703 words
November 15, 2023
4 minutes read
Is Countermail the most secure email service ?
Introduction

Claims
They claim to only provide email metadata to Swedish authorities after reviewing the requests with their lawyers which is also the claimed to be the case with ProtonMail and Tuta/Tutanota. According to their assertions, the metadata shared in this case would only include email recipients and subjects, which is standard since this information cannot be encrypted with PGP as it needs to be known to the mail server. Additionally, they assert that they do not store nor have the capability to log client IP addresses.
Cons
There are also privacy issues; they lack a Tor domain (which seems unusual for a service of this type), and they do not accept Monero. Unfortunately, the limited acceptance of Monero is a common issue, with Tuta/Tutanota being the only email service that supports Monero through a proxy seller.
CounterMail also doesn’t have any open-source clients. The issue goes further as they don’t even have any client. Even their password manager named SafeBox needs to be accessed in the account settings. Not that I would have used it anyway as it lacks many modern functions.
They also don’t have their own data centers nor even their own IP addresses, which could pose issues as they have less control over their infrastructure compared to, for example, ProtonMail or Tuta/Tutanota.
The last issues may not be problematic for the majority of people but could be viewed as concerns for others. Firstly, this is an invite-only service, which might seem unusual for a privacy-focused service to limit access in such a way (though they are not the only ones, and I understand the desire to control access). Secondly, they are relatively expensive, with a price slightly higher than ProtonMail Plus despite offering a lot less functionalities and updates. They also do not offer any free-plan (there is only a 7 day free trial).
Conclusion
To really conclude, I think that the only matter is that you can’t see the server code nor config for all of the services of this type. So you need to trust someone and this choice is personal. I can understand why someone would trust countermail more than for example ProtonMail but I don’t.