Case file · Email
Tuta
The strongest zero-access model in the category - it encrypts the subject line, attachments, contacts and calendar, not just the body, so it cannot read your stored mail. Genuinely no-KYC. A 2020 German court order forced monitoring of named accounts going forward, but even then it could not decrypt existing end-to-end-encrypted mail.
The systematized overview
The bureau vs the internet.
8.7/10 · No identity required
Tuta has the strongest at-rest encryption of any mainstream provider: end-to-end encryption covers not just the message body but the subject line, attachments, contacts and calendar, so Tuta genuinely cannot read your stored mail. Signup needs no phone, alternate email or name, even over Tor. The defining case is a 2020 German court order (upheld by the Federal Court of Justice) forcing Tuta to build a monitoring function on a named account - but crucially it could only expose future, non-end-to-end mail, not decrypt anything already encrypted. Native Monero checkout is the main gap.
3 recurring praises · 2 recurring gripes
Most praised: best-in-class encryption (subject + metadata included). Most cited downside: no native monero / crypto checkout.
We track our editorial score and community sentiment separately — neither moves the other. Read together, they're the systematized overview.
The facts
Jurisdiction, sign-up & encryption.
- Jurisdiction
- Tutao GmbH, Hanover, Germany
- Sign-up needs
- No phone, alternate email or name; Tor-friendly (free tier may face manual approval)
- KYC trigger
- None at signup; a court can compel prospective monitoring of a named account
- Encryption
- End-to-end at rest incl. subject line, attachments, contacts + calendar - strongest in class
- Provider access
- Cannot decrypt stored mailboxes; future plaintext-path mail exposable only under a targeted court order
- Anon. payment
- Card/PayPal native; Monero/BTC only via donations or a third-party proxy store (no native checkout)
- Logging
- Minimal; German data-protection regime
- Open source
- Yes (clients)
- Audited
- Community-reviewable; open-source clients
- Custom domain
- Custom domains on paid plans
- Free tier
- Yes
- Since
- 2011 (as Tutanota; rebranded Tuta 2023)
The full read
Our analysis, in plain words.
Tuta has the most thorough encryption model of any mainstream provider. Where others encrypt the message body but leave the subject line and metadata readable, Tuta end-to-end encrypts the subject, attachments, contacts and calendar too, and states plainly in its transparency report that it cannot decrypt the data stored in mailboxes. Signup asks for nothing identifying - no phone, alternate email or name - and works over Tor. On the two axes that matter most, encryption and no-KYC signup, it is best-in-class.
The defining event tells you exactly where the limit sits. In 2020 a German court, upheld by the Federal Court of Justice, ordered Tuta to build a monitoring function on a named account in a blackmail case, exposing future incoming and outgoing mail for up to three months. Critically, mail that was already end-to-end encrypted could not be decrypted even then - the order only reached future, plaintext-path messages. That is the honest boundary of secure email: a provider can be compelled to watch a specific account going forward, but strong at-rest encryption still protects your stored history.
The gaps are modest. There is no native Monero checkout (crypto is only accepted for donations or via a third-party proxy), and free accounts sometimes wait on a manual anti-abuse approval. Neither undermines the core proposition. Tuta sits just behind Posteo in our scoring, held there mainly by the payment-privacy gap and the documented monitoring case - not by any failure of its encryption, which is its strongest feature.
The score, broken down
How the 8.7 is built.
Privacy
weight 50%What identity, data and metadata the service can demand or collect.
90 × 50% = 4.5 of 10
Trust
weight 30%Whether it can technically deliver what it claims — code, audits, age.
85 × 30% = 2.5 of 10
Reliability
weight 20%Whether the no-KYC claim holds under real-world pressure.
82 × 20% = 1.6 of 10
Weighted total 8.7 / 10 · no reliability rule triggered, so the score stands. See the rubric →
Every point, sourced
What earned the score.
Privacy
The fine print, read for you
The clause they bury.
“The encrypted data stored in Tuta mailboxes can not be decrypted by us. [Under a 2020 court order] Tuta was required to release unencrypted incoming and outgoing messages of named accounts going forward - it could not decrypt already end-to-end-encrypted mail.”
What it meansThis is the most important nuance in private email. A court can compel a provider to start monitoring a specific account, exposing future mail that travels in plaintext (e.g. to or from a non-encrypting provider). But mail that was already end-to-end encrypted stayed unreadable even under the order. So Tuta cannot betray your stored history - the limit is future messages on named accounts, not a mass or retroactive capability.
Read the source →None to sign up. Tuta requires no phone, alternate email or name for a free account, and signup works over Tor (free accounts may hit a manual anti-abuse approval delay). The limit on privacy is not signup but a court order: German courts can compel prospective monitoring of a named account, but only future plaintext-path mail is exposed, never already-encrypted mail. We rate it KYC level 1.
Policy review — point by point
-
Full zero-access encryption
End-to-end encryption covers subject, attachments, contacts and calendar; Tuta states it cannot decrypt stored mailboxes. ↗
-
No-KYC signup
No phone, alternate email or name required, even over Tor. ↗
-
Court-ordered prospective monitoring
A 2020 order (upheld by the BGH) compelled monitoring of named accounts’ future plaintext mail; already-encrypted mail stayed unreadable. ↗
-
No native Monero
Monero/BTC are accepted only via donations or a third-party proxy store, not native checkout. ↗
Tuta operates under German law. German courts can compel prospective monitoring of a specific account (as the 2020 case showed), but the reach is limited to future plaintext-path mail because Tuta cannot decrypt already-encrypted data. Its transparency report and warrant canary (no NSLs/FISA/gag orders) are primary sources; the monitoring case is documented in court reporting.
We keep watching
Incident & policy timeline.
- 2020-2021
Court-ordered account monitoring (upheld by the Federal Court of Justice)
A Cologne court, upheld by Germany’s Federal Court of Justice, ordered Tuta to implement a monitoring function releasing unencrypted incoming/outgoing mail of a named account in a blackmail case, going forward for up to three months. Already end-to-end-encrypted mail could not be decrypted even under the order.
source ↗ - 2023
Rebranded Tutanota to Tuta
Tutanota rebranded to Tuta, continuing its encrypted-by-default model and open-source clients.
source ↗ - 2025
Transparency report: rejects ~75% of requests
Tuta’s H2 2025 transparency report shows it rejected about 75% of all requests in 2025, released limited inventory/traffic data under valid orders, and maintains a warrant canary (no NSLs/FISA/gag orders, no backdoors).
source ↗
The verdict
Where it stands.
Strengths
- Encrypts subject line, attachments, contacts and calendar - not just the body
- No phone, alternate email or name at signup (Tor-friendly)
- Open-source clients; German jurisdiction; strong transparency reporting
- Cannot decrypt already-encrypted stored mail, even under court order
Trade-offs
- No native Monero checkout (donations / third-party proxy only)
- Court can compel prospective monitoring of named accounts (future plaintext-path mail)
- Free accounts may face a manual approval delay
Across the internet
What reviewers report.
Consistently praised
- Best-in-class encryption (subject + metadata included)
- Genuinely anonymous, Tor-friendly signup
- Open source and strong transparency reporting
Recurring complaints
- No native Monero / crypto checkout
- Free-tier approval delays
Privacy communities rate Tuta at or near the top for encryption depth and no-KYC signup; the recurring gripes are the lack of native crypto payment and occasional free-tier approval friction. The court-monitoring case is widely discussed as the model of a targeted, non-retroactive order. Synthesized from Tuta primary sources and privacy-community reviews.
Keep exploring
Related lists & categories.
Ask the bureau
Tuta, common questions.
Is Tuta no-KYC?
Yes. A free Tuta account needs no phone number, alternate email or name, and signup works over Tor (with a possible manual approval delay). We rate it KYC level 1 - identity-free in practice.
Can Tuta read my email?
No, not your stored mail. Tuta’s end-to-end encryption covers the body, subject line, attachments, contacts and calendar, and its transparency report states the encrypted data in mailboxes cannot be decrypted by Tuta. Mail to and from non-encrypting providers travels in plaintext on that leg, which is the usual email limit.
Didn’t a court force Tuta to monitor accounts?
Yes - in 2020 a German court (upheld by the Federal Court of Justice) ordered Tuta to build a monitoring function on a named account in a blackmail case, releasing future unencrypted mail for up to three months. But it could not decrypt mail that was already end-to-end encrypted. It is a targeted, forward-looking order, not a retroactive or mass-surveillance capability.
Your exact case not covered? The live Ask the bureau answers it and turns it into a public FAQ.