🆕 Software Suggestion | Migadu #1856

Open
opened 2020-04-23 14:52:19 +00:00 by freddy-m · 6 comments
freddy-m commented 2020-04-23 14:52:19 +00:00 (Migrated from github.com)

Basic Information

Name: Migadu
Category: Email
URL: https://www.migadu.com/
Jurisdiction: Switzerland

Description

Migadu is an independent email hosting from Switzerland.

Why I am making the suggestion

The service is open source and offers unlimited domains on as many emails as a user could want.

Encryption:

  • Allow users to use their own domain name.
  • Supports standard email access protocols. (IMAP, POP3, SMTP).

Privacy:

  • Doesn't require personally identifiable information (PII) besides username and password.
  • Privacy policy that meets the requirements defined by the GDPR

Security:

  • Allows 2FA,
  • Supports DNSSEC
  • Website uses HTTPS and Subresource Integrity
  • Registered on the EFF's STARTTLS-Everywhere
  • No TLS errors/vulnerabilities when being profiled by tools such as Hardenize or Qualys SSL Labs, this includes certificate related errors, poor or weak ciphers suites, weak DH parameters such as those that led to Logjam.
  • Valid DANE records.
  • Valid DMARC, SPF and DKIM
  • Valid MTA-STS and TLS-RPT policy

Trust:

  • Public-facing leadership or ownership.

Marketing:

  • Complies with DNT, no poor claims.
  • Must self host analytics (no Google Analytics etc).

My connection with the software

I have used the software.

  • I will keep the issue up-to-date if something I have said changes or I remember a connection with the software.
## Basic Information **Name:** Migadu **Category:** Email **URL:** https://www.migadu.com/ **Jurisdiction:** Switzerland ## Description Migadu is an independent email hosting from Switzerland. ## Why I am making the suggestion The service is [open source](https://github.com/migadu/) and offers unlimited domains on as many emails as a user could want. Encryption: - [x] Allow users to use their own domain name. - [x] Supports standard email access protocols. (IMAP, POP3, SMTP). Privacy: - [x] Doesn't require personally identifiable information (PII) besides username and password. - [x] Privacy policy that meets the requirements defined by the GDPR **Security:** - [x] Allows 2FA, - [x] Supports DNSSEC - [x] Website uses HTTP**S** and Subresource Integrity - [x] [Registered](https://starttls-everywhere.org/results/?migadu.com) on the EFF's STARTTLS-Everywhere - [x] No TLS errors/vulnerabilities when being profiled by tools such as [Hardenize](https://www.hardenize.com/report/migadu.com/1587654402) or [Qualys SSL Labs](https://www.ssllabs.com/ssltest/analyze.html?d=www.migadu.com), this includes certificate related errors, poor or weak ciphers suites, weak DH parameters such as those that led to Logjam. - [x] Valid DANE records. - [x] Valid DMARC, SPF and DKIM - [x] Valid MTA-STS and TLS-RPT policy **Trust:** - [x] Public-facing leadership or ownership. Marketing: - [x] Complies with DNT, no poor claims. - [x] Must self host analytics (no Google Analytics etc). ## My connection with the software I have used the software. - [x] I will keep the issue up-to-date if something I have said changes or I remember a connection with the software.
freddy-m commented 2020-04-26 18:17:14 +00:00 (Migrated from github.com)

Doesn't fit the requirements after testing against guidelines. Will contact them and reopen the issue if this changes.

Doesn't fit the requirements after testing against guidelines. Will contact them and reopen the issue if this changes.
freddy-m commented 2020-08-12 16:30:39 +00:00 (Migrated from github.com)

Reopening this issue, because we have been in contact with the Migadu team.

Reopening this issue, because we have been in contact with the Migadu team.
gary-host-laptop commented 2020-09-27 13:16:08 +00:00 (Migrated from github.com)

@freddy-m What did they say?

@freddy-m What did they say?
merlinscholz commented 2021-02-13 22:16:38 +00:00 (Migrated from github.com)

The original issue seems to be outdated, there is no Google Tag Manager on the homepage (https://www.migadu.com/) anymore.

The original issue seems to be outdated, there is no Google Tag Manager on the homepage (https://www.migadu.com/) anymore.
freddy-m commented 2021-02-14 11:06:00 +00:00 (Migrated from github.com)

Ahh, will update accordingly.

Ahh, will update accordingly.
mishushakov commented 2021-03-02 19:46:52 +00:00 (Migrated from github.com)

note that hosting is in France

This may come as a surprise, but we do not host our servers in Switzerland. Current data centers are located in France. We may in the near future add Swiss data centers too but this is not our priority.

from https://www.migadu.com/procon/#in-switzerland-but-servers-are-not

note that hosting is in France > This may come as a surprise, but we do not host our servers in Switzerland. Current data centers are located in France. We may in the near future add Swiss data centers too but this is not our priority. from https://www.migadu.com/procon/#in-switzerland-but-servers-are-not
This repo is archived. You cannot comment on issues.
No Milestone
No Assignees
1 Participants
Due Date
The due date is invalid or out of range. Please use the format 'yyyy-mm-dd'.

No due date set.

Dependencies

No dependencies set.

Reference: privacyguides/privacytools.io#1856
No description provided.