the &lt;a href="https://techsov-catalogue.eu/"&gt;Tech Sovereignty Catalogue&lt;/a&gt;, Europe’s verified list for proven digital sovereignty. The catalogue helps to identify genuine European alternatives to Google, Microsoft and AWS. Providers listed in the Tech Sovereignty Catalogue must meet the &lt;a href="https://mailbox.org/en/blog/find-european-alternatives-to-google-and-microsoft/" data-entity-type="node" data-entity-uuid="e6fcf9aa-3a3d-40d8-9f95-594258e79050" data-entity-substitution="canonical" title="Moving away from the US cloud: Find European alternatives to Google and Microsoft"&gt;criteria of the catalogue&lt;/a&gt;.&lt;/p&gt;&lt;h2&gt;BSI C5: Guidance on evaluating cloud providers&lt;/h2&gt;&lt;p&gt;Digital sovereignty affects every business, every public authority and every individual. So choose your cloud provider carefully. The BSI C5 catalogue provides a reliable framework for evaluating cloud providers.&lt;/p&gt;&lt;p&gt;The Cloud Computing Compliance Criteria Catalogue (C5) of the Federal Office for Information Security (BSI) is explicitly tailored to cloud services: It assesses cloud-specific requirements across 17 criteria domains, including data localisation, client isolation, transparency regarding subcontractors and processing locations, and the ability to exit the service. For companies wishing to evaluate cloud providers in a structured manner, and for organisations operating in a regulated environment, a C5 certificate is therefore more meaningful than ISO 27001 certification alone.&lt;/p&gt;

          
                                                  
      


  
    
      &lt;h2 class="ticket__title"&gt; Find out more about our safety and quality standards&lt;/h2&gt;
              

&lt;a data-component-id="boxy:knob" data-component-variant="tertiary" class="knob knob--tertiary" href="https://mailbox.org/en/security/"&gt;Certified quality at mailbox&lt;/a&gt;

          
    
          
                  
              
                  &lt;img loading="lazy" height="816" width="1472" src="https://mailbox.org/sites/default/files/2025-04/mailbox-news-und-updates-sicherheit.jpg" alt="Schloss"&gt;

  


    
  



      
      &lt;h2 class="row__intro__title"&gt;            Insights &amp;amp; Trends
      &lt;/h2&gt;
      Discover more articles on the topic of data protection.
              
            

&lt;a data-component-id="boxy:knob" data-component-variant="secondary" class="knob knob--secondary" href="https://mailbox.org/en/insights/"&gt;All articles&lt;/a&gt;

        
          
    
      
      
  
  
                    
                  
              
                  &lt;img loading="lazy" height="4065" width="6098" src="https://mailbox.org/sites/default/files/2026-07/mailbox%20Blog%20E-Mail-Alias.jpeg" alt="mailbox Blog E-Mail-Alias"&gt;

  


      
      
      
      Best practice, Data protection
    
    &lt;h3 class="snip__title"&gt;Email alias: How to protect your email address from spam&lt;/h3&gt;
  &lt;a class="snip__arrow" href="https://mailbox.org/en/blog/email-alias-protection-against-spam/" aria-hidden="true"&gt;→&lt;/a&gt;
  &lt;a class="snip__link" href="https://mailbox.org/en/blog/email-alias-protection-against-spam/"&gt;Read more about &lt;em class="placeholder"&gt;Email alias: How to protect your email address from spam&lt;/em&gt;&lt;/a&gt;


    
      
      
  
  
                    
                  
              
                  &lt;img loading="lazy" height="3770" width="5700" src="https://mailbox.org/sites/default/files/2026-06/mailbox%20Blog%20Kostenlose%20E-Mail-Anbieter%20Datenschutz%20Wechsel.jpeg" alt="mailbox Blog Kostenlose E-Mail-Anbieter Datenschutz Wechsel"&gt;

  


      
      
      
      Best practice, Data protection
    
    &lt;h3 class="snip__title"&gt;Free email: What Gmail and the like really cost&lt;/h3&gt;
  &lt;a class="snip__arrow" href="https://mailbox.org/en/blog/what-free-email-really-costs/" aria-hidden="true"&gt;→&lt;/a&gt;
  &lt;a class="snip__link" href="https://mailbox.org/en/blog/what-free-email-really-costs/"&gt;Read more about &lt;em class="placeholder"&gt;Free email: What Gmail and the like really cost&lt;/em&gt;&lt;/a&gt;


    
  
  


</description>
  <guid isPermaLink="false">a24aa792-dac3-41f3-9b36-926010aadbdd</guid>
    <pubDate>Wed, 22 Jul 2026 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>The sovereign cloud: Who really has control over your data?</dc:title>
    <dc:identifier>a24aa792-dac3-41f3-9b36-926010aadbdd</dc:identifier>
    </item>
<item>
  <title>How to avoid shadow IT when your communication tools fail</title>
  <link>https://mailbox.org/en/blog/avoiding-shadow-IT-in-an-emergency/</link>
  <description>&lt;p&gt;&lt;em&gt;Reading time: 5 minutes&lt;/em&gt;&lt;/p&gt;&lt;p&gt;When the primary communication platform fails, staff often resort to personal accounts and improvised workarounds – so-called ‘shadow IT’. This ill-considered pragmatism poses risks to your organisation’s security and reputation. In our article, you will learn what the practical dangers of shadow IT are and why reliable emergency communication is a fundamental prerequisite for business continuity and reputation.&lt;/p&gt;


      
                  
              
              
              
              
              
              
              
                  &lt;img loading="lazy" height="4912" width="7360" src="https://mailbox.org/sites/default/files/2026-07/mailbox%20EVAC%20Blog%20Schatten-IT%20als%20Notfalllo%CC%88sung%20vermeiden.jpeg" alt="mailbox EVAC Blog Schatten-IT als Notfalllösung vermeiden"&gt;

  


  
          

              


  
    
    
    
    &lt;h2&gt;What shadow IT is and why an IT failure exacerbates it&lt;/h2&gt;&lt;p&gt;Shadow IT refers to the use of applications, services and accounts that have never been officially authorised. These might include a private email account, a messenger group set up on the spur of the moment, or a free file-sharing service for quick file exchanges. It becomes established unobtrusively in day-to-day working life, usually with the best of intentions and out of a desire to remain able to act in exceptional situations.&lt;/p&gt;&lt;p&gt;In the event of an acute crisis, however, the phenomenon intensifies dramatically. As soon as the central communication platform fails, numerous employees simultaneously begin to improvise – each using the first available channel. In such a situation, employees’ behaviour is fundamentally understandable: pragmatic, solution-oriented and, in the best sense of the word, committed. Yet within hours, these convenient shortcuts turn into an uncontrolled patchwork of parallel, unreliable and insecure communication channels, in which information security and data protection are the first casualties.&lt;/p&gt;&lt;h2&gt;GDPR and information security: Invisible risks&lt;/h2&gt;&lt;p&gt;At a technical level, the consequences of using shadow IT are severe. Customer data and confidential documents are sent unencrypted via private email accounts over which the company has neither access nor control. This is a clear breach of the requirements of the GDPR.&lt;/p&gt;&lt;p&gt;When shadow IT is used, data flows without proper traceability, without being backed up and without a regulated deletion process. Sensitive data may be transferred via the cloud to foreign jurisdictions – with unknown implications for data access rights by foreign authorities.&lt;/p&gt;&lt;p&gt;At the same time, the organisation loses track of which channel is actually the official one. Information thus becomes fragmented across an unknown number of private accounts.&lt;/p&gt;

          
                                                  
      


  
          
        

  💡︎

      
        
        
    
      &lt;p&gt;Attackers are well aware of this pattern of behaviour. They know that, following a publicised IT failure, people tend to improvise, and that in the resulting confusion, hardly anyone checks the actual source address of a message. It is precisely this state of emergency that provides the ideal breeding ground for phishing, &lt;a href="https://mailbox.org/en/blog/business-email-compromise-protection-against-email-fraud/" data-entity-type="node" data-entity-uuid="3a9f36b1-3f8a-4f84-8126-95585abf91e8" data-entity-substitution="canonical" title="Business Email Compromise: How to prevent email fraud"&gt;CEO fraud&lt;/a&gt; and identity theft. Cyberattacks or technical glitches therefore not only weaken defences but actively open up new vulnerabilities.&lt;/p&gt;
    
      

              


  
    
    
    
    &lt;h2&gt;Damage to reputation: The most lasting effect is felt by the recipient&lt;/h2&gt;&lt;p&gt;In a crisis situation, the recipients of the communication suffer damage that is often overlooked in the heat of the moment. It is worth shifting perspective: a business partner receives a message from an unknown private email address, accompanied by a request to return confidential contract documents to that very address.&lt;/p&gt;&lt;p&gt;How is he supposed to assess its authenticity? What will they make of this strategy? And what consequences will this have for the future business relationship? At best, the process appears disorganised and unprofessional. At worst, it resembles the very type of fraud that their own IT department regularly warns them about.&lt;/p&gt;&lt;p&gt;Every message improvised in this way conveys an unspoken message: this company does not have its processes under control. And this, of all times, during a crisis – precisely when customers, partners and authorities are scrutinising matters particularly closely and reliability is of the utmost importance. Trust that has been built up over many years suffers measurable damage at such moments.&lt;/p&gt;&lt;h2&gt;Communicating confidently despite a system failure&lt;/h2&gt;&lt;p&gt;A system failure scenario can also be approached differently: The primary communication tool has also failed, but staff communicate via a familiar and recognisable business address using their own company domain.&lt;/p&gt;&lt;p&gt;The key element is the use of a standardised, organisation-wide communication platform and the company’s own domain. A company’s own domain can be technically verified, it forms part of the brand and acts as an anchor of trust in external communications. Those who continue to communicate under their own name during an outage do not merely appear professional in spite of the crisis, but are all the more convincing precisely because of their confident handling of it.&lt;/p&gt;&lt;h2&gt;How to recognise a reliable emergency solution&lt;/h2&gt;&lt;p&gt;A prerequisite for communicating without losing trust in an emergency is a secondary communication platform that can be deployed immediately. Three characteristics determine whether such a solution will hold up in an emergency or whether it itself becomes a risk:&lt;/p&gt;&lt;h3&gt;1. Complete independence from the primary infrastructure&lt;/h3&gt;&lt;p&gt;An emergency solution operated on the same infrastructure or by the same provider as the primary IT system is highly likely to fail alongside it in an emergency. A ‘backup mailbox’ as an additional tenant within the same system does not provide a robust solution.&lt;/p&gt;&lt;p&gt;True independence means separate infrastructure and an independent operator. The secondary communication platform must not depend on the very system whose failure it is intended to compensate for. Only this consistent separation creates a resilient fallback option and thus a viable component of Business Continuity Management (BCM).&lt;/p&gt;

          
                                                  
      


  
    
      &lt;h2 class="ticket__title"&gt;Business Continuity Plan in accordance with BSI Standard 200-4&lt;/h2&gt;
              

&lt;a data-component-id="boxy:knob" data-component-variant="tertiary" class="knob knob--tertiary" href="https://mailbox.org/en/blog/business-continuity-plan-bsi-200-4-sme/"&gt;Start building your Business Continuity Plan now&lt;/a&gt;

          
    
          
                  
              
                  &lt;img loading="lazy" height="4283" width="6628" src="https://mailbox.org/sites/default/files/2026-04/Blog%20mailbox%20EVAC%20Gescha%CC%88ftsfortfu%CC%88hrungsplan%20nach%20BSI%20Standard%20200-4%20BCM%20fu%CC%88r%20KMU.jpeg" alt="Blog mailbox EVAC Business Continuity Plan according to BSI Standard 200-4 BCM for SMEs"&gt;

  


    
  

              


  
    
    
    
    &lt;h3&gt;2. Verified reliability in information security and data protection&lt;/h3&gt;&lt;p&gt;In an incident, an emergency platform processes the most sensitive data of all, such as ongoing customer communications, contracts or internal coordination under time pressure. It would be negligent, in this context of all things, to rely on a solution whose security level is merely claimed.&lt;/p&gt;&lt;p&gt;Verified reliability therefore means: confirmed by independent third parties, not merely assured by the provider. Recognised evidence such as the BSI C5 certificate or ISO 27001 certification demonstrates that information security is implemented in accordance with defined standards and is subject to external audits. In data protection, what counts is demonstrable GDPR compliance, including transparent statements about where and under which legislation data is processed.&lt;/p&gt;&lt;p&gt;This aspect not only provides technical protection but also delivers evidence that you can present to customers and partners. In the wake of &lt;a href="https://mailbox.org/en/blog/nis-2-implementation-act-germany-obligations-business-continuity/" data-entity-type="node" data-entity-uuid="39c7c4b3-4771-4a2d-be32-be147cb897ed" data-entity-substitution="canonical" title="NIS-2 Implementation Act Germany: Obligations &amp;amp; Business Continuity"&gt;NIS-2&lt;/a&gt;, robust security evidence is increasingly being demanded throughout the supply chain, even by companies that are not themselves subject to their national NIS-2 Implementation Acts. Verified reliability and business continuity are thus becoming a competitive advantage.&lt;/p&gt;&lt;h3&gt;3. Digital sovereignty as a strategic prerequisite&lt;/h3&gt;&lt;p&gt;An emergency solution should reduce dependencies, not create new ones. Anyone who, in an emergency, switches to a platform subject to a foreign jurisdiction – where data flows remain opaque or the terms of use can change at any time – is merely replacing one risk with another.&lt;/p&gt;&lt;p&gt;Digital sovereignty means retaining control over one’s own communications. Essential to digital sovereignty are hosting exclusively in Germany or the EU, data processing verifiably in accordance with European law only, open standards rather than vendor lock-in, and an operator that refrains from advertising, tracking and the monetisation of data.&lt;/p&gt;&lt;p&gt;Particularly when, during a crisis, so much lies beyond one’s own control, at least the emergency channel must remain entirely in one’s own hands. In the current debate on technological independence, digital sovereignty has long since become a strategic criterion.&lt;/p&gt;

          
                                                  
      


  
          
        

  ✔

      
        
        
    
      &lt;p&gt;When choosing your secondary communication platform, ensure that it is independent, verified, reliable and digitally sovereign, and that it allows communication under your own domain.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;mailbox was developed specifically to meet this set of requirements &lt;a href="https://mailbox.org/en/evac/" data-entity-type="node" data-entity-uuid="8d62b38c-25b3-4011-a5f2-de2d2e58cc87" data-entity-substitution="canonical" title="EVAC: Business continuity in an emergency"&gt;EVAC&lt;/a&gt;: A professional communication and collaboration platform that runs in the background and can be activated at the touch of a button in an emergency.&lt;/p&gt;
    
      

              


  
    
    
    
    &lt;h2&gt;Conclusion: Proactive planning means professionalism and resilience&lt;/h2&gt;&lt;p&gt;Resorting to shadow IT is, in principle, an understandable response in emergency situations. So offer your staff a better, reputable, secure and reliable alternative.&lt;/p&gt;&lt;p&gt;Those who have a contingency communication plan in place protect two things at once: data and reputation. Reliability and composure in a crisis are the result of thorough preparation. And this becomes immediately apparent at the crucial moment: in every message that remains professional and trustworthy even if the primary platform fails.&lt;/p&gt;

          
                                                  
      


  
    
      &lt;h2 class="ticket__title"&gt;How can your business remain operational in an emergency?&lt;/h2&gt;
              

&lt;a data-component-id="boxy:knob" data-component-variant="tertiary" class="knob knob--tertiary" href="https://mailbox.org/en/evac/"&gt;Discover EVAC by mailbox now&lt;/a&gt;

          
    
          
                  
              
                  &lt;img loading="lazy" height="1219" width="2200" src="https://mailbox.org/sites/default/files/2025-05/mailbox_evac_infrastruktur_web_rgb.jpg" alt="EVAC Button"&gt;

  


    
  



      
      &lt;h2 class="row__intro__title"&gt;            Insights &amp;amp; Trends
      &lt;/h2&gt;
      Discover more articles on the topic of business continuity.
              
            

&lt;a data-component-id="boxy:knob" data-component-variant="secondary" class="knob knob--secondary" href="https://mailbox.org/en/insights/"&gt;All articles&lt;/a&gt;

        
          
    
      
      
  
  
                    
                  
              
                  &lt;img loading="lazy" height="2160" width="4096" src="https://mailbox.org/sites/default/files/2026-08/mailbox%20EVAC%20Blog%20IT-Sicherheit%20kleine%20Unternehmen.jpeg" alt="mailbox EVAC Blog IT-Sicherheit kleine Unternehmen"&gt;

  


      
      
      
      Business Continuitiy, Security
    
    &lt;h3 class="snip__title"&gt;IT security: Why small businesses in particular are targeted by cyberattacks&lt;/h3&gt;
  &lt;a class="snip__arrow" href="https://mailbox.org/en/blog/IT-security-for-small-businesses/" aria-hidden="true"&gt;→&lt;/a&gt;
  &lt;a class="snip__link" href="https://mailbox.org/en/blog/IT-security-for-small-businesses/"&gt;Read more about &lt;em class="placeholder"&gt;IT security: Why small businesses in particular are targeted by cyberattacks&lt;/em&gt;&lt;/a&gt;


    
      
      
  
  
                    
                  
              
                  &lt;img loading="lazy" height="2160" width="4096" src="https://mailbox.org/sites/default/files/2026-08/mailbox%20EVAC%20Blog%20Business%20Continuity%20in%20der%20Lieferkette.jpeg" alt="mailbox EVAC Blog Business Continuity in der Lieferkette"&gt;

  


      
      
      
      Best practice, Business Continuitiy
    
    &lt;h3 class="snip__title"&gt;How to use business continuity as a competitive advantage in the supply chain&lt;/h3&gt;
  &lt;a class="snip__arrow" href="https://mailbox.org/en/blog/business-continuity-supply-chain/" aria-hidden="true"&gt;→&lt;/a&gt;
  &lt;a class="snip__link" href="https://mailbox.org/en/blog/business-continuity-supply-chain/"&gt;Read more about &lt;em class="placeholder"&gt;How to use business continuity as a competitive advantage in the supply chain&lt;/em&gt;&lt;/a&gt;


    
  
  


</description>
  <guid isPermaLink="false">b90536ef-164c-4f1d-977d-3e0bc70df148</guid>
    <pubDate>Wed, 15 Jul 2026 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>How to avoid shadow IT when your communication tools fail</dc:title>
    <dc:identifier>b90536ef-164c-4f1d-977d-3e0bc70df148</dc:identifier>
    </item>
<item>
  <title>mailbox plan adjustment: What’s changing in summer 2026</title>
  <link>https://mailbox.org/en/news/plan-adjustment-2026/</link>
  <description/>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2026-06/mailbox-news-und-updates-anku%CC%88ndigung.png?itok=CjJbt8r-" type="image/png" length="271781"/><guid isPermaLink="false">414dd82f-9136-4cbf-a5ff-9a710528b189</guid>
    <pubDate>Wed, 15 Jul 2026 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>mailbox plan adjustment: What’s changing in summer 2026</dc:title>
    <dc:identifier>414dd82f-9136-4cbf-a5ff-9a710528b189</dc:identifier>
    </item>
<item>
  <title>mailbox plan adjustment: What’s changing in summer 2026</title>
  <link>https://mailbox.org/en/news/plan-adjustment-2026/</link>
  <description/>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2026-06/mailbox-news-und-updates-anku%CC%88ndigung.png?itok=CjJbt8r-" type="image/png" length="271781"/><guid isPermaLink="false">414dd82f-9136-4cbf-a5ff-9a710528b189</guid>
    <pubDate>Wed, 15 Jul 2026 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>mailbox plan adjustment: What’s changing in summer 2026</dc:title>
    <dc:identifier>414dd82f-9136-4cbf-a5ff-9a710528b189</dc:identifier>
    </item>
<item>
  <title>Business Email Compromise: How to prevent email fraud</title>
  <link>https://mailbox.org/en/blog/business-email-compromise-protection-against-email-fraud/</link>
  <description>&lt;p&gt;&lt;em&gt;Reading time: 12 minutes&lt;/em&gt;&lt;/p&gt;&lt;p&gt;“Urgent bank transfer, please complete today.” – That is the subject line of the email sent by the managing director to the accountant. The tone seems familiar, the email signature is correct and the reason given sounds plausible. The conscientious employee transfers several thousand euros. But the managing director knows nothing about it, because this is not a genuine email, but a case of Business Email Compromise (BEC), a sophisticated and widespread form of cyber fraud. In our blog, you can find out how Business Email Compromise works, how AI exacerbates this cyber threat, and how you can protect yourself against this new generation of email fraud.&lt;/p&gt;


      
                  
              
              
              
              
              
              
              
                  &lt;img loading="lazy" height="4596" width="8688" src="https://mailbox.org/sites/default/files/2026-06/mailbox%20EVAC%20Blog%20Business%20Email%20Compromise.jpeg" alt="mailbox EVAC Blog Business Email Compromise E-Mail-Betrug"&gt;

  


  
          

              


  
    
    
    
    &lt;h2&gt;What is Business Email Compromise (BEC)?&lt;/h2&gt;&lt;p&gt;Business Email Compromise refers to a form of targeted email fraud in which attackers either take over genuine accounts or use deceptively genuine sender addresses to trick employees into carrying out fraudulent actions. The aim is to steal money, data or both.&lt;/p&gt;&lt;p&gt;Alongside ransomware, phishing and DDoS attacks, Business Email Compromise is one of the most financially damaging cyber threats. In Germany, according to the 2024 research report ‘Costs and Damage Caused by Cybercrime in Germany’ by the Federal Criminal Police Office (Bundeskriminalamt), the damage amounted to just under 110 million euros. The reason for the high success rate lies in psychology. BEC attacks exploit:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Authority: A message from the managing director or the CFO is not questioned.&lt;/li&gt;&lt;li&gt;Time pressure: “Please do this today” leaves no time to think.&lt;/li&gt;&lt;li&gt;Trust: Familiar names, correct signatures, plausible contexts and authentic-sounding phrasing.&lt;/li&gt;&lt;li&gt;Isolation: You are often asked to handle the matter ‘discreetly’.&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;CEO Fraud &amp;amp; Co: The most common BEC attack patterns&lt;/h2&gt;&lt;p&gt;Business Email Compromise is an umbrella term for various types of email fraud. Here is an overview of the most important ones:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;CEO Fraud (also known as ‘Fake President Fraud‘):&lt;/p&gt;&lt;p&gt;CEO Fraud is, so to speak, the classic example of a BEC attack. Attackers pose as senior management and instruct staff in the accounts or finance departments to make urgent bank transfers. They exploit employees’ loyalty and trust and put the victims under time pressure to bypass standard security procedures.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Invoice fraud:&lt;/p&gt;&lt;p&gt;This involves forging supplier emails and phone calls (‘Vendor impersonation‘) or genuine accounts are compromised in order to persuade employees to transfer funds to alternative bank accounts – either for payments that are actually due or for services that were never provided. Here, too, pressure is applied, for example through conspicuously short payment deadlines or the threat of debt collection proceedings and debt collection agencies.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Identity theft involving lawyers or consultants (‘Lawyer Impersonation‘):&lt;/p&gt;&lt;p&gt;In this scheme, cyber fraudsters assume the identity of an external individual who possesses information about confidential internal processes and projects. Here, too, the aim is to persuade staff to make bank transfers.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Data fraud or data theft (‘Data Theft via BEC‘):&lt;/p&gt;&lt;p&gt;In this type of cyber fraud, the specific aim is to steal data rather than money. The aim is to trick employees into sharing confidential data – such as HR and payroll data, login credentials, invoices and tax documents – in order to use this to launch larger-scale cyberattacks.&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Email fraud in the age of AI and deepfakes&lt;/h2&gt;&lt;p&gt;Until recently, Business Email Compromise could often be identified by certain details: unusual phrasing, a slightly different sender address, or a voice on the phone that sounded strange. Artificial intelligence has partially eliminated these tell-tale signs, and deepfakes such as voice cloning make them significantly harder to spot than before.&lt;/p&gt;&lt;p&gt;AI is thus taking email fraud to a whole new level of threat. According to the loss statistics report by Allianz Trade, losses from CEO fraud have tripled since 2024. The Federal Criminal Police Office (Bundeskriminalamt) also warns of this development in its ‘Federal Cybercrime Situation Report 2025’.&lt;/p&gt;&lt;p&gt;Attackers now use AI to combine multiple channels: an AI-generated email is followed by a vishing call with a cloned voice; in extreme cases, even a deepfake video call. The very factors that enable small and medium-sized enterprises (SMEs) to operate flexibly in their day-to-day business – such as flat hierarchies and short decision-making processes – become a vulnerability, particularly in the case of deepfake CEO fraud.&lt;/p&gt;

          
                                                  
      

  
    
      &lt;h2 class="accordion__headline"&gt;Key terms&lt;/h2&gt;
          
    
    
                        
            
              What is social engineering?
              
                
              
            

            
              
                &lt;p&gt;BEC does not involve the use of malware; instead, the attackers make use of social engineering. Social engineering is a method that exploits traits such as trust, a willingness to help, fear or curiosity to persuade people to disclose sensitive data, transfer money or grant unauthorised access to IT systems. The combination of social engineering and targeted deception used in BEC attacks is effective across all sectors and organisations of all sizes.&lt;/p&gt;
              
            
          
                                
            
              What is vishing?
              
                
              
            

            
              
                &lt;p&gt;The term ‘vishing’ combines ‘voice’ and ‘phishing’, meaning phishing via a phone call rather than by email. New-generation vishing attacks make use of AI voice cloning. Instead of a random, generic voice, employees hear a voice that sounds exactly like a person they know, such as their CEO or CFO.&lt;/p&gt;
              
            
          
                                
            
              What is email spoofing?
              
                
              
            

            
              
                &lt;p&gt;In email spoofing, the attacker forges the sender address of an email, with the result that the message appears deceptively genuine and appears to come from a known contact or a reputable service. Spoofing is easier to carry out if the targeted domain has not implemented strict authentication standards such as DMARC, DKIM and SPF.&lt;/p&gt;
              
            
          
                  

  

              


  
    
    
    
    &lt;h2&gt;How Business Email Compromise works: The four stages of a BEC attack&lt;/h2&gt;&lt;p&gt;A typical Business Email Compromise attack unfolds in several stages:&lt;/p&gt;&lt;h3&gt;Stage 1: Reconnaissance&lt;/h3&gt;&lt;p&gt;Business Email Compromise does not require malware, but it does require thorough preparation. Attackers research publicly available information, such as LinkedIn profiles, legal notices, press releases or organisational charts. The aim of this first phase is to understand who communicates with whom, who authorises payments and who responds to instructions from senior management.&lt;/p&gt;&lt;p&gt;With the help of AI, vast amounts of public data can now be analysed automatically – including social media posts, conference videos, podcast appearances and press photos. Audio and video material of senior executives – for example, from presentations, interviews or corporate videos – provides the raw material needed for subsequent voice or image cloning. Just a few seconds of publicly available voice recording are enough to replicate a voice with astonishing realism.&lt;/p&gt;&lt;h3&gt;Phase 2: Manipulation via email spoofing, vishing or account compromise&lt;/h3&gt;&lt;p&gt;Either a genuine email account is compromised through phishing, weak passwords or a lack of multi-factor authentication (MFA), or the sender’s address is forged using email spoofing.&lt;/p&gt;&lt;p&gt;Whilst phishing emails used to be easily recognisable by spelling mistakes or awkward phrasing, AI language models now make even this step easier: phishing emails designed to steal login credentials can be created in flawless, authentic German. The same applies to vishing.&lt;/p&gt;&lt;h3&gt;Phase 3: The actual BEC attack&lt;/h3&gt;&lt;p&gt;Using the previous steps, the attackers strike. They choose their timing and context carefully: just before holidays, on a Friday afternoon or during periods of high workload, the deceptively genuine-looking email or the phone call with the cloned voice reaches the victim.&lt;/p&gt;&lt;p&gt;In particularly elaborate cases, a video call is even included, in which not only the voice but also the face is synthetically generated in real time. This combination of multiple channels increases the psychological pressure on the victim: an email on its own can still be questioned, but a phone call featuring the supposedly familiar voice of senior management is much harder to doubt.&lt;/p&gt;&lt;h3&gt;Phase 4: Money laundering or data exfiltration&lt;/h3&gt;&lt;p&gt;Transferred sums are immediately channelled on – often across several countries. Depending on the timing and nature of the transfer, it is difficult or even impossible to reverse a transfer made as a result of email fraud. This final phase, too, is now increasingly automated: AI-powered systems distribute funds in a matter of seconds across numerous accounts and cryptocurrency wallets in various countries to cover their tracks and hinder investigations. The speed at which this happens often leaves banks and authorities with no time to stop a transaction.&lt;/p&gt;

          
                                                  
      


  
        
        
    
      &lt;p&gt;Important: The opportunities that artificial intelligence offers attackers today make prevention all the more important.&lt;/p&gt;
    
      

              


  
    
    
    
    &lt;h2&gt;Recognising email fraud: How to protect your business&lt;/h2&gt;&lt;p&gt;By implementing the right technical and organisational measures, you can significantly reduce the risk posed by business email compromise and AI-powered fraud attempts:&lt;/p&gt;&lt;h3&gt;Technical safeguards&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;Email authentication with DMARC, DKIM and SPF:&lt;/p&gt;&lt;p&gt;DMARC (Domain-based Message Authentication, Reporting &amp;amp; Conformance), DKIM (DomainKeys Identified Mail) and SPF (Sender Policy Framework) are fundamental safeguards against email spoofing. Ensure that these standards are fully and correctly configured so that attackers cannot exploit your domain for CEO fraud without being detected.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Multi-factor authentication (MFA) for all email accounts:&lt;/p&gt;&lt;p&gt;MFA helps to prevent a significant proportion of BEC attacks that rely on compromised login credentials. Precisely because AI-powered phishing emails are so convincingly worded these days, the likelihood of employees entering their login credentials is increasing. This makes multi-factor authentication even more important. You should therefore adopt “No account without a second factor” as your email security principle.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Anomaly detection and alerting:&lt;/p&gt;&lt;p&gt;Modern email security solutions detect unusual patterns, such as logins from unknown locations, suspicious forwarding rules or mass downloads of mailbox contents. They utilise AI to identify linguistic anomalies, atypical communication patterns or irregularities in writing style and metadata. This protective measure gives you a head start: if you are alerted at an early stage, you can intervene before any damage occurs.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;A robust email infrastructure as the foundation of security:&lt;/p&gt;&lt;p&gt;If your email communication runs on an infrastructure with high security standards, data stored exclusively in Germany or Europe, transparent security configuration options and no dependencies on US hyperscalers, this further enhances your control over your data.&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;

          
                                                  
      


  
    
      &lt;h2 class="ticket__title"&gt;This is how mailbox ensures your security&lt;/h2&gt;
              

&lt;a data-component-id="boxy:knob" data-component-variant="tertiary" class="knob knob--tertiary" href="https://mailbox.org/en/security/"&gt;Email security at mailbox&lt;/a&gt;

          
    
          
                  
              
                  &lt;img loading="lazy" height="816" width="1472" src="https://mailbox.org/sites/default/files/2025-04/mailbox-news-und-updates-sicherheit.jpg" alt="Schloss"&gt;

  


    
  

              


  
    
    
    
    &lt;h3&gt;Organisational protective measures&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;Regular training and simulations:&lt;/p&gt;&lt;p&gt;Employees are the gateway for cyber fraud. This makes them the most effective line of defence – provided they are well prepared. Regular BEC, voice and deepfake simulations, along with training on recognising social engineering, measurably increase the detection rate of vishing and similar attacks.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Clear communication protocols:&lt;/p&gt;&lt;p&gt;Set out which requests may be made by email and which may not. Who is authorised to authorise payments, and via which channel? Which types of payment instructions are never authorised exclusively by telephone or video call, regardless of how convincing the voice or image may seem? The clearer these rules are, the easier it is to spot deviations – and thus (AI-powered) BEC attacks.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Dual-control principle for payments:&lt;/p&gt;&lt;p&gt;Do not authorise any payment order above a defined threshold without a second approval. This principle must also apply even if an instruction appears to have already been verified (e.g. via a phone call); otherwise, a convincing voice clone in a vishing attack could circumvent precisely this second level of control if staff believe verification has already taken place. The dual-control principle helps you prevent the majority of BEC-related losses in the areas of CEO fraud and invoice fraud.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Obligation to call back in the event of unusual enquiries:&lt;/p&gt;&lt;p&gt;If the accounts department receives an unusual instruction – even if it appears to come from senior management – the following rule should apply: Under no circumstances should you confirm by replying to the same email; always verify by telephone.&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;

          
                                                  
      


  
        
        
    
      &lt;p&gt;Caution regarding call-back rules and vishing: Caution is advised due to the increasing number of AI-assisted fraud attempts. Call-back verification can become less effective if not only the email is forged, but the voice on the other end of the line is also cloned. You should therefore supplement the measures described with additional verification steps, such as code words and security questions, or tests during video calls – which many deepfake tools still fail at today – for example, asking the person to briefly hold their hand in front of their face or turn their head.&lt;/p&gt;
    
      

              


  
    
    
    
    &lt;h2&gt;Why government bodies, local authorities and public administrations are in the spotlight&lt;/h2&gt;&lt;p&gt;Business Email Compromise affects companies, but it is not solely a problem for the private sector. Public administrations, local authorities and government bodies are also attractive targets for cyberattacks via email:&lt;/p&gt;

          
                                                  
      

    
          
        &lt;h2 class="mosaic__title"&gt;
                    1. Publicly documented processes
        &lt;/h2&gt;
        &lt;p&gt;Anyone who knows how an authority communicates internally or what payment schedules apply to projects can create deceptively genuine enquiries.&lt;/p&gt;
              
          
        &lt;h2 class="mosaic__title"&gt;
                    2. Lack of cybersecurity resources
        &lt;/h2&gt;
        &lt;p&gt;Many public authorities lack the technical and human resources required for effective IT security. This also affects security training for staff.&lt;/p&gt;
              
          
        &lt;h2 class="mosaic__title"&gt;
                    3. High transaction volumes
        &lt;/h2&gt;
        &lt;p&gt;Whether it’s subsidy payments, construction costs or grant funding: transaction volumes in the public sector are often very high.&lt;/p&gt;
              
      

              


  
    
    
    
    &lt;p&gt;The German Federal Office for Information Security (Bundesamt für Sicherheit in der Informationstechnik, BSI) therefore explicitly recommends that public authorities and administrative bodies make the implementation of email authentication standards such as DMARC, DKIM and SPF mandatory, and regularly train staff to recognise cyberattacks.&lt;/p&gt;&lt;h2&gt;Business continuity following a cyber attack&lt;/h2&gt;&lt;p&gt;Whether through traditional business email compromise or using deepfakes, even well-prepared organisations can fall victim to a BEC attack. If internal systems or communication channels need to be isolated as a result, the question arises as to how your organisation can still remain operational. As part of your Business Continuity Management (BCM), you must ensure that critical communication processes continue to run even if the primary infrastructure is compromised or temporarily unavailable in the wake of an incident.&lt;/p&gt;&lt;p&gt;This also applies to scenarios in which the communication channels themselves become a weapon: If an email account has been compromised, a voice cloned or a video call spoofed, it is often only after a thorough investigation that it can be determined which internal systems are still trustworthy and which need to be isolated as a precaution. It is precisely during this phase of uncertainty that the extent of the damage caused by an attack is determined. If you are then left without a reliable communication channel, you lose time and the ability to investigate the incident in a coordinated manner.&lt;/p&gt;&lt;p&gt;In this context, business continuity specifically means: maintaining communication, when the primary communication system cannot or must not be used, for example because it is unclear whether an account remains under the attackers’ control. To do this, you need a system that is completely independent of the compromised primary system and &lt;a href="https://mailbox.org/en/evac/" data-entity-type="node" data-entity-uuid="8d62b38c-25b3-4011-a5f2-de2d2e58cc87" data-entity-substitution="canonical" title="EVAC: Business continuity in an emergency"&gt;secondary communication platform that is ready for immediate use&lt;/a&gt;, enabling you to coordinate crisis management without having to rely on channels that may have been compromised. Only then can you keep staff, customers, authorities and partners informed and facilitate forensic analysis and incident response.&lt;/p&gt;

          
                                                  
      


  
        
        
    
      &lt;p&gt;Ensure business continuity: Organisations that neglect this aspect lose valuable time after a BEC or deepfake attack when it comes to minimising damage and restoring trust.&lt;/p&gt;
    
      

              


  
    
    
    
    &lt;h2&gt;Conclusion: You can protect yourself against Business Email Compromise&lt;/h2&gt;&lt;p&gt;In the various forms of BEC, attackers exploit deeply human traits and capitalise on the fact that email is generally regarded as trustworthy. By combining the following measures, you can minimise your organisation’s vulnerability:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Technical safeguards that make email spoofing and account takeovers more difficult (SPF, DKIM, DMARC, MFA),&lt;/li&gt;&lt;li&gt;organisational processes that intercept suspicious requests before they cause damage,&lt;/li&gt;&lt;li&gt;regular, AI-informed staff training, enabling employees to recognise email fraud,&lt;/li&gt;&lt;li&gt;a secure, GDPR-compliant &lt;a href="https://mailbox.org/en/news/bsi-awards-mailbox-the-gold-status/" data-entity-type="node" data-entity-uuid="6cad208b-281b-4192-815d-dbf0d8785061" data-entity-substitution="canonical" title="BSI gold status for mailbox"&gt;email infrastructure&lt;/a&gt;, which offers no unnecessary vulnerabilities,&lt;/li&gt;&lt;li&gt;and a business continuity strategy that ensures operations continue even in the event of an emergency.&lt;/li&gt;&lt;/ul&gt;

          
                                                  
      


  
    
      &lt;h2 class="ticket__title"&gt;How can your business remain operational in an emergency?&lt;/h2&gt;
              

&lt;a data-component-id="boxy:knob" data-component-variant="tertiary" class="knob knob--tertiary" href="https://mailbox.org/en/evac/"&gt;Learn more now&lt;/a&gt;

          
    
          
                  
              
                  &lt;img loading="lazy" height="1219" width="2200" src="https://mailbox.org/sites/default/files/2025-05/mailbox_evac_infrastruktur_web_rgb.jpg" alt="EVAC Button"&gt;

  


    
  



      
      &lt;h2 class="row__intro__title"&gt;            Insights &amp;amp; Trends
      &lt;/h2&gt;
      Discover more articles on the topic of security.
              
            

&lt;a data-component-id="boxy:knob" data-component-variant="secondary" class="knob knob--secondary" href="https://mailbox.org/en/insights/"&gt;All articles&lt;/a&gt;

        
          
    
      
      
  
  
                    
                  
              
                  &lt;img loading="lazy" height="4065" width="6098" src="https://mailbox.org/sites/default/files/2026-07/mailbox%20Blog%20E-Mail-Alias.jpeg" alt="mailbox Blog E-Mail-Alias"&gt;

  


      
      
      
      Best practice, Data protection
    
    &lt;h3 class="snip__title"&gt;Email alias: How to protect your email address from spam&lt;/h3&gt;
  &lt;a class="snip__arrow" href="https://mailbox.org/en/blog/email-alias-protection-against-spam/" aria-hidden="true"&gt;→&lt;/a&gt;
  &lt;a class="snip__link" href="https://mailbox.org/en/blog/email-alias-protection-against-spam/"&gt;Read more about &lt;em class="placeholder"&gt;Email alias: How to protect your email address from spam&lt;/em&gt;&lt;/a&gt;


    
      
      
  
  
                    
                  
              
                  &lt;img loading="lazy" height="4753" width="7121" src="https://mailbox.org/sites/default/files/2026-07/mailbox%20Blog%20Souvera%CC%88ne%20Cloud.jpeg" alt="mailbox Blog Souveräne Cloud"&gt;

  


      
      
      
      Data protection
    
    &lt;h3 class="snip__title"&gt;The sovereign cloud: Who really has control over your data?&lt;/h3&gt;
  &lt;a class="snip__arrow" href="https://mailbox.org/en/blog/sovereign-cloud-providers/" aria-hidden="true"&gt;→&lt;/a&gt;
  &lt;a class="snip__link" href="https://mailbox.org/en/blog/sovereign-cloud-providers/"&gt;Read more about &lt;em class="placeholder"&gt;The sovereign cloud: Who really has control over your data?&lt;/em&gt;&lt;/a&gt;


    
  
  


</description>
  <guid isPermaLink="false">3a9f36b1-3f8a-4f84-8126-95585abf91e8</guid>
    <pubDate>Mon, 29 Jun 2026 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Business Email Compromise: How to prevent email fraud</dc:title>
    <dc:identifier>3a9f36b1-3f8a-4f84-8126-95585abf91e8</dc:identifier>
    </item>
<item>
  <title>Free email: What Gmail and the like really cost</title>
  <link>https://mailbox.org/en/blog/what-free-email-really-costs/</link>
  <description>&lt;p&gt;&lt;em&gt;Reading time: 6 minutes&lt;/em&gt;&lt;/p&gt;&lt;p&gt;Millions of people use free email services every day, like Gmail, GMX or WEB.DE. What looks like a good deal at first glance is actually based on a business model that primarily benefits the provider. If you understand how the business model behind free email providers works, you can make more informed decisions. In this article, you’ll find out what lies behind supposedly free services, where the specific data protection risks lie, and what you should bear in mind when switching to a secure, ad-free email account.&lt;/p&gt;


      
                  
              
              
              
              
              
              
              
                  &lt;img loading="lazy" height="3770" width="5700" src="https://mailbox.org/sites/default/files/2026-06/mailbox%20Blog%20Kostenlose%20E-Mail-Anbieter%20Datenschutz%20Wechsel.jpeg" alt="mailbox Blog Kostenlose E-Mail-Anbieter Datenschutz Wechsel"&gt;

  


  
          

              


  
    
    
    
    &lt;h2&gt;What your inbox says about you&lt;/h2&gt;&lt;p&gt;Take a look back at your email account over the past few months: It contains personal correspondence with family and friends, as well as booking confirmations and payslips, possibly job application documents, and correspondence with doctors, insurance companies or solicitors.&lt;/p&gt;&lt;p&gt;Your email account is one of the most private digital spaces there is. The question of who you entrust this account to, and what financial interest the provider has in exploiting its contents, thus becomes a decision about your own digital sovereignty.&lt;/p&gt;&lt;h2&gt;The business model behind free email&lt;/h2&gt;&lt;p&gt;When a service is free, an obvious question arises: How does the provider make money? In Google’s case, the answer is clear: three-quarters of Alphabet’s total revenue comes from Google advertising. For the full year 2025, Alphabet’s revenue stood at just under 403 billion US dollars. Advertising is not a sideline, but forms the foundation of the US corporation.&lt;/p&gt;&lt;p&gt;This lucrative business thrives on one raw material: knowledge about users that is as precise as possible: Who are they? What are they interested in? How do they behave online? – The more a provider knows about the users of its service, the more valuable an advert placement becomes. An email account used daily, containing personal correspondence, order confirmations and appointment reminders, is a rich source of information in this context, enabling personalised advertising.&lt;/p&gt;&lt;h2&gt;Google and data protection: What Google does with your emails and data&lt;/h2&gt;&lt;p&gt;Google offers a comprehensive suite of services including email, calendar, cloud storage, login and other services. When you use these services, Google collects the content that is created, uploaded or received from others, including emails sent and received. This means that even if you do not use Gmail yourself, but are merely the sender, the content you send is still collected and processed by Google.&lt;/p&gt;&lt;p&gt;Emails themselves are not specifically searched or read for the purpose of displaying personalised adverts. Personalised adverts are based on online activities that users carry out whilst signed in to Google. This is because Google collects metadata such as location or devices used, from which personal profiles can be created.&lt;/p&gt;&lt;p&gt;The aforementioned ecosystem comprising email, the cloud, YouTube, Google Maps, Android and login services is therefore the level at which the actual data potential for Google unfolds: For personalised advertising, activities are analysed in order to present tailored adverts across Google services such as Search and YouTube.&lt;/p&gt;

          
                                                  
      


  
        
        
    
      &lt;p&gt;All these touchpoints feed into an account-linked user profile. Anyone with a Gmail account is therefore constantly under the scrutiny of a commercial profiling system – even if the actual content of their emails is officially left out of the equation. This is precisely why the term ‘free email’ is not accurate in this context: ultimately, within the Google ecosystem, you pay with your own user data, which Google turns into hard cash for itself.&lt;/p&gt;
    
      

              


  
    
    
    
    &lt;h2&gt;GMX and WEB.DE: European, but funded by advertising&lt;/h2&gt;&lt;p&gt;Those who have concerns about Google’s data protection policies often switch to a German email provider, such as WEB.DE or GMX. Both are owned by the German company United Internet AG, are subject to German data protection law and are regarded as an alternative to US corporations.&lt;/p&gt;&lt;p&gt;Many people overlook the fact that free email accounts with GMX and WEB.DE are also funded by advertising. According to United Internet’s annual report, in 2025 around 39 million ad-supported free accounts formed a large pool for monetisation through advertising and e-commerce. The further development of data-driven business models is explicitly cited in the report as a key focus of the previous year. The more precise a user profile is, the more money can be generated through the sale of advertising space. The same therefore applies to GMX and WEB.DE: here, an email service is provided in exchange for data analysis.&lt;/p&gt;&lt;h2&gt;The US CLOUD Act and the GDPR: Why the location of the headquarters is crucial&lt;/h2&gt;&lt;p&gt;For users in the EU, the GDPR provides important safeguards – but it does not apply fully in every scenario. The crucial point regarding email data protection concerns the origin of the providers: the US CLOUD Act allows US authorities to access data stored by US companies – regardless of where it is stored. Even if data is stored in a data centre in Germany or elsewhere in Europe, US authorities can access it as long as the provider is a US company or is under US control.&lt;/p&gt;&lt;p&gt;US CLOUD Act requests are often accompanied by non-disclosure orders. The US provider is legally prohibited from informing the European customer whose data is affected. For German email providers such as GMX and WEB.DE, this specific US risk does not apply. However, the core problem of advertising-based funding remains.&lt;/p&gt;

          
                                                  
      


  
    
      &lt;h2 class="ticket__title"&gt;Identifying European alternatives to Google and Microsoft&lt;/h2&gt;
              

&lt;a data-component-id="boxy:knob" data-component-variant="tertiary" class="knob knob--tertiary" href="https://mailbox.org/en/blog/find-european-alternatives-to-google-and-microsoft/"&gt;Leave the US cloud now&lt;/a&gt;

          
    
          
                  
              
                  &lt;img loading="lazy" height="5461" width="8192" src="https://mailbox.org/sites/default/files/2026-04/mailbox%20Blog%20Europa%CC%88ische%20Alternativen%20zu%20Microsoft%20und%20Google.jpeg" alt="mailbox Blog Europäische Alternativen zu Microsoft und Google"&gt;

  


    
  

              


  
    
    
    
    &lt;h2&gt;A different approach is possible: privacy-friendly email providers&lt;/h2&gt;&lt;p&gt;The business model of privacy-friendly email providers is based on a monthly subscription. There is no tracking, no advertising-based funding and no data-driven marketing. Because operations are not cross-subsidised by advertising, there is no structural incentive to exploit data. The headquarters and data centres of independent providers are located in Europe – or, better still, within the EU – meaning they are subject to strict EU data protection regulations, such as the GDPR.&lt;/p&gt;&lt;p&gt;As a German, tracking-free provider, mailbox also follows this model: our data centres are located exclusively in Germany and we are subject solely to German and EU law. As part of the Heinlein Group, we have been committed to secure and independent communication, data protection and information security for over 30 years.&lt;/p&gt;&lt;h2&gt;Switching email providers: How to make the transition&lt;/h2&gt;&lt;p&gt;Anyone who decides to switch to a privacy-friendly email provider in order to use an ad-free email account faces a practical question: How do I go about it without losing anything? With the right steps, the switch can be easily planned and carried out:&lt;/p&gt;

          
                                                  
      

    
          
        &lt;h2 class="mosaic__title"&gt;
                    1. Choosing the right email provider
        &lt;/h2&gt;
        &lt;p&gt;The operator should be based in a country with robust data protection legislation and its business model should be transparently based on a subscription, not on advertising. A look at the privacy policy and the company’s history will provide further information.&lt;/p&gt;
              
          
        &lt;h2 class="mosaic__title"&gt;
                    2. Back up your data &amp;amp; set up a new account
        &lt;/h2&gt;
        &lt;p&gt;Back up what’s important to you from your old account: export your emails, contacts and calendar entries, and import them into your new provider. Many email services offer free migration tools to handle this transfer for you.&lt;/p&gt;
              
          
        &lt;h2 class="mosaic__title"&gt;
                    3. Set up forwarding &amp;amp; inform your contacts
        &lt;/h2&gt;
        &lt;p&gt;Set up an automatic forwarding from your old email account to your new address. Then work your way through your services systematically: banks, insurance companies and payment services take priority, followed by subscriptions, online shops, etc.&lt;/p&gt;
              
          
        &lt;h2 class="mosaic__title"&gt;
                    4. Allow for a transition period &amp;amp; close your old account
        &lt;/h2&gt;
        &lt;p&gt;Allow for a generous transition period. This will ensure you don’t overlook any services that haven’t yet been migrated. Only close the old email account once this is complete. You also have the option of requesting GDPR-compliant data deletion for this purpose.&lt;/p&gt;
              
      



  
        
        
    
      &lt;p&gt;Tip: Don’t rush into anything. If you close your old email account too soon, you risk losing access to services that are still linked to your old address.&lt;/p&gt;
    
      

              


  
    
    
    
    &lt;h2&gt;Conclusion: Digital sovereignty starts in your inbox&lt;/h2&gt;&lt;p&gt;There are differences between a US corporation that displays adverts based on cross-account user profiles and a German email provider that does the same to fund its advertising, but without being subject to US jurisdiction. Nevertheless, the underlying principle is the same: users are used to generate advertising revenue.&lt;/p&gt;&lt;p&gt;Your email account contains a wealth of sensitive data and provides insights into your personal and professional life. So make an informed and critical decision about whose hands you entrust this data to.&lt;/p&gt;

          
                                                  
      


  
    
      &lt;h2 class="ticket__title"&gt;Your move to mailbox&lt;/h2&gt;
              

&lt;a data-component-id="boxy:knob" data-component-variant="tertiary" class="knob knob--tertiary" href="https://mailbox.org/en/move-mailbox-migrate-your-emails-securely/"&gt;Migrating emails securely&lt;/a&gt;

          
    
          
                  
              
                  &lt;img loading="lazy" height="1632" width="2912" src="https://mailbox.org/sites/default/files/2025-05/news-envelope-1.png" alt="Envelope"&gt;

  


    
  



      
      &lt;h2 class="row__intro__title"&gt;            Insights &amp;amp; Trends
      &lt;/h2&gt;
      Discover more articles on the topic of data protection.
              
            

&lt;a data-component-id="boxy:knob" data-component-variant="secondary" class="knob knob--secondary" href="https://mailbox.org/en/insights/"&gt;All articles&lt;/a&gt;

        
          
    
      
      
  
  
                    
                  
              
                  &lt;img loading="lazy" height="4065" width="6098" src="https://mailbox.org/sites/default/files/2026-07/mailbox%20Blog%20E-Mail-Alias.jpeg" alt="mailbox Blog E-Mail-Alias"&gt;

  


      
      
      
      Best practice, Data protection
    
    &lt;h3 class="snip__title"&gt;Email alias: How to protect your email address from spam&lt;/h3&gt;
  &lt;a class="snip__arrow" href="https://mailbox.org/en/blog/email-alias-protection-against-spam/" aria-hidden="true"&gt;→&lt;/a&gt;
  &lt;a class="snip__link" href="https://mailbox.org/en/blog/email-alias-protection-against-spam/"&gt;Read more about &lt;em class="placeholder"&gt;Email alias: How to protect your email address from spam&lt;/em&gt;&lt;/a&gt;


    
      
      
  
  
                    
                  
              
                  &lt;img loading="lazy" height="4753" width="7121" src="https://mailbox.org/sites/default/files/2026-07/mailbox%20Blog%20Souvera%CC%88ne%20Cloud.jpeg" alt="mailbox Blog Souveräne Cloud"&gt;

  


      
      
      
      Data protection
    
    &lt;h3 class="snip__title"&gt;The sovereign cloud: Who really has control over your data?&lt;/h3&gt;
  &lt;a class="snip__arrow" href="https://mailbox.org/en/blog/sovereign-cloud-providers/" aria-hidden="true"&gt;→&lt;/a&gt;
  &lt;a class="snip__link" href="https://mailbox.org/en/blog/sovereign-cloud-providers/"&gt;Read more about &lt;em class="placeholder"&gt;The sovereign cloud: Who really has control over your data?&lt;/em&gt;&lt;/a&gt;


    
  
  


</description>
  <guid isPermaLink="false">fb5babd7-02d2-4162-a473-017ae6c8a678</guid>
    <pubDate>Tue, 23 Jun 2026 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Free email: What Gmail and the like really cost</dc:title>
    <dc:identifier>fb5babd7-02d2-4162-a473-017ae6c8a678</dc:identifier>
    </item>
<item>
  <title>Email encryption in companies: Turning awareness into a real safety culture</title>
  <link>https://mailbox.org/en/blog/e-mail-encryption-for-companies-and-authorities/</link>
  <description>&lt;p&gt;&lt;em&gt;Reading time: 7 minutes&lt;/em&gt;&lt;/p&gt;&lt;p&gt;Many organisations assume that their emails are transmitted securely. But between sending and receiving a message, there are several points at which content can be intercepted, read or manipulated. Email encryption provides protection at precisely these points – provided it is used correctly and utilised by employees. This article shows what companies and authorities can actually do.&lt;/p&gt;


      
                  
              
              
              
              
              
              
              
                  &lt;img loading="lazy" height="2160" width="4096" src="https://mailbox.org/sites/default/files/2026-05/mailbox%20Blog%20E-Mail-Verschlu%CC%88sselung%20in%20Organisationen%20etablieren.jpeg" alt="mailbox E-Mail-Verschlüsselung in Organisationen etablieren"&gt;

  


  
          

              


  
    
    
    
    &lt;h2&gt;Unencrypted emails: postcards that anyone can read&lt;/h2&gt;&lt;p&gt;An unencrypted email is like a postcard: the content is exposed and whoever gets hold of it on the way to the recipient can read it. In times of digital communication, this sounds abstract – but it describes pretty accurately what happens technically when organisations communicate without adequate protection.&lt;/p&gt;&lt;p&gt;E-mails pass through several servers and network nodes on their way to the recipient. At each of these points, there is always the possibility of messages being intercepted, copied or manipulated. This is not always done by external attackers – incorrect configurations, compromised servers or insecure WLAN connections also open doors that are better left closed. It is worth taking a closer look at how exactly attackers go about this and what risks are lurking in everyday life.&lt;/p&gt;&lt;h2&gt;Typical risks in everyday email&lt;/h2&gt;&lt;p&gt;Before looking at solutions, it is worth taking a look at the real attack vectors that are repeatedly exploited in day-to-day business:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Man-in-the-middle attacks: An attacker positions themselves between the sender and recipient and reads the communication or modifies it.&lt;/li&gt;&lt;li&gt;Interception on mail servers: Compromised or poorly secured mail servers from providers or third-party providers can read messages in plain text.&lt;/li&gt;&lt;li&gt;Phishing and spoofing: Without a signature, the sender of an email can be easily falsified. Employees can thus be tricked into handing over sensitive data.&lt;/li&gt;&lt;li&gt;Insecure network connections: Anyone working from home or on the move on insecure Wi-Fi networks runs the risk of emails being read – especially if end-to-end encryption is not active.&lt;/li&gt;&lt;li&gt;Misdirected or stored messages: Unencrypted mail is also available in plain text on the servers of your own email provider.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;These risks cannot be eliminated by caution alone. They require technical protective measures – and this is exactly where email encryption comes in. However, not all encryption is the same: the scope of protection and intended use differ considerably depending on which level is being protected.&lt;/p&gt;&lt;h2&gt;Two levels of protection in email encryption: transport encryption and end-to-end encryption&lt;/h2&gt;&lt;p&gt;When people talk about "email encryption", they often mean different things. Two basic concepts can be clearly distinguished from each other – and the difference is crucial in practice:&lt;/p&gt;&lt;h3&gt;Transport encryption (TLS)&lt;/h3&gt;&lt;p&gt;Most modern mail servers today use TLS (Transport Layer Security) to encrypt the connection between the servers. This protects emails in transit, comparable to a secure tunnel between two postal stations. TLS is now standard and should be a prerequisite for all email communication.&lt;/p&gt;&lt;p&gt;The problem is that the message is available in plain text on the servers themselves. TLS protects the line, not the content. In addition, TLS is only effective if both mail servers involved support it and have configured it correctly – which is not always guaranteed. Anyone who has access to one of these servers can still read the messages.&lt;/p&gt;&lt;h3&gt;End-to-end encryption (E2EE)&lt;/h3&gt;&lt;p&gt;With end-to-end encryption, the message is encrypted on the sender's device and only decrypted again on the recipient's device. No server in between – not even that of the email provider – can read the content. This is true confidentiality, and there is no way around it for really sensitive content.&lt;/p&gt;&lt;p&gt;Two standards have been established for end-to-end encryption of emails:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="https://mailbox.org/en/blog/smime-secure-e-mail-encryption-and-signature/" data-entity-type="node" data-entity-uuid="fcb79eca-189f-4b16-af88-c0f2a34ede37" data-entity-substitution="canonical" title="S/MIME: Secure e-mail encryption and signature"&gt;S/MIME&lt;/a&gt; (Secure/Multipurpose Internet Mail Extensions): A certificate-based standard that builds on a PKI (Public Key Infrastructure). Certificates are issued by certification authorities and can be easily integrated into existing company infrastructures and common email clients. S/MIME is particularly widespread in corporate and government environments.&lt;/li&gt;&lt;li&gt;&lt;a href="https://mailbox.org/en/blog/pgp-encryption-at-mailboxorg/" data-entity-type="node" data-entity-uuid="5c710490-9276-4b9f-854d-c9c1b4af845b" data-entity-substitution="canonical" title="PGP encryption for maximum email protection"&gt;PGP&lt;/a&gt; (Pretty Good Privacy): An open standard in which each communication partner has a key pair: a public key for encryption and a private key for decryption. The sender and recipient must exchange their public keys. PGP is particularly widespread in tech-savvy environments and is natively supported by mailbox.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;In addition to encryption, both standards also enable emails to be digitally signed – another important security feature that confirms the identity of the sender and makes tampering recognisable.&lt;/p&gt;

          
                                                  
      


  &lt;h2 class="referent__title"&gt;&lt;/h2&gt;
  
                
        
                    
            
            
            
                          &lt;p&gt;TLS vs. End-to-End Encryption:&lt;/p&gt;&lt;p&gt;TLS protects emails while they are in transit between two servers. On the server itself, they are stored in plain text.&lt;/p&gt;&lt;p&gt;End-to-end encryption using PGP or S/MIME fully protects the content: only the sender and recipient can read the message.&lt;/p&gt;
                        
        
      
      

              


  
    
    
    
    &lt;h2&gt;Why technical solutions alone are not enough&lt;/h2&gt;&lt;p&gt;Even the best encryption standard is of little use if it is not used in practice. Many organisations have the technical possibilities, but employees do not use them in their day-to-day work. The reasons for this are usually the same: encryption is considered complicated, time-consuming or "not relevant to me".&lt;/p&gt;&lt;p&gt;Awareness of secure email communication can be built up in a targeted manner – and it pays off.&lt;/p&gt;&lt;h2&gt;Creating awareness: how to make email encryption a lived practice&lt;/h2&gt;&lt;h3&gt;Step 1: Honestly assess the status quo&lt;/h3&gt;&lt;p&gt;Before planning measures, it is worth taking an internal look: How are emails currently sent? Which systems are in use? Are there already guidelines in place and are they being adhered to? A brief internal survey or a security audit can provide clarity.&lt;/p&gt;&lt;h3&gt;Step 2: Formulate clear guidelines&lt;/h3&gt;&lt;p&gt;Organisations need binding guidelines on what type of information must be protected and how. A simple classification into "internal/non-sensitive", "confidential" (e.g. personnel data, contracts) and "strictly confidential" helps to decide whether transport encryption is sufficient or whether end-to-end encryption is recommended or even mandatory.&lt;/p&gt;&lt;h3&gt;Step 3: Carry out targeted training on email encryption&lt;/h3&gt;&lt;p&gt;One-off mandatory training sessions quickly fizzle out. Measures such as the following are more effective, as they have been proven to increase participation:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Short, regular learning units (5-10 minutes) on specific scenarios&lt;/li&gt;&lt;li&gt;Practical examples from your own industry, e.g. a simulated phishing attempt or a "what if" scenario&lt;/li&gt;&lt;li&gt;Playful elements such as quizzes&lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;Step 4: Provide the right tools at a low threshold&lt;/h3&gt;&lt;p&gt;Willingness increases significantly when encryption simply works. This means:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Organising key management centrally, not leaving it to each individual&lt;/li&gt;&lt;li&gt;Ensuring integration into existing email clients&lt;/li&gt;&lt;li&gt;Providing instructions that are really understandable for the workforce&lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;Step 5: Involve managers as role models&lt;/h3&gt;&lt;p&gt;Security culture comes from the top. If the management or head of the authority communicates in encrypted form – and makes this visible – the inhibition threshold in the team drops significantly. Managers should therefore be involved and trained at a particularly early stage.&lt;/p&gt;&lt;h3&gt;Step 6: Test and improve regularly&lt;/h3&gt;&lt;p&gt;Creating awareness is not a one-off task. Regular tests – such as simulated phishing emails or reviews of encryption practices – show where gaps exist and help to tighten up measures in a targeted manner.&lt;/p&gt;

          
                                                  
      


  
    
      &lt;h2 class="ticket__title"&gt;mailbox: The secure space for your e-mail communication&lt;/h2&gt;
              

&lt;a data-component-id="boxy:knob" data-component-variant="tertiary" class="knob knob--tertiary" href="https://mailbox.org/en/blog/nis-2-implementation-act-germany-obligations-business-continuity/"&gt;Security at mailbox&lt;/a&gt;

          
    
          
                  
              
                  &lt;img loading="lazy" height="1632" width="2912" src="https://mailbox.org/sites/default/files/2025-05/news-jurisdiction-2.png" alt="Decision announced with a judge's gavel"&gt;

  


    
  

              


  
    
    
    
    &lt;h2&gt;Legal framework and affected sectors&lt;/h2&gt;&lt;p&gt;The GDPR obliges organisations to protect personal data with "appropriate technical and organisational measures" (Art. 32 GDPR). Email encryption is one such measure and failure to apply it can be considered an omission in the event of damage.&lt;/p&gt;&lt;p&gt;Authorities in Germany are also required by the BSI baseline protection compendium to implement measures for secure email communication. The BSI expressly categorises end-to-end encryption as a recommended measure. In some areas, secure email communication is not only useful, but also required by law or regulation:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;In healthcare, the GDPR and Patient Data Protection Act require the protection of highly sensitive patient data.&lt;/li&gt;&lt;li&gt;Legal and tax professionals are subject to a duty of confidentiality – unencrypted client communication can have consequences under professional law.&lt;/li&gt;&lt;li&gt;Public administrations must protect confidential administrative processes on a daily basis.&lt;/li&gt;&lt;li&gt;Banks and insurance companies are subject to strict compliance requirements such as MaRisk and DORA.&lt;/li&gt;&lt;li&gt;Companies in research and development – for example in the pharmaceutical industry or mechanical engineering – are attractive targets for industrial espionage.&lt;/li&gt;&lt;li&gt;The BSI Act prescribes increased protective measures for operators of critical infrastructure (KRITIS).&lt;/li&gt;&lt;/ul&gt;

          
                                                  
      


  &lt;h2 class="referent__title"&gt;&lt;/h2&gt;
  
                
        
                    
            
            
            
                          &lt;p&gt;GDPR and Email:&lt;/p&gt;&lt;p&gt;The GDPR requires organizations to implement “appropriate technical measures” to protect personal data (Art. 32). In the case of sensitive content such as health or financial data, the lack of encryption can be considered a breach of duty. If a data breach occurs, companies and government agencies must notify the relevant supervisory authority within 72 hours. If there is a high risk to the individuals concerned, they must also be notified directly.&lt;/p&gt;
                        
        
      
      

              


  
    
    
    
    &lt;h2&gt;Conclusion: email encryption is not an IT issue – it is an organisational issue&lt;/h2&gt;&lt;p&gt;Email encryption is a basic requirement for trustworthy digital communication: in companies, public authorities and wherever sensitive information is exchanged on a daily basis.&lt;/p&gt;&lt;p&gt;Transport encryption via TLS is standard today and should be taken for granted. For truly confidential content, however, there is no way around end-to-end encryption with S/MIME or PGP. Which standard is more suitable depends on the infrastructure, the requirements and the communication partners – both can be reliably implemented in modern mail environments. Find out in our blogs, how to use &lt;a href="https://mailbox.org/en/blog/smime-secure-e-mail-encryption-and-signature/" data-entity-type="node" data-entity-uuid="fcb79eca-189f-4b16-af88-c0f2a34ede37" data-entity-substitution="canonical" title="S/MIME: Secure e-mail encryption and signature"&gt;S/MIME&lt;/a&gt; and &lt;a href="https://mailbox.org/en/blog/pgp-encryption-at-mailboxorg/" data-entity-type="node" data-entity-uuid="5c710490-9276-4b9f-854d-c9c1b4af845b" data-entity-substitution="canonical" title="PGP encryption for maximum email protection"&gt;PGP&lt;/a&gt; for mailbox.&lt;/p&gt;&lt;p&gt;The real challenge lies not in the technology, but in the culture: email encryption must become a matter of course. This can be achieved through clear guidelines, practical training and tools that make it easier to use rather than more difficult. In this way, secure communication becomes the norm, not the exception.&lt;/p&gt;

          
                                                  
      


      
      &lt;h2 class="row__intro__title"&gt;            Insights &amp;amp; Trends
      &lt;/h2&gt;
      Discover more articles on the topic of security.
              
            

&lt;a data-component-id="boxy:knob" data-component-variant="secondary" class="knob knob--secondary" href="https://mailbox.org/en/insights/"&gt;All articles&lt;/a&gt;

        
          
    
      
      
  
  
                    
                  
              
                  &lt;img loading="lazy" height="2160" width="4096" src="https://mailbox.org/sites/default/files/2026-08/mailbox%20EVAC%20Blog%20IT-Sicherheit%20kleine%20Unternehmen.jpeg" alt="mailbox EVAC Blog IT-Sicherheit kleine Unternehmen"&gt;

  


      
      
      
      Business Continuitiy, Security
    
    &lt;h3 class="snip__title"&gt;IT security: Why small businesses in particular are targeted by cyberattacks&lt;/h3&gt;
  &lt;a class="snip__arrow" href="https://mailbox.org/en/blog/IT-security-for-small-businesses/" aria-hidden="true"&gt;→&lt;/a&gt;
  &lt;a class="snip__link" href="https://mailbox.org/en/blog/IT-security-for-small-businesses/"&gt;Read more about &lt;em class="placeholder"&gt;IT security: Why small businesses in particular are targeted by cyberattacks&lt;/em&gt;&lt;/a&gt;


    
      
      
  
  
                    
                  
              
                  &lt;img loading="lazy" height="2160" width="4096" src="https://mailbox.org/sites/default/files/2026-08/mailbox%20EVAC%20Blog%20Business%20Continuity%20in%20der%20Lieferkette.jpeg" alt="mailbox EVAC Blog Business Continuity in der Lieferkette"&gt;

  


      
      
      
      Best practice, Business Continuitiy
    
    &lt;h3 class="snip__title"&gt;How to use business continuity as a competitive advantage in the supply chain&lt;/h3&gt;
  &lt;a class="snip__arrow" href="https://mailbox.org/en/blog/business-continuity-supply-chain/" aria-hidden="true"&gt;→&lt;/a&gt;
  &lt;a class="snip__link" href="https://mailbox.org/en/blog/business-continuity-supply-chain/"&gt;Read more about &lt;em class="placeholder"&gt;How to use business continuity as a competitive advantage in the supply chain&lt;/em&gt;&lt;/a&gt;


    
  
  


</description>
  <guid isPermaLink="false">62bab616-2d39-4492-8226-500c23a5a2e2</guid>
    <pubDate>Wed, 20 May 2026 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Email encryption in companies: Turning awareness into a real safety culture</dc:title>
    <dc:identifier>62bab616-2d39-4492-8226-500c23a5a2e2</dc:identifier>
    </item>
<item>
  <title>Business continuity plan in accordance with BSI Standard 200-4: How SMEs ensure their business continuity</title>
  <link>https://mailbox.org/en/blog/business-continuity-plan-bsi-200-4-sme/</link>
  <description>&lt;p&gt;&lt;em&gt;Reading time: 13 minutes&lt;/em&gt;&lt;/p&gt;&lt;p&gt;Imagine this: It's Tuesday morning. The sales manager of a medium-sized mechanical engineering company wants to answer an urgent request for quotation – but her inbox isn't loading. Colleagues in the open-plan office stare at their screens, perplexed. The managing director's phone is ringing: An important customer from France can no longer reach anyone by email.&lt;/p&gt;&lt;p&gt;Shortly afterwards, it becomes clear that a cyber attack has paralysed the company's communication system overnight. No one has access to the inbox, the video conferencing tool or the address book. Even the calendar with today's appointments is affected. Nobody knows who to inform. No one can reach their colleagues in the home office.&lt;/p&gt;&lt;p&gt;The managing director is faced with an existential question: "How do we communicate now – with our employees, with customers, with suppliers?" Every hour without an answer costs trust, orders and possibly the company itself in the end.&lt;/p&gt;


      
                  
              
              
              
              
              
              
              
                  &lt;img loading="lazy" height="4283" width="6628" src="https://mailbox.org/sites/default/files/2026-04/Blog%20mailbox%20EVAC%20Gescha%CC%88ftsfortfu%CC%88hrungsplan%20nach%20BSI%20Standard%20200-4%20BCM%20fu%CC%88r%20KMU.jpeg" alt="Blog mailbox EVAC Business Continuity Plan according to BSI Standard 200-4 BCM for SMEs"&gt;

  


  
          

              


  
    
    
    
    &lt;h2&gt;SMEs are the most frequent target of high-impact cyberattacks&lt;/h2&gt;&lt;p&gt;This scenario is not theoretical. It is part of everyday life in small and medium-sized enterprises (SMEs). According to the BSI's situation report on IT security in Germany 2025, 80% of reported attacks were directed against SMEs in the reporting period. Small and medium-sized enterprises do not have the security budgets of large corporations at their disposal. And while large companies have well-established crisis teams and fallback systems, SMEs are usually hit as cold as ice: if the email service is down, the whole business is down.&lt;/p&gt;&lt;p&gt;What does this mean for you? The question is not whether your company will be in this situation one day, but when – and whether you will still be able to act. This is precisely where a business continuity plan in accordance with BSI Standard 200-4 comes in – the methodical basis for effective business continuity management (BCM) in small and medium-sized companies.&lt;/p&gt;

          
                                                  
      


  &lt;h2 class="referent__title"&gt;&lt;/h2&gt;
  
                
        
                    
            
            
            
                          &lt;p&gt;The &lt;a href="https://mailbox.org/en/blog/nis-2-implementation-act-germany-obligations-business-continuity/" data-entity-type="node" data-entity-uuid="39c7c4b3-4771-4a2d-be32-be147cb897ed" data-entity-substitution="canonical" title="NIS-2 Implementation Act Germany: Obligations &amp;amp; Business Continuity"&gt;NIS-2 Implementation Act has been in force in Germany&lt;/a&gt; since 6 December 2025 – without a transition period. Around 29,500 companies must now prove that they operate a structured business continuity management (BCM) system. BSI Standard 200-4 provides the methodological framework for this.&lt;/p&gt;
                        
        
      
      

              


  
    
    
    
    &lt;h2&gt;What is a business continuity plan – and why SMEs need one?&lt;/h2&gt;&lt;p&gt;A business continuity plan (BCP) systematically describes how a company maintains or restores its critical processes as quickly as possible in the event of serious disruptions – from cyber attacks to power outages and natural disasters. It is the core result of a comprehensive Business Continuity Management System (BCMS).&lt;/p&gt;&lt;p&gt;BCM goes far beyond traditional IT contingency plans and backup concepts. It considers the interaction between organisation, technology, building infrastructure and personnel. After all, the best backup is of little use in an emergency if no one knows who decides which channel to use to communicate and which processes need to be restarted first.&lt;/p&gt;&lt;p&gt;For SMEs, a business continuity plan is doubly valuable: it not only secures their existence in the event of an emergency, but also fulfils the central requirements of the NIS 2 Implementation Act for business continuity management in SMEs.&lt;/p&gt;&lt;h2&gt;BSI Standard 200-4: The guide for your BCM&lt;/h2&gt;&lt;p&gt;The BSI Standard 200-4 was published by the German Federal Office for Information Security (BSI) in June 2023 and replaces its predecessor BSI Standard 100-4. It is based on the international standard ISO 22301:2019 and offers practical guidance for setting up a BCMS – regardless of industry and company size.&lt;/p&gt;

          
                                                  
      


    
    &lt;h3&gt;BCM according to BSI 200-4 is not a project – it's a cycle&lt;/h3&gt;&lt;p&gt;Many companies view BCM as a project with a beginning and an end – write an emergency manual, file it, done. BSI Standard 200-4 deliberately counters this with a different model: the PDCA cycle (Plan-Do-Check-Act), which is also the basis of ISO 22301.&lt;/p&gt;&lt;p&gt;BCM is a continuous process in four phases:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Plan: Define context and objectives, carry out business impact analysis (BIA) and risk analyses, develop emergency strategies.&lt;/li&gt;&lt;li&gt;Do: Implement measures, i.e. document emergency plans, form a crisis team, train employees, set up backup systems.&lt;/li&gt;&lt;li&gt;Check: Check effectiveness, i.e. carry out exercises, evaluate key figures, internal audits, lessons learnt from real incidents.&lt;/li&gt;&lt;li&gt;Act: Improve and adapt, i.e. incorporate findings, update plans, include new risks.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;This approach is a relief for SMEs: they do not have to present a perfect BCM on the first day. It is enough to enter the cycle – and get better with every round.&lt;/p&gt;
            &lt;img loading="lazy" height width src="https://mailbox.org/sites/default/files/2026-04/Blog_mailbox%20EVAC_GFP%20BSI%20Standard%20200-4%20PDCA%20Cycle_0.svg" alt="mailbox EVAC GFP BSI Standard 200-4 PDCA Cycle"&gt;


      
      
      
    
  
              


  
    
    
    
    &lt;h3&gt;The staged model of BSI Standard 200-4: Customised entry&lt;/h3&gt;&lt;p&gt;A key feature of the standard is its three-stage approach, which enables companies to get started flexibly:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Reactive BCMS (4–8 weeks): Immediate measures and emergency contacts. Fulfils the NIS 2 minimum requirement and creates a basis for further expansion.&lt;/li&gt;&lt;li&gt;Build-up BCMS (3–6 months): Complete business impact analysis (BIA), risk analyses and initial emergency plans. Critical processes are identified and recovery times are defined.&lt;/li&gt;&lt;li&gt;Standard BCMS (6–12 months): Comprehensive, ISO 22301-compliant BCM with regular exercises, analyses and continuous improvement.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;This step-by-step approach is particularly attractive for medium-sized companies: you can start quickly with the reactive stage and gradually expand your BCM – without having to manage a major project from the outset.&lt;/p&gt;&lt;h3&gt;The three phases of an incident: from alarm to normal operation&lt;/h3&gt;&lt;p&gt;The BSI Standard 200-4 does not think of incidents as a single moment, but as a time course with clearly distinguishable phases. This model helps enormously in structuring emergency plans in a meaningful way – and shows why some precautions must take effect immediately, while others only become relevant days later:&lt;/p&gt;

          
                                                  
      

    
          
        &lt;h2 class="mosaic__title"&gt;
                    1. Immediate reaction
        &lt;/h2&gt;
        &lt;p&gt;Minutes to hours: Recognise and contain damage, convene crisis team, start initial internal and external communication, check reporting obligations (for NIS-2: 24-hour early warning to the BSI).&lt;/p&gt;
              
          
        &lt;h2 class="mosaic__title"&gt;
                    2. Emergency operation
        &lt;/h2&gt;
        &lt;p&gt;Hours to weeks: Critical processes continue to run at a defined minimum level (MBCO) – often with alternative systems, reduced functions or manual processes. Customers, suppliers and employees must be kept informed at all times.&lt;/p&gt;
              
          
        &lt;h2 class="mosaic__title"&gt;
                    3. Restart &amp;amp; return
        &lt;/h2&gt;
        &lt;p&gt;Days to months: Step-by-step restoration of regular systems and processes, follow-up, evaluation and incorporation of the findings into the BCM (back into the PDCA cycle)&lt;/p&gt;
              
      

              


  
    
    
    
    &lt;p&gt;Important: Effective communication is a basic requirement in all three phases. If you cannot reach your crisis team during the immediate response or cannot inform customers during emergency operations, you will lose valuable time – and the trust of your stakeholders.&lt;/p&gt;&lt;h3&gt;The Business Impact Analysis: The centrepiece of BSI Standard 200-4&lt;/h3&gt;&lt;p&gt;The Business Impact Analysis (BIA) is the central tool in BSI Standard 200-4. It answers the key questions:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Which business processes are time-critical?&lt;/li&gt;&lt;li&gt;What dependencies exist (IT systems, personnel, service providers, buildings)?&lt;/li&gt;&lt;li&gt;What is the maximum time a process can be down before damage that threatens the company's existence occurs?&lt;/li&gt;&lt;li&gt;At what minimum level must operations continue in an emergency?&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;In practice, a BIA typically involves five steps:&lt;/p&gt;&lt;ol&gt;&lt;li&gt;Capturing business processes: A structured inventory of all key processes – from incoming orders to production and invoicing. Important: This also includes supporting processes such as human resources or IT support.&lt;/li&gt;&lt;li&gt;Evaluate damage scenarios: The consequences of a failure after 1 hour, 1 day, 1 week are checked for each process – financially, legally, reputationally and with regard to customers and employees.&lt;/li&gt;&lt;li&gt;Map dependencies: Which IT systems, service providers, premises, key personnel and external communication channels does each process need? This is often where the biggest blind spots are discovered.&lt;/li&gt;&lt;li&gt;Determine key figures: MTPD, RTO, RPO and MBCO are defined for each critical process (see overview below). These values later form the basis for all restart plans.&lt;/li&gt;&lt;li&gt;Prioritise and document: The results are summarised in a BIA report. This forms the basis for all further BCM decisions. The BSI provides free templates and a BIA evaluation form for this purpose.&lt;/li&gt;&lt;/ol&gt;

          
                                                  
      


  &lt;h2 class="referent__title"&gt;&lt;/h2&gt;
  
                
        
                    
            
            
            
                          &lt;p&gt;Four key figures that every company should know:&lt;/p&gt;&lt;p&gt;MTPD: Maximum Tolerable Period of Disruption&lt;/p&gt;&lt;p&gt;RTO: Recovery Time Objective&lt;/p&gt;&lt;p&gt;RPO: Recovery Point Objective (Maximum tolerable data loss)&lt;/p&gt;&lt;p&gt;MBCO: Minimum Business Continuity Objective (Minimum performance in emergency operation)&lt;/p&gt;
                        
        
      
      

              


  
    
    
    
    &lt;p&gt;An example from a medium-sized retail company makes the BIA tangible:&lt;/p&gt;&lt;p&gt;The "order acceptance and confirmation" process runs entirely via email and the ERP system. The BIA shows: After 4 hours without customer communication, the first orders migrate to the competition, after 2 days there is a threat of contractual penalties, after a week key customers are irreparably annoyed.&lt;/p&gt;&lt;p&gt;The key figures could look like this:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;MTPD = 48 hours&lt;/li&gt;&lt;li&gt;RTO = 4 hours&lt;/li&gt;&lt;li&gt;RPO = 1 hour&lt;/li&gt;&lt;li&gt;MBCO = order acceptance via alternative channel with reduced capacity&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;It is precisely these values that provide the benchmark for investments in backup systems, backup communication and personnel planning.&lt;/p&gt;&lt;h2&gt;NIS-2 makes BCM a legal requirement&lt;/h2&gt;&lt;p&gt;With the NIS-2 Implementation Act coming into force on 6 December 2025, business continuity management is a legal requirement for a significantly expanded group of companies in Germany. § 30 para. 2 no. 3 BSIG explicitly requires measures to maintain operations, including backup management, recovery and crisis management.&lt;/p&gt;&lt;p&gt;What this means for you:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Around 29,500 companies in Germany are affected – this means an increase from around 4,500 regulated organisations to date.&lt;/li&gt;&lt;li&gt;There are no transition periods: the requirements apply immediately.&lt;/li&gt;&lt;li&gt;Management is personally liable and is obliged to undergo cyber security training.&lt;/li&gt;&lt;li&gt;Failure to comply could result in fines of up to 10 million euros or 2 % of annual global turnover.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;In relation to NIS-2, BSI Standard 200-4 is not a requirement, but a recognised methodology. Those who align their BCM with it create a reliable basis for demonstrably fulfilling the NIS-2 requirements.&lt;/p&gt;

          
                                                  
      


  
    
      &lt;h2 class="ticket__title"&gt;NIS-2: Affectedness, obligations &amp;amp; sanctions&lt;/h2&gt;
              

&lt;a data-component-id="boxy:knob" data-component-variant="tertiary" class="knob knob--tertiary" href="https://mailbox.org/en/blog/nis-2-implementation-act-germany-obligations-business-continuity/"&gt;Find out more about the NIS-2 Implementation Act&lt;/a&gt;

          
    
          
                  
              
                  &lt;img loading="lazy" height="1632" width="2912" src="https://mailbox.org/sites/default/files/2025-05/news-jurisdiction-2.png" alt="Decision announced with a judge's gavel"&gt;

  


    
  

              


  
    
    
    
    &lt;h2&gt;The underestimated weak point: communication in an emergency&lt;/h2&gt;&lt;p&gt;Many emergency scenarios reveal a critical gap: Organisations plan restart processes and backup strategies, but overlook the fundamental issue of communication skills. How do companies and authorities communicate when the primary means of communication fail?&lt;/p&gt;&lt;p&gt;In the event of a ransomware attack, for example, it is often not only business data that is affected, but also email systems, collaboration platforms and video conferencing solutions. As a result, the crisis team is unable to coordinate, employees receive no instructions and customers and partners remain in the dark.&lt;/p&gt;&lt;p&gt;A business continuity plan in accordance with BSI 200-4 must therefore also include an answer to this question: What secondary communication system is available if the primary system is no longer usable?&lt;/p&gt;&lt;h2&gt;EVAC by mailbox: communication capability at the touch of a button&lt;/h2&gt;&lt;p&gt;It is precisely for this scenario that mailbox has developed &lt;a href="https://mailbox.org/en/evac/" data-entity-type="node" data-entity-uuid="8d62b38c-25b3-4011-a5f2-de2d2e58cc87" data-entity-substitution="canonical" title="EVAC: Business continuity in an emergency"&gt;EVAC&lt;/a&gt; – an immediately deployable, secondary communication platform for companies and public authorities. EVAC can be activated at the touch of a button when regular IT communication tools are no longer available during a cyber emergency.&lt;/p&gt;&lt;h3&gt;What EVAC includes:&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;Secure email communication – regardless of your compromised infrastructure&lt;/li&gt;&lt;li&gt;Video conferencing – for crisis team meetings, coordination and online meetings with external stakeholders&lt;/li&gt;&lt;li&gt;Cloud storage – for sharing important documents during emergency operations&lt;/li&gt;&lt;li&gt;Calendar, address book and online office tools – for basic work capability&lt;/li&gt;&lt;/ul&gt;

          
                                                  
      


  
        
  
                &lt;img loading="lazy" src="https://mailbox.org/sites/default/files/2026-01/mailbox%20EVAC%20Console%20overview.png" width="8190" height="4334" alt="mailbox EVAC Console overview"&gt;


      


  


  &lt;h2 class="referent__title"&gt;&lt;/h2&gt;
  
                
        
                    
            
            
            
                          &lt;p&gt;EVAC in the BCM context&lt;/p&gt;&lt;p&gt;EVAC is not a replacement infrastructure for continuous operation, but a targeted building block in your business continuity plan: the solution for communication capability in an emergency. As an external, independent system, EVAC is not affected by an attack on your primary IT – and that is precisely what makes it so valuable.&lt;/p&gt;
                        
        
      
      

              


  
    
    
    
    &lt;h2&gt;Conclusion: Preparation beats reaction&lt;/h2&gt;&lt;p&gt;The BSI Standard 200-4 makes business continuity management tangible and feasible – even for companies that have not yet implemented formal BCM. With the three-stage model, you can get started quickly and gradually build up a resilient system.&lt;/p&gt;&lt;p&gt;The decisive factor is: don't wait for an emergency. The NIS-2 requirements apply now. And the question of whether your company remains capable of communicating and acting after a cyberattack should not be answered in the crisis team – but today, in your business continuity plan.&lt;/p&gt;&lt;h2&gt;Five steps to a business continuity plan&lt;/h2&gt;&lt;p&gt;Would you like to start with your BCM or improve existing measures? These five steps are based on BSI Standard 200-4:&lt;/p&gt;&lt;ol&gt;&lt;li&gt;Clarify responsibility: BCM is a matter for the boss. Appoint a responsible person (BCM officer) and ensure that the management actively supports the topic.&lt;/li&gt;&lt;li&gt;Carry out a business impact analysis: Identify your time-critical business processes, their dependencies and the maximum tolerable downtimes. The BSI provides &lt;a href="https://www.bsi.bund.de/DE/Themen/Unternehmen-und-Organisationen/Standards-und-Zertifizierung/IT-Grundschutz/BSI-Standards/BSI-Standard-200-4-Business-Continuity-Management/bsi-standard-200-4_Business_Continuity_Management_node.html"&gt;free templates&lt;/a&gt; for this purpose.&lt;/li&gt;&lt;li&gt;Ensure emergency communication: Define a secondary communication channel that works independently of your primary IT - for example with a solution such as &lt;a href="https://mailbox.org/en/evac/" data-entity-type="node" data-entity-uuid="8d62b38c-25b3-4011-a5f2-de2d2e58cc87" data-entity-substitution="canonical" title="EVAC: Business continuity in an emergency"&gt;EVAC&lt;/a&gt; from mailbox.&lt;/li&gt;&lt;li&gt;Create recovery plans: For each critical process, document what the emergency operation looks like and what steps are necessary for recovery.&lt;/li&gt;&lt;li&gt;Regularly practise and improve: A plan that is never tested is worthless in an emergency. Carry out regular BCM exercises and adapt your plans to changing conditions.&lt;/li&gt;&lt;/ol&gt;

          
                                                  
      

  
    
      &lt;h2 class="accordion__headline"&gt;FAQ about the BCM in accordance with BSI 200-4&lt;/h2&gt;
          
    
    
                        
            
              What is a business continuity plan?
              
                
              
            

            
              
                &lt;p&gt;A business continuity plan (BCM) is a documented action plan that describes how a company maintains its critical business processes after a serious disruption or restores them in the shortest possible time. It is the central result of a business continuity management system (BCMS) in accordance with BSI standard 200-4.&lt;/p&gt;
              
            
          
                                
            
              Is BCM according to BSI 200-4 mandatory for SMEs?
              
                
              
            

            
              
                &lt;p&gt;Since 6 December 2025, the NIS-2 Implementation Act has required around 29,500 companies in Germany to have structured business continuity management. Many medium-sized companies with 50 or more employees or a turnover of 10 million euros or more in the affected sectors are among them. BSI Standard 200-4 is not a legal requirement, but it is the recognised methodology for verifiably fulfilling the NIS-2 requirements.&lt;/p&gt;
              
            
          
                                
            
              How long does it take to set up a BCM in accordance with BSI 200-4?
              
                
              
            

            
              
                &lt;p&gt;Thanks to the three-stage model, SMEs can establish a reactive BCMS that fulfils the NIS-2 minimum requirements in just four to eight weeks. It takes three to six months to set up a complete reactive BCMS and six to 12 months for a comprehensive standard BCMS.&lt;/p&gt;
              
            
          
                                
            
              What role does emergency communication play in the business continuity plan?
              
                
              
            

            
              
                &lt;p&gt;Emergency communication is crucial in all phases of a disruption. BSI standard 200-4 requires that companies can continue to communicate with employees, customers and authorities even if their primary IT system fails. Secondary communication platforms such as EVAC from mailbox close precisely this gap.&lt;/p&gt;
              
            
          
                  

  



  
    
      &lt;h2 class="ticket__title"&gt;Business continuity at the touch of a button&lt;/h2&gt;
              

&lt;a data-component-id="boxy:knob" data-component-variant="tertiary" class="knob knob--tertiary" href="https://mailbox.org/en/evac/"&gt;Discover EVAC now&lt;/a&gt;

          
    
          
                  
              
                  &lt;img loading="lazy" height="1632" width="2944" src="https://mailbox.org/sites/default/files/2025-04/mailbox-evac-button-web-rgb.jpg" alt="Kommunikation auf Knopfdruck"&gt;

  


    
  



      
      &lt;h2 class="row__intro__title"&gt;            Insights &amp;amp; Trends
      &lt;/h2&gt;
      Discover more articles on the topic of security.
              
            

&lt;a data-component-id="boxy:knob" data-component-variant="secondary" class="knob knob--secondary" href="https://mailbox.org/en/insights/"&gt;All contributions&lt;/a&gt;

        
          
    
      
      
  
  
                    
                  
              
                  &lt;img loading="lazy" height="2160" width="4096" src="https://mailbox.org/sites/default/files/2026-08/mailbox%20EVAC%20Blog%20IT-Sicherheit%20kleine%20Unternehmen.jpeg" alt="mailbox EVAC Blog IT-Sicherheit kleine Unternehmen"&gt;

  


      
      
      
      Business Continuitiy, Security
    
    &lt;h3 class="snip__title"&gt;IT security: Why small businesses in particular are targeted by cyberattacks&lt;/h3&gt;
  &lt;a class="snip__arrow" href="https://mailbox.org/en/blog/IT-security-for-small-businesses/" aria-hidden="true"&gt;→&lt;/a&gt;
  &lt;a class="snip__link" href="https://mailbox.org/en/blog/IT-security-for-small-businesses/"&gt;Read more about &lt;em class="placeholder"&gt;IT security: Why small businesses in particular are targeted by cyberattacks&lt;/em&gt;&lt;/a&gt;


    
      
      
  
  
                    
                  
              
                  &lt;img loading="lazy" height="2160" width="4096" src="https://mailbox.org/sites/default/files/2026-08/mailbox%20EVAC%20Blog%20Business%20Continuity%20in%20der%20Lieferkette.jpeg" alt="mailbox EVAC Blog Business Continuity in der Lieferkette"&gt;

  


      
      
      
      Best practice, Business Continuitiy
    
    &lt;h3 class="snip__title"&gt;How to use business continuity as a competitive advantage in the supply chain&lt;/h3&gt;
  &lt;a class="snip__arrow" href="https://mailbox.org/en/blog/business-continuity-supply-chain/" aria-hidden="true"&gt;→&lt;/a&gt;
  &lt;a class="snip__link" href="https://mailbox.org/en/blog/business-continuity-supply-chain/"&gt;Read more about &lt;em class="placeholder"&gt;How to use business continuity as a competitive advantage in the supply chain&lt;/em&gt;&lt;/a&gt;


    
  
  


</description>
  <guid isPermaLink="false">51b24a68-8b81-49c8-9a03-d3c407f2465d</guid>
    <pubDate>Wed, 22 Apr 2026 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Business continuity plan in accordance with BSI Standard 200-4: How SMEs ensure their business continuity</dc:title>
    <dc:identifier>51b24a68-8b81-49c8-9a03-d3c407f2465d</dc:identifier>
    </item>
<item>
  <title>Moving away from the US cloud: Find European alternatives to Google and Microsoft</title>
  <link>https://mailbox.org/en/blog/find-european-alternatives-to-google-and-microsoft/</link>
  <description>&lt;p&gt;&lt;em&gt;Reading time: 10 minutes&lt;/em&gt;&lt;/p&gt;&lt;p&gt;Europe imports the majority of its digital infrastructure. Email, cloud, AI – in most cases, they run on the servers of US corporations, under US jurisdiction and on the corporations' terms. Due to a lack of awareness and visibility of digitally sovereign alternatives, the recourse to big tech often seems unavoidable for public authorities, private individuals and companies.&lt;/p&gt;&lt;p&gt;Changing geopolitical circumstances and rising costs are prompting a necessary rethink. But how do you recognise whether a European alternative really delivers what it promises? What is the best way to go about switching? And how do labels and catalogues help you?&lt;/p&gt;


      
                  
              
              
              
              
              
              
              
                  &lt;img loading="lazy" height="5461" width="8192" src="https://mailbox.org/sites/default/files/2026-04/mailbox%20Blog%20Europa%CC%88ische%20Alternativen%20zu%20Microsoft%20und%20Google.jpeg" alt="mailbox Blog Europäische Alternativen zu Microsoft und Google"&gt;

  


  
          

              


  
    
    
    
    &lt;h2&gt;96 % digital imports: How dependent German companies really are on US tech&lt;/h2&gt;&lt;p&gt;In most cases, anyone who sends an email, saves a document in the cloud or starts a video conference uses Microsoft 365, Google Workspace and co. That is: infrastructure from US corporations. This is convenient – and at the same time a digital policy problem that has preoccupied Europe for years.&lt;/p&gt;&lt;p&gt;As part of the "Digital Sovereignty" study in 2025, the German association Bitkom asked over 600 companies from all sectors in Germany with 20 or more employees how dependent they are on digital imports. According to the study, 96 % of the companies surveyed source digital services and technologies from abroad. 90 % of them consider themselves to be "heavily" or "somewhat" dependent on foreign partners.&lt;/p&gt;&lt;p&gt;60 % of the companies surveyed expect Germany to become increasingly dependent on imports. At 87 %, the USA is one of the most important regions of origin for German companies.&lt;/p&gt;&lt;h2&gt;Google and Microsoft for companies: US CLOUD Act, GDPR and the data protection risk&lt;/h2&gt;&lt;p&gt;Email is the most widely used digital communication medium. At the same time, it is the least scrutinised when it comes to digital sovereignty. Yet the starting point for Google, Microsoft 365 and the like is clear: the mailboxes of most Europeans run on US infrastructure and are located on US servers. They are subject to US law and are financed in part through data analysis.&lt;/p&gt;&lt;p&gt;US authorities are allowed to access data stored by US companies via the CLOUD Act, even if the server location is in Europe. For European companies and authorities, this means that the location of the data centre alone is not enough. It depends on the ownership structure, the jurisdiction and the actual control structure.&lt;/p&gt;&lt;p&gt;This is where the danger of dependence on digital imports becomes apparent. And this is precisely the core problem of many supposedly European alternatives that are advertised by Microsoft and Amazon Web Services (AWS), for example.&lt;/p&gt;

          
                                                  
      


  &lt;h2 class="referent__title"&gt;&lt;/h2&gt;
  
                
        
                    
            
            
            
                          &lt;h2&gt;Real European alternatives instead of sovereignty-washing&lt;/h2&gt;&lt;p&gt;It is important to take a closer look, because supposedly sovereign solutions run on European servers but belong to US corporations or are dependent on their infrastructure: The so-called European Sovereign Cloud from AWS is the product of a US corporation. The German company SAP works with Microsoft, Amazon and Google for its cloud services. The Delos Cloud – a subsidiary of SAP – is based on Microsoft 365 and Microsoft Azure and is therefore dependent on US companies for its infrastructure.&lt;/p&gt;&lt;p&gt;The brand names or corporate structures of these solutions suggest European data security or sovereignty. However, this does not protect European users from US law if the parent company is based in the US or the infrastructure of US corporations is used. On the other hand, choosing a German email provider or cloud service with servers and its own infrastructure exclusively in Germany structurally excludes access by US authorities.&lt;/p&gt;
                        
        
      
      

              


  
    
    
    
    &lt;h2&gt;NIS-2, GDPR, CLOUD Act: Why the choice of provider becomes a compliance issue&lt;/h2&gt;&lt;p&gt;The question of whose servers and on which infrastructure your company communication runs and who has access in case of doubt is not a theoretical one. Whether &lt;a href="https://mailbox.org/en/blog/nis-2-implementation-act-germany-obligations-business-continuity/" data-entity-type="node" data-entity-uuid="39c7c4b3-4771-4a2d-be32-be147cb897ed" data-entity-substitution="canonical" title="NIS-2 Implementation Act Germany: Obligations &amp;amp; Business Continuity"&gt;The German NIS-2 Directive Implementation Act&lt;/a&gt; (NIS-2-UmsuCG), geopolitical risks, cyber attacks: Virtually all companies and organisations process personal data that needs to be protected from access. The choice of provider is therefore a compliance and security issue with practical implications.&lt;/p&gt;&lt;p&gt;Digital sovereignty has been a buzzword in Brussels for years. This is not about symbolism or protectionism, but about tangible issues of legal security, data control and critical infrastructure. Decisions on digital sovereignty are increasingly having political and economic consequences for more and more organisations. For example, companies that &lt;a href="https://mailbox.org/en/blog/gdpr-violations-5-costly-traps-companies/" data-entity-type="node" data-entity-uuid="fab139b9-84c0-49ff-bc51-8e17bd6c4f2e" data-entity-substitution="canonical" title="GDPR violations: 5 common mistakes to avoid"&gt;have to demonstrate GDPR compliance&lt;/a&gt; are affected, or authorities that need to secure their communication infrastructure in accordance with NIS-2. They all need offers that they can choose from without compromising on control and trust.&lt;/p&gt;&lt;h2&gt;Parent company, cloud infrastructure, server location: 3 questions to ask before switching software&lt;/h2&gt;&lt;p&gt;Email, cloud storage, video conferencing and collaboration tools are part of everyday digital life. If you are evaluating a digital tool as an option or as a European alternative, three key questions can help:&lt;/p&gt;&lt;h3&gt;1. Where is the parent company legally based?&lt;/h3&gt;&lt;p&gt;A location in Germany or the EU says little if the company is part of a US corporation. The decisive factor is the question of the control structure: who ultimately decides on data access, who is obliged to provide information to authorities in case of doubt?&lt;/p&gt;&lt;h3&gt;2. Where is the data located – and on whose infrastructure?&lt;/h3&gt;&lt;p&gt;The decisive factor is not the server location, but on whose infrastructure and under whose jurisdiction the service runs. For example, US law ultimately applies to capacity rented from US companies such as AWS, Microsoft Azure or Google Cloud.&lt;/p&gt;&lt;h3&gt;3. Is there verifiable evidence?&lt;/h3&gt;&lt;p&gt;Own statements on legal security are not independent confirmation. Look for certificates and labels that are based on an external audit.&lt;/p&gt;&lt;h2&gt;Tech Sovereignty Catalogue: Europe's verified list for digital sovereignty&lt;/h2&gt;&lt;p&gt;The &lt;a href="https://techsov-catalogue.eu/"&gt;Tech Sovereignty Catalogue&lt;/a&gt; helps organisations and individuals to identify genuine European alternatives to Google, Microsoft and Amazon. It brings together European technology providers who can prove that they are genuine alternatives. What's behind it, why it's more than just a directory and how the listing process works:&lt;/p&gt;&lt;h3&gt;What is the Tech Sovereignty Catalogue?&lt;/h3&gt;&lt;p&gt;The Tech Sovereignty Catalogue is a European initiative that has been making trustworthy digital solutions from the EU and EFTA visible since the end of 2025. It is not a classic industry directory, but rather sees itself as a political instrument: the catalogue is a showcase for European technology sovereignty and is intended to connect decision-makers in companies, public authorities and politics with concrete alternatives to Google, Microsoft 365 and other big tech products.&lt;/p&gt;&lt;p&gt;The catalogue is backed by a high-ranking advisory board from research, civil society and digital policy. The catalogue is based on seven core principles:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Sovereignty &amp;amp; Security&lt;/li&gt;&lt;li&gt;De-Proprietarisation &amp;amp; Interoperability&lt;/li&gt;&lt;li&gt;Sustainability&lt;/li&gt;&lt;li&gt;Data as a Common Good&lt;/li&gt;&lt;li&gt;Decentralised Sovereign Infrastructure&lt;/li&gt;&lt;li&gt;Inclusive Governance&lt;/li&gt;&lt;li&gt;Strong Democracy&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Those who want to be included in the catalogue must show that they actually fulfil these principles.&lt;/p&gt;&lt;h3&gt;How the admission process works&lt;/h3&gt;&lt;p&gt;The path to the Tech Sovereignty Catalogue follows a clearly structured, multi-stage process. It is deliberately more demanding than a classic listing process:&lt;/p&gt;

          
                                                  
      

    
          
        &lt;h2 class="mosaic__title"&gt;
                    1. Submission
        &lt;/h2&gt;
        &lt;p&gt;European technology providers apply via a form on the catalogue website. Basic requirement: The provider must be headquartered in the EU or an EFTA country.&lt;/p&gt;
              
          
        &lt;h2 class="mosaic__title"&gt;
                    2. Eligibility check
        &lt;/h2&gt;
        &lt;p&gt;The submitted solution is checked for market maturity, European origin and actual control over the technology. Those who do not pass here do not enter the procedure.&lt;/p&gt;
              
          
        &lt;h2 class="mosaic__title"&gt;
                    3. Expert evaluation
        &lt;/h2&gt;
        &lt;p&gt;Independent experts evaluate the submitted solution based on the catalogue criteria. This involves not only technical features, but also the business model, data protection architecture and actual independence from non-European providers.&lt;/p&gt;
              
          
        &lt;h2 class="mosaic__title"&gt;
                    4. Decision
        &lt;/h2&gt;
        &lt;p&gt;If the result is positive, the solution is added to the catalogue and made publicly visible.&lt;/p&gt;
              
      

              


  
    
    
    
    &lt;h2&gt;What inclusion in the Tech Sovereignty Catalogue means for mailbox&lt;/h2&gt;&lt;p&gt;For mailbox, inclusion in the Tech Sovereignty Catalogue is an external confirmation of the principles we live by:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Company headquarters and parent company in the EU: We are a German-owned company founded in Germany.&lt;/li&gt;&lt;li&gt;Our servers are located exclusively in German data centres.&lt;/li&gt;&lt;li&gt;We do not pass on any data to third parties, we are ad-free, we do not use data-driven tracking and our service is GDPR-compliant.&lt;/li&gt;&lt;li&gt;At mailbox, sovereignty, information security and data protection are &lt;a href="https://mailbox.org/en/certified-quality/" data-entity-type="node" data-entity-uuid="63a24500-5ad6-4ee2-b951-4070d88f2285" data-entity-substitution="canonical" title="Certified quality"&gt;externally audited and confirmed&lt;/a&gt;: ISO 27001 and BSI C5 certificate, BSI IT Security label and BSI Gold status for email security, Software Hosted and Made in Germany seal of approval, holder of the Cybersecurity Made in Europe label and part of the Tech Sovereignty Catalogue&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;This is not a matter of course in a market where European services are regularly taken over by US corporations.&lt;/p&gt;&lt;p&gt;What we particularly like about the Tech Sovereignty Catalogue is that it sees sovereignty as a European project. The catalogue brings together providers that are linked by common values and a common legal framework. After all, digital self-determination is the result of conscious decisions – for infrastructure that can be trusted, for providers that can be held accountable and for an ecosystem that is committed to democratic principles.&lt;/p&gt;&lt;h2&gt;Switching to European providers: 3 steps to digital independence&lt;/h2&gt;&lt;p&gt;The Tech Sovereignty Catalogue makes it easier for organisations and private individuals to find truly European sovereign solutions. It thus helps organisations and individuals take an important step towards digital sovereignty.&lt;/p&gt;&lt;p&gt;Digital sovereignty is not a one-off project, but an ongoing decision. Take these three concrete steps on the path to your digital self-determination:&lt;/p&gt;

          
                                                  
      

    
          
        &lt;h2 class="mosaic__title"&gt;
                    1. Determine the current status
        &lt;/h2&gt;
        &lt;p&gt;Which digital services do you use every day? Where is the data stored? Who owns the provider? Even if the findings can be sobering: An honest inventory is the first step.&lt;/p&gt;
              
          
        &lt;h2 class="mosaic__title"&gt;
                    2. Identify software made in Europe
        &lt;/h2&gt;
        &lt;p&gt;Use the Tech Sovereignty Catalogue as a starting point. On the website you will find verified European providers in categories such as cybersecurity, cloud, platform services, data and AI: techsov-catalogue.eu&lt;/p&gt;
              
          
        &lt;h2 class="mosaic__title"&gt;
                    3. Migrate according to priorities
        &lt;/h2&gt;
        &lt;p&gt;A complete change of digital infrastructure in a short space of time is unrealistic. It makes more sense to prioritise according to sensitivity: Which services process particularly sensitive data? That's where it's worth switching first.&lt;/p&gt;
              
      



      
      &lt;h2 class="row__intro__title"&gt;            Insights &amp;amp; Trends
      &lt;/h2&gt;
      Discover further best practices for your digital security.
              
            

&lt;a data-component-id="boxy:knob" data-component-variant="secondary" class="knob knob--secondary" href="https://mailbox.org/en/insights/"&gt;All articles&lt;/a&gt;

        
          
    
      
      
  
  
                    
                  
              
                  &lt;img loading="lazy" height="2160" width="4096" src="https://mailbox.org/sites/default/files/2026-08/mailbox%20EVAC%20Blog%20IT-Sicherheit%20kleine%20Unternehmen.jpeg" alt="mailbox EVAC Blog IT-Sicherheit kleine Unternehmen"&gt;

  


      
      
      
      Business Continuitiy, Security
    
    &lt;h3 class="snip__title"&gt;IT security: Why small businesses in particular are targeted by cyberattacks&lt;/h3&gt;
  &lt;a class="snip__arrow" href="https://mailbox.org/en/blog/IT-security-for-small-businesses/" aria-hidden="true"&gt;→&lt;/a&gt;
  &lt;a class="snip__link" href="https://mailbox.org/en/blog/IT-security-for-small-businesses/"&gt;Read more about &lt;em class="placeholder"&gt;IT security: Why small businesses in particular are targeted by cyberattacks&lt;/em&gt;&lt;/a&gt;


    
      
      
  
  
                    
                  
              
                  &lt;img loading="lazy" height="4912" width="7360" src="https://mailbox.org/sites/default/files/2026-07/mailbox%20EVAC%20Blog%20Schatten-IT%20als%20Notfalllo%CC%88sung%20vermeiden.jpeg" alt="mailbox EVAC Blog Schatten-IT als Notfalllösung vermeiden"&gt;

  


      
      
      
      Business Continuitiy, Security
    
    &lt;h3 class="snip__title"&gt;How to avoid shadow IT when your communication tools fail&lt;/h3&gt;
  &lt;a class="snip__arrow" href="https://mailbox.org/en/blog/avoiding-shadow-IT-in-an-emergency/" aria-hidden="true"&gt;→&lt;/a&gt;
  &lt;a class="snip__link" href="https://mailbox.org/en/blog/avoiding-shadow-IT-in-an-emergency/"&gt;Read more about &lt;em class="placeholder"&gt;How to avoid shadow IT when your communication tools fail&lt;/em&gt;&lt;/a&gt;


    
  
  


</description>
  <guid isPermaLink="false">e6fcf9aa-3a3d-40d8-9f95-594258e79050</guid>
    <pubDate>Tue, 07 Apr 2026 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Moving away from the US cloud: Find European alternatives to Google and Microsoft</dc:title>
    <dc:identifier>e6fcf9aa-3a3d-40d8-9f95-594258e79050</dc:identifier>
    </item>
<item>
  <title>Label "Cybersecurity Made in Europe" for mailbox</title>
  <link>https://mailbox.org/en/news/label-cybersecurity-made-europe-mailbox/</link>
  <description>&lt;h2&gt;"Cybersecurity Made in Europe": Transparency builds trust&lt;/h2&gt;&lt;p&gt;The label makes it clear at first glance that mailbox has anchored its infrastructure and governance in Europe, fulfils verifiable security standards and guarantees European data protection. Holders of the label must:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;be a legal entity with its headquarters in Europe. If the company is part of a group of companies, the headquarters of the group must be registered in Europe.&lt;/li&gt;&lt;li&gt;European ownership must be ensured. There must be no significant ownership or control outside Europe.&lt;/li&gt;&lt;li&gt;prove that Europe is the primary business location and that over 50 % of its cybersecurity research and development activities and over 50 % of its employees (full-time equivalents) are based in the EU27, EFTA, EEA countries and the United Kingdom.&lt;/li&gt;&lt;li&gt;comply with the security requirements of the European Network and Information Security Agency (ENISA) for secure ICT products and services, including a no-spy declaration that ensures that no product or solution offered contains backdoors (undeclared functions).&lt;/li&gt;&lt;li&gt;comply with the GDPR.&lt;/li&gt;&lt;/ul&gt;


  
        
  
                &lt;img loading="lazy" src="https://mailbox.org/sites/default/files/2026-02/Cybersecurity%20made%20in%20Europe.png" width="1216" height="684" alt="Cybersecurity made in Europe"&gt;


      


  
              


  
    
    
    
    &lt;p&gt;Whether it's sensitive government communications that remain under German jurisdiction, business secrets that are secured against non-European access rights, or the protection of personal data and personal communication as well as control over your own data: With mailbox, companies, the public sector and private individuals benefit from legal certainty, GDPR conformity, information security, compliance and transparency. The label awarded by ECSO confirms that mailbox is not only committed to European sovereignty, but is actually European.&lt;/p&gt;&lt;h2&gt;Why digital sovereignty is now more important than ever&lt;/h2&gt;&lt;p&gt;The geopolitical developments of recent years impressively demonstrate how vulnerable dependence on non-European technology providers makes us. The US CLOUD Act, for example, obliges American companies to grant US authorities access to data – even if it is stored on servers in Europe. European companies, authorities and private individuals can thus inadvertently become transparent citizens. What's more:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Political uncertainties due to changing governments and legislation in third countries&lt;/li&gt;&lt;li&gt;Economic risks due to monopoly structures at US big tech companies&lt;/li&gt;&lt;li&gt;Legal grey areas in the transfer of personal data outside the EU&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;In this area of tension, digital sovereignty – the ability to control one's own digital infrastructure is being challenged, to have self-determination over one's own digital infrastructure – becomes a question of capacity to act.&lt;/p&gt;&lt;h2&gt;Beware of "sovereignty washing": Not every data centre in Europe is sovereign&lt;/h2&gt;&lt;p&gt;Many providers advertise with servers in Germany or Europe. However, a data centre in Germany does not make a US company or its subsidiary a European provider. The decisive factor is which law the company is subject to. mailbox is not dependent on non-European parent companies: As a German company, mailbox is subject exclusively to German and EU law – including the strict requirements of the General Data Protection Regulation (GDPR). Data processing at mailbox only takes place in Germany.&lt;/p&gt;&lt;h2&gt;Independently tested security at mailbox&lt;/h2&gt;&lt;p&gt;In addition to the "Cybersecurity Made in Europe" label, mailbox has received a number of other awards and certifications that prove the high quality and priority of data protection and information security:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;ISO/IEC 27001 certificate: The International Standard for Information Security Management Systems confirms that a company protects data and systems with a structured security management system and actively manages risks.&lt;/li&gt;&lt;li&gt;BSI C5-Typ 1-certificate: BSI C5 is the cloud criteria catalogue of the German Federal Office for Information Security (Bundesamt für Sicherheit in der Informationstechnik, BSI). A C5 certificate proves that a cloud provider works according to tested German cloud security criteria.&lt;/li&gt;&lt;li&gt;Quality seal "Software made in Germany" and "Software hosted in Germany" of the Bundesverband IT-Mittelstand e. V. (BITMi).V. (BITMi):&lt;ul&gt;&lt;li&gt;"Made in Germany": The seal of quality stands for IT solutions that are developed in Germany and whose quality assurance takes place in Germany.&lt;/li&gt;&lt;li&gt;"Hosted in Germany": All data and the software itself are demonstrably processed exclusively in German data centres and all data processing is subject exclusively to German law.&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;Gold status as part of the BSI Email Security Year 2025: mailbox has committed to fully implementing the latest email security standards and has already successfully implemented them.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Whoever chooses mailbox is not only opting for a secure digital workplace, but also for an independently audited European sovereign alternative to Big Tech. &lt;a href="https://mailbox.org/en/security/" data-entity-type="node" data-entity-uuid="2b846140-bfc8-4154-b324-43cee2bd3bfb" data-entity-substitution="canonical" title="Email encryption: Best protection for your data"&gt;Find out more&lt;/a&gt; about security, encryption, spam and virus protection with mailbox.&lt;/p&gt;

          
                                                  
      


  
    
      &lt;h2 class="ticket__title"&gt;Find out more about the certifications of mailbox!&lt;/h2&gt;
              

&lt;a data-component-id="boxy:knob" data-component-variant="tertiary" class="knob knob--tertiary" href="https://mailbox.org/en/certified-quality/"&gt;Discover certifications&lt;/a&gt;

          
    
          
                  
              
                  &lt;img loading="lazy" height="1632" width="2912" src="https://mailbox.org/sites/default/files/2025-05/news-trophy-1.png" alt="Trophy in recognition of excellent performance"&gt;

  


    
  

</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-trophy-2.png?itok=X4dOmDiQ" type="image/png" length="336184"/><guid isPermaLink="false">94bba910-b5a0-416c-a4ac-bb5c193948d5</guid>
    <pubDate>Mon, 16 Feb 2026 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Label "Cybersecurity Made in Europe" for mailbox</dc:title>
    <dc:identifier>94bba910-b5a0-416c-a4ac-bb5c193948d5</dc:identifier>
    </item>
<item>
  <title>Label "Cybersecurity Made in Europe" for mailbox</title>
  <link>https://mailbox.org/en/news/label-cybersecurity-made-europe-mailbox/</link>
  <description>&lt;h2&gt;"Cybersecurity Made in Europe": Transparency builds trust&lt;/h2&gt;&lt;p&gt;The label makes it clear at first glance that mailbox has anchored its infrastructure and governance in Europe, fulfils verifiable security standards and guarantees European data protection. Holders of the label must:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;be a legal entity with its headquarters in Europe. If the company is part of a group of companies, the headquarters of the group must be registered in Europe.&lt;/li&gt;&lt;li&gt;European ownership must be ensured. There must be no significant ownership or control outside Europe.&lt;/li&gt;&lt;li&gt;prove that Europe is the primary business location and that over 50 % of its cybersecurity research and development activities and over 50 % of its employees (full-time equivalents) are based in the EU27, EFTA, EEA countries and the United Kingdom.&lt;/li&gt;&lt;li&gt;comply with the security requirements of the European Network and Information Security Agency (ENISA) for secure ICT products and services, including a no-spy declaration that ensures that no product or solution offered contains backdoors (undeclared functions).&lt;/li&gt;&lt;li&gt;comply with the GDPR.&lt;/li&gt;&lt;/ul&gt;


  
        
  
                &lt;img loading="lazy" src="https://mailbox.org/sites/default/files/2026-02/Cybersecurity%20made%20in%20Europe.png" width="1216" height="684" alt="Cybersecurity made in Europe"&gt;


      


  
              


  
    
    
    
    &lt;p&gt;Whether it's sensitive government communications that remain under German jurisdiction, business secrets that are secured against non-European access rights, or the protection of personal data and personal communication as well as control over your own data: With mailbox, companies, the public sector and private individuals benefit from legal certainty, GDPR conformity, information security, compliance and transparency. The label awarded by ECSO confirms that mailbox is not only committed to European sovereignty, but is actually European.&lt;/p&gt;&lt;h2&gt;Why digital sovereignty is now more important than ever&lt;/h2&gt;&lt;p&gt;The geopolitical developments of recent years impressively demonstrate how vulnerable dependence on non-European technology providers makes us. The US CLOUD Act, for example, obliges American companies to grant US authorities access to data – even if it is stored on servers in Europe. European companies, authorities and private individuals can thus inadvertently become transparent citizens. What's more:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Political uncertainties due to changing governments and legislation in third countries&lt;/li&gt;&lt;li&gt;Economic risks due to monopoly structures at US big tech companies&lt;/li&gt;&lt;li&gt;Legal grey areas in the transfer of personal data outside the EU&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;In this area of tension, digital sovereignty – the ability to control one's own digital infrastructure is being challenged, to have self-determination over one's own digital infrastructure – becomes a question of capacity to act.&lt;/p&gt;&lt;h2&gt;Beware of "sovereignty washing": Not every data centre in Europe is sovereign&lt;/h2&gt;&lt;p&gt;Many providers advertise with servers in Germany or Europe. However, a data centre in Germany does not make a US company or its subsidiary a European provider. The decisive factor is which law the company is subject to. mailbox is not dependent on non-European parent companies: As a German company, mailbox is subject exclusively to German and EU law – including the strict requirements of the General Data Protection Regulation (GDPR). Data processing at mailbox only takes place in Germany.&lt;/p&gt;&lt;h2&gt;Independently tested security at mailbox&lt;/h2&gt;&lt;p&gt;In addition to the "Cybersecurity Made in Europe" label, mailbox has received a number of other awards and certifications that prove the high quality and priority of data protection and information security:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;ISO/IEC 27001 certificate: The International Standard for Information Security Management Systems confirms that a company protects data and systems with a structured security management system and actively manages risks.&lt;/li&gt;&lt;li&gt;BSI C5-Typ 1-certificate: BSI C5 is the cloud criteria catalogue of the German Federal Office for Information Security (Bundesamt für Sicherheit in der Informationstechnik, BSI). A C5 certificate proves that a cloud provider works according to tested German cloud security criteria.&lt;/li&gt;&lt;li&gt;Quality seal "Software made in Germany" and "Software hosted in Germany" of the Bundesverband IT-Mittelstand e. V. (BITMi).V. (BITMi):&lt;ul&gt;&lt;li&gt;"Made in Germany": The seal of quality stands for IT solutions that are developed in Germany and whose quality assurance takes place in Germany.&lt;/li&gt;&lt;li&gt;"Hosted in Germany": All data and the software itself are demonstrably processed exclusively in German data centres and all data processing is subject exclusively to German law.&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;Gold status as part of the BSI Email Security Year 2025: mailbox has committed to fully implementing the latest email security standards and has already successfully implemented them.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Whoever chooses mailbox is not only opting for a secure digital workplace, but also for an independently audited European sovereign alternative to Big Tech. &lt;a href="https://mailbox.org/en/security/" data-entity-type="node" data-entity-uuid="2b846140-bfc8-4154-b324-43cee2bd3bfb" data-entity-substitution="canonical" title="Email encryption: Best protection for your data"&gt;Find out more&lt;/a&gt; about security, encryption, spam and virus protection with mailbox.&lt;/p&gt;

          
                                                  
      


  
    
      &lt;h2 class="ticket__title"&gt;Find out more about the certifications of mailbox!&lt;/h2&gt;
              

&lt;a data-component-id="boxy:knob" data-component-variant="tertiary" class="knob knob--tertiary" href="https://mailbox.org/en/certified-quality/"&gt;Discover certifications&lt;/a&gt;

          
    
          
                  
              
                  &lt;img loading="lazy" height="1632" width="2912" src="https://mailbox.org/sites/default/files/2025-05/news-trophy-1.png" alt="Trophy in recognition of excellent performance"&gt;

  


    
  

</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-trophy-2.png?itok=X4dOmDiQ" type="image/png" length="336184"/><guid isPermaLink="false">94bba910-b5a0-416c-a4ac-bb5c193948d5</guid>
    <pubDate>Mon, 16 Feb 2026 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Label "Cybersecurity Made in Europe" for mailbox</dc:title>
    <dc:identifier>94bba910-b5a0-416c-a4ac-bb5c193948d5</dc:identifier>
    </item>
<item>
  <title>Transparency Report 2025: A quarter of all requests from authorities rejected</title>
  <link>https://mailbox.org/en/news/transparency-report-2025/</link>
  <description>&lt;h2&gt;Number of requests for information and most frequent reason for rejection&lt;/h2&gt;&lt;p&gt;In 2025, a total of 74 official requests for information were sent to mailbox. As in previous years, the most common reason for rejection remains the unencrypted transmission of the request: "Data protection and information security are a priority for mailbox. We also adhere to the strict requirements of the Federal Network Agency (Bundesnetzagentur) for requests for information from authorities, which stipulate that requests must be encrypted," explains Balint Gyemant, Chief Product Officer at mailbox.&lt;/p&gt;&lt;p&gt;Of the 63 requests sent to mailbox by email, however, 27 were unencrypted. A further six were unlawful for other reasons, and mailbox received five requests by post. "It is encouraging that we received no more enquiries by fax in 2025. This was still the case until 2024, although requests for information by fax have actually been prohibited since 2021," says Balint Gyemant.&lt;/p&gt;&lt;p&gt;Unlawful requests for information are consistently rejected by mailbox. In 2025, unencrypted requests were corrected by the investigating authorities in 15 cases, meaning that we responded to a total of 56 requests. 18 requests were not corrected and were rejected by us due to various deficiencies.&lt;/p&gt;&lt;h2&gt;Who submits which requests for information?&lt;/h2&gt;&lt;p&gt;The majority of requests for information in 2025 came from German authorities. Only three requests came from authorities in other EU countries and one request from an authority outside the EU. 72 requests for information were made in the context of criminal prosecution, two by intelligence services. Inventory data requests were the most common type of request, with only two relating to the seizure of mailboxes.&lt;/p&gt;


  
        
  
                &lt;img loading="lazy" src="https://mailbox.org/sites/default/files/2026-02/mailbox_transparency_report_2025_EN_0.png" width="1179" height="641" alt="mailbox Transparency Report 2025: Rejected requests for information"&gt;


      


  
              


  
    
    
    
    &lt;h2&gt;Data protection developments and geopolitical conditions&lt;/h2&gt;&lt;p&gt;We are publishing our transparency report at a time when data protection is under threat of weakening in the EU and worldwide. Twenty-five years ago, the European Data Protection Convention recognised the highest priority of protecting personal data and regulating its cross-border exchange. Today, these achievements are under attack like never before in the last 25 years: Anti-democratic forces and the EU's Digital Omnibus are threatening to weaken data protection. Chat control and data retention are being pushed forward again. In addition, the US CLOUD Act could become a gateway for data access in Europe. We are monitoring these developments closely and critically. Data protection and information security remain our priority.&lt;/p&gt;&lt;h2&gt;In a nutshell: requests compared to the previous year&lt;/h2&gt;&lt;ol&gt;&lt;li&gt;The total number of requests fell again in 2025: by 10.84 % from 83 (2024) to 74.&lt;/li&gt;&lt;li&gt;In 2025, 75.7 % of requests were ultimately submitted correctly – in some cases only at the second attempt. In 2024, the final figure was 69.9 %.&lt;/li&gt;&lt;li&gt;As in the previous year, we received the majority of enquiries by email in 2025, encrypted with PGP.&lt;/li&gt;&lt;/ol&gt;&lt;h2&gt;An overview of the specific figures for 2025&lt;/h2&gt;&lt;h3&gt;Number of requests to mailbox&lt;/h3&gt;&lt;p&gt;Total: 74&lt;br&gt;of which German authorities: 70&lt;br&gt;of which foreign EU authorities: 3&lt;br&gt;of which foreign non-EU authorities: 1&lt;/p&gt;&lt;h3&gt;Type of authority&lt;/h3&gt;&lt;p&gt;Criminal investigative authorities: 72&lt;br&gt;Intelligence services: 2&lt;br&gt;Customs authorities: 0&lt;/p&gt;&lt;h3&gt;Type of request&lt;/h3&gt;&lt;p&gt;Contact data requests: 72&lt;br&gt;Inbox confiscations: 2&lt;br&gt;Traffic data requests: 0&lt;br&gt;Telecommunications interceptions: 0&lt;/p&gt;&lt;p&gt;The reports from recent years can be found at &lt;a href="https://mailbox.org/en/transparency-report" target="_blank" title="About the transparency reports of mailbox.org" id="2601" rel="noopener"&gt;Transparency reports&lt;/a&gt;.&lt;/p&gt;

          
                                                  
      

  
    
      &lt;h2 class="accordion__headline"&gt;FAQ&lt;/h2&gt;
          
    
    
                        
            
              How we deal with requests
              
                
              
            

            
              
                &lt;p&gt;mailbox follows a standardised process when dealing with requests for information from official authorities. Each request will be comprehensively reviewed and assessed by our data protection officer and a lawyer, and then either processed or rejected accordingly. When a request gets rejected, the submitting authority may correct any errors and then resubmit for another review. Data will only be released by us if a related request is actually lawful and formally correct.&lt;/p&gt;
              
            
          
                                
            
              Data that authorities may be interested in
              
                
              
            

            
              
                &lt;ol&gt;&lt;li&gt;Contact data: This includes the name, address and phone number of the account holder, as well as details about their contract with us.&lt;/li&gt;&lt;li&gt;E-mail data: Access to all e-mails currently held in an account's mailbox.&lt;/li&gt;&lt;li&gt;Traffic data: The IP addresses associated with mail server logins when fetching, reading, or sending e-mails.&lt;/li&gt;&lt;li&gt;Telecommunications interception data: Obtained through the temporary surveillance of all ongoing e-mail communication of an account.&lt;/li&gt;&lt;/ol&gt;
              
            
          
                  

  

</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-04/mailbox-news-und-updates-transparenzbericht.jpg?itok=SMV4eTPL" type="image/jpeg" length="268110"/><guid isPermaLink="false">f5648aa2-1257-4e42-9435-c24087637cde</guid>
    <pubDate>Tue, 10 Feb 2026 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Transparency Report 2025: A quarter of all requests from authorities rejected</dc:title>
    <dc:identifier>f5648aa2-1257-4e42-9435-c24087637cde</dc:identifier>
    </item>
<item>
  <title>Transparency Report 2025: A quarter of all requests from authorities rejected</title>
  <link>https://mailbox.org/en/news/transparency-report-2025/</link>
  <description>&lt;h2&gt;Number of requests for information and most frequent reason for rejection&lt;/h2&gt;&lt;p&gt;In 2025, a total of 74 official requests for information were sent to mailbox. As in previous years, the most common reason for rejection remains the unencrypted transmission of the request: "Data protection and information security are a priority for mailbox. We also adhere to the strict requirements of the Federal Network Agency (Bundesnetzagentur) for requests for information from authorities, which stipulate that requests must be encrypted," explains Balint Gyemant, Chief Product Officer at mailbox.&lt;/p&gt;&lt;p&gt;Of the 63 requests sent to mailbox by email, however, 27 were unencrypted. A further six were unlawful for other reasons, and mailbox received five requests by post. "It is encouraging that we received no more enquiries by fax in 2025. This was still the case until 2024, although requests for information by fax have actually been prohibited since 2021," says Balint Gyemant.&lt;/p&gt;&lt;p&gt;Unlawful requests for information are consistently rejected by mailbox. In 2025, unencrypted requests were corrected by the investigating authorities in 15 cases, meaning that we responded to a total of 56 requests. 18 requests were not corrected and were rejected by us due to various deficiencies.&lt;/p&gt;&lt;h2&gt;Who submits which requests for information?&lt;/h2&gt;&lt;p&gt;The majority of requests for information in 2025 came from German authorities. Only three requests came from authorities in other EU countries and one request from an authority outside the EU. 72 requests for information were made in the context of criminal prosecution, two by intelligence services. Inventory data requests were the most common type of request, with only two relating to the seizure of mailboxes.&lt;/p&gt;


  
        
  
                &lt;img loading="lazy" src="https://mailbox.org/sites/default/files/2026-02/mailbox_transparency_report_2025_EN_0.png" width="1179" height="641" alt="mailbox Transparency Report 2025: Rejected requests for information"&gt;


      


  
              


  
    
    
    
    &lt;h2&gt;Data protection developments and geopolitical conditions&lt;/h2&gt;&lt;p&gt;We are publishing our transparency report at a time when data protection is under threat of weakening in the EU and worldwide. Twenty-five years ago, the European Data Protection Convention recognised the highest priority of protecting personal data and regulating its cross-border exchange. Today, these achievements are under attack like never before in the last 25 years: Anti-democratic forces and the EU's Digital Omnibus are threatening to weaken data protection. Chat control and data retention are being pushed forward again. In addition, the US CLOUD Act could become a gateway for data access in Europe. We are monitoring these developments closely and critically. Data protection and information security remain our priority.&lt;/p&gt;&lt;h2&gt;In a nutshell: requests compared to the previous year&lt;/h2&gt;&lt;ol&gt;&lt;li&gt;The total number of requests fell again in 2025: by 10.84 % from 83 (2024) to 74.&lt;/li&gt;&lt;li&gt;In 2025, 75.7 % of requests were ultimately submitted correctly – in some cases only at the second attempt. In 2024, the final figure was 69.9 %.&lt;/li&gt;&lt;li&gt;As in the previous year, we received the majority of enquiries by email in 2025, encrypted with PGP.&lt;/li&gt;&lt;/ol&gt;&lt;h2&gt;An overview of the specific figures for 2025&lt;/h2&gt;&lt;h3&gt;Number of requests to mailbox&lt;/h3&gt;&lt;p&gt;Total: 74&lt;br&gt;of which German authorities: 70&lt;br&gt;of which foreign EU authorities: 3&lt;br&gt;of which foreign non-EU authorities: 1&lt;/p&gt;&lt;h3&gt;Type of authority&lt;/h3&gt;&lt;p&gt;Criminal investigative authorities: 72&lt;br&gt;Intelligence services: 2&lt;br&gt;Customs authorities: 0&lt;/p&gt;&lt;h3&gt;Type of request&lt;/h3&gt;&lt;p&gt;Contact data requests: 72&lt;br&gt;Inbox confiscations: 2&lt;br&gt;Traffic data requests: 0&lt;br&gt;Telecommunications interceptions: 0&lt;/p&gt;&lt;p&gt;The reports from recent years can be found at &lt;a href="https://mailbox.org/en/transparency-report" target="_blank" title="About the transparency reports of mailbox.org" id="2601" rel="noopener"&gt;Transparency reports&lt;/a&gt;.&lt;/p&gt;

          
                                                  
      

  
    
      &lt;h2 class="accordion__headline"&gt;FAQ&lt;/h2&gt;
          
    
    
                        
            
              How we deal with requests
              
                
              
            

            
              
                &lt;p&gt;mailbox follows a standardised process when dealing with requests for information from official authorities. Each request will be comprehensively reviewed and assessed by our data protection officer and a lawyer, and then either processed or rejected accordingly. When a request gets rejected, the submitting authority may correct any errors and then resubmit for another review. Data will only be released by us if a related request is actually lawful and formally correct.&lt;/p&gt;
              
            
          
                                
            
              Data that authorities may be interested in
              
                
              
            

            
              
                &lt;ol&gt;&lt;li&gt;Contact data: This includes the name, address and phone number of the account holder, as well as details about their contract with us.&lt;/li&gt;&lt;li&gt;E-mail data: Access to all e-mails currently held in an account's mailbox.&lt;/li&gt;&lt;li&gt;Traffic data: The IP addresses associated with mail server logins when fetching, reading, or sending e-mails.&lt;/li&gt;&lt;li&gt;Telecommunications interception data: Obtained through the temporary surveillance of all ongoing e-mail communication of an account.&lt;/li&gt;&lt;/ol&gt;
              
            
          
                  

  

</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-04/mailbox-news-und-updates-transparenzbericht.jpg?itok=SMV4eTPL" type="image/jpeg" length="268110"/><guid isPermaLink="false">f5648aa2-1257-4e42-9435-c24087637cde</guid>
    <pubDate>Tue, 10 Feb 2026 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Transparency Report 2025: A quarter of all requests from authorities rejected</dc:title>
    <dc:identifier>f5648aa2-1257-4e42-9435-c24087637cde</dc:identifier>
    </item>
<item>
  <title>S/MIME: Secure e-mail encryption and signature</title>
  <link>https://mailbox.org/en/blog/smime-secure-e-mail-encryption-and-signature/</link>
  <description>&lt;p&gt;&lt;em&gt;Reading time: 9 minutes&lt;/em&gt;&lt;/p&gt;&lt;p&gt;Email is still the most important means of communication in the digital world. However, the email correspondence of over 4.5 billion users worldwide is exposed to attacks on a daily basis. This makes reliable solutions for encryption and digital signatures all the more important. In this article, you will learn how to protect your email communication with S/MIME, ensure the authenticity of your correspondence and use S/MIME at mailbox.&lt;/p&gt;


      
                  
              
              
              
              
              
              
              
                  &lt;img loading="lazy" height="3187" width="4789" src="https://mailbox.org/sites/default/files/2026-01/Blog_SMIME.jpeg" alt="mailbox: Der sichere digitale Arbeitsplatz. Ein junger Mann sitzt am Schreibtisch und blickt zufrieden in das Notebookdisplay vor ihm."&gt;

  


  
          

              


  
    
    
    
    &lt;h2&gt;What is S/MIME?&lt;/h2&gt;&lt;p&gt;S/MIME stands for Secure/Multipurpose Internet Mail Extensions and is an internationally recognised standard for email encryption and digital signatures for emails. MIME (Multipurpose Internet Mail Extensions) is the standard for the transmission of various file types via email – S/MIME extends this with security functions.&lt;/p&gt;&lt;p&gt;S/MIME is based on public-key encryption, also known as asymmetric encryption. This technology enables the secure transmission of confidential emails over the internet. S/MIME is supported by mailbox and most other email clients, fulfils high data protection requirements and offers legal security through trusted certification authorities.&lt;/p&gt;&lt;h2&gt;How does S/MIME encryption and signing work with S/MIME?&lt;/h2&gt;&lt;p&gt;With public-key encryption, each user has a key pair consisting of a public key and a private key. The public key is passed on to communication partners and is used to encrypt messages. The private key remains secret and is used to decrypt received messages and to create digital signatures.&lt;/p&gt;&lt;p&gt;S/MIME works with X.509 certificates, which are issued by trustworthy certification authorities. These digital certificates contain the user's public key and make it possible to verify the identity of the sender and encrypt the messages.&lt;/p&gt;&lt;h3&gt;How S/MIME encryption works explained step by step:&lt;/h3&gt;&lt;p&gt;In order to encrypt an email before sending and decrypt it after receiving it, the communication partners must set up S/MIME before the first encrypted email.&lt;/p&gt;&lt;h4&gt;One-time setup:&lt;/h4&gt;&lt;ol&gt;&lt;li&gt;The communication partners request an S/MIME certificate from a certificate authority. The certificate contains the sender's private key.&lt;/li&gt;&lt;li&gt;The communication partners set up their certificates for encryption and signing.&lt;/li&gt;&lt;li&gt;The sender requires the recipient's public key or S/MIME certificate. This is usually done easily and automatically by email: The public key is attached to a message and the mail client on the recipient's side automatically saves the key.&lt;/li&gt;&lt;/ol&gt;&lt;h4&gt;The encryption process with S/MIME:&lt;/h4&gt;&lt;ol&gt;&lt;li&gt;The sender encrypts the email. The mail client generates a random symmetric session key for this individual message.&lt;/li&gt;&lt;li&gt;This session key is in turn encrypted asymmetrically by the mail client using the recipient's known public key. Both the content of the message and the session key are now encrypted.&lt;/li&gt;&lt;li&gt;The encrypted message is transmitted.&lt;/li&gt;&lt;li&gt;The recipient's mail client recognises the S/MIME-encrypted message.&lt;/li&gt;&lt;li&gt;The recipient uses their private key to decrypt the session key.&lt;/li&gt;&lt;li&gt;The recipient uses the session key to decrypt the content of the email.&lt;/li&gt;&lt;/ol&gt;&lt;h3&gt;How S/MIME signing works explained step by step:&lt;/h3&gt;&lt;p&gt;The S/MIME signature is used to prove that the sender is actually the sender of the message. The signature alone does not encrypt the message.&lt;/p&gt;&lt;h4&gt;The signing process with S/MIME:&lt;/h4&gt;&lt;ol&gt;&lt;li&gt;The sender signs the email digitally with their private key. The mail client calculates a hash – a kind of fingerprint – of the content and generates the digital signature.&lt;/li&gt;&lt;li&gt;The signed message is transmitted.&lt;/li&gt;&lt;li&gt;The recipient's mail client recognises the S/MIME signature of the received message and checks the certificate.&lt;/li&gt;&lt;li&gt;The mail client then calculates the hash of the received content and verifies the signature with the public key from the sender's certificate.&lt;/li&gt;&lt;li&gt;This allows the recipient to confirm the identity of the sender and recognise whether the message is unchanged.&lt;/li&gt;&lt;/ol&gt;&lt;h2&gt;Email security with S/MIME: The three pillars&lt;/h2&gt;&lt;p&gt;S/MIME offers three essential security functions that together ensure a high level of protection for your email communication. This combination of encryption and digital signature makes S/MIME the preferred solution for secure business correspondence.&lt;/p&gt;&lt;h3&gt;1. Confidentiality through email encryption&lt;/h3&gt;&lt;p&gt;Encryption ensures that only the intended recipient can read the content of the email. This provides protection against unauthorised access to confidential information during transmission. S/MIME encryption is carried out using the recipient's public key, which can only be decrypted using the recipient's private key. This asymmetric encryption ensures maximum security for personal data in accordance with the requirements of the GDPR.&lt;/p&gt;&lt;h3&gt;2. Integrity through digital signature&lt;/h3&gt;&lt;p&gt;The digital signature enables the recipient to check whether the message has been manipulated during transmission. Any change to the content, no matter how small, renders the S/MIME signature invalid. The digital signature is created using the sender's private key and can be verified by the recipient using the public key. This guarantees message integrity.&lt;/p&gt;&lt;h3&gt;3. Authenticity and email authentication&lt;/h3&gt;&lt;p&gt;The digital signature confirms the identity of the sender and ensures that the email actually comes from the person specified. This protects against phishing and spoofing attacks. In addition, the sender cannot deny having sent the message – an important aspect for legally compliant email communication in a business context.&lt;/p&gt;&lt;h3&gt;Interaction with TLS&lt;/h3&gt;&lt;p&gt;S/MIME can be used simultaneously with other security technologies such as Transport Layer Security (TLS). TLS encrypts the connection between email servers during transmission. So while TLS protects the transport routes, S/MIME provides end-to-end encryption of the message itself – from sender to recipient. This combination ensures maximum email security at all levels of transmission.&lt;/p&gt;&lt;p&gt;Important to know: With S/MIME, the subject line and metadata – i.e. sender, recipient, timestamp and routing information – are not encrypted. For maximum confidentiality, subject lines should therefore not contain any sensitive information.&lt;/p&gt;&lt;h2&gt;S/MIME certificates: classes and sources&lt;/h2&gt;&lt;p&gt;S/MIME certificates are divided into different classes, which differ in the scope of identity verification by the certificate authority:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Class 1 certificates: Only the email address is verified. This is automated and is usually free of charge. Suitable for basic email security.&lt;/li&gt;&lt;li&gt;Class 2 certificates: In addition, the name and, if applicable, the organisation are verified. Ideal for companies and secure business correspondence.&lt;/li&gt;&lt;li&gt;Class 3 certificates: Comprehensive identity verification based on ID documents or extracts from the commercial register. Highest level of trust for confidential emails.&lt;/li&gt;&lt;li&gt;Class 4 certificates: Personal identity verification with mandatory identification at the certification authority. Maximum email authentication.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Digital certificates for S/MIME can be obtained from various trusted certification authorities. Established providers include Thawte, VeriSign and DigiCert.&lt;/p&gt;&lt;p&gt;Important note on certificate security: Certificates that you create yourself are not classified as trustworthy by most email clients and should not be used as they jeopardise secure email communication and do not provide reliable email authentication. For example, &lt;a href="https://kb.mailbox.org/en/private/encryption/s-mime-encryption/"&gt;mailbox&lt;/a&gt; does not accept self-generated certificates.&lt;/p&gt;&lt;h2&gt;S/MIME vs PGP: Differences in email encryption&lt;/h2&gt;&lt;p&gt;In addition to S/MIME, &lt;a href="https://mailbox.org/en/blog/pgp-encryption-at-mailboxorg/" data-entity-type="node" data-entity-uuid="5c710490-9276-4b9f-854d-c9c1b4af845b" data-entity-substitution="canonical" title="PGP encryption for maximum email protection"&gt;PGP (Pretty Good Privacy)&lt;/a&gt; is another established standard for email encryption. Both encryption methods pursue the same goal – secure email communication – and both use asymmetric encryption with public and private keys.&lt;/p&gt;&lt;p&gt;Both standards offer strong email encryption and digital signatures, but they differ in important aspects of implementation and certificate management. mailbox supports both encryption methods and allows users to choose the appropriate method for email encryption depending on the communication partner.&lt;/p&gt;&lt;h2&gt;S/MIME with mailbox: Encrypt and sign emails&lt;/h2&gt;&lt;p&gt;mailbox supports S/MIME encryption in the webmailer for all customers on the Premium, Standard and Light tariffs. This email security function is particularly relevant for business customers, as not only encryption but also digital signatures play an important role in GDPR-compliant communication.&lt;/p&gt;&lt;p&gt;mailbox offers the option of using S/MIME certificates from over 100 reliable certification authorities with mailbox Guard. For security reasons, mailbox does not accept self-created certificates. &lt;a href="https://kb.mailbox.org/en/private/encryption/s-mime-encryption/"&gt;Find out more&lt;/a&gt; about the certificates supported by mailbox.&lt;/p&gt;&lt;p&gt;In mailbox, you can encrypt and sign emails with S/MIME using a button. Only supported certificates are recognised and the digital signature is automatically verified when S/MIME-signed emails are received. This is how S/MIME ensures secure email communication with authentication.&lt;/p&gt;&lt;p&gt;S/MIME step-by-step guide: &lt;a href="https://kb.mailbox.org/en/private/encryption/s-mime-encryption/"&gt;In our knowledge base&lt;/a&gt; you can find out everything you need to know about setting up and using S/MIME at mailbox.&lt;/p&gt;&lt;h2&gt;Conclusion: S/MIME for secure email communication&lt;/h2&gt;&lt;p&gt;S/MIME is a proven and widely used standard for email encryption and digital signatures. The integration into common email clients makes email security particularly easy to use, while the certification authorities ensure trust and reliability in email authentication. In the business environment in particular, S/MIME offers comprehensive protection for confidential emails and GDPR-compliant communication thanks to digital signatures and end-to-end encryption.&lt;/p&gt;&lt;p&gt;mailbox's support for S/MIME enables both private and business customers to secure their email communication with professional email encryption. With the correct setup of an S/MIME certificate and the choice of a trustworthy certification authority, nothing stands in the way of secure and authenticated email communication. In a time of increasing cyberattacks, encrypting confidential information with digital signatures is no longer an option, but a necessity for secure email communication.&lt;/p&gt;

          
                                                  
      


      
      &lt;h2 class="row__intro__title"&gt;            Insights &amp;amp; Trends
      &lt;/h2&gt;
      Discover more articles on the topic of security.
              
            

&lt;a data-component-id="boxy:knob" data-component-variant="secondary" class="knob knob--secondary" href="https://mailbox.org/en/insights/"&gt;All articles&lt;/a&gt;

        
          
    
      
      
  
  
                    
                  
              
                  &lt;img loading="lazy" height="2160" width="4096" src="https://mailbox.org/sites/default/files/2026-08/mailbox%20EVAC%20Blog%20IT-Sicherheit%20kleine%20Unternehmen.jpeg" alt="mailbox EVAC Blog IT-Sicherheit kleine Unternehmen"&gt;

  


      
      
      
      Business Continuitiy, Security
    
    &lt;h3 class="snip__title"&gt;IT security: Why small businesses in particular are targeted by cyberattacks&lt;/h3&gt;
  &lt;a class="snip__arrow" href="https://mailbox.org/en/blog/IT-security-for-small-businesses/" aria-hidden="true"&gt;→&lt;/a&gt;
  &lt;a class="snip__link" href="https://mailbox.org/en/blog/IT-security-for-small-businesses/"&gt;Read more about &lt;em class="placeholder"&gt;IT security: Why small businesses in particular are targeted by cyberattacks&lt;/em&gt;&lt;/a&gt;


    
      
      
  
  
                    
                  
              
                  &lt;img loading="lazy" height="4912" width="7360" src="https://mailbox.org/sites/default/files/2026-07/mailbox%20EVAC%20Blog%20Schatten-IT%20als%20Notfalllo%CC%88sung%20vermeiden.jpeg" alt="mailbox EVAC Blog Schatten-IT als Notfalllösung vermeiden"&gt;

  


      
      
      
      Business Continuitiy, Security
    
    &lt;h3 class="snip__title"&gt;How to avoid shadow IT when your communication tools fail&lt;/h3&gt;
  &lt;a class="snip__arrow" href="https://mailbox.org/en/blog/avoiding-shadow-IT-in-an-emergency/" aria-hidden="true"&gt;→&lt;/a&gt;
  &lt;a class="snip__link" href="https://mailbox.org/en/blog/avoiding-shadow-IT-in-an-emergency/"&gt;Read more about &lt;em class="placeholder"&gt;How to avoid shadow IT when your communication tools fail&lt;/em&gt;&lt;/a&gt;


    
  
  


</description>
  <guid isPermaLink="false">fcb79eca-189f-4b16-af88-c0f2a34ede37</guid>
    <pubDate>Thu, 29 Jan 2026 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>S/MIME: Secure e-mail encryption and signature</dc:title>
    <dc:identifier>fcb79eca-189f-4b16-af88-c0f2a34ede37</dc:identifier>
    </item>
<item>
  <title>NIS-2 Implementation Act Germany: Obligations &amp; Business Continuity</title>
  <link>https://mailbox.org/en/blog/nis-2-implementation-act-germany-obligations-business-continuity/</link>
  <description>&lt;p&gt;&lt;em&gt;Reading time: 6 minutes&lt;/em&gt;&lt;/p&gt;&lt;p&gt;With NIS-2, the EU is making cybersecurity a joint task. The German NIS-2 Implementation Act has been in force since 6 December 2025. What companies, authorities and other organisations need to know now about how they are affected, their obligations and the role of business continuity management.&lt;/p&gt;


      
                  
              
              
              
              
              
              
              
                  &lt;img loading="lazy" height="1632" width="2912" src="https://mailbox.org/sites/default/files/2025-05/news-jurisdiction-2.png" alt="Decision announced with a judge's gavel"&gt;

  


  
          

              


  
    
    
    
    &lt;h3&gt;What is NIS-2? What does the NIS-2 Implementation Act mean for Germany?&lt;/h3&gt;&lt;p&gt;The NIS-2 Directive is the second EU directive on network and information security. It obliges significantly more organisations than before to systematically improve their IT and information security and report cyber incidents. It also makes cyber security a mandatory task at management level and supplements existing requirements such as the GDPR, ISO standards or BSI specifications – with significantly stricter sanctions for violations.&lt;/p&gt;&lt;p&gt;NIS-2 has been a binding legal act of the European Union at EU level since 2023. It is transposed into national law in the member states – in Germany via the NIS-2 Implementation Act (NIS-2-UmsuCG). The law came into force on 6 December 2025. There is no general transition period, i.e. affected organisations and companies must fulfil their obligations immediately after entry into force.&lt;/p&gt;&lt;h3&gt;Check NIS-2 compliance: These organisations must act&lt;/h3&gt;&lt;p&gt;In Germany, an estimated 29,500 new critical entities ("wichtige Einrichtungen" – wE) or particularly critical entities ("besonders wichtige Einrichtungen" – bwE) are affected. The decisive factor in determining whether an organisation is affected is whether it belongs to a certain sector or not, as well as the number of employees, annual turnover and annual balance sheet total.&lt;/p&gt;&lt;p&gt;The organisations affected include:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;KRITIS ("Kritische Infrastrukturen" – automatically classified as bwE)&lt;/li&gt;&lt;li&gt;natural or&lt;/li&gt;&lt;li&gt;legal entities or&lt;/li&gt;&lt;li&gt;legally dependent organisational units of a local authority,&lt;/li&gt;&lt;li&gt;that offer goods or services to other natural or legal persons in return for payment and&lt;/li&gt;&lt;li&gt;that are assigned to one of the sectors concerned and&lt;/li&gt;&lt;li&gt;that have at least 50 (wE) or at least 250 employees (bwE). at least 250 employees (bwE) or&lt;/li&gt;&lt;li&gt;have an annual turnover of more than 10 (wE) or 50 (bwE) million euros and&lt;/li&gt;&lt;li&gt;an annual balance sheet total of more than 10 (wE) or 43 (bwE) million euros.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;The affected sectors include energy, transport, banking and healthcare, digital and financial market infrastructure, drinking water and wastewater, management of ICT services, public administration and space. Also affected are postal and courier services, waste management, production, manufacture and trade of chemicals, production, processing and distribution of food, manufacturing and production of goods, digital service providers and research.&lt;/p&gt;&lt;h3&gt;NIS-2 obligations: Registration, risk management and reporting obligations&lt;/h3&gt;&lt;p&gt;Affected organisations face extensive new requirements. The most important obligations of the German NIS-2 Implementation Act at a glance:&lt;/p&gt;&lt;h4&gt;Registration obligation&lt;/h4&gt;&lt;p&gt;Important and particularly important institutions are obliged to register with the registration body no later than three months after they are affected by NIS-2 for the first time or again. The Federal Office for Information Security (Bundesamt für Sicherheit in der Informationstechnik – BSI) is the supervisory authority for affected organisations in Germany.&lt;/p&gt;&lt;h4&gt;Risk management&lt;/h4&gt;&lt;p&gt;In accordance with § 30 BSIG-new (BSI Act), affected organisations must implement and document suitable, effective and proportionate risk management measures. Risk management is intended to prevent disruptions and minimise the impact of security incidents. A key factor for organisations affected by NIS-2 is the improvement of cyber security, including incident management and business continuity management.&lt;/p&gt;&lt;h4&gt;Mandatory reporting&lt;/h4&gt;&lt;p&gt;The BSI must be notified of serious operational disruptions or security incidents that could lead to significant material or immaterial damage for third parties. There is a defined reporting process for this.&lt;/p&gt;&lt;h3&gt;What are the penalties for NIS-2 violations?&lt;/h3&gt;&lt;p&gt;For violations of the NIS 2 Implementation Act, affected organisations face severe penalties that go well beyond previous regulations. Violations include a lack of risk management, inadequate security measures or failure to comply with reporting obligations – in other words, not only security breaches but also organisational failures. The amount of the fines depends on whether the organisations in question are important or particularly important. They can amount to up to 10 million euros or 2 % of annual global turnover. There is also the threat of injunctions, coercive measures and reputational damage.&lt;/p&gt;&lt;p&gt;In § 38 of BSIG-new, management boards are expressly obliged to implement and monitor risk management measures and are also subject to a regular training obligation. Management boards are personally liable if they violate their implementation and monitoring obligations.&lt;/p&gt;&lt;h3&gt;Business continuity management: obligation and success factor for NIS-2 compliance&lt;/h3&gt;&lt;p&gt;NIS-2 is aimed at the resilience of organisations: They must remain capable of acting even in the event of cyber attacks, IT failures or crises. As NIS-2 requires critical business processes to be maintained, business continuity management (BCM) plays a central role in fulfilling the NIS-2 implementation law.&lt;/p&gt;&lt;p&gt;In the event of an emergency, specific measures must be defined and documented in order to be able to react immediately in crisis situations. Against the backdrop of increasing cyberattacks, one thing is crucial for a continuous ability to act: being able to continue to communicate and collaborate in teams. EVAC by mailbox provides a reliable secondary communication platform when primary systems fail.&lt;/p&gt;

          
                                                  
      


  
    
      &lt;h2 class="ticket__title"&gt;Business continuity at the touch of a button&lt;/h2&gt;
              

&lt;a data-component-id="boxy:knob" data-component-variant="tertiary" class="knob knob--tertiary" href="https://mailbox.org/en/evac/"&gt;Discover EVAC now&lt;/a&gt;

          
    
          
                  
              
                  &lt;img loading="lazy" height="1632" width="2944" src="https://mailbox.org/sites/default/files/2025-04/mailbox-evac-button-web-rgb.jpg" alt="Kommunikation auf Knopfdruck"&gt;

  


    
  



      
      &lt;h2 class="row__intro__title"&gt;            Insights &amp;amp; Trends
      &lt;/h2&gt;
      Discover more articles on the topic of security.
              
            

&lt;a data-component-id="boxy:knob" data-component-variant="secondary" class="knob knob--secondary" href="https://mailbox.org/en/insights/"&gt;All articles&lt;/a&gt;

        
          
    
      
      
  
  
                    
                  
              
                  &lt;img loading="lazy" height="2160" width="4096" src="https://mailbox.org/sites/default/files/2026-08/mailbox%20EVAC%20Blog%20IT-Sicherheit%20kleine%20Unternehmen.jpeg" alt="mailbox EVAC Blog IT-Sicherheit kleine Unternehmen"&gt;

  


      
      
      
      Business Continuitiy, Security
    
    &lt;h3 class="snip__title"&gt;IT security: Why small businesses in particular are targeted by cyberattacks&lt;/h3&gt;
  &lt;a class="snip__arrow" href="https://mailbox.org/en/blog/IT-security-for-small-businesses/" aria-hidden="true"&gt;→&lt;/a&gt;
  &lt;a class="snip__link" href="https://mailbox.org/en/blog/IT-security-for-small-businesses/"&gt;Read more about &lt;em class="placeholder"&gt;IT security: Why small businesses in particular are targeted by cyberattacks&lt;/em&gt;&lt;/a&gt;


    
      
      
  
  
                    
                  
              
                  &lt;img loading="lazy" height="2160" width="4096" src="https://mailbox.org/sites/default/files/2026-08/mailbox%20EVAC%20Blog%20Business%20Continuity%20in%20der%20Lieferkette.jpeg" alt="mailbox EVAC Blog Business Continuity in der Lieferkette"&gt;

  


      
      
      
      Best practice, Business Continuitiy
    
    &lt;h3 class="snip__title"&gt;How to use business continuity as a competitive advantage in the supply chain&lt;/h3&gt;
  &lt;a class="snip__arrow" href="https://mailbox.org/en/blog/business-continuity-supply-chain/" aria-hidden="true"&gt;→&lt;/a&gt;
  &lt;a class="snip__link" href="https://mailbox.org/en/blog/business-continuity-supply-chain/"&gt;Read more about &lt;em class="placeholder"&gt;How to use business continuity as a competitive advantage in the supply chain&lt;/em&gt;&lt;/a&gt;


    
  
  


</description>
  <guid isPermaLink="false">39c7c4b3-4771-4a2d-be32-be147cb897ed</guid>
    <pubDate>Thu, 22 Jan 2026 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>NIS-2 Implementation Act Germany: Obligations &amp; Business Continuity</dc:title>
    <dc:identifier>39c7c4b3-4771-4a2d-be32-be147cb897ed</dc:identifier>
    </item>
<item>
  <title>EVAC by mailbox: Business Continuity and Capacity to act</title>
  <link>https://mailbox.org/en/news/evac-mailbox-business-continuity-and-capacity-act/</link>
  <description>&lt;h2&gt;One step ahead of the crisis with EVAC&lt;/h2&gt;&lt;p&gt;According to the World Economic Forum, 72 % of all organisations worldwide reported an increasing cyber risk in 2025. With EVAC, you are not alone in an emergency. Your communication continues – securely, reliably and immediately. EVAC includes a complete communication infrastructure in the web interface:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Email communication via web-based access&lt;/li&gt;&lt;li&gt;Video conferencing for virtual meetings&lt;/li&gt;&lt;li&gt;Drive for file storage and exchange&lt;/li&gt;&lt;li&gt;Online Office for collaborative document editing&lt;/li&gt;&lt;li&gt;Calendar &amp;amp; address book for appointment coordination&lt;/li&gt;&lt;li&gt;Task management for project organisation&lt;/li&gt;&lt;/ul&gt;


  
        
  
                &lt;img loading="lazy" src="https://mailbox.org/sites/default/files/2026-01/EVAC_Console_EN.png" width="4095" height="2167" alt="EVAC Console mailbox"&gt;


      


  
              


  
    
    
    
    &lt;h2&gt;Mastering NIS-2 and BSI Standard 200-4 with EVAC&lt;/h2&gt;&lt;p&gt;In accordance with the NIS-2 Directive and the German NIS-2-UmsuCG, companies and authorities must prove that they have functioning business continuity measures in place. EVAC supports you in fulfilling key NIS-2 requirements, e.g. in risk management, incident response and reporting obligations.&lt;/p&gt;&lt;p&gt;In addition, EVAC helps you to fulfil the requirements of BSI Standard 200-4 on business continuity management: As part of your business continuity plan (CFP), EVAC enables you to continue your time-critical business processes.&lt;/p&gt;&lt;h2&gt;Minimising the recovery time objective (RTO) with EVAC&lt;/h2&gt;&lt;p&gt;In 2024, according to IBM, the inability to act after a cyberattack averaged 185 days. In the same year, the damage caused by cybercrime in Germany alone totalled 178.6 billion euros. Whether cyberattacks and ransomware, hardware and server failures or power outages and natural disasters – in the event of a crisis, minimising the RTO is crucial to reducing downtime. EVAC was developed specifically for this requirement and works in three simple steps:&lt;/p&gt;&lt;p&gt;1. Selection and preparation: You select the desired mailboxes and data. You can add or remove them at any time. Your EVAC platform is ready in standby mode.&lt;/p&gt;&lt;p&gt;2. Activation in an emergency: The emergency mailboxes are activated and employees automatically receive instructions on password assignment and access.&lt;/p&gt;&lt;p&gt;3. Communication continues: Your employees access their mailboxes via webmail – including cloud storage, video conferencing, online office, calendar and task management. Business communication continues without interruption.&lt;/p&gt;&lt;h2&gt;EVAC: Security even in times of crisis&lt;/h2&gt;&lt;p&gt;Even in times of crisis, you need to be able to rely on your partner's data protection and data security. This is why the following also applies to EVAC: &lt;a href="https://mailbox.org/en/security/" data-entity-type="node" data-entity-uuid="2b846140-bfc8-4154-b324-43cee2bd3bfb" data-entity-substitution="canonical" title="Email encryption: Best protection for your data"&gt;information security and the protection of your data&lt;/a&gt; are our priority.&lt;/p&gt;&lt;p&gt;As part of the Heinlein Group, mailbox has over 30 years of experience in the field of secure communication. mailbox holds the BSI C5 Type 1 certificate and is ISO 27001-certified. In addition, mailbox has been awarded Gold status by the BSI for email security standards and the "Software made in Germany" and "Software hosted in Germany" quality seals by the German Association of IT SMEs (BITMi). For maximum availability, we host your data 100 % GDPR-compliant in secure, redundant data centres in Germany.&lt;/p&gt;

          
                                                  
      

  
      
  &lt;a name="logos-10257"&gt;&lt;/a&gt;
  
  
          
  
                &lt;img loading="lazy" src="https://mailbox.org/sites/default/files/2026-01/Software%20Hosted%20in%20Germany%202026_0.png" width="304" height="219" alt="Quality label: Software hosted in Germany 2026"&gt;


      


          
  
                &lt;img loading="lazy" src="https://mailbox.org/sites/default/files/2026-01/Software%20Made%20in%20Germany%202026_english.png" width="304" height="219" alt="SMiG Quality label 2026"&gt;


      


          
  
                &lt;img loading="lazy" src="https://mailbox.org/sites/default/files/2025-07/allianz-cyber-sicherheit.png" width="636" height="424" alt="Logo Allianz für Cyber-Sicherheit"&gt;


      


          
  
                &lt;img loading="lazy" src="https://mailbox.org/sites/default/files/2026-01/zertifikate-BSI-C5-Type-1.svg" alt="BSI C5 Type 1 Testat"&gt;


      


          
  
                &lt;img loading="lazy" src="https://mailbox.org/sites/default/files/2026-01/Zertifikate-ISO-IEC-27001-2022.svg" alt="ISO/IEC 27001:2022 Zertifikat"&gt;


      


          
  
                &lt;img loading="lazy" src="https://mailbox.org/sites/default/files/2025-11/mailbox-renewable-energy.svg" alt="100 percent renewable energy"&gt;


      


      
    
  

  
    
      &lt;h2 class="ticket__title"&gt;Business continuity at the touch of a button&lt;/h2&gt;
              

&lt;a data-component-id="boxy:knob" data-component-variant="tertiary" class="knob knob--tertiary" href="https://mailbox.org/en/evac/"&gt;Discover EVAC now&lt;/a&gt;

          
    
          
                  
              
                  &lt;img loading="lazy" height="1632" width="2944" src="https://mailbox.org/sites/default/files/2025-04/mailbox-evac-button-web-rgb.jpg" alt="Kommunikation auf Knopfdruck"&gt;

  


    
  

</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/mailbox_evac_infrastruktur_web_rgb.jpg?itok=fn-XhAXu" type="image/jpeg" length="185015"/><guid isPermaLink="false">91fe2206-5de1-4b48-b0fc-cc0b4f1429d2</guid>
    <pubDate>Wed, 21 Jan 2026 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>EVAC by mailbox: Business Continuity and Capacity to act</dc:title>
    <dc:identifier>91fe2206-5de1-4b48-b0fc-cc0b4f1429d2</dc:identifier>
    </item>
<item>
  <title>EVAC by mailbox: Business Continuity and Capacity to act</title>
  <link>https://mailbox.org/en/news/evac-mailbox-business-continuity-and-capacity-act/</link>
  <description>&lt;h2&gt;One step ahead of the crisis with EVAC&lt;/h2&gt;&lt;p&gt;According to the World Economic Forum, 72 % of all organisations worldwide reported an increasing cyber risk in 2025. With EVAC, you are not alone in an emergency. Your communication continues – securely, reliably and immediately. EVAC includes a complete communication infrastructure in the web interface:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Email communication via web-based access&lt;/li&gt;&lt;li&gt;Video conferencing for virtual meetings&lt;/li&gt;&lt;li&gt;Drive for file storage and exchange&lt;/li&gt;&lt;li&gt;Online Office for collaborative document editing&lt;/li&gt;&lt;li&gt;Calendar &amp;amp; address book for appointment coordination&lt;/li&gt;&lt;li&gt;Task management for project organisation&lt;/li&gt;&lt;/ul&gt;


  
        
  
                &lt;img loading="lazy" src="https://mailbox.org/sites/default/files/2026-01/EVAC_Console_EN.png" width="4095" height="2167" alt="EVAC Console mailbox"&gt;


      


  
              


  
    
    
    
    &lt;h2&gt;Mastering NIS-2 and BSI Standard 200-4 with EVAC&lt;/h2&gt;&lt;p&gt;In accordance with the NIS-2 Directive and the German NIS-2-UmsuCG, companies and authorities must prove that they have functioning business continuity measures in place. EVAC supports you in fulfilling key NIS-2 requirements, e.g. in risk management, incident response and reporting obligations.&lt;/p&gt;&lt;p&gt;In addition, EVAC helps you to fulfil the requirements of BSI Standard 200-4 on business continuity management: As part of your business continuity plan (CFP), EVAC enables you to continue your time-critical business processes.&lt;/p&gt;&lt;h2&gt;Minimising the recovery time objective (RTO) with EVAC&lt;/h2&gt;&lt;p&gt;In 2024, according to IBM, the inability to act after a cyberattack averaged 185 days. In the same year, the damage caused by cybercrime in Germany alone totalled 178.6 billion euros. Whether cyberattacks and ransomware, hardware and server failures or power outages and natural disasters – in the event of a crisis, minimising the RTO is crucial to reducing downtime. EVAC was developed specifically for this requirement and works in three simple steps:&lt;/p&gt;&lt;p&gt;1. Selection and preparation: You select the desired mailboxes and data. You can add or remove them at any time. Your EVAC platform is ready in standby mode.&lt;/p&gt;&lt;p&gt;2. Activation in an emergency: The emergency mailboxes are activated and employees automatically receive instructions on password assignment and access.&lt;/p&gt;&lt;p&gt;3. Communication continues: Your employees access their mailboxes via webmail – including cloud storage, video conferencing, online office, calendar and task management. Business communication continues without interruption.&lt;/p&gt;&lt;h2&gt;EVAC: Security even in times of crisis&lt;/h2&gt;&lt;p&gt;Even in times of crisis, you need to be able to rely on your partner's data protection and data security. This is why the following also applies to EVAC: &lt;a href="https://mailbox.org/en/security/" data-entity-type="node" data-entity-uuid="2b846140-bfc8-4154-b324-43cee2bd3bfb" data-entity-substitution="canonical" title="Email encryption: Best protection for your data"&gt;information security and the protection of your data&lt;/a&gt; are our priority.&lt;/p&gt;&lt;p&gt;As part of the Heinlein Group, mailbox has over 30 years of experience in the field of secure communication. mailbox holds the BSI C5 Type 1 certificate and is ISO 27001-certified. In addition, mailbox has been awarded Gold status by the BSI for email security standards and the "Software made in Germany" and "Software hosted in Germany" quality seals by the German Association of IT SMEs (BITMi). For maximum availability, we host your data 100 % GDPR-compliant in secure, redundant data centres in Germany.&lt;/p&gt;

          
                                                  
      

  
      
  &lt;a name="logos-10257"&gt;&lt;/a&gt;
  
  
          
  
                &lt;img loading="lazy" src="https://mailbox.org/sites/default/files/2026-01/Software%20Hosted%20in%20Germany%202026_0.png" width="304" height="219" alt="Quality label: Software hosted in Germany 2026"&gt;


      


          
  
                &lt;img loading="lazy" src="https://mailbox.org/sites/default/files/2026-01/Software%20Made%20in%20Germany%202026_english.png" width="304" height="219" alt="SMiG Quality label 2026"&gt;


      


          
  
                &lt;img loading="lazy" src="https://mailbox.org/sites/default/files/2025-07/allianz-cyber-sicherheit.png" width="636" height="424" alt="Logo Allianz für Cyber-Sicherheit"&gt;


      


          
  
                &lt;img loading="lazy" src="https://mailbox.org/sites/default/files/2026-01/zertifikate-BSI-C5-Type-1.svg" alt="BSI C5 Type 1 Testat"&gt;


      


          
  
                &lt;img loading="lazy" src="https://mailbox.org/sites/default/files/2026-01/Zertifikate-ISO-IEC-27001-2022.svg" alt="ISO/IEC 27001:2022 Zertifikat"&gt;


      


          
  
                &lt;img loading="lazy" src="https://mailbox.org/sites/default/files/2025-11/mailbox-renewable-energy.svg" alt="100 percent renewable energy"&gt;


      


      
    
  

  
    
      &lt;h2 class="ticket__title"&gt;Business continuity at the touch of a button&lt;/h2&gt;
              

&lt;a data-component-id="boxy:knob" data-component-variant="tertiary" class="knob knob--tertiary" href="https://mailbox.org/en/evac/"&gt;Discover EVAC now&lt;/a&gt;

          
    
          
                  
              
                  &lt;img loading="lazy" height="1632" width="2944" src="https://mailbox.org/sites/default/files/2025-04/mailbox-evac-button-web-rgb.jpg" alt="Kommunikation auf Knopfdruck"&gt;

  


    
  

</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/mailbox_evac_infrastruktur_web_rgb.jpg?itok=fn-XhAXu" type="image/jpeg" length="185015"/><guid isPermaLink="false">91fe2206-5de1-4b48-b0fc-cc0b4f1429d2</guid>
    <pubDate>Wed, 21 Jan 2026 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>EVAC by mailbox: Business Continuity and Capacity to act</dc:title>
    <dc:identifier>91fe2206-5de1-4b48-b0fc-cc0b4f1429d2</dc:identifier>
    </item>
<item>
  <title>BSI C5 certificate and ISO 27001 certificate for mailbox</title>
  <link>https://mailbox.org/en/news/bsi-c5-certification-mailbox-full-compliance-bsi-criteria-cloud-security-confirmed/</link>
  <description>&lt;p&gt;mailbox is the digital workplace that offers the highest data protection and security standards. The mailbox Suite combines email, calendar, contacts, Office, video conferencing and Drive in one intuitive solution – operated exclusively in German data centres.&lt;/p&gt;&lt;p&gt;We are delighted with the new BSI C5 certification, which complements mailbox's ISO/IEC 27001 certification. These certificates confirm our high security standards, especially for cloud services, through independent testing agencies and demonstrate our consistent commitment to protecting your data.&lt;/p&gt;

  
      
  &lt;a name="logos-10233"&gt;&lt;/a&gt;
  
  
          
  
                &lt;img loading="lazy" src="https://mailbox.org/sites/default/files/2026-01/zertifikate-BSI-C5-Type-1.svg" alt="BSI C5 Type 1 Testat"&gt;


      


          
  
                &lt;img loading="lazy" src="https://mailbox.org/sites/default/files/2026-01/Zertifikate-ISO-IEC-27001-2022.svg" alt="ISO/IEC 27001:2022 Zertifikat"&gt;


      


      
    
                


  
    
    
    
    &lt;h2&gt;BSI C5 attestation: Seal of quality for data security&lt;/h2&gt;&lt;p&gt;The Cloud Computing Compliance Criteria Catalogue (C5) is a catalogue of criteria developed specifically for cloud providers that raises the information security, availability and confidentiality of your data to a tested and transparent level. It was developed by the BSI to ensure the highest security and compliance requirements, particularly in sensitive areas such as public authorities or the healthcare industry. "We are very proud of this certification. It is another clear signal to our customers that the safety of their data is subject to the strict tests and controls required for the German and European markets and sensitive applications," says our founder and CEO Peer Heinlein.&lt;/p&gt;&lt;h2&gt;Criterion for provider selection with growing relevance&lt;/h2&gt;&lt;p&gt;For more and more industries and public institutions, the BSI C5 certification is becoming a relevant or even mandatory criterion when selecting their partners. ‘mailbox has been committed to data security for years. We are therefore particularly pleased that the certificate officially confirms this,’ says Peer Heinlein. ‘Our customers can rely on certified cloud security and the highest level of information security, as evidenced by our ISO 27001 certification and other awards.’&lt;/p&gt;&lt;h2&gt;mailbox: ISO 27001 certified and awarded quality seals&lt;/h2&gt;&lt;p&gt;ISO/IEC 27001 is the international standard for information security management systems (ISMS). It offers organisations a systematic approach to protecting their information. Specifically, this approach helps to identify, assess and control risks to the confidentiality, integrity and availability of information.&lt;/p&gt;&lt;p&gt;In addition, mailbox 2025 has been awarded the ‘Software made in Germany’ and ‘Software hosted in Germany’ quality seals by the German Federal Association of IT SMEs (BITMi). mailbox has also achieved gold status as part of the BSI's Email Security Year 2025. We are committed to the full implementation of state-of-the-art email security standards and have already successfully implemented them. This makes us one of the industry leaders in email security and data protection.&lt;/p&gt;&lt;p&gt;Put your trust in certified cloud security and &lt;a href="https://mailbox.org/en/product/" data-entity-type="node" data-entity-uuid="f3b95bfa-a5b2-450f-b3f5-c7568fc49082" data-entity-substitution="canonical" title="Your digital workspace - secure email, cloud &amp;amp; more"&gt;learn more&lt;/a&gt; about mailbox's secure digital workplace.&lt;/p&gt;

          
                                                  
      
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-trophy-2.png?itok=X4dOmDiQ" type="image/png" length="336184"/><guid isPermaLink="false">df447873-195c-4e3b-8224-f05aa4d33a99</guid>
    <pubDate>Wed, 07 Jan 2026 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>BSI C5 certificate and ISO 27001 certificate for mailbox</dc:title>
    <dc:identifier>df447873-195c-4e3b-8224-f05aa4d33a99</dc:identifier>
    </item>
<item>
  <title>BSI C5 certificate and ISO 27001 certificate for mailbox</title>
  <link>https://mailbox.org/en/news/bsi-c5-certification-mailbox-full-compliance-bsi-criteria-cloud-security-confirmed/</link>
  <description>&lt;p&gt;mailbox is the digital workplace that offers the highest data protection and security standards. The mailbox Suite combines email, calendar, contacts, Office, video conferencing and Drive in one intuitive solution – operated exclusively in German data centres.&lt;/p&gt;&lt;p&gt;We are delighted with the new BSI C5 certification, which complements mailbox's ISO/IEC 27001 certification. These certificates confirm our high security standards, especially for cloud services, through independent testing agencies and demonstrate our consistent commitment to protecting your data.&lt;/p&gt;

  
      
  &lt;a name="logos-10233"&gt;&lt;/a&gt;
  
  
          
  
                &lt;img loading="lazy" src="https://mailbox.org/sites/default/files/2026-01/zertifikate-BSI-C5-Type-1.svg" alt="BSI C5 Type 1 Testat"&gt;


      


          
  
                &lt;img loading="lazy" src="https://mailbox.org/sites/default/files/2026-01/Zertifikate-ISO-IEC-27001-2022.svg" alt="ISO/IEC 27001:2022 Zertifikat"&gt;


      


      
    
                


  
    
    
    
    &lt;h2&gt;BSI C5 attestation: Seal of quality for data security&lt;/h2&gt;&lt;p&gt;The Cloud Computing Compliance Criteria Catalogue (C5) is a catalogue of criteria developed specifically for cloud providers that raises the information security, availability and confidentiality of your data to a tested and transparent level. It was developed by the BSI to ensure the highest security and compliance requirements, particularly in sensitive areas such as public authorities or the healthcare industry. "We are very proud of this certification. It is another clear signal to our customers that the safety of their data is subject to the strict tests and controls required for the German and European markets and sensitive applications," says our founder and CEO Peer Heinlein.&lt;/p&gt;&lt;h2&gt;Criterion for provider selection with growing relevance&lt;/h2&gt;&lt;p&gt;For more and more industries and public institutions, the BSI C5 certification is becoming a relevant or even mandatory criterion when selecting their partners. ‘mailbox has been committed to data security for years. We are therefore particularly pleased that the certificate officially confirms this,’ says Peer Heinlein. ‘Our customers can rely on certified cloud security and the highest level of information security, as evidenced by our ISO 27001 certification and other awards.’&lt;/p&gt;&lt;h2&gt;mailbox: ISO 27001 certified and awarded quality seals&lt;/h2&gt;&lt;p&gt;ISO/IEC 27001 is the international standard for information security management systems (ISMS). It offers organisations a systematic approach to protecting their information. Specifically, this approach helps to identify, assess and control risks to the confidentiality, integrity and availability of information.&lt;/p&gt;&lt;p&gt;In addition, mailbox 2025 has been awarded the ‘Software made in Germany’ and ‘Software hosted in Germany’ quality seals by the German Federal Association of IT SMEs (BITMi). mailbox has also achieved gold status as part of the BSI's Email Security Year 2025. We are committed to the full implementation of state-of-the-art email security standards and have already successfully implemented them. This makes us one of the industry leaders in email security and data protection.&lt;/p&gt;&lt;p&gt;Put your trust in certified cloud security and &lt;a href="https://mailbox.org/en/product/" data-entity-type="node" data-entity-uuid="f3b95bfa-a5b2-450f-b3f5-c7568fc49082" data-entity-substitution="canonical" title="Your digital workspace - secure email, cloud &amp;amp; more"&gt;learn more&lt;/a&gt; about mailbox's secure digital workplace.&lt;/p&gt;

          
                                                  
      
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-trophy-2.png?itok=X4dOmDiQ" type="image/png" length="336184"/><guid isPermaLink="false">df447873-195c-4e3b-8224-f05aa4d33a99</guid>
    <pubDate>Wed, 07 Jan 2026 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>BSI C5 certificate and ISO 27001 certificate for mailbox</dc:title>
    <dc:identifier>df447873-195c-4e3b-8224-f05aa4d33a99</dc:identifier>
    </item>
<item>
  <title>mailbox Year in Review 2025: Secure communication needs a firm stance</title>
  <link>https://mailbox.org/en/news/2025-mailbox-secure-communication-needs-firm-stance/</link>
  <description>&lt;p&gt;As the year draws to a close, it is clear how much the framework conditions for digital communication and collaboration have changed. Security, data protection and political influencing factors have not remained abstract in 2025, but have become part of everyday life for companies, public authorities and private users. With this in mind, it is worth taking a look back at the developments that have characterised this year – and which show why reliable email communication and secure digital collaboration matter more than ever today.&lt;/p&gt;&lt;h2&gt;mailbox becomes a secure digital workplace&lt;/h2&gt;&lt;p&gt;These changing requirements are also reflected in the further development of mailbox. With the development towards an integrated, digitally sovereign workplace, a central step has been taken. Email, calendar, contacts, cloud storage and collaboration are growing closer together – with the aim of enabling secure communication and productive work in a trustworthy environment. The focus was on clarity, control over data and the deliberate reduction of external dependencies.&lt;/p&gt;&lt;h2&gt;Political developments worldwide and the call for European alternatives&lt;/h2&gt;&lt;p&gt;The fact that technological decisions cannot be viewed in isolation from political developments became particularly clear in 2025. The political change of course in the USA has once again made many organisations aware of how quickly legal and regulatory frameworks can change. Against this backdrop, many users scrutinised existing dependencies. Many made a conscious and forward-looking decision to switch to European alternatives.&lt;/p&gt;&lt;h2&gt;BSI Gold status and transparency about data localisation&lt;/h2&gt;&lt;p&gt;In such an environment, verifiable security standards and transparent origins are becoming increasingly important. An important signal of this was the award of mailbox with the &lt;a href="https://mailbox.org/en/press/mailbox-achieves-gold-status-in-bsi-e-mail-security-year-2025/" data-entity-type="node" data-entity-uuid="0ecc3f47-f901-4c78-8e0d-74c309818a49" data-entity-substitution="canonical" title="Email security: mailbox.org achieves gold status"&gt;Gold status of the German Federal Office for Information Security (BSI)&lt;/a&gt;. Complemented by &lt;a href="https://mailbox.org/en/news/mailbox-receives-prestigious-seal-quality-german-software-and-hosting/" data-entity-type="node" data-entity-uuid="222c1f06-9d97-454d-bb06-60b1f67073a7" data-entity-substitution="canonical" title="mailbox receives prestigious seal of quality"&gt;renowned quality seals for German software and hosting&lt;/a&gt;, this underlines our commitment to combining the highest security requirements with clear legal positioning – a decisive factor for many organisations when choosing their digital infrastructure.&lt;/p&gt;&lt;h2&gt;Chat control and the question of digital self-determination&lt;/h2&gt;&lt;p&gt;Parallel to this, fundamental questions of digital self-determination came back into focus in 2025. The political debate surrounding chat control in 2025 made it clear how fragile the right to confidential communication remains. The attempt to weaken encryption through technical backdoors calls into question the basic principles of data protection and IT security. &lt;a href="https://mailbox.org/en/news/chat-control-theres-no-such-thing-little-backdoor/" data-entity-type="node" data-entity-uuid="e01ecc19-ec89-422d-b591-77d091746c14" data-entity-substitution="canonical" title="Open letter: mailbox against chat control"&gt;mailbox has taken a clear stance in this discussion:&lt;/a&gt; Security is not divisible – and digital independence requires that communication can remain confidential.&lt;/p&gt;&lt;h2&gt;As the year draws to a close&lt;/h2&gt;&lt;p&gt;All these developments show how closely technology, politics and social responsibility are now interlinked. We would like to thank all our customers, partners and supporters for their trust and open dialogue during this eventful year. We wish you a relaxing holiday season and a happy new year. May 2026 be characterised by decisions in the spirit of digital sovereignty, secure communication and the responsible use of digital technologies.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-12/mailbox_news-2025-secure-communication.jpg?itok=s-uIIH00" type="image/jpeg" length="230957"/><guid isPermaLink="false">3afc79d4-e5d6-4fb7-9720-05b06532bca7</guid>
    <pubDate>Thu, 18 Dec 2025 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>mailbox Year in Review 2025: Secure communication needs a firm stance</dc:title>
    <dc:identifier>3afc79d4-e5d6-4fb7-9720-05b06532bca7</dc:identifier>
    </item>
<item>
  <title>mailbox Year in Review 2025: Secure communication needs a firm stance</title>
  <link>https://mailbox.org/en/news/2025-mailbox-secure-communication-needs-firm-stance/</link>
  <description>&lt;p&gt;As the year draws to a close, it is clear how much the framework conditions for digital communication and collaboration have changed. Security, data protection and political influencing factors have not remained abstract in 2025, but have become part of everyday life for companies, public authorities and private users. With this in mind, it is worth taking a look back at the developments that have characterised this year – and which show why reliable email communication and secure digital collaboration matter more than ever today.&lt;/p&gt;&lt;h2&gt;mailbox becomes a secure digital workplace&lt;/h2&gt;&lt;p&gt;These changing requirements are also reflected in the further development of mailbox. With the development towards an integrated, digitally sovereign workplace, a central step has been taken. Email, calendar, contacts, cloud storage and collaboration are growing closer together – with the aim of enabling secure communication and productive work in a trustworthy environment. The focus was on clarity, control over data and the deliberate reduction of external dependencies.&lt;/p&gt;&lt;h2&gt;Political developments worldwide and the call for European alternatives&lt;/h2&gt;&lt;p&gt;The fact that technological decisions cannot be viewed in isolation from political developments became particularly clear in 2025. The political change of course in the USA has once again made many organisations aware of how quickly legal and regulatory frameworks can change. Against this backdrop, many users scrutinised existing dependencies. Many made a conscious and forward-looking decision to switch to European alternatives.&lt;/p&gt;&lt;h2&gt;BSI Gold status and transparency about data localisation&lt;/h2&gt;&lt;p&gt;In such an environment, verifiable security standards and transparent origins are becoming increasingly important. An important signal of this was the award of mailbox with the &lt;a href="https://mailbox.org/en/press/mailbox-achieves-gold-status-in-bsi-e-mail-security-year-2025/" data-entity-type="node" data-entity-uuid="0ecc3f47-f901-4c78-8e0d-74c309818a49" data-entity-substitution="canonical" title="Email security: mailbox.org achieves gold status"&gt;Gold status of the German Federal Office for Information Security (BSI)&lt;/a&gt;. Complemented by &lt;a href="https://mailbox.org/en/news/mailbox-receives-prestigious-seal-quality-german-software-and-hosting/" data-entity-type="node" data-entity-uuid="222c1f06-9d97-454d-bb06-60b1f67073a7" data-entity-substitution="canonical" title="mailbox receives prestigious seal of quality"&gt;renowned quality seals for German software and hosting&lt;/a&gt;, this underlines our commitment to combining the highest security requirements with clear legal positioning – a decisive factor for many organisations when choosing their digital infrastructure.&lt;/p&gt;&lt;h2&gt;Chat control and the question of digital self-determination&lt;/h2&gt;&lt;p&gt;Parallel to this, fundamental questions of digital self-determination came back into focus in 2025. The political debate surrounding chat control in 2025 made it clear how fragile the right to confidential communication remains. The attempt to weaken encryption through technical backdoors calls into question the basic principles of data protection and IT security. &lt;a href="https://mailbox.org/en/news/chat-control-theres-no-such-thing-little-backdoor/" data-entity-type="node" data-entity-uuid="e01ecc19-ec89-422d-b591-77d091746c14" data-entity-substitution="canonical" title="Open letter: mailbox against chat control"&gt;mailbox has taken a clear stance in this discussion:&lt;/a&gt; Security is not divisible – and digital independence requires that communication can remain confidential.&lt;/p&gt;&lt;h2&gt;As the year draws to a close&lt;/h2&gt;&lt;p&gt;All these developments show how closely technology, politics and social responsibility are now interlinked. We would like to thank all our customers, partners and supporters for their trust and open dialogue during this eventful year. We wish you a relaxing holiday season and a happy new year. May 2026 be characterised by decisions in the spirit of digital sovereignty, secure communication and the responsible use of digital technologies.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-12/mailbox_news-2025-secure-communication.jpg?itok=s-uIIH00" type="image/jpeg" length="230957"/><guid isPermaLink="false">3afc79d4-e5d6-4fb7-9720-05b06532bca7</guid>
    <pubDate>Thu, 18 Dec 2025 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>mailbox Year in Review 2025: Secure communication needs a firm stance</dc:title>
    <dc:identifier>3afc79d4-e5d6-4fb7-9720-05b06532bca7</dc:identifier>
    </item>
<item>
  <title>GDPR violations: 5 common mistakes to avoid</title>
  <link>https://mailbox.org/en/blog/gdpr-violations-5-costly-traps-companies/</link>
  <description>&lt;p&gt;&lt;em&gt;Reading time: 8 minutes&lt;/em&gt;&lt;/p&gt;&lt;p&gt;The bill was unexpected: 1.2 billion euros for Meta, 50 million euros for Orange SA, 15,000 euros for the Belgian SME Jubel.be. Breaches of the GDPR are costly and penalising them is no longer an exception. For Europe's supervisory authorities, prosecuting such cases has long been part of everyday life – regardless of the size of the company.&lt;/p&gt;&lt;p&gt;Since the GDPR was launched in May 2018, corporations, SMEs and small businesses alike have learnt some painful lessons. Even after seven years, data protection is clearly far from routine. In essence, many cases can be traced back to five cardinal errors. They show a clear pattern: those who underestimate data protection obligations risk tangible consequences.&lt;/p&gt;


      
                  
              
              
              
              
              
              
              
                  &lt;img loading="lazy" height="5464" width="8192" src="https://mailbox.org/sites/default/files/2025-11/Blog_DSVGO-Versto%CC%88%C3%9Fe.jpeg" alt="You can see a young man with short hair and a beard. He is wearing glasses and a shirt. The young man is sitting at a desk in an office, with a laptop in front of him and a notepad and smartphone on the table. The man smiles directly into the camera."&gt;

  


  
          

              


  
    
    
    
    &lt;h2&gt;The GDPR at a glance&lt;/h2&gt;&lt;p&gt;The General Data Protection Regulation (GDPR) has been the standardised European set of rules for the protection of personal data since May 2018. It regulates how companies and organisations may collect, process and store data and gives data subjects comprehensive rights over their data. Serious violations can result in fines of up to 20 million euros or 4% of annual global turnover, whichever is higher.&amp;nbsp;&lt;br&gt;&lt;br&gt;Current developments are expanding the scope of data protection: The EU AI Act, which has been in force since August 2024 and whose obligations will gradually take effect from 2025, regulates the use of AI systems. The Data Act has strengthened users' access to data from their networked devices since September 2025. There are also new proposals for the handling of AI training data and for amended rules on cookies and tracking – making regular compliance checks even more important.&lt;/p&gt;&lt;h2&gt;Costly lessons: When everyday practices become a fine trap&lt;/h2&gt;&lt;p&gt;In May 2023, Meta Platforms Ireland Limited was hit particularly hard. The Irish data protection authority imposed a €1.2 billion fine because the company transferred the personal data of European users (in particular Facebook user data) to the USA without complying with the necessary safeguards. Following the ECJ's "Schrems II" judgement, the specific standard contractual clauses used were deemed inadequate without additional safeguards. This ultimately led to the highest GDPR sanction ever imposed.&lt;/p&gt;&lt;p&gt;However, fines do not only affect large corporations. Orange SA learnt this in December 2024. The established French telecommunications provider had to pay a fine of 50 million euros because it displayed adverts in its customers' email inboxes that were barely distinguishable from regular emails. This was also done without obtaining valid consent beforehand. The CNIL also objected to the fact that Orange continued to read cookies on the website despite the withdrawal of consent.&lt;/p&gt;&lt;p&gt;The case of Jubel.be, a legal information platform from Belgium, shows that even smaller providers are not exempt. The Belgian data protection authority imposed a fine of 15,000 euros at the end of 2019 because the website set cookies without consent, did not offer an opt-out option and did not provide users with sufficient information about the tracking technologies used.&lt;/p&gt;&lt;h2&gt;The five cardinal errors of GDPR compliance&lt;/h2&gt;&lt;p&gt;These and numerous other examples show: Despite years of experience with the GDPR, companies keep making the same mistakes. Here are five examples that often lead to heavy fines and can be easily avoided with a systematic approach:&lt;/p&gt;&lt;h3&gt;1. Lack of a legal basis: The foundation of data protection&lt;/h3&gt;&lt;p&gt;One of the most common and most serious violations of the GDPR is the processing of personal data without a valid legal basis. All data processing must be based on one of the six legal grounds listed in Article 6 GDPR: consent, contract fulfilment, legal obligation, protection of vital interests, public interest or legitimate interest.&lt;/p&gt;&lt;p&gt;If this basis is missing, all data processing is unlawful – with corresponding financial consequences. It becomes particularly problematic when companies rely on supposed consent that does not fulfil the strict GDPR criteria: They must be voluntary, informed, specific and unambiguous.&lt;/p&gt;&lt;h3&gt;2. Inadequate security measures: The digital Achilles heel&lt;/h3&gt;&lt;p&gt;Inadequate technical and organisational measures (TOM) are another common cause of GDPR breaches. These include a lack of encryption, inadequate access controls, outdated software and inadequate backup systems. The GDPR requires state-of-the-art protection of personal data. It's a moving target that requires continuous investment in IT security. Companies that skimp here not only risk cyberattacks and data leaks, but also hefty fines for breaching their duty of care.&lt;/p&gt;&lt;h3&gt;3. Disregarded data subject rights: When customers become petitioners&lt;/h3&gt;&lt;p&gt;The GDPR grants data subjects in the European Economic Area (EEA) extensive rights to their personal data, including access, rectification, erasure, restriction of processing, data portability and objection. Companies that ignore, incompletely process or excessively delay such requests are in breach of the requirements.&lt;/p&gt;&lt;p&gt;The refusal to erase data – the "right to be forgotten" – is particularly sensitive once statutory retention periods have expired. These rights are mandatory and must generally be responded to within one month. In complex cases, a justified extension is possible.&lt;/p&gt;&lt;p&gt;By the way: this will become even more important with the new AI Act. As AI systems are often trained with personal data, companies must ensure that data subjects can also exercise their GDPR rights in this context. This includes people being able to request information about their data, object to processing or request erasure. Companies must review these requests and – where legally possible – implement them.&lt;/p&gt;&lt;h3&gt;4. Silent data breaches: Silence is not golden&lt;/h3&gt;&lt;p&gt;Data breaches happen. The key is dealing with them correctly. The GDPR obliges companies to report serious incidents to the competent supervisory authority within 72 hours and to inform the authority if there is a high risk for those affected. Companies that conceal mishaps or report them too late risk double penalties: once for the incident itself and once for failing to report it. Transparency and a swift response are legal obligations here and not just confidence-building measures.&lt;/p&gt;&lt;h3&gt;5. Unauthorised advertising: When marketing becomes a boomerang&lt;/h3&gt;&lt;p&gt;The unauthorised processing of personal data for advertising purposes remains a perennial issue among GDPR breaches. Whether unauthorised email newsletters, purchased address lists or tracking without consent – marketing without a solid legal basis can cause rapid damage.&lt;/p&gt;&lt;p&gt;A case from Amazon underlines the dimensions: In July 2021, the group received a 746 million euro fine from the Luxembourg authority CNPD because personalised advertising was carried out on the website without valid, voluntary consent and the refusal of tracking options was made unnecessarily complicated. This violation affected millions of users and violated the strict consent rules of the GDPR (Art. 7).&lt;/p&gt;&lt;h2&gt;How companies can avoid expensive fines&lt;/h2&gt;&lt;p&gt;To avoid the pitfalls mentioned above, it is worth taking a systematic approach:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Create a register of processing activities: Complete documentation of all data flows within the company: What data is processed for what purpose, on what legal basis and for how long?&lt;/li&gt;&lt;li&gt;Implement technical and organisational measures: Regular security updates, strong password guidelines, encryption of sensitive data and access restrictions based on the "need-to-know" principle.&lt;/li&gt;&lt;li&gt;Write transparent data protection declarations: Explain in simple language which data is processed and why, and enable data subjects to exercise their rights easily.&lt;/li&gt;&lt;li&gt;Establish a system for data subject enquiries: Central point of contact, clear processes and defined processing times to comply with legal deadlines.&lt;/li&gt;&lt;li&gt;Conclude GDPR-compliant data processing agreements: Agree clear rules on obligations and responsibilities with all partners.&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Conclusion: Prevention is cheaper than fines&lt;/h2&gt;&lt;p&gt;The most common GDPR violations are usually caused by negligence, but these compliance errors cost European companies hundreds of millions of euros in fines every year. This money would be better invested in business development and innovation. However, the combination of stricter law enforcement and new regulations such as the AI Act makes proactive data protection a strategic necessity. Companies that invest in GDPR-compliant systems and European technology providers not only protect themselves against fines, but also build trust with customers and business partners. In a digital economy, data protection is no longer a cost factor, but a competitive advantage.&lt;/p&gt;

          
                                                  
      


      
      &lt;h2 class="row__intro__title"&gt;            Insights &amp;amp; Trends
      &lt;/h2&gt;
      Discover more articles on the topic of data protection.
              
            

&lt;a data-component-id="boxy:knob" data-component-variant="secondary" class="knob knob--secondary" href="https://mailbox.org/en/insights/"&gt;All articles&lt;/a&gt;

        
          
    
      
      
  
  
                    
                  
              
                  &lt;img loading="lazy" height="4065" width="6098" src="https://mailbox.org/sites/default/files/2026-07/mailbox%20Blog%20E-Mail-Alias.jpeg" alt="mailbox Blog E-Mail-Alias"&gt;

  


      
      
      
      Best practice, Data protection
    
    &lt;h3 class="snip__title"&gt;Email alias: How to protect your email address from spam&lt;/h3&gt;
  &lt;a class="snip__arrow" href="https://mailbox.org/en/blog/email-alias-protection-against-spam/" aria-hidden="true"&gt;→&lt;/a&gt;
  &lt;a class="snip__link" href="https://mailbox.org/en/blog/email-alias-protection-against-spam/"&gt;Read more about &lt;em class="placeholder"&gt;Email alias: How to protect your email address from spam&lt;/em&gt;&lt;/a&gt;


    
      
      
  
  
                    
                  
              
                  &lt;img loading="lazy" height="4753" width="7121" src="https://mailbox.org/sites/default/files/2026-07/mailbox%20Blog%20Souvera%CC%88ne%20Cloud.jpeg" alt="mailbox Blog Souveräne Cloud"&gt;

  


      
      
      
      Data protection
    
    &lt;h3 class="snip__title"&gt;The sovereign cloud: Who really has control over your data?&lt;/h3&gt;
  &lt;a class="snip__arrow" href="https://mailbox.org/en/blog/sovereign-cloud-providers/" aria-hidden="true"&gt;→&lt;/a&gt;
  &lt;a class="snip__link" href="https://mailbox.org/en/blog/sovereign-cloud-providers/"&gt;Read more about &lt;em class="placeholder"&gt;The sovereign cloud: Who really has control over your data?&lt;/em&gt;&lt;/a&gt;


    
  
  


</description>
  <guid isPermaLink="false">fab139b9-84c0-49ff-bc51-8e17bd6c4f2e</guid>
    <pubDate>Mon, 24 Nov 2025 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>GDPR violations: 5 common mistakes to avoid</dc:title>
    <dc:identifier>fab139b9-84c0-49ff-bc51-8e17bd6c4f2e</dc:identifier>
    </item>
<item>
  <title>The offer of the year: 50% discount on the Black Week deal</title>
  <link>https://mailbox.org/en/news/black-week-deal25/</link>
  <description>&lt;p&gt;Black Friday is approaching and we are kicking off Black Week with a spectacular offer! From 24 November up to and including 1 December 2025, you have the unique opportunity to get our secure mailbox Suite at half price.&lt;/p&gt;&lt;h3&gt;Our exclusive Black Week deal&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;New customers get 2 years for the price of 1 year on the Standard and Premium plans&lt;/li&gt;&lt;li&gt;Exclusively for private customers&lt;/li&gt;&lt;li&gt;Including 30-day trial period&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;The choice is yours: Standard or Premium with a 50% discount&lt;/h2&gt;&lt;h3&gt;Standard plan&lt;/h3&gt;&lt;p&gt;Perfect for beginners and anyone who wants a reliable email solution – including the use of their own domains. With the Standard plan, you get all the functions of the mailbox Suite with Mail, Drive, Meet, and Office. Now two years for just €36 instead of €72.&lt;/p&gt;&lt;h3&gt;Premium plan&lt;/h3&gt;&lt;p&gt;Maximum performance for the highest demands. The Premium plan offers you more aliases, more storage space and priority support. Ideal for power users and anyone who wants to get the best out of mailbox. Now two years for just €108 instead of €216.&lt;/p&gt;&lt;h3&gt;5 reasons to choose mailbox&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;Data protection instead of data trading: No advertising, no tracking.&lt;/li&gt;&lt;li&gt;Servers in Germany: GDPR-compliant and redundantly secured.&lt;/li&gt;&lt;li&gt;Everything under one roof: Mail, Calendar, Drive, Meet, &amp;amp; Office.&lt;/li&gt;&lt;li&gt;Own domain &amp;amp; aliases: Flexible and professionally usable.&lt;/li&gt;&lt;li&gt;Safe &amp;amp; sustainable: High security standards, encryption and 100% green energy.&lt;/li&gt;&lt;/ul&gt;


  
    
      &lt;h2 class="ticket__title"&gt;Secure your Black Week deal now!&lt;/h2&gt;
              

&lt;a data-track="bwd-news" data-component-id="boxy:knob" data-component-variant="tertiary" class="knob knob--tertiary" href="https://mailbox.org/en/prices/#private"&gt;Redeem offer now&lt;/a&gt;

          
    
          
                  
              
                  &lt;img loading="lazy" height="2700" width="5120" src="https://mailbox.org/sites/default/files/2025-11/blackweekdeal2025.jpeg" alt="Junger Mann freut sich über den Black Week Deal bei mailbox"&gt;

  


    
  



  &lt;h2 class="referent__title"&gt;&lt;/h2&gt;
  
                
        
                    
            
                          &lt;h3 class="referent__headline"&gt;
                Black Week deal terms and conditions
                              &lt;/h3&gt;
            
            
                          &lt;p&gt;The promotion runs from 24 November 2025 up to and including 1 December 2025. If you register a new private email inbox on the Premium or Standard plan during the promotion period, you will receive 2 years for the price of one. To do this, select the option "Black Week Deal" in the mailbox settings (Contract and payment &amp;gt; Payment) when making your first payment (Standard € 36, Premium for € 108). The first month is generally free.&lt;/p&gt;&lt;p&gt;A plan change to a lower plan is only possible after the 2-year term has expired. The promotion is non-refundable, non-payable and cannot be transferred to existing accounts. The promotion does not apply to family accounts and can only be claimed once with the first payment.&lt;/p&gt;&lt;p&gt;Choose a privacy-friendly, European alternative and become part of the growing community that values digital self-determination.&lt;/p&gt;
                        
        
      
      

</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-11/blackweekdeal2025.jpeg?itok=Df_ur0Rr" type="image/jpeg" length="336260"/><guid isPermaLink="false">e7d8c07a-4376-473c-b2be-7420c0ca106c</guid>
    <pubDate>Mon, 24 Nov 2025 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>The offer of the year: 50% discount on the Black Week deal</dc:title>
    <dc:identifier>e7d8c07a-4376-473c-b2be-7420c0ca106c</dc:identifier>
    </item>
<item>
  <title>The offer of the year: 50% discount on the Black Week deal</title>
  <link>https://mailbox.org/en/news/black-week-deal25/</link>
  <description>&lt;p&gt;Black Friday is approaching and we are kicking off Black Week with a spectacular offer! From 24 November up to and including 1 December 2025, you have the unique opportunity to get our secure mailbox Suite at half price.&lt;/p&gt;&lt;h3&gt;Our exclusive Black Week deal&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;New customers get 2 years for the price of 1 year on the Standard and Premium plans&lt;/li&gt;&lt;li&gt;Exclusively for private customers&lt;/li&gt;&lt;li&gt;Including 30-day trial period&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;The choice is yours: Standard or Premium with a 50% discount&lt;/h2&gt;&lt;h3&gt;Standard plan&lt;/h3&gt;&lt;p&gt;Perfect for beginners and anyone who wants a reliable email solution – including the use of their own domains. With the Standard plan, you get all the functions of the mailbox Suite with Mail, Drive, Meet, and Office. Now two years for just €36 instead of €72.&lt;/p&gt;&lt;h3&gt;Premium plan&lt;/h3&gt;&lt;p&gt;Maximum performance for the highest demands. The Premium plan offers you more aliases, more storage space and priority support. Ideal for power users and anyone who wants to get the best out of mailbox. Now two years for just €108 instead of €216.&lt;/p&gt;&lt;h3&gt;5 reasons to choose mailbox&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;Data protection instead of data trading: No advertising, no tracking.&lt;/li&gt;&lt;li&gt;Servers in Germany: GDPR-compliant and redundantly secured.&lt;/li&gt;&lt;li&gt;Everything under one roof: Mail, Calendar, Drive, Meet, &amp;amp; Office.&lt;/li&gt;&lt;li&gt;Own domain &amp;amp; aliases: Flexible and professionally usable.&lt;/li&gt;&lt;li&gt;Safe &amp;amp; sustainable: High security standards, encryption and 100% green energy.&lt;/li&gt;&lt;/ul&gt;


  
    
      &lt;h2 class="ticket__title"&gt;Secure your Black Week deal now!&lt;/h2&gt;
              

&lt;a data-track="bwd-news" data-component-id="boxy:knob" data-component-variant="tertiary" class="knob knob--tertiary" href="https://mailbox.org/en/prices/#private"&gt;Redeem offer now&lt;/a&gt;

          
    
          
                  
              
                  &lt;img loading="lazy" height="2700" width="5120" src="https://mailbox.org/sites/default/files/2025-11/blackweekdeal2025.jpeg" alt="Junger Mann freut sich über den Black Week Deal bei mailbox"&gt;

  


    
  



  &lt;h2 class="referent__title"&gt;&lt;/h2&gt;
  
                
        
                    
            
                          &lt;h3 class="referent__headline"&gt;
                Black Week deal terms and conditions
                              &lt;/h3&gt;
            
            
                          &lt;p&gt;The promotion runs from 24 November 2025 up to and including 1 December 2025. If you register a new private email inbox on the Premium or Standard plan during the promotion period, you will receive 2 years for the price of one. To do this, select the option "Black Week Deal" in the mailbox settings (Contract and payment &amp;gt; Payment) when making your first payment (Standard € 36, Premium for € 108). The first month is generally free.&lt;/p&gt;&lt;p&gt;A plan change to a lower plan is only possible after the 2-year term has expired. The promotion is non-refundable, non-payable and cannot be transferred to existing accounts. The promotion does not apply to family accounts and can only be claimed once with the first payment.&lt;/p&gt;&lt;p&gt;Choose a privacy-friendly, European alternative and become part of the growing community that values digital self-determination.&lt;/p&gt;
                        
        
      
      

</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-11/blackweekdeal2025.jpeg?itok=Df_ur0Rr" type="image/jpeg" length="336260"/><guid isPermaLink="false">e7d8c07a-4376-473c-b2be-7420c0ca106c</guid>
    <pubDate>Mon, 24 Nov 2025 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>The offer of the year: 50% discount on the Black Week deal</dc:title>
    <dc:identifier>e7d8c07a-4376-473c-b2be-7420c0ca106c</dc:identifier>
    </item>
<item>
  <title>Open letter: mailbox against chat control</title>
  <link>https://mailbox.org/en/news/chat-control-theres-no-such-thing-little-backdoor/</link>
  <description/>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-surveillance.png?itok=xKoQ4dlZ" type="image/png" length="275481"/><guid isPermaLink="false">e01ecc19-ec89-422d-b591-77d091746c14</guid>
    <pubDate>Tue, 07 Oct 2025 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Open letter: mailbox against chat control</dc:title>
    <dc:identifier>e01ecc19-ec89-422d-b591-77d091746c14</dc:identifier>
    </item>
<item>
  <title>Open letter: mailbox against chat control</title>
  <link>https://mailbox.org/en/news/chat-control-theres-no-such-thing-little-backdoor/</link>
  <description/>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-surveillance.png?itok=xKoQ4dlZ" type="image/png" length="275481"/><guid isPermaLink="false">e01ecc19-ec89-422d-b591-77d091746c14</guid>
    <pubDate>Tue, 07 Oct 2025 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Open letter: mailbox against chat control</dc:title>
    <dc:identifier>e01ecc19-ec89-422d-b591-77d091746c14</dc:identifier>
    </item>
<item>
  <title>Jutta Horstmann becomes co-CEO at Heinlein</title>
  <link>https://mailbox.org/en/news/jutta-horstmann-joins-heinleins-leadership-team-co-ceo/</link>
  <description>&lt;p&gt;We have exciting news: From 15th September, our company founder Peer Heinlein will have a new partner leading the Heinlein Group. Jutta Horstmann is taking on the role of co-CEO and will lead the company alongside him, focusing particularly on strategic development and strengthening digital sovereignty in Europe.&lt;/p&gt;&lt;p&gt;As part of the Heinlein Group, which includes mailbox alongside Heinlein Support, OpenTalk and OpenCloud, we're particularly pleased about this development. With Jutta Horstmann, we're strengthening our position as a provider of independent and secure communication solutions for Germany and Europe.&lt;/p&gt;&lt;h2&gt;Experienced open source expert as new leader&lt;/h2&gt;&lt;p&gt;Jutta Horstmann brings decades of experience from the open source community. Most recently, she served as managing director of the Centre for Digital Sovereignty (ZenDiS). Before that, she worked as COO and CTO at international tech company eyeo (Adblock Plus), where she drove both the technological realignment and company growth to over 300 employees.&lt;/p&gt;&lt;p&gt;This expertise fits perfectly with our shared approach: throughout her career, she has supported community-focused digitalisation, open source technologies and sustainable business development – exactly the values we've stood for at the Heinlein Group for over 30 years.&lt;/p&gt;&lt;h2&gt;Our mission: digital sovereignty&lt;/h2&gt;&lt;p&gt;Under the Heinlein Group umbrella, mailbox, OpenTalk, OpenCloud and Heinlein Support form important parts for an independent digital infrastructure. Our philosophy: all our solutions are based on open source technologies, can be operated independently, and stand for data protection and long-term availability. Together, we help public institutions, businesses and civil society reduce critical dependencies on big tech corporations and work towards an open and secure digital future for Europe.&lt;/p&gt;&lt;h2&gt;More about the Heinlein Group&lt;/h2&gt;In recent years, Heinlein has grown significantly as a group of companies. Today, our team consists of four strong brands – Heinlein Support, mailbox, OpenTalk and OpenCloud – and employs over 150 people. It is time to present our group and our vision with our own website. Find out more at &lt;a class="linkified" href="https://www.heinlein.group/en/" target="_blank" rel="noreferrer noopener"&gt;www.heinlein.group&lt;/a&gt;.&amp;nbsp;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-09/Peer%20Heinlein_Jutta%20Horstmann_Heinlein.jpg?itok=W2AURKiZ" type="image/jpeg" length="364140"/><guid isPermaLink="false">e3332847-f3e9-47f5-9edd-be78608a027e</guid>
    <pubDate>Thu, 11 Sep 2025 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Jutta Horstmann becomes co-CEO at Heinlein</dc:title>
    <dc:identifier>e3332847-f3e9-47f5-9edd-be78608a027e</dc:identifier>
    </item>
<item>
  <title>Jutta Horstmann becomes co-CEO at Heinlein</title>
  <link>https://mailbox.org/en/news/jutta-horstmann-joins-heinleins-leadership-team-co-ceo/</link>
  <description>&lt;p&gt;We have exciting news: From 15th September, our company founder Peer Heinlein will have a new partner leading the Heinlein Group. Jutta Horstmann is taking on the role of co-CEO and will lead the company alongside him, focusing particularly on strategic development and strengthening digital sovereignty in Europe.&lt;/p&gt;&lt;p&gt;As part of the Heinlein Group, which includes mailbox alongside Heinlein Support, OpenTalk and OpenCloud, we're particularly pleased about this development. With Jutta Horstmann, we're strengthening our position as a provider of independent and secure communication solutions for Germany and Europe.&lt;/p&gt;&lt;h2&gt;Experienced open source expert as new leader&lt;/h2&gt;&lt;p&gt;Jutta Horstmann brings decades of experience from the open source community. Most recently, she served as managing director of the Centre for Digital Sovereignty (ZenDiS). Before that, she worked as COO and CTO at international tech company eyeo (Adblock Plus), where she drove both the technological realignment and company growth to over 300 employees.&lt;/p&gt;&lt;p&gt;This expertise fits perfectly with our shared approach: throughout her career, she has supported community-focused digitalisation, open source technologies and sustainable business development – exactly the values we've stood for at the Heinlein Group for over 30 years.&lt;/p&gt;&lt;h2&gt;Our mission: digital sovereignty&lt;/h2&gt;&lt;p&gt;Under the Heinlein Group umbrella, mailbox, OpenTalk, OpenCloud and Heinlein Support form important parts for an independent digital infrastructure. Our philosophy: all our solutions are based on open source technologies, can be operated independently, and stand for data protection and long-term availability. Together, we help public institutions, businesses and civil society reduce critical dependencies on big tech corporations and work towards an open and secure digital future for Europe.&lt;/p&gt;&lt;h2&gt;More about the Heinlein Group&lt;/h2&gt;In recent years, Heinlein has grown significantly as a group of companies. Today, our team consists of four strong brands – Heinlein Support, mailbox, OpenTalk and OpenCloud – and employs over 150 people. It is time to present our group and our vision with our own website. Find out more at &lt;a class="linkified" href="https://www.heinlein.group/en/" target="_blank" rel="noreferrer noopener"&gt;www.heinlein.group&lt;/a&gt;.&amp;nbsp;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-09/Peer%20Heinlein_Jutta%20Horstmann_Heinlein.jpg?itok=W2AURKiZ" type="image/jpeg" length="364140"/><guid isPermaLink="false">e3332847-f3e9-47f5-9edd-be78608a027e</guid>
    <pubDate>Thu, 11 Sep 2025 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Jutta Horstmann becomes co-CEO at Heinlein</dc:title>
    <dc:identifier>e3332847-f3e9-47f5-9edd-be78608a027e</dc:identifier>
    </item>
<item>
  <title>mailbox relaunch: Europe's new digitally sovereign workplace</title>
  <link>https://mailbox.org/en/news/mailbox-becomes-the-digitally-sovereign-workplace/</link>
  <description/>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-07/mailbox-social.png?itok=IdGq0q2R" type="image/png" length="250715"/><guid isPermaLink="false">a1c5f0c7-a3fa-45b0-a5eb-8356116019d9</guid>
    <pubDate>Tue, 09 Sep 2025 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>mailbox relaunch: Europe's new digitally sovereign workplace</dc:title>
    <dc:identifier>a1c5f0c7-a3fa-45b0-a5eb-8356116019d9</dc:identifier>
    </item>
<item>
  <title>mailbox relaunch: Europe's new digitally sovereign workplace</title>
  <link>https://mailbox.org/en/news/mailbox-becomes-the-digitally-sovereign-workplace/</link>
  <description/>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-07/mailbox-social.png?itok=IdGq0q2R" type="image/png" length="250715"/><guid isPermaLink="false">a1c5f0c7-a3fa-45b0-a5eb-8356116019d9</guid>
    <pubDate>Tue, 09 Sep 2025 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>mailbox relaunch: Europe's new digitally sovereign workplace</dc:title>
    <dc:identifier>a1c5f0c7-a3fa-45b0-a5eb-8356116019d9</dc:identifier>
    </item>
<item>
  <title>BSI gold status for mailbox</title>
  <link>https://mailbox.org/en/news/bsi-awards-mailbox-the-gold-status/</link>
  <description>&lt;p&gt;Great news for anyone who values secure email communication: mailbox.org has been awarded gold status in the 2025 Email Security Year by Germany's Federal Office for Information Security (BSI)!&lt;/p&gt;&lt;h2&gt;What does this mean for you?&lt;/h2&gt;&lt;p&gt;This gold status officially confirms our position as an industry leader in Germany. We haven't just committed to implementing the latest email security standards – we've been successfully using them for years.&lt;/p&gt;&lt;h2&gt;Maximum security through DNSSEC and more&lt;/h2&gt;&lt;p&gt;To achieve gold status, we've met BSI's strictest requirements, particularly through full implementation of DNSSEC (Domain Name System Security Extensions). This technology protects you from DNS attacks and ensures your emails genuinely come from the stated servers.&lt;/p&gt;&lt;p&gt;We also use all other security protocols recommended by BSI:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;DMARC and DKIM for authentication&lt;/li&gt;&lt;li&gt;DANE for additional encryption&lt;/li&gt;&lt;li&gt;SPF to prevent email spoofing&lt;/li&gt;&lt;li&gt;TLS for secure transmission&lt;/li&gt;&lt;li&gt;MTA-STS for secure server connections&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Your protection from cybercriminals&lt;/h2&gt;&lt;p&gt;What does this mean in practice? Fraudsters find it much harder to send fake emails in your name or trick you with phishing attacks. All your emails are transmitted with encryption, so nobody can read or tamper with them during transit. Your digital identity receives the best possible protection with us.&lt;/p&gt;&lt;h2&gt;A shared effort for better security&lt;/h2&gt;&lt;p&gt;Email Security Year 2025 is a joint initiative by BSI, eco and bitkom with a clear goal: to make email communication in Germany measurably more secure. We're delighted to be part of this important initiative and to lead by example.&lt;/p&gt;&lt;p&gt;As Peer Heinlein, founder and CEO of Heinlein Group, puts it: "We've been implementing these security standards at mailbox.org as a matter of course for many years. Our customers can rely on us to protect their digital identity reliably."&lt;/p&gt;&lt;h2&gt;Transparency through the new email checker&lt;/h2&gt;&lt;p&gt;You can now easily check your email provider's security standards: BSI has developed a new &lt;a href="https://bsi.bund.de/dok/E-Mail-Checker"&gt;email checker&lt;/a&gt; that transparently shows which security measures your provider implements.&amp;nbsp;&lt;/p&gt;&lt;h2&gt;Why we do this&lt;/h2&gt;&lt;p&gt;At mailbox.org, your digital sovereignty and data protection have been central to everything we do since our founding in 2014. This award confirms what we've long believed: security isn't optional – it's a fundamental right. And you can continue to rely on that.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-trophy-2.png?itok=X4dOmDiQ" type="image/png" length="336184"/><guid isPermaLink="false">6cad208b-281b-4192-815d-dbf0d8785061</guid>
    <pubDate>Fri, 22 Aug 2025 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>BSI gold status for mailbox</dc:title>
    <dc:identifier>6cad208b-281b-4192-815d-dbf0d8785061</dc:identifier>
    </item>
<item>
  <title>BSI gold status for mailbox</title>
  <link>https://mailbox.org/en/news/bsi-awards-mailbox-the-gold-status/</link>
  <description>&lt;p&gt;Great news for anyone who values secure email communication: mailbox.org has been awarded gold status in the 2025 Email Security Year by Germany's Federal Office for Information Security (BSI)!&lt;/p&gt;&lt;h2&gt;What does this mean for you?&lt;/h2&gt;&lt;p&gt;This gold status officially confirms our position as an industry leader in Germany. We haven't just committed to implementing the latest email security standards – we've been successfully using them for years.&lt;/p&gt;&lt;h2&gt;Maximum security through DNSSEC and more&lt;/h2&gt;&lt;p&gt;To achieve gold status, we've met BSI's strictest requirements, particularly through full implementation of DNSSEC (Domain Name System Security Extensions). This technology protects you from DNS attacks and ensures your emails genuinely come from the stated servers.&lt;/p&gt;&lt;p&gt;We also use all other security protocols recommended by BSI:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;DMARC and DKIM for authentication&lt;/li&gt;&lt;li&gt;DANE for additional encryption&lt;/li&gt;&lt;li&gt;SPF to prevent email spoofing&lt;/li&gt;&lt;li&gt;TLS for secure transmission&lt;/li&gt;&lt;li&gt;MTA-STS for secure server connections&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Your protection from cybercriminals&lt;/h2&gt;&lt;p&gt;What does this mean in practice? Fraudsters find it much harder to send fake emails in your name or trick you with phishing attacks. All your emails are transmitted with encryption, so nobody can read or tamper with them during transit. Your digital identity receives the best possible protection with us.&lt;/p&gt;&lt;h2&gt;A shared effort for better security&lt;/h2&gt;&lt;p&gt;Email Security Year 2025 is a joint initiative by BSI, eco and bitkom with a clear goal: to make email communication in Germany measurably more secure. We're delighted to be part of this important initiative and to lead by example.&lt;/p&gt;&lt;p&gt;As Peer Heinlein, founder and CEO of Heinlein Group, puts it: "We've been implementing these security standards at mailbox.org as a matter of course for many years. Our customers can rely on us to protect their digital identity reliably."&lt;/p&gt;&lt;h2&gt;Transparency through the new email checker&lt;/h2&gt;&lt;p&gt;You can now easily check your email provider's security standards: BSI has developed a new &lt;a href="https://bsi.bund.de/dok/E-Mail-Checker"&gt;email checker&lt;/a&gt; that transparently shows which security measures your provider implements.&amp;nbsp;&lt;/p&gt;&lt;h2&gt;Why we do this&lt;/h2&gt;&lt;p&gt;At mailbox.org, your digital sovereignty and data protection have been central to everything we do since our founding in 2014. This award confirms what we've long believed: security isn't optional – it's a fundamental right. And you can continue to rely on that.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-trophy-2.png?itok=X4dOmDiQ" type="image/png" length="336184"/><guid isPermaLink="false">6cad208b-281b-4192-815d-dbf0d8785061</guid>
    <pubDate>Fri, 22 Aug 2025 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>BSI gold status for mailbox</dc:title>
    <dc:identifier>6cad208b-281b-4192-815d-dbf0d8785061</dc:identifier>
    </item>
<item>
  <title>PGP encryption for maximum email protection</title>
  <link>https://mailbox.org/en/blog/pgp-encryption-at-mailboxorg/</link>
  <description>&lt;p&gt;&lt;em&gt;Reading time: 6 minutes&lt;/em&gt;&lt;/p&gt;&lt;p&gt;A sensitive email that transforms into cryptic gibberish with a single click – readable only to the intended recipient with the corresponding key. PGP (Pretty Good Privacy) was developed in 1991 by Phil Zimmermann and was considered not only revolutionary encryption technology at the time, but in the eyes of US authorities such as the FBI, it was even deemed an illegal weapon, classified alongside rockets, machine guns and bombs, which led to a three-year investigation.&lt;/p&gt;


      
                  
              
              
              
              
              
              
              
                  &lt;img loading="lazy" height="3584" width="5376" src="https://mailbox.org/sites/default/files/2025-06/Blog_PGP%20Encryption.jpeg" alt="Young woman smiling as she looks at her mobile phone while sitting on the bus."&gt;

  


  
          

              


  
    
    
    
    &lt;p&gt;Perhaps due to this explosive start, this powerful encryption technology was long considered complicated and therefore remained largely the preserve of experts. It has since become established wherever business-critical and confidential information must be shared securely, such as in law firms, medical practices, journalism and corporations. But is PGP also suitable for the general public? mailbox says yes and has made encryption to the highest standards a central element of its service from the very beginning. In addition to &lt;a href="https://mailbox.org/en/blog/smime-secure-e-mail-encryption-and-signature/" data-entity-type="node" data-entity-uuid="fcb79eca-189f-4b16-af88-c0f2a34ede37" data-entity-substitution="canonical" title="S/MIME: Secure e-mail encryption and signature"&gt;S/MIME&lt;/a&gt;, mailbox offers the option of securely encrypting emails with PGP.&lt;/p&gt;&lt;h2&gt;The foundation of digital security: How PGP works&lt;/h2&gt;&lt;p&gt;Here's how it works: Each user generates a key pair consisting of a public and private key. The public key is shared and can be used to encrypt messages or verify digital signatures. If Person A wants to encrypt an email to Person B, they use Person B's public key to render the message unreadable.&lt;br&gt;To read this PGP-encrypted message, Person B needs their private key – only this can make the message encrypted with the public key readable again.&lt;/p&gt;&lt;h2&gt;Why PGP is so secure&lt;/h2&gt;&lt;p&gt;PGP combines two methods: asymmetric and symmetric encryption. First, the actual message is encrypted with a fast symmetric key. This key is then encrypted with Person B's public key and sent along with the message. This principle of asymmetric encryption forms the foundation of PGP's security.&lt;br&gt;Encrypted messages can only be exchanged between people who actively use PGP and whose public keys are known. This ensures that only the private key is needed for decryption. Incidentally, a public key alone doesn't enable decryption – this requires exclusively the private key, which must be kept secure and secret. The private key cannot be calculated from the public key.&lt;/p&gt;&lt;h2&gt;mailbox Guard: Integrated PGP encryption in focus&lt;/h2&gt;&lt;p&gt;Whilst PGP encryption is merely a retrofitted technical feature with many providers, it has formed a central building block at mailbox since the company's founding. As part of the Guard system, PGP encryption is seamlessly integrated into the email environment.&lt;/p&gt;&lt;p&gt;Guard differs fundamentally from conventional PGP implementations. Complicated software installations and basic cryptographic knowledge aren't required. Instead, encryption takes place directly through the web interface. What's unique is that even non-PGP users can receive encrypted messages thanks to temporary, secure mailboxes.&lt;/p&gt;&lt;p&gt;The system automatically generates key pairs, manages them in the background and makes them available in a searchable directory. Private keys are stored encrypted on German servers and can only be decrypted with the user password.&lt;/p&gt;&lt;h2&gt;Technical implementation and practical application&lt;/h2&gt;&lt;p&gt;Technically, Guard is based on OpenPGP standards, but combines these with a user-friendly interface. Users can choose between fully automatic encryption and manual control. The integration works not only through the web interface, but also via standard email clients such as Thunderbird or Outlook.&lt;/p&gt;&lt;p&gt;Activation takes place directly in the account settings, so no additional software is required. After activation, the system automatically takes over key management and provides detailed instructions for various email programmes.&lt;/p&gt;&lt;h2&gt;Future-proof communication for a digital world&lt;/h2&gt;&lt;p&gt;Given growing cyber threats, PGP encryption remains a proven pillar for secure emails. Thanks to solutions like mailbox Guard, it's more user-friendly than ever and is constantly being developed to meet new challenges. PGP offers flexibility for businesses and individuals who demand the highest standards of data protection. With seamless integration and a strong focus on security, PGP is a future-proof choice for confidential communication.&lt;/p&gt;

          
                                                  
      


      
      &lt;h2 class="row__intro__title"&gt;            Insights &amp;amp; trends
      &lt;/h2&gt;
      Discover further best practices for your digital security.
              
            

&lt;a data-component-id="boxy:knob" data-component-variant="secondary" class="knob knob--secondary" href="https://mailbox.org/en/insights/"&gt;All articles&lt;/a&gt;

        
          
    
      
      
  
  
                    
                  
              
                  &lt;img loading="lazy" height="2160" width="4096" src="https://mailbox.org/sites/default/files/2026-08/mailbox%20EVAC%20Blog%20IT-Sicherheit%20kleine%20Unternehmen.jpeg" alt="mailbox EVAC Blog IT-Sicherheit kleine Unternehmen"&gt;

  


      
      
      
      Business Continuitiy, Security
    
    &lt;h3 class="snip__title"&gt;IT security: Why small businesses in particular are targeted by cyberattacks&lt;/h3&gt;
  &lt;a class="snip__arrow" href="https://mailbox.org/en/blog/IT-security-for-small-businesses/" aria-hidden="true"&gt;→&lt;/a&gt;
  &lt;a class="snip__link" href="https://mailbox.org/en/blog/IT-security-for-small-businesses/"&gt;Read more about &lt;em class="placeholder"&gt;IT security: Why small businesses in particular are targeted by cyberattacks&lt;/em&gt;&lt;/a&gt;


    
      
      
  
  
                    
                  
              
                  &lt;img loading="lazy" height="4912" width="7360" src="https://mailbox.org/sites/default/files/2026-07/mailbox%20EVAC%20Blog%20Schatten-IT%20als%20Notfalllo%CC%88sung%20vermeiden.jpeg" alt="mailbox EVAC Blog Schatten-IT als Notfalllösung vermeiden"&gt;

  


      
      
      
      Business Continuitiy, Security
    
    &lt;h3 class="snip__title"&gt;How to avoid shadow IT when your communication tools fail&lt;/h3&gt;
  &lt;a class="snip__arrow" href="https://mailbox.org/en/blog/avoiding-shadow-IT-in-an-emergency/" aria-hidden="true"&gt;→&lt;/a&gt;
  &lt;a class="snip__link" href="https://mailbox.org/en/blog/avoiding-shadow-IT-in-an-emergency/"&gt;Read more about &lt;em class="placeholder"&gt;How to avoid shadow IT when your communication tools fail&lt;/em&gt;&lt;/a&gt;


    
  
  


</description>
  <guid isPermaLink="false">5c710490-9276-4b9f-854d-c9c1b4af845b</guid>
    <pubDate>Wed, 18 Jun 2025 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>PGP encryption for maximum email protection</dc:title>
    <dc:identifier>5c710490-9276-4b9f-854d-c9c1b4af845b</dc:identifier>
    </item>
<item>
  <title>Disposable email addresses: Protection from spam &amp; data misuse</title>
  <link>https://mailbox.org/en/blog/how-disposable-addresses-protect-against-digital-threat/</link>
  <description>&lt;p&gt;&lt;em&gt;Reading time: 7 minutes&lt;/em&gt;&lt;/p&gt;&lt;p&gt;Email addresses have become an indispensable part of our digital identity. Registrations, order confirmations, newsletters and countless other online activities require us to share our email address. Yet with each disclosure, the risk of falling victim to spam, phishing attempts or data breaches increases. This is where disposable email addresses offer an elegant solution: they act as a digital shield for your main address, protecting you from unwanted messages.&lt;/p&gt;


      
                  
              
              
              
              
              
              
              
                  &lt;img loading="lazy" height="4672" width="7008" src="https://mailbox.org/sites/default/files/2025-06/Blog_Wegwerfadressen_0.jpeg" alt="Young woman sits with coffee in the living room and looks at her mobile phone with a smile"&gt;

  


  
          

              


  
    
    
    
    &lt;h2&gt;What's behind the term disposable address?&lt;/h2&gt;&lt;p&gt;A disposable email address – also known as a "temporary email" or "burner email" – is a temporary email address created for a specific purpose and "disposed of" after use. These addresses work like a proxy between user and sender: they forward incoming messages to your primary inbox without the sender knowing your real email address.&lt;/p&gt;&lt;p&gt;The key advantage lies in the time limitation and anonymity. After the predefined validity period expires, these addresses are automatically deactivated or can be manually deleted. This creates a natural barrier against long-term spam attacks and data misuse.&lt;/p&gt;&lt;h2&gt;The invisible enemy: Why email addresses need protection&lt;/h2&gt;&lt;p&gt;Once an email address falls into the wrong hands, it can become a gateway for various threats. Spam senders use automated programmes to collect email addresses and sell them to advertising networks. Cybercriminals use this information for targeted phishing attacks, where they pose as trustworthy senders to steal sensitive data.&lt;/p&gt;&lt;p&gt;The situation becomes particularly problematic when legitimate companies pass data on to third parties or are compromised through data breaches. Suddenly, users receive advertising from firms they've never been in contact with, or become targets of fraudsters who know a surprising amount about them.&lt;/p&gt;&lt;h2&gt;When disposable addresses are used&lt;/h2&gt;&lt;p&gt;The applications for disposable email addresses are varied and focus on situations where privacy needs protecting. When registering with unknown online services, perhaps for a one-off download or to enter a competition, disposable addresses prevent your main address from ending up in dodgy mailing lists.&lt;/p&gt;&lt;p&gt;When shopping online with new retailers, they protect against unwanted marketing emails and the sale of data to third parties. Developers and testers use these addresses to check registration processes without revealing their personal contact details. They're also useful when commenting on forums or blogs where an email address is required but no permanent connection is desired.&lt;/p&gt;&lt;h2&gt;The benefits at a glance&lt;/h2&gt;&lt;p&gt;The most obvious benefit is the dramatic reduction in spam in your main inbox. Your primary email address remains hidden, minimising the risk of data breaches and the sale of personal information. Users retain complete control over who knows their real email address and can deactivate problematic disposable addresses at any time.&lt;/p&gt;&lt;p&gt;Enhanced internet anonymity is another key advantage. Should a disposable address become compromised, your main address remains untouched. The straightforward management of modern disposable address systems makes their use uncomplicated and user-friendly.&lt;/p&gt;&lt;h2&gt;mailbox: Disposable emails "Made in Germany"&lt;/h2&gt;&lt;p&gt;German email provider mailbox offers a particularly elegant solution for disposable addresses. This function is seamlessly integrated into your existing email account and doesn't require external services.&lt;/p&gt;&lt;p&gt;Setup is done through the web portal: after logging in, navigate to settings and the "Disposable addresses" menu item. Here you can create new addresses that are automatically generated randomly – for example in the format "abcde@temp.mailbox.org".&lt;/p&gt;&lt;h2&gt;Intelligent management and flexible validity periods&lt;/h2&gt;&lt;p&gt;Depending on your chosen tariff, disposable addresses remain active for different periods: 90 days on the standard tariff, and up to 365 days on the premium tariff. This timespan can be extended if needed, should the address be required for longer. All incoming emails automatically land in your primary inbox without needing to set up separate forwarding rules.&lt;/p&gt;&lt;p&gt;Particularly handy is the comment function: you can add a note to each disposable address, such as "Newsletter signup Shop XY" or "Competition June 2024". This organisational aid makes management considerably easier when using multiple addresses in parallel.&lt;/p&gt;&lt;h2&gt;Technical limitations and data protection advantages&lt;/h2&gt;&lt;p&gt;Unlike full email aliases, disposable addresses at mailbox can only be used for receiving emails. Sending emails via these addresses isn't possible. After the validity period expires, incoming emails are automatically rejected with the message "User unknown", creating a reliable barrier against future spam.&lt;/p&gt;&lt;p&gt;These technical features go hand in hand with the provider's high data protection standards. As a German provider, mailbox is subject to strict European and German data protection laws. The servers are located in Germany, providing an additional measure of trust and legal security. This distinguishes the service from many international providers where it's often unclear where and how data is processed.&lt;/p&gt;&lt;h2&gt;Conclusion: More control over your digital identity&lt;/h2&gt;&lt;p&gt;Disposable email addresses are an indispensable tool for anyone who takes their digital privacy seriously and wants to protect their inbox from spam. mailbox's solution offers a professional alternative to the often insecure and publicly accessible temp-mail services. Through intelligent integration into the existing email system, flexible validity periods and the ability for detailed organisation, users gain a powerful instrument for controlling their online communication and protecting their digital identity from unwanted messages.&lt;/p&gt;

          
                                                  
      


      
      &lt;h2 class="row__intro__title"&gt;            Insights &amp;amp; trends
      &lt;/h2&gt;
      Discover further best practices for your digital security.
              
            

&lt;a data-component-id="boxy:knob" data-component-variant="secondary" class="knob knob--secondary" href="https://mailbox.org/en/insights/"&gt;All articles&lt;/a&gt;

        
          
    
      
      
  
  
                    
                  
              
                  &lt;img loading="lazy" height="2160" width="4096" src="https://mailbox.org/sites/default/files/2026-08/mailbox%20EVAC%20Blog%20Business%20Continuity%20in%20der%20Lieferkette.jpeg" alt="mailbox EVAC Blog Business Continuity in der Lieferkette"&gt;

  


      
      
      
      Best practice, Business Continuitiy
    
    &lt;h3 class="snip__title"&gt;How to use business continuity as a competitive advantage in the supply chain&lt;/h3&gt;
  &lt;a class="snip__arrow" href="https://mailbox.org/en/blog/business-continuity-supply-chain/" aria-hidden="true"&gt;→&lt;/a&gt;
  &lt;a class="snip__link" href="https://mailbox.org/en/blog/business-continuity-supply-chain/"&gt;Read more about &lt;em class="placeholder"&gt;How to use business continuity as a competitive advantage in the supply chain&lt;/em&gt;&lt;/a&gt;


    
      
      
  
  
                    
                  
              
                  &lt;img loading="lazy" height="4065" width="6098" src="https://mailbox.org/sites/default/files/2026-07/mailbox%20Blog%20E-Mail-Alias.jpeg" alt="mailbox Blog E-Mail-Alias"&gt;

  


      
      
      
      Best practice, Data protection
    
    &lt;h3 class="snip__title"&gt;Email alias: How to protect your email address from spam&lt;/h3&gt;
  &lt;a class="snip__arrow" href="https://mailbox.org/en/blog/email-alias-protection-against-spam/" aria-hidden="true"&gt;→&lt;/a&gt;
  &lt;a class="snip__link" href="https://mailbox.org/en/blog/email-alias-protection-against-spam/"&gt;Read more about &lt;em class="placeholder"&gt;Email alias: How to protect your email address from spam&lt;/em&gt;&lt;/a&gt;


    
  
  


</description>
  <guid isPermaLink="false">ee09eda0-758d-4a59-bc38-323b7d7b4565</guid>
    <pubDate>Tue, 10 Jun 2025 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Disposable email addresses: Protection from spam &amp; data misuse</dc:title>
    <dc:identifier>ee09eda0-758d-4a59-bc38-323b7d7b4565</dc:identifier>
    </item>
<item>
  <title>European alternatives for business emails</title>
  <link>https://mailbox.org/en/blog/european-alternatives-for-businesses/</link>
  <description>&lt;p&gt;&lt;em&gt;Reading time: 6 minutes&lt;/em&gt;&lt;/p&gt;&lt;p&gt;Does your company also rely on email services from the US? Google, Microsoft and Co. dominate the market – but this dependence poses significant risks, particularly for European businesses. Sensitive commercial data, confidential customer communications and internal strategy papers flow through these channels daily. Should they suddenly become unavailable, many companies face complete system failure. The good news: powerful European email alternatives are already proving themselves, not just technically, but also with the highest data protection standards.&lt;/p&gt;


      
                  
              
              
              
              
              
              
              
                  &lt;img loading="lazy" height="5760" width="8640" src="https://mailbox.org/sites/default/files/2025-06/Blog-Europa%CC%88ische-Alternativen-052025.jpeg" alt="Smiling woman with laptop on her lap"&gt;

  


  
          

              


  
    
    
    
    &lt;h2&gt;Legal pitfalls with US providers&lt;/h2&gt;&lt;p&gt;The US CLOUD Act enables US authorities to access data extensively – even on European servers – which fundamentally conflicts with EU data protection principles. Following the collapse of Privacy Shield and the restrictions on Standard Contractual Clauses imposed by the ECJ (Schrems II decision), there's no legally secure foundation for transatlantic data transfers. Companies must therefore navigate a constant balancing act between practical necessity and legal compliance, risking GDPR fines whilst losing control over their sensitive data.&lt;/p&gt;&lt;p&gt;Another risk is so-called vendor lock-in – dependence on a single technology provider where switching to another solution would involve significant costs, technical hurdles or data loss.&lt;/p&gt;&lt;h2&gt;When the service fails: Business risks&lt;/h2&gt;&lt;p&gt;There are countless examples of this risky dependence: In April 2022, Google Cloud failed across Europe when cooling problems following a power outage brought numerous services to a halt for over eight hours. This affected not only email systems, but also business-critical applications hosted in Google Cloud. Microsoft's Exchange Online went down for over five hours in January 2023. Email communication ground to a complete halt in thousands of companies.&lt;/p&gt;&lt;p&gt;The most recent example is the disruption to the International Criminal Court's (ICC) work after Microsoft blocked Chief Prosecutor Karim Khan's email account following sanctions imposed by US President Donald Trump. This time it wasn't a technical failure, but the consequence of political decisions. What these examples share isn't just their cost to affected companies and institutions, but above all the dramatic importance of a diversified IT strategy and the urgency of switching to European alternatives without delay.&lt;/p&gt;&lt;h2&gt;European alternatives as the solution&lt;/h2&gt;&lt;p&gt;To avoid dependencies, increasing numbers of companies are turning to European alternatives to the US giants. These solutions offer not only legal security, but also strengthen their own digital sovereignty. Those choosing this path should look carefully though, as not every European provider meets the requirements of modern business communication.&lt;/p&gt;&lt;p&gt;For a future-proof email solution, several key requirements must be met:&lt;/p&gt;&lt;h3&gt;Security as the foundation&lt;/h3&gt;&lt;p&gt;Modern email providers should meet the highest security standards. End-to-end encryption with PGP or S/MIME, two-factor authentication and intelligent systems to ward off spam, phishing and malware form the foundation. European providers often place particular emphasis on these security functions, as they operate in a stricter regulatory environment than their US competitors.&lt;/p&gt;&lt;h3&gt;Data protection as competitive advantage&lt;/h3&gt;&lt;p&gt;GDPR compliance isn't just a legal obligation, but can also be a strategic advantage. With European alternatives, companies should look for providers designed from the ground up for these requirements – with servers exclusively in the EU and transparent data processing procedures. A privacy-friendly approach supports companies in fulfilling their compliance obligations and strengthens trust with customers and business partners.&lt;/p&gt;&lt;h3&gt;Seamless integration into corporate IT&lt;/h3&gt;&lt;p&gt;A contemporary business email service is an integral part of a company's entire IT landscape. It connects seamlessly with existing systems via open APIs, offers comprehensive collaboration functions (calendar, contacts, office, drive, video conferencing) and grows flexibly with the company's requirements. This integration reduces media breaks and increases business process efficiency whilst maintaining data sovereignty.&lt;/p&gt;&lt;h2&gt;mailbox.org – The German specialist for business communication&lt;/h2&gt;&lt;p&gt;mailbox.org has established itself as one of Germany's leading email providers and offers solutions specifically tailored to companies with its business tariffs. Exclusive server use in Germany guarantees complete GDPR compliance, whilst comprehensive security functions such as PGP/S/MIME, 2FA and subsequent encryption of incoming emails provide the highest protection.&lt;/p&gt;&lt;p&gt;With mailbox.org's business offering, companies receive email addresses under their own domain in flexible tariffs, central administration options for all accounts via a dedicated administration interface and an API for integration into existing processes. Particularly valuable is the professional support – depending on the service package, up to 24/7 availability with a personal contact. For more complex migrations, mailbox.org also offers a free migration service.&lt;/p&gt;&lt;h2&gt;Your path to digital sovereignty&lt;/h2&gt;&lt;p&gt;Choosing an alternative email provider is more than a technical decision – it's a statement for digital sovereignty and responsible data handling. Providers like mailbox.org represent genuine alternatives to US services whilst combining security, compliance and innovation.&lt;/p&gt;&lt;p&gt;For companies that value data protection, legal certainty and independence, there's no alternative to European providers.&lt;/p&gt;

          
                                                  
      


      
      &lt;h2 class="row__intro__title"&gt;            Insights &amp;amp; trends
      &lt;/h2&gt;
      Discover further articles on data protection.
              
            

&lt;a data-component-id="boxy:knob" data-component-variant="secondary" class="knob knob--secondary" href="https://mailbox.org/en/insights/"&gt;All articles&lt;/a&gt;

        
          
    
      
      
  
  
                    
                  
              
                  &lt;img loading="lazy" height="2160" width="4096" src="https://mailbox.org/sites/default/files/2026-08/mailbox%20EVAC%20Blog%20IT-Sicherheit%20kleine%20Unternehmen.jpeg" alt="mailbox EVAC Blog IT-Sicherheit kleine Unternehmen"&gt;

  


      
      
      
      Business Continuitiy, Security
    
    &lt;h3 class="snip__title"&gt;IT security: Why small businesses in particular are targeted by cyberattacks&lt;/h3&gt;
  &lt;a class="snip__arrow" href="https://mailbox.org/en/blog/IT-security-for-small-businesses/" aria-hidden="true"&gt;→&lt;/a&gt;
  &lt;a class="snip__link" href="https://mailbox.org/en/blog/IT-security-for-small-businesses/"&gt;Read more about &lt;em class="placeholder"&gt;IT security: Why small businesses in particular are targeted by cyberattacks&lt;/em&gt;&lt;/a&gt;


    
      
      
  
  
                    
                  
              
                  &lt;img loading="lazy" height="2160" width="4096" src="https://mailbox.org/sites/default/files/2026-08/mailbox%20EVAC%20Blog%20Business%20Continuity%20in%20der%20Lieferkette.jpeg" alt="mailbox EVAC Blog Business Continuity in der Lieferkette"&gt;

  


      
      
      
      Best practice, Business Continuitiy
    
    &lt;h3 class="snip__title"&gt;How to use business continuity as a competitive advantage in the supply chain&lt;/h3&gt;
  &lt;a class="snip__arrow" href="https://mailbox.org/en/blog/business-continuity-supply-chain/" aria-hidden="true"&gt;→&lt;/a&gt;
  &lt;a class="snip__link" href="https://mailbox.org/en/blog/business-continuity-supply-chain/"&gt;Read more about &lt;em class="placeholder"&gt;How to use business continuity as a competitive advantage in the supply chain&lt;/em&gt;&lt;/a&gt;


    
  
  


</description>
  <guid isPermaLink="false">4534c16f-1407-465d-a8c4-72ef5a9fac11</guid>
    <pubDate>Tue, 27 May 2025 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>European alternatives for business emails</dc:title>
    <dc:identifier>4534c16f-1407-465d-a8c4-72ef5a9fac11</dc:identifier>
    </item>
<item>
  <title>Digital sovereignty: Why it affects everyone</title>
  <link>https://mailbox.org/en/blog/digital-sovereignty-affects-everyone/</link>
  <description>&lt;p&gt;&lt;em&gt;Reading time: 6 minutes&lt;/em&gt;&lt;/p&gt;&lt;p&gt;Digital sovereignty is no longer just a concern for tech experts or businesses – it's become a fundamental requirement for data protection and digital self-determination. Whilst millions of people entrust their most sensitive data to tech giants daily, they rarely know what happens to it. Emails, photos and documents end up on servers owned by companies whose business model is built on monetising this information. Taking control of one's own digital information has thus become one of the central challenges of our time.&lt;/p&gt;


      
                  
              
              
              
              
              
              
              
                  &lt;img loading="lazy" height="3423" width="6465" src="https://mailbox.org/sites/default/files/2025-05/Blog-Digitale-Souveraenitaet-geht-jeden-an.jpeg" alt="Male hiker with rucksack taking photos of a mountain landscape with his smartphone."&gt;

  


  
          

              


  
    
    
    
    &lt;h2&gt;What does digital sovereignty mean?&lt;/h2&gt;&lt;p&gt;Digital sovereignty describes the ability of individuals, businesses or states to independently control their digital data, processes and technologies. The concept aims to be independent of large tech corporations or foreign infrastructures and to make one's own decisions about the use, storage and processing of data.&lt;/p&gt;&lt;p&gt;At its heart lies complete data control – the ability to determine where data is stored and who may access it. Closely linked to this is technological independence, achieved through transparent, secure and monopoly-free software and services. Data protection forms another cornerstone, safeguarding against surveillance, data misuse or unauthorised access. Regional sovereignty completes the concept through the use of services that comply with local data protection laws such as the GDPR.&lt;/p&gt;&lt;h2&gt;Why digital sovereignty is indispensable&lt;/h2&gt;&lt;p&gt;Our dependence on digital technologies is growing exponentially. Particularly problematic is the concentration on a few market-dominant providers. Anyone who builds their entire digital infrastructure on one or a few services becomes dependent on business decisions such as price increases, sudden service discontinuations, or arbitrary changes to terms and conditions.&lt;/p&gt;&lt;h2&gt;How tech giants seize digital control&lt;/h2&gt;&lt;p&gt;Large technology companies have developed sophisticated systems to bind users to them long-term. So-called "vendor lock-in" makes switching to other providers practically impossible through incompatible data formats, proprietary standards or high switching costs.&lt;/p&gt;&lt;p&gt;Alongside this, these corporations continuously collect and analyse user data, often without sufficient transparency about how it's used. This data monopolisation enables them to create detailed profiles and predict user behaviour. This becomes additionally problematic due to the lack of control over where this data is stored – often in countries with less stringent data protection laws. The systematic surveillance of user data for advertising, profiling or even state purposes further reinforces this concentration of power.&lt;/p&gt;&lt;h2&gt;When states and corporations work together&lt;/h2&gt;&lt;p&gt;Recent events highlight the risks of digital dependency. In February 2025, Microsoft blocked the official email account of Karim Khan, the chief prosecutor of the International Criminal Court, after the US government imposed sanctions against him.&lt;/p&gt;&lt;p&gt;According to revelations by The Guardian and Israeli media from 2024, Israeli intelligence services monitored the communications of ICC staff for over nine years to obstruct investigations. These cases demonstrate how the concentration of digital infrastructures in few hands can become a weapon against international institutions.&lt;/p&gt;&lt;h2&gt;The path to digital independence&lt;/h2&gt;&lt;p&gt;Digital sovereignty requires conscious decisions across several areas. One should choose providers that operate within one's own legal jurisdiction and maintain strict data protection standards. Encrypted communication and cloud storage ensure that data remains protected even during server attacks.&lt;/p&gt;&lt;p&gt;Open-source software plays a central role in digital sovereignty. Since the source code is publicly viewable, security experts worldwide can identify and fix vulnerabilities. Numerous European alternatives offer not only transparency but also independence from commercial interests.&lt;/p&gt;&lt;p&gt;Choosing regional providers subject to local laws reduces the risk of data transfers to countries with weaker data protection. Regular reviews of privacy policies and conscious adjustments to privacy settings minimise unwanted tracking.&lt;/p&gt;&lt;h2&gt;Conclusion: The time to act is now&lt;/h2&gt;&lt;p&gt;Digital sovereignty isn't a theoretical future vision but a current necessity. Recent incidents show how quickly digital dependencies can become real instruments of power. Those who consciously choose privacy-friendly and transparent alternatives today protect not only their own data but also strengthen society's digital independence. Control over one's own data isn't a luxury – it's a fundamental right in the digital era.&lt;/p&gt;

          
                                                  
      


      
      &lt;h2 class="row__intro__title"&gt;            Insights &amp;amp; trends
      &lt;/h2&gt;
      Discover further articles on IT security.
              
            

&lt;a data-component-id="boxy:knob" data-component-variant="secondary" class="knob knob--secondary" href="https://mailbox.org/en/insights/"&gt;All articles&lt;/a&gt;

        
          
    
      
      
  
  
                    
                  
              
                  &lt;img loading="lazy" height="2160" width="4096" src="https://mailbox.org/sites/default/files/2026-08/mailbox%20EVAC%20Blog%20IT-Sicherheit%20kleine%20Unternehmen.jpeg" alt="mailbox EVAC Blog IT-Sicherheit kleine Unternehmen"&gt;

  


      
      
      
      Business Continuitiy, Security
    
    &lt;h3 class="snip__title"&gt;IT security: Why small businesses in particular are targeted by cyberattacks&lt;/h3&gt;
  &lt;a class="snip__arrow" href="https://mailbox.org/en/blog/IT-security-for-small-businesses/" aria-hidden="true"&gt;→&lt;/a&gt;
  &lt;a class="snip__link" href="https://mailbox.org/en/blog/IT-security-for-small-businesses/"&gt;Read more about &lt;em class="placeholder"&gt;IT security: Why small businesses in particular are targeted by cyberattacks&lt;/em&gt;&lt;/a&gt;


    
      
      
  
  
                    
                  
              
                  &lt;img loading="lazy" height="2160" width="4096" src="https://mailbox.org/sites/default/files/2026-08/mailbox%20EVAC%20Blog%20Business%20Continuity%20in%20der%20Lieferkette.jpeg" alt="mailbox EVAC Blog Business Continuity in der Lieferkette"&gt;

  


      
      
      
      Best practice, Business Continuitiy
    
    &lt;h3 class="snip__title"&gt;How to use business continuity as a competitive advantage in the supply chain&lt;/h3&gt;
  &lt;a class="snip__arrow" href="https://mailbox.org/en/blog/business-continuity-supply-chain/" aria-hidden="true"&gt;→&lt;/a&gt;
  &lt;a class="snip__link" href="https://mailbox.org/en/blog/business-continuity-supply-chain/"&gt;Read more about &lt;em class="placeholder"&gt;How to use business continuity as a competitive advantage in the supply chain&lt;/em&gt;&lt;/a&gt;


    
  
  


</description>
  <guid isPermaLink="false">bdc06ba2-b179-4c6a-aa8c-9344ceeff05e</guid>
    <pubDate>Mon, 26 May 2025 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Digital sovereignty: Why it affects everyone</dc:title>
    <dc:identifier>bdc06ba2-b179-4c6a-aa8c-9344ceeff05e</dc:identifier>
    </item>
<item>
  <title>Email that grows with your business: LinuxNews story</title>
  <link>https://mailbox.org/en/success-story/how-mailbox-grows-with-linuxnews/</link>
  <description>&lt;p&gt;&lt;em&gt;Reading time: 7 minutes&lt;/em&gt;&lt;/p&gt;&lt;p&gt;When a one-man operation suddenly becomes a team, the digital infrastructure needs rethinking too. This was the experience of mailbox.org customer LinuxNews when tech expert Stefan joined founder Ferdinand. The portal's privately configured email solution quickly revealed itself as both an organisational bottleneck and a security risk. What followed was a complete overhaul of their email organisation, which Stefan now describes with a wink as a "perfect match" with mailbox.org.&lt;/p&gt;


      
                  
              
              
              
              
              
              
              
                  &lt;img loading="lazy" height="4000" width="6000" src="https://mailbox.org/sites/default/files/2025-06/SSY-LinuxNews.jpeg" alt="Person sitting at the table with hot drink and mobile phone in hand"&gt;

  


  
          

              


  
    
    
    
    &lt;h2&gt;Email chaos: When nobody responds&lt;/h2&gt;&lt;p&gt;Email service provider mailbox.org already offered the perfect technical foundation for LinuxNews, but it soon became apparent that the chosen private plan couldn't meet the team's new requirements: the editorial team's central info@ address was merely linked as an alias to founder Ferdinand's private mailbox.&lt;/p&gt;&lt;p&gt;"We preach IT security, but weren't following our own advice," Stefan self-critically describes the situation. During holidays or when the founder was ill, enquiries would remain unanswered for weeks, leading to repeated follow-ups. Their external image suffered considerably, even attracting public criticism.&lt;/p&gt;&lt;h2&gt;The password disaster&lt;/h2&gt;&lt;p&gt;Even more problematic was the security risk: Ferdinand's private mailbox password had to be stored on the server to ensure the website's contact form functioned properly. "If the server had been compromised during this time, an attacker could have read his private emails," Stefan explains, highlighting the serious security vulnerability in their previous setup.&lt;/p&gt;&lt;p&gt;The breaking point came when Ferdinand changed his private password – and promptly caused the website's contact form to fail. "Technology is Stefan's responsibility; who would think that changing a password would break the contact form..." Stefan describes the unfortunate situation.&lt;/p&gt;&lt;h2&gt;Proven quality: mailbox.org remains the best solution&lt;/h2&gt;&lt;p&gt;When searching for a solution, the team evaluated other providers too, but none impressed them as much as mailbox.org. The reason was simple: both had been using and appreciating the German email provider privately for a long time and saw no better alternative for business purposes. mailbox.org fulfilled all their basic requirements, including Germany as a server location, the highest standards of data protection and privacy, and reliable delivery of automated messages from the contact form.&lt;/p&gt;&lt;p&gt;Beyond technical requirements, compatibility with the portal's values was paramount. For a portal reporting on IT security, there was no question of compromising on data protection standards. "The biggest advantages have always been mailbox.org's data protection and reputation in the community," Stefan emphasises.&lt;/p&gt;&lt;p&gt;The challenge, therefore, was more about how they could optimally use the valued service for their editorial requirements.&lt;/p&gt;&lt;h2&gt;Business instead of private: The upgrade&lt;/h2&gt;&lt;p&gt;Switching to mailbox.org's business tariff was the logical consequence and went smoothly. Since both team members were already familiar with the service, there were no hurdles: "Thanks to the intuitive setup, it wasn't a notable challenge," reports Stefan. A particular advantage: since they had already set the MX records in the Domain Name System (DNS) to mailbox.org, the transition remained invisible to users – there was virtually no downtime.&lt;/p&gt;&lt;h2&gt;Teamwork instead of solo struggle&lt;/h2&gt;&lt;p&gt;The new solution with business mailboxes brought immediately noticeable improvements. The contact form has been working reliably and without security risks ever since. Through shared mailbox access, the team is now reachable even during absences, which significantly simplifies holiday cover. The team also benefits from improved email delivery – even to critical recipients such as Microsoft customers.&lt;/p&gt;

          
                                                  
      


  &lt;h2 class="referent__title"&gt;&lt;/h2&gt;
  
                
        
                      
                &lt;img loading="lazy" height width src="https://mailbox.org/sites/default/files/2025-05/referenz-linuxnews.svg" alt="Linux News Logo"&gt;


            
                    
            
                          &lt;h3 class="referent__headline"&gt;
                Stefan, Technology and Administration at LinuxNews
                              &lt;/h3&gt;
            
            
                          &lt;p&gt;"At the core, we’re fighting for the same cause: secure communication, open source, and data protection – a perfect match. The business mailbox from mailbox.org immediately solved our team challenges and today enables us to communicate reliably and securely, without compromise."&lt;/p&gt;
                        
        
      
      

              


  
    
    
    
    &lt;h2&gt;When values and technology harmonise&lt;/h2&gt;&lt;p&gt;Today, the email system for LinuxNews is no longer an issue – in the best possible way. "It works so well that I don't even think about email anymore," Stefan says happily. And LinuxNews and mailbox.org also align in their values: "At our core, we're fighting for the same cause: secure communication, open source, and data protection. On Tinder, they'd call this a 'perfect match'," Stefan humorously summarises the partnership.&lt;/p&gt;&lt;p&gt;The satisfaction is so great that Stefan actively recommends the service. "The business offering has impressed me so much that I've provided it to a former employer and deliberately used an unsupported configuration. Support was granted even for this. I'm also already planning to delight my next employer with mailbox.org."&lt;/p&gt;&lt;h2&gt;About LinuxNews&lt;/h2&gt;&lt;p&gt;LinuxNews is an independent portal that provides daily current information from the world of open source, free software, data protection, and IT security. With this thematic focus, LinuxNews has established itself as a trusted voice in the community since its founding in 2017 and enjoys high standing in the Linux community, including data protection officers and IT security experts. The team consists of founder Ferdinand and Stefan, who is responsible for technology and administrative matters.&lt;/p&gt;&lt;p&gt;To support the independent news portal in their work for free software and open source, mailbox.org has been sponsoring LinuxNews since 2023 with a free business account. This has no impact on the portal's coverage of mailbox.org.&lt;/p&gt;

          
                                                  
      


      
      &lt;h2 class="row__intro__title"&gt;            Insights &amp;amp; trends
      &lt;/h2&gt;
      Discover further best practices for your digital security.
              
            

&lt;a data-component-id="boxy:knob" data-component-variant="secondary" class="knob knob--secondary" href="https://mailbox.org/en/insights/"&gt;All articles&lt;/a&gt;

        
          
    
      
      
  
  
                    
                  
              
                  &lt;img loading="lazy" height="3760" width="5652" src="https://mailbox.org/sites/default/files/2025-05/Blog-oncampus.jpeg" alt="Konzentrierte afroamerikanische Studentin, die sich während des Online-Unterrichts Notizen auf einem Notizblock macht, E-Learning-Konzept"&gt;

  


      
      
      
      Public sector
    
    &lt;h3 class="snip__title"&gt;More email security in the education sector&lt;/h3&gt;
  &lt;a class="snip__arrow" href="https://mailbox.org/en/success-story/enhanced-email-security-education-sector/" aria-hidden="true"&gt;→&lt;/a&gt;
  &lt;a class="snip__link" href="https://mailbox.org/en/success-story/enhanced-email-security-education-sector/"&gt;Read more about &lt;em class="placeholder"&gt;More email security in the education sector&lt;/em&gt;&lt;/a&gt;


    
      
      
  
  
                    
                  
              
                  &lt;img loading="lazy" height="3648" width="5472" src="https://mailbox.org/sites/default/files/2025-05/news-education-2.jpeg" alt="Teacher with pupils at the laptop"&gt;

  


      
      
      
      Public sector
    
    &lt;h3 class="snip__title"&gt;Digital sovereignty in schools: A case study&lt;/h3&gt;
  &lt;a class="snip__arrow" href="https://mailbox.org/en/success-story/digital-sovereignty-in-schools/" aria-hidden="true"&gt;→&lt;/a&gt;
  &lt;a class="snip__link" href="https://mailbox.org/en/success-story/digital-sovereignty-in-schools/"&gt;Read more about &lt;em class="placeholder"&gt;Digital sovereignty in schools: A case study&lt;/em&gt;&lt;/a&gt;


    
  
  


</description>
  <guid isPermaLink="false">9b75b1d7-742e-46ff-9f8b-9be9a0c2c649</guid>
    <pubDate>Wed, 21 May 2025 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Email that grows with your business: LinuxNews story</dc:title>
    <dc:identifier>9b75b1d7-742e-46ff-9f8b-9be9a0c2c649</dc:identifier>
    </item>
<item>
  <title>mailbox Suite: New design and smart features</title>
  <link>https://mailbox.org/en/news/new-mailbox-suite-modern-design-and-smart-features-now-available-beta/</link>
  <description>&lt;h2&gt;The suite at a glance&lt;/h2&gt;&lt;p&gt;Look forward to a fundamental improvement in your daily work with mailbox! The new mailbox Suite offers not only a fresh, modern design, but also intuitive operation that noticeably simplifies your digital everyday life. Every aspect of the user interface has been revised to provide you with faster navigation, better overview, and more efficiency. Discover numerous new functions that increase your productivity whilst ensuring a pleasant working experience – a user experience that excites!&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Completely redesigned user interface with faster navigation and a new design&lt;/li&gt;&lt;li&gt;Improved dark mode for eye-friendly working&lt;/li&gt;&lt;li&gt;Comprehensive revision of settings: Important settings are easier to find&lt;/li&gt;&lt;li&gt;Keyboard shortcuts for more efficient working&lt;/li&gt;&lt;li&gt;Better navigation between apps with support for your browser's forward and back functions&lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;Improved mobile experience&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;Fully revised mobile experience&lt;/li&gt;&lt;li&gt;With the update, we are introducing a Progressive Web App (PWA) for an app-like experience&lt;/li&gt;&lt;li&gt;With the PWA, you also receive notifications about new emails when the browser is closed&lt;/li&gt;&lt;li&gt;The mobile setup assistant has been simplified.&lt;/li&gt;&lt;li&gt;The new notification centre keeps you informed about all important events&lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;What is a Progressive Web App (PWA)?&lt;/h3&gt;&lt;p&gt;A PWA (Progressive Web App) is, simply put, a website that behaves like a normal app on your smartphone without needing to download it from an app store. Your benefits with a PWA: You save storage space, don't need an app store, and receive automatic updates. PWAs can send notifications and allow quick access directly from the home screen. Available for Apple iPhones with iOS and Android smartphones.&lt;/p&gt;&lt;h3&gt;New email functions&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;Undo send: Did you accidentally click "Send"? No problem! You can cancel sending an email shortly afterwards&lt;/li&gt;&lt;li&gt;Categories for emails: Organise your emails with categories, just like your appointments, contacts and tasks&lt;/li&gt;&lt;li&gt;Mark as read: Choose how quickly an email is marked as read (immediately, after 5 seconds, after 20 seconds, or never)&lt;/li&gt;&lt;li&gt;Advanced reply options: Specify to whom replies should be sent&lt;/li&gt;&lt;li&gt;Reuse attachments: Add attachments from recently viewed emails directly into new messages&lt;/li&gt;&lt;li&gt;Customisable font sizes for better readability&lt;/li&gt;&lt;li&gt;Configurable area labels for email accounts&lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;New features in the calendar&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;Create a video conference link directly with the calendar entry&lt;/li&gt;&lt;li&gt;Mark participants as optional&lt;/li&gt;&lt;li&gt;Countdown reminders for upcoming meetings&lt;/li&gt;&lt;li&gt;Improved participant sorting&lt;/li&gt;&lt;li&gt;Management of shared resources&lt;/li&gt;&lt;li&gt;Forwarding of meeting invitations&lt;/li&gt;&lt;li&gt;Year view is now also available on mobile devices&lt;/li&gt;&lt;li&gt;New dynamic week view for mobile devices&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Participate in the beta program&lt;/h2&gt;&lt;p&gt;To test the new mailbox Suite, you must be a participant in the mailbox beta program:&lt;/p&gt;&lt;ol&gt;&lt;li&gt;You must be a private customer in the Premium, Standard or Light tariff&lt;/li&gt;&lt;li&gt;You must have already been activated for the &lt;a href="https://mailbox.org/en/post/the-new-login" target="_blank" title="new Login 2.0" rel="noopener"&gt;new Login 2.0&lt;/a&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;How to participate in the beta program:&lt;/p&gt;&lt;ol&gt;&lt;li&gt;In the mailbox webmailer, select: Settings &amp;gt; mailbox &amp;gt; Services &amp;gt; mailbox beta&lt;/li&gt;&lt;li&gt;Accept the terms of participation&lt;/li&gt;&lt;li&gt;Activate the beta feature&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;Important note:&lt;/p&gt;&lt;p&gt;Beta features may still contain bugs. We therefore recommend not linking critical processes to these features.&lt;br&gt;The number of beta participants for this beta feature is limited at the start.&lt;/p&gt;&lt;p&gt;Become part of the beta program now and help us make the new mailbox features even better!&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-06/news-beta-mailbox-suite.jpeg?itok=d-cqmrD_" type="image/jpeg" length="345679"/><guid isPermaLink="false">6344e8a2-1477-4177-9202-c0c4b3640bbc</guid>
    <pubDate>Mon, 19 May 2025 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>mailbox Suite: New design and smart features</dc:title>
    <dc:identifier>6344e8a2-1477-4177-9202-c0c4b3640bbc</dc:identifier>
    </item>
<item>
  <title>mailbox Suite: New design and smart features</title>
  <link>https://mailbox.org/en/news/new-mailbox-suite-modern-design-and-smart-features-now-available-beta/</link>
  <description>&lt;h2&gt;The suite at a glance&lt;/h2&gt;&lt;p&gt;Look forward to a fundamental improvement in your daily work with mailbox! The new mailbox Suite offers not only a fresh, modern design, but also intuitive operation that noticeably simplifies your digital everyday life. Every aspect of the user interface has been revised to provide you with faster navigation, better overview, and more efficiency. Discover numerous new functions that increase your productivity whilst ensuring a pleasant working experience – a user experience that excites!&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Completely redesigned user interface with faster navigation and a new design&lt;/li&gt;&lt;li&gt;Improved dark mode for eye-friendly working&lt;/li&gt;&lt;li&gt;Comprehensive revision of settings: Important settings are easier to find&lt;/li&gt;&lt;li&gt;Keyboard shortcuts for more efficient working&lt;/li&gt;&lt;li&gt;Better navigation between apps with support for your browser's forward and back functions&lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;Improved mobile experience&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;Fully revised mobile experience&lt;/li&gt;&lt;li&gt;With the update, we are introducing a Progressive Web App (PWA) for an app-like experience&lt;/li&gt;&lt;li&gt;With the PWA, you also receive notifications about new emails when the browser is closed&lt;/li&gt;&lt;li&gt;The mobile setup assistant has been simplified.&lt;/li&gt;&lt;li&gt;The new notification centre keeps you informed about all important events&lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;What is a Progressive Web App (PWA)?&lt;/h3&gt;&lt;p&gt;A PWA (Progressive Web App) is, simply put, a website that behaves like a normal app on your smartphone without needing to download it from an app store. Your benefits with a PWA: You save storage space, don't need an app store, and receive automatic updates. PWAs can send notifications and allow quick access directly from the home screen. Available for Apple iPhones with iOS and Android smartphones.&lt;/p&gt;&lt;h3&gt;New email functions&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;Undo send: Did you accidentally click "Send"? No problem! You can cancel sending an email shortly afterwards&lt;/li&gt;&lt;li&gt;Categories for emails: Organise your emails with categories, just like your appointments, contacts and tasks&lt;/li&gt;&lt;li&gt;Mark as read: Choose how quickly an email is marked as read (immediately, after 5 seconds, after 20 seconds, or never)&lt;/li&gt;&lt;li&gt;Advanced reply options: Specify to whom replies should be sent&lt;/li&gt;&lt;li&gt;Reuse attachments: Add attachments from recently viewed emails directly into new messages&lt;/li&gt;&lt;li&gt;Customisable font sizes for better readability&lt;/li&gt;&lt;li&gt;Configurable area labels for email accounts&lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;New features in the calendar&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;Create a video conference link directly with the calendar entry&lt;/li&gt;&lt;li&gt;Mark participants as optional&lt;/li&gt;&lt;li&gt;Countdown reminders for upcoming meetings&lt;/li&gt;&lt;li&gt;Improved participant sorting&lt;/li&gt;&lt;li&gt;Management of shared resources&lt;/li&gt;&lt;li&gt;Forwarding of meeting invitations&lt;/li&gt;&lt;li&gt;Year view is now also available on mobile devices&lt;/li&gt;&lt;li&gt;New dynamic week view for mobile devices&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Participate in the beta program&lt;/h2&gt;&lt;p&gt;To test the new mailbox Suite, you must be a participant in the mailbox beta program:&lt;/p&gt;&lt;ol&gt;&lt;li&gt;You must be a private customer in the Premium, Standard or Light tariff&lt;/li&gt;&lt;li&gt;You must have already been activated for the &lt;a href="https://mailbox.org/en/post/the-new-login" target="_blank" title="new Login 2.0" rel="noopener"&gt;new Login 2.0&lt;/a&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;How to participate in the beta program:&lt;/p&gt;&lt;ol&gt;&lt;li&gt;In the mailbox webmailer, select: Settings &amp;gt; mailbox &amp;gt; Services &amp;gt; mailbox beta&lt;/li&gt;&lt;li&gt;Accept the terms of participation&lt;/li&gt;&lt;li&gt;Activate the beta feature&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;Important note:&lt;/p&gt;&lt;p&gt;Beta features may still contain bugs. We therefore recommend not linking critical processes to these features.&lt;br&gt;The number of beta participants for this beta feature is limited at the start.&lt;/p&gt;&lt;p&gt;Become part of the beta program now and help us make the new mailbox features even better!&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-06/news-beta-mailbox-suite.jpeg?itok=d-cqmrD_" type="image/jpeg" length="345679"/><guid isPermaLink="false">6344e8a2-1477-4177-9202-c0c4b3640bbc</guid>
    <pubDate>Mon, 19 May 2025 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>mailbox Suite: New design and smart features</dc:title>
    <dc:identifier>6344e8a2-1477-4177-9202-c0c4b3640bbc</dc:identifier>
    </item>
<item>
  <title>BÜPF Revision: The Swiss Surveillance Law</title>
  <link>https://mailbox.org/en/news/buepf-revision-2025-will-switzerland-become-a-surveillance-state/</link>
  <description>&lt;p&gt;The Swiss government intends to toughen its surveillance law. With the revision of the BÜPF (Federal Act on the Surveillance of Post and Telecommunications), potentially far-reaching changes are on the horizon that could affect the data protection of millions of users. The supposedly safe haven for digital privacy is crumbling: in future, Swiss email providers with more than 5,000 users may be required to deliver metadata to authorities in real time. This would particularly affect those Swiss services that have until now advertised strict data protection.&lt;/p&gt;&lt;h2&gt;The BÜPF and the planned revision: The digital overhaul&lt;/h2&gt;&lt;p&gt;Since 2002, Switzerland's surveillance law has regulated the circumstances under which authorities may access communication data. However, the partial revision of the associated ordinances (VÜPF and VD-ÜPF) now sought by the Federal Council goes far beyond a mere update. Whilst official bodies present the changes as necessary adaptations to 5G technology, the draft contains measures that would significantly increase the level of state surveillance.&lt;/p&gt;&lt;h2&gt;Digital X-ray: How deep the new surveillance would reach&lt;/h2&gt;&lt;p&gt;The planned changes to the BÜPF would deeply encroach on digital privacy and would also affect users of Swiss email services. It is crucial for users to understand what authorities might see in the future and what they would not.&lt;/p&gt;&lt;p&gt;Future surveillance would encompass significantly more metadata, including IP addresses, recipient data and location information – data that is just as sensitive as content, as it can reveal movement and relationship profiles. Authorities would thus gain systematic access to information about who communicates with whom, when this happens and from which location. This metadata would be collected in real time and transmitted to authorities. For Swiss email services that have so far not stored IP addresses as standard, such data protection-friendly practices would no longer be possible. Last but not least, the processing deadlines for requests are to be shortened – from one working day to six hours for large providers and from two working days to one for smaller services.&lt;/p&gt;&lt;p&gt;End-to-end encryption through PGP remains untouched, meaning Swiss providers would still not be required to decrypt encrypted content. Anyone who consistently encrypts their emails with PGP would therefore continue to protect the content of their communications even after the potential legislative change.&lt;/p&gt;&lt;h2&gt;What happens after the end of the consultation?&lt;/h2&gt;&lt;p&gt;The deadline for the consultation – a Swiss procedure in which cantons, parties, associations and affected organisations could comment on the draft – expired on 6 May 2025. According to reports, this consultation is said to have met with widespread rejection. The Federal Department of Justice and Police (FDJP) is now evaluating the submitted statements and revising the draft if necessary. This process can take several months.&lt;/p&gt;&lt;p&gt;The Federal Council will decide on the final version no earlier than autumn 2025. If approved, the new regulations could come into force from 2026, although massive resistance from businesses and data protection organisations could delay the process or lead to substantial changes.&lt;/p&gt;&lt;h2&gt;The great exodus has begun&lt;/h2&gt;&lt;p&gt;In response to the impending regulations, leading providers have already begun relocating their servers abroad – primarily to Germany and Scandinavian countries. Some companies are even considering moving their headquarters completely out of Switzerland. This development shows how seriously the industry is taking the planned changes. Leading industry representatives particularly criticise that the planned measures would go far beyond the regulations in Germany and the EU.&lt;/p&gt;&lt;h2&gt;Data protection in international comparison&lt;/h2&gt;&lt;p&gt;Whilst Switzerland has long been known for its high standards in digital privacy, Germany now offers significantly stronger protection in some areas. Since 1997, Switzerland has permitted blanket, non-targeted data retention for six months, which would be extended to continuous real-time surveillance with the planned BÜPF revision. In Germany, on the other hand, the Federal Constitutional Court has repeatedly declared such blanket data retention unconstitutional. Here, surveillance measures generally require a judicial order and specific suspicion – basic principles that could potentially be diluted with the Swiss law revision.&lt;/p&gt;&lt;h3&gt;Checklist: What users should check now&lt;/h3&gt;&lt;p&gt;If you currently use a Swiss email service, you should check the following aspects in light of the possible legislative changes:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Encryption level of your emails: Is only transport encryption activated, or do you use end-to-end encryption like PGP?&lt;/li&gt;&lt;li&gt;Metadata protection: What metadata does your provider store, and how will they handle the potential real-time surveillance obligation?&lt;/li&gt;&lt;li&gt;Server locations: Has your provider already relocated servers abroad? If so, which law applies to your data stored there?&lt;/li&gt;&lt;li&gt;Future plans of the provider: Are there official statements on possible relocations or adjustments to data protection policies?&lt;/li&gt;&lt;li&gt;Examine alternatives: Consider switching to a German provider like mailbox.org, which is protected by strict constitutional court rulings and the GDPR.&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Outlook: The price of security&lt;/h2&gt;&lt;p&gt;The planned revision of Swiss surveillance law marks a turning point. What was once considered a data protection paradise is increasingly developing into a surveillance state that recalibrates the balance between security and privacy – and, in the view of many experts, goes too far. The threatened exodus of email providers is a wake-up call – not just for Switzerland, but for everyone who values digital fundamental rights. The debate shows once again that data protection is not a given, but a fragile asset that requires constant vigilance.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-07/Blog-Schweizer-ueberwachungsgesetz-454804036.jpeg?itok=vDpMl7ZV" type="image/jpeg" length="581330"/><guid isPermaLink="false">201be851-3713-4139-9757-1dca3568f7e6</guid>
    <pubDate>Tue, 13 May 2025 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>BÜPF Revision: The Swiss Surveillance Law</dc:title>
    <dc:identifier>201be851-3713-4139-9757-1dca3568f7e6</dc:identifier>
    </item>
<item>
  <title>BÜPF Revision: The Swiss Surveillance Law</title>
  <link>https://mailbox.org/en/news/buepf-revision-2025-will-switzerland-become-a-surveillance-state/</link>
  <description>&lt;p&gt;The Swiss government intends to toughen its surveillance law. With the revision of the BÜPF (Federal Act on the Surveillance of Post and Telecommunications), potentially far-reaching changes are on the horizon that could affect the data protection of millions of users. The supposedly safe haven for digital privacy is crumbling: in future, Swiss email providers with more than 5,000 users may be required to deliver metadata to authorities in real time. This would particularly affect those Swiss services that have until now advertised strict data protection.&lt;/p&gt;&lt;h2&gt;The BÜPF and the planned revision: The digital overhaul&lt;/h2&gt;&lt;p&gt;Since 2002, Switzerland's surveillance law has regulated the circumstances under which authorities may access communication data. However, the partial revision of the associated ordinances (VÜPF and VD-ÜPF) now sought by the Federal Council goes far beyond a mere update. Whilst official bodies present the changes as necessary adaptations to 5G technology, the draft contains measures that would significantly increase the level of state surveillance.&lt;/p&gt;&lt;h2&gt;Digital X-ray: How deep the new surveillance would reach&lt;/h2&gt;&lt;p&gt;The planned changes to the BÜPF would deeply encroach on digital privacy and would also affect users of Swiss email services. It is crucial for users to understand what authorities might see in the future and what they would not.&lt;/p&gt;&lt;p&gt;Future surveillance would encompass significantly more metadata, including IP addresses, recipient data and location information – data that is just as sensitive as content, as it can reveal movement and relationship profiles. Authorities would thus gain systematic access to information about who communicates with whom, when this happens and from which location. This metadata would be collected in real time and transmitted to authorities. For Swiss email services that have so far not stored IP addresses as standard, such data protection-friendly practices would no longer be possible. Last but not least, the processing deadlines for requests are to be shortened – from one working day to six hours for large providers and from two working days to one for smaller services.&lt;/p&gt;&lt;p&gt;End-to-end encryption through PGP remains untouched, meaning Swiss providers would still not be required to decrypt encrypted content. Anyone who consistently encrypts their emails with PGP would therefore continue to protect the content of their communications even after the potential legislative change.&lt;/p&gt;&lt;h2&gt;What happens after the end of the consultation?&lt;/h2&gt;&lt;p&gt;The deadline for the consultation – a Swiss procedure in which cantons, parties, associations and affected organisations could comment on the draft – expired on 6 May 2025. According to reports, this consultation is said to have met with widespread rejection. The Federal Department of Justice and Police (FDJP) is now evaluating the submitted statements and revising the draft if necessary. This process can take several months.&lt;/p&gt;&lt;p&gt;The Federal Council will decide on the final version no earlier than autumn 2025. If approved, the new regulations could come into force from 2026, although massive resistance from businesses and data protection organisations could delay the process or lead to substantial changes.&lt;/p&gt;&lt;h2&gt;The great exodus has begun&lt;/h2&gt;&lt;p&gt;In response to the impending regulations, leading providers have already begun relocating their servers abroad – primarily to Germany and Scandinavian countries. Some companies are even considering moving their headquarters completely out of Switzerland. This development shows how seriously the industry is taking the planned changes. Leading industry representatives particularly criticise that the planned measures would go far beyond the regulations in Germany and the EU.&lt;/p&gt;&lt;h2&gt;Data protection in international comparison&lt;/h2&gt;&lt;p&gt;Whilst Switzerland has long been known for its high standards in digital privacy, Germany now offers significantly stronger protection in some areas. Since 1997, Switzerland has permitted blanket, non-targeted data retention for six months, which would be extended to continuous real-time surveillance with the planned BÜPF revision. In Germany, on the other hand, the Federal Constitutional Court has repeatedly declared such blanket data retention unconstitutional. Here, surveillance measures generally require a judicial order and specific suspicion – basic principles that could potentially be diluted with the Swiss law revision.&lt;/p&gt;&lt;h3&gt;Checklist: What users should check now&lt;/h3&gt;&lt;p&gt;If you currently use a Swiss email service, you should check the following aspects in light of the possible legislative changes:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Encryption level of your emails: Is only transport encryption activated, or do you use end-to-end encryption like PGP?&lt;/li&gt;&lt;li&gt;Metadata protection: What metadata does your provider store, and how will they handle the potential real-time surveillance obligation?&lt;/li&gt;&lt;li&gt;Server locations: Has your provider already relocated servers abroad? If so, which law applies to your data stored there?&lt;/li&gt;&lt;li&gt;Future plans of the provider: Are there official statements on possible relocations or adjustments to data protection policies?&lt;/li&gt;&lt;li&gt;Examine alternatives: Consider switching to a German provider like mailbox.org, which is protected by strict constitutional court rulings and the GDPR.&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Outlook: The price of security&lt;/h2&gt;&lt;p&gt;The planned revision of Swiss surveillance law marks a turning point. What was once considered a data protection paradise is increasingly developing into a surveillance state that recalibrates the balance between security and privacy – and, in the view of many experts, goes too far. The threatened exodus of email providers is a wake-up call – not just for Switzerland, but for everyone who values digital fundamental rights. The debate shows once again that data protection is not a given, but a fragile asset that requires constant vigilance.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-07/Blog-Schweizer-ueberwachungsgesetz-454804036.jpeg?itok=vDpMl7ZV" type="image/jpeg" length="581330"/><guid isPermaLink="false">201be851-3713-4139-9757-1dca3568f7e6</guid>
    <pubDate>Tue, 13 May 2025 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>BÜPF Revision: The Swiss Surveillance Law</dc:title>
    <dc:identifier>201be851-3713-4139-9757-1dca3568f7e6</dc:identifier>
    </item>
<item>
  <title>Microsoft price increase 2025: A wake-up call</title>
  <link>https://mailbox.org/en/news/microsoft-price-increase-2025-a-wakeup-call/</link>
  <description>&lt;p&gt;As of 1 April 2025 at the latest, a comprehensive price increase for nearly all Microsoft services has come into effect. This affects both business and private customers and has been gradually implemented since December 2024. These price increases come at a particularly inopportune moment for many companies, given the current inflation and general fears of recession. They represent not only a financial burden but also raise fundamental questions about long-term strategy and dependencies in the area of digital infrastructure.&lt;/p&gt;&lt;h2&gt;Affected products and specific increases&lt;/h2&gt;&lt;p&gt;Microsoft's price adjustments affect almost their entire cloud portfolio, including Microsoft 365, Office 365 subscriptions, Windows 365, Power BI Pro and Premium-per-User, as well as Teams Phone. Some price increases are particularly dramatic: Teams Phone will be 25% more expensive (from $8 to $10 per user), whilst Power BI Pro will increase by as much as 40% (from $10 to $14). For Windows Server and System Center, increases of 10% have been announced.&lt;/p&gt;&lt;h2&gt;The new billing model: Additional costs through monthly payments&lt;/h2&gt;&lt;p&gt;In addition to these direct price increases, Microsoft has introduced a new billing model where annual subscriptions with monthly payment will be 5% more expensive than annual advance payments. This seemingly small adjustment means a significant cost increase for companies with numerous licences and aims to encourage customers to pay in advance.&lt;/p&gt;&lt;h2&gt;Strategies behind the price adjustment&lt;/h2&gt;&lt;p&gt;Microsoft justifies the price increases with the "increased value" of their products through continuous innovation, particularly in the field of artificial intelligence – such as with Copilot – as well as with higher development costs. However, the adjustment of the billing models also serves to steer customers towards annual contracts with advance payment. This improves Microsoft's cash flow and binds customers in the longer term – a classic example of vendor lock-in strategies.&lt;/p&gt;&lt;h2&gt;Options for affected companies&lt;/h2&gt;&lt;p&gt;Companies affected by the price increases have a special right of termination at the time the changes take effect. However, upon termination, the contract does not end immediately but at the end of the respective contract term. Those who do not exercise their special right of termination automatically accept the new prices.&lt;/p&gt;&lt;p&gt;Those who wish to avoid vendor lock-in and want to strategically realign should take the following measures:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Analyse licence inventory: Which Microsoft products are actually being used and to what extent? Are there unused or oversized licences?&lt;/li&gt;&lt;li&gt;Review payment model: Consider switching from monthly to annual payment to avoid the 5% price surcharge, if it's too late to cancel&lt;/li&gt;&lt;li&gt;Evaluate alternatives: Are there more cost-effective alternatives that offer the needed functions?&lt;/li&gt;&lt;li&gt;Strategic realignment: Align long-term IT strategy towards independence, data protection and cost control&lt;/li&gt;&lt;li&gt;Examine hybrid solutions: Does the entire company need to use Microsoft products, or can some areas already be switched to alternatives?&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;mailbox.org as a data protection-compliant alternative&lt;/h2&gt;&lt;p&gt;For companies wishing to become independent from US providers, mailbox.org offers a secure, privacy-friendly alternative. mailbox.org impresses with PGP-encrypted emails, calendar, contacts, task management and browser-based office applications. A decisive advantage lies in the exclusive data storage in Germany, complying with the strictest data protection regulations.&lt;/p&gt;&lt;p&gt;The solution is characterised by a transparent pricing model without hidden costs and offers a balanced relationship between functionality and costs, especially for small and medium-sized enterprises. With its focus on security, data protection and European values, mailbox.org positions itself as a future-proof alternative in the changing digital landscape.&lt;/p&gt;&lt;h2&gt;Impact for private users&lt;/h2&gt;&lt;p&gt;For private users, mailbox.org also offers an attractive alternative with tariffs starting from €1 per month, as they too are affected by the price increases. Microsoft 365 Family prices will rise from €99 to €129 (+30%) and Personal from €69 to €99 (+43%). It's worth noting that the advertised AI functions such as Copilot are subject to significant limitations and are only available to the main account user.&lt;/p&gt;&lt;h2&gt;Digital sovereignty as a future perspective&lt;/h2&gt;&lt;p&gt;The current price increases highlight the problem of comprehensive dependence on non-European tech giants. Forward-thinking companies now have the opportunity to reconsider their digital infrastructure and switch to European solutions. This is more than a price issue – it's an investment in digital sovereignty, data security and entrepreneurial independence in an increasingly data-sensitive business world.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-04/blog-microsoft-preiserhoehung.jpeg?itok=0l30YTxm" type="image/jpeg" length="391568"/><guid isPermaLink="false">8d2f88a8-efce-4747-9880-a28ad497c765</guid>
    <pubDate>Mon, 28 Apr 2025 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Microsoft price increase 2025: A wake-up call</dc:title>
    <dc:identifier>8d2f88a8-efce-4747-9880-a28ad497c765</dc:identifier>
    </item>
<item>
  <title>Microsoft price increase 2025: A wake-up call</title>
  <link>https://mailbox.org/en/news/microsoft-price-increase-2025-a-wakeup-call/</link>
  <description>&lt;p&gt;As of 1 April 2025 at the latest, a comprehensive price increase for nearly all Microsoft services has come into effect. This affects both business and private customers and has been gradually implemented since December 2024. These price increases come at a particularly inopportune moment for many companies, given the current inflation and general fears of recession. They represent not only a financial burden but also raise fundamental questions about long-term strategy and dependencies in the area of digital infrastructure.&lt;/p&gt;&lt;h2&gt;Affected products and specific increases&lt;/h2&gt;&lt;p&gt;Microsoft's price adjustments affect almost their entire cloud portfolio, including Microsoft 365, Office 365 subscriptions, Windows 365, Power BI Pro and Premium-per-User, as well as Teams Phone. Some price increases are particularly dramatic: Teams Phone will be 25% more expensive (from $8 to $10 per user), whilst Power BI Pro will increase by as much as 40% (from $10 to $14). For Windows Server and System Center, increases of 10% have been announced.&lt;/p&gt;&lt;h2&gt;The new billing model: Additional costs through monthly payments&lt;/h2&gt;&lt;p&gt;In addition to these direct price increases, Microsoft has introduced a new billing model where annual subscriptions with monthly payment will be 5% more expensive than annual advance payments. This seemingly small adjustment means a significant cost increase for companies with numerous licences and aims to encourage customers to pay in advance.&lt;/p&gt;&lt;h2&gt;Strategies behind the price adjustment&lt;/h2&gt;&lt;p&gt;Microsoft justifies the price increases with the "increased value" of their products through continuous innovation, particularly in the field of artificial intelligence – such as with Copilot – as well as with higher development costs. However, the adjustment of the billing models also serves to steer customers towards annual contracts with advance payment. This improves Microsoft's cash flow and binds customers in the longer term – a classic example of vendor lock-in strategies.&lt;/p&gt;&lt;h2&gt;Options for affected companies&lt;/h2&gt;&lt;p&gt;Companies affected by the price increases have a special right of termination at the time the changes take effect. However, upon termination, the contract does not end immediately but at the end of the respective contract term. Those who do not exercise their special right of termination automatically accept the new prices.&lt;/p&gt;&lt;p&gt;Those who wish to avoid vendor lock-in and want to strategically realign should take the following measures:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Analyse licence inventory: Which Microsoft products are actually being used and to what extent? Are there unused or oversized licences?&lt;/li&gt;&lt;li&gt;Review payment model: Consider switching from monthly to annual payment to avoid the 5% price surcharge, if it's too late to cancel&lt;/li&gt;&lt;li&gt;Evaluate alternatives: Are there more cost-effective alternatives that offer the needed functions?&lt;/li&gt;&lt;li&gt;Strategic realignment: Align long-term IT strategy towards independence, data protection and cost control&lt;/li&gt;&lt;li&gt;Examine hybrid solutions: Does the entire company need to use Microsoft products, or can some areas already be switched to alternatives?&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;mailbox.org as a data protection-compliant alternative&lt;/h2&gt;&lt;p&gt;For companies wishing to become independent from US providers, mailbox.org offers a secure, privacy-friendly alternative. mailbox.org impresses with PGP-encrypted emails, calendar, contacts, task management and browser-based office applications. A decisive advantage lies in the exclusive data storage in Germany, complying with the strictest data protection regulations.&lt;/p&gt;&lt;p&gt;The solution is characterised by a transparent pricing model without hidden costs and offers a balanced relationship between functionality and costs, especially for small and medium-sized enterprises. With its focus on security, data protection and European values, mailbox.org positions itself as a future-proof alternative in the changing digital landscape.&lt;/p&gt;&lt;h2&gt;Impact for private users&lt;/h2&gt;&lt;p&gt;For private users, mailbox.org also offers an attractive alternative with tariffs starting from €1 per month, as they too are affected by the price increases. Microsoft 365 Family prices will rise from €99 to €129 (+30%) and Personal from €69 to €99 (+43%). It's worth noting that the advertised AI functions such as Copilot are subject to significant limitations and are only available to the main account user.&lt;/p&gt;&lt;h2&gt;Digital sovereignty as a future perspective&lt;/h2&gt;&lt;p&gt;The current price increases highlight the problem of comprehensive dependence on non-European tech giants. Forward-thinking companies now have the opportunity to reconsider their digital infrastructure and switch to European solutions. This is more than a price issue – it's an investment in digital sovereignty, data security and entrepreneurial independence in an increasingly data-sensitive business world.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-04/blog-microsoft-preiserhoehung.jpeg?itok=0l30YTxm" type="image/jpeg" length="391568"/><guid isPermaLink="false">8d2f88a8-efce-4747-9880-a28ad497c765</guid>
    <pubDate>Mon, 28 Apr 2025 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Microsoft price increase 2025: A wake-up call</dc:title>
    <dc:identifier>8d2f88a8-efce-4747-9880-a28ad497c765</dc:identifier>
    </item>
<item>
  <title>GoEuropean: Decide in favour of Europe!</title>
  <link>https://mailbox.org/en/news/goeuropean-offer/</link>
  <description>&lt;p&gt;At a time when digital freedom is becoming increasingly important, we at mailbox.org would like to make you a special offer: With the voucher code GoEuropean, new customers get 6 months free on the Premium and Standard tariffs!&lt;/p&gt;&lt;h2&gt;Why choose European alternatives?&lt;/h2&gt;&lt;p&gt;The current trend shows: many people are looking for trustworthy alternatives to the big American tech companies. They want to take their digital communication into their own hands and rely on services that work according to European data protection standards.&lt;/p&gt;&lt;h3&gt;mailbox.org - your fully-fledged alternative to Google and Microsoft&lt;/h3&gt;&lt;p&gt;As a German email provider, we offer you all the functions you expect from modern email services, but with one decisive advantage: your data is stored exclusively in Germany and is subject to strict data protection laws.&lt;/p&gt;&lt;p&gt;Our services include:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Secure email communication with PGP encryption and your own domain&lt;/li&gt;&lt;li&gt;Extensive calendar and contact management&lt;/li&gt;&lt;li&gt;Drive for your important documents&lt;/li&gt;&lt;li&gt;Office for text documents, spreadsheets and presentations&lt;/li&gt;&lt;li&gt;Secure and professional video conferencing&lt;/li&gt;&lt;li&gt;Spam and virus protection to the highest standards&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;So easy is the switch&lt;/h2&gt;&lt;p&gt;Switching to mailbox.org is quick and easy. With our migration service, you can even simply take your existing emails with you. Our support team is available to answer your questions at any time.&lt;/p&gt;&lt;h3&gt;Use the voucher code now: GoEuropean&lt;/h3&gt;&lt;p&gt;The voucher can be redeemed up to and including 31 May 2025 when registering a new private email account on the Premium and Standard plans. It is entered in the second step of the registration process and is automatically credited for a term of 12 months when you make your first payment. Instead of 12 months, you only pay for 6! The first month is generally free. A change of tariff is only possible after the 12-month term has expired. The voucher is non-refundable, non-payable and cannot be transferred to existing accounts.&lt;/p&gt;&lt;p&gt;Choose a privacy-friendly, European alternative and become part of the growing community that values digital self-determination.&lt;/p&gt;


  
    
      &lt;h2 class="ticket__title"&gt;Switch to mailbox.org now!&lt;/h2&gt;
              

&lt;a data-component-id="boxy:knob" data-component-variant="tertiary" class="knob knob--tertiary" href="https://register.mailbox.org/de"&gt;Start now&lt;/a&gt;

          
    
      
    
  

</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-goeuropean-aktion.jpeg?itok=nuVN9cOQ" type="image/jpeg" length="549480"/><guid isPermaLink="false">1db306fa-7b38-418c-9bfc-32067f35eae9</guid>
    <pubDate>Wed, 23 Apr 2025 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>GoEuropean: Decide in favour of Europe!</dc:title>
    <dc:identifier>1db306fa-7b38-418c-9bfc-32067f35eae9</dc:identifier>
    </item>
<item>
  <title>GoEuropean: Decide in favour of Europe!</title>
  <link>https://mailbox.org/en/news/goeuropean-offer/</link>
  <description>&lt;p&gt;At a time when digital freedom is becoming increasingly important, we at mailbox.org would like to make you a special offer: With the voucher code GoEuropean, new customers get 6 months free on the Premium and Standard tariffs!&lt;/p&gt;&lt;h2&gt;Why choose European alternatives?&lt;/h2&gt;&lt;p&gt;The current trend shows: many people are looking for trustworthy alternatives to the big American tech companies. They want to take their digital communication into their own hands and rely on services that work according to European data protection standards.&lt;/p&gt;&lt;h3&gt;mailbox.org - your fully-fledged alternative to Google and Microsoft&lt;/h3&gt;&lt;p&gt;As a German email provider, we offer you all the functions you expect from modern email services, but with one decisive advantage: your data is stored exclusively in Germany and is subject to strict data protection laws.&lt;/p&gt;&lt;p&gt;Our services include:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Secure email communication with PGP encryption and your own domain&lt;/li&gt;&lt;li&gt;Extensive calendar and contact management&lt;/li&gt;&lt;li&gt;Drive for your important documents&lt;/li&gt;&lt;li&gt;Office for text documents, spreadsheets and presentations&lt;/li&gt;&lt;li&gt;Secure and professional video conferencing&lt;/li&gt;&lt;li&gt;Spam and virus protection to the highest standards&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;So easy is the switch&lt;/h2&gt;&lt;p&gt;Switching to mailbox.org is quick and easy. With our migration service, you can even simply take your existing emails with you. Our support team is available to answer your questions at any time.&lt;/p&gt;&lt;h3&gt;Use the voucher code now: GoEuropean&lt;/h3&gt;&lt;p&gt;The voucher can be redeemed up to and including 31 May 2025 when registering a new private email account on the Premium and Standard plans. It is entered in the second step of the registration process and is automatically credited for a term of 12 months when you make your first payment. Instead of 12 months, you only pay for 6! The first month is generally free. A change of tariff is only possible after the 12-month term has expired. The voucher is non-refundable, non-payable and cannot be transferred to existing accounts.&lt;/p&gt;&lt;p&gt;Choose a privacy-friendly, European alternative and become part of the growing community that values digital self-determination.&lt;/p&gt;


  
    
      &lt;h2 class="ticket__title"&gt;Switch to mailbox.org now!&lt;/h2&gt;
              

&lt;a data-component-id="boxy:knob" data-component-variant="tertiary" class="knob knob--tertiary" href="https://register.mailbox.org/de"&gt;Start now&lt;/a&gt;

          
    
      
    
  

</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-goeuropean-aktion.jpeg?itok=nuVN9cOQ" type="image/jpeg" length="549480"/><guid isPermaLink="false">1db306fa-7b38-418c-9bfc-32067f35eae9</guid>
    <pubDate>Wed, 23 Apr 2025 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>GoEuropean: Decide in favour of Europe!</dc:title>
    <dc:identifier>1db306fa-7b38-418c-9bfc-32067f35eae9</dc:identifier>
    </item>
<item>
  <title>The best email providers for European businesses</title>
  <link>https://mailbox.org/en/blog/best-email-providers-european-businesses/</link>
  <description>&lt;p&gt;&lt;em&gt;Reading time: 8 minutes&lt;/em&gt;&lt;/p&gt;&lt;p&gt;Email remains the primary communication tool for businesses worldwide. Choosing the best email provider is therefore a strategic decision that can have far-reaching implications for your business operations, data security, and compliance requirements.&lt;/p&gt;


      
                  
              
              
              
              
              
              
              
                  &lt;img loading="lazy" height="4480" width="6720" src="https://mailbox.org/sites/default/files/2025-04/Blog-Beste%20E-Mail-Anbieter-042025.jpeg" alt="Frau sitzt im Homeoffice vor dem Laptop"&gt;

  


  
          

              


  
    
    
    
    &lt;h2&gt;Why European businesses should reconsider their email provider&lt;/h2&gt;&lt;p&gt;The digital landscape has changed dramatically in recent years. With the Trump administration back in power in the US, concerns regarding the US CLOUD Act have intensified, giving US authorities extensive access to data stored by American technology companies – regardless of where this data is physically located. For European businesses, this means an increased risk that confidential business communications could potentially become accessible to US authorities.&lt;/p&gt;&lt;p&gt;At the same time, the General Data Protection Regulation (GDPR) has set a stringent standard for handling personal data in Europe. Non-compliance can lead to substantial penalties – up to 4% of global annual turnover. This regulatory landscape makes it essential for European businesses to choose an email provider that is not only technically reliable but also complies with strict European data protection standards.&lt;/p&gt;&lt;h2&gt;The key criteria for choosing the best email provider in Europe&lt;/h2&gt;&lt;h3&gt;GDPR compliance and data protection&lt;/h3&gt;&lt;p&gt;Perhaps the most important factor for European businesses is full GDPR compliance. A trustworthy email provider should operate its servers within the EU and offer comprehensive data protection agreements. This &lt;a href="https://mailbox.org/en/blog/gdpr-violations-5-costly-traps-companies/" data-entity-type="node" data-entity-uuid="fab139b9-84c0-49ff-bc51-8e17bd6c4f2e" data-entity-substitution="canonical" title="GDPR violations: 5 common mistakes to avoid"&gt;minimises the risk of breaching data protection regulations&lt;/a&gt; and protects against associated penalties and reputational damage.&lt;/p&gt;&lt;p&gt;The best email provider for your business should have transparent privacy policies and clearly communicate how they handle your data. An important question to ask: Are your data used for advertising purposes or shared with third parties? Providers headquartered in the EU are typically subject to stricter data protection laws than their US counterparts.&lt;/p&gt;&lt;h3&gt;Security features&lt;/h3&gt;&lt;p&gt;In an era of increasing cyber threats, robust security features are non-negotiable. The best email provider for your business should offer advanced security measures such as end-to-end encryption, two-factor authentication (2FA), and comprehensive protection against spam and viruses.&lt;/p&gt;&lt;p&gt;Encryption options like &lt;a href="https://mailbox.org/en/blog/pgp-encryption-at-mailboxorg/" data-entity-type="node" data-entity-uuid="5c710490-9276-4b9f-854d-c9c1b4af845b" data-entity-substitution="canonical" title="PGP encryption for maximum email protection"&gt;PGP&lt;/a&gt; (Pretty Good Privacy) or &lt;a href="https://mailbox.org/en/blog/smime-secure-e-mail-encryption-and-signature/" data-entity-type="node" data-entity-uuid="fcb79eca-189f-4b16-af88-c0f2a34ede37" data-entity-substitution="canonical" title="S/MIME: Secure e-mail encryption and signature"&gt;S/MIME&lt;/a&gt; (Secure/Multipurpose Internet Mail Extensions) should be available as standard. These technologies ensure that, even if data is intercepted, it cannot be read without the corresponding key. Another important security aspect is the provider's ability to detect and block suspicious login activities.&lt;/p&gt;&lt;h3&gt;Reliability and scalability&lt;/h3&gt;&lt;p&gt;A reliable email service is essential for business continuity. The best email provider should offer an uptime guarantee of at least 99.9%, ideally with redundant data centres within the EU to ensure constant availability.&lt;/p&gt;&lt;p&gt;At the same time, the service should be able to grow with your business. Flexible storage options, the ability to add additional user accounts as needed, and scalable pricing models are crucial for growth-oriented businesses. The ability to use your &lt;a href="https://mailbox.org/en/blog/email-adress-with-your-custom-domain/" data-entity-type="node" data-entity-uuid="b060164d-12d0-4068-ae62-e004982b9fc8" data-entity-substitution="canonical" title="Email address with your custom domain: introduction and tips"&gt;own domain&lt;/a&gt; supports your brand identity and conveys a professional impression.&lt;/p&gt;&lt;h3&gt;Integration capability and collaboration tools&lt;/h3&gt;&lt;p&gt;Modern businesses use a variety of digital tools, and the best email provider should be able to work seamlessly with these. Support for standard protocols such as IMAP, POP3, and SMTP, as well as a robust API for custom integrations, are essential.&lt;/p&gt;&lt;p&gt;Furthermore, many email providers today offer additional collaboration tools that can boost team productivity. Features such as shared calendars, shared contacts, document editing, and video conferencing can provide considerable added value and reduce the number of separate services needed.&lt;/p&gt;&lt;h3&gt;User-friendliness and customer support&lt;/h3&gt;&lt;p&gt;An often overlooked but critical factor is the user-friendliness of the email service. An intuitive user interface reduces training needs and increases productivity. The best email provider should offer a clear webmail interface but also support integration with common email clients such as Outlook or Thunderbird.&lt;/p&gt;&lt;p&gt;Equally important is reliable customer support. Technical issues can arise at any time, and responsive support can minimise downtime. Look for providers that offer multilingual support through various channels (email, telephone, helpdesk) and ideally provide dedicated contacts for business customers.&lt;/p&gt;&lt;p&gt;Also, consider the availability of a migration service, which can significantly ease the transition to a new provider. A high-quality migration service enables the seamless transfer of emails, contacts, calendars, and folder structures from the old to the new provider. Some providers offer this service free of charge.&lt;/p&gt;&lt;h2&gt;Why mailbox is the right choice&lt;/h2&gt;&lt;p&gt;When searching for the best email provider for European businesses, mailbox may be the right choice for your company as well. As a German provider, we fulfil all the criteria mentioned above:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;GDPR compliance and certified information security: mailbox is a German company and operates its servers exclusively in Germany. It is therefore fully subject to German and European data protection legislation. mailbox is ISO 27001-certified and BSI C5-tested. We offer comprehensive data protection agreements and anonymous usage options.&lt;/li&gt;&lt;li&gt;Security: With features such as PGP and S/MIME encryption, our own PGP key servers, two-factor authentication (2FA), and professional spam and virus protection, mailbox offers a &lt;a href="https://mailbox.org/en/move-mailbox-migrate-your-emails-securely/"&gt;high level of security&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;Reliability: At mailbox, we operate two independent data centres, thereby guaranteeing high availability.&lt;/li&gt;&lt;li&gt;Scalability: From small businesses to large organisations, mailbox offers &lt;a href="https://mailbox.org/en/prices/" data-entity-type="node" data-entity-uuid="8530ebb3-7b78-4efe-a0f9-c13b757e9407" data-entity-substitution="canonical" title="Our price plans: Transparent &amp;amp; flexible"&gt;various tariffs&lt;/a&gt; with expandable storage options.&lt;/li&gt;&lt;li&gt;User-friendliness and support: The webmail client is intuitively designed, and tiered support is available for business customers, including a 24/7 emergency hotline for higher service packages.&lt;/li&gt;&lt;li&gt;Integration and collaboration: mailbox supports all common email protocols and offers an API for custom integrations. In addition, the package includes a fully-fledged digital workspace, featuring cloud storage and video conferencing, as well as calendar, contacts and task management functions, and an online office suite with documents, spreadsheets and presentations.&lt;/li&gt;&lt;li&gt;Migration service: mailbox's &lt;a href="https://mailbox.org/en/move-mailbox-migrate-your-emails-securely/" data-entity-type="node" data-entity-uuid="c6b65ee6-1da6-4943-b221-834f1eb4cce2" data-entity-substitution="canonical" title="Move to mailbox: Migrate your emails securely"&gt;migration service&lt;/a&gt; enables the free transfer of emails, folders, contacts, and calendars from common email providers for Premium and Standard tariff customers. Alternatively, manual transfer options are also available.&lt;/li&gt;&lt;li&gt;Central control: A particular advantage of mailbox is the central administration console for businesses, which facilitates the management of domains, inboxes, and user settings. This is particularly valuable for IT administrators in medium-sized enterprises.&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Conclusion: Finding the best email provider for your European business&lt;/h2&gt;&lt;p&gt;The choice of the best email provider for your business should be carefully considered in the current geopolitical and regulatory landscape. European providers such as mailbox offer significant advantages in terms of data protection and GDPR compliance, whilst also meeting basic requirements for security, reliability, and user-friendliness. Always consider your company-specific needs – be it enhanced data protection or comprehensive collaboration tools – as the right choice can represent a decisive competitive advantage in an increasingly complex digital environment.&lt;/p&gt;

          
                                                  
      


      
      &lt;h2 class="row__intro__title"&gt;            Insights &amp;amp; trends
      &lt;/h2&gt;
      Discover further best practices for your digital security.
              
            

&lt;a data-component-id="boxy:knob" data-component-variant="secondary" class="knob knob--secondary" href="https://mailbox.org/en/insights/"&gt;All articles&lt;/a&gt;

        
          
    
      
      
  
  
                    
                  
              
                  &lt;img loading="lazy" height="2160" width="4096" src="https://mailbox.org/sites/default/files/2026-08/mailbox%20EVAC%20Blog%20Business%20Continuity%20in%20der%20Lieferkette.jpeg" alt="mailbox EVAC Blog Business Continuity in der Lieferkette"&gt;

  


      
      
      
      Best practice, Business Continuitiy
    
    &lt;h3 class="snip__title"&gt;How to use business continuity as a competitive advantage in the supply chain&lt;/h3&gt;
  &lt;a class="snip__arrow" href="https://mailbox.org/en/blog/business-continuity-supply-chain/" aria-hidden="true"&gt;→&lt;/a&gt;
  &lt;a class="snip__link" href="https://mailbox.org/en/blog/business-continuity-supply-chain/"&gt;Read more about &lt;em class="placeholder"&gt;How to use business continuity as a competitive advantage in the supply chain&lt;/em&gt;&lt;/a&gt;


    
      
      
  
  
                    
                  
              
                  &lt;img loading="lazy" height="4065" width="6098" src="https://mailbox.org/sites/default/files/2026-07/mailbox%20Blog%20E-Mail-Alias.jpeg" alt="mailbox Blog E-Mail-Alias"&gt;

  


      
      
      
      Best practice, Data protection
    
    &lt;h3 class="snip__title"&gt;Email alias: How to protect your email address from spam&lt;/h3&gt;
  &lt;a class="snip__arrow" href="https://mailbox.org/en/blog/email-alias-protection-against-spam/" aria-hidden="true"&gt;→&lt;/a&gt;
  &lt;a class="snip__link" href="https://mailbox.org/en/blog/email-alias-protection-against-spam/"&gt;Read more about &lt;em class="placeholder"&gt;Email alias: How to protect your email address from spam&lt;/em&gt;&lt;/a&gt;


    
  
  


</description>
  <guid isPermaLink="false">8278e3e0-4b22-4b60-9a1b-509b864c8457</guid>
    <pubDate>Wed, 16 Apr 2025 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>The best email providers for European businesses</dc:title>
    <dc:identifier>8278e3e0-4b22-4b60-9a1b-509b864c8457</dc:identifier>
    </item>
<item>
  <title>mailbox receives prestigious seal of quality</title>
  <link>https://mailbox.org/en/news/mailbox-receives-prestigious-seal-quality-german-software-and-hosting/</link>
  <description>&lt;p&gt;Good news for anyone who values data protection and digital sovereignty: The Bundesverband IT-Mittelstand e.V. (BITMi) has honoured mailbox.org with two important seals. With the "Software made in Germany" and "Software hosted in Germany" quality seals, the German email provider emphasises its commitment to the highest quality standards and consistent data protection.&lt;/p&gt;&lt;h2&gt;Development according to German standards&lt;/h2&gt;&lt;p&gt;The "Software made in Germany" quality seal stands for IT solutions that are developed in Germany and whose quality assurance takes place in Germany. The seal confirms that mailbox.org is designed to be user-friendly and comes with comprehensive German-language documentation as well as reliable service and support. For users, it also means long-term investment security.&lt;/p&gt;&lt;h2&gt;Hosted in German data centres&lt;/h2&gt;&lt;p&gt;The "Software hosted in Germany" seal relates to the operation of the services. To receive this award, it must be proven that all data and the software itself are processed exclusively in German data centres and that all data processing is subject exclusively to German law. This means that emails and user data never leave German data centres and enjoy the protection of strict German data protection laws - an important argument for privacy-conscious individuals and companies.&lt;/p&gt;&lt;h2&gt;Real digital sovereignty for users&lt;/h2&gt;&lt;p&gt;With both seals, mailbox.org is strengthening its position as a trustworthy alternative to large international providers. In times when data protection and digital sovereignty are becoming increasingly important, the company offers its users the security of knowing that their personal information is protected to the highest standards - developed and hosted in Germany, under the control of German data protection laws.&lt;/p&gt;&lt;p&gt;For anyone who values privacy, security and quality, these seals are another good reason to use the services of mailbox.org.&lt;/p&gt;&amp;nbsp;

  
      
  &lt;a name="logos-9508"&gt;&lt;/a&gt;
  
  
      
    
  </description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-BITMi-siegel-software-made-in-germany.jpeg?itok=IdAyOy_t" type="image/jpeg" length="432600"/><guid isPermaLink="false">222c1f06-9d97-454d-bb06-60b1f67073a7</guid>
    <pubDate>Tue, 15 Apr 2025 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>mailbox receives prestigious seal of quality</dc:title>
    <dc:identifier>222c1f06-9d97-454d-bb06-60b1f67073a7</dc:identifier>
    </item>
<item>
  <title>mailbox receives prestigious seal of quality</title>
  <link>https://mailbox.org/en/news/mailbox-receives-prestigious-seal-quality-german-software-and-hosting/</link>
  <description>&lt;p&gt;Good news for anyone who values data protection and digital sovereignty: The Bundesverband IT-Mittelstand e.V. (BITMi) has honoured mailbox.org with two important seals. With the "Software made in Germany" and "Software hosted in Germany" quality seals, the German email provider emphasises its commitment to the highest quality standards and consistent data protection.&lt;/p&gt;&lt;h2&gt;Development according to German standards&lt;/h2&gt;&lt;p&gt;The "Software made in Germany" quality seal stands for IT solutions that are developed in Germany and whose quality assurance takes place in Germany. The seal confirms that mailbox.org is designed to be user-friendly and comes with comprehensive German-language documentation as well as reliable service and support. For users, it also means long-term investment security.&lt;/p&gt;&lt;h2&gt;Hosted in German data centres&lt;/h2&gt;&lt;p&gt;The "Software hosted in Germany" seal relates to the operation of the services. To receive this award, it must be proven that all data and the software itself are processed exclusively in German data centres and that all data processing is subject exclusively to German law. This means that emails and user data never leave German data centres and enjoy the protection of strict German data protection laws - an important argument for privacy-conscious individuals and companies.&lt;/p&gt;&lt;h2&gt;Real digital sovereignty for users&lt;/h2&gt;&lt;p&gt;With both seals, mailbox.org is strengthening its position as a trustworthy alternative to large international providers. In times when data protection and digital sovereignty are becoming increasingly important, the company offers its users the security of knowing that their personal information is protected to the highest standards - developed and hosted in Germany, under the control of German data protection laws.&lt;/p&gt;&lt;p&gt;For anyone who values privacy, security and quality, these seals are another good reason to use the services of mailbox.org.&lt;/p&gt;&amp;nbsp;

  
      
  &lt;a name="logos-9508"&gt;&lt;/a&gt;
  
  
      
    
  </description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-BITMi-siegel-software-made-in-germany.jpeg?itok=IdAyOy_t" type="image/jpeg" length="432600"/><guid isPermaLink="false">222c1f06-9d97-454d-bb06-60b1f67073a7</guid>
    <pubDate>Tue, 15 Apr 2025 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>mailbox receives prestigious seal of quality</dc:title>
    <dc:identifier>222c1f06-9d97-454d-bb06-60b1f67073a7</dc:identifier>
    </item>
<item>
  <title>Digital strategy in the 2025 coalition agreement</title>
  <link>https://mailbox.org/en/news/digital-strategy-in-the-2025-coalition-agreement/</link>
  <description>&lt;h2&gt;Germany's path to digital sovereignty&lt;/h2&gt;&lt;p&gt;The new coalition agreement has been signed – and the digital strategy has become a strategic pillar for Germany's future. Digital policy is now unambiguously defined as "power politics" in the current agreement. But what's different this time? After a decade of grand announcements and often disappointing implementation, the question arises: Can Germany finally hope for concrete results rather than mere statements of intent?&lt;/p&gt;&lt;h3&gt;The new digital strategy: Sovereignty as a core principle&lt;/h3&gt;&lt;p&gt;The new coalition has placed its digital strategy under the guiding principle "Digital. Sovereign. Ambitious". Unlike previous approaches, the digital strategy is no longer viewed in isolation but is closely linked to geopolitical, economic and security policy objectives. The central focus lies on digital sovereignty – the ability to act independently and autonomously in the digital space.&lt;/p&gt;&lt;p&gt;The strategy encompasses three core areas:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Digital policy as power politics: Germany aims to reduce digital dependencies by developing key technologies itself, securing standards and protecting digital infrastructures. This includes building European-integrated and resilient value chains – from raw materials through chips to hardware and software.&lt;/li&gt;&lt;li&gt;Digital policy as economic policy: Germany should be "put in the digital fast lane" through better conditions for application-oriented research, start-ups and knowledge transfer. A particular emphasis is placed on building computing capacities.&lt;/li&gt;&lt;li&gt;Digital policy as social policy: Digital competencies of all citizens should be strengthened to enable social participation and protect democracy against disinformation.&lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;Open source as a strategic key&lt;/h3&gt;&lt;p&gt;Open source and open standards play a central role in implementing digital sovereignty. The 2025 coalition agreement stipulates that open interfaces and standards be defined across all levels, and that open source be strategically advanced with private and public actors in the European ecosystem. In other words: federal, state and local governments should work together on open technical solutions that can be used by all, rather than creating closed, isolated solutions. Institutions such as the Centre for Digital Sovereignty (ZenDiS), the Sovereign Tech Agency and the Federal Agency for Disruptive Innovation (SPRIND) are to be utilised for this purpose. The announcement to strategically align the IT budget and define concrete goals for open source underscores the importance of open technologies as a foundation for digital sovereignty.&lt;/p&gt;&lt;h3&gt;From vague goals to concrete measures: A new era?&lt;/h3&gt;&lt;p&gt;A look at the past shows why the current strategy could represent a turning point. Previous digital strategies suffered from vague formulations, unclear responsibilities and insufficient funding. This led to a sobering balance sheet for flagship projects such as broadband expansion or administrative digitalisation.&lt;/p&gt;


  &lt;h2 class="referent__title"&gt;&lt;/h2&gt;
  
                
        
                    
            
                          &lt;h3 class="referent__headline"&gt;
                The role of digitalisation in coalition agreements
                              &lt;/h3&gt;
            
            
                          &lt;p&gt;In previous coalition agreements, the importance of digitalisation varied considerably: In the "Digital Agenda" (2013-2017), it was still a marginal issue without a strategic vision, primarily focused on broadband expansion. The "National Digital Strategy" (2017-2021) suffered from fragmented responsibilities and lack of coordination. Only the "Digital Strategy Germany" (2021-2025) established concrete fields of action and measurable goals. These approaches usually failed due to the lack of coordination between federal, state and local governments, inadequate financing concepts and unrealistic timelines – often leaving little of the grandiose promises.&lt;/p&gt;
                        
        
      
      

              


  
    
    
    
    &lt;p&gt;What distinguishes the current 2025 coalition agreement is its significantly higher level of specificity: instead of vague declarations of intent, measurable results are sought, for example in AI promotion, in the establishment of "AI gigafactories" or with the Germany Stack – a kind of digital operating system for administration that combines AI, cloud services and basic components in one system. Implementation responsibilities are more clearly named, and financing receives a higher priority. This could represent a decisive difference from previous practice.&lt;/p&gt;&lt;h3&gt;When geopolitics determines digital policy&lt;/h3&gt;&lt;p&gt;The new coalition agreement breaks with diplomatic platitudes: "Untrustworthy providers" will in future be "legally excluded". This clear positioning reflects the new geopolitical reality in which technology has become a strategic power factor.&lt;/p&gt;&lt;p&gt;This formulation doesn't come by chance at a time of growing tensions. Over the past decades, Germany has placed itself in deep technological dependencies – be it in cloud infrastructures, operating systems and software from the US, or in network technologies from China. What was long considered a purely economic decision is increasingly seen as a security policy risk.&lt;/p&gt;&lt;h3&gt;Package of measures for digital sovereignty&lt;/h3&gt;&lt;p&gt;The new coalition is thus responding with a comprehensive package of measures: A German Administrative Cloud (DVC) with sovereign standards is to prevent uncontrolled data outflows. The interoperable Germany Stack is to be compatible with European systems, and in the future, only components from "trustworthy states" will be used in critical infrastructures. By strategically aligning the IT budget towards open source, the state aims to become an "anchor customer for the digital economy" – a potentially powerful lever for greater digital sovereignty.&lt;/p&gt;&lt;h3&gt;Outlook: From announcement champion to implementation champion?&lt;/h3&gt;&lt;p&gt;The central anchoring of the digital strategy in the 2025 coalition agreement marks an important turning point for Germany. In a world where digital technologies determine economic strength and geopolitical influence, Germany can no longer afford to miss the digital connection. The new strategy, with its focus on sovereignty, innovation and open source, could initiate a change in thinking. The decisive factor will be whether Germany this time finds its way from "announcement champion" to "implementation champion". The more concrete goal-setting and geopolitical embedding suggest a more serious approach – the coming years will show whether Germany finally achieves the digital breakthrough.&lt;/p&gt;

          
                                                  
      
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-07/Blog-Koalitionsvertrag-042025.jpeg?itok=lN4_wRIP" type="image/jpeg" length="465748"/><guid isPermaLink="false">b0f7010b-1f62-410c-a1f5-fd0805693dd0</guid>
    <pubDate>Fri, 11 Apr 2025 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Digital strategy in the 2025 coalition agreement</dc:title>
    <dc:identifier>b0f7010b-1f62-410c-a1f5-fd0805693dd0</dc:identifier>
    </item>
<item>
  <title>Digital strategy in the 2025 coalition agreement</title>
  <link>https://mailbox.org/en/news/digital-strategy-in-the-2025-coalition-agreement/</link>
  <description>&lt;h2&gt;Germany's path to digital sovereignty&lt;/h2&gt;&lt;p&gt;The new coalition agreement has been signed – and the digital strategy has become a strategic pillar for Germany's future. Digital policy is now unambiguously defined as "power politics" in the current agreement. But what's different this time? After a decade of grand announcements and often disappointing implementation, the question arises: Can Germany finally hope for concrete results rather than mere statements of intent?&lt;/p&gt;&lt;h3&gt;The new digital strategy: Sovereignty as a core principle&lt;/h3&gt;&lt;p&gt;The new coalition has placed its digital strategy under the guiding principle "Digital. Sovereign. Ambitious". Unlike previous approaches, the digital strategy is no longer viewed in isolation but is closely linked to geopolitical, economic and security policy objectives. The central focus lies on digital sovereignty – the ability to act independently and autonomously in the digital space.&lt;/p&gt;&lt;p&gt;The strategy encompasses three core areas:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Digital policy as power politics: Germany aims to reduce digital dependencies by developing key technologies itself, securing standards and protecting digital infrastructures. This includes building European-integrated and resilient value chains – from raw materials through chips to hardware and software.&lt;/li&gt;&lt;li&gt;Digital policy as economic policy: Germany should be "put in the digital fast lane" through better conditions for application-oriented research, start-ups and knowledge transfer. A particular emphasis is placed on building computing capacities.&lt;/li&gt;&lt;li&gt;Digital policy as social policy: Digital competencies of all citizens should be strengthened to enable social participation and protect democracy against disinformation.&lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;Open source as a strategic key&lt;/h3&gt;&lt;p&gt;Open source and open standards play a central role in implementing digital sovereignty. The 2025 coalition agreement stipulates that open interfaces and standards be defined across all levels, and that open source be strategically advanced with private and public actors in the European ecosystem. In other words: federal, state and local governments should work together on open technical solutions that can be used by all, rather than creating closed, isolated solutions. Institutions such as the Centre for Digital Sovereignty (ZenDiS), the Sovereign Tech Agency and the Federal Agency for Disruptive Innovation (SPRIND) are to be utilised for this purpose. The announcement to strategically align the IT budget and define concrete goals for open source underscores the importance of open technologies as a foundation for digital sovereignty.&lt;/p&gt;&lt;h3&gt;From vague goals to concrete measures: A new era?&lt;/h3&gt;&lt;p&gt;A look at the past shows why the current strategy could represent a turning point. Previous digital strategies suffered from vague formulations, unclear responsibilities and insufficient funding. This led to a sobering balance sheet for flagship projects such as broadband expansion or administrative digitalisation.&lt;/p&gt;


  &lt;h2 class="referent__title"&gt;&lt;/h2&gt;
  
                
        
                    
            
                          &lt;h3 class="referent__headline"&gt;
                The role of digitalisation in coalition agreements
                              &lt;/h3&gt;
            
            
                          &lt;p&gt;In previous coalition agreements, the importance of digitalisation varied considerably: In the "Digital Agenda" (2013-2017), it was still a marginal issue without a strategic vision, primarily focused on broadband expansion. The "National Digital Strategy" (2017-2021) suffered from fragmented responsibilities and lack of coordination. Only the "Digital Strategy Germany" (2021-2025) established concrete fields of action and measurable goals. These approaches usually failed due to the lack of coordination between federal, state and local governments, inadequate financing concepts and unrealistic timelines – often leaving little of the grandiose promises.&lt;/p&gt;
                        
        
      
      

              


  
    
    
    
    &lt;p&gt;What distinguishes the current 2025 coalition agreement is its significantly higher level of specificity: instead of vague declarations of intent, measurable results are sought, for example in AI promotion, in the establishment of "AI gigafactories" or with the Germany Stack – a kind of digital operating system for administration that combines AI, cloud services and basic components in one system. Implementation responsibilities are more clearly named, and financing receives a higher priority. This could represent a decisive difference from previous practice.&lt;/p&gt;&lt;h3&gt;When geopolitics determines digital policy&lt;/h3&gt;&lt;p&gt;The new coalition agreement breaks with diplomatic platitudes: "Untrustworthy providers" will in future be "legally excluded". This clear positioning reflects the new geopolitical reality in which technology has become a strategic power factor.&lt;/p&gt;&lt;p&gt;This formulation doesn't come by chance at a time of growing tensions. Over the past decades, Germany has placed itself in deep technological dependencies – be it in cloud infrastructures, operating systems and software from the US, or in network technologies from China. What was long considered a purely economic decision is increasingly seen as a security policy risk.&lt;/p&gt;&lt;h3&gt;Package of measures for digital sovereignty&lt;/h3&gt;&lt;p&gt;The new coalition is thus responding with a comprehensive package of measures: A German Administrative Cloud (DVC) with sovereign standards is to prevent uncontrolled data outflows. The interoperable Germany Stack is to be compatible with European systems, and in the future, only components from "trustworthy states" will be used in critical infrastructures. By strategically aligning the IT budget towards open source, the state aims to become an "anchor customer for the digital economy" – a potentially powerful lever for greater digital sovereignty.&lt;/p&gt;&lt;h3&gt;Outlook: From announcement champion to implementation champion?&lt;/h3&gt;&lt;p&gt;The central anchoring of the digital strategy in the 2025 coalition agreement marks an important turning point for Germany. In a world where digital technologies determine economic strength and geopolitical influence, Germany can no longer afford to miss the digital connection. The new strategy, with its focus on sovereignty, innovation and open source, could initiate a change in thinking. The decisive factor will be whether Germany this time finds its way from "announcement champion" to "implementation champion". The more concrete goal-setting and geopolitical embedding suggest a more serious approach – the coming years will show whether Germany finally achieves the digital breakthrough.&lt;/p&gt;

          
                                                  
      
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-07/Blog-Koalitionsvertrag-042025.jpeg?itok=lN4_wRIP" type="image/jpeg" length="465748"/><guid isPermaLink="false">b0f7010b-1f62-410c-a1f5-fd0805693dd0</guid>
    <pubDate>Fri, 11 Apr 2025 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Digital strategy in the 2025 coalition agreement</dc:title>
    <dc:identifier>b0f7010b-1f62-410c-a1f5-fd0805693dd0</dc:identifier>
    </item>
<item>
  <title>The new and improved Login 2.0</title>
  <link>https://mailbox.org/en/news/the-new-login/</link>
  <description>&lt;p&gt;Good news for all mailbox.org users! What was previously only available as a beta version for selected testers is now being activated for all customers: the new Login 2.0. After a successful testing phase, users can benefit from improved security and convenience features. New customers will automatically receive access to Login 2.0 from now on. Existing customers will be migrated gradually over the coming weeks and notified by email before the change.&lt;/p&gt;&lt;h2&gt;What is Login 2.0?&lt;/h2&gt;&lt;p&gt;Login 2.0 is a fundamental revision of the mailbox.org login system. The new version offers a modern design and improved security features.&lt;/p&gt;&lt;h3&gt;New features at a glance&lt;/h3&gt;&lt;p&gt;With Login 2.0, several improvements are coming that make your email experience more secure and convenient:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Simplified handling of Two-Factor Authentication (2FA)&lt;/li&gt;&lt;li&gt;The new feature for Email App Passwords for external email programmes&lt;/li&gt;&lt;li&gt;Single Sign-on (SSO) for seamless access to various mailbox.org services&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;New Feature 1: Two-Factor Authentication (2FA) modernised&lt;/h2&gt;&lt;p&gt;Two-Factor Authentication (2FA) is one of the most important measures to protect your account. We understand that the previous setup process was too complex and prevented many users from activating this important security feature. With Login 2.0 and our new security architecture, we have reduced the entire process to just three simple steps. The setup is now significantly more intuitive and quicker to complete. Through this simplification, we want to give all users access to more security without having to compromise on user-friendliness. A secure account doesn't have to be complicated – with the new 2FA setup, it becomes more convenient and easier than ever to effectively secure your login.&lt;/p&gt;&lt;h3&gt;Simple setup in 3 steps with Authenticator app&lt;/h3&gt;&lt;p&gt;1. Scan the QR code in an Authenticator app of your choice&lt;br&gt;2. Enter the TOTP code from the app&lt;br&gt;3. Assign a device name and save&lt;/p&gt;&lt;p&gt;You can find detailed instructions in our &lt;a href="https://kb.mailbox.org/en/private/account-article/how-to-use-two-factor-authentication-2fa/" target="_blank" title="go to knowledge base" rel="noopener"&gt;knowledge base&lt;/a&gt;.&lt;/p&gt;&lt;h3&gt;2FA briefly explained&lt;/h3&gt;&lt;p&gt;Two-Factor Authentication is an additional security layer for your account. Besides your password (first factor), you need a second factor to log in – for example, a code sent to your mobile phone or generated by an Authenticator app. This makes your account significantly more secure, as potential attackers would need both factors.&lt;/p&gt;&lt;h2&gt;New Feature 2: Single Sign-on – Log in once, use everything&lt;/h2&gt;&lt;p&gt;A particularly practical innovation of Login 2.0 is the Single Sign-on function. With this feature, you only need to log in once to gain access to all mailbox.org services. This means:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Seamless switching between email, forum, support, and other services&lt;/li&gt;&lt;li&gt;Increased security through centralised authentication&lt;/li&gt;&lt;li&gt;Time savings and more convenience in daily use of your mailbox.org account&lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;Single Sign-on (SSO) briefly explained&lt;/h3&gt;&lt;p&gt;Single Sign-on means "one-time login" and allows you to log in just once with your credentials to subsequently access multiple different services and applications. This saves time and reduces the need to log in multiple times.&lt;/p&gt;&lt;h2&gt;New Feature 3: Email App Passwords – new and important!&lt;/h2&gt;&lt;p&gt;A special highlight of Login 2.0 is the new Email App Passwords. These are individual credentials specifically created for email apps and programmes. This feature offers several advantages:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Protection of your main password, as it doesn't need to be stored in various apps&lt;/li&gt;&lt;li&gt;Possibility to create a separate password for each app&lt;/li&gt;&lt;li&gt;If a device is lost, you can simply block the corresponding app password without having to change your main password&lt;/li&gt;&lt;li&gt;Separate control of IMAP and SMTP access for each app password&lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;How to set up Email App Passwords&lt;/h3&gt;&lt;p&gt;Setting up the new app passwords is simple:&lt;/p&gt;&lt;p&gt;1. Log in to your mailbox.org account&lt;br&gt;2. Go to "Settings" &amp;gt; "mailbox.org" &amp;gt; "Email App Passwords"&lt;br&gt;3. Create a separate password for each of your email applications&lt;br&gt;4. You can optionally add a note to keep track&lt;br&gt;5. Set IMAP and SMTP permissions according to your preferences&lt;/p&gt;&lt;p&gt;You can find detailed instructions in our &lt;a href="https://kb.mailbox.org/en/private/security-privacy-article/email-app-passwords/" target="_blank" title="go to knowledge base" rel="noopener"&gt;knowledge base&lt;/a&gt;.&lt;/p&gt;&lt;h3&gt;Email App Passwords briefly explained&lt;/h3&gt;&lt;p&gt;Email App Passwords are special credentials that only grant access to your account for a specific programme or app. The advantage: these passwords have limited rights and can be revoked individually without having to change your main password.&lt;/p&gt;&lt;h2&gt;The rollout of Login 2.0 for our customers&lt;/h2&gt;&lt;h3&gt;The rollout of Login 2.0 for beta testers&lt;/h3&gt;&lt;p&gt;All beta testers who have already tested and are using the new Login 2.0 don't need to do anything and have already been automatically switched over.&lt;/p&gt;&lt;h3&gt;The rollout of Login 2.0 for existing customers without 2FA&lt;/h3&gt;&lt;p&gt;Existing customers without active Two-Factor Authentication will be gradually enabled for Login 2.0 in the coming weeks. We are implementing a gradual transition to ensure a smooth changeover. On the day of your personal transition, you will automatically receive an email with all important information and instructions about the new login system. This way, you can familiarise yourself with the new features at your leisure. Please pay attention to this notification to stay informed about your upcoming transition.&lt;/p&gt;&lt;h3&gt;The rollout of Login 2.0 for existing customers with 2FA&lt;/h3&gt;&lt;p&gt;If you are already using the previous version of Two-Factor Authentication, you will be redirected to a special page after logging in. There, you can easily and conveniently switch to the new 2FA method. The transition is important to continue benefiting from all security advantages. You will also receive an email when Login 2.0 is ready for you.&lt;/p&gt;&lt;h3&gt;The rollout of Login 2.0 for business customers and resellers&lt;/h3&gt;&lt;p&gt;After we have migrated all private customers, business customers and resellers will be informed about the schedule for the rollout in due course.&lt;/p&gt;&lt;h2&gt;Login 2.0: Your security – Easier than ever before&lt;/h2&gt;&lt;p&gt;With Login 2.0, mailbox.org is taking an important step towards increased security and user-friendliness. The new features help you to protect your emails and personal data even better, while convenience is significantly enhanced through features like Single Sign-on. If you have questions about the transition, mailbox.org support is happy to help.&lt;/p&gt;&lt;h3&gt;A big thank you to our beta testers&lt;/h3&gt;&lt;p&gt;At this point, we would like to express our sincere thanks to all beta testers who have thoroughly examined Login 2.0. Through your valuable feedback, we were able to optimise the new features and eliminate initial problems before making them available to all users. Your suggestions and input were invaluable for the development of this important update. By the way: If you would like to participate in beta tests in the future, you can sign up for our beta programme at any time. Simply visit the "Settings" &amp;gt; "mailbox.org" &amp;gt; "Beta Programme" section and activate the corresponding option. This way, you will always stay informed about our latest developments and can actively help shape them.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-der-neue-login-2.jpeg?itok=dy-beDyi" type="image/jpeg" length="308399"/><guid isPermaLink="false">9be4b46c-7926-40b1-9ceb-23abb5ac4b3e</guid>
    <pubDate>Wed, 09 Apr 2025 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>The new and improved Login 2.0</dc:title>
    <dc:identifier>9be4b46c-7926-40b1-9ceb-23abb5ac4b3e</dc:identifier>
    </item>
<item>
  <title>The new and improved Login 2.0</title>
  <link>https://mailbox.org/en/news/the-new-login/</link>
  <description>&lt;p&gt;Good news for all mailbox.org users! What was previously only available as a beta version for selected testers is now being activated for all customers: the new Login 2.0. After a successful testing phase, users can benefit from improved security and convenience features. New customers will automatically receive access to Login 2.0 from now on. Existing customers will be migrated gradually over the coming weeks and notified by email before the change.&lt;/p&gt;&lt;h2&gt;What is Login 2.0?&lt;/h2&gt;&lt;p&gt;Login 2.0 is a fundamental revision of the mailbox.org login system. The new version offers a modern design and improved security features.&lt;/p&gt;&lt;h3&gt;New features at a glance&lt;/h3&gt;&lt;p&gt;With Login 2.0, several improvements are coming that make your email experience more secure and convenient:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Simplified handling of Two-Factor Authentication (2FA)&lt;/li&gt;&lt;li&gt;The new feature for Email App Passwords for external email programmes&lt;/li&gt;&lt;li&gt;Single Sign-on (SSO) for seamless access to various mailbox.org services&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;New Feature 1: Two-Factor Authentication (2FA) modernised&lt;/h2&gt;&lt;p&gt;Two-Factor Authentication (2FA) is one of the most important measures to protect your account. We understand that the previous setup process was too complex and prevented many users from activating this important security feature. With Login 2.0 and our new security architecture, we have reduced the entire process to just three simple steps. The setup is now significantly more intuitive and quicker to complete. Through this simplification, we want to give all users access to more security without having to compromise on user-friendliness. A secure account doesn't have to be complicated – with the new 2FA setup, it becomes more convenient and easier than ever to effectively secure your login.&lt;/p&gt;&lt;h3&gt;Simple setup in 3 steps with Authenticator app&lt;/h3&gt;&lt;p&gt;1. Scan the QR code in an Authenticator app of your choice&lt;br&gt;2. Enter the TOTP code from the app&lt;br&gt;3. Assign a device name and save&lt;/p&gt;&lt;p&gt;You can find detailed instructions in our &lt;a href="https://kb.mailbox.org/en/private/account-article/how-to-use-two-factor-authentication-2fa/" target="_blank" title="go to knowledge base" rel="noopener"&gt;knowledge base&lt;/a&gt;.&lt;/p&gt;&lt;h3&gt;2FA briefly explained&lt;/h3&gt;&lt;p&gt;Two-Factor Authentication is an additional security layer for your account. Besides your password (first factor), you need a second factor to log in – for example, a code sent to your mobile phone or generated by an Authenticator app. This makes your account significantly more secure, as potential attackers would need both factors.&lt;/p&gt;&lt;h2&gt;New Feature 2: Single Sign-on – Log in once, use everything&lt;/h2&gt;&lt;p&gt;A particularly practical innovation of Login 2.0 is the Single Sign-on function. With this feature, you only need to log in once to gain access to all mailbox.org services. This means:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Seamless switching between email, forum, support, and other services&lt;/li&gt;&lt;li&gt;Increased security through centralised authentication&lt;/li&gt;&lt;li&gt;Time savings and more convenience in daily use of your mailbox.org account&lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;Single Sign-on (SSO) briefly explained&lt;/h3&gt;&lt;p&gt;Single Sign-on means "one-time login" and allows you to log in just once with your credentials to subsequently access multiple different services and applications. This saves time and reduces the need to log in multiple times.&lt;/p&gt;&lt;h2&gt;New Feature 3: Email App Passwords – new and important!&lt;/h2&gt;&lt;p&gt;A special highlight of Login 2.0 is the new Email App Passwords. These are individual credentials specifically created for email apps and programmes. This feature offers several advantages:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Protection of your main password, as it doesn't need to be stored in various apps&lt;/li&gt;&lt;li&gt;Possibility to create a separate password for each app&lt;/li&gt;&lt;li&gt;If a device is lost, you can simply block the corresponding app password without having to change your main password&lt;/li&gt;&lt;li&gt;Separate control of IMAP and SMTP access for each app password&lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;How to set up Email App Passwords&lt;/h3&gt;&lt;p&gt;Setting up the new app passwords is simple:&lt;/p&gt;&lt;p&gt;1. Log in to your mailbox.org account&lt;br&gt;2. Go to "Settings" &amp;gt; "mailbox.org" &amp;gt; "Email App Passwords"&lt;br&gt;3. Create a separate password for each of your email applications&lt;br&gt;4. You can optionally add a note to keep track&lt;br&gt;5. Set IMAP and SMTP permissions according to your preferences&lt;/p&gt;&lt;p&gt;You can find detailed instructions in our &lt;a href="https://kb.mailbox.org/en/private/security-privacy-article/email-app-passwords/" target="_blank" title="go to knowledge base" rel="noopener"&gt;knowledge base&lt;/a&gt;.&lt;/p&gt;&lt;h3&gt;Email App Passwords briefly explained&lt;/h3&gt;&lt;p&gt;Email App Passwords are special credentials that only grant access to your account for a specific programme or app. The advantage: these passwords have limited rights and can be revoked individually without having to change your main password.&lt;/p&gt;&lt;h2&gt;The rollout of Login 2.0 for our customers&lt;/h2&gt;&lt;h3&gt;The rollout of Login 2.0 for beta testers&lt;/h3&gt;&lt;p&gt;All beta testers who have already tested and are using the new Login 2.0 don't need to do anything and have already been automatically switched over.&lt;/p&gt;&lt;h3&gt;The rollout of Login 2.0 for existing customers without 2FA&lt;/h3&gt;&lt;p&gt;Existing customers without active Two-Factor Authentication will be gradually enabled for Login 2.0 in the coming weeks. We are implementing a gradual transition to ensure a smooth changeover. On the day of your personal transition, you will automatically receive an email with all important information and instructions about the new login system. This way, you can familiarise yourself with the new features at your leisure. Please pay attention to this notification to stay informed about your upcoming transition.&lt;/p&gt;&lt;h3&gt;The rollout of Login 2.0 for existing customers with 2FA&lt;/h3&gt;&lt;p&gt;If you are already using the previous version of Two-Factor Authentication, you will be redirected to a special page after logging in. There, you can easily and conveniently switch to the new 2FA method. The transition is important to continue benefiting from all security advantages. You will also receive an email when Login 2.0 is ready for you.&lt;/p&gt;&lt;h3&gt;The rollout of Login 2.0 for business customers and resellers&lt;/h3&gt;&lt;p&gt;After we have migrated all private customers, business customers and resellers will be informed about the schedule for the rollout in due course.&lt;/p&gt;&lt;h2&gt;Login 2.0: Your security – Easier than ever before&lt;/h2&gt;&lt;p&gt;With Login 2.0, mailbox.org is taking an important step towards increased security and user-friendliness. The new features help you to protect your emails and personal data even better, while convenience is significantly enhanced through features like Single Sign-on. If you have questions about the transition, mailbox.org support is happy to help.&lt;/p&gt;&lt;h3&gt;A big thank you to our beta testers&lt;/h3&gt;&lt;p&gt;At this point, we would like to express our sincere thanks to all beta testers who have thoroughly examined Login 2.0. Through your valuable feedback, we were able to optimise the new features and eliminate initial problems before making them available to all users. Your suggestions and input were invaluable for the development of this important update. By the way: If you would like to participate in beta tests in the future, you can sign up for our beta programme at any time. Simply visit the "Settings" &amp;gt; "mailbox.org" &amp;gt; "Beta Programme" section and activate the corresponding option. This way, you will always stay informed about our latest developments and can actively help shape them.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-der-neue-login-2.jpeg?itok=dy-beDyi" type="image/jpeg" length="308399"/><guid isPermaLink="false">9be4b46c-7926-40b1-9ceb-23abb5ac4b3e</guid>
    <pubDate>Wed, 09 Apr 2025 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>The new and improved Login 2.0</dc:title>
    <dc:identifier>9be4b46c-7926-40b1-9ceb-23abb5ac4b3e</dc:identifier>
    </item>
<item>
  <title>More email security in the education sector</title>
  <link>https://mailbox.org/en/success-story/enhanced-email-security-education-sector/</link>
  <description>&lt;p&gt;&lt;em&gt;Reading time: 6 minutes&lt;/em&gt;&lt;/p&gt;&lt;p&gt;When emails fail to arrive or end up in spam folders, the consequences for the digital education industry can be far-reaching. This was precisely the challenge facing oncampus GmbH, one of Germany's leading e-learning providers, in 2021. The subsidiary of the Technical University of Lübeck serves thousands of learners daily with part-time degree programmes, professional development courses, and innovative online training. Reliable email communication is therefore business-critical.&lt;/p&gt;


      
                  
              
              
              
              
              
              
              
                  &lt;img loading="lazy" height="3760" width="5652" src="https://mailbox.org/sites/default/files/2025-05/Blog-oncampus.jpeg" alt="Concentrated African-American student taking notes on a notepad during online lessons, e-learning concept"&gt;

  


  
          

              


  
    
    
    
    &lt;h3&gt;Delivery problems jeopardise business communication&lt;/h3&gt;&lt;p&gt;Patrick Müller, IT System Administrator at oncampus, recalls the initial situation: "A major problem was that emails sent by us were classified as untrustworthy at server level and consequently not delivered." This was an existential issue for the e-learning provider—especially since municipal institutions were among the users of their platform. The search for a reliable alternative quickly led oncampus to mailbox.org, whose service promise directly addressed the existing problem areas.&lt;/p&gt;&lt;h3&gt;Priorities: Reliability, security and Moodle integration&lt;/h3&gt;&lt;p&gt;The requirements for the new email service provider were clear: alongside reliable delivery of all emails—even for mass mailings—high security and comprehensive data protection standards were priorities. As a full-service provider for the Virtual University of Applied Sciences (VFH) consortium, seamless integration with the Moodle learning platform was also of great importance. The university consortium provides course materials and collaboration functions for students through this platform—making smooth email connectivity essential. Last but not least, oncampus was keen to help its users achieve greater digital sovereignty and data autonomy.&lt;/p&gt;&lt;h3&gt;Service package: Data protection made in Germany&lt;/h3&gt;&lt;p&gt;mailbox.org not only fulfilled all these requirements but also offered secure and advertisement-free email inboxes, reliable malware screening including innovative spam filters, and consistent SSL/TLS encryption. It was equally impressive that the Germany-based email provider operates its own IT server infrastructure in two German data centres and is committed to full compliance with GDPR and German data protection law. The many additional features were also positively received, such as the mailbox.org Office package with its virtual desktop, mobile access to documents, appointments and tasks, or the ability to hold video conferences directly within the platform.&lt;/p&gt;&lt;h3&gt;Smooth transition without disruption&lt;/h3&gt;&lt;p&gt;The collaboration began in summer 2021. The transition process went smoothly—mailbox.org took over the management of all email addresses and ensured a seamless changeover. Thanks to the convenient migration service, existing email inboxes were transferred without interruption. The integration with the Moodle platform also worked flawlessly from the start, so that today, sending and receiving emails in the Moodle forums runs without complications.&lt;/p&gt;

          
                                                  
      


  &lt;h2 class="referent__title"&gt;&lt;/h2&gt;
  
                
        
                      
                &lt;img loading="lazy" height width src="https://mailbox.org/sites/default/files/2025-05/referenz-oncampus.svg" alt="On Campus Logo"&gt;


            
                    
            
                          &lt;h3 class="referent__headline"&gt;
                Marc Vorreiter, IT Manager at oncampus.
                              &lt;/h3&gt;
            
            
                          &lt;p class="huge"&gt;"We are very grateful for the quick, straightforward service and the personal, competent support.“&lt;/p&gt;
                        
        
      
      

              


  
    
    
    
    &lt;h3&gt;Authenticated communication and reliable support&lt;/h3&gt;&lt;p&gt;oncampus now benefits from a thoroughly reliable solution. The emails are officially authenticated and no longer end up in spam folders—even with mass mailings. Communication with students, customers and partners runs without disruption. Should problems still arise, mailbox.org's professional support is always available to answer questions. Thanks to the high security standards, which ensure the best possible protection of sensitive educational data, Patrick Müller is completely satisfied with the solution.&lt;/p&gt;&lt;h3&gt;Assessment: Digital education on a secure foundation&lt;/h3&gt;&lt;p&gt;For oncampus, switching to mailbox.org has proven beneficial in every respect. The email solution not only meets the highest security and data protection standards but also perfectly supports the specific requirements of a digital education provider. Since email communication has been working reliably since implementation, oncampus can once again focus entirely on its core business: providing high-quality digital education offerings.&lt;/p&gt;&lt;h3&gt;About oncampus&lt;/h3&gt;&lt;p&gt;oncampus GmbH is a German e-learning provider and a wholly owned subsidiary of the Technical University of Lübeck. The company was founded in 2003 and specialises in digital education offerings—the spectrum ranges from individual online courses and part-time online master's degree programmes to customised e-learning solutions for universities, institutions and companies. Today, oncampus employs more than 60 staff at its Lübeck location and counts over 200,000 learners among its users.&lt;/p&gt;

          
                                                  
      


      
      &lt;h2 class="row__intro__title"&gt;            Insights &amp;amp; trends
      &lt;/h2&gt;
      Discover further best practices for your digital security.
              
            

&lt;a data-component-id="boxy:knob" data-component-variant="secondary" class="knob knob--secondary" href="https://mailbox.org/en/insights/"&gt;All articles&lt;/a&gt;

        
          
    
      
      
  
  
                    
                  
              
                  &lt;img loading="lazy" height="4000" width="6000" src="https://mailbox.org/sites/default/files/2025-06/SSY-LinuxNews.jpeg" alt="Person sitting at the table with hot drink and mobile phone in hand"&gt;

  


      
      
      
      Best practice
    
    &lt;h3 class="snip__title"&gt;Email that grows with your business: LinuxNews story&lt;/h3&gt;
  &lt;a class="snip__arrow" href="https://mailbox.org/en/success-story/how-mailbox-grows-with-linuxnews/" aria-hidden="true"&gt;→&lt;/a&gt;
  &lt;a class="snip__link" href="https://mailbox.org/en/success-story/how-mailbox-grows-with-linuxnews/"&gt;Read more about &lt;em class="placeholder"&gt;Email that grows with your business: LinuxNews story&lt;/em&gt;&lt;/a&gt;


    
      
      
  
  
                    
                  
              
                  &lt;img loading="lazy" height="3648" width="5472" src="https://mailbox.org/sites/default/files/2025-05/news-education-2.jpeg" alt="Teacher with pupils at the laptop"&gt;

  


      
      
      
      Public sector
    
    &lt;h3 class="snip__title"&gt;Digital sovereignty in schools: A case study&lt;/h3&gt;
  &lt;a class="snip__arrow" href="https://mailbox.org/en/success-story/digital-sovereignty-in-schools/" aria-hidden="true"&gt;→&lt;/a&gt;
  &lt;a class="snip__link" href="https://mailbox.org/en/success-story/digital-sovereignty-in-schools/"&gt;Read more about &lt;em class="placeholder"&gt;Digital sovereignty in schools: A case study&lt;/em&gt;&lt;/a&gt;


    
  
  


</description>
  <guid isPermaLink="false">d37917bd-f637-42b5-9f9f-b33aaaba7961</guid>
    <pubDate>Tue, 08 Apr 2025 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>More email security in the education sector</dc:title>
    <dc:identifier>d37917bd-f637-42b5-9f9f-b33aaaba7961</dc:identifier>
    </item>
<item>
  <title>EU Tariffs &amp; ACI: A Tech Trade War?</title>
  <link>https://mailbox.org/en/news/eu-tariffs-and-aci-a-tech-trade-war/</link>
  <description>&lt;p&gt;From Liberation Day to Anti-Coercion Instrument (ACI)? The currently looming trade war between the USA and Europe could have devastating consequences for European businesses that rely on US technologies. Trump's imposition of 20% tariffs on EU imports on 2nd April 2025 has significantly intensified the trade conflict between the USA and the EU. This could be the beginning of an escalation that extends far beyond traditional traded goods. Is a tech trade war now threatening?&lt;/p&gt;&lt;h2&gt;From steel to silicon valley: How the ACI comes into play&lt;/h2&gt;&lt;p&gt;The tariffs imposed by Trump initially primarily affect physical goods such as cars, steel and aluminium. However, the conflict could quickly spread to the digital sector. The EU has already announced countermeasures worth €26 billion, but these could be just the beginning.&lt;br&gt;The EU is considering using the Anti-Coercion Instrument (ACI) against the USA as a "last resort". Specifically, the ACI could be used to make it more difficult for US tech companies to access the European public procurement market – a market worth around €2 trillion (approximately $2.2 trillion) annually. This would mean that American technology providers could be disadvantaged or even excluded from public tenders in the EU. In addition, fiscal and regulatory measures could be targeted specifically against digital platforms from the USA.&lt;/p&gt;


  &lt;h2 class="referent__title"&gt;&lt;/h2&gt;
  
                
        
                    
            
                          &lt;h3 class="referent__headline"&gt;
                Anti-Coercion Instrument (ACI)
                              &lt;/h3&gt;
            
            
                          &lt;p&gt;The ACI came into force in 2023 and provides the EU with a legal framework to respond to economic coercive measures from third countries. It encompasses a wide range of possible countermeasures such as tariffs, restrictions on trade in services, limitations on intellectual property rights and exclusion from public contracts, which could make it difficult for US tech companies to access the €2 trillion procurement market. These measures are designed to exert economic pressure to promote compliance with international obligations.&lt;/p&gt;
                        
        
      
      

              


  
    
    
    
    &lt;h2&gt;Threatened infrastructure: How European businesses could be affected&lt;/h2&gt;&lt;p&gt;For European businesses that rely on US technology services such as cloud solutions or email services, the consequences could be far-reaching. Initially, costs are likely to rise, as tech giants such as Apple, Google and Meta will probably pass additional regulatory burdens on to their customers. At the same time, uncertainties in the EU-US data privacy framework could lead to legal complications in data transfer – a problem that is particularly critical for data-intensive business models.&lt;/p&gt;&lt;p&gt;In extreme cases, access to important updates, security patches or technical support could even be restricted, which would bring considerable security risks. Last but not least, businesses face new compliance challenges, as they may need to comprehensively adapt their IT infrastructure to meet changed regulatory requirements.&lt;/p&gt;&lt;p&gt;Small and medium-sized enterprises in particular could be disproportionately affected, as they often lack the resources for costly and rapid IT changes.&lt;/p&gt;&lt;h2&gt;Danish pioneers: How European alternatives are already being used&lt;/h2&gt;&lt;p&gt;Those who want to act now can follow Denmark's example. In response to geopolitical tensions, Danish healthcare has already begun to convert its digital infrastructure. A strategically valuable decision to reduce dependence on US technologies.&lt;/p&gt;&lt;p&gt;This development is in line with the EU's long-term aspirations for greater digital sovereignty. The EuroStack initiative, which is supported by over 100 EU organisations and is driving the development of a European cloud stack infrastructure, shows the growing awareness of the need for technological independence. What is already happening in Denmark could soon become standard practice for businesses across the EU – not just as a response to acute geopolitical tensions, but as a long-term strategy for minimising risk.&lt;/p&gt;&lt;h2&gt;Strategic steps for European businesses&lt;/h2&gt;&lt;p&gt;To avoid being surprised by "Day Zero" – the moment when US technology services suddenly disappear – European businesses should act now:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Conduct a risk assessment: Analyse your dependence on US technology providers and identify critical areas.&lt;/li&gt;&lt;li&gt;Evaluate European alternatives: Examine available European options for your IT infrastructure and start with pilot projects.&lt;/li&gt;&lt;li&gt;Review data management: Rethink your data storage and processing strategies with a view to possible restrictions on transatlantic data traffic.&lt;/li&gt;&lt;li&gt;Develop contingency plans: Create strategies in case US services suddenly become more expensive or restricted.&lt;/li&gt;&lt;li&gt;Invest in digital sovereignty: Support EU initiatives and European technology development as a long-term strategy.&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Outlook: Between escalation and cooperation&lt;/h2&gt;&lt;p&gt;While the situation remains dynamic and negotiations could still bring about de-escalation, much points to a longer-term trend towards greater technological autonomy in Europe. The Anti-Coercion Instrument represents a powerful tool with which the EU can defend its economic interests. For European businesses, the current situation offers both risks and opportunities: those who opt for European alternatives early on could not only minimise risks, but also benefit from a growing market for European technology solutions.&lt;/p&gt;

          
                                                  
      
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-07/Blog-Handelskrieg-042025.jpeg?itok=IvDaB4U1" type="image/jpeg" length="306377"/><guid isPermaLink="false">1245b683-a68b-454d-a05a-adf56b41482e</guid>
    <pubDate>Fri, 04 Apr 2025 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>EU Tariffs &amp; ACI: A Tech Trade War?</dc:title>
    <dc:identifier>1245b683-a68b-454d-a05a-adf56b41482e</dc:identifier>
    </item>
<item>
  <title>EU Tariffs &amp; ACI: A Tech Trade War?</title>
  <link>https://mailbox.org/en/news/eu-tariffs-and-aci-a-tech-trade-war/</link>
  <description>&lt;p&gt;From Liberation Day to Anti-Coercion Instrument (ACI)? The currently looming trade war between the USA and Europe could have devastating consequences for European businesses that rely on US technologies. Trump's imposition of 20% tariffs on EU imports on 2nd April 2025 has significantly intensified the trade conflict between the USA and the EU. This could be the beginning of an escalation that extends far beyond traditional traded goods. Is a tech trade war now threatening?&lt;/p&gt;&lt;h2&gt;From steel to silicon valley: How the ACI comes into play&lt;/h2&gt;&lt;p&gt;The tariffs imposed by Trump initially primarily affect physical goods such as cars, steel and aluminium. However, the conflict could quickly spread to the digital sector. The EU has already announced countermeasures worth €26 billion, but these could be just the beginning.&lt;br&gt;The EU is considering using the Anti-Coercion Instrument (ACI) against the USA as a "last resort". Specifically, the ACI could be used to make it more difficult for US tech companies to access the European public procurement market – a market worth around €2 trillion (approximately $2.2 trillion) annually. This would mean that American technology providers could be disadvantaged or even excluded from public tenders in the EU. In addition, fiscal and regulatory measures could be targeted specifically against digital platforms from the USA.&lt;/p&gt;


  &lt;h2 class="referent__title"&gt;&lt;/h2&gt;
  
                
        
                    
            
                          &lt;h3 class="referent__headline"&gt;
                Anti-Coercion Instrument (ACI)
                              &lt;/h3&gt;
            
            
                          &lt;p&gt;The ACI came into force in 2023 and provides the EU with a legal framework to respond to economic coercive measures from third countries. It encompasses a wide range of possible countermeasures such as tariffs, restrictions on trade in services, limitations on intellectual property rights and exclusion from public contracts, which could make it difficult for US tech companies to access the €2 trillion procurement market. These measures are designed to exert economic pressure to promote compliance with international obligations.&lt;/p&gt;
                        
        
      
      

              


  
    
    
    
    &lt;h2&gt;Threatened infrastructure: How European businesses could be affected&lt;/h2&gt;&lt;p&gt;For European businesses that rely on US technology services such as cloud solutions or email services, the consequences could be far-reaching. Initially, costs are likely to rise, as tech giants such as Apple, Google and Meta will probably pass additional regulatory burdens on to their customers. At the same time, uncertainties in the EU-US data privacy framework could lead to legal complications in data transfer – a problem that is particularly critical for data-intensive business models.&lt;/p&gt;&lt;p&gt;In extreme cases, access to important updates, security patches or technical support could even be restricted, which would bring considerable security risks. Last but not least, businesses face new compliance challenges, as they may need to comprehensively adapt their IT infrastructure to meet changed regulatory requirements.&lt;/p&gt;&lt;p&gt;Small and medium-sized enterprises in particular could be disproportionately affected, as they often lack the resources for costly and rapid IT changes.&lt;/p&gt;&lt;h2&gt;Danish pioneers: How European alternatives are already being used&lt;/h2&gt;&lt;p&gt;Those who want to act now can follow Denmark's example. In response to geopolitical tensions, Danish healthcare has already begun to convert its digital infrastructure. A strategically valuable decision to reduce dependence on US technologies.&lt;/p&gt;&lt;p&gt;This development is in line with the EU's long-term aspirations for greater digital sovereignty. The EuroStack initiative, which is supported by over 100 EU organisations and is driving the development of a European cloud stack infrastructure, shows the growing awareness of the need for technological independence. What is already happening in Denmark could soon become standard practice for businesses across the EU – not just as a response to acute geopolitical tensions, but as a long-term strategy for minimising risk.&lt;/p&gt;&lt;h2&gt;Strategic steps for European businesses&lt;/h2&gt;&lt;p&gt;To avoid being surprised by "Day Zero" – the moment when US technology services suddenly disappear – European businesses should act now:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Conduct a risk assessment: Analyse your dependence on US technology providers and identify critical areas.&lt;/li&gt;&lt;li&gt;Evaluate European alternatives: Examine available European options for your IT infrastructure and start with pilot projects.&lt;/li&gt;&lt;li&gt;Review data management: Rethink your data storage and processing strategies with a view to possible restrictions on transatlantic data traffic.&lt;/li&gt;&lt;li&gt;Develop contingency plans: Create strategies in case US services suddenly become more expensive or restricted.&lt;/li&gt;&lt;li&gt;Invest in digital sovereignty: Support EU initiatives and European technology development as a long-term strategy.&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Outlook: Between escalation and cooperation&lt;/h2&gt;&lt;p&gt;While the situation remains dynamic and negotiations could still bring about de-escalation, much points to a longer-term trend towards greater technological autonomy in Europe. The Anti-Coercion Instrument represents a powerful tool with which the EU can defend its economic interests. For European businesses, the current situation offers both risks and opportunities: those who opt for European alternatives early on could not only minimise risks, but also benefit from a growing market for European technology solutions.&lt;/p&gt;

          
                                                  
      
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-07/Blog-Handelskrieg-042025.jpeg?itok=IvDaB4U1" type="image/jpeg" length="306377"/><guid isPermaLink="false">1245b683-a68b-454d-a05a-adf56b41482e</guid>
    <pubDate>Fri, 04 Apr 2025 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>EU Tariffs &amp; ACI: A Tech Trade War?</dc:title>
    <dc:identifier>1245b683-a68b-454d-a05a-adf56b41482e</dc:identifier>
    </item>
<item>
  <title>End of Support: Microsoft Exchange 2016/2019 - What Now?</title>
  <link>https://mailbox.org/en/news/end-of-support-for-microsoft-exchange-server-2016-and-2019/</link>
  <description>&lt;p&gt;What do the end of support for Microsoft Exchange Server 2016 and 2019 and the Hafnium hack of 2021 have in common? Both dramatically demonstrate how crucial security updates are for business communications. When the hacker group known as "Hafnium" exploited critical security vulnerabilities in Exchange servers in March 2021, IT departments worldwide went on high alert. The attackers were able to read e-mails, install malware, and establish themselves in their victims' networks. Even the German Federal Office for Information Security (BSI) raised the alarm: more than 20,000 servers in Germany alone were affected. The only salvation: an emergency security update provided by Microsoft.&lt;/p&gt;&lt;p&gt;This dramatic episode illustrates the vital importance of regular updates for business-critical systems. Yet these essential updates will soon be discontinued for many businesses.&lt;/p&gt;&lt;h2&gt;Microsoft pushing for cloud migration&lt;/h2&gt;&lt;p&gt;On 14th October 2025, Microsoft will end support for Exchange Server 2016 and 2019. This means the end of security updates, bug fixes, and technical support for these widely used e-mail server solutions, which will result in e-mail blocking for numerous businesses. This development is part of Microsoft's long-term strategy to move customers to the cloud. For many businesses, this means a critical decision between various migration options – and potentially even against their data sovereignty.&lt;/p&gt;&lt;h2&gt;Why businesses still rely on Microsoft Exchange 2016/2019&lt;/h2&gt;&lt;p&gt;Microsoft Exchange Server is an on-premises solution for e-mail, calendar, and collaboration that serves as a central communication platform in businesses and is independent of the cloud. Versions 2016 and 2019 follow Microsoft's "Fixed Lifecycle Policy", with a support period of 10 years, comprising 5 years of mainstream support and 5 years of extended support.&lt;/p&gt;&lt;p&gt;Despite the trend towards cloud solutions, numerous businesses still use the on-premises versions. The reasons for this are diverse: data sovereignty and compliance play a central role, particularly in regions with strict data protection laws such as the EU, where businesses are legally obliged to ensure complete control over their data. From an economic perspective, maintaining existing on-premises systems can be more cost-effective than migrating to subscription-based cloud services, especially when investments have already been made in hardware running the service.&lt;/p&gt;&lt;h2&gt;E-mail blocking and other critical consequences&lt;/h2&gt;&lt;p&gt;With the end of support for Exchange Server 2016 and 2019, businesses face several challenges: Particularly critical is the announced e-mail blocking by Exchange Online. After the deadline, Microsoft will block e-mails from unsupported Exchange versions. This means that affected businesses will no longer be able to send e-mails to partners using newer Exchange Online services – regardless of their own server configuration. The communication capability of many businesses is thus fundamentally at risk.&lt;/p&gt;&lt;p&gt;At the same time, security risks increase due to missing updates, making Exchange servers attractive targets for attacks. On the other hand, migration to the Microsoft Cloud creates significant GDPR compliance risks: business data stored on Microsoft servers is subject to the US CLOUD Act. This directly conflicts with European data protection requirements and could also be overturned by the European Court of Justice in the near future.&lt;/p&gt;&lt;h2&gt;Three paths, one sovereign choice&lt;/h2&gt;&lt;p&gt;Businesses essentially have three options to respond to the end of support:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Migration to Exchange Online (Microsoft 365): Offers continuous updates and integration with other Microsoft 365 services, but comes with limited control over data.&lt;/li&gt;&lt;li&gt;Upgrade to Exchange Server Subscription Edition (SE): Available from Q3 2025, allows maintaining the on-premises infrastructure with relatively simple upgrades for Exchange 2019 users, but may lead to vendor lock-in.&lt;/li&gt;&lt;li&gt;Switch to a data sovereign alternative such as mailbox.org: Ensures complete data sovereignty and GDPR compliance without dependence on the Microsoft ecosystem, with free migration of existing data and complete independence in the choice of IT solutions.&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Why choose an independent e-mail provider?&lt;/h2&gt;&lt;p&gt;In times of growing concerns regarding data protection and digital sovereignty, independent e-mail providers like mailbox.org offer decisive advantages over remaining in the Microsoft ecosystem.&lt;/p&gt;&lt;p&gt;Unlike Microsoft Exchange Online, where data can be stored in global data centres, mailbox.org guarantees data storage in Germany under the strict data protection standards of the EU and German law – a crucial advantage for businesses with sensitive information or special compliance requirements. While Microsoft, as a US company, is subject to the CLOUD Act, which can allow US authorities access to data, mailbox.org exclusively follows European data protection standards with encryption of data as a central element of its business model.&lt;/p&gt;&lt;h2&gt;Looming vendor lock-in: The alternative&lt;/h2&gt;&lt;p&gt;The transition to Microsoft Exchange Online or the new Exchange Server Subscription Edition (SE) leads to increasing dependence on the Microsoft platform. With the progressive integration of all Microsoft services, it becomes increasingly difficult for businesses to replace individual components or to flexibly design their IT infrastructure – a classic vendor lock-in threatens.&lt;/p&gt;&lt;p&gt;A switch to mailbox.org, on the other hand, offers genuine independence in the choice of IT solutions. The open standards and interfaces allow connection to or switching to other systems at any time. Business customers also receive personal and competent support that caters to their individual needs and assists with the free migration.&lt;/p&gt;&lt;h2&gt;Conclusion and outlook&lt;/h2&gt;&lt;p&gt;The end of support for Exchange Server 2016 and 2019 marks a turning point in business communication and represents a strategic moment for IT decisions. While Microsoft is forcing cloud migration, a window of opportunity for fundamental reorientations is simultaneously opening. The future should increasingly belong to decentralised, data sovereign IT solutions that guarantee both security and independence.&lt;/p&gt;&lt;p&gt;Businesses that now rely on platforms like mailbox.org are positioning themselves not only for short-term security against the looming e-mail blockade but also for the long term in a world where data protection and digital self-determination are becoming increasingly important.&lt;/p&gt;&lt;h2&gt;About Microsoft Exchange&lt;/h2&gt;&lt;p&gt;Microsoft Exchange has been the backbone of business communication worldwide since the 1990s. As a central platform for e-mail, calendar, and collaboration, it enables the management of communication across various devices. Microsoft Exchange Server is the classic, locally (on-premises) installed software that is operated in one's own IT infrastructure. Businesses that use Exchange Server manage the hardware, updates, and security themselves.&lt;/p&gt;&lt;p&gt;Microsoft's strategy has fundamentally changed: the focus today is on the cloud-based Exchange Online version as part of Microsoft 365 and a subscription business model. The Exchange Server Subscription Edition, releasing in 2025, serves as an intermediate step for businesses that do not yet want to fully switch to the cloud. This development is part of a larger trend at Microsoft to offer all services as Software-as-a-Service – a challenge for businesses with special requirements for data sovereignty.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-07/Blog-Support-Ende-Microsoft-042025.jpeg?itok=iz58ndZG" type="image/jpeg" length="376363"/><guid isPermaLink="false">7dc8f922-779f-4934-8a65-411368b0e163</guid>
    <pubDate>Tue, 01 Apr 2025 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>End of Support: Microsoft Exchange 2016/2019 - What Now?</dc:title>
    <dc:identifier>7dc8f922-779f-4934-8a65-411368b0e163</dc:identifier>
    </item>
<item>
  <title>End of Support: Microsoft Exchange 2016/2019 - What Now?</title>
  <link>https://mailbox.org/en/news/end-of-support-for-microsoft-exchange-server-2016-and-2019/</link>
  <description>&lt;p&gt;What do the end of support for Microsoft Exchange Server 2016 and 2019 and the Hafnium hack of 2021 have in common? Both dramatically demonstrate how crucial security updates are for business communications. When the hacker group known as "Hafnium" exploited critical security vulnerabilities in Exchange servers in March 2021, IT departments worldwide went on high alert. The attackers were able to read e-mails, install malware, and establish themselves in their victims' networks. Even the German Federal Office for Information Security (BSI) raised the alarm: more than 20,000 servers in Germany alone were affected. The only salvation: an emergency security update provided by Microsoft.&lt;/p&gt;&lt;p&gt;This dramatic episode illustrates the vital importance of regular updates for business-critical systems. Yet these essential updates will soon be discontinued for many businesses.&lt;/p&gt;&lt;h2&gt;Microsoft pushing for cloud migration&lt;/h2&gt;&lt;p&gt;On 14th October 2025, Microsoft will end support for Exchange Server 2016 and 2019. This means the end of security updates, bug fixes, and technical support for these widely used e-mail server solutions, which will result in e-mail blocking for numerous businesses. This development is part of Microsoft's long-term strategy to move customers to the cloud. For many businesses, this means a critical decision between various migration options – and potentially even against their data sovereignty.&lt;/p&gt;&lt;h2&gt;Why businesses still rely on Microsoft Exchange 2016/2019&lt;/h2&gt;&lt;p&gt;Microsoft Exchange Server is an on-premises solution for e-mail, calendar, and collaboration that serves as a central communication platform in businesses and is independent of the cloud. Versions 2016 and 2019 follow Microsoft's "Fixed Lifecycle Policy", with a support period of 10 years, comprising 5 years of mainstream support and 5 years of extended support.&lt;/p&gt;&lt;p&gt;Despite the trend towards cloud solutions, numerous businesses still use the on-premises versions. The reasons for this are diverse: data sovereignty and compliance play a central role, particularly in regions with strict data protection laws such as the EU, where businesses are legally obliged to ensure complete control over their data. From an economic perspective, maintaining existing on-premises systems can be more cost-effective than migrating to subscription-based cloud services, especially when investments have already been made in hardware running the service.&lt;/p&gt;&lt;h2&gt;E-mail blocking and other critical consequences&lt;/h2&gt;&lt;p&gt;With the end of support for Exchange Server 2016 and 2019, businesses face several challenges: Particularly critical is the announced e-mail blocking by Exchange Online. After the deadline, Microsoft will block e-mails from unsupported Exchange versions. This means that affected businesses will no longer be able to send e-mails to partners using newer Exchange Online services – regardless of their own server configuration. The communication capability of many businesses is thus fundamentally at risk.&lt;/p&gt;&lt;p&gt;At the same time, security risks increase due to missing updates, making Exchange servers attractive targets for attacks. On the other hand, migration to the Microsoft Cloud creates significant GDPR compliance risks: business data stored on Microsoft servers is subject to the US CLOUD Act. This directly conflicts with European data protection requirements and could also be overturned by the European Court of Justice in the near future.&lt;/p&gt;&lt;h2&gt;Three paths, one sovereign choice&lt;/h2&gt;&lt;p&gt;Businesses essentially have three options to respond to the end of support:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Migration to Exchange Online (Microsoft 365): Offers continuous updates and integration with other Microsoft 365 services, but comes with limited control over data.&lt;/li&gt;&lt;li&gt;Upgrade to Exchange Server Subscription Edition (SE): Available from Q3 2025, allows maintaining the on-premises infrastructure with relatively simple upgrades for Exchange 2019 users, but may lead to vendor lock-in.&lt;/li&gt;&lt;li&gt;Switch to a data sovereign alternative such as mailbox.org: Ensures complete data sovereignty and GDPR compliance without dependence on the Microsoft ecosystem, with free migration of existing data and complete independence in the choice of IT solutions.&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Why choose an independent e-mail provider?&lt;/h2&gt;&lt;p&gt;In times of growing concerns regarding data protection and digital sovereignty, independent e-mail providers like mailbox.org offer decisive advantages over remaining in the Microsoft ecosystem.&lt;/p&gt;&lt;p&gt;Unlike Microsoft Exchange Online, where data can be stored in global data centres, mailbox.org guarantees data storage in Germany under the strict data protection standards of the EU and German law – a crucial advantage for businesses with sensitive information or special compliance requirements. While Microsoft, as a US company, is subject to the CLOUD Act, which can allow US authorities access to data, mailbox.org exclusively follows European data protection standards with encryption of data as a central element of its business model.&lt;/p&gt;&lt;h2&gt;Looming vendor lock-in: The alternative&lt;/h2&gt;&lt;p&gt;The transition to Microsoft Exchange Online or the new Exchange Server Subscription Edition (SE) leads to increasing dependence on the Microsoft platform. With the progressive integration of all Microsoft services, it becomes increasingly difficult for businesses to replace individual components or to flexibly design their IT infrastructure – a classic vendor lock-in threatens.&lt;/p&gt;&lt;p&gt;A switch to mailbox.org, on the other hand, offers genuine independence in the choice of IT solutions. The open standards and interfaces allow connection to or switching to other systems at any time. Business customers also receive personal and competent support that caters to their individual needs and assists with the free migration.&lt;/p&gt;&lt;h2&gt;Conclusion and outlook&lt;/h2&gt;&lt;p&gt;The end of support for Exchange Server 2016 and 2019 marks a turning point in business communication and represents a strategic moment for IT decisions. While Microsoft is forcing cloud migration, a window of opportunity for fundamental reorientations is simultaneously opening. The future should increasingly belong to decentralised, data sovereign IT solutions that guarantee both security and independence.&lt;/p&gt;&lt;p&gt;Businesses that now rely on platforms like mailbox.org are positioning themselves not only for short-term security against the looming e-mail blockade but also for the long term in a world where data protection and digital self-determination are becoming increasingly important.&lt;/p&gt;&lt;h2&gt;About Microsoft Exchange&lt;/h2&gt;&lt;p&gt;Microsoft Exchange has been the backbone of business communication worldwide since the 1990s. As a central platform for e-mail, calendar, and collaboration, it enables the management of communication across various devices. Microsoft Exchange Server is the classic, locally (on-premises) installed software that is operated in one's own IT infrastructure. Businesses that use Exchange Server manage the hardware, updates, and security themselves.&lt;/p&gt;&lt;p&gt;Microsoft's strategy has fundamentally changed: the focus today is on the cloud-based Exchange Online version as part of Microsoft 365 and a subscription business model. The Exchange Server Subscription Edition, releasing in 2025, serves as an intermediate step for businesses that do not yet want to fully switch to the cloud. This development is part of a larger trend at Microsoft to offer all services as Software-as-a-Service – a challenge for businesses with special requirements for data sovereignty.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-07/Blog-Support-Ende-Microsoft-042025.jpeg?itok=iz58ndZG" type="image/jpeg" length="376363"/><guid isPermaLink="false">7dc8f922-779f-4934-8a65-411368b0e163</guid>
    <pubDate>Tue, 01 Apr 2025 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>End of Support: Microsoft Exchange 2016/2019 - What Now?</dc:title>
    <dc:identifier>7dc8f922-779f-4934-8a65-411368b0e163</dc:identifier>
    </item>
<item>
  <title>Host Europe E-mail migration: Loss of data sovereignty</title>
  <link>https://mailbox.org/en/news/host-europe-e-mail-migration/</link>
  <description>&lt;p&gt;Host Europe, one of Germany's largest hosting providers, is migrating all e-mail accounts to Microsoft 365 from May 2025. What initially appears to be a purely technical change reveals itself upon closer inspection as a significant risk to digital sovereignty and data protection – with the potential consequence of vendor lock-in. This problem illustrates a fundamental European dilemma: the continuing dependence on US technology corporations.&lt;/p&gt;&lt;h2&gt;Legal risks in detail&lt;/h2&gt;&lt;p&gt;The migration can have serious data protection implications – particularly for businesses. Host Europe had originally advertised secure data storage in Germany and compliance with German data protection standards. However, this promise was already compromised in 2017 when they were acquired by the US corporation GoDaddy.&lt;/p&gt;&lt;p&gt;With the now planned transition to Microsoft 365, the situation is worsening: companies that had deliberately chosen not to use US providers now face the risk of potential vendor lock-in – i.e., through the migration, they will be closely tied to the Microsoft ecosystem, from which a later exit would only be possible with considerable effort and high costs.&lt;/p&gt;&lt;h2&gt;US CLOUD act versus GDPR – an irresolvable contradiction&lt;/h2&gt;&lt;p&gt;Particularly critical: As a US company, Microsoft is subject to the CLOUD Act, which grants US authorities extensive access rights to stored data – regardless of where the servers are physically located. This stands in direct contradiction to the European General Data Protection Regulation (GDPR).&lt;/p&gt;&lt;p&gt;The currently valid Trans-Atlantic Data Privacy Framework (TADPF) was intended to mitigate this contradiction, but it stands on legally uncertain ground – not least due to political developments in the US. Experts currently assume that this agreement – like its predecessors "Safe Harbor" and "Privacy Shield" – could fail before the European Court of Justice.&lt;/p&gt;&lt;p&gt;If the TADPF is overturned, companies will lack the legal basis for using Microsoft 365 – with potentially high fines as a consequence. This turns technological dependence into a substantial compliance risk.&lt;/p&gt;&lt;h2&gt;European service providers as secure alternatives&lt;/h2&gt;&lt;p&gt;Those who wish to avoid data protection risks and escape vendor lock-in should act now and turn their backs on both Host Europe and Microsoft 365. Numerous European providers offer comparable solutions with full GDPR compliance.&lt;br&gt;One example is the German service provider mailbox.org, which offers a comprehensive solution with e-mail, calendar, contacts, office applications, video conferencing, and cloud storage. Unlike Microsoft, all data is stored exclusively in German data centres – and is therefore not subject to the US CLOUD Act.&lt;/p&gt;&lt;h2&gt;Switching to mailbox.org: Simple, quick, and secure&lt;/h2&gt;&lt;p&gt;Moving from Host Europe to mailbox.org is straightforward and can be accomplished without data loss. mailbox.org offers a free e-mail migration service that can complete the transition in just a few hours, depending on the data volume. During the migration, both systems can be used in parallel, and existing domains remain intact.&lt;/p&gt;&lt;h3&gt;The switch in six steps:&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="https://mailbox.org/en/business-customers#prices-and-contact" target="_blank" rel="noopener"&gt;Register&lt;/a&gt; with mailbox.org and select the appropriate tariff&lt;/li&gt;&lt;li&gt;Set up your own domain&lt;/li&gt;&lt;li&gt;Start the free migration via the relocation service&lt;/li&gt;&lt;li&gt;Verify the migrated data&lt;/li&gt;&lt;li&gt;Change the DNS entries to mailbox.org&lt;/li&gt;&lt;li&gt;Cancel the old Host Europe account&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;For private users too: Data security instead of data collection&lt;/h2&gt;&lt;p&gt;Private users are also affected by the Host Europe migration and should reconsider their digital sovereignty. &lt;a href="https://register.mailbox.org/en" target="_blank" rel="noopener"&gt;Switching to mailbox.org&lt;/a&gt; brings decisive advantages: no data analysis for advertising purposes, complete encryption, and data processing according to the strictest German data protection law.&lt;/p&gt;&lt;h2&gt;Conclusion: Reclaiming digital sovereignty&lt;/h2&gt;&lt;p&gt;The migration from Host Europe to Microsoft 365 symbolises the strong dominance of US technology corporations. It carries significant legal risks – and weakens digital self-determination in Europe.&lt;/p&gt;&lt;p&gt;With mailbox.org, a reliable and data protection-compliant alternative is available – developed for the needs of European users. Those who act now not only strengthen their own security but also make an important contribution to the independence and resilience of European digital infrastructure.&lt;/p&gt;&lt;h2&gt;About Host Europe&lt;/h2&gt;&lt;p&gt;Host Europe was founded in 1997 and developed into one of the leading hosting providers in Germany. The company originally advertised "Hosting made in Germany" and secure data storage according to German standards. In 2017, Host Europe was acquired by the US company GoDaddy, one of the world's largest domain registrars. The now announced migration to Microsoft 365 effectively marks the end of the promise of purely German data storage.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-07/Blog-Host-Europe-032025.jpeg?itok=BGxTmmap" type="image/jpeg" length="407327"/><guid isPermaLink="false">da35e88b-5428-4dec-b86b-fafa2eea2c0c</guid>
    <pubDate>Wed, 26 Mar 2025 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Host Europe E-mail migration: Loss of data sovereignty</dc:title>
    <dc:identifier>da35e88b-5428-4dec-b86b-fafa2eea2c0c</dc:identifier>
    </item>
<item>
  <title>Host Europe E-mail migration: Loss of data sovereignty</title>
  <link>https://mailbox.org/en/news/host-europe-e-mail-migration/</link>
  <description>&lt;p&gt;Host Europe, one of Germany's largest hosting providers, is migrating all e-mail accounts to Microsoft 365 from May 2025. What initially appears to be a purely technical change reveals itself upon closer inspection as a significant risk to digital sovereignty and data protection – with the potential consequence of vendor lock-in. This problem illustrates a fundamental European dilemma: the continuing dependence on US technology corporations.&lt;/p&gt;&lt;h2&gt;Legal risks in detail&lt;/h2&gt;&lt;p&gt;The migration can have serious data protection implications – particularly for businesses. Host Europe had originally advertised secure data storage in Germany and compliance with German data protection standards. However, this promise was already compromised in 2017 when they were acquired by the US corporation GoDaddy.&lt;/p&gt;&lt;p&gt;With the now planned transition to Microsoft 365, the situation is worsening: companies that had deliberately chosen not to use US providers now face the risk of potential vendor lock-in – i.e., through the migration, they will be closely tied to the Microsoft ecosystem, from which a later exit would only be possible with considerable effort and high costs.&lt;/p&gt;&lt;h2&gt;US CLOUD act versus GDPR – an irresolvable contradiction&lt;/h2&gt;&lt;p&gt;Particularly critical: As a US company, Microsoft is subject to the CLOUD Act, which grants US authorities extensive access rights to stored data – regardless of where the servers are physically located. This stands in direct contradiction to the European General Data Protection Regulation (GDPR).&lt;/p&gt;&lt;p&gt;The currently valid Trans-Atlantic Data Privacy Framework (TADPF) was intended to mitigate this contradiction, but it stands on legally uncertain ground – not least due to political developments in the US. Experts currently assume that this agreement – like its predecessors "Safe Harbor" and "Privacy Shield" – could fail before the European Court of Justice.&lt;/p&gt;&lt;p&gt;If the TADPF is overturned, companies will lack the legal basis for using Microsoft 365 – with potentially high fines as a consequence. This turns technological dependence into a substantial compliance risk.&lt;/p&gt;&lt;h2&gt;European service providers as secure alternatives&lt;/h2&gt;&lt;p&gt;Those who wish to avoid data protection risks and escape vendor lock-in should act now and turn their backs on both Host Europe and Microsoft 365. Numerous European providers offer comparable solutions with full GDPR compliance.&lt;br&gt;One example is the German service provider mailbox.org, which offers a comprehensive solution with e-mail, calendar, contacts, office applications, video conferencing, and cloud storage. Unlike Microsoft, all data is stored exclusively in German data centres – and is therefore not subject to the US CLOUD Act.&lt;/p&gt;&lt;h2&gt;Switching to mailbox.org: Simple, quick, and secure&lt;/h2&gt;&lt;p&gt;Moving from Host Europe to mailbox.org is straightforward and can be accomplished without data loss. mailbox.org offers a free e-mail migration service that can complete the transition in just a few hours, depending on the data volume. During the migration, both systems can be used in parallel, and existing domains remain intact.&lt;/p&gt;&lt;h3&gt;The switch in six steps:&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="https://mailbox.org/en/business-customers#prices-and-contact" target="_blank" rel="noopener"&gt;Register&lt;/a&gt; with mailbox.org and select the appropriate tariff&lt;/li&gt;&lt;li&gt;Set up your own domain&lt;/li&gt;&lt;li&gt;Start the free migration via the relocation service&lt;/li&gt;&lt;li&gt;Verify the migrated data&lt;/li&gt;&lt;li&gt;Change the DNS entries to mailbox.org&lt;/li&gt;&lt;li&gt;Cancel the old Host Europe account&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;For private users too: Data security instead of data collection&lt;/h2&gt;&lt;p&gt;Private users are also affected by the Host Europe migration and should reconsider their digital sovereignty. &lt;a href="https://register.mailbox.org/en" target="_blank" rel="noopener"&gt;Switching to mailbox.org&lt;/a&gt; brings decisive advantages: no data analysis for advertising purposes, complete encryption, and data processing according to the strictest German data protection law.&lt;/p&gt;&lt;h2&gt;Conclusion: Reclaiming digital sovereignty&lt;/h2&gt;&lt;p&gt;The migration from Host Europe to Microsoft 365 symbolises the strong dominance of US technology corporations. It carries significant legal risks – and weakens digital self-determination in Europe.&lt;/p&gt;&lt;p&gt;With mailbox.org, a reliable and data protection-compliant alternative is available – developed for the needs of European users. Those who act now not only strengthen their own security but also make an important contribution to the independence and resilience of European digital infrastructure.&lt;/p&gt;&lt;h2&gt;About Host Europe&lt;/h2&gt;&lt;p&gt;Host Europe was founded in 1997 and developed into one of the leading hosting providers in Germany. The company originally advertised "Hosting made in Germany" and secure data storage according to German standards. In 2017, Host Europe was acquired by the US company GoDaddy, one of the world's largest domain registrars. The now announced migration to Microsoft 365 effectively marks the end of the promise of purely German data storage.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-07/Blog-Host-Europe-032025.jpeg?itok=BGxTmmap" type="image/jpeg" length="407327"/><guid isPermaLink="false">da35e88b-5428-4dec-b86b-fafa2eea2c0c</guid>
    <pubDate>Wed, 26 Mar 2025 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Host Europe E-mail migration: Loss of data sovereignty</dc:title>
    <dc:identifier>da35e88b-5428-4dec-b86b-fafa2eea2c0c</dc:identifier>
    </item>
<item>
  <title>CLOUD Act: European companies must act now</title>
  <link>https://mailbox.org/en/news/digital-sovereignty-in-uncertain-times/</link>
  <description>&lt;h2&gt;The new political realities and their impact on data protection&lt;/h2&gt;&lt;p&gt;The change of power in Washington in early 2025 marks a significant turning point for transatlantic data protection relations. The fundamental differences between US and European data protection law are thereby intensified, presenting European companies with new challenges. While the EU has established a comprehensive legal framework with the GDPR that enshrines the protection of personal data as a fundamental right, US data protection is based on a patchwork of sectoral regulations and corporate self-commitments.&lt;/p&gt;&lt;h3&gt;Political decisions with far-reaching consequences&lt;/h3&gt;&lt;p&gt;This discrepancy has become particularly evident through recent events: On 3rd February 2025, President Trump dismissed three Democratic members of the Privacy and Civil Liberties Oversight Board (PCLOB). This decision has direct implications for the Transatlantic Data Privacy Framework (TADPF), which governs legal data transfer between the EU and the US. The now inquorate supervisory body can no longer fulfil its central task – namely overseeing US intelligence agencies regarding their data protection practices.&lt;/p&gt;&lt;p&gt;Experts warn that this could be just the beginning of a series of measures endangering the entire TADPF. Executive orders, on which the framework is substantially based, could be revoked in the coming weeks. This would particularly affect companies and institutions that currently rely heavily on US cloud services.&lt;/p&gt;&lt;h3&gt;Cloud Act and TADPF: The fundamental legal conflict&lt;/h3&gt;&lt;p&gt;The legal core of the problem lies in the CLOUD Act (Clarifying Lawful Overseas Use of Data Act) passed in 2018. This US law enables American authorities and intelligence agencies to legally access data stored by US companies – regardless of where in the world this data is physically located. For European companies using services such as AWS, Microsoft 365, or Google Cloud, this specifically means: Even if data is stored in European data centres of American providers, US authorities can access it by invoking the CLOUD Act.&lt;/p&gt;&lt;p&gt;US companies are legally obliged to comply with this access, even if it violates European law. In many cases, the affected European companies may not even be informed about this access ("Gag Orders").&lt;/p&gt;&lt;h3&gt;TADPF is not legally binding&lt;/h3&gt;&lt;p&gt;This stands in direct contradiction to the GDPR, which demands a high standard of protection for personal data and sets strict requirements for international data transfers. European data protection legislation requires:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Transparency in data processing&lt;/li&gt;&lt;li&gt;Purpose limitation of collected data&lt;/li&gt;&lt;li&gt;Restriction of governmental access possibilities&lt;/li&gt;&lt;li&gt;Legal remedies for affected individuals&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;The TADPF was developed to defuse this legal collision by ensuring that US companies offer a level of data protection comparable to the EU. However, it is primarily based on executive orders rather than statutory regulations.&lt;/p&gt;


  &lt;h2 class="referent__title"&gt;&lt;/h2&gt;
  
                
        
                    
            
                          &lt;h3 class="referent__headline"&gt;
                Executive orders vs. laws
                              &lt;/h3&gt;
            
            
                          &lt;p&gt;This is a crucial weakness of the TADPF. While laws are passed by Congress and can only be changed through new legislation, executive orders are merely instructions from the President to federal agencies. A new President can revoke or alter these at any time – without Congressional approval. This makes the TADPF inherently unstable and vulnerable to political power shifts, as we are experiencing now.&lt;/p&gt;
                        
        
      
      

              


  
    
    
    
    &lt;h3&gt;The role of the PCLOB: Guardians without power&lt;/h3&gt;&lt;p&gt;The Privacy and Civil Liberties Oversight Board (PCLOB) is an independent agency within the US government that functions as a central pillar of the TADPF. Its main task is to monitor the activities of US intelligence agencies with regard to data protection and civil liberties. The board reviews whether surveillance measures comply with legal requirements and ensures that US authorities adhere to the data protection obligations stipulated in the TADPF. In case of violations, it can report and recommend corrective measures.&lt;/p&gt;&lt;p&gt;However, with the dismissal of three of the five members, the PCLOB is no longer quorate and cannot fulfil its supervisory function. This means that one of the most important guarantees that the TADPF offers to European citizens and companies – namely the independent control of US surveillance – effectively no longer exists. With the weakening of this control mechanism, the entire architecture of the framework is under scrutiny. Data protection activists like Max Schrems are already warning that US cloud services could soon be considered illegal in the EU – similar to the predecessor agreements Safe Harbor (2015) and Privacy Shield (2020) that were overturned by the European Court of Justice.&lt;/p&gt;&lt;h3&gt;Illegal overnight: Risks for European companies&lt;/h3&gt;&lt;p&gt;With an EU market heavily dependent on US tech giants, companies face significant challenges. The compliance risks are substantial – if the TADPF collapses, data transfers to the US could become illegal overnight, exposing companies to GDPR violations and potential fines. Simultaneously, there is a threat of significant operational disruptions, as forced migration from US services to European alternatives would entail high transition costs and business process disturbances. Furthermore, the continuing CLOUD Act potentially enables unauthorised access to sensitive company data, leading to a fundamental loss of data sovereignty. Last but not least, the political instability regarding US-EU data protection agreements creates ongoing planning uncertainty that significantly complicates long-term strategic decisions.&lt;/p&gt;&lt;h2&gt;European and Open-Source alternatives as a solution path&lt;/h2&gt;&lt;p&gt;European open-source solutions offer a safe way out of this dilemma. These providers operate entirely under European law and are not subject to the requirements of the US CLOUD Act.&lt;/p&gt;&lt;h3&gt;Advantages of European services:&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;GDPR compliance: Complete alignment with European data protection standards&lt;/li&gt;&lt;li&gt;Data sovereignty: Physical and legal control over data within the EU&lt;/li&gt;&lt;li&gt;Legal certainty: Reduced vulnerability to political changes in the US&lt;/li&gt;&lt;li&gt;Comprehensive security: Advanced encryption and international security certifications&lt;/li&gt;&lt;li&gt;Promotion of European technology: Support for Europe's digital sovereignty&lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;Additional benefits of open-source solutions:&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;Transparency: Open source code allows checking for backdoors or security vulnerabilities&lt;/li&gt;&lt;li&gt;Independence: Reduced dependence on individual providers and proprietary formats&lt;/li&gt;&lt;li&gt;Adaptability: Flexibility in implementing one's own security and data protection measures&lt;/li&gt;&lt;li&gt;Sustainability: Long-term availability and further development by the community&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;European providers ensure compliance with European data protection laws and ensure that company data remains securely within the EU – protected from the uncertainties of US legislation.&lt;/p&gt;&lt;h2&gt;The time to act is now&lt;/h2&gt;&lt;p&gt;With increasing uncertainty surrounding the TADPF, companies should act proactively now. A comprehensive risk assessment is the first step, evaluating the dependence on US cloud services and the associated legal and operational risks. Building on this, it is advisable to develop a gradual migration strategy, beginning with the most sensitive data and critical applications. Legal advice from data protection experts can help understand and implement the specific compliance requirements. When selecting European alternatives, companies should conduct a thorough assessment of the technical capabilities, security measures, and reliability of potential providers to ensure a smooth transition.&lt;/p&gt;&lt;h2&gt;Conclusion: Sovereignty as a strategic advantage&lt;/h2&gt;&lt;p&gt;Current developments show the vulnerability of European companies that rely on US cloud services. The switch to European and open-source providers is more than a compliance measure – it is a strategic step towards digital sovereignty.&lt;br&gt;By choosing European providers, companies can not only minimise legal risks but also strengthen the European digital infrastructure. In times of geopolitical tensions, control over one's own data becomes a decisive competitive advantage. Companies that act now are actively shaping a more secure and sovereign digital future.&lt;/p&gt;

          
                                                  
      
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-07/Blog-US-Cloud-Act.jpg?itok=qheqmGxx" type="image/jpeg" length="430976"/><guid isPermaLink="false">542790ef-5a89-41d1-b222-d886987cd6b4</guid>
    <pubDate>Wed, 19 Mar 2025 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>CLOUD Act: European companies must act now</dc:title>
    <dc:identifier>542790ef-5a89-41d1-b222-d886987cd6b4</dc:identifier>
    </item>
<item>
  <title>CLOUD Act: European companies must act now</title>
  <link>https://mailbox.org/en/news/digital-sovereignty-in-uncertain-times/</link>
  <description>&lt;h2&gt;The new political realities and their impact on data protection&lt;/h2&gt;&lt;p&gt;The change of power in Washington in early 2025 marks a significant turning point for transatlantic data protection relations. The fundamental differences between US and European data protection law are thereby intensified, presenting European companies with new challenges. While the EU has established a comprehensive legal framework with the GDPR that enshrines the protection of personal data as a fundamental right, US data protection is based on a patchwork of sectoral regulations and corporate self-commitments.&lt;/p&gt;&lt;h3&gt;Political decisions with far-reaching consequences&lt;/h3&gt;&lt;p&gt;This discrepancy has become particularly evident through recent events: On 3rd February 2025, President Trump dismissed three Democratic members of the Privacy and Civil Liberties Oversight Board (PCLOB). This decision has direct implications for the Transatlantic Data Privacy Framework (TADPF), which governs legal data transfer between the EU and the US. The now inquorate supervisory body can no longer fulfil its central task – namely overseeing US intelligence agencies regarding their data protection practices.&lt;/p&gt;&lt;p&gt;Experts warn that this could be just the beginning of a series of measures endangering the entire TADPF. Executive orders, on which the framework is substantially based, could be revoked in the coming weeks. This would particularly affect companies and institutions that currently rely heavily on US cloud services.&lt;/p&gt;&lt;h3&gt;Cloud Act and TADPF: The fundamental legal conflict&lt;/h3&gt;&lt;p&gt;The legal core of the problem lies in the CLOUD Act (Clarifying Lawful Overseas Use of Data Act) passed in 2018. This US law enables American authorities and intelligence agencies to legally access data stored by US companies – regardless of where in the world this data is physically located. For European companies using services such as AWS, Microsoft 365, or Google Cloud, this specifically means: Even if data is stored in European data centres of American providers, US authorities can access it by invoking the CLOUD Act.&lt;/p&gt;&lt;p&gt;US companies are legally obliged to comply with this access, even if it violates European law. In many cases, the affected European companies may not even be informed about this access ("Gag Orders").&lt;/p&gt;&lt;h3&gt;TADPF is not legally binding&lt;/h3&gt;&lt;p&gt;This stands in direct contradiction to the GDPR, which demands a high standard of protection for personal data and sets strict requirements for international data transfers. European data protection legislation requires:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Transparency in data processing&lt;/li&gt;&lt;li&gt;Purpose limitation of collected data&lt;/li&gt;&lt;li&gt;Restriction of governmental access possibilities&lt;/li&gt;&lt;li&gt;Legal remedies for affected individuals&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;The TADPF was developed to defuse this legal collision by ensuring that US companies offer a level of data protection comparable to the EU. However, it is primarily based on executive orders rather than statutory regulations.&lt;/p&gt;


  &lt;h2 class="referent__title"&gt;&lt;/h2&gt;
  
                
        
                    
            
                          &lt;h3 class="referent__headline"&gt;
                Executive orders vs. laws
                              &lt;/h3&gt;
            
            
                          &lt;p&gt;This is a crucial weakness of the TADPF. While laws are passed by Congress and can only be changed through new legislation, executive orders are merely instructions from the President to federal agencies. A new President can revoke or alter these at any time – without Congressional approval. This makes the TADPF inherently unstable and vulnerable to political power shifts, as we are experiencing now.&lt;/p&gt;
                        
        
      
      

              


  
    
    
    
    &lt;h3&gt;The role of the PCLOB: Guardians without power&lt;/h3&gt;&lt;p&gt;The Privacy and Civil Liberties Oversight Board (PCLOB) is an independent agency within the US government that functions as a central pillar of the TADPF. Its main task is to monitor the activities of US intelligence agencies with regard to data protection and civil liberties. The board reviews whether surveillance measures comply with legal requirements and ensures that US authorities adhere to the data protection obligations stipulated in the TADPF. In case of violations, it can report and recommend corrective measures.&lt;/p&gt;&lt;p&gt;However, with the dismissal of three of the five members, the PCLOB is no longer quorate and cannot fulfil its supervisory function. This means that one of the most important guarantees that the TADPF offers to European citizens and companies – namely the independent control of US surveillance – effectively no longer exists. With the weakening of this control mechanism, the entire architecture of the framework is under scrutiny. Data protection activists like Max Schrems are already warning that US cloud services could soon be considered illegal in the EU – similar to the predecessor agreements Safe Harbor (2015) and Privacy Shield (2020) that were overturned by the European Court of Justice.&lt;/p&gt;&lt;h3&gt;Illegal overnight: Risks for European companies&lt;/h3&gt;&lt;p&gt;With an EU market heavily dependent on US tech giants, companies face significant challenges. The compliance risks are substantial – if the TADPF collapses, data transfers to the US could become illegal overnight, exposing companies to GDPR violations and potential fines. Simultaneously, there is a threat of significant operational disruptions, as forced migration from US services to European alternatives would entail high transition costs and business process disturbances. Furthermore, the continuing CLOUD Act potentially enables unauthorised access to sensitive company data, leading to a fundamental loss of data sovereignty. Last but not least, the political instability regarding US-EU data protection agreements creates ongoing planning uncertainty that significantly complicates long-term strategic decisions.&lt;/p&gt;&lt;h2&gt;European and Open-Source alternatives as a solution path&lt;/h2&gt;&lt;p&gt;European open-source solutions offer a safe way out of this dilemma. These providers operate entirely under European law and are not subject to the requirements of the US CLOUD Act.&lt;/p&gt;&lt;h3&gt;Advantages of European services:&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;GDPR compliance: Complete alignment with European data protection standards&lt;/li&gt;&lt;li&gt;Data sovereignty: Physical and legal control over data within the EU&lt;/li&gt;&lt;li&gt;Legal certainty: Reduced vulnerability to political changes in the US&lt;/li&gt;&lt;li&gt;Comprehensive security: Advanced encryption and international security certifications&lt;/li&gt;&lt;li&gt;Promotion of European technology: Support for Europe's digital sovereignty&lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;Additional benefits of open-source solutions:&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;Transparency: Open source code allows checking for backdoors or security vulnerabilities&lt;/li&gt;&lt;li&gt;Independence: Reduced dependence on individual providers and proprietary formats&lt;/li&gt;&lt;li&gt;Adaptability: Flexibility in implementing one's own security and data protection measures&lt;/li&gt;&lt;li&gt;Sustainability: Long-term availability and further development by the community&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;European providers ensure compliance with European data protection laws and ensure that company data remains securely within the EU – protected from the uncertainties of US legislation.&lt;/p&gt;&lt;h2&gt;The time to act is now&lt;/h2&gt;&lt;p&gt;With increasing uncertainty surrounding the TADPF, companies should act proactively now. A comprehensive risk assessment is the first step, evaluating the dependence on US cloud services and the associated legal and operational risks. Building on this, it is advisable to develop a gradual migration strategy, beginning with the most sensitive data and critical applications. Legal advice from data protection experts can help understand and implement the specific compliance requirements. When selecting European alternatives, companies should conduct a thorough assessment of the technical capabilities, security measures, and reliability of potential providers to ensure a smooth transition.&lt;/p&gt;&lt;h2&gt;Conclusion: Sovereignty as a strategic advantage&lt;/h2&gt;&lt;p&gt;Current developments show the vulnerability of European companies that rely on US cloud services. The switch to European and open-source providers is more than a compliance measure – it is a strategic step towards digital sovereignty.&lt;br&gt;By choosing European providers, companies can not only minimise legal risks but also strengthen the European digital infrastructure. In times of geopolitical tensions, control over one's own data becomes a decisive competitive advantage. Companies that act now are actively shaping a more secure and sovereign digital future.&lt;/p&gt;

          
                                                  
      
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-07/Blog-US-Cloud-Act.jpg?itok=qheqmGxx" type="image/jpeg" length="430976"/><guid isPermaLink="false">542790ef-5a89-41d1-b222-d886987cd6b4</guid>
    <pubDate>Wed, 19 Mar 2025 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>CLOUD Act: European companies must act now</dc:title>
    <dc:identifier>542790ef-5a89-41d1-b222-d886987cd6b4</dc:identifier>
    </item>
<item>
  <title>Digital sovereignty in schools: A case study</title>
  <link>https://mailbox.org/en/success-story/digital-sovereignty-in-schools/</link>
  <description>&lt;p&gt;&lt;em&gt;Reading time: 6 minutes&lt;/em&gt;&lt;/p&gt;&lt;p&gt;Digital sovereignty and data protection in schools are no longer mere aspirations for the future. The case of Gymnasium and ORG Dachsberg in Austria demonstrates how transitioning to a GDPR-compliant IT infrastructure can successfully unite data protection with digital self-determination in education. Following their move away from Google, approximately 900 students and 100 teachers now communicate via mailbox.org services. A success story that could be a textbook example for others.&lt;/p&gt;


      
                  
              
              
              
              
              
              
              
                  &lt;img loading="lazy" height="3648" width="5472" src="https://mailbox.org/sites/default/files/2025-05/news-education-2.jpeg" alt="Teacher with pupils at the laptop"&gt;

  


  
          

              


  
    
    
    
    &lt;h3&gt;Protecting student data: A necessity&lt;/h3&gt;&lt;p&gt;Daily school operations involve the exchange of confidential information via email—from discussions about grades and medical reports to individual learning support requirements. This prompted Thomas Krupa, the school's IT administrator, to seek a solution that would ensure compliance with data protection regulations.&lt;/p&gt;&lt;p&gt;"We sought a communication tool that would maintain data privacy and prevent sensitive information from being handed over to large corporations that might exploit it for advertising and personal profiling," Krupa explains.&lt;/p&gt;

          
                                                  
      


  &lt;h2 class="referent__title"&gt;&lt;/h2&gt;
  
                
        
                      
                &lt;img loading="lazy" height width src="https://mailbox.org/sites/default/files/2025-05/gymnasium_dachsberg_freigestellt.svg" alt="Gymnasium Org Dachsberg Logo"&gt;


            
                    
            
                          &lt;h3 class="referent__headline"&gt;
                Thomas Krupa, IT administrator Gymnasium Dachsberg
                              &lt;/h3&gt;
            
            
                          &lt;p class="huge"&gt;“Unlike big tech giants, mailbox.org does not engage in surveillance capitalism. This considerably reduces students' digital footprint."&lt;/p&gt;
                        
        
      
      

              


  
    
    
    
    &lt;h3&gt;Technical expertise meets data protection&lt;/h3&gt;&lt;p&gt;When searching for a suitable alternative, mailbox.org distinguished itself for several reasons. The provider's technical expertise, positive user testimonials, and its status as a GDPR-compliant, German-based service ultimately proved decisive. Key technical considerations included the ability to retain existing email addresses, API-supported migration, and a flexible webmail interface with IMAP support.&lt;/p&gt;&lt;p&gt;“Unlike big tech giants, mailbox.org does not engage in surveillance capitalism. This considerably reduces students' digital footprint," says Krupa, emphasising that this philosophy was the determining factor behind the school's transition—a tailored solution for educational institutions with stringent data protection requirements.&lt;/p&gt;&lt;h3&gt;Gaining acceptance: Training as a success factor&lt;/h3&gt;&lt;p&gt;Although Krupa was swiftly convinced of mailbox.org's advantages, he initially faced the task of winning over the school community. "There wasn't full awareness of the issue at first," he recalls. To address this, he developed a comprehensive training programme: teachers and students received in-person training sessions, video tutorials, and specialised courses. These proactive measures proved successful—initial concerns have since dissipated. "One reason for that, of course, is that everything functions smoothly," Krupa adds with a slight smile.&lt;/p&gt;&lt;h3&gt;A seamless technical transition&lt;/h3&gt;&lt;p&gt;Krupa worked closely with mailbox.org's experts to ensure a well-prepared transition. Following the placement of the order in summer 2023, the school conducted a structured testing phase, verifying API integration and gradually establishing accounts. The final migration on 1 November 2023 was executed without complication.&lt;/p&gt;&lt;h3&gt;One year on: A positive outcome&lt;/h3&gt;&lt;p&gt;More than a year after the migration, the new system has firmly established itself in everyday school life. Both teachers and students appreciate its reliability and the newfound digital autonomy. Would Krupa make the same decision today? "Without a doubt," he responds promptly.&lt;/p&gt;&lt;h3&gt;Conclusion and future outlook&lt;/h3&gt;&lt;p&gt;Investing in data protection and digital sovereignty has proven worthwhile for Gymnasium Dachsberg. While the transition required financial investment, the long-term benefits considerably outweigh the costs. The school serves as an exemplary model of how educational institutions can successfully implement data protection and digital self-determination. Gymnasium Dachsberg now stands as an inspiration for other schools considering similar steps towards greater digital sovereignty.&lt;/p&gt;

          
                                                  
      


      
                  
              
              
              
              
              
              
              
                  &lt;img loading="lazy" height="507" width="1200" src="https://mailbox.org/sites/default/files/2025-04/SSY-Dachsberg-032025.jpg" alt="Gymnasium Dachsberg"&gt;

  


  
          



  &lt;h2 class="referent__title"&gt;&lt;/h2&gt;
  
                
        
                    
            
                          &lt;h3 class="referent__headline"&gt;
                What Gymnasium Dachsberg values most about mailbox.org
                              &lt;/h3&gt;
            
            
                          &lt;ul&gt;&lt;li&gt;Data protection &amp;amp; GDPR compliance&lt;/li&gt;&lt;li&gt;Independence from US-based corporations&lt;/li&gt;&lt;li&gt;Enhanced security for student &amp;amp; teacher data&lt;/li&gt;&lt;li&gt;Seamless migration &amp;amp; retention of email addresses&lt;/li&gt;&lt;li&gt;Automated account management via API&lt;/li&gt;&lt;li&gt;Flexible use via webmail &amp;amp; IMAP&lt;/li&gt;&lt;li&gt;Integrated calendar &amp;amp; groupware functions&lt;/li&gt;&lt;li&gt;Comprehensive documentation &amp;amp; support&lt;/li&gt;&lt;li&gt;Sustainable &amp;amp; ethical IT strategy&lt;/li&gt;&lt;li&gt;Long-term control over the school's IT infrastructure&lt;/li&gt;&lt;/ul&gt;
                        
        
      
      

              


  
    
    
    
    &lt;p&gt;About Gymnasium and ORG Dachsberg&lt;/p&gt;&lt;p&gt;Gymnasium Dachsberg is a Roman Catholic private school situated in the former Dachsberg Castle in Prambachkirchen, Upper Austria. Founded in 1920, it offers both a modern language-focused secondary school and an upper secondary school with a scientific focus. Currently, approximately 900 students are taught by around 100 teachers. The school places significant emphasis on a well-rounded education, incorporating traditional subjects alongside ecological education and democratic values.&lt;/p&gt;

          
                                                  
      


      
      &lt;h2 class="row__intro__title"&gt;            Insights &amp;amp; trends
      &lt;/h2&gt;
      Discover further success stories.
              
            

&lt;a data-component-id="boxy:knob" data-component-variant="secondary" class="knob knob--secondary" href="https://mailbox.org/en/insights/"&gt;All articles&lt;/a&gt;

        
          
    
      
      
  
  
                    
                  
              
                  &lt;img loading="lazy" height="4000" width="6000" src="https://mailbox.org/sites/default/files/2025-06/SSY-LinuxNews.jpeg" alt="Person sitting at the table with hot drink and mobile phone in hand"&gt;

  


      
      
      
      Best practice
    
    &lt;h3 class="snip__title"&gt;Email that grows with your business: LinuxNews story&lt;/h3&gt;
  &lt;a class="snip__arrow" href="https://mailbox.org/en/success-story/how-mailbox-grows-with-linuxnews/" aria-hidden="true"&gt;→&lt;/a&gt;
  &lt;a class="snip__link" href="https://mailbox.org/en/success-story/how-mailbox-grows-with-linuxnews/"&gt;Read more about &lt;em class="placeholder"&gt;Email that grows with your business: LinuxNews story&lt;/em&gt;&lt;/a&gt;


    
      
      
  
  
                    
                  
              
                  &lt;img loading="lazy" height="3760" width="5652" src="https://mailbox.org/sites/default/files/2025-05/Blog-oncampus.jpeg" alt="Konzentrierte afroamerikanische Studentin, die sich während des Online-Unterrichts Notizen auf einem Notizblock macht, E-Learning-Konzept"&gt;

  


      
      
      
      Public sector
    
    &lt;h3 class="snip__title"&gt;More email security in the education sector&lt;/h3&gt;
  &lt;a class="snip__arrow" href="https://mailbox.org/en/success-story/enhanced-email-security-education-sector/" aria-hidden="true"&gt;→&lt;/a&gt;
  &lt;a class="snip__link" href="https://mailbox.org/en/success-story/enhanced-email-security-education-sector/"&gt;Read more about &lt;em class="placeholder"&gt;More email security in the education sector&lt;/em&gt;&lt;/a&gt;


    
  
  


</description>
  <guid isPermaLink="false">28bf227c-4323-484a-ad56-59f6525b0a3a</guid>
    <pubDate>Mon, 10 Mar 2025 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Digital sovereignty in schools: A case study</dc:title>
    <dc:identifier>28bf227c-4323-484a-ad56-59f6525b0a3a</dc:identifier>
    </item>
<item>
  <title>Transparency Report 2024: 30% of all requests from authorities rejected</title>
  <link>https://mailbox.org/en/news/transparency-report-2024/</link>
  <description>&lt;p&gt;In our transparency report, we disclose the type and scope of requests for information that mailbox.org has received from public authorities. In the previous year 2024, the total number of requests decreased. However, almost one-third of all requests had errors.&lt;/p&gt;&lt;p&gt;A total of 25 out of the 83 requests we received from public authorities in 2024 were rejected because of errors that made them legally inadmissible. Compared to the previous year, the proportion of unlawful requests that were ultimately rejected did slightly decrease: from 33.8 % in 2023 to 30.1 % in 2024.&lt;/p&gt;&lt;h2&gt;The most common reason for rejection&lt;/h2&gt;&lt;p&gt;Not much has improved on the part of the authorities since last year. The most common reason for rejection continues to be the transmission of the request on an unencrypted channel, such as by fax, and by e-mail in plain text. In 2024, almost a quarter (24.1 %) of all requests for information were received by fax or plain text email. We consistently reject these requests.&lt;/p&gt;&lt;p&gt;Although the total number of enquiries has decreased, the enquiries have caused more work, as we had to explain to some authorities how encrypted emails work with PGP.&lt;/p&gt;&lt;h2&gt;A brief comparison to the year before&lt;/h2&gt;&lt;ol&gt;&lt;li&gt;The total number of enquiries decreased from 133 (2023) to 83 (2024).&lt;/li&gt;&lt;li&gt;Only 69.9 % of requests were submitted correctly, compared to 66.2 % in 2023.&lt;/li&gt;&lt;li&gt;We received most requests by email, encrypted with PGP.&lt;/li&gt;&lt;/ol&gt;&lt;h2&gt;Requests sent to mailbox.org in the year 2023&lt;/h2&gt;&lt;p&gt;Total number of requests: 83&lt;br&gt;From German authorities: 82&lt;br&gt;From foreign authorities: 0&lt;br&gt;From foreign non-EU authorities: 1&lt;/p&gt;&lt;p&gt;Organisations&lt;br&gt;Criminal investigative authorities: 81&lt;br&gt;Customs authorities: 1&lt;br&gt;Intelligence services: 1&lt;/p&gt;&lt;p&gt;Request type&lt;br&gt;Contact data requests: 79&lt;br&gt;Inbox confiscations: 3&lt;br&gt;Traffic data requests: 0&lt;br&gt;Telecommunications interceptions: 1&lt;/p&gt;&lt;p&gt;Our reports from previous years can be found in the section &lt;a href="https://mailbox.org//en/company#transparency-report" target="_blank" title="Go to all transparency reports" rel="noopener"&gt;transparency reports&lt;/a&gt;.&lt;/p&gt;

  
    
      &lt;h2 class="accordion__headline"&gt;FAQ&lt;/h2&gt;
          
    
    
                        
            
              How we deal with requests
              
                
              
            

            
              
                &lt;p&gt;mailbox.org follows a standardised process when dealing with requests for information from official authorities. Each request will be comprehensively reviewed and assessed by our data protection officer and a lawyer, and then either processed or rejected accordingly. When a request gets rejected, the submitting authority may correct any errors and then resubmit for another review. Data will only be released by us if a related request is actually lawful and formally correct.&lt;/p&gt;
              
            
          
                                
            
              Data that authorities may be interested in
              
                
              
            

            
              
                &lt;ol&gt;&lt;li&gt;Contact data: This includes the name, address and phone number of the account holder, as well as details about their contract with us.&lt;/li&gt;&lt;li&gt;E-mail data: Access to all e-mails currently held in an account's mailbox.&lt;/li&gt;&lt;li&gt;Traffic data: The IP addresses associated with mail server logins when fetching, reading, or sending e-mails.&lt;/li&gt;&lt;li&gt;Telecommunications interception data: Obtained through the temporary surveillance of all ongoing e-mail communication of an account.&lt;/li&gt;&lt;/ol&gt;
              
            
          
                  

  

</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-04/mailbox-news-und-updates-transparenzbericht.jpg?itok=SMV4eTPL" type="image/jpeg" length="268110"/><guid isPermaLink="false">29e4496c-556f-49dc-aad6-328e43509ba0</guid>
    <pubDate>Thu, 30 Jan 2025 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Transparency Report 2024: 30% of all requests from authorities rejected</dc:title>
    <dc:identifier>29e4496c-556f-49dc-aad6-328e43509ba0</dc:identifier>
    </item>
<item>
  <title>Transparency Report 2024: 30% of all requests from authorities rejected</title>
  <link>https://mailbox.org/en/news/transparency-report-2024/</link>
  <description>&lt;p&gt;In our transparency report, we disclose the type and scope of requests for information that mailbox.org has received from public authorities. In the previous year 2024, the total number of requests decreased. However, almost one-third of all requests had errors.&lt;/p&gt;&lt;p&gt;A total of 25 out of the 83 requests we received from public authorities in 2024 were rejected because of errors that made them legally inadmissible. Compared to the previous year, the proportion of unlawful requests that were ultimately rejected did slightly decrease: from 33.8 % in 2023 to 30.1 % in 2024.&lt;/p&gt;&lt;h2&gt;The most common reason for rejection&lt;/h2&gt;&lt;p&gt;Not much has improved on the part of the authorities since last year. The most common reason for rejection continues to be the transmission of the request on an unencrypted channel, such as by fax, and by e-mail in plain text. In 2024, almost a quarter (24.1 %) of all requests for information were received by fax or plain text email. We consistently reject these requests.&lt;/p&gt;&lt;p&gt;Although the total number of enquiries has decreased, the enquiries have caused more work, as we had to explain to some authorities how encrypted emails work with PGP.&lt;/p&gt;&lt;h2&gt;A brief comparison to the year before&lt;/h2&gt;&lt;ol&gt;&lt;li&gt;The total number of enquiries decreased from 133 (2023) to 83 (2024).&lt;/li&gt;&lt;li&gt;Only 69.9 % of requests were submitted correctly, compared to 66.2 % in 2023.&lt;/li&gt;&lt;li&gt;We received most requests by email, encrypted with PGP.&lt;/li&gt;&lt;/ol&gt;&lt;h2&gt;Requests sent to mailbox.org in the year 2023&lt;/h2&gt;&lt;p&gt;Total number of requests: 83&lt;br&gt;From German authorities: 82&lt;br&gt;From foreign authorities: 0&lt;br&gt;From foreign non-EU authorities: 1&lt;/p&gt;&lt;p&gt;Organisations&lt;br&gt;Criminal investigative authorities: 81&lt;br&gt;Customs authorities: 1&lt;br&gt;Intelligence services: 1&lt;/p&gt;&lt;p&gt;Request type&lt;br&gt;Contact data requests: 79&lt;br&gt;Inbox confiscations: 3&lt;br&gt;Traffic data requests: 0&lt;br&gt;Telecommunications interceptions: 1&lt;/p&gt;&lt;p&gt;Our reports from previous years can be found in the section &lt;a href="https://mailbox.org//en/company#transparency-report" target="_blank" title="Go to all transparency reports" rel="noopener"&gt;transparency reports&lt;/a&gt;.&lt;/p&gt;

  
    
      &lt;h2 class="accordion__headline"&gt;FAQ&lt;/h2&gt;
          
    
    
                        
            
              How we deal with requests
              
                
              
            

            
              
                &lt;p&gt;mailbox.org follows a standardised process when dealing with requests for information from official authorities. Each request will be comprehensively reviewed and assessed by our data protection officer and a lawyer, and then either processed or rejected accordingly. When a request gets rejected, the submitting authority may correct any errors and then resubmit for another review. Data will only be released by us if a related request is actually lawful and formally correct.&lt;/p&gt;
              
            
          
                                
            
              Data that authorities may be interested in
              
                
              
            

            
              
                &lt;ol&gt;&lt;li&gt;Contact data: This includes the name, address and phone number of the account holder, as well as details about their contract with us.&lt;/li&gt;&lt;li&gt;E-mail data: Access to all e-mails currently held in an account's mailbox.&lt;/li&gt;&lt;li&gt;Traffic data: The IP addresses associated with mail server logins when fetching, reading, or sending e-mails.&lt;/li&gt;&lt;li&gt;Telecommunications interception data: Obtained through the temporary surveillance of all ongoing e-mail communication of an account.&lt;/li&gt;&lt;/ol&gt;
              
            
          
                  

  

</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-04/mailbox-news-und-updates-transparenzbericht.jpg?itok=SMV4eTPL" type="image/jpeg" length="268110"/><guid isPermaLink="false">29e4496c-556f-49dc-aad6-328e43509ba0</guid>
    <pubDate>Thu, 30 Jan 2025 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Transparency Report 2024: 30% of all requests from authorities rejected</dc:title>
    <dc:identifier>29e4496c-556f-49dc-aad6-328e43509ba0</dc:identifier>
    </item>
<item>
  <title>The mailbox.org Christmas voucher 2024</title>
  <link>https://mailbox.org/en/news/christmas-voucher-2024/</link>
  <description>&lt;p&gt;You've probably already bought some gifts – but how about a secure email inbox for your friends and family?&lt;br&gt;New customers will receive 6 months in the PREMIUM or STANDARD plan. In addition to the email inbox, the plan includes cloud storage, office, video conferencing, and much more. Of course, everything is hosted in German data centres, is spam-free, and has no advertising.&lt;/p&gt;&lt;h2&gt;Voucher code “Christmas2024”&lt;/h2&gt;&lt;p&gt;So if you want to communicate securely with your loved ones by email or video conference in the future, put our voucher under the Christmas tree. Click here for the gift voucher, which you can print out: &lt;a href="https://mailbox.org/files/downloads/Christmas-voucher-2024.pdf" target="_blank" title="Download the christmas voucher as PDF" rel="noopener"&gt;Voucher “Christmas2024”&lt;/a&gt;&lt;/p&gt;&lt;p&gt;The voucher code can be redeemed for all new registrations of a private email account in the PREMIUM or STANDARD plan up to and including 31 December 2024 and is redeemed in the 2nd step of the registration process. After the first payment for at least 12 months, this new email account will receive a bonus worth 6 months in the PREMIUM or STANDARD plan. The first month is generally free of charge. A change of tariff is only possible after expiry. The voucher cannot be refunded, paid out, or transferred to existing accounts.&lt;/p&gt;&lt;p&gt;&lt;br&gt;We wish everyone a happy and relaxing holiday season and a Merry Christmas.&lt;/p&gt;&lt;p&gt;The mailbox.org team&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-04/mailbox-news-und-updates-weihnachtsgutschein.jpg?itok=ZSpgk0we" type="image/jpeg" length="230957"/><guid isPermaLink="false">9c3db284-0714-42fe-8657-e22e18079513</guid>
    <pubDate>Fri, 06 Dec 2024 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>The mailbox.org Christmas voucher 2024</dc:title>
    <dc:identifier>9c3db284-0714-42fe-8657-e22e18079513</dc:identifier>
    </item>
<item>
  <title>The mailbox.org Christmas voucher 2024</title>
  <link>https://mailbox.org/en/news/christmas-voucher-2024/</link>
  <description>&lt;p&gt;You've probably already bought some gifts – but how about a secure email inbox for your friends and family?&lt;br&gt;New customers will receive 6 months in the PREMIUM or STANDARD plan. In addition to the email inbox, the plan includes cloud storage, office, video conferencing, and much more. Of course, everything is hosted in German data centres, is spam-free, and has no advertising.&lt;/p&gt;&lt;h2&gt;Voucher code “Christmas2024”&lt;/h2&gt;&lt;p&gt;So if you want to communicate securely with your loved ones by email or video conference in the future, put our voucher under the Christmas tree. Click here for the gift voucher, which you can print out: &lt;a href="https://mailbox.org/files/downloads/Christmas-voucher-2024.pdf" target="_blank" title="Download the christmas voucher as PDF" rel="noopener"&gt;Voucher “Christmas2024”&lt;/a&gt;&lt;/p&gt;&lt;p&gt;The voucher code can be redeemed for all new registrations of a private email account in the PREMIUM or STANDARD plan up to and including 31 December 2024 and is redeemed in the 2nd step of the registration process. After the first payment for at least 12 months, this new email account will receive a bonus worth 6 months in the PREMIUM or STANDARD plan. The first month is generally free of charge. A change of tariff is only possible after expiry. The voucher cannot be refunded, paid out, or transferred to existing accounts.&lt;/p&gt;&lt;p&gt;&lt;br&gt;We wish everyone a happy and relaxing holiday season and a Merry Christmas.&lt;/p&gt;&lt;p&gt;The mailbox.org team&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-04/mailbox-news-und-updates-weihnachtsgutschein.jpg?itok=ZSpgk0we" type="image/jpeg" length="230957"/><guid isPermaLink="false">9c3db284-0714-42fe-8657-e22e18079513</guid>
    <pubDate>Fri, 06 Dec 2024 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>The mailbox.org Christmas voucher 2024</dc:title>
    <dc:identifier>9c3db284-0714-42fe-8657-e22e18079513</dc:identifier>
    </item>
<item>
  <title>Email address with your custom domain: introduction and tips</title>
  <link>https://mailbox.org/en/blog/email-adress-with-your-custom-domain/</link>
  <description>&lt;p&gt;&lt;em&gt;Reading time: 11 minutes&lt;/em&gt;&lt;/p&gt;&lt;p&gt;In a world where we rely on email daily, why settle for an email address with the provider domain when you can have a personal email address? An email address with your own domain makes your online presence unique. It helps you stand out from the crowd. Plus, you retain control over your data. This article explains why having your custom email domain is useful. We'll show you the benefits and give you tips on how to get the most out of your domain.&lt;/p&gt;


      
                  
              
              
              
              
              
              
              
                  &lt;img loading="lazy" height="2407" width="4136" src="https://mailbox.org/sites/default/files/2025-05/iStock-1312667928.jpg" alt="Junger Mann, der am Laptop arbeitet. Mann, der zu Hause am Tisch sitzt und einen Laptop benutzt."&gt;

  


  
          

              


  
    
    
    
    &lt;h2&gt;FAQ: What is a custom email domain and why is it useful?&lt;/h2&gt;&lt;h3&gt;Why should I use a custom email domain as a private individual?&lt;/h3&gt;&lt;p&gt;A custom email domain gives you full control over your email addresses and allows you to use a customised and professional address. In many cases, email addresses with first names are already taken and some providers try to suggest unnecessarily complicated and untrustworthy addresses, such as susanne1234@provider.de.&lt;/p&gt;&lt;p&gt;Instead of using standardised, long and impersonal email addresses, you can use addresses like vorname@meinedomain.de. This looks more trustworthy and is particularly useful if you want to use a central email address for yourself, your family or different projects. You remain flexible and create a lasting, personal impression.&lt;/p&gt;&lt;h3&gt;Is setting up your custom email domain complicated?&lt;/h3&gt;&lt;p&gt;No, it's easier than you might think. First, you must purchase a domain from a domain name registrar (e.g. INWX). Then you connect this domain to your email provider. Make sure that your email provider also supports custom domains.&lt;/p&gt;&lt;p&gt;Your email provider will guide you through the process step by step. You just need to make a few settings with your domain provider, for which there are detailed instructions. If you need support, our support team is happy to help. With mailbox.org, there are three steps to setting up your first email address with your own domain. We will explain the necessary steps for setting up your own domain in detail later in this text.&lt;/p&gt;&lt;h3&gt;How much does it cost to use a custom email domain?&lt;/h3&gt;&lt;p&gt;The costs usually consist of two components:&lt;/p&gt;&lt;ol&gt;&lt;li&gt;Domain registration: Registering a domain usually costs between €5 and €15 per year, depending on the provider and the domain extension (.de, .com, etc.).&lt;/li&gt;&lt;li&gt;Email providers: You can use your own domain with mailbox.org on the STANDARD price plan. With annual payment, an inbox on the STANDARD price plan costs €30 per year. This gives you an ad-free, secure email account including Drive, Office, video conferencing, and 50 aliases with your custom domain.&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;Overall, the investment is manageable but offers many advantages.&lt;/p&gt;&lt;h3&gt;How secure is a custom email domain?&lt;/h3&gt;&lt;p&gt;Security depends on several factors, in particular on your email provider and the configuration. mailbox.org places a high value on data protection and security. Your emails are stored in German data centres and are secured by powerful spam and virus filters, SSL/TLS transmission and, in addition, (optionally) PGP and S/MIME encryption. This means that your communication not only remains private but is also protected against phishing and spam. With us, you don't need to be a security expert – we take care of that for you! Our team consists of specialists who are always up to date and keep our spam and virus filters current.&lt;/p&gt;&lt;h3&gt;What is the difference between a custom domain and a regular email address?&lt;/h3&gt;&lt;p&gt;The biggest difference is personalisation and control. With many email providers, easy-to-remember email addresses such as vorname@anbieter.de are often already taken. With a custom domain, you can choose any email address under that domain, e.g. kontakt@mydomain.de or info@mydomain.de. This makes a positive impression, especially for official emails or job applications. What's more, you have full control over the domain. You can change email providers at any time without losing your email addresses.&lt;/p&gt;&lt;h3&gt;Can I use multiple email addresses with a custom domain?&lt;/h3&gt;&lt;p&gt;Yes, that's one of the biggest advantages of having your custom domain. You can create a large number of email addresses, e.g. for every family member or for every purpose. For a family member, it could be maria@mydomain.de, for business contacts info@mydomain.de and for personal correspondence firstname@mydomain.de. This creates clarity and helps you to organise your emails better.&lt;/p&gt;&lt;h3&gt;Can I use my custom domain for other purposes as well?&lt;/h3&gt;&lt;p&gt;Yes, that's one of the advantages of owning a domain. Not only can you create email addresses, but you can also operate your website under that domain. If you want to build a website one day, the domain is already registered and ready to go.&lt;/p&gt;&lt;h3&gt;What happens if I want to change my email provider?&lt;/h3&gt;&lt;p&gt;With a custom domain, you are flexible. You can change email providers without having to change your email address. This is particularly useful if you want to change providers in the future but want to keep your email addresses. As long as you have control over the domain, you can use it with any email provider.&lt;/p&gt;&lt;h3&gt;Is it easy to move to mailbox.org with my own domain?&lt;/h3&gt;&lt;p&gt;Thanks to our migration service, moving to mailbox.org with your custom domain is quick and easy. We help you to seamlessly transfer your emails.&lt;/p&gt;&lt;ol&gt;&lt;li&gt;Create your mailbox.org account.&lt;/li&gt;&lt;li&gt;Transfer your existing emails using our free email migration service.&lt;/li&gt;&lt;li&gt;Adjust your DNS settings, so that all new emails reach our servers.&lt;/li&gt;&lt;li&gt;Configure your spam settings (SPF, DKIM and DMARC) to ensure that your emails will be highly secure and deliverable. We explain the details and background below in the text.&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;Our team is on hand to help you with detailed instructions and personalised support to make the switch as smooth as possible.&lt;/p&gt;&lt;h2&gt;Tips and tricks: custom email domain for privacy and how to avoid spam&lt;/h2&gt;&lt;p&gt;There are a few practical tips for organising your emails with the help of a custom domain and avoiding spam:&lt;/p&gt;&lt;h3&gt;Tip 1: Different email addresses for different purposes&lt;/h3&gt;&lt;p&gt;Use your own domain to create multiple email addresses for different activities or areas of your life. Examples:&lt;/p&gt;&lt;ol&gt;&lt;li&gt;personal@mydomain.de for friends and family.&lt;/li&gt;&lt;li&gt;work@mydomain.de for professional contacts.&lt;/li&gt;&lt;li&gt;shopping@mydomain.de for online shopping and newsletters.&lt;/li&gt;&lt;li&gt;social@mydomain.de for social media accounts and online profiles.&lt;/li&gt;&lt;li&gt;travel@mydomain.de for travel bookings and holiday planning.&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;This clear separation allows you to manage each address specifically and reduce spam to a minimum.&lt;/p&gt;&lt;h3&gt;Tip 2: Catch-all function – catch everything&lt;/h3&gt;&lt;p&gt;A catch-all address catches all emails sent to non-existent addresses under your domain. This allows you to use different email addresses for unique purposes, such as summervacation2024@mydomain.de for travel bookings.&lt;/p&gt;&lt;p&gt;Sometimes there are also situations in which you have to provide an email address. A catch-all address is ideal for this. If you notice that this address is flooded with spam, you can simply block this catch-all address.&lt;/p&gt;&lt;h3&gt;Tip 3: Set up email filters&lt;/h3&gt;&lt;p&gt;Use your email provider's filter functions to organise incoming messages automatically. Emails sent to a specific address can be moved directly to particular folders. For example:&lt;/p&gt;&lt;ol&gt;&lt;li&gt;Have messages to shopping@mydomain.de automatically moved to the ‘Purchases’ folder.&lt;/li&gt;&lt;li&gt;For messages to social@mydomain.de, go straight to the ‘Social Media’ folder.&lt;/li&gt;&lt;li&gt;Emails from unknown senders go straight to the ‘Spam’ folder.&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;This keeps your main mailbox clear and you can search for messages in the relevant folders.&lt;/p&gt;&lt;h3&gt;Tip 4: Use a separate login address&lt;/h3&gt;&lt;p&gt;If you want to further increase your security when logging in, then using different email addresses for logging in and for daily communication is a good way to do this. This means that the email address you use in public (e.g. info@meinedomain.de) should not be the same as the one you use to log in to your email inbox.&lt;/p&gt;&lt;p&gt;By setting up a separate login address, an otherwise exposed part of your login data remains secret. If your public email address falls into the wrong hands, your inbox will remain secure because hackers will not know your actual login address. This way, you increase the security of your online communication and make unauthorised access to your account more difficult.&lt;/p&gt;&lt;h2&gt;Set up your custom domain with mailbox in three steps&lt;/h2&gt;&lt;p&gt;As soon as you have your custom domain, setting it up with mailbox is easy and takes just three steps. Our setup assistant will guide you through the process step by step. Here is an overview of how it works:&lt;/p&gt;&lt;h3&gt;Step 1: Validating your custom domain&lt;/h3&gt;&lt;p&gt;The first step is to verify that you have access to the domain you have provided. To do this, a TXT record with an activation code is entered in the DNS table for your domain. mailbox.org uses this entry to verify that the domain belongs to you and activates it for use with your email account.&lt;/p&gt;&lt;h3&gt;Step 2: Set up your custom domain for receiving emails&lt;/h3&gt;&lt;p&gt;To ensure that emails can be received via your custom domain, the so-called MX (Mail Exchange) records must be set up correctly. These DNS records forward all emails sent to your domain to the mailbox mail servers so that you can receive your messages directly in your inbox.&lt;/p&gt;&lt;h3&gt;Step 3: Improve your custom domain's spam reputation&lt;/h3&gt;&lt;p&gt;Now that your domain is ready to receive email, there is one last step. Set up SPF, DKIM, and DMARC to improve the security and deliverability of your email.&lt;/p&gt;&amp;nbsp;

          
                                                  
      


  
          
        

  💡︎

      
        
        
    
      &lt;p&gt;SPF (Sender Policy Framework): This DNS record determines which mail servers are authorised to send emails on behalf of your domain. This prevents unauthorised third parties from sending spam or phishing messages using your domain.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;DKIM (DomainKeys Identified Mail): DKIM adds a digital signature to your emails, that proves that the message was sent from your domain and has not been tampered with in transit.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;DMARC (Domain-based Message Authentication, Reporting &amp;amp; Conformance): DMARC combines the functions of SPF and DKIM and specifies how receiving servers should handle unauthenticated emails. It provides your domain with additional protection against misuse for spam or phishing.&lt;/p&gt;
    
      

              


  
    
    
    
    &lt;p&gt;You can &lt;a href="https://kb.mailbox.org/en/private/custom-domains/" target="_blank" title="Using e-mails with a custom domain" rel="noopener"&gt;find a detailed description of these steps in our knowledge base&lt;/a&gt;. If you have any further questions, our support team will be happy to help.&lt;/p&gt;&lt;h2&gt;Conclusion: Your custom email domain – individual, flexible, and secure with mailbox&lt;/h2&gt;&lt;p&gt;A custom domain gives your email address more individuality and flexibility, and also protects your privacy. This gives you more control over your digital communication.&lt;/p&gt;&lt;p&gt;If you are looking for an easy way to use your own email domain, mailbox is a good choice. Use our simple migration service to move your existing emails. Rely on secure and private email communication. Use our services for your everyday needs, such as: calendar, contacts, office, drive, video conferencing and more!&lt;/p&gt;

          
                                                  
      


  
    
      &lt;h2 class="ticket__title"&gt;Try out mailbox and take back control of your data!&lt;/h2&gt;
              

&lt;a data-track="Blog Custom Domain" data-component-id="boxy:knob" data-component-variant="tertiary" class="knob knob--tertiary" href="https://mailbox.org/en/prices/"&gt;Test mailbox now&lt;/a&gt;

          
    
          
                  
              
                  &lt;img loading="lazy" height="1632" width="2912" src="https://mailbox.org/sites/default/files/2025-05/news-envelope-1.png" alt="Envelope"&gt;

  


    
  



      
      &lt;h2 class="row__intro__title"&gt;            Insights &amp;amp; trends
      &lt;/h2&gt;
      Discover further best practices for your digital security.
              
            

&lt;a data-component-id="boxy:knob" data-component-variant="secondary" class="knob knob--secondary" href="https://mailbox.org/en/insights/"&gt;All articles&lt;/a&gt;

        
          
    
      
      
  
  
                    
                  
              
                  &lt;img loading="lazy" height="2160" width="4096" src="https://mailbox.org/sites/default/files/2026-08/mailbox%20EVAC%20Blog%20Business%20Continuity%20in%20der%20Lieferkette.jpeg" alt="mailbox EVAC Blog Business Continuity in der Lieferkette"&gt;

  


      
      
      
      Best practice, Business Continuitiy
    
    &lt;h3 class="snip__title"&gt;How to use business continuity as a competitive advantage in the supply chain&lt;/h3&gt;
  &lt;a class="snip__arrow" href="https://mailbox.org/en/blog/business-continuity-supply-chain/" aria-hidden="true"&gt;→&lt;/a&gt;
  &lt;a class="snip__link" href="https://mailbox.org/en/blog/business-continuity-supply-chain/"&gt;Read more about &lt;em class="placeholder"&gt;How to use business continuity as a competitive advantage in the supply chain&lt;/em&gt;&lt;/a&gt;


    
      
      
  
  
                    
                  
              
                  &lt;img loading="lazy" height="4065" width="6098" src="https://mailbox.org/sites/default/files/2026-07/mailbox%20Blog%20E-Mail-Alias.jpeg" alt="mailbox Blog E-Mail-Alias"&gt;

  


      
      
      
      Best practice, Data protection
    
    &lt;h3 class="snip__title"&gt;Email alias: How to protect your email address from spam&lt;/h3&gt;
  &lt;a class="snip__arrow" href="https://mailbox.org/en/blog/email-alias-protection-against-spam/" aria-hidden="true"&gt;→&lt;/a&gt;
  &lt;a class="snip__link" href="https://mailbox.org/en/blog/email-alias-protection-against-spam/"&gt;Read more about &lt;em class="placeholder"&gt;Email alias: How to protect your email address from spam&lt;/em&gt;&lt;/a&gt;


    
  
  


</description>
  <guid isPermaLink="false">b060164d-12d0-4068-ae62-e004982b9fc8</guid>
    <pubDate>Thu, 21 Nov 2024 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Email address with your custom domain: introduction and tips</dc:title>
    <dc:identifier>b060164d-12d0-4068-ae62-e004982b9fc8</dc:identifier>
    </item>
<item>
  <title>OpenTalk update for mailbox: New features &amp; improved usability</title>
  <link>https://mailbox.org/en/news/opentalk-update-mailbox-new-features-and-improved-usability/</link>
  <description>&lt;p&gt;We are thrilled to announce a new version of OpenTalk. The update brings a range of new features and improvements that increase usability and make video conferencing even smoother. OpenTalk is the video conferencing solution from mailbox.org. Launched at the end of 2022 and hosted in our data centres. OpenTalk is a sister company of mailbox.org and is also part of the Heinlein Group.&lt;/p&gt;&lt;h2&gt;New features and improvements&lt;/h2&gt;&lt;h3&gt;Better participant management&lt;/h3&gt;&lt;p&gt;Moderators can now change participant names directly from the participant list. This is particularly useful for identifying telephone participants or correcting spelling mistakes. In addition, a new dialogue for recurring meetings has been introduced, which allows precise setting of repeat frequencies and end dates for series meetings. The display of relevant meeting information next to the conference title can now also be selected by the moderator in the dashboard. Participants can be sent to a waiting room and retrieved later, giving moderators more flexibility in meeting control. In addition, microphones can be disabled globally to allow for better control of audio settings in training or discussion sessions, for example.&lt;/p&gt;&lt;h3&gt;More user-friendly and accessible&lt;/h3&gt;&lt;p&gt;Confirmation windows can now be closed using the Escape key, by clicking outside the window or by clicking the X. When using polls, participants can change their mind before confirming the final choice. The moderator view has been optimised so that polls and votes are fully functional on tablets, and close buttons have been made accessible. Moderators also benefit from comprehensive notifications about whom they have given rights to within the web conference and when.&lt;/p&gt;&lt;p&gt;Further technical improvements to accessibility have also been implemented. These include adjustments to colours, contrast, and keyboard control. Use on mobile devices has also been optimised. This means that users with disabilities can also make optimal use of OpenTalk.&lt;/p&gt;&lt;h3&gt;Improved navigation&lt;/h3&gt;&lt;p&gt;The display of raised hands is now more reliable and clearer. The navigation bar has been improved, especially on mobile devices, particularly in the Safari browser – missing elements such as the logo and the drop-down menu are now functional again. In addition, the user guidance for keyboard users has been further optimised so that participants with disabilities can also use an improved personal navigation bar.&lt;/p&gt;&lt;h2&gt;Achieve more with OpenTalk&lt;/h2&gt;&lt;p&gt;Our team combines know-how, passion, and a wealth of experience in the design and operation of secure electronic communication across all brands of the &lt;a class="external-link" href="https://heinlein-support.de/jobs" target="_blank" title="Heinlein Group" rel="nofollow noopener"&gt;Heinlein Group&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;OpenTalk is open source. The source code was published in February 2023. OpenTalk thus creates full transparency for the community and also inspires other developers to work on OpenTalk. Join us: &lt;a class="external-link" href="https://opentalk.eu/en/community" target="_blank" title="OpenTalk Community" rel="nofollow noopener"&gt;Find out more →&lt;/a&gt;&lt;/p&gt;&lt;p&gt;The OpenTalk team has big plans and is looking forward to new members. The backend team programs in Rust, the frontend team in JavaScript/React and Redux. Are you looking for a challenge and want to work on a future-oriented product? Become part of the team: &lt;a class="external-link" href="https://opentalk.eu/en/jobs" target="_blank" title="Jobs at OpenTalk" rel="nofollow noopener"&gt;Jobs at OpenTalk →&lt;/a&gt;&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-mailbox-meet-update-1.jpg?itok=58F0QRRO" type="image/jpeg" length="353603"/><guid isPermaLink="false">56f68177-8597-4c98-a196-c5a046d106d7</guid>
    <pubDate>Tue, 01 Oct 2024 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>OpenTalk update for mailbox: New features &amp; improved usability</dc:title>
    <dc:identifier>56f68177-8597-4c98-a196-c5a046d106d7</dc:identifier>
    </item>
<item>
  <title>OpenTalk update for mailbox: New features &amp; improved usability</title>
  <link>https://mailbox.org/en/news/opentalk-update-mailbox-new-features-and-improved-usability/</link>
  <description>&lt;p&gt;We are thrilled to announce a new version of OpenTalk. The update brings a range of new features and improvements that increase usability and make video conferencing even smoother. OpenTalk is the video conferencing solution from mailbox.org. Launched at the end of 2022 and hosted in our data centres. OpenTalk is a sister company of mailbox.org and is also part of the Heinlein Group.&lt;/p&gt;&lt;h2&gt;New features and improvements&lt;/h2&gt;&lt;h3&gt;Better participant management&lt;/h3&gt;&lt;p&gt;Moderators can now change participant names directly from the participant list. This is particularly useful for identifying telephone participants or correcting spelling mistakes. In addition, a new dialogue for recurring meetings has been introduced, which allows precise setting of repeat frequencies and end dates for series meetings. The display of relevant meeting information next to the conference title can now also be selected by the moderator in the dashboard. Participants can be sent to a waiting room and retrieved later, giving moderators more flexibility in meeting control. In addition, microphones can be disabled globally to allow for better control of audio settings in training or discussion sessions, for example.&lt;/p&gt;&lt;h3&gt;More user-friendly and accessible&lt;/h3&gt;&lt;p&gt;Confirmation windows can now be closed using the Escape key, by clicking outside the window or by clicking the X. When using polls, participants can change their mind before confirming the final choice. The moderator view has been optimised so that polls and votes are fully functional on tablets, and close buttons have been made accessible. Moderators also benefit from comprehensive notifications about whom they have given rights to within the web conference and when.&lt;/p&gt;&lt;p&gt;Further technical improvements to accessibility have also been implemented. These include adjustments to colours, contrast, and keyboard control. Use on mobile devices has also been optimised. This means that users with disabilities can also make optimal use of OpenTalk.&lt;/p&gt;&lt;h3&gt;Improved navigation&lt;/h3&gt;&lt;p&gt;The display of raised hands is now more reliable and clearer. The navigation bar has been improved, especially on mobile devices, particularly in the Safari browser – missing elements such as the logo and the drop-down menu are now functional again. In addition, the user guidance for keyboard users has been further optimised so that participants with disabilities can also use an improved personal navigation bar.&lt;/p&gt;&lt;h2&gt;Achieve more with OpenTalk&lt;/h2&gt;&lt;p&gt;Our team combines know-how, passion, and a wealth of experience in the design and operation of secure electronic communication across all brands of the &lt;a class="external-link" href="https://heinlein-support.de/jobs" target="_blank" title="Heinlein Group" rel="nofollow noopener"&gt;Heinlein Group&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;OpenTalk is open source. The source code was published in February 2023. OpenTalk thus creates full transparency for the community and also inspires other developers to work on OpenTalk. Join us: &lt;a class="external-link" href="https://opentalk.eu/en/community" target="_blank" title="OpenTalk Community" rel="nofollow noopener"&gt;Find out more →&lt;/a&gt;&lt;/p&gt;&lt;p&gt;The OpenTalk team has big plans and is looking forward to new members. The backend team programs in Rust, the frontend team in JavaScript/React and Redux. Are you looking for a challenge and want to work on a future-oriented product? Become part of the team: &lt;a class="external-link" href="https://opentalk.eu/en/jobs" target="_blank" title="Jobs at OpenTalk" rel="nofollow noopener"&gt;Jobs at OpenTalk →&lt;/a&gt;&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-mailbox-meet-update-1.jpg?itok=58F0QRRO" type="image/jpeg" length="353603"/><guid isPermaLink="false">56f68177-8597-4c98-a196-c5a046d106d7</guid>
    <pubDate>Tue, 01 Oct 2024 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>OpenTalk update for mailbox: New features &amp; improved usability</dc:title>
    <dc:identifier>56f68177-8597-4c98-a196-c5a046d106d7</dc:identifier>
    </item>
<item>
  <title>Peer Heinlein on NIS-2 at ISD 2024: Focus on security</title>
  <link>https://mailbox.org/en/news/peer-heinlein-speaker-nis-2-internet-security-days-2024/</link>
  <description>&lt;p&gt;The Internet Security Days 2024 (ISD) will once again offer a diverse program on cyber security on 10 and 11 September 2024 at the RheinEnergieSTADION in Cologne. As one of the leading specialist conferences in the field of IT security, the event has been attracting experts, decision-makers and user companies to discuss current threats and protective measures since 2011.&lt;/p&gt;&lt;p&gt;ISD 2024 participants can expect a comprehensive overview of the latest developments and challenges in IT and data security. Numerous specialist presentations and discussion panels will focus on current trends and provide practical tips for implementing security strategies. Relevant topics from the fields of data protection, computer security and IT infrastructure will be addressed.&lt;/p&gt;&lt;h2&gt;Secure communication and business continuity&lt;/h2&gt;&lt;p&gt;One topic at this year's event is the implementation of the NIS 2 directive, which provides for a significant expansion of the requirements for companies in the critical infrastructure sector. Instead of just 3,700 companies to date, almost 30,000 companies will be subject to the NIS 2 requirements in future, including new sectors that were previously hardly affected by the requirements.&lt;/p&gt;&lt;p&gt;In addition to securing the supply chain, the use of secure voice, video and text communication is a key component of the NIS 2 requirements. This also includes the preparation and use of secure emergency communication systems as part of business continuity, which companies must ensure.&lt;/p&gt;&lt;p&gt;Just how much companies take smooth e-mail communication for granted these days becomes apparent in the event of a lengthy outage. The costs for failures of the existing e-mail infrastructure can easily skyrocket and the damage to a company's image is enormous. You should take precautions to ensure that you remain capable of acting should the worst happen. With the email continuity service from mailbox.org, your communication is quickly restored in an emergency. Further information on the &lt;a href="https://mailbox.org/en/evac"&gt;email emergency platform&lt;/a&gt; can be found here.&lt;/p&gt;&lt;h2&gt;Expert presentations on the NIS 2 Directive and critical infrastructures&lt;/h2&gt;&lt;p&gt;Date: September 11, 2024&lt;br&gt;Time: 15:30&lt;br&gt;Location: Tech Stage&lt;br&gt;Topic: NIS-2: Secure communication systems for business continuity&lt;br&gt;Speaker: Peer Heinlein, Managing Director of the Heinlein Group&lt;/p&gt;&lt;p&gt;Date: September 11, 2024&lt;br&gt;Time: 16:20&lt;br&gt;Location: Tech Stage&lt;br&gt;Topic: Regulated security: NIS2 and the practice&lt;br&gt;Expert: inside: Peer Heinlein, Managing Director of the Heinlein Group; Isabella Norbu (Eversheds Sutherland); Sunita Ute Saxena (Telekom)&lt;br&gt;Moderation: Ulrich Plate (eco - Association of the Internet Industry / nGENn GmbH)&lt;/p&gt;&lt;p&gt;We look forward to welcoming a large audience and will also be available for discussions on site.&lt;/p&gt;&lt;p&gt;Further information on the Internet Security Days 2024 can be found &lt;a href="https://www.eco.de/events/internet-security-days-2024/"&gt;here&lt;/a&gt;.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/mailbox-presse-portrait-peer-heinlein.jpg?itok=i8DawJEx" type="image/jpeg" length="287875"/><guid isPermaLink="false">42308338-b225-4093-9357-1ede7c35c727</guid>
    <pubDate>Wed, 04 Sep 2024 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Peer Heinlein on NIS-2 at ISD 2024: Focus on security</dc:title>
    <dc:identifier>42308338-b225-4093-9357-1ede7c35c727</dc:identifier>
    </item>
<item>
  <title>Peer Heinlein on NIS-2 at ISD 2024: Focus on security</title>
  <link>https://mailbox.org/en/news/peer-heinlein-speaker-nis-2-internet-security-days-2024/</link>
  <description>&lt;p&gt;The Internet Security Days 2024 (ISD) will once again offer a diverse program on cyber security on 10 and 11 September 2024 at the RheinEnergieSTADION in Cologne. As one of the leading specialist conferences in the field of IT security, the event has been attracting experts, decision-makers and user companies to discuss current threats and protective measures since 2011.&lt;/p&gt;&lt;p&gt;ISD 2024 participants can expect a comprehensive overview of the latest developments and challenges in IT and data security. Numerous specialist presentations and discussion panels will focus on current trends and provide practical tips for implementing security strategies. Relevant topics from the fields of data protection, computer security and IT infrastructure will be addressed.&lt;/p&gt;&lt;h2&gt;Secure communication and business continuity&lt;/h2&gt;&lt;p&gt;One topic at this year's event is the implementation of the NIS 2 directive, which provides for a significant expansion of the requirements for companies in the critical infrastructure sector. Instead of just 3,700 companies to date, almost 30,000 companies will be subject to the NIS 2 requirements in future, including new sectors that were previously hardly affected by the requirements.&lt;/p&gt;&lt;p&gt;In addition to securing the supply chain, the use of secure voice, video and text communication is a key component of the NIS 2 requirements. This also includes the preparation and use of secure emergency communication systems as part of business continuity, which companies must ensure.&lt;/p&gt;&lt;p&gt;Just how much companies take smooth e-mail communication for granted these days becomes apparent in the event of a lengthy outage. The costs for failures of the existing e-mail infrastructure can easily skyrocket and the damage to a company's image is enormous. You should take precautions to ensure that you remain capable of acting should the worst happen. With the email continuity service from mailbox.org, your communication is quickly restored in an emergency. Further information on the &lt;a href="https://mailbox.org/en/evac"&gt;email emergency platform&lt;/a&gt; can be found here.&lt;/p&gt;&lt;h2&gt;Expert presentations on the NIS 2 Directive and critical infrastructures&lt;/h2&gt;&lt;p&gt;Date: September 11, 2024&lt;br&gt;Time: 15:30&lt;br&gt;Location: Tech Stage&lt;br&gt;Topic: NIS-2: Secure communication systems for business continuity&lt;br&gt;Speaker: Peer Heinlein, Managing Director of the Heinlein Group&lt;/p&gt;&lt;p&gt;Date: September 11, 2024&lt;br&gt;Time: 16:20&lt;br&gt;Location: Tech Stage&lt;br&gt;Topic: Regulated security: NIS2 and the practice&lt;br&gt;Expert: inside: Peer Heinlein, Managing Director of the Heinlein Group; Isabella Norbu (Eversheds Sutherland); Sunita Ute Saxena (Telekom)&lt;br&gt;Moderation: Ulrich Plate (eco - Association of the Internet Industry / nGENn GmbH)&lt;/p&gt;&lt;p&gt;We look forward to welcoming a large audience and will also be available for discussions on site.&lt;/p&gt;&lt;p&gt;Further information on the Internet Security Days 2024 can be found &lt;a href="https://www.eco.de/events/internet-security-days-2024/"&gt;here&lt;/a&gt;.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/mailbox-presse-portrait-peer-heinlein.jpg?itok=i8DawJEx" type="image/jpeg" length="287875"/><guid isPermaLink="false">42308338-b225-4093-9357-1ede7c35c727</guid>
    <pubDate>Wed, 04 Sep 2024 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Peer Heinlein on NIS-2 at ISD 2024: Focus on security</dc:title>
    <dc:identifier>42308338-b225-4093-9357-1ede7c35c727</dc:identifier>
    </item>
<item>
  <title>Global IT outage: a challenge for global companies</title>
  <link>https://mailbox.org/en/news/global-it-breakdown-challenge-companies-worldwide/</link>
  <description>&lt;p&gt;The digital infrastructure of many companies worldwide was shaken today by a massive outage of Microsoft systems, triggered by problems at the IT security company Crowdstrike. Companies are suddenly facing serious disruptions to their workflows, with significant economic consequences.&lt;/p&gt;&lt;p&gt;Dependence on large providers such as Microsoft carries the risk that technical problems can have far-reaching consequences. Companies therefore urgently need to consider alternatives and solutions to help them bridge such outages and ensure business continuity.&lt;/p&gt;&lt;h2&gt;A robust solution for email continuity&lt;/h2&gt;&lt;p&gt;In this regard, mailbox.org offers a compelling solution. As a provider of open source email services with over 30 years of expertise, mailbox.org places particular emphasis on security, reliability, and independence. The recently introduced “Emergency” features are specifically designed to support companies in emergencies such as the Microsoft outage.&lt;/p&gt;&lt;h2&gt;Advantages of mailbox.org for companies&lt;/h2&gt;&lt;p&gt;1. business continuity: mailbox.org ensures that communications, such as emails and video conferencing, continue to function reliably even during outages of major providers. This ensures that communication is not interrupted in times of crisis.&lt;/p&gt;&lt;p&gt;2. open source technology: The use of open source software offers transparency and security. Companies can check the source code and ensure that there are no hidden vulnerabilities or backdoors.&lt;/p&gt;&lt;p&gt;3. data protection and security: mailbox.org attaches great importance to the protection of its users' data. With strict data protection guidelines and comprehensive security measures, the service offers a high level of confidentiality and protection against data loss.&lt;/p&gt;&lt;p&gt;4. independence: By using mailbox.org, companies reduce their dependence on large providers and their infrastructure. This creates an additional layer of security and minimizes the risk of major outages.&lt;/p&gt;&lt;p&gt;Find out more about our emergency platform here: &lt;a href="https://mailbox.org/en/evac" target="_blank" title="mailbox.org emergency" rel="noopener"&gt;https://mailbox.org/en/evac&lt;/a&gt;&lt;/p&gt;&lt;h2&gt;Conclusion&lt;/h2&gt;&lt;p&gt;The recent events surrounding the Microsoft outage have highlighted the need for robust and independent solutions for business communications. mailbox.org offers an excellent alternative that not only ensures security and reliability, but also takes advantage of open source technology. Companies that ensure their business continuity in this way are better equipped to withstand future challenges and maintain their business operations on an ongoing basis.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-04/mailbox-news-und-updates-warnung.jpg?itok=reW9cU74" type="image/jpeg" length="238141"/><guid isPermaLink="false">20d0919a-e536-4d6b-b511-e5ae19d79a9c</guid>
    <pubDate>Fri, 19 Jul 2024 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Global IT outage: a challenge for global companies</dc:title>
    <dc:identifier>20d0919a-e536-4d6b-b511-e5ae19d79a9c</dc:identifier>
    </item>
<item>
  <title>Global IT outage: a challenge for global companies</title>
  <link>https://mailbox.org/en/news/global-it-breakdown-challenge-companies-worldwide/</link>
  <description>&lt;p&gt;The digital infrastructure of many companies worldwide was shaken today by a massive outage of Microsoft systems, triggered by problems at the IT security company Crowdstrike. Companies are suddenly facing serious disruptions to their workflows, with significant economic consequences.&lt;/p&gt;&lt;p&gt;Dependence on large providers such as Microsoft carries the risk that technical problems can have far-reaching consequences. Companies therefore urgently need to consider alternatives and solutions to help them bridge such outages and ensure business continuity.&lt;/p&gt;&lt;h2&gt;A robust solution for email continuity&lt;/h2&gt;&lt;p&gt;In this regard, mailbox.org offers a compelling solution. As a provider of open source email services with over 30 years of expertise, mailbox.org places particular emphasis on security, reliability, and independence. The recently introduced “Emergency” features are specifically designed to support companies in emergencies such as the Microsoft outage.&lt;/p&gt;&lt;h2&gt;Advantages of mailbox.org for companies&lt;/h2&gt;&lt;p&gt;1. business continuity: mailbox.org ensures that communications, such as emails and video conferencing, continue to function reliably even during outages of major providers. This ensures that communication is not interrupted in times of crisis.&lt;/p&gt;&lt;p&gt;2. open source technology: The use of open source software offers transparency and security. Companies can check the source code and ensure that there are no hidden vulnerabilities or backdoors.&lt;/p&gt;&lt;p&gt;3. data protection and security: mailbox.org attaches great importance to the protection of its users' data. With strict data protection guidelines and comprehensive security measures, the service offers a high level of confidentiality and protection against data loss.&lt;/p&gt;&lt;p&gt;4. independence: By using mailbox.org, companies reduce their dependence on large providers and their infrastructure. This creates an additional layer of security and minimizes the risk of major outages.&lt;/p&gt;&lt;p&gt;Find out more about our emergency platform here: &lt;a href="https://mailbox.org/en/evac" target="_blank" title="mailbox.org emergency" rel="noopener"&gt;https://mailbox.org/en/evac&lt;/a&gt;&lt;/p&gt;&lt;h2&gt;Conclusion&lt;/h2&gt;&lt;p&gt;The recent events surrounding the Microsoft outage have highlighted the need for robust and independent solutions for business communications. mailbox.org offers an excellent alternative that not only ensures security and reliability, but also takes advantage of open source technology. Companies that ensure their business continuity in this way are better equipped to withstand future challenges and maintain their business operations on an ongoing basis.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-04/mailbox-news-und-updates-warnung.jpg?itok=reW9cU74" type="image/jpeg" length="238141"/><guid isPermaLink="false">20d0919a-e536-4d6b-b511-e5ae19d79a9c</guid>
    <pubDate>Fri, 19 Jul 2024 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Global IT outage: a challenge for global companies</dc:title>
    <dc:identifier>20d0919a-e536-4d6b-b511-e5ae19d79a9c</dc:identifier>
    </item>
<item>
  <title>The official mailbox.org beta program is now live</title>
  <link>https://mailbox.org/en/news/beta-program-starts/</link>
  <description>&lt;p&gt;We are excited to announce the launch of our official beta program today! All private customers who decide to participate in the beta program can test our new features exclusively - before they become available to all mailbox.org customers.&lt;/p&gt;&lt;p&gt;With the beta program, we want to involve our customers early, and finally test new functions during operation and under real everyday conditions. Beta testers can give us feedback on these new features and report any bugs.&lt;/p&gt;&lt;p&gt;The start of our beta program is all about more security and the login.&lt;/p&gt;&lt;h2&gt;What is a beta program?&lt;/h2&gt;&lt;p&gt;A beta program for software is like an exclusive preview of a film before it is officially released in cinemas. Imagine you are a film critic and get the chance to see the movie before anyone else. Your job is then to give feedback to the director on how the film can be improved before it becomes available to the general public.&lt;/p&gt;&lt;p&gt;Similarly, software companies invite people who are interested in their products to try out a pre-release version of their software before it is released to everyone. This pre-release version is called a ‘beta version’. Participants in the beta program test the software on different devices and in different environments to find bugs and make suggestions for improvement. The feedback from beta testers helps developers to fix bugs, improve features and optimise the overall user experience.&lt;/p&gt;&lt;p&gt;In a way, beta testers are like film critics - they help polish the final product so it's ready for the big audience. And just as a film premieres in cinemas after beta testing, the software is officially released after the beta program in the hope that users will well receive it.&lt;/p&gt;&lt;h2&gt;Our first beta feature: Login 2.0&lt;/h2&gt;&lt;p&gt;Security is our top priority, which is why our first beta feature is all about it. We are improving the login with a major change in the underlying architecture. The new architecture enables single sign-on (SSO) and improved two-factor authentication (2FA). And of course, in terms of technology, we are relying on the Open Source solution Keycloak, which we host ourselves in the usual manner.&lt;/p&gt;&lt;h3&gt;Single sign-on (SSO)&lt;/h3&gt;&lt;p&gt;Thanks to single sign-on, you only have to log in to our system once and can then switch smoothly between all our products and services (webmailer, forum, helpdesk and OpenTalk). Conveniently, without having to re-enter your login details each time.&lt;/p&gt;&lt;h2&gt;What is single sign-on?&lt;/h2&gt;&lt;p&gt;Single sign-on allows users to log in to multiple web services with just one login. Imagine going to a huge library with many different rooms and books. Instead of using a separate key each time you enter a new room, you can open all the doors with a single key. This saves time and effort. This is basically how single sign-on works: You sign in once and gain access to different services without re-entering your login details each time.&lt;/p&gt;&lt;h3&gt;Two-factor authentication (2FA)&lt;/h3&gt;&lt;p&gt;Until now, setting up 2FA was relatively complex and time-consuming. Unfortunately, this also prevented some users from increasing their account security. With our new security architecture through Keycloak, we have simplified the process to 3 steps. This improvement makes it easier and more convenient to secure your login.&lt;/p&gt;&lt;h3&gt;Simple setup in 3 steps with an authenticator app&lt;/h3&gt;&lt;p&gt;1. Scan the QR code in an authenticator app&lt;br&gt;2. Enter the TOTP code from the app&lt;br&gt;3. Assign and save the device name&lt;/p&gt;&lt;h2&gt;What is two-factor authentication?&lt;/h2&gt;&lt;p&gt;Two-factor authentication (2FA) for web services is like a double-secured lock for your digital door.&lt;/p&gt;&lt;p&gt;Imagine you have a traditional lock on your front door that can only be opened with a key. It's like the password for your online accounts - a first layer of security. But sometimes a key can be lost or stolen. This is where two-factor authentication comes into play.&lt;/p&gt;&lt;p&gt;With 2FA, you add an extra layer of security, similar to a security deadbolt or alarm system. After you enter your password, another code is sent to you via text message, app or email. This code is like a second key that you need to open the door. Even if someone knows your password, they also need this code to gain access.&lt;/p&gt;&lt;p&gt;In short, two-factor authentication provides an extra layer of security for your online accounts to protect them from unauthorised access, much like a double-locked padlock for your digital door.&lt;/p&gt;&lt;h3&gt;Important notes on two-factor authentication (2FA) in the beta&lt;/h3&gt;&lt;p&gt;To enable you as a beta participant to make an informed decision about the use of 2FA, we would like to provide you with the following important information:&lt;/p&gt;&lt;ol&gt;&lt;li&gt;Only private customers in the beta can use this feature.&lt;/li&gt;&lt;li&gt;If the old 2FA is already set up, it must first be deactivated before the new 2FA is available.&lt;/li&gt;&lt;li&gt;For the time being, we only support Authenticator apps. The use of a Yubikey is not possible.&lt;/li&gt;&lt;li&gt;App passwords are required for the following applications:&lt;ol&gt;&lt;li&gt;Calendar (CalDAV)&lt;/li&gt;&lt;li&gt;Contacts (CardDAV)&lt;/li&gt;&lt;li&gt;Drive (WebDAV)&lt;/li&gt;&lt;/ol&gt;&lt;/li&gt;&lt;li&gt;External email clients with IMAP or SMTP still require the normal customer password (without 2FA)&lt;ol&gt;&lt;li&gt;We will introduce the ‘high-security level’ option (deactivate IMAP) later.&lt;/li&gt;&lt;/ol&gt;&lt;/li&gt;&lt;/ol&gt;&lt;h3&gt;Availability in the mailbox.org beta program&lt;/h3&gt;&lt;p&gt;The beta of Login 2.0 is now available. All participants in the beta program can activate the Login 2.0 beta function directly.&lt;/p&gt;&lt;hr&gt;&lt;h2&gt;Participation in the mailbox.org beta program&lt;/h2&gt;&lt;p&gt;To join the mailbox.org beta program, you must be a private customer on the PREMIUM, STANDARD or LIGHT plan and have made at least one deposit.&lt;/p&gt;&lt;h3&gt;Join the beta program&lt;/h3&gt;&lt;p&gt;How to become a beta member in just a few minutes:&lt;/p&gt;&lt;p&gt;1. In the mailbox.org webmailer, select: Settings &amp;gt; mailbox.org &amp;gt; Services &amp;gt; mailbox.org beta&lt;/p&gt;&lt;p&gt;2. Accept the conditions of participation so that we can also contact you for the beta program&lt;/p&gt;&lt;p&gt;3. Activate the exclusive beta features&lt;/p&gt;&lt;h3&gt;Important notes on the beta program&lt;/h3&gt;&lt;ol&gt;&lt;li&gt;The beta program is only available for private customers on the PREMIUM, STANDARD or LIGHT plan.&lt;/li&gt;&lt;li&gt;Naturally, there may still be bugs hidden in features in the beta stage, which we are continuously eliminating. We therefore recommend that you do not link any critical processes to features from the beta program.&lt;/li&gt;&lt;li&gt;You can deactivate most beta features at any time. However, there will also be beta features that you will not be able to leave until the official launch. These or other consequences will always be pointed out before activating a beta feature.&lt;/li&gt;&lt;/ol&gt;&lt;h2&gt;Join the beta today!&lt;/h2&gt;&lt;p&gt;Help us make the new mailbox.org features even better!&lt;/p&gt;&lt;p&gt;&lt;a href="https://login.mailbox.org/en" target="_blank" title="Log in and get started" rel="noopener"&gt;Log in and get started&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-beta-programm-startet.jpg?itok=QAjfdnVL" type="image/jpeg" length="450634"/><guid isPermaLink="false">eccfac04-8a33-4298-bf9e-b90cfef929b9</guid>
    <pubDate>Tue, 11 Jun 2024 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>The official mailbox.org beta program is now live</dc:title>
    <dc:identifier>eccfac04-8a33-4298-bf9e-b90cfef929b9</dc:identifier>
    </item>
<item>
  <title>The official mailbox.org beta program is now live</title>
  <link>https://mailbox.org/en/news/beta-program-starts/</link>
  <description>&lt;p&gt;We are excited to announce the launch of our official beta program today! All private customers who decide to participate in the beta program can test our new features exclusively - before they become available to all mailbox.org customers.&lt;/p&gt;&lt;p&gt;With the beta program, we want to involve our customers early, and finally test new functions during operation and under real everyday conditions. Beta testers can give us feedback on these new features and report any bugs.&lt;/p&gt;&lt;p&gt;The start of our beta program is all about more security and the login.&lt;/p&gt;&lt;h2&gt;What is a beta program?&lt;/h2&gt;&lt;p&gt;A beta program for software is like an exclusive preview of a film before it is officially released in cinemas. Imagine you are a film critic and get the chance to see the movie before anyone else. Your job is then to give feedback to the director on how the film can be improved before it becomes available to the general public.&lt;/p&gt;&lt;p&gt;Similarly, software companies invite people who are interested in their products to try out a pre-release version of their software before it is released to everyone. This pre-release version is called a ‘beta version’. Participants in the beta program test the software on different devices and in different environments to find bugs and make suggestions for improvement. The feedback from beta testers helps developers to fix bugs, improve features and optimise the overall user experience.&lt;/p&gt;&lt;p&gt;In a way, beta testers are like film critics - they help polish the final product so it's ready for the big audience. And just as a film premieres in cinemas after beta testing, the software is officially released after the beta program in the hope that users will well receive it.&lt;/p&gt;&lt;h2&gt;Our first beta feature: Login 2.0&lt;/h2&gt;&lt;p&gt;Security is our top priority, which is why our first beta feature is all about it. We are improving the login with a major change in the underlying architecture. The new architecture enables single sign-on (SSO) and improved two-factor authentication (2FA). And of course, in terms of technology, we are relying on the Open Source solution Keycloak, which we host ourselves in the usual manner.&lt;/p&gt;&lt;h3&gt;Single sign-on (SSO)&lt;/h3&gt;&lt;p&gt;Thanks to single sign-on, you only have to log in to our system once and can then switch smoothly between all our products and services (webmailer, forum, helpdesk and OpenTalk). Conveniently, without having to re-enter your login details each time.&lt;/p&gt;&lt;h2&gt;What is single sign-on?&lt;/h2&gt;&lt;p&gt;Single sign-on allows users to log in to multiple web services with just one login. Imagine going to a huge library with many different rooms and books. Instead of using a separate key each time you enter a new room, you can open all the doors with a single key. This saves time and effort. This is basically how single sign-on works: You sign in once and gain access to different services without re-entering your login details each time.&lt;/p&gt;&lt;h3&gt;Two-factor authentication (2FA)&lt;/h3&gt;&lt;p&gt;Until now, setting up 2FA was relatively complex and time-consuming. Unfortunately, this also prevented some users from increasing their account security. With our new security architecture through Keycloak, we have simplified the process to 3 steps. This improvement makes it easier and more convenient to secure your login.&lt;/p&gt;&lt;h3&gt;Simple setup in 3 steps with an authenticator app&lt;/h3&gt;&lt;p&gt;1. Scan the QR code in an authenticator app&lt;br&gt;2. Enter the TOTP code from the app&lt;br&gt;3. Assign and save the device name&lt;/p&gt;&lt;h2&gt;What is two-factor authentication?&lt;/h2&gt;&lt;p&gt;Two-factor authentication (2FA) for web services is like a double-secured lock for your digital door.&lt;/p&gt;&lt;p&gt;Imagine you have a traditional lock on your front door that can only be opened with a key. It's like the password for your online accounts - a first layer of security. But sometimes a key can be lost or stolen. This is where two-factor authentication comes into play.&lt;/p&gt;&lt;p&gt;With 2FA, you add an extra layer of security, similar to a security deadbolt or alarm system. After you enter your password, another code is sent to you via text message, app or email. This code is like a second key that you need to open the door. Even if someone knows your password, they also need this code to gain access.&lt;/p&gt;&lt;p&gt;In short, two-factor authentication provides an extra layer of security for your online accounts to protect them from unauthorised access, much like a double-locked padlock for your digital door.&lt;/p&gt;&lt;h3&gt;Important notes on two-factor authentication (2FA) in the beta&lt;/h3&gt;&lt;p&gt;To enable you as a beta participant to make an informed decision about the use of 2FA, we would like to provide you with the following important information:&lt;/p&gt;&lt;ol&gt;&lt;li&gt;Only private customers in the beta can use this feature.&lt;/li&gt;&lt;li&gt;If the old 2FA is already set up, it must first be deactivated before the new 2FA is available.&lt;/li&gt;&lt;li&gt;For the time being, we only support Authenticator apps. The use of a Yubikey is not possible.&lt;/li&gt;&lt;li&gt;App passwords are required for the following applications:&lt;ol&gt;&lt;li&gt;Calendar (CalDAV)&lt;/li&gt;&lt;li&gt;Contacts (CardDAV)&lt;/li&gt;&lt;li&gt;Drive (WebDAV)&lt;/li&gt;&lt;/ol&gt;&lt;/li&gt;&lt;li&gt;External email clients with IMAP or SMTP still require the normal customer password (without 2FA)&lt;ol&gt;&lt;li&gt;We will introduce the ‘high-security level’ option (deactivate IMAP) later.&lt;/li&gt;&lt;/ol&gt;&lt;/li&gt;&lt;/ol&gt;&lt;h3&gt;Availability in the mailbox.org beta program&lt;/h3&gt;&lt;p&gt;The beta of Login 2.0 is now available. All participants in the beta program can activate the Login 2.0 beta function directly.&lt;/p&gt;&lt;hr&gt;&lt;h2&gt;Participation in the mailbox.org beta program&lt;/h2&gt;&lt;p&gt;To join the mailbox.org beta program, you must be a private customer on the PREMIUM, STANDARD or LIGHT plan and have made at least one deposit.&lt;/p&gt;&lt;h3&gt;Join the beta program&lt;/h3&gt;&lt;p&gt;How to become a beta member in just a few minutes:&lt;/p&gt;&lt;p&gt;1. In the mailbox.org webmailer, select: Settings &amp;gt; mailbox.org &amp;gt; Services &amp;gt; mailbox.org beta&lt;/p&gt;&lt;p&gt;2. Accept the conditions of participation so that we can also contact you for the beta program&lt;/p&gt;&lt;p&gt;3. Activate the exclusive beta features&lt;/p&gt;&lt;h3&gt;Important notes on the beta program&lt;/h3&gt;&lt;ol&gt;&lt;li&gt;The beta program is only available for private customers on the PREMIUM, STANDARD or LIGHT plan.&lt;/li&gt;&lt;li&gt;Naturally, there may still be bugs hidden in features in the beta stage, which we are continuously eliminating. We therefore recommend that you do not link any critical processes to features from the beta program.&lt;/li&gt;&lt;li&gt;You can deactivate most beta features at any time. However, there will also be beta features that you will not be able to leave until the official launch. These or other consequences will always be pointed out before activating a beta feature.&lt;/li&gt;&lt;/ol&gt;&lt;h2&gt;Join the beta today!&lt;/h2&gt;&lt;p&gt;Help us make the new mailbox.org features even better!&lt;/p&gt;&lt;p&gt;&lt;a href="https://login.mailbox.org/en" target="_blank" title="Log in and get started" rel="noopener"&gt;Log in and get started&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-beta-programm-startet.jpg?itok=QAjfdnVL" type="image/jpeg" length="450634"/><guid isPermaLink="false">eccfac04-8a33-4298-bf9e-b90cfef929b9</guid>
    <pubDate>Tue, 11 Jun 2024 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>The official mailbox.org beta program is now live</dc:title>
    <dc:identifier>eccfac04-8a33-4298-bf9e-b90cfef929b9</dc:identifier>
    </item>
<item>
  <title>BSI extends IT security certification for mailbox.org</title>
  <link>https://mailbox.org/en/news/bsi-reconfirms-it-security-labels/</link>
  <description>&lt;p&gt;We are delighted that the German Federal Office for Information Security (BSI) has reconfirmed our three IT Security Labels. Our PREMIUM, STANDARD and LIGHT plans have been bearing the BSI's IT Security Label since 2022. The authenticity and up-to-dateness can be checked by scanning the QR code.&lt;/p&gt;&lt;p&gt;We are proud that we fulfil the BSI's requirements for consumer protection and security requirements – following the technical guideline "Secure e-mail transport" (&lt;a href="https://www.bsi.bund.de/DE/Themen/Unternehmen-und-Organisationen/Standards-und-Zertifizierung/Technische-Richtlinien/TR-nach-Thema-sortiert/tr03108/tr03108_node.html" target="_blank" rel="noopener"&gt;BSI TR 03108&lt;/a&gt;, page in German) – as an e-mail provider, even after being re-tested. We did not have to make any changes to our systems for the audit.&lt;/p&gt;&lt;h2&gt;What is the BSI IT Security Label about?&lt;/h2&gt;&lt;p&gt;The German IT Security Act 2.0 made digital consumer protection a primary task of the BSI, who officially presented their "IT Security Label" in February 2022. The aim is to promote digital consumer protection and more straightforward consumer orientation when it comes to product security. Companies can apply for the security label by submitting a declaration about the security features of their services, which the BSI will then check for completeness and plausibility. This procedure has been successfully completed by mailbox.org.&lt;/p&gt;&lt;h2&gt;Which security aspects were checked?&lt;/h2&gt;&lt;p&gt;We have provided the BSI with a range of information about the security features guaranteed by mailbox.org, including:&lt;/p&gt;&lt;ol&gt;&lt;li&gt;Transport encryption&lt;br&gt;We use the common IMAP, POP3 and SMTP protocols, with transport encryption enabled. Whenever possible, the latest TLS 1.3 standard is employed.&lt;/li&gt;&lt;li&gt;Server location Berlin&lt;br&gt;We operate our own infrastructure across two independent data centres.&lt;/li&gt;&lt;li&gt;Protection of user data&lt;br&gt;The principle of data economy is very important to us, and we allow anonymous registration and payment for our services. All our systems receive updates on a regular basis so that any emerging vulnerabilities get fixed as soon as possible. We also enforce a strict policy for the creation of strong passwords. Login procedures are protected against brute force attacks, and further by optional two-factor authentication (2FA) for private customers. The "Have I Been Pwned" service is integrated and alerts users in the event that their email addresses get compromised in data breaches around the Web.&lt;/li&gt;&lt;li&gt;Secure data transmission&amp;nbsp;&lt;br&gt;In addition to TLS transport security, all private mailbox.org customers have access to @secure.mailbox.org addresses. These enforce the use of transport encryption, without which e-mails will not be transmitted at all. Our systems also use the network protocol DANE (DNS-based Authentication of Named Entities) that further enhances the TLS standard. All mailbox.org customers also benefit from SPF and DKIM, which are additional protection measures and can even be configured to work with custom domain names.&lt;/li&gt;&lt;/ol&gt;

  
      
  &lt;a name="logos-9345"&gt;&lt;/a&gt;
  
  
          
  
                &lt;img loading="lazy" src="https://mailbox.org/sites/default/files/2025-05/sik-01010_Light.svg" alt="sik Light"&gt;


        
  mailbox.org LIGHT




          
  
                &lt;img loading="lazy" src="https://mailbox.org/sites/default/files/2025-05/sik-01011_Standard.svg" alt="sik Standard"&gt;


        
  mailbox.org STANDARD




          
  
                &lt;img loading="lazy" src="https://mailbox.org/sites/default/files/2025-05/sik-01012_Premium.svg" alt="sik Premium"&gt;


        
  mailbox.org PREMIUM




      
    
  </description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-team-2.jpeg?itok=JunenBYW" type="image/jpeg" length="404224"/><guid isPermaLink="false">d0c43467-82a7-4e71-8383-7600e0d41230</guid>
    <pubDate>Tue, 07 May 2024 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>BSI extends IT security certification for mailbox.org</dc:title>
    <dc:identifier>d0c43467-82a7-4e71-8383-7600e0d41230</dc:identifier>
    </item>
<item>
  <title>BSI extends IT security certification for mailbox.org</title>
  <link>https://mailbox.org/en/news/bsi-reconfirms-it-security-labels/</link>
  <description>&lt;p&gt;We are delighted that the German Federal Office for Information Security (BSI) has reconfirmed our three IT Security Labels. Our PREMIUM, STANDARD and LIGHT plans have been bearing the BSI's IT Security Label since 2022. The authenticity and up-to-dateness can be checked by scanning the QR code.&lt;/p&gt;&lt;p&gt;We are proud that we fulfil the BSI's requirements for consumer protection and security requirements – following the technical guideline "Secure e-mail transport" (&lt;a href="https://www.bsi.bund.de/DE/Themen/Unternehmen-und-Organisationen/Standards-und-Zertifizierung/Technische-Richtlinien/TR-nach-Thema-sortiert/tr03108/tr03108_node.html" target="_blank" rel="noopener"&gt;BSI TR 03108&lt;/a&gt;, page in German) – as an e-mail provider, even after being re-tested. We did not have to make any changes to our systems for the audit.&lt;/p&gt;&lt;h2&gt;What is the BSI IT Security Label about?&lt;/h2&gt;&lt;p&gt;The German IT Security Act 2.0 made digital consumer protection a primary task of the BSI, who officially presented their "IT Security Label" in February 2022. The aim is to promote digital consumer protection and more straightforward consumer orientation when it comes to product security. Companies can apply for the security label by submitting a declaration about the security features of their services, which the BSI will then check for completeness and plausibility. This procedure has been successfully completed by mailbox.org.&lt;/p&gt;&lt;h2&gt;Which security aspects were checked?&lt;/h2&gt;&lt;p&gt;We have provided the BSI with a range of information about the security features guaranteed by mailbox.org, including:&lt;/p&gt;&lt;ol&gt;&lt;li&gt;Transport encryption&lt;br&gt;We use the common IMAP, POP3 and SMTP protocols, with transport encryption enabled. Whenever possible, the latest TLS 1.3 standard is employed.&lt;/li&gt;&lt;li&gt;Server location Berlin&lt;br&gt;We operate our own infrastructure across two independent data centres.&lt;/li&gt;&lt;li&gt;Protection of user data&lt;br&gt;The principle of data economy is very important to us, and we allow anonymous registration and payment for our services. All our systems receive updates on a regular basis so that any emerging vulnerabilities get fixed as soon as possible. We also enforce a strict policy for the creation of strong passwords. Login procedures are protected against brute force attacks, and further by optional two-factor authentication (2FA) for private customers. The "Have I Been Pwned" service is integrated and alerts users in the event that their email addresses get compromised in data breaches around the Web.&lt;/li&gt;&lt;li&gt;Secure data transmission&amp;nbsp;&lt;br&gt;In addition to TLS transport security, all private mailbox.org customers have access to @secure.mailbox.org addresses. These enforce the use of transport encryption, without which e-mails will not be transmitted at all. Our systems also use the network protocol DANE (DNS-based Authentication of Named Entities) that further enhances the TLS standard. All mailbox.org customers also benefit from SPF and DKIM, which are additional protection measures and can even be configured to work with custom domain names.&lt;/li&gt;&lt;/ol&gt;

  
      
  &lt;a name="logos-9345"&gt;&lt;/a&gt;
  
  
          
  
                &lt;img loading="lazy" src="https://mailbox.org/sites/default/files/2025-05/sik-01010_Light.svg" alt="sik Light"&gt;


        
  mailbox.org LIGHT




          
  
                &lt;img loading="lazy" src="https://mailbox.org/sites/default/files/2025-05/sik-01011_Standard.svg" alt="sik Standard"&gt;


        
  mailbox.org STANDARD




          
  
                &lt;img loading="lazy" src="https://mailbox.org/sites/default/files/2025-05/sik-01012_Premium.svg" alt="sik Premium"&gt;


        
  mailbox.org PREMIUM




      
    
  </description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-team-2.jpeg?itok=JunenBYW" type="image/jpeg" length="404224"/><guid isPermaLink="false">d0c43467-82a7-4e71-8383-7600e0d41230</guid>
    <pubDate>Tue, 07 May 2024 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>BSI extends IT security certification for mailbox.org</dc:title>
    <dc:identifier>d0c43467-82a7-4e71-8383-7600e0d41230</dc:identifier>
    </item>
<item>
  <title>Transparency Report 2023: 33.8% of all requests unlawful</title>
  <link>https://mailbox.org/en/news/transparency-report-2023/</link>
  <description>&lt;p&gt;In our transparency report, we disclose the type and scope of requests for information that mailbox.org has received from public authorities. In the previous year 2023, the total number of requests has increased. However, more than one-third of all requests had errors.&lt;/p&gt;&lt;p&gt;A total of 45 out of the 133 requests we received from public authorities in 2023 were rejected because of errors that made them legally inadmissible. Compared to the previous year, the proportion of unlawful requests that were ultimately rejected did increase: from 12.7 % in 2022 to 33.8 % in 2023.&lt;/p&gt;&lt;h2&gt;The use of e-mails and the most common reason for rejection&lt;/h2&gt;&lt;p&gt;Many authorities have now also recognised that requests for information by fax and e-mail in plain text are no longer accepted. After all, in 2023, most requests for information were made by encrypted e-mail, which we were then able to assess properly. Nevertheless, 27.1 % of enquiries were still received by plain text email and 6.0 % by fax. However, this form of transmission has no longer been permitted by the Federal Network Agency since 2023 for security reasons. We hope that the investigating authorities will soon all comply with this instruction.&lt;/p&gt;&lt;h2&gt;A brief comparison to the year before&lt;/h2&gt;&lt;ol&gt;&lt;li&gt;The total number of enquiries rose from 55 (2022) to 133 (2023).&lt;/li&gt;&lt;li&gt;Only 66.2 % of requests were submitted correctly, compared to 74.6 % in 2022.&lt;/li&gt;&lt;li&gt;We received most requests by email, encrypted with PGP.&lt;/li&gt;&lt;/ol&gt;&lt;h2&gt;Requests sent to mailbox.org in the year 2023&lt;/h2&gt;&lt;p&gt;Total number of requests: 133&lt;br&gt;From German authorities: 130&lt;br&gt;From foreign authorities: 2&lt;br&gt;From foreign non-EU authorities: 1&lt;/p&gt;&lt;p&gt;Organisations&lt;br&gt;Criminal investigative authorities: 133&lt;br&gt;Customs authorities: 0&lt;br&gt;Intelligence services: 0&lt;/p&gt;&lt;p&gt;Request type&lt;br&gt;Contact data requests: 130&lt;br&gt;Inbox confiscations: 3&lt;br&gt;Traffic data requests: 0&lt;br&gt;Telecommunications interceptions: 0&lt;/p&gt;&lt;p&gt;Our reports from previous years can be found in the section &lt;a href="https://mailbox.org/preview.php/en/company#transparency-report" target="_blank" title="Go to all transparency reports" rel="noopener"&gt;transparency reports&lt;/a&gt;.&lt;/p&gt;&lt;h3&gt;How we deal with requests&lt;/h3&gt;&lt;p&gt;mailbox.org follows a standardised process when dealing with requests for information from official authorities. Each request will be comprehensively reviewed and assessed by our data protection officer and a lawyer, and then either processed or rejected accordingly. When a request gets rejected, the submitting authority may correct any errors and then resubmit for another review. Data will only be released by us if a related request is actually lawful and formally correct.&lt;/p&gt;&lt;h3&gt;Data that authorities may be interested in&lt;/h3&gt;&lt;ol&gt;&lt;li&gt;Contact data: This includes the name, address and phone number of the account holder, as well as details about their contract with us.&lt;/li&gt;&lt;li&gt;E-mail data: Access to all e-mails currently held in an account's mailbox.&lt;/li&gt;&lt;li&gt;Traffic data: The IP addresses associated with mail server logins when fetching, reading, or sending e-mails.&lt;/li&gt;&lt;li&gt;Telecommunications interception data: Obtained through the temporary surveillance of all ongoing e-mail communication of an account.&lt;/li&gt;&lt;/ol&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-04/mailbox-news-und-updates-transparenzbericht.jpg?itok=SMV4eTPL" type="image/jpeg" length="268110"/><guid isPermaLink="false">c3ba9ce7-99db-4dcd-803a-964a922e8c9b</guid>
    <pubDate>Tue, 27 Feb 2024 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Transparency Report 2023: 33.8% of all requests unlawful</dc:title>
    <dc:identifier>c3ba9ce7-99db-4dcd-803a-964a922e8c9b</dc:identifier>
    </item>
<item>
  <title>Transparency Report 2023: 33.8% of all requests unlawful</title>
  <link>https://mailbox.org/en/news/transparency-report-2023/</link>
  <description>&lt;p&gt;In our transparency report, we disclose the type and scope of requests for information that mailbox.org has received from public authorities. In the previous year 2023, the total number of requests has increased. However, more than one-third of all requests had errors.&lt;/p&gt;&lt;p&gt;A total of 45 out of the 133 requests we received from public authorities in 2023 were rejected because of errors that made them legally inadmissible. Compared to the previous year, the proportion of unlawful requests that were ultimately rejected did increase: from 12.7 % in 2022 to 33.8 % in 2023.&lt;/p&gt;&lt;h2&gt;The use of e-mails and the most common reason for rejection&lt;/h2&gt;&lt;p&gt;Many authorities have now also recognised that requests for information by fax and e-mail in plain text are no longer accepted. After all, in 2023, most requests for information were made by encrypted e-mail, which we were then able to assess properly. Nevertheless, 27.1 % of enquiries were still received by plain text email and 6.0 % by fax. However, this form of transmission has no longer been permitted by the Federal Network Agency since 2023 for security reasons. We hope that the investigating authorities will soon all comply with this instruction.&lt;/p&gt;&lt;h2&gt;A brief comparison to the year before&lt;/h2&gt;&lt;ol&gt;&lt;li&gt;The total number of enquiries rose from 55 (2022) to 133 (2023).&lt;/li&gt;&lt;li&gt;Only 66.2 % of requests were submitted correctly, compared to 74.6 % in 2022.&lt;/li&gt;&lt;li&gt;We received most requests by email, encrypted with PGP.&lt;/li&gt;&lt;/ol&gt;&lt;h2&gt;Requests sent to mailbox.org in the year 2023&lt;/h2&gt;&lt;p&gt;Total number of requests: 133&lt;br&gt;From German authorities: 130&lt;br&gt;From foreign authorities: 2&lt;br&gt;From foreign non-EU authorities: 1&lt;/p&gt;&lt;p&gt;Organisations&lt;br&gt;Criminal investigative authorities: 133&lt;br&gt;Customs authorities: 0&lt;br&gt;Intelligence services: 0&lt;/p&gt;&lt;p&gt;Request type&lt;br&gt;Contact data requests: 130&lt;br&gt;Inbox confiscations: 3&lt;br&gt;Traffic data requests: 0&lt;br&gt;Telecommunications interceptions: 0&lt;/p&gt;&lt;p&gt;Our reports from previous years can be found in the section &lt;a href="https://mailbox.org/preview.php/en/company#transparency-report" target="_blank" title="Go to all transparency reports" rel="noopener"&gt;transparency reports&lt;/a&gt;.&lt;/p&gt;&lt;h3&gt;How we deal with requests&lt;/h3&gt;&lt;p&gt;mailbox.org follows a standardised process when dealing with requests for information from official authorities. Each request will be comprehensively reviewed and assessed by our data protection officer and a lawyer, and then either processed or rejected accordingly. When a request gets rejected, the submitting authority may correct any errors and then resubmit for another review. Data will only be released by us if a related request is actually lawful and formally correct.&lt;/p&gt;&lt;h3&gt;Data that authorities may be interested in&lt;/h3&gt;&lt;ol&gt;&lt;li&gt;Contact data: This includes the name, address and phone number of the account holder, as well as details about their contract with us.&lt;/li&gt;&lt;li&gt;E-mail data: Access to all e-mails currently held in an account's mailbox.&lt;/li&gt;&lt;li&gt;Traffic data: The IP addresses associated with mail server logins when fetching, reading, or sending e-mails.&lt;/li&gt;&lt;li&gt;Telecommunications interception data: Obtained through the temporary surveillance of all ongoing e-mail communication of an account.&lt;/li&gt;&lt;/ol&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-04/mailbox-news-und-updates-transparenzbericht.jpg?itok=SMV4eTPL" type="image/jpeg" length="268110"/><guid isPermaLink="false">c3ba9ce7-99db-4dcd-803a-964a922e8c9b</guid>
    <pubDate>Tue, 27 Feb 2024 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Transparency Report 2023: 33.8% of all requests unlawful</dc:title>
    <dc:identifier>c3ba9ce7-99db-4dcd-803a-964a922e8c9b</dc:identifier>
    </item>
<item>
  <title>We are celebrating 10 years of mailbox.org!</title>
  <link>https://mailbox.org/en/news/we-are-celebrating-10-years-mailbox/</link>
  <description>&lt;p&gt;Exactly 10 years ago, mailbox.org saw the first light of day – as an ad-free and secure provider that not only offers secure e-mail addresses but also a truly comprehensive alternative to Google G Suite. Then and now, we are committed to making the Internet a better place and doing our bit for digital sovereignty in Germany and Europe. We also place very high demands on ourselves in terms of data protection and IT security. This also means that we operate our services and infrastructure entirely ourselves – with our own hardware in our own data centres – under our control.&lt;/p&gt;&lt;p&gt;This was made possible by the expertise that founder Peer Heinlein and his team brought with them from Heinlein Support GmbH. To this day, the experienced professionals at Heinlein Support enable their customers to achieve digital sovereignty by providing practical Linux consulting and training for administrators, among other things.&lt;/p&gt;&lt;p&gt;A lot has happened since the founding of mailbox.org and the introduction of the "encrypted mailbox" for private and later also business customers. We have twice been recognised as the test winner with a "very good" rating in the leading German consumer organization’s "Stiftung Warentest" e-mail provider comparison. In 2022, the German Federal Office for Information Security (BSI) awarded us the IT security label for "Secure e-mail transport" (BSI TR 03108). In the same year, mailbox.org also introduced OpenTalk - the user-friendly, modern and secure video conferencing solution from Europe. Founded as an independent company by Peer Heinlein, today a team of around 20 developers work on OpenTalk. This was also a big step on the way to our dream: to be the secure, comprehensive communication platform for everyone!&lt;/p&gt;&lt;p&gt;We have campaigned for data protection, digital sovereignty and IT security in many areas and made a difference - for example with our fight against data retention, which we took all the way to the Federal Constitutional Court.&lt;/p&gt;&lt;p&gt;Business customers have also recognised the need for digitally sovereign communication in recent years. As a result, mailbox.org has built up an exciting circle of well-known business customers, including the ComputerBase platform, the Senckenberg research organisation and SENEC. For teachers in Berlin and Thuringia, mailbox.org also provides secure e-mail addresses or the Online Suite on behalf of the respective ministries of education.&lt;/p&gt;&lt;h2&gt;Our outlook for the future&lt;/h2&gt;&lt;p&gt;This year we finally have the retread of our web interface up our sleeve, which we and our partner Open-Xchange have been working towards for over two years. This will bring many new features and a smooth, beautifully fast user interface - but more on that when the time comes.&lt;/p&gt;&lt;p&gt;We will also finally be able to switch our central authentication system completely over to OpenIDConnect, which will enable us to provide a completely revised end-to-end 2-factor authentication. We are currently setting up an official beta programme for our customers with exclusive advance access to new features for the many small and large innovations. Further details will follow shortly.&lt;/p&gt;&lt;h2&gt;Thank you to all our supporters&lt;/h2&gt;&lt;p&gt;Looking back, we would of course like to thank our many loyal supporters who have accompanied us over the past ten years. Many of you have done a lot for us, mailbox.org and "the idea" and have campaigned and taken a stand for free and secure communication with mailbox.org up and down the country, in forums, social media, with friends and acquaintances. We would like to thank our customers, some of whom have been with us since the very beginning and who continue to encourage us to keep improving with both positive and critical feedback and good ideas. We would like to thank all our companions and partners who are fighting side by side with us for digital sovereignty and free communication.&lt;/p&gt;&lt;p&gt;And we would like to thank our fantastic team, without whom mailbox.org would simply not be where it is today. Thank you for your commitment, knowledge and perseverance - for mailbox.org, for our partners and for our customers who have placed their trust in us.&lt;/p&gt;&lt;h4&gt;Thank you!&lt;/h4&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-mailbox-geburtstag.png?itok=divs983z" type="image/png" length="262374"/><guid isPermaLink="false">d34e3656-53a2-415b-bb8d-eae0eb410e75</guid>
    <pubDate>Tue, 20 Feb 2024 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>We are celebrating 10 years of mailbox.org!</dc:title>
    <dc:identifier>d34e3656-53a2-415b-bb8d-eae0eb410e75</dc:identifier>
    </item>
<item>
  <title>We are celebrating 10 years of mailbox.org!</title>
  <link>https://mailbox.org/en/news/we-are-celebrating-10-years-mailbox/</link>
  <description>&lt;p&gt;Exactly 10 years ago, mailbox.org saw the first light of day – as an ad-free and secure provider that not only offers secure e-mail addresses but also a truly comprehensive alternative to Google G Suite. Then and now, we are committed to making the Internet a better place and doing our bit for digital sovereignty in Germany and Europe. We also place very high demands on ourselves in terms of data protection and IT security. This also means that we operate our services and infrastructure entirely ourselves – with our own hardware in our own data centres – under our control.&lt;/p&gt;&lt;p&gt;This was made possible by the expertise that founder Peer Heinlein and his team brought with them from Heinlein Support GmbH. To this day, the experienced professionals at Heinlein Support enable their customers to achieve digital sovereignty by providing practical Linux consulting and training for administrators, among other things.&lt;/p&gt;&lt;p&gt;A lot has happened since the founding of mailbox.org and the introduction of the "encrypted mailbox" for private and later also business customers. We have twice been recognised as the test winner with a "very good" rating in the leading German consumer organization’s "Stiftung Warentest" e-mail provider comparison. In 2022, the German Federal Office for Information Security (BSI) awarded us the IT security label for "Secure e-mail transport" (BSI TR 03108). In the same year, mailbox.org also introduced OpenTalk - the user-friendly, modern and secure video conferencing solution from Europe. Founded as an independent company by Peer Heinlein, today a team of around 20 developers work on OpenTalk. This was also a big step on the way to our dream: to be the secure, comprehensive communication platform for everyone!&lt;/p&gt;&lt;p&gt;We have campaigned for data protection, digital sovereignty and IT security in many areas and made a difference - for example with our fight against data retention, which we took all the way to the Federal Constitutional Court.&lt;/p&gt;&lt;p&gt;Business customers have also recognised the need for digitally sovereign communication in recent years. As a result, mailbox.org has built up an exciting circle of well-known business customers, including the ComputerBase platform, the Senckenberg research organisation and SENEC. For teachers in Berlin and Thuringia, mailbox.org also provides secure e-mail addresses or the Online Suite on behalf of the respective ministries of education.&lt;/p&gt;&lt;h2&gt;Our outlook for the future&lt;/h2&gt;&lt;p&gt;This year we finally have the retread of our web interface up our sleeve, which we and our partner Open-Xchange have been working towards for over two years. This will bring many new features and a smooth, beautifully fast user interface - but more on that when the time comes.&lt;/p&gt;&lt;p&gt;We will also finally be able to switch our central authentication system completely over to OpenIDConnect, which will enable us to provide a completely revised end-to-end 2-factor authentication. We are currently setting up an official beta programme for our customers with exclusive advance access to new features for the many small and large innovations. Further details will follow shortly.&lt;/p&gt;&lt;h2&gt;Thank you to all our supporters&lt;/h2&gt;&lt;p&gt;Looking back, we would of course like to thank our many loyal supporters who have accompanied us over the past ten years. Many of you have done a lot for us, mailbox.org and "the idea" and have campaigned and taken a stand for free and secure communication with mailbox.org up and down the country, in forums, social media, with friends and acquaintances. We would like to thank our customers, some of whom have been with us since the very beginning and who continue to encourage us to keep improving with both positive and critical feedback and good ideas. We would like to thank all our companions and partners who are fighting side by side with us for digital sovereignty and free communication.&lt;/p&gt;&lt;p&gt;And we would like to thank our fantastic team, without whom mailbox.org would simply not be where it is today. Thank you for your commitment, knowledge and perseverance - for mailbox.org, for our partners and for our customers who have placed their trust in us.&lt;/p&gt;&lt;h4&gt;Thank you!&lt;/h4&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-mailbox-geburtstag.png?itok=divs983z" type="image/png" length="262374"/><guid isPermaLink="false">d34e3656-53a2-415b-bb8d-eae0eb410e75</guid>
    <pubDate>Tue, 20 Feb 2024 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>We are celebrating 10 years of mailbox.org!</dc:title>
    <dc:identifier>d34e3656-53a2-415b-bb8d-eae0eb410e75</dc:identifier>
    </item>
<item>
  <title>mailbox.org introduces new knowledge base and help desk</title>
  <link>https://mailbox.org/en/news/introducing-new-knowledge-base-and-helpdesk/</link>
  <description>&lt;p&gt;Today, we are switching the software behind our knowledge base and our helpdesk, as the previous software manufacturer has made (continued) operation on its own servers extremely expensive and therefore impossible. To protect your data in the best possible way in the future, we have now opted for Open Source software, which we can continue to operate for you in our Berlin data centres. The change of software will result in minor differences in the user interface and utilisation for you.&lt;/p&gt;&lt;h2&gt;Our update for the helpdesk&lt;/h2&gt;&lt;p&gt;Everyone needs a little help sometimes. The helpdesk is for anyone who wants to contact our mailbox.org experts with their complex questions. This service is available for customers on the PREMIUM and STANDARD plans.&lt;/p&gt;&lt;p&gt;We utilise the Open Source solution Zammad for our new helpdesk. The ticket creation process remains uncomplicated and you can see your tickets and their status in an organised view.&lt;/p&gt;&lt;p&gt;You can log in at &lt;a href="https://support.mailbox.org" target="_blank" title="Visit the helpdesk" rel="noopener"&gt;https://support.mailbox.org&lt;/a&gt; with your e-mail address and password. A new login screen awaits you here.&lt;/p&gt;&lt;h3&gt;New helpdesk login&lt;/h3&gt;&lt;img src="https://mailbox.org/sites/default/files/inline-images/news-helpdesk-update-1_0.png" data-entity-uuid="81cd8a00-3741-41ee-9da5-c29193eeee3b" data-entity-type="file" width="500" height="358" alt="Support Login" loading="lazy"&gt;&amp;nbsp;&lt;h3&gt;New helpdesk dashboard&lt;/h3&gt;&lt;img src="https://mailbox.org/sites/default/files/inline-images/news-helpdesk-update-2_0.png" data-entity-uuid="23848b98-40f1-49c4-9207-b0579e99c03c" data-entity-type="file" width="500" height="358" alt="Support Overview" loading="lazy"&gt;&amp;nbsp;&lt;p&gt;You can create a new support ticket by clicking on the + symbol. This is where all communication with our support team takes place. You also have an overview of all enquiries that have already been submitted.&lt;/p&gt;&lt;h2&gt;Our update for the knowledge base&lt;/h2&gt;&lt;p&gt;Our new knowledge base is getting fast, really fast – on desktops and smartphones. We have opted for the Open Source solution Docusaurus for our new knowledge base. With Docusaurus, our articles not only look great, but they also load efficiently and fast. The navigation is simple and clear.&lt;/p&gt;&lt;h3&gt;New knowledge base&lt;/h3&gt;&lt;img src="https://mailbox.org/sites/default/files/inline-images/news-KB-update_0.png" data-entity-uuid="9c6b3a8d-6aa0-4c08-9940-45c05ff27b17" data-entity-type="file" width="500" height="358" alt="Knowledge Base" loading="lazy"&gt;&amp;nbsp;&lt;h2&gt;We love Open Source&lt;/h2&gt;&lt;p&gt;We are committed to Open Source out of conviction and with a passion for free communication. The decision in favour of Open Source is more than just a technical preference – it is our fundamental philosophy, which places transparency, security and user-friendliness at the forefront. By using Open Source solutions, we not only have access to a wide range of proven tools but can also ensure that the services meet our high-security standards. The transparent nature of Open Source allows the community to review the code, identify vulnerabilities and collaborate on improvements.&lt;/p&gt;&lt;h2&gt;Wir sind für Sie da!&lt;/h2&gt;&lt;ul&gt;&lt;li&gt;The point of contact is still our knowledge base. &lt;a href="https://kb.mailbox.org" target="_blank" title="Visit knowledge base" rel="noopener"&gt;Visit the knowledge base →&lt;/a&gt;&lt;/li&gt;&lt;li&gt;The mailbox.org community also provides exemplary support in our user forum. &lt;a href="https://userforum.mailbox.org" target="_blank" title="Visit the user forum" rel="noopener"&gt;Visit the user forum →&lt;/a&gt;&lt;/li&gt;&lt;li&gt;For complex questions, our helpdesk is available for you in the PREMIUM or STANDARD plan. &lt;a href="https://support.mailbox.org" target="_blank" title="Visit helpdesk" rel="noopener"&gt;Visit the helpdesk →&lt;/a&gt;&lt;/li&gt;&lt;li&gt;For customers who prefer personal contact, we also offer a telephone support callback service. Telephone support can be booked via the helpdesk and is only available in the PREMIUM plan. &lt;a href="https://support.mailbox.org" target="_blank" title="Visit helpdesk" rel="noopener"&gt;Visit the helpdesk →&lt;/a&gt;&lt;/li&gt;&lt;li&gt;You can also find us on &lt;a href="https://social.mailbox.org/@mailbox_org" target="_blank" title rel="noopener"&gt;Mastodon&lt;/a&gt;, &lt;a href="https://twitter.com/mailbox_org" target="_blank" title rel="noopener"&gt;Twitter&lt;/a&gt;, &lt;a href="https://bsky.app/profile/mailbox.org" title&gt;BlueSky&lt;/a&gt; and &lt;a href="https://de.linkedin.com/company/mailbox.org" target="_blank" title rel="noopener"&gt;LinkedIn&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-support.jpg?itok=zLcWLJo1" type="image/jpeg" length="272690"/><guid isPermaLink="false">e971818d-6952-47d1-a579-7997cea26413</guid>
    <pubDate>Thu, 08 Feb 2024 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>mailbox.org introduces new knowledge base and help desk</dc:title>
    <dc:identifier>e971818d-6952-47d1-a579-7997cea26413</dc:identifier>
    </item>
<item>
  <title>mailbox.org introduces new knowledge base and help desk</title>
  <link>https://mailbox.org/en/news/introducing-new-knowledge-base-and-helpdesk/</link>
  <description>&lt;p&gt;Today, we are switching the software behind our knowledge base and our helpdesk, as the previous software manufacturer has made (continued) operation on its own servers extremely expensive and therefore impossible. To protect your data in the best possible way in the future, we have now opted for Open Source software, which we can continue to operate for you in our Berlin data centres. The change of software will result in minor differences in the user interface and utilisation for you.&lt;/p&gt;&lt;h2&gt;Our update for the helpdesk&lt;/h2&gt;&lt;p&gt;Everyone needs a little help sometimes. The helpdesk is for anyone who wants to contact our mailbox.org experts with their complex questions. This service is available for customers on the PREMIUM and STANDARD plans.&lt;/p&gt;&lt;p&gt;We utilise the Open Source solution Zammad for our new helpdesk. The ticket creation process remains uncomplicated and you can see your tickets and their status in an organised view.&lt;/p&gt;&lt;p&gt;You can log in at &lt;a href="https://support.mailbox.org" target="_blank" title="Visit the helpdesk" rel="noopener"&gt;https://support.mailbox.org&lt;/a&gt; with your e-mail address and password. A new login screen awaits you here.&lt;/p&gt;&lt;h3&gt;New helpdesk login&lt;/h3&gt;&lt;img src="https://mailbox.org/sites/default/files/inline-images/news-helpdesk-update-1_0.png" data-entity-uuid="81cd8a00-3741-41ee-9da5-c29193eeee3b" data-entity-type="file" width="500" height="358" alt="Support Login" loading="lazy"&gt;&amp;nbsp;&lt;h3&gt;New helpdesk dashboard&lt;/h3&gt;&lt;img src="https://mailbox.org/sites/default/files/inline-images/news-helpdesk-update-2_0.png" data-entity-uuid="23848b98-40f1-49c4-9207-b0579e99c03c" data-entity-type="file" width="500" height="358" alt="Support Overview" loading="lazy"&gt;&amp;nbsp;&lt;p&gt;You can create a new support ticket by clicking on the + symbol. This is where all communication with our support team takes place. You also have an overview of all enquiries that have already been submitted.&lt;/p&gt;&lt;h2&gt;Our update for the knowledge base&lt;/h2&gt;&lt;p&gt;Our new knowledge base is getting fast, really fast – on desktops and smartphones. We have opted for the Open Source solution Docusaurus for our new knowledge base. With Docusaurus, our articles not only look great, but they also load efficiently and fast. The navigation is simple and clear.&lt;/p&gt;&lt;h3&gt;New knowledge base&lt;/h3&gt;&lt;img src="https://mailbox.org/sites/default/files/inline-images/news-KB-update_0.png" data-entity-uuid="9c6b3a8d-6aa0-4c08-9940-45c05ff27b17" data-entity-type="file" width="500" height="358" alt="Knowledge Base" loading="lazy"&gt;&amp;nbsp;&lt;h2&gt;We love Open Source&lt;/h2&gt;&lt;p&gt;We are committed to Open Source out of conviction and with a passion for free communication. The decision in favour of Open Source is more than just a technical preference – it is our fundamental philosophy, which places transparency, security and user-friendliness at the forefront. By using Open Source solutions, we not only have access to a wide range of proven tools but can also ensure that the services meet our high-security standards. The transparent nature of Open Source allows the community to review the code, identify vulnerabilities and collaborate on improvements.&lt;/p&gt;&lt;h2&gt;Wir sind für Sie da!&lt;/h2&gt;&lt;ul&gt;&lt;li&gt;The point of contact is still our knowledge base. &lt;a href="https://kb.mailbox.org" target="_blank" title="Visit knowledge base" rel="noopener"&gt;Visit the knowledge base →&lt;/a&gt;&lt;/li&gt;&lt;li&gt;The mailbox.org community also provides exemplary support in our user forum. &lt;a href="https://userforum.mailbox.org" target="_blank" title="Visit the user forum" rel="noopener"&gt;Visit the user forum →&lt;/a&gt;&lt;/li&gt;&lt;li&gt;For complex questions, our helpdesk is available for you in the PREMIUM or STANDARD plan. &lt;a href="https://support.mailbox.org" target="_blank" title="Visit helpdesk" rel="noopener"&gt;Visit the helpdesk →&lt;/a&gt;&lt;/li&gt;&lt;li&gt;For customers who prefer personal contact, we also offer a telephone support callback service. Telephone support can be booked via the helpdesk and is only available in the PREMIUM plan. &lt;a href="https://support.mailbox.org" target="_blank" title="Visit helpdesk" rel="noopener"&gt;Visit the helpdesk →&lt;/a&gt;&lt;/li&gt;&lt;li&gt;You can also find us on &lt;a href="https://social.mailbox.org/@mailbox_org" target="_blank" title rel="noopener"&gt;Mastodon&lt;/a&gt;, &lt;a href="https://twitter.com/mailbox_org" target="_blank" title rel="noopener"&gt;Twitter&lt;/a&gt;, &lt;a href="https://bsky.app/profile/mailbox.org" title&gt;BlueSky&lt;/a&gt; and &lt;a href="https://de.linkedin.com/company/mailbox.org" target="_blank" title rel="noopener"&gt;LinkedIn&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-support.jpg?itok=zLcWLJo1" type="image/jpeg" length="272690"/><guid isPermaLink="false">e971818d-6952-47d1-a579-7997cea26413</guid>
    <pubDate>Thu, 08 Feb 2024 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>mailbox.org introduces new knowledge base and help desk</dc:title>
    <dc:identifier>e971818d-6952-47d1-a579-7997cea26413</dc:identifier>
    </item>
<item>
  <title>Use of e-mail continuity in the event of ransomware attacks</title>
  <link>https://mailbox.org/en/blog/e-mail-continuity-for-ransomware-attacks/</link>
  <description>&lt;p&gt;&lt;em&gt;Reading time: 6 minutes&lt;/em&gt;&lt;/p&gt;&lt;p&gt;Cyberattacks are a threat to every company these days. Although there are increasingly frequent reports in the media about extensive ransomware attacks and how they affect IT companies and their customers, but the number of unreported cases is probably much higher.&lt;/p&gt;


      
                  
              
              
              
              
              
              
              
                  &lt;img loading="lazy" height="1219" width="2200" src="https://mailbox.org/sites/default/files/2025-05/mailbox_evac_infrastruktur_web_rgb.jpg" alt="EVAC Button"&gt;

  


  
          

              


  
    
    
    
    &lt;p&gt;Companies face considerable problems with ransomware attacks. The immediate challenge is the disruption to day-to-day business and, in particular, the massive disruption to email communication, which is essential for normal business operations today. Customer orders can't come in, own orders can't go out, agreements with customers or within the team can't be made. E-mails have simply become indispensable. In addition, such attacks harbour serious security and data protection risks. This makes ransomware attacks a particularly dangerous threat for companies. One possible safeguard in the event of an emergency is to set up an e-mail continuity service in advance.&lt;/p&gt;

          
                                                  
      


  &lt;h2 class="referent__title"&gt;&lt;/h2&gt;
  
                
        
                    
            
                          &lt;h3 class="referent__headline"&gt;
                What is a ransomware attack?
                              &lt;/h3&gt;
            
            
                          &lt;p&gt;A ransomware attack is a type of cyberattack in which malicious software (ransomware) is used to block or encrypt access to data or systems. A ransom is then demanded from the affected company.&lt;/p&gt;&lt;p&gt;These attacks often begin with infection through phishing e-mail, infected software downloads or exploited security vulnerabilities. After infection, the ransomware encrypts important data on the system and demands a ransom, usually in cryptocurrency, for its release. The attackers threaten permanent data loss, publication on the darknet or further damage if the ransom is not paid.&lt;/p&gt;&lt;p&gt;This is particularly threatening for companies, as it not only results in financial damage and possible loss of business but also harbours data loss, loss of reputation and potential legal consequences. Companies should therefore rely on regular security updates, training their employees in dealing with phishing attempts and regular data backups to protect themselves against such attacks.&lt;/p&gt;
                        
        
      
      

              


  
    
    
    
    &lt;h2&gt;E-mail continuity as insurance for emergencies&lt;/h2&gt;&lt;p&gt;E-mail continuity refers to systems and measures that ensure that a company's e-mail service continues to function even in the event of a failure, such as technical problems or cyber-attacks. The aim is to maintain e-mail traffic without major interruptions or data loss.&lt;/p&gt;&lt;p&gt;You can think of it like an insurance for e-mail: If the normal e-mail system is down for any reason, e-mail continuity is activated so that employees can continue to send and receive e-mails. This is especially important in organisations where e-mail communication is critical to daily operations.&lt;/p&gt;&lt;h3&gt;What is e-mail continuity?&lt;/h3&gt;&lt;p&gt;With an e-mail continuity service, mailboxes are prepared in advance for all employees. These clean e-mail inboxes can be activated in the event of a crisis to ensure that e-mails can be received and sent without major interruption. They run on their IT infrastructure and are not connected to the company's systems and services. The mailboxes are accessed via a webmailer, which only requires a normal browser. This means that secure e-mail communication is quickly restored.&lt;/p&gt;&lt;h3&gt;In which scenarios does e-mail continuity help?&lt;/h3&gt;&lt;p&gt;E-mail continuity helps in various scenarios, especially in situations where a company's normal e-mail communication is interrupted. Some examples are:&lt;/p&gt;&lt;ol&gt;&lt;li&gt;Technical disruptions: including server failures, power outages, hardware problems or a fire in the data centre&lt;/li&gt;&lt;li&gt;Cyber attacks: In the event of ransomware attacks, viruses or other cyber threats&lt;/li&gt;&lt;li&gt;Security vulnerabilities: Through attack vectors or compromise of the existing solution&lt;/li&gt;&lt;li&gt;Natural disasters: In the event of events such as floods, earthquakes or severe storms that can damage physical infrastructure&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;h2&gt;E-Mail continuity with EVAC by mailbox&lt;/h2&gt;&lt;p&gt;With &lt;a href="https://mailbox.org/en/evac/" data-entity-type="node" data-entity-uuid="8d62b38c-25b3-4011-a5f2-de2d2e58cc87" data-entity-substitution="canonical" title="EVAC: Business continuity in an emergency"&gt;EVAC&lt;/a&gt;, mailbox has developed a business continuity solution that protects your company against such threat scenarios. If your primary system fails, you can activate the secondary communication platform EVAC at the touch of a button. With a single click, you and your teams immediately have access to secure and uncompromised emergency mailboxes, video conferencing and cloud storage, calendars, task management and office tools. This ensures you remain operational even in an emergency.&lt;/p&gt;

          
                                                  
      


  
    
      &lt;h2 class="ticket__title"&gt;Business continuity at the touch of a button&lt;/h2&gt;
              

&lt;a data-component-id="boxy:knob" data-component-variant="tertiary" class="knob knob--tertiary" href="https://mailbox.org/en/evac/"&gt;Discover EVAC now&lt;/a&gt;

          
    
          
                  
              
                  &lt;img loading="lazy" height="1632" width="2944" src="https://mailbox.org/sites/default/files/2025-04/mailbox-evac-button-web-rgb.jpg" alt="Kommunikation auf Knopfdruck"&gt;

  


    
  



      
      &lt;h2 class="row__intro__title"&gt;            Insights &amp;amp; trends
      &lt;/h2&gt;
      Discover further best practices for your digital security.
              
            

&lt;a data-component-id="boxy:knob" data-component-variant="secondary" class="knob knob--secondary" href="https://mailbox.org/en/insights/"&gt;All articles&lt;/a&gt;

        
          
    
      
      
  
  
                    
                  
              
                  &lt;img loading="lazy" height="2160" width="4096" src="https://mailbox.org/sites/default/files/2026-08/mailbox%20EVAC%20Blog%20IT-Sicherheit%20kleine%20Unternehmen.jpeg" alt="mailbox EVAC Blog IT-Sicherheit kleine Unternehmen"&gt;

  


      
      
      
      Business Continuitiy, Security
    
    &lt;h3 class="snip__title"&gt;IT security: Why small businesses in particular are targeted by cyberattacks&lt;/h3&gt;
  &lt;a class="snip__arrow" href="https://mailbox.org/en/blog/IT-security-for-small-businesses/" aria-hidden="true"&gt;→&lt;/a&gt;
  &lt;a class="snip__link" href="https://mailbox.org/en/blog/IT-security-for-small-businesses/"&gt;Read more about &lt;em class="placeholder"&gt;IT security: Why small businesses in particular are targeted by cyberattacks&lt;/em&gt;&lt;/a&gt;


    
      
      
  
  
                    
                  
              
                  &lt;img loading="lazy" height="2160" width="4096" src="https://mailbox.org/sites/default/files/2026-08/mailbox%20EVAC%20Blog%20Business%20Continuity%20in%20der%20Lieferkette.jpeg" alt="mailbox EVAC Blog Business Continuity in der Lieferkette"&gt;

  


      
      
      
      Best practice, Business Continuitiy
    
    &lt;h3 class="snip__title"&gt;How to use business continuity as a competitive advantage in the supply chain&lt;/h3&gt;
  &lt;a class="snip__arrow" href="https://mailbox.org/en/blog/business-continuity-supply-chain/" aria-hidden="true"&gt;→&lt;/a&gt;
  &lt;a class="snip__link" href="https://mailbox.org/en/blog/business-continuity-supply-chain/"&gt;Read more about &lt;em class="placeholder"&gt;How to use business continuity as a competitive advantage in the supply chain&lt;/em&gt;&lt;/a&gt;


    
  
  


</description>
  <guid isPermaLink="false">e5d32c68-2134-47e1-8914-6f7dbb20b164</guid>
    <pubDate>Thu, 18 Jan 2024 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Use of e-mail continuity in the event of ransomware attacks</dc:title>
    <dc:identifier>e5d32c68-2134-47e1-8914-6f7dbb20b164</dc:identifier>
    </item>
<item>
  <title>Warning: New Outlook transfers passwords and data to Microsoft</title>
  <link>https://mailbox.org/en/news/warning-new-outlook-sends-passwords-mails-and-other-data-microsoft/</link>
  <description>&lt;p&gt;&lt;a href="https://www.heise.de/news/Microsoft-krallt-sich-Zugangsdaten-Achtung-vorm-neuen-Outlook-9357691.html" target="_blank" title rel="noopener"&gt;"Microsoft steals access data"&lt;/a&gt; - When the well-known German IT portal "Heise Online" uses such drastic words in its headline, then something is up. If Microsoft has its way, all Windows users will have to switch to the latest version of Microsoft Outlook. But: Not only can the IMAP and SMTP access data of your e-mail account be transferred to Microsoft, but all e-mails in the INBOX can also be copied to the Microsoft servers, even if you have your mailbox with a completely different provider such as mailbox.org.&lt;/p&gt;&lt;h3&gt;Main risk: Transferring your data to Microsoft "Synchronisation with the Microsoft server" - and everything is copied!&lt;/h3&gt;&lt;p&gt;If you set up a new account in the software, Microsoft offers a supposed security function: It says that non-Microsoft accounts are synchronised with the Microsoft cloud and that copies of "emails, calendars and contacts are therefore synchronised between your email provider and Microsoft data centres".&lt;/p&gt;&lt;p&gt;Anyone who reads this carefully may be perplexed, no question. But we all know how easy it is to agree to supposed banalities without reading them and to click away notices, especially when setting up software. In view of the drastic consequences of giving consent here, the warnings and explanations from Microsoft are probably too inconspicuous. Only a few users will realise that they are giving Microsoft comprehensive access to passwords, mail and more. Therefore, once again clearly:&lt;/p&gt;&lt;p&gt;Microsoft gets full access to mails, calendars and contacts!&lt;/p&gt;&lt;p&gt;But not only Windows users are at risk: Outlook versions for iOS, Mac and even Android are also affected, according to Heise.&lt;/p&gt;&lt;h3&gt;mailbox.org warns against using the new Microsoft Outlook&lt;/h3&gt;&lt;p&gt;mailbox.org warns its users: there is a high risk that sensitive data may be transmitted to Microsoft when using the new Outlook! And by the way: this compromised data includes not only emails, but also calendar and contact data.&lt;/p&gt;&lt;p&gt;For business customers, storing personal data in this way (albeit unintentionally) may constitute a GDPR offence that is subject to fines. After all, storing data in the Microsoft cloud legally constitutes data processing that requires the conclusion of an order data processing agreement (DPA) with Microsoft - and companies may have to identify this as such in their data protection declarations and in the data processing directory. It is irrelevant whether this is done intentionally by the company management or ultimately through the uninformed consent of an individual employee.&lt;/p&gt;&lt;h3&gt;Our recommendation&lt;/h3&gt;&lt;p&gt;Whether business or private: We strongly advise all our customers not to use the new Outlook! And we have the following alternatives for you:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Another e-mail client: We advise you to switch to the popular e-mail client "Thunderbird" on your computer. This is compatible with Windows and easy to set up. On mobile devices, there are a number of different IMAP mail clients, such as FairEmail and K9 Mail (which will also be called Thunderbird in the future).&lt;/li&gt;&lt;li&gt;Using the webmailer: As a mailbox.org customer, you can use our secure webmail portal at any time, which offers an excellent alternative to desktop email clients. In addition to mail, calendar and contacts, you also have secure access to files and Office documents - and your personal video conference with OpenTalk is just a click away.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;We do everything we can to protect the security and privacy of your e-mail communication. But we also need your help: make sure you use apps from providers that respect and protect your privacy and security.&lt;/p&gt;&lt;h3&gt;Update&lt;/h3&gt;&lt;p&gt;The German Federal Commissioner for Data Protection and Freedom of Information, Ulrich Kelber, is also alarmed: On the &lt;a href="https://social.mailbox.org/@bfdi@social.bund.de/111381793879390891" target="_blank" title="social media network Mastodon" rel="noopener"&gt;social media network Mastodon&lt;/a&gt;, he described the data collection as "alarming" and announced his intention to pursue the issue at European level through the data protection authorities as early as next Tuesday.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-04/mailbox-news-und-updates-warnung.jpg?itok=reW9cU74" type="image/jpeg" length="238141"/><guid isPermaLink="false">eec8c2ff-3c48-41c7-b672-e7c119f7bd0a</guid>
    <pubDate>Fri, 10 Nov 2023 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Warning: New Outlook transfers passwords and data to Microsoft</dc:title>
    <dc:identifier>eec8c2ff-3c48-41c7-b672-e7c119f7bd0a</dc:identifier>
    </item>
<item>
  <title>Warning: New Outlook transfers passwords and data to Microsoft</title>
  <link>https://mailbox.org/en/news/warning-new-outlook-sends-passwords-mails-and-other-data-microsoft/</link>
  <description>&lt;p&gt;&lt;a href="https://www.heise.de/news/Microsoft-krallt-sich-Zugangsdaten-Achtung-vorm-neuen-Outlook-9357691.html" target="_blank" title rel="noopener"&gt;"Microsoft steals access data"&lt;/a&gt; - When the well-known German IT portal "Heise Online" uses such drastic words in its headline, then something is up. If Microsoft has its way, all Windows users will have to switch to the latest version of Microsoft Outlook. But: Not only can the IMAP and SMTP access data of your e-mail account be transferred to Microsoft, but all e-mails in the INBOX can also be copied to the Microsoft servers, even if you have your mailbox with a completely different provider such as mailbox.org.&lt;/p&gt;&lt;h3&gt;Main risk: Transferring your data to Microsoft "Synchronisation with the Microsoft server" - and everything is copied!&lt;/h3&gt;&lt;p&gt;If you set up a new account in the software, Microsoft offers a supposed security function: It says that non-Microsoft accounts are synchronised with the Microsoft cloud and that copies of "emails, calendars and contacts are therefore synchronised between your email provider and Microsoft data centres".&lt;/p&gt;&lt;p&gt;Anyone who reads this carefully may be perplexed, no question. But we all know how easy it is to agree to supposed banalities without reading them and to click away notices, especially when setting up software. In view of the drastic consequences of giving consent here, the warnings and explanations from Microsoft are probably too inconspicuous. Only a few users will realise that they are giving Microsoft comprehensive access to passwords, mail and more. Therefore, once again clearly:&lt;/p&gt;&lt;p&gt;Microsoft gets full access to mails, calendars and contacts!&lt;/p&gt;&lt;p&gt;But not only Windows users are at risk: Outlook versions for iOS, Mac and even Android are also affected, according to Heise.&lt;/p&gt;&lt;h3&gt;mailbox.org warns against using the new Microsoft Outlook&lt;/h3&gt;&lt;p&gt;mailbox.org warns its users: there is a high risk that sensitive data may be transmitted to Microsoft when using the new Outlook! And by the way: this compromised data includes not only emails, but also calendar and contact data.&lt;/p&gt;&lt;p&gt;For business customers, storing personal data in this way (albeit unintentionally) may constitute a GDPR offence that is subject to fines. After all, storing data in the Microsoft cloud legally constitutes data processing that requires the conclusion of an order data processing agreement (DPA) with Microsoft - and companies may have to identify this as such in their data protection declarations and in the data processing directory. It is irrelevant whether this is done intentionally by the company management or ultimately through the uninformed consent of an individual employee.&lt;/p&gt;&lt;h3&gt;Our recommendation&lt;/h3&gt;&lt;p&gt;Whether business or private: We strongly advise all our customers not to use the new Outlook! And we have the following alternatives for you:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Another e-mail client: We advise you to switch to the popular e-mail client "Thunderbird" on your computer. This is compatible with Windows and easy to set up. On mobile devices, there are a number of different IMAP mail clients, such as FairEmail and K9 Mail (which will also be called Thunderbird in the future).&lt;/li&gt;&lt;li&gt;Using the webmailer: As a mailbox.org customer, you can use our secure webmail portal at any time, which offers an excellent alternative to desktop email clients. In addition to mail, calendar and contacts, you also have secure access to files and Office documents - and your personal video conference with OpenTalk is just a click away.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;We do everything we can to protect the security and privacy of your e-mail communication. But we also need your help: make sure you use apps from providers that respect and protect your privacy and security.&lt;/p&gt;&lt;h3&gt;Update&lt;/h3&gt;&lt;p&gt;The German Federal Commissioner for Data Protection and Freedom of Information, Ulrich Kelber, is also alarmed: On the &lt;a href="https://social.mailbox.org/@bfdi@social.bund.de/111381793879390891" target="_blank" title="social media network Mastodon" rel="noopener"&gt;social media network Mastodon&lt;/a&gt;, he described the data collection as "alarming" and announced his intention to pursue the issue at European level through the data protection authorities as early as next Tuesday.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-04/mailbox-news-und-updates-warnung.jpg?itok=reW9cU74" type="image/jpeg" length="238141"/><guid isPermaLink="false">eec8c2ff-3c48-41c7-b672-e7c119f7bd0a</guid>
    <pubDate>Fri, 10 Nov 2023 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Warning: New Outlook transfers passwords and data to Microsoft</dc:title>
    <dc:identifier>eec8c2ff-3c48-41c7-b672-e7c119f7bd0a</dc:identifier>
    </item>
<item>
  <title>New feature: mailbox.org introduces S/MIME</title>
  <link>https://mailbox.org/en/news/new-feature-mailboxorg-introduces-smime-webmailer/</link>
  <description>&lt;p&gt;We are working constantly to strengthen the security of our users. As of now, S/MIME is supported as an additional security measure for the webmailer. With this new feature, users can encrypt their emails and use digital signatures to ensure the confidentiality, integrity and authenticity of their messages. In this blog article, we will explain the benefits of S/MIME and how you can use it on your mailbox.org account.&lt;/p&gt;&lt;p&gt;Especially for business customers, not only the encryption of emails plays a very important role, but also the digital signature. The introduction of S/MIME is therefore particularly relevant for corporate e-mail accounts. Business and private customers on the PREMIUM, STANDARD and LIGHT plans can use the new feature.&lt;/p&gt;&lt;h2&gt;What is S/MIME and how does it contribute to email security?&lt;/h2&gt;&lt;h3&gt;What is S/MIME?&lt;/h3&gt;&lt;p&gt;S/MIME (Secure/Multipurpose Internet Mail Extensions) is a security standard for the encryption and digital signature of emails. It enables the secure transmission of confidential information over the Internet and guarantees the authenticity and integrity of emails.&lt;/p&gt;&lt;p&gt;S/MIME is based on the public-key cryptosystem, in which each user has a pair of keys - a public key for encrypting messages and a private key for decrypting messages and creating digital signatures. The public key is passed on to other users, while the private key is kept secret.&lt;/p&gt;&lt;p&gt;The use of S/MIME offers several advantages:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Confidentiality: by encrypting emails, only the intended recipient and sender can read the content.&lt;/li&gt;&lt;li&gt;Integrity: The digital signature allows the recipient to check whether the message has been tampered with during transmission.&lt;/li&gt;&lt;li&gt;Authenticity: The digital signature enables the recipient to verify the identity of the sender and ensure that the message actually comes from the person specified.&lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;How S/MIME contributes to email security&lt;/h3&gt;&lt;p&gt;With S/MIME, emails can be encrypted so that only the intended recipient can read the content. This provides protection against unauthorised access to confidential information during transmission. Encryption is carried out using the recipient's public key, which can only be decrypted by the recipient.&lt;/p&gt;&lt;p&gt;Another contribution to security is the digital signature. The digital signature enables the recipient of an e-mail to check whether the message has been tampered with during transmission. The digital signature uses the sender's private key to digitally sign the e-mail. The recipient can then use the sender's public key to verify the signature and ensure that the message actually originates from the specified person and has not been altered.&lt;/p&gt;&lt;p&gt;S/MIME also contributes to authenticity. The digital signature allows the recipient to verify the identity of the sender and ensure that the message actually originates from the specified person. This is particularly important when it comes to confidential or business communications where the identity of the sender is crucial.&lt;/p&gt;&lt;h3&gt;The difference between S/MIME and PGP&lt;/h3&gt;&lt;p&gt;S/MIME and PGP (Pretty Good Privacy) or GPG (GNU Privacy Guard) are two different standards for securing emails.&lt;/p&gt;&lt;p&gt;Both S/MIME and PGP/GPG offer encryption and digital signatures for emails. However, the main difference lies in the way they are implemented and how they are used.&lt;/p&gt;&lt;p&gt;S/MIME is closely linked to X.509 certificates issued by certification authorities. These certificates contain the user's public key and enable verification of the sender's identity and encryption of messages. S/MIME is integrated into many email clients and services and usually requires certificates to be set up and managed.&lt;/p&gt;&lt;p&gt;PGP and GPG, on the other hand, use a web-of-trust model where users can create their own key pairs and sign the public keys. This enables verification of the sender's identity and encryption of messages. PGP and GPG are usually open-source software and require the installation of a separate program or plugin. They are not as widely used as S/MIME but offer greater flexibility and control over the encryption process.&lt;/p&gt;&lt;p&gt;Another difference is that S/MIME is integrated directly into the email client and does not normally require any additional software installation. PGP and GPG, on the other hand, require the use of a separate program or plugin to perform the encryption and digital signature.&lt;/p&gt;&lt;p&gt;It is also important to note that S/MIME and PGP/GPG use different certification authorities and key management systems. S/MIME is based on the X.509 standard for certificates, while PGP/GPG uses the web-of-trust model.&lt;/p&gt;&lt;p&gt;In terms of security, both S/MIME and PGP/GPG offer strong encryption and digital signatures. The choice between the two depends on individual requirements, the level of control and trust in the certification authorities.&lt;/p&gt;&lt;h2&gt;Supported S/MIME certificates in the mailbox.org webmailer&lt;/h2&gt;&lt;p&gt;To use S/MIME, a valid certificate is required for each address. The following certificates are supported:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Thawte&lt;/li&gt;&lt;li&gt;VeriSign&lt;/li&gt;&lt;li&gt;DigiCert&lt;/li&gt;&lt;li&gt;and over 100 other certificates from other providers. &lt;a href="https://kb.mailbox.org/en/private/security-privacy-article/s-mime-encryption" target="_blank" title="knowledge base: S/MIME Encryption" rel="noopener"&gt;You can find out more in our knowledge base -&amp;gt;&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Attention: Self-created certificates are not accepted!&lt;/p&gt;&lt;h2&gt;S/MIME for mailbox.org business and private customers&lt;/h2&gt;&lt;h3 id="S/MIMEEinführung-SettingupS/MIMEinthemailbox.orgwebmailer"&gt;Setting up S/MIME in the mailbox.org webmailer&lt;/h3&gt;&lt;p&gt;To set up, you need a separate certificate for each e-mail address (and each alias) and can upload this in the webmailer.&lt;br&gt;To set it up in an external email client (e.g. Thunderbird, Outlook or Mail App), the certificate must be stored there separately.&lt;/p&gt;&lt;p&gt;&lt;a href="https://kb.mailbox.org/en/private/security-privacy-article/s-mime-encryption" target="_blank" title="knowledge base: S/MIME Encryption" rel="noopener"&gt;Find out more about setting up S/MIME in our knowledge base -&amp;gt;&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;Using S/MIME in the mailbox.org webmailer&lt;/h3&gt;&lt;p&gt;There is a new button for using S/MIME, which is simply selected when sending the email. When receiving S/MIME-signed emails, please note that only the certificates listed above are supported.&lt;/p&gt;&lt;p&gt;&lt;a href="https://kb.mailbox.org/en/private/security-privacy-article/s-mime-encryption" target="_blank" title="knowledge base: S/MIME Encryption" rel="noopener"&gt;Find out more about using S/MIME in our knowledge base -&amp;gt;&lt;/a&gt;&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-envelope-1.png?itok=ahABjshn" type="image/png" length="394797"/><guid isPermaLink="false">07ecd3ea-8381-4f34-b19b-3c01a6c01e89</guid>
    <pubDate>Thu, 09 Nov 2023 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>New feature: mailbox.org introduces S/MIME</dc:title>
    <dc:identifier>07ecd3ea-8381-4f34-b19b-3c01a6c01e89</dc:identifier>
    </item>
<item>
  <title>New feature: mailbox.org introduces S/MIME</title>
  <link>https://mailbox.org/en/news/new-feature-mailboxorg-introduces-smime-webmailer/</link>
  <description>&lt;p&gt;We are working constantly to strengthen the security of our users. As of now, S/MIME is supported as an additional security measure for the webmailer. With this new feature, users can encrypt their emails and use digital signatures to ensure the confidentiality, integrity and authenticity of their messages. In this blog article, we will explain the benefits of S/MIME and how you can use it on your mailbox.org account.&lt;/p&gt;&lt;p&gt;Especially for business customers, not only the encryption of emails plays a very important role, but also the digital signature. The introduction of S/MIME is therefore particularly relevant for corporate e-mail accounts. Business and private customers on the PREMIUM, STANDARD and LIGHT plans can use the new feature.&lt;/p&gt;&lt;h2&gt;What is S/MIME and how does it contribute to email security?&lt;/h2&gt;&lt;h3&gt;What is S/MIME?&lt;/h3&gt;&lt;p&gt;S/MIME (Secure/Multipurpose Internet Mail Extensions) is a security standard for the encryption and digital signature of emails. It enables the secure transmission of confidential information over the Internet and guarantees the authenticity and integrity of emails.&lt;/p&gt;&lt;p&gt;S/MIME is based on the public-key cryptosystem, in which each user has a pair of keys - a public key for encrypting messages and a private key for decrypting messages and creating digital signatures. The public key is passed on to other users, while the private key is kept secret.&lt;/p&gt;&lt;p&gt;The use of S/MIME offers several advantages:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Confidentiality: by encrypting emails, only the intended recipient and sender can read the content.&lt;/li&gt;&lt;li&gt;Integrity: The digital signature allows the recipient to check whether the message has been tampered with during transmission.&lt;/li&gt;&lt;li&gt;Authenticity: The digital signature enables the recipient to verify the identity of the sender and ensure that the message actually comes from the person specified.&lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;How S/MIME contributes to email security&lt;/h3&gt;&lt;p&gt;With S/MIME, emails can be encrypted so that only the intended recipient can read the content. This provides protection against unauthorised access to confidential information during transmission. Encryption is carried out using the recipient's public key, which can only be decrypted by the recipient.&lt;/p&gt;&lt;p&gt;Another contribution to security is the digital signature. The digital signature enables the recipient of an e-mail to check whether the message has been tampered with during transmission. The digital signature uses the sender's private key to digitally sign the e-mail. The recipient can then use the sender's public key to verify the signature and ensure that the message actually originates from the specified person and has not been altered.&lt;/p&gt;&lt;p&gt;S/MIME also contributes to authenticity. The digital signature allows the recipient to verify the identity of the sender and ensure that the message actually originates from the specified person. This is particularly important when it comes to confidential or business communications where the identity of the sender is crucial.&lt;/p&gt;&lt;h3&gt;The difference between S/MIME and PGP&lt;/h3&gt;&lt;p&gt;S/MIME and PGP (Pretty Good Privacy) or GPG (GNU Privacy Guard) are two different standards for securing emails.&lt;/p&gt;&lt;p&gt;Both S/MIME and PGP/GPG offer encryption and digital signatures for emails. However, the main difference lies in the way they are implemented and how they are used.&lt;/p&gt;&lt;p&gt;S/MIME is closely linked to X.509 certificates issued by certification authorities. These certificates contain the user's public key and enable verification of the sender's identity and encryption of messages. S/MIME is integrated into many email clients and services and usually requires certificates to be set up and managed.&lt;/p&gt;&lt;p&gt;PGP and GPG, on the other hand, use a web-of-trust model where users can create their own key pairs and sign the public keys. This enables verification of the sender's identity and encryption of messages. PGP and GPG are usually open-source software and require the installation of a separate program or plugin. They are not as widely used as S/MIME but offer greater flexibility and control over the encryption process.&lt;/p&gt;&lt;p&gt;Another difference is that S/MIME is integrated directly into the email client and does not normally require any additional software installation. PGP and GPG, on the other hand, require the use of a separate program or plugin to perform the encryption and digital signature.&lt;/p&gt;&lt;p&gt;It is also important to note that S/MIME and PGP/GPG use different certification authorities and key management systems. S/MIME is based on the X.509 standard for certificates, while PGP/GPG uses the web-of-trust model.&lt;/p&gt;&lt;p&gt;In terms of security, both S/MIME and PGP/GPG offer strong encryption and digital signatures. The choice between the two depends on individual requirements, the level of control and trust in the certification authorities.&lt;/p&gt;&lt;h2&gt;Supported S/MIME certificates in the mailbox.org webmailer&lt;/h2&gt;&lt;p&gt;To use S/MIME, a valid certificate is required for each address. The following certificates are supported:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Thawte&lt;/li&gt;&lt;li&gt;VeriSign&lt;/li&gt;&lt;li&gt;DigiCert&lt;/li&gt;&lt;li&gt;and over 100 other certificates from other providers. &lt;a href="https://kb.mailbox.org/en/private/security-privacy-article/s-mime-encryption" target="_blank" title="knowledge base: S/MIME Encryption" rel="noopener"&gt;You can find out more in our knowledge base -&amp;gt;&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Attention: Self-created certificates are not accepted!&lt;/p&gt;&lt;h2&gt;S/MIME for mailbox.org business and private customers&lt;/h2&gt;&lt;h3 id="S/MIMEEinführung-SettingupS/MIMEinthemailbox.orgwebmailer"&gt;Setting up S/MIME in the mailbox.org webmailer&lt;/h3&gt;&lt;p&gt;To set up, you need a separate certificate for each e-mail address (and each alias) and can upload this in the webmailer.&lt;br&gt;To set it up in an external email client (e.g. Thunderbird, Outlook or Mail App), the certificate must be stored there separately.&lt;/p&gt;&lt;p&gt;&lt;a href="https://kb.mailbox.org/en/private/security-privacy-article/s-mime-encryption" target="_blank" title="knowledge base: S/MIME Encryption" rel="noopener"&gt;Find out more about setting up S/MIME in our knowledge base -&amp;gt;&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;Using S/MIME in the mailbox.org webmailer&lt;/h3&gt;&lt;p&gt;There is a new button for using S/MIME, which is simply selected when sending the email. When receiving S/MIME-signed emails, please note that only the certificates listed above are supported.&lt;/p&gt;&lt;p&gt;&lt;a href="https://kb.mailbox.org/en/private/security-privacy-article/s-mime-encryption" target="_blank" title="knowledge base: S/MIME Encryption" rel="noopener"&gt;Find out more about using S/MIME in our knowledge base -&amp;gt;&lt;/a&gt;&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-envelope-1.png?itok=ahABjshn" type="image/png" length="394797"/><guid isPermaLink="false">07ecd3ea-8381-4f34-b19b-3c01a6c01e89</guid>
    <pubDate>Thu, 09 Nov 2023 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>New feature: mailbox.org introduces S/MIME</dc:title>
    <dc:identifier>07ecd3ea-8381-4f34-b19b-3c01a6c01e89</dc:identifier>
    </item>
<item>
  <title>Exchange platform for BlueSky invitation codes</title>
  <link>https://mailbox.org/en/news/mailboxorg-opens-bluesky-invitation-code-exchange-platform/</link>
  <description>&lt;p&gt;The takeover by Elon Musk has changed Twitter - now also known as X - dramatically. Less stringent moderation by the X/Twitter team, more radical communication and botnets posing as X/Twitter users and abusing the platform are just some of the effects. In response, many users worldwide sought refuge in the federated network Mastodon. We are also represented there with our accounts and our own instances via mailbox.org, OpenTalk and Heinlein Support. Mastodon's decentralized approach offers numerous advantages for a robust, uncensored network.&lt;/p&gt;&lt;h2&gt;Mastodon as a Twitter alternative?&lt;/h2&gt;&lt;p&gt;However, many X/Twitter users struggle with Mastodon and have not yet fully embraced it. Commercial or professional accounts have been very hesitant to switch to Mastodon. Despite their dissatisfaction, many users remain with X/Twitter, as Mastodon has unfortunately not yet been able to achieve the desired popularity.&lt;/p&gt;&lt;h2&gt;New perspectives through BlueSky&lt;/h2&gt;&lt;p&gt;BlueSky has been bringing a breath of fresh air to the social media landscape for a few weeks now. This platform was launched by Twitter founder and former CEO Jack Dorsey and is similar to Twitter in many respects, but also has its own unique approach. Today's BlueSky platform looks very similar to Twitter.&lt;/p&gt;&lt;h3&gt;Professionals are increasingly switching to BlueSky&lt;/h3&gt;&lt;p&gt;User numbers and interest in BlueSky have risen sharply in recent weeks, which is certainly also due to a clever shortage campaign. A BlueSky account can only be opened if you can produce one of the coveted invitation codes from an already registered BlueSky user. These invitation codes help to keep abuse and botnets away from the platform. Many professional Twitter users, especially those with a large and dedicated reach, have switched to BlueSky in recent days and some have officially left Twitter. Invitation codes are now traded on exchanges.&lt;/p&gt;&lt;p&gt;We are also active on BlueSky as &lt;a href="https://bsky.app/profile/mailbox.org" target="_blank" title="Visit the profile of mailbox.org on BlueSky" rel="noopener"&gt;@mailbox.org&lt;/a&gt;, &lt;a href="https://bsky.app/profile/opentalk.eu" target="_blank" title="Visit the profile of OpenTalk on BlueSky" rel="noopener"&gt;@opentalk.eu&lt;/a&gt; and &lt;a href="https://bsky.app/profile/heinlein-support.de" target="_blank" title="Visit the profile of Heinlein Support on BlueSky" rel="noopener"&gt;@heinlein-support.de&lt;/a&gt; and experience increasing joy every day when our followers also appear on BlueSky and connect with us there.&lt;/p&gt;&lt;h2&gt;Our exchange platform for BlueSky invitation codes&lt;/h2&gt;&lt;p&gt;In order to provide mailbox.org users with easy access to BlueSky, we have set up an exchange platform for invitation codes.&lt;/p&gt;&lt;p&gt;Get your BlueSky invitation code: (Service discontinued – see below)&lt;/p&gt;&lt;ul&gt;&lt;li&gt;mailbox.org customers who are already on BlueSky and have codes available can upload them. On behalf of the mailbox.org community, we would like to thank all committed contributors!&lt;/li&gt;&lt;li&gt;mailbox.org customers who do not yet have a BlueSky invitation code can be placed on a digital waiting list and will receive it by e-mail as soon as possible.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Note: To prevent abuse, only mailbox.org users who have had a regular, paid account for more than four weeks can access the exchange.&lt;/p&gt;&lt;h2&gt;How will BlueSky develop?&lt;/h2&gt;&lt;p&gt;Although it is still unclear how BlueSky will develop and critical questions can be asked about the future of the platform, we currently see it as absolutely worthwhile to escape the decline of X/Twitter not only on Mastodon or LinkedIn but also on BlueSky. Personally, we prefer federated systems such as Mastodon, but the quality of communication and accounts on BlueSky has been convincing so far and we view the development positively. Definitely more positive than the developments on Twitter that we have seen in recent weeks.&lt;/p&gt;&lt;p&gt;We look forward to meeting many of our users there again.&lt;/p&gt;&lt;p&gt;Peer Heinlein&lt;/p&gt;&lt;p&gt;&lt;em&gt;P.S.: mailbox.org will continue to publish on all four platforms in parallel. Follow us on &lt;/em&gt;&lt;a href="https://twitter.com/mailbox_org" target="_blank" title="Follow mailbox.org on Twitter" rel="noopener"&gt;&lt;em&gt;Twitter&lt;/em&gt;&lt;/a&gt;&lt;em&gt;, &lt;/em&gt;&lt;a href="https://social.mailbox.org/@mailbox_org" target="_blank" title="Follow mailbox.org on Mastodon" rel="noopener"&gt;&lt;em&gt;Mastodon&lt;/em&gt;&lt;/a&gt;&lt;em&gt;, &lt;/em&gt;&lt;a href="https://de.linkedin.com/company/mailbox.org" target="_blank" title="Follow mailbox.org on LinkedIn" rel="noopener"&gt;&lt;em&gt;LinkedIn&lt;/em&gt;&lt;/a&gt;&lt;em&gt; and &lt;/em&gt;&lt;a href="https://bsky.app/profile/mailbox.org" target="_blank" title="Follow mailbox.org on BlueSky" rel="noopener"&gt;&lt;em&gt;BlueSky&lt;/em&gt;&lt;/a&gt;&lt;em&gt;.&lt;/em&gt;&lt;br&gt;&amp;nbsp;&lt;/p&gt;&lt;h2&gt;Update: Discontinuation of the BlueSky invitation code exchange&lt;/h2&gt;&lt;p&gt;We are pleased to see that the BlueSky platform is now freely accessible to all users and that invitation codes are no longer needed. As a result of this development, we have discontinued the invitation code exchange. We would like to thank everyone who contributed to the community and facilitated access to BlueSky. We look forward to continuing to meet you on social platforms such as BlueSky, Mastodon, LinkedIn and Twitter to stay in touch and promote a vibrant social media culture.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-tauschboerse-bluesky.png?itok=VOA3ECT5" type="image/png" length="380533"/><guid isPermaLink="false">875e1f53-2b6d-41c9-91f4-8816ab4c1188</guid>
    <pubDate>Fri, 03 Nov 2023 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Exchange platform for BlueSky invitation codes</dc:title>
    <dc:identifier>875e1f53-2b6d-41c9-91f4-8816ab4c1188</dc:identifier>
    </item>
<item>
  <title>Exchange platform for BlueSky invitation codes</title>
  <link>https://mailbox.org/en/news/mailboxorg-opens-bluesky-invitation-code-exchange-platform/</link>
  <description>&lt;p&gt;The takeover by Elon Musk has changed Twitter - now also known as X - dramatically. Less stringent moderation by the X/Twitter team, more radical communication and botnets posing as X/Twitter users and abusing the platform are just some of the effects. In response, many users worldwide sought refuge in the federated network Mastodon. We are also represented there with our accounts and our own instances via mailbox.org, OpenTalk and Heinlein Support. Mastodon's decentralized approach offers numerous advantages for a robust, uncensored network.&lt;/p&gt;&lt;h2&gt;Mastodon as a Twitter alternative?&lt;/h2&gt;&lt;p&gt;However, many X/Twitter users struggle with Mastodon and have not yet fully embraced it. Commercial or professional accounts have been very hesitant to switch to Mastodon. Despite their dissatisfaction, many users remain with X/Twitter, as Mastodon has unfortunately not yet been able to achieve the desired popularity.&lt;/p&gt;&lt;h2&gt;New perspectives through BlueSky&lt;/h2&gt;&lt;p&gt;BlueSky has been bringing a breath of fresh air to the social media landscape for a few weeks now. This platform was launched by Twitter founder and former CEO Jack Dorsey and is similar to Twitter in many respects, but also has its own unique approach. Today's BlueSky platform looks very similar to Twitter.&lt;/p&gt;&lt;h3&gt;Professionals are increasingly switching to BlueSky&lt;/h3&gt;&lt;p&gt;User numbers and interest in BlueSky have risen sharply in recent weeks, which is certainly also due to a clever shortage campaign. A BlueSky account can only be opened if you can produce one of the coveted invitation codes from an already registered BlueSky user. These invitation codes help to keep abuse and botnets away from the platform. Many professional Twitter users, especially those with a large and dedicated reach, have switched to BlueSky in recent days and some have officially left Twitter. Invitation codes are now traded on exchanges.&lt;/p&gt;&lt;p&gt;We are also active on BlueSky as &lt;a href="https://bsky.app/profile/mailbox.org" target="_blank" title="Visit the profile of mailbox.org on BlueSky" rel="noopener"&gt;@mailbox.org&lt;/a&gt;, &lt;a href="https://bsky.app/profile/opentalk.eu" target="_blank" title="Visit the profile of OpenTalk on BlueSky" rel="noopener"&gt;@opentalk.eu&lt;/a&gt; and &lt;a href="https://bsky.app/profile/heinlein-support.de" target="_blank" title="Visit the profile of Heinlein Support on BlueSky" rel="noopener"&gt;@heinlein-support.de&lt;/a&gt; and experience increasing joy every day when our followers also appear on BlueSky and connect with us there.&lt;/p&gt;&lt;h2&gt;Our exchange platform for BlueSky invitation codes&lt;/h2&gt;&lt;p&gt;In order to provide mailbox.org users with easy access to BlueSky, we have set up an exchange platform for invitation codes.&lt;/p&gt;&lt;p&gt;Get your BlueSky invitation code: (Service discontinued – see below)&lt;/p&gt;&lt;ul&gt;&lt;li&gt;mailbox.org customers who are already on BlueSky and have codes available can upload them. On behalf of the mailbox.org community, we would like to thank all committed contributors!&lt;/li&gt;&lt;li&gt;mailbox.org customers who do not yet have a BlueSky invitation code can be placed on a digital waiting list and will receive it by e-mail as soon as possible.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Note: To prevent abuse, only mailbox.org users who have had a regular, paid account for more than four weeks can access the exchange.&lt;/p&gt;&lt;h2&gt;How will BlueSky develop?&lt;/h2&gt;&lt;p&gt;Although it is still unclear how BlueSky will develop and critical questions can be asked about the future of the platform, we currently see it as absolutely worthwhile to escape the decline of X/Twitter not only on Mastodon or LinkedIn but also on BlueSky. Personally, we prefer federated systems such as Mastodon, but the quality of communication and accounts on BlueSky has been convincing so far and we view the development positively. Definitely more positive than the developments on Twitter that we have seen in recent weeks.&lt;/p&gt;&lt;p&gt;We look forward to meeting many of our users there again.&lt;/p&gt;&lt;p&gt;Peer Heinlein&lt;/p&gt;&lt;p&gt;&lt;em&gt;P.S.: mailbox.org will continue to publish on all four platforms in parallel. Follow us on &lt;/em&gt;&lt;a href="https://twitter.com/mailbox_org" target="_blank" title="Follow mailbox.org on Twitter" rel="noopener"&gt;&lt;em&gt;Twitter&lt;/em&gt;&lt;/a&gt;&lt;em&gt;, &lt;/em&gt;&lt;a href="https://social.mailbox.org/@mailbox_org" target="_blank" title="Follow mailbox.org on Mastodon" rel="noopener"&gt;&lt;em&gt;Mastodon&lt;/em&gt;&lt;/a&gt;&lt;em&gt;, &lt;/em&gt;&lt;a href="https://de.linkedin.com/company/mailbox.org" target="_blank" title="Follow mailbox.org on LinkedIn" rel="noopener"&gt;&lt;em&gt;LinkedIn&lt;/em&gt;&lt;/a&gt;&lt;em&gt; and &lt;/em&gt;&lt;a href="https://bsky.app/profile/mailbox.org" target="_blank" title="Follow mailbox.org on BlueSky" rel="noopener"&gt;&lt;em&gt;BlueSky&lt;/em&gt;&lt;/a&gt;&lt;em&gt;.&lt;/em&gt;&lt;br&gt;&amp;nbsp;&lt;/p&gt;&lt;h2&gt;Update: Discontinuation of the BlueSky invitation code exchange&lt;/h2&gt;&lt;p&gt;We are pleased to see that the BlueSky platform is now freely accessible to all users and that invitation codes are no longer needed. As a result of this development, we have discontinued the invitation code exchange. We would like to thank everyone who contributed to the community and facilitated access to BlueSky. We look forward to continuing to meet you on social platforms such as BlueSky, Mastodon, LinkedIn and Twitter to stay in touch and promote a vibrant social media culture.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-tauschboerse-bluesky.png?itok=VOA3ECT5" type="image/png" length="380533"/><guid isPermaLink="false">875e1f53-2b6d-41c9-91f4-8816ab4c1188</guid>
    <pubDate>Fri, 03 Nov 2023 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Exchange platform for BlueSky invitation codes</dc:title>
    <dc:identifier>875e1f53-2b6d-41c9-91f4-8816ab4c1188</dc:identifier>
    </item>
<item>
  <title>Chat control: A step forward for secure communication</title>
  <link>https://mailbox.org/en/news/chat-control-stage-victory-europeans-secure-communication/</link>
  <description>&lt;p&gt;The EU Parliament overturns critical aspects of the EU Commission's controversial bill on warrantless chat control.&lt;/p&gt;&lt;ol&gt;&lt;li&gt;No warrantless monitoring&lt;/li&gt;&lt;li&gt;End-to-end encrypted interpersonal communications must not be monitored&lt;/li&gt;&lt;li&gt;Client-side scanning was rejected&lt;/li&gt;&lt;li&gt;The right to anonymous communication remains&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;The political groups of the EU Parliament yesterday agreed on a common position on suspicionless mass surveillance of communications. The corresponding compromises were presented the same day by the negotiators of the Committee on Civil Liberties, Justice and Home Affairs (LIBE). The EU Parliament’s civil liberties committee will take a final vote on the proposals on November 13, 2023.&lt;/p&gt;&lt;h2&gt;The most important positions at a glance&lt;/h2&gt;&lt;h3&gt;No surveillance without any reason&lt;/h3&gt;&lt;p&gt;The EU Commission's original proposal for blanket surveillance of all users has been scrapped. Only individual persons or groups of persons are to be monitored - and only with judicial authorization. The current voluntary chat monitoring of private messages (not in social networks) by U.S. Internet companies is also to be gradually abolished.&lt;/p&gt;&lt;h3&gt;End-to-end encryption and client-side scanning&lt;/h3&gt;&lt;p&gt;The EU Parliament wants to strengthen trust in secure end-to-end encryption. Therefore, end-to-end encrypted interpersonal communications must not be monitored. In addition, the use of so-called client-side scanning is excluded, i.e. the installation of monitoring functions and security loopholes in smartphones.&lt;/p&gt;&lt;h3&gt;Right to anonymous communication&lt;/h3&gt;&lt;p&gt;The EU Parliament also strengthens the right to anonymous communication and wants to abolish the mandatory age verification for users of communication services proposed by the EU Commission. Whistleblowers can thus continue to anonymously expose wrongdoing without having to show their ID or face.&lt;/p&gt;&lt;h2&gt;A step in the right direction&lt;/h2&gt;&lt;p&gt;"In our view, the agreement reached by the Interior Committee on October 26 is an essentially important step in the right direction, which we welcome. Mass surveillance of private individuals' communications without suspicion not only jeopardizes the digital privacy of correspondence but is also contrary to fundamental rights, as it would invalidate the presumption of innocence, a principle of the rule of law. End-to-end encryption is also to remain possible under the proposals of the Interior Committee. We also see this as a victory for freedom of thought and expression. We look forward to the results of the final vote by the committee on November 13 and the subsequent trilogue negotiations with the EU Commission and the individual member states.&lt;/p&gt;&lt;p&gt;Our appeal to national and Commission leaders: Listen to those responsible from the Interior Committee and leave the topic of chat control alone once and for all! Not only will essential European rights and constitutional principles be preserved in this way, but there are also numerous methods for the actual goal of chat control - the protection of children and young people online - that are much more effective. The proposals from the European Parliament offer valuable starting points here." Peer Heinlein, founder and CEO of mailbox.org&lt;/p&gt;&lt;p&gt;The discussions surrounding the draft law, which threatens the whole of Europe with surveillance machinery, have been occupying us for some time now. We look forward with excitement, but also optimism, to the final agreement of the EU Parliament’s civil liberties committee on November 13, 2023.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-surveillance.png?itok=xKoQ4dlZ" type="image/png" length="275481"/><guid isPermaLink="false">863fd406-5051-4597-ac52-69386c1beb9a</guid>
    <pubDate>Fri, 27 Oct 2023 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Chat control: A step forward for secure communication</dc:title>
    <dc:identifier>863fd406-5051-4597-ac52-69386c1beb9a</dc:identifier>
    </item>
<item>
  <title>Chat control: A step forward for secure communication</title>
  <link>https://mailbox.org/en/news/chat-control-stage-victory-europeans-secure-communication/</link>
  <description>&lt;p&gt;The EU Parliament overturns critical aspects of the EU Commission's controversial bill on warrantless chat control.&lt;/p&gt;&lt;ol&gt;&lt;li&gt;No warrantless monitoring&lt;/li&gt;&lt;li&gt;End-to-end encrypted interpersonal communications must not be monitored&lt;/li&gt;&lt;li&gt;Client-side scanning was rejected&lt;/li&gt;&lt;li&gt;The right to anonymous communication remains&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;The political groups of the EU Parliament yesterday agreed on a common position on suspicionless mass surveillance of communications. The corresponding compromises were presented the same day by the negotiators of the Committee on Civil Liberties, Justice and Home Affairs (LIBE). The EU Parliament’s civil liberties committee will take a final vote on the proposals on November 13, 2023.&lt;/p&gt;&lt;h2&gt;The most important positions at a glance&lt;/h2&gt;&lt;h3&gt;No surveillance without any reason&lt;/h3&gt;&lt;p&gt;The EU Commission's original proposal for blanket surveillance of all users has been scrapped. Only individual persons or groups of persons are to be monitored - and only with judicial authorization. The current voluntary chat monitoring of private messages (not in social networks) by U.S. Internet companies is also to be gradually abolished.&lt;/p&gt;&lt;h3&gt;End-to-end encryption and client-side scanning&lt;/h3&gt;&lt;p&gt;The EU Parliament wants to strengthen trust in secure end-to-end encryption. Therefore, end-to-end encrypted interpersonal communications must not be monitored. In addition, the use of so-called client-side scanning is excluded, i.e. the installation of monitoring functions and security loopholes in smartphones.&lt;/p&gt;&lt;h3&gt;Right to anonymous communication&lt;/h3&gt;&lt;p&gt;The EU Parliament also strengthens the right to anonymous communication and wants to abolish the mandatory age verification for users of communication services proposed by the EU Commission. Whistleblowers can thus continue to anonymously expose wrongdoing without having to show their ID or face.&lt;/p&gt;&lt;h2&gt;A step in the right direction&lt;/h2&gt;&lt;p&gt;"In our view, the agreement reached by the Interior Committee on October 26 is an essentially important step in the right direction, which we welcome. Mass surveillance of private individuals' communications without suspicion not only jeopardizes the digital privacy of correspondence but is also contrary to fundamental rights, as it would invalidate the presumption of innocence, a principle of the rule of law. End-to-end encryption is also to remain possible under the proposals of the Interior Committee. We also see this as a victory for freedom of thought and expression. We look forward to the results of the final vote by the committee on November 13 and the subsequent trilogue negotiations with the EU Commission and the individual member states.&lt;/p&gt;&lt;p&gt;Our appeal to national and Commission leaders: Listen to those responsible from the Interior Committee and leave the topic of chat control alone once and for all! Not only will essential European rights and constitutional principles be preserved in this way, but there are also numerous methods for the actual goal of chat control - the protection of children and young people online - that are much more effective. The proposals from the European Parliament offer valuable starting points here." Peer Heinlein, founder and CEO of mailbox.org&lt;/p&gt;&lt;p&gt;The discussions surrounding the draft law, which threatens the whole of Europe with surveillance machinery, have been occupying us for some time now. We look forward with excitement, but also optimism, to the final agreement of the EU Parliament’s civil liberties committee on November 13, 2023.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-surveillance.png?itok=xKoQ4dlZ" type="image/png" length="275481"/><guid isPermaLink="false">863fd406-5051-4597-ac52-69386c1beb9a</guid>
    <pubDate>Fri, 27 Oct 2023 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Chat control: A step forward for secure communication</dc:title>
    <dc:identifier>863fd406-5051-4597-ac52-69386c1beb9a</dc:identifier>
    </item>
<item>
  <title>IP whitelisting: Greater security for businesses</title>
  <link>https://mailbox.org/en/news/mailboxorg-ip-whitelisting-more-security-companies/</link>
  <description>&lt;p&gt;In today's digitalised world, the security of networks and systems is an increasingly important topic. One of the methods IT professionals use to secure networks and services is IP whitelisting. mailbox.org now offers IP whitelisting as a new feature for business customers. But what exactly is IP whitelisting and how can it help make your company more secure? In this article, we will go into what IP whitelisting is, how it works and in which scenarios it can be particularly useful.&lt;/p&gt;&lt;p&gt;In addition, another security-relevant feature for business customers is presented: the forced password reset.&lt;/p&gt;&lt;h3&gt;New feature: IP whitelisting&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;Access to e-mail inboxes is only possible via predefined networks&lt;/li&gt;&lt;li&gt;Restrictions apply to login via the website and access to IMAP servers (when using e-mail clients)&lt;/li&gt;&lt;li&gt;Maximum flexibility through individual configuration of individual mailboxes&lt;/li&gt;&lt;li&gt;Multiple IP address records can be inserted as a comma-separated list&lt;/li&gt;&lt;li&gt;Compatibility with IP standards IPv4 and IPv6&lt;/li&gt;&lt;li&gt;Easy access via admin interface or API&lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;New feature: Forced password reset&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;Inboxes can be better protected against password theft in case of suspicion&lt;/li&gt;&lt;li&gt;Users are forced to enter a new password after login&lt;/li&gt;&lt;li&gt;Easy access via the admin interface or via API&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;h2&gt;What is IP whitelisting?&lt;/h2&gt;&lt;p&gt;IP whitelisting is a security measure where only pre-determined IP addresses are given access to a particular service, website or network. Imagine a VIP list for a party: Only people whose names are on the list are allowed in. With IP whitelisting, it is not the names of people but the IP addresses of computers or networks that gain access.&lt;/p&gt;&lt;p&gt;When a computer tries to access a service that uses IP whitelisting, its IP address is compared to the whitelist. If the IP address is on the list, access is granted. If it is not on the list, access is denied.&lt;/p&gt;&lt;p&gt;This is often used to increase security, as only known and trusted addresses are granted access.&lt;/p&gt;&lt;h2&gt;VPN as an ideal complement to IP whitelisting&lt;/h2&gt;&lt;p&gt;The use of VPN (Virtual Private Networks) is widespread in the corporate world, especially to allow employees to securely access corporate networks from remote locations. This has become particularly relevant as many companies have moved to flexible working models such as the home office.&lt;/p&gt;&lt;p&gt;A VPN is used to establish a secure and encrypted connection between a user's terminal device and the corporate network. This encryption significantly reduces the risk of data theft and cyber attacks, as potential attackers cannot access the transmitted information.&lt;/p&gt;&lt;h2&gt;More security through VPN and IP whitelisting&lt;/h2&gt;&lt;p&gt;The combination of Virtual Private Network (VPN) and IP whitelisting provides organisations with a high level of security and control over data traffic. Both technologies have their own strengths, and when used together, they can provide a powerful solution for protecting sensitive corporate data. Here are some reasons why this combination is useful for businesses:&lt;/p&gt;&lt;h3&gt;Increased security&lt;/h3&gt;&lt;p&gt;A VPN encrypts internet traffic so that external attackers cannot easily access data exchanged between the corporate network and external devices. IP whitelisting, on the other hand, ensures that only certain pre-approved IP addresses have access to the network. Combining the two creates an additional layer of security.&lt;/p&gt;&lt;h3&gt;Better compliance&lt;/h3&gt;&lt;p&gt;Companies are often subject to strict data protection regulations. The combination of VPN and IP whitelisting can help meet compliance requirements more easily by both encrypting traffic and strictly regulating access to the network.&lt;/p&gt;&lt;h3&gt;Reduced risk of insider attacks&lt;/h3&gt;&lt;p&gt;Because IP whitelisting only allows access to certain IP addresses, the risk of insider attacks is reduced. Even if an internal device is compromised, the attacker would not be able to perform malicious actions without a permitted IP address.&lt;/p&gt;&lt;h3&gt;Reduction of attack vectors&lt;/h3&gt;&lt;p&gt;The combination of VPN and IP whitelisting effectively reduces the attack surface vulnerable to potential cyberattacks. With fewer opportunities for attackers to penetrate the network, the entire corporate infrastructure is more secure.&lt;/p&gt;&lt;p&gt;Overall, the combination of VPN and IP whitelisting offers companies a robust and versatile security solution that can adapt to different requirements and threat models. It represents a sensible investment in the long-term security strategy of any modern company.&lt;/p&gt;&lt;h2&gt;How to set up IP whitelisting for your company at mailbox.org&lt;/h2&gt;&lt;p&gt;You can create an individual IP whitelist for each mailbox, giving you the greatest possible control and accuracy. If you want to protect a large number of mailboxes with IP whitelisting, you can also configure the IP whitelists as you wish via API.&lt;/p&gt;&lt;p&gt;If you work with your company via a VPN network - for example in the home office or during a business trip - the IP address of the employee remains constant through the VPN network.&lt;/p&gt;&lt;p&gt;In combination with IP whitelisting, only employees can access the login page of the web mailer or via an e-mail app through the VPN network.&lt;/p&gt;&lt;h3&gt;Manually setting up IP whitelisting&lt;/h3&gt;&lt;p&gt;Via the business administration, the IP whitelist can be set for each individual mailbox in the CIDR notation (Classless Inter-Domain Routing). This option provides the greatest flexibility and control for the administrator.&lt;/p&gt;&lt;p&gt;&lt;a href="https://kb.mailbox.org/en/business/security-privacy-article/ip-whitelisting" target="_blank" title="IP whitelisting for mailbox.org business customers Link to IP whitelisting for mailbox.org business customers" rel="noopener"&gt;You can find out more about this in our knowledge base -&amp;gt;&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;Using the API to set up IP whitelisting&lt;/h3&gt;&lt;p&gt;If you have a larger number of mailboxes, you can of course also use our API. Using our API can reduce manual work and thus be a time saver and minimise the risk of errors. The method mail.set has been extended by the parameter allow_nets for this purpose.&lt;/p&gt;&lt;p&gt;&lt;a href="https://api.mailbox.org/v1/doc/methods/index.html#mail-set" target="_blank" title="Go to API documentation" rel="noopener"&gt;You can find out more about this in our API documentation -&amp;gt;&lt;/a&gt;&lt;/p&gt;&lt;h2&gt;How the new forced password reset works&lt;/h2&gt;&lt;p&gt;mailbox.org has developed a forced password reset function for business customers, which is now available. This function can be used, for example, when a security incident is suspected.&lt;/p&gt;&lt;h3&gt;How it works&lt;/h3&gt;&lt;ol&gt;&lt;li&gt;The administrator can select the relevant mailbox via the business account&lt;/li&gt;&lt;li&gt;Activate forced password reset: Select the mailbox and click "Force password change at next login".&lt;/li&gt;&lt;li&gt;At the next login, the mailbox user is prompted to enter a new password. The mailbox user receives this prompt on an intermediate page after entering his current password.&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;A password change can also be forced via the API. The method mail.set has been extended by the parameter "require_reset_password". &lt;a href="https://api.mailbox.org/v1/doc/methods/index.html#mail-set" target="_blank" title="Read API documentation" rel="noopener"&gt;You can find out more about this in our API documentation -&amp;gt;&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;Usage scenarios&lt;/h3&gt;&lt;ol&gt;&lt;li&gt;Security incident: If a security incident is suspected (such as a phishing attack), an immediate password reset may be required to prevent potential damage.&lt;/li&gt;&lt;li&gt;Routine check: Companies could use this feature to perform regular password changes to keep security levels high.&lt;/li&gt;&lt;/ol&gt;&lt;h3&gt;Benefits&lt;/h3&gt;&lt;ol&gt;&lt;li&gt;Increased security: A forced password reset can help increase security by immediately cutting off access if compromise is suspected.&lt;/li&gt;&lt;li&gt;Compliance: Some industries and company policies require regular password changes, and a forced password reset can help ensure compliance with such policies.&lt;/li&gt;&lt;li&gt;Ease of use: This feature allows administrators to centrally control and perform password resets, reducing administrative overhead.&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;As your secure email provider, we are pleased to contribute with these new features to help you as an organization effectively manage and improve your data security.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-concentration.jpeg?itok=-QF6F_Kp" type="image/jpeg" length="315705"/><guid isPermaLink="false">aa0c7bae-72f2-4d22-b5e4-3e7d45123608</guid>
    <pubDate>Fri, 29 Sep 2023 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>IP whitelisting: Greater security for businesses</dc:title>
    <dc:identifier>aa0c7bae-72f2-4d22-b5e4-3e7d45123608</dc:identifier>
    </item>
<item>
  <title>IP whitelisting: Greater security for businesses</title>
  <link>https://mailbox.org/en/news/mailboxorg-ip-whitelisting-more-security-companies/</link>
  <description>&lt;p&gt;In today's digitalised world, the security of networks and systems is an increasingly important topic. One of the methods IT professionals use to secure networks and services is IP whitelisting. mailbox.org now offers IP whitelisting as a new feature for business customers. But what exactly is IP whitelisting and how can it help make your company more secure? In this article, we will go into what IP whitelisting is, how it works and in which scenarios it can be particularly useful.&lt;/p&gt;&lt;p&gt;In addition, another security-relevant feature for business customers is presented: the forced password reset.&lt;/p&gt;&lt;h3&gt;New feature: IP whitelisting&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;Access to e-mail inboxes is only possible via predefined networks&lt;/li&gt;&lt;li&gt;Restrictions apply to login via the website and access to IMAP servers (when using e-mail clients)&lt;/li&gt;&lt;li&gt;Maximum flexibility through individual configuration of individual mailboxes&lt;/li&gt;&lt;li&gt;Multiple IP address records can be inserted as a comma-separated list&lt;/li&gt;&lt;li&gt;Compatibility with IP standards IPv4 and IPv6&lt;/li&gt;&lt;li&gt;Easy access via admin interface or API&lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;New feature: Forced password reset&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;Inboxes can be better protected against password theft in case of suspicion&lt;/li&gt;&lt;li&gt;Users are forced to enter a new password after login&lt;/li&gt;&lt;li&gt;Easy access via the admin interface or via API&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;h2&gt;What is IP whitelisting?&lt;/h2&gt;&lt;p&gt;IP whitelisting is a security measure where only pre-determined IP addresses are given access to a particular service, website or network. Imagine a VIP list for a party: Only people whose names are on the list are allowed in. With IP whitelisting, it is not the names of people but the IP addresses of computers or networks that gain access.&lt;/p&gt;&lt;p&gt;When a computer tries to access a service that uses IP whitelisting, its IP address is compared to the whitelist. If the IP address is on the list, access is granted. If it is not on the list, access is denied.&lt;/p&gt;&lt;p&gt;This is often used to increase security, as only known and trusted addresses are granted access.&lt;/p&gt;&lt;h2&gt;VPN as an ideal complement to IP whitelisting&lt;/h2&gt;&lt;p&gt;The use of VPN (Virtual Private Networks) is widespread in the corporate world, especially to allow employees to securely access corporate networks from remote locations. This has become particularly relevant as many companies have moved to flexible working models such as the home office.&lt;/p&gt;&lt;p&gt;A VPN is used to establish a secure and encrypted connection between a user's terminal device and the corporate network. This encryption significantly reduces the risk of data theft and cyber attacks, as potential attackers cannot access the transmitted information.&lt;/p&gt;&lt;h2&gt;More security through VPN and IP whitelisting&lt;/h2&gt;&lt;p&gt;The combination of Virtual Private Network (VPN) and IP whitelisting provides organisations with a high level of security and control over data traffic. Both technologies have their own strengths, and when used together, they can provide a powerful solution for protecting sensitive corporate data. Here are some reasons why this combination is useful for businesses:&lt;/p&gt;&lt;h3&gt;Increased security&lt;/h3&gt;&lt;p&gt;A VPN encrypts internet traffic so that external attackers cannot easily access data exchanged between the corporate network and external devices. IP whitelisting, on the other hand, ensures that only certain pre-approved IP addresses have access to the network. Combining the two creates an additional layer of security.&lt;/p&gt;&lt;h3&gt;Better compliance&lt;/h3&gt;&lt;p&gt;Companies are often subject to strict data protection regulations. The combination of VPN and IP whitelisting can help meet compliance requirements more easily by both encrypting traffic and strictly regulating access to the network.&lt;/p&gt;&lt;h3&gt;Reduced risk of insider attacks&lt;/h3&gt;&lt;p&gt;Because IP whitelisting only allows access to certain IP addresses, the risk of insider attacks is reduced. Even if an internal device is compromised, the attacker would not be able to perform malicious actions without a permitted IP address.&lt;/p&gt;&lt;h3&gt;Reduction of attack vectors&lt;/h3&gt;&lt;p&gt;The combination of VPN and IP whitelisting effectively reduces the attack surface vulnerable to potential cyberattacks. With fewer opportunities for attackers to penetrate the network, the entire corporate infrastructure is more secure.&lt;/p&gt;&lt;p&gt;Overall, the combination of VPN and IP whitelisting offers companies a robust and versatile security solution that can adapt to different requirements and threat models. It represents a sensible investment in the long-term security strategy of any modern company.&lt;/p&gt;&lt;h2&gt;How to set up IP whitelisting for your company at mailbox.org&lt;/h2&gt;&lt;p&gt;You can create an individual IP whitelist for each mailbox, giving you the greatest possible control and accuracy. If you want to protect a large number of mailboxes with IP whitelisting, you can also configure the IP whitelists as you wish via API.&lt;/p&gt;&lt;p&gt;If you work with your company via a VPN network - for example in the home office or during a business trip - the IP address of the employee remains constant through the VPN network.&lt;/p&gt;&lt;p&gt;In combination with IP whitelisting, only employees can access the login page of the web mailer or via an e-mail app through the VPN network.&lt;/p&gt;&lt;h3&gt;Manually setting up IP whitelisting&lt;/h3&gt;&lt;p&gt;Via the business administration, the IP whitelist can be set for each individual mailbox in the CIDR notation (Classless Inter-Domain Routing). This option provides the greatest flexibility and control for the administrator.&lt;/p&gt;&lt;p&gt;&lt;a href="https://kb.mailbox.org/en/business/security-privacy-article/ip-whitelisting" target="_blank" title="IP whitelisting for mailbox.org business customers Link to IP whitelisting for mailbox.org business customers" rel="noopener"&gt;You can find out more about this in our knowledge base -&amp;gt;&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;Using the API to set up IP whitelisting&lt;/h3&gt;&lt;p&gt;If you have a larger number of mailboxes, you can of course also use our API. Using our API can reduce manual work and thus be a time saver and minimise the risk of errors. The method mail.set has been extended by the parameter allow_nets for this purpose.&lt;/p&gt;&lt;p&gt;&lt;a href="https://api.mailbox.org/v1/doc/methods/index.html#mail-set" target="_blank" title="Go to API documentation" rel="noopener"&gt;You can find out more about this in our API documentation -&amp;gt;&lt;/a&gt;&lt;/p&gt;&lt;h2&gt;How the new forced password reset works&lt;/h2&gt;&lt;p&gt;mailbox.org has developed a forced password reset function for business customers, which is now available. This function can be used, for example, when a security incident is suspected.&lt;/p&gt;&lt;h3&gt;How it works&lt;/h3&gt;&lt;ol&gt;&lt;li&gt;The administrator can select the relevant mailbox via the business account&lt;/li&gt;&lt;li&gt;Activate forced password reset: Select the mailbox and click "Force password change at next login".&lt;/li&gt;&lt;li&gt;At the next login, the mailbox user is prompted to enter a new password. The mailbox user receives this prompt on an intermediate page after entering his current password.&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;A password change can also be forced via the API. The method mail.set has been extended by the parameter "require_reset_password". &lt;a href="https://api.mailbox.org/v1/doc/methods/index.html#mail-set" target="_blank" title="Read API documentation" rel="noopener"&gt;You can find out more about this in our API documentation -&amp;gt;&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;Usage scenarios&lt;/h3&gt;&lt;ol&gt;&lt;li&gt;Security incident: If a security incident is suspected (such as a phishing attack), an immediate password reset may be required to prevent potential damage.&lt;/li&gt;&lt;li&gt;Routine check: Companies could use this feature to perform regular password changes to keep security levels high.&lt;/li&gt;&lt;/ol&gt;&lt;h3&gt;Benefits&lt;/h3&gt;&lt;ol&gt;&lt;li&gt;Increased security: A forced password reset can help increase security by immediately cutting off access if compromise is suspected.&lt;/li&gt;&lt;li&gt;Compliance: Some industries and company policies require regular password changes, and a forced password reset can help ensure compliance with such policies.&lt;/li&gt;&lt;li&gt;Ease of use: This feature allows administrators to centrally control and perform password resets, reducing administrative overhead.&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;As your secure email provider, we are pleased to contribute with these new features to help you as an organization effectively manage and improve your data security.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-concentration.jpeg?itok=-QF6F_Kp" type="image/jpeg" length="315705"/><guid isPermaLink="false">aa0c7bae-72f2-4d22-b5e4-3e7d45123608</guid>
    <pubDate>Fri, 29 Sep 2023 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>IP whitelisting: Greater security for businesses</dc:title>
    <dc:identifier>aa0c7bae-72f2-4d22-b5e4-3e7d45123608</dc:identifier>
    </item>
<item>
  <title>Phishing warning: Fake mailbox.org invoices</title>
  <link>https://mailbox.org/en/news/phishing-warning-fake-mailboxorg-invoices/</link>
  <description>&lt;p&gt;Many fake invoices have been sent to mailbox.org customers recently. They suggest that a certain amount must be transferred promptly and list invoice items such as "service fee" or "anti-spam protection".&lt;/p&gt;&lt;p&gt;These e-mails are sent from any account such as support@pay-security.de, payment@team-support.email or payment@account-dashboard.at. From which you can also easily recognise them.&lt;/p&gt;&lt;p&gt;These invoices are not from mailbox.org. Do not pay them!&lt;/p&gt;&lt;h2&gt;Important information about the current phishing wave&lt;/h2&gt;&lt;p&gt;Please become suspicious if you receive strange e-mails with requests for payment, which are often combined with the threat of imminent account deactivation. Our support has received several complaints about how "dubious" mailbox.org would send invoices here – and we agree: Yes, they are dubious. But not from us.&lt;/p&gt;&lt;p&gt;Therefore:&lt;/p&gt;&lt;ol&gt;&lt;li&gt;mailbox.org does not send questionable invoices by e-mail.&lt;/li&gt;&lt;li&gt;mailbox.org does not send e-mails from other domains, but only from mailbox.org.&lt;/li&gt;&lt;li&gt;mailbox.org only sends e-mails via support@mailbox.org and noreply@mailbox.org.&lt;/li&gt;&lt;li&gt;Our e-mails are usually PGP-signed.&lt;/li&gt;&lt;li&gt;Please only pay logged in in the administration area via the menu item "Add credit" to the bank details and payment methods mentioned there.&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;We are constantly adapting our spam filters against these attacks and are thus able to block the majority of these e-mails successfully. Only in rare cases do these e-mails reach our users. In most cases, our users remain largely unaffected by such attacks. However, this is naturally not 100% successful, so especially in the early stages of such a wave, some e-mails can still get through.&lt;/p&gt;&lt;p&gt;So: Be suspicious and stay suspicious. Your suspicions are justified.&lt;/p&gt;&lt;p&gt;With best regards&lt;/p&gt;&lt;p&gt;Your mailbox.org team&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-04/mailbox-news-und-updates-warnung.jpg?itok=reW9cU74" type="image/jpeg" length="238141"/><guid isPermaLink="false">afb5a4e5-585f-4b50-be5f-eb6c17454a3d</guid>
    <pubDate>Tue, 22 Aug 2023 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Phishing warning: Fake mailbox.org invoices</dc:title>
    <dc:identifier>afb5a4e5-585f-4b50-be5f-eb6c17454a3d</dc:identifier>
    </item>
<item>
  <title>Phishing warning: Fake mailbox.org invoices</title>
  <link>https://mailbox.org/en/news/phishing-warning-fake-mailboxorg-invoices/</link>
  <description>&lt;p&gt;Many fake invoices have been sent to mailbox.org customers recently. They suggest that a certain amount must be transferred promptly and list invoice items such as "service fee" or "anti-spam protection".&lt;/p&gt;&lt;p&gt;These e-mails are sent from any account such as support@pay-security.de, payment@team-support.email or payment@account-dashboard.at. From which you can also easily recognise them.&lt;/p&gt;&lt;p&gt;These invoices are not from mailbox.org. Do not pay them!&lt;/p&gt;&lt;h2&gt;Important information about the current phishing wave&lt;/h2&gt;&lt;p&gt;Please become suspicious if you receive strange e-mails with requests for payment, which are often combined with the threat of imminent account deactivation. Our support has received several complaints about how "dubious" mailbox.org would send invoices here – and we agree: Yes, they are dubious. But not from us.&lt;/p&gt;&lt;p&gt;Therefore:&lt;/p&gt;&lt;ol&gt;&lt;li&gt;mailbox.org does not send questionable invoices by e-mail.&lt;/li&gt;&lt;li&gt;mailbox.org does not send e-mails from other domains, but only from mailbox.org.&lt;/li&gt;&lt;li&gt;mailbox.org only sends e-mails via support@mailbox.org and noreply@mailbox.org.&lt;/li&gt;&lt;li&gt;Our e-mails are usually PGP-signed.&lt;/li&gt;&lt;li&gt;Please only pay logged in in the administration area via the menu item "Add credit" to the bank details and payment methods mentioned there.&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;We are constantly adapting our spam filters against these attacks and are thus able to block the majority of these e-mails successfully. Only in rare cases do these e-mails reach our users. In most cases, our users remain largely unaffected by such attacks. However, this is naturally not 100% successful, so especially in the early stages of such a wave, some e-mails can still get through.&lt;/p&gt;&lt;p&gt;So: Be suspicious and stay suspicious. Your suspicions are justified.&lt;/p&gt;&lt;p&gt;With best regards&lt;/p&gt;&lt;p&gt;Your mailbox.org team&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-04/mailbox-news-und-updates-warnung.jpg?itok=reW9cU74" type="image/jpeg" length="238141"/><guid isPermaLink="false">afb5a4e5-585f-4b50-be5f-eb6c17454a3d</guid>
    <pubDate>Tue, 22 Aug 2023 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Phishing warning: Fake mailbox.org invoices</dc:title>
    <dc:identifier>afb5a4e5-585f-4b50-be5f-eb6c17454a3d</dc:identifier>
    </item>
<item>
  <title>Phishing alert: How to spot fake mailbox.org e-mails</title>
  <link>https://mailbox.org/en/blog/phishing-alarm-how-to-spot-fake-mailboxorg-emails/</link>
  <description>&lt;p&gt;Phishing attacks are a constant threat on the internet and are not always easy to detect. Through fake e-mails, cybercriminals try to lure users to fake login pages in order to steal login credentials.&lt;/p&gt;&lt;p&gt;Although we at mailbox.org take various technical measures to ensure that such e-mails do not get into your inbox in the first place, we would like to show you in this blog article how you can recognise that an e-mail does not originate from mailbox.org itself.&lt;/p&gt;


      
                  
              
              
              
              
              
              
              
                  &lt;img loading="lazy" height="1632" width="2912" src="https://mailbox.org/sites/default/files/2025-05/news-envelope-2.png" alt="Envelope"&gt;

  


  
          



  &lt;h2 class="referent__title"&gt;&lt;/h2&gt;
  
                
        
                    
            
                          &lt;h3 class="referent__headline"&gt;
                What are Phishing attacks?
                              &lt;/h3&gt;
            
            
                          &lt;p&gt;Phishing is a term that refers to a type of cyber attack in which criminals attempt to steal sensitive information such as usernames, passwords and credit card numbers from unsuspecting victims. Phishing attacks often occur via fake e-mails or websites that look like they come from trusted sources such as banks, government agencies or large companies.&lt;/p&gt;&lt;p&gt;An example of a phishing e-mail would be a fake e-mail from a bank that asks the recipient to click on a link and log in with their banking information. The fake website that the link leads to looks exactly like the real bank website, but the data entered is intercepted by the criminals and used for fraudulent purposes.&lt;/p&gt;&lt;p&gt;Another type of phishing attack can be a fake e-mail from a streaming service asking the recipient to update their credentials in order to continue accessing the service. If the recipient clicks on the malicious link in the e-mail and enters their credentials, the criminals can access the victim's account and potentially steal money or personal sensitive data.&lt;/p&gt;
                        
        
      
      

              


  
    
    
    
    &lt;h2&gt;1.&amp;nbsp;Check sender: Recognise genuine e-mails from mailbox.org&lt;/h2&gt;&lt;ul&gt;&lt;li&gt;Be wary of e-mails from unknown senders and check the e-mail address for plausibility.&lt;/li&gt;&lt;li&gt;Check the digital signature, if present.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;The "from address" can help you distinguish genuine e-mails from mailbox.org from fraudulent phishing attempts. Legitimate e-mails from mailbox.org are typically sent from the address "noreply@mailbox.org". Different departments, such as our support, of course use their own address - but our support contacts customers onlfy when they have a customer enquiry and not proactively.&lt;/p&gt;&lt;p&gt;If you receive an e-mail from an unknown address or even another domain claiming to be from mailbox.org, you should become extremely suspicious. It is important to pay attention not only to the displayed name of the sender, but also to the actual e-mail address. If the address is not "noreply@mailbox.org", it is probably a phishing attempt.&lt;/p&gt;&lt;p&gt;A trustworthy sender signs his e-mails with a digital signature. Our e-mails from noreply@mailbox.org are always signed. No fingerprint matching is necessary in the webmailer. The public key is already available. If an external e-mail client is used (Thunderbird or Outlook, etc.), which has its own PGP key management, the public key from noreply@mailbox.org must be imported. In this case, matching of the fingerprint is necessary. Here you can find our public key and key ID: &lt;a href="https://mailbox.org/en/legal-information"&gt;Digital signature from mailbox.org →&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;h2&gt;2. Avoid typical traps: Watch out for suspicious links, attachments and login pages&lt;/h2&gt;&lt;ul&gt;&lt;li&gt;Check the URL of the website you are visiting carefully and look out for spelling mistakes or unusual domain names.&lt;/li&gt;&lt;li&gt;Never open files in the attachment of a suspicious e-mail.&lt;/li&gt;&lt;li&gt;Be sceptical of e-mails that ask you to click on a link and log in or give out personal information.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;A key feature of phishing emails is the use of fake links that lead to mock login or password reset pages. If you receive an e-mail from mailbox.org asking you to visit a link, first check the URL of the link.&lt;/p&gt;&lt;p&gt;A genuine mailbox.org URL should always begin with "https://mailbox.org/" or "https://www.mailbox.org/". However, if the link points to another domain that looks similar to the real domain, it is probably a phishing attempt. For example, a phishing URL might look like "https://mailb0x.org/" or "https://www.mailbox-org.net/".&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;h2&gt;3. Identify inconsistencies: Mistakes, grammatical and spelling errors and unusual layout and design&lt;/h2&gt;&lt;ul&gt;&lt;li&gt;Be suspicious if you are not addressed as usual or the e-mail uses a different language.&lt;/li&gt;&lt;li&gt;Look out for deviations from the e-mails you have received so far.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Phishing e-mails often contain spelling, grammatical or spelling mistakes that should not appear in official e-mails from mailbox.org. Pay attention to whether the e-mail is worded unusually or contains errors that may indicate forgery.&lt;/p&gt;&lt;p&gt;Many phishing e-mails try to imitate the layout and design of the official e-mails of the attacked company. However, differences and inconsistencies are often noticeable. Look out for unusual formatting that differs from the normal e-mails from mailbox.org.&lt;/p&gt;&lt;p&gt;There are cases of very well-made forgeries, especially from well-known companies, which are difficult if not impossible to distinguish from the original.&lt;/p&gt;&lt;h2&gt;4. Do not disclose personal information&lt;/h2&gt;&lt;ul&gt;&lt;li&gt;Avoid sharing personal information in e-mails, even if they appear to come from trustworthy sources.&lt;/li&gt;&lt;li&gt;If you are unsure whether an e-mail may legitimately ask for confidential data, it is best to ask the named provider via the support team or helpdesk.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Another important detail to keep in mind is that mailbox.org never asks its customers for passwords or credit card details via e-mail. Official e-mails from mailbox.org may inform you about changes to your account or new features, but they will never ask you to reveal your login details or payment information directly via e-mail.&lt;/p&gt;&lt;h2&gt;5. When in doubt: make enquiries&lt;/h2&gt;&lt;ul&gt;&lt;li&gt;Report suspicious e-mails to the mailbox.org support team.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;If you have doubts about the legitimacy of an e-mail, contact mailbox.org or suspicious companies and ask for clarification. You may provide the crucial tip to avoid further phishing attacks on other customers.&lt;/p&gt;&lt;h2&gt;This is how mailbox.org protects their customers from phishing attacks&lt;/h2&gt;&lt;ul&gt;&lt;li&gt;mailbox.org digitally signs its own e-mails.&lt;/li&gt;&lt;li&gt;mailbox.org uses state-of-the-art spam filters.&lt;/li&gt;&lt;li&gt;mailbox.org follows up on its customers' tips immediately.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;We sign our own e-mails so that verification is possible. Our spam filters screen out e-mails with known phishing URLs. So that our customers do not receive them in the first place. We use public phishing databases for this purpose. In addition, SPAM senders reported by our customers are thoroughly checked by us and blocked if necessary.&lt;/p&gt;&lt;p&gt;Despite all these measures, it is always a cat-and-mouse game between the cyber criminals and our defence measures. And that is why you should always remain vigilant.&lt;/p&gt;&lt;h2&gt;Conclusion&lt;/h2&gt;&lt;p&gt;To successfully protect yourself from phishing attacks, it is crucial to be vigilant and pay close attention to the e-mails you receive. If you receive an e-mail purporting to be from mailbox.org asking you to give up your password, credit card details or other confidential information, it is most likely a phishing attempt. Check links carefully before clicking on them. Look for spelling mistakes, unusual design elements and suspicious salutations.&lt;/p&gt;&lt;p&gt;If you suspect phishing, do not open any links or attachments. If in doubt, log in directly to mailbox.org yourself. By taking these tips to heart, you can better protect your personal data and minimise the risks of phishing attacks.&lt;/p&gt;

          
                                                  
      


  
          
        

  💡︎

      
        
        
    
      &lt;p&gt;New developments driven by artificial intelligence&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;br&gt;Although these guidelines remain valid, the rapid development of artificial intelligence means it is no longer sufficient to rely solely on the traditional tell-tale signs of phishing emails. Today, attackers use AI to combine multiple channels: an AI-generated, deceptively genuine email is followed by a vishing call with a cloned voice, or in extreme cases even a deepfake video call. Find out &lt;a href="https://mailbox.org/en/blog/business-email-compromise-protection-against-email-fraud/" data-entity-type="node" data-entity-uuid="3a9f36b1-3f8a-4f84-8126-95585abf91e8" data-entity-substitution="canonical" title="Business Email Compromise: How to prevent email fraud"&gt;in our blog on Business Email Compromise (BEC)&lt;/a&gt; how AI is making email fraud even more dangerous.&lt;/p&gt;
    
      

              


  
    
    
    
    &lt;h2&gt;1.&amp;nbsp;Check sender: Recognise genuine e-mails from mailbox.org&lt;/h2&gt;&lt;ul&gt;&lt;li&gt;Be wary of e-mails from unknown senders and check the e-mail address for plausibility.&lt;/li&gt;&lt;li&gt;Check the digital signature, if present.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;The "from address" can help you distinguish genuine e-mails from mailbox.org from fraudulent phishing attempts. Legitimate e-mails from mailbox.org are typically sent from the address "noreply@mailbox.org". Different departments, such as our support, of course use their own address - but our support contacts customers onlfy when they have a customer enquiry and not proactively.&lt;/p&gt;&lt;p&gt;If you receive an e-mail from an unknown address or even another domain claiming to be from mailbox.org, you should become extremely suspicious. It is important to pay attention not only to the displayed name of the sender, but also to the actual e-mail address. If the address is not "noreply@mailbox.org", it is probably a phishing attempt.&lt;/p&gt;&lt;p&gt;A trustworthy sender signs his e-mails with a digital signature. Our e-mails from noreply@mailbox.org are always signed. No fingerprint matching is necessary in the webmailer. The public key is already available. If an external e-mail client is used (Thunderbird or Outlook, etc.), which has its own PGP key management, the public key from noreply@mailbox.org must be imported. In this case, matching of the fingerprint is necessary. Here you can find our public key and key ID: &lt;a href="https://mailbox.org/en/legal-information"&gt;Digital signature from mailbox.org →&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;h2&gt;2. Avoid typical traps: Watch out for suspicious links, attachments and login pages&lt;/h2&gt;&lt;ul&gt;&lt;li&gt;Check the URL of the website you are visiting carefully and look out for spelling mistakes or unusual domain names.&lt;/li&gt;&lt;li&gt;Never open files in the attachment of a suspicious e-mail.&lt;/li&gt;&lt;li&gt;Be sceptical of e-mails that ask you to click on a link and log in or give out personal information.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;A key feature of phishing emails is the use of fake links that lead to mock login or password reset pages. If you receive an e-mail from mailbox.org asking you to visit a link, first check the URL of the link.&lt;/p&gt;&lt;p&gt;A genuine mailbox.org URL should always begin with "https://mailbox.org/" or "https://www.mailbox.org/". However, if the link points to another domain that looks similar to the real domain, it is probably a phishing attempt. For example, a phishing URL might look like "https://mailb0x.org/" or "https://www.mailbox-org.net/".&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;h2&gt;3. Identify inconsistencies: Mistakes, grammatical and spelling errors and unusual layout and design&lt;/h2&gt;&lt;ul&gt;&lt;li&gt;Be suspicious if you are not addressed as usual or the e-mail uses a different language.&lt;/li&gt;&lt;li&gt;Look out for deviations from the e-mails you have received so far.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Phishing e-mails often contain spelling, grammatical or spelling mistakes that should not appear in official e-mails from mailbox.org. Pay attention to whether the e-mail is worded unusually or contains errors that may indicate forgery.&lt;/p&gt;&lt;p&gt;Many phishing e-mails try to imitate the layout and design of the official e-mails of the attacked company. However, differences and inconsistencies are often noticeable. Look out for unusual formatting that differs from the normal e-mails from mailbox.org.&lt;/p&gt;&lt;p&gt;There are cases of very well-made forgeries, especially from well-known companies, which are difficult if not impossible to distinguish from the original.&lt;/p&gt;&lt;h2&gt;4. Do not disclose personal information&lt;/h2&gt;&lt;ul&gt;&lt;li&gt;Avoid sharing personal information in e-mails, even if they appear to come from trustworthy sources.&lt;/li&gt;&lt;li&gt;If you are unsure whether an e-mail may legitimately ask for confidential data, it is best to ask the named provider via the support team or helpdesk.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Another important detail to keep in mind is that mailbox.org never asks its customers for passwords or credit card details via e-mail. Official e-mails from mailbox.org may inform you about changes to your account or new features, but they will never ask you to reveal your login details or payment information directly via e-mail.&lt;/p&gt;&lt;h2&gt;5. When in doubt: make enquiries&lt;/h2&gt;&lt;ul&gt;&lt;li&gt;Report suspicious e-mails to the mailbox.org support team.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;If you have doubts about the legitimacy of an e-mail, contact mailbox.org or suspicious companies and ask for clarification. You may provide the crucial tip to avoid further phishing attacks on other customers.&lt;/p&gt;&lt;h2&gt;This is how mailbox.org protects their customers from phishing attacks&lt;/h2&gt;&lt;ul&gt;&lt;li&gt;mailbox.org digitally signs its own e-mails.&lt;/li&gt;&lt;li&gt;mailbox.org uses state-of-the-art spam filters.&lt;/li&gt;&lt;li&gt;mailbox.org follows up on its customers' tips immediately.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;We sign our own e-mails so that verification is possible. Our spam filters screen out e-mails with known phishing URLs. So that our customers do not receive them in the first place. We use public phishing databases for this purpose. In addition, SPAM senders reported by our customers are thoroughly checked by us and blocked if necessary.&lt;/p&gt;&lt;p&gt;Despite all these measures, it is always a cat-and-mouse game between the cyber criminals and our defence measures. And that is why you should always remain vigilant.&lt;/p&gt;&lt;h2&gt;Conclusion&lt;/h2&gt;&lt;p&gt;To successfully protect yourself from phishing attacks, it is crucial to be vigilant and pay close attention to the e-mails you receive. If you receive an e-mail purporting to be from mailbox.org asking you to give up your password, credit card details or other confidential information, it is most likely a phishing attempt. Check links carefully before clicking on them. Look for spelling mistakes, unusual design elements and suspicious salutations.&lt;/p&gt;&lt;p&gt;If you suspect phishing, do not open any links or attachments. If in doubt, log in directly to mailbox.org yourself. By taking these tips to heart, you can better protect your personal data and minimise the risks of phishing attacks.&lt;/p&gt;

          
                                                  
      


      
      &lt;h2 class="row__intro__title"&gt;            Insights &amp;amp; trends
      &lt;/h2&gt;
      Discover further best practices for your digital security.
              
            

&lt;a data-component-id="boxy:knob" data-component-variant="secondary" class="knob knob--secondary" href="https://mailbox.org/en/insights/"&gt;All articles&lt;/a&gt;

        
          
    
      
      
  
  
                    
                  
              
                  &lt;img loading="lazy" height="2160" width="4096" src="https://mailbox.org/sites/default/files/2026-08/mailbox%20EVAC%20Blog%20Business%20Continuity%20in%20der%20Lieferkette.jpeg" alt="mailbox EVAC Blog Business Continuity in der Lieferkette"&gt;

  


      
      
      
      Best practice, Business Continuitiy
    
    &lt;h3 class="snip__title"&gt;How to use business continuity as a competitive advantage in the supply chain&lt;/h3&gt;
  &lt;a class="snip__arrow" href="https://mailbox.org/en/blog/business-continuity-supply-chain/" aria-hidden="true"&gt;→&lt;/a&gt;
  &lt;a class="snip__link" href="https://mailbox.org/en/blog/business-continuity-supply-chain/"&gt;Read more about &lt;em class="placeholder"&gt;How to use business continuity as a competitive advantage in the supply chain&lt;/em&gt;&lt;/a&gt;


    
      
      
  
  
                    
                  
              
                  &lt;img loading="lazy" height="4065" width="6098" src="https://mailbox.org/sites/default/files/2026-07/mailbox%20Blog%20E-Mail-Alias.jpeg" alt="mailbox Blog E-Mail-Alias"&gt;

  


      
      
      
      Best practice, Data protection
    
    &lt;h3 class="snip__title"&gt;Email alias: How to protect your email address from spam&lt;/h3&gt;
  &lt;a class="snip__arrow" href="https://mailbox.org/en/blog/email-alias-protection-against-spam/" aria-hidden="true"&gt;→&lt;/a&gt;
  &lt;a class="snip__link" href="https://mailbox.org/en/blog/email-alias-protection-against-spam/"&gt;Read more about &lt;em class="placeholder"&gt;Email alias: How to protect your email address from spam&lt;/em&gt;&lt;/a&gt;


    
  
  


</description>
  <guid isPermaLink="false">2db1b30d-ccf2-40fb-bf08-b28a69e166ac</guid>
    <pubDate>Fri, 02 Jun 2023 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Phishing alert: How to spot fake mailbox.org e-mails</dc:title>
    <dc:identifier>2db1b30d-ccf2-40fb-bf08-b28a69e166ac</dc:identifier>
    </item>
<item>
  <title>Press Freedom Day: Protect privacy!</title>
  <link>https://mailbox.org/en/news/call-governments-world-press-freedom-day-protect-user-privacy/</link>
  <description>&lt;p&gt;On May 3, 2023, World Press Freedom Day, a global network of over XX organisations and companies united to release an open letter calling on governments to uphold the right to privacy and ensure a free and open internet. The letter highlights the importance of encryption in protecting user privacy, data security, safety online, press freedom, self-determination, and free expression.&lt;/p&gt;&lt;h2&gt;Why is encrypted communication so important for everyone?&lt;/h2&gt;&lt;p&gt;Encryption is a critical tool in preventing access to user data and communications by law enforcement and malicious actors. However, many governments in democratic countries, including the EU, the USA, UK, and Australia, are pushing for encrypted services to backdoor their encryption or otherwise block access to encrypted tools and services such as Tor, Signal, or Tutanota. These actions pose a significant threat to privacy, press freedom, and other fundamental human rights.&lt;/p&gt;&lt;p&gt;Many journalists, whistleblowers, and activists depend on secure, encrypted solutions to protect their data and identity. Access to these tools can be life or death for those who rely on them. While attacks on encryption might seem like a distant problem primarily faced in authoritarian countries, the threat is just as real and knocking at the doors of democratic nations.&lt;/p&gt;&lt;p&gt;End-to-end encryption makes it impossible for messaging apps such as WhatsApp and Signal to share users’ messages with anyone, including law enforcement, politicians, government officials, and hackers. It also stops the companies themselves from using user data for ads, marketing, and other profit-grabbing schemes. However, law enforcement argues that the ability to freely access individuals’ communications is critical for criminal investigations. This messaging has spurred worrying initiatives such as the Online Safety Bill in the UK, the Lawful Access to Encrypted Data Act and EARN IT Act in the USA, India’s Directions 20(3)/2022 - CERT-In, the Surveillance Legislation Amendment Act in Australia, and the proposed rules to prevent and combat child sexual abuse in the EU.&lt;/p&gt;&lt;h2&gt;The consequences of problematic laws: The surveillance state&lt;/h2&gt;&lt;p&gt;Should these laws pass, encrypted services will have only two options: weaken their level of security to comply with legislative guidelines or be blocked by governments. Services such as Signal, Tutanota, and Threema have already announced that they will not weaken their encryption to comply with such stipulations, likely forcing countries like the UK to block access to these services instead.&lt;/p&gt;&lt;p&gt;The ban on encrypted services is not surprising from authoritarian regimes. However, it is worrying that democratic governments like the UK, the US, the European Union, India, and Australia are moving in the same direction. Taking away the right to privacy online limits the ability to exercise fundamental human rights such as freedom of expression and opinion, press freedom, and freedom of speech.&lt;/p&gt;&lt;h2&gt;Our appeal: The fair, free internet.&lt;/h2&gt;&lt;p&gt;The internet must remain inclusive, free, and fair by providing everyone with unfettered access to online services, including encrypted services. This enables users to exercise their right to privacy, their right to engage in private discourse, and their right to hold those in power accountable by shedding light on human rights abuses, corruption, misinformation, and environmental destruction – something that is vital to the democratic process of forming public opinion.&lt;/p&gt;&lt;p&gt;As organisations that believe in the power of the right to privacy as an enabler of free speech and freedom of the press, we call on all governments to ensure that encryption is not being undermined via overreaching legislative initiatives. We urge them to revisit any bills, laws, and policies that legitimize undermining encryption or blocking access to secure communication.&lt;/p&gt;&lt;h2&gt;Our motivation: Protect the freedom of speech!&lt;/h2&gt;&lt;p&gt;We believe that encrypted communication is the cornerstone of a free and open internet. It is essential to the protection of human rights and the preservation of democracy. The efforts by some governments to undermine encryption are an attack on the right to privacy, and we must resist these attempts to ensure that we maintain a free and open society. It is up to all of us to speak out against these actions and demand that our governments protect our right to privacy and security online.&lt;/p&gt;&lt;p&gt;We encourage everyone to support these efforts and take action to protect our right to privacy. You can sign petitions, write to your elected representatives, and support organizations that are working to protect our digital rights. We must ensure that the internet remains a place where we can freely express ourselves, engage in private discourse, and hold those in power accountable. On this World Press Freedom Day, let us reaffirm our commitment to a free and open internet and pledge to defend our right to privacy and security online.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;The mailbox.org team&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-04/eigener-kommentar.png?itok=X4dWxdY_" type="image/png" length="134894"/><guid isPermaLink="false">c64b68b0-b87c-4f33-bcf9-cc9819538671</guid>
    <pubDate>Wed, 03 May 2023 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Press Freedom Day: Protect privacy!</dc:title>
    <dc:identifier>c64b68b0-b87c-4f33-bcf9-cc9819538671</dc:identifier>
    </item>
<item>
  <title>Press Freedom Day: Protect privacy!</title>
  <link>https://mailbox.org/en/news/call-governments-world-press-freedom-day-protect-user-privacy/</link>
  <description>&lt;p&gt;On May 3, 2023, World Press Freedom Day, a global network of over XX organisations and companies united to release an open letter calling on governments to uphold the right to privacy and ensure a free and open internet. The letter highlights the importance of encryption in protecting user privacy, data security, safety online, press freedom, self-determination, and free expression.&lt;/p&gt;&lt;h2&gt;Why is encrypted communication so important for everyone?&lt;/h2&gt;&lt;p&gt;Encryption is a critical tool in preventing access to user data and communications by law enforcement and malicious actors. However, many governments in democratic countries, including the EU, the USA, UK, and Australia, are pushing for encrypted services to backdoor their encryption or otherwise block access to encrypted tools and services such as Tor, Signal, or Tutanota. These actions pose a significant threat to privacy, press freedom, and other fundamental human rights.&lt;/p&gt;&lt;p&gt;Many journalists, whistleblowers, and activists depend on secure, encrypted solutions to protect their data and identity. Access to these tools can be life or death for those who rely on them. While attacks on encryption might seem like a distant problem primarily faced in authoritarian countries, the threat is just as real and knocking at the doors of democratic nations.&lt;/p&gt;&lt;p&gt;End-to-end encryption makes it impossible for messaging apps such as WhatsApp and Signal to share users’ messages with anyone, including law enforcement, politicians, government officials, and hackers. It also stops the companies themselves from using user data for ads, marketing, and other profit-grabbing schemes. However, law enforcement argues that the ability to freely access individuals’ communications is critical for criminal investigations. This messaging has spurred worrying initiatives such as the Online Safety Bill in the UK, the Lawful Access to Encrypted Data Act and EARN IT Act in the USA, India’s Directions 20(3)/2022 - CERT-In, the Surveillance Legislation Amendment Act in Australia, and the proposed rules to prevent and combat child sexual abuse in the EU.&lt;/p&gt;&lt;h2&gt;The consequences of problematic laws: The surveillance state&lt;/h2&gt;&lt;p&gt;Should these laws pass, encrypted services will have only two options: weaken their level of security to comply with legislative guidelines or be blocked by governments. Services such as Signal, Tutanota, and Threema have already announced that they will not weaken their encryption to comply with such stipulations, likely forcing countries like the UK to block access to these services instead.&lt;/p&gt;&lt;p&gt;The ban on encrypted services is not surprising from authoritarian regimes. However, it is worrying that democratic governments like the UK, the US, the European Union, India, and Australia are moving in the same direction. Taking away the right to privacy online limits the ability to exercise fundamental human rights such as freedom of expression and opinion, press freedom, and freedom of speech.&lt;/p&gt;&lt;h2&gt;Our appeal: The fair, free internet.&lt;/h2&gt;&lt;p&gt;The internet must remain inclusive, free, and fair by providing everyone with unfettered access to online services, including encrypted services. This enables users to exercise their right to privacy, their right to engage in private discourse, and their right to hold those in power accountable by shedding light on human rights abuses, corruption, misinformation, and environmental destruction – something that is vital to the democratic process of forming public opinion.&lt;/p&gt;&lt;p&gt;As organisations that believe in the power of the right to privacy as an enabler of free speech and freedom of the press, we call on all governments to ensure that encryption is not being undermined via overreaching legislative initiatives. We urge them to revisit any bills, laws, and policies that legitimize undermining encryption or blocking access to secure communication.&lt;/p&gt;&lt;h2&gt;Our motivation: Protect the freedom of speech!&lt;/h2&gt;&lt;p&gt;We believe that encrypted communication is the cornerstone of a free and open internet. It is essential to the protection of human rights and the preservation of democracy. The efforts by some governments to undermine encryption are an attack on the right to privacy, and we must resist these attempts to ensure that we maintain a free and open society. It is up to all of us to speak out against these actions and demand that our governments protect our right to privacy and security online.&lt;/p&gt;&lt;p&gt;We encourage everyone to support these efforts and take action to protect our right to privacy. You can sign petitions, write to your elected representatives, and support organizations that are working to protect our digital rights. We must ensure that the internet remains a place where we can freely express ourselves, engage in private discourse, and hold those in power accountable. On this World Press Freedom Day, let us reaffirm our commitment to a free and open internet and pledge to defend our right to privacy and security online.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;The mailbox.org team&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-04/eigener-kommentar.png?itok=X4dWxdY_" type="image/png" length="134894"/><guid isPermaLink="false">c64b68b0-b87c-4f33-bcf9-cc9819538671</guid>
    <pubDate>Wed, 03 May 2023 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Press Freedom Day: Protect privacy!</dc:title>
    <dc:identifier>c64b68b0-b87c-4f33-bcf9-cc9819538671</dc:identifier>
    </item>
<item>
  <title>Unencrypted password transmission in myMail</title>
  <link>https://mailbox.org/en/news/mailboxorg-discovers-unencrypted-password-transmission-mymail/</link>
  <description>&lt;p&gt;At mailbox.org, security and privacy are of the utmost importance to us, particularly in the area of email communication. Therefore, we would like to inform you about a critical security vulnerability in the myMail client for iOS that we have recently discovered. This vulnerability results in unencrypted transmission of user passwords and emails.&lt;/p&gt;&lt;p&gt;Our team became aware of the issue after our customers reported transmission errors when sending emails via the myMail client in the user forum. Upon a thorough examination of the logs, we found that the myMail app attempts to transmit passwords without the required TLS encryption, thus leaving them unprotected and posing a significant security risk. Instead of sending the usual "STARTTLS" command after establishing a connection, the app continued to transmit the user's login details unencrypted. As a result, we were able to extract users' passwords from the connection logs.&lt;/p&gt;&lt;p&gt;At mailbox.org, we consistently reject unencrypted connections on our servers to ensure your security at all times. It was only for this reason that the myMail app's connection attempts failed, bringing the issue to our attention.&lt;/p&gt;&lt;p&gt;This problem not only affects our customers but also poses a general security risk for all users who use the myMail client. Contents and passwords can be intercepted and read by third parties, especially when users are in an open network. If other providers allow unencrypted connections and are used in conjunction with the current version of the myMail app, attackers can also read the content of unencrypted emails.&lt;/p&gt;&lt;p&gt;We strongly recommend that you stop using the myMail client with our service or other email providers until the app developers have resolved these security issues. There are numerous alternative email clients that offer higher security standards and better protect your privacy. At the same time, the current incident underscores the importance of communicating exclusively through securely configured systems that enforce encryption.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-04/mailbox-news-und-updates-warnung.jpg?itok=reW9cU74" type="image/jpeg" length="238141"/><guid isPermaLink="false">bed1f422-c51d-4762-96b5-342813edb9d3</guid>
    <pubDate>Wed, 26 Apr 2023 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Unencrypted password transmission in myMail</dc:title>
    <dc:identifier>bed1f422-c51d-4762-96b5-342813edb9d3</dc:identifier>
    </item>
<item>
  <title>Unencrypted password transmission in myMail</title>
  <link>https://mailbox.org/en/news/mailboxorg-discovers-unencrypted-password-transmission-mymail/</link>
  <description>&lt;p&gt;At mailbox.org, security and privacy are of the utmost importance to us, particularly in the area of email communication. Therefore, we would like to inform you about a critical security vulnerability in the myMail client for iOS that we have recently discovered. This vulnerability results in unencrypted transmission of user passwords and emails.&lt;/p&gt;&lt;p&gt;Our team became aware of the issue after our customers reported transmission errors when sending emails via the myMail client in the user forum. Upon a thorough examination of the logs, we found that the myMail app attempts to transmit passwords without the required TLS encryption, thus leaving them unprotected and posing a significant security risk. Instead of sending the usual "STARTTLS" command after establishing a connection, the app continued to transmit the user's login details unencrypted. As a result, we were able to extract users' passwords from the connection logs.&lt;/p&gt;&lt;p&gt;At mailbox.org, we consistently reject unencrypted connections on our servers to ensure your security at all times. It was only for this reason that the myMail app's connection attempts failed, bringing the issue to our attention.&lt;/p&gt;&lt;p&gt;This problem not only affects our customers but also poses a general security risk for all users who use the myMail client. Contents and passwords can be intercepted and read by third parties, especially when users are in an open network. If other providers allow unencrypted connections and are used in conjunction with the current version of the myMail app, attackers can also read the content of unencrypted emails.&lt;/p&gt;&lt;p&gt;We strongly recommend that you stop using the myMail client with our service or other email providers until the app developers have resolved these security issues. There are numerous alternative email clients that offer higher security standards and better protect your privacy. At the same time, the current incident underscores the importance of communicating exclusively through securely configured systems that enforce encryption.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-04/mailbox-news-und-updates-warnung.jpg?itok=reW9cU74" type="image/jpeg" length="238141"/><guid isPermaLink="false">bed1f422-c51d-4762-96b5-342813edb9d3</guid>
    <pubDate>Wed, 26 Apr 2023 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Unencrypted password transmission in myMail</dc:title>
    <dc:identifier>bed1f422-c51d-4762-96b5-342813edb9d3</dc:identifier>
    </item>
<item>
  <title>Data retention remains illegal</title>
  <link>https://mailbox.org/en/news/data-retention-remains-illegal-our-statement-federal-constitutional-courts-ruling/</link>
  <description>&lt;p&gt;Today, the German Federal Constitutional Court published its decision on a constitutional complaint against the law on indiscriminate data retention. The decision is overshadowed by a ruling of the European Court of Justice (ECJ) already issued in September 2022, which has already judged this law to be incompatible with EU law. The German Federal Constitutional Court has now adopted the position of the ECJ in full, with further evidence, and confirmed the unconstitutionality defacto.&lt;/p&gt;&lt;p&gt;The indiscriminate retention of data without any reason would lead to a preventive collection of all communication data – connection data of calls, SMS and IP addresses including location information - of the citizens and thus to an encroachment on their fundamental rights. Experts deplore a kind of "general suspicion" against one's own citizens, which invalidates an essential principle of the German legal system – based on the presumption of innocence.&lt;/p&gt;&lt;p&gt;As a representative of the internet and provider industry, mailbox.org filed a constitutional complaint against the law in February 2018. The constitutional complaint was made together with the association "Digitalcourage", the German journalists' association DJV and other representatives of civil society.&lt;/p&gt;&lt;p&gt;Peer Heinlein, founder and managing director of mailbox.org, says about today's decision of the BVerfG:&lt;/p&gt;&lt;p&gt;"The fact that this constitutional complaint was made was right and important. Once again, the Federal Constitutional Court has strengthened fundamental rights and rejected the encroaching surveillance policy. It has made clear how important free, non-surveillance communication is as the basis of freedom of thought and expression. For years, German politicians have tried again and again to introduce data retention through the back door. It is socially necessary that this issue is put to rest once and for all. Conservative political circles who would wish otherwise must also realise this.&lt;/p&gt;&lt;p&gt;The success of the complaint also shows how important socially and democratically oriented communication providers like mailbox.org are, and the crash of the once so popular communication platform Twitter has shown how important distributed decentralised alternatives are. Unlike large commercial providers like Twitter &amp;amp; Co, these watch over free and secure communication and spare neither expense nor effort to defend it elaborately. They are the antithesis to the bundling of power of communication with large providers and thus an important cornerstone of democratic structures and free and secure communication on the internet."&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-jurisdiction-2.png?itok=wh-UKMiR" type="image/png" length="260317"/><guid isPermaLink="false">ac8061d3-9f2b-4876-820c-2b0a0dcb17f7</guid>
    <pubDate>Thu, 30 Mar 2023 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Data retention remains illegal</dc:title>
    <dc:identifier>ac8061d3-9f2b-4876-820c-2b0a0dcb17f7</dc:identifier>
    </item>
<item>
  <title>Data retention remains illegal</title>
  <link>https://mailbox.org/en/news/data-retention-remains-illegal-our-statement-federal-constitutional-courts-ruling/</link>
  <description>&lt;p&gt;Today, the German Federal Constitutional Court published its decision on a constitutional complaint against the law on indiscriminate data retention. The decision is overshadowed by a ruling of the European Court of Justice (ECJ) already issued in September 2022, which has already judged this law to be incompatible with EU law. The German Federal Constitutional Court has now adopted the position of the ECJ in full, with further evidence, and confirmed the unconstitutionality defacto.&lt;/p&gt;&lt;p&gt;The indiscriminate retention of data without any reason would lead to a preventive collection of all communication data – connection data of calls, SMS and IP addresses including location information - of the citizens and thus to an encroachment on their fundamental rights. Experts deplore a kind of "general suspicion" against one's own citizens, which invalidates an essential principle of the German legal system – based on the presumption of innocence.&lt;/p&gt;&lt;p&gt;As a representative of the internet and provider industry, mailbox.org filed a constitutional complaint against the law in February 2018. The constitutional complaint was made together with the association "Digitalcourage", the German journalists' association DJV and other representatives of civil society.&lt;/p&gt;&lt;p&gt;Peer Heinlein, founder and managing director of mailbox.org, says about today's decision of the BVerfG:&lt;/p&gt;&lt;p&gt;"The fact that this constitutional complaint was made was right and important. Once again, the Federal Constitutional Court has strengthened fundamental rights and rejected the encroaching surveillance policy. It has made clear how important free, non-surveillance communication is as the basis of freedom of thought and expression. For years, German politicians have tried again and again to introduce data retention through the back door. It is socially necessary that this issue is put to rest once and for all. Conservative political circles who would wish otherwise must also realise this.&lt;/p&gt;&lt;p&gt;The success of the complaint also shows how important socially and democratically oriented communication providers like mailbox.org are, and the crash of the once so popular communication platform Twitter has shown how important distributed decentralised alternatives are. Unlike large commercial providers like Twitter &amp;amp; Co, these watch over free and secure communication and spare neither expense nor effort to defend it elaborately. They are the antithesis to the bundling of power of communication with large providers and thus an important cornerstone of democratic structures and free and secure communication on the internet."&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-jurisdiction-2.png?itok=wh-UKMiR" type="image/png" length="260317"/><guid isPermaLink="false">ac8061d3-9f2b-4876-820c-2b0a0dcb17f7</guid>
    <pubDate>Thu, 30 Mar 2023 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Data retention remains illegal</dc:title>
    <dc:identifier>ac8061d3-9f2b-4876-820c-2b0a0dcb17f7</dc:identifier>
    </item>
<item>
  <title>The new reseller management from mailbox.org</title>
  <link>https://mailbox.org/en/news/new-reseller-administration-mailboxorg/</link>
  <description>&lt;p&gt;Not only private customers and companies are among mailbox.org's customers, but also resellers. For example, IT system houses, web agencies and other service providers have the opportunity to offer their customers the secure email mailboxes of mailbox.org as resellers. Today, we are pleased to release a completely newly developed administration for resellers. With the help of this new interface, it will be easier in the future for smaller resellers who do not use API interfaces to distribute our services.&lt;/p&gt;&lt;h2&gt;Functions and advantages of the reseller administration&lt;/h2&gt;&lt;p&gt;Our reseller administration can be conveniently operated via a web browser enabling quick and easy handling of your own customers. The core functions of the administration are the creation, management and deletion of customer accounts. Resellers can create new customer accounts, adjust customer settings and delete accounts when they are closed. In addition, resellers can also retrieve invoices in PDF and CSV format. The CSV format is particularly useful as it allows for easier further processing of the data in other software.&lt;br&gt;mailbox.org services for resellers&lt;/p&gt;&lt;p&gt;The new administration will make it easier for resellers to use the mailbox.org service and offer their customers a secure e-mail service. With mailbox.org, resellers and their customers benefit from our professional email infrastructure as well as the comprehensive communication platform, which is ad-free, hosted in Germany and equipped with solid spam and virus filters.&lt;/p&gt;&lt;p&gt;mailbox.org for resellers includes the following services:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;The secure e-mail box under your own domain, incl. calendar and address book.&lt;/li&gt;&lt;li&gt;Cloud storage incl. encryption and content sharing&lt;/li&gt;&lt;li&gt;The online office for the most common applications, in the browser - without installation&lt;/li&gt;&lt;li&gt;Video conferencing with OpenTalk, the Heinlein Group's own development&lt;/li&gt;&lt;li&gt;Support for customers can either be provided by the company itself or by mailbox.org support in the form of appropriate service packages.&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Digitally sovereign with mailbox.org&lt;/h2&gt;&lt;p&gt;Overall, mailbox.org's reseller administration is a useful addition for resellers who want to offer secure and DSGVO-compliant services. The administration offers a simple alternative to the API of mailbox.org and is particularly suitable for resellers who do not have their own developer teams or do not want to use an API. With mailbox.org, they can thus offer secure email services, groupware, cloud storage, an office suite and video conferencing and thus contribute to a digitally sovereign society.&lt;/p&gt;&lt;p&gt;Are you interested in more information? Please contact us through our &lt;a href="https://mailbox.org/en/resellers"&gt;reseller page →&lt;/a&gt;&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-team-2.jpeg?itok=JunenBYW" type="image/jpeg" length="404224"/><guid isPermaLink="false">b2e6207b-edf6-4fe7-bc27-af397a898f22</guid>
    <pubDate>Thu, 16 Mar 2023 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>The new reseller management from mailbox.org</dc:title>
    <dc:identifier>b2e6207b-edf6-4fe7-bc27-af397a898f22</dc:identifier>
    </item>
<item>
  <title>The new reseller management from mailbox.org</title>
  <link>https://mailbox.org/en/news/new-reseller-administration-mailboxorg/</link>
  <description>&lt;p&gt;Not only private customers and companies are among mailbox.org's customers, but also resellers. For example, IT system houses, web agencies and other service providers have the opportunity to offer their customers the secure email mailboxes of mailbox.org as resellers. Today, we are pleased to release a completely newly developed administration for resellers. With the help of this new interface, it will be easier in the future for smaller resellers who do not use API interfaces to distribute our services.&lt;/p&gt;&lt;h2&gt;Functions and advantages of the reseller administration&lt;/h2&gt;&lt;p&gt;Our reseller administration can be conveniently operated via a web browser enabling quick and easy handling of your own customers. The core functions of the administration are the creation, management and deletion of customer accounts. Resellers can create new customer accounts, adjust customer settings and delete accounts when they are closed. In addition, resellers can also retrieve invoices in PDF and CSV format. The CSV format is particularly useful as it allows for easier further processing of the data in other software.&lt;br&gt;mailbox.org services for resellers&lt;/p&gt;&lt;p&gt;The new administration will make it easier for resellers to use the mailbox.org service and offer their customers a secure e-mail service. With mailbox.org, resellers and their customers benefit from our professional email infrastructure as well as the comprehensive communication platform, which is ad-free, hosted in Germany and equipped with solid spam and virus filters.&lt;/p&gt;&lt;p&gt;mailbox.org for resellers includes the following services:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;The secure e-mail box under your own domain, incl. calendar and address book.&lt;/li&gt;&lt;li&gt;Cloud storage incl. encryption and content sharing&lt;/li&gt;&lt;li&gt;The online office for the most common applications, in the browser - without installation&lt;/li&gt;&lt;li&gt;Video conferencing with OpenTalk, the Heinlein Group's own development&lt;/li&gt;&lt;li&gt;Support for customers can either be provided by the company itself or by mailbox.org support in the form of appropriate service packages.&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Digitally sovereign with mailbox.org&lt;/h2&gt;&lt;p&gt;Overall, mailbox.org's reseller administration is a useful addition for resellers who want to offer secure and DSGVO-compliant services. The administration offers a simple alternative to the API of mailbox.org and is particularly suitable for resellers who do not have their own developer teams or do not want to use an API. With mailbox.org, they can thus offer secure email services, groupware, cloud storage, an office suite and video conferencing and thus contribute to a digitally sovereign society.&lt;/p&gt;&lt;p&gt;Are you interested in more information? Please contact us through our &lt;a href="https://mailbox.org/en/resellers"&gt;reseller page →&lt;/a&gt;&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-team-2.jpeg?itok=JunenBYW" type="image/jpeg" length="404224"/><guid isPermaLink="false">b2e6207b-edf6-4fe7-bc27-af397a898f22</guid>
    <pubDate>Thu, 16 Mar 2023 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>The new reseller management from mailbox.org</dc:title>
    <dc:identifier>b2e6207b-edf6-4fe7-bc27-af397a898f22</dc:identifier>
    </item>
<item>
  <title>mailbox.org at CloudFest from 21 to 23 March 2023</title>
  <link>https://mailbox.org/en/news/mailboxorg-cloudfest-21-23-march-2023/</link>
  <description>&lt;p&gt;&lt;a href="https://www.cloudfest.com/" target="_blank" rel="noopener"&gt;CloudFest&lt;/a&gt; is the world's leading trade fair and conference for the global cloud computing industry and will take place from 21 to 23 March 2023 at Europa-Park in Rust. More than 6000 participants from 65 countries will learn about the latest trends.&lt;/p&gt;&lt;p&gt;mailbox.org will be present as an exhibitor with its own booth and is looking forward to many good conversations with visitors and co-exhibitors. - We will be happy to answer your questions about secure email mailboxes and our features such as online office, cloud storage and video conferencing and explain the possibilities of integration for companies, educational institutions and also resellers.&lt;/p&gt;&lt;p&gt;We look forward to seeing you on site at booth R38.&lt;/p&gt;&lt;p&gt;See you soon,&lt;br&gt;Your mailbox.org team&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-events.jpeg?itok=xm5FlWxg" type="image/jpeg" length="391248"/><guid isPermaLink="false">3186543b-2610-40b7-8c7e-a7852956135d</guid>
    <pubDate>Tue, 07 Mar 2023 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>mailbox.org at CloudFest from 21 to 23 March 2023</dc:title>
    <dc:identifier>3186543b-2610-40b7-8c7e-a7852956135d</dc:identifier>
    </item>
<item>
  <title>mailbox.org at CloudFest from 21 to 23 March 2023</title>
  <link>https://mailbox.org/en/news/mailboxorg-cloudfest-21-23-march-2023/</link>
  <description>&lt;p&gt;&lt;a href="https://www.cloudfest.com/" target="_blank" rel="noopener"&gt;CloudFest&lt;/a&gt; is the world's leading trade fair and conference for the global cloud computing industry and will take place from 21 to 23 March 2023 at Europa-Park in Rust. More than 6000 participants from 65 countries will learn about the latest trends.&lt;/p&gt;&lt;p&gt;mailbox.org will be present as an exhibitor with its own booth and is looking forward to many good conversations with visitors and co-exhibitors. - We will be happy to answer your questions about secure email mailboxes and our features such as online office, cloud storage and video conferencing and explain the possibilities of integration for companies, educational institutions and also resellers.&lt;/p&gt;&lt;p&gt;We look forward to seeing you on site at booth R38.&lt;/p&gt;&lt;p&gt;See you soon,&lt;br&gt;Your mailbox.org team&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-events.jpeg?itok=xm5FlWxg" type="image/jpeg" length="391248"/><guid isPermaLink="false">3186543b-2610-40b7-8c7e-a7852956135d</guid>
    <pubDate>Tue, 07 Mar 2023 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>mailbox.org at CloudFest from 21 to 23 March 2023</dc:title>
    <dc:identifier>3186543b-2610-40b7-8c7e-a7852956135d</dc:identifier>
    </item>
<item>
  <title>Transparency Report 2022</title>
  <link>https://mailbox.org/en/news/transparency-report-2022/</link>
  <description>&lt;p&gt;In our transparency report, we disclose the type and scope of requests for information that mailbox.org has received from public authorities. In the previous year 2022, the total number of requests has decreased the second year in a row. However, more than a quarter of all initial requests had errors.&lt;/p&gt;&lt;p&gt;A total of 14 out of the 55 requests we received by public authorities in 2022 were rejected because of errors that made them legally inadmissible. Seven of these requests were subsequently resubmitted in correct form and processed accordingly. The other seven requests were rejected. Compared to the previous year, the proportion of unlawful requests that were ultimately rejected did increase slightly: from 9.2% in 2021 to 12.7% in 2022.&lt;/p&gt;&lt;h2&gt;Finally: No more unencrypted requests&lt;/h2&gt;&lt;p&gt;2022 was the last year in which we had to accept requests through unencrypted means such as fax or e-mails in plain text. These accounted for a considerable 61.8 % of all the requests sent to us in 2022. While the German Federal Network Agency has required providers like mailbox.org to maintain a secure data interface since 2017, investigating authorities were only mandated to use “secure” data transmission from 2023 onward.&lt;/p&gt;&lt;p&gt;Consequently, starting from 2023, we will only respond to requests for information that are transmitted to us over adequate secure channels (PGP e-mail or letter mail).&lt;/p&gt;&lt;p&gt;&lt;em&gt;“It is good to see that finally, more and more investigating authorities now support the “E-Mail-ESB” mechanism (PGP-encrypted transmission of requests), as required by the German Federal Network Agency. For over four years, providers like us have been obliged to use “secure” channels for data transmission, and we have been supporting this requirement right from the start. However, until now there was no binding requirement for any investigating authorities to do the same, and many continued to send requests unencrypted over the Internet, even though these requests may have contained highly sensitive data.&lt;/em&gt;&lt;/p&gt;&lt;p&gt;&lt;em&gt;In late 2021, the Federal Network Agency ruled that requests for information must be sent entirely through “secure” channels, which now also includes the investigating authorities communicating to providers. Secure channels means encrypted e-mail or letter mail. Fax, which had been widely used until recently, is no longer considered “secure”. There was a grace period covering 2022 but starting at the beginning of this year, the requirements have been in force without exception, at last. We welcome this (late) development, as any user data subject to those requests will now be protected during transmission.”&amp;nbsp;&lt;/em&gt;&lt;br&gt;&lt;em&gt;Peer Hartleben, Data Protection Officer at mailbox.org&lt;/em&gt;&lt;/p&gt;&lt;h2&gt;A brief comparison to the year before&lt;/h2&gt;&lt;ol&gt;&lt;li&gt;The total number of requests has decreased from 65 (2021) to 55 (2022).&lt;/li&gt;&lt;li&gt;74.6% of all requests were formally correct, compared to 84.6% in 2021.&lt;/li&gt;&lt;li&gt;Most of the requests were received as a plain-text email.&lt;/li&gt;&lt;/ol&gt;&lt;h2&gt;Requests sent to mailbox.org in the year 2022&lt;/h2&gt;&lt;p&gt;Total number of requests: 55&lt;br&gt;From German authorities: 51&lt;br&gt;From foreign authorities: 1&lt;br&gt;From foreign non-EU authorities: 3&lt;/p&gt;&lt;p&gt;Organisations&lt;br&gt;Criminal investigative authorities: 55&lt;br&gt;Customs authorities: 0&lt;br&gt;Intelligence services: 0&lt;/p&gt;&lt;p&gt;Request type&lt;br&gt;Contact data requests: 49&lt;br&gt;Inbox confiscations: 1&lt;br&gt;Traffic data requests: 0&lt;br&gt;Telecommunications interceptions: 5&lt;/p&gt;&lt;p&gt;Our reports from previous years can be found in the section &lt;a href="https://mailbox.org/preview.php/en/company#transparency-report" target="_blank" title="Go to all transparency reports" rel="noopener"&gt;transparency reports&lt;/a&gt;.&lt;/p&gt;&lt;h3&gt;How we deal with requests&lt;/h3&gt;&lt;p&gt;mailbox.org follows a standardised process when dealing with requests for information from official authorities. Each request will be comprehensively reviewed and assessed by our data protection officer and a lawyer, and then either processed or rejected accordingly. When a request gets rejected, the submitting authority may correct any errors and then resubmit for another review. Data will only be released by us if a related request is actually lawful and formally correct.&lt;/p&gt;&lt;h3&gt;Data that authorities may be interested in&lt;/h3&gt;&lt;ol&gt;&lt;li&gt;Contact data: This includes the name, address and phone number of the account holder, as well as details about their contract with us.&lt;/li&gt;&lt;li&gt;E-mail data: Access to all e-mails currently held in an account's mailbox.&lt;/li&gt;&lt;li&gt;Traffic data: The IP addresses associated with mail server logins when fetching, reading, or sending e-mails.&lt;/li&gt;&lt;li&gt;Telecommunications interception data: Obtained through the permanent surveillance of all ongoing e-mail communication of an account.&lt;/li&gt;&lt;/ol&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-04/mailbox-news-und-updates-transparenzbericht.jpg?itok=SMV4eTPL" type="image/jpeg" length="268110"/><guid isPermaLink="false">d5fd2613-037f-4b2a-bf36-68c3da0d9d76</guid>
    <pubDate>Tue, 07 Feb 2023 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Transparency Report 2022</dc:title>
    <dc:identifier>d5fd2613-037f-4b2a-bf36-68c3da0d9d76</dc:identifier>
    </item>
<item>
  <title>Transparency Report 2022</title>
  <link>https://mailbox.org/en/news/transparency-report-2022/</link>
  <description>&lt;p&gt;In our transparency report, we disclose the type and scope of requests for information that mailbox.org has received from public authorities. In the previous year 2022, the total number of requests has decreased the second year in a row. However, more than a quarter of all initial requests had errors.&lt;/p&gt;&lt;p&gt;A total of 14 out of the 55 requests we received by public authorities in 2022 were rejected because of errors that made them legally inadmissible. Seven of these requests were subsequently resubmitted in correct form and processed accordingly. The other seven requests were rejected. Compared to the previous year, the proportion of unlawful requests that were ultimately rejected did increase slightly: from 9.2% in 2021 to 12.7% in 2022.&lt;/p&gt;&lt;h2&gt;Finally: No more unencrypted requests&lt;/h2&gt;&lt;p&gt;2022 was the last year in which we had to accept requests through unencrypted means such as fax or e-mails in plain text. These accounted for a considerable 61.8 % of all the requests sent to us in 2022. While the German Federal Network Agency has required providers like mailbox.org to maintain a secure data interface since 2017, investigating authorities were only mandated to use “secure” data transmission from 2023 onward.&lt;/p&gt;&lt;p&gt;Consequently, starting from 2023, we will only respond to requests for information that are transmitted to us over adequate secure channels (PGP e-mail or letter mail).&lt;/p&gt;&lt;p&gt;&lt;em&gt;“It is good to see that finally, more and more investigating authorities now support the “E-Mail-ESB” mechanism (PGP-encrypted transmission of requests), as required by the German Federal Network Agency. For over four years, providers like us have been obliged to use “secure” channels for data transmission, and we have been supporting this requirement right from the start. However, until now there was no binding requirement for any investigating authorities to do the same, and many continued to send requests unencrypted over the Internet, even though these requests may have contained highly sensitive data.&lt;/em&gt;&lt;/p&gt;&lt;p&gt;&lt;em&gt;In late 2021, the Federal Network Agency ruled that requests for information must be sent entirely through “secure” channels, which now also includes the investigating authorities communicating to providers. Secure channels means encrypted e-mail or letter mail. Fax, which had been widely used until recently, is no longer considered “secure”. There was a grace period covering 2022 but starting at the beginning of this year, the requirements have been in force without exception, at last. We welcome this (late) development, as any user data subject to those requests will now be protected during transmission.”&amp;nbsp;&lt;/em&gt;&lt;br&gt;&lt;em&gt;Peer Hartleben, Data Protection Officer at mailbox.org&lt;/em&gt;&lt;/p&gt;&lt;h2&gt;A brief comparison to the year before&lt;/h2&gt;&lt;ol&gt;&lt;li&gt;The total number of requests has decreased from 65 (2021) to 55 (2022).&lt;/li&gt;&lt;li&gt;74.6% of all requests were formally correct, compared to 84.6% in 2021.&lt;/li&gt;&lt;li&gt;Most of the requests were received as a plain-text email.&lt;/li&gt;&lt;/ol&gt;&lt;h2&gt;Requests sent to mailbox.org in the year 2022&lt;/h2&gt;&lt;p&gt;Total number of requests: 55&lt;br&gt;From German authorities: 51&lt;br&gt;From foreign authorities: 1&lt;br&gt;From foreign non-EU authorities: 3&lt;/p&gt;&lt;p&gt;Organisations&lt;br&gt;Criminal investigative authorities: 55&lt;br&gt;Customs authorities: 0&lt;br&gt;Intelligence services: 0&lt;/p&gt;&lt;p&gt;Request type&lt;br&gt;Contact data requests: 49&lt;br&gt;Inbox confiscations: 1&lt;br&gt;Traffic data requests: 0&lt;br&gt;Telecommunications interceptions: 5&lt;/p&gt;&lt;p&gt;Our reports from previous years can be found in the section &lt;a href="https://mailbox.org/preview.php/en/company#transparency-report" target="_blank" title="Go to all transparency reports" rel="noopener"&gt;transparency reports&lt;/a&gt;.&lt;/p&gt;&lt;h3&gt;How we deal with requests&lt;/h3&gt;&lt;p&gt;mailbox.org follows a standardised process when dealing with requests for information from official authorities. Each request will be comprehensively reviewed and assessed by our data protection officer and a lawyer, and then either processed or rejected accordingly. When a request gets rejected, the submitting authority may correct any errors and then resubmit for another review. Data will only be released by us if a related request is actually lawful and formally correct.&lt;/p&gt;&lt;h3&gt;Data that authorities may be interested in&lt;/h3&gt;&lt;ol&gt;&lt;li&gt;Contact data: This includes the name, address and phone number of the account holder, as well as details about their contract with us.&lt;/li&gt;&lt;li&gt;E-mail data: Access to all e-mails currently held in an account's mailbox.&lt;/li&gt;&lt;li&gt;Traffic data: The IP addresses associated with mail server logins when fetching, reading, or sending e-mails.&lt;/li&gt;&lt;li&gt;Telecommunications interception data: Obtained through the permanent surveillance of all ongoing e-mail communication of an account.&lt;/li&gt;&lt;/ol&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-04/mailbox-news-und-updates-transparenzbericht.jpg?itok=SMV4eTPL" type="image/jpeg" length="268110"/><guid isPermaLink="false">d5fd2613-037f-4b2a-bf36-68c3da0d9d76</guid>
    <pubDate>Tue, 07 Feb 2023 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Transparency Report 2022</dc:title>
    <dc:identifier>d5fd2613-037f-4b2a-bf36-68c3da0d9d76</dc:identifier>
    </item>
<item>
  <title>New features: Scheduling and live text editor</title>
  <link>https://mailbox.org/en/news/new-collaboration-features-appointment-scheduling-and-multi-user-text-editing/</link>
  <description>&lt;p&gt;Two new features are now available in our PREMIUM and STANDARD price plans. With "Framadate" users can easily coordinate appointments and create polls, share a link to these with others, and evaluate the results. Our new "Etherpad" offers a web-based text editing tool that several people can use at the same time to edit documents and collaborate with each other.&lt;/p&gt;&lt;p&gt;Like all our other services, these new features are also hosted in our German data centres, free of advertising and tracking, and fully meeting the requirements of the General Data Protection Regulation (GDPR). Of course they are also open source – just the way we like it. The Framadate and Etherpad features are part of the mailbox.org Online Office and can be accessed directly in the menu bar at the top.&lt;/p&gt;&lt;h2&gt;Framadate at mailbox.org&lt;/h2&gt;&lt;p&gt;The Framadate tool has two basic functions: "Schedule an event" and "Standard poll". They will save you time by making it easy to conduct polls among small and large groups of people. These additional options are also available:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Invitations by link or e-mail address&lt;/li&gt;&lt;li&gt;Password protection&lt;/li&gt;&lt;li&gt;Assigning an expiry date to a poll&lt;/li&gt;&lt;li&gt;Display of poll results&lt;/li&gt;&lt;li&gt;Customisable URLs&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Etherpad at mailbox.org&lt;/h2&gt;&lt;p&gt;Etherpad is our new service for collaborative text processing. Any changes made by a user will be immediately visible to all other editors who are working on the same text, and the individual contributions can be distinguished by colour. In addition, there is an integrated chat that can be used to coordinate the editing work. See below a summary of what the Etherpad feature has to offer:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Collaborative writing&lt;/li&gt;&lt;li&gt;Import/export (Etherpad file, HTML, TXT)&lt;/li&gt;&lt;li&gt;Text processing (Rich Text)&lt;/li&gt;&lt;li&gt;Editing history&lt;/li&gt;&lt;li&gt;Colours for individual authors&lt;/li&gt;&lt;li&gt;Comment function&lt;/li&gt;&lt;li&gt;Integrated chat&lt;/li&gt;&lt;li&gt;Administration of existing Etherpads&lt;/li&gt;&lt;/ul&gt;&lt;h2 class="western" id="FramadateundEtherpad-Undjetztmalganzpraktisch"&gt;Practically speaking – an example use case&lt;/h2&gt;&lt;p&gt;How can our new features help to make your everyday life easier? Whether it's about organising a family reunion, a meeting with your parents or a holiday trip with friends: Finding a date that suits everyone or getting a quick idea about what people think or want to do can quickly become complicated and laborious to do via e-mail. The it is good to have a useful tool at hand that help you get things done while also protecting your privacy at the same time.&lt;/p&gt;&lt;p&gt;Framadate helps you coordinate activities and dates with multiple people and make decisions together with everyone. For example, what would be a good date for a trip with your friends, and where to go?&lt;/p&gt;&lt;p&gt;You can use the "Schedule an event" button to create a poll with a selection of dates, and then send e-mail invitations to anyone involved.&lt;/p&gt;&lt;p&gt;When you need to make a decision about something, use the standard poll of Framadate. Images can be attached here for illustration and so, your friends get a much better idea of what the different travel destinations have to offer.&lt;/p&gt;&lt;p&gt;Now that there is a basic plan for your holiday with friends, it's time to sort out the finer details. Perhaps do a &lt;a href="https://mailbox.org/en/post/hello-opentalk-the-gdpr-compliant-video-conferencing-solution" target="_blank" title="Read more about OpenTalk" rel="noopener"&gt;video call using our new OpenTalk&lt;/a&gt; solution? You can also use Etherpad to jot down some notes and ideas about planned holiday activities and the places to visit on your trip.&lt;/p&gt;&lt;p&gt;Have fun and work well together,&lt;br&gt;Your mailbox.org team&lt;/p&gt;&lt;hr&gt;&lt;h2&gt;New: OpenTalk at mailbox.org&lt;/h2&gt;&lt;p&gt;OpenTalk is a new video conferencing solution with many interesting features, such as breakout rooms, a lobby and waiting room, polls, moderation roles, chat, telephone dial-in, and straightforward conference scheduling. OpenTalk runs directly in your browser.&lt;/p&gt;&lt;p&gt;Learn more about our new video conferencing solution &lt;a href="https://mailbox.org/en/post/hello-opentalk-the-gdpr-compliant-video-conferencing-solution" target="_blank" title="Read more about OpenTalk" rel="noopener"&gt;OpenTalk -&amp;gt;&lt;/a&gt;&lt;/p&gt;&amp;nbsp;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-calendar.jpeg?itok=jdhFuIrn" type="image/jpeg" length="409238"/><guid isPermaLink="false">f8e57e86-ad48-4bd4-882b-17f402caa8ec</guid>
    <pubDate>Tue, 15 Nov 2022 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>New features: Scheduling and live text editor</dc:title>
    <dc:identifier>f8e57e86-ad48-4bd4-882b-17f402caa8ec</dc:identifier>
    </item>
<item>
  <title>New features: Scheduling and live text editor</title>
  <link>https://mailbox.org/en/news/new-collaboration-features-appointment-scheduling-and-multi-user-text-editing/</link>
  <description>&lt;p&gt;Two new features are now available in our PREMIUM and STANDARD price plans. With "Framadate" users can easily coordinate appointments and create polls, share a link to these with others, and evaluate the results. Our new "Etherpad" offers a web-based text editing tool that several people can use at the same time to edit documents and collaborate with each other.&lt;/p&gt;&lt;p&gt;Like all our other services, these new features are also hosted in our German data centres, free of advertising and tracking, and fully meeting the requirements of the General Data Protection Regulation (GDPR). Of course they are also open source – just the way we like it. The Framadate and Etherpad features are part of the mailbox.org Online Office and can be accessed directly in the menu bar at the top.&lt;/p&gt;&lt;h2&gt;Framadate at mailbox.org&lt;/h2&gt;&lt;p&gt;The Framadate tool has two basic functions: "Schedule an event" and "Standard poll". They will save you time by making it easy to conduct polls among small and large groups of people. These additional options are also available:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Invitations by link or e-mail address&lt;/li&gt;&lt;li&gt;Password protection&lt;/li&gt;&lt;li&gt;Assigning an expiry date to a poll&lt;/li&gt;&lt;li&gt;Display of poll results&lt;/li&gt;&lt;li&gt;Customisable URLs&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Etherpad at mailbox.org&lt;/h2&gt;&lt;p&gt;Etherpad is our new service for collaborative text processing. Any changes made by a user will be immediately visible to all other editors who are working on the same text, and the individual contributions can be distinguished by colour. In addition, there is an integrated chat that can be used to coordinate the editing work. See below a summary of what the Etherpad feature has to offer:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Collaborative writing&lt;/li&gt;&lt;li&gt;Import/export (Etherpad file, HTML, TXT)&lt;/li&gt;&lt;li&gt;Text processing (Rich Text)&lt;/li&gt;&lt;li&gt;Editing history&lt;/li&gt;&lt;li&gt;Colours for individual authors&lt;/li&gt;&lt;li&gt;Comment function&lt;/li&gt;&lt;li&gt;Integrated chat&lt;/li&gt;&lt;li&gt;Administration of existing Etherpads&lt;/li&gt;&lt;/ul&gt;&lt;h2 class="western" id="FramadateundEtherpad-Undjetztmalganzpraktisch"&gt;Practically speaking – an example use case&lt;/h2&gt;&lt;p&gt;How can our new features help to make your everyday life easier? Whether it's about organising a family reunion, a meeting with your parents or a holiday trip with friends: Finding a date that suits everyone or getting a quick idea about what people think or want to do can quickly become complicated and laborious to do via e-mail. The it is good to have a useful tool at hand that help you get things done while also protecting your privacy at the same time.&lt;/p&gt;&lt;p&gt;Framadate helps you coordinate activities and dates with multiple people and make decisions together with everyone. For example, what would be a good date for a trip with your friends, and where to go?&lt;/p&gt;&lt;p&gt;You can use the "Schedule an event" button to create a poll with a selection of dates, and then send e-mail invitations to anyone involved.&lt;/p&gt;&lt;p&gt;When you need to make a decision about something, use the standard poll of Framadate. Images can be attached here for illustration and so, your friends get a much better idea of what the different travel destinations have to offer.&lt;/p&gt;&lt;p&gt;Now that there is a basic plan for your holiday with friends, it's time to sort out the finer details. Perhaps do a &lt;a href="https://mailbox.org/en/post/hello-opentalk-the-gdpr-compliant-video-conferencing-solution" target="_blank" title="Read more about OpenTalk" rel="noopener"&gt;video call using our new OpenTalk&lt;/a&gt; solution? You can also use Etherpad to jot down some notes and ideas about planned holiday activities and the places to visit on your trip.&lt;/p&gt;&lt;p&gt;Have fun and work well together,&lt;br&gt;Your mailbox.org team&lt;/p&gt;&lt;hr&gt;&lt;h2&gt;New: OpenTalk at mailbox.org&lt;/h2&gt;&lt;p&gt;OpenTalk is a new video conferencing solution with many interesting features, such as breakout rooms, a lobby and waiting room, polls, moderation roles, chat, telephone dial-in, and straightforward conference scheduling. OpenTalk runs directly in your browser.&lt;/p&gt;&lt;p&gt;Learn more about our new video conferencing solution &lt;a href="https://mailbox.org/en/post/hello-opentalk-the-gdpr-compliant-video-conferencing-solution" target="_blank" title="Read more about OpenTalk" rel="noopener"&gt;OpenTalk -&amp;gt;&lt;/a&gt;&lt;/p&gt;&amp;nbsp;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-calendar.jpeg?itok=jdhFuIrn" type="image/jpeg" length="409238"/><guid isPermaLink="false">f8e57e86-ad48-4bd4-882b-17f402caa8ec</guid>
    <pubDate>Tue, 15 Nov 2022 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>New features: Scheduling and live text editor</dc:title>
    <dc:identifier>f8e57e86-ad48-4bd4-882b-17f402caa8ec</dc:identifier>
    </item>
<item>
  <title>Say hello to OpenTalk – secure video conferencing</title>
  <link>https://mailbox.org/en/news/say-hello-opentalk-future-secure-video-conferencing/</link>
  <description>&lt;p&gt;We are pleased to announce the start of the introductory phase of OpenTalk - our new video conferencing solution at mailbox.org. This is an exciting event for colleagues at our sister company, which was founded in 2021. OpenTalk offers a user-friendly, secure, and digitally sovereign video conferencing experience. Thanks to its open-source code base and modern IT architecture, the software is GDPR-compliant and supports special requirements and sessions with many users.&lt;/p&gt;&lt;p&gt;“Good communication starts with independence. And that is exactly what the development of OpenTalk represents: a secure alternative to other video conferencing solutions that offers true data autonomy.“ says Markus Michels, CEO of OpenTalk.&lt;/p&gt;&lt;p&gt;As of today, all subscribers to a mailbox.org PREMIUM or STANDARD price plan can go ahead and test OpenTalk. The feature is accessible through the menu bar after login, which now has a new video conferencing icon. Alternatively, users can log in directly at &lt;a href="https://opentalk.mailbox.org" target="_blank" title="Go to OpenTalk login" rel="noopener"&gt;https://opentalk.mailbox.org&lt;/a&gt; using their regular mailbox.org login credentials.&lt;/p&gt;&lt;p&gt;Initially, OpenTalk will be available as an additional option alongside our existing video conferencing solution Jitsi. After the introductory phase has ended, Jitsi will be replaced completely by OpenTalk, as the latter offers a much better user experience, improved security, and better features to meet the requirements of provider operations. Like our other services, mailbox.org operates the new video conferencing solution within our own data centre in Germany.&lt;/p&gt;&lt;h2&gt;An idea becomes OpenTalk&lt;/h2&gt;&lt;p&gt;How did OpenTalk actually come about? Over the last two years, the work lives of many people have changed dramatically. Our team members, too, suddenly found themselves working remotely and experimenting with different video conferencing solutions. As it happened, Heinlein Support had been commissioned to set up a video conferencing platform for the administration of the city of Berlin around the same time. Any of the existing solutions, most of which hosted in the US, were not acceptable for data protection reasons. We wanted a video conferencing solution that respects the digital sovereignty of its users and that can be operated independently. As for existing open-source solutions, we found that these suffered from image quality and performance issues, which made them difficult to scale for deployment at a professional level in a provider environment like that of mailbox.org.&lt;/p&gt;&lt;p&gt;We soon realised that we weren't getting anywhere with those existing solutions. Instead, we realised that we can create what we need, and more: a solution that is more modern, more comfortable to use, more secure and, of course, open-source! The founding of OpenTalk as a product development company was the logical consequence, and our team quickly developed ideas for a whole range of features that would make a video conference experience more productive and user-friendly. And then they got to work and started developing that solution.&lt;/p&gt;&lt;p&gt;The launch of OpenTalk marks an important milestone for digital sovereignity and security for video conferences.&lt;/p&gt;&lt;h2&gt;OpenTalk starts with these features&lt;/h2&gt;&lt;p&gt;At launch, OpenTalk will come with all features that are essential for a modern video conference experience. During the introductory phase, the existing features will be further optimised and new features rolled out.&lt;/p&gt;&lt;h3&gt;Currently available features:&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;Dashboard&lt;ul&gt;&lt;li&gt;Schedule new meetings&lt;/li&gt;&lt;li&gt;Send meeting invite links&lt;/li&gt;&lt;li&gt;Start ad-hoc meetings&lt;/li&gt;&lt;li&gt;Display meeting schedule&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;Lobby and connection/audio/video tests&lt;/li&gt;&lt;li&gt;Dynamic video quality adjustment&lt;/li&gt;&lt;li&gt;Background pictures and blurring&lt;/li&gt;&lt;li&gt;Screen sharing&lt;/li&gt;&lt;li&gt;Chat (Public and private messages)&lt;/li&gt;&lt;li&gt;Breakout rooms&lt;/li&gt;&lt;li&gt;Voting&lt;/li&gt;&lt;li&gt;Mute participants (individually / everyone)&lt;/li&gt;&lt;li&gt;Raise hand&lt;/li&gt;&lt;li&gt;Stopwatch / Timer&lt;/li&gt;&lt;li&gt;Push-to-Talk&lt;/li&gt;&lt;li&gt;Telephone dial-in&lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;Some features that are coming soon:&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;Waiting room&lt;/li&gt;&lt;li&gt;Agenda&lt;/li&gt;&lt;li&gt;Multiple moderators&lt;/li&gt;&lt;li&gt;Legally compliant voting&lt;/li&gt;&lt;li&gt;Whiteboard&lt;/li&gt;&lt;li&gt;Meeting minutes&lt;/li&gt;&lt;li&gt;GDPR-compliant recording&lt;/li&gt;&lt;li&gt;Automatic moderation&lt;/li&gt;&lt;li&gt;Offboarding&lt;/li&gt;&lt;li&gt;Whispering (Private audio chat)&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Details about all features can be found on the &lt;a href="https://opentalk.eu/en/product" target="_blank" title="Go to the OpenTalk product page" rel="noopener"&gt;OpenTalk product page -&amp;gt;&lt;/a&gt;&lt;/p&gt;&lt;h2&gt;Interested in testing OpenTalk?&lt;/h2&gt;&lt;p&gt;All subscribers to a mailbox.org PREMIUM or STANDARD price plan simply log in to the web portal to access the OpenTalk video conferencing feature directly: &lt;a href="https://login.mailbox.org" target="_blank" title="Log in to your existing account" rel="noopener"&gt;Log in to your existing account →&lt;/a&gt;&lt;/p&gt;&lt;p&gt;New customers and those users who are currently not subscribed to an eligible plan can create a free test account: &lt;a href="https://register.mailbox.org/en/tariff?tariff=standard" target="_blank" title="Create a new account" rel="noopener"&gt;Create a new account →&lt;/a&gt;&lt;/p&gt;&lt;p&gt;We are very grateful for any feedback we receive from our users. Our team can be contacted at help.mailbox.org or by using the feedback feature on the OpenTalk dashboard. More information about OpenTalk can also be found in our &lt;a href="https://kb.mailbox.org/en/private/opentalk-faq" target="_blank" title="Go to the knowledge base" rel="noopener"&gt;knowledge base →&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;Notes about the OpenTalk introductory phase&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;No separate installation of software necessary. OpenTalk runs instantly with recent browsers for desktop and mobile devices such as Mozilla Firefox, Google Chrome, Microsoft Edge, and other Chromium-based browsers. Support for Apple Safari on iMac and mobile devices is currently limited, though. We are working towards providing full functionality for this specific browser in the future.&lt;/li&gt;&lt;li&gt;The team at OpenTalk is continuously developing new features for the solution. Make sure to check in regularly to see what’s new.&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Availability in the price plans after the Introductory phase&lt;/h2&gt;&lt;p&gt;During the introductory phase, an account may create any number of videoconferences with all features enabled, including support for unlimited numbers of participants. After the introductory phase has ended, the LIGHT price plan willget access to OpenTalk and the features available to individual users will depend on their chosen price plan.&lt;/p&gt;&lt;p&gt;Below we would like to give you a first glance into the planned availability in the price plans:&lt;/p&gt;&lt;p&gt;Furthermore, we are planning an additional package with additional features and higher limits for professional use cases, such as legally compliant voting. The OpenTalk team is working on further features which we will announce in due course – stay tuned!&lt;/p&gt;&lt;h2&gt;Do more with OpenTalk&lt;/h2&gt;&lt;p&gt;Know-how, passion, and a great deal of experience in the design and operation of secure electronic communication unite our teams across the &lt;a href="https://www.heinlein-support.de/jobs" target="_blank" title="Discover the Heinlein Group" rel="noopener"&gt;Heinlein Group&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;The OpenTalk team still has a long way to go and needs talented people to support its efforts. Software development happens in Rust for the back end, and JavaScript/React and Redux for the front end.Are you looking for a challenge, and do you want to work on a future-oriented product? Become part of the team: Check out &lt;a href="https://opentalk.eu/en/jobs" target="_blank" title="Jobs at OpenTalk" rel="noopener"&gt;Jobs at OpenTalk →&lt;/a&gt;&lt;/p&gt;&lt;p&gt;OpenTalk is open source software. The source code will be published on GitHub in the fourth quarter of 2022. With this, we want to ensure full transparency but also create a community and encourage other developers to contribute their ideas. Find out how you can engage: &lt;a href="https://opentalk.eu/en/community" target="_blank" title="Learn more" rel="noopener"&gt;Learn more →&lt;/a&gt;&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-mailbox-meet-update.jpeg?itok=usSiHx_u" type="image/jpeg" length="336340"/><guid isPermaLink="false">f9df64dc-d865-49dc-b3cd-c086cdc4f5a5</guid>
    <pubDate>Thu, 20 Oct 2022 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Say hello to OpenTalk – secure video conferencing</dc:title>
    <dc:identifier>f9df64dc-d865-49dc-b3cd-c086cdc4f5a5</dc:identifier>
    </item>
<item>
  <title>Say hello to OpenTalk – secure video conferencing</title>
  <link>https://mailbox.org/en/news/say-hello-opentalk-future-secure-video-conferencing/</link>
  <description>&lt;p&gt;We are pleased to announce the start of the introductory phase of OpenTalk - our new video conferencing solution at mailbox.org. This is an exciting event for colleagues at our sister company, which was founded in 2021. OpenTalk offers a user-friendly, secure, and digitally sovereign video conferencing experience. Thanks to its open-source code base and modern IT architecture, the software is GDPR-compliant and supports special requirements and sessions with many users.&lt;/p&gt;&lt;p&gt;“Good communication starts with independence. And that is exactly what the development of OpenTalk represents: a secure alternative to other video conferencing solutions that offers true data autonomy.“ says Markus Michels, CEO of OpenTalk.&lt;/p&gt;&lt;p&gt;As of today, all subscribers to a mailbox.org PREMIUM or STANDARD price plan can go ahead and test OpenTalk. The feature is accessible through the menu bar after login, which now has a new video conferencing icon. Alternatively, users can log in directly at &lt;a href="https://opentalk.mailbox.org" target="_blank" title="Go to OpenTalk login" rel="noopener"&gt;https://opentalk.mailbox.org&lt;/a&gt; using their regular mailbox.org login credentials.&lt;/p&gt;&lt;p&gt;Initially, OpenTalk will be available as an additional option alongside our existing video conferencing solution Jitsi. After the introductory phase has ended, Jitsi will be replaced completely by OpenTalk, as the latter offers a much better user experience, improved security, and better features to meet the requirements of provider operations. Like our other services, mailbox.org operates the new video conferencing solution within our own data centre in Germany.&lt;/p&gt;&lt;h2&gt;An idea becomes OpenTalk&lt;/h2&gt;&lt;p&gt;How did OpenTalk actually come about? Over the last two years, the work lives of many people have changed dramatically. Our team members, too, suddenly found themselves working remotely and experimenting with different video conferencing solutions. As it happened, Heinlein Support had been commissioned to set up a video conferencing platform for the administration of the city of Berlin around the same time. Any of the existing solutions, most of which hosted in the US, were not acceptable for data protection reasons. We wanted a video conferencing solution that respects the digital sovereignty of its users and that can be operated independently. As for existing open-source solutions, we found that these suffered from image quality and performance issues, which made them difficult to scale for deployment at a professional level in a provider environment like that of mailbox.org.&lt;/p&gt;&lt;p&gt;We soon realised that we weren't getting anywhere with those existing solutions. Instead, we realised that we can create what we need, and more: a solution that is more modern, more comfortable to use, more secure and, of course, open-source! The founding of OpenTalk as a product development company was the logical consequence, and our team quickly developed ideas for a whole range of features that would make a video conference experience more productive and user-friendly. And then they got to work and started developing that solution.&lt;/p&gt;&lt;p&gt;The launch of OpenTalk marks an important milestone for digital sovereignity and security for video conferences.&lt;/p&gt;&lt;h2&gt;OpenTalk starts with these features&lt;/h2&gt;&lt;p&gt;At launch, OpenTalk will come with all features that are essential for a modern video conference experience. During the introductory phase, the existing features will be further optimised and new features rolled out.&lt;/p&gt;&lt;h3&gt;Currently available features:&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;Dashboard&lt;ul&gt;&lt;li&gt;Schedule new meetings&lt;/li&gt;&lt;li&gt;Send meeting invite links&lt;/li&gt;&lt;li&gt;Start ad-hoc meetings&lt;/li&gt;&lt;li&gt;Display meeting schedule&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;Lobby and connection/audio/video tests&lt;/li&gt;&lt;li&gt;Dynamic video quality adjustment&lt;/li&gt;&lt;li&gt;Background pictures and blurring&lt;/li&gt;&lt;li&gt;Screen sharing&lt;/li&gt;&lt;li&gt;Chat (Public and private messages)&lt;/li&gt;&lt;li&gt;Breakout rooms&lt;/li&gt;&lt;li&gt;Voting&lt;/li&gt;&lt;li&gt;Mute participants (individually / everyone)&lt;/li&gt;&lt;li&gt;Raise hand&lt;/li&gt;&lt;li&gt;Stopwatch / Timer&lt;/li&gt;&lt;li&gt;Push-to-Talk&lt;/li&gt;&lt;li&gt;Telephone dial-in&lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;Some features that are coming soon:&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;Waiting room&lt;/li&gt;&lt;li&gt;Agenda&lt;/li&gt;&lt;li&gt;Multiple moderators&lt;/li&gt;&lt;li&gt;Legally compliant voting&lt;/li&gt;&lt;li&gt;Whiteboard&lt;/li&gt;&lt;li&gt;Meeting minutes&lt;/li&gt;&lt;li&gt;GDPR-compliant recording&lt;/li&gt;&lt;li&gt;Automatic moderation&lt;/li&gt;&lt;li&gt;Offboarding&lt;/li&gt;&lt;li&gt;Whispering (Private audio chat)&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Details about all features can be found on the &lt;a href="https://opentalk.eu/en/product" target="_blank" title="Go to the OpenTalk product page" rel="noopener"&gt;OpenTalk product page -&amp;gt;&lt;/a&gt;&lt;/p&gt;&lt;h2&gt;Interested in testing OpenTalk?&lt;/h2&gt;&lt;p&gt;All subscribers to a mailbox.org PREMIUM or STANDARD price plan simply log in to the web portal to access the OpenTalk video conferencing feature directly: &lt;a href="https://login.mailbox.org" target="_blank" title="Log in to your existing account" rel="noopener"&gt;Log in to your existing account →&lt;/a&gt;&lt;/p&gt;&lt;p&gt;New customers and those users who are currently not subscribed to an eligible plan can create a free test account: &lt;a href="https://register.mailbox.org/en/tariff?tariff=standard" target="_blank" title="Create a new account" rel="noopener"&gt;Create a new account →&lt;/a&gt;&lt;/p&gt;&lt;p&gt;We are very grateful for any feedback we receive from our users. Our team can be contacted at help.mailbox.org or by using the feedback feature on the OpenTalk dashboard. More information about OpenTalk can also be found in our &lt;a href="https://kb.mailbox.org/en/private/opentalk-faq" target="_blank" title="Go to the knowledge base" rel="noopener"&gt;knowledge base →&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;Notes about the OpenTalk introductory phase&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;No separate installation of software necessary. OpenTalk runs instantly with recent browsers for desktop and mobile devices such as Mozilla Firefox, Google Chrome, Microsoft Edge, and other Chromium-based browsers. Support for Apple Safari on iMac and mobile devices is currently limited, though. We are working towards providing full functionality for this specific browser in the future.&lt;/li&gt;&lt;li&gt;The team at OpenTalk is continuously developing new features for the solution. Make sure to check in regularly to see what’s new.&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Availability in the price plans after the Introductory phase&lt;/h2&gt;&lt;p&gt;During the introductory phase, an account may create any number of videoconferences with all features enabled, including support for unlimited numbers of participants. After the introductory phase has ended, the LIGHT price plan willget access to OpenTalk and the features available to individual users will depend on their chosen price plan.&lt;/p&gt;&lt;p&gt;Below we would like to give you a first glance into the planned availability in the price plans:&lt;/p&gt;&lt;p&gt;Furthermore, we are planning an additional package with additional features and higher limits for professional use cases, such as legally compliant voting. The OpenTalk team is working on further features which we will announce in due course – stay tuned!&lt;/p&gt;&lt;h2&gt;Do more with OpenTalk&lt;/h2&gt;&lt;p&gt;Know-how, passion, and a great deal of experience in the design and operation of secure electronic communication unite our teams across the &lt;a href="https://www.heinlein-support.de/jobs" target="_blank" title="Discover the Heinlein Group" rel="noopener"&gt;Heinlein Group&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;The OpenTalk team still has a long way to go and needs talented people to support its efforts. Software development happens in Rust for the back end, and JavaScript/React and Redux for the front end.Are you looking for a challenge, and do you want to work on a future-oriented product? Become part of the team: Check out &lt;a href="https://opentalk.eu/en/jobs" target="_blank" title="Jobs at OpenTalk" rel="noopener"&gt;Jobs at OpenTalk →&lt;/a&gt;&lt;/p&gt;&lt;p&gt;OpenTalk is open source software. The source code will be published on GitHub in the fourth quarter of 2022. With this, we want to ensure full transparency but also create a community and encourage other developers to contribute their ideas. Find out how you can engage: &lt;a href="https://opentalk.eu/en/community" target="_blank" title="Learn more" rel="noopener"&gt;Learn more →&lt;/a&gt;&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-mailbox-meet-update.jpeg?itok=usSiHx_u" type="image/jpeg" length="336340"/><guid isPermaLink="false">f9df64dc-d865-49dc-b3cd-c086cdc4f5a5</guid>
    <pubDate>Thu, 20 Oct 2022 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Say hello to OpenTalk – secure video conferencing</dc:title>
    <dc:identifier>f9df64dc-d865-49dc-b3cd-c086cdc4f5a5</dc:identifier>
    </item>
<item>
  <title>ECJ overturns indiscriminate data retention</title>
  <link>https://mailbox.org/en/news/european-court-justice-overturns-german-law-indiscriminate-data-retention/</link>
  <description>&lt;p&gt;Today, the European Court of Justice (ECJ) ruled in a landmark decision that the German law on indiscriminate data retention and thus the suspicion-independent storage of telephone and internet connection data is not compatible with EU law.&lt;/p&gt;&lt;p&gt;In recent months, the ECJ has already shown less understanding for politicians in EU member states who continue to call for data retention without any reason, despite the unambiguous legal situation and case law. With unusually clear words, Advocate General Campos Sánchez-Bordona, an expert of the European Court of Justice, caused a furor in an opinion in November 2021 (&lt;a href="https://curia.europa.eu/jcms/upload/docs/application/pdf/2021-11/cp210206de.pdf" target="_blank" rel="noopener"&gt;press release&lt;/a&gt;). From his point of view, indiscriminate data retention without any reason would simply not be permissible in the fight against crime.&lt;/p&gt;&lt;p&gt;Experts and politicians have been arguing for almost fifteen years now. The advocates of data retention cite organized crime, child sexual abuse material, illegal file sharing, and recently also hate speech and other crimes. Their opponents accuse them of wanting to disregard courts, fundamental rights, and values and of ignoring laws and rulings time and again.&lt;/p&gt;&lt;h3&gt;Peer Heinlein, CEO of mailbox.org, on today’s ECJ ruling:&lt;/h3&gt;&lt;p&gt;"I am relieved that the ECJ has once again overturned indiscriminate data retention and has once again clearly rejected the overreaching wishes of politicians. After more than 15 years of discussions, the time has come to an end. indiscriminate data retention of all citizens without any reason would place everyone under general suspicion, would be a profound violation of our fundamental rights, and would open the floodgates to unlawful misuse of the collected data. If all courts, no matter where they are, always come to the same conclusion, politicians must finally accept this. The indiscriminate data retention is dead and now hopefully finally off the table.&lt;/p&gt;&lt;p&gt;With today’s ruling, the ECJ has clarified within which limits and under which very narrow conditions data collection is permissible – for example, in the case of severe crimes and always in compliance with proportionality. This should in no way be confused with the broad-based and, in particular, without any reason, data retention. On the contrary, it shows how high the hurdles for data collection are to be set constitutionally. And that is a good thing."&lt;/p&gt;&lt;h2&gt;mailbox.org has been committed in opposing indiscriminate data retention for some time now&lt;/h2&gt;&lt;p&gt;In an &lt;a href="https://mailbox.org/de/post/offener-brief-gegen-die-vorratsdatenspeicherung-von-ip-daten" target="_blank" rel="noopener"&gt;open letter&lt;/a&gt; and together with more than 20 other organisations and experts, mailbox.org yesterday called on the German coalition government to keep the promises of the coalition agreement and to follow the path of a policy free of mass surveillance in the long term.&lt;/p&gt;&lt;p&gt;A constitutional complaint against the retention of data by mailbox.org has been pending before the German Federal Constitutional Court since 2015 but has not yet been decided. It is to be expected that the Federal Constitutional Court will now also rule in the same way after the ECJ ruling.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-jurisdiction.png?itok=OZMKk08b" type="image/png" length="218284"/><guid isPermaLink="false">85b0c27a-dbca-46c4-9daa-ec51c0164f59</guid>
    <pubDate>Tue, 20 Sep 2022 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>ECJ overturns indiscriminate data retention</dc:title>
    <dc:identifier>85b0c27a-dbca-46c4-9daa-ec51c0164f59</dc:identifier>
    </item>
<item>
  <title>ECJ overturns indiscriminate data retention</title>
  <link>https://mailbox.org/en/news/european-court-justice-overturns-german-law-indiscriminate-data-retention/</link>
  <description>&lt;p&gt;Today, the European Court of Justice (ECJ) ruled in a landmark decision that the German law on indiscriminate data retention and thus the suspicion-independent storage of telephone and internet connection data is not compatible with EU law.&lt;/p&gt;&lt;p&gt;In recent months, the ECJ has already shown less understanding for politicians in EU member states who continue to call for data retention without any reason, despite the unambiguous legal situation and case law. With unusually clear words, Advocate General Campos Sánchez-Bordona, an expert of the European Court of Justice, caused a furor in an opinion in November 2021 (&lt;a href="https://curia.europa.eu/jcms/upload/docs/application/pdf/2021-11/cp210206de.pdf" target="_blank" rel="noopener"&gt;press release&lt;/a&gt;). From his point of view, indiscriminate data retention without any reason would simply not be permissible in the fight against crime.&lt;/p&gt;&lt;p&gt;Experts and politicians have been arguing for almost fifteen years now. The advocates of data retention cite organized crime, child sexual abuse material, illegal file sharing, and recently also hate speech and other crimes. Their opponents accuse them of wanting to disregard courts, fundamental rights, and values and of ignoring laws and rulings time and again.&lt;/p&gt;&lt;h3&gt;Peer Heinlein, CEO of mailbox.org, on today’s ECJ ruling:&lt;/h3&gt;&lt;p&gt;"I am relieved that the ECJ has once again overturned indiscriminate data retention and has once again clearly rejected the overreaching wishes of politicians. After more than 15 years of discussions, the time has come to an end. indiscriminate data retention of all citizens without any reason would place everyone under general suspicion, would be a profound violation of our fundamental rights, and would open the floodgates to unlawful misuse of the collected data. If all courts, no matter where they are, always come to the same conclusion, politicians must finally accept this. The indiscriminate data retention is dead and now hopefully finally off the table.&lt;/p&gt;&lt;p&gt;With today’s ruling, the ECJ has clarified within which limits and under which very narrow conditions data collection is permissible – for example, in the case of severe crimes and always in compliance with proportionality. This should in no way be confused with the broad-based and, in particular, without any reason, data retention. On the contrary, it shows how high the hurdles for data collection are to be set constitutionally. And that is a good thing."&lt;/p&gt;&lt;h2&gt;mailbox.org has been committed in opposing indiscriminate data retention for some time now&lt;/h2&gt;&lt;p&gt;In an &lt;a href="https://mailbox.org/de/post/offener-brief-gegen-die-vorratsdatenspeicherung-von-ip-daten" target="_blank" rel="noopener"&gt;open letter&lt;/a&gt; and together with more than 20 other organisations and experts, mailbox.org yesterday called on the German coalition government to keep the promises of the coalition agreement and to follow the path of a policy free of mass surveillance in the long term.&lt;/p&gt;&lt;p&gt;A constitutional complaint against the retention of data by mailbox.org has been pending before the German Federal Constitutional Court since 2015 but has not yet been decided. It is to be expected that the Federal Constitutional Court will now also rule in the same way after the ECJ ruling.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-jurisdiction.png?itok=OZMKk08b" type="image/png" length="218284"/><guid isPermaLink="false">85b0c27a-dbca-46c4-9daa-ec51c0164f59</guid>
    <pubDate>Tue, 20 Sep 2022 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>ECJ overturns indiscriminate data retention</dc:title>
    <dc:identifier>85b0c27a-dbca-46c4-9daa-ec51c0164f59</dc:identifier>
    </item>
<item>
  <title>Attractive new feature for teams and families</title>
  <link>https://mailbox.org/en/news/attractive-change-teams-and-families-custom-domains-available-light-plan/</link>
  <description>&lt;ul&gt;&lt;li&gt;As of now, team members who use e-mail-addresses with their custom domain can also choose our LIGHT plan.&lt;/li&gt;&lt;li&gt;In addition, the verification of custom domains in team accounts has been simplified.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;E-mail addresses with a custom domain (instead of @mailbox.org) are practical and popular for families and teams. Until now, custom domains have been only available in the PREMIUM and STANDARD plans. As of today, we are introducing custom domains to our team members in the LIGHT plan.&lt;/p&gt;&lt;p&gt;From now on, in order to use custom domains, it’s sufficient for the team administrator to use the PREMIUM or STANDARD plan. Team members who are happy with the reduced feature scope of e-mail, address books, and calendars, may choose the LIGHT plan. They can now create up to three additional e-mail-addresses with custom domains. These three aliases come extra, so no existing e-mail-address has to be deleted.&lt;/p&gt;&lt;p&gt;This will benefit most families and small teams who value using their custom domain while using team features like joint billing and sharing of calendars and address books.&lt;/p&gt;&lt;h2&gt;Features to consider&lt;/h2&gt;&lt;p&gt;The features of the PREMIUM and STANDARD plans are much more extensive than those of the LIGHT plan. Please note that the following features are only available in the PREMIUM and STANDARD plans: video conferencing, chat, online office, and document editing as well as cloud storage. You can find all details in the &lt;a href="https://mailbox.org/en/services#price-plans" target="_blank" title="price plan overview" rel="noopener"&gt;price plan overview -&amp;gt;&lt;/a&gt;&lt;/p&gt;&lt;h2&gt;The advantages of team accounts&lt;/h2&gt;&lt;p&gt;With a team account, a total of up to 10 accounts can use shared calendars, address books and drive folders. In addition, the team administrator the rights to create new team members, reset forgotten passwords and pay for all accounts together.&lt;/p&gt;&lt;h2&gt;Simplified verification of custom domains for team accounts&lt;/h2&gt;&lt;p&gt;We have also significantly simplified the verification of custom domains. From now on, a second "team DNS entry" is displayed in the settings. As soon as the domain – with the corresponding "team DNS entry" at the registrar – has been set up, all accounts in the team can set up aliases with this custom domain. This eliminates the time-consuming setup of each individual team account and the corresponding individual DNS entries with the registrar.&lt;/p&gt;&lt;h3&gt;Further articles&lt;/h3&gt;&lt;ol&gt;&lt;li&gt;How to set up team accounts: &lt;a href="https://kb.mailbox.org/en/private/account-article/how-to-set-up-team-accounts" target="_blank" title="How to set up team accounts" rel="noopener"&gt;https://kb.mailbox.org/en/private/account-article/how-to-set-up-team-accounts&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Custom domains: &lt;a href="https://kb.mailbox.org/en/private/custom-domains" target="_blank" title="Custom domains" rel="noopener"&gt;https://kb.mailbox.org/en/private/custom-domains&lt;/a&gt;&lt;/li&gt;&lt;/ol&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-family-accounts.jpeg?itok=eyqZ04QL" type="image/jpeg" length="409169"/><guid isPermaLink="false">9a5d4d94-e2ac-428f-b056-9c307ef8cf32</guid>
    <pubDate>Fri, 02 Sep 2022 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Attractive new feature for teams and families</dc:title>
    <dc:identifier>9a5d4d94-e2ac-428f-b056-9c307ef8cf32</dc:identifier>
    </item>
<item>
  <title>Attractive new feature for teams and families</title>
  <link>https://mailbox.org/en/news/attractive-change-teams-and-families-custom-domains-available-light-plan/</link>
  <description>&lt;ul&gt;&lt;li&gt;As of now, team members who use e-mail-addresses with their custom domain can also choose our LIGHT plan.&lt;/li&gt;&lt;li&gt;In addition, the verification of custom domains in team accounts has been simplified.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;E-mail addresses with a custom domain (instead of @mailbox.org) are practical and popular for families and teams. Until now, custom domains have been only available in the PREMIUM and STANDARD plans. As of today, we are introducing custom domains to our team members in the LIGHT plan.&lt;/p&gt;&lt;p&gt;From now on, in order to use custom domains, it’s sufficient for the team administrator to use the PREMIUM or STANDARD plan. Team members who are happy with the reduced feature scope of e-mail, address books, and calendars, may choose the LIGHT plan. They can now create up to three additional e-mail-addresses with custom domains. These three aliases come extra, so no existing e-mail-address has to be deleted.&lt;/p&gt;&lt;p&gt;This will benefit most families and small teams who value using their custom domain while using team features like joint billing and sharing of calendars and address books.&lt;/p&gt;&lt;h2&gt;Features to consider&lt;/h2&gt;&lt;p&gt;The features of the PREMIUM and STANDARD plans are much more extensive than those of the LIGHT plan. Please note that the following features are only available in the PREMIUM and STANDARD plans: video conferencing, chat, online office, and document editing as well as cloud storage. You can find all details in the &lt;a href="https://mailbox.org/en/services#price-plans" target="_blank" title="price plan overview" rel="noopener"&gt;price plan overview -&amp;gt;&lt;/a&gt;&lt;/p&gt;&lt;h2&gt;The advantages of team accounts&lt;/h2&gt;&lt;p&gt;With a team account, a total of up to 10 accounts can use shared calendars, address books and drive folders. In addition, the team administrator the rights to create new team members, reset forgotten passwords and pay for all accounts together.&lt;/p&gt;&lt;h2&gt;Simplified verification of custom domains for team accounts&lt;/h2&gt;&lt;p&gt;We have also significantly simplified the verification of custom domains. From now on, a second "team DNS entry" is displayed in the settings. As soon as the domain – with the corresponding "team DNS entry" at the registrar – has been set up, all accounts in the team can set up aliases with this custom domain. This eliminates the time-consuming setup of each individual team account and the corresponding individual DNS entries with the registrar.&lt;/p&gt;&lt;h3&gt;Further articles&lt;/h3&gt;&lt;ol&gt;&lt;li&gt;How to set up team accounts: &lt;a href="https://kb.mailbox.org/en/private/account-article/how-to-set-up-team-accounts" target="_blank" title="How to set up team accounts" rel="noopener"&gt;https://kb.mailbox.org/en/private/account-article/how-to-set-up-team-accounts&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Custom domains: &lt;a href="https://kb.mailbox.org/en/private/custom-domains" target="_blank" title="Custom domains" rel="noopener"&gt;https://kb.mailbox.org/en/private/custom-domains&lt;/a&gt;&lt;/li&gt;&lt;/ol&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-family-accounts.jpeg?itok=eyqZ04QL" type="image/jpeg" length="409169"/><guid isPermaLink="false">9a5d4d94-e2ac-428f-b056-9c307ef8cf32</guid>
    <pubDate>Fri, 02 Sep 2022 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Attractive new feature for teams and families</dc:title>
    <dc:identifier>9a5d4d94-e2ac-428f-b056-9c307ef8cf32</dc:identifier>
    </item>
<item>
  <title>mailbox.org receives IT security certification from the BSI</title>
  <link>https://mailbox.org/en/news/mailboxorg-received-bsi-it-security-label/</link>
  <description>&lt;p&gt;We are pleased to announce that mailbox.org has received the new IT Security Label issued by the German Federal Office for Information Security (BSI). The IT Security Label is an official recognition of the standards with which e-mail providers meet the requirements for consumer protection and IT security that were defined by the BSI.&lt;/p&gt;&lt;p&gt;As of today, our PREMIUM, STANDARD and LIGHT price plans bear the BSI's IT security label, which can be confirmed with a QR code.&lt;/p&gt;&lt;p&gt;The IT standards at mailbox.org met the requirements of the technical guideline "Secure E-Mail Transport" (&lt;a href="https://www.bsi.bund.de/DE/Themen/Unternehmen-und-Organisationen/Standards-und-Zertifizierung/Technische-Richtlinien/TR-nach-Thema-sortiert/tr03108/tr03108_node.html" target="_blank" rel="noopener"&gt;BSI TR 03108&lt;/a&gt;, page in German) right away - we did not need to make any changes to our systems after the audit in order to receive the award.&lt;/p&gt;&lt;h2&gt;What is the BSI IT Security Label about?&lt;/h2&gt;&lt;p&gt;The German IT Security Act 2.0 made digital consumer protection a primary task of the BSI, who officially presented their "IT Security Label" in February 2022. The aim is to promote digital consumer protection and more straightforward consumer orientation when it comes to product security. Companies can apply for the security label by submitting a declaration about the security features of their services, which the BSI will then check for completeness and plausibility. This procedure has been successfully completed by mailbox.org.&lt;/p&gt;&lt;h2&gt;Which security aspects were checked?&lt;/h2&gt;&lt;p&gt;We have provided the BSI with a range of information about the security features guaranteed by mailbox.org, including:&lt;/p&gt;&lt;ol&gt;&lt;li&gt;Transport encryption&lt;br&gt;We use the common IMAP, POP3 and SMTP protocols, with transport encryption enabled. Whenever possible, the latest TLS 1.3 standard is employed.&lt;/li&gt;&lt;li&gt;Server location Berlin&lt;br&gt;We operate our own infrastructure across two independent data centres.&lt;/li&gt;&lt;li&gt;Protection of user data&lt;br&gt;The principle of data economy is very important to us, and we allow anonymous registration and payment for our services. All our systems receive updates on a regular basis so that any emerging vulnerabilities get fixed as soon as possible. We also enforce a strict policy for the creation of strong passwords. Login procedures are protected against brute force attacks, and further by optional two-factor authentication (2FA) for private customers. The "Have I Been Pwned" service is integrated and alerts users in the event that their email addresses get compromised in data breaches around the Web.&lt;/li&gt;&lt;li&gt;Secure data transmission&amp;nbsp;&lt;br&gt;In addition to TLS transport security, all private mailbox.org customers have access to @secure.mailbox.org addresses. These enforce the use of transport encryption, without which e-mails will not be transmitted at all. Our systems also use the network protocol DANE (DNS-based Authentication of Named Entities) that further enhances the TLS standard. All mailbox.org customers also benefit from SPF and DKIM, which are additional protection measures and can even be configured to work with custom domain names.&lt;/li&gt;&lt;/ol&gt;&lt;h2&gt;The BSI IT Security Label could be an important first step towards more secure e-mail&lt;/h2&gt;&lt;p&gt;Will the new security label make e-mail providers more secure? We are not sure about that. But we do think it will make it easier for consumers to choose trustworthy providers. In our opinion, the requirements for the BSI IT Security Label correspond to basic features that every e-mail provider who cares about data protection should fullfil.&lt;/p&gt;&lt;p&gt;We at mailbox.org help our customers to make their private and business communication as secure as possible. However, there is also something that users can do from their end. Consider that an unencrypted e-mail is as private as a normal postcard – everyone could read it if they make the effort. Only by adding encryption can you put your message into a sealed envelope. Ultimately, everyone can make decisions about how secure they want their own communication to be. Learn more about how to encrypt e-mails at mailbox.org in our &lt;a href="https://kb.mailbox.org/en/private/encryption/" target="_blank" rel="noopener"&gt;knowledge base&lt;/a&gt;, and also find out about how &lt;a href="https://mailbox.org/en/security/" data-entity-type="node" data-entity-uuid="2b846140-bfc8-4154-b324-43cee2bd3bfb" data-entity-substitution="canonical" title="securityy"&gt;security and data protection&lt;/a&gt; works at mailbox.org, and how to set up SPF and DKIM for your &lt;a href="https://kb.mailbox.org/en/private/custom-domains/"&gt;custom domain name&lt;/a&gt;.&lt;/p&gt;

  
      
  &lt;a name="logos-9346"&gt;&lt;/a&gt;
  
  
      
    
  </description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-team.jpeg?itok=dGTTQB1f" type="image/jpeg" length="320376"/><guid isPermaLink="false">25f6e205-dc7b-49b7-a96f-3ab9600f4879</guid>
    <pubDate>Wed, 01 Jun 2022 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>mailbox.org receives IT security certification from the BSI</dc:title>
    <dc:identifier>25f6e205-dc7b-49b7-a96f-3ab9600f4879</dc:identifier>
    </item>
<item>
  <title>mailbox.org receives IT security certification from the BSI</title>
  <link>https://mailbox.org/en/news/mailboxorg-received-bsi-it-security-label/</link>
  <description>&lt;p&gt;We are pleased to announce that mailbox.org has received the new IT Security Label issued by the German Federal Office for Information Security (BSI). The IT Security Label is an official recognition of the standards with which e-mail providers meet the requirements for consumer protection and IT security that were defined by the BSI.&lt;/p&gt;&lt;p&gt;As of today, our PREMIUM, STANDARD and LIGHT price plans bear the BSI's IT security label, which can be confirmed with a QR code.&lt;/p&gt;&lt;p&gt;The IT standards at mailbox.org met the requirements of the technical guideline "Secure E-Mail Transport" (&lt;a href="https://www.bsi.bund.de/DE/Themen/Unternehmen-und-Organisationen/Standards-und-Zertifizierung/Technische-Richtlinien/TR-nach-Thema-sortiert/tr03108/tr03108_node.html" target="_blank" rel="noopener"&gt;BSI TR 03108&lt;/a&gt;, page in German) right away - we did not need to make any changes to our systems after the audit in order to receive the award.&lt;/p&gt;&lt;h2&gt;What is the BSI IT Security Label about?&lt;/h2&gt;&lt;p&gt;The German IT Security Act 2.0 made digital consumer protection a primary task of the BSI, who officially presented their "IT Security Label" in February 2022. The aim is to promote digital consumer protection and more straightforward consumer orientation when it comes to product security. Companies can apply for the security label by submitting a declaration about the security features of their services, which the BSI will then check for completeness and plausibility. This procedure has been successfully completed by mailbox.org.&lt;/p&gt;&lt;h2&gt;Which security aspects were checked?&lt;/h2&gt;&lt;p&gt;We have provided the BSI with a range of information about the security features guaranteed by mailbox.org, including:&lt;/p&gt;&lt;ol&gt;&lt;li&gt;Transport encryption&lt;br&gt;We use the common IMAP, POP3 and SMTP protocols, with transport encryption enabled. Whenever possible, the latest TLS 1.3 standard is employed.&lt;/li&gt;&lt;li&gt;Server location Berlin&lt;br&gt;We operate our own infrastructure across two independent data centres.&lt;/li&gt;&lt;li&gt;Protection of user data&lt;br&gt;The principle of data economy is very important to us, and we allow anonymous registration and payment for our services. All our systems receive updates on a regular basis so that any emerging vulnerabilities get fixed as soon as possible. We also enforce a strict policy for the creation of strong passwords. Login procedures are protected against brute force attacks, and further by optional two-factor authentication (2FA) for private customers. The "Have I Been Pwned" service is integrated and alerts users in the event that their email addresses get compromised in data breaches around the Web.&lt;/li&gt;&lt;li&gt;Secure data transmission&amp;nbsp;&lt;br&gt;In addition to TLS transport security, all private mailbox.org customers have access to @secure.mailbox.org addresses. These enforce the use of transport encryption, without which e-mails will not be transmitted at all. Our systems also use the network protocol DANE (DNS-based Authentication of Named Entities) that further enhances the TLS standard. All mailbox.org customers also benefit from SPF and DKIM, which are additional protection measures and can even be configured to work with custom domain names.&lt;/li&gt;&lt;/ol&gt;&lt;h2&gt;The BSI IT Security Label could be an important first step towards more secure e-mail&lt;/h2&gt;&lt;p&gt;Will the new security label make e-mail providers more secure? We are not sure about that. But we do think it will make it easier for consumers to choose trustworthy providers. In our opinion, the requirements for the BSI IT Security Label correspond to basic features that every e-mail provider who cares about data protection should fullfil.&lt;/p&gt;&lt;p&gt;We at mailbox.org help our customers to make their private and business communication as secure as possible. However, there is also something that users can do from their end. Consider that an unencrypted e-mail is as private as a normal postcard – everyone could read it if they make the effort. Only by adding encryption can you put your message into a sealed envelope. Ultimately, everyone can make decisions about how secure they want their own communication to be. Learn more about how to encrypt e-mails at mailbox.org in our &lt;a href="https://kb.mailbox.org/en/private/encryption/" target="_blank" rel="noopener"&gt;knowledge base&lt;/a&gt;, and also find out about how &lt;a href="https://mailbox.org/en/security/" data-entity-type="node" data-entity-uuid="2b846140-bfc8-4154-b324-43cee2bd3bfb" data-entity-substitution="canonical" title="securityy"&gt;security and data protection&lt;/a&gt; works at mailbox.org, and how to set up SPF and DKIM for your &lt;a href="https://kb.mailbox.org/en/private/custom-domains/"&gt;custom domain name&lt;/a&gt;.&lt;/p&gt;

  
      
  &lt;a name="logos-9346"&gt;&lt;/a&gt;
  
  
      
    
  </description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-team.jpeg?itok=dGTTQB1f" type="image/jpeg" length="320376"/><guid isPermaLink="false">25f6e205-dc7b-49b7-a96f-3ab9600f4879</guid>
    <pubDate>Wed, 01 Jun 2022 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>mailbox.org receives IT security certification from the BSI</dc:title>
    <dc:identifier>25f6e205-dc7b-49b7-a96f-3ab9600f4879</dc:identifier>
    </item>
<item>
  <title>Russian hacker group attacks IT infrastructures</title>
  <link>https://mailbox.org/en/news/cyberwar-suspected-russian-hacker-group-attacks-western-it-infrastructure/</link>
  <description>&lt;ol&gt;&lt;li&gt;mailbox.org is currently not under attack&lt;/li&gt;&lt;li&gt;Our team is as well prepared as possible and on slightly heightened alert&lt;/li&gt;&lt;li&gt;If we notice any attacks, we will inform you immediately&lt;/li&gt;&lt;li&gt;In this case, we ask our customers to refrain from support requests&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;As part of the Russia-Ukraine war, the suspected Russian hacker group "Legion Russia" has been specifically attacking Western IT infrastructures and also e-mail providers for several days. Attack targets are collected and commissioned by Legion Russia in internal lists - these are known to us at mailbox.org.&lt;/p&gt;&lt;p&gt;Currently, we are not named as a target there – a few days ago, however, the portal "berlin.de" was attacked and struggled for several hours.&lt;/p&gt;&lt;p&gt;At this point, we would like to inform our customers purely preventively and proactively about possible upcoming attacks and their impact on our services. However, there is no reason for you to act.&lt;/p&gt;&lt;p&gt;In the past, we at mailbox.org have been able to defend ourselves very well even &lt;a href="https://mailbox.org/en/post/extortionate-ddos-attacks-on-mailbox-org" target="_blank" title="mailbox.org blog: DDoS attacks in 2021" rel="noopener"&gt;against large-scale distributed denial of service (DDoS) attacks&lt;/a&gt;. Nevertheless, we may become the target of such attacks in the coming days and weeks as well. In recent years, we have prepared a number of different defences, with external DDoS protection providers contracted and paid by us on standby around the clock.&lt;/p&gt;&lt;p&gt;Our team is now on slightly heightened alert and has recently evaluated all defensive measures. We consider ourselves to be as well prepared as possible.&lt;/p&gt;&lt;p&gt;Of course every defence has its limits, every attack may require the development of concrete defensive measures and may lead to impairments.&lt;/p&gt;&lt;p&gt;In case of disruptions:&lt;/p&gt;&lt;ol&gt;&lt;li&gt;follow our social media channels on &lt;a href="https://twitter.com/mailbox_org" target="_blank" title="Twitter: @mailbox.org" rel="noopener"&gt;Twitter&lt;/a&gt; and &lt;a href="https://social.mailbox.org/@mailbox_org" target="_blank" title=" Mastodon: @mailbox_org@social.mailbox.org" rel="noopener"&gt;Mastodon&lt;/a&gt; as well as our status page.&lt;/li&gt;&lt;li&gt;mostly the websites of the providers are attacked. If necessary, use our &lt;a href="https://login.mailbox.org/en" target="_blank" title="Go to direct login" rel="noopener"&gt;direct login page&lt;/a&gt;, which may not be affected. Also, access via e-mail client with POP3/IMAP is often possible without problems.&lt;/li&gt;&lt;li&gt;we ask you to refrain from individual support requests so that our entire team can concentrate on defence.&lt;/li&gt;&lt;li&gt;in the event of temporary inaccessibility, no e-mails will be lost, but only delivered with a delay.&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;The attacks of the suspected Russian hacker group have so far not had the goal of stealing data but were only intended to temporarily paralyse the respective IT infrastructures.&lt;/p&gt;&lt;p&gt;At the moment, you as a user do not need to do anything. We will inform you about any developments regarding this situation.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Your mailbox.org team&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-04/mailbox-news-und-updates-warnung.jpg?itok=reW9cU74" type="image/jpeg" length="238141"/><guid isPermaLink="false">e73503d8-4a5d-4196-8269-9eadfe0b4076</guid>
    <pubDate>Tue, 24 May 2022 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Russian hacker group attacks IT infrastructures</dc:title>
    <dc:identifier>e73503d8-4a5d-4196-8269-9eadfe0b4076</dc:identifier>
    </item>
<item>
  <title>Russian hacker group attacks IT infrastructures</title>
  <link>https://mailbox.org/en/news/cyberwar-suspected-russian-hacker-group-attacks-western-it-infrastructure/</link>
  <description>&lt;ol&gt;&lt;li&gt;mailbox.org is currently not under attack&lt;/li&gt;&lt;li&gt;Our team is as well prepared as possible and on slightly heightened alert&lt;/li&gt;&lt;li&gt;If we notice any attacks, we will inform you immediately&lt;/li&gt;&lt;li&gt;In this case, we ask our customers to refrain from support requests&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;As part of the Russia-Ukraine war, the suspected Russian hacker group "Legion Russia" has been specifically attacking Western IT infrastructures and also e-mail providers for several days. Attack targets are collected and commissioned by Legion Russia in internal lists - these are known to us at mailbox.org.&lt;/p&gt;&lt;p&gt;Currently, we are not named as a target there – a few days ago, however, the portal "berlin.de" was attacked and struggled for several hours.&lt;/p&gt;&lt;p&gt;At this point, we would like to inform our customers purely preventively and proactively about possible upcoming attacks and their impact on our services. However, there is no reason for you to act.&lt;/p&gt;&lt;p&gt;In the past, we at mailbox.org have been able to defend ourselves very well even &lt;a href="https://mailbox.org/en/post/extortionate-ddos-attacks-on-mailbox-org" target="_blank" title="mailbox.org blog: DDoS attacks in 2021" rel="noopener"&gt;against large-scale distributed denial of service (DDoS) attacks&lt;/a&gt;. Nevertheless, we may become the target of such attacks in the coming days and weeks as well. In recent years, we have prepared a number of different defences, with external DDoS protection providers contracted and paid by us on standby around the clock.&lt;/p&gt;&lt;p&gt;Our team is now on slightly heightened alert and has recently evaluated all defensive measures. We consider ourselves to be as well prepared as possible.&lt;/p&gt;&lt;p&gt;Of course every defence has its limits, every attack may require the development of concrete defensive measures and may lead to impairments.&lt;/p&gt;&lt;p&gt;In case of disruptions:&lt;/p&gt;&lt;ol&gt;&lt;li&gt;follow our social media channels on &lt;a href="https://twitter.com/mailbox_org" target="_blank" title="Twitter: @mailbox.org" rel="noopener"&gt;Twitter&lt;/a&gt; and &lt;a href="https://social.mailbox.org/@mailbox_org" target="_blank" title=" Mastodon: @mailbox_org@social.mailbox.org" rel="noopener"&gt;Mastodon&lt;/a&gt; as well as our status page.&lt;/li&gt;&lt;li&gt;mostly the websites of the providers are attacked. If necessary, use our &lt;a href="https://login.mailbox.org/en" target="_blank" title="Go to direct login" rel="noopener"&gt;direct login page&lt;/a&gt;, which may not be affected. Also, access via e-mail client with POP3/IMAP is often possible without problems.&lt;/li&gt;&lt;li&gt;we ask you to refrain from individual support requests so that our entire team can concentrate on defence.&lt;/li&gt;&lt;li&gt;in the event of temporary inaccessibility, no e-mails will be lost, but only delivered with a delay.&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;The attacks of the suspected Russian hacker group have so far not had the goal of stealing data but were only intended to temporarily paralyse the respective IT infrastructures.&lt;/p&gt;&lt;p&gt;At the moment, you as a user do not need to do anything. We will inform you about any developments regarding this situation.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Your mailbox.org team&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-04/mailbox-news-und-updates-warnung.jpg?itok=reW9cU74" type="image/jpeg" length="238141"/><guid isPermaLink="false">e73503d8-4a5d-4196-8269-9eadfe0b4076</guid>
    <pubDate>Tue, 24 May 2022 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Russian hacker group attacks IT infrastructures</dc:title>
    <dc:identifier>e73503d8-4a5d-4196-8269-9eadfe0b4076</dc:identifier>
    </item>
<item>
  <title>Transparency Report 2021</title>
  <link>https://mailbox.org/en/news/transparency-report-2021/</link>
  <description>&lt;p&gt;Today we publish our transparency report for 2021, accounting for all requests for information that we as a provider have received by any authorities over the last year. For the first time ever, the overall number of requests has decreased when compared with previous years. The proportion of rejected requests has also turned out lower than before.&lt;/p&gt;&lt;p&gt;There were 65 requests in total submitted by the authorities in 2021, of which ten were rejected due to being unlawful or containing formal errors. Four of these requests were subsequently corrected and resubmitted, and then processed accordingly. The other six were ultimately rejected. In comparison to the year before, the proportion of ultimately rejected requests for information has decreased substantially (9.2 % in 2021, and 27.1 % in 2020). See the visualisation from last year's report below.&lt;/p&gt;&lt;h2&gt;The authorities have caught up&lt;/h2&gt;&lt;p&gt;Probably the most remarkable observation has been the large amount of correctly submitted requests that we received last year. While only 49.4 % of all initial requests in 2020 were correctly made, the figure for 2021 is an impressive 84.6 %. One explanation for this is that requests have become more standardised across different authorities. On top of that, we reckon that an increasing number of authorities may have noticed by now that they won't get very far by submitting incorrect or unlawful requests.&lt;/p&gt;&lt;h2&gt;Lawful interception is possible again&lt;/h2&gt;&lt;p&gt;Previously, the legal basis for any telecommunications surveillance measures was the German Telecommunications Act (TKG), plus some special regulations for customs enforcement and the intelligence services. However, a ruling by the German Federal Constitutional Court put into question whether communications handled by e-mail providers actually fall within the scope of that legislation. mailbox.org had therefore temporarily suspended the processing of any surveillance requests that cited the Telecommunications Act as a justification.&lt;/p&gt;&lt;p&gt;However, an amendment to the TKG was enacted on 1 December 2021 and according to this, e-mail providers such as mailbox.org are currently subject to TKG legislation. As a consequence, the TKG has once again become a legal basis for authorities requesting telecommunications surveillance measures.&lt;/p&gt;&lt;p&gt;As part of the legislative process, mailbox.org CEO Peer Heinlein had been invited as an expert to contribute to the work of the relevant parliamentary committee. Last year, he published a comprehensive statement criticising the proposed changes to the law. However, these were eventually pushed through by the government regardless.&lt;/p&gt;&lt;p&gt;In 2021, we were ordered to put in place surveillance measures based on the TKG four times.&lt;/p&gt;&lt;h2&gt;Fax more popular than e-mail&lt;/h2&gt;&lt;p&gt;Surprisingly, more than half of all enquiries in 2021 reached us by fax, which indicates that this technology is still popular with many authorities. Unfortunately, the majority of e-mails that we received from the authorities in 2021 were sent unencrypted, which is not appropriate considering that these usually contain personal information about any suspects, and sometimes even sensitive details about the investigation.&lt;/p&gt;&lt;p&gt;In 2017, the German Federal Network Agency mandated e-mail providers like mailbox.org to offer secure interfaces, through which the authorities can make data queries. This includes support for e-mails encrypted with PGP. However, the authorities are too slow to adopt these standards, many do not use secure communication, and their staff is often not sensitised to issues of data protection and security.&lt;/p&gt;&lt;h2&gt;Overview: The requests of 2021 and 2020 compared&lt;/h2&gt;&lt;ul&gt;&lt;li&gt;The total number of requests fell by almost a quarter&lt;/li&gt;&lt;li&gt;84.6 % of all requests were made correctly (2020: 49.4%)&lt;/li&gt;&lt;li&gt;Most requests were received by fax message&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Read the &lt;a href="https://mailbox.org/en/post/transparency-report-mailbox-org-2020" target="_blank" title="Go to the the transparency report of 2020" rel="noopener"&gt;transparency report of 2020 -&amp;gt;&lt;/a&gt;&lt;/p&gt;&lt;h2&gt;Requests sent to mailbox.org in the year 2021&lt;/h2&gt;&lt;p&gt;Total number of requests: 65&lt;br&gt;From German authorities: 62&lt;br&gt;From foreign non-EU authorities: 3&lt;/p&gt;&lt;p&gt;Organisations&lt;br&gt;Criminal investigative authorities: 65&lt;br&gt;Customs authorities: 0&lt;br&gt;Intelligence services: 0&lt;/p&gt;&lt;p&gt;Request type&lt;br&gt;Contact data requests: 61&lt;br&gt;Inbox confiscations: 0&lt;br&gt;Traffic data requests: 0&lt;br&gt;Telecommunications interceptions: 4&lt;/p&gt;&lt;p&gt;Our reports from previous years can be found in the section &lt;a href="https://mailbox.org/en/company#transparency-report" target="_blank" title="Go to all transparency reports" rel="noopener"&gt;transparency reports&lt;/a&gt;.&lt;/p&gt;&lt;h2&gt;How we deal with requests&lt;/h2&gt;&lt;p&gt;mailbox.org follows a standardised process when dealing with requests for information from official authorities. Each request will be comprehensively reviewed and assessed by our data protection officer and a lawyer, and then either processed or rejected accordingly. When a request gets rejected, the submitting authority may correct any errors and then resubmit for another review. Data will only be released by us if a related request is actually lawful and formally correct.&lt;/p&gt;&lt;h2&gt;Data that authorities may be interested in&lt;/h2&gt;&lt;ol&gt;&lt;li&gt;Contact data: This includes the name, address and phone number of the account holder, as well as details about their contract with us.&lt;/li&gt;&lt;li&gt;E-mail data: Access to all e-mails currently held in an account's mailbox.&lt;/li&gt;&lt;li&gt;Traffic data: The IP addresses associated with mail server logins when fetching, reading, or sending e-mails.&lt;/li&gt;&lt;li&gt;Telecommunications interception data: Obtained through the permanent surveillance of all ongoing e-mail communication of an account.&lt;/li&gt;&lt;/ol&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-04/mailbox-news-und-updates-transparenzbericht.jpg?itok=SMV4eTPL" type="image/jpeg" length="268110"/><guid isPermaLink="false">ea5c22a4-3ecb-4d38-8159-4177775f2547</guid>
    <pubDate>Tue, 10 May 2022 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Transparency Report 2021</dc:title>
    <dc:identifier>ea5c22a4-3ecb-4d38-8159-4177775f2547</dc:identifier>
    </item>
<item>
  <title>Transparency Report 2021</title>
  <link>https://mailbox.org/en/news/transparency-report-2021/</link>
  <description>&lt;p&gt;Today we publish our transparency report for 2021, accounting for all requests for information that we as a provider have received by any authorities over the last year. For the first time ever, the overall number of requests has decreased when compared with previous years. The proportion of rejected requests has also turned out lower than before.&lt;/p&gt;&lt;p&gt;There were 65 requests in total submitted by the authorities in 2021, of which ten were rejected due to being unlawful or containing formal errors. Four of these requests were subsequently corrected and resubmitted, and then processed accordingly. The other six were ultimately rejected. In comparison to the year before, the proportion of ultimately rejected requests for information has decreased substantially (9.2 % in 2021, and 27.1 % in 2020). See the visualisation from last year's report below.&lt;/p&gt;&lt;h2&gt;The authorities have caught up&lt;/h2&gt;&lt;p&gt;Probably the most remarkable observation has been the large amount of correctly submitted requests that we received last year. While only 49.4 % of all initial requests in 2020 were correctly made, the figure for 2021 is an impressive 84.6 %. One explanation for this is that requests have become more standardised across different authorities. On top of that, we reckon that an increasing number of authorities may have noticed by now that they won't get very far by submitting incorrect or unlawful requests.&lt;/p&gt;&lt;h2&gt;Lawful interception is possible again&lt;/h2&gt;&lt;p&gt;Previously, the legal basis for any telecommunications surveillance measures was the German Telecommunications Act (TKG), plus some special regulations for customs enforcement and the intelligence services. However, a ruling by the German Federal Constitutional Court put into question whether communications handled by e-mail providers actually fall within the scope of that legislation. mailbox.org had therefore temporarily suspended the processing of any surveillance requests that cited the Telecommunications Act as a justification.&lt;/p&gt;&lt;p&gt;However, an amendment to the TKG was enacted on 1 December 2021 and according to this, e-mail providers such as mailbox.org are currently subject to TKG legislation. As a consequence, the TKG has once again become a legal basis for authorities requesting telecommunications surveillance measures.&lt;/p&gt;&lt;p&gt;As part of the legislative process, mailbox.org CEO Peer Heinlein had been invited as an expert to contribute to the work of the relevant parliamentary committee. Last year, he published a comprehensive statement criticising the proposed changes to the law. However, these were eventually pushed through by the government regardless.&lt;/p&gt;&lt;p&gt;In 2021, we were ordered to put in place surveillance measures based on the TKG four times.&lt;/p&gt;&lt;h2&gt;Fax more popular than e-mail&lt;/h2&gt;&lt;p&gt;Surprisingly, more than half of all enquiries in 2021 reached us by fax, which indicates that this technology is still popular with many authorities. Unfortunately, the majority of e-mails that we received from the authorities in 2021 were sent unencrypted, which is not appropriate considering that these usually contain personal information about any suspects, and sometimes even sensitive details about the investigation.&lt;/p&gt;&lt;p&gt;In 2017, the German Federal Network Agency mandated e-mail providers like mailbox.org to offer secure interfaces, through which the authorities can make data queries. This includes support for e-mails encrypted with PGP. However, the authorities are too slow to adopt these standards, many do not use secure communication, and their staff is often not sensitised to issues of data protection and security.&lt;/p&gt;&lt;h2&gt;Overview: The requests of 2021 and 2020 compared&lt;/h2&gt;&lt;ul&gt;&lt;li&gt;The total number of requests fell by almost a quarter&lt;/li&gt;&lt;li&gt;84.6 % of all requests were made correctly (2020: 49.4%)&lt;/li&gt;&lt;li&gt;Most requests were received by fax message&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Read the &lt;a href="https://mailbox.org/en/post/transparency-report-mailbox-org-2020" target="_blank" title="Go to the the transparency report of 2020" rel="noopener"&gt;transparency report of 2020 -&amp;gt;&lt;/a&gt;&lt;/p&gt;&lt;h2&gt;Requests sent to mailbox.org in the year 2021&lt;/h2&gt;&lt;p&gt;Total number of requests: 65&lt;br&gt;From German authorities: 62&lt;br&gt;From foreign non-EU authorities: 3&lt;/p&gt;&lt;p&gt;Organisations&lt;br&gt;Criminal investigative authorities: 65&lt;br&gt;Customs authorities: 0&lt;br&gt;Intelligence services: 0&lt;/p&gt;&lt;p&gt;Request type&lt;br&gt;Contact data requests: 61&lt;br&gt;Inbox confiscations: 0&lt;br&gt;Traffic data requests: 0&lt;br&gt;Telecommunications interceptions: 4&lt;/p&gt;&lt;p&gt;Our reports from previous years can be found in the section &lt;a href="https://mailbox.org/en/company#transparency-report" target="_blank" title="Go to all transparency reports" rel="noopener"&gt;transparency reports&lt;/a&gt;.&lt;/p&gt;&lt;h2&gt;How we deal with requests&lt;/h2&gt;&lt;p&gt;mailbox.org follows a standardised process when dealing with requests for information from official authorities. Each request will be comprehensively reviewed and assessed by our data protection officer and a lawyer, and then either processed or rejected accordingly. When a request gets rejected, the submitting authority may correct any errors and then resubmit for another review. Data will only be released by us if a related request is actually lawful and formally correct.&lt;/p&gt;&lt;h2&gt;Data that authorities may be interested in&lt;/h2&gt;&lt;ol&gt;&lt;li&gt;Contact data: This includes the name, address and phone number of the account holder, as well as details about their contract with us.&lt;/li&gt;&lt;li&gt;E-mail data: Access to all e-mails currently held in an account's mailbox.&lt;/li&gt;&lt;li&gt;Traffic data: The IP addresses associated with mail server logins when fetching, reading, or sending e-mails.&lt;/li&gt;&lt;li&gt;Telecommunications interception data: Obtained through the permanent surveillance of all ongoing e-mail communication of an account.&lt;/li&gt;&lt;/ol&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-04/mailbox-news-und-updates-transparenzbericht.jpg?itok=SMV4eTPL" type="image/jpeg" length="268110"/><guid isPermaLink="false">ea5c22a4-3ecb-4d38-8159-4177775f2547</guid>
    <pubDate>Tue, 10 May 2022 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Transparency Report 2021</dc:title>
    <dc:identifier>ea5c22a4-3ecb-4d38-8159-4177775f2547</dc:identifier>
    </item>
<item>
  <title>Restrictions on Gmail for third-party providers</title>
  <link>https://mailbox.org/en/news/google-announces-restriction-gmail-third-party-services/</link>
  <description>&lt;ul&gt;&lt;li&gt;From June 2022, Gmail mailboxes can no longer be accessed via mailbox.org&lt;/li&gt;&lt;li&gt;Use the free relocation service&lt;/li&gt;&lt;li&gt;Alternatively, you can set up e-mail forwarding to your mailbox.org address&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Google has already restricted the integration of calendars and contacts with third-party services, such as mailbox.org, in 2020 – from June 2022, this will now also affect Gmail inboxes.&lt;/p&gt;&lt;h2&gt;No alternative: Certification by Google&lt;/h2&gt;&lt;p&gt;Google requires third-party services to undergo extensive certification by an American service provider named by Google in order for their users to continue to be able to integrate Google mailboxes. In general, we welcome the fact that Google is raising its security standards in order to minimise dubious offers and abuse. However, Google is using its market power to make it impossible for reputable and privacy-conscious third-party services to comply with this certification. We are not willing to give Google or other US companies access to our infrastructure in the course of the certification. We already &lt;a href="https://mailbox.org/en/post/google-about-to-restrict-third-party-integration-of-calendars-contacts-and-drive" target="_blank" rel="noopener"&gt;explained this in detail in 2020&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;So if you currently have a Gmail mailbox integrated in the mailbox.org webmailer, this will unfortunately no longer work as usual from June 2022. Since the use of two parallel email accounts is impractical for many customers, we have two suggestions for you to solve this problem.&lt;/p&gt;&lt;h2&gt;Option 1: Temporary forwarding&lt;/h2&gt;&lt;p&gt;If you use a Gmail account, then you can set up an automatic forwarding from Gmail to your mailbox.org address. If this is an option for you, then you can find instructions here:&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&amp;nbsp;&lt;p&gt;&amp;nbsp;&lt;/p&gt;Setup forwarding&lt;ol&gt;&lt;li&gt;Set up Gmail forwarding: &lt;a href="https://support.google.com/mail/answer/10957?hl=en-GB" target="_blank" rel="noopener"&gt;Automatically forward Gmail messages to another e-mail account →&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Automatically store e-mails from Gmail in a separate folder at mailbox.org. If you do not want to have the e-mails from your Gmail inbox directly in your mailbox.org inbox, then you can set up a filter rule for this.&lt;br&gt;&amp;nbsp;&lt;/li&gt;&lt;li&gt;Go to Settings &amp;gt; E-mail &amp;gt; Filter Rules &amp;gt; Add New Rule&lt;/li&gt;&lt;li&gt;Assign a unique name&lt;/li&gt;&lt;li&gt;Add the "From" condition with the Gmail address. Preferably with the endings @gmail.com and @googlemail.com.&lt;/li&gt;&lt;li&gt;Select "Apply rule if any condition is met" above the conditions.&lt;/li&gt;&lt;li&gt;Select the action "Save as" and the desired folder. You can also conveniently create a new folder here.&lt;/li&gt;&lt;li&gt;Click on "Save&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;Henceforth, the e-mails from the selected sender address are moved directly to the desired folder.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;h2&gt;Option 2: Say goodbye to Google&lt;/h2&gt;&lt;p&gt;Perhaps this is the opportunity to make your move to mailbox.org complete. If you've been afraid of the hassle, why not take advantage of our free moving service for your emails, calendars and contacts.&lt;/p&gt;&lt;p&gt;&lt;a href="https://kb.mailbox.org/en/private/account-article/move-away-from-gmail-to-mailbox-org-step-by-step" target="_blank" title="Move away from Gmail to mailbox.org: step-by-step" rel="noopener"&gt;Move away from Gmail to mailbox.org: step-by-step -&amp;gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="https://kb.mailbox.org/en/private/account-article/audriga-your-e-mail-migration-service" target="_blank" rel="noopener"&gt;Learn more about our move service →&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;br&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Your mailbox.org team&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-04/mailbox-news-und-updates-warnung.jpg?itok=reW9cU74" type="image/jpeg" length="238141"/><guid isPermaLink="false">fa2c846a-0379-4b6e-a8fc-fc3c777a2f37</guid>
    <pubDate>Thu, 28 Apr 2022 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Restrictions on Gmail for third-party providers</dc:title>
    <dc:identifier>fa2c846a-0379-4b6e-a8fc-fc3c777a2f37</dc:identifier>
    </item>
<item>
  <title>Restrictions on Gmail for third-party providers</title>
  <link>https://mailbox.org/en/news/google-announces-restriction-gmail-third-party-services/</link>
  <description>&lt;ul&gt;&lt;li&gt;From June 2022, Gmail mailboxes can no longer be accessed via mailbox.org&lt;/li&gt;&lt;li&gt;Use the free relocation service&lt;/li&gt;&lt;li&gt;Alternatively, you can set up e-mail forwarding to your mailbox.org address&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Google has already restricted the integration of calendars and contacts with third-party services, such as mailbox.org, in 2020 – from June 2022, this will now also affect Gmail inboxes.&lt;/p&gt;&lt;h2&gt;No alternative: Certification by Google&lt;/h2&gt;&lt;p&gt;Google requires third-party services to undergo extensive certification by an American service provider named by Google in order for their users to continue to be able to integrate Google mailboxes. In general, we welcome the fact that Google is raising its security standards in order to minimise dubious offers and abuse. However, Google is using its market power to make it impossible for reputable and privacy-conscious third-party services to comply with this certification. We are not willing to give Google or other US companies access to our infrastructure in the course of the certification. We already &lt;a href="https://mailbox.org/en/post/google-about-to-restrict-third-party-integration-of-calendars-contacts-and-drive" target="_blank" rel="noopener"&gt;explained this in detail in 2020&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;So if you currently have a Gmail mailbox integrated in the mailbox.org webmailer, this will unfortunately no longer work as usual from June 2022. Since the use of two parallel email accounts is impractical for many customers, we have two suggestions for you to solve this problem.&lt;/p&gt;&lt;h2&gt;Option 1: Temporary forwarding&lt;/h2&gt;&lt;p&gt;If you use a Gmail account, then you can set up an automatic forwarding from Gmail to your mailbox.org address. If this is an option for you, then you can find instructions here:&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&amp;nbsp;&lt;p&gt;&amp;nbsp;&lt;/p&gt;Setup forwarding&lt;ol&gt;&lt;li&gt;Set up Gmail forwarding: &lt;a href="https://support.google.com/mail/answer/10957?hl=en-GB" target="_blank" rel="noopener"&gt;Automatically forward Gmail messages to another e-mail account →&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Automatically store e-mails from Gmail in a separate folder at mailbox.org. If you do not want to have the e-mails from your Gmail inbox directly in your mailbox.org inbox, then you can set up a filter rule for this.&lt;br&gt;&amp;nbsp;&lt;/li&gt;&lt;li&gt;Go to Settings &amp;gt; E-mail &amp;gt; Filter Rules &amp;gt; Add New Rule&lt;/li&gt;&lt;li&gt;Assign a unique name&lt;/li&gt;&lt;li&gt;Add the "From" condition with the Gmail address. Preferably with the endings @gmail.com and @googlemail.com.&lt;/li&gt;&lt;li&gt;Select "Apply rule if any condition is met" above the conditions.&lt;/li&gt;&lt;li&gt;Select the action "Save as" and the desired folder. You can also conveniently create a new folder here.&lt;/li&gt;&lt;li&gt;Click on "Save&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;Henceforth, the e-mails from the selected sender address are moved directly to the desired folder.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;h2&gt;Option 2: Say goodbye to Google&lt;/h2&gt;&lt;p&gt;Perhaps this is the opportunity to make your move to mailbox.org complete. If you've been afraid of the hassle, why not take advantage of our free moving service for your emails, calendars and contacts.&lt;/p&gt;&lt;p&gt;&lt;a href="https://kb.mailbox.org/en/private/account-article/move-away-from-gmail-to-mailbox-org-step-by-step" target="_blank" title="Move away from Gmail to mailbox.org: step-by-step" rel="noopener"&gt;Move away from Gmail to mailbox.org: step-by-step -&amp;gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="https://kb.mailbox.org/en/private/account-article/audriga-your-e-mail-migration-service" target="_blank" rel="noopener"&gt;Learn more about our move service →&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;br&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Your mailbox.org team&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-04/mailbox-news-und-updates-warnung.jpg?itok=reW9cU74" type="image/jpeg" length="238141"/><guid isPermaLink="false">fa2c846a-0379-4b6e-a8fc-fc3c777a2f37</guid>
    <pubDate>Thu, 28 Apr 2022 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Restrictions on Gmail for third-party providers</dc:title>
    <dc:identifier>fa2c846a-0379-4b6e-a8fc-fc3c777a2f37</dc:identifier>
    </item>
<item>
  <title>Free choice of operating systems, software and services</title>
  <link>https://mailbox.org/en/news/open-letter-free-choice-operating-systems-software-and-services/</link>
  <description>&lt;p&gt;mailbox.org supports an open letter by FSFE (&lt;a href="https://fsfe.org/" target="_blank" title="Free Software Foundation Europe" rel="noopener"&gt;Free Software Foundation Europe&lt;/a&gt;) in which the signatories demand a "universal right" from European Union legislators to run any software on any device. This includes the development of software and operating systems as well as services offered by manufacturers and a universal right to repair without hurdles built-in by the manufacturer. Nowadays, too many devices would be thrown away simply because manufacturers refuse to allow their customers to repair devices or run them with software from other manufacturers. It is not uncommon for manufacturers to encrypt bootloaders on smartphones or tablets, for example, just to prevent users from installing alternative software. This is not sustainable, says FSFE, and certainly not customer-friendly or market-driven:&lt;/p&gt;&lt;p&gt;&lt;em&gt;"Software design is crucial for the ecodesign and sustainability of products and hardware. Free Software systems and services enable reuse, repurposing and interoperability of devices. The universal right to freely choose operating systems, software and services is crucial for a more sustainable digital society." FSFE&lt;/em&gt;&lt;/p&gt;&lt;h2&gt;Open standards&lt;/h2&gt;&lt;p&gt;Open standards play an important role in FSFE's demands. Only these standards ensure that devices, software, and services can communicate freely with each other, independent of manufacturers and their proprietary products. Only in this way can a customer be sure that he can take his data with him at any time, for example by exporting it from mobile phones or internet services and importing it elsewhere.&lt;/p&gt;&lt;h2&gt;Right to repair&lt;/h2&gt;&lt;p&gt;FSFE also includes the right to repair in its open letter. This also includes the obligation for manufacturers to publish all necessary drivers, tools, and interfaces under a free software license as soon as devices are available on the market. Only then can developers, for example, develop free, independent, and data-saving operating systems on these devices as well, which can not only be more secure but also be available to the user with all necessary updates and security patches after the end of the manufacturer support.&lt;/p&gt;&lt;h2&gt;Ban on technical hurdles&lt;/h2&gt;&lt;p&gt;All legal, technical, or whatever obstacles in hardware and software that block the fulfillment of the three demands should be banned, FSFE said. The FSFE's open letter has been signed 38 times, &lt;a href="https://fsfe.org/activities/upcyclingandroid/openletter.en.html" target="_blank" title=" Open Letter: The universal right to install any software on any device" rel="noopener"&gt;the full letter can be found here&lt;/a&gt;.&lt;/p&gt;&lt;h2&gt;mailbox.org also supports open standards&lt;/h2&gt;&lt;p&gt;mailbox.org supports all these demands, for many years we have been relying on open source software and open standards, because we firmly believe that this is the only way for users to experience and verify the optimal (freedom of) choice, security, privacy, and reliability of the tools used.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-envelope-1.png?itok=ahABjshn" type="image/png" length="394797"/><guid isPermaLink="false">99b0ebe6-60bd-4a8f-a9c3-b7456f7fa2c1</guid>
    <pubDate>Wed, 27 Apr 2022 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Free choice of operating systems, software and services</dc:title>
    <dc:identifier>99b0ebe6-60bd-4a8f-a9c3-b7456f7fa2c1</dc:identifier>
    </item>
<item>
  <title>Free choice of operating systems, software and services</title>
  <link>https://mailbox.org/en/news/open-letter-free-choice-operating-systems-software-and-services/</link>
  <description>&lt;p&gt;mailbox.org supports an open letter by FSFE (&lt;a href="https://fsfe.org/" target="_blank" title="Free Software Foundation Europe" rel="noopener"&gt;Free Software Foundation Europe&lt;/a&gt;) in which the signatories demand a "universal right" from European Union legislators to run any software on any device. This includes the development of software and operating systems as well as services offered by manufacturers and a universal right to repair without hurdles built-in by the manufacturer. Nowadays, too many devices would be thrown away simply because manufacturers refuse to allow their customers to repair devices or run them with software from other manufacturers. It is not uncommon for manufacturers to encrypt bootloaders on smartphones or tablets, for example, just to prevent users from installing alternative software. This is not sustainable, says FSFE, and certainly not customer-friendly or market-driven:&lt;/p&gt;&lt;p&gt;&lt;em&gt;"Software design is crucial for the ecodesign and sustainability of products and hardware. Free Software systems and services enable reuse, repurposing and interoperability of devices. The universal right to freely choose operating systems, software and services is crucial for a more sustainable digital society." FSFE&lt;/em&gt;&lt;/p&gt;&lt;h2&gt;Open standards&lt;/h2&gt;&lt;p&gt;Open standards play an important role in FSFE's demands. Only these standards ensure that devices, software, and services can communicate freely with each other, independent of manufacturers and their proprietary products. Only in this way can a customer be sure that he can take his data with him at any time, for example by exporting it from mobile phones or internet services and importing it elsewhere.&lt;/p&gt;&lt;h2&gt;Right to repair&lt;/h2&gt;&lt;p&gt;FSFE also includes the right to repair in its open letter. This also includes the obligation for manufacturers to publish all necessary drivers, tools, and interfaces under a free software license as soon as devices are available on the market. Only then can developers, for example, develop free, independent, and data-saving operating systems on these devices as well, which can not only be more secure but also be available to the user with all necessary updates and security patches after the end of the manufacturer support.&lt;/p&gt;&lt;h2&gt;Ban on technical hurdles&lt;/h2&gt;&lt;p&gt;All legal, technical, or whatever obstacles in hardware and software that block the fulfillment of the three demands should be banned, FSFE said. The FSFE's open letter has been signed 38 times, &lt;a href="https://fsfe.org/activities/upcyclingandroid/openletter.en.html" target="_blank" title=" Open Letter: The universal right to install any software on any device" rel="noopener"&gt;the full letter can be found here&lt;/a&gt;.&lt;/p&gt;&lt;h2&gt;mailbox.org also supports open standards&lt;/h2&gt;&lt;p&gt;mailbox.org supports all these demands, for many years we have been relying on open source software and open standards, because we firmly believe that this is the only way for users to experience and verify the optimal (freedom of) choice, security, privacy, and reliability of the tools used.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-envelope-1.png?itok=ahABjshn" type="image/png" length="394797"/><guid isPermaLink="false">99b0ebe6-60bd-4a8f-a9c3-b7456f7fa2c1</guid>
    <pubDate>Wed, 27 Apr 2022 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Free choice of operating systems, software and services</dc:title>
    <dc:identifier>99b0ebe6-60bd-4a8f-a9c3-b7456f7fa2c1</dc:identifier>
    </item>
<item>
  <title>Power outage at the data centre caused outages</title>
  <link>https://mailbox.org/en/news/power-outage-data-centre-led-downtime-mailboxorg/</link>
  <description>&lt;h2&gt;The reconstruction of an outage&lt;/h2&gt;&lt;p&gt;By Peer Heinlein, mailbox.org CEO&lt;/p&gt;&lt;p&gt;A power outage caused by a short circuit in a 10kV line in the Tiergarten area of Berlin on Tuesday afternoon also damaged the emergency power system of a large data center we use there, resulting in a prolonged power outage in the data center as well and tens of thousands of servers down. There were widespread Internet disruptions in Berlin and also a prolonged outage at mailbox.org.&lt;/p&gt;&lt;p&gt;Actually, mailbox.org specifically uses two data centers in parallel to be able to compensate for outages of this kind. Nevertheless, there were operational disruptions. It is not easy to explain the cause - because there was not "one big classic problem". Rather, the concatenation of several small problems and unfortunate circumstances led to the outage in both data centers.&lt;/p&gt;&lt;h2&gt;The non-technical short version&lt;/h2&gt;&lt;p&gt;No data was lost.&lt;/p&gt;&lt;p&gt;A power outage in Berlin and a failure of an emergency power system led to a widespread power outage at a data center we use. Internet in Berlin was disrupted over a large area in the afternoon and evening hours, and tens of thousands of servers lost power. Due to various complications that had been analyzed and clarified in the meantime, our second data center was not able to take over operations without disruptions as expected. After the power supply was restored, it took our team another two and a half hours until all our services were available again. Considering the severity and scope of the outage, this may not be an unusual amount of time. However, we have technically analyzed why our replacement data center could not take over the service without interruption and have remedied the causes - the details are prepared for interested technicians :-) in this article below.&lt;/p&gt;&lt;h2&gt;The long and technical version&lt;/h2&gt;&lt;p&gt;For the sake of transparency, we will try to reconstruct the sequence of events here. It cannot be avoided that this will be a technical description, as the technical interrelationships cannot be explained in any other way. In the following, some facts are shortened and simplified and some technical details of our infrastructure cannot be published for security reasons.&lt;/p&gt;&lt;p&gt;mailbox.org and Heinlein Hosting operate two physically completely separate server locations in Berlin. For this purpose we have rented our own technology and infrastructure from two different data center providers. Like a "shopping mall", these providers operate the building and the air conditioning and power technology, while we are responsible for the use of our proportionate area and premises with servers, data traffic &amp;amp; Co.&lt;/p&gt;&lt;p&gt;At both locations, we operate virtualization systems that are physically and also largely logically independent of each other, as well as large hard disk storage on which our services run. Both virtualization clusters are connected via a common control unit. Should this fail, the clusters can continue to run autonomously, but restarts or other work may then not be possible.&lt;/p&gt;&lt;p&gt;If one site or virtualization cluster fails, the second site should ideally continue to function without interruption, or at least be able to take over operation within a reasonable time after minor adaptation or conversion work.&lt;/p&gt;&lt;h3&gt;1. The power outage in Berlin&lt;/h3&gt;&lt;p&gt;A power failure in the power grid happens every now and then. Data centers are equipped against this with battery buffers and large emergency power systems and usually even have two separate power circuits for parallel internal supply.&lt;/p&gt;&lt;p&gt;After all, what must not happen in the event of a public power outage is that a power outage will penetrate the data center with its tens of thousands of servers.&lt;/p&gt;&lt;p&gt;What happened: At one of our two sites, the provider's emergency power system failed and tens of thousands of servers from a wide range of providers and companies went offline. Our hardware, too. This "shouldn't" happen, but "can" happen and "has" happened. We, too, are eagerly awaiting the root cause analysis and report from the data center provider. According to initial feedback, the short-circuit of a 10,000-volt line in the Berlin city grid also blew through into the data center in such a way that the battery system of the emergency power supply also suffered damage.&lt;/p&gt;&lt;p&gt;The consequences were felt by numerous Internet services: Depending on the situation, there were large-scale disruptions lasting for hours until late at night, the Berlin data exchange node BCIX was partially affected in the meantime, and in the end even a daily newspaper could no longer produce a print edition.&lt;/p&gt;&lt;p&gt;It is rare for not just individual devices but the entire IT infrastructure at a site to go offline, and because of the sheer volume involved, it takes a lot of effort to restore everything.&lt;/p&gt;&lt;p&gt;But to minimize this, we operate our servers at several sites - and our second site had of course not been affected by the power outage and failure of the emergency power systems. Nevertheless, there was a noticeable disruption, even for users. Why?&lt;/p&gt;&lt;h3&gt;2. Unexpected disruptions in two data centres&lt;/h3&gt;&lt;p&gt;After a major alarm and an "all hands on deck," our team found a very unclear and contradictory picture with numerous malfunctions at the second site as well: Numerous systems were running, yet there were impairments and failures that could not be explained at first.&lt;/p&gt;&lt;p&gt;It quickly became apparent that even in the second location, which was not actually affected, the virtualization cluster with hundreds of our systems was "up and running", but could no longer be properly controlled and addressed, and some servers were no longer working reliably. To speed up troubleshooting, we called in external experts around 4 p.m. who specialize in the VMware virtualization software we use there, but even with their combined efforts it was difficult to explain the symptoms and problems.&lt;/p&gt;&lt;p&gt;In the end, the cause was a still ongoing malfunction in our Domain Name System, i.e. the system for resolving server hostnames to IP addresses. For this purpose, we operate several so-called DNS resolvers, which are divided between both data centers in order to intercept a total failure of a site here as well.&lt;/p&gt;&lt;p&gt;Two of our three DNS resolvers were affected by the outage - but this was not a problem for our servers at first and did not show up as a failure, because the third DNS resolver continued to work without any problems and only one working system was needed. Hundreds of systems therefore continued to function as planned for the time being.&lt;/p&gt;&lt;h3&gt;3. Undetected malfunctions of a DNS resolver and VMware specifics&lt;/h3&gt;&lt;p&gt;Unlike other (Linux) server systems, however, only two instead of the usual three different DNS servers can be used simultaneously in a VMware virtualisation. Care is taken to use systems from each location. Nevertheless, DNS resolvers at each location were disturbed and VMware happened to use exactly and exclusively the two failed systems.&lt;/p&gt;&lt;p&gt;As a result, the virtualisation servers involved could no longer "see" each other properly at all locations and could no longer communicate properly internally, so that the loss of control of the virtualisation cluster occurred at both locations at the same time.&lt;/p&gt;&lt;p&gt;For us, this in itself very banal circumstance was difficult to recognise, as for all other systems everything could still be operated and queried without any problems on the basis of the 3rd running DNS resolver. In addition, the two DNS resolvers that had failed also appeared externally intact and we assumed for a long time that they were functioning normally, so that they were not the focus of the analysis.&lt;/p&gt;&lt;h3&gt;4. Looking for the cause in the wrong place&lt;/h3&gt;&lt;p&gt;Our team, together with the external experts, therefore spent (too) long looking for a problem within the virtualisation solution and only belatedly realised that the symptoms were caused by the missing, externally faultless DNS resolvers.&lt;/p&gt;&lt;p&gt;After we restarted one of the two compromised DNS resolvers, all problems and causes in the cluster abruptly resolved, we regained control and were able to start restarting failed and disturbed servers around 5:30 p.m., so that relatively quickly around 6 p.m. all services were available again at both locations. Our team was then busy until after midnight restoring numerous other systems, while mailbox.org was already up and running again.&lt;/p&gt;&lt;p&gt;Our status page "https://status.mailbox.org" is automatically controlled by our monitoring system so that our admin team can concentrate fully on error analysis in the event of disruptions. Due to the widespread outage, one monitoring system was also affected, so the status display continued to show "green" for the first hour before we manually set the fault. This caused confusion for some users - but we ask for your understanding that in this situation we first took care of the root cause analysis.&lt;/p&gt;&lt;h2&gt;The conclusion&lt;/h2&gt;&lt;ol&gt;&lt;li&gt;A power outage in the data centre must not happen and we are looking forward to the final report from our provider. However, we are prepared for this circumstance ourselves, so that we could have continued operation with the second location even in the event of a prolonged outage, or actually the second location should have continued operation without interruption.&lt;/li&gt;&lt;li&gt;The fact that both virtualisation clusters at both locations used the two failed DNS resolvers and were not physically but logically affected was very unlucky, but must not happen either. We will therefore carry out technical modifications in several places so that this problem can no longer occur and certainly no longer occur undetected. Moreover, we now know how to interpret the resulting (very crazy) symptoms.&lt;/li&gt;&lt;li&gt;But apart from that, none of this would have been a problem if there hadn't also been a small network-related peculiarity due to maintenance work. This is in itself known, trivial, and harmless, but in the end, it contributed to the failure of the DNS resolver at the uninvolved site in the cascade of very small and foreseeable and planned faults, and the sum of the in itself harmless faults to escalation.&lt;/li&gt;&lt;li&gt;The major malfunction was the combined result of about half a dozen, individually harmless small things. Only through the combined occurrence of all these problems together could the total disturbance occur; any omission of a partial problem would not have allowed the total problem to occur.&lt;/li&gt;&lt;li&gt;The cooperation of our incident team - about 20 team members worked together on the outage - worked well and within minutes; our own backup by external specialists also worked.&lt;/li&gt;&lt;li&gt;Data and e-mails were not lost at any time.&lt;/li&gt;&lt;li&gt;After the power outage at around 3 pm, our services were available again around 6 pm.&lt;/li&gt;&lt;li&gt;The causes are known, analysed, and understood and can be ruled out in the future by taking them into account and rebuilding them&lt;/li&gt;&lt;/ol&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-04/mailbox-news-und-updates-warnung.jpg?itok=reW9cU74" type="image/jpeg" length="238141"/><guid isPermaLink="false">080fcfee-9fd0-4697-91ee-a3625db8554c</guid>
    <pubDate>Wed, 20 Apr 2022 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Power outage at the data centre caused outages</dc:title>
    <dc:identifier>080fcfee-9fd0-4697-91ee-a3625db8554c</dc:identifier>
    </item>
<item>
  <title>Power outage at the data centre caused outages</title>
  <link>https://mailbox.org/en/news/power-outage-data-centre-led-downtime-mailboxorg/</link>
  <description>&lt;h2&gt;The reconstruction of an outage&lt;/h2&gt;&lt;p&gt;By Peer Heinlein, mailbox.org CEO&lt;/p&gt;&lt;p&gt;A power outage caused by a short circuit in a 10kV line in the Tiergarten area of Berlin on Tuesday afternoon also damaged the emergency power system of a large data center we use there, resulting in a prolonged power outage in the data center as well and tens of thousands of servers down. There were widespread Internet disruptions in Berlin and also a prolonged outage at mailbox.org.&lt;/p&gt;&lt;p&gt;Actually, mailbox.org specifically uses two data centers in parallel to be able to compensate for outages of this kind. Nevertheless, there were operational disruptions. It is not easy to explain the cause - because there was not "one big classic problem". Rather, the concatenation of several small problems and unfortunate circumstances led to the outage in both data centers.&lt;/p&gt;&lt;h2&gt;The non-technical short version&lt;/h2&gt;&lt;p&gt;No data was lost.&lt;/p&gt;&lt;p&gt;A power outage in Berlin and a failure of an emergency power system led to a widespread power outage at a data center we use. Internet in Berlin was disrupted over a large area in the afternoon and evening hours, and tens of thousands of servers lost power. Due to various complications that had been analyzed and clarified in the meantime, our second data center was not able to take over operations without disruptions as expected. After the power supply was restored, it took our team another two and a half hours until all our services were available again. Considering the severity and scope of the outage, this may not be an unusual amount of time. However, we have technically analyzed why our replacement data center could not take over the service without interruption and have remedied the causes - the details are prepared for interested technicians :-) in this article below.&lt;/p&gt;&lt;h2&gt;The long and technical version&lt;/h2&gt;&lt;p&gt;For the sake of transparency, we will try to reconstruct the sequence of events here. It cannot be avoided that this will be a technical description, as the technical interrelationships cannot be explained in any other way. In the following, some facts are shortened and simplified and some technical details of our infrastructure cannot be published for security reasons.&lt;/p&gt;&lt;p&gt;mailbox.org and Heinlein Hosting operate two physically completely separate server locations in Berlin. For this purpose we have rented our own technology and infrastructure from two different data center providers. Like a "shopping mall", these providers operate the building and the air conditioning and power technology, while we are responsible for the use of our proportionate area and premises with servers, data traffic &amp;amp; Co.&lt;/p&gt;&lt;p&gt;At both locations, we operate virtualization systems that are physically and also largely logically independent of each other, as well as large hard disk storage on which our services run. Both virtualization clusters are connected via a common control unit. Should this fail, the clusters can continue to run autonomously, but restarts or other work may then not be possible.&lt;/p&gt;&lt;p&gt;If one site or virtualization cluster fails, the second site should ideally continue to function without interruption, or at least be able to take over operation within a reasonable time after minor adaptation or conversion work.&lt;/p&gt;&lt;h3&gt;1. The power outage in Berlin&lt;/h3&gt;&lt;p&gt;A power failure in the power grid happens every now and then. Data centers are equipped against this with battery buffers and large emergency power systems and usually even have two separate power circuits for parallel internal supply.&lt;/p&gt;&lt;p&gt;After all, what must not happen in the event of a public power outage is that a power outage will penetrate the data center with its tens of thousands of servers.&lt;/p&gt;&lt;p&gt;What happened: At one of our two sites, the provider's emergency power system failed and tens of thousands of servers from a wide range of providers and companies went offline. Our hardware, too. This "shouldn't" happen, but "can" happen and "has" happened. We, too, are eagerly awaiting the root cause analysis and report from the data center provider. According to initial feedback, the short-circuit of a 10,000-volt line in the Berlin city grid also blew through into the data center in such a way that the battery system of the emergency power supply also suffered damage.&lt;/p&gt;&lt;p&gt;The consequences were felt by numerous Internet services: Depending on the situation, there were large-scale disruptions lasting for hours until late at night, the Berlin data exchange node BCIX was partially affected in the meantime, and in the end even a daily newspaper could no longer produce a print edition.&lt;/p&gt;&lt;p&gt;It is rare for not just individual devices but the entire IT infrastructure at a site to go offline, and because of the sheer volume involved, it takes a lot of effort to restore everything.&lt;/p&gt;&lt;p&gt;But to minimize this, we operate our servers at several sites - and our second site had of course not been affected by the power outage and failure of the emergency power systems. Nevertheless, there was a noticeable disruption, even for users. Why?&lt;/p&gt;&lt;h3&gt;2. Unexpected disruptions in two data centres&lt;/h3&gt;&lt;p&gt;After a major alarm and an "all hands on deck," our team found a very unclear and contradictory picture with numerous malfunctions at the second site as well: Numerous systems were running, yet there were impairments and failures that could not be explained at first.&lt;/p&gt;&lt;p&gt;It quickly became apparent that even in the second location, which was not actually affected, the virtualization cluster with hundreds of our systems was "up and running", but could no longer be properly controlled and addressed, and some servers were no longer working reliably. To speed up troubleshooting, we called in external experts around 4 p.m. who specialize in the VMware virtualization software we use there, but even with their combined efforts it was difficult to explain the symptoms and problems.&lt;/p&gt;&lt;p&gt;In the end, the cause was a still ongoing malfunction in our Domain Name System, i.e. the system for resolving server hostnames to IP addresses. For this purpose, we operate several so-called DNS resolvers, which are divided between both data centers in order to intercept a total failure of a site here as well.&lt;/p&gt;&lt;p&gt;Two of our three DNS resolvers were affected by the outage - but this was not a problem for our servers at first and did not show up as a failure, because the third DNS resolver continued to work without any problems and only one working system was needed. Hundreds of systems therefore continued to function as planned for the time being.&lt;/p&gt;&lt;h3&gt;3. Undetected malfunctions of a DNS resolver and VMware specifics&lt;/h3&gt;&lt;p&gt;Unlike other (Linux) server systems, however, only two instead of the usual three different DNS servers can be used simultaneously in a VMware virtualisation. Care is taken to use systems from each location. Nevertheless, DNS resolvers at each location were disturbed and VMware happened to use exactly and exclusively the two failed systems.&lt;/p&gt;&lt;p&gt;As a result, the virtualisation servers involved could no longer "see" each other properly at all locations and could no longer communicate properly internally, so that the loss of control of the virtualisation cluster occurred at both locations at the same time.&lt;/p&gt;&lt;p&gt;For us, this in itself very banal circumstance was difficult to recognise, as for all other systems everything could still be operated and queried without any problems on the basis of the 3rd running DNS resolver. In addition, the two DNS resolvers that had failed also appeared externally intact and we assumed for a long time that they were functioning normally, so that they were not the focus of the analysis.&lt;/p&gt;&lt;h3&gt;4. Looking for the cause in the wrong place&lt;/h3&gt;&lt;p&gt;Our team, together with the external experts, therefore spent (too) long looking for a problem within the virtualisation solution and only belatedly realised that the symptoms were caused by the missing, externally faultless DNS resolvers.&lt;/p&gt;&lt;p&gt;After we restarted one of the two compromised DNS resolvers, all problems and causes in the cluster abruptly resolved, we regained control and were able to start restarting failed and disturbed servers around 5:30 p.m., so that relatively quickly around 6 p.m. all services were available again at both locations. Our team was then busy until after midnight restoring numerous other systems, while mailbox.org was already up and running again.&lt;/p&gt;&lt;p&gt;Our status page "https://status.mailbox.org" is automatically controlled by our monitoring system so that our admin team can concentrate fully on error analysis in the event of disruptions. Due to the widespread outage, one monitoring system was also affected, so the status display continued to show "green" for the first hour before we manually set the fault. This caused confusion for some users - but we ask for your understanding that in this situation we first took care of the root cause analysis.&lt;/p&gt;&lt;h2&gt;The conclusion&lt;/h2&gt;&lt;ol&gt;&lt;li&gt;A power outage in the data centre must not happen and we are looking forward to the final report from our provider. However, we are prepared for this circumstance ourselves, so that we could have continued operation with the second location even in the event of a prolonged outage, or actually the second location should have continued operation without interruption.&lt;/li&gt;&lt;li&gt;The fact that both virtualisation clusters at both locations used the two failed DNS resolvers and were not physically but logically affected was very unlucky, but must not happen either. We will therefore carry out technical modifications in several places so that this problem can no longer occur and certainly no longer occur undetected. Moreover, we now know how to interpret the resulting (very crazy) symptoms.&lt;/li&gt;&lt;li&gt;But apart from that, none of this would have been a problem if there hadn't also been a small network-related peculiarity due to maintenance work. This is in itself known, trivial, and harmless, but in the end, it contributed to the failure of the DNS resolver at the uninvolved site in the cascade of very small and foreseeable and planned faults, and the sum of the in itself harmless faults to escalation.&lt;/li&gt;&lt;li&gt;The major malfunction was the combined result of about half a dozen, individually harmless small things. Only through the combined occurrence of all these problems together could the total disturbance occur; any omission of a partial problem would not have allowed the total problem to occur.&lt;/li&gt;&lt;li&gt;The cooperation of our incident team - about 20 team members worked together on the outage - worked well and within minutes; our own backup by external specialists also worked.&lt;/li&gt;&lt;li&gt;Data and e-mails were not lost at any time.&lt;/li&gt;&lt;li&gt;After the power outage at around 3 pm, our services were available again around 6 pm.&lt;/li&gt;&lt;li&gt;The causes are known, analysed, and understood and can be ruled out in the future by taking them into account and rebuilding them&lt;/li&gt;&lt;/ol&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-04/mailbox-news-und-updates-warnung.jpg?itok=reW9cU74" type="image/jpeg" length="238141"/><guid isPermaLink="false">080fcfee-9fd0-4697-91ee-a3625db8554c</guid>
    <pubDate>Wed, 20 Apr 2022 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Power outage at the data centre caused outages</dc:title>
    <dc:identifier>080fcfee-9fd0-4697-91ee-a3625db8554c</dc:identifier>
    </item>
<item>
  <title>Free mailboxes for Ukraine aid projects</title>
  <link>https://mailbox.org/en/news/free-accounts-ukraine-aid-projects/</link>
  <description>&lt;p&gt;We already announced our support on Twitter some time ago. Since the end of February, we have been supporting humanitarian projects (e.g. for the coordination of aid and accommodation) with our mail infrastructure. We offer the use of our service with e-mail, drive, office and video conferencing free of charge for Ukraine aid projects.&lt;/p&gt;&lt;h2&gt;Get an aid project account in 2 steps&lt;/h2&gt;&lt;p&gt;1. Create an account: Create a normal account with your desired address. If you need several accounts, you can use a team with a total of up to 10 accounts.&lt;br&gt;&lt;a href="https://register.mailbox.org/en/tariff?tariff=premium" target="_blank" title="Create account here" rel="noopener"&gt;Create account here -&amp;gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;2. Activate account: Write a request to our support team with a short description of your aid project. We will check your request for plausibility and activate your account quickly.&amp;nbsp;&lt;br&gt;&lt;a href="https://help.mailbox.org" target="_blank" title="Contact support" rel="noopener"&gt;Contact support -&amp;gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;The support is initially intended for 12 months. Of course, we will monitor developments and extend this period if necessary. Our heartfelt thanks go to all those who are helping and we hope to be able to support their commitment in this way.&lt;/p&gt;&lt;p&gt;The mailbox.org team&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-help.jpeg?itok=vR1hsZrC" type="image/jpeg" length="270739"/><guid isPermaLink="false">7aafeb41-0bed-49cb-b593-3d41941011f4</guid>
    <pubDate>Tue, 22 Mar 2022 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Free mailboxes for Ukraine aid projects</dc:title>
    <dc:identifier>7aafeb41-0bed-49cb-b593-3d41941011f4</dc:identifier>
    </item>
<item>
  <title>Free mailboxes for Ukraine aid projects</title>
  <link>https://mailbox.org/en/news/free-accounts-ukraine-aid-projects/</link>
  <description>&lt;p&gt;We already announced our support on Twitter some time ago. Since the end of February, we have been supporting humanitarian projects (e.g. for the coordination of aid and accommodation) with our mail infrastructure. We offer the use of our service with e-mail, drive, office and video conferencing free of charge for Ukraine aid projects.&lt;/p&gt;&lt;h2&gt;Get an aid project account in 2 steps&lt;/h2&gt;&lt;p&gt;1. Create an account: Create a normal account with your desired address. If you need several accounts, you can use a team with a total of up to 10 accounts.&lt;br&gt;&lt;a href="https://register.mailbox.org/en/tariff?tariff=premium" target="_blank" title="Create account here" rel="noopener"&gt;Create account here -&amp;gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;2. Activate account: Write a request to our support team with a short description of your aid project. We will check your request for plausibility and activate your account quickly.&amp;nbsp;&lt;br&gt;&lt;a href="https://help.mailbox.org" target="_blank" title="Contact support" rel="noopener"&gt;Contact support -&amp;gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;The support is initially intended for 12 months. Of course, we will monitor developments and extend this period if necessary. Our heartfelt thanks go to all those who are helping and we hope to be able to support their commitment in this way.&lt;/p&gt;&lt;p&gt;The mailbox.org team&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-help.jpeg?itok=vR1hsZrC" type="image/jpeg" length="270739"/><guid isPermaLink="false">7aafeb41-0bed-49cb-b593-3d41941011f4</guid>
    <pubDate>Tue, 22 Mar 2022 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Free mailboxes for Ukraine aid projects</dc:title>
    <dc:identifier>7aafeb41-0bed-49cb-b593-3d41941011f4</dc:identifier>
    </item>
<item>
  <title>The new OX Drive app for iOS is here</title>
  <link>https://mailbox.org/en/news/welcome-new-ox-drive-app-ios/</link>
  <description>&lt;h2&gt;The new OX Drive app for iOS&lt;/h2&gt;&lt;p&gt;The beta test of the new OX Drive app for iOS has been a success and we were pleased about the numerous testers among our customers. The feedback for the new app was consistently very good. From now on, the mailbox.org Drive can be used directly via Apple's pre-installed Files app.&lt;/p&gt;&lt;p&gt;Features at a glance&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Use Apple's pre-installed Files app to browse and organise your Drive content&lt;/li&gt;&lt;li&gt;Move files between your mailbox.org Drive directory and other storage locations or other apps with simple drag and drop&lt;/li&gt;&lt;li&gt;Compress files to save storage space&lt;/li&gt;&lt;li&gt;Scan documents and upload them directly to mailbox.org Drive&lt;/li&gt;&lt;li&gt;Edit your documents and save updated versions directly to Drive&lt;/li&gt;&lt;li&gt;Create share links with expiry date and password protection&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;br&gt;Click here for the &lt;a href="https://apps.apple.com/app/ox-drive-by-open-xchange/id1585939206" target="_blank" title="go to the Apple App Store" rel="noopener"&gt;new OX Drive app for iOS -&amp;gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;br&gt;&amp;nbsp;&lt;/p&gt;&lt;h2&gt;Additional update: Larger files in Drive&lt;/h2&gt;&lt;p&gt;Some customers use their mailbox.org Drive for backups or large data archives. Therefore, we have raised the limit for the maximum size of files from 10 GB to 40 GB.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-drive-1.png?itok=Cdaxpixf" type="image/png" length="245668"/><guid isPermaLink="false">6b7ea260-97b2-447a-a933-f52579fe619f</guid>
    <pubDate>Thu, 10 Mar 2022 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>The new OX Drive app for iOS is here</dc:title>
    <dc:identifier>6b7ea260-97b2-447a-a933-f52579fe619f</dc:identifier>
    </item>
<item>
  <title>The new OX Drive app for iOS is here</title>
  <link>https://mailbox.org/en/news/welcome-new-ox-drive-app-ios/</link>
  <description>&lt;h2&gt;The new OX Drive app for iOS&lt;/h2&gt;&lt;p&gt;The beta test of the new OX Drive app for iOS has been a success and we were pleased about the numerous testers among our customers. The feedback for the new app was consistently very good. From now on, the mailbox.org Drive can be used directly via Apple's pre-installed Files app.&lt;/p&gt;&lt;p&gt;Features at a glance&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Use Apple's pre-installed Files app to browse and organise your Drive content&lt;/li&gt;&lt;li&gt;Move files between your mailbox.org Drive directory and other storage locations or other apps with simple drag and drop&lt;/li&gt;&lt;li&gt;Compress files to save storage space&lt;/li&gt;&lt;li&gt;Scan documents and upload them directly to mailbox.org Drive&lt;/li&gt;&lt;li&gt;Edit your documents and save updated versions directly to Drive&lt;/li&gt;&lt;li&gt;Create share links with expiry date and password protection&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;br&gt;Click here for the &lt;a href="https://apps.apple.com/app/ox-drive-by-open-xchange/id1585939206" target="_blank" title="go to the Apple App Store" rel="noopener"&gt;new OX Drive app for iOS -&amp;gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;br&gt;&amp;nbsp;&lt;/p&gt;&lt;h2&gt;Additional update: Larger files in Drive&lt;/h2&gt;&lt;p&gt;Some customers use their mailbox.org Drive for backups or large data archives. Therefore, we have raised the limit for the maximum size of files from 10 GB to 40 GB.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-drive-1.png?itok=Cdaxpixf" type="image/png" length="245668"/><guid isPermaLink="false">6b7ea260-97b2-447a-a933-f52579fe619f</guid>
    <pubDate>Thu, 10 Mar 2022 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>The new OX Drive app for iOS is here</dc:title>
    <dc:identifier>6b7ea260-97b2-447a-a933-f52579fe619f</dc:identifier>
    </item>
<item>
  <title>Log4j: mailbox.org is not affected</title>
  <link>https://mailbox.org/en/news/log4j-mailboxorg-secure/</link>
  <description>&lt;p&gt;A small open-source tool called "&lt;a href="https://logging.apache.org/log4j/2.x/" target="_blank" rel="noopener"&gt;log4j&lt;/a&gt;" has caused a bit of an uproar last weekend and was even mentioned on the main national TV news program "&lt;a href="https://www.tagesschau.de/inland/bsi-schadsoftware-101.html" target="_blank" rel="noopener"&gt;Tagesschau&lt;/a&gt;" (in German). The tool is used by some Java applications for the purpose of monitoring network connections and older versions of it were found to contain a serious vulnerability. There has been growing concern across many sectors within and beyond IT as last Saturday, the German Federal Office for Information Security (&lt;a href="https://www.bsi.bund.de/DE/Themen/Verbraucherinnen-und-Verbraucher/Cyber-Sicherheitslage/Schwachstelle-log4Shell-Java-Bibliothek/log4j_node.html" target="_blank" rel="noopener"&gt;BSI&lt;/a&gt;) raised their security alert level to the maximum because of the issue. It appears that thousands of businesses are affected, and that user data and even administrator accounts are at risk.&lt;/p&gt;&lt;p&gt;mailbox.org is also currently receiving many enquiries from concerned users - but mailbox.org is not affected.&lt;/p&gt;&lt;h2&gt;Our IT security service providers warned early in the morning&lt;/h2&gt;&lt;p&gt;Even before log4j began to run its circles over the news tickers on Friday lunchtime, we were proactively alerted to the problem as early as 9:23 in the morning by our own contracted IT security service providers, Zero BS.&lt;/p&gt;&lt;p&gt;Our team then immediately began checking all potentially affected systems. All important systems "in the first row" (OX, Atlassian, Jitsi) were not vulnerable to log4j, because either log4j was not used or was configured by us from the beginning in a way that the vulnerability could not be exploited. We found a potential vulnerability on a rather unimportant system (ELK stack) in the second row, but this was very quickly mitigated by us on Friday at 1 pm through a configuration adjustment. Our team continued to monitor and analyse the situation over the weekend and found no further threats.&lt;/p&gt;&lt;p&gt;According to our assessment, customer data and the security of our systems were not seriously affected at any time.&lt;/p&gt;&lt;h2&gt;Background&lt;/h2&gt;&lt;p&gt;Last weekend, the Randoori Attack Team published a vulnerability in the Java tool log4j, now known as &lt;a href="https://www.randori.com/blog/cve-2021-44228/" target="_blank" rel="noopener"&gt;CVE-2021-44228&lt;/a&gt;. When log4j is used in a version between 2.0 and 2.14.1, attackers can obtain elevated access permissions by transmitting to an affected server a malicious URL that contains hidden commands. These commands will then be executed on the server side using administrative permissions. The vulnerability was fixed on Thursday, 9 December 2021 and is no longer present in log4j version 2.15. However, this is still a concern because not all affected servers will have been updated yet to use this latest version of the tool.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-04/mailbox-news-und-updates-warnung.jpg?itok=reW9cU74" type="image/jpeg" length="238141"/><guid isPermaLink="false">724e37fd-f62d-46ee-bc74-f926fd35c77e</guid>
    <pubDate>Tue, 14 Dec 2021 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Log4j: mailbox.org is not affected</dc:title>
    <dc:identifier>724e37fd-f62d-46ee-bc74-f926fd35c77e</dc:identifier>
    </item>
<item>
  <title>Log4j: mailbox.org is not affected</title>
  <link>https://mailbox.org/en/news/log4j-mailboxorg-secure/</link>
  <description>&lt;p&gt;A small open-source tool called "&lt;a href="https://logging.apache.org/log4j/2.x/" target="_blank" rel="noopener"&gt;log4j&lt;/a&gt;" has caused a bit of an uproar last weekend and was even mentioned on the main national TV news program "&lt;a href="https://www.tagesschau.de/inland/bsi-schadsoftware-101.html" target="_blank" rel="noopener"&gt;Tagesschau&lt;/a&gt;" (in German). The tool is used by some Java applications for the purpose of monitoring network connections and older versions of it were found to contain a serious vulnerability. There has been growing concern across many sectors within and beyond IT as last Saturday, the German Federal Office for Information Security (&lt;a href="https://www.bsi.bund.de/DE/Themen/Verbraucherinnen-und-Verbraucher/Cyber-Sicherheitslage/Schwachstelle-log4Shell-Java-Bibliothek/log4j_node.html" target="_blank" rel="noopener"&gt;BSI&lt;/a&gt;) raised their security alert level to the maximum because of the issue. It appears that thousands of businesses are affected, and that user data and even administrator accounts are at risk.&lt;/p&gt;&lt;p&gt;mailbox.org is also currently receiving many enquiries from concerned users - but mailbox.org is not affected.&lt;/p&gt;&lt;h2&gt;Our IT security service providers warned early in the morning&lt;/h2&gt;&lt;p&gt;Even before log4j began to run its circles over the news tickers on Friday lunchtime, we were proactively alerted to the problem as early as 9:23 in the morning by our own contracted IT security service providers, Zero BS.&lt;/p&gt;&lt;p&gt;Our team then immediately began checking all potentially affected systems. All important systems "in the first row" (OX, Atlassian, Jitsi) were not vulnerable to log4j, because either log4j was not used or was configured by us from the beginning in a way that the vulnerability could not be exploited. We found a potential vulnerability on a rather unimportant system (ELK stack) in the second row, but this was very quickly mitigated by us on Friday at 1 pm through a configuration adjustment. Our team continued to monitor and analyse the situation over the weekend and found no further threats.&lt;/p&gt;&lt;p&gt;According to our assessment, customer data and the security of our systems were not seriously affected at any time.&lt;/p&gt;&lt;h2&gt;Background&lt;/h2&gt;&lt;p&gt;Last weekend, the Randoori Attack Team published a vulnerability in the Java tool log4j, now known as &lt;a href="https://www.randori.com/blog/cve-2021-44228/" target="_blank" rel="noopener"&gt;CVE-2021-44228&lt;/a&gt;. When log4j is used in a version between 2.0 and 2.14.1, attackers can obtain elevated access permissions by transmitting to an affected server a malicious URL that contains hidden commands. These commands will then be executed on the server side using administrative permissions. The vulnerability was fixed on Thursday, 9 December 2021 and is no longer present in log4j version 2.15. However, this is still a concern because not all affected servers will have been updated yet to use this latest version of the tool.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-04/mailbox-news-und-updates-warnung.jpg?itok=reW9cU74" type="image/jpeg" length="238141"/><guid isPermaLink="false">724e37fd-f62d-46ee-bc74-f926fd35c77e</guid>
    <pubDate>Tue, 14 Dec 2021 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Log4j: mailbox.org is not affected</dc:title>
    <dc:identifier>724e37fd-f62d-46ee-bc74-f926fd35c77e</dc:identifier>
    </item>
<item>
  <title>Data retention: ECJ experts have had enough of politics</title>
  <link>https://mailbox.org/en/news/indiscriminate-data-retention-advocate-general-ecj-loses-patience-politicians/</link>
  <description>&lt;p&gt;It was an unusually strong rebuke coming from a prominent figure at the European Court of Justice, targeted at politicians of some EU member states who, despite unambiguous legal clarity and existing rulings, continue to call for indiscriminate data retention measures to be introduced. Advocate General Campos Sánchez-Bordona, a legal adviser for the European Court of Justice, caused a bit of a furore last week after releasing a statement about an upcoming ECJ ruling on the matter (&lt;a href="https://curia.europa.eu/jcms/upload/docs/application/pdf/2021-11/cp210206en.pdf" target="_blank" rel="noopener"&gt;Press release&lt;/a&gt;). In it, he makes blistering remarks about recent calls for indiscriminate data retention for the sake of fighting crime, coming out of France, Germany, and Ireland, and points out that such measures would be illegal for the purpose.&lt;/p&gt;&lt;h2&gt;FAZ: All questions were answered long ago&lt;/h2&gt;&lt;p&gt;Although his work titled “Advocate General's Opinion in Joined Cases” is not a law but a contribution to the legal debate and by no means binding, it is not unusual for the ECJ to follow the recommendations of their legal counsel. A decision on the issue of data retention is expected to come in early 2022. According to Sánchez-Bordona’s opinion, the case is absolutely clear, and the matter was thoroughly examined and explained over and over again. All open questions were addressed a long time ago, with the result that normally, data retention measures may only be used selectively and if there is probable cause. This has not changed, no matter the frequent attempts to undermine the fact.&lt;/p&gt;&lt;p&gt;Considering that Sánchez-Bordonas is a lawyer, his choice of language may appear somewhat unusual, in that he leaves no doubt about what he thinks. Perhaps this is one of the reasons why media outlets such as the German FAZ see the publication as the harbinger of a resounding defeat for the politicians. Indeed, the legal expert repeatedly states his surprise at the fact that some member states still demand a measure that previous rulings by the ECJ, made over the course of the past ten years, have deemed inappropriate and illegal. One might have expected the debate about this to be long over, especially as the European Court had actively sought the dialogue with national courts and explained its position in detail. In a nutshell: Probable cause is always required, and the state may not use surveillance measures without good reason. The only exception is a “threat to national security”, as was recognised in the case of Ireland:&lt;/p&gt;&lt;p&gt;“37. According to the Court, the general and indiscriminate retention of traffic data could be justified only on grounds of safeguarding national security, the importance of which goes beyond that of the other objectives referred to in Article 15(1) of Directive 2002/58’. (25)” (&lt;a href="https://curia.europa.eu/juris/document/document.jsf?text=&amp;amp;docid=249521&amp;amp;pageIndex=0&amp;amp;doclang=EN&amp;amp;mode=lst&amp;amp;dir=&amp;amp;occ=first&amp;amp;part=1&amp;amp;cid=799263" target="_blank" rel="noopener"&gt;Original document&lt;/a&gt;)&lt;/p&gt;&lt;p&gt;The ECJ has made it clear that introducing measures to impose indiscriminate mass surveillance on European citizens for the purpose of fighting serious crime is not reconcilable with our fundamental European rights and values.&lt;/p&gt;&lt;h2&gt;Endless discussions?&lt;/h2&gt;&lt;p&gt;Experts and politicians have been arguing about data retention for almost fifteen years. Those in favour cite the need to fight organised crime, child pornography, illegal file sharing, and more recently also hate speech and other crimes. Those against argue that politicians cannot ignore judicial decisions and point out the importance of our fundamental rights and values.&lt;/p&gt;&lt;p&gt;However, unlike politics, both the national and the European judiciary have always been consistent: The German parliament first introduced data retention measures in 2007 to implement a corresponding EU directive that required the capture and storage of communication meta data, meaning information about who communicated when, where and with whom. As it happened, the German Constitutional Court overturned this law in 2010 and furthermore, the ECJ overturned the original EU directive in 2014. Sánchez-Bordona points to the unambiguous rulings dating from 2014, 2016, 2018, and 2020 to seriously wonder why there even is a debate about this today, considering the facts have not changed and the related judgments are considered final.&lt;/p&gt;&lt;p&gt;Meanwhile, the bodies representing industry and business, including the German Association of the Internet Economy (ECO), stand united in their opposition to indiscriminate data retention. The current case went to the ECJ through what was originally a federal court complaint lodged by two German Internet providers. mailbox.org is party to a wider constitutional complaint, with a decision by the Federal Constitutional Court pending since 2015, and currently still awaiting a ruling by the ECJ. The fight goes on, as the topic forms part of the coalition negotiations of the future German government, where it turns out the Liberals and the Greens are against it, while the Social Democrats are in favour – even though some of their digital experts, like the D-64 Foundation, strongly dissent. For the time being at least, indiscriminate data retention remains a zombie issue that refuses to die.&lt;/p&gt;&lt;h2&gt;Update&lt;/h2&gt;&lt;p&gt;The coalition agreement adopts the proposals of the SPD-affiliated organisation D-64 and buries the VDS. It is to be replaced by concepts such as the login trap:&lt;/p&gt;&lt;p&gt;"In view of the current legal uncertainty, the upcoming ruling of the European Court of Justice and the resulting security policy challenges, we will develop the regulations on data retention in such a way that data can be stored in a legally secure manner on an ad hoc basis and by judicial order. With the login trap, we want to create instruments that protect fundamental rights and are freedom-oriented in order to achieve the identification of perpetrators."&lt;/p&gt;&lt;p&gt;With the login trap, operators of social networks are to be forced to cooperate with investigators via open standards, but they are only allowed to receive login data on an occasion-related basis, for example if there is a report of hate speech or child pornography.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-jurisdiction.png?itok=OZMKk08b" type="image/png" length="218284"/><guid isPermaLink="false">df17bacc-ec4e-4ee0-9c7b-84f398a80af7</guid>
    <pubDate>Thu, 25 Nov 2021 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Data retention: ECJ experts have had enough of politics</dc:title>
    <dc:identifier>df17bacc-ec4e-4ee0-9c7b-84f398a80af7</dc:identifier>
    </item>
<item>
  <title>Data retention: ECJ experts have had enough of politics</title>
  <link>https://mailbox.org/en/news/indiscriminate-data-retention-advocate-general-ecj-loses-patience-politicians/</link>
  <description>&lt;p&gt;It was an unusually strong rebuke coming from a prominent figure at the European Court of Justice, targeted at politicians of some EU member states who, despite unambiguous legal clarity and existing rulings, continue to call for indiscriminate data retention measures to be introduced. Advocate General Campos Sánchez-Bordona, a legal adviser for the European Court of Justice, caused a bit of a furore last week after releasing a statement about an upcoming ECJ ruling on the matter (&lt;a href="https://curia.europa.eu/jcms/upload/docs/application/pdf/2021-11/cp210206en.pdf" target="_blank" rel="noopener"&gt;Press release&lt;/a&gt;). In it, he makes blistering remarks about recent calls for indiscriminate data retention for the sake of fighting crime, coming out of France, Germany, and Ireland, and points out that such measures would be illegal for the purpose.&lt;/p&gt;&lt;h2&gt;FAZ: All questions were answered long ago&lt;/h2&gt;&lt;p&gt;Although his work titled “Advocate General's Opinion in Joined Cases” is not a law but a contribution to the legal debate and by no means binding, it is not unusual for the ECJ to follow the recommendations of their legal counsel. A decision on the issue of data retention is expected to come in early 2022. According to Sánchez-Bordona’s opinion, the case is absolutely clear, and the matter was thoroughly examined and explained over and over again. All open questions were addressed a long time ago, with the result that normally, data retention measures may only be used selectively and if there is probable cause. This has not changed, no matter the frequent attempts to undermine the fact.&lt;/p&gt;&lt;p&gt;Considering that Sánchez-Bordonas is a lawyer, his choice of language may appear somewhat unusual, in that he leaves no doubt about what he thinks. Perhaps this is one of the reasons why media outlets such as the German FAZ see the publication as the harbinger of a resounding defeat for the politicians. Indeed, the legal expert repeatedly states his surprise at the fact that some member states still demand a measure that previous rulings by the ECJ, made over the course of the past ten years, have deemed inappropriate and illegal. One might have expected the debate about this to be long over, especially as the European Court had actively sought the dialogue with national courts and explained its position in detail. In a nutshell: Probable cause is always required, and the state may not use surveillance measures without good reason. The only exception is a “threat to national security”, as was recognised in the case of Ireland:&lt;/p&gt;&lt;p&gt;“37. According to the Court, the general and indiscriminate retention of traffic data could be justified only on grounds of safeguarding national security, the importance of which goes beyond that of the other objectives referred to in Article 15(1) of Directive 2002/58’. (25)” (&lt;a href="https://curia.europa.eu/juris/document/document.jsf?text=&amp;amp;docid=249521&amp;amp;pageIndex=0&amp;amp;doclang=EN&amp;amp;mode=lst&amp;amp;dir=&amp;amp;occ=first&amp;amp;part=1&amp;amp;cid=799263" target="_blank" rel="noopener"&gt;Original document&lt;/a&gt;)&lt;/p&gt;&lt;p&gt;The ECJ has made it clear that introducing measures to impose indiscriminate mass surveillance on European citizens for the purpose of fighting serious crime is not reconcilable with our fundamental European rights and values.&lt;/p&gt;&lt;h2&gt;Endless discussions?&lt;/h2&gt;&lt;p&gt;Experts and politicians have been arguing about data retention for almost fifteen years. Those in favour cite the need to fight organised crime, child pornography, illegal file sharing, and more recently also hate speech and other crimes. Those against argue that politicians cannot ignore judicial decisions and point out the importance of our fundamental rights and values.&lt;/p&gt;&lt;p&gt;However, unlike politics, both the national and the European judiciary have always been consistent: The German parliament first introduced data retention measures in 2007 to implement a corresponding EU directive that required the capture and storage of communication meta data, meaning information about who communicated when, where and with whom. As it happened, the German Constitutional Court overturned this law in 2010 and furthermore, the ECJ overturned the original EU directive in 2014. Sánchez-Bordona points to the unambiguous rulings dating from 2014, 2016, 2018, and 2020 to seriously wonder why there even is a debate about this today, considering the facts have not changed and the related judgments are considered final.&lt;/p&gt;&lt;p&gt;Meanwhile, the bodies representing industry and business, including the German Association of the Internet Economy (ECO), stand united in their opposition to indiscriminate data retention. The current case went to the ECJ through what was originally a federal court complaint lodged by two German Internet providers. mailbox.org is party to a wider constitutional complaint, with a decision by the Federal Constitutional Court pending since 2015, and currently still awaiting a ruling by the ECJ. The fight goes on, as the topic forms part of the coalition negotiations of the future German government, where it turns out the Liberals and the Greens are against it, while the Social Democrats are in favour – even though some of their digital experts, like the D-64 Foundation, strongly dissent. For the time being at least, indiscriminate data retention remains a zombie issue that refuses to die.&lt;/p&gt;&lt;h2&gt;Update&lt;/h2&gt;&lt;p&gt;The coalition agreement adopts the proposals of the SPD-affiliated organisation D-64 and buries the VDS. It is to be replaced by concepts such as the login trap:&lt;/p&gt;&lt;p&gt;"In view of the current legal uncertainty, the upcoming ruling of the European Court of Justice and the resulting security policy challenges, we will develop the regulations on data retention in such a way that data can be stored in a legally secure manner on an ad hoc basis and by judicial order. With the login trap, we want to create instruments that protect fundamental rights and are freedom-oriented in order to achieve the identification of perpetrators."&lt;/p&gt;&lt;p&gt;With the login trap, operators of social networks are to be forced to cooperate with investigators via open standards, but they are only allowed to receive login data on an occasion-related basis, for example if there is a report of hate speech or child pornography.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-jurisdiction.png?itok=OZMKk08b" type="image/png" length="218284"/><guid isPermaLink="false">df17bacc-ec4e-4ee0-9c7b-84f398a80af7</guid>
    <pubDate>Thu, 25 Nov 2021 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Data retention: ECJ experts have had enough of politics</dc:title>
    <dc:identifier>df17bacc-ec4e-4ee0-9c7b-84f398a80af7</dc:identifier>
    </item>
<item>
  <title>Chatcontrol: EU wants to ban encryption</title>
  <link>https://mailbox.org/en/news/chat-control-latest-eu-plans-outlaw-encryption-and-introduce-telecommunications-surveillance/</link>
  <description>&lt;p&gt;EU Commission plans to proactively involve telecommunications providers in the surveillance of their customers’ e-mail and chat messages has been a contentious issue for some time. mailbox.org has &lt;a href="https://mailbox.org/en/post/open-letter-to-apple-against-the-surveillance-of-users" target="_blank" title="mailbox.org: “Open letter to Apple against the surveillance of users”" rel="noopener"&gt;reported&lt;/a&gt; on this repeatedly, criticised the proposals, and contributed to &lt;a href="https://mailbox.org/en/post/it-companies-warn-eu-plans-to-ban-encryption" target="_blank" title="mailbox.org: “IT companies warn in open letter: EU wants to ban encryption”" rel="noopener"&gt;open letters&lt;/a&gt;. Instead of taking the public response into account, the EU has opted to double down and tighten their surveillance requirements even further than was originally planned – to an extent that data protection professionals have denounced the plans as a blatant attempt to abolish the legal protection of private correspondence in the digital realm. The proposed changes include a ban of properly encrypted communication, disguised as a measure to combat child pornography. We believe this would open the door to the widespread surveillance of all telecommunication activity, threaten the privacy of all people and shake the foundations of our values and fundamental rights as European and German citizens.&lt;/p&gt;&lt;p&gt;mailbox.org CEO Peer Heinlein says:&lt;/p&gt;&lt;p&gt;“It is alarming how the fight against child pornography, which in itself is necessary and right, is being used here as an excuse to pursue much broader and general goals. In reality, this legislative initiative will undermine the protection and security of all private communication, which is protected by the German constitution, and introduce mass surveillance with the use of artificial intelligence. This is yet another attempt to railroad the abolition of secure, encrypted communication through parliament in the middle of a heated debate. The entire approach is wrong and trying to ram it down people’s throats repeatedly does not make it right. It is no surprise that IT professionals and victim organisations stand united to criticise the current draft law as dangerous and counterproductive.”&lt;/p&gt;&lt;h2&gt;Summer 2021: The EU tightens the reins&lt;/h2&gt;&lt;p&gt;The EU Commission signed a transitional law (“&lt;a href="https://ec.europa.eu/info/law/better-regulation/have-your-say/initiatives/12726-Fighting-child-sexual-abuse-detection-removal-and-reporting-of-illegal-content-online_en" target="_blank" title="European Commission: Fighting child sexual abuse: detection, removal and reporting of illegal content online" rel="noopener"&gt;Procedure 2020/0259/COD&lt;/a&gt;”) in July 2021. This law allows platform and service providers to access and search customer data (&lt;a href="https://www.heise.de/news/EU-Parlament-erlaubt-flaechendeckende-Scans-nach-Kinderpornografie-6130267.html" target="_blank" title="heise online: EU-Parlament erlaubt flächendeckende Scans nach Kinderpornografie (in German)" rel="noopener"&gt;Heise reported&lt;/a&gt;). Normally, such course of action would be either prohibited, or in the least severely restricted by current GDPR legislation, so an exemption was required to go ahead. Providers like Google and Microsoft do already process messages to search for indicators for child and youth pornography without probable cause. If their search algorithms report a hit, the affected users can get automatically reported to the police, despite the system being highly unreliable. There is also no requirement for them to inform the users about what has happened.&lt;/p&gt;&lt;p&gt;Extending the current “exemption” to permit more surveillance has been on the cards for some time. For example, Apple received a lot of media attention after announcing that they would integrate special software agents into their iPhones that would search for criminal content and automatically report or even delete data using AI, even before any of it gets uploaded to the cloud. This was entirely in line with the EC guidelines but after widespread protest, &lt;a href="https://cdt.org/wp-content/uploads/2021/08/CDT-Coalition-ltr-to-Apple-19-August-2021.pdf" target="_blank" title="Center for Democracy &amp;amp; Technology: Open letter to Apple (PDF)" rel="noopener"&gt;also from mailbox.org&lt;/a&gt;, the company decided to withdraw these plans for the time being.&lt;/p&gt;&lt;h2&gt;Mandatory surveillance and a ban of secure encryption&lt;/h2&gt;&lt;p&gt;In the autumn of 2021, it &lt;a href="https://www.statewatch.org/news/2021/november/policing-the-internet-interior-ministers-to-seek-solutions-regarding-data-retention-encryption-e-evidence-and-the-darknet/" target="_blank" title="statewatch: Policing the internet: interior ministers to seek " rel="noopener"&gt;transpired&lt;/a&gt; that the EU Commission intends to make the previous “voluntary participation” in their surveillance measures mandatory. They also plan to widen the scope to include other serious offenses such as terrorism and violent crime. Until now, only those providers who already process customer data for purposes such as offering personalised ads were required to monitor communications for potential legal offences. The documents published by the EU parliament reveal plans that would force all providers to engage in the same activities. Those who currently cannot monitor the data are supposed to install suitable technology to make sure they can do so in the future and change their existing practices. Secure methods like end-to-end encryption that make sure only the sender and the receiver can read a message would be undermined. Telecommunications providers would be asked to actively prevent encryption, or search messages for targeted content before encryption takes place and would be required to give law enforcement authorities access to their data. Once such a process to systematically remove protections is in place, the data would eventually become exposed to unauthorised access by competitors, criminals, or dictators. A detailed summary of the possible technologies and danger scenarios has been compiled by &lt;a href="https://netzpolitik.org/2021/eu-kommission-warum-die-chatkontrolle-so-gefaehrlich-ist/" target="_blank" title="Netzpolitik.org: Warum die Chatkontrolle so gefährlich ist (in German)" rel="noopener"&gt;Netzpolitik&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;Originally, a decision was to be made in December 2021 but as of today (November), the item has miraculously disappeared from the commission’s schedule. However, European parliamentarians such as Patrick Breyer (Pirate Party) &lt;a href="https://www.patrick-breyer.de/en/posts/messaging-and-chat-control/" target="_blank" title="Patrick Breyer: Chat Control – The End of the Privacy of Digital Correspondence" rel="noopener"&gt;reported&lt;/a&gt; that this does in no way mean the topic is off the agenda. The planned parliamentary vote has been merely postponed until the first quarter of 2022.&lt;/p&gt;&lt;h2&gt;mailbox.org sharply criticises the EU’s plans&lt;/h2&gt;&lt;p&gt;We are convinced that the current EU plans should be rejected outright. If implemented, the proposed measures would weaken everyone’s security, undermine trust in communication tools, and turn everyone into a suspect without probable cause. The measures would also weaken trust in state and law enforcement authorities and endanger social cohesion. They would expose to great dangers those people who have special protection needs such as lawyers, doctors, journalists, or whistleblowers. The measures would also be counterproductive because they make it easier for hackers to obtain personal information from data. Once message and chat control technologies are established, there is a danger that they will be misused for shady purposes. This door must remain firmly shut.&lt;/p&gt;&lt;p&gt;We at mailbox.org openly protest against these efforts and call on all citizens to do the same. We recommend people visit the website of the MEP Patrick Breyer, who has made available a lot of information about the topic, including explainer videos, background details, and links to legal documents, as well as a &lt;a href="https://www.patrick-breyer.de/en/posts/messaging-and-chat-control/" target="_blank" title="Patrick Breyer: Chat Control – The End of the Privacy of Digital Correspondence" rel="noopener"&gt;list of the EU commissioners&lt;/a&gt; who are involved in this initiative. All citizens should call them or write to them directly to make their views heard.&lt;/p&gt;&lt;p&gt;We at mailbox.org support this call to action.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-surveillance-2.png?itok=78OXDh68" type="image/png" length="265392"/><guid isPermaLink="false">bfd26b67-1d4d-4382-9562-9fea5a86b0e5</guid>
    <pubDate>Wed, 17 Nov 2021 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Chatcontrol: EU wants to ban encryption</dc:title>
    <dc:identifier>bfd26b67-1d4d-4382-9562-9fea5a86b0e5</dc:identifier>
    </item>
<item>
  <title>Chatcontrol: EU wants to ban encryption</title>
  <link>https://mailbox.org/en/news/chat-control-latest-eu-plans-outlaw-encryption-and-introduce-telecommunications-surveillance/</link>
  <description>&lt;p&gt;EU Commission plans to proactively involve telecommunications providers in the surveillance of their customers’ e-mail and chat messages has been a contentious issue for some time. mailbox.org has &lt;a href="https://mailbox.org/en/post/open-letter-to-apple-against-the-surveillance-of-users" target="_blank" title="mailbox.org: “Open letter to Apple against the surveillance of users”" rel="noopener"&gt;reported&lt;/a&gt; on this repeatedly, criticised the proposals, and contributed to &lt;a href="https://mailbox.org/en/post/it-companies-warn-eu-plans-to-ban-encryption" target="_blank" title="mailbox.org: “IT companies warn in open letter: EU wants to ban encryption”" rel="noopener"&gt;open letters&lt;/a&gt;. Instead of taking the public response into account, the EU has opted to double down and tighten their surveillance requirements even further than was originally planned – to an extent that data protection professionals have denounced the plans as a blatant attempt to abolish the legal protection of private correspondence in the digital realm. The proposed changes include a ban of properly encrypted communication, disguised as a measure to combat child pornography. We believe this would open the door to the widespread surveillance of all telecommunication activity, threaten the privacy of all people and shake the foundations of our values and fundamental rights as European and German citizens.&lt;/p&gt;&lt;p&gt;mailbox.org CEO Peer Heinlein says:&lt;/p&gt;&lt;p&gt;“It is alarming how the fight against child pornography, which in itself is necessary and right, is being used here as an excuse to pursue much broader and general goals. In reality, this legislative initiative will undermine the protection and security of all private communication, which is protected by the German constitution, and introduce mass surveillance with the use of artificial intelligence. This is yet another attempt to railroad the abolition of secure, encrypted communication through parliament in the middle of a heated debate. The entire approach is wrong and trying to ram it down people’s throats repeatedly does not make it right. It is no surprise that IT professionals and victim organisations stand united to criticise the current draft law as dangerous and counterproductive.”&lt;/p&gt;&lt;h2&gt;Summer 2021: The EU tightens the reins&lt;/h2&gt;&lt;p&gt;The EU Commission signed a transitional law (“&lt;a href="https://ec.europa.eu/info/law/better-regulation/have-your-say/initiatives/12726-Fighting-child-sexual-abuse-detection-removal-and-reporting-of-illegal-content-online_en" target="_blank" title="European Commission: Fighting child sexual abuse: detection, removal and reporting of illegal content online" rel="noopener"&gt;Procedure 2020/0259/COD&lt;/a&gt;”) in July 2021. This law allows platform and service providers to access and search customer data (&lt;a href="https://www.heise.de/news/EU-Parlament-erlaubt-flaechendeckende-Scans-nach-Kinderpornografie-6130267.html" target="_blank" title="heise online: EU-Parlament erlaubt flächendeckende Scans nach Kinderpornografie (in German)" rel="noopener"&gt;Heise reported&lt;/a&gt;). Normally, such course of action would be either prohibited, or in the least severely restricted by current GDPR legislation, so an exemption was required to go ahead. Providers like Google and Microsoft do already process messages to search for indicators for child and youth pornography without probable cause. If their search algorithms report a hit, the affected users can get automatically reported to the police, despite the system being highly unreliable. There is also no requirement for them to inform the users about what has happened.&lt;/p&gt;&lt;p&gt;Extending the current “exemption” to permit more surveillance has been on the cards for some time. For example, Apple received a lot of media attention after announcing that they would integrate special software agents into their iPhones that would search for criminal content and automatically report or even delete data using AI, even before any of it gets uploaded to the cloud. This was entirely in line with the EC guidelines but after widespread protest, &lt;a href="https://cdt.org/wp-content/uploads/2021/08/CDT-Coalition-ltr-to-Apple-19-August-2021.pdf" target="_blank" title="Center for Democracy &amp;amp; Technology: Open letter to Apple (PDF)" rel="noopener"&gt;also from mailbox.org&lt;/a&gt;, the company decided to withdraw these plans for the time being.&lt;/p&gt;&lt;h2&gt;Mandatory surveillance and a ban of secure encryption&lt;/h2&gt;&lt;p&gt;In the autumn of 2021, it &lt;a href="https://www.statewatch.org/news/2021/november/policing-the-internet-interior-ministers-to-seek-solutions-regarding-data-retention-encryption-e-evidence-and-the-darknet/" target="_blank" title="statewatch: Policing the internet: interior ministers to seek " rel="noopener"&gt;transpired&lt;/a&gt; that the EU Commission intends to make the previous “voluntary participation” in their surveillance measures mandatory. They also plan to widen the scope to include other serious offenses such as terrorism and violent crime. Until now, only those providers who already process customer data for purposes such as offering personalised ads were required to monitor communications for potential legal offences. The documents published by the EU parliament reveal plans that would force all providers to engage in the same activities. Those who currently cannot monitor the data are supposed to install suitable technology to make sure they can do so in the future and change their existing practices. Secure methods like end-to-end encryption that make sure only the sender and the receiver can read a message would be undermined. Telecommunications providers would be asked to actively prevent encryption, or search messages for targeted content before encryption takes place and would be required to give law enforcement authorities access to their data. Once such a process to systematically remove protections is in place, the data would eventually become exposed to unauthorised access by competitors, criminals, or dictators. A detailed summary of the possible technologies and danger scenarios has been compiled by &lt;a href="https://netzpolitik.org/2021/eu-kommission-warum-die-chatkontrolle-so-gefaehrlich-ist/" target="_blank" title="Netzpolitik.org: Warum die Chatkontrolle so gefährlich ist (in German)" rel="noopener"&gt;Netzpolitik&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;Originally, a decision was to be made in December 2021 but as of today (November), the item has miraculously disappeared from the commission’s schedule. However, European parliamentarians such as Patrick Breyer (Pirate Party) &lt;a href="https://www.patrick-breyer.de/en/posts/messaging-and-chat-control/" target="_blank" title="Patrick Breyer: Chat Control – The End of the Privacy of Digital Correspondence" rel="noopener"&gt;reported&lt;/a&gt; that this does in no way mean the topic is off the agenda. The planned parliamentary vote has been merely postponed until the first quarter of 2022.&lt;/p&gt;&lt;h2&gt;mailbox.org sharply criticises the EU’s plans&lt;/h2&gt;&lt;p&gt;We are convinced that the current EU plans should be rejected outright. If implemented, the proposed measures would weaken everyone’s security, undermine trust in communication tools, and turn everyone into a suspect without probable cause. The measures would also weaken trust in state and law enforcement authorities and endanger social cohesion. They would expose to great dangers those people who have special protection needs such as lawyers, doctors, journalists, or whistleblowers. The measures would also be counterproductive because they make it easier for hackers to obtain personal information from data. Once message and chat control technologies are established, there is a danger that they will be misused for shady purposes. This door must remain firmly shut.&lt;/p&gt;&lt;p&gt;We at mailbox.org openly protest against these efforts and call on all citizens to do the same. We recommend people visit the website of the MEP Patrick Breyer, who has made available a lot of information about the topic, including explainer videos, background details, and links to legal documents, as well as a &lt;a href="https://www.patrick-breyer.de/en/posts/messaging-and-chat-control/" target="_blank" title="Patrick Breyer: Chat Control – The End of the Privacy of Digital Correspondence" rel="noopener"&gt;list of the EU commissioners&lt;/a&gt; who are involved in this initiative. All citizens should call them or write to them directly to make their views heard.&lt;/p&gt;&lt;p&gt;We at mailbox.org support this call to action.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-surveillance-2.png?itok=78OXDh68" type="image/png" length="265392"/><guid isPermaLink="false">bfd26b67-1d4d-4382-9562-9fea5a86b0e5</guid>
    <pubDate>Wed, 17 Nov 2021 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Chatcontrol: EU wants to ban encryption</dc:title>
    <dc:identifier>bfd26b67-1d4d-4382-9562-9fea5a86b0e5</dc:identifier>
    </item>
<item>
  <title>Improvements for your email inbox, Drive and Office</title>
  <link>https://mailbox.org/en/news/improved-e-mail-inbox-drive-storage-and-online-office-mailboxorg/</link>
  <description>&lt;p&gt;The latest update of our web interface (OX AppSuite 7.10.5) makes it easier to set up devices, fixes bugs, and brings a range of smaller improvements to some frequently used features. For example, more reliable saving of e-mail drafts, uploading of entire folders to the Drive using drag &amp;amp; drop, and much more.&lt;/p&gt;&lt;h2&gt;E-mail &amp;amp; Drive updates&lt;/h2&gt;&lt;h3&gt;E-mail drafts&lt;/h3&gt;&lt;p&gt;Drafts are now saved more reliable in the “Drafts” folder and so, available across all synchronized devices, providing great flexibility for your workflow.&lt;/p&gt;&lt;h3&gt;Improved setup assistent&lt;/h3&gt;&lt;p&gt;It is now even easier to set up your devices for the use of mailbox.org e-mail, calendar, and addressbook. The new setup assistant guides through the installation process in three simple steps.&lt;/p&gt;&lt;h3&gt;Drive: Drag &amp;amp; drop uploads&lt;/h3&gt;&lt;p&gt;Upload entire folders from your computer to the Drive using drag &amp;amp; drop, or even several folders in one go. This is making the storage of large numbers of files really easy.&lt;/p&gt;&lt;h3&gt;Improved navigation&lt;/h3&gt;&lt;p&gt;The upper sections of the web interface navigation have been redesigned to simplify access to different modules, help pages, and settings.&lt;/p&gt;&lt;h2&gt;Office updates&lt;/h2&gt;&lt;h3&gt;Collaborate more easily with mentions&lt;/h3&gt;&lt;p&gt;Comments are a great communication tool for collaborators working on the same draft. It is possible to use the “@” symbol followed by a user’s name to mention a specific person and make sure they are made aware of any comments directed at them – available in documents, spreadsheets and presentations. The tagged person will receive an e-mail that contains a hyperlink to the document.&lt;/p&gt;&lt;h3&gt;Presentations: Improved performance and usability&lt;/h3&gt;&lt;p&gt;The update brings improved performance for presentations and increased playback control through the presentation toolbar. There is also a new menu option for embedding background images.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-04/mailbox-news-und-updates-produktupdate.jpg?itok=VmAEEH73" type="image/jpeg" length="400284"/><guid isPermaLink="false">87901eaf-913f-4e32-aeb8-1ecaa67b8b51</guid>
    <pubDate>Thu, 04 Nov 2021 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Improvements for your email inbox, Drive and Office</dc:title>
    <dc:identifier>87901eaf-913f-4e32-aeb8-1ecaa67b8b51</dc:identifier>
    </item>
<item>
  <title>Improvements for your email inbox, Drive and Office</title>
  <link>https://mailbox.org/en/news/improved-e-mail-inbox-drive-storage-and-online-office-mailboxorg/</link>
  <description>&lt;p&gt;The latest update of our web interface (OX AppSuite 7.10.5) makes it easier to set up devices, fixes bugs, and brings a range of smaller improvements to some frequently used features. For example, more reliable saving of e-mail drafts, uploading of entire folders to the Drive using drag &amp;amp; drop, and much more.&lt;/p&gt;&lt;h2&gt;E-mail &amp;amp; Drive updates&lt;/h2&gt;&lt;h3&gt;E-mail drafts&lt;/h3&gt;&lt;p&gt;Drafts are now saved more reliable in the “Drafts” folder and so, available across all synchronized devices, providing great flexibility for your workflow.&lt;/p&gt;&lt;h3&gt;Improved setup assistent&lt;/h3&gt;&lt;p&gt;It is now even easier to set up your devices for the use of mailbox.org e-mail, calendar, and addressbook. The new setup assistant guides through the installation process in three simple steps.&lt;/p&gt;&lt;h3&gt;Drive: Drag &amp;amp; drop uploads&lt;/h3&gt;&lt;p&gt;Upload entire folders from your computer to the Drive using drag &amp;amp; drop, or even several folders in one go. This is making the storage of large numbers of files really easy.&lt;/p&gt;&lt;h3&gt;Improved navigation&lt;/h3&gt;&lt;p&gt;The upper sections of the web interface navigation have been redesigned to simplify access to different modules, help pages, and settings.&lt;/p&gt;&lt;h2&gt;Office updates&lt;/h2&gt;&lt;h3&gt;Collaborate more easily with mentions&lt;/h3&gt;&lt;p&gt;Comments are a great communication tool for collaborators working on the same draft. It is possible to use the “@” symbol followed by a user’s name to mention a specific person and make sure they are made aware of any comments directed at them – available in documents, spreadsheets and presentations. The tagged person will receive an e-mail that contains a hyperlink to the document.&lt;/p&gt;&lt;h3&gt;Presentations: Improved performance and usability&lt;/h3&gt;&lt;p&gt;The update brings improved performance for presentations and increased playback control through the presentation toolbar. There is also a new menu option for embedding background images.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-04/mailbox-news-und-updates-produktupdate.jpg?itok=VmAEEH73" type="image/jpeg" length="400284"/><guid isPermaLink="false">87901eaf-913f-4e32-aeb8-1ecaa67b8b51</guid>
    <pubDate>Thu, 04 Nov 2021 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Improvements for your email inbox, Drive and Office</dc:title>
    <dc:identifier>87901eaf-913f-4e32-aeb8-1ecaa67b8b51</dc:identifier>
    </item>
<item>
  <title>Extortionate DDoS attacks on mailbox.org</title>
  <link>https://mailbox.org/en/news/distributed-denial-service-attacks-mailboxorg/</link>
  <description>&lt;p&gt;There has been a steep increase in Distributed-Denial-of-Service (DDoS) attacks against e-mail providers worldwide in the past few weeks, and more recently these attacks have become even more frequent. Attacks like this are essentially a form of blackmail, as they have the objective of bringing services to a standstill first to then offer relief in exchange for money. As it happened, mailbox.org was also targeted, on Thursday night and Friday afternoon. At the same time, we received a communication in which the attackers demanded we pay them money in Bitcoin. - Of course, we will do no such thing.&lt;/p&gt;&lt;p&gt;We are expecting more attacks in the coming days, though. This blog article has information for our users, including some more background about DDoS attacks and their possible impact. We hope any disruption can be avoided or kept to a minimum. Thank you in advance for your understanding should any services become temporarily unavailable during the next few days.&lt;/p&gt;&lt;p&gt;Please note:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Should any services become temporarily unavailable, for example if you are unable to retrieve your e-mails as usual, please try again later.&lt;/li&gt;&lt;li&gt;Within the next few days, try not to issue any unnecessary support requests concerning, or notify us of any temporary downtime of services. We are expecting more attacks and will do everything required to restore services as quickly as possible.&lt;/li&gt;&lt;li&gt;Any e-mails sent to you won't be lost, even if the service is temporarily unavailable. In the current circumstances, these may just be delivered a little later than usual.&lt;/li&gt;&lt;li&gt;If you are experiencing any difficulties with using our services, please let us know on &lt;a href="https://twitter.com/mailbox_org" target="_blank" title="Twitter" rel="noopener"&gt;Twitter&lt;/a&gt;, if possible. Twitter is also a good place to look first in case something isn't working.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Background:&lt;/p&gt;&lt;h2&gt;DDoS attacks aim to knock out their targets&lt;/h2&gt;&lt;p&gt;A Distributed-Denial-of-Service (DDoS) attack requires a large number of computers to get infected by viruses first. Then, the attackers control these machines to send large quantities of data to a shared target in a coordinated fashion, with the goal of disabling the target's ability to respond to other requests. What we experienced was quite extraordinary: About 147.000 different computers had been infiltrated to be involved in the attack, and our servers received data through the Internet at a rate of 150 million data packets per second. As an analogy, imagine 147.000 people dialling the same phone number, every second, in order to knock out the telephone network of a city, a business, or a local authority.&lt;/p&gt;&lt;p&gt;The data that is sent in DDoS attacks has usually normal or even meaningless contents, because the primary goal is to impact the function of systems, firewalls, servers and networks through the huge amounts of data that are being sent. For example, doing so can overload a server, such that it is kept busy processing the DDoS data, while regular user requests suffer severe delays or even time-outs. It is important to point out, though, that at no point do the attackers actually have access to the targeted network. That is why we are confident that all customer data has always been secure and protected during the attacks.&lt;/p&gt;&lt;p&gt;For any internet host, it is not really possible to avoid DDoS attacks when they come. However, it is possible to create a resilient infrastructure that provides protection and a level of performance which is more difficult for attackers to knock out. However, the idea that someone could achieve full protection is an illusion: The opponent that fields more capable hardware and software will win eventually. On the attacking side, these are the number of systems that are coordinated to produce and send the data, and on the defending side, it's the systems that receive and process the data as well as those that detect and counter such attacks.&lt;/p&gt;&lt;h2&gt;mailbox.org is well-prepared for DDoS attacks&lt;/h2&gt;&lt;p&gt;We at mailbox.org have previously monitored occasional smaller-scale DDoS attacks, which usually go unnoticed by customers. We have also worked to prepare against larger efforts that would target our systems directly and invested considerably in a robust infrastructure that provides appropriate defensive measures. For example, we operate our servers redundantly across two separate data centres and have four different communication lines for data exchange with other providers on the Internet. Also, our network infrastructure has been designed to have a considerable amount of resources to spare during normal operations, which provides our systems with the performance to scale rapidly, if required.&lt;/p&gt;&lt;p&gt;Furthermore, we are working together with MyraSecurity, a German company that specializes in protection against DDoS attacks. MyraSecurity maintain a powerful infrastructure for the detection and filtering of DDoS data traffic and their systems provide additional protection by blocking a large amount of the incoming malicious traffic that is caused by DDoS attacks. During regular, everyday operations, these systems just sit there and don't need to do much. However, once an attack has been detected, our mailbox.org systems will switch over their regular data lines to filter the incoming traffic through this “DDoS shield”. As a result, less traffic reaches our critical infrastructure, which minimizes the potential of disruption.&lt;/p&gt;&lt;p&gt;It is important to note that MyraSecurity has been set up such that they have no actual access to the encrypted data traffic. Any DDoS protection measures will only look at external characteristics of the data packets they filter, to decide which ones will be blocked and which ones will be let through.&lt;/p&gt;&lt;h2&gt;The first attack on Thursday&lt;/h2&gt;&lt;p&gt;The difference between theory and practice: You will only know if your preparations were sufficient once the worst is actually happening. Last Thursday, we had a few teething problems at first but were able to defend ourselves effectively against the first large DDoS attack. At the beginning, we saw some disruption to services. However, we were able to find and disable the root causes quickly and adapt our infrastructure to better withstand any future attacks.&lt;/p&gt;&lt;p&gt;After about 30 to 60 minutes had passed, hardly any impact was noticeable anymore by our users despite the attack continuing at full strength. Some of our websites may have responded less quickly than usual but we were able to fix this as well by changing some configuration options. At 10pm it was all over – the attack stopped, after services had been running close to normal for some time already. All in all, we were reasonably happy with how things went down that night and considered our systems better prepared for whatever might be coming next.&lt;/p&gt;&lt;h2&gt;The second attack on Friday&lt;/h2&gt;&lt;p&gt;The team spent some time on Friday (22 October) to analyse what had happened the previous day, and we decided to put additional measures in place to further improve resilience. Yet, another attack came at 4pm, at the very second when we temporarily disabled some of our new firewall improvements to adjust some of the settings. That's hard luck! We were able to counter the attack within minutes just by enabling our firewall settings. However, due to a brief but large spike in traffic, one of our internal load balancers had crashed and for some reason, the automatic takeover by the replacement unit didn't work as smoothly as we had hoped. We needed a technician to actually go to the data centre and fix the problem on location, and for a duration of about 60 minutes there were some problems with logging in and accessing services through IPv6. We have now put further measures in place that will prevent a similar situation from arising in the future and also improved our ability to react more quickly.&lt;/p&gt;&lt;h2&gt;Outlook&lt;/h2&gt;&lt;p&gt;Attacks against e-mail providers that have the intent to extort money will likely continue in the future. We at mailbox.org expect more attacks to follow in the coming days, and it is the same for our colleagues who are with other organizations that are facing the same DDoS attack wave. As we are writing this blog, we are also extensively networking and communicating with other providers worldwide, to exchange experiences and best practices about how to deal effectively with these kinds of attacks.&lt;/p&gt;&lt;p&gt;It's hard to say what will happen in the future. There may well be that one attack that is so massive that it might overwhelm our infrastructure, but it's also possible that we will remain as resilient as we have so far, and that future DDoS attacks will continue to fail to have any noticeable impact on our operations.&lt;/p&gt;&lt;p&gt;What we can say is that we are prepared. With our knowledge and experience, we did our best to create good defensive measures. Yet, every network and every data line has physical limits, and that is something we cannot change. However, we know that it is also expensive for the attackers to actually run a coordinated DDoS operation that requires many resources. That means they have limits, too, and cannot push on forever.&lt;/p&gt;&lt;h2&gt;We ask for your understanding&lt;/h2&gt;&lt;p&gt;In light of the situation, we ask our users for their patience and understanding should they experience any disruption to services within the next few days. We will be doing our best to deflect any incoming attacks as quickly as possible.&lt;/p&gt;&lt;p&gt;We are asking in particular that general inquiries are kept to a minimum at the moment. Please accept our apologies that while an attack is ongoing, we may not be able to communicate with you as fully, speedily, and individually as you may have come to expect from us under normal circumstances. There is a chance that blog articles, user forum, and disruption banners may be affected as well. If things get sticky, watch out for the announcements and status updates the team will post on our &lt;a href="https://twitter.com/mailbox_org" target="_blank" title="Twitter channel" rel="noopener"&gt;Twitter channel&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;Lastly, everyone can rest assured that under no circumstances will mailbox.org be blackmailed or submit to paying any money to any attacker.&lt;br&gt;---&lt;br&gt;Our admin and network teams at Heinlein Hosting and mailbox.org would like to take the opportunity to also thank our colleagues at &lt;a href="https://www.myrasecurity.com/de/" target="_blank" title="MyraSecurity" rel="noopener"&gt;MyraSecurity&lt;/a&gt; for their excellent support and friendly cooperation.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-04/mailbox-news-und-updates-warnung.jpg?itok=reW9cU74" type="image/jpeg" length="238141"/><guid isPermaLink="false">c3577fe8-8e55-44ad-ab54-98dbced4cc20</guid>
    <pubDate>Sat, 23 Oct 2021 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Extortionate DDoS attacks on mailbox.org</dc:title>
    <dc:identifier>c3577fe8-8e55-44ad-ab54-98dbced4cc20</dc:identifier>
    </item>
<item>
  <title>Extortionate DDoS attacks on mailbox.org</title>
  <link>https://mailbox.org/en/news/distributed-denial-service-attacks-mailboxorg/</link>
  <description>&lt;p&gt;There has been a steep increase in Distributed-Denial-of-Service (DDoS) attacks against e-mail providers worldwide in the past few weeks, and more recently these attacks have become even more frequent. Attacks like this are essentially a form of blackmail, as they have the objective of bringing services to a standstill first to then offer relief in exchange for money. As it happened, mailbox.org was also targeted, on Thursday night and Friday afternoon. At the same time, we received a communication in which the attackers demanded we pay them money in Bitcoin. - Of course, we will do no such thing.&lt;/p&gt;&lt;p&gt;We are expecting more attacks in the coming days, though. This blog article has information for our users, including some more background about DDoS attacks and their possible impact. We hope any disruption can be avoided or kept to a minimum. Thank you in advance for your understanding should any services become temporarily unavailable during the next few days.&lt;/p&gt;&lt;p&gt;Please note:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Should any services become temporarily unavailable, for example if you are unable to retrieve your e-mails as usual, please try again later.&lt;/li&gt;&lt;li&gt;Within the next few days, try not to issue any unnecessary support requests concerning, or notify us of any temporary downtime of services. We are expecting more attacks and will do everything required to restore services as quickly as possible.&lt;/li&gt;&lt;li&gt;Any e-mails sent to you won't be lost, even if the service is temporarily unavailable. In the current circumstances, these may just be delivered a little later than usual.&lt;/li&gt;&lt;li&gt;If you are experiencing any difficulties with using our services, please let us know on &lt;a href="https://twitter.com/mailbox_org" target="_blank" title="Twitter" rel="noopener"&gt;Twitter&lt;/a&gt;, if possible. Twitter is also a good place to look first in case something isn't working.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Background:&lt;/p&gt;&lt;h2&gt;DDoS attacks aim to knock out their targets&lt;/h2&gt;&lt;p&gt;A Distributed-Denial-of-Service (DDoS) attack requires a large number of computers to get infected by viruses first. Then, the attackers control these machines to send large quantities of data to a shared target in a coordinated fashion, with the goal of disabling the target's ability to respond to other requests. What we experienced was quite extraordinary: About 147.000 different computers had been infiltrated to be involved in the attack, and our servers received data through the Internet at a rate of 150 million data packets per second. As an analogy, imagine 147.000 people dialling the same phone number, every second, in order to knock out the telephone network of a city, a business, or a local authority.&lt;/p&gt;&lt;p&gt;The data that is sent in DDoS attacks has usually normal or even meaningless contents, because the primary goal is to impact the function of systems, firewalls, servers and networks through the huge amounts of data that are being sent. For example, doing so can overload a server, such that it is kept busy processing the DDoS data, while regular user requests suffer severe delays or even time-outs. It is important to point out, though, that at no point do the attackers actually have access to the targeted network. That is why we are confident that all customer data has always been secure and protected during the attacks.&lt;/p&gt;&lt;p&gt;For any internet host, it is not really possible to avoid DDoS attacks when they come. However, it is possible to create a resilient infrastructure that provides protection and a level of performance which is more difficult for attackers to knock out. However, the idea that someone could achieve full protection is an illusion: The opponent that fields more capable hardware and software will win eventually. On the attacking side, these are the number of systems that are coordinated to produce and send the data, and on the defending side, it's the systems that receive and process the data as well as those that detect and counter such attacks.&lt;/p&gt;&lt;h2&gt;mailbox.org is well-prepared for DDoS attacks&lt;/h2&gt;&lt;p&gt;We at mailbox.org have previously monitored occasional smaller-scale DDoS attacks, which usually go unnoticed by customers. We have also worked to prepare against larger efforts that would target our systems directly and invested considerably in a robust infrastructure that provides appropriate defensive measures. For example, we operate our servers redundantly across two separate data centres and have four different communication lines for data exchange with other providers on the Internet. Also, our network infrastructure has been designed to have a considerable amount of resources to spare during normal operations, which provides our systems with the performance to scale rapidly, if required.&lt;/p&gt;&lt;p&gt;Furthermore, we are working together with MyraSecurity, a German company that specializes in protection against DDoS attacks. MyraSecurity maintain a powerful infrastructure for the detection and filtering of DDoS data traffic and their systems provide additional protection by blocking a large amount of the incoming malicious traffic that is caused by DDoS attacks. During regular, everyday operations, these systems just sit there and don't need to do much. However, once an attack has been detected, our mailbox.org systems will switch over their regular data lines to filter the incoming traffic through this “DDoS shield”. As a result, less traffic reaches our critical infrastructure, which minimizes the potential of disruption.&lt;/p&gt;&lt;p&gt;It is important to note that MyraSecurity has been set up such that they have no actual access to the encrypted data traffic. Any DDoS protection measures will only look at external characteristics of the data packets they filter, to decide which ones will be blocked and which ones will be let through.&lt;/p&gt;&lt;h2&gt;The first attack on Thursday&lt;/h2&gt;&lt;p&gt;The difference between theory and practice: You will only know if your preparations were sufficient once the worst is actually happening. Last Thursday, we had a few teething problems at first but were able to defend ourselves effectively against the first large DDoS attack. At the beginning, we saw some disruption to services. However, we were able to find and disable the root causes quickly and adapt our infrastructure to better withstand any future attacks.&lt;/p&gt;&lt;p&gt;After about 30 to 60 minutes had passed, hardly any impact was noticeable anymore by our users despite the attack continuing at full strength. Some of our websites may have responded less quickly than usual but we were able to fix this as well by changing some configuration options. At 10pm it was all over – the attack stopped, after services had been running close to normal for some time already. All in all, we were reasonably happy with how things went down that night and considered our systems better prepared for whatever might be coming next.&lt;/p&gt;&lt;h2&gt;The second attack on Friday&lt;/h2&gt;&lt;p&gt;The team spent some time on Friday (22 October) to analyse what had happened the previous day, and we decided to put additional measures in place to further improve resilience. Yet, another attack came at 4pm, at the very second when we temporarily disabled some of our new firewall improvements to adjust some of the settings. That's hard luck! We were able to counter the attack within minutes just by enabling our firewall settings. However, due to a brief but large spike in traffic, one of our internal load balancers had crashed and for some reason, the automatic takeover by the replacement unit didn't work as smoothly as we had hoped. We needed a technician to actually go to the data centre and fix the problem on location, and for a duration of about 60 minutes there were some problems with logging in and accessing services through IPv6. We have now put further measures in place that will prevent a similar situation from arising in the future and also improved our ability to react more quickly.&lt;/p&gt;&lt;h2&gt;Outlook&lt;/h2&gt;&lt;p&gt;Attacks against e-mail providers that have the intent to extort money will likely continue in the future. We at mailbox.org expect more attacks to follow in the coming days, and it is the same for our colleagues who are with other organizations that are facing the same DDoS attack wave. As we are writing this blog, we are also extensively networking and communicating with other providers worldwide, to exchange experiences and best practices about how to deal effectively with these kinds of attacks.&lt;/p&gt;&lt;p&gt;It's hard to say what will happen in the future. There may well be that one attack that is so massive that it might overwhelm our infrastructure, but it's also possible that we will remain as resilient as we have so far, and that future DDoS attacks will continue to fail to have any noticeable impact on our operations.&lt;/p&gt;&lt;p&gt;What we can say is that we are prepared. With our knowledge and experience, we did our best to create good defensive measures. Yet, every network and every data line has physical limits, and that is something we cannot change. However, we know that it is also expensive for the attackers to actually run a coordinated DDoS operation that requires many resources. That means they have limits, too, and cannot push on forever.&lt;/p&gt;&lt;h2&gt;We ask for your understanding&lt;/h2&gt;&lt;p&gt;In light of the situation, we ask our users for their patience and understanding should they experience any disruption to services within the next few days. We will be doing our best to deflect any incoming attacks as quickly as possible.&lt;/p&gt;&lt;p&gt;We are asking in particular that general inquiries are kept to a minimum at the moment. Please accept our apologies that while an attack is ongoing, we may not be able to communicate with you as fully, speedily, and individually as you may have come to expect from us under normal circumstances. There is a chance that blog articles, user forum, and disruption banners may be affected as well. If things get sticky, watch out for the announcements and status updates the team will post on our &lt;a href="https://twitter.com/mailbox_org" target="_blank" title="Twitter channel" rel="noopener"&gt;Twitter channel&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;Lastly, everyone can rest assured that under no circumstances will mailbox.org be blackmailed or submit to paying any money to any attacker.&lt;br&gt;---&lt;br&gt;Our admin and network teams at Heinlein Hosting and mailbox.org would like to take the opportunity to also thank our colleagues at &lt;a href="https://www.myrasecurity.com/de/" target="_blank" title="MyraSecurity" rel="noopener"&gt;MyraSecurity&lt;/a&gt; for their excellent support and friendly cooperation.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-04/mailbox-news-und-updates-warnung.jpg?itok=reW9cU74" type="image/jpeg" length="238141"/><guid isPermaLink="false">c3577fe8-8e55-44ad-ab54-98dbced4cc20</guid>
    <pubDate>Sat, 23 Oct 2021 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Extortionate DDoS attacks on mailbox.org</dc:title>
    <dc:identifier>c3577fe8-8e55-44ad-ab54-98dbced4cc20</dc:identifier>
    </item>
<item>
  <title>Phone support in the PREMIUM price plan</title>
  <link>https://mailbox.org/en/news/new-telephone-support-premium-plan/</link>
  <description>&lt;p&gt;With the introduction of our new price plans in early 2021, we also mentioned the future availability of telephone support for all customers in our new PREMIUM plan. The time has come, and we are pleased to announce that as of now, all PREMIUM mailbox users can reach us in person over the phone to sort out any issues related to their e-mail account.&lt;/p&gt;&lt;p&gt;In brief:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Telephone support (Callback service)&lt;/li&gt;&lt;li&gt;Exclusive for customers in the PREMIUM plan&lt;/li&gt;&lt;li&gt;Direct line to the support team&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Talk directly to the experts with our callback service&lt;/h2&gt;&lt;p&gt;We appreciate that our customers' time is valuable, which is why we are doing things a little differently. We won't put you on hold to keep you waiting in a loop. We also won't bombard you with impersonal recorded messages before you can talk to us. Our new telephone support is designed as a callback service, which can be requested conveniently through the Helpdesk portal: Simply describe what the issue is, provide your telephone number, and select a desired date and time window for your callback - done. An expert from our support team will then get back to you at the requested time, and you can rest assured that they will be well-prepared to sort out whatever issue you are experiencing.&lt;/p&gt;&lt;p&gt;Find more information about this in our knowledge base: &lt;a href="https://kb.mailbox.org/display/MBOKBEN/How+to+use+the+callback+service" target="_blank" title="go to knowledge base article" rel="noopener"&gt;How to use the callback service -&amp;gt;&lt;/a&gt;&lt;/p&gt;&lt;h2&gt;Exclusive for PREMIUM customers&lt;/h2&gt;&lt;p&gt;Telephone support is available to all customers in the PREMIUM price plan. For € 9 per month, this also includes 25 GB mail storage, 50 GB cloud storage, 25 mailbox.org aliases, 250 aliases for your own domain name and much more! As before, all private customers can benefit from our special offer: Pay in advance for 10 months and receive 2 months free (select “12 months = €90.00 instead of €108.00”).&lt;/p&gt;&lt;h2&gt;Tip: Make sure to create a telephone password&lt;/h2&gt;&lt;p&gt;When you receive a call back from us, our support agent will need to verify your identity first. If you create a personal telephone password and store this in your account in advance, then this will not only make the verification process a lot simpler, it will also help protect your account and e-mail inbox.&lt;/p&gt;&lt;p&gt;To create and store a telephone password, please log on to your account and visit Settings → mailbox.org → Personal Data.&lt;/p&gt;&lt;p&gt;Please note that the telephone password is different from your account password and solely used for identity checks over the phone. Our support agents will never ask you for your account password.&lt;/p&gt;&lt;h2&gt;Business customers&lt;/h2&gt;&lt;p&gt;Where business customers have arranged direct mailbox.org support for their teams and employees, the callback service will be available for all users of a PREMIUM e-mail inbox under this arrangement.&lt;/p&gt;&lt;p&gt;Account administrators of our business customers should note that the support options of your chosen service package will apply as usual. Depending on your selected package, our support team can be reached by e-mail ticket, telephone during business hours, or the 24/7 emergency hotline.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-support.jpg?itok=zLcWLJo1" type="image/jpeg" length="272690"/><guid isPermaLink="false">5fca1545-a23b-413e-a76d-2df674474b2b</guid>
    <pubDate>Tue, 21 Sep 2021 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Phone support in the PREMIUM price plan</dc:title>
    <dc:identifier>5fca1545-a23b-413e-a76d-2df674474b2b</dc:identifier>
    </item>
<item>
  <title>Phone support in the PREMIUM price plan</title>
  <link>https://mailbox.org/en/news/new-telephone-support-premium-plan/</link>
  <description>&lt;p&gt;With the introduction of our new price plans in early 2021, we also mentioned the future availability of telephone support for all customers in our new PREMIUM plan. The time has come, and we are pleased to announce that as of now, all PREMIUM mailbox users can reach us in person over the phone to sort out any issues related to their e-mail account.&lt;/p&gt;&lt;p&gt;In brief:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Telephone support (Callback service)&lt;/li&gt;&lt;li&gt;Exclusive for customers in the PREMIUM plan&lt;/li&gt;&lt;li&gt;Direct line to the support team&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Talk directly to the experts with our callback service&lt;/h2&gt;&lt;p&gt;We appreciate that our customers' time is valuable, which is why we are doing things a little differently. We won't put you on hold to keep you waiting in a loop. We also won't bombard you with impersonal recorded messages before you can talk to us. Our new telephone support is designed as a callback service, which can be requested conveniently through the Helpdesk portal: Simply describe what the issue is, provide your telephone number, and select a desired date and time window for your callback - done. An expert from our support team will then get back to you at the requested time, and you can rest assured that they will be well-prepared to sort out whatever issue you are experiencing.&lt;/p&gt;&lt;p&gt;Find more information about this in our knowledge base: &lt;a href="https://kb.mailbox.org/display/MBOKBEN/How+to+use+the+callback+service" target="_blank" title="go to knowledge base article" rel="noopener"&gt;How to use the callback service -&amp;gt;&lt;/a&gt;&lt;/p&gt;&lt;h2&gt;Exclusive for PREMIUM customers&lt;/h2&gt;&lt;p&gt;Telephone support is available to all customers in the PREMIUM price plan. For € 9 per month, this also includes 25 GB mail storage, 50 GB cloud storage, 25 mailbox.org aliases, 250 aliases for your own domain name and much more! As before, all private customers can benefit from our special offer: Pay in advance for 10 months and receive 2 months free (select “12 months = €90.00 instead of €108.00”).&lt;/p&gt;&lt;h2&gt;Tip: Make sure to create a telephone password&lt;/h2&gt;&lt;p&gt;When you receive a call back from us, our support agent will need to verify your identity first. If you create a personal telephone password and store this in your account in advance, then this will not only make the verification process a lot simpler, it will also help protect your account and e-mail inbox.&lt;/p&gt;&lt;p&gt;To create and store a telephone password, please log on to your account and visit Settings → mailbox.org → Personal Data.&lt;/p&gt;&lt;p&gt;Please note that the telephone password is different from your account password and solely used for identity checks over the phone. Our support agents will never ask you for your account password.&lt;/p&gt;&lt;h2&gt;Business customers&lt;/h2&gt;&lt;p&gt;Where business customers have arranged direct mailbox.org support for their teams and employees, the callback service will be available for all users of a PREMIUM e-mail inbox under this arrangement.&lt;/p&gt;&lt;p&gt;Account administrators of our business customers should note that the support options of your chosen service package will apply as usual. Depending on your selected package, our support team can be reached by e-mail ticket, telephone during business hours, or the 24/7 emergency hotline.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-support.jpg?itok=zLcWLJo1" type="image/jpeg" length="272690"/><guid isPermaLink="false">5fca1545-a23b-413e-a76d-2df674474b2b</guid>
    <pubDate>Tue, 21 Sep 2021 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Phone support in the PREMIUM price plan</dc:title>
    <dc:identifier>5fca1545-a23b-413e-a76d-2df674474b2b</dc:identifier>
    </item>
<item>
  <title>Open letter to Apple against user surveillance</title>
  <link>https://mailbox.org/en/news/open-letter-apple-against-surveillance-users/</link>
  <description>&lt;p&gt;It is with great concern that we at mailbox.org observe the plans published by Apple to use a surveillance algorithm for images in Messenger and the iCloud. While the motives – fighting child pornography – are right and also very important, the planned tool is extremely dangerous. We fear that this AI tool – once in use – can be used to monitor citizen, journalists and critics.&lt;/p&gt;&lt;p&gt;For us, safe, free and unmonitored communication is a matter of the heart and that is why we have signed the &lt;a href="https://cdt.org/wp-content/uploads/2021/08/CDT-Coalition-ltr-to-Apple-19-August-2021.pdf" target="_blank" rel="noopener"&gt;open letter&lt;/a&gt; of the Center for Democracy &amp;amp; Technology (CDT). Together with 90 other organisations, we demand that Apple refrain from using the surveillance algorithm.&lt;/p&gt;&lt;h3&gt;Related links:&lt;/h3&gt;&lt;ol&gt;&lt;li&gt;CDT: &lt;a href="https://cdt.org/insights/international-coalition-calls-on-apple-to-abandon-plan-to-build-surveillance-capabilities-into-iphones-ipads-and-other-products/" target="_blank" rel="noopener"&gt;International Coalition Calls on Apple to Abandon Plan to Build Surveillance Capabilities into iPhones, iPads, and other Products&lt;/a&gt;&lt;/li&gt;&lt;li&gt;The Verge: &lt;a href="https://www.theverge.com/2021/8/19/22632722/apple-child-abuse-scan-ios-abandon-request-privacy" target="_blank" rel="noopener"&gt;Policy groups request Apple abandon plans to scan devices for child abuse imagery&lt;/a&gt;&lt;/li&gt;&lt;/ol&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-04/mailbox-news-und-updates-warnung.jpg?itok=reW9cU74" type="image/jpeg" length="238141"/><guid isPermaLink="false">278f81c8-c60a-449d-abbd-d64d3349c7ba</guid>
    <pubDate>Mon, 23 Aug 2021 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Open letter to Apple against user surveillance</dc:title>
    <dc:identifier>278f81c8-c60a-449d-abbd-d64d3349c7ba</dc:identifier>
    </item>
<item>
  <title>Open letter to Apple against user surveillance</title>
  <link>https://mailbox.org/en/news/open-letter-apple-against-surveillance-users/</link>
  <description>&lt;p&gt;It is with great concern that we at mailbox.org observe the plans published by Apple to use a surveillance algorithm for images in Messenger and the iCloud. While the motives – fighting child pornography – are right and also very important, the planned tool is extremely dangerous. We fear that this AI tool – once in use – can be used to monitor citizen, journalists and critics.&lt;/p&gt;&lt;p&gt;For us, safe, free and unmonitored communication is a matter of the heart and that is why we have signed the &lt;a href="https://cdt.org/wp-content/uploads/2021/08/CDT-Coalition-ltr-to-Apple-19-August-2021.pdf" target="_blank" rel="noopener"&gt;open letter&lt;/a&gt; of the Center for Democracy &amp;amp; Technology (CDT). Together with 90 other organisations, we demand that Apple refrain from using the surveillance algorithm.&lt;/p&gt;&lt;h3&gt;Related links:&lt;/h3&gt;&lt;ol&gt;&lt;li&gt;CDT: &lt;a href="https://cdt.org/insights/international-coalition-calls-on-apple-to-abandon-plan-to-build-surveillance-capabilities-into-iphones-ipads-and-other-products/" target="_blank" rel="noopener"&gt;International Coalition Calls on Apple to Abandon Plan to Build Surveillance Capabilities into iPhones, iPads, and other Products&lt;/a&gt;&lt;/li&gt;&lt;li&gt;The Verge: &lt;a href="https://www.theverge.com/2021/8/19/22632722/apple-child-abuse-scan-ios-abandon-request-privacy" target="_blank" rel="noopener"&gt;Policy groups request Apple abandon plans to scan devices for child abuse imagery&lt;/a&gt;&lt;/li&gt;&lt;/ol&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-04/mailbox-news-und-updates-warnung.jpg?itok=reW9cU74" type="image/jpeg" length="238141"/><guid isPermaLink="false">278f81c8-c60a-449d-abbd-d64d3349c7ba</guid>
    <pubDate>Mon, 23 Aug 2021 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Open letter to Apple against user surveillance</dc:title>
    <dc:identifier>278f81c8-c60a-449d-abbd-d64d3349c7ba</dc:identifier>
    </item>
<item>
  <title>The German government's naive cyber security strategy</title>
  <link>https://mailbox.org/en/news/federal-governments-cybersecurity-strategy-naive-and-dangerous/</link>
  <description>&lt;p&gt;The German federal government has recently published a strategy paper on cybersecurity. Its declared purpose is to improve the security of citizens and businesses in the country, and to equip law enforcement authorities for the digital challenges of the 21st century. However, experts have criticized the suggestions as dangerous and simplistic. People have only until Wednesday 16 June to send their comments and feedback to the federal department of interior affairs. Doing so might perhaps help avoid the worst outcomes but time is very short indeed.&lt;/p&gt;&lt;h2&gt;Government fails again on the issue of cybersecurity&lt;/h2&gt;&lt;p&gt;The document currently has 128 pages and is entitled „&lt;a href="https://www.bmi.bund.de/SharedDocs/kurzmeldungen/DE/2021/06/css-2021-beteiligungsformat.html" target="_blank" title="Cybersicherheitsstrategie für Deutschland 2021" rel="noopener"&gt;Cybersicherheitsstrategie für Deutschland 2021&lt;/a&gt;“ (Cybersecurity strategy for Germany 2021). It can be downloaded as a &lt;a href="https://www.bmi.bund.de/SharedDocs/downloads/DE/veroeffentlichungen/2021/06/entwurf-cybersicherheitsstrategie-2021.pdf" target="_blank" title="PDF here" rel="noopener"&gt;PDF here&lt;/a&gt; (in German only).&lt;/p&gt;&lt;p&gt;People may submit their thoughts using another &lt;a href="https://www.bmi.bund.de/SharedDocs/downloads/DE/veroeffentlichungen/2021/06/entwurf-cybersicherheitsstrategie-2021-fragebogen.pdf" target="_blank" title="PDF document" rel="noopener"&gt;PDF document,&lt;/a&gt; which invites feedback and comments on each of the individual chapters. The goal is straightforward: more efficient law enforcement, especially on the Internet. The department for interior affairs thinks it necessary to be able to „crack“ secure encryption mechanisms in order to put criminals under surveillance. Furthermore, new plans are to be developed and organizations set up whose purpose it will be to deliberately hide and obscure information about existing software bugs, security vulnerabilities, and potential backdoors. That way, developers will unlikely fix these problems so that the authorities can exploit them for their own purposes. While addressing the problems would clearly improve software security, this is not desired by the legislature, as doing so could mean not just criminal actors might be shut out but investigators as well.&lt;/p&gt;&lt;p&gt;This so-called „verantwortliches Schwachstellenmanagement” (responsible vulnerability management), as detailed in section 8.3.8 of the draft, clearly indicates the intention of state actors to keep citizens in the dark about security loopholes for the purpose of facilitating unfettered surveillance. However, the end does not always justify the means, even in cases where authorities justifiably require access (e.g., for investigations of serious crimes). Critics say it is incredibly naive to assume that criminals won’t find and actively use any backdoors to computer systems that are deliberately not getting fixed. The whole approach is flawed in that it opens the gates for all kinds of attackers, and because it is conducive to criminal activity rather than preventing it, with wide-ranging societal implications. The state would negligently fail in one of its core duties: To protect its citizens, authorities, and businesses from criminals.&lt;/p&gt;&lt;h2&gt;The planned circumvention of encryption mechanisms&lt;/h2&gt;&lt;p&gt;Similarly controversial is another idea about maintaining security both through the use of encryption and also by working around encryption (Section 8.3.9). This approach is not new and has been repeatedly criticized for absence of technical expertise and also a blatant lack of respect for the constitutional rights of citizens. The paper's characterization of the much-criticized IT bills of 2021 as “appropriate measures to adjust to technological progress” (Section 8.3.14) presents a thinly veiled attempt to further tighten laws that are likely already unconstitutional in their current form. (For example, lawful telecommunications interception, or the recent &lt;a href="https://mailbox.org/en/post/rushed-through-the-back-door-new-g-10-bill-introduces-measures-for-the-direct-surveillance-of-users" target="_blank" title="G-10 bill" rel="noopener"&gt;G-10 bill&lt;/a&gt;).&lt;/p&gt;&lt;p&gt;The express objective of this cybersecurity strategy is to develop technical and operative solutions for lawful access to encrypted communication contents. From our perspective, this is a direct attack not only on e-mail encryption mechanisms and so, on our customers' right to privacy. Without there being any pressing need, the government risks eroding the integrity and confidentiality of our data, as well as the peoples' trust in the constitutional state, law enforcement, intelligence services, and democracy in general.&lt;/p&gt;&lt;h2&gt;Security for citizens or for intelligence services?&lt;/h2&gt;&lt;p&gt;Even IT experts don't seem to be able to find anything positive in the current strategy paper: Manuel Atug, speaker of the independent working group for the improvement of IT security and resilience of critical infrastructures (AG KRITIS), went on Twitter to denounce the paper as „völlig defekt“ (entirely defective) and „ein trauriges Bild für Deutschland“ (Germany cutting a bad figure). There is no explanation of any fundamental cyberthreat situation in the draft. However, wouldn't this be a basic requirement before anyone even starts calling for the expansion of surveillance measures?&lt;/p&gt;&lt;p&gt;Atug criticizes those who think that state-sponsored „Trojan horses“ and back-hacking (the cyber-attacking of hackers) are appropriate measures for active defense. He also points at the obvious conflict between the objective of achieving digital sovereignty and collaborating with organizations such as „ZITiS“, who are close to the intelligence services and act as a commercial enterprise in the development and purchase of security vulnerabilities. He says the proponents of such measures have a totally warped perception of what cybersecurity is. Further, Atug explains that encryption is the only feasible way for civil society, businesses, and critical infrastructures to maintain their security, while any approach trying to circumvent or disable encryption is exclusively of interest to law enforcement and intelligence services.&lt;/p&gt;&lt;p&gt;In light of this, we hope many of our citizens will participate and send their comments and feedback on this cybersecurity strategy paper.&lt;/p&gt;&lt;p&gt;&lt;br&gt;Author: Markus Feilner&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-surveillance.png-3.png?itok=n7qe3gyS" type="image/png" length="330780"/><guid isPermaLink="false">e31f39fb-fd0b-4abd-a3dc-ecee603a4cef</guid>
    <pubDate>Tue, 15 Jun 2021 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>The German government's naive cyber security strategy</dc:title>
    <dc:identifier>e31f39fb-fd0b-4abd-a3dc-ecee603a4cef</dc:identifier>
    </item>
<item>
  <title>The German government's naive cyber security strategy</title>
  <link>https://mailbox.org/en/news/federal-governments-cybersecurity-strategy-naive-and-dangerous/</link>
  <description>&lt;p&gt;The German federal government has recently published a strategy paper on cybersecurity. Its declared purpose is to improve the security of citizens and businesses in the country, and to equip law enforcement authorities for the digital challenges of the 21st century. However, experts have criticized the suggestions as dangerous and simplistic. People have only until Wednesday 16 June to send their comments and feedback to the federal department of interior affairs. Doing so might perhaps help avoid the worst outcomes but time is very short indeed.&lt;/p&gt;&lt;h2&gt;Government fails again on the issue of cybersecurity&lt;/h2&gt;&lt;p&gt;The document currently has 128 pages and is entitled „&lt;a href="https://www.bmi.bund.de/SharedDocs/kurzmeldungen/DE/2021/06/css-2021-beteiligungsformat.html" target="_blank" title="Cybersicherheitsstrategie für Deutschland 2021" rel="noopener"&gt;Cybersicherheitsstrategie für Deutschland 2021&lt;/a&gt;“ (Cybersecurity strategy for Germany 2021). It can be downloaded as a &lt;a href="https://www.bmi.bund.de/SharedDocs/downloads/DE/veroeffentlichungen/2021/06/entwurf-cybersicherheitsstrategie-2021.pdf" target="_blank" title="PDF here" rel="noopener"&gt;PDF here&lt;/a&gt; (in German only).&lt;/p&gt;&lt;p&gt;People may submit their thoughts using another &lt;a href="https://www.bmi.bund.de/SharedDocs/downloads/DE/veroeffentlichungen/2021/06/entwurf-cybersicherheitsstrategie-2021-fragebogen.pdf" target="_blank" title="PDF document" rel="noopener"&gt;PDF document,&lt;/a&gt; which invites feedback and comments on each of the individual chapters. The goal is straightforward: more efficient law enforcement, especially on the Internet. The department for interior affairs thinks it necessary to be able to „crack“ secure encryption mechanisms in order to put criminals under surveillance. Furthermore, new plans are to be developed and organizations set up whose purpose it will be to deliberately hide and obscure information about existing software bugs, security vulnerabilities, and potential backdoors. That way, developers will unlikely fix these problems so that the authorities can exploit them for their own purposes. While addressing the problems would clearly improve software security, this is not desired by the legislature, as doing so could mean not just criminal actors might be shut out but investigators as well.&lt;/p&gt;&lt;p&gt;This so-called „verantwortliches Schwachstellenmanagement” (responsible vulnerability management), as detailed in section 8.3.8 of the draft, clearly indicates the intention of state actors to keep citizens in the dark about security loopholes for the purpose of facilitating unfettered surveillance. However, the end does not always justify the means, even in cases where authorities justifiably require access (e.g., for investigations of serious crimes). Critics say it is incredibly naive to assume that criminals won’t find and actively use any backdoors to computer systems that are deliberately not getting fixed. The whole approach is flawed in that it opens the gates for all kinds of attackers, and because it is conducive to criminal activity rather than preventing it, with wide-ranging societal implications. The state would negligently fail in one of its core duties: To protect its citizens, authorities, and businesses from criminals.&lt;/p&gt;&lt;h2&gt;The planned circumvention of encryption mechanisms&lt;/h2&gt;&lt;p&gt;Similarly controversial is another idea about maintaining security both through the use of encryption and also by working around encryption (Section 8.3.9). This approach is not new and has been repeatedly criticized for absence of technical expertise and also a blatant lack of respect for the constitutional rights of citizens. The paper's characterization of the much-criticized IT bills of 2021 as “appropriate measures to adjust to technological progress” (Section 8.3.14) presents a thinly veiled attempt to further tighten laws that are likely already unconstitutional in their current form. (For example, lawful telecommunications interception, or the recent &lt;a href="https://mailbox.org/en/post/rushed-through-the-back-door-new-g-10-bill-introduces-measures-for-the-direct-surveillance-of-users" target="_blank" title="G-10 bill" rel="noopener"&gt;G-10 bill&lt;/a&gt;).&lt;/p&gt;&lt;p&gt;The express objective of this cybersecurity strategy is to develop technical and operative solutions for lawful access to encrypted communication contents. From our perspective, this is a direct attack not only on e-mail encryption mechanisms and so, on our customers' right to privacy. Without there being any pressing need, the government risks eroding the integrity and confidentiality of our data, as well as the peoples' trust in the constitutional state, law enforcement, intelligence services, and democracy in general.&lt;/p&gt;&lt;h2&gt;Security for citizens or for intelligence services?&lt;/h2&gt;&lt;p&gt;Even IT experts don't seem to be able to find anything positive in the current strategy paper: Manuel Atug, speaker of the independent working group for the improvement of IT security and resilience of critical infrastructures (AG KRITIS), went on Twitter to denounce the paper as „völlig defekt“ (entirely defective) and „ein trauriges Bild für Deutschland“ (Germany cutting a bad figure). There is no explanation of any fundamental cyberthreat situation in the draft. However, wouldn't this be a basic requirement before anyone even starts calling for the expansion of surveillance measures?&lt;/p&gt;&lt;p&gt;Atug criticizes those who think that state-sponsored „Trojan horses“ and back-hacking (the cyber-attacking of hackers) are appropriate measures for active defense. He also points at the obvious conflict between the objective of achieving digital sovereignty and collaborating with organizations such as „ZITiS“, who are close to the intelligence services and act as a commercial enterprise in the development and purchase of security vulnerabilities. He says the proponents of such measures have a totally warped perception of what cybersecurity is. Further, Atug explains that encryption is the only feasible way for civil society, businesses, and critical infrastructures to maintain their security, while any approach trying to circumvent or disable encryption is exclusively of interest to law enforcement and intelligence services.&lt;/p&gt;&lt;p&gt;In light of this, we hope many of our citizens will participate and send their comments and feedback on this cybersecurity strategy paper.&lt;/p&gt;&lt;p&gt;&lt;br&gt;Author: Markus Feilner&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-surveillance.png-3.png?itok=n7qe3gyS" type="image/png" length="330780"/><guid isPermaLink="false">e31f39fb-fd0b-4abd-a3dc-ecee603a4cef</guid>
    <pubDate>Tue, 15 Jun 2021 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>The German government's naive cyber security strategy</dc:title>
    <dc:identifier>e31f39fb-fd0b-4abd-a3dc-ecee603a4cef</dc:identifier>
    </item>
<item>
  <title>mailbox.org – Test winner in Switzerland too!</title>
  <link>https://mailbox.org/en/news/mailbox-test-winner-switzerland-too/</link>
  <description>&lt;p&gt;"Eight out of ten clouds are not trustworthy - The Swiss Linuxfabrik and the German mailbox.org scored best" is the conclusion of the renowned Swiss consumer magazine &lt;a href="https://www.ktipp.ch/" target="_blank" title="K-Tipp" rel="noopener"&gt;K-Tipp&lt;/a&gt;. Cloud providers of all sizes were put under the microscope, from Google to Dropbox to smaller providers like mailbox.org. In their test, the Swiss consumer protection agency placed particular emphasis on data protection, user-friendliness and versatility of the offer. - With 14 out of 15 possible points, mailbox.org was able to convince the editors and landed in first place together with the Swiss Linuxfabrik.&lt;/p&gt;&lt;p&gt;Only in terms of usability did mailbox.org receive "only" four out of five stars; Apple's iCloud was more convincing to the testers from Switzerland. Overall, however, Apple's service came in last due to a lack of data protection, versatility and the absence of an Android app - only Microsoft and Dropbox scored worse.&lt;/p&gt;&lt;p&gt;Other candidates in the test were Linuxfabrik (also 14 out of 15 points), Mega (11), Swisscom Mycloud light (11), Backup ONE (10), Tresorit (10), Google Drive (9), Apple Icloud (8), Microsoft OneDrive (7) and in last place Dropbox (5). We find it striking that four of the five free services ended up at the bottom of the field; only Mega from New Zealand/Canada was able to take one of the top places, but it probably "annoys" its users with advertising in apps and mails.&lt;/p&gt;&lt;h3&gt;About K-Tipp&lt;/h3&gt;&lt;p&gt;With its focus on consumer protection, &lt;a href="https://www.ktipp.ch/" target="_blank" title="K-Tipp" rel="noopener"&gt;K-Tipp&lt;/a&gt; is published every fortnight with a circulation of more than 250,000 copies and reaches almost one million readers. &lt;a href="https://www.ktipp.ch/artikel/artikeldetail/acht-von-zehn-clouds-sind-nicht-vertrauenswuerdig/" target="_blank" title="German version of the full report" rel="noopener"&gt;The full test report is available here&lt;/a&gt; after taking out an online subscription (from 8 Swiss francs).&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-celebration.jpeg?itok=wIZsodf0" type="image/jpeg" length="326204"/><guid isPermaLink="false">f30e6e5c-7ec7-4daf-b326-2ef3a2107c5a</guid>
    <pubDate>Mon, 14 Jun 2021 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>mailbox.org – Test winner in Switzerland too!</dc:title>
    <dc:identifier>f30e6e5c-7ec7-4daf-b326-2ef3a2107c5a</dc:identifier>
    </item>
<item>
  <title>mailbox.org – Test winner in Switzerland too!</title>
  <link>https://mailbox.org/en/news/mailbox-test-winner-switzerland-too/</link>
  <description>&lt;p&gt;"Eight out of ten clouds are not trustworthy - The Swiss Linuxfabrik and the German mailbox.org scored best" is the conclusion of the renowned Swiss consumer magazine &lt;a href="https://www.ktipp.ch/" target="_blank" title="K-Tipp" rel="noopener"&gt;K-Tipp&lt;/a&gt;. Cloud providers of all sizes were put under the microscope, from Google to Dropbox to smaller providers like mailbox.org. In their test, the Swiss consumer protection agency placed particular emphasis on data protection, user-friendliness and versatility of the offer. - With 14 out of 15 possible points, mailbox.org was able to convince the editors and landed in first place together with the Swiss Linuxfabrik.&lt;/p&gt;&lt;p&gt;Only in terms of usability did mailbox.org receive "only" four out of five stars; Apple's iCloud was more convincing to the testers from Switzerland. Overall, however, Apple's service came in last due to a lack of data protection, versatility and the absence of an Android app - only Microsoft and Dropbox scored worse.&lt;/p&gt;&lt;p&gt;Other candidates in the test were Linuxfabrik (also 14 out of 15 points), Mega (11), Swisscom Mycloud light (11), Backup ONE (10), Tresorit (10), Google Drive (9), Apple Icloud (8), Microsoft OneDrive (7) and in last place Dropbox (5). We find it striking that four of the five free services ended up at the bottom of the field; only Mega from New Zealand/Canada was able to take one of the top places, but it probably "annoys" its users with advertising in apps and mails.&lt;/p&gt;&lt;h3&gt;About K-Tipp&lt;/h3&gt;&lt;p&gt;With its focus on consumer protection, &lt;a href="https://www.ktipp.ch/" target="_blank" title="K-Tipp" rel="noopener"&gt;K-Tipp&lt;/a&gt; is published every fortnight with a circulation of more than 250,000 copies and reaches almost one million readers. &lt;a href="https://www.ktipp.ch/artikel/artikeldetail/acht-von-zehn-clouds-sind-nicht-vertrauenswuerdig/" target="_blank" title="German version of the full report" rel="noopener"&gt;The full test report is available here&lt;/a&gt; after taking out an online subscription (from 8 Swiss francs).&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-celebration.jpeg?itok=wIZsodf0" type="image/jpeg" length="326204"/><guid isPermaLink="false">f30e6e5c-7ec7-4daf-b326-2ef3a2107c5a</guid>
    <pubDate>Mon, 14 Jun 2021 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>mailbox.org – Test winner in Switzerland too!</dc:title>
    <dc:identifier>f30e6e5c-7ec7-4daf-b326-2ef3a2107c5a</dc:identifier>
    </item>
<item>
  <title>New G-10 law aims to monitor users more directly</title>
  <link>https://mailbox.org/en/news/rushed-through-back-door-new-g-10-bill-introduces-measures-direct-surveillance-users/</link>
  <description>&lt;p&gt;Last Thursday, 10 June, the German government coalition of SPD, CDU, and CSU voted in a bill that may open the door to widespread state surveillance. Hastily rushed through, an exacerbating amendment was introduced and passed at the last minute, which went far beyond the previously agreed changes, and which was controversially debated even within the governing coalition. Although app vendors and e-mail services such as mailbox.org are explicitly excluded, this kind of legislation massively undermines the security and trust of Internet providers, explains Peer Heinlein.&lt;/p&gt;&lt;p&gt;The bill prescribes how exactly peoples' telecommunications secrecy rights as defined in the German basic law, article 10, and limited in paragraph 2, are to be applied by investigative authorities and intelligence services. The reforms that just went through parliament extend the measures for lawful telecommunication interception and aim to force the providers of communication services to limit the security and integrity of their own services so as to support the intelligence services in performing surveillance on people.&lt;/p&gt;&lt;p&gt;Not only does the new bill mandate Internet providers to assist in the setup of devices but also in the supply of any information that is required for the installation of surveillance software. It also enables the intelligence services to obtain data from cell phones, for example. Critics of the new legislation have pointed out that the very security vulnerabilities that need to be maintained for state surveillance software to work properly can also be exploited by common criminals. More generally, this approach will only serve to increase the general feeling of mistrust and lack of security among Internet users.&lt;/p&gt;&lt;p&gt;In worst case, telecommunication service providers could be forced to spy on their own customers, something the parliamentary party “Die Linke” compared to the aiding and abetting of (state-sponsored) hacking. Unsurprisingly, constitutional complaints concerning this issue have been lining up already. Konstantin von Notz, expert for domestic and digital policy from the green party called the bill „disastrous“ and said it was „unbearable” that this particular bill, which so massively restricts individual freedoms, had been „disguised” among 70 other agenda points of the home affairs committee, one day before the vote.&lt;/p&gt;&lt;p&gt;mailbox.org-CEO Peer Heinlein says:&lt;/p&gt;&lt;p&gt;&lt;em&gt;„There is no question that investigative authorities and intelligence services need to keep up with modern technology to fulfil their mandate in the 21st century. No one wants to see those who work in law enforcement to be undermined or prevented from carrying out their duties. It always has been and still is possible for them to do their job. However, the idea of maintaining common security vulnerabilities because these are required for the so-called lawful interception of telecommunications is a risk for everyone’s security and inconsistent with the basic rights granted by our constitutional law. Any constitutional state should aim to protect the security of its citizens, and not work to undermine it. In our country, the separation of powers with checks and balances present a higher good to society, which stands in contrast to these plans, which effectively try to conscript providers to act as deputy law enforcement officers.&lt;/em&gt;&lt;/p&gt;&lt;p&gt;&lt;em&gt;The haste with which the amendments were pushed through is clear evidence that those responsible were very well aware of their wrongdoing. Once again, this federal government has chosen to ignore the provisions issued by our constitutional judges and so, this bill will - once again - be smashed by the federal constitutional court in Karlsruhe.&lt;/em&gt;&lt;/p&gt;&lt;p&gt;&lt;em&gt;We at mailbox.org will never consider ourselves to be an extension of law enforcement. We will continue to protect the privacy of our users, for example by promoting and further developing end-to-end encryption, and making it as easy as possible to use for people. mailbox.org will also continue to invest in the development of technologies that enforce privacy by design to make sure service providers do not have access to the communication contents of their users.“&lt;/em&gt;&lt;/p&gt;&lt;p&gt;Together with our many partners, mailbox.org has contributed to an &lt;a href="https://www.ccc.de/system/uploads/317/original/210601_Gemeinsamer_Brief_G10_BVerfSchG_updated_.pdf" target="_blank" title="open letter" rel="noopener"&gt;open letter&lt;/a&gt; that argued against the original plans of the federal government that suggested a massive expansion of digital surveillance as well as a ban of the use of effective encryption techniques.&lt;/p&gt;&lt;p&gt;Aside from mailbox.org, signatories of the open letter include our colleagues at Tutanota and mail.de, the Chaos Computer Club, Facebook, Google and many other affected service providers. We call for the legislature to cease introducing any further measures that are deemed to endanger the security of all citizens.&lt;/p&gt;&lt;p&gt;The open letter also demands that any legislation that has such significance be prepared carefully and prudently, and not hurried along at the end of a legislative period. The ultimate mandate of parliament and government is to protect citizens and businesses, and we think this means the development of encryption technology should not be weakened but promoted and encouraged to maintain the integrity of all digital communication.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-04/mailbox-news-und-updates-warnung.jpg?itok=reW9cU74" type="image/jpeg" length="238141"/><guid isPermaLink="false">602967c6-bbc2-4f0e-b0dd-21cbcbf4e0f6</guid>
    <pubDate>Fri, 11 Jun 2021 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>New G-10 law aims to monitor users more directly</dc:title>
    <dc:identifier>602967c6-bbc2-4f0e-b0dd-21cbcbf4e0f6</dc:identifier>
    </item>
<item>
  <title>New G-10 law aims to monitor users more directly</title>
  <link>https://mailbox.org/en/news/rushed-through-back-door-new-g-10-bill-introduces-measures-direct-surveillance-users/</link>
  <description>&lt;p&gt;Last Thursday, 10 June, the German government coalition of SPD, CDU, and CSU voted in a bill that may open the door to widespread state surveillance. Hastily rushed through, an exacerbating amendment was introduced and passed at the last minute, which went far beyond the previously agreed changes, and which was controversially debated even within the governing coalition. Although app vendors and e-mail services such as mailbox.org are explicitly excluded, this kind of legislation massively undermines the security and trust of Internet providers, explains Peer Heinlein.&lt;/p&gt;&lt;p&gt;The bill prescribes how exactly peoples' telecommunications secrecy rights as defined in the German basic law, article 10, and limited in paragraph 2, are to be applied by investigative authorities and intelligence services. The reforms that just went through parliament extend the measures for lawful telecommunication interception and aim to force the providers of communication services to limit the security and integrity of their own services so as to support the intelligence services in performing surveillance on people.&lt;/p&gt;&lt;p&gt;Not only does the new bill mandate Internet providers to assist in the setup of devices but also in the supply of any information that is required for the installation of surveillance software. It also enables the intelligence services to obtain data from cell phones, for example. Critics of the new legislation have pointed out that the very security vulnerabilities that need to be maintained for state surveillance software to work properly can also be exploited by common criminals. More generally, this approach will only serve to increase the general feeling of mistrust and lack of security among Internet users.&lt;/p&gt;&lt;p&gt;In worst case, telecommunication service providers could be forced to spy on their own customers, something the parliamentary party “Die Linke” compared to the aiding and abetting of (state-sponsored) hacking. Unsurprisingly, constitutional complaints concerning this issue have been lining up already. Konstantin von Notz, expert for domestic and digital policy from the green party called the bill „disastrous“ and said it was „unbearable” that this particular bill, which so massively restricts individual freedoms, had been „disguised” among 70 other agenda points of the home affairs committee, one day before the vote.&lt;/p&gt;&lt;p&gt;mailbox.org-CEO Peer Heinlein says:&lt;/p&gt;&lt;p&gt;&lt;em&gt;„There is no question that investigative authorities and intelligence services need to keep up with modern technology to fulfil their mandate in the 21st century. No one wants to see those who work in law enforcement to be undermined or prevented from carrying out their duties. It always has been and still is possible for them to do their job. However, the idea of maintaining common security vulnerabilities because these are required for the so-called lawful interception of telecommunications is a risk for everyone’s security and inconsistent with the basic rights granted by our constitutional law. Any constitutional state should aim to protect the security of its citizens, and not work to undermine it. In our country, the separation of powers with checks and balances present a higher good to society, which stands in contrast to these plans, which effectively try to conscript providers to act as deputy law enforcement officers.&lt;/em&gt;&lt;/p&gt;&lt;p&gt;&lt;em&gt;The haste with which the amendments were pushed through is clear evidence that those responsible were very well aware of their wrongdoing. Once again, this federal government has chosen to ignore the provisions issued by our constitutional judges and so, this bill will - once again - be smashed by the federal constitutional court in Karlsruhe.&lt;/em&gt;&lt;/p&gt;&lt;p&gt;&lt;em&gt;We at mailbox.org will never consider ourselves to be an extension of law enforcement. We will continue to protect the privacy of our users, for example by promoting and further developing end-to-end encryption, and making it as easy as possible to use for people. mailbox.org will also continue to invest in the development of technologies that enforce privacy by design to make sure service providers do not have access to the communication contents of their users.“&lt;/em&gt;&lt;/p&gt;&lt;p&gt;Together with our many partners, mailbox.org has contributed to an &lt;a href="https://www.ccc.de/system/uploads/317/original/210601_Gemeinsamer_Brief_G10_BVerfSchG_updated_.pdf" target="_blank" title="open letter" rel="noopener"&gt;open letter&lt;/a&gt; that argued against the original plans of the federal government that suggested a massive expansion of digital surveillance as well as a ban of the use of effective encryption techniques.&lt;/p&gt;&lt;p&gt;Aside from mailbox.org, signatories of the open letter include our colleagues at Tutanota and mail.de, the Chaos Computer Club, Facebook, Google and many other affected service providers. We call for the legislature to cease introducing any further measures that are deemed to endanger the security of all citizens.&lt;/p&gt;&lt;p&gt;The open letter also demands that any legislation that has such significance be prepared carefully and prudently, and not hurried along at the end of a legislative period. The ultimate mandate of parliament and government is to protect citizens and businesses, and we think this means the development of encryption technology should not be weakened but promoted and encouraged to maintain the integrity of all digital communication.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-04/mailbox-news-und-updates-warnung.jpg?itok=reW9cU74" type="image/jpeg" length="238141"/><guid isPermaLink="false">602967c6-bbc2-4f0e-b0dd-21cbcbf4e0f6</guid>
    <pubDate>Fri, 11 Jun 2021 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>New G-10 law aims to monitor users more directly</dc:title>
    <dc:identifier>602967c6-bbc2-4f0e-b0dd-21cbcbf4e0f6</dc:identifier>
    </item>
<item>
  <title>Switch discount for tariff change extended</title>
  <link>https://mailbox.org/en/news/introductory-discount-new-price-plans-extended-news-team-accounts/</link>
  <description>&lt;p&gt;After the introduction of our new pricing in mid-April we received a lot of positive feedback from our users but also criticism. We have taken this into account and made some adjustments to the new price plans. For example, the number of possible e-mail aliases per account has been increased, and the LIGHT price plan is now also available for team accounts, which is something that especially our user families have asked for.&lt;/p&gt;&lt;p&gt;We are very pleased with the positive feedback on the &lt;a href="https://mailbox.org/en/services#price-plans" target="_blank" title="new price plan structure" rel="noopener"&gt;new price plan structure&lt;/a&gt; and, together with our attractive switch offer for existing customers, this has already led to many tariff changes. Good reasons for switching to the new tariffs are:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Individual mail and cloud storage&lt;/li&gt;&lt;li&gt;More aliases for your custom domain&lt;/li&gt;&lt;li&gt;Support over the phone coming in summer (PREMIUM plan)&lt;/li&gt;&lt;li&gt;Generous introductory discount when you switch&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Existing customers who prefer to keep their old plan can do so – no action is required. Everyone else should take note of our special offer for those who want to switch:&lt;/p&gt;&lt;h2&gt;50% discount for switching plans – extended until 15 June 2021&lt;/h2&gt;&lt;p&gt;We would like all our existing customers to benefit from our introductory offer when they switch from their old price plan to a new STANDARD or PREMIUM plan. A technical problem has unfortunately prevented some of those on team accounts with joint billing to make use of the offer. This will be fixed during next week, and to make sure no one loses out because of this issue, we have extended our introductory offer for existing customers until 15 June 2021.&lt;/p&gt;&lt;h3&gt;How to use the 50 % discount for switching plans&lt;/h3&gt;&lt;p&gt;Only once during the introductory period, existing customers receive two years in the STANDARD or PREMIUM plan for the price of one year. How does it work? Switch your price plan to STANDARD or PREMIUM and choose the option “24 months for the price of 12 months” when paying for your subscription. This option will be available in the drop-down menu for the payment method.&lt;/p&gt;&lt;p&gt;1. Switch your plan: Settings → mailbox.org → Contract and Fees → Switch to a STANDARD or PREMIUM price plan&lt;br&gt;2. Select the offer here: Settings → mailbox.org → Add Credit to your Balance → Select the discount from the drop-down menu: “24 months for the price of 12 months”&lt;/p&gt;&lt;h3&gt;Important&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;If you want to stay on your current price plan then you don’t need to do anything.&lt;/li&gt;&lt;li&gt;Note that once your account has been switched over to a new price plan, you can no longer go back to any of the legacy plans afterwards.&lt;/li&gt;&lt;li&gt;When switching from a legacy plan to one of the new price plans, your credit balance will be transferred automatically. The amount will be converted to reflect a corresponding contract period.&lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;News for team accounts&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;Team account members with joint billing can switch to a new price plan together, during next week&lt;/li&gt;&lt;li&gt;Members of team accounts with an @mailbox.org address can go LIGHT&lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;Switching plan with joint billing&lt;/h3&gt;&lt;p&gt;Those users who manage a team account with joint billing can comfortably move the entire team to the new price plans, during next week.&lt;/p&gt;&lt;p&gt;Individual team members will be able to switch to the LIGHT plan if they use @mailbox.org e-mail addresses. If they use an e-mail address with a custom domain name then a switch to the STANDARD plan will be required. (Please note that LIGHT accounts may only share calendars and contacts with other team members.)&lt;/p&gt;&lt;h3&gt;Switching plan with separate billing&lt;/h3&gt;&lt;p&gt;If billing is separate for all team members then admins and members can each switch individually to a new price plan.&lt;/p&gt;&lt;p&gt;Individual team members can now also choose the LIGHT price plan if they use @mailbox.org e-mail addresses. If they use an e-mail address with a custom domain name then a switch to the STANDARD plan will still be required. (Please note that LIGHT accounts may only share calendars and contacts with other team members.)&lt;/p&gt;&lt;p&gt;Your mailbox.org-Team&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-team-2.jpeg?itok=JunenBYW" type="image/jpeg" length="404224"/><guid isPermaLink="false">86070d4a-2040-4087-83ce-855db8bb54cf</guid>
    <pubDate>Thu, 27 May 2021 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Switch discount for tariff change extended</dc:title>
    <dc:identifier>86070d4a-2040-4087-83ce-855db8bb54cf</dc:identifier>
    </item>
<item>
  <title>Switch discount for tariff change extended</title>
  <link>https://mailbox.org/en/news/introductory-discount-new-price-plans-extended-news-team-accounts/</link>
  <description>&lt;p&gt;After the introduction of our new pricing in mid-April we received a lot of positive feedback from our users but also criticism. We have taken this into account and made some adjustments to the new price plans. For example, the number of possible e-mail aliases per account has been increased, and the LIGHT price plan is now also available for team accounts, which is something that especially our user families have asked for.&lt;/p&gt;&lt;p&gt;We are very pleased with the positive feedback on the &lt;a href="https://mailbox.org/en/services#price-plans" target="_blank" title="new price plan structure" rel="noopener"&gt;new price plan structure&lt;/a&gt; and, together with our attractive switch offer for existing customers, this has already led to many tariff changes. Good reasons for switching to the new tariffs are:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Individual mail and cloud storage&lt;/li&gt;&lt;li&gt;More aliases for your custom domain&lt;/li&gt;&lt;li&gt;Support over the phone coming in summer (PREMIUM plan)&lt;/li&gt;&lt;li&gt;Generous introductory discount when you switch&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Existing customers who prefer to keep their old plan can do so – no action is required. Everyone else should take note of our special offer for those who want to switch:&lt;/p&gt;&lt;h2&gt;50% discount for switching plans – extended until 15 June 2021&lt;/h2&gt;&lt;p&gt;We would like all our existing customers to benefit from our introductory offer when they switch from their old price plan to a new STANDARD or PREMIUM plan. A technical problem has unfortunately prevented some of those on team accounts with joint billing to make use of the offer. This will be fixed during next week, and to make sure no one loses out because of this issue, we have extended our introductory offer for existing customers until 15 June 2021.&lt;/p&gt;&lt;h3&gt;How to use the 50 % discount for switching plans&lt;/h3&gt;&lt;p&gt;Only once during the introductory period, existing customers receive two years in the STANDARD or PREMIUM plan for the price of one year. How does it work? Switch your price plan to STANDARD or PREMIUM and choose the option “24 months for the price of 12 months” when paying for your subscription. This option will be available in the drop-down menu for the payment method.&lt;/p&gt;&lt;p&gt;1. Switch your plan: Settings → mailbox.org → Contract and Fees → Switch to a STANDARD or PREMIUM price plan&lt;br&gt;2. Select the offer here: Settings → mailbox.org → Add Credit to your Balance → Select the discount from the drop-down menu: “24 months for the price of 12 months”&lt;/p&gt;&lt;h3&gt;Important&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;If you want to stay on your current price plan then you don’t need to do anything.&lt;/li&gt;&lt;li&gt;Note that once your account has been switched over to a new price plan, you can no longer go back to any of the legacy plans afterwards.&lt;/li&gt;&lt;li&gt;When switching from a legacy plan to one of the new price plans, your credit balance will be transferred automatically. The amount will be converted to reflect a corresponding contract period.&lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;News for team accounts&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;Team account members with joint billing can switch to a new price plan together, during next week&lt;/li&gt;&lt;li&gt;Members of team accounts with an @mailbox.org address can go LIGHT&lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;Switching plan with joint billing&lt;/h3&gt;&lt;p&gt;Those users who manage a team account with joint billing can comfortably move the entire team to the new price plans, during next week.&lt;/p&gt;&lt;p&gt;Individual team members will be able to switch to the LIGHT plan if they use @mailbox.org e-mail addresses. If they use an e-mail address with a custom domain name then a switch to the STANDARD plan will be required. (Please note that LIGHT accounts may only share calendars and contacts with other team members.)&lt;/p&gt;&lt;h3&gt;Switching plan with separate billing&lt;/h3&gt;&lt;p&gt;If billing is separate for all team members then admins and members can each switch individually to a new price plan.&lt;/p&gt;&lt;p&gt;Individual team members can now also choose the LIGHT price plan if they use @mailbox.org e-mail addresses. If they use an e-mail address with a custom domain name then a switch to the STANDARD plan will still be required. (Please note that LIGHT accounts may only share calendars and contacts with other team members.)&lt;/p&gt;&lt;p&gt;Your mailbox.org-Team&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-team-2.jpeg?itok=JunenBYW" type="image/jpeg" length="404224"/><guid isPermaLink="false">86070d4a-2040-4087-83ce-855db8bb54cf</guid>
    <pubDate>Thu, 27 May 2021 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Switch discount for tariff change extended</dc:title>
    <dc:identifier>86070d4a-2040-4087-83ce-855db8bb54cf</dc:identifier>
    </item>
<item>
  <title>EU wants to ban encryption</title>
  <link>https://mailbox.org/en/news/it-companies-warn-open-letter-eu-wants-ban-encryption/</link>
  <description>&lt;p&gt;Together with the companies Tutanota, Boxcryptor, Cryptomator, mail.de, Mailfence, Praxonomy, and Tresorit, mailbox.org has written an &lt;a href="https://tutanota.com/blog/posts/european-autonomy-in-danger/" target="_blank" title="Tutanota: Joint open letter for right to privacy" rel="noopener"&gt;open letter to the EU&lt;/a&gt; strongly criticizing upcoming plans for communication surveillance.&lt;/p&gt;&lt;h2&gt;A future without privacy?&lt;/h2&gt;&lt;p&gt;In the fight against child pornography, the EU Council of Ministers endorsed the proposal to repeal the E-Privacy directive with a &lt;a href="https://edri.org/our-work/is-surveilling-children-really-protecting-them-our-concerns-on-the-interim-csam-regulation/" target="_blank" title="EDRi: Is surveilling children really protecting them? Our concerns on the interim CSAM regulation" rel="noopener"&gt;transitional regulation&lt;/a&gt; in late 2020. Before that, in July, the EU Commission had declared encryption to be the main obstacle in the fight against child molesters. More recently, in December, the EU Parliament's Committee on Civil Liberties, Justice and Home Affairs also voted to restrict data protection in favour of law enforcement.&lt;/p&gt;&lt;p&gt;Only end-to-end encryption is able to guarantee confidential communication and both privacy and secrecy of correspondence between users. But in the fight against child pornography, domestic politicians and legislators have identified it as the core problem and would prefer to ban it.&lt;/p&gt;&lt;h2&gt;European values under attack&lt;/h2&gt;&lt;p&gt;According to the signatories of the open letter, any obligation to screen all private chat messages contradicts European principles of data protection. The authors are convinced: Allowing access to encrypted communication by private organizations and public authorities is incompatible with a strong EU as a technology location, It would enormously damage European ideals and the indisputable foundations of our democracy, namely freedom of expression and the protection of privacy.&lt;/p&gt;&lt;p&gt;mailbox.org CEO Peer Heinlein comments: “Nobody wants to limit the prosecution of child pornography. But the perpetrators in these circles know how to evade and digitally protect themselves. The current legislative initiatives will not bring about any change here.&lt;/p&gt;&lt;p&gt;Instead, the restriction of encrypted communication causes great harm to society and is a profound encroachment on the fundamental rights of freedom of thought and expression of all citizens. The protection of secure communication must not be sacrificed here, no: It is under attack and must be protected and expanded.”&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-04/mailbox-news-und-updates-warnung.jpg?itok=reW9cU74" type="image/jpeg" length="238141"/><guid isPermaLink="false">e793801b-621a-4526-a72f-fea1b5fc9bd5</guid>
    <pubDate>Thu, 15 Apr 2021 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>EU wants to ban encryption</dc:title>
    <dc:identifier>e793801b-621a-4526-a72f-fea1b5fc9bd5</dc:identifier>
    </item>
<item>
  <title>EU wants to ban encryption</title>
  <link>https://mailbox.org/en/news/it-companies-warn-open-letter-eu-wants-ban-encryption/</link>
  <description>&lt;p&gt;Together with the companies Tutanota, Boxcryptor, Cryptomator, mail.de, Mailfence, Praxonomy, and Tresorit, mailbox.org has written an &lt;a href="https://tutanota.com/blog/posts/european-autonomy-in-danger/" target="_blank" title="Tutanota: Joint open letter for right to privacy" rel="noopener"&gt;open letter to the EU&lt;/a&gt; strongly criticizing upcoming plans for communication surveillance.&lt;/p&gt;&lt;h2&gt;A future without privacy?&lt;/h2&gt;&lt;p&gt;In the fight against child pornography, the EU Council of Ministers endorsed the proposal to repeal the E-Privacy directive with a &lt;a href="https://edri.org/our-work/is-surveilling-children-really-protecting-them-our-concerns-on-the-interim-csam-regulation/" target="_blank" title="EDRi: Is surveilling children really protecting them? Our concerns on the interim CSAM regulation" rel="noopener"&gt;transitional regulation&lt;/a&gt; in late 2020. Before that, in July, the EU Commission had declared encryption to be the main obstacle in the fight against child molesters. More recently, in December, the EU Parliament's Committee on Civil Liberties, Justice and Home Affairs also voted to restrict data protection in favour of law enforcement.&lt;/p&gt;&lt;p&gt;Only end-to-end encryption is able to guarantee confidential communication and both privacy and secrecy of correspondence between users. But in the fight against child pornography, domestic politicians and legislators have identified it as the core problem and would prefer to ban it.&lt;/p&gt;&lt;h2&gt;European values under attack&lt;/h2&gt;&lt;p&gt;According to the signatories of the open letter, any obligation to screen all private chat messages contradicts European principles of data protection. The authors are convinced: Allowing access to encrypted communication by private organizations and public authorities is incompatible with a strong EU as a technology location, It would enormously damage European ideals and the indisputable foundations of our democracy, namely freedom of expression and the protection of privacy.&lt;/p&gt;&lt;p&gt;mailbox.org CEO Peer Heinlein comments: “Nobody wants to limit the prosecution of child pornography. But the perpetrators in these circles know how to evade and digitally protect themselves. The current legislative initiatives will not bring about any change here.&lt;/p&gt;&lt;p&gt;Instead, the restriction of encrypted communication causes great harm to society and is a profound encroachment on the fundamental rights of freedom of thought and expression of all citizens. The protection of secure communication must not be sacrificed here, no: It is under attack and must be protected and expanded.”&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-04/mailbox-news-und-updates-warnung.jpg?itok=reW9cU74" type="image/jpeg" length="238141"/><guid isPermaLink="false">e793801b-621a-4526-a72f-fea1b5fc9bd5</guid>
    <pubDate>Thu, 15 Apr 2021 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>EU wants to ban encryption</dc:title>
    <dc:identifier>e793801b-621a-4526-a72f-fea1b5fc9bd5</dc:identifier>
    </item>
<item>
  <title>The new plans</title>
  <link>https://mailbox.org/en/news/new-price-plans-available-mailboxorg/</link>
  <description>&lt;p&gt;Seven years after we started out with mailbox.org, we are now introducing a new set of price plans. By doing so, we are creating a simpler and more flexible pricing system that is easier to manage, and that also reflects many ideas and feedback received from our active user base.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;As of today, the new price plans STANDARD, PREMIUM and LIGHT are available to all private and business customers.&lt;/li&gt;&lt;li&gt;Existing customers can choose to either remain on their old plan or switch over to a new plan.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Previously, we offered the packages „Secure Mail“, „Team Mail“ and „Office“. These came with different allowances for storage space, which were not very flexible. Our new price plans STANDARD, PREMIUM, and LIGHT have been specifically designed with the different feature and support needs of our users in mind. Additional storage capacity for mails and files on the Drive can now be added more flexibly than before.&lt;/p&gt;&lt;h2&gt;Three e-mail packages: simple and flexible&lt;/h2&gt;&lt;h3&gt;Our STANDARD plan: The fully-featured allrounder&lt;/h3&gt;&lt;p&gt;Our new STANDARD price plan offers a secure and ad-free communication package with e-mail, calendar, address book, online office suite, cloud storage, web chat, and video conferencing for only € 3 per month – a solution that makes data protection easy, includes groupware functionality, and supports the integration of a custom domain name. Customers choosing the STANDARD plan will receive a comprehensive package that includes all mailbox.org features, as well as 10 GB mail storage and 5 GB cloud storage for your data.&lt;/p&gt;&lt;p&gt;Introducing the new STANDARD plan has also given us an opportunity to roll out new features for our users. Right from the start, the popular „Dark theme“ will be available, as well as an increased number of aliases. Users choosing this plan can now also flexibly book additional storage capacity, as required.&lt;/p&gt;&lt;h3&gt;Our PREMIUM plan: For those who require more extras&lt;/h3&gt;&lt;p&gt;Get all available features plus 25 GB mail storage and 50 GB cloud storage in our PREMIUM plan for € 9 per month. This package also includes priority support and additional service options for power users. More storage space can be added to this package at a discount.&lt;/p&gt;&lt;p&gt;The new PREMIUM plan does not only offer improved support for customers, as helpdesk support tickets will be handled with higher priority. It also provides the necessary resources for us to offer even better service: From summer 2021, we are introducing a call-back service, where our support team will be dealing with any issues that our PREMIUM users may have directly and individually over the phone.&lt;/p&gt;&lt;h3&gt;Our LIGHT plan: Secure e-mail at a small price&lt;/h3&gt;&lt;p&gt;Our new plans continue to offer our basic package: secure, economical, ad-free, encrypted e-mail, with 2 GB mail storage, calendar and address book from € 1 per month. Our LIGHT price plan is ideal for those who want to use an e-mail service that is free of ads, offers our best data protection features but without most of the other extras, and limited support options. This package comes at a bargain price of € 1 per month.&lt;/p&gt;&lt;p&gt;New customers will always start out with a free trial in either the STANDARD or the PREMIUM plan and given the opportunity to test all features free of charge for 30 days. After the trial period, everyone can then decide for themselves which of the three plans works best for them.&lt;/p&gt;&lt;h2&gt;Existing customers get to choose&lt;/h2&gt;&lt;p&gt;Many who already have an account at mailbox.org will find that the new price plans are cheaper than their existing plan: For example, users previously required one of our “Office” packages for a minimum of € 4.50 per month to access all features of the mailbox.org online office – this is now available for € 3 per month in the STANDARD plan.&lt;/p&gt;&lt;p&gt;However, for some customers the monthly amount they need to pay may go up slightly (even though they get more for their money). As this is a consequence of the restructuring of our features and prices, nobody will be required to change if they don’t want to. Existing customers are given a choice to either switch to one of our new price plans or simply remain on their old plan, if preferred.&lt;/p&gt;&lt;p&gt;For example, consider the new STANDARD plan: With € 3 per month, it appears slightly more expensive than the previous “Team Mail” or “MailXL” plans which were € 2.50 per month. However, customers who pay for a full year in advance benefit from a bonus where they get 12 months but only pay for 10. That means the overall price remains the same – it actually may be less than before, because we now also cover the transaction charges for any PayPal or credit card payments, which would previously have come on top of the monthly fee.&lt;/p&gt;&lt;p&gt;So, all existing customers have full control: If you like one of the new plans, it is very simple to switch over. If you like your old plan better, then just stay on that plan, no problem. Please consider carefully which option works better for you. Once switched over to one of our new price plans it is not possible to go back to any of the old plans.&lt;/p&gt;&lt;h3&gt;50% introductory discount for existing customers&lt;/h3&gt;&lt;p&gt;Any existing customers switching plans by 31 May 2021 get a one-time special offer from us: Choose either the STANDARD plan or the PREMIUM plan and receive 24 months for the price of 12 months with the next deposit!&lt;/p&gt;&lt;p&gt;In effect, this means those who decide to switch early will receive a 50% discount on their monthly fee over the next two years – which will lower the monthly amount expended for the STANDARD plan to € 1.50 a month, and for the PREMIUM plan to € 4.50 a month over two years.&lt;/p&gt;&lt;h2&gt;Further news and updates&lt;/h2&gt;&lt;h3&gt;No transaction charges on new plans for all payment methods&lt;/h3&gt;&lt;p&gt;When paying your account fees for any of the new price plans, we will cover the transaction charges for any payments made via PayPal or credit card, saving you between 35 to 60 cents per transaction. Users on the STANDARD and PREMIUM plans can pay monthly, if they want, and so avoid committing to a minimum contract term. However, in order for us to be able to offer free payments in our cheapest LIGHT plan for € 1 per month as well, customers on the LIGHT plan will need to pay for a full year in advance.&lt;/p&gt;&lt;h3&gt;Advance payment discount&lt;/h3&gt;&lt;p&gt;Customers in the STANDARD or PREMIUM plan who pay their account fee as one annual lump sum help us to keep our prices low, and we are happy to give something back in return in the form of free bonus months and other varying benefits! Currently, if you pay for 10 months in advance, you get 2 bonus months on top for free.&lt;/p&gt;&lt;h3&gt;Migration service for moving your mail account to us is now free&lt;/h3&gt;&lt;p&gt;Our e-mail migration service allows users to conveniently transfer their e-mail account data and settings from another provider to mailbox.org. This previously attracted a charge of € 3 per account. From now on, this service is included at no extra cost in our STANDARD and PREMIUM price plans. Our specialist partner audriga will stand ready to facilitate the migration of an unlimited number of e-mail accounts from any supported provider to mailbox.org. In addition to e-mail, this includes the transfer of calendar, address books, and files on a Drive cloud storage, if supported by your previous provider. This feature can be used by any new customers moving to mailbox.org, even if they are still within their free trial period.&lt;/p&gt;&lt;h3&gt;Contract duration of new price plans&lt;/h3&gt;&lt;p&gt;Unlike the legacy packages, our new price plans are no longer based on prepaid credit. Instead, there is now a definitive contract term with a fixed end date, and the actual length is defined by the amount paid in. When switching from a legacy package to one of our new price plans, any existing credit will be automatically used as a payment and so, determine the initial end date of the contract under the new plan. We needed to make this change as the current legislation around prepaid services would have made it difficult to roll out the new plans under the old system. It is still possible to switch between plans, as any change in price will be reflected by a different end date under your new plan.&lt;/p&gt;&lt;h2&gt;FAQ&lt;/h2&gt;I already have a mailbox.org account. How can I switch to one of the new plans?&lt;p&gt;Log in as usual and visit the settings (cogwheel symbol in the upper right corner of the browser window). To switch plan, go to Settings -&amp;gt; mailbox.org -&amp;gt; Contract and Fees.&lt;br&gt;Please note: Once you have changed to a new price plan, it won’t be possible to go back to any of the legacy plans.&lt;/p&gt;How can I access the special offer for existing customers?&lt;p&gt;After switching from your old plan to a new STANDARD or PREMIUM plan, an additional option will become available for selection on the page where you normally pay your account fees: “24 months for the price of 12 months”.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Switch plan here: Settings -&amp;gt; mailbox.org -&amp;gt; Contract and Fees&lt;/li&gt;&lt;li&gt;Select the offer here: Settings -&amp;gt; mailbox.org -&amp;gt; Add Credit to your Balance&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;This discount is only available for customers switching plans to STANDARD or PREMIUM by 31 May 2021.&lt;/p&gt;I like my old price plan and would like to keep it. Do I have to change to a new plan?&lt;p&gt;No, you don’t have to switch if you don’t want to. If you prefer staying on your existing plan, there is nothing you need to do.&lt;/p&gt;As an existing customer, can I still switch between the old price plans?&lt;p&gt;Yes. Existing customers can still switch between the old price plans by increasing or reducing the storage on the contract page.&lt;/p&gt;Can I open a new account using an old price plan?&lt;p&gt;No, that is not possible. New accounts are only available with our new price plans.&lt;/p&gt;I have a Team Mail account. Will it be possible to set up additional inboxes for this account under the new plans?&lt;p&gt;Yes, you can keep using your Team Mail account but any new inboxes need to be set up using either the PREMIUM or the STANDARD price plan.&lt;/p&gt;How can I access the free e-mail migration service?&lt;p&gt;Log in to mailbox.org and go to Settings -&amp;gt; mailbox.org -&amp;gt; E-mail migration service. Click on the link to visit the audriga website and move your existing account in a few simple steps. &lt;a href="https://kb.mailbox.org/display/MBOKBEN/Audriga+-+Your+e-mail+migration+service" target="_blank" title="Click here for more information about the e-mail migration service" rel="noopener"&gt;Click here for more information about the e-mail migration service&lt;/a&gt;&lt;/p&gt;Will future mailbox.org feature releases be available through any of the old plans?&lt;p&gt;Well, yes and no. Core functionality in relation to e-mail and security will always be available for everyone, including the legacy plans and the new LIGHT package – we will never make any compromises here. Other, additional functionality (much like the video conferencing feature we introduced recently) will from now on only be available with the new plans.&lt;/p&gt;Is there a minimum contract term?&lt;p&gt;Users on the STANDARD or PREMIUM price plans can choose to pay either monthly, every six months, or annually, and so fully control their contractual term. Larger payments help us save costs, and we reward users by giving them extra bonus months for free when they commit to stay with us for longer. However, users who are on the LIGHT plan need to pay up for a full year, as small monthly payments would be uneconomical given the associated transaction fees (which we still need to cover), so there is in effect an annual contract term for those on the LIGHT plan.&lt;/p&gt;Can I switch plan between STANDARD, PREMIUM and LIGHT?&lt;p&gt;Yes, switching between the new plans is possible. Although note that the new price plans are no longer based on pre-paid credit, meaning every payment will result in a contract term corresponding to the amount paid in. We needed to make this change as the legislation for services based on pre-paid credit is not straightforward. But that’s not a problem: When switching over to another price plan, we will simply amend the contract term accordingly, so that users who want to switch do not lose out.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-celebration.jpeg?itok=wIZsodf0" type="image/jpeg" length="326204"/><guid isPermaLink="false">633618ab-0ed6-4327-847f-1510fd1a4a0a</guid>
    <pubDate>Wed, 14 Apr 2021 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>The new plans</dc:title>
    <dc:identifier>633618ab-0ed6-4327-847f-1510fd1a4a0a</dc:identifier>
    </item>
<item>
  <title>The new plans</title>
  <link>https://mailbox.org/en/news/new-price-plans-available-mailboxorg/</link>
  <description>&lt;p&gt;Seven years after we started out with mailbox.org, we are now introducing a new set of price plans. By doing so, we are creating a simpler and more flexible pricing system that is easier to manage, and that also reflects many ideas and feedback received from our active user base.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;As of today, the new price plans STANDARD, PREMIUM and LIGHT are available to all private and business customers.&lt;/li&gt;&lt;li&gt;Existing customers can choose to either remain on their old plan or switch over to a new plan.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Previously, we offered the packages „Secure Mail“, „Team Mail“ and „Office“. These came with different allowances for storage space, which were not very flexible. Our new price plans STANDARD, PREMIUM, and LIGHT have been specifically designed with the different feature and support needs of our users in mind. Additional storage capacity for mails and files on the Drive can now be added more flexibly than before.&lt;/p&gt;&lt;h2&gt;Three e-mail packages: simple and flexible&lt;/h2&gt;&lt;h3&gt;Our STANDARD plan: The fully-featured allrounder&lt;/h3&gt;&lt;p&gt;Our new STANDARD price plan offers a secure and ad-free communication package with e-mail, calendar, address book, online office suite, cloud storage, web chat, and video conferencing for only € 3 per month – a solution that makes data protection easy, includes groupware functionality, and supports the integration of a custom domain name. Customers choosing the STANDARD plan will receive a comprehensive package that includes all mailbox.org features, as well as 10 GB mail storage and 5 GB cloud storage for your data.&lt;/p&gt;&lt;p&gt;Introducing the new STANDARD plan has also given us an opportunity to roll out new features for our users. Right from the start, the popular „Dark theme“ will be available, as well as an increased number of aliases. Users choosing this plan can now also flexibly book additional storage capacity, as required.&lt;/p&gt;&lt;h3&gt;Our PREMIUM plan: For those who require more extras&lt;/h3&gt;&lt;p&gt;Get all available features plus 25 GB mail storage and 50 GB cloud storage in our PREMIUM plan for € 9 per month. This package also includes priority support and additional service options for power users. More storage space can be added to this package at a discount.&lt;/p&gt;&lt;p&gt;The new PREMIUM plan does not only offer improved support for customers, as helpdesk support tickets will be handled with higher priority. It also provides the necessary resources for us to offer even better service: From summer 2021, we are introducing a call-back service, where our support team will be dealing with any issues that our PREMIUM users may have directly and individually over the phone.&lt;/p&gt;&lt;h3&gt;Our LIGHT plan: Secure e-mail at a small price&lt;/h3&gt;&lt;p&gt;Our new plans continue to offer our basic package: secure, economical, ad-free, encrypted e-mail, with 2 GB mail storage, calendar and address book from € 1 per month. Our LIGHT price plan is ideal for those who want to use an e-mail service that is free of ads, offers our best data protection features but without most of the other extras, and limited support options. This package comes at a bargain price of € 1 per month.&lt;/p&gt;&lt;p&gt;New customers will always start out with a free trial in either the STANDARD or the PREMIUM plan and given the opportunity to test all features free of charge for 30 days. After the trial period, everyone can then decide for themselves which of the three plans works best for them.&lt;/p&gt;&lt;h2&gt;Existing customers get to choose&lt;/h2&gt;&lt;p&gt;Many who already have an account at mailbox.org will find that the new price plans are cheaper than their existing plan: For example, users previously required one of our “Office” packages for a minimum of € 4.50 per month to access all features of the mailbox.org online office – this is now available for € 3 per month in the STANDARD plan.&lt;/p&gt;&lt;p&gt;However, for some customers the monthly amount they need to pay may go up slightly (even though they get more for their money). As this is a consequence of the restructuring of our features and prices, nobody will be required to change if they don’t want to. Existing customers are given a choice to either switch to one of our new price plans or simply remain on their old plan, if preferred.&lt;/p&gt;&lt;p&gt;For example, consider the new STANDARD plan: With € 3 per month, it appears slightly more expensive than the previous “Team Mail” or “MailXL” plans which were € 2.50 per month. However, customers who pay for a full year in advance benefit from a bonus where they get 12 months but only pay for 10. That means the overall price remains the same – it actually may be less than before, because we now also cover the transaction charges for any PayPal or credit card payments, which would previously have come on top of the monthly fee.&lt;/p&gt;&lt;p&gt;So, all existing customers have full control: If you like one of the new plans, it is very simple to switch over. If you like your old plan better, then just stay on that plan, no problem. Please consider carefully which option works better for you. Once switched over to one of our new price plans it is not possible to go back to any of the old plans.&lt;/p&gt;&lt;h3&gt;50% introductory discount for existing customers&lt;/h3&gt;&lt;p&gt;Any existing customers switching plans by 31 May 2021 get a one-time special offer from us: Choose either the STANDARD plan or the PREMIUM plan and receive 24 months for the price of 12 months with the next deposit!&lt;/p&gt;&lt;p&gt;In effect, this means those who decide to switch early will receive a 50% discount on their monthly fee over the next two years – which will lower the monthly amount expended for the STANDARD plan to € 1.50 a month, and for the PREMIUM plan to € 4.50 a month over two years.&lt;/p&gt;&lt;h2&gt;Further news and updates&lt;/h2&gt;&lt;h3&gt;No transaction charges on new plans for all payment methods&lt;/h3&gt;&lt;p&gt;When paying your account fees for any of the new price plans, we will cover the transaction charges for any payments made via PayPal or credit card, saving you between 35 to 60 cents per transaction. Users on the STANDARD and PREMIUM plans can pay monthly, if they want, and so avoid committing to a minimum contract term. However, in order for us to be able to offer free payments in our cheapest LIGHT plan for € 1 per month as well, customers on the LIGHT plan will need to pay for a full year in advance.&lt;/p&gt;&lt;h3&gt;Advance payment discount&lt;/h3&gt;&lt;p&gt;Customers in the STANDARD or PREMIUM plan who pay their account fee as one annual lump sum help us to keep our prices low, and we are happy to give something back in return in the form of free bonus months and other varying benefits! Currently, if you pay for 10 months in advance, you get 2 bonus months on top for free.&lt;/p&gt;&lt;h3&gt;Migration service for moving your mail account to us is now free&lt;/h3&gt;&lt;p&gt;Our e-mail migration service allows users to conveniently transfer their e-mail account data and settings from another provider to mailbox.org. This previously attracted a charge of € 3 per account. From now on, this service is included at no extra cost in our STANDARD and PREMIUM price plans. Our specialist partner audriga will stand ready to facilitate the migration of an unlimited number of e-mail accounts from any supported provider to mailbox.org. In addition to e-mail, this includes the transfer of calendar, address books, and files on a Drive cloud storage, if supported by your previous provider. This feature can be used by any new customers moving to mailbox.org, even if they are still within their free trial period.&lt;/p&gt;&lt;h3&gt;Contract duration of new price plans&lt;/h3&gt;&lt;p&gt;Unlike the legacy packages, our new price plans are no longer based on prepaid credit. Instead, there is now a definitive contract term with a fixed end date, and the actual length is defined by the amount paid in. When switching from a legacy package to one of our new price plans, any existing credit will be automatically used as a payment and so, determine the initial end date of the contract under the new plan. We needed to make this change as the current legislation around prepaid services would have made it difficult to roll out the new plans under the old system. It is still possible to switch between plans, as any change in price will be reflected by a different end date under your new plan.&lt;/p&gt;&lt;h2&gt;FAQ&lt;/h2&gt;I already have a mailbox.org account. How can I switch to one of the new plans?&lt;p&gt;Log in as usual and visit the settings (cogwheel symbol in the upper right corner of the browser window). To switch plan, go to Settings -&amp;gt; mailbox.org -&amp;gt; Contract and Fees.&lt;br&gt;Please note: Once you have changed to a new price plan, it won’t be possible to go back to any of the legacy plans.&lt;/p&gt;How can I access the special offer for existing customers?&lt;p&gt;After switching from your old plan to a new STANDARD or PREMIUM plan, an additional option will become available for selection on the page where you normally pay your account fees: “24 months for the price of 12 months”.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Switch plan here: Settings -&amp;gt; mailbox.org -&amp;gt; Contract and Fees&lt;/li&gt;&lt;li&gt;Select the offer here: Settings -&amp;gt; mailbox.org -&amp;gt; Add Credit to your Balance&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;This discount is only available for customers switching plans to STANDARD or PREMIUM by 31 May 2021.&lt;/p&gt;I like my old price plan and would like to keep it. Do I have to change to a new plan?&lt;p&gt;No, you don’t have to switch if you don’t want to. If you prefer staying on your existing plan, there is nothing you need to do.&lt;/p&gt;As an existing customer, can I still switch between the old price plans?&lt;p&gt;Yes. Existing customers can still switch between the old price plans by increasing or reducing the storage on the contract page.&lt;/p&gt;Can I open a new account using an old price plan?&lt;p&gt;No, that is not possible. New accounts are only available with our new price plans.&lt;/p&gt;I have a Team Mail account. Will it be possible to set up additional inboxes for this account under the new plans?&lt;p&gt;Yes, you can keep using your Team Mail account but any new inboxes need to be set up using either the PREMIUM or the STANDARD price plan.&lt;/p&gt;How can I access the free e-mail migration service?&lt;p&gt;Log in to mailbox.org and go to Settings -&amp;gt; mailbox.org -&amp;gt; E-mail migration service. Click on the link to visit the audriga website and move your existing account in a few simple steps. &lt;a href="https://kb.mailbox.org/display/MBOKBEN/Audriga+-+Your+e-mail+migration+service" target="_blank" title="Click here for more information about the e-mail migration service" rel="noopener"&gt;Click here for more information about the e-mail migration service&lt;/a&gt;&lt;/p&gt;Will future mailbox.org feature releases be available through any of the old plans?&lt;p&gt;Well, yes and no. Core functionality in relation to e-mail and security will always be available for everyone, including the legacy plans and the new LIGHT package – we will never make any compromises here. Other, additional functionality (much like the video conferencing feature we introduced recently) will from now on only be available with the new plans.&lt;/p&gt;Is there a minimum contract term?&lt;p&gt;Users on the STANDARD or PREMIUM price plans can choose to pay either monthly, every six months, or annually, and so fully control their contractual term. Larger payments help us save costs, and we reward users by giving them extra bonus months for free when they commit to stay with us for longer. However, users who are on the LIGHT plan need to pay up for a full year, as small monthly payments would be uneconomical given the associated transaction fees (which we still need to cover), so there is in effect an annual contract term for those on the LIGHT plan.&lt;/p&gt;Can I switch plan between STANDARD, PREMIUM and LIGHT?&lt;p&gt;Yes, switching between the new plans is possible. Although note that the new price plans are no longer based on pre-paid credit, meaning every payment will result in a contract term corresponding to the amount paid in. We needed to make this change as the legislation for services based on pre-paid credit is not straightforward. But that’s not a problem: When switching over to another price plan, we will simply amend the contract term accordingly, so that users who want to switch do not lose out.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-celebration.jpeg?itok=wIZsodf0" type="image/jpeg" length="326204"/><guid isPermaLink="false">633618ab-0ed6-4327-847f-1510fd1a4a0a</guid>
    <pubDate>Wed, 14 Apr 2021 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>The new plans</dc:title>
    <dc:identifier>633618ab-0ed6-4327-847f-1510fd1a4a0a</dc:identifier>
    </item>
<item>
  <title>Peer Heinlein interviewed by tarnkappe.info</title>
  <link>https://mailbox.org/en/news/interview/interview-peer-heinlein-tarnkappeinfo/</link>
  <description>&lt;p&gt;&lt;em&gt;Reading time: 5 minutes&lt;/em&gt;&lt;/p&gt;


      
                  
              
              
              
              
              
              
              
                  &lt;img loading="lazy" height="2008" width="3008" src="https://mailbox.org/sites/default/files/2025-05/mailbox-presse-portrait-peer-heinlein.jpg" alt="Portrait of Peer Heinlein"&gt;

  


  
          

              


  
    
    
    
    &lt;p&gt;In an extended interview with the news website tarnkappe.info, mailbox.org CEO Peer Heinlein talks about the history, motivations, mission and future of mailbox.org. Readers of the news site sent in their questions in advance of the interview.&lt;/p&gt;&lt;p&gt;We briefly revisit the beginnings of the company back in 1989, which created the foundation for the IT consulting business of today, their passion for Linux and open source software, and their mission to promote independence and freedom on the Internet. Looking into the future, the founding of mailbox.org was the next logical step for them to take.&lt;/p&gt;&lt;p&gt;The readers of tarnkappe.info asked many questions about the political developments in Germany and the EU, and the possible ramifications for e-mail providers. Peer Heinlein talks about his views on the possibility of government backdoors that may be used to circumvent encryption, the noticeable trend towards targeted access, increasing state control, but also why their business is based in Berlin and not somewhere else. He also answers questions about mailbox.org’s two data centers and who has access there, and how the data is being routed.&lt;/p&gt;&lt;p&gt;Peer Heinlein gives a clear answer to the question why mailbox.org is constantly extending their services beyond pure e-mail: "From the very beginning, we did not see ourselves as an ‘email-only provider’, but more as a communications provider - the European data-protecting alternative to Gmail &amp;amp; Co. Of course, this is a bit like David vs Goliath, and we know that Google will never tremble with fear because of us. But we do show that there are very good alternatives and that we do not do lazy compromises."&lt;/p&gt;&lt;p&gt;&lt;a href="https://tarnkappe.info/mailbox-org-came-after-the-snowden-revelations-a-talk-with-peer-heinlein/" target="_blank" title="tarnkappe.info: mailbox.org came after the Snowden revelations" rel="noopener"&gt;Read the full interview&lt;/a&gt;&lt;/p&gt;

          
                                                  
      


      
      &lt;h2 class="row__intro__title"&gt;            Insights &amp;amp; trends
      &lt;/h2&gt;
      Discover further articles on IT security.
              
            

&lt;a data-component-id="boxy:knob" data-component-variant="secondary" class="knob knob--secondary" href="https://mailbox.org/en/insights/"&gt;All articles&lt;/a&gt;

        
          
    
      
      
  
  
                    
                  
              
                  &lt;img loading="lazy" height="2160" width="4096" src="https://mailbox.org/sites/default/files/2026-08/mailbox%20EVAC%20Blog%20IT-Sicherheit%20kleine%20Unternehmen.jpeg" alt="mailbox EVAC Blog IT-Sicherheit kleine Unternehmen"&gt;

  


      
      
      
      Business Continuitiy, Security
    
    &lt;h3 class="snip__title"&gt;IT security: Why small businesses in particular are targeted by cyberattacks&lt;/h3&gt;
  &lt;a class="snip__arrow" href="https://mailbox.org/en/blog/IT-security-for-small-businesses/" aria-hidden="true"&gt;→&lt;/a&gt;
  &lt;a class="snip__link" href="https://mailbox.org/en/blog/IT-security-for-small-businesses/"&gt;Read more about &lt;em class="placeholder"&gt;IT security: Why small businesses in particular are targeted by cyberattacks&lt;/em&gt;&lt;/a&gt;


    
      
      
  
  
                    
                  
              
                  &lt;img loading="lazy" height="2160" width="4096" src="https://mailbox.org/sites/default/files/2026-08/mailbox%20EVAC%20Blog%20Business%20Continuity%20in%20der%20Lieferkette.jpeg" alt="mailbox EVAC Blog Business Continuity in der Lieferkette"&gt;

  


      
      
      
      Best practice, Business Continuitiy
    
    &lt;h3 class="snip__title"&gt;How to use business continuity as a competitive advantage in the supply chain&lt;/h3&gt;
  &lt;a class="snip__arrow" href="https://mailbox.org/en/blog/business-continuity-supply-chain/" aria-hidden="true"&gt;→&lt;/a&gt;
  &lt;a class="snip__link" href="https://mailbox.org/en/blog/business-continuity-supply-chain/"&gt;Read more about &lt;em class="placeholder"&gt;How to use business continuity as a competitive advantage in the supply chain&lt;/em&gt;&lt;/a&gt;


    
  
  


</description>
  <guid isPermaLink="false">dad32041-238a-45ce-ae05-e42914b36496</guid>
    <pubDate>Fri, 19 Mar 2021 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Peer Heinlein interviewed by tarnkappe.info</dc:title>
    <dc:identifier>dad32041-238a-45ce-ae05-e42914b36496</dc:identifier>
    </item>
<item>
  <title>Major security holes in Exchange</title>
  <link>https://mailbox.org/en/news/exchange-server-security-vulnerabilities-its-time-switch-mailboxorg/</link>
  <description>&lt;p&gt;While more and more security experts and data protection professionals are warning about security vulnerabilities in Microsoft Exchange, mailbox.org offers a secure alternative.&lt;/p&gt;&lt;p&gt;It looks as if March 2021 is not going to be a good month for customers of Microsoft’s “Exchange” mail server. Heinz Müller, the most senior data protection official for the federal state of Mecklenburg and Western Pomerania, now said openly what other data protection professionals and legal scholars have known for some time: There are many Microsoft products that should not be used by businesses and authorities in the country because doing so would be illegal. As the German IT publisher &lt;a href="https://www.heise.de/news/Datenschutzbeauftragter-Behoerden-sollten-unverzueglich-auf-Microsoft-verzichten-5990886.html" target="_blank" title="[Article in German] Heise News: Datenschutzbeauftragter: Behörden sollen unverzüglich auf Microsoft verzichten" rel="noopener"&gt;Heise News&lt;/a&gt; wrote: “The data protection commissioner for Mecklenburg-Western Pomerania and the state’s audit office are both calling for the state government to cease using any Microsoft products, immediately.” and also: “the only feasible option for upholding required data protection standards and maintaining the digital sovereignty of the state government is to use open source software products”.&lt;/p&gt;&lt;h2&gt;Security alert level RED – “extremely critical”&lt;/h2&gt;&lt;p&gt;Further considering the current security concerns about Microsoft’s products, there are now many good reasons to look for alternatives: On 2 March 2021, the vendor published a number of critical security updates that every customer was supposed to install on their MS Exchange servers, most recently even packaged up in a specially developed software tool.&lt;/p&gt;&lt;p&gt;The security updates that were provided did unfortunately not bring the relief everyone was hoping for. Within a week, IT security researchers had established that there were tens of thousands of vulnerable servers in Germany alone, and about the same number also in the US. As the situation developed further, the German federal office for information security (BSI) talked of an “&lt;a href="https://www.heise.de/news/Exchange-Luecken-BSI-ruft-IT-Bedrohungslage-rot-aus-5075457.html" target="_blank" title="[Article in German] Heise News: https://www.heise.de/news/Exchange-Luecken-BSI-ruft-IT-Bedrohungslage-rot-aus-5075457.html" rel="noopener"&gt;extremely critical situation&lt;/a&gt;”, which led them to issue a red security alert concerning Microsoft Exchange Server on 9 March. A week later, attackers still managed to further refine their exploit methods so as to utilize servers and client computers for &lt;a href="https://www.heise.de/news/Exchange-Luecken-werden-von-Krypto-Minern-ausgenutzt-5991001.html" target="_blank" title="[Article in German] Heise News: Exchange-Lücken werden von Krypto-Minern ausgenutzt​" rel="noopener"&gt;automated Bitcoin mining&lt;/a&gt; (i.e., using their computing resources to create crypto currency).&lt;/p&gt;&lt;h2&gt;Active Directory and Office 365 affected by major issues&lt;/h2&gt;&lt;p&gt;As if that wasn’t enough, Microsoft’s Active Directory service, which is part of the critical infrastructure of many businesses, &lt;a href="https://www.heise.de/news/Microsoft-Dienste-fallen-wegen-Authentifizierungs-Fehler-aus-5989379.html" target="_blank" title="[Article in German] Heise News: Microsoft-Dienste fielen wegen Authentifizierungs-Fehler aus" rel="noopener"&gt;failed completely&lt;/a&gt; on 15 March. Two days later, the news were that “71% of Office 365 implementations &lt;a href="https://www.heise.de/news/Grossteil-der-MS-365-Konten-2020-erfolgreich-uebernommen-5990195.html" target="_blank" title="[Article in German] Heise News: https://www.heise.de/news/Grossteil-der-MS-365-Konten-2020-erfolgreich-uebernommen-5990195.html" rel="noopener"&gt;had been successfully attacked in 2020&lt;/a&gt;” (Office 365 is the latest incarnation of the Microsoft Office product, which can run in a Web browser).&lt;/p&gt;&lt;h2&gt;Secure and legally compliant: mailbox.org and Heinlein Support&lt;/h2&gt;&lt;p&gt;As many will have guessed, mailbox.org is not affected by any of the problems mentioned above. Customers who use our e-mail, data synchronization, office and chat services are and have been secure and fully protected by data protection measures that are fully compliant with German and European law. Heinlein Support, the company that operates mailbox.org, specializes in e-mail servers and Linux for data centers. We pass on our knowledge and experience through the Heinlein Academy, individual consultancy, our hosting services, and the e-mail provider mailbox.org.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-04/mailbox-news-und-updates-warnung.jpg?itok=reW9cU74" type="image/jpeg" length="238141"/><guid isPermaLink="false">01b61188-80d1-478a-ae87-2b477dfddc84</guid>
    <pubDate>Fri, 19 Mar 2021 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Major security holes in Exchange</dc:title>
    <dc:identifier>01b61188-80d1-478a-ae87-2b477dfddc84</dc:identifier>
    </item>
<item>
  <title>Major security holes in Exchange</title>
  <link>https://mailbox.org/en/news/exchange-server-security-vulnerabilities-its-time-switch-mailboxorg/</link>
  <description>&lt;p&gt;While more and more security experts and data protection professionals are warning about security vulnerabilities in Microsoft Exchange, mailbox.org offers a secure alternative.&lt;/p&gt;&lt;p&gt;It looks as if March 2021 is not going to be a good month for customers of Microsoft’s “Exchange” mail server. Heinz Müller, the most senior data protection official for the federal state of Mecklenburg and Western Pomerania, now said openly what other data protection professionals and legal scholars have known for some time: There are many Microsoft products that should not be used by businesses and authorities in the country because doing so would be illegal. As the German IT publisher &lt;a href="https://www.heise.de/news/Datenschutzbeauftragter-Behoerden-sollten-unverzueglich-auf-Microsoft-verzichten-5990886.html" target="_blank" title="[Article in German] Heise News: Datenschutzbeauftragter: Behörden sollen unverzüglich auf Microsoft verzichten" rel="noopener"&gt;Heise News&lt;/a&gt; wrote: “The data protection commissioner for Mecklenburg-Western Pomerania and the state’s audit office are both calling for the state government to cease using any Microsoft products, immediately.” and also: “the only feasible option for upholding required data protection standards and maintaining the digital sovereignty of the state government is to use open source software products”.&lt;/p&gt;&lt;h2&gt;Security alert level RED – “extremely critical”&lt;/h2&gt;&lt;p&gt;Further considering the current security concerns about Microsoft’s products, there are now many good reasons to look for alternatives: On 2 March 2021, the vendor published a number of critical security updates that every customer was supposed to install on their MS Exchange servers, most recently even packaged up in a specially developed software tool.&lt;/p&gt;&lt;p&gt;The security updates that were provided did unfortunately not bring the relief everyone was hoping for. Within a week, IT security researchers had established that there were tens of thousands of vulnerable servers in Germany alone, and about the same number also in the US. As the situation developed further, the German federal office for information security (BSI) talked of an “&lt;a href="https://www.heise.de/news/Exchange-Luecken-BSI-ruft-IT-Bedrohungslage-rot-aus-5075457.html" target="_blank" title="[Article in German] Heise News: https://www.heise.de/news/Exchange-Luecken-BSI-ruft-IT-Bedrohungslage-rot-aus-5075457.html" rel="noopener"&gt;extremely critical situation&lt;/a&gt;”, which led them to issue a red security alert concerning Microsoft Exchange Server on 9 March. A week later, attackers still managed to further refine their exploit methods so as to utilize servers and client computers for &lt;a href="https://www.heise.de/news/Exchange-Luecken-werden-von-Krypto-Minern-ausgenutzt-5991001.html" target="_blank" title="[Article in German] Heise News: Exchange-Lücken werden von Krypto-Minern ausgenutzt​" rel="noopener"&gt;automated Bitcoin mining&lt;/a&gt; (i.e., using their computing resources to create crypto currency).&lt;/p&gt;&lt;h2&gt;Active Directory and Office 365 affected by major issues&lt;/h2&gt;&lt;p&gt;As if that wasn’t enough, Microsoft’s Active Directory service, which is part of the critical infrastructure of many businesses, &lt;a href="https://www.heise.de/news/Microsoft-Dienste-fallen-wegen-Authentifizierungs-Fehler-aus-5989379.html" target="_blank" title="[Article in German] Heise News: Microsoft-Dienste fielen wegen Authentifizierungs-Fehler aus" rel="noopener"&gt;failed completely&lt;/a&gt; on 15 March. Two days later, the news were that “71% of Office 365 implementations &lt;a href="https://www.heise.de/news/Grossteil-der-MS-365-Konten-2020-erfolgreich-uebernommen-5990195.html" target="_blank" title="[Article in German] Heise News: https://www.heise.de/news/Grossteil-der-MS-365-Konten-2020-erfolgreich-uebernommen-5990195.html" rel="noopener"&gt;had been successfully attacked in 2020&lt;/a&gt;” (Office 365 is the latest incarnation of the Microsoft Office product, which can run in a Web browser).&lt;/p&gt;&lt;h2&gt;Secure and legally compliant: mailbox.org and Heinlein Support&lt;/h2&gt;&lt;p&gt;As many will have guessed, mailbox.org is not affected by any of the problems mentioned above. Customers who use our e-mail, data synchronization, office and chat services are and have been secure and fully protected by data protection measures that are fully compliant with German and European law. Heinlein Support, the company that operates mailbox.org, specializes in e-mail servers and Linux for data centers. We pass on our knowledge and experience through the Heinlein Academy, individual consultancy, our hosting services, and the e-mail provider mailbox.org.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-04/mailbox-news-und-updates-warnung.jpg?itok=reW9cU74" type="image/jpeg" length="238141"/><guid isPermaLink="false">01b61188-80d1-478a-ae87-2b477dfddc84</guid>
    <pubDate>Fri, 19 Mar 2021 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Major security holes in Exchange</dc:title>
    <dc:identifier>01b61188-80d1-478a-ae87-2b477dfddc84</dc:identifier>
    </item>
<item>
  <title>Why we have two data centres at mailbox.org</title>
  <link>https://mailbox.org/en/news/why-mailboxorg-operates-two-data-centers/</link>
  <description>&lt;p&gt;As reported earlier on dna.fr, a fire in Strasbourg has devastated a main data center of the French cloud operator OVH. Locations SBG-1 and SBG-2 have been largely destroyed, and SBG-3 and SBG-4 had to be taken offline temporarily. Customers, which include the French government and the Centre Pompidou, were advised by OVH to engage „Disaster Recovery Plans“, which can only mean that all servers were destroyed and the data stored on them irretrievably lost.&lt;/p&gt;&lt;p&gt;Looking at the images that were taken at the scene of the fire, one can see &lt;a href="https://twitter.com/HackInScience/status/1369558519586955264" target="_blank" rel="noopener"&gt;completely burned-out multi-story buildings&lt;/a&gt;. Anyone affected by such an event can be lucky if they have a disaster recovery plan, and additional copies of their data kept elsewhere. Sadly, those who rented their servers in Strasbourg and maintained no further backups will in all likelihood have lost all their data forever.&lt;/p&gt;&lt;p&gt;Unlike other providers, we at mailbox.org do not rent root servers externally with commercial companies such as OVH. Instead, we are operating two independent and geographically separate data centers with two providers: IPB (Internet Provider Berlin) and Lumen (formerly known as Level 3). Both data centers are structurally similar, and we use our own dedicated data lines, which allow mailbox.org to operate services independently even in case of disruption elsewhere.&lt;/p&gt;&lt;p&gt;Biometric access control, multiple physical levels of redundant power supply from different energy providers, cooling systems, and the continuous monitoring of system status are international standards that are implemented in our data centers. In addition, uninterruptible power supply is provided through batteries, as well as emergency generators on standby to respond in the event that the electricity grid fails. Furthermore, there are automatic fire-extinguishing systems installed, which use CO2 or argon gas and can quickly suppress any fire flaring up. Given these measures are well-established, it is surprising how it was possible for the fire in Strasbourg to get out of control so dramatically. Some experts have said that French &lt;a href="https://www.journaldunet.com/web-tech/cloud/1498567-incendie-chez-ovh-de-nombreuses-sauvegardes-irrecuperables/" target="_blank" rel="noopener"&gt;fire protection standards may be insufficient&lt;/a&gt; and so, less strict than those we have in Germany, for example. Even the fire fighters on location to extinguish the flames were &lt;a href="https://www.lemonde.fr/societe/article/2021/03/10/a-strasbourg-un-important-incendie-sur-le-site-de-l-entreprise-ovh-classe-seveso_6072548_3224.html" target="_blank" rel="noopener"&gt;surprised by the scale of the fire&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;If different parts of a house are allocated to special fire protection zones, this won't necessarily help in the catastrophic event that the entire building is on fire. The only way to counter this kind of risk is to maintain redundant data centers at geographically separate locations, despite the significant additional expense that doing so incurs. Since this is normally a choice that remains opaque to customers, everyone would be well-advised to ask how their current provider is keeping their data safe.&lt;/p&gt;&lt;p&gt;On this subject, mailbox.org CEO Peer Heinlein says: „Looking at the events in Strasbourg, we are reaffirmed in our approach not to rent servers elsewhere but operate our own dedicated systems instead. Sure, it is more expensive to do so and a lot of effort overall. However, keeping server systems and data in two separate locations also offers a lot of security and flexibility in the event of catastrophe. Even if one of our data centers were to fail completely, then this would only cause minor disruption to our service, which makes the situation as a whole much more controllable.”, says Heinlein.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-drive-1.png?itok=Cdaxpixf" type="image/png" length="245668"/><guid isPermaLink="false">8f878b6d-3c63-4500-8da6-bf9a7b887ff8</guid>
    <pubDate>Wed, 10 Mar 2021 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Why we have two data centres at mailbox.org</dc:title>
    <dc:identifier>8f878b6d-3c63-4500-8da6-bf9a7b887ff8</dc:identifier>
    </item>
<item>
  <title>Why we have two data centres at mailbox.org</title>
  <link>https://mailbox.org/en/news/why-mailboxorg-operates-two-data-centers/</link>
  <description>&lt;p&gt;As reported earlier on dna.fr, a fire in Strasbourg has devastated a main data center of the French cloud operator OVH. Locations SBG-1 and SBG-2 have been largely destroyed, and SBG-3 and SBG-4 had to be taken offline temporarily. Customers, which include the French government and the Centre Pompidou, were advised by OVH to engage „Disaster Recovery Plans“, which can only mean that all servers were destroyed and the data stored on them irretrievably lost.&lt;/p&gt;&lt;p&gt;Looking at the images that were taken at the scene of the fire, one can see &lt;a href="https://twitter.com/HackInScience/status/1369558519586955264" target="_blank" rel="noopener"&gt;completely burned-out multi-story buildings&lt;/a&gt;. Anyone affected by such an event can be lucky if they have a disaster recovery plan, and additional copies of their data kept elsewhere. Sadly, those who rented their servers in Strasbourg and maintained no further backups will in all likelihood have lost all their data forever.&lt;/p&gt;&lt;p&gt;Unlike other providers, we at mailbox.org do not rent root servers externally with commercial companies such as OVH. Instead, we are operating two independent and geographically separate data centers with two providers: IPB (Internet Provider Berlin) and Lumen (formerly known as Level 3). Both data centers are structurally similar, and we use our own dedicated data lines, which allow mailbox.org to operate services independently even in case of disruption elsewhere.&lt;/p&gt;&lt;p&gt;Biometric access control, multiple physical levels of redundant power supply from different energy providers, cooling systems, and the continuous monitoring of system status are international standards that are implemented in our data centers. In addition, uninterruptible power supply is provided through batteries, as well as emergency generators on standby to respond in the event that the electricity grid fails. Furthermore, there are automatic fire-extinguishing systems installed, which use CO2 or argon gas and can quickly suppress any fire flaring up. Given these measures are well-established, it is surprising how it was possible for the fire in Strasbourg to get out of control so dramatically. Some experts have said that French &lt;a href="https://www.journaldunet.com/web-tech/cloud/1498567-incendie-chez-ovh-de-nombreuses-sauvegardes-irrecuperables/" target="_blank" rel="noopener"&gt;fire protection standards may be insufficient&lt;/a&gt; and so, less strict than those we have in Germany, for example. Even the fire fighters on location to extinguish the flames were &lt;a href="https://www.lemonde.fr/societe/article/2021/03/10/a-strasbourg-un-important-incendie-sur-le-site-de-l-entreprise-ovh-classe-seveso_6072548_3224.html" target="_blank" rel="noopener"&gt;surprised by the scale of the fire&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;If different parts of a house are allocated to special fire protection zones, this won't necessarily help in the catastrophic event that the entire building is on fire. The only way to counter this kind of risk is to maintain redundant data centers at geographically separate locations, despite the significant additional expense that doing so incurs. Since this is normally a choice that remains opaque to customers, everyone would be well-advised to ask how their current provider is keeping their data safe.&lt;/p&gt;&lt;p&gt;On this subject, mailbox.org CEO Peer Heinlein says: „Looking at the events in Strasbourg, we are reaffirmed in our approach not to rent servers elsewhere but operate our own dedicated systems instead. Sure, it is more expensive to do so and a lot of effort overall. However, keeping server systems and data in two separate locations also offers a lot of security and flexibility in the event of catastrophe. Even if one of our data centers were to fail completely, then this would only cause minor disruption to our service, which makes the situation as a whole much more controllable.”, says Heinlein.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-drive-1.png?itok=Cdaxpixf" type="image/png" length="245668"/><guid isPermaLink="false">8f878b6d-3c63-4500-8da6-bf9a7b887ff8</guid>
    <pubDate>Wed, 10 Mar 2021 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Why we have two data centres at mailbox.org</dc:title>
    <dc:identifier>8f878b6d-3c63-4500-8da6-bf9a7b887ff8</dc:identifier>
    </item>
<item>
  <title>Transparency Report 2020</title>
  <link>https://mailbox.org/en/news/transparency-report-2020/</link>
  <description>&lt;p&gt;Today we publish our transparency report of 2020, in which we account for all requests for information that we as a provider have received by the authorities last year.&lt;/p&gt;&lt;p&gt;Requests sent to mailbox.org in the year 2020&lt;br&gt;Total number of requests: 85&lt;br&gt;From German authorities: 79&lt;br&gt;From foreign authorities: 6&lt;/p&gt;&lt;p&gt;Organisations&lt;br&gt;Criminal investigative authorities: 85&lt;br&gt;Customs authorities: 0&lt;br&gt;Intelligence services: 0&lt;/p&gt;&lt;p&gt;Request type&lt;br&gt;Contact data requests: 80&lt;br&gt;Inbox confiscations: 4&lt;br&gt;Traffic data requests: 1&lt;br&gt;Telecommunications interceptions: 0&lt;/p&gt;&lt;p&gt;The overall number of requests we received in 2020 has increased slightly when compared to the previous year. A total of 43 requests were found to contain flaws or be unlawful for other reasons – those requests were consequentially rejected. Of all unlawful requests, 20 were subsequently re-submitted with their formal issues remedied, and then processed. 23 requests were ultimately rejected.&lt;/p&gt;&lt;p&gt;How was it possible that such a large number of official requests were deemed unlawful? The reason was that the majority of these were made based on inappropriate legal grounds. Whenever a request to obtain information about one of our customers is submitted, the legal basis for such a request must be explicitly stated. It is concerning that so many of the investigative authorities appear to be ignorant of the relevant legal requirements: 40% of all requests quoted the wrong legal basis or did not provide any at all. We also note that there was an overall lower number of requests this year that were subsequently resubmitted with corrections.&lt;/p&gt;&lt;p&gt;About half of the requests sent by investigative authorities in 2020 have reached us by e-mail, so the use of fax seems to be on the way out. Unfortunately, most of these e-mails were sent to us as unencrypted plain text, which we think is highly inappropriate, considering the sensitive information transmitted.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-04/mailbox-news-und-updates-transparenzbericht.jpg?itok=SMV4eTPL" type="image/jpeg" length="268110"/><guid isPermaLink="false">146357e8-9e72-4903-be7b-01dceeed8553</guid>
    <pubDate>Tue, 16 Feb 2021 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Transparency Report 2020</dc:title>
    <dc:identifier>146357e8-9e72-4903-be7b-01dceeed8553</dc:identifier>
    </item>
<item>
  <title>Transparency Report 2020</title>
  <link>https://mailbox.org/en/news/transparency-report-2020/</link>
  <description>&lt;p&gt;Today we publish our transparency report of 2020, in which we account for all requests for information that we as a provider have received by the authorities last year.&lt;/p&gt;&lt;p&gt;Requests sent to mailbox.org in the year 2020&lt;br&gt;Total number of requests: 85&lt;br&gt;From German authorities: 79&lt;br&gt;From foreign authorities: 6&lt;/p&gt;&lt;p&gt;Organisations&lt;br&gt;Criminal investigative authorities: 85&lt;br&gt;Customs authorities: 0&lt;br&gt;Intelligence services: 0&lt;/p&gt;&lt;p&gt;Request type&lt;br&gt;Contact data requests: 80&lt;br&gt;Inbox confiscations: 4&lt;br&gt;Traffic data requests: 1&lt;br&gt;Telecommunications interceptions: 0&lt;/p&gt;&lt;p&gt;The overall number of requests we received in 2020 has increased slightly when compared to the previous year. A total of 43 requests were found to contain flaws or be unlawful for other reasons – those requests were consequentially rejected. Of all unlawful requests, 20 were subsequently re-submitted with their formal issues remedied, and then processed. 23 requests were ultimately rejected.&lt;/p&gt;&lt;p&gt;How was it possible that such a large number of official requests were deemed unlawful? The reason was that the majority of these were made based on inappropriate legal grounds. Whenever a request to obtain information about one of our customers is submitted, the legal basis for such a request must be explicitly stated. It is concerning that so many of the investigative authorities appear to be ignorant of the relevant legal requirements: 40% of all requests quoted the wrong legal basis or did not provide any at all. We also note that there was an overall lower number of requests this year that were subsequently resubmitted with corrections.&lt;/p&gt;&lt;p&gt;About half of the requests sent by investigative authorities in 2020 have reached us by e-mail, so the use of fax seems to be on the way out. Unfortunately, most of these e-mails were sent to us as unencrypted plain text, which we think is highly inappropriate, considering the sensitive information transmitted.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-04/mailbox-news-und-updates-transparenzbericht.jpg?itok=SMV4eTPL" type="image/jpeg" length="268110"/><guid isPermaLink="false">146357e8-9e72-4903-be7b-01dceeed8553</guid>
    <pubDate>Tue, 16 Feb 2021 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Transparency Report 2020</dc:title>
    <dc:identifier>146357e8-9e72-4903-be7b-01dceeed8553</dc:identifier>
    </item>
<item>
  <title>Berlin teachers equipped with secure email</title>
  <link>https://mailbox.org/en/news/secure-e-mail-teachers-german-capital-counts-mailbox/</link>
  <description>&lt;p&gt;The 33,000 teachers working in the public service of the German capital can look forward to receiving their own dedicated, secure e-mail account, operated by mailbox.org. Berlin’s senate department for Education, Youth, and Families will be providing all teaching staff in the city with a secure work e-mail address that they can use for official business. The service will be operated by mailbox.org, which means: Servers located in Germany, solid data protection guarantees, and thorough encryption of all communication pathways.&lt;/p&gt;&lt;p&gt;We are already providing secure e-mail inboxes for teachers in the federal state of Thuringia, and are very pleased to now be in a position to also support those in Berlin in their digitization efforts. Crucial for the senate decision to select mailbox.org as a partner has been our ability to fulfill all data security, encryption, and usability requirements of the tender.&lt;/p&gt;&lt;p&gt;All teaching staff in Berlin are going to receive their own e-mail account for official business communications, which enables them to send e-mails and files, and also manage tasks and appointments. They will also be able to use our online Office to create and edit text documents, spreadsheets, and presentations that are needed for their daily educational work, and share these documents easily with colleagues, students, and parents, all in accordance with the strict German data protection laws. Teachers will also benefit from an e-mail inbox that they can choose to encrypt automatically, which is a good measure to protect incoming e-mails from unauthorized access.&lt;/p&gt;&lt;p&gt;mailbox.org can use existing interfaces to integrate seamlessly with Berlin’s school portal on the Web, and their administrators will be able to manage everything independently from their end.&lt;/p&gt;&lt;h2&gt;German data protection standards – important for the security of our schools&lt;/h2&gt;&lt;p&gt;Similar to many workplaces, schools are an environment that is seeing more and more use of services such as MS Office 365, Gmail, or Whatsapp. How the companies behind these services collect and share their users’ data has raised widespread concerns about data protection and security. By opting for a communications solution that has been developed and operated in Germany, the senate department for Education, Youth, and Families in Berlin has recognized these concerns and acted responsibly to protect the data of teachers, students, and parents.&lt;/p&gt;&lt;p&gt;While Thuringia and Berlin have been the first to adopt our solution, we are aware that decision-makers in other federal states are also thinking about ways to acquire secure e-mail inboxes for their teachers. mailbox.org offers the highest security standards, and our reputation and technical experience not just in e-mail but also IT interfaces makes us an ideal partner for these kinds of projects. Interested? Don't hesitate to get in touch with Claas Heinrich at &lt;a href="https://mailbox.org/mailto:business-support@mailbox.org" title="Get in touch with us"&gt;business-support@mailbox.org&lt;/a&gt;.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-education.jpeg?itok=OXxFnSh0" type="image/jpeg" length="273492"/><guid isPermaLink="false">1ea09d39-58d1-43ff-9f06-fcd4c26899ad</guid>
    <pubDate>Tue, 19 Jan 2021 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Berlin teachers equipped with secure email</dc:title>
    <dc:identifier>1ea09d39-58d1-43ff-9f06-fcd4c26899ad</dc:identifier>
    </item>
<item>
  <title>Berlin teachers equipped with secure email</title>
  <link>https://mailbox.org/en/news/secure-e-mail-teachers-german-capital-counts-mailbox/</link>
  <description>&lt;p&gt;The 33,000 teachers working in the public service of the German capital can look forward to receiving their own dedicated, secure e-mail account, operated by mailbox.org. Berlin’s senate department for Education, Youth, and Families will be providing all teaching staff in the city with a secure work e-mail address that they can use for official business. The service will be operated by mailbox.org, which means: Servers located in Germany, solid data protection guarantees, and thorough encryption of all communication pathways.&lt;/p&gt;&lt;p&gt;We are already providing secure e-mail inboxes for teachers in the federal state of Thuringia, and are very pleased to now be in a position to also support those in Berlin in their digitization efforts. Crucial for the senate decision to select mailbox.org as a partner has been our ability to fulfill all data security, encryption, and usability requirements of the tender.&lt;/p&gt;&lt;p&gt;All teaching staff in Berlin are going to receive their own e-mail account for official business communications, which enables them to send e-mails and files, and also manage tasks and appointments. They will also be able to use our online Office to create and edit text documents, spreadsheets, and presentations that are needed for their daily educational work, and share these documents easily with colleagues, students, and parents, all in accordance with the strict German data protection laws. Teachers will also benefit from an e-mail inbox that they can choose to encrypt automatically, which is a good measure to protect incoming e-mails from unauthorized access.&lt;/p&gt;&lt;p&gt;mailbox.org can use existing interfaces to integrate seamlessly with Berlin’s school portal on the Web, and their administrators will be able to manage everything independently from their end.&lt;/p&gt;&lt;h2&gt;German data protection standards – important for the security of our schools&lt;/h2&gt;&lt;p&gt;Similar to many workplaces, schools are an environment that is seeing more and more use of services such as MS Office 365, Gmail, or Whatsapp. How the companies behind these services collect and share their users’ data has raised widespread concerns about data protection and security. By opting for a communications solution that has been developed and operated in Germany, the senate department for Education, Youth, and Families in Berlin has recognized these concerns and acted responsibly to protect the data of teachers, students, and parents.&lt;/p&gt;&lt;p&gt;While Thuringia and Berlin have been the first to adopt our solution, we are aware that decision-makers in other federal states are also thinking about ways to acquire secure e-mail inboxes for their teachers. mailbox.org offers the highest security standards, and our reputation and technical experience not just in e-mail but also IT interfaces makes us an ideal partner for these kinds of projects. Interested? Don't hesitate to get in touch with Claas Heinrich at &lt;a href="https://mailbox.org/mailto:business-support@mailbox.org" title="Get in touch with us"&gt;business-support@mailbox.org&lt;/a&gt;.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-education.jpeg?itok=OXxFnSh0" type="image/jpeg" length="273492"/><guid isPermaLink="false">1ea09d39-58d1-43ff-9f06-fcd4c26899ad</guid>
    <pubDate>Tue, 19 Jan 2021 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Berlin teachers equipped with secure email</dc:title>
    <dc:identifier>1ea09d39-58d1-43ff-9f06-fcd4c26899ad</dc:identifier>
    </item>
<item>
  <title>Spin-off of mailbox.org into a custom limited liability company</title>
  <link>https://mailbox.org/en/news/spin-out-mailboxorg-separate-limited-liability-company-gmbh/</link>
  <description>&lt;p&gt;Dear mailbox.org customers,&lt;/p&gt;&lt;p&gt;We would like to wish all of you a happy and healthy year 2021!&lt;/p&gt;&lt;p&gt;Since its inception in 2014, mailbox.org has been operated by the Heinlein Support GmbH - a German company that is active in several areas such as IT-Administrator training, Linux consulting for business, as well as server hosting.&lt;/p&gt;&lt;p&gt;mailbox.org has been growing and prospering continuously to become a successful brand and business unit within our company. We needed to make some changes to put our business on a better foundation for the future, and enable us to manage potential risks more efficiently. That is why we decided to spin out some of our business divisions into separate legal entities.&lt;/p&gt;&lt;p&gt;As a result, the divisions "mailbox.org" and "Heinlein Hosting" are now operating under the banner of the company "Heinlein Hosting GmbH", which is 100% subsidiary to its parent "Heinlein Support GmbH", to independently operate our data centres and our provider for "mailbox.org".&lt;/p&gt;&lt;p&gt;The new "Heinlein Hosting GmbH" enters into all existing supplier or service contracts as well as commissioned data processing contracts as part of the legal succession. Please note that invoices issued as of 1 January 2021 will now legally originate from Heinlein Hosting GmbH. Mail addresses, postal addresses and telephone numbers have not changed.&lt;/p&gt;&lt;p&gt;&lt;br&gt;Private customers&lt;/p&gt;&lt;p&gt;As a private customer with an "MBO" invoice number, you continue to pay into our account at the "Sozialbank" as indicated on the invoices.&lt;/p&gt;&lt;p&gt;&lt;br&gt;Business customer&lt;/p&gt;&lt;p&gt;As a business customer, please use the newly established "Postbank" account, as indicated on your invoices. - We kindly ask our business customers to amend their contract, invoice or supplier master data accordingly, if necessary. Thank you for your cooperation - we apologise for any inconvenience this change may cause at your end.&lt;br&gt;&lt;br&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;See below the key information about our spin-off company:&lt;/p&gt;&lt;p&gt;Heinlein Hosting GmbH&lt;br&gt;Schwedter Str. 8/9b, D-10119 Berlin&lt;br&gt;German tax number 37/337/50030&lt;br&gt;International sales tax identification number: DE335125423&lt;br&gt;Commercial register number: HRB 220010 B&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Best regards,&lt;br&gt;Your mailbox.org team&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-04/mailbox-news-und-updates-produktupdate.jpg?itok=VmAEEH73" type="image/jpeg" length="400284"/><guid isPermaLink="false">a7f2a1c0-4565-49f6-98ef-2f811c2c92e8</guid>
    <pubDate>Tue, 12 Jan 2021 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Spin-off of mailbox.org into a custom limited liability company</dc:title>
    <dc:identifier>a7f2a1c0-4565-49f6-98ef-2f811c2c92e8</dc:identifier>
    </item>
<item>
  <title>Spin-off of mailbox.org into a custom limited liability company</title>
  <link>https://mailbox.org/en/news/spin-out-mailboxorg-separate-limited-liability-company-gmbh/</link>
  <description>&lt;p&gt;Dear mailbox.org customers,&lt;/p&gt;&lt;p&gt;We would like to wish all of you a happy and healthy year 2021!&lt;/p&gt;&lt;p&gt;Since its inception in 2014, mailbox.org has been operated by the Heinlein Support GmbH - a German company that is active in several areas such as IT-Administrator training, Linux consulting for business, as well as server hosting.&lt;/p&gt;&lt;p&gt;mailbox.org has been growing and prospering continuously to become a successful brand and business unit within our company. We needed to make some changes to put our business on a better foundation for the future, and enable us to manage potential risks more efficiently. That is why we decided to spin out some of our business divisions into separate legal entities.&lt;/p&gt;&lt;p&gt;As a result, the divisions "mailbox.org" and "Heinlein Hosting" are now operating under the banner of the company "Heinlein Hosting GmbH", which is 100% subsidiary to its parent "Heinlein Support GmbH", to independently operate our data centres and our provider for "mailbox.org".&lt;/p&gt;&lt;p&gt;The new "Heinlein Hosting GmbH" enters into all existing supplier or service contracts as well as commissioned data processing contracts as part of the legal succession. Please note that invoices issued as of 1 January 2021 will now legally originate from Heinlein Hosting GmbH. Mail addresses, postal addresses and telephone numbers have not changed.&lt;/p&gt;&lt;p&gt;&lt;br&gt;Private customers&lt;/p&gt;&lt;p&gt;As a private customer with an "MBO" invoice number, you continue to pay into our account at the "Sozialbank" as indicated on the invoices.&lt;/p&gt;&lt;p&gt;&lt;br&gt;Business customer&lt;/p&gt;&lt;p&gt;As a business customer, please use the newly established "Postbank" account, as indicated on your invoices. - We kindly ask our business customers to amend their contract, invoice or supplier master data accordingly, if necessary. Thank you for your cooperation - we apologise for any inconvenience this change may cause at your end.&lt;br&gt;&lt;br&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;See below the key information about our spin-off company:&lt;/p&gt;&lt;p&gt;Heinlein Hosting GmbH&lt;br&gt;Schwedter Str. 8/9b, D-10119 Berlin&lt;br&gt;German tax number 37/337/50030&lt;br&gt;International sales tax identification number: DE335125423&lt;br&gt;Commercial register number: HRB 220010 B&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Best regards,&lt;br&gt;Your mailbox.org team&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-04/mailbox-news-und-updates-produktupdate.jpg?itok=VmAEEH73" type="image/jpeg" length="400284"/><guid isPermaLink="false">a7f2a1c0-4565-49f6-98ef-2f811c2c92e8</guid>
    <pubDate>Tue, 12 Jan 2021 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Spin-off of mailbox.org into a custom limited liability company</dc:title>
    <dc:identifier>a7f2a1c0-4565-49f6-98ef-2f811c2c92e8</dc:identifier>
    </item>
<item>
  <title>mailbox.org launches secure video conferencing</title>
  <link>https://mailbox.org/en/news/mailboxorg-rolls-out-secure-video-conferences-business-customers-and-schools/</link>
  <description>&lt;ul&gt;&lt;li&gt;Video conferences with up to 25 participants for businesses&lt;/li&gt;&lt;li&gt;Schools and teachers benefit from a special plan supporting up to 50 participants&lt;/li&gt;&lt;li&gt;Encrypted connections and unlimited conference duration&lt;/li&gt;&lt;li&gt;Extended: Included in our basic one-euro-per-month plan until 1 March 2021&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Private customers and team accounts have been using secure video conferences at mailbox.org for a few weeks already. We are pleased to announce that this feature is now also available to all our business customers, and also for schools and their teaching staff.&lt;/p&gt;&lt;p&gt;Hosted in Germany, GDPR-compliant, securely encrypted, easy to use, and inexpensive: Our video conferencing solution, integrated in the mailbox.org Office, is ideal for businesses, schools, and other organizations that value privacy and have a legal duty to protect their data, and those of their customers or students. Our solution is based on an adaptation of the well-known Open Source-Software „Jitsi“.&lt;/p&gt;&lt;h2&gt;Secure video conferences for your business&lt;/h2&gt;&lt;p&gt;Our business customers can now run their own secure video conferences with up to 25 participants, and it certainly couldn't come at a better time, with so many people working from home right now. The video conference feature is available directly in the mailbox.org Office in price plans from 2,50 per month. For a limited time, the feature is also available in our most basic plan for 1 EUR per month.&lt;/p&gt;&lt;h3&gt;Facilitating large conferences with more than 100 participants&lt;/h3&gt;&lt;p&gt;mailbox.org can offer dedicated, closed video conferencing systems to large organizations. These systems can run sessions with more than 100 participants at a time. If you are interested in this solution, please get in touch with our business support team: &lt;a href="https://mailbox.org/mailto:business-support@mailbox.org"&gt;business-support@mailbox.org&lt;/a&gt;&lt;/p&gt;&lt;h2&gt;Secure video conferences for schools and teaching staff&lt;/h2&gt;&lt;p&gt;Many schools and teachers already use mailbox.org for secure e-mail communication that is also compliant with data protection legislation, and for the secure sharing of documents with students and parents. Teachers can now use the video conferencing feature to give classes and deliver instruction synchronously online, and fully GDPR-compliant. This can be a great solution if there is a need to be in quarantine because of Coronavirus but also a need to continue teaching. Specifically for this purpose, we created a special package that gives schools but also individual teachers access to a video conferencing solution for up to 50 participants per session, and no limits on the session duration. For a limited time until 1 March 2021, this feature is also available in our most basic price plan for EUR 1.00 / month.&lt;/p&gt;&lt;p&gt;The school package is available through our support team on request. If you are a school administrator or a teacher and interested in using mailbox.org video conferences for teaching, please contact &lt;a href="https://mailbox.org/mailto:eduvideo@mailbox.org"&gt;eduvideo@mailbox.org&lt;/a&gt; for further information and to let us know your mailbox.org address, and the name of the school you work at.&lt;/p&gt;&lt;h2&gt;Servers are located in Germany&lt;/h2&gt;&lt;p&gt;mailbox.org runs all required servers in data centers that are located in Germany. This is how we can guarantee that any personal data about you, your business, your staff, or your students will be kept secure and compliant with data protection laws, with a trustworthy provider in Germany. This is particularly relevant for European businesses and any organization subject to public law, in light of a recent judicial decision by the European Court of Justice (ECJ) that declared the so-called „US-Privacy Shield“ mechanism void. This has rendered the use of most US-based cloud services in Europe unlawful from a data protection perspective. Please click &lt;a href="https://mailbox.org/de/post/interview-mit-mailbox-org-ceo-peer-heinlein-zum-aus-fuers-privacy-shield"&gt;here&lt;/a&gt; for our interview on the ECJ decision about the US Privacy Shield (In German only).&lt;/p&gt;&lt;h2&gt;This is how it works&lt;/h2&gt;&lt;p&gt;Participants require only a regular web browser to attend (We recommend Firefox or Chrome) – no additional software is required. As an alternative, participants can use the service on mobile devices. There are free apps available for Google Android and Apple iOS.&lt;/p&gt;&lt;p&gt;All connections to mailbox.org video conferences are encrypted. The feature can be used easily and intuitively, especially also by less technically-minded people. Users can set up virtual conference rooms in their mailbox.org Office and assign a room name and a password. Participants receive their invitation links by e-mail.&lt;/p&gt;&lt;p&gt;In addition to video communication, participants can of course also use a text chat and share their screens, document views, etc. with each other.&lt;/p&gt;&lt;h3&gt;Features of mailbox.org video conferencing&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;Runs in the Web browser, no further software installation required&lt;/li&gt;&lt;li&gt;Invite links are sent by e-mail&lt;/li&gt;&lt;li&gt;Up to 25 participants per session for business customers / up to 50 for schools&lt;/li&gt;&lt;li&gt;Unlimited session duration&lt;/li&gt;&lt;li&gt;Share your screen or presentation slides&lt;/li&gt;&lt;li&gt;Text-based chat with moderation features&lt;/li&gt;&lt;li&gt;Participant management (muting of participants, etc.)&lt;/li&gt;&lt;li&gt;Participants do not need to have an existing mailbox.org account&lt;/li&gt;&lt;li&gt;Free Jitsi apps for mobile devices&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Prices and availability&lt;/h2&gt;&lt;p&gt;mailbox.org video conferencing is available now in our price plans from EUR 2,50 per month and user. To continue supporting our users in times of COVID-19, video conferences are currently also available free of charge in the basic “Secure Mail” package (EUR 1 per month), until the 1. March 2021.&lt;/p&gt;&lt;h3&gt;More information&lt;/h3&gt;&lt;p&gt;Want to know more? Use our knowledge base and FAQ to find out everything about the topic &lt;a href="https://kb.mailbox.org/display/MBOKBEN/Video+conferencing+FAQ" target="_blank" rel="noopener"&gt;video conferences at mailbox.org&lt;/a&gt;.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-mailbox-meet-update.jpeg?itok=usSiHx_u" type="image/jpeg" length="336340"/><guid isPermaLink="false">4502c1e4-29fc-4a22-b250-699b40858918</guid>
    <pubDate>Wed, 25 Nov 2020 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>mailbox.org launches secure video conferencing</dc:title>
    <dc:identifier>4502c1e4-29fc-4a22-b250-699b40858918</dc:identifier>
    </item>
<item>
  <title>mailbox.org launches secure video conferencing</title>
  <link>https://mailbox.org/en/news/mailboxorg-rolls-out-secure-video-conferences-business-customers-and-schools/</link>
  <description>&lt;ul&gt;&lt;li&gt;Video conferences with up to 25 participants for businesses&lt;/li&gt;&lt;li&gt;Schools and teachers benefit from a special plan supporting up to 50 participants&lt;/li&gt;&lt;li&gt;Encrypted connections and unlimited conference duration&lt;/li&gt;&lt;li&gt;Extended: Included in our basic one-euro-per-month plan until 1 March 2021&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Private customers and team accounts have been using secure video conferences at mailbox.org for a few weeks already. We are pleased to announce that this feature is now also available to all our business customers, and also for schools and their teaching staff.&lt;/p&gt;&lt;p&gt;Hosted in Germany, GDPR-compliant, securely encrypted, easy to use, and inexpensive: Our video conferencing solution, integrated in the mailbox.org Office, is ideal for businesses, schools, and other organizations that value privacy and have a legal duty to protect their data, and those of their customers or students. Our solution is based on an adaptation of the well-known Open Source-Software „Jitsi“.&lt;/p&gt;&lt;h2&gt;Secure video conferences for your business&lt;/h2&gt;&lt;p&gt;Our business customers can now run their own secure video conferences with up to 25 participants, and it certainly couldn't come at a better time, with so many people working from home right now. The video conference feature is available directly in the mailbox.org Office in price plans from 2,50 per month. For a limited time, the feature is also available in our most basic plan for 1 EUR per month.&lt;/p&gt;&lt;h3&gt;Facilitating large conferences with more than 100 participants&lt;/h3&gt;&lt;p&gt;mailbox.org can offer dedicated, closed video conferencing systems to large organizations. These systems can run sessions with more than 100 participants at a time. If you are interested in this solution, please get in touch with our business support team: &lt;a href="https://mailbox.org/mailto:business-support@mailbox.org"&gt;business-support@mailbox.org&lt;/a&gt;&lt;/p&gt;&lt;h2&gt;Secure video conferences for schools and teaching staff&lt;/h2&gt;&lt;p&gt;Many schools and teachers already use mailbox.org for secure e-mail communication that is also compliant with data protection legislation, and for the secure sharing of documents with students and parents. Teachers can now use the video conferencing feature to give classes and deliver instruction synchronously online, and fully GDPR-compliant. This can be a great solution if there is a need to be in quarantine because of Coronavirus but also a need to continue teaching. Specifically for this purpose, we created a special package that gives schools but also individual teachers access to a video conferencing solution for up to 50 participants per session, and no limits on the session duration. For a limited time until 1 March 2021, this feature is also available in our most basic price plan for EUR 1.00 / month.&lt;/p&gt;&lt;p&gt;The school package is available through our support team on request. If you are a school administrator or a teacher and interested in using mailbox.org video conferences for teaching, please contact &lt;a href="https://mailbox.org/mailto:eduvideo@mailbox.org"&gt;eduvideo@mailbox.org&lt;/a&gt; for further information and to let us know your mailbox.org address, and the name of the school you work at.&lt;/p&gt;&lt;h2&gt;Servers are located in Germany&lt;/h2&gt;&lt;p&gt;mailbox.org runs all required servers in data centers that are located in Germany. This is how we can guarantee that any personal data about you, your business, your staff, or your students will be kept secure and compliant with data protection laws, with a trustworthy provider in Germany. This is particularly relevant for European businesses and any organization subject to public law, in light of a recent judicial decision by the European Court of Justice (ECJ) that declared the so-called „US-Privacy Shield“ mechanism void. This has rendered the use of most US-based cloud services in Europe unlawful from a data protection perspective. Please click &lt;a href="https://mailbox.org/de/post/interview-mit-mailbox-org-ceo-peer-heinlein-zum-aus-fuers-privacy-shield"&gt;here&lt;/a&gt; for our interview on the ECJ decision about the US Privacy Shield (In German only).&lt;/p&gt;&lt;h2&gt;This is how it works&lt;/h2&gt;&lt;p&gt;Participants require only a regular web browser to attend (We recommend Firefox or Chrome) – no additional software is required. As an alternative, participants can use the service on mobile devices. There are free apps available for Google Android and Apple iOS.&lt;/p&gt;&lt;p&gt;All connections to mailbox.org video conferences are encrypted. The feature can be used easily and intuitively, especially also by less technically-minded people. Users can set up virtual conference rooms in their mailbox.org Office and assign a room name and a password. Participants receive their invitation links by e-mail.&lt;/p&gt;&lt;p&gt;In addition to video communication, participants can of course also use a text chat and share their screens, document views, etc. with each other.&lt;/p&gt;&lt;h3&gt;Features of mailbox.org video conferencing&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;Runs in the Web browser, no further software installation required&lt;/li&gt;&lt;li&gt;Invite links are sent by e-mail&lt;/li&gt;&lt;li&gt;Up to 25 participants per session for business customers / up to 50 for schools&lt;/li&gt;&lt;li&gt;Unlimited session duration&lt;/li&gt;&lt;li&gt;Share your screen or presentation slides&lt;/li&gt;&lt;li&gt;Text-based chat with moderation features&lt;/li&gt;&lt;li&gt;Participant management (muting of participants, etc.)&lt;/li&gt;&lt;li&gt;Participants do not need to have an existing mailbox.org account&lt;/li&gt;&lt;li&gt;Free Jitsi apps for mobile devices&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Prices and availability&lt;/h2&gt;&lt;p&gt;mailbox.org video conferencing is available now in our price plans from EUR 2,50 per month and user. To continue supporting our users in times of COVID-19, video conferences are currently also available free of charge in the basic “Secure Mail” package (EUR 1 per month), until the 1. March 2021.&lt;/p&gt;&lt;h3&gt;More information&lt;/h3&gt;&lt;p&gt;Want to know more? Use our knowledge base and FAQ to find out everything about the topic &lt;a href="https://kb.mailbox.org/display/MBOKBEN/Video+conferencing+FAQ" target="_blank" rel="noopener"&gt;video conferences at mailbox.org&lt;/a&gt;.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-mailbox-meet-update.jpeg?itok=usSiHx_u" type="image/jpeg" length="336340"/><guid isPermaLink="false">4502c1e4-29fc-4a22-b250-699b40858918</guid>
    <pubDate>Wed, 25 Nov 2020 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>mailbox.org launches secure video conferencing</dc:title>
    <dc:identifier>4502c1e4-29fc-4a22-b250-699b40858918</dc:identifier>
    </item>
<item>
  <title>Integration of additional external cloud storage</title>
  <link>https://mailbox.org/en/news/mailboxorg-office-update-allows-integration-additional-external-cloud-storage/</link>
  <description>&lt;p&gt;Our current release 7.10.4 of our mailbox.org Office contains two main improvements: The integration of further external cloud services as well as the possibility to use own, especially secure PGP key pairs with our mailbox.org Guard.&lt;br&gt;&lt;br&gt;&amp;nbsp;&lt;/p&gt;&lt;h3&gt;Integration of further external cloud storage&lt;/h3&gt;&lt;p&gt;mailbox.org combines not only e-mail, online office and recently also &lt;a href="https://mailbox.org/en/services#video-conferencing" target="_blank" rel="noopener"&gt;video conferencing&lt;/a&gt; in one platform, but also a cloud storage for your documents and (image) files. You are free to use our own "drive" storage or integrate external services such as Dropbox, Microsoft, Box.com or Google.&lt;/p&gt;&lt;p&gt;From now on you can also use the cloud services ownCloud and Nextcloud as well as the WebDAV protocol in the mailbox.org Office and integrate your files into the mailbox.org platform via these services. So you have all your data conveniently bundled in the mailbox.org Office.&lt;/p&gt;&lt;p&gt;Quick guide: Connecting external cloud storage in the "Drive" is very simple: Click on "Add storage account", select the cloud service to be connected in the window that now opens, enter the requested credentials, click on "Add" and you have access to your other data storage.&lt;br&gt;Your files from the external cloud are displayed below your own mailbox.org cloud, similar to integrated calendars or address books.&lt;/p&gt;&lt;h3&gt;&lt;br&gt;Upload your own secure PGP key pairs&lt;/h3&gt;&lt;p&gt;Customers who use our mailbox.org Guard in their webmailer for email encryption can now upload their own PGP key pairs, which were created using the ed25519 algorithm, to Guard and use them for email encryption. This allows our customers to use one of the currently most secure encryption variants on the mailbox.org platform and further increase their security in e-mail communication.&lt;/p&gt;&lt;h3&gt;&lt;br&gt;Change in the design of the webmailer&lt;/h3&gt;&lt;p&gt;Not only on a technical level, but also in the design there are innovations. For example, the window for composing an e-mail has been revised. A more modern design now offers more clarity when writing an e-mail.&lt;/p&gt;&lt;h3&gt;&lt;br&gt;Bugfixes in the new version&lt;/h3&gt;&lt;p&gt;The following issues could be fixed with the update to version 7.10.4:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Reminder emails: From now on your time zone is used and a conversion from UTC to local time is not necessary.&lt;/li&gt;&lt;li&gt;Attachments visible everywhere: No matter which device you use, e.g. smartphone, desktop etc., now all attachments are immediately visible in every client (Thunderbird, email app).&lt;/li&gt;&lt;li&gt;Standard fonts &amp;amp; signature: On the web interface, the default font you set is now displayed even if you have selected a different font for the e-mail signature.&lt;/li&gt;&lt;/ul&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-drive-2.png?itok=FYPdRtHq" type="image/png" length="309230"/><guid isPermaLink="false">28faa45f-ff7a-4f34-b3c9-3fcda3396e23</guid>
    <pubDate>Thu, 08 Oct 2020 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Integration of additional external cloud storage</dc:title>
    <dc:identifier>28faa45f-ff7a-4f34-b3c9-3fcda3396e23</dc:identifier>
    </item>
<item>
  <title>Integration of additional external cloud storage</title>
  <link>https://mailbox.org/en/news/mailboxorg-office-update-allows-integration-additional-external-cloud-storage/</link>
  <description>&lt;p&gt;Our current release 7.10.4 of our mailbox.org Office contains two main improvements: The integration of further external cloud services as well as the possibility to use own, especially secure PGP key pairs with our mailbox.org Guard.&lt;br&gt;&lt;br&gt;&amp;nbsp;&lt;/p&gt;&lt;h3&gt;Integration of further external cloud storage&lt;/h3&gt;&lt;p&gt;mailbox.org combines not only e-mail, online office and recently also &lt;a href="https://mailbox.org/en/services#video-conferencing" target="_blank" rel="noopener"&gt;video conferencing&lt;/a&gt; in one platform, but also a cloud storage for your documents and (image) files. You are free to use our own "drive" storage or integrate external services such as Dropbox, Microsoft, Box.com or Google.&lt;/p&gt;&lt;p&gt;From now on you can also use the cloud services ownCloud and Nextcloud as well as the WebDAV protocol in the mailbox.org Office and integrate your files into the mailbox.org platform via these services. So you have all your data conveniently bundled in the mailbox.org Office.&lt;/p&gt;&lt;p&gt;Quick guide: Connecting external cloud storage in the "Drive" is very simple: Click on "Add storage account", select the cloud service to be connected in the window that now opens, enter the requested credentials, click on "Add" and you have access to your other data storage.&lt;br&gt;Your files from the external cloud are displayed below your own mailbox.org cloud, similar to integrated calendars or address books.&lt;/p&gt;&lt;h3&gt;&lt;br&gt;Upload your own secure PGP key pairs&lt;/h3&gt;&lt;p&gt;Customers who use our mailbox.org Guard in their webmailer for email encryption can now upload their own PGP key pairs, which were created using the ed25519 algorithm, to Guard and use them for email encryption. This allows our customers to use one of the currently most secure encryption variants on the mailbox.org platform and further increase their security in e-mail communication.&lt;/p&gt;&lt;h3&gt;&lt;br&gt;Change in the design of the webmailer&lt;/h3&gt;&lt;p&gt;Not only on a technical level, but also in the design there are innovations. For example, the window for composing an e-mail has been revised. A more modern design now offers more clarity when writing an e-mail.&lt;/p&gt;&lt;h3&gt;&lt;br&gt;Bugfixes in the new version&lt;/h3&gt;&lt;p&gt;The following issues could be fixed with the update to version 7.10.4:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Reminder emails: From now on your time zone is used and a conversion from UTC to local time is not necessary.&lt;/li&gt;&lt;li&gt;Attachments visible everywhere: No matter which device you use, e.g. smartphone, desktop etc., now all attachments are immediately visible in every client (Thunderbird, email app).&lt;/li&gt;&lt;li&gt;Standard fonts &amp;amp; signature: On the web interface, the default font you set is now displayed even if you have selected a different font for the e-mail signature.&lt;/li&gt;&lt;/ul&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-drive-2.png?itok=FYPdRtHq" type="image/png" length="309230"/><guid isPermaLink="false">28faa45f-ff7a-4f34-b3c9-3fcda3396e23</guid>
    <pubDate>Thu, 08 Oct 2020 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Integration of additional external cloud storage</dc:title>
    <dc:identifier>28faa45f-ff7a-4f34-b3c9-3fcda3396e23</dc:identifier>
    </item>
<item>
  <title>Expansion to secure video conferencing</title>
  <link>https://mailbox.org/en/news/new-video-conferencing-feature-mailboxorg-office/</link>
  <description>&lt;ul&gt;&lt;li&gt;Ideal for families and small businesses with up to 10 participants per session&lt;/li&gt;&lt;li&gt;Encrypted connections and unlimited session duration&lt;/li&gt;&lt;li&gt;„mailbox.org video conference“ included in the basic € 1 price plan until the end of 2020&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Secure video conferences, hosted in Germany, easy to use, and inexpensive: We are very pleased to announce this new feature as part of the mailbox.org Office, which is available to our private customers as well as team accounts. By integrating secure video conferencing into our service portfolio, we are making the next step towards providing a comprehensive communication platform.&lt;/p&gt;&lt;p&gt;The feature is based on a further development of the open-source software „Jitsi“ and regularly available for all but the most basic of our mail packages. However, in light of the Covid pandemic, we made the new feature also available in our basic €1-per-month “Secure Mail” plan until the end of the year.&lt;/p&gt;&lt;p&gt;mailbox.org runs all the required servers, in data centers that are located in Germany. This is how we can guarantee that any personal data about you, your family members, or your staff will be kept secure and compliant with data protection laws, with a trustworthy provider in Germany. None of the data is being stored or analyzed by American companies, which is important in light of a recent judicial decision by the European Court of Justice (ECJ) that declared the so-called „US-Privacy Shield“ mechanism invalid, rendering the use of most US-based cloud services in Europe unlawful from a data protection perspective. Please read our &lt;a href="https://mailbox.org/de/post/interview-mit-mailbox-org-ceo-peer-heinlein-zum-aus-fuers-privacy-shield"&gt;interview&lt;/a&gt; on the ECJ decision about the US Privacy Shield (in German).&lt;/p&gt;&lt;h2&gt;Video conferences - secure and easy to use&lt;/h2&gt;&lt;p&gt;All connections to mailbox.org video conferences are encrypted. The feature can be used easily and intuitively, especially also by less technically-minded people. Users can set up virtual conference rooms in their mailbox.org Office and assign a room name and a password, if desired. Participants receive their invitation links by e-mail.&lt;/p&gt;&lt;p&gt;Being secure and easy to use, our new video conferencing feature is not only interesting for businesses, small teams, and training sessions, but also for private use, also considering that due to the Corona pandemic, it can be difficult for friends and family to meet in person. For the time being, there is a limit of 10 participants per conference session.&lt;/p&gt;&lt;p&gt;mailbox.org can offer dedicated, closed video conferencing systems to large organizations. These systems allow sessions with more than 100 participants. If you are interested in such a solution, please get in touch: &lt;a href="https://mailbox.org/mailto:business-support@mailbox.org"&gt;business-support@mailbox.org&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Participants require only a regular web browser to attend (We recommend Firefox or Chrome) – no additional software is required. As an alternative, participants can use the service on mobile devices. There are free apps available for Google Android and Apple iOS.&lt;/p&gt;&lt;p&gt;In addition to the core video conferencing functionality, it is also possible to communicate via chat or share one's screen or presentations slides during a session.&lt;/p&gt;&lt;h2&gt;mailbox.org video conference – the features:&lt;/h2&gt;&lt;ul&gt;&lt;li&gt;Runs in the Web browser, no further software installation necessary&lt;/li&gt;&lt;li&gt;Invite links are sent by e-mail&lt;/li&gt;&lt;li&gt;Up to 10 participants per session&lt;/li&gt;&lt;li&gt;Unlimited session duration&lt;/li&gt;&lt;li&gt;Share your screen and show presentation slides&lt;/li&gt;&lt;li&gt;Text-based chat with moderation features&lt;/li&gt;&lt;li&gt;Participant management, such as the muting of individual attendees&lt;/li&gt;&lt;li&gt;Securely encrypted connections&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Prices and availability&lt;/h2&gt;&lt;p&gt;mailbox.org video conferencing is available now in our price plans starting with „Team-Mail“ (EUR 2,50 per month and user), which includes 5 GB Mail storage, 25 aliases, and further team- and groupware features.&lt;/p&gt;&lt;p&gt;To support our users in times of COVID-19, video conferences are currently also available in the basic “Secure Mail” package (EUR 1 per month), up until 31 December 2020.&lt;/p&gt;&lt;p&gt;Over the first few weeks of running the service, we will be monitoring general usage to gather more experience about the extent to which video conferencing is used by our customers. This is necessary to enable us to optimally provision and scale the computing capacity that is required for videoconferencing. The service will start in a beta phase at first. As we gain more experience, we will be able to adapt and expand the offer in the medium term.&lt;/p&gt;&lt;h3&gt;Further information&lt;/h3&gt;&lt;p&gt;In our knowledge base you will find further information as well as a number of FAQs about &lt;a href="https://kb.mailbox.org/display/MBOKBEN/Video+conferencing+FAQ?beecom.language=en" target="_blank" rel="noopener"&gt;video conferencing at mailbox.org&lt;/a&gt;.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-mailbox-meet-update-1.jpg?itok=58F0QRRO" type="image/jpeg" length="353603"/><guid isPermaLink="false">6a37b168-e70e-41cb-a864-0820e7138a80</guid>
    <pubDate>Wed, 30 Sep 2020 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Expansion to secure video conferencing</dc:title>
    <dc:identifier>6a37b168-e70e-41cb-a864-0820e7138a80</dc:identifier>
    </item>
<item>
  <title>Expansion to secure video conferencing</title>
  <link>https://mailbox.org/en/news/new-video-conferencing-feature-mailboxorg-office/</link>
  <description>&lt;ul&gt;&lt;li&gt;Ideal for families and small businesses with up to 10 participants per session&lt;/li&gt;&lt;li&gt;Encrypted connections and unlimited session duration&lt;/li&gt;&lt;li&gt;„mailbox.org video conference“ included in the basic € 1 price plan until the end of 2020&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Secure video conferences, hosted in Germany, easy to use, and inexpensive: We are very pleased to announce this new feature as part of the mailbox.org Office, which is available to our private customers as well as team accounts. By integrating secure video conferencing into our service portfolio, we are making the next step towards providing a comprehensive communication platform.&lt;/p&gt;&lt;p&gt;The feature is based on a further development of the open-source software „Jitsi“ and regularly available for all but the most basic of our mail packages. However, in light of the Covid pandemic, we made the new feature also available in our basic €1-per-month “Secure Mail” plan until the end of the year.&lt;/p&gt;&lt;p&gt;mailbox.org runs all the required servers, in data centers that are located in Germany. This is how we can guarantee that any personal data about you, your family members, or your staff will be kept secure and compliant with data protection laws, with a trustworthy provider in Germany. None of the data is being stored or analyzed by American companies, which is important in light of a recent judicial decision by the European Court of Justice (ECJ) that declared the so-called „US-Privacy Shield“ mechanism invalid, rendering the use of most US-based cloud services in Europe unlawful from a data protection perspective. Please read our &lt;a href="https://mailbox.org/de/post/interview-mit-mailbox-org-ceo-peer-heinlein-zum-aus-fuers-privacy-shield"&gt;interview&lt;/a&gt; on the ECJ decision about the US Privacy Shield (in German).&lt;/p&gt;&lt;h2&gt;Video conferences - secure and easy to use&lt;/h2&gt;&lt;p&gt;All connections to mailbox.org video conferences are encrypted. The feature can be used easily and intuitively, especially also by less technically-minded people. Users can set up virtual conference rooms in their mailbox.org Office and assign a room name and a password, if desired. Participants receive their invitation links by e-mail.&lt;/p&gt;&lt;p&gt;Being secure and easy to use, our new video conferencing feature is not only interesting for businesses, small teams, and training sessions, but also for private use, also considering that due to the Corona pandemic, it can be difficult for friends and family to meet in person. For the time being, there is a limit of 10 participants per conference session.&lt;/p&gt;&lt;p&gt;mailbox.org can offer dedicated, closed video conferencing systems to large organizations. These systems allow sessions with more than 100 participants. If you are interested in such a solution, please get in touch: &lt;a href="https://mailbox.org/mailto:business-support@mailbox.org"&gt;business-support@mailbox.org&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Participants require only a regular web browser to attend (We recommend Firefox or Chrome) – no additional software is required. As an alternative, participants can use the service on mobile devices. There are free apps available for Google Android and Apple iOS.&lt;/p&gt;&lt;p&gt;In addition to the core video conferencing functionality, it is also possible to communicate via chat or share one's screen or presentations slides during a session.&lt;/p&gt;&lt;h2&gt;mailbox.org video conference – the features:&lt;/h2&gt;&lt;ul&gt;&lt;li&gt;Runs in the Web browser, no further software installation necessary&lt;/li&gt;&lt;li&gt;Invite links are sent by e-mail&lt;/li&gt;&lt;li&gt;Up to 10 participants per session&lt;/li&gt;&lt;li&gt;Unlimited session duration&lt;/li&gt;&lt;li&gt;Share your screen and show presentation slides&lt;/li&gt;&lt;li&gt;Text-based chat with moderation features&lt;/li&gt;&lt;li&gt;Participant management, such as the muting of individual attendees&lt;/li&gt;&lt;li&gt;Securely encrypted connections&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Prices and availability&lt;/h2&gt;&lt;p&gt;mailbox.org video conferencing is available now in our price plans starting with „Team-Mail“ (EUR 2,50 per month and user), which includes 5 GB Mail storage, 25 aliases, and further team- and groupware features.&lt;/p&gt;&lt;p&gt;To support our users in times of COVID-19, video conferences are currently also available in the basic “Secure Mail” package (EUR 1 per month), up until 31 December 2020.&lt;/p&gt;&lt;p&gt;Over the first few weeks of running the service, we will be monitoring general usage to gather more experience about the extent to which video conferencing is used by our customers. This is necessary to enable us to optimally provision and scale the computing capacity that is required for videoconferencing. The service will start in a beta phase at first. As we gain more experience, we will be able to adapt and expand the offer in the medium term.&lt;/p&gt;&lt;h3&gt;Further information&lt;/h3&gt;&lt;p&gt;In our knowledge base you will find further information as well as a number of FAQs about &lt;a href="https://kb.mailbox.org/display/MBOKBEN/Video+conferencing+FAQ?beecom.language=en" target="_blank" rel="noopener"&gt;video conferencing at mailbox.org&lt;/a&gt;.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-mailbox-meet-update-1.jpg?itok=58F0QRRO" type="image/jpeg" length="353603"/><guid isPermaLink="false">6a37b168-e70e-41cb-a864-0820e7138a80</guid>
    <pubDate>Wed, 30 Sep 2020 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Expansion to secure video conferencing</dc:title>
    <dc:identifier>6a37b168-e70e-41cb-a864-0820e7138a80</dc:identifier>
    </item>
<item>
  <title>Security adjustments and deactivation of functions</title>
  <link>https://mailbox.org/en/news/security-adjustment-and-deactivation-certain-mail-functions/</link>
  <description>&lt;p&gt;Dear users of mailbox.org,&lt;/p&gt;&lt;p&gt;we will make some security adjustments to mailbox.org in the next few weeks, which may affect you personally. Please briefly note the following information:&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;As of September 16, 2020&lt;/p&gt;&lt;h2&gt;Discontinuation of TLS 1.0 and 1.1 support&lt;/h2&gt;&lt;p&gt;All connections to mailbox.org are always encrypted with SSL/TLS. No matter whether web pages (https) or mail receiving/sending (POP3, IMAP, SMTP). On September 16th we will discontinue support for the obsolete and no longer sufficiently secure TLS protocols TLS 1.0 and TLS 1.1 and instead only support the current TLS 1.2 and TLS 1.3. Fewer than 100 users still use old e-mail programs with the outdated TLS procedures. These users have been contacted by us in the last few weeks and must obtain more recent software versions; otherwise a connection to mailbox.org will no longer be possible.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;As of September 29, 2020&lt;/p&gt;&lt;h2&gt;Sending e-mails only possible with registered e-mail addresses/aliases&lt;/h2&gt;&lt;p&gt;With effect from September 29, 2020, our mail servers will only allow those senders from an account who are also assigned to this account as mail address or alias. This will help us to prevent forgeries of senders.&lt;/p&gt;&lt;p&gt;In individual cases, however, private and some business customers use mailbox.org accounts to send e-mails with senders they have registered at other providers. This will then no longer be possible - the respective addresses must be explicitly created or at least assigned as "catch-all".&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;As of September 30, 2020&lt;/p&gt;&lt;h2&gt;DKIM signatures for all outgoing e-mails&lt;/h2&gt;&lt;p&gt;We have been signing all e-mails sent through us with DKIM signatures for a long time. This prevents sender forgery and phishing attacks and significantly reduces the risk of e-mails from other providers being filtered into the suspected spam folder. Some of our users also sends e-mails with mailbox.org sender addresses via other ISPs, so that these e-mails do not have a DKIM signature from mailbox.org. For this reason, we have not been able to inform other providers via the so-called "DMARC" rules that 100% of our mailbox.org e-mails must have DKIM signatures in any case and that if this signature is missing, it must be a phishing e-mail or other forged sender addresses.&lt;/p&gt;&lt;p&gt;However, an increasing number of providers, including the industry giants, are demanding restrictive DMARC regulations and require 100% fully signed emails. With effect from September 30, 2020, we will therefore also make our SPF/DMARC/DKIM rules more restrictive. E-mails with mailbox.org senders that were not sent via our servers but via other providers could be rejected completely or filtered into spam folders. Our users must ensure that e-mails with our senders are always actually sent via our SMTP servers.&lt;/p&gt;&lt;p&gt;Best wishes,&lt;br&gt;Your mailbox.org team&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-04/mailbox-news-und-updates-warnung.jpg?itok=reW9cU74" type="image/jpeg" length="238141"/><guid isPermaLink="false">78327df9-d422-43de-bad9-b58ecc0ccb82</guid>
    <pubDate>Fri, 11 Sep 2020 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Security adjustments and deactivation of functions</dc:title>
    <dc:identifier>78327df9-d422-43de-bad9-b58ecc0ccb82</dc:identifier>
    </item>
<item>
  <title>Security adjustments and deactivation of functions</title>
  <link>https://mailbox.org/en/news/security-adjustment-and-deactivation-certain-mail-functions/</link>
  <description>&lt;p&gt;Dear users of mailbox.org,&lt;/p&gt;&lt;p&gt;we will make some security adjustments to mailbox.org in the next few weeks, which may affect you personally. Please briefly note the following information:&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;As of September 16, 2020&lt;/p&gt;&lt;h2&gt;Discontinuation of TLS 1.0 and 1.1 support&lt;/h2&gt;&lt;p&gt;All connections to mailbox.org are always encrypted with SSL/TLS. No matter whether web pages (https) or mail receiving/sending (POP3, IMAP, SMTP). On September 16th we will discontinue support for the obsolete and no longer sufficiently secure TLS protocols TLS 1.0 and TLS 1.1 and instead only support the current TLS 1.2 and TLS 1.3. Fewer than 100 users still use old e-mail programs with the outdated TLS procedures. These users have been contacted by us in the last few weeks and must obtain more recent software versions; otherwise a connection to mailbox.org will no longer be possible.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;As of September 29, 2020&lt;/p&gt;&lt;h2&gt;Sending e-mails only possible with registered e-mail addresses/aliases&lt;/h2&gt;&lt;p&gt;With effect from September 29, 2020, our mail servers will only allow those senders from an account who are also assigned to this account as mail address or alias. This will help us to prevent forgeries of senders.&lt;/p&gt;&lt;p&gt;In individual cases, however, private and some business customers use mailbox.org accounts to send e-mails with senders they have registered at other providers. This will then no longer be possible - the respective addresses must be explicitly created or at least assigned as "catch-all".&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;As of September 30, 2020&lt;/p&gt;&lt;h2&gt;DKIM signatures for all outgoing e-mails&lt;/h2&gt;&lt;p&gt;We have been signing all e-mails sent through us with DKIM signatures for a long time. This prevents sender forgery and phishing attacks and significantly reduces the risk of e-mails from other providers being filtered into the suspected spam folder. Some of our users also sends e-mails with mailbox.org sender addresses via other ISPs, so that these e-mails do not have a DKIM signature from mailbox.org. For this reason, we have not been able to inform other providers via the so-called "DMARC" rules that 100% of our mailbox.org e-mails must have DKIM signatures in any case and that if this signature is missing, it must be a phishing e-mail or other forged sender addresses.&lt;/p&gt;&lt;p&gt;However, an increasing number of providers, including the industry giants, are demanding restrictive DMARC regulations and require 100% fully signed emails. With effect from September 30, 2020, we will therefore also make our SPF/DMARC/DKIM rules more restrictive. E-mails with mailbox.org senders that were not sent via our servers but via other providers could be rejected completely or filtered into spam folders. Our users must ensure that e-mails with our senders are always actually sent via our SMTP servers.&lt;/p&gt;&lt;p&gt;Best wishes,&lt;br&gt;Your mailbox.org team&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-04/mailbox-news-und-updates-warnung.jpg?itok=reW9cU74" type="image/jpeg" length="238141"/><guid isPermaLink="false">78327df9-d422-43de-bad9-b58ecc0ccb82</guid>
    <pubDate>Fri, 11 Sep 2020 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Security adjustments and deactivation of functions</dc:title>
    <dc:identifier>78327df9-d422-43de-bad9-b58ecc0ccb82</dc:identifier>
    </item>
<item>
  <title>TLS 1.3: Secure email and transport encryption</title>
  <link>https://mailbox.org/en/news/tls-13-secure-email-and-transport-encryption-mailboxorg/</link>
  <description>&lt;ul&gt;&lt;li&gt;Encryption mechanisms updated on our server infrastructure&lt;/li&gt;&lt;li&gt;Better security for e-mails, calendars, contacts, and file transmission&lt;br&gt;&lt;br&gt;&amp;nbsp;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;The mailbox.org Office now offers better security for the sending of e-mails by supporting the improved HTTPS transport layer security protocol „TLS 1.3“, which presents the most recent SSL/TLS standard that is currently available. This new version offers better security because some obsolete encryption mechanisms („Ciphers“) were removed, and also because structural security issues that were inherent in older TLS protocol versions have been fixed. Being able to support the latest state of the art in encryption is crucial for us to maintaining the privacy and data protection that is so important for our users.&lt;/p&gt;&lt;p&gt;Aside from improved security, there is another major benefit to using TLS 1.3: With the new protocol, it usually takes less time to establish a connection. While this does not increase the basic transmission speed for data or e-mail downloads, it makes interactive websites like our mailbox.org Office much more snappy to use. Applications that handle a large number of separate web requests will see improved usability, as the servers can now respond quicker to these individual requests.&lt;/p&gt;&lt;p&gt;All modern Web browsers already support TLS 1.3, for example Chrome 70, Firefox 63, MS Edge 76 and also Safari with MacOS 10.14.4 or higher. From a user perspective, nothing really changes as the encryption protocol operates in the background.&lt;br&gt;&lt;br&gt;&amp;nbsp;&lt;/p&gt;&lt;h3&gt;What is TLS?&lt;/h3&gt;&lt;p&gt;TLS („Transport Layer Security“) is a mechanism for communication partners on the Internet (such as a Web browser and a Web server) to encrypt the data that is being transmitted between the two. To do this, the browser and the server will negotiate the security standard to use for encryption and agree on the best one that is available to both. So, if you use a reasonably modern browser and log on to our mailbox.org Office, you will now get to enjoy the most secure TLS 1.3 encryption standard.&lt;br&gt;&lt;br&gt;&amp;nbsp;&lt;/p&gt;&lt;h3&gt;mailbox.org: Always aiming to use the best encryption mechanisms available&lt;/h3&gt;&lt;p&gt;Offering support for TLS 1.3 has been on our roadmap for some time, in line with our general aim to always offer the best encryption mechanisms for e-mail and web-mail applications. Within the last few weeks, new Linux versions have been released for the particular distributions that we use as operating systems on our servers, and these do now support OpenSSL with TLS 1.3 out of the box. - For stability and security reasons, we decided to wait until the new protocol was properly supported by those distributions.&lt;br&gt;&lt;br&gt;&amp;nbsp;&lt;/p&gt;&lt;h3&gt;Sending e-mails with TLS 1.3 available soon&lt;/h3&gt;&lt;p&gt;Currently, not all of our services can actually operate with TLS 1.3 just yet. We will be upgrading services such as XMPP Web chat, some of the less important API servers, and the user forum over the next few weeks to support TLS 1.3. Our mail servers will get their regular updates in the next few weeks also, and it will then be possible to send e-mails securely using TLS 1.3, given the providers on the receiving end also support the new protocol.&lt;/p&gt;&lt;p&gt;Upgrading servers during regular operation is something that requires careful handling, thorough testing, and absolute focus on the task. So, please bear with us as we are finishing the task step by step over the coming weeks. Soon, our team will be at full strength again once everyone has returned from their summer vacation.&lt;br&gt;&lt;br&gt;&amp;nbsp;&lt;/p&gt;&lt;h3&gt;TLS 1.0 and lower no longer secure – mailbox.org does not support outdated protocols&lt;/h3&gt;&lt;p&gt;Please note: Outdated SSL mechanisms like SSLv2, SSLv3, and also TLS 1.0 are no longer considered sufficiently secure for Internet communication use. The German Federal Office for Information Security has advised to not use these anymore. While there are still e-mail providers around that keep supporting TLS 1.0, to us this is a “No-Go” from a security and privacy perspective. - For security and data protection reasons, mailbox.org stopped supporting TLS 1.0 as well as TLS 1.1 a while ago.&lt;/p&gt;&lt;p&gt;Best wishes,&lt;br&gt;Your mailbox.org team&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-04/mailbox-news-und-updates-sicherheit.jpg?itok=4LMJmUnZ" type="image/jpeg" length="194998"/><guid isPermaLink="false">ac824bfa-4ea0-4de8-a894-dc03805236e5</guid>
    <pubDate>Thu, 30 Jul 2020 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>TLS 1.3: Secure email and transport encryption</dc:title>
    <dc:identifier>ac824bfa-4ea0-4de8-a894-dc03805236e5</dc:identifier>
    </item>
<item>
  <title>TLS 1.3: Secure email and transport encryption</title>
  <link>https://mailbox.org/en/news/tls-13-secure-email-and-transport-encryption-mailboxorg/</link>
  <description>&lt;ul&gt;&lt;li&gt;Encryption mechanisms updated on our server infrastructure&lt;/li&gt;&lt;li&gt;Better security for e-mails, calendars, contacts, and file transmission&lt;br&gt;&lt;br&gt;&amp;nbsp;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;The mailbox.org Office now offers better security for the sending of e-mails by supporting the improved HTTPS transport layer security protocol „TLS 1.3“, which presents the most recent SSL/TLS standard that is currently available. This new version offers better security because some obsolete encryption mechanisms („Ciphers“) were removed, and also because structural security issues that were inherent in older TLS protocol versions have been fixed. Being able to support the latest state of the art in encryption is crucial for us to maintaining the privacy and data protection that is so important for our users.&lt;/p&gt;&lt;p&gt;Aside from improved security, there is another major benefit to using TLS 1.3: With the new protocol, it usually takes less time to establish a connection. While this does not increase the basic transmission speed for data or e-mail downloads, it makes interactive websites like our mailbox.org Office much more snappy to use. Applications that handle a large number of separate web requests will see improved usability, as the servers can now respond quicker to these individual requests.&lt;/p&gt;&lt;p&gt;All modern Web browsers already support TLS 1.3, for example Chrome 70, Firefox 63, MS Edge 76 and also Safari with MacOS 10.14.4 or higher. From a user perspective, nothing really changes as the encryption protocol operates in the background.&lt;br&gt;&lt;br&gt;&amp;nbsp;&lt;/p&gt;&lt;h3&gt;What is TLS?&lt;/h3&gt;&lt;p&gt;TLS („Transport Layer Security“) is a mechanism for communication partners on the Internet (such as a Web browser and a Web server) to encrypt the data that is being transmitted between the two. To do this, the browser and the server will negotiate the security standard to use for encryption and agree on the best one that is available to both. So, if you use a reasonably modern browser and log on to our mailbox.org Office, you will now get to enjoy the most secure TLS 1.3 encryption standard.&lt;br&gt;&lt;br&gt;&amp;nbsp;&lt;/p&gt;&lt;h3&gt;mailbox.org: Always aiming to use the best encryption mechanisms available&lt;/h3&gt;&lt;p&gt;Offering support for TLS 1.3 has been on our roadmap for some time, in line with our general aim to always offer the best encryption mechanisms for e-mail and web-mail applications. Within the last few weeks, new Linux versions have been released for the particular distributions that we use as operating systems on our servers, and these do now support OpenSSL with TLS 1.3 out of the box. - For stability and security reasons, we decided to wait until the new protocol was properly supported by those distributions.&lt;br&gt;&lt;br&gt;&amp;nbsp;&lt;/p&gt;&lt;h3&gt;Sending e-mails with TLS 1.3 available soon&lt;/h3&gt;&lt;p&gt;Currently, not all of our services can actually operate with TLS 1.3 just yet. We will be upgrading services such as XMPP Web chat, some of the less important API servers, and the user forum over the next few weeks to support TLS 1.3. Our mail servers will get their regular updates in the next few weeks also, and it will then be possible to send e-mails securely using TLS 1.3, given the providers on the receiving end also support the new protocol.&lt;/p&gt;&lt;p&gt;Upgrading servers during regular operation is something that requires careful handling, thorough testing, and absolute focus on the task. So, please bear with us as we are finishing the task step by step over the coming weeks. Soon, our team will be at full strength again once everyone has returned from their summer vacation.&lt;br&gt;&lt;br&gt;&amp;nbsp;&lt;/p&gt;&lt;h3&gt;TLS 1.0 and lower no longer secure – mailbox.org does not support outdated protocols&lt;/h3&gt;&lt;p&gt;Please note: Outdated SSL mechanisms like SSLv2, SSLv3, and also TLS 1.0 are no longer considered sufficiently secure for Internet communication use. The German Federal Office for Information Security has advised to not use these anymore. While there are still e-mail providers around that keep supporting TLS 1.0, to us this is a “No-Go” from a security and privacy perspective. - For security and data protection reasons, mailbox.org stopped supporting TLS 1.0 as well as TLS 1.1 a while ago.&lt;/p&gt;&lt;p&gt;Best wishes,&lt;br&gt;Your mailbox.org team&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-04/mailbox-news-und-updates-sicherheit.jpg?itok=4LMJmUnZ" type="image/jpeg" length="194998"/><guid isPermaLink="false">ac824bfa-4ea0-4de8-a894-dc03805236e5</guid>
    <pubDate>Thu, 30 Jul 2020 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>TLS 1.3: Secure email and transport encryption</dc:title>
    <dc:identifier>ac824bfa-4ea0-4de8-a894-dc03805236e5</dc:identifier>
    </item>
<item>
  <title>New option for loading external images in Webmail</title>
  <link>https://mailbox.org/en/news/new-setting-downloading-externally-hosted-images-emails/</link>
  <description>&lt;p&gt;In order to best protect our mailbox.org customers, externally hosted images that are linked up in e-mails, such as newsletters, will normally not be downloaded and displayed automatically in the Webmail interface. This is because oftentimes, these kinds of images are also being used for tracking the recipient's reading behavior and topic interest.&lt;/p&gt;&lt;p&gt;If they get a message by a sender they trust, users can easily enable the display of any external images while viewing that e-mail. Further, it is also possible to trigger the automatic download and display of externally linked images for particular senders or domains. To do this, click on the cogwheel symbol in the upper-right corner of your Webmail window to access “Settings” and then click on “Security” to see the relevant options. Many will find this to be a useful feature, especially for any wanted communications that are recurring, such as product updates or newsletters.&lt;br&gt;&lt;br&gt;Feedback received by our customer support team suggests that even though there is the tracking issue, some of our users would prefer to have externally hosted images in their e-mails downloaded automatically, regardless of the sender or domain where these are hosted. This is now possible on the same screen (go to “Settings” → “Security”) by checking the box that says „Allow pre-loading of externally linked images“ (see screen snapshot).&lt;/p&gt;&lt;p&gt;Please be aware that by enabling this feature without specifying any restrictions regarding the permitted domains or senders, the Webmail client will automatically download all images in all e-mails.&amp;nbsp;&lt;br&gt;&lt;br&gt;It is important to understand that this will also include images that form part of any spam or phishing e-mails you might receive. As a consequence, not restricting this feature will make it harder for you to detect and avoid malicious e-mails. For this reason, the feature is disabled by default. If a user wants to enable it, they need to do so manually.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-envelope-2.png?itok=VczfRatn" type="image/png" length="349291"/><guid isPermaLink="false">c7fbfc19-8798-479c-a18a-4ce19a57825a</guid>
    <pubDate>Fri, 24 Jul 2020 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>New option for loading external images in Webmail</dc:title>
    <dc:identifier>c7fbfc19-8798-479c-a18a-4ce19a57825a</dc:identifier>
    </item>
<item>
  <title>New option for loading external images in Webmail</title>
  <link>https://mailbox.org/en/news/new-setting-downloading-externally-hosted-images-emails/</link>
  <description>&lt;p&gt;In order to best protect our mailbox.org customers, externally hosted images that are linked up in e-mails, such as newsletters, will normally not be downloaded and displayed automatically in the Webmail interface. This is because oftentimes, these kinds of images are also being used for tracking the recipient's reading behavior and topic interest.&lt;/p&gt;&lt;p&gt;If they get a message by a sender they trust, users can easily enable the display of any external images while viewing that e-mail. Further, it is also possible to trigger the automatic download and display of externally linked images for particular senders or domains. To do this, click on the cogwheel symbol in the upper-right corner of your Webmail window to access “Settings” and then click on “Security” to see the relevant options. Many will find this to be a useful feature, especially for any wanted communications that are recurring, such as product updates or newsletters.&lt;br&gt;&lt;br&gt;Feedback received by our customer support team suggests that even though there is the tracking issue, some of our users would prefer to have externally hosted images in their e-mails downloaded automatically, regardless of the sender or domain where these are hosted. This is now possible on the same screen (go to “Settings” → “Security”) by checking the box that says „Allow pre-loading of externally linked images“ (see screen snapshot).&lt;/p&gt;&lt;p&gt;Please be aware that by enabling this feature without specifying any restrictions regarding the permitted domains or senders, the Webmail client will automatically download all images in all e-mails.&amp;nbsp;&lt;br&gt;&lt;br&gt;It is important to understand that this will also include images that form part of any spam or phishing e-mails you might receive. As a consequence, not restricting this feature will make it harder for you to detect and avoid malicious e-mails. For this reason, the feature is disabled by default. If a user wants to enable it, they need to do so manually.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-envelope-2.png?itok=VczfRatn" type="image/png" length="349291"/><guid isPermaLink="false">c7fbfc19-8798-479c-a18a-4ce19a57825a</guid>
    <pubDate>Fri, 24 Jul 2020 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>New option for loading external images in Webmail</dc:title>
    <dc:identifier>c7fbfc19-8798-479c-a18a-4ce19a57825a</dc:identifier>
    </item>
<item>
  <title>Update: Data export at the touch of a button</title>
  <link>https://mailbox.org/en/news/data-export-touch-button-whats-new-after-recent-update/</link>
  <description>&lt;p&gt;A main feature of the latest release 7.10.3 of our mailbox.org Office is the data export button. Any mailbox.org user can now download a file that contains their entire user data as stored on our systems, and they can do this by simply clicking on a button. The ZIP archive that will then be created for download has all the data related to e-mails, calendars, address books, files on their Drive, and task lists – and all provided using open data formats, of course, so that importing the data elsewhere is hassle-free.&lt;/p&gt;&lt;p&gt;The idea for creating such a simple data export feature emerged when the mailbox.org team attended the annual Open-Xchange (OX) conference in Rome some time ago. We are very pleased that OX has now implemented this feature at our request.&lt;br&gt;&lt;br&gt;&amp;nbsp;While many providers make it difficult for their users to export data from their platforms, often to create barriers for moving the data and with this, also the services to another provider („Vendor lock in“), it has always been our policy not to do this with our customers. Instead, all mailbox.org users are given full flexibility and control over their own data.&lt;/p&gt;&lt;p&gt;For technical reasons, any contract-related data (e.g. name, price plan, or billing address) are currently not included in that export file. However, the information can be retrieved via our existing GDPR „Personal Data Access“ feature in the mailbox.org settings.&lt;/p&gt;&lt;p&gt;There are many others reasons for our team to look forward to the new release 7.10.3, as this also contains a number of bug fixes. For example, some of the current issues around Apple devices and how they operate with calendars and task lists have been addressed in the new version.&lt;/p&gt;&lt;p&gt;Note:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;The settings can now be found in the mailbox.org Office at the top right.&lt;/li&gt;&lt;/ul&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-drive-1.png?itok=Cdaxpixf" type="image/png" length="245668"/><guid isPermaLink="false">ddb29da2-3313-45d7-a9ae-82b7541ef3a5</guid>
    <pubDate>Fri, 05 Jun 2020 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Update: Data export at the touch of a button</dc:title>
    <dc:identifier>ddb29da2-3313-45d7-a9ae-82b7541ef3a5</dc:identifier>
    </item>
<item>
  <title>Update: Data export at the touch of a button</title>
  <link>https://mailbox.org/en/news/data-export-touch-button-whats-new-after-recent-update/</link>
  <description>&lt;p&gt;A main feature of the latest release 7.10.3 of our mailbox.org Office is the data export button. Any mailbox.org user can now download a file that contains their entire user data as stored on our systems, and they can do this by simply clicking on a button. The ZIP archive that will then be created for download has all the data related to e-mails, calendars, address books, files on their Drive, and task lists – and all provided using open data formats, of course, so that importing the data elsewhere is hassle-free.&lt;/p&gt;&lt;p&gt;The idea for creating such a simple data export feature emerged when the mailbox.org team attended the annual Open-Xchange (OX) conference in Rome some time ago. We are very pleased that OX has now implemented this feature at our request.&lt;br&gt;&lt;br&gt;&amp;nbsp;While many providers make it difficult for their users to export data from their platforms, often to create barriers for moving the data and with this, also the services to another provider („Vendor lock in“), it has always been our policy not to do this with our customers. Instead, all mailbox.org users are given full flexibility and control over their own data.&lt;/p&gt;&lt;p&gt;For technical reasons, any contract-related data (e.g. name, price plan, or billing address) are currently not included in that export file. However, the information can be retrieved via our existing GDPR „Personal Data Access“ feature in the mailbox.org settings.&lt;/p&gt;&lt;p&gt;There are many others reasons for our team to look forward to the new release 7.10.3, as this also contains a number of bug fixes. For example, some of the current issues around Apple devices and how they operate with calendars and task lists have been addressed in the new version.&lt;/p&gt;&lt;p&gt;Note:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;The settings can now be found in the mailbox.org Office at the top right.&lt;/li&gt;&lt;/ul&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-drive-1.png?itok=Cdaxpixf" type="image/png" length="245668"/><guid isPermaLink="false">ddb29da2-3313-45d7-a9ae-82b7541ef3a5</guid>
    <pubDate>Fri, 05 Jun 2020 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Update: Data export at the touch of a button</dc:title>
    <dc:identifier>ddb29da2-3313-45d7-a9ae-82b7541ef3a5</dc:identifier>
    </item>
<item>
  <title>Roskomnadzor withdraws blocking request</title>
  <link>https://mailbox.org/en/news/roskomnadzor-withdraws-petition-block-access-mailboxorg-russia/</link>
  <description>&lt;p&gt;Yesterdy morning in Moscow, the Taganskiy court heard case number 02-4272/2019. Our attorney informed us that the defense strategy had been successful, as the representatives of the Russian telecommunications supervisory authority Roskomnadzor declared their intention to withdraw the petition to ban access to mailbox.org in Russia.&lt;/p&gt;&lt;p&gt;We don't know if Roskomnadzor had planned to score any political points with this case but if they had, it certainly didn't go well. Present at the hearing were the representatives of Roskomnadzor and the Russian security service FSB, our own attorney, and apparently, also two journalists. However, no courtroom drama was to follow – instead, Roskomnadzor simply pulled out of the case.&lt;/p&gt;&lt;p&gt;In the run-up to these events, mailbox.org had agreed with our legal representative that we would allow our business contact details to be included in the Russian telecommunications register. This information comprises mailbox.org's postal address, commercial register number, and e-mail contact address – all freely and publicly available from our website disclaimer. mailbox.org has not entered into any further agreements with Roskomnadzor. The information given is similar to that held in Germany by the Bundesnetzagentur supervisory authority.&lt;/p&gt;&lt;p&gt;mailbox.org continues to be critical of the objectives and general practices of Roskomnadzor: We are not a Russian provider, have no Russian services, and to our knowledge, no Russian user base either. Hence, we don't see any legal reason why we should be obliged to be on the Russian telecommunications register. However, since the information we agreed to supply is publicly available from our website anyway, we decided it’s better to voluntarily provide this limited amount of information in order to defuse the situation somewhat, and avoid giving Roskomnadzor a pretense to call for the more drastic action of banning mailbox.org entirely, be it for political or whatever other reasons.&lt;/p&gt;&lt;p&gt;So, as a result, access to mailbox.org will remain available in Russia for the time being, and we appreciate this outcome as it helps maintain a free Internet and secure communication. The fact that a ban had been publicly announced and was then withdrawn sends a strong political signal.&lt;/p&gt;&lt;h3&gt;&lt;br&gt;Our data will never be stored in foreign countries&lt;/h3&gt;&lt;p&gt;Still, there were activities going on behind the scenes to attempt and interpret the outcome as a win for Roskomnadzor. A report by the Russian news agency &lt;a href="https://www.interfax.ru/russia/693888" target="_blank" title="Interfax" rel="noopener"&gt;Interfax&lt;/a&gt; suggested that mailbox.org had agreed to general data storage within the Russian territory. This is false. We strongly deny such insinuations and stress again that mailbox.org will never permit the storage of any user data in Russia. An entry in the Russian telecommunications register does not entail any obligation to do so, and by the way, it would be illegal with respect to established German and European laws, including those on data protection.&lt;/p&gt;&lt;p&gt;It remains to be seen if the FSB and Roskomnadzor will initiate further actions against mailbox.org in the future. Currently, there are further similar cases ongoing against other providers (Reported on by the &lt;a href="https://www.heise.de/newsticker/meldung/Facebook-und-Twitter-droht-Strafe-und-Sperre-in-Russland-4652095.html" target="_blank" title="Heise" rel="noopener"&gt;Heise&lt;/a&gt; and &lt;a href="https://www.golem.de/news/zensur-russland-blockiert-protonmail-mailbox-org-soll-folgen-2001-146365.html" target="_blank" title="Golem" rel="noopener"&gt;Golem&lt;/a&gt; news outlets). At the end of January, access to Protonmail had been blocked in Russia, with much fanfare in the media.&lt;/p&gt;&lt;p&gt;After we have demonstrated that mailbox.org will resist both on the legal track as well as by raising public awareness, it is our hope (based on the assessment of our attorneys and legal advisors) that the Russian side will now let the matter go. In the event that the FSB or Roskomnadzor come back to demand data storage inside the Russian territory, we will fight back against any such requests with the utmost fervor – under no circumstances will we let this happen.&lt;/p&gt;&lt;p&gt;At the bottom line, we will never be pressured or forced to comply with illegal requests by attempts to block access to mailbox.org, or any threats of doing so, by anyone.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-trophy-2.png?itok=X4dOmDiQ" type="image/png" length="336184"/><guid isPermaLink="false">18f7baba-1a3b-4fd5-af28-c6e9eb0744fa</guid>
    <pubDate>Wed, 05 Feb 2020 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Roskomnadzor withdraws blocking request</dc:title>
    <dc:identifier>18f7baba-1a3b-4fd5-af28-c6e9eb0744fa</dc:identifier>
    </item>
<item>
  <title>Roskomnadzor withdraws blocking request</title>
  <link>https://mailbox.org/en/news/roskomnadzor-withdraws-petition-block-access-mailboxorg-russia/</link>
  <description>&lt;p&gt;Yesterdy morning in Moscow, the Taganskiy court heard case number 02-4272/2019. Our attorney informed us that the defense strategy had been successful, as the representatives of the Russian telecommunications supervisory authority Roskomnadzor declared their intention to withdraw the petition to ban access to mailbox.org in Russia.&lt;/p&gt;&lt;p&gt;We don't know if Roskomnadzor had planned to score any political points with this case but if they had, it certainly didn't go well. Present at the hearing were the representatives of Roskomnadzor and the Russian security service FSB, our own attorney, and apparently, also two journalists. However, no courtroom drama was to follow – instead, Roskomnadzor simply pulled out of the case.&lt;/p&gt;&lt;p&gt;In the run-up to these events, mailbox.org had agreed with our legal representative that we would allow our business contact details to be included in the Russian telecommunications register. This information comprises mailbox.org's postal address, commercial register number, and e-mail contact address – all freely and publicly available from our website disclaimer. mailbox.org has not entered into any further agreements with Roskomnadzor. The information given is similar to that held in Germany by the Bundesnetzagentur supervisory authority.&lt;/p&gt;&lt;p&gt;mailbox.org continues to be critical of the objectives and general practices of Roskomnadzor: We are not a Russian provider, have no Russian services, and to our knowledge, no Russian user base either. Hence, we don't see any legal reason why we should be obliged to be on the Russian telecommunications register. However, since the information we agreed to supply is publicly available from our website anyway, we decided it’s better to voluntarily provide this limited amount of information in order to defuse the situation somewhat, and avoid giving Roskomnadzor a pretense to call for the more drastic action of banning mailbox.org entirely, be it for political or whatever other reasons.&lt;/p&gt;&lt;p&gt;So, as a result, access to mailbox.org will remain available in Russia for the time being, and we appreciate this outcome as it helps maintain a free Internet and secure communication. The fact that a ban had been publicly announced and was then withdrawn sends a strong political signal.&lt;/p&gt;&lt;h3&gt;&lt;br&gt;Our data will never be stored in foreign countries&lt;/h3&gt;&lt;p&gt;Still, there were activities going on behind the scenes to attempt and interpret the outcome as a win for Roskomnadzor. A report by the Russian news agency &lt;a href="https://www.interfax.ru/russia/693888" target="_blank" title="Interfax" rel="noopener"&gt;Interfax&lt;/a&gt; suggested that mailbox.org had agreed to general data storage within the Russian territory. This is false. We strongly deny such insinuations and stress again that mailbox.org will never permit the storage of any user data in Russia. An entry in the Russian telecommunications register does not entail any obligation to do so, and by the way, it would be illegal with respect to established German and European laws, including those on data protection.&lt;/p&gt;&lt;p&gt;It remains to be seen if the FSB and Roskomnadzor will initiate further actions against mailbox.org in the future. Currently, there are further similar cases ongoing against other providers (Reported on by the &lt;a href="https://www.heise.de/newsticker/meldung/Facebook-und-Twitter-droht-Strafe-und-Sperre-in-Russland-4652095.html" target="_blank" title="Heise" rel="noopener"&gt;Heise&lt;/a&gt; and &lt;a href="https://www.golem.de/news/zensur-russland-blockiert-protonmail-mailbox-org-soll-folgen-2001-146365.html" target="_blank" title="Golem" rel="noopener"&gt;Golem&lt;/a&gt; news outlets). At the end of January, access to Protonmail had been blocked in Russia, with much fanfare in the media.&lt;/p&gt;&lt;p&gt;After we have demonstrated that mailbox.org will resist both on the legal track as well as by raising public awareness, it is our hope (based on the assessment of our attorneys and legal advisors) that the Russian side will now let the matter go. In the event that the FSB or Roskomnadzor come back to demand data storage inside the Russian territory, we will fight back against any such requests with the utmost fervor – under no circumstances will we let this happen.&lt;/p&gt;&lt;p&gt;At the bottom line, we will never be pressured or forced to comply with illegal requests by attempts to block access to mailbox.org, or any threats of doing so, by anyone.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-trophy-2.png?itok=X4dOmDiQ" type="image/png" length="336184"/><guid isPermaLink="false">18f7baba-1a3b-4fd5-af28-c6e9eb0744fa</guid>
    <pubDate>Wed, 05 Feb 2020 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Roskomnadzor withdraws blocking request</dc:title>
    <dc:identifier>18f7baba-1a3b-4fd5-af28-c6e9eb0744fa</dc:identifier>
    </item>
<item>
  <title>Roskomnadzor requests blocking of mailbox.org</title>
  <link>https://mailbox.org/en/news/russian-regulators-roskomnadzor-bring-case-court-calling-mailboxorg-ban-russia/</link>
  <description>&lt;p&gt;In a few days’ time, a court in Moscow will hear a case that has the goal to restrict access to mailbox.org in Russia. The Russian telecommunications supervisory authority Roskomnadzor is responsible for bringing this case to court. For us at mailbox.org, fighting back against such attempts to manifest Internet censorship is a matter of principle and so, we decided to get legal representation and argue the case from our standpoint.&lt;/p&gt;&lt;p&gt;There were early signs in the fall of 2019, when Russian media outlets announced that the Russian telecommunications supervisory authority Roskomnadzor („Federal Service for the Supervision of Communications, Information Technology and Mass Media“) was actively working towards implementing a ban of mailbox.org. At the time, we reported about this in our &lt;a href="https://mailbox.org/en/post/russian-intelligence-service-fsb-plans-to-block-mailbox-org" target="_blank" title="Blog" rel="noopener"&gt;Blog&lt;/a&gt; to raise public awareness.&lt;/p&gt;&lt;p&gt;One of the central demands made by Roskomnadzor is that mailbox.org should register as a Russian telecommunications provider because our service can be accessed from within Russia. We do not agree with this view, as we do not maintain a website in Russian language, do not operate any IT equipment in Russia, and do not advertise our services to Russian customers specifically. As a result, we do not see any reason why mailbox.org should be obliged to register with Roskomnadzor.&lt;/p&gt;&lt;h3&gt;&lt;br&gt;Free secure communication is at risk&lt;/h3&gt;&lt;p&gt;We are observing what we think are very concerning developments, as there appear to be attempts to establish a centralized, censored, and controlled Internet within Russia. We at mailbox.org consider this a blatant attack on Freedom of Expression and Speech, and Freedom of the Press. From our perspective, it looks as if Roskomnadzor is trying to single out individual companies to make an example of, so as to set the ground and prepare for a larger-scale purge of other Internet services in the future.&lt;/p&gt;&lt;p&gt;We also suspect that Roskomnadzor might be under political pressure to present successes with regard to the stricter regulation of national Internet access. Roskomnadzor has been unusually active in the press lately, announcing that several foreign providers are to be banned in the future. When we look at the information emerging around those individual cases, it seems to us that often, there is a prominent lack of concrete legal reasons for the actions proposed. Instead, the selection of providers appears to be quite arbitrary, and maybe the underlying reasoning is that single companies might accept their fate more willingly under Roskomnadzor’s pressure, which the regulators can then present as quick wins.&lt;/p&gt;&lt;p&gt;In recent months, Roskomnadzor announced that they would take legal action against different providers and proposed that these services be banned in Russia, including Startmail, Protonmail, or Scryptmail. Yesterday, it was reported that Roskomnadzor has already started the process of blocking Protonmail. (&lt;a href="https://www.reuters.com/article/us-russia-protonmail/russia-blocks-encrypted-email-service-protonmail-idUSKBN1ZS1K8" target="_blank" title="→ Reuters report" rel="noopener"&gt;→ Reuters report&lt;/a&gt;)&lt;br&gt;&lt;br&gt;&amp;nbsp;&lt;/p&gt;&lt;h3&gt;Court action to block access to mailbox.org&lt;/h3&gt;&lt;p&gt;With respect to mailbox.org, Roskomnadzor made a move on 29th December 2019 and submitted their case for blocking access to our services in Russia to a court in Moscow. The first hearing was scheduled for the 15th January, which was very short notice, considering Russian Christmas and New Year holidays are later than elsewhere and end just a week before the date.&lt;/p&gt;&lt;p&gt;mailbox.org has decided to take part in the court proceedings and bring forward legal arguments against the actions proposed by Roskomnadzor. Consequently, we have sought legal representation for the upcoming court session on 5th February 2020. We believe that free and secure communication is of fundamental importance for any free society, and we will stand firm to defend our convictions. We are also confident that our lawyers will be able to make convincing points to argue the upcoming case from our side, and prevent a court order that would lead to the blocking of mailbox.org services in Russia.&lt;/p&gt;&lt;p&gt;In case a ban is actually enacted as a result of the court proceedings, we will be able to adapt to the new situation. After all, our team has 30 years of professional experience. Over the previous few weeks, we have analyzed a range of different blocking- and censoring measures that are currently available and developed appropriate countermeasures. In any case, our dedicated Tor-Exit-Node will ensure availability of mailbox.org for our international customers. It wouldn’t be the first time that Roskomnadzor failed to block access to an Internet service...&lt;br&gt;&lt;br&gt;&amp;nbsp;&lt;/p&gt;&lt;h3&gt;Russian authorities and requests for handing over user data&lt;/h3&gt;&lt;p&gt;Current Russian laws that govern Internet services include a stipulation that requires registered Russian providers to store all data of Russian users on Russian servers, when asked to do so. While so far, mailbox.org has not received any such demand from Roskomnadzor, we would never comply if such a request was made in the future. For us, it is not acceptable to hand over user data to the authorities in this manner.&lt;/p&gt;&lt;p&gt;Of course, mailbox.org will never act unlawfully, in that we will consider requests for information that are valid on the basis of German and European law, or legally correct international letters of request. We do appreciate and respect the necessity to fight criminal activity on the Web, and accept that the Internet cannot be a space where the law is absent. However, there is a careful balance to be struck, as new laws and regulations could unduly infringe on Freedom of Expression and Speech, or Freedom of the Press, and possibly lead to bans that would exclude providers and their entire user bases. mailbox.org does not tolerate any forms of abuse or criminal activity. We have a dedicated team for handling cases of misuse or abuse, and they take any reports of suspicious activity very seriously, and are trained to be persistent and thorough in following up on any such cases.&lt;/p&gt;&lt;p&gt;While Roskomnadzor alleges that bomb threats were supposedly sent from a mailbox.org account, our records show that we did not receive any related requests for information from the Russian authorities.&lt;br&gt;&lt;br&gt;&amp;nbsp;&lt;/p&gt;&lt;h3&gt;Possible consequences for our users&lt;/h3&gt;&lt;p&gt;For the time being, we will wait and see how the court case proceeds. In the event that access to mailbox.org will actually be blocked in Russia, this may affect those users who are travelling to Russia, or those who are communicating by e-mail with other people or businesses that are located in Russia. While we are reasonably confident that we will be able to prevent restrictions from being imposed, we need to ask for your understanding that no definitive statements can be made at this point in time.&lt;br&gt;&lt;br&gt;Keep an eye on our blog if you are interested in following up on further updates and news.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-jurisdiction.png?itok=OZMKk08b" type="image/png" length="218284"/><guid isPermaLink="false">e6aba08d-f1f6-4f28-bbcb-510eda9df1fe</guid>
    <pubDate>Thu, 30 Jan 2020 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Roskomnadzor requests blocking of mailbox.org</dc:title>
    <dc:identifier>e6aba08d-f1f6-4f28-bbcb-510eda9df1fe</dc:identifier>
    </item>
<item>
  <title>Roskomnadzor requests blocking of mailbox.org</title>
  <link>https://mailbox.org/en/news/russian-regulators-roskomnadzor-bring-case-court-calling-mailboxorg-ban-russia/</link>
  <description>&lt;p&gt;In a few days’ time, a court in Moscow will hear a case that has the goal to restrict access to mailbox.org in Russia. The Russian telecommunications supervisory authority Roskomnadzor is responsible for bringing this case to court. For us at mailbox.org, fighting back against such attempts to manifest Internet censorship is a matter of principle and so, we decided to get legal representation and argue the case from our standpoint.&lt;/p&gt;&lt;p&gt;There were early signs in the fall of 2019, when Russian media outlets announced that the Russian telecommunications supervisory authority Roskomnadzor („Federal Service for the Supervision of Communications, Information Technology and Mass Media“) was actively working towards implementing a ban of mailbox.org. At the time, we reported about this in our &lt;a href="https://mailbox.org/en/post/russian-intelligence-service-fsb-plans-to-block-mailbox-org" target="_blank" title="Blog" rel="noopener"&gt;Blog&lt;/a&gt; to raise public awareness.&lt;/p&gt;&lt;p&gt;One of the central demands made by Roskomnadzor is that mailbox.org should register as a Russian telecommunications provider because our service can be accessed from within Russia. We do not agree with this view, as we do not maintain a website in Russian language, do not operate any IT equipment in Russia, and do not advertise our services to Russian customers specifically. As a result, we do not see any reason why mailbox.org should be obliged to register with Roskomnadzor.&lt;/p&gt;&lt;h3&gt;&lt;br&gt;Free secure communication is at risk&lt;/h3&gt;&lt;p&gt;We are observing what we think are very concerning developments, as there appear to be attempts to establish a centralized, censored, and controlled Internet within Russia. We at mailbox.org consider this a blatant attack on Freedom of Expression and Speech, and Freedom of the Press. From our perspective, it looks as if Roskomnadzor is trying to single out individual companies to make an example of, so as to set the ground and prepare for a larger-scale purge of other Internet services in the future.&lt;/p&gt;&lt;p&gt;We also suspect that Roskomnadzor might be under political pressure to present successes with regard to the stricter regulation of national Internet access. Roskomnadzor has been unusually active in the press lately, announcing that several foreign providers are to be banned in the future. When we look at the information emerging around those individual cases, it seems to us that often, there is a prominent lack of concrete legal reasons for the actions proposed. Instead, the selection of providers appears to be quite arbitrary, and maybe the underlying reasoning is that single companies might accept their fate more willingly under Roskomnadzor’s pressure, which the regulators can then present as quick wins.&lt;/p&gt;&lt;p&gt;In recent months, Roskomnadzor announced that they would take legal action against different providers and proposed that these services be banned in Russia, including Startmail, Protonmail, or Scryptmail. Yesterday, it was reported that Roskomnadzor has already started the process of blocking Protonmail. (&lt;a href="https://www.reuters.com/article/us-russia-protonmail/russia-blocks-encrypted-email-service-protonmail-idUSKBN1ZS1K8" target="_blank" title="→ Reuters report" rel="noopener"&gt;→ Reuters report&lt;/a&gt;)&lt;br&gt;&lt;br&gt;&amp;nbsp;&lt;/p&gt;&lt;h3&gt;Court action to block access to mailbox.org&lt;/h3&gt;&lt;p&gt;With respect to mailbox.org, Roskomnadzor made a move on 29th December 2019 and submitted their case for blocking access to our services in Russia to a court in Moscow. The first hearing was scheduled for the 15th January, which was very short notice, considering Russian Christmas and New Year holidays are later than elsewhere and end just a week before the date.&lt;/p&gt;&lt;p&gt;mailbox.org has decided to take part in the court proceedings and bring forward legal arguments against the actions proposed by Roskomnadzor. Consequently, we have sought legal representation for the upcoming court session on 5th February 2020. We believe that free and secure communication is of fundamental importance for any free society, and we will stand firm to defend our convictions. We are also confident that our lawyers will be able to make convincing points to argue the upcoming case from our side, and prevent a court order that would lead to the blocking of mailbox.org services in Russia.&lt;/p&gt;&lt;p&gt;In case a ban is actually enacted as a result of the court proceedings, we will be able to adapt to the new situation. After all, our team has 30 years of professional experience. Over the previous few weeks, we have analyzed a range of different blocking- and censoring measures that are currently available and developed appropriate countermeasures. In any case, our dedicated Tor-Exit-Node will ensure availability of mailbox.org for our international customers. It wouldn’t be the first time that Roskomnadzor failed to block access to an Internet service...&lt;br&gt;&lt;br&gt;&amp;nbsp;&lt;/p&gt;&lt;h3&gt;Russian authorities and requests for handing over user data&lt;/h3&gt;&lt;p&gt;Current Russian laws that govern Internet services include a stipulation that requires registered Russian providers to store all data of Russian users on Russian servers, when asked to do so. While so far, mailbox.org has not received any such demand from Roskomnadzor, we would never comply if such a request was made in the future. For us, it is not acceptable to hand over user data to the authorities in this manner.&lt;/p&gt;&lt;p&gt;Of course, mailbox.org will never act unlawfully, in that we will consider requests for information that are valid on the basis of German and European law, or legally correct international letters of request. We do appreciate and respect the necessity to fight criminal activity on the Web, and accept that the Internet cannot be a space where the law is absent. However, there is a careful balance to be struck, as new laws and regulations could unduly infringe on Freedom of Expression and Speech, or Freedom of the Press, and possibly lead to bans that would exclude providers and their entire user bases. mailbox.org does not tolerate any forms of abuse or criminal activity. We have a dedicated team for handling cases of misuse or abuse, and they take any reports of suspicious activity very seriously, and are trained to be persistent and thorough in following up on any such cases.&lt;/p&gt;&lt;p&gt;While Roskomnadzor alleges that bomb threats were supposedly sent from a mailbox.org account, our records show that we did not receive any related requests for information from the Russian authorities.&lt;br&gt;&lt;br&gt;&amp;nbsp;&lt;/p&gt;&lt;h3&gt;Possible consequences for our users&lt;/h3&gt;&lt;p&gt;For the time being, we will wait and see how the court case proceeds. In the event that access to mailbox.org will actually be blocked in Russia, this may affect those users who are travelling to Russia, or those who are communicating by e-mail with other people or businesses that are located in Russia. While we are reasonably confident that we will be able to prevent restrictions from being imposed, we need to ask for your understanding that no definitive statements can be made at this point in time.&lt;br&gt;&lt;br&gt;Keep an eye on our blog if you are interested in following up on further updates and news.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-jurisdiction.png?itok=OZMKk08b" type="image/png" length="218284"/><guid isPermaLink="false">e6aba08d-f1f6-4f28-bbcb-510eda9df1fe</guid>
    <pubDate>Thu, 30 Jan 2020 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Roskomnadzor requests blocking of mailbox.org</dc:title>
    <dc:identifier>e6aba08d-f1f6-4f28-bbcb-510eda9df1fe</dc:identifier>
    </item>
<item>
  <title>Transparenzbericht 2019</title>
  <link>https://mailbox.org/en/news/transparency-report-2019/</link>
  <description>&lt;p&gt;Today we publish our transparency report of 2019, in which we account for all requests for information that we as a provider have received by the authorities last year.&lt;/p&gt;&lt;p&gt;Requests sent to mailbox.org in the year 2019&lt;br&gt;Total number of requests: 79&lt;br&gt;From German authorities: 72&lt;br&gt;From foreign authorities: 7 (EU+Switzerland)&lt;/p&gt;&lt;p&gt;Organisations&lt;br&gt;Criminal investigative authorities: 79&lt;br&gt;Customs authorities: 0&lt;br&gt;Intelligence services: 0&lt;/p&gt;&lt;p&gt;Request type&lt;br&gt;Contact data requests: 74&lt;br&gt;Inbox confiscations: 0&lt;br&gt;Traffic data requests: 2&lt;br&gt;Telecommunications interceptions: 3&lt;/p&gt;&lt;p&gt;The overall number of requests we received in 2019 has increased slightly when compared to the previous year. A total of 26 requests were found to contain flaws or be unlawful for other reasons – those requests were consequentially rejected. Of all unlawful requests, 22 were subsequently re-submitted with their formal issues remedied, and then processed. Four requests were ultimately rejected.&lt;/p&gt;&lt;p&gt;While more and more German authorities e-mail us to request information, their awareness of the related security and data protection needs is still quite low. For example, almost all e-mail requests we received were sent across the Web unencrypted, which is unlawful in this country. Only three of the authorities managed to send their requests encrypted and in accordance with the rules.&lt;/p&gt;&lt;p&gt;The second reason why we rejected some requests for information was the non-identification of a legal basis for the request, or the putting forward of a legal basis that was not applicable or insufficient. Only a single out of the total seven requests we received from foreign organizations also contained the required rogatory letters. The remaining six requests were rejected as there was no legal basis for those requests.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-04/mailbox-news-und-updates-transparenzbericht.jpg?itok=SMV4eTPL" type="image/jpeg" length="268110"/><guid isPermaLink="false">00504975-f8c8-43fd-b2c4-bfeb51bcfe4c</guid>
    <pubDate>Wed, 22 Jan 2020 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Transparenzbericht 2019</dc:title>
    <dc:identifier>00504975-f8c8-43fd-b2c4-bfeb51bcfe4c</dc:identifier>
    </item>
<item>
  <title>Transparenzbericht 2019</title>
  <link>https://mailbox.org/en/news/transparency-report-2019/</link>
  <description>&lt;p&gt;Today we publish our transparency report of 2019, in which we account for all requests for information that we as a provider have received by the authorities last year.&lt;/p&gt;&lt;p&gt;Requests sent to mailbox.org in the year 2019&lt;br&gt;Total number of requests: 79&lt;br&gt;From German authorities: 72&lt;br&gt;From foreign authorities: 7 (EU+Switzerland)&lt;/p&gt;&lt;p&gt;Organisations&lt;br&gt;Criminal investigative authorities: 79&lt;br&gt;Customs authorities: 0&lt;br&gt;Intelligence services: 0&lt;/p&gt;&lt;p&gt;Request type&lt;br&gt;Contact data requests: 74&lt;br&gt;Inbox confiscations: 0&lt;br&gt;Traffic data requests: 2&lt;br&gt;Telecommunications interceptions: 3&lt;/p&gt;&lt;p&gt;The overall number of requests we received in 2019 has increased slightly when compared to the previous year. A total of 26 requests were found to contain flaws or be unlawful for other reasons – those requests were consequentially rejected. Of all unlawful requests, 22 were subsequently re-submitted with their formal issues remedied, and then processed. Four requests were ultimately rejected.&lt;/p&gt;&lt;p&gt;While more and more German authorities e-mail us to request information, their awareness of the related security and data protection needs is still quite low. For example, almost all e-mail requests we received were sent across the Web unencrypted, which is unlawful in this country. Only three of the authorities managed to send their requests encrypted and in accordance with the rules.&lt;/p&gt;&lt;p&gt;The second reason why we rejected some requests for information was the non-identification of a legal basis for the request, or the putting forward of a legal basis that was not applicable or insufficient. Only a single out of the total seven requests we received from foreign organizations also contained the required rogatory letters. The remaining six requests were rejected as there was no legal basis for those requests.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-04/mailbox-news-und-updates-transparenzbericht.jpg?itok=SMV4eTPL" type="image/jpeg" length="268110"/><guid isPermaLink="false">00504975-f8c8-43fd-b2c4-bfeb51bcfe4c</guid>
    <pubDate>Wed, 22 Jan 2020 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Transparenzbericht 2019</dc:title>
    <dc:identifier>00504975-f8c8-43fd-b2c4-bfeb51bcfe4c</dc:identifier>
    </item>
<item>
  <title>Update: Calendar, Documents, Drive</title>
  <link>https://mailbox.org/en/news/calendars-documents-drive-whats-new-after-yesterdays-update/</link>
  <description>&lt;p&gt;The latest update of our mailbox.org Office fixes about 100 bugs and brings improvements for your daily interaction with our platform. In particular, users can look forward to a range of optimizations to calendars, documents, and file handling. Read on for more details.&lt;/p&gt;&lt;h2&gt;mailbox.org finances the integration of Mailvelope into the mailbox.org Office&lt;/h2&gt;&lt;p&gt;mailbox.org has been upgraded to now use the OX AppSuite version 7.10.2. While this version has been released some time ago, there were some obstacles that we first needed to overcome before an upgrade was possible on our systems.&lt;/p&gt;&lt;p&gt;Unfortunately, the software company responsible for Open-Xchange (OX) decided to no longer support integration of the PGP tool &lt;a href="https://www.mailvelope.com/de" target="_blank" title="Mailvelope" rel="noopener"&gt;„Mailvelope“&lt;/a&gt; in its latest version, in favour of its own „OX Guard“ development.&lt;/p&gt;&lt;p&gt;We at mailbox.org would like to continue to offer our users a choice when it comes to e-mail encryption. There are those who want to use the browser plug-in „Mailvelope“ and store the private key on their local devices. Others prefer to use „Guard“, which keeps the private key separately encrypted on the mailbox.org servers, and enables users to read their e-mail wherever they are, using a webmail client. Both ways of handling e-mail encryption have their practical and security-related advantages and disadvantages, as we have previously discussed (Check out our knowledge base for details: → &lt;a href="https://kb.mailbox.org/display/MBOKBEN/An+introduction+to+mailbox.org+Guard" target="_blank" title="mailbox.org Guard" rel="noopener"&gt;mailbox.org Guard&lt;/a&gt;, → &lt;a href="https://kb.mailbox.org/display/MBOKBEN/How+to+set+up+Mailvelope" target="_blank" title="Mailvelope" rel="noopener"&gt;Mailvelope&lt;/a&gt;).&lt;/p&gt;&lt;p&gt;We didn't want our users to lose the option of having Mailvelope and decided to take matters into our own hands: So, we set up and funded a project to re-establish support for Mailvelope in the OX AppSuite, which is exclusively available for mailbox.org users. Half a year later, we were finally ready and could proceed with the roll-out of the new OX version. On the outside, nothing has changed for the users of Mailvelope – they can just keep using things as usual.&lt;/p&gt;&lt;p&gt;We would like to thank both Open-Xchange and the Mailvelope developer Thomas Oberndörfer for the support they have given to our project.&lt;br&gt;&amp;nbsp;&lt;/p&gt;&lt;h3&gt;What's new in the mailbox.org Office:&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;Calendars:&amp;nbsp;&lt;br&gt;Organizers of an appointment can now decide if participants are permitted to change the event date. Furthermore, the role of organizer can be transferred to other participants. It is now possible to download multiple attachments related to appointments. Users can also explicitly configure which of their shared or public calendars are to be synchronized with other devices via CalDAV.&lt;br&gt;&amp;nbsp;&lt;/li&gt;&lt;li&gt;Edit documents within browser tabs:&amp;nbsp;&lt;br&gt;The editing of documents does now work across browser tabs, which makes it possible to keep open and edit several documents at the same time, each using its own tab. Tabs can be arranged as required, which makes the joint editing of e-mails or documents much easier.&lt;br&gt;&amp;nbsp;&lt;/li&gt;&lt;li&gt;Additional file handling support:&amp;nbsp;&lt;br&gt;OX Drive now supports the display of EXIF data, which includes meta data of digital photographs such as the GPS coordinates, aperture, or shutter speed from when a picture was taken. Further, OX Drive will track file versions, so that users can always inspect, download, or delete previous versions of a file. If you don't want to use previous file versions, then they can all be easily removed in one go.&lt;br&gt;&amp;nbsp;&lt;/li&gt;&lt;li&gt;Upload attachments in the background:&lt;br&gt;Another feature that has been improved is the attaching of files to e-mails. Uploading is now running in the background so that users can continue to work while an attachment is being uploaded. Meanwhile, progress is shown in a small window. Once a file has been uploaded completely, a small preview of it can be seen while drafting the current e-mail.&lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;mailbox.org Guard&lt;/h3&gt;&lt;p&gt;The mailbox.org Guard, which performs server-side encryption of e-mails, has seen a few improvements, too:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;When using the guest inbox that comes with Guard, users would previously experience occasional time-outs, and sometimes, e-mails would not be displayed properly. This bug has been fixed by improving server synchronization within the cluster.&lt;/li&gt;&lt;li&gt;The import of ical files from encrypted e-mails is now supported by Guard.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Your mailbox.org team&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-04/mailbox-news-und-updates-produktupdate.jpg?itok=VmAEEH73" type="image/jpeg" length="400284"/><guid isPermaLink="false">17745c5a-df37-4c88-818f-c3bff8170f5c</guid>
    <pubDate>Wed, 15 Jan 2020 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Update: Calendar, Documents, Drive</dc:title>
    <dc:identifier>17745c5a-df37-4c88-818f-c3bff8170f5c</dc:identifier>
    </item>
<item>
  <title>Update: Calendar, Documents, Drive</title>
  <link>https://mailbox.org/en/news/calendars-documents-drive-whats-new-after-yesterdays-update/</link>
  <description>&lt;p&gt;The latest update of our mailbox.org Office fixes about 100 bugs and brings improvements for your daily interaction with our platform. In particular, users can look forward to a range of optimizations to calendars, documents, and file handling. Read on for more details.&lt;/p&gt;&lt;h2&gt;mailbox.org finances the integration of Mailvelope into the mailbox.org Office&lt;/h2&gt;&lt;p&gt;mailbox.org has been upgraded to now use the OX AppSuite version 7.10.2. While this version has been released some time ago, there were some obstacles that we first needed to overcome before an upgrade was possible on our systems.&lt;/p&gt;&lt;p&gt;Unfortunately, the software company responsible for Open-Xchange (OX) decided to no longer support integration of the PGP tool &lt;a href="https://www.mailvelope.com/de" target="_blank" title="Mailvelope" rel="noopener"&gt;„Mailvelope“&lt;/a&gt; in its latest version, in favour of its own „OX Guard“ development.&lt;/p&gt;&lt;p&gt;We at mailbox.org would like to continue to offer our users a choice when it comes to e-mail encryption. There are those who want to use the browser plug-in „Mailvelope“ and store the private key on their local devices. Others prefer to use „Guard“, which keeps the private key separately encrypted on the mailbox.org servers, and enables users to read their e-mail wherever they are, using a webmail client. Both ways of handling e-mail encryption have their practical and security-related advantages and disadvantages, as we have previously discussed (Check out our knowledge base for details: → &lt;a href="https://kb.mailbox.org/display/MBOKBEN/An+introduction+to+mailbox.org+Guard" target="_blank" title="mailbox.org Guard" rel="noopener"&gt;mailbox.org Guard&lt;/a&gt;, → &lt;a href="https://kb.mailbox.org/display/MBOKBEN/How+to+set+up+Mailvelope" target="_blank" title="Mailvelope" rel="noopener"&gt;Mailvelope&lt;/a&gt;).&lt;/p&gt;&lt;p&gt;We didn't want our users to lose the option of having Mailvelope and decided to take matters into our own hands: So, we set up and funded a project to re-establish support for Mailvelope in the OX AppSuite, which is exclusively available for mailbox.org users. Half a year later, we were finally ready and could proceed with the roll-out of the new OX version. On the outside, nothing has changed for the users of Mailvelope – they can just keep using things as usual.&lt;/p&gt;&lt;p&gt;We would like to thank both Open-Xchange and the Mailvelope developer Thomas Oberndörfer for the support they have given to our project.&lt;br&gt;&amp;nbsp;&lt;/p&gt;&lt;h3&gt;What's new in the mailbox.org Office:&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;Calendars:&amp;nbsp;&lt;br&gt;Organizers of an appointment can now decide if participants are permitted to change the event date. Furthermore, the role of organizer can be transferred to other participants. It is now possible to download multiple attachments related to appointments. Users can also explicitly configure which of their shared or public calendars are to be synchronized with other devices via CalDAV.&lt;br&gt;&amp;nbsp;&lt;/li&gt;&lt;li&gt;Edit documents within browser tabs:&amp;nbsp;&lt;br&gt;The editing of documents does now work across browser tabs, which makes it possible to keep open and edit several documents at the same time, each using its own tab. Tabs can be arranged as required, which makes the joint editing of e-mails or documents much easier.&lt;br&gt;&amp;nbsp;&lt;/li&gt;&lt;li&gt;Additional file handling support:&amp;nbsp;&lt;br&gt;OX Drive now supports the display of EXIF data, which includes meta data of digital photographs such as the GPS coordinates, aperture, or shutter speed from when a picture was taken. Further, OX Drive will track file versions, so that users can always inspect, download, or delete previous versions of a file. If you don't want to use previous file versions, then they can all be easily removed in one go.&lt;br&gt;&amp;nbsp;&lt;/li&gt;&lt;li&gt;Upload attachments in the background:&lt;br&gt;Another feature that has been improved is the attaching of files to e-mails. Uploading is now running in the background so that users can continue to work while an attachment is being uploaded. Meanwhile, progress is shown in a small window. Once a file has been uploaded completely, a small preview of it can be seen while drafting the current e-mail.&lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;mailbox.org Guard&lt;/h3&gt;&lt;p&gt;The mailbox.org Guard, which performs server-side encryption of e-mails, has seen a few improvements, too:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;When using the guest inbox that comes with Guard, users would previously experience occasional time-outs, and sometimes, e-mails would not be displayed properly. This bug has been fixed by improving server synchronization within the cluster.&lt;/li&gt;&lt;li&gt;The import of ical files from encrypted e-mails is now supported by Guard.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Your mailbox.org team&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-04/mailbox-news-und-updates-produktupdate.jpg?itok=VmAEEH73" type="image/jpeg" length="400284"/><guid isPermaLink="false">17745c5a-df37-4c88-818f-c3bff8170f5c</guid>
    <pubDate>Wed, 15 Jan 2020 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Update: Calendar, Documents, Drive</dc:title>
    <dc:identifier>17745c5a-df37-4c88-818f-c3bff8170f5c</dc:identifier>
    </item>
<item>
  <title>Secure email for teachers: Thuringian Ministry of Education</title>
  <link>https://mailbox.org/en/news/secure-e-mail-teachers-german-federal-state-thuringia-puts-their-trust-mailbox/</link>
  <description/>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-education-2.jpeg?itok=bYl95Uqp" type="image/jpeg" length="426130"/><guid isPermaLink="false">64a41f3b-c261-461f-8182-fb410d441e42</guid>
    <pubDate>Wed, 08 Jan 2020 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Secure email for teachers: Thuringian Ministry of Education</dc:title>
    <dc:identifier>64a41f3b-c261-461f-8182-fb410d441e42</dc:identifier>
    </item>
<item>
  <title>Secure email for teachers: Thuringian Ministry of Education</title>
  <link>https://mailbox.org/en/news/secure-e-mail-teachers-german-federal-state-thuringia-puts-their-trust-mailbox/</link>
  <description/>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-education-2.jpeg?itok=bYl95Uqp" type="image/jpeg" length="426130"/><guid isPermaLink="false">64a41f3b-c261-461f-8182-fb410d441e42</guid>
    <pubDate>Wed, 08 Jan 2020 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Secure email for teachers: Thuringian Ministry of Education</dc:title>
    <dc:identifier>64a41f3b-c261-461f-8182-fb410d441e42</dc:identifier>
    </item>
<item>
  <title>Credit card payments now accepted</title>
  <link>https://mailbox.org/en/news/credit-card-payments-available/</link>
  <description>&lt;p&gt;In response to customer requests - especially from our international customers - we are expanding our payment methods and now accept credit card payments via MasterCard, Visa and American Express.&lt;/p&gt;&lt;p&gt;To this end, we work with one of the largest and most experienced billing service providers. The Dutch company Adyen will handle all credit card payments on our behalf and protect our customers and ourselves from misuse. Adyen is a trustworthy provider with many years of extensive expertise in online payments. Adyen only receives the country set in the user data from mailbox.org in order to set the language of the form correctly. Adyen and mailbox.org arrange payments only via internal temporary transaction IDs that do not allow Adyen to deduce user data. At no time does Adyen receive information about the respective mailbox that the user is currently paying for.&lt;/p&gt;&lt;p&gt;You can find out more about Adyen &lt;a href="https://www.adyen.com" target="_blank" rel="noopener"&gt;here.&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-payment-credit-card.jpeg?itok=X0rlqwA-" type="image/jpeg" length="276063"/><guid isPermaLink="false">5a7ab79c-e919-435f-9b21-7ebf743850b0</guid>
    <pubDate>Mon, 23 Sep 2019 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Credit card payments now accepted</dc:title>
    <dc:identifier>5a7ab79c-e919-435f-9b21-7ebf743850b0</dc:identifier>
    </item>
<item>
  <title>Credit card payments now accepted</title>
  <link>https://mailbox.org/en/news/credit-card-payments-available/</link>
  <description>&lt;p&gt;In response to customer requests - especially from our international customers - we are expanding our payment methods and now accept credit card payments via MasterCard, Visa and American Express.&lt;/p&gt;&lt;p&gt;To this end, we work with one of the largest and most experienced billing service providers. The Dutch company Adyen will handle all credit card payments on our behalf and protect our customers and ourselves from misuse. Adyen is a trustworthy provider with many years of extensive expertise in online payments. Adyen only receives the country set in the user data from mailbox.org in order to set the language of the form correctly. Adyen and mailbox.org arrange payments only via internal temporary transaction IDs that do not allow Adyen to deduce user data. At no time does Adyen receive information about the respective mailbox that the user is currently paying for.&lt;/p&gt;&lt;p&gt;You can find out more about Adyen &lt;a href="https://www.adyen.com" target="_blank" rel="noopener"&gt;here.&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-payment-credit-card.jpeg?itok=X0rlqwA-" type="image/jpeg" length="276063"/><guid isPermaLink="false">5a7ab79c-e919-435f-9b21-7ebf743850b0</guid>
    <pubDate>Mon, 23 Sep 2019 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Credit card payments now accepted</dc:title>
    <dc:identifier>5a7ab79c-e919-435f-9b21-7ebf743850b0</dc:identifier>
    </item>
<item>
  <title>Russian secret service FSB plans block</title>
  <link>https://mailbox.org/en/news/russian-intelligence-service-fsb-plans-block-mailbox/</link>
  <description>&lt;p&gt;[Ниже мы опубликовали русский перевод статьи.]&lt;/p&gt;&lt;p&gt;According to reports of the Russian media company RBC, the Russian secret service FSB plans to request an Internet block against mailbox.org and other providers. The reason is supposed to be e-mails sent via the providers with bomb threats. As a result, websites or mailbox.org mail services from the Russian Internet may no longer be accessible in whole or in part.&lt;/p&gt;&lt;p&gt;According to media reports, representatives of the Russian telecommunications authority Roskomnadzor state that mailbox.org did not respond to a request for information in the second quarter of 2019 and is not listed in the Russian telecommunications directory "ARI".&lt;/p&gt;&lt;p&gt;Peer Heinlein, founder and CEO of mailbox.org, explains: "We are not aware of any inquiry from Roskomnadzor that we should have answered. We do not have an official letter from the authorities nor have we received a corresponding request for legal assistance from German authorities. Contrary to the statements made by representatives of Roskomnadzor, mailbox.org is not aware of any Russian court decision according to which mailbox.org would have had to release data. If there was a decision, it was never delivered to us. In this respect we are very surprised by the incident and the accusations of Roskomnadzor".&lt;/p&gt;&lt;p&gt;"Of course, mailbox.org would answer legitimate requests for information from authorities. However, these must also be permissible on the basis of the German and European legal situation," says Peer Heinlein. As a rule, foreign authorities would have to choose the path of a request for judicial assistance. "In no case, however, will mailbox.org illegally disclose data of its users to domestic or foreign authorities. Each request for information will always be checked for admissibility by lawyers specialising in this area in individual cases".&lt;/p&gt;&lt;p&gt;"Like every e-mail service, mailbox.org has to struggle with a multitude of fake account registrations on a daily basis. mailbox.org has developed very good defence methods to detect and block abusive fake accounts. We do not tolerate abuse of our service for criminal activities," says Peer Heinlein. If accounts were to be used for criminal activities, mailbox.org would of course cooperate and block them after a very precise case-by-case examination. The Anti-Abuse-Team of mailbox.org would even accept such hints with thanks.&lt;/p&gt;&lt;p&gt;"If a user of mailbox.org sends e-mails with the threat of a bomb attack, this must be condemned in the strongest possible terms and not tolerated," says Heinlein. Of course, mailbox.org strongly dissociates itself from such actions. If, however, a free telecommunications provider is blocked due to individual incidents and all its users are placed under general suspicion, this is exaggeratedly excessive and purely arbitrary. If this then happens without compliance with a constitutional procedure, it would not be tolerable for any democratic state.&lt;/p&gt;&lt;p&gt;Whether and how the request of the Russian secret service FSB will be followed remains to be seen. It also remains to be seen what consequences a possible ban on mailbox.org will actually have for users on Russian soil. mailbox.org recommends that affected users access mailbox.org via the TOR network, which could not be blocked or censored by the FSB either.&lt;/p&gt;&lt;p&gt;"This incident shows once again how important free communication structures like the worldwide TOR network are," says Heinlein. This enables users in totalitarian and monitoring states to participate securely in the Internet and to communicate freely. For this reason, mailbox.org operates its own TOR servers for secure communication and can also be reached worldwide via the so-called TOR onion addresses".&lt;/p&gt;&lt;p&gt;&lt;br&gt;How to use TOR: &lt;a href="https://kb.mailbox.org/display/MBOKBEN/The+Tor+exit+node+of+mailbox.org" target="_blank" rel="noopener"&gt;https://kb.mailbox.org/display/MBOKBEN/The+Tor+exit+node+of+mailbox.org&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Sources for reporting (Russian):&lt;/p&gt;&lt;p&gt;&lt;a href="https://www.rbc.ru/technology_and_media/13/09/2019/5d7a4a4a9a7947394d62f38e" target="_blank" rel="noopener"&gt;https://www.rbc.ru/technology_and_media/13/09/2019/5d7a4a4a9a7947394d62f38e&lt;/a&gt;&lt;br&gt;&lt;a href="https://www.rbc.ru/technology_and_media/13/09/2019/5d7a4a4a9a7947394d62f38e" target="_blank" rel="noopener"&gt;https://tass.ru/obschestvo/6882094&lt;/a&gt;&lt;br&gt;&lt;a href="https://lenta.ru/news/2019/09/13/telega" target="_blank" rel="noopener"&gt;https://lenta.ru/news/2019/09/13/telega&lt;/a&gt;&lt;/p&gt;&lt;p&gt;About mailbox.org&lt;/p&gt;&lt;p&gt;mailbox.org was the world's first provider to automatically offer PGP-encrypted mailboxes and was the test winner of Stiftung Warentest among 15 tested mail providers in September 2016. Launched at the beginning of 2014, mailbox.org has quickly established itself as an easy-to-use service for secure e-mail communication. In addition to classic e-mail core functions, security-conscious customers also receive calendars, task management, online word processing, file storage in the cloud and a chat solution based on the OX App Suite.&lt;/p&gt;&lt;p&gt;mailbox.org is a product of Heinlein Support GmbH. The owner and managing director of the independent company is the Berlin e-mail expert and IT security consultant Peer Heinlein. He has been offering e-mail services for security-conscious companies and private users for over 25 years. Since 1992, Peer Heinlein has been operating the e-mail provider JPBerlin.de, with which he makes trustworthy digital infrastructures available to companies and institutions such as the OpenSUSE project. NGOs such as Attac, Doctors Without Borders, Arbeitskreis Vorratsdatenspeicherung, Wikimedia and X1000malquer as well as volunteers have been successfully using the communication solutions for their work for years. The services range from secure e-mail boxes and mailing lists to web hosting and DNSSEC domain registration.&lt;/p&gt;&lt;p&gt;Contact for journalists: Stefen Niemeyer, Fresh fish: +49 (0) 171 499 05 60&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Переведено с помощью www.DeepL.com/Translator&lt;/p&gt;&lt;p&gt;Российская спецслужба ФСБ планирует заблокировать mailbox.org&lt;/p&gt;&lt;p&gt;По сообщению российской медиакомпании РБК, спецслужба ФСБ планирует запросить блокировку доступа в Интернет для mailbox.org и других провайдеров. В результате этого веб-сайты или почтовые сервисы mailbox.org из российского Интернета могут быть полностью или частично недоступны.&lt;/p&gt;&lt;p&gt;Как сообщают СМИ, представители Роскомнадзора заявляют, что mailbox.org не отвечал на запрос информации во втором квартале 2019 года и не фигурирует в российском телекоммуникационном справочнике "ARI".&lt;/p&gt;&lt;p&gt;Основатель и генеральный директор mailbox.org коллега Хайнляйн объясняет: "Нам не известно о каком-либо запросе Роскомнадзора о том, что нам следовало ответить. У нас нет ни официального письма от властей, ни соответствующего запроса о правовой помощи от немецких властей. Вопреки заявлениям представителей Роскомнадзора, mailbox.org не знает о каком-либо решении российского суда, в соответствии с которым mailbox.org должен был бы раскрыть данные. Если и было решение, то никогда не было доставлено нам. В этой связи мы очень удивлены инцидентом и обвинениями Роскомнадзора".&lt;/p&gt;&lt;p&gt;"Конечно, mailbox.org будет отвечать на законные запросы властей о предоставлении информации. Однако они также должны быть допустимы в зависимости от правовой ситуации в Германии и Европе", - говорит Пир Хайнляйн. Как правило, иностранные органы власти должны будут выбирать путь подачи просьбы об оказании судебной помощи. "Однако mailbox.org ни в коем случае не будет незаконно раскрывать данные своих пользователей местным или иностранным властям. Каждый запрос на информацию всегда будет проверяться на приемлемость юристами, специализирующимися в данной области, в отдельных случаях".&lt;/p&gt;&lt;p&gt;"Как и любая служба электронной почты, mailbox.org ежедневно сталкивается с множеством поддельных регистраций учетных записей. mailbox.org разработал очень хорошие методы защиты для обнаружения и блокирования поддельных учетных записей. Мы не допускаем злоупотребления нашими услугами в преступных целях", - говорит коллега Хайнляйн. Если учетные записи будут использоваться для преступной деятельности, mailbox.org, разумеется, будет сотрудничать и блокировать их после тщательного изучения каждого конкретного случая. Команда Anti-Abuse-Team mailbox.org даже приняла бы такие советы с благодарностью.&lt;/p&gt;&lt;p&gt;"Если пользователь mailbox.org посылает электронные письма с угрозой взрыва, это должно быть осуждено самым решительным образом и недопустимо", - говорит Хайнляйн. Конечно, mailbox.org сильно отличается от подобных действий. Однако, если свободный оператор связи блокируется в результате отдельных инцидентов и все его пользователи подвергаются общим подозрениям, то это чрезмерно завышено и является чисто произвольным. Если это произойдет без соблюдения конституционной процедуры, то это будет недопустимо для любого демократического государства.&lt;/p&gt;&lt;p&gt;Будет ли и как будет выполняться запрос российской спецслужбы ФСБ, еще предстоит выяснить. Также остается неясным, какие последствия может иметь возможный запрет на mailbox.org для пользователей на российской земле. mailbox.org рекомендует, чтобы пострадавшие пользователи имели доступ к mailbox.org через сеть TOR, которая также не может быть заблокирована или цензурирована FSB.&lt;/p&gt;&lt;p&gt;"Этот инцидент еще раз показывает, насколько важны структуры свободного общения, такие как всемирная сеть TOR, - говорит Хайнляйн. Это позволяет пользователям в тоталитарных и контролирующих государствах безопасно участвовать в Интернете и свободно общаться. По этой причине mailbox.org имеет свои собственные TOR-серверы для безопасной связи, а также может быть доступен по всему миру через так называемые TOR-адреса лука".&lt;/p&gt;&lt;p&gt;Как использовать ТЗ: &lt;a href="https://kb.mailbox.org/display/MBOKBEN/The+Tor+exit+node+of+mailbox.org" target="_blank" rel="noopener"&gt;https://kb.mailbox.org/display/MBOKBEN/The+Tor+exit+node+of+mailbox.org&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Источники информации (на русском языке):&lt;/p&gt;&lt;p&gt;&lt;a href="https://www.rbc.ru/technology_and_media/13/09/2019/5d7a4a4a9a7947394d62f38e" target="_blank" rel="noopener"&gt;https://www.rbc.ru/technology_and_media/13/09/2019/5d7a4a4a9a7947394d62f38e&lt;/a&gt;&lt;br&gt;&lt;a href="https://tass.ru/obschestvo/6882094" target="_blank" rel="noopener"&gt;https://tass.ru/obschestvo/6882094&lt;/a&gt;&lt;br&gt;&lt;a href="https://lenta.ru/news/2019/09/13/telega" target="_blank" rel="noopener"&gt;https://lenta.ru/news/2019/09/13/telega&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Информация о mailbox.org&lt;/p&gt;&lt;p&gt;mailbox.org стал первым в мире провайдером, который автоматически предложил почтовые ящики с шифрованием PGP и стал победителем теста Stiftung Warentest среди 15 проверенных почтовых провайдеров в сентябре 2016 года. Запущенный в начале 2014 года, mailbox.org быстро зарекомендовал себя как простая в использовании услуга для безопасной электронной почты. В дополнение к классическим основным функциям электронной почты, клиенты, заботящиеся о безопасности, также получают календари, управление задачами, онлайн-обработку текстов, хранение файлов в облаке и чат-решение на базе OX App Suite.&lt;/p&gt;&lt;p&gt;mailbox.org является продуктом компании Heinlein Support GmbH. Владельцем и управляющим директором независимой компании является берлинский эксперт по электронной почте и консультант по информационной безопасности Peer Heinlein. Более 25 лет он предлагает услуги электронной почты для компаний, заботящихся о безопасности, и частных пользователей. С 1992 года Peer Heinlein управляет провайдером электронной почты JPBerlin.de, с которым предоставляет надежные цифровые инфраструктуры в распоряжение компаний и учреждений, таких как проект OpenSUSE. Такие НПО, как Аттак, Врачи без границ, Arbeitskreis Vorratsdatenspeicherung, Wikimedia и X1000malquer, а также волонтеры успешно используют коммуникационные решения в своей работе на протяжении многих лет. Спектр услуг варьируется от защищенных почтовых ящиков и списков рассылки до веб-хостинга и регистрации домена DNSSEC.&lt;/p&gt;&lt;p&gt;Контактное лицо для журналистов: Stefen Niemeyer, Fresh fish: +49 (0) 171 499 05 60&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-04/mailbox-news-und-updates-warnung.jpg?itok=reW9cU74" type="image/jpeg" length="238141"/><guid isPermaLink="false">14926190-ea16-4680-a5ff-eb6c41752fda</guid>
    <pubDate>Fri, 13 Sep 2019 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Russian secret service FSB plans block</dc:title>
    <dc:identifier>14926190-ea16-4680-a5ff-eb6c41752fda</dc:identifier>
    </item>
<item>
  <title>Russian secret service FSB plans block</title>
  <link>https://mailbox.org/en/news/russian-intelligence-service-fsb-plans-block-mailbox/</link>
  <description>&lt;p&gt;[Ниже мы опубликовали русский перевод статьи.]&lt;/p&gt;&lt;p&gt;According to reports of the Russian media company RBC, the Russian secret service FSB plans to request an Internet block against mailbox.org and other providers. The reason is supposed to be e-mails sent via the providers with bomb threats. As a result, websites or mailbox.org mail services from the Russian Internet may no longer be accessible in whole or in part.&lt;/p&gt;&lt;p&gt;According to media reports, representatives of the Russian telecommunications authority Roskomnadzor state that mailbox.org did not respond to a request for information in the second quarter of 2019 and is not listed in the Russian telecommunications directory "ARI".&lt;/p&gt;&lt;p&gt;Peer Heinlein, founder and CEO of mailbox.org, explains: "We are not aware of any inquiry from Roskomnadzor that we should have answered. We do not have an official letter from the authorities nor have we received a corresponding request for legal assistance from German authorities. Contrary to the statements made by representatives of Roskomnadzor, mailbox.org is not aware of any Russian court decision according to which mailbox.org would have had to release data. If there was a decision, it was never delivered to us. In this respect we are very surprised by the incident and the accusations of Roskomnadzor".&lt;/p&gt;&lt;p&gt;"Of course, mailbox.org would answer legitimate requests for information from authorities. However, these must also be permissible on the basis of the German and European legal situation," says Peer Heinlein. As a rule, foreign authorities would have to choose the path of a request for judicial assistance. "In no case, however, will mailbox.org illegally disclose data of its users to domestic or foreign authorities. Each request for information will always be checked for admissibility by lawyers specialising in this area in individual cases".&lt;/p&gt;&lt;p&gt;"Like every e-mail service, mailbox.org has to struggle with a multitude of fake account registrations on a daily basis. mailbox.org has developed very good defence methods to detect and block abusive fake accounts. We do not tolerate abuse of our service for criminal activities," says Peer Heinlein. If accounts were to be used for criminal activities, mailbox.org would of course cooperate and block them after a very precise case-by-case examination. The Anti-Abuse-Team of mailbox.org would even accept such hints with thanks.&lt;/p&gt;&lt;p&gt;"If a user of mailbox.org sends e-mails with the threat of a bomb attack, this must be condemned in the strongest possible terms and not tolerated," says Heinlein. Of course, mailbox.org strongly dissociates itself from such actions. If, however, a free telecommunications provider is blocked due to individual incidents and all its users are placed under general suspicion, this is exaggeratedly excessive and purely arbitrary. If this then happens without compliance with a constitutional procedure, it would not be tolerable for any democratic state.&lt;/p&gt;&lt;p&gt;Whether and how the request of the Russian secret service FSB will be followed remains to be seen. It also remains to be seen what consequences a possible ban on mailbox.org will actually have for users on Russian soil. mailbox.org recommends that affected users access mailbox.org via the TOR network, which could not be blocked or censored by the FSB either.&lt;/p&gt;&lt;p&gt;"This incident shows once again how important free communication structures like the worldwide TOR network are," says Heinlein. This enables users in totalitarian and monitoring states to participate securely in the Internet and to communicate freely. For this reason, mailbox.org operates its own TOR servers for secure communication and can also be reached worldwide via the so-called TOR onion addresses".&lt;/p&gt;&lt;p&gt;&lt;br&gt;How to use TOR: &lt;a href="https://kb.mailbox.org/display/MBOKBEN/The+Tor+exit+node+of+mailbox.org" target="_blank" rel="noopener"&gt;https://kb.mailbox.org/display/MBOKBEN/The+Tor+exit+node+of+mailbox.org&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Sources for reporting (Russian):&lt;/p&gt;&lt;p&gt;&lt;a href="https://www.rbc.ru/technology_and_media/13/09/2019/5d7a4a4a9a7947394d62f38e" target="_blank" rel="noopener"&gt;https://www.rbc.ru/technology_and_media/13/09/2019/5d7a4a4a9a7947394d62f38e&lt;/a&gt;&lt;br&gt;&lt;a href="https://www.rbc.ru/technology_and_media/13/09/2019/5d7a4a4a9a7947394d62f38e" target="_blank" rel="noopener"&gt;https://tass.ru/obschestvo/6882094&lt;/a&gt;&lt;br&gt;&lt;a href="https://lenta.ru/news/2019/09/13/telega" target="_blank" rel="noopener"&gt;https://lenta.ru/news/2019/09/13/telega&lt;/a&gt;&lt;/p&gt;&lt;p&gt;About mailbox.org&lt;/p&gt;&lt;p&gt;mailbox.org was the world's first provider to automatically offer PGP-encrypted mailboxes and was the test winner of Stiftung Warentest among 15 tested mail providers in September 2016. Launched at the beginning of 2014, mailbox.org has quickly established itself as an easy-to-use service for secure e-mail communication. In addition to classic e-mail core functions, security-conscious customers also receive calendars, task management, online word processing, file storage in the cloud and a chat solution based on the OX App Suite.&lt;/p&gt;&lt;p&gt;mailbox.org is a product of Heinlein Support GmbH. The owner and managing director of the independent company is the Berlin e-mail expert and IT security consultant Peer Heinlein. He has been offering e-mail services for security-conscious companies and private users for over 25 years. Since 1992, Peer Heinlein has been operating the e-mail provider JPBerlin.de, with which he makes trustworthy digital infrastructures available to companies and institutions such as the OpenSUSE project. NGOs such as Attac, Doctors Without Borders, Arbeitskreis Vorratsdatenspeicherung, Wikimedia and X1000malquer as well as volunteers have been successfully using the communication solutions for their work for years. The services range from secure e-mail boxes and mailing lists to web hosting and DNSSEC domain registration.&lt;/p&gt;&lt;p&gt;Contact for journalists: Stefen Niemeyer, Fresh fish: +49 (0) 171 499 05 60&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Переведено с помощью www.DeepL.com/Translator&lt;/p&gt;&lt;p&gt;Российская спецслужба ФСБ планирует заблокировать mailbox.org&lt;/p&gt;&lt;p&gt;По сообщению российской медиакомпании РБК, спецслужба ФСБ планирует запросить блокировку доступа в Интернет для mailbox.org и других провайдеров. В результате этого веб-сайты или почтовые сервисы mailbox.org из российского Интернета могут быть полностью или частично недоступны.&lt;/p&gt;&lt;p&gt;Как сообщают СМИ, представители Роскомнадзора заявляют, что mailbox.org не отвечал на запрос информации во втором квартале 2019 года и не фигурирует в российском телекоммуникационном справочнике "ARI".&lt;/p&gt;&lt;p&gt;Основатель и генеральный директор mailbox.org коллега Хайнляйн объясняет: "Нам не известно о каком-либо запросе Роскомнадзора о том, что нам следовало ответить. У нас нет ни официального письма от властей, ни соответствующего запроса о правовой помощи от немецких властей. Вопреки заявлениям представителей Роскомнадзора, mailbox.org не знает о каком-либо решении российского суда, в соответствии с которым mailbox.org должен был бы раскрыть данные. Если и было решение, то никогда не было доставлено нам. В этой связи мы очень удивлены инцидентом и обвинениями Роскомнадзора".&lt;/p&gt;&lt;p&gt;"Конечно, mailbox.org будет отвечать на законные запросы властей о предоставлении информации. Однако они также должны быть допустимы в зависимости от правовой ситуации в Германии и Европе", - говорит Пир Хайнляйн. Как правило, иностранные органы власти должны будут выбирать путь подачи просьбы об оказании судебной помощи. "Однако mailbox.org ни в коем случае не будет незаконно раскрывать данные своих пользователей местным или иностранным властям. Каждый запрос на информацию всегда будет проверяться на приемлемость юристами, специализирующимися в данной области, в отдельных случаях".&lt;/p&gt;&lt;p&gt;"Как и любая служба электронной почты, mailbox.org ежедневно сталкивается с множеством поддельных регистраций учетных записей. mailbox.org разработал очень хорошие методы защиты для обнаружения и блокирования поддельных учетных записей. Мы не допускаем злоупотребления нашими услугами в преступных целях", - говорит коллега Хайнляйн. Если учетные записи будут использоваться для преступной деятельности, mailbox.org, разумеется, будет сотрудничать и блокировать их после тщательного изучения каждого конкретного случая. Команда Anti-Abuse-Team mailbox.org даже приняла бы такие советы с благодарностью.&lt;/p&gt;&lt;p&gt;"Если пользователь mailbox.org посылает электронные письма с угрозой взрыва, это должно быть осуждено самым решительным образом и недопустимо", - говорит Хайнляйн. Конечно, mailbox.org сильно отличается от подобных действий. Однако, если свободный оператор связи блокируется в результате отдельных инцидентов и все его пользователи подвергаются общим подозрениям, то это чрезмерно завышено и является чисто произвольным. Если это произойдет без соблюдения конституционной процедуры, то это будет недопустимо для любого демократического государства.&lt;/p&gt;&lt;p&gt;Будет ли и как будет выполняться запрос российской спецслужбы ФСБ, еще предстоит выяснить. Также остается неясным, какие последствия может иметь возможный запрет на mailbox.org для пользователей на российской земле. mailbox.org рекомендует, чтобы пострадавшие пользователи имели доступ к mailbox.org через сеть TOR, которая также не может быть заблокирована или цензурирована FSB.&lt;/p&gt;&lt;p&gt;"Этот инцидент еще раз показывает, насколько важны структуры свободного общения, такие как всемирная сеть TOR, - говорит Хайнляйн. Это позволяет пользователям в тоталитарных и контролирующих государствах безопасно участвовать в Интернете и свободно общаться. По этой причине mailbox.org имеет свои собственные TOR-серверы для безопасной связи, а также может быть доступен по всему миру через так называемые TOR-адреса лука".&lt;/p&gt;&lt;p&gt;Как использовать ТЗ: &lt;a href="https://kb.mailbox.org/display/MBOKBEN/The+Tor+exit+node+of+mailbox.org" target="_blank" rel="noopener"&gt;https://kb.mailbox.org/display/MBOKBEN/The+Tor+exit+node+of+mailbox.org&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Источники информации (на русском языке):&lt;/p&gt;&lt;p&gt;&lt;a href="https://www.rbc.ru/technology_and_media/13/09/2019/5d7a4a4a9a7947394d62f38e" target="_blank" rel="noopener"&gt;https://www.rbc.ru/technology_and_media/13/09/2019/5d7a4a4a9a7947394d62f38e&lt;/a&gt;&lt;br&gt;&lt;a href="https://tass.ru/obschestvo/6882094" target="_blank" rel="noopener"&gt;https://tass.ru/obschestvo/6882094&lt;/a&gt;&lt;br&gt;&lt;a href="https://lenta.ru/news/2019/09/13/telega" target="_blank" rel="noopener"&gt;https://lenta.ru/news/2019/09/13/telega&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Информация о mailbox.org&lt;/p&gt;&lt;p&gt;mailbox.org стал первым в мире провайдером, который автоматически предложил почтовые ящики с шифрованием PGP и стал победителем теста Stiftung Warentest среди 15 проверенных почтовых провайдеров в сентябре 2016 года. Запущенный в начале 2014 года, mailbox.org быстро зарекомендовал себя как простая в использовании услуга для безопасной электронной почты. В дополнение к классическим основным функциям электронной почты, клиенты, заботящиеся о безопасности, также получают календари, управление задачами, онлайн-обработку текстов, хранение файлов в облаке и чат-решение на базе OX App Suite.&lt;/p&gt;&lt;p&gt;mailbox.org является продуктом компании Heinlein Support GmbH. Владельцем и управляющим директором независимой компании является берлинский эксперт по электронной почте и консультант по информационной безопасности Peer Heinlein. Более 25 лет он предлагает услуги электронной почты для компаний, заботящихся о безопасности, и частных пользователей. С 1992 года Peer Heinlein управляет провайдером электронной почты JPBerlin.de, с которым предоставляет надежные цифровые инфраструктуры в распоряжение компаний и учреждений, таких как проект OpenSUSE. Такие НПО, как Аттак, Врачи без границ, Arbeitskreis Vorratsdatenspeicherung, Wikimedia и X1000malquer, а также волонтеры успешно используют коммуникационные решения в своей работе на протяжении многих лет. Спектр услуг варьируется от защищенных почтовых ящиков и списков рассылки до веб-хостинга и регистрации домена DNSSEC.&lt;/p&gt;&lt;p&gt;Контактное лицо для журналистов: Stefen Niemeyer, Fresh fish: +49 (0) 171 499 05 60&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-04/mailbox-news-und-updates-warnung.jpg?itok=reW9cU74" type="image/jpeg" length="238141"/><guid isPermaLink="false">14926190-ea16-4680-a5ff-eb6c41752fda</guid>
    <pubDate>Fri, 13 Sep 2019 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Russian secret service FSB plans block</dc:title>
    <dc:identifier>14926190-ea16-4680-a5ff-eb6c41752fda</dc:identifier>
    </item>
<item>
  <title>PGP exploit EFAIL — mailbox.org Guard secure</title>
  <link>https://mailbox.org/en/news/pgp-exploit-efail-discovered-mailbox-guard-unaffected/</link>
  <description>&lt;p&gt;A research team around Professor Sebastian Schinzel from the University of Applied Sciences in Münster, Germany, has announced that they are going to go public with details about a newly discovered vulnerability in PGP on Tuesday this week. This discovery could cause ripples across the Internet, as many modern communication services depend on the asymmetric encryption technology that PGP provides.&lt;/p&gt;&lt;p&gt;There appears to be a previously unknown bug in the implementation of many PGP software programs. If an attacker manages to manipulate an encrypted message prior to transmission, then the content may get transmitted as plain text. In effect, this vulnerability could compromise worldwide e-mail communication, if exploited.&lt;/p&gt;&lt;p&gt;Update: The results have now been published on &lt;a href="https://efail.de/" target="_blank" rel="noopener"&gt;https://efail.de&lt;/a&gt; and further details are provided in a paper (&lt;a href="https://efail.de/efail-attack-paper.pdf" target="_blank" rel="noopener"&gt;PDF download&lt;/a&gt;).&lt;/p&gt;&lt;h2 class="western"&gt;mailbox.org Guard appears to be unaffected for now&lt;/h2&gt;&lt;p&gt;&lt;em&gt;At this point, all the checks we have carried out suggest that the PGP implementation of mailbox.org IS NOT AFFECTED. In none of the tested scenarios were we able to replicate the supposed exploit. Any manipulated messages were reliably identified and caught by the Guard PGP system. As a result, no mail contents were transmitted without encryption, which gives us some confidence that the Guard system is probably not compromised like other implementations.&lt;/em&gt;&lt;/p&gt;&lt;p&gt;&lt;em&gt;Update: The information provided in their paper alludes to a problem with Mailvelope that is not really new and not related to any mailbox.org services, but a more fundamental issue with Mailvelope and general web browser behaviour.&lt;/em&gt;&lt;/p&gt;&lt;h2 class="western"&gt;Precautionary measures that users can take&lt;/h2&gt;&lt;p&gt;Some vendors of affected software were informed in advance about the security problem and have taken countermeasures as a result. Although the team of researchers from Münster advises users to disable PGP entirely, we think updating mail clients and PGP tools to their latest versions is always a good idea. As far as we could determine in our tests, up-to-date versions of Enigmail for Thunderbird appear to have relevant fixes in place already.&lt;/p&gt;&lt;p&gt;While the researchers who reported on the vulnerability are asking users to disable PGP, we think there is little justification for such a drastic measure. Why should users keep using PGP? We think no one should disable encryption out of fear of the vulnerability at this point, as this would mean sending messages in plain text anyway. At the end of the day, &lt;em&gt;Man-in-the-Middle&lt;/em&gt;attacks are even more likely if messages are not encrypted at all, whereas the number of users targeted by a specific exploit will likely be limited in comparison.&lt;/p&gt;&lt;p&gt;Based on what we currently know, the only way to keep sensitive data secure is to not send them by e-mail at all – with or without PGP. If alternative secure communication channels are available, then that’s a good option but apart from these, users need to realise that general security against interception of encrypted e-mail is currently compromised.&lt;/p&gt;&lt;p&gt;However, the question remains if the problem is really as dramatic as it has been presented in the research publication and the subsequent media coverage. The research group from Münster has promised to release a list of affected programs and versions.&lt;/p&gt;&lt;h2 class="western"&gt;Our recommendation: Users should reconfigure Thunderbird but leave encryption enabled!&lt;/h2&gt;&lt;p&gt;It appears that many current implementations are not affected, and it will usually be sufficient to suppress the use of HTML messages to be on the safe side. Based on what our own team was able to find out, Thunderbird can be secured by&lt;/p&gt;&lt;ul&gt;&lt;li&gt;disabling the display of HTML messages on the receiving end&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;and&lt;/p&gt;&lt;ul&gt;&lt;li&gt;disabling the automatic fetching of web content (Images, CSS files) in messages&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;&amp;nbsp;&lt;/h2&gt;&lt;h2 class="western"&gt;Workaround: Disable HTML in Thunderbird!&lt;/h2&gt;&lt;p&gt;As an alternative to disabling PGP-encrypted messages entirely, we think it may be useful to switch to the &lt;em&gt;text-only&lt;/em&gt;display of messages in Mozilla Thunderbird:&lt;/p&gt;&lt;h2&gt;Thunderbird: How-to&lt;/h2&gt;&lt;ul&gt;&lt;li&gt;Make sure this box is UNTICKED:&lt;br&gt;Edit → Preferences → Privacy → “Allow remote content in messages”&lt;/li&gt;&lt;li&gt;Select the following from the menu bar:&lt;br&gt;View → Message Body As → Plain Text&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Still, it is obvious that the receiver of a message needs to do the above if the settings are to have any effect, and the sender of an encrypted message won’t necessarily know if this has happened. Note that for a possible exploit to work, it is irrelevant if the message sent was in HTML format or not.&lt;/p&gt;&lt;h2 class="western"&gt;For e-mail professionals: DKIM could help but is not widely available yet&lt;/h2&gt;&lt;p&gt;If DKIM and DMARC were widely used by e-mail providers, then this would help in the detection of manipulated messages. This goes to show how important the consistent and widespread use of parallel security measures is for digital communication. For good reason, we at mailbox.org have been using these technologies for some time and make sure all outgoing e-mails are properly signed. However, since DKIM is still not used by all providers, the benefits to communication security are rather modest on the wider scale. Also, the few mail clients that do support DKIM are still having problems with preventing the automatic display of a received message when DKIM records indicate that the message has been manipulated. We hope the newly discovered security vulnerability will motivate more providers to adopt these technologies and work hard to further their distribution.&lt;/p&gt;&lt;h2 class="western"&gt;UPDATE: Questionable practices – misleading headlines – PGP is still secure&lt;/h2&gt;&lt;p&gt;Considering the fact that 1) non-secure communication that transmits data as plain text is not a solution, 2) users with increased security requirements can use workarounds to avoid the exploit, and 3) many implementations were fixed some time ago or not affected in the first place, we are wondering why the team of researchers at the University of Applied Sciences in Münster engaged in publicising their results the way they did. Those who demand the wide-spread deactivation of PGP encryption are not doing the users and professionals who are concerned about e-mail security any service. It’s quite the contrary, as the resulting media echo has shown.&lt;/p&gt;&lt;p&gt;We can only assume that the researchers may have had an increased desire for publicity and got carried away a bit in the process. Unfortunately, the result was that national newspapers picked up the story to report that „PGP has been cracked“ and other such nonsense. This is not true. PGP encryption has NOT been compromised and is still secure. While a significant vulnerability lies in the handling of HTML e-mails in some mail clients – this problem has been known for a long time.&lt;/p&gt;&lt;p&gt;In the second part of their paper, the researchers reveal what is potentially a real security vulnerability in PGP – however, they also point out that there isn’t actually any known attack that would enable anyone to exploit this vulnerability. Maybe this would have somehow justified a headline along the lines of „PGP has been cracked“. However, the developers of &lt;a href="https://lists.gnupg.org/pipermail/gnupg-users/2018-May/060334.html" target="_blank" rel="noopener"&gt;Gnu PGP and GPG4 &lt;/a&gt;Win have issued a joint statement explaining that the attack scenario described in the paper was already known in 1999 and fixed in the subsequent year, so that the described exploit has no longer been possible as of summer 2000. So, all that was reported yesterday was just hypothetical false alarm, based on incomplete research, it appears.&lt;/p&gt;&lt;p&gt;As a result, different media outlets have already started issuing correction statements. However, progress is sluggish. The German daily “Die Zeit” simply amended their article heading to defuse the strong wording previously used but still suggests to their readers that PGP encryption has been compromised somehow. This is quite misleading, as those who are not technically-minded or sufficiently experienced to be able to question the media reporting will not realise that it is not the encryption that is at fault (If anything, it is the particular mail client used). But the story continues to resonate in the media and statements like “People need to trust the recipient” and “No one can be sure that an encrypted message may not be openly published somewhere” are not helping at all. It would be much more important to point out that many users lack proper virus protection and keep working with PCs that have been infected by programs that make it a lot more likely for their data getting stolen. If the media outlets’ motivation was to increase circulation of their product, they might as well have used a headline like „Researchers are saying that computers should not be used“. But we’d rather not give them any ideas…&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-04/mailbox-news-und-updates-warnung.jpg?itok=reW9cU74" type="image/jpeg" length="238141"/><guid isPermaLink="false">0f7a01a6-cc5a-4a1e-8047-ecb92dc5ea4b</guid>
    <pubDate>Mon, 14 May 2018 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>PGP exploit EFAIL — mailbox.org Guard secure</dc:title>
    <dc:identifier>0f7a01a6-cc5a-4a1e-8047-ecb92dc5ea4b</dc:identifier>
    </item>
<item>
  <title>PGP exploit EFAIL — mailbox.org Guard secure</title>
  <link>https://mailbox.org/en/news/pgp-exploit-efail-discovered-mailbox-guard-unaffected/</link>
  <description>&lt;p&gt;A research team around Professor Sebastian Schinzel from the University of Applied Sciences in Münster, Germany, has announced that they are going to go public with details about a newly discovered vulnerability in PGP on Tuesday this week. This discovery could cause ripples across the Internet, as many modern communication services depend on the asymmetric encryption technology that PGP provides.&lt;/p&gt;&lt;p&gt;There appears to be a previously unknown bug in the implementation of many PGP software programs. If an attacker manages to manipulate an encrypted message prior to transmission, then the content may get transmitted as plain text. In effect, this vulnerability could compromise worldwide e-mail communication, if exploited.&lt;/p&gt;&lt;p&gt;Update: The results have now been published on &lt;a href="https://efail.de/" target="_blank" rel="noopener"&gt;https://efail.de&lt;/a&gt; and further details are provided in a paper (&lt;a href="https://efail.de/efail-attack-paper.pdf" target="_blank" rel="noopener"&gt;PDF download&lt;/a&gt;).&lt;/p&gt;&lt;h2 class="western"&gt;mailbox.org Guard appears to be unaffected for now&lt;/h2&gt;&lt;p&gt;&lt;em&gt;At this point, all the checks we have carried out suggest that the PGP implementation of mailbox.org IS NOT AFFECTED. In none of the tested scenarios were we able to replicate the supposed exploit. Any manipulated messages were reliably identified and caught by the Guard PGP system. As a result, no mail contents were transmitted without encryption, which gives us some confidence that the Guard system is probably not compromised like other implementations.&lt;/em&gt;&lt;/p&gt;&lt;p&gt;&lt;em&gt;Update: The information provided in their paper alludes to a problem with Mailvelope that is not really new and not related to any mailbox.org services, but a more fundamental issue with Mailvelope and general web browser behaviour.&lt;/em&gt;&lt;/p&gt;&lt;h2 class="western"&gt;Precautionary measures that users can take&lt;/h2&gt;&lt;p&gt;Some vendors of affected software were informed in advance about the security problem and have taken countermeasures as a result. Although the team of researchers from Münster advises users to disable PGP entirely, we think updating mail clients and PGP tools to their latest versions is always a good idea. As far as we could determine in our tests, up-to-date versions of Enigmail for Thunderbird appear to have relevant fixes in place already.&lt;/p&gt;&lt;p&gt;While the researchers who reported on the vulnerability are asking users to disable PGP, we think there is little justification for such a drastic measure. Why should users keep using PGP? We think no one should disable encryption out of fear of the vulnerability at this point, as this would mean sending messages in plain text anyway. At the end of the day, &lt;em&gt;Man-in-the-Middle&lt;/em&gt;attacks are even more likely if messages are not encrypted at all, whereas the number of users targeted by a specific exploit will likely be limited in comparison.&lt;/p&gt;&lt;p&gt;Based on what we currently know, the only way to keep sensitive data secure is to not send them by e-mail at all – with or without PGP. If alternative secure communication channels are available, then that’s a good option but apart from these, users need to realise that general security against interception of encrypted e-mail is currently compromised.&lt;/p&gt;&lt;p&gt;However, the question remains if the problem is really as dramatic as it has been presented in the research publication and the subsequent media coverage. The research group from Münster has promised to release a list of affected programs and versions.&lt;/p&gt;&lt;h2 class="western"&gt;Our recommendation: Users should reconfigure Thunderbird but leave encryption enabled!&lt;/h2&gt;&lt;p&gt;It appears that many current implementations are not affected, and it will usually be sufficient to suppress the use of HTML messages to be on the safe side. Based on what our own team was able to find out, Thunderbird can be secured by&lt;/p&gt;&lt;ul&gt;&lt;li&gt;disabling the display of HTML messages on the receiving end&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;and&lt;/p&gt;&lt;ul&gt;&lt;li&gt;disabling the automatic fetching of web content (Images, CSS files) in messages&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;&amp;nbsp;&lt;/h2&gt;&lt;h2 class="western"&gt;Workaround: Disable HTML in Thunderbird!&lt;/h2&gt;&lt;p&gt;As an alternative to disabling PGP-encrypted messages entirely, we think it may be useful to switch to the &lt;em&gt;text-only&lt;/em&gt;display of messages in Mozilla Thunderbird:&lt;/p&gt;&lt;h2&gt;Thunderbird: How-to&lt;/h2&gt;&lt;ul&gt;&lt;li&gt;Make sure this box is UNTICKED:&lt;br&gt;Edit → Preferences → Privacy → “Allow remote content in messages”&lt;/li&gt;&lt;li&gt;Select the following from the menu bar:&lt;br&gt;View → Message Body As → Plain Text&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Still, it is obvious that the receiver of a message needs to do the above if the settings are to have any effect, and the sender of an encrypted message won’t necessarily know if this has happened. Note that for a possible exploit to work, it is irrelevant if the message sent was in HTML format or not.&lt;/p&gt;&lt;h2 class="western"&gt;For e-mail professionals: DKIM could help but is not widely available yet&lt;/h2&gt;&lt;p&gt;If DKIM and DMARC were widely used by e-mail providers, then this would help in the detection of manipulated messages. This goes to show how important the consistent and widespread use of parallel security measures is for digital communication. For good reason, we at mailbox.org have been using these technologies for some time and make sure all outgoing e-mails are properly signed. However, since DKIM is still not used by all providers, the benefits to communication security are rather modest on the wider scale. Also, the few mail clients that do support DKIM are still having problems with preventing the automatic display of a received message when DKIM records indicate that the message has been manipulated. We hope the newly discovered security vulnerability will motivate more providers to adopt these technologies and work hard to further their distribution.&lt;/p&gt;&lt;h2 class="western"&gt;UPDATE: Questionable practices – misleading headlines – PGP is still secure&lt;/h2&gt;&lt;p&gt;Considering the fact that 1) non-secure communication that transmits data as plain text is not a solution, 2) users with increased security requirements can use workarounds to avoid the exploit, and 3) many implementations were fixed some time ago or not affected in the first place, we are wondering why the team of researchers at the University of Applied Sciences in Münster engaged in publicising their results the way they did. Those who demand the wide-spread deactivation of PGP encryption are not doing the users and professionals who are concerned about e-mail security any service. It’s quite the contrary, as the resulting media echo has shown.&lt;/p&gt;&lt;p&gt;We can only assume that the researchers may have had an increased desire for publicity and got carried away a bit in the process. Unfortunately, the result was that national newspapers picked up the story to report that „PGP has been cracked“ and other such nonsense. This is not true. PGP encryption has NOT been compromised and is still secure. While a significant vulnerability lies in the handling of HTML e-mails in some mail clients – this problem has been known for a long time.&lt;/p&gt;&lt;p&gt;In the second part of their paper, the researchers reveal what is potentially a real security vulnerability in PGP – however, they also point out that there isn’t actually any known attack that would enable anyone to exploit this vulnerability. Maybe this would have somehow justified a headline along the lines of „PGP has been cracked“. However, the developers of &lt;a href="https://lists.gnupg.org/pipermail/gnupg-users/2018-May/060334.html" target="_blank" rel="noopener"&gt;Gnu PGP and GPG4 &lt;/a&gt;Win have issued a joint statement explaining that the attack scenario described in the paper was already known in 1999 and fixed in the subsequent year, so that the described exploit has no longer been possible as of summer 2000. So, all that was reported yesterday was just hypothetical false alarm, based on incomplete research, it appears.&lt;/p&gt;&lt;p&gt;As a result, different media outlets have already started issuing correction statements. However, progress is sluggish. The German daily “Die Zeit” simply amended their article heading to defuse the strong wording previously used but still suggests to their readers that PGP encryption has been compromised somehow. This is quite misleading, as those who are not technically-minded or sufficiently experienced to be able to question the media reporting will not realise that it is not the encryption that is at fault (If anything, it is the particular mail client used). But the story continues to resonate in the media and statements like “People need to trust the recipient” and “No one can be sure that an encrypted message may not be openly published somewhere” are not helping at all. It would be much more important to point out that many users lack proper virus protection and keep working with PCs that have been infected by programs that make it a lot more likely for their data getting stolen. If the media outlets’ motivation was to increase circulation of their product, they might as well have used a headline like „Researchers are saying that computers should not be used“. But we’d rather not give them any ideas…&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-04/mailbox-news-und-updates-warnung.jpg?itok=reW9cU74" type="image/jpeg" length="238141"/><guid isPermaLink="false">0f7a01a6-cc5a-4a1e-8047-ecb92dc5ea4b</guid>
    <pubDate>Mon, 14 May 2018 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>PGP exploit EFAIL — mailbox.org Guard secure</dc:title>
    <dc:identifier>0f7a01a6-cc5a-4a1e-8047-ecb92dc5ea4b</dc:identifier>
    </item>
<item>
  <title>mailbox.org is accessible for IPv6-based connections</title>
  <link>https://mailbox.org/en/news/technical-infrastructure-update-mailbox/</link>
  <description>&lt;p&gt;&lt;em&gt;Executive summary:&lt;/em&gt;&lt;/p&gt;&lt;p&gt;&lt;em&gt;The mailbox.org admin team has been working hard to improve our infrastructure, with the result that our server systems now accept connections via the latest version of the internet protocol IPv6. Customers who use devices that support IPv6 will benefit from connections that get established quicker and show improved latency.&lt;/em&gt;&lt;/p&gt;&lt;p&gt;mailbox.org now offers all customers the option to use IPv6-based connections to our server systems. With our latest infrastructure update, e-mail services, website, and the cloud office can be accessed through this latest version of the internet protocol. With IPv6, customers benefit from lower latency times and better connection speed. The only requirement: Devices and internet connection at the client side need to be able to “speak” IPv6 as well. However, most broadband- or cable internet providers will support IPv6 already and those that don’t will likely do so soon. Needless to say, mobile devices like smartphones and tablet computers increasingly communicate via IPv6, too.&lt;/p&gt;&lt;p&gt;For example, if a compatible device connects to “imap.mailbox.org” to retrieve e-mails, then that server will automatically resolve an IPv6 address without the need for any separate configuration. Devices that do not support the new protocol version can still use all services as usual with the IPv4 protocol, because mailbox.org provides interfaces for both the old and the new protocol in parallel (Dual Stack).&lt;/p&gt;&lt;p&gt;The new technology also helps increasing our reach towards other parts of the world. For instance, most of the broadband connections on offer in Asian countries have already dropped support for IPv4 and exclusively communicate through IPv6. If internet services don’t support the new protocol, they remain practically invisible to these users.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;h3&gt;mailbox.org services that can be accessed through IPv6:&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;Website: https://mailbox.org, user forum, helpdesk, knowledge-base&lt;/li&gt;&lt;li&gt;Cloud office: https://office.mailbox.org&lt;/li&gt;&lt;li&gt;E-mail (IMAP): imap.mailbox.org&lt;/li&gt;&lt;li&gt;E-mail (SMTP): smtp.mailbox.org&lt;/li&gt;&lt;li&gt;CalDAV/CardDAV/WebDAV: dav.mailbox.org&lt;/li&gt;&lt;li&gt;HKP-Server: pgp.mailbox.org&lt;/li&gt;&lt;li&gt;Download-Links: share.mailbox.org&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;In summary, all our systems that users communicate with directly support both IPv4 and IPv6. On the back-end side, the MX relay servers, which internet providers use to exchange e-mail traffic, still run on IPv4. We decided not to upgrade these just yet, as we expect there may be communication problems if we did this too soon. The reason is that not all providers (and especially the spam protection software they use) would currently cope equally well with the new protocol. There is also no real technical advantage in upgrading the MX relays to IPv6, so leaving things as they are for the time being will protect users against unwanted side effects.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;h3&gt;About IPv6&lt;/h3&gt;&lt;p&gt;The number of internet-connected devices is growing at an increasing scale, and it is foreseeable that the amount of internet addresses that can be provided under the IPv4 protocol will soon not suffice any more. IPv6 offers a vastly greater address space to solve this problem – about 340 sextillion addresses as opposed to IPv4’s 4.3 billion addresses.(*) In some Asian countries, IPv4 addresses are already getting scarce, leading to many providers requiring IPv6 for all internet connections. The “old” IPv4 protocol is still more widely used in Europe but its replacement with IPv6 is already in progress.&lt;/p&gt;&lt;p&gt;(*) Source: &lt;a href="https://en.wikipedia.org/wiki/IPv6" target="_blank" rel="noopener"&gt;https://en.wikipedia.org/wiki/IPv6&lt;/a&gt;&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-04/mailbox-news-und-updates-produktupdate.jpg?itok=VmAEEH73" type="image/jpeg" length="400284"/><guid isPermaLink="false">3641a808-60b4-4b9b-bdcd-07dfd86f0fca</guid>
    <pubDate>Thu, 01 Mar 2018 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>mailbox.org is accessible for IPv6-based connections</dc:title>
    <dc:identifier>3641a808-60b4-4b9b-bdcd-07dfd86f0fca</dc:identifier>
    </item>
<item>
  <title>mailbox.org is accessible for IPv6-based connections</title>
  <link>https://mailbox.org/en/news/technical-infrastructure-update-mailbox/</link>
  <description>&lt;p&gt;&lt;em&gt;Executive summary:&lt;/em&gt;&lt;/p&gt;&lt;p&gt;&lt;em&gt;The mailbox.org admin team has been working hard to improve our infrastructure, with the result that our server systems now accept connections via the latest version of the internet protocol IPv6. Customers who use devices that support IPv6 will benefit from connections that get established quicker and show improved latency.&lt;/em&gt;&lt;/p&gt;&lt;p&gt;mailbox.org now offers all customers the option to use IPv6-based connections to our server systems. With our latest infrastructure update, e-mail services, website, and the cloud office can be accessed through this latest version of the internet protocol. With IPv6, customers benefit from lower latency times and better connection speed. The only requirement: Devices and internet connection at the client side need to be able to “speak” IPv6 as well. However, most broadband- or cable internet providers will support IPv6 already and those that don’t will likely do so soon. Needless to say, mobile devices like smartphones and tablet computers increasingly communicate via IPv6, too.&lt;/p&gt;&lt;p&gt;For example, if a compatible device connects to “imap.mailbox.org” to retrieve e-mails, then that server will automatically resolve an IPv6 address without the need for any separate configuration. Devices that do not support the new protocol version can still use all services as usual with the IPv4 protocol, because mailbox.org provides interfaces for both the old and the new protocol in parallel (Dual Stack).&lt;/p&gt;&lt;p&gt;The new technology also helps increasing our reach towards other parts of the world. For instance, most of the broadband connections on offer in Asian countries have already dropped support for IPv4 and exclusively communicate through IPv6. If internet services don’t support the new protocol, they remain practically invisible to these users.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;h3&gt;mailbox.org services that can be accessed through IPv6:&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;Website: https://mailbox.org, user forum, helpdesk, knowledge-base&lt;/li&gt;&lt;li&gt;Cloud office: https://office.mailbox.org&lt;/li&gt;&lt;li&gt;E-mail (IMAP): imap.mailbox.org&lt;/li&gt;&lt;li&gt;E-mail (SMTP): smtp.mailbox.org&lt;/li&gt;&lt;li&gt;CalDAV/CardDAV/WebDAV: dav.mailbox.org&lt;/li&gt;&lt;li&gt;HKP-Server: pgp.mailbox.org&lt;/li&gt;&lt;li&gt;Download-Links: share.mailbox.org&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;In summary, all our systems that users communicate with directly support both IPv4 and IPv6. On the back-end side, the MX relay servers, which internet providers use to exchange e-mail traffic, still run on IPv4. We decided not to upgrade these just yet, as we expect there may be communication problems if we did this too soon. The reason is that not all providers (and especially the spam protection software they use) would currently cope equally well with the new protocol. There is also no real technical advantage in upgrading the MX relays to IPv6, so leaving things as they are for the time being will protect users against unwanted side effects.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;h3&gt;About IPv6&lt;/h3&gt;&lt;p&gt;The number of internet-connected devices is growing at an increasing scale, and it is foreseeable that the amount of internet addresses that can be provided under the IPv4 protocol will soon not suffice any more. IPv6 offers a vastly greater address space to solve this problem – about 340 sextillion addresses as opposed to IPv4’s 4.3 billion addresses.(*) In some Asian countries, IPv4 addresses are already getting scarce, leading to many providers requiring IPv6 for all internet connections. The “old” IPv4 protocol is still more widely used in Europe but its replacement with IPv6 is already in progress.&lt;/p&gt;&lt;p&gt;(*) Source: &lt;a href="https://en.wikipedia.org/wiki/IPv6" target="_blank" rel="noopener"&gt;https://en.wikipedia.org/wiki/IPv6&lt;/a&gt;&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-04/mailbox-news-und-updates-produktupdate.jpg?itok=VmAEEH73" type="image/jpeg" length="400284"/><guid isPermaLink="false">3641a808-60b4-4b9b-bdcd-07dfd86f0fca</guid>
    <pubDate>Thu, 01 Mar 2018 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>mailbox.org is accessible for IPv6-based connections</dc:title>
    <dc:identifier>3641a808-60b4-4b9b-bdcd-07dfd86f0fca</dc:identifier>
    </item>
<item>
  <title>Introduction of new payment methods ‘paydirekt’ and ‘Sofort’</title>
  <link>https://mailbox.org/en/news/introduction-new-payment-methods/</link>
  <description>&lt;p&gt;We are pleased to announce two additional payment methods that are now available for all customers topping up their mailbox.org credit balance. Both „paydirekt“ and „Sofort-Überweisung“ offer their users real-time express bank transfer transactions.&lt;/p&gt;&lt;p&gt;This also means that all new customers of mailbox.org can now access the full range of their cloud office features immediately, without needing a PayPal account.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;h2&gt;New payment method “paydirekt”&lt;/h2&gt;&lt;p&gt;Unlike many other payment services, paydirekt is not a separate third-party service but offered as an extension for ordinary bank accounts. Users can register for paydirekt through their online banking interface and set up a username and password there. Please consult your bank or building society to find out if they offer paydirekt integration with their products and services. If your German is up for it, you can also search the current list of participating organisations (“Bankensuche”) on the paydirekt website to find out.&lt;/p&gt;&lt;h4&gt;Advantages of paydirekt&lt;/h4&gt;&lt;ul&gt;&lt;li&gt;Secure and approved service integration by your own banking institution&lt;/li&gt;&lt;li&gt;Transactions do not require the involvement of any third-party partners&lt;/li&gt;&lt;li&gt;Buyer protection included&lt;/li&gt;&lt;li&gt;Any paydirekt payments appear automatically on your regular bank statement&lt;/li&gt;&lt;li&gt;Real-time transaction confirmation makes it possible for new customers of mailbox.org to use the full feature-range of their tariff immediately. Previously, customers either needed to wait for their regular bank transfer to complete, or use a PayPal account.&lt;/li&gt;&lt;/ul&gt;&lt;h2 class="western"&gt;New payment method “Sofort” by Klarna&lt;/h2&gt;&lt;p&gt;“Sofort-Überweisung” by &lt;a href="https://www.klarna.com/sofort/" target="_blank" rel="noopener"&gt;Klarna&lt;/a&gt; offers a regular bank transfer service with the added benefit of instant transaction confirmation. Even though the money may take a few days to arrive in our account (like any ordinary bank transfer), the instant confirmation allows us to credit your account in advance of actually receiving the payment. However, if you want to use the Sofort-Überweisung, you need to trust the vendor with your online banking credentials, including PIN and TAN. This may not be acceptable for those customers who have particular security needs.&lt;/p&gt;&lt;h4&gt;Advantages of Sofort-Überweisung&lt;/h4&gt;&lt;ul&gt;&lt;li&gt;Transaction confirmation in real-time. This makes it possible for any of our new mailbox.org customers to access all of their cloud office features immediately – an improvement over using ordinary bank transfer.&lt;/li&gt;&lt;li&gt;Sofort-Überweisung allows online bank transfer payments across country borders and is currently available in the following countries: Germany, Austria, Switzerland, Belgium, United Kingdom, Netherlands, Italy, Poland, Hungary, Slovakia, Czech Republic, France, and Spain.&lt;/li&gt;&lt;/ul&gt;&lt;h2 class="western"&gt;Overview: our payment methods&lt;/h2&gt;&lt;ul&gt;&lt;li&gt;Bank transfer&lt;/li&gt;&lt;li&gt;Paydirekt&lt;/li&gt;&lt;li&gt;Sofort-Überweisung&lt;/li&gt;&lt;li&gt;Bitcoin&lt;/li&gt;&lt;li&gt;PayPal&lt;/li&gt;&lt;li&gt;Cash by mail (EURO currency only. No cheques.)&lt;/li&gt;&lt;li&gt;Cash payment into our bank account&lt;/li&gt;&lt;/ul&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-payment-credit-card.jpeg?itok=X0rlqwA-" type="image/jpeg" length="276063"/><guid isPermaLink="false">0d3e1201-7f91-4fa3-af22-870fe0947a5e</guid>
    <pubDate>Fri, 01 Dec 2017 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Introduction of new payment methods ‘paydirekt’ and ‘Sofort’</dc:title>
    <dc:identifier>0d3e1201-7f91-4fa3-af22-870fe0947a5e</dc:identifier>
    </item>
<item>
  <title>Introduction of new payment methods ‘paydirekt’ and ‘Sofort’</title>
  <link>https://mailbox.org/en/news/introduction-new-payment-methods/</link>
  <description>&lt;p&gt;We are pleased to announce two additional payment methods that are now available for all customers topping up their mailbox.org credit balance. Both „paydirekt“ and „Sofort-Überweisung“ offer their users real-time express bank transfer transactions.&lt;/p&gt;&lt;p&gt;This also means that all new customers of mailbox.org can now access the full range of their cloud office features immediately, without needing a PayPal account.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;h2&gt;New payment method “paydirekt”&lt;/h2&gt;&lt;p&gt;Unlike many other payment services, paydirekt is not a separate third-party service but offered as an extension for ordinary bank accounts. Users can register for paydirekt through their online banking interface and set up a username and password there. Please consult your bank or building society to find out if they offer paydirekt integration with their products and services. If your German is up for it, you can also search the current list of participating organisations (“Bankensuche”) on the paydirekt website to find out.&lt;/p&gt;&lt;h4&gt;Advantages of paydirekt&lt;/h4&gt;&lt;ul&gt;&lt;li&gt;Secure and approved service integration by your own banking institution&lt;/li&gt;&lt;li&gt;Transactions do not require the involvement of any third-party partners&lt;/li&gt;&lt;li&gt;Buyer protection included&lt;/li&gt;&lt;li&gt;Any paydirekt payments appear automatically on your regular bank statement&lt;/li&gt;&lt;li&gt;Real-time transaction confirmation makes it possible for new customers of mailbox.org to use the full feature-range of their tariff immediately. Previously, customers either needed to wait for their regular bank transfer to complete, or use a PayPal account.&lt;/li&gt;&lt;/ul&gt;&lt;h2 class="western"&gt;New payment method “Sofort” by Klarna&lt;/h2&gt;&lt;p&gt;“Sofort-Überweisung” by &lt;a href="https://www.klarna.com/sofort/" target="_blank" rel="noopener"&gt;Klarna&lt;/a&gt; offers a regular bank transfer service with the added benefit of instant transaction confirmation. Even though the money may take a few days to arrive in our account (like any ordinary bank transfer), the instant confirmation allows us to credit your account in advance of actually receiving the payment. However, if you want to use the Sofort-Überweisung, you need to trust the vendor with your online banking credentials, including PIN and TAN. This may not be acceptable for those customers who have particular security needs.&lt;/p&gt;&lt;h4&gt;Advantages of Sofort-Überweisung&lt;/h4&gt;&lt;ul&gt;&lt;li&gt;Transaction confirmation in real-time. This makes it possible for any of our new mailbox.org customers to access all of their cloud office features immediately – an improvement over using ordinary bank transfer.&lt;/li&gt;&lt;li&gt;Sofort-Überweisung allows online bank transfer payments across country borders and is currently available in the following countries: Germany, Austria, Switzerland, Belgium, United Kingdom, Netherlands, Italy, Poland, Hungary, Slovakia, Czech Republic, France, and Spain.&lt;/li&gt;&lt;/ul&gt;&lt;h2 class="western"&gt;Overview: our payment methods&lt;/h2&gt;&lt;ul&gt;&lt;li&gt;Bank transfer&lt;/li&gt;&lt;li&gt;Paydirekt&lt;/li&gt;&lt;li&gt;Sofort-Überweisung&lt;/li&gt;&lt;li&gt;Bitcoin&lt;/li&gt;&lt;li&gt;PayPal&lt;/li&gt;&lt;li&gt;Cash by mail (EURO currency only. No cheques.)&lt;/li&gt;&lt;li&gt;Cash payment into our bank account&lt;/li&gt;&lt;/ul&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-payment-credit-card.jpeg?itok=X0rlqwA-" type="image/jpeg" length="276063"/><guid isPermaLink="false">0d3e1201-7f91-4fa3-af22-870fe0947a5e</guid>
    <pubDate>Fri, 01 Dec 2017 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Introduction of new payment methods ‘paydirekt’ and ‘Sofort’</dc:title>
    <dc:identifier>0d3e1201-7f91-4fa3-af22-870fe0947a5e</dc:identifier>
    </item>
<item>
  <title>Useful additional features for your email inbox</title>
  <link>https://mailbox.org/en/news/new-and-improved-features-coming-our-latest-website-update/</link>
  <description>&lt;p&gt;The most recent mailbox.org software update delivers improvements for the full-text search tool, better usability of inbox features, and easier editing of encrypted documents that are located on the Drive online storage. Furthermore, spamfilter settings can now be customized to meet special requirements.&lt;/p&gt;&lt;h2&gt;Improvements and new features of the mailbox.org web interface&lt;/h2&gt;&lt;p&gt;Intelligent full-text search&lt;/p&gt;&lt;ul&gt;&lt;li&gt;The new full-text search not only allows searching the inbox contents for keywords relating to recipient, sender, and subject line but can now also parse the actual content of e-mails, as well as MS Word and PDF attachments.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;E-mail improvements&lt;/p&gt;&lt;ul&gt;&lt;li&gt;If presentation files are received as e-mail attachments, these can now be run directly from the e-mail window. Saving those files to the Drive or changing to the presentations menu first is no longer necessary for this.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Any e-mails left in editing mode before logout from the web interface will be automatically restored to editing mode after the next login. Upon logging in, the mailbox.org interface will display a pop-up window to offer restoring any open applications such as unsent e-mail drafts. Here, users can simply select a message to pick up editing where they left off last time.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;When selecting different addresses, for instance to find shared meetings or appointments, the selected addresses can now be saved as a mailing list for convenience.&lt;/li&gt;&lt;li&gt;There is also an additional folder „Unread messages“. As the name suggests, all unread e-mails will be automatically filtered to be easily accessible here. This is a virtual folder – the actual e-mails are still physically located in the normal inbox folder.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Improvements in contacts and calendars&lt;/p&gt;&lt;p&gt;The calendar has been enhanced to improve general usability. The application now responds to key shortcuts. There is also better handling of recurring apointments so for instance, it is now possible to set an event to occur on the „Last Friday of every month“.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;The address book has got an additional option for printing lists that may contain not just the phone numbers but also other details of your contacts, as required.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;New features for the Drive online storage&lt;/p&gt;&lt;p&gt;Users of mailbox.org Guard can now open encrypted mailbox.org Office files more quickly with a doubleclick and without having to enter the decryption password repeatedly.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Photos can be displayed automatically as a slide show. To do this, users simply click on the semi-transparent arrow overlay that appears in the centre of the image.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Additional settings&lt;/p&gt;&lt;ul&gt;&lt;li&gt;The mailbox.org e-mail settings now contain an additional section for setting the default font style, -size, and -colour to be used in e-mails.&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;New feature: Customized mailbox.org spam filter settings&lt;/h2&gt;&lt;p&gt;Due to popular demand, we have implemented a spam protection interface that allows our private users to adjust their own spam filter settings to suit individual needs. However, note that for the vast majority of users, modifying the spam filter configuration is not necessary – the default settings already provide optimal protection!&lt;/p&gt;&lt;p&gt;Therefore, we generally recommend using the default settings unless there are significant problems with false positives.&lt;/p&gt;&lt;p&gt;How does spam filtering work at mailbox.org?&lt;/p&gt;&lt;p&gt;Our spam protection system does not use a spam or quarantine folder to store suspicious messages in, as is often the case with other e-mail providers. Our servers are capable of checking e-mails for spam and viruses in realtime as they arrive on our systems. If any spam has been found, the corresponding e-mails will be instantly rejected and returned to sender with a delivery failure message.&lt;/p&gt;&lt;p&gt;This way of handling spam has certain advantages, firstly in terms of communication and, depending on the user’s country of residence, also legally. With regard to the first, the sender of an e-mail will instantly know whether their message has been delivered or rejected and does not need to rely on the recipient to frequently check spam or quarantine folders. On the legal side, in countries like Germany an e-mail sent by government authorities can have a status similar to an official letter and is considered „delivered“ upon arrival at the recipient’s inbox, even if it has been moved to a spam folder – which, in practice, does not necessarily mean the recipient is actually aware of that message. If such a problematic e-mail is rejected instead, then it is clear that the user has not received the message, which creates certainty for everyone involved.&lt;/p&gt;&lt;p&gt;Configuration options for the individual spam filter&lt;/p&gt;&lt;p&gt;The following options are available for configuring the spam protection on an individual level:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Greylisting&lt;/li&gt;&lt;li&gt;SMTP plausibility check&lt;/li&gt;&lt;li&gt;Realtime Blacklists (RBL)&lt;/li&gt;&lt;li&gt;Content spam filter&lt;/li&gt;&lt;li&gt;Executable attachments&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Whenever changes to the spam filter settings are made, a coloured bar will indicate the approximate protection level achieved. While changes may be useful in certain circumstances, users should be aware that deviating from the default settings can lead to lower protection or an increase in false positives.&lt;/p&gt;&lt;p&gt;Users are responsible for any changes they make to their individual spam filter configuration. Please note that we are unable to provide support in cases where protection levels are set below 100%.&lt;/p&gt;&lt;p&gt;Please consult our dedicated &lt;a href="https://support-en.mailbox.org/knowledge-base/article/customizing-your-mailbox-org-spam-filter-settings" target="_blank" rel="noopener"&gt;knowledge base article&lt;/a&gt; on the subject to learn more about how the individual spam filter components work, and how they are properly configured.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-04/mailbox-news-und-updates-produktupdate-2.jpg?itok=_u6eySrM" type="image/jpeg" length="284259"/><guid isPermaLink="false">f5c1332c-9b32-44af-bc99-cbbba8ba4d5b</guid>
    <pubDate>Wed, 19 Jul 2017 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Useful additional features for your email inbox</dc:title>
    <dc:identifier>f5c1332c-9b32-44af-bc99-cbbba8ba4d5b</dc:identifier>
    </item>
<item>
  <title>Useful additional features for your email inbox</title>
  <link>https://mailbox.org/en/news/new-and-improved-features-coming-our-latest-website-update/</link>
  <description>&lt;p&gt;The most recent mailbox.org software update delivers improvements for the full-text search tool, better usability of inbox features, and easier editing of encrypted documents that are located on the Drive online storage. Furthermore, spamfilter settings can now be customized to meet special requirements.&lt;/p&gt;&lt;h2&gt;Improvements and new features of the mailbox.org web interface&lt;/h2&gt;&lt;p&gt;Intelligent full-text search&lt;/p&gt;&lt;ul&gt;&lt;li&gt;The new full-text search not only allows searching the inbox contents for keywords relating to recipient, sender, and subject line but can now also parse the actual content of e-mails, as well as MS Word and PDF attachments.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;E-mail improvements&lt;/p&gt;&lt;ul&gt;&lt;li&gt;If presentation files are received as e-mail attachments, these can now be run directly from the e-mail window. Saving those files to the Drive or changing to the presentations menu first is no longer necessary for this.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Any e-mails left in editing mode before logout from the web interface will be automatically restored to editing mode after the next login. Upon logging in, the mailbox.org interface will display a pop-up window to offer restoring any open applications such as unsent e-mail drafts. Here, users can simply select a message to pick up editing where they left off last time.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;When selecting different addresses, for instance to find shared meetings or appointments, the selected addresses can now be saved as a mailing list for convenience.&lt;/li&gt;&lt;li&gt;There is also an additional folder „Unread messages“. As the name suggests, all unread e-mails will be automatically filtered to be easily accessible here. This is a virtual folder – the actual e-mails are still physically located in the normal inbox folder.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Improvements in contacts and calendars&lt;/p&gt;&lt;p&gt;The calendar has been enhanced to improve general usability. The application now responds to key shortcuts. There is also better handling of recurring apointments so for instance, it is now possible to set an event to occur on the „Last Friday of every month“.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;The address book has got an additional option for printing lists that may contain not just the phone numbers but also other details of your contacts, as required.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;New features for the Drive online storage&lt;/p&gt;&lt;p&gt;Users of mailbox.org Guard can now open encrypted mailbox.org Office files more quickly with a doubleclick and without having to enter the decryption password repeatedly.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Photos can be displayed automatically as a slide show. To do this, users simply click on the semi-transparent arrow overlay that appears in the centre of the image.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Additional settings&lt;/p&gt;&lt;ul&gt;&lt;li&gt;The mailbox.org e-mail settings now contain an additional section for setting the default font style, -size, and -colour to be used in e-mails.&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;New feature: Customized mailbox.org spam filter settings&lt;/h2&gt;&lt;p&gt;Due to popular demand, we have implemented a spam protection interface that allows our private users to adjust their own spam filter settings to suit individual needs. However, note that for the vast majority of users, modifying the spam filter configuration is not necessary – the default settings already provide optimal protection!&lt;/p&gt;&lt;p&gt;Therefore, we generally recommend using the default settings unless there are significant problems with false positives.&lt;/p&gt;&lt;p&gt;How does spam filtering work at mailbox.org?&lt;/p&gt;&lt;p&gt;Our spam protection system does not use a spam or quarantine folder to store suspicious messages in, as is often the case with other e-mail providers. Our servers are capable of checking e-mails for spam and viruses in realtime as they arrive on our systems. If any spam has been found, the corresponding e-mails will be instantly rejected and returned to sender with a delivery failure message.&lt;/p&gt;&lt;p&gt;This way of handling spam has certain advantages, firstly in terms of communication and, depending on the user’s country of residence, also legally. With regard to the first, the sender of an e-mail will instantly know whether their message has been delivered or rejected and does not need to rely on the recipient to frequently check spam or quarantine folders. On the legal side, in countries like Germany an e-mail sent by government authorities can have a status similar to an official letter and is considered „delivered“ upon arrival at the recipient’s inbox, even if it has been moved to a spam folder – which, in practice, does not necessarily mean the recipient is actually aware of that message. If such a problematic e-mail is rejected instead, then it is clear that the user has not received the message, which creates certainty for everyone involved.&lt;/p&gt;&lt;p&gt;Configuration options for the individual spam filter&lt;/p&gt;&lt;p&gt;The following options are available for configuring the spam protection on an individual level:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Greylisting&lt;/li&gt;&lt;li&gt;SMTP plausibility check&lt;/li&gt;&lt;li&gt;Realtime Blacklists (RBL)&lt;/li&gt;&lt;li&gt;Content spam filter&lt;/li&gt;&lt;li&gt;Executable attachments&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Whenever changes to the spam filter settings are made, a coloured bar will indicate the approximate protection level achieved. While changes may be useful in certain circumstances, users should be aware that deviating from the default settings can lead to lower protection or an increase in false positives.&lt;/p&gt;&lt;p&gt;Users are responsible for any changes they make to their individual spam filter configuration. Please note that we are unable to provide support in cases where protection levels are set below 100%.&lt;/p&gt;&lt;p&gt;Please consult our dedicated &lt;a href="https://support-en.mailbox.org/knowledge-base/article/customizing-your-mailbox-org-spam-filter-settings" target="_blank" rel="noopener"&gt;knowledge base article&lt;/a&gt; on the subject to learn more about how the individual spam filter components work, and how they are properly configured.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-04/mailbox-news-und-updates-produktupdate-2.jpg?itok=_u6eySrM" type="image/jpeg" length="284259"/><guid isPermaLink="false">f5c1332c-9b32-44af-bc99-cbbba8ba4d5b</guid>
    <pubDate>Wed, 19 Jul 2017 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Useful additional features for your email inbox</dc:title>
    <dc:identifier>f5c1332c-9b32-44af-bc99-cbbba8ba4d5b</dc:identifier>
    </item>
<item>
  <title>Now also presentations in Online Office</title>
  <link>https://mailbox.org/en/news/software-update-create-and-share-presentations-mailbox-cloud-office/</link>
  <description>&lt;p&gt;There has been a recent update of the mailbox.org cloud office which includes a number of usability and accessibility improvements. In addition, there is now also a new feature for creating and editing presentations online.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;h3&gt;New feature – Presentation&lt;/h3&gt;&lt;p&gt;The update brings a new „Presentation“ module to the cloud office, which allows users to create and edit presentations at home and on the go, as a sole user or collaboratively with colleagues or fellow students. You can access your presentations and templates from anywhere and show them directly from the mailbox.org cloud office in the browser window.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;These are some of the key features:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Support for handling Microsoft Powerpoint files (from version 2007) with the original formatting remaining intact upon import&lt;/li&gt;&lt;li&gt;Master and Layout slides can be edited easily&lt;/li&gt;&lt;li&gt;Add figures and shapes to your presentation&lt;/li&gt;&lt;li&gt;Straightforward format adjustments and grouping of objects; convenient drag&amp;amp;drop of pictures from web pages or the local desktop into the presentation in the browser&lt;/li&gt;&lt;li&gt;Shared and collaborative editing of presentations across the Web&lt;/li&gt;&lt;/ul&gt;&amp;nbsp;Master and Layout slides can be edited easily&lt;h3&gt;Improved calendar view for appointments with many attendees.&lt;/h3&gt;&lt;p&gt;There is now an improved view in the calendar for setting up appointments that involve a large number of people. Selected attendees and their appointments can be displayed in a list, which makes it easier to consider everyone’s existing commitments and find a free slot that will suit all those to be invited.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;h3&gt;Improvements in „Documents“&lt;/h3&gt;&lt;p&gt;Any documents that were encrypted with GUARD can now be opened faster by entering the password just once. It is no longer required to decrypt documents individually as long as the correct password was entered once during the current session.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;h3&gt;Shared images preview for Drive Mail&lt;/h3&gt;&lt;p&gt;When users share files, recipients will receive an e-mail from the Drive module. We improved the usability here by giving users the option to see a thumbnail preview of the shared image.&lt;/p&gt;&lt;h3&gt;Better usability of GUARD function&lt;/h3&gt;&lt;p&gt;Feedback we have received from our users suggests that some of them are struggling a bit with the setup and use of encryption with their account. As a consequence, we have made some encryption features easier to use, with improved support and guidance for encrypting documents and files on the Drive..&lt;/p&gt;&lt;h3&gt;Users can also look forward to the following advanced inbox features:&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;When composing an e-mail, click the plus-symbol within any of the recipient fields („To“, „CC“, BCC“) to conveniently view and select one or more of your address book contacts from a list.&lt;/li&gt;&lt;li&gt;Mailing lists can now be imported and exported.&lt;/li&gt;&lt;/ul&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-04/mailbox-news-und-updates-produktupdate.jpg?itok=VmAEEH73" type="image/jpeg" length="400284"/><guid isPermaLink="false">af6d7dc0-88ab-467a-8cd3-cff81a0655d9</guid>
    <pubDate>Wed, 22 Mar 2017 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Now also presentations in Online Office</dc:title>
    <dc:identifier>af6d7dc0-88ab-467a-8cd3-cff81a0655d9</dc:identifier>
    </item>
<item>
  <title>Now also presentations in Online Office</title>
  <link>https://mailbox.org/en/news/software-update-create-and-share-presentations-mailbox-cloud-office/</link>
  <description>&lt;p&gt;There has been a recent update of the mailbox.org cloud office which includes a number of usability and accessibility improvements. In addition, there is now also a new feature for creating and editing presentations online.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;h3&gt;New feature – Presentation&lt;/h3&gt;&lt;p&gt;The update brings a new „Presentation“ module to the cloud office, which allows users to create and edit presentations at home and on the go, as a sole user or collaboratively with colleagues or fellow students. You can access your presentations and templates from anywhere and show them directly from the mailbox.org cloud office in the browser window.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;These are some of the key features:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Support for handling Microsoft Powerpoint files (from version 2007) with the original formatting remaining intact upon import&lt;/li&gt;&lt;li&gt;Master and Layout slides can be edited easily&lt;/li&gt;&lt;li&gt;Add figures and shapes to your presentation&lt;/li&gt;&lt;li&gt;Straightforward format adjustments and grouping of objects; convenient drag&amp;amp;drop of pictures from web pages or the local desktop into the presentation in the browser&lt;/li&gt;&lt;li&gt;Shared and collaborative editing of presentations across the Web&lt;/li&gt;&lt;/ul&gt;&amp;nbsp;Master and Layout slides can be edited easily&lt;h3&gt;Improved calendar view for appointments with many attendees.&lt;/h3&gt;&lt;p&gt;There is now an improved view in the calendar for setting up appointments that involve a large number of people. Selected attendees and their appointments can be displayed in a list, which makes it easier to consider everyone’s existing commitments and find a free slot that will suit all those to be invited.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;h3&gt;Improvements in „Documents“&lt;/h3&gt;&lt;p&gt;Any documents that were encrypted with GUARD can now be opened faster by entering the password just once. It is no longer required to decrypt documents individually as long as the correct password was entered once during the current session.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;h3&gt;Shared images preview for Drive Mail&lt;/h3&gt;&lt;p&gt;When users share files, recipients will receive an e-mail from the Drive module. We improved the usability here by giving users the option to see a thumbnail preview of the shared image.&lt;/p&gt;&lt;h3&gt;Better usability of GUARD function&lt;/h3&gt;&lt;p&gt;Feedback we have received from our users suggests that some of them are struggling a bit with the setup and use of encryption with their account. As a consequence, we have made some encryption features easier to use, with improved support and guidance for encrypting documents and files on the Drive..&lt;/p&gt;&lt;h3&gt;Users can also look forward to the following advanced inbox features:&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;When composing an e-mail, click the plus-symbol within any of the recipient fields („To“, „CC“, BCC“) to conveniently view and select one or more of your address book contacts from a list.&lt;/li&gt;&lt;li&gt;Mailing lists can now be imported and exported.&lt;/li&gt;&lt;/ul&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-04/mailbox-news-und-updates-produktupdate.jpg?itok=VmAEEH73" type="image/jpeg" length="400284"/><guid isPermaLink="false">af6d7dc0-88ab-467a-8cd3-cff81a0655d9</guid>
    <pubDate>Wed, 22 Mar 2017 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Now also presentations in Online Office</dc:title>
    <dc:identifier>af6d7dc0-88ab-467a-8cd3-cff81a0655d9</dc:identifier>
    </item>
<item>
  <title>Important: TLS encryption upgrade</title>
  <link>https://mailbox.org/en/news/important-mailbox-upgrades-tls-encryption-protocols/</link>
  <description>&lt;p&gt;Security is not a one-off activity but a process that needs permanent checking and updating. We at mailbox.org are constantly striving towards offering a wide range of security measures, compliant with current standards, and implementing the highest level of security possible on our servers.&lt;/p&gt;&lt;p&gt;In the week running up to Christmas, we are going to make the first of a series of changes to the background encryption technologies that are used on our servers. Doing this will not just increase security for our customers but is also required for us to maintain compliance, because, from January 2017, the German federal office for information security (BSI) has increased the requirements for their Certification as a “Secure E-mail Provider“.&lt;/p&gt;&lt;p&gt;The new rules that will come into force mean that TLS protocol versions 1.0 and 1.1 must not be used anymore, to be replaced comprehensively by TLS 1.2. The vast majority of implementations do already use this new protocol version and won’t notice a change; however, we estimate there are about 2-3% of systems that use the outdated TLS protocols, especially where customers run older software on legacy operating systems. It is to be expected that other platforms and online shops on the Internet will experience similar compatibility problems, as other providers get their systems up-to-date. Making these systems fit for the new protocols is therefore strongly recommended, as support for legacy systems is going to fade over time.&lt;/p&gt;&lt;p&gt;If your own IT has a few quiet days after Christmas, then this could be an opportunity to have a software review and look for opportunities to replace those products that present a security risk and are no longer fit for service.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;h2&gt;Planned changes and software compatibility&lt;/h2&gt;&lt;p&gt;Older software might no longer be compatible with the new technologies used. The following legacy web browsers may become incompatible with the mailbox.org Office (and other applications on the Internet) sooner or later and will need to be updated:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Internet Explorer version 10 or less&lt;/li&gt;&lt;li&gt;Firefox version 24 or less&lt;/li&gt;&lt;li&gt;Google Chrome version 29 or less&lt;/li&gt;&lt;li&gt;Safari version 8 or less&lt;/li&gt;&lt;li&gt;Opera version 16 or less&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Further, e-mail, contacts and calendar functions may no longer work or no longer sync with the mailbox.org Office and other services IF you use the following outdated smartphone operating systems:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Android version 4.3 or less&lt;/li&gt;&lt;li&gt;Windows 8.1 without further updates&lt;/li&gt;&lt;li&gt;iOS version 8.4 or less&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Users of our dedicated Jabber service will be affected by the changes if they use the Jitsi client für Windows. For now, these users will need to change their client, as Jitsi does not support the new protocol yet.&lt;/p&gt;&lt;p&gt;Please note that updating software products is often generally beneficial as more recent versions may contain fixes to security issues that exist in older versions. Therefore, we would ask all customers who use old software to consider updating it.&lt;/p&gt;&lt;p&gt;At this point, we cannot say when the implementation of the new security requirements will be completed. We are currently determining which customers may be affected by the various changes and how we can ensure a smooth transition for all. However, it is certain that TLS versions 1.0 and 1.1 will sooner or later disappear from the Internet entirely and it is therefore important to take precautions.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;h2&gt;Technical details and background&lt;/h2&gt;&lt;p&gt;In the week coming up to Christmas day, we are going to start implementing the first set of upgrades to TLS encryption on our servers, based on the BSI guidelines &lt;a href="https://www.bsi.bund.de/DE/Publikationen/TechnischeRichtlinien/tr03116/index_htm.html"&gt;TR-03116-4&lt;/a&gt; (Communication security requirements for TLS, S/MIME, OpenPGP and SAML) and &lt;a href="https://www.bsi.bund.de/DE/Publikationen/TechnischeRichtlinien/tr02102/index_htm.html"&gt;TR-02102-2 &lt;/a&gt;(Cryptographic mechanisms and keys). Only those providers implementing the above guidelines will be considered for continued certification as a “Secure E-mail Provider” according to BSI guideline &lt;a href="https://www.bsi.bund.de/DE/Publikationen/TechnischeRichtlinien/tr03108/index_htm.html"&gt;TR-03108-4&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;h3&gt;SHA-1 Hash Algorithm has become obsolete&lt;/h3&gt;&lt;p&gt;The grace period for using the SHA-1 algorithm for TLS encryption (BSI guideline TR-02102-2) will cease at the end of 2016. From January 2017, this hash algorithm may no longer be used for authenticating TLS-encrypted messages and certificates. SHA-1 is to be replaced by the stronger variants SHA256 and SHA384.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;h3&gt;TLS 1.0 and TLS 1.1 may no longer be used&lt;/h3&gt;&lt;p&gt;According to the BSI guideline TR-02102-2, TLSv1.0 and TLSv1.1 may no longer be used for encryption from January 2017. The main reason is that the only hash cipher suites defined for these protocols are of the SHA-1 kind, which will be obsolete from next year on. We are currently in the process of assessing the impact of an upgrade on our systems and will be announcing a transition date in early January.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;h3&gt;Brainpool curves for ECDHE key exchange&lt;/h3&gt;&lt;p&gt;Whenever a browser or e-mail client connects to our servers, there is going to be an exchange of temporary session keys required for any data transmitted via TLS. After the connection is closed, the key becomes invalid. This mechanism is also called „Forward Secrecy“ and prevents any subsequent, future decryption of the transmitted data.&lt;/p&gt;&lt;p&gt;For negotiating the temporary session key, there are two principal methods, either the traditional Diffie-Hellman key exchange or a variant that is based on using elliptic curves. The second method supports different kinds of curves, and commonly used today are the NIST-specified „secp256r1“ and „secp384r1“.&lt;/p&gt;&lt;p&gt;The BSI guideline TR-03116-4 requires secure e-mail providers to prefer the elliptic curves „brainpoolP256r1“ or better as specified by the Brainpool consortium over those by NIST. NIST curves are only allowed if the connecting clients (e.g., browsers, or e-mail programs) do not support the Brainpool elliptic curves.&lt;/p&gt;&lt;p&gt;We are going to make changes to the e-mail servers this week to make sure they can offer keys based on Brainpool curves. The upgrades on our web servers are then to follow in January. For you as a customer, there won’t be any adverse effects because the existing methods are going to be maintained as a fall-back option.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-04/mailbox-news-und-updates-sicherheit.jpg?itok=4LMJmUnZ" type="image/jpeg" length="194998"/><guid isPermaLink="false">4439bbd0-eb54-4529-84de-6a5ca32001b0</guid>
    <pubDate>Thu, 15 Dec 2016 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Important: TLS encryption upgrade</dc:title>
    <dc:identifier>4439bbd0-eb54-4529-84de-6a5ca32001b0</dc:identifier>
    </item>
<item>
  <title>Important: TLS encryption upgrade</title>
  <link>https://mailbox.org/en/news/important-mailbox-upgrades-tls-encryption-protocols/</link>
  <description>&lt;p&gt;Security is not a one-off activity but a process that needs permanent checking and updating. We at mailbox.org are constantly striving towards offering a wide range of security measures, compliant with current standards, and implementing the highest level of security possible on our servers.&lt;/p&gt;&lt;p&gt;In the week running up to Christmas, we are going to make the first of a series of changes to the background encryption technologies that are used on our servers. Doing this will not just increase security for our customers but is also required for us to maintain compliance, because, from January 2017, the German federal office for information security (BSI) has increased the requirements for their Certification as a “Secure E-mail Provider“.&lt;/p&gt;&lt;p&gt;The new rules that will come into force mean that TLS protocol versions 1.0 and 1.1 must not be used anymore, to be replaced comprehensively by TLS 1.2. The vast majority of implementations do already use this new protocol version and won’t notice a change; however, we estimate there are about 2-3% of systems that use the outdated TLS protocols, especially where customers run older software on legacy operating systems. It is to be expected that other platforms and online shops on the Internet will experience similar compatibility problems, as other providers get their systems up-to-date. Making these systems fit for the new protocols is therefore strongly recommended, as support for legacy systems is going to fade over time.&lt;/p&gt;&lt;p&gt;If your own IT has a few quiet days after Christmas, then this could be an opportunity to have a software review and look for opportunities to replace those products that present a security risk and are no longer fit for service.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;h2&gt;Planned changes and software compatibility&lt;/h2&gt;&lt;p&gt;Older software might no longer be compatible with the new technologies used. The following legacy web browsers may become incompatible with the mailbox.org Office (and other applications on the Internet) sooner or later and will need to be updated:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Internet Explorer version 10 or less&lt;/li&gt;&lt;li&gt;Firefox version 24 or less&lt;/li&gt;&lt;li&gt;Google Chrome version 29 or less&lt;/li&gt;&lt;li&gt;Safari version 8 or less&lt;/li&gt;&lt;li&gt;Opera version 16 or less&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Further, e-mail, contacts and calendar functions may no longer work or no longer sync with the mailbox.org Office and other services IF you use the following outdated smartphone operating systems:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Android version 4.3 or less&lt;/li&gt;&lt;li&gt;Windows 8.1 without further updates&lt;/li&gt;&lt;li&gt;iOS version 8.4 or less&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Users of our dedicated Jabber service will be affected by the changes if they use the Jitsi client für Windows. For now, these users will need to change their client, as Jitsi does not support the new protocol yet.&lt;/p&gt;&lt;p&gt;Please note that updating software products is often generally beneficial as more recent versions may contain fixes to security issues that exist in older versions. Therefore, we would ask all customers who use old software to consider updating it.&lt;/p&gt;&lt;p&gt;At this point, we cannot say when the implementation of the new security requirements will be completed. We are currently determining which customers may be affected by the various changes and how we can ensure a smooth transition for all. However, it is certain that TLS versions 1.0 and 1.1 will sooner or later disappear from the Internet entirely and it is therefore important to take precautions.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;h2&gt;Technical details and background&lt;/h2&gt;&lt;p&gt;In the week coming up to Christmas day, we are going to start implementing the first set of upgrades to TLS encryption on our servers, based on the BSI guidelines &lt;a href="https://www.bsi.bund.de/DE/Publikationen/TechnischeRichtlinien/tr03116/index_htm.html"&gt;TR-03116-4&lt;/a&gt; (Communication security requirements for TLS, S/MIME, OpenPGP and SAML) and &lt;a href="https://www.bsi.bund.de/DE/Publikationen/TechnischeRichtlinien/tr02102/index_htm.html"&gt;TR-02102-2 &lt;/a&gt;(Cryptographic mechanisms and keys). Only those providers implementing the above guidelines will be considered for continued certification as a “Secure E-mail Provider” according to BSI guideline &lt;a href="https://www.bsi.bund.de/DE/Publikationen/TechnischeRichtlinien/tr03108/index_htm.html"&gt;TR-03108-4&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;h3&gt;SHA-1 Hash Algorithm has become obsolete&lt;/h3&gt;&lt;p&gt;The grace period for using the SHA-1 algorithm for TLS encryption (BSI guideline TR-02102-2) will cease at the end of 2016. From January 2017, this hash algorithm may no longer be used for authenticating TLS-encrypted messages and certificates. SHA-1 is to be replaced by the stronger variants SHA256 and SHA384.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;h3&gt;TLS 1.0 and TLS 1.1 may no longer be used&lt;/h3&gt;&lt;p&gt;According to the BSI guideline TR-02102-2, TLSv1.0 and TLSv1.1 may no longer be used for encryption from January 2017. The main reason is that the only hash cipher suites defined for these protocols are of the SHA-1 kind, which will be obsolete from next year on. We are currently in the process of assessing the impact of an upgrade on our systems and will be announcing a transition date in early January.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;h3&gt;Brainpool curves for ECDHE key exchange&lt;/h3&gt;&lt;p&gt;Whenever a browser or e-mail client connects to our servers, there is going to be an exchange of temporary session keys required for any data transmitted via TLS. After the connection is closed, the key becomes invalid. This mechanism is also called „Forward Secrecy“ and prevents any subsequent, future decryption of the transmitted data.&lt;/p&gt;&lt;p&gt;For negotiating the temporary session key, there are two principal methods, either the traditional Diffie-Hellman key exchange or a variant that is based on using elliptic curves. The second method supports different kinds of curves, and commonly used today are the NIST-specified „secp256r1“ and „secp384r1“.&lt;/p&gt;&lt;p&gt;The BSI guideline TR-03116-4 requires secure e-mail providers to prefer the elliptic curves „brainpoolP256r1“ or better as specified by the Brainpool consortium over those by NIST. NIST curves are only allowed if the connecting clients (e.g., browsers, or e-mail programs) do not support the Brainpool elliptic curves.&lt;/p&gt;&lt;p&gt;We are going to make changes to the e-mail servers this week to make sure they can offer keys based on Brainpool curves. The upgrades on our web servers are then to follow in January. For you as a customer, there won’t be any adverse effects because the existing methods are going to be maintained as a fall-back option.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-04/mailbox-news-und-updates-sicherheit.jpg?itok=4LMJmUnZ" type="image/jpeg" length="194998"/><guid isPermaLink="false">4439bbd0-eb54-4529-84de-6a5ca32001b0</guid>
    <pubDate>Thu, 15 Dec 2016 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Important: TLS encryption upgrade</dc:title>
    <dc:identifier>4439bbd0-eb54-4529-84de-6a5ca32001b0</dc:identifier>
    </item>
<item>
  <title>mailbox.org activates new features in Online Office</title>
  <link>https://mailbox.org/en/news/mailboxorg-enables-new-features-web-interface/</link>
  <description>&lt;p&gt;Over the past few days, we have updated the mailbox.org web application. As a result, there are now some new features and a number of improvements at the interface level available to our customers.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Tabs for your webmail inbox&lt;/li&gt;&lt;li&gt;Alternative handling of large e-mail attachments (Drive-Mail)&lt;/li&gt;&lt;li&gt;Export and conversion of files into PDF&lt;/li&gt;&lt;li&gt;Improved e-mail usability&lt;/li&gt;&lt;li&gt;New CalDAV and CardDAV app for Android systems&lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;Tabs for your webmail inbox&lt;/h3&gt;&lt;p&gt;It is now possible to group e-mails in the inbox according to different categories and have them displayed together – many will know this feature from services like Gmail. mailbox.org offers up to five tabs for this: &lt;em&gt;General, Social, Purchase, Newsletters, &lt;/em&gt;and&lt;em&gt; Favorites&lt;/em&gt;. The last two can be renamed. Any existing or new filter rules can be used to allocate incoming e-mails to the different categories.&lt;/p&gt;&lt;p&gt;The new webmail tabs can be enabled via &lt;em&gt;Settings -&amp;gt; Email (scroll down) -&amp;gt; Inbox Tabs.&lt;/em&gt;&lt;/p&gt;&lt;p&gt;See the &lt;a href="https://support-en.mailbox.org/knowledge-base/article/tabs-for-your-webmail-inbox" target="_blank" rel="noopener"&gt;FAQ&lt;/a&gt; for more details.&lt;/p&gt;&amp;nbsp;&lt;h3&gt;Alternative handling of large e-mail attachments (Drive-Mail)&lt;/h3&gt;&lt;p&gt;mailbox.org stands out from the crowd by allowing e-mail attachments of up to 100MB size. However, sending large attachments can be problematic if the recipients do not have sufficient storage space in their own inbox. For this reason, we are offering an alternative way of transmitting (even) large(r) files. When composing an e-mail, users can choose the option „Drive-Mail“. Attachments will then be moved to the Drive area and a download link automatically embedded into the current e-mail. Before making use of this option, users should make sure they have sufficient storage space on their Drive to accommodate the attachments. A validity duration for the link can be specified, as well as a password for protecting access. Any e-mails residing in the ‘Sent’ folder that had their large attachments handled this way will be marked up with a „cloud“ symbol.&lt;/p&gt;&lt;p&gt;See the &lt;a href="https://support-en.mailbox.org/knowledge-base/article/drive-mail-sending-large-attachments-via-web-link" target="_blank" rel="noopener"&gt;FAQ&lt;/a&gt; for more details.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;h3&gt;Export and conversion of files into PDF&lt;/h3&gt;&lt;p&gt;Visit the file menu of the text processing or spread sheet software in your mailbox.org Office to find a new option that allows direct PDF export of these kinds of documents.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;h3&gt;Improved mail usability&lt;/h3&gt;&lt;p&gt;When composing an e-mail, a simple click on „TO“, „CC“, or „BCC“ will open a pop-up window that allows selecting recipients from the address book contacts. Further, filter rules can now be created directly in the e-mail overview page.&lt;/p&gt;&amp;nbsp;&lt;h3&gt;New CalDAV and CardDAV app for Android systems&lt;/h3&gt;&lt;p&gt;The „&lt;a href="https://play.google.com/store/apps/details?id=com.openexchange.mobile.syncapp.enterprise&amp;amp;hl=en" target="_blank" rel="noopener"&gt;OX Sync App&lt;/a&gt;“ synchronises appointments, tasks, and contacts between your mailbox.org account and your Android device. This app can be downloaded free of charge from the Google playstore.&lt;/p&gt;&lt;p&gt;See our FAQ for advice on setup and configuration for the &lt;a href="https://support-en.mailbox.org/knowledge-base/article/caldav-and-carddav-app-for-android" target="_blank" rel="noopener"&gt;CalDAV and CardDAV app for Android&lt;/a&gt;.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-04/mailbox-news-und-updates-produktupdate-2.jpg?itok=_u6eySrM" type="image/jpeg" length="284259"/><guid isPermaLink="false">a58e70d6-abac-4c6d-b12e-7890626aab1e</guid>
    <pubDate>Fri, 25 Nov 2016 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>mailbox.org activates new features in Online Office</dc:title>
    <dc:identifier>a58e70d6-abac-4c6d-b12e-7890626aab1e</dc:identifier>
    </item>
<item>
  <title>mailbox.org activates new features in Online Office</title>
  <link>https://mailbox.org/en/news/mailboxorg-enables-new-features-web-interface/</link>
  <description>&lt;p&gt;Over the past few days, we have updated the mailbox.org web application. As a result, there are now some new features and a number of improvements at the interface level available to our customers.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Tabs for your webmail inbox&lt;/li&gt;&lt;li&gt;Alternative handling of large e-mail attachments (Drive-Mail)&lt;/li&gt;&lt;li&gt;Export and conversion of files into PDF&lt;/li&gt;&lt;li&gt;Improved e-mail usability&lt;/li&gt;&lt;li&gt;New CalDAV and CardDAV app for Android systems&lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;Tabs for your webmail inbox&lt;/h3&gt;&lt;p&gt;It is now possible to group e-mails in the inbox according to different categories and have them displayed together – many will know this feature from services like Gmail. mailbox.org offers up to five tabs for this: &lt;em&gt;General, Social, Purchase, Newsletters, &lt;/em&gt;and&lt;em&gt; Favorites&lt;/em&gt;. The last two can be renamed. Any existing or new filter rules can be used to allocate incoming e-mails to the different categories.&lt;/p&gt;&lt;p&gt;The new webmail tabs can be enabled via &lt;em&gt;Settings -&amp;gt; Email (scroll down) -&amp;gt; Inbox Tabs.&lt;/em&gt;&lt;/p&gt;&lt;p&gt;See the &lt;a href="https://support-en.mailbox.org/knowledge-base/article/tabs-for-your-webmail-inbox" target="_blank" rel="noopener"&gt;FAQ&lt;/a&gt; for more details.&lt;/p&gt;&amp;nbsp;&lt;h3&gt;Alternative handling of large e-mail attachments (Drive-Mail)&lt;/h3&gt;&lt;p&gt;mailbox.org stands out from the crowd by allowing e-mail attachments of up to 100MB size. However, sending large attachments can be problematic if the recipients do not have sufficient storage space in their own inbox. For this reason, we are offering an alternative way of transmitting (even) large(r) files. When composing an e-mail, users can choose the option „Drive-Mail“. Attachments will then be moved to the Drive area and a download link automatically embedded into the current e-mail. Before making use of this option, users should make sure they have sufficient storage space on their Drive to accommodate the attachments. A validity duration for the link can be specified, as well as a password for protecting access. Any e-mails residing in the ‘Sent’ folder that had their large attachments handled this way will be marked up with a „cloud“ symbol.&lt;/p&gt;&lt;p&gt;See the &lt;a href="https://support-en.mailbox.org/knowledge-base/article/drive-mail-sending-large-attachments-via-web-link" target="_blank" rel="noopener"&gt;FAQ&lt;/a&gt; for more details.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;h3&gt;Export and conversion of files into PDF&lt;/h3&gt;&lt;p&gt;Visit the file menu of the text processing or spread sheet software in your mailbox.org Office to find a new option that allows direct PDF export of these kinds of documents.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;h3&gt;Improved mail usability&lt;/h3&gt;&lt;p&gt;When composing an e-mail, a simple click on „TO“, „CC“, or „BCC“ will open a pop-up window that allows selecting recipients from the address book contacts. Further, filter rules can now be created directly in the e-mail overview page.&lt;/p&gt;&amp;nbsp;&lt;h3&gt;New CalDAV and CardDAV app for Android systems&lt;/h3&gt;&lt;p&gt;The „&lt;a href="https://play.google.com/store/apps/details?id=com.openexchange.mobile.syncapp.enterprise&amp;amp;hl=en" target="_blank" rel="noopener"&gt;OX Sync App&lt;/a&gt;“ synchronises appointments, tasks, and contacts between your mailbox.org account and your Android device. This app can be downloaded free of charge from the Google playstore.&lt;/p&gt;&lt;p&gt;See our FAQ for advice on setup and configuration for the &lt;a href="https://support-en.mailbox.org/knowledge-base/article/caldav-and-carddav-app-for-android" target="_blank" rel="noopener"&gt;CalDAV and CardDAV app for Android&lt;/a&gt;.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-04/mailbox-news-und-updates-produktupdate-2.jpg?itok=_u6eySrM" type="image/jpeg" length="284259"/><guid isPermaLink="false">a58e70d6-abac-4c6d-b12e-7890626aab1e</guid>
    <pubDate>Fri, 25 Nov 2016 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>mailbox.org activates new features in Online Office</dc:title>
    <dc:identifier>a58e70d6-abac-4c6d-b12e-7890626aab1e</dc:identifier>
    </item>
<item>
  <title>mailbox.org once again wins Stiftung Warentest test</title>
  <link>https://mailbox.org/en/news/secure-e-mail-service-mailbox-wins-product-test/</link>
  <description>&lt;p&gt;mailbox.org came out on top in a comparison of e-mail services published in Germany’s leading consumer advice magazine: Stiftung Warentest. Mailbox.org ranked first in the category ‘privacy and data protection’ and received high grades for usability and functionality.&lt;/p&gt;&lt;p&gt;“Stiftung Warentest” is a publicly funded, not-for-profit consumer advice organisation in Germany that conducts independent scientific tests of products of everyday life, thus supporting consumers by providing impartial and objective information. Stiftung Warentest is considered a trusted service with a positive image and valued for the guidance provided on purchasing decisions by millions of its online and offline magazine readers.&lt;/p&gt;&lt;p&gt;In its most recent publication (‘Test 10/2016’), Stiftung Warentest evaluated several national and international e-mail providers, considering aspects such as functionality and usability, and especially data security and privacy features.&lt;/p&gt;&lt;p&gt;The result of the test was no surprise to us: mailbox.org achieved top grades in all categories evaluated and dominated big players like Gmail, Outlook.com and Yahoo Mail. In particular, the easy-to-use encryption options for users and the general approach taken to data security and minimization were highlighted. In times of digital surveillance and shoulder-surfing, it should be highly appreciated that Stiftung Warentest has emphasized the importance of these issues in e-mail communication.&lt;/p&gt;&lt;p&gt;I would like to thank the entire team at mailbox.org and all of our external security experts who continually support us in setting new standards when it comes to the effective use of encryption mechanisms. I also want to thank all our customers for their trust and continued support.&lt;/p&gt;&lt;p&gt;Yours Sincerely,&lt;br&gt;Peer Heinlein&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-celebration.jpeg?itok=wIZsodf0" type="image/jpeg" length="326204"/><guid isPermaLink="false">72884725-5d9f-4bc4-9f8b-708caee5b7d1</guid>
    <pubDate>Wed, 28 Sep 2016 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>mailbox.org once again wins Stiftung Warentest test</dc:title>
    <dc:identifier>72884725-5d9f-4bc4-9f8b-708caee5b7d1</dc:identifier>
    </item>
<item>
  <title>mailbox.org once again wins Stiftung Warentest test</title>
  <link>https://mailbox.org/en/news/secure-e-mail-service-mailbox-wins-product-test/</link>
  <description>&lt;p&gt;mailbox.org came out on top in a comparison of e-mail services published in Germany’s leading consumer advice magazine: Stiftung Warentest. Mailbox.org ranked first in the category ‘privacy and data protection’ and received high grades for usability and functionality.&lt;/p&gt;&lt;p&gt;“Stiftung Warentest” is a publicly funded, not-for-profit consumer advice organisation in Germany that conducts independent scientific tests of products of everyday life, thus supporting consumers by providing impartial and objective information. Stiftung Warentest is considered a trusted service with a positive image and valued for the guidance provided on purchasing decisions by millions of its online and offline magazine readers.&lt;/p&gt;&lt;p&gt;In its most recent publication (‘Test 10/2016’), Stiftung Warentest evaluated several national and international e-mail providers, considering aspects such as functionality and usability, and especially data security and privacy features.&lt;/p&gt;&lt;p&gt;The result of the test was no surprise to us: mailbox.org achieved top grades in all categories evaluated and dominated big players like Gmail, Outlook.com and Yahoo Mail. In particular, the easy-to-use encryption options for users and the general approach taken to data security and minimization were highlighted. In times of digital surveillance and shoulder-surfing, it should be highly appreciated that Stiftung Warentest has emphasized the importance of these issues in e-mail communication.&lt;/p&gt;&lt;p&gt;I would like to thank the entire team at mailbox.org and all of our external security experts who continually support us in setting new standards when it comes to the effective use of encryption mechanisms. I also want to thank all our customers for their trust and continued support.&lt;/p&gt;&lt;p&gt;Yours Sincerely,&lt;br&gt;Peer Heinlein&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-celebration.jpeg?itok=wIZsodf0" type="image/jpeg" length="326204"/><guid isPermaLink="false">72884725-5d9f-4bc4-9f8b-708caee5b7d1</guid>
    <pubDate>Wed, 28 Sep 2016 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>mailbox.org once again wins Stiftung Warentest test</dc:title>
    <dc:identifier>72884725-5d9f-4bc4-9f8b-708caee5b7d1</dc:identifier>
    </item>
<item>
  <title>Updates: OTP 2-factor authentication, PGP keyserver, Mailvelope</title>
  <link>https://mailbox.org/en/news/new-mailbox-features-otp-two-factor-auth-pgp-key-server-mailvelope-support-e-mail-backup/</link>
  <description>&lt;p&gt;“April showers bring May flowers!” In fact, a lot has happened in May as we launched a whole range of new features and ways to use mailbox.org. Some of the related developments have been going on for well over a year and we are very happy to now be able to present the fruits of our labour to our users. So, what is new? There’s a whole list of things:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;POP3 mail collection service with PGP-encrypted inbox&lt;/li&gt;&lt;li&gt;User access to e-mail backups&lt;/li&gt;&lt;li&gt;Two-factor authentication and One-Time Password methods like Google Authenticator&lt;/li&gt;&lt;li&gt;PGP key server (HKP)&lt;/li&gt;&lt;li&gt;Auto-configuration wizard&lt;/li&gt;&lt;li&gt;mailbox.org Guard now with comprehensive Mailvelope support&lt;/li&gt;&lt;li&gt;30-day disposable e-mail addresses&lt;/li&gt;&lt;li&gt;Coming very shortly:&lt;ul&gt;&lt;li&gt;Dedicated Android app for calendar and contacts&lt;/li&gt;&lt;li&gt;Mailtrace: Log file search for our users&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;and finally…&lt;ul&gt;&lt;li&gt;…a new virtualization cluster&lt;/li&gt;&lt;li&gt;…BGP routing and BCIX peering&lt;/li&gt;&lt;li&gt;…new staff&lt;/li&gt;&lt;li&gt;…user support forum launch&lt;/li&gt;&lt;li&gt;…better resolution of contact images&lt;/li&gt;&lt;li&gt;…names of special “Drafts/Trash/Sent” folders adjusted&lt;/li&gt;&lt;li&gt;…Envelope-To addresses available as a filter element&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;See below for details:&lt;/p&gt;&lt;h2&gt;POP3 mail collection service with PGP-encrypted Inbox&lt;/h2&gt;&lt;p&gt;Our new POP3 mail collection service (to be found on the settings page) can perform scheduled imports of e-mail inboxes that are hosted with other providers. These e-mails can be run through our mail filter and so distributed to a separate IMAP folder on mailbox.org. Best of all: If you are using the fully-encrypted inbox, all e-mails collected in this way will get PGP-encrypted as well! There is another difference to the existing POP3 service that is accessible through the mail menu: The new service can work entirely in the background and will import e-mails automatically every 30 minutes, without prompting the user to log in every time. It may therefore present an interesting option for those customers who use a dedicated mail client to access mailbox.org.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;h2&gt;User access to e-mail backups&lt;/h2&gt;&lt;p&gt;It can happen to everyone and at any time: Just one wrong keypress and an important e-mail message or even an entire folder is gone. E-mail backup is not included in our tariffs, however, we do perform regular backups for technical purposes that cover the e-mail data of the past few days. We have now created a self-service interface (to be found in the settings pages) which gives users access to an e-mail recovery function. It is now possible to re-import the inbox and other IMAP folders from a backup and so, replace any (recently) deleted e-mails without the need to contact our support team. Please note that we needed to make adjustments to §11 (2) of our &lt;a href="https://mailbox.org/en/general-terms-and-conditions/" target="_blank" rel="noopener"&gt;General Terms and Conditions&lt;/a&gt; to accommodate this new service.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;h2&gt;Two-factor authentication and One-Time Password methods like Google Authenticator&lt;/h2&gt;&lt;p&gt;After more than a year of development effort, mailbox.org now benefits from a completely overhauled authentication module. In addition to the usual password protection, the supported mechanisms include our dedicated mailbox.org YubiKeys and multiple One-time password token generators, such as Google Authenticator or the OATH service that is common on iPhones. In principle, all token generators that work based on HOTP, TOTP, or mOTP can be used. Due to popular demand, we also enabled YubiCloud authentication for those who did not obtain their YubiKeys directly from mailbox.org but from external vendors.&lt;/p&gt;&lt;p&gt;See the FAQ for more details:&lt;br&gt;&lt;a href="https://support-en.mailbox.org/knowledge-base/article/is-there-a-two-factor-authentication" target="_blank" rel="noopener"&gt;https://support-en.mailbox.org/knowledge-base/article/is-there-a-two-factor-authentication&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;h2&gt;PGP key server (HKP)&lt;/h2&gt;&lt;p&gt;Our mailbox.org Guard has further evolved into a central tool for PGP management. The public keys of our users are now being distributed publicly through a dedicated PGP key server (hkps://pgp.mailbox.org. Special DNS records make sure that PGP-relevant programs of other users will find this key server automatically to retrieve verified keys of our users.&lt;/p&gt;&lt;p&gt;Please consult the FAQ for more details:&lt;br&gt;&lt;a href="https://support-en.mailbox.org/knowledge-base/article/the-mailbox-org-hkps-key-server" target="_blank" rel="noopener"&gt;https://support-en.mailbox.org/knowledge-base/article/the-mailbox-org-hkps-key-server&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;h2&gt;Auto-configuration wizard&lt;/h2&gt;&lt;p&gt;Users will find a new tile on their office dashboard or, alternatively, a new settings menu entry called „Connect Your Device“ which links to our improved auto-config wizard: Simply select your device or application from a list and the wizard will display the correct configuration for connecting it with mailbox.org. If you are an iPhone user, a configuration text message can be sent directly to your phone, and then it is a simple matter of confirming the settings to make the connection. iPad and Mac users can download a configuration file to import to their devices. Users of Microsoft Outlook will also benefit from an improved auto-configuration. For connecting most applications and devices, it will be sufficient from now on to simply state a username and password to retrieve the required settings automatically.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;h2&gt;mailbox.org Guard now with comprehensive Mailvelope support&lt;/h2&gt;&lt;p&gt;Previously, the mailbox.org Guard would manage user keys entirely on the server side in order to allow comprehensive use of PGP, even on the go. As an alternative, we have now added to Guard full support for Mailvelope, a browser plugin that can be installed by the users that will store encryption keys directly on their local machine. We support the plugin as it appears to be popular with many users, and common with other providers, where Mailvelope presents the foundation of their PGP services. From a security perspective, we are still somewhat critical of the approach underlying Mailvelope, yet at the same time, we want to give our users the freedom to choose the mechanism they prefer. As a result, mailbox.org does now offer the same Mailvelope support as other providers do. Any mailbox.org accounts which have the Guard extension enabled for the first time will now be able to select either server-side PGP encryption, as usual, or configure Guard for use with the Mailvelope-Plugin. Note that once Guard is fully configured and operational, this setting cannot be reversed. We urge our users to please read the FAQs on this subject before setting up Guard.&lt;/p&gt;&lt;p&gt;See the FAQ for more details:&lt;br&gt;&lt;a href="https://support-en.mailbox.org/knowledge-base/article/how-to-set-up-mailvelope-with-guard" target="_blank" rel="noopener"&gt;https://support-en.mailbox.org/knowledge-base/article/how-to-set-up-mailvelope-with-guard&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;h2&gt;30-days disposable e-mail addresses&lt;/h2&gt;&lt;p&gt;Many web services and forums require registration with an e-mail address and sometimes, we might prefer not to hand over the address that we use regularly. One alternative is to use e-mail aliases, yet the number of aliases one can create per account is limited, and their use is potentially unsafe, as other people might re-register an alias sometime after it was deleted. For this reason, users may now create disposable e-mail addresses in the mailbox.org settings. These are valid for 30 days, after which they expire and are deleted automatically. Please note: You can only receive but not send any e-mails using disposable addresses!&lt;/p&gt;&lt;h2&gt;Coming very shortly&lt;/h2&gt;&lt;h3&gt;A dedicated Android app for calendar and contacts&lt;/h3&gt;&lt;p&gt;Our new app is currently going through the Google Playstore publishing process and activation is imminent. Having our own calendar and contacts app will allow seamless integration with the mailbox.org-Office and makes mobile configuration much easier. The basis for our app are the calendar and contacts apps by Marten Gajda, which we whole-heartedly recommend, and which have been adapted to create a dedicated app for mailbox.org. Our auto-configuration wizard will also link to any new apps as soon as they become available.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;h3&gt;Mailtrace: Log file search for our users&lt;/h3&gt;&lt;p&gt;In cases where there is uncertainty about the status of an e-mail, the only way to find out is usually to look through the server logs. However, these are not normally accessible to ordinary users. Our new „Mailtrace“-service offers a search facility to all mailbox.org users where they can inspect their individual e-mail activity: The results indicate the transmission status of any outgoing and incoming mail in real time, using an easy-to-recognize traffic-light metaphor. Those users who are interested in technical details can get such more in-depth information as well. Presently, we cannot announce a release date yet, but any users interested in becoming beta testers for this feature should get in touch with Peer Heinlein (p.heinlein@mailbox.org).&lt;/p&gt;&lt;h2&gt;and finally…&lt;/h2&gt;&lt;p&gt;A quick peek behind the scenes – for anyone who is interested in what’s going on at mailbox.org – the business:&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;h3&gt;…a new virtualization cluster&lt;/h3&gt;&lt;p&gt;It took 18 months of preparation but at the beginning of May, we could finally take into operation an entirely new server cluster at our data center. For this cluster, we have chosen to adopt another virtualization technology that will help implement our long-term strategy of establishing hardware- as well as software-redundant solutions that are more robust and reliable when it comes to technical faults and security challenges. So, for instance, the server clusters that comprise several physical machines will be set up in parallel alternative configurations, using two different virtualization technologies at the same time.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;h3&gt;…BGP-Routing und BCIX-Peering&lt;/h3&gt;&lt;p&gt;Another project that was finished in the first quarter of 2016 (after two years of work) concerned the Border Gateway Protocol (BGP) and the Berlin Commercial Internet Exchange (BCIX): Traffic between mailbox.org and other German and international providers is now routed directly through the Berlin exchange BCIX, which means increased speed and shorter pathways for the routing of data packets. To achieve this, all mailbox.org data centers have been connected to the BCIX node and &lt;a href="http://www.bcix.de/bcix/members/" target="_blank" rel="noopener"&gt;BGP peering was subsequently arranged with all major internet providers&lt;/a&gt;. The improved infrastructure makes mailbox.org a lot more independent when it comes to general internet service disruptions or cases of traffic congestion at other routing-relevant locations, as they may occur due to hardware failure or DDoS attacks. mailbox.org is now connected to the Internet using four parallel and completely redundant firewall- and router systems, which are situated at different geographic locations.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;h3&gt;…new staff&lt;/h3&gt;&lt;p&gt;We have hired additional developers, support workers, and system administrators in the past six months who joined teams at mailbox.org and Heinlein Support. Our entire team is currently 29 heads strong and even more people will start in their new roles from 1st June. Sebastian „Ben“ Knopp and the helpdesk team are working incredibly hard to keep our SLA below 24 hours and the numerous features described above demonstrate the magnificent feats our developers and administrators were able to pull off in the previous months. This growth also meant that physical space is getting scarce at our premises and so, Heinlein Support will be taking over another 200 sqm of office space in our building from 1st June, taking the total space allocated to company offices to 700 sqm.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;h3&gt;…User support forum&lt;/h3&gt;&lt;p&gt;We launched the new &lt;a href="https://support-en.mailbox.org/" target="_blank" rel="noopener"&gt;support forum&lt;/a&gt; early this year which has shown some amazing growth. Users actively engage to help other users, answer their questions, exchange experiences, or give advice on configuration settings for special software. Our helpdesk team uses the forum to interact with our user base and provide voluntary support (Please keep in mind that we keep providing individual support for our services via e-mail: support@mailbox.org). Nevertheless, the team is actively following the issues discussed in the forum and take away ideas that come directly from our loyal customers about possible improvements to mailbox.org – some of which have already been implemented (see below)! We really appreciate the interaction with our users and would like to thank everyone who participates in user support forum activities.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;h3&gt;…better resolution of contact images&lt;/h3&gt;&lt;p&gt;Triggered by a discussion between users in the forum, we increased the resolution of contact images from 250×250 to 720×720 pixels. In light of the ever-growing screen size and resolution of modern mobile devices, the previous image resolution was not timely anymore. Although newly uploaded images will be saved automatically in the new resolution of 720×720 pixels, we obviously cannot increase the quality of existing contact images. Please update these existing images with higher quality versions, if desired, by simply uploading new images.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;h3&gt;…names of special “Drafts/Trash/Sent” folders adjusted&lt;/h3&gt;&lt;p&gt;Changes in recent versions of Microsoft Outlook have caused confusion with some of the standard e-mail folders used by Outlook and mailbox.org, in particular when non-English names were used for folders like „Drafts“, or „Sent“, etc. In order for e-mail clients to recognize these special folders correctly, new mailbox.org accounts will from now on adopt the English default names „Drafts“, „Trash“, „Sent“, and „Archive“, even though these might still be displayed properly in the web interface in the language selected by the user. Any current mailbox.org accounts will not be changed automatically in order to preserve their existing configuration. However, we are happy to apply the above changes to the name schema on request – if you would like us to do this, please send an e-mail to &lt;a href="https://mailbox.org/mailto:support@mailbox.org" target="_blank" rel="noopener"&gt;support@mailbox.org&lt;/a&gt; quoting “folder change“ in the subject line.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;h3&gt;… „Envelope-To“ addresses available as a filter element&lt;/h3&gt;&lt;p&gt;A feature long-desired by our users has finally arrived with the May update: From now on, e-mail addresses that use external domain names will be considered by the Sieve mail filter and there will be a filter element called „Envelope-To“. Especially those customers who use their own domain name and corresponding alias-addresses will be delighted, because the new feature allows the automatic filtering and sorting of e-mails sent to particular addresses into separate subfolders.&lt;br&gt;Please note: The filter element „Any recipient“ will make the search engine look at the header entries „To:“ and „CC:“ – if the e-mail was forwarded or sent via BCC, then there won’t be any information about the real recipient and the entry will point to the previous recipient address (before the message was forwarded). The filter element „Envelope-To“, however, will check the real recipient to which the e-mail is currently addressed.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-04/mailbox-news-und-updates-sicherheit.jpg?itok=4LMJmUnZ" type="image/jpeg" length="194998"/><guid isPermaLink="false">1acf2e14-cbea-4dea-bed4-dff44dc4ce6b</guid>
    <pubDate>Mon, 30 May 2016 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Updates: OTP 2-factor authentication, PGP keyserver, Mailvelope</dc:title>
    <dc:identifier>1acf2e14-cbea-4dea-bed4-dff44dc4ce6b</dc:identifier>
    </item>
<item>
  <title>Updates: OTP 2-factor authentication, PGP keyserver, Mailvelope</title>
  <link>https://mailbox.org/en/news/new-mailbox-features-otp-two-factor-auth-pgp-key-server-mailvelope-support-e-mail-backup/</link>
  <description>&lt;p&gt;“April showers bring May flowers!” In fact, a lot has happened in May as we launched a whole range of new features and ways to use mailbox.org. Some of the related developments have been going on for well over a year and we are very happy to now be able to present the fruits of our labour to our users. So, what is new? There’s a whole list of things:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;POP3 mail collection service with PGP-encrypted inbox&lt;/li&gt;&lt;li&gt;User access to e-mail backups&lt;/li&gt;&lt;li&gt;Two-factor authentication and One-Time Password methods like Google Authenticator&lt;/li&gt;&lt;li&gt;PGP key server (HKP)&lt;/li&gt;&lt;li&gt;Auto-configuration wizard&lt;/li&gt;&lt;li&gt;mailbox.org Guard now with comprehensive Mailvelope support&lt;/li&gt;&lt;li&gt;30-day disposable e-mail addresses&lt;/li&gt;&lt;li&gt;Coming very shortly:&lt;ul&gt;&lt;li&gt;Dedicated Android app for calendar and contacts&lt;/li&gt;&lt;li&gt;Mailtrace: Log file search for our users&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;and finally…&lt;ul&gt;&lt;li&gt;…a new virtualization cluster&lt;/li&gt;&lt;li&gt;…BGP routing and BCIX peering&lt;/li&gt;&lt;li&gt;…new staff&lt;/li&gt;&lt;li&gt;…user support forum launch&lt;/li&gt;&lt;li&gt;…better resolution of contact images&lt;/li&gt;&lt;li&gt;…names of special “Drafts/Trash/Sent” folders adjusted&lt;/li&gt;&lt;li&gt;…Envelope-To addresses available as a filter element&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;See below for details:&lt;/p&gt;&lt;h2&gt;POP3 mail collection service with PGP-encrypted Inbox&lt;/h2&gt;&lt;p&gt;Our new POP3 mail collection service (to be found on the settings page) can perform scheduled imports of e-mail inboxes that are hosted with other providers. These e-mails can be run through our mail filter and so distributed to a separate IMAP folder on mailbox.org. Best of all: If you are using the fully-encrypted inbox, all e-mails collected in this way will get PGP-encrypted as well! There is another difference to the existing POP3 service that is accessible through the mail menu: The new service can work entirely in the background and will import e-mails automatically every 30 minutes, without prompting the user to log in every time. It may therefore present an interesting option for those customers who use a dedicated mail client to access mailbox.org.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;h2&gt;User access to e-mail backups&lt;/h2&gt;&lt;p&gt;It can happen to everyone and at any time: Just one wrong keypress and an important e-mail message or even an entire folder is gone. E-mail backup is not included in our tariffs, however, we do perform regular backups for technical purposes that cover the e-mail data of the past few days. We have now created a self-service interface (to be found in the settings pages) which gives users access to an e-mail recovery function. It is now possible to re-import the inbox and other IMAP folders from a backup and so, replace any (recently) deleted e-mails without the need to contact our support team. Please note that we needed to make adjustments to §11 (2) of our &lt;a href="https://mailbox.org/en/general-terms-and-conditions/" target="_blank" rel="noopener"&gt;General Terms and Conditions&lt;/a&gt; to accommodate this new service.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;h2&gt;Two-factor authentication and One-Time Password methods like Google Authenticator&lt;/h2&gt;&lt;p&gt;After more than a year of development effort, mailbox.org now benefits from a completely overhauled authentication module. In addition to the usual password protection, the supported mechanisms include our dedicated mailbox.org YubiKeys and multiple One-time password token generators, such as Google Authenticator or the OATH service that is common on iPhones. In principle, all token generators that work based on HOTP, TOTP, or mOTP can be used. Due to popular demand, we also enabled YubiCloud authentication for those who did not obtain their YubiKeys directly from mailbox.org but from external vendors.&lt;/p&gt;&lt;p&gt;See the FAQ for more details:&lt;br&gt;&lt;a href="https://support-en.mailbox.org/knowledge-base/article/is-there-a-two-factor-authentication" target="_blank" rel="noopener"&gt;https://support-en.mailbox.org/knowledge-base/article/is-there-a-two-factor-authentication&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;h2&gt;PGP key server (HKP)&lt;/h2&gt;&lt;p&gt;Our mailbox.org Guard has further evolved into a central tool for PGP management. The public keys of our users are now being distributed publicly through a dedicated PGP key server (hkps://pgp.mailbox.org. Special DNS records make sure that PGP-relevant programs of other users will find this key server automatically to retrieve verified keys of our users.&lt;/p&gt;&lt;p&gt;Please consult the FAQ for more details:&lt;br&gt;&lt;a href="https://support-en.mailbox.org/knowledge-base/article/the-mailbox-org-hkps-key-server" target="_blank" rel="noopener"&gt;https://support-en.mailbox.org/knowledge-base/article/the-mailbox-org-hkps-key-server&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;h2&gt;Auto-configuration wizard&lt;/h2&gt;&lt;p&gt;Users will find a new tile on their office dashboard or, alternatively, a new settings menu entry called „Connect Your Device“ which links to our improved auto-config wizard: Simply select your device or application from a list and the wizard will display the correct configuration for connecting it with mailbox.org. If you are an iPhone user, a configuration text message can be sent directly to your phone, and then it is a simple matter of confirming the settings to make the connection. iPad and Mac users can download a configuration file to import to their devices. Users of Microsoft Outlook will also benefit from an improved auto-configuration. For connecting most applications and devices, it will be sufficient from now on to simply state a username and password to retrieve the required settings automatically.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;h2&gt;mailbox.org Guard now with comprehensive Mailvelope support&lt;/h2&gt;&lt;p&gt;Previously, the mailbox.org Guard would manage user keys entirely on the server side in order to allow comprehensive use of PGP, even on the go. As an alternative, we have now added to Guard full support for Mailvelope, a browser plugin that can be installed by the users that will store encryption keys directly on their local machine. We support the plugin as it appears to be popular with many users, and common with other providers, where Mailvelope presents the foundation of their PGP services. From a security perspective, we are still somewhat critical of the approach underlying Mailvelope, yet at the same time, we want to give our users the freedom to choose the mechanism they prefer. As a result, mailbox.org does now offer the same Mailvelope support as other providers do. Any mailbox.org accounts which have the Guard extension enabled for the first time will now be able to select either server-side PGP encryption, as usual, or configure Guard for use with the Mailvelope-Plugin. Note that once Guard is fully configured and operational, this setting cannot be reversed. We urge our users to please read the FAQs on this subject before setting up Guard.&lt;/p&gt;&lt;p&gt;See the FAQ for more details:&lt;br&gt;&lt;a href="https://support-en.mailbox.org/knowledge-base/article/how-to-set-up-mailvelope-with-guard" target="_blank" rel="noopener"&gt;https://support-en.mailbox.org/knowledge-base/article/how-to-set-up-mailvelope-with-guard&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;h2&gt;30-days disposable e-mail addresses&lt;/h2&gt;&lt;p&gt;Many web services and forums require registration with an e-mail address and sometimes, we might prefer not to hand over the address that we use regularly. One alternative is to use e-mail aliases, yet the number of aliases one can create per account is limited, and their use is potentially unsafe, as other people might re-register an alias sometime after it was deleted. For this reason, users may now create disposable e-mail addresses in the mailbox.org settings. These are valid for 30 days, after which they expire and are deleted automatically. Please note: You can only receive but not send any e-mails using disposable addresses!&lt;/p&gt;&lt;h2&gt;Coming very shortly&lt;/h2&gt;&lt;h3&gt;A dedicated Android app for calendar and contacts&lt;/h3&gt;&lt;p&gt;Our new app is currently going through the Google Playstore publishing process and activation is imminent. Having our own calendar and contacts app will allow seamless integration with the mailbox.org-Office and makes mobile configuration much easier. The basis for our app are the calendar and contacts apps by Marten Gajda, which we whole-heartedly recommend, and which have been adapted to create a dedicated app for mailbox.org. Our auto-configuration wizard will also link to any new apps as soon as they become available.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;h3&gt;Mailtrace: Log file search for our users&lt;/h3&gt;&lt;p&gt;In cases where there is uncertainty about the status of an e-mail, the only way to find out is usually to look through the server logs. However, these are not normally accessible to ordinary users. Our new „Mailtrace“-service offers a search facility to all mailbox.org users where they can inspect their individual e-mail activity: The results indicate the transmission status of any outgoing and incoming mail in real time, using an easy-to-recognize traffic-light metaphor. Those users who are interested in technical details can get such more in-depth information as well. Presently, we cannot announce a release date yet, but any users interested in becoming beta testers for this feature should get in touch with Peer Heinlein (p.heinlein@mailbox.org).&lt;/p&gt;&lt;h2&gt;and finally…&lt;/h2&gt;&lt;p&gt;A quick peek behind the scenes – for anyone who is interested in what’s going on at mailbox.org – the business:&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;h3&gt;…a new virtualization cluster&lt;/h3&gt;&lt;p&gt;It took 18 months of preparation but at the beginning of May, we could finally take into operation an entirely new server cluster at our data center. For this cluster, we have chosen to adopt another virtualization technology that will help implement our long-term strategy of establishing hardware- as well as software-redundant solutions that are more robust and reliable when it comes to technical faults and security challenges. So, for instance, the server clusters that comprise several physical machines will be set up in parallel alternative configurations, using two different virtualization technologies at the same time.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;h3&gt;…BGP-Routing und BCIX-Peering&lt;/h3&gt;&lt;p&gt;Another project that was finished in the first quarter of 2016 (after two years of work) concerned the Border Gateway Protocol (BGP) and the Berlin Commercial Internet Exchange (BCIX): Traffic between mailbox.org and other German and international providers is now routed directly through the Berlin exchange BCIX, which means increased speed and shorter pathways for the routing of data packets. To achieve this, all mailbox.org data centers have been connected to the BCIX node and &lt;a href="http://www.bcix.de/bcix/members/" target="_blank" rel="noopener"&gt;BGP peering was subsequently arranged with all major internet providers&lt;/a&gt;. The improved infrastructure makes mailbox.org a lot more independent when it comes to general internet service disruptions or cases of traffic congestion at other routing-relevant locations, as they may occur due to hardware failure or DDoS attacks. mailbox.org is now connected to the Internet using four parallel and completely redundant firewall- and router systems, which are situated at different geographic locations.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;h3&gt;…new staff&lt;/h3&gt;&lt;p&gt;We have hired additional developers, support workers, and system administrators in the past six months who joined teams at mailbox.org and Heinlein Support. Our entire team is currently 29 heads strong and even more people will start in their new roles from 1st June. Sebastian „Ben“ Knopp and the helpdesk team are working incredibly hard to keep our SLA below 24 hours and the numerous features described above demonstrate the magnificent feats our developers and administrators were able to pull off in the previous months. This growth also meant that physical space is getting scarce at our premises and so, Heinlein Support will be taking over another 200 sqm of office space in our building from 1st June, taking the total space allocated to company offices to 700 sqm.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;h3&gt;…User support forum&lt;/h3&gt;&lt;p&gt;We launched the new &lt;a href="https://support-en.mailbox.org/" target="_blank" rel="noopener"&gt;support forum&lt;/a&gt; early this year which has shown some amazing growth. Users actively engage to help other users, answer their questions, exchange experiences, or give advice on configuration settings for special software. Our helpdesk team uses the forum to interact with our user base and provide voluntary support (Please keep in mind that we keep providing individual support for our services via e-mail: support@mailbox.org). Nevertheless, the team is actively following the issues discussed in the forum and take away ideas that come directly from our loyal customers about possible improvements to mailbox.org – some of which have already been implemented (see below)! We really appreciate the interaction with our users and would like to thank everyone who participates in user support forum activities.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;h3&gt;…better resolution of contact images&lt;/h3&gt;&lt;p&gt;Triggered by a discussion between users in the forum, we increased the resolution of contact images from 250×250 to 720×720 pixels. In light of the ever-growing screen size and resolution of modern mobile devices, the previous image resolution was not timely anymore. Although newly uploaded images will be saved automatically in the new resolution of 720×720 pixels, we obviously cannot increase the quality of existing contact images. Please update these existing images with higher quality versions, if desired, by simply uploading new images.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;h3&gt;…names of special “Drafts/Trash/Sent” folders adjusted&lt;/h3&gt;&lt;p&gt;Changes in recent versions of Microsoft Outlook have caused confusion with some of the standard e-mail folders used by Outlook and mailbox.org, in particular when non-English names were used for folders like „Drafts“, or „Sent“, etc. In order for e-mail clients to recognize these special folders correctly, new mailbox.org accounts will from now on adopt the English default names „Drafts“, „Trash“, „Sent“, and „Archive“, even though these might still be displayed properly in the web interface in the language selected by the user. Any current mailbox.org accounts will not be changed automatically in order to preserve their existing configuration. However, we are happy to apply the above changes to the name schema on request – if you would like us to do this, please send an e-mail to &lt;a href="https://mailbox.org/mailto:support@mailbox.org" target="_blank" rel="noopener"&gt;support@mailbox.org&lt;/a&gt; quoting “folder change“ in the subject line.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;h3&gt;… „Envelope-To“ addresses available as a filter element&lt;/h3&gt;&lt;p&gt;A feature long-desired by our users has finally arrived with the May update: From now on, e-mail addresses that use external domain names will be considered by the Sieve mail filter and there will be a filter element called „Envelope-To“. Especially those customers who use their own domain name and corresponding alias-addresses will be delighted, because the new feature allows the automatic filtering and sorting of e-mails sent to particular addresses into separate subfolders.&lt;br&gt;Please note: The filter element „Any recipient“ will make the search engine look at the header entries „To:“ and „CC:“ – if the e-mail was forwarded or sent via BCC, then there won’t be any information about the real recipient and the entry will point to the previous recipient address (before the message was forwarded). The filter element „Envelope-To“, however, will check the real recipient to which the e-mail is currently addressed.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-04/mailbox-news-und-updates-sicherheit.jpg?itok=4LMJmUnZ" type="image/jpeg" length="194998"/><guid isPermaLink="false">1acf2e14-cbea-4dea-bed4-dff44dc4ce6b</guid>
    <pubDate>Mon, 30 May 2016 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Updates: OTP 2-factor authentication, PGP keyserver, Mailvelope</dc:title>
    <dc:identifier>1acf2e14-cbea-4dea-bed4-dff44dc4ce6b</dc:identifier>
    </item>
<item>
  <title>Web interface update</title>
  <link>https://mailbox.org/en/news/update-web-interface-november-2015/</link>
  <description>&lt;p&gt;&lt;em&gt;Update 26/11/2015 at 8 am (CET): Our colleagues worked hard. The update is done. – But there are still some things to fix today.&lt;/em&gt;&lt;br&gt;Dear mailbox.org customers,&lt;/p&gt;&lt;p&gt;We are writing to you today to let you know that there we are going to perform an update of our web interface later at 9 pm (Central European Time) tonight. There is a possibility that this might lead to temporary delays in the processing of logins to the cloud office, and we would like to apologise for any inconvenience this might cause. We will do our utmost to keep any interference between the update process and user operations as minimal as possible.&lt;/p&gt;&lt;p&gt;On the positive side, the new updated version of the web interface will bring a number of exciting changes and improvements.&lt;/p&gt;&lt;h2&gt;What’s new?&lt;/h2&gt;&lt;h4&gt;Sharing of files, calendars, tasks, and contacts&lt;/h4&gt;&lt;p&gt;The updated version introduces a new way to collaborate and share content with both internal and external users of mailbox.org. These are the different options:&lt;/p&gt;&lt;p&gt;Guest Access: Users can be given access to shared content via a slimmed-down office interface. This lets them access shared data, and edit, create and upload content. Note that real-time collaboration between internal users and guest users is also possible.&lt;/p&gt;&lt;p&gt;Invitation: To share something outside of the Office suite, a mailbox.org user can grant access permissions to external users by adding their e-mail address.&lt;/p&gt;&lt;p&gt;Permissions Management: Through the user permissions view, both mailbox.org users and external users can be granted permanent sharing permissions for accessing data.&lt;/p&gt;&lt;h4&gt;Calendar&lt;/h4&gt;&lt;p&gt;The sharing of calendars has improved considerably, in that different colours can now be assigned to appointments, folders and calendars (at last!). Further, there is a new folder for “All my appointments” that consolidates the information contained in different calendars into a single view.&lt;/p&gt;&lt;h4&gt;Presentations&lt;/h4&gt;&lt;p&gt;Users can now display presentations using their cloud office interface.&lt;/p&gt;&lt;h4&gt;Drive&lt;/h4&gt;&lt;p&gt;A whole range of usability enhancements have been implemented in order to improve the display of folders and image files. When uploading files, users can now see the estimated upload time. Further, users can connect their mailbox.org drive with other cloud storage services such as Google Drive, DropBox, Box, and OneDrive, and move files between these via drag&amp;amp;drop.&lt;/p&gt;&lt;h4&gt;E-mail&lt;/h4&gt;&lt;p&gt;The most obvious change is the simplified page layout. Note that all previous features are still present. We also updated the design of our special icons that indicate the encrypted transmission of e-mails via SSL/DANE.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-04/mailbox-news-und-updates-produktupdate-2.jpg?itok=_u6eySrM" type="image/jpeg" length="284259"/><guid isPermaLink="false">53773d5b-9e2c-4da6-b0a1-6456170d1aec</guid>
    <pubDate>Wed, 25 Nov 2015 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Web interface update</dc:title>
    <dc:identifier>53773d5b-9e2c-4da6-b0a1-6456170d1aec</dc:identifier>
    </item>
<item>
  <title>Web interface update</title>
  <link>https://mailbox.org/en/news/update-web-interface-november-2015/</link>
  <description>&lt;p&gt;&lt;em&gt;Update 26/11/2015 at 8 am (CET): Our colleagues worked hard. The update is done. – But there are still some things to fix today.&lt;/em&gt;&lt;br&gt;Dear mailbox.org customers,&lt;/p&gt;&lt;p&gt;We are writing to you today to let you know that there we are going to perform an update of our web interface later at 9 pm (Central European Time) tonight. There is a possibility that this might lead to temporary delays in the processing of logins to the cloud office, and we would like to apologise for any inconvenience this might cause. We will do our utmost to keep any interference between the update process and user operations as minimal as possible.&lt;/p&gt;&lt;p&gt;On the positive side, the new updated version of the web interface will bring a number of exciting changes and improvements.&lt;/p&gt;&lt;h2&gt;What’s new?&lt;/h2&gt;&lt;h4&gt;Sharing of files, calendars, tasks, and contacts&lt;/h4&gt;&lt;p&gt;The updated version introduces a new way to collaborate and share content with both internal and external users of mailbox.org. These are the different options:&lt;/p&gt;&lt;p&gt;Guest Access: Users can be given access to shared content via a slimmed-down office interface. This lets them access shared data, and edit, create and upload content. Note that real-time collaboration between internal users and guest users is also possible.&lt;/p&gt;&lt;p&gt;Invitation: To share something outside of the Office suite, a mailbox.org user can grant access permissions to external users by adding their e-mail address.&lt;/p&gt;&lt;p&gt;Permissions Management: Through the user permissions view, both mailbox.org users and external users can be granted permanent sharing permissions for accessing data.&lt;/p&gt;&lt;h4&gt;Calendar&lt;/h4&gt;&lt;p&gt;The sharing of calendars has improved considerably, in that different colours can now be assigned to appointments, folders and calendars (at last!). Further, there is a new folder for “All my appointments” that consolidates the information contained in different calendars into a single view.&lt;/p&gt;&lt;h4&gt;Presentations&lt;/h4&gt;&lt;p&gt;Users can now display presentations using their cloud office interface.&lt;/p&gt;&lt;h4&gt;Drive&lt;/h4&gt;&lt;p&gt;A whole range of usability enhancements have been implemented in order to improve the display of folders and image files. When uploading files, users can now see the estimated upload time. Further, users can connect their mailbox.org drive with other cloud storage services such as Google Drive, DropBox, Box, and OneDrive, and move files between these via drag&amp;amp;drop.&lt;/p&gt;&lt;h4&gt;E-mail&lt;/h4&gt;&lt;p&gt;The most obvious change is the simplified page layout. Note that all previous features are still present. We also updated the design of our special icons that indicate the encrypted transmission of e-mails via SSL/DANE.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-04/mailbox-news-und-updates-produktupdate-2.jpg?itok=_u6eySrM" type="image/jpeg" length="284259"/><guid isPermaLink="false">53773d5b-9e2c-4da6-b0a1-6456170d1aec</guid>
    <pubDate>Wed, 25 Nov 2015 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Web interface update</dc:title>
    <dc:identifier>53773d5b-9e2c-4da6-b0a1-6456170d1aec</dc:identifier>
    </item>
<item>
  <title>mailbox.org shows recipient security level before sending</title>
  <link>https://mailbox.org/en/news/mailbox-checks-security-standard-e-mail-recipients-sending/</link>
  <description>&lt;ul&gt;&lt;li&gt;How would you know if your e-mail will be delivered via SSL? When composing your message with mailbox.org, just by typing the recipient address you will find out in an instant – before actually sending anything!&lt;/li&gt;&lt;li&gt;A simple symbol on the screen will tell you what kind of transport security is supported by the e-mail provider of the recipient.&lt;/li&gt;&lt;li&gt;As a result, your private and business communication will become more secure and transparent.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;All customers of mailbox.org can now easily see if the message they wish to send will be transmitted to recipients on an SSL-encrypted connection.&lt;br&gt;mailbox.org uses a straightforward way to classify the e-mail providers at the receiving end of the communication. Basically, there are three symbols indicating the supported transport security level: 1) If the provider offers no encryption whatsoever, users will see a red, open padlock symbol next to the recipient’s address; 2) normal SSL encryption support will yield a green padlock symbol, and 3) if the system supports the highest SSL standard as well as DANE and DNSSEC security, users will be presented with a symbol showing a green sealed padlock.&lt;/p&gt;&lt;p&gt;„Even though surveillance scandals are in the news on an almost daily basis, only 85 per cent of e-mail providers offer basic SSL encryption.“, says Peer Heinlein, founder and operator of mailbox.org. „For this reason, users have no real certainty about the secure transmission of their e-mail messages around the world.“&lt;/p&gt;&lt;h3&gt;Offering secure transmission everywhere&lt;/h3&gt;&lt;p&gt;E-mail providers are not obliged to facilitate any secure communication with other providers. If there is no encryption, a malicious user could act as a „man in the middle“ and manipulate the SMTP connection process in order to force the unencrypted delivery of an e-mail message.&lt;/p&gt;&lt;p&gt;At mailbox.org, such attacks will be detected automatically and if an external mail server suddenly falls below its previously known security standard, we will stop the delivery of e-mails to this server until our administrative team has investigated the case and determined that message delivery to this server is safe again.&lt;/p&gt;&lt;p&gt;Through these measures, mailbox.org creates a new level of security for the sending of e-mails. The new service works with all mail servers on the Web, which stands in contrast to „E-Mail made in Germany“, where the secure transmission of messages is limited to a few selected providers. mailbox.org can now guarantee the secure sending of e-mails to all providers which offer a secure encrypted connection.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-04/mailbox-news-und-updates-sicherheit.jpg?itok=4LMJmUnZ" type="image/jpeg" length="194998"/><guid isPermaLink="false">e8e2aac8-d203-49af-b570-721efa9e741e</guid>
    <pubDate>Thu, 28 May 2015 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>mailbox.org shows recipient security level before sending</dc:title>
    <dc:identifier>e8e2aac8-d203-49af-b570-721efa9e741e</dc:identifier>
    </item>
<item>
  <title>mailbox.org shows recipient security level before sending</title>
  <link>https://mailbox.org/en/news/mailbox-checks-security-standard-e-mail-recipients-sending/</link>
  <description>&lt;ul&gt;&lt;li&gt;How would you know if your e-mail will be delivered via SSL? When composing your message with mailbox.org, just by typing the recipient address you will find out in an instant – before actually sending anything!&lt;/li&gt;&lt;li&gt;A simple symbol on the screen will tell you what kind of transport security is supported by the e-mail provider of the recipient.&lt;/li&gt;&lt;li&gt;As a result, your private and business communication will become more secure and transparent.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;All customers of mailbox.org can now easily see if the message they wish to send will be transmitted to recipients on an SSL-encrypted connection.&lt;br&gt;mailbox.org uses a straightforward way to classify the e-mail providers at the receiving end of the communication. Basically, there are three symbols indicating the supported transport security level: 1) If the provider offers no encryption whatsoever, users will see a red, open padlock symbol next to the recipient’s address; 2) normal SSL encryption support will yield a green padlock symbol, and 3) if the system supports the highest SSL standard as well as DANE and DNSSEC security, users will be presented with a symbol showing a green sealed padlock.&lt;/p&gt;&lt;p&gt;„Even though surveillance scandals are in the news on an almost daily basis, only 85 per cent of e-mail providers offer basic SSL encryption.“, says Peer Heinlein, founder and operator of mailbox.org. „For this reason, users have no real certainty about the secure transmission of their e-mail messages around the world.“&lt;/p&gt;&lt;h3&gt;Offering secure transmission everywhere&lt;/h3&gt;&lt;p&gt;E-mail providers are not obliged to facilitate any secure communication with other providers. If there is no encryption, a malicious user could act as a „man in the middle“ and manipulate the SMTP connection process in order to force the unencrypted delivery of an e-mail message.&lt;/p&gt;&lt;p&gt;At mailbox.org, such attacks will be detected automatically and if an external mail server suddenly falls below its previously known security standard, we will stop the delivery of e-mails to this server until our administrative team has investigated the case and determined that message delivery to this server is safe again.&lt;/p&gt;&lt;p&gt;Through these measures, mailbox.org creates a new level of security for the sending of e-mails. The new service works with all mail servers on the Web, which stands in contrast to „E-Mail made in Germany“, where the secure transmission of messages is limited to a few selected providers. mailbox.org can now guarantee the secure sending of e-mails to all providers which offer a secure encrypted connection.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-04/mailbox-news-und-updates-sicherheit.jpg?itok=4LMJmUnZ" type="image/jpeg" length="194998"/><guid isPermaLink="false">e8e2aac8-d203-49af-b570-721efa9e741e</guid>
    <pubDate>Thu, 28 May 2015 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>mailbox.org shows recipient security level before sending</dc:title>
    <dc:identifier>e8e2aac8-d203-49af-b570-721efa9e741e</dc:identifier>
    </item>
<item>
  <title>mailbox.org launches secure instant messaging service</title>
  <link>https://mailbox.org/en/news/mailbox-launched-secure-instant-messaging-service/</link>
  <description>&lt;p&gt;The use of instant messaging software like Skype or WhatsApp has become widely popular for both private and business communication. When exchanging personal information or otherwise sensitive data, users need to be careful because the German data protection law does not necessarily apply to services located in other countries.&lt;/p&gt;&lt;p&gt;mailbox.org has started their own instant messaging service to extend its existing portfolio of secure communication services. As of February 2015, all mailbox.org account holders can instantly access the new messaging service – free of charge. The system is based on Jabber and the Extensible Messaging and Presence Protocol (XMPP) and allows the sending and receiving of encrypted text messages and files not just between users of mailbox.org but also those registered with other Jabber service providers.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Jabber server for the secure exchange of messages and files in real-time&lt;/li&gt;&lt;li&gt;Supports SSL/TLS as well as end-to-end encryption via OTR&lt;/li&gt;&lt;li&gt;Security and ease-of-use for businesses and home users&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;h3&gt;Quick to set up and easy to use&lt;/h3&gt;&lt;p&gt;The new service is based on Jabber and uses the established instant messaging protocol XMPP. Getting everything up and running is very simple: Customers of mailbox.org who want to use the new service must download one of the various free Jabber clients available on the Web. When setting up the software, all they need to do is enter their mailbox.org e-mail address and password – everything else works automatically and the service will be configured and ready within a matter of seconds. Depending on the client used, the new service also supports encrypted conferences for several users.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;h3&gt;Encryption without compromises&lt;/h3&gt;&lt;p&gt;Similar to our secure e-mail service, the new instant messaging service supports various encryption mechanisms to implement high data protection standards. Connections to the Jabber server are only possible with transport security via SSL/TLS enabled. DANE and DNSSEC are used to prevent any third-party manipulation of the connection. Secure end-to-end encryption is facilitated through the „Off-the-Record“ mechanism, which even less tech-savvy users can enable easily with a few mouse clicks. Any communication secured this way can only be read by the users who are communicating with each other, and no-one else.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;h3&gt;Recommended Jabber software&lt;/h3&gt;&lt;p&gt;For best communication security with the new instant messaging service, we recommend installing client software that supports OTR encryption (either natively or via a plugin). This includes the clients Pidgin for Linux or Windows, and Adium for Mac OS X. There are also clients available to use with smartphones and tablet computers running Android or iOS as operating system. Integration of the new service into the mailbox.org web interface is currently in preparation and will be finished in April 2015.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;h3&gt;Further information in our FAQ:&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="https://mailbox.org/en/how-to-install-jabberxmpp/"&gt;How to install Jabber/XMPP&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="https://mailbox.org/en/how-to-set-up-off-the-record-encryption-for-jabberxmpp/"&gt;How to Set up Off-the-Record-Encryption for Jabber/XMPP&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="https://mailbox.org/en/how-to-install-adium-as-jabber-client-on-os-x/"&gt;How to install Adium as Jabber client on OS X&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="https://mailbox.org/en/notes-on-our-jabber-server-test-run-and-available-support/"&gt;Notes on our Jabber server test run and available support&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-04/mailbox-news-und-updates-sicherheit.jpg?itok=4LMJmUnZ" type="image/jpeg" length="194998"/><guid isPermaLink="false">6f8c1b30-867c-45c0-a3d7-67fa53f9eca0</guid>
    <pubDate>Thu, 19 Feb 2015 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>mailbox.org launches secure instant messaging service</dc:title>
    <dc:identifier>6f8c1b30-867c-45c0-a3d7-67fa53f9eca0</dc:identifier>
    </item>
<item>
  <title>mailbox.org launches secure instant messaging service</title>
  <link>https://mailbox.org/en/news/mailbox-launched-secure-instant-messaging-service/</link>
  <description>&lt;p&gt;The use of instant messaging software like Skype or WhatsApp has become widely popular for both private and business communication. When exchanging personal information or otherwise sensitive data, users need to be careful because the German data protection law does not necessarily apply to services located in other countries.&lt;/p&gt;&lt;p&gt;mailbox.org has started their own instant messaging service to extend its existing portfolio of secure communication services. As of February 2015, all mailbox.org account holders can instantly access the new messaging service – free of charge. The system is based on Jabber and the Extensible Messaging and Presence Protocol (XMPP) and allows the sending and receiving of encrypted text messages and files not just between users of mailbox.org but also those registered with other Jabber service providers.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Jabber server for the secure exchange of messages and files in real-time&lt;/li&gt;&lt;li&gt;Supports SSL/TLS as well as end-to-end encryption via OTR&lt;/li&gt;&lt;li&gt;Security and ease-of-use for businesses and home users&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;h3&gt;Quick to set up and easy to use&lt;/h3&gt;&lt;p&gt;The new service is based on Jabber and uses the established instant messaging protocol XMPP. Getting everything up and running is very simple: Customers of mailbox.org who want to use the new service must download one of the various free Jabber clients available on the Web. When setting up the software, all they need to do is enter their mailbox.org e-mail address and password – everything else works automatically and the service will be configured and ready within a matter of seconds. Depending on the client used, the new service also supports encrypted conferences for several users.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;h3&gt;Encryption without compromises&lt;/h3&gt;&lt;p&gt;Similar to our secure e-mail service, the new instant messaging service supports various encryption mechanisms to implement high data protection standards. Connections to the Jabber server are only possible with transport security via SSL/TLS enabled. DANE and DNSSEC are used to prevent any third-party manipulation of the connection. Secure end-to-end encryption is facilitated through the „Off-the-Record“ mechanism, which even less tech-savvy users can enable easily with a few mouse clicks. Any communication secured this way can only be read by the users who are communicating with each other, and no-one else.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;h3&gt;Recommended Jabber software&lt;/h3&gt;&lt;p&gt;For best communication security with the new instant messaging service, we recommend installing client software that supports OTR encryption (either natively or via a plugin). This includes the clients Pidgin for Linux or Windows, and Adium for Mac OS X. There are also clients available to use with smartphones and tablet computers running Android or iOS as operating system. Integration of the new service into the mailbox.org web interface is currently in preparation and will be finished in April 2015.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;h3&gt;Further information in our FAQ:&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="https://mailbox.org/en/how-to-install-jabberxmpp/"&gt;How to install Jabber/XMPP&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="https://mailbox.org/en/how-to-set-up-off-the-record-encryption-for-jabberxmpp/"&gt;How to Set up Off-the-Record-Encryption for Jabber/XMPP&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="https://mailbox.org/en/how-to-install-adium-as-jabber-client-on-os-x/"&gt;How to install Adium as Jabber client on OS X&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="https://mailbox.org/en/notes-on-our-jabber-server-test-run-and-available-support/"&gt;Notes on our Jabber server test run and available support&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-04/mailbox-news-und-updates-sicherheit.jpg?itok=4LMJmUnZ" type="image/jpeg" length="194998"/><guid isPermaLink="false">6f8c1b30-867c-45c0-a3d7-67fa53f9eca0</guid>
    <pubDate>Thu, 19 Feb 2015 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>mailbox.org launches secure instant messaging service</dc:title>
    <dc:identifier>6f8c1b30-867c-45c0-a3d7-67fa53f9eca0</dc:identifier>
    </item>
<item>
  <title>Transparency Report 2014</title>
  <link>https://mailbox.org/en/news/transparency-report-2014/</link>
  <description>&lt;p&gt;We at JPBerlin.de and mailbox.org are keen to publish our transparency report on the requests for information made by public authorities and provide insight into the respective figures in light of current discussions about inquiries made to Internet providers. We’re pleased to say that these figures are quite unspectacular:&lt;/p&gt;&lt;p&gt;Number of requests made to JPBerlin.de in 2013&lt;/p&gt;&lt;p&gt;Total: 1&lt;br&gt;German authorities: 1&lt;br&gt;Foreign authorities: 0&lt;/p&gt;&lt;p&gt;Type of authority&lt;br&gt;Law enforcement agencies: 1&lt;br&gt;Intelligence services: 0&lt;/p&gt;&lt;p&gt;Type of request&lt;br&gt;Inventory data inquiries: 1&lt;br&gt;Request for a mailbox name for existing bank details: 0&lt;br&gt;Mailbox confiscations: 0&lt;br&gt;Traffic data inquiries: 0&lt;br&gt;LI (Lawful Interception – surveillance of a mailbox for a specified period of time): 0&lt;/p&gt;&lt;p&gt;Our mailbox.org project started in February 2014. That’s why we don’t have any figures for 2013.&lt;/p&gt;&lt;p&gt;Our providers JPBerlin.de and mailbox.org have not yet received any information requests in 2014. Throughout the company’s 25-year history, JPBerlin.de has never experienced lawful interception in accordance with the TKÜV (German Telecommunications Interception Ordinance).&lt;br&gt;If we receive requests, they are always checked by our lawyers who specialize in this area.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-04/mailbox-news-und-updates-transparenzbericht.jpg?itok=SMV4eTPL" type="image/jpeg" length="268110"/><guid isPermaLink="false">aa43b00c-0985-406e-94d2-53a0a4bd068c</guid>
    <pubDate>Thu, 29 Jan 2015 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Transparency Report 2014</dc:title>
    <dc:identifier>aa43b00c-0985-406e-94d2-53a0a4bd068c</dc:identifier>
    </item>
<item>
  <title>Transparency Report 2014</title>
  <link>https://mailbox.org/en/news/transparency-report-2014/</link>
  <description>&lt;p&gt;We at JPBerlin.de and mailbox.org are keen to publish our transparency report on the requests for information made by public authorities and provide insight into the respective figures in light of current discussions about inquiries made to Internet providers. We’re pleased to say that these figures are quite unspectacular:&lt;/p&gt;&lt;p&gt;Number of requests made to JPBerlin.de in 2013&lt;/p&gt;&lt;p&gt;Total: 1&lt;br&gt;German authorities: 1&lt;br&gt;Foreign authorities: 0&lt;/p&gt;&lt;p&gt;Type of authority&lt;br&gt;Law enforcement agencies: 1&lt;br&gt;Intelligence services: 0&lt;/p&gt;&lt;p&gt;Type of request&lt;br&gt;Inventory data inquiries: 1&lt;br&gt;Request for a mailbox name for existing bank details: 0&lt;br&gt;Mailbox confiscations: 0&lt;br&gt;Traffic data inquiries: 0&lt;br&gt;LI (Lawful Interception – surveillance of a mailbox for a specified period of time): 0&lt;/p&gt;&lt;p&gt;Our mailbox.org project started in February 2014. That’s why we don’t have any figures for 2013.&lt;/p&gt;&lt;p&gt;Our providers JPBerlin.de and mailbox.org have not yet received any information requests in 2014. Throughout the company’s 25-year history, JPBerlin.de has never experienced lawful interception in accordance with the TKÜV (German Telecommunications Interception Ordinance).&lt;br&gt;If we receive requests, they are always checked by our lawyers who specialize in this area.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-04/mailbox-news-und-updates-transparenzbericht.jpg?itok=SMV4eTPL" type="image/jpeg" length="268110"/><guid isPermaLink="false">aa43b00c-0985-406e-94d2-53a0a4bd068c</guid>
    <pubDate>Thu, 29 Jan 2015 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Transparency Report 2014</dc:title>
    <dc:identifier>aa43b00c-0985-406e-94d2-53a0a4bd068c</dc:identifier>
    </item>
<item>
  <title>Catch-All for custom domains</title>
  <link>https://mailbox.org/en/news/catch-all-now-works-custom-domain-names/</link>
  <description>&lt;p&gt;Since mailbox.org allows the use of custom domain names with e-mail accounts, various users have approached our support team to ask about the availability of catch-all functionality.&lt;/p&gt;&lt;h3&gt;What is catch-all?&lt;/h3&gt;&lt;p&gt;Catch-all means that all e-mails sent to addresses at a particular domain will be received through a specific e-mail alias, regardless of whether the addresses used by the sender actually exist (as long as the domain name is valid). It doesn’t matter what the sender puts in the local address part before the ‘@’ – the message will come through, even if no e-mail account is actually linked to this address. This is useful if users want to hand out many different e-mail addresses to people or organizations, or if they just want to make sure not to lose any e-mails sent to them where addresses have been spelled wrongly.&lt;br&gt;We are happy to announce that this functionality is now available to all customers.&amp;nbsp;&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-envelope-1.png?itok=ahABjshn" type="image/png" length="394797"/><guid isPermaLink="false">a536f181-320f-43a8-84f3-44edfaf4519c</guid>
    <pubDate>Fri, 09 Jan 2015 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Catch-All for custom domains</dc:title>
    <dc:identifier>a536f181-320f-43a8-84f3-44edfaf4519c</dc:identifier>
    </item>
<item>
  <title>Catch-All for custom domains</title>
  <link>https://mailbox.org/en/news/catch-all-now-works-custom-domain-names/</link>
  <description>&lt;p&gt;Since mailbox.org allows the use of custom domain names with e-mail accounts, various users have approached our support team to ask about the availability of catch-all functionality.&lt;/p&gt;&lt;h3&gt;What is catch-all?&lt;/h3&gt;&lt;p&gt;Catch-all means that all e-mails sent to addresses at a particular domain will be received through a specific e-mail alias, regardless of whether the addresses used by the sender actually exist (as long as the domain name is valid). It doesn’t matter what the sender puts in the local address part before the ‘@’ – the message will come through, even if no e-mail account is actually linked to this address. This is useful if users want to hand out many different e-mail addresses to people or organizations, or if they just want to make sure not to lose any e-mails sent to them where addresses have been spelled wrongly.&lt;br&gt;We are happy to announce that this functionality is now available to all customers.&amp;nbsp;&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-envelope-1.png?itok=ahABjshn" type="image/png" length="394797"/><guid isPermaLink="false">a536f181-320f-43a8-84f3-44edfaf4519c</guid>
    <pubDate>Fri, 09 Jan 2015 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Catch-All for custom domains</dc:title>
    <dc:identifier>a536f181-320f-43a8-84f3-44edfaf4519c</dc:identifier>
    </item>
<item>
  <title>mailbox.org launches secure ‘family accounts’</title>
  <link>https://mailbox.org/en/news/mailbox-now-offers-secure-family-accounts/</link>
  <description>&lt;p&gt;Finally! We are happy to announce that starting from today, customers have access to our new mailbox.org family account which offers a range of exciting new features. Users with family accounts may form groups to easily share calendars, contacts, files, or task lists with each other. Despite the name, it is not just for families: We are confident that groups of friends, or students living in shared accommodation will find the new features very useful as well.&lt;/p&gt;&lt;p&gt;In the past, we were frequently contacted by customers inquiring about the availability of basic groupware functionality. We realized there was huge demand for shared calendars, with which family members wanted to organize their daily schedules, for example. Other items on our customers’ wish list included shared address books, task lists, and file storage. We introduced family accounts to meet this demand and provide an attractive, easy-to-use alternative to other services which may have similar functionality but lack the level of data protection we can offer.&lt;/p&gt;&lt;p&gt;To benefit from the new features, users require at least the „Mail XL“ package which costs 2,50 Euro per account and month. This tariff includes 5 GB e-mail storage and 100MB file storage space, as well as access to online text processing software. In addition, users may create up to 25 e-mail aliases per account and &lt;a href="https://mailbox.org/en/how-to-use-mailbox-org-with-individual-domains/" target="_blank" rel="noopener"&gt;integrate e-mail addresses from personal internet domains&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;New customers can instantly set up and use their family accounts after obtaining any eligible e-mail package. Existing customers should get in touch with our technical support who will be happy to help them enable the new features.&lt;/p&gt;&lt;h3&gt;Don’t miss our FAQ on family accounts:&lt;/h3&gt;&lt;p&gt;&lt;a href="https://mailbox.org/en/family-accounts-all-questions-and-all-answers/" target="_blank" rel="noopener"&gt;Family accounts – All questions and answers&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="https://mailbox.org/en/how-to-set-up-family-accounts/" title="How to set up family accounts"&gt;How to set up family accounts&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="https://mailbox.org/en/how-to-use-your-family-account/" title="How to use your family account"&gt;How to use your family account&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Because of licensing restrictions there is currently a limit of 10 users that can be member of any one group. Family accounts are available to home users only. A similar product offering group accounts for businesses is in preparation, to be rolled out by the end of the year.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-family-accounts.jpeg?itok=eyqZ04QL" type="image/jpeg" length="409169"/><guid isPermaLink="false">7083d77c-e4d1-4770-be9f-fe41e66a11ca</guid>
    <pubDate>Tue, 16 Sep 2014 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>mailbox.org launches secure ‘family accounts’</dc:title>
    <dc:identifier>7083d77c-e4d1-4770-be9f-fe41e66a11ca</dc:identifier>
    </item>
<item>
  <title>mailbox.org launches secure ‘family accounts’</title>
  <link>https://mailbox.org/en/news/mailbox-now-offers-secure-family-accounts/</link>
  <description>&lt;p&gt;Finally! We are happy to announce that starting from today, customers have access to our new mailbox.org family account which offers a range of exciting new features. Users with family accounts may form groups to easily share calendars, contacts, files, or task lists with each other. Despite the name, it is not just for families: We are confident that groups of friends, or students living in shared accommodation will find the new features very useful as well.&lt;/p&gt;&lt;p&gt;In the past, we were frequently contacted by customers inquiring about the availability of basic groupware functionality. We realized there was huge demand for shared calendars, with which family members wanted to organize their daily schedules, for example. Other items on our customers’ wish list included shared address books, task lists, and file storage. We introduced family accounts to meet this demand and provide an attractive, easy-to-use alternative to other services which may have similar functionality but lack the level of data protection we can offer.&lt;/p&gt;&lt;p&gt;To benefit from the new features, users require at least the „Mail XL“ package which costs 2,50 Euro per account and month. This tariff includes 5 GB e-mail storage and 100MB file storage space, as well as access to online text processing software. In addition, users may create up to 25 e-mail aliases per account and &lt;a href="https://mailbox.org/en/how-to-use-mailbox-org-with-individual-domains/" target="_blank" rel="noopener"&gt;integrate e-mail addresses from personal internet domains&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;New customers can instantly set up and use their family accounts after obtaining any eligible e-mail package. Existing customers should get in touch with our technical support who will be happy to help them enable the new features.&lt;/p&gt;&lt;h3&gt;Don’t miss our FAQ on family accounts:&lt;/h3&gt;&lt;p&gt;&lt;a href="https://mailbox.org/en/family-accounts-all-questions-and-all-answers/" target="_blank" rel="noopener"&gt;Family accounts – All questions and answers&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="https://mailbox.org/en/how-to-set-up-family-accounts/" title="How to set up family accounts"&gt;How to set up family accounts&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="https://mailbox.org/en/how-to-use-your-family-account/" title="How to use your family account"&gt;How to use your family account&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Because of licensing restrictions there is currently a limit of 10 users that can be member of any one group. Family accounts are available to home users only. A similar product offering group accounts for businesses is in preparation, to be rolled out by the end of the year.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-family-accounts.jpeg?itok=eyqZ04QL" type="image/jpeg" length="409169"/><guid isPermaLink="false">7083d77c-e4d1-4770-be9f-fe41e66a11ca</guid>
    <pubDate>Tue, 16 Sep 2014 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>mailbox.org launches secure ‘family accounts’</dc:title>
    <dc:identifier>7083d77c-e4d1-4770-be9f-fe41e66a11ca</dc:identifier>
    </item>
<item>
  <title>How to use mailbox.org with individual domains</title>
  <link>https://mailbox.org/en/news/how-use-mailbox-individual-domains/</link>
  <description>&lt;p class="western"&gt;As of now, you can use mailbox.org with individual domains. However, there are a few points you need to keep in mind, so please read the following article at our knowledge base carefully.&lt;/p&gt;&lt;p&gt;&lt;a href="https://kb.mailbox.org/en/private/custom-domains/" target="_blank" rel="noopener"&gt;https://kb.mailbox.org/en/private/custom-domains/&lt;/a&gt;&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-envelope-2.png?itok=VczfRatn" type="image/png" length="349291"/><guid isPermaLink="false">3c94cf2b-4dd1-4019-8238-117ad9a2bc15</guid>
    <pubDate>Thu, 19 Jun 2014 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>How to use mailbox.org with individual domains</dc:title>
    <dc:identifier>3c94cf2b-4dd1-4019-8238-117ad9a2bc15</dc:identifier>
    </item>
<item>
  <title>How to use mailbox.org with individual domains</title>
  <link>https://mailbox.org/en/news/how-use-mailbox-individual-domains/</link>
  <description>&lt;p class="western"&gt;As of now, you can use mailbox.org with individual domains. However, there are a few points you need to keep in mind, so please read the following article at our knowledge base carefully.&lt;/p&gt;&lt;p&gt;&lt;a href="https://kb.mailbox.org/en/private/custom-domains/" target="_blank" rel="noopener"&gt;https://kb.mailbox.org/en/private/custom-domains/&lt;/a&gt;&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-envelope-2.png?itok=VczfRatn" type="image/png" length="349291"/><guid isPermaLink="false">3c94cf2b-4dd1-4019-8238-117ad9a2bc15</guid>
    <pubDate>Thu, 19 Jun 2014 00:00:00 +0200</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>How to use mailbox.org with individual domains</dc:title>
    <dc:identifier>3c94cf2b-4dd1-4019-8238-117ad9a2bc15</dc:identifier>
    </item>
<item>
  <title>Report about mailbox.org on ZDF</title>
  <link>https://mailbox.org/en/news/story-about-mailbox-zdf/</link>
  <description>&lt;p&gt;Last Sunday, right around breakfast-time, the German television station ZDF aired a story about e-mail security and one of the topics they covered was our mailbox.org project. A few days ago, journalist Ulrich Hansen came to visit us in Berlin for an entire day. The television report, together with additional information, is available &lt;a href="http://www.heute.de/sichere-mails-wer-mein-postfach-liest-weiss-was-ich-denke-32417864.html"&gt;on the ZDF website&lt;/a&gt;.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-tv-bericht.png?itok=WHLq6gKw" type="image/png" length="258245"/><guid isPermaLink="false">60b650e6-e04d-4464-8016-30e351c0eeee</guid>
    <pubDate>Fri, 21 Mar 2014 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Report about mailbox.org on ZDF</dc:title>
    <dc:identifier>60b650e6-e04d-4464-8016-30e351c0eeee</dc:identifier>
    </item>
<item>
  <title>Report about mailbox.org on ZDF</title>
  <link>https://mailbox.org/en/news/story-about-mailbox-zdf/</link>
  <description>&lt;p&gt;Last Sunday, right around breakfast-time, the German television station ZDF aired a story about e-mail security and one of the topics they covered was our mailbox.org project. A few days ago, journalist Ulrich Hansen came to visit us in Berlin for an entire day. The television report, together with additional information, is available &lt;a href="http://www.heute.de/sichere-mails-wer-mein-postfach-liest-weiss-was-ich-denke-32417864.html"&gt;on the ZDF website&lt;/a&gt;.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-tv-bericht.png?itok=WHLq6gKw" type="image/png" length="258245"/><guid isPermaLink="false">60b650e6-e04d-4464-8016-30e351c0eeee</guid>
    <pubDate>Fri, 21 Mar 2014 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Report about mailbox.org on ZDF</dc:title>
    <dc:identifier>60b650e6-e04d-4464-8016-30e351c0eeee</dc:identifier>
    </item>
<item>
  <title>Report in The Irish Times</title>
  <link>https://mailbox.org/en/news/article-irish-times/</link>
  <description>&lt;p&gt;After The Irish Times took the opportunity to speak with Peer Heinlein in person at the CeBit, we were pleased to see the paper publish a long article about e-mail security and mailbox.org. You can find the complete article on the website of &lt;a href="http://www.irishtimes.com/business/sectors/technology/time-to-batten-down-the-hatches-against-email-snoopers-but-how-1.1730946" target="_blank" rel="noopener"&gt;The Irish Times&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;You’ve probably noticed the British flag on our website by now. We are in the process of translating our website and we will let you know once it is finished.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-reading-news.jpeg?itok=mDgC-6GJ" type="image/jpeg" length="303159"/><guid isPermaLink="false">63992e67-b0ca-4389-a297-a28e7a4aa0d9</guid>
    <pubDate>Thu, 20 Mar 2014 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Report in The Irish Times</dc:title>
    <dc:identifier>63992e67-b0ca-4389-a297-a28e7a4aa0d9</dc:identifier>
    </item>
<item>
  <title>Report in The Irish Times</title>
  <link>https://mailbox.org/en/news/article-irish-times/</link>
  <description>&lt;p&gt;After The Irish Times took the opportunity to speak with Peer Heinlein in person at the CeBit, we were pleased to see the paper publish a long article about e-mail security and mailbox.org. You can find the complete article on the website of &lt;a href="http://www.irishtimes.com/business/sectors/technology/time-to-batten-down-the-hatches-against-email-snoopers-but-how-1.1730946" target="_blank" rel="noopener"&gt;The Irish Times&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;You’ve probably noticed the British flag on our website by now. We are in the process of translating our website and we will let you know once it is finished.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-reading-news.jpeg?itok=mDgC-6GJ" type="image/jpeg" length="303159"/><guid isPermaLink="false">63992e67-b0ca-4389-a297-a28e7a4aa0d9</guid>
    <pubDate>Thu, 20 Mar 2014 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Report in The Irish Times</dc:title>
    <dc:identifier>63992e67-b0ca-4389-a297-a28e7a4aa0d9</dc:identifier>
    </item>
<item>
  <title>mailbox.org on taz.de and Focus online</title>
  <link>https://mailbox.org/en/news/mailbox-taz-and-focus-online/</link>
  <description>&lt;p&gt;Other large German media outlets such as taz and Focus have reported on mailbox.org over the past few days. taz wrote that the demand for e-mails services with better data protection is on the rise and that the use of GPG keys makes our mailbox.org service all the more attractive. We agree wholeheartedly. Read the entire &lt;a href="http://www.taz.de/Kommunikation-mit-Datenschutz/!134032/" target="_blank" rel="noopener"&gt;taz article&lt;/a&gt; here. The Focus online article reports on alternatives to Apple Mail and explains how easy it is to switch to other providers such as mailbox.org. Read the entire (German) article from &lt;a href="http://www.focus.de/digital/computer/internet-apple-mail-ade-wechsel-zu-neuem-provider-nicht-schwer_id_3696669.html" target="_blank" rel="noopener"&gt;Focus online&lt;/a&gt;.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-team.jpeg?itok=dGTTQB1f" type="image/jpeg" length="320376"/><guid isPermaLink="false">8e16a7c7-7fc5-4644-9fc0-005bf9582597</guid>
    <pubDate>Thu, 20 Mar 2014 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>mailbox.org on taz.de and Focus online</dc:title>
    <dc:identifier>8e16a7c7-7fc5-4644-9fc0-005bf9582597</dc:identifier>
    </item>
<item>
  <title>mailbox.org on taz.de and Focus online</title>
  <link>https://mailbox.org/en/news/mailbox-taz-and-focus-online/</link>
  <description>&lt;p&gt;Other large German media outlets such as taz and Focus have reported on mailbox.org over the past few days. taz wrote that the demand for e-mails services with better data protection is on the rise and that the use of GPG keys makes our mailbox.org service all the more attractive. We agree wholeheartedly. Read the entire &lt;a href="http://www.taz.de/Kommunikation-mit-Datenschutz/!134032/" target="_blank" rel="noopener"&gt;taz article&lt;/a&gt; here. The Focus online article reports on alternatives to Apple Mail and explains how easy it is to switch to other providers such as mailbox.org. Read the entire (German) article from &lt;a href="http://www.focus.de/digital/computer/internet-apple-mail-ade-wechsel-zu-neuem-provider-nicht-schwer_id_3696669.html" target="_blank" rel="noopener"&gt;Focus online&lt;/a&gt;.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-team.jpeg?itok=dGTTQB1f" type="image/jpeg" length="320376"/><guid isPermaLink="false">8e16a7c7-7fc5-4644-9fc0-005bf9582597</guid>
    <pubDate>Thu, 20 Mar 2014 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>mailbox.org on taz.de and Focus online</dc:title>
    <dc:identifier>8e16a7c7-7fc5-4644-9fc0-005bf9582597</dc:identifier>
    </item>
<item>
  <title>mailbox.org had a birthday</title>
  <link>https://mailbox.org/en/news/happy-birthday-mailbox/</link>
  <description>&lt;p&gt;mailbox.org just celebrated its tenth birthday How time flies! Okay, fine, so maybe it’s just been ten days, but a whole lot has happened since then. Our Doodle Video about GPG has over 6,000 views and over 4,000 users have opened an account with us. In this article, we want to provide you with another update on the different events and changes here at mailbox.org.&lt;/p&gt;&lt;h2&gt;Difficulties&lt;/h2&gt;&lt;p&gt;Regarding the error when integrating external e-mail accounts: Last Wednesday, the manufacturer of our new groupware solution released a new software version to rectify the problem. Unfortunately, we had to deactivate this option again after just a short period of time because not all of the problems had been addressed. We hope that the manufacturer will release a new error-free software version for this option over the next few days. Some users are still having problems entering their GPG key in the ‘Settings’ menu in order to activate the fully encrypted mailbox. We are working on a bugfix for this error and hopefully we will be able to solve the problem over the next few days. Invoices for payments: You will receive the PDF invoices for the payments you have made over the next few days. We will keep you informed as to any developments. We ask for your continued patience and understanding and we will be in touch as soon as new versions are available and have been tested and approved. Come check in on our ever-changing ‘&lt;a href="https://mailbox.org/work-in-progress/"&gt;Work-in-progress&lt;/a&gt;’ page from time to time.&lt;/p&gt;&lt;h2&gt;Over 1,000 support requests&lt;/h2&gt;&lt;p&gt;Over the past few days, we have received many, many inquiries and we have attempted to address each and every one of these messages to the best of our ability. Some of these issues were very specific problems involving individual mobile devices and their particular quirks and sometimes the inquiries were related to unclear information in our instructions, which we have attempted to revise in our Help/FAQ section. In some cases, our support team made confusing statements and sometimes, because we were forced to work so quickly, we did not address your exact problem as described. We apologize for any inconvenience and ask for your patience. Our colleagues on the support team are giving it their all and doing their best to help each and every user. If we have failed to address your problem, please contact us again. But rest assured: We have read and registered all of your questions. I have personally read, re-read, and reviewed over 1,000 support inquiries and these messages have inspired a wide array of suggestions for changes and improvements, even if we were not always able to thank everyone who wrote us.&lt;/p&gt;&lt;h2&gt;Important new FAQ articles&lt;/h2&gt;&lt;p&gt;We would like to inform you that we have created the following Help/FAQ articles for current support tickets:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="https://mailbox.org/activesync-does-not-sync-past-e-mails-properly/"&gt;ActiveSync does not sync all past e-mails&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="https://mailbox.org/i-cant-see-imap-folders-that-i-recently-created/"&gt;Recently created folders are not visible/must be subscribed&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="https://mailbox.org/ip-addresses-appear-as-if-they-are-in-ukraine/"&gt;mailbox.org IP addresses from Ukraine?&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="https://mailbox.org/synchronization-with-google-is-not-working/"&gt;Problems syncing with Google&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Feature of the week: Mail extensions&lt;/h2&gt;&lt;p&gt;Did you know that our systems support mail extensions? These are short tags that you can add to your existing e-mail address so that you can track how your e-mail address is forwarded by third parties. In addition, your mailbox can sort your e-mails into IMAP subfolders without the need for you to set up any special mail filters. Our &lt;a href="https://mailbox.org/what-are-mailbox-extensions-and-how-do-i-set-them-up/"&gt;FAQ article on mail extensions&lt;/a&gt; explains this process in detail.&lt;/p&gt;&lt;h2&gt;News about us&lt;/h2&gt;&lt;p&gt;Last week, the German radio station Mitteldeutscher Rundfunk (MDR) joined us at our offices in Berlin and broadcast a short – and in our opinion very accurate – radio story about us and the motivation behind our project. You can listen to &lt;a href="https://mailbox.org/mdr-radio-report-on-mailbox-org/"&gt;our part of the recording&lt;/a&gt;. This coming Sunday, the television station ZDF is planning to report on us in a segment on the ‘sonntags’ show. With that in mind, we wish you lots of fun with our new service. Peer Heinlein and the team from mailbox.org&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-mailbox-geburtstag.png?itok=divs983z" type="image/png" length="262374"/><guid isPermaLink="false">6e795b3f-cfc8-4ff5-99bf-87f90ceb0fc9</guid>
    <pubDate>Mon, 03 Mar 2014 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>mailbox.org had a birthday</dc:title>
    <dc:identifier>6e795b3f-cfc8-4ff5-99bf-87f90ceb0fc9</dc:identifier>
    </item>
<item>
  <title>mailbox.org had a birthday</title>
  <link>https://mailbox.org/en/news/happy-birthday-mailbox/</link>
  <description>&lt;p&gt;mailbox.org just celebrated its tenth birthday How time flies! Okay, fine, so maybe it’s just been ten days, but a whole lot has happened since then. Our Doodle Video about GPG has over 6,000 views and over 4,000 users have opened an account with us. In this article, we want to provide you with another update on the different events and changes here at mailbox.org.&lt;/p&gt;&lt;h2&gt;Difficulties&lt;/h2&gt;&lt;p&gt;Regarding the error when integrating external e-mail accounts: Last Wednesday, the manufacturer of our new groupware solution released a new software version to rectify the problem. Unfortunately, we had to deactivate this option again after just a short period of time because not all of the problems had been addressed. We hope that the manufacturer will release a new error-free software version for this option over the next few days. Some users are still having problems entering their GPG key in the ‘Settings’ menu in order to activate the fully encrypted mailbox. We are working on a bugfix for this error and hopefully we will be able to solve the problem over the next few days. Invoices for payments: You will receive the PDF invoices for the payments you have made over the next few days. We will keep you informed as to any developments. We ask for your continued patience and understanding and we will be in touch as soon as new versions are available and have been tested and approved. Come check in on our ever-changing ‘&lt;a href="https://mailbox.org/work-in-progress/"&gt;Work-in-progress&lt;/a&gt;’ page from time to time.&lt;/p&gt;&lt;h2&gt;Over 1,000 support requests&lt;/h2&gt;&lt;p&gt;Over the past few days, we have received many, many inquiries and we have attempted to address each and every one of these messages to the best of our ability. Some of these issues were very specific problems involving individual mobile devices and their particular quirks and sometimes the inquiries were related to unclear information in our instructions, which we have attempted to revise in our Help/FAQ section. In some cases, our support team made confusing statements and sometimes, because we were forced to work so quickly, we did not address your exact problem as described. We apologize for any inconvenience and ask for your patience. Our colleagues on the support team are giving it their all and doing their best to help each and every user. If we have failed to address your problem, please contact us again. But rest assured: We have read and registered all of your questions. I have personally read, re-read, and reviewed over 1,000 support inquiries and these messages have inspired a wide array of suggestions for changes and improvements, even if we were not always able to thank everyone who wrote us.&lt;/p&gt;&lt;h2&gt;Important new FAQ articles&lt;/h2&gt;&lt;p&gt;We would like to inform you that we have created the following Help/FAQ articles for current support tickets:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="https://mailbox.org/activesync-does-not-sync-past-e-mails-properly/"&gt;ActiveSync does not sync all past e-mails&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="https://mailbox.org/i-cant-see-imap-folders-that-i-recently-created/"&gt;Recently created folders are not visible/must be subscribed&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="https://mailbox.org/ip-addresses-appear-as-if-they-are-in-ukraine/"&gt;mailbox.org IP addresses from Ukraine?&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="https://mailbox.org/synchronization-with-google-is-not-working/"&gt;Problems syncing with Google&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Feature of the week: Mail extensions&lt;/h2&gt;&lt;p&gt;Did you know that our systems support mail extensions? These are short tags that you can add to your existing e-mail address so that you can track how your e-mail address is forwarded by third parties. In addition, your mailbox can sort your e-mails into IMAP subfolders without the need for you to set up any special mail filters. Our &lt;a href="https://mailbox.org/what-are-mailbox-extensions-and-how-do-i-set-them-up/"&gt;FAQ article on mail extensions&lt;/a&gt; explains this process in detail.&lt;/p&gt;&lt;h2&gt;News about us&lt;/h2&gt;&lt;p&gt;Last week, the German radio station Mitteldeutscher Rundfunk (MDR) joined us at our offices in Berlin and broadcast a short – and in our opinion very accurate – radio story about us and the motivation behind our project. You can listen to &lt;a href="https://mailbox.org/mdr-radio-report-on-mailbox-org/"&gt;our part of the recording&lt;/a&gt;. This coming Sunday, the television station ZDF is planning to report on us in a segment on the ‘sonntags’ show. With that in mind, we wish you lots of fun with our new service. Peer Heinlein and the team from mailbox.org&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-mailbox-geburtstag.png?itok=divs983z" type="image/png" length="262374"/><guid isPermaLink="false">6e795b3f-cfc8-4ff5-99bf-87f90ceb0fc9</guid>
    <pubDate>Mon, 03 Mar 2014 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>mailbox.org had a birthday</dc:title>
    <dc:identifier>6e795b3f-cfc8-4ff5-99bf-87f90ceb0fc9</dc:identifier>
    </item>
<item>
  <title>MDR makes radio report about mailbox.org</title>
  <link>https://mailbox.org/en/news/mdr-makes-radio-report-about-mailbox/</link>
  <description>&lt;p&gt;Last week, a journalist from Mitteldeutscher Rundfunk (MDR) visited us in Berlin and interviewed us for a radio programme about mailbox.org. We think he did a great job of summarising our motivation and what we do here. Thank you very much for that!&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-radio.png?itok=-q_DVXUO" type="image/png" length="314046"/><guid isPermaLink="false">187aad22-8906-4cf0-9039-f553d234cf82</guid>
    <pubDate>Mon, 03 Mar 2014 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>MDR makes radio report about mailbox.org</dc:title>
    <dc:identifier>187aad22-8906-4cf0-9039-f553d234cf82</dc:identifier>
    </item>
<item>
  <title>MDR makes radio report about mailbox.org</title>
  <link>https://mailbox.org/en/news/mdr-makes-radio-report-about-mailbox/</link>
  <description>&lt;p&gt;Last week, a journalist from Mitteldeutscher Rundfunk (MDR) visited us in Berlin and interviewed us for a radio programme about mailbox.org. We think he did a great job of summarising our motivation and what we do here. Thank you very much for that!&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-radio.png?itok=-q_DVXUO" type="image/png" length="314046"/><guid isPermaLink="false">187aad22-8906-4cf0-9039-f553d234cf82</guid>
    <pubDate>Mon, 03 Mar 2014 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>MDR makes radio report about mailbox.org</dc:title>
    <dc:identifier>187aad22-8906-4cf0-9039-f553d234cf82</dc:identifier>
    </item>
<item>
  <title>A look back at the early days of mailbox.org</title>
  <link>https://mailbox.org/en/news/look-back-first-few-days-mailbox/</link>
  <description>&lt;p&gt;We had hoped for positive feedback, but the response we received last Friday was nothing short of amazing. We were delighted to receive hundreds of positive, encouraging, and excited e-mails and we were touched by the fact that so many users invested a lot of time and energy in taking a close look at our service, asking questions, and offering serious suggestions for improvement.&lt;/p&gt;&lt;p&gt;Last Friday – within just a short period of time – over 2,000 users registered with our service and our support team took a special weekend shift to respond to around 500 support tickets and other requests for information. Thank you!&lt;/p&gt;&lt;h2&gt;Difficulties&lt;/h2&gt;&lt;p&gt;We had a few problems with regard to accessibility over the weekend and on Monday morning. Although we have a lot of experience operating large web and mail server clusters, we encountered two quirks involving the interaction between our Office software and our mail cluster that we had not discovered prior to this. Ultimately, we were faced with capacity problems and difficulties logging in to the web Office and connecting using CalDAV, etc. As of 11 a.m. today, these problems have been identified and resolved.&lt;/p&gt;&lt;p&gt;We apologize for any inconvenience. However, this weekend – particularly on Saturday – there were a number of serious problems at data centers in Düsseldorf and Berlin. These problems had nothing to do with our service and did not affect our servers. There were multiple denial-of-service attacks against another customer in those data centers, meaning that someone was trying to disrupt their servers. These attacks also affected all other users whose data was ‘just trying to squeeze by.’ Over the course of the day on Saturday, there were multiple ten-minute disruptions to different parts of the network in Germany. Again, this had nothing to do with us.&lt;/p&gt;&lt;p&gt;If you noticed a few strange things over the weekend, this may be the reason. Please try again. If you are still experiencing problems, contact our support team.&lt;/p&gt;&lt;p&gt;In addition, users are still having a few problems creating e-mail filters. In certain situations, the program fails to edit the e-mail filter and activate the encrypted mailbox. This error is not related to our servers; it is caused by problems in the Office interface. We have reported the bug to the manufacturer of the Office software and ask for your patience through the minor difficulties we are experiencing in the launch phase.&lt;/p&gt;&lt;h2&gt;Outlook, ActiveSync, Android Sync, WebDAV/Linux, OX Drive&lt;/h2&gt;&lt;p&gt;In short, it is questions about these services that make up the bulk of our customer inquiries. We have written a number of new Help articles to address these questions (Frequently Asked Questions = FAQ). Have a look at our Help section every so often: &lt;a href="https://mailbox.org/en/help/" title="https://mailbox.org/en/help/"&gt;https://mailbox.org/en/help/&lt;/a&gt;. We add new articles every few hours. Our support team is always on call working to answer each question individually. We want to answer all questions quickly and promptly, so please understand that for standard questions, we will often only have time to provide a short response with a link to our FAQ. Brief overview of the top five questions:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="https://mailbox.org/en/no-connection-with-outlook-2011-what-is-the-problem/"&gt;Outlook 2011:&lt;/a&gt; Doesn’t work because Outlook uses only RC4 SSL encryption, which is not trustworthy.&lt;/li&gt;&lt;li&gt;ActiveSync/smartphone synchronization: Works, but there are a few special conditions to note (&lt;a href="https://mailbox.org/en/data-synchronization-with-mac-os-x-and-windows/"&gt;Windows/Mac&lt;/a&gt;, &lt;a href="https://mailbox.org/daten-abgleich-mit-active-sync-auf-android-geraeten/"&gt;Android&lt;/a&gt;, &lt;a href="https://mailbox.org/en/data-synchronization-with-caldav-and-carddav-for-ios-devices-iphone-ipad"&gt;iOS&lt;/a&gt;)&lt;/li&gt;&lt;li&gt;&lt;a href="https://mailbox.org/en/using-drive-with-webdav-for-linux/"&gt;WebDAV/Linux&lt;/a&gt;: Of course you can also access your data from your mailbox.org Office DRIVE using WebDAV. You can use the DAV protocol to access this data directly as a network drive, particularly as a Linux user.&lt;/li&gt;&lt;li&gt;&lt;a href="https://mailbox.org/en/work-in-progress/"&gt;OX Drive app for Windows&lt;/a&gt;: There is currently a technical problem in which the Windows app still denies SSL access. This is not a problem with Linux. We have contacted the manufacturer about this problem.&lt;/li&gt;&lt;li&gt;&lt;a href="https://mailbox.org/en/data-synchronization-with-the-outlook-connector-for-windows/"&gt;Outlook Connector&lt;/a&gt;: Here there are a number of different issues.&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Additional requests for us: Work in progress&lt;/h2&gt;&lt;p&gt;Many users have requested that we expand our service to include additional functions and features. See &lt;a href="https://mailbox.org/en/work-in-progress/"&gt;https://mailbox.org/en/work-in-progress/&lt;/a&gt; for a list of features we are currently working on. These new functions will be available for you as soon as possible. This page is updated frequently and also includes status reports about current problems or changes.&lt;/p&gt;&lt;h2&gt;Use of individual domains&lt;/h2&gt;&lt;p&gt;We were surprised by the number of requests we received for the use of individual mail domains at mailbox.org. Until now, we have always said that this is not possible. We didn’t expect that there would be this much interest. However, things have certainly changed. If you are interested in this service, you can follow the status of our work in the FAQ article: &lt;a href="https://mailbox.org/en/can-i-use-e-mail-addresses-from-my-own-domain-with-mailbox-org/"&gt;https://mailbox.org/en/can-i-use-e-mail-addresses-from-my-own-domain-with-mailbox-org/&lt;/a&gt;&lt;/p&gt;&lt;h2&gt;Questions or concerns? Compliments or criticisms?&lt;/h2&gt;&lt;p&gt;Thank you for your encouraging and motivating e-mails over the past few days – we received literally hundreds. There were also a number of lively discussions on Internet forums as well as on Facebook. Our colleagues are very pleased with this feedback. I mean, we have all spent weeks working overtime, nights, and weekends.&lt;/p&gt;&lt;p&gt;Feel free to contact our support team with any compliments, criticisms, and suggestions for improvement.&lt;/p&gt;&lt;p&gt;Please understand that it may take us a few days to respond to messages that are not urgent in nature. If you would like to really encourage our team (and other users) and share your opinions and experiences regarding our services, please feel free to leave a &lt;a href="https://mailbox.org/comments/"&gt;public comment on our feedback page&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;Sunny Greetings from Berlin!&lt;/p&gt;&lt;p&gt;Peer Heinlein&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-team.jpeg?itok=dGTTQB1f" type="image/jpeg" length="320376"/><guid isPermaLink="false">1987b016-c6c4-4fc7-96b1-9e4e38794c1c</guid>
    <pubDate>Mon, 24 Feb 2014 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>A look back at the early days of mailbox.org</dc:title>
    <dc:identifier>1987b016-c6c4-4fc7-96b1-9e4e38794c1c</dc:identifier>
    </item>
<item>
  <title>A look back at the early days of mailbox.org</title>
  <link>https://mailbox.org/en/news/look-back-first-few-days-mailbox/</link>
  <description>&lt;p&gt;We had hoped for positive feedback, but the response we received last Friday was nothing short of amazing. We were delighted to receive hundreds of positive, encouraging, and excited e-mails and we were touched by the fact that so many users invested a lot of time and energy in taking a close look at our service, asking questions, and offering serious suggestions for improvement.&lt;/p&gt;&lt;p&gt;Last Friday – within just a short period of time – over 2,000 users registered with our service and our support team took a special weekend shift to respond to around 500 support tickets and other requests for information. Thank you!&lt;/p&gt;&lt;h2&gt;Difficulties&lt;/h2&gt;&lt;p&gt;We had a few problems with regard to accessibility over the weekend and on Monday morning. Although we have a lot of experience operating large web and mail server clusters, we encountered two quirks involving the interaction between our Office software and our mail cluster that we had not discovered prior to this. Ultimately, we were faced with capacity problems and difficulties logging in to the web Office and connecting using CalDAV, etc. As of 11 a.m. today, these problems have been identified and resolved.&lt;/p&gt;&lt;p&gt;We apologize for any inconvenience. However, this weekend – particularly on Saturday – there were a number of serious problems at data centers in Düsseldorf and Berlin. These problems had nothing to do with our service and did not affect our servers. There were multiple denial-of-service attacks against another customer in those data centers, meaning that someone was trying to disrupt their servers. These attacks also affected all other users whose data was ‘just trying to squeeze by.’ Over the course of the day on Saturday, there were multiple ten-minute disruptions to different parts of the network in Germany. Again, this had nothing to do with us.&lt;/p&gt;&lt;p&gt;If you noticed a few strange things over the weekend, this may be the reason. Please try again. If you are still experiencing problems, contact our support team.&lt;/p&gt;&lt;p&gt;In addition, users are still having a few problems creating e-mail filters. In certain situations, the program fails to edit the e-mail filter and activate the encrypted mailbox. This error is not related to our servers; it is caused by problems in the Office interface. We have reported the bug to the manufacturer of the Office software and ask for your patience through the minor difficulties we are experiencing in the launch phase.&lt;/p&gt;&lt;h2&gt;Outlook, ActiveSync, Android Sync, WebDAV/Linux, OX Drive&lt;/h2&gt;&lt;p&gt;In short, it is questions about these services that make up the bulk of our customer inquiries. We have written a number of new Help articles to address these questions (Frequently Asked Questions = FAQ). Have a look at our Help section every so often: &lt;a href="https://mailbox.org/en/help/" title="https://mailbox.org/en/help/"&gt;https://mailbox.org/en/help/&lt;/a&gt;. We add new articles every few hours. Our support team is always on call working to answer each question individually. We want to answer all questions quickly and promptly, so please understand that for standard questions, we will often only have time to provide a short response with a link to our FAQ. Brief overview of the top five questions:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="https://mailbox.org/en/no-connection-with-outlook-2011-what-is-the-problem/"&gt;Outlook 2011:&lt;/a&gt; Doesn’t work because Outlook uses only RC4 SSL encryption, which is not trustworthy.&lt;/li&gt;&lt;li&gt;ActiveSync/smartphone synchronization: Works, but there are a few special conditions to note (&lt;a href="https://mailbox.org/en/data-synchronization-with-mac-os-x-and-windows/"&gt;Windows/Mac&lt;/a&gt;, &lt;a href="https://mailbox.org/daten-abgleich-mit-active-sync-auf-android-geraeten/"&gt;Android&lt;/a&gt;, &lt;a href="https://mailbox.org/en/data-synchronization-with-caldav-and-carddav-for-ios-devices-iphone-ipad"&gt;iOS&lt;/a&gt;)&lt;/li&gt;&lt;li&gt;&lt;a href="https://mailbox.org/en/using-drive-with-webdav-for-linux/"&gt;WebDAV/Linux&lt;/a&gt;: Of course you can also access your data from your mailbox.org Office DRIVE using WebDAV. You can use the DAV protocol to access this data directly as a network drive, particularly as a Linux user.&lt;/li&gt;&lt;li&gt;&lt;a href="https://mailbox.org/en/work-in-progress/"&gt;OX Drive app for Windows&lt;/a&gt;: There is currently a technical problem in which the Windows app still denies SSL access. This is not a problem with Linux. We have contacted the manufacturer about this problem.&lt;/li&gt;&lt;li&gt;&lt;a href="https://mailbox.org/en/data-synchronization-with-the-outlook-connector-for-windows/"&gt;Outlook Connector&lt;/a&gt;: Here there are a number of different issues.&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Additional requests for us: Work in progress&lt;/h2&gt;&lt;p&gt;Many users have requested that we expand our service to include additional functions and features. See &lt;a href="https://mailbox.org/en/work-in-progress/"&gt;https://mailbox.org/en/work-in-progress/&lt;/a&gt; for a list of features we are currently working on. These new functions will be available for you as soon as possible. This page is updated frequently and also includes status reports about current problems or changes.&lt;/p&gt;&lt;h2&gt;Use of individual domains&lt;/h2&gt;&lt;p&gt;We were surprised by the number of requests we received for the use of individual mail domains at mailbox.org. Until now, we have always said that this is not possible. We didn’t expect that there would be this much interest. However, things have certainly changed. If you are interested in this service, you can follow the status of our work in the FAQ article: &lt;a href="https://mailbox.org/en/can-i-use-e-mail-addresses-from-my-own-domain-with-mailbox-org/"&gt;https://mailbox.org/en/can-i-use-e-mail-addresses-from-my-own-domain-with-mailbox-org/&lt;/a&gt;&lt;/p&gt;&lt;h2&gt;Questions or concerns? Compliments or criticisms?&lt;/h2&gt;&lt;p&gt;Thank you for your encouraging and motivating e-mails over the past few days – we received literally hundreds. There were also a number of lively discussions on Internet forums as well as on Facebook. Our colleagues are very pleased with this feedback. I mean, we have all spent weeks working overtime, nights, and weekends.&lt;/p&gt;&lt;p&gt;Feel free to contact our support team with any compliments, criticisms, and suggestions for improvement.&lt;/p&gt;&lt;p&gt;Please understand that it may take us a few days to respond to messages that are not urgent in nature. If you would like to really encourage our team (and other users) and share your opinions and experiences regarding our services, please feel free to leave a &lt;a href="https://mailbox.org/comments/"&gt;public comment on our feedback page&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;Sunny Greetings from Berlin!&lt;/p&gt;&lt;p&gt;Peer Heinlein&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-team.jpeg?itok=dGTTQB1f" type="image/jpeg" length="320376"/><guid isPermaLink="false">1987b016-c6c4-4fc7-96b1-9e4e38794c1c</guid>
    <pubDate>Mon, 24 Feb 2014 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>A look back at the early days of mailbox.org</dc:title>
    <dc:identifier>1987b016-c6c4-4fc7-96b1-9e4e38794c1c</dc:identifier>
    </item>
<item>
  <title>Heise Online reports on the launch of mailbox.org</title>
  <link>https://mailbox.org/en/news/heise-online-reports-launch-mailbox/</link>
  <description>&lt;p&gt;Today’s Heise Online article about the launch of our new e-mail service reported: “The offer is very impressive – not only for its compliance with German data protection laws, but also, for security provided by its strong encryption system.” mailbox.org utilizes the proven GPG and SSL technologies, but unlike other solutions, the service provided by the Berlin-based company does not simply offer the option of using strong asymmetric keys and secure data transfer using SSL; this provider makes these measures mandatory upon user request. &lt;a href="http://www.heise.de/newsticker/meldung/Mailbox-org-Vollstaendig-verschluesselter-deutscher-E-Mail-Dienst-2120363.html" target="_blank" title="Heise Online" rel="noopener"&gt;http://www.heise.de/newsticker/meldung/Mailbox-org-Vollstaendig-verschluesselter-deutscher-E-Mail-Dienst-2120363.html&lt;/a&gt;&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-04/eigener-kommentar.png?itok=X4dWxdY_" type="image/png" length="134894"/><guid isPermaLink="false">6fe0007c-58ca-49b1-8e61-17916c0ff3f0</guid>
    <pubDate>Fri, 21 Feb 2014 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Heise Online reports on the launch of mailbox.org</dc:title>
    <dc:identifier>6fe0007c-58ca-49b1-8e61-17916c0ff3f0</dc:identifier>
    </item>
<item>
  <title>Heise Online reports on the launch of mailbox.org</title>
  <link>https://mailbox.org/en/news/heise-online-reports-launch-mailbox/</link>
  <description>&lt;p&gt;Today’s Heise Online article about the launch of our new e-mail service reported: “The offer is very impressive – not only for its compliance with German data protection laws, but also, for security provided by its strong encryption system.” mailbox.org utilizes the proven GPG and SSL technologies, but unlike other solutions, the service provided by the Berlin-based company does not simply offer the option of using strong asymmetric keys and secure data transfer using SSL; this provider makes these measures mandatory upon user request. &lt;a href="http://www.heise.de/newsticker/meldung/Mailbox-org-Vollstaendig-verschluesselter-deutscher-E-Mail-Dienst-2120363.html" target="_blank" title="Heise Online" rel="noopener"&gt;http://www.heise.de/newsticker/meldung/Mailbox-org-Vollstaendig-verschluesselter-deutscher-E-Mail-Dienst-2120363.html&lt;/a&gt;&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-04/eigener-kommentar.png?itok=X4dWxdY_" type="image/png" length="134894"/><guid isPermaLink="false">6fe0007c-58ca-49b1-8e61-17916c0ff3f0</guid>
    <pubDate>Fri, 21 Feb 2014 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Heise Online reports on the launch of mailbox.org</dc:title>
    <dc:identifier>6fe0007c-58ca-49b1-8e61-17916c0ff3f0</dc:identifier>
    </item>
<item>
  <title>Email provider with encrypted mailboxes</title>
  <link>https://mailbox.org/en/news/mailbox-first-e-mail-provider-fully-encrypted-mailboxes/</link>
  <description>&lt;p&gt;Under the motto "So that private things remain private", we are today presenting our new email provider "mailbox.org". In addition to a particularly securely encrypted e-mail inbox with calendar and contact management, we also want to impress you with mobile phone synchronisation, online text processing and a file storage system that can be used to securely exchange files between computers and mobile phones. With these many functions, we are your secure alternative to the major American providers.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-celebration.jpeg?itok=wIZsodf0" type="image/jpeg" length="326204"/><guid isPermaLink="false">49614f69-4d83-4a5a-a7b0-50c23e0d06e8</guid>
    <pubDate>Fri, 21 Feb 2014 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Email provider with encrypted mailboxes</dc:title>
    <dc:identifier>49614f69-4d83-4a5a-a7b0-50c23e0d06e8</dc:identifier>
    </item>
<item>
  <title>Email provider with encrypted mailboxes</title>
  <link>https://mailbox.org/en/news/mailbox-first-e-mail-provider-fully-encrypted-mailboxes/</link>
  <description>&lt;p&gt;Under the motto "So that private things remain private", we are today presenting our new email provider "mailbox.org". In addition to a particularly securely encrypted e-mail inbox with calendar and contact management, we also want to impress you with mobile phone synchronisation, online text processing and a file storage system that can be used to securely exchange files between computers and mobile phones. With these many functions, we are your secure alternative to the major American providers.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-05/news-celebration.jpeg?itok=wIZsodf0" type="image/jpeg" length="326204"/><guid isPermaLink="false">49614f69-4d83-4a5a-a7b0-50c23e0d06e8</guid>
    <pubDate>Fri, 21 Feb 2014 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Email provider with encrypted mailboxes</dc:title>
    <dc:identifier>49614f69-4d83-4a5a-a7b0-50c23e0d06e8</dc:identifier>
    </item>
<item>
  <title>Encrypted email Perfect Forward Secrecy</title>
  <link>https://mailbox.org/en/news/encrypted-e-mailing-perfect-forward-secrecy-pfs-and-ssl-tls/</link>
  <description>&lt;p&gt;Do you share the opinion that your data is for you and you alone to see? If so, you’ve come to the right place – fighting data snooping is what we do best.&lt;/p&gt;&lt;h3&gt;Here’s what we offer:&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;Encrypted SMTP, POP, IMAP mail access with SSL/TLS.&lt;/li&gt;&lt;li&gt;Encrypted webmail client access with SSL/TLS.&lt;/li&gt;&lt;li&gt;We use ‘real’ high-quality certificates.&lt;/li&gt;&lt;li&gt;Long-term security thanks to Perfect Forward Secrecy.&lt;/li&gt;&lt;li&gt;Support for setting up GPG and S/MIME.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;The SSL/TLS protocol for securely exchanging data between two networks has been around for nearly 20 years. The most well-known variant is undoubtedly https://, the secure version of http://. However, there are also ‘s’ versions for the SMTP, POP3, and IMAP mail protocols. For more than 15 years, discerning providers have been ensuring that their sending and receiving of e-mails via the public Internet always takes place via SSL/TLS-secured connections. However, many of the more well-known providers have shown little ambition over the past years to secure the e-mail traffic between them and other providers. Far too many ISPs only offered non-encrypted data communications for this, presumably to cut down on computing power (i.e., costs). Only with the advent of the NSA scandal did several larger German providers – such as GMX, web.de, and T-Online – lurch into action, widely promoting “secure mail traffic” since the summer of 2013. All this means, of course, is that they finally also adopted SSL/TLS 15 years down the track. In many cases, it’s still only a very perfunctory improvement…&lt;/p&gt;&lt;h3&gt;At Heinlein: Consistent Encryption for More Than 15 Years&lt;/h3&gt;&lt;p&gt;JPBerlin, our ISP for political security use, has been consistently offering encryption of all incoming and outgoing mail connections since the mid-1990s. This includes cutting-edge ‘Perfect Forward Secrecy’ (PFS), a special process that makes it impossible to decrypt previously-captured data traffic later on. Naturally, we’re also making use of PFS for mailbox.org.&lt;/p&gt;&lt;h3&gt;Our Webmail Client is Similarly Well Protected&lt;/h3&gt;&lt;p&gt;SSL/TLS protection is always granted via https:// whenever you access our webmail client. Naturally, we also make sure to use only the very best encryption algorithms – something you’d never notice on a user level. In early August 2013, the media focused on ‘Perfect Forward Secrecy’ (PFS) within SSL, which is designed to prevent data streams that are being captured today from being decrypted later on, such as years in the future. Many providers and operators of https websites do not support PFS. Our SSL sites as well as our webmail client, on the other hand, have been making use of PFS for several years already.&lt;/p&gt;&lt;h3&gt;There’s Still More To Do&lt;/h3&gt;&lt;p&gt;Encryption via SSL/TLS secures data communication via the Internet, protecting it against unauthorized access. In the source and destination networks, on the other hand, the e-mails are not encrypted at all; otherwise, the users wouldn’t be able to read their own e-mails. What this means is that the administrators of a provider (i.e., us) theoretically have access to their users’ e-mail contents, much like a mailman being able to read postcards or unsealed letters. Because of this, we recommend to take a more thorough approach and implement ‘true’ e-mail encryption based on GPG or S/MIME. With these, you can ensure that absolutely no one, apart from the actual sender and recipient, can read an e-mail’s contents.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-04/mailbox-news-und-updates-sicherheit.jpg?itok=4LMJmUnZ" type="image/jpeg" length="194998"/><guid isPermaLink="false">d8d0cc51-66ec-423c-85ea-6ae20d5d8157</guid>
    <pubDate>Thu, 13 Feb 2014 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Encrypted email Perfect Forward Secrecy</dc:title>
    <dc:identifier>d8d0cc51-66ec-423c-85ea-6ae20d5d8157</dc:identifier>
    </item>
<item>
  <title>Encrypted email Perfect Forward Secrecy</title>
  <link>https://mailbox.org/en/news/encrypted-e-mailing-perfect-forward-secrecy-pfs-and-ssl-tls/</link>
  <description>&lt;p&gt;Do you share the opinion that your data is for you and you alone to see? If so, you’ve come to the right place – fighting data snooping is what we do best.&lt;/p&gt;&lt;h3&gt;Here’s what we offer:&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;Encrypted SMTP, POP, IMAP mail access with SSL/TLS.&lt;/li&gt;&lt;li&gt;Encrypted webmail client access with SSL/TLS.&lt;/li&gt;&lt;li&gt;We use ‘real’ high-quality certificates.&lt;/li&gt;&lt;li&gt;Long-term security thanks to Perfect Forward Secrecy.&lt;/li&gt;&lt;li&gt;Support for setting up GPG and S/MIME.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;The SSL/TLS protocol for securely exchanging data between two networks has been around for nearly 20 years. The most well-known variant is undoubtedly https://, the secure version of http://. However, there are also ‘s’ versions for the SMTP, POP3, and IMAP mail protocols. For more than 15 years, discerning providers have been ensuring that their sending and receiving of e-mails via the public Internet always takes place via SSL/TLS-secured connections. However, many of the more well-known providers have shown little ambition over the past years to secure the e-mail traffic between them and other providers. Far too many ISPs only offered non-encrypted data communications for this, presumably to cut down on computing power (i.e., costs). Only with the advent of the NSA scandal did several larger German providers – such as GMX, web.de, and T-Online – lurch into action, widely promoting “secure mail traffic” since the summer of 2013. All this means, of course, is that they finally also adopted SSL/TLS 15 years down the track. In many cases, it’s still only a very perfunctory improvement…&lt;/p&gt;&lt;h3&gt;At Heinlein: Consistent Encryption for More Than 15 Years&lt;/h3&gt;&lt;p&gt;JPBerlin, our ISP for political security use, has been consistently offering encryption of all incoming and outgoing mail connections since the mid-1990s. This includes cutting-edge ‘Perfect Forward Secrecy’ (PFS), a special process that makes it impossible to decrypt previously-captured data traffic later on. Naturally, we’re also making use of PFS for mailbox.org.&lt;/p&gt;&lt;h3&gt;Our Webmail Client is Similarly Well Protected&lt;/h3&gt;&lt;p&gt;SSL/TLS protection is always granted via https:// whenever you access our webmail client. Naturally, we also make sure to use only the very best encryption algorithms – something you’d never notice on a user level. In early August 2013, the media focused on ‘Perfect Forward Secrecy’ (PFS) within SSL, which is designed to prevent data streams that are being captured today from being decrypted later on, such as years in the future. Many providers and operators of https websites do not support PFS. Our SSL sites as well as our webmail client, on the other hand, have been making use of PFS for several years already.&lt;/p&gt;&lt;h3&gt;There’s Still More To Do&lt;/h3&gt;&lt;p&gt;Encryption via SSL/TLS secures data communication via the Internet, protecting it against unauthorized access. In the source and destination networks, on the other hand, the e-mails are not encrypted at all; otherwise, the users wouldn’t be able to read their own e-mails. What this means is that the administrators of a provider (i.e., us) theoretically have access to their users’ e-mail contents, much like a mailman being able to read postcards or unsealed letters. Because of this, we recommend to take a more thorough approach and implement ‘true’ e-mail encryption based on GPG or S/MIME. With these, you can ensure that absolutely no one, apart from the actual sender and recipient, can read an e-mail’s contents.&lt;/p&gt;
</description>
  <enclosure url="https://mailbox.org/sites/default/files/styles/w800/public/2025-04/mailbox-news-und-updates-sicherheit.jpg?itok=4LMJmUnZ" type="image/jpeg" length="194998"/><guid isPermaLink="false">d8d0cc51-66ec-423c-85ea-6ae20d5d8157</guid>
    <pubDate>Thu, 13 Feb 2014 00:00:00 +0100</pubDate>
    <source url="https://mailbox.org/en/feed.rss">Mailbox</source>
    <dc:title>Encrypted email Perfect Forward Secrecy</dc:title>
    <dc:identifier>d8d0cc51-66ec-423c-85ea-6ae20d5d8157</dc:identifier>
    </item>
</channel>
</rss>
