← all articles

Proton Mail vs Tuta (Tutanota) in 2026: Full Comparison

In September 2021, Proton handed a Swiss court the IP address tied to one of its Mail accounts, because a judge ordered it to and Swiss law left no room to say no. The account belonged to a climate activist involved in a Paris protest, the request had gone through Europol, and Proton complied. It’s the single most cited case in any Proton vs Tuta argument, and it’s a useful place to start because it says something both companies would rather you learn from a marketing page: encrypted email protects the contents of your mail from the provider and from anyone intercepting it in transit. It does not make the provider immune to its own country’s courts.

I’ve run Proton Mail as my main inbox for about six years, two paid accounts across personal and work. I moved a chunk of client correspondence over to Tuta more recently to see whether the fuss about its own encryption protocol held up day to day. Both are real, both are good, and neither is the universal answer half the privacy subreddits want it to be.

This is a comparison, not a eulogy for Gmail. If you’re just trying to figure out what shows up when someone looks you up, or what a phone number attached to your accounts actually exposes, those are separate problems from which encrypted mail provider you pick, and I’ve covered them elsewhere on the blog.

TL;DR comparison table

Proton Mail Tuta (Tutanota)
Pricing Free (1GB); Mail Plus ~$4.99/mo; Unlimited bundle ~$9.99/mo, billed annually Free (1GB); Revolutionary ~€3/mo; Legend ~€6/mo, billed annually
Features VPN, Drive, Pass, and Calendar bundled on Unlimited; Bridge app for IMAP/SMTP; Scribe AI drafting Encrypted calendar and contacts built in; subject-line encryption; post-quantum TutaCrypt
Encryption OpenPGP (RFC 4880); body encrypted, subject line is not Proprietary hybrid protocol; body and subject line both encrypted
Jurisdiction Switzerland (Geneva), Proton AG Germany (Hannover), under GDPR
Support Help center, ticketed email support, active community forum Help center, ticketed email support, smaller community
Target user People consolidating VPN, password manager, and mail under one bill; non-technical switchers People who want the protocol itself to go further, and want the full stack open source

Proton Mail at a glance

Proton Mail launched in 2014, built by a group of scientists and engineers who’d worked at CERN, and it’s still run out of Geneva by Proton AG, the same company behind Proton VPN, Proton Drive, Proton Pass, and Proton Calendar. It’s the biggest name in encrypted email by a wide margin, tens of millions of accounts, and the scale shows in the product: fast search, a mobile app that doesn’t feel like an afterthought, and a composer that in late 2024 picked up Scribe, a locally-hosted AI writing assistant for drafting and rewriting mail without your prompts leaving Proton’s infrastructure. If you’re shopping for AI writing tools more broadly, aitoolgazette.com tracks that category in more depth than I will here, Scribe is a nice bonus, not the reason to pick Proton.

The core pitch hasn’t changed since 2014: mail between Proton accounts is end to end encrypted using OpenPGP, Proton can’t read it, and the clients ship as open source, so a security researcher can check the claim instead of taking Proton’s word for it. Proton Mail lays out the details straight from the source if you want to go deeper than this piece.

Tuta (Tutanota) at a glance

Tuta started life as Tutanota, founded in 2011 out of Hannover, Germany, and dropped the “nota” in a 2024 rebrand. tuta.com is the current domain, tutanota.com still redirects there. It’s smaller than Proton and stays narrow on purpose, no separate VPN product, no password manager, calendar and contacts live inside the mail product itself rather than as add-ons you buy separately.

The pitch is that Tuta didn’t adopt PGP and call it a day, it built its own encryption from the ground up, encrypting subject lines and calendar entries along with the message body, and in 2024 it became one of the first mainstream email providers to ship post-quantum encryption by default instead of as an opt-in beta. It’s also more aggressively open source than Proton, publishing server-side code alongside the clients. Tuta explains the technical reasoning on its own site if you want the protocol details in full.

Head-to-head

Threat model it actually addresses

Both solve the same core problem: the provider can’t read mail sent between two accounts on its own service, because the decryption keys are derived from your password and never leave your device in usable form. That’s real, and it’s the main thing separating either of them from Gmail, Outlook, or Yahoo, which do scan mail content, for spam filtering, ad ranking, abuse detection, pick whichever justification you find least annoying.

What neither one solves: mail to someone on Gmail arrives as plaintext at Gmail’s servers unless you’re both correctly using PGP, which almost nobody actually does. Metadata, who emailed whom, how often, when, is visible to the provider regardless, and a contact pattern is frequently more useful to an investigator than the message body would have been anyway. And if your adversary already has a foothold on your device, a keylogger, a compromised browser extension, encryption in transit and at rest does nothing for you. Email encryption stops passive scanning and third-party interception. It doesn’t stop a targeted attacker who’s already inside.

Encryption and protocol

Proton uses OpenPGP, the open standard defined in RFC 4880, implemented client-side through the OpenPGP.js library. Mail between two Proton accounts encrypts automatically. Mail to an external PGP user works if you exchange public keys, which Proton smooths over but still involves real key management. Mail to someone with no PGP key at all goes out as a password-protected link instead. One quirk worth knowing: standard PGP doesn’t encrypt the subject line, only the body, that’s a limitation baked into the spec itself, not a Proton choice.

Tuta skipped PGP entirely. It runs its own scheme, historically AES-256 symmetric plus RSA-2048 asymmetric, and since 2024 layers in what Tuta calls TutaCrypt, a hybrid protocol that adds a post-quantum key exchange on top of the existing elliptic-curve exchange, from the same Kyber family NIST finalized as its ML-KEM standard in August 2024. Because Tuta owns the whole protocol instead of implementing someone else’s standard, it encrypts the subject line too. The tradeoff: Tuta’s encryption doesn’t interoperate with anyone else’s PGP setup. It’s Tuta talking to Tuta for true end to end encryption, full stop.

Jurisdiction and logging policy

Proton is Swiss, based in Geneva. Switzerland isn’t in the EU and isn’t part of the intelligence-sharing arrangements people cite constantly (Five Eyes and its extensions), which is a real point in its favor. But Switzerland has its own surveillance law and its own courts, and the 2021 case above shows those courts can and do issue orders that reach Proton. Proton didn’t have a historical IP log to hand over, its default is not to log, but it was ordered to start logging on that one account going forward, and it complied because Swiss law gave it no basis to refuse. Proton has since said it pushes back harder on scope. I still tell people not to rely on email encryption alone if their threat model includes a government coming after them by name, pair it with a no-log VPN or Tor for the connection itself.

Tuta is German, based in Hannover, squarely under GDPR and German telecom law. Germany has its own history of pushing providers toward lawful interception, in one documented case a German court ordered Tuta to enable monitoring of future incoming mail on a specific account under investigation. Since Tuta can’t retroactively decrypt content it already stored, the order was narrower than it sounds, and Tuta fought the scope publicly rather than quietly complying. Neither country is a safe harbor the way marketing copy implies. Both have functioning courts that can compel a company operating on their soil, the real difference is which legal system and which precedent you’re betting on.

Independent audits

Proton’s cryptography runs on OpenPGP.js, which has been through multiple rounds of audit by Cure53, a firm that does this professionally, and Proton publishes the reports. Proton Pass, the password manager bundled into the higher tiers, got its own audit from Securitum. None of that makes Proton bulletproof, audits catch known bug classes, not everything, but there’s a paper trail you can go read.

Tuta’s paper trail is thinner. The apps are open source and anyone can read the code, which is worth something on its own, but I couldn’t find the same volume of named, dated, third-party audit reports Proton publishes. That’s not an accusation Tuta is hiding anything, most email providers I’ve looked at over the years publish nothing at all, Tuta is still ahead of Gmail or Outlook here. It’s just behind Proton specifically.

Open source status

Both ship open source apps, which matters more than it sounds, closed-source crypto asks you to trust the vendor’s word instead of letting anyone check it. Proton publishes its web, iOS, Android, Bridge, and VPN client code on GitHub, plus OpenPGP.js. What stays closed is the backend, the servers that store the encrypted blobs and route mail, Proton has never open sourced that part.

Tuta goes further and open sources its server code too, not just the clients. Whether that actually changes your practical risk, you still can’t verify what’s running in production without reproducible builds and a way to check the deployed binary matches the repo, is a fair question. But it’s a genuine difference in how far each company is willing to go, and Tuta is right to bring it up.

Platform coverage

Proton works with normal mail clients. Pay for a plan that includes Bridge, a small local app that translates Proton’s encryption into standard IMAP/SMTP, and you can point Thunderbird, Outlook, or Apple Mail at your Proton inbox like any other account. Native apps exist too, for web, iOS, Android, and desktop.

Tuta doesn’t, on purpose. No IMAP, no SMTP, no Bridge equivalent. You use Tuta’s web app, its iOS or Android app, or its desktop app, full stop. Tuta’s argument is that IMAP was never designed with end to end encryption in mind, and bolting it on reopens the local-storage and metadata leakage they built their own protocol to avoid. I get the argument. It’s still a real inconvenience if your workflow depends on a unified inbox across five accounts in one client.

Pricing

Proton’s free tier gives you 1GB and one address. Mail Plus runs about $4.99 a month on the annual plan and adds storage, custom domains, and the Bridge app. Most people land on Proton Unlimited instead, around $9.99 a month annually, because it bundles Mail with Proton VPN, Drive, Pass, and Calendar under one price, genuinely useful if you were going to buy a VPN and a password manager separately anyway. I’ve weighed that bundle math against the competition in Proton VPN vs NordVPN if it matters to your decision.

Tuta’s free tier is also 1GB. Paid plans are Revolutionary at roughly €3 a month and Legend at roughly €6 a month, both billed annually, both cheaper than Proton’s equivalents once you convert. Tuta doesn’t bundle a VPN or password manager into anything, it’s an email company and stays one, so comparing it against Proton Unlimited isn’t really apples to apples unless you were never buying those extra tools anyway.

Usability for non-technical people

Proton’s onboarding is closer to what a normal person expects from webmail. Search behaves the way Gmail’s search behaves, the interface doesn’t ask you to understand public and private keys, and sending a password-protected email to someone outside Proton is a checkbox, not a PGP key exchange. I’ve set Proton Mail up for my mother. It went fine.

Tuta’s interface is plain, honestly a little dated next to Proton or Gmail, but it’s not harder to use day to day, the encryption happens invisibly the same way. Where it gets friction-y is search: because subject lines and bodies are encrypted client-side, Tuta’s search has historically been slower and more limited than Proton’s, though local indexing has been closing that gap. Two-factor setup is standard TOTP or a security key on both services, nothing unusual, I’ve written up what actually stops phishing versus what just feels safer, if you want the deeper version of that question.

Use-case verdicts

Journalist or activist corresponding with sources: edge to Tuta, mainly for subject-line encryption and a protocol that wasn’t built to interoperate with a standard that leaks headers by design. Pair it with Tor Browser regardless, the mail provider was never going to solve connection-level anonymity on its own.

Someone who wants one subscription covering VPN, password manager, and mail: Proton, clearly. Proton Unlimited at roughly $9.99 a month replaces three separate subscriptions with one, and the apps talk to each other.

Setting up a first encrypted inbox for a non-technical family member: Proton. Familiar interface, better search, documentation that assumes less prior knowledge.

Small business that wants a custom domain on a stack that’s open source top to bottom, including the server: Tuta. Proton’s backend stays closed no matter which plan you’re on.

Who should pick Proton Mail

  • you already pay for a VPN or password manager and would rather consolidate into one Swiss company and one invoice
  • you need to keep using Thunderbird, Outlook, or Apple Mail through Bridge instead of switching apps entirely
  • you’re setting this up for someone who finds new software stressful and wants an interface that behaves like the webmail they already know
  • you want a longer, published audit trail before trusting a provider with years of stored mail

Who should pick Tuta (Tutanota)

  • subject lines matter to you as much as message bodies, and you don’t want to lean on standard PGP’s gaps
  • you want every layer of the stack, client and server, open to inspection, not just the apps
  • you’re fine living entirely inside Tuta’s own apps and don’t need IMAP access from a third-party mail client
  • post-quantum resistance shipped today matters more to you than interoperability with existing PGP contacts

Verdict overall

Neither one is wrong. If I had to bet which holds up better against a government that specifically wants your mail, I’d lean Tuta on protocol design, subject-line encryption and post-quantum key exchange already shipped, not promised. I’d lean Proton on ecosystem and polish. For most readers here, people trying to get off Gmail without a headache, or wanting to fold VPN and password manager spend into one bill, Proton is the one I recommend first. For people whose work puts them in a government’s crosshairs specifically, I’d want Tuta’s subject-line encryption, and I’d still pair either service with a separate no-log VPN or Tor for the connection itself, because the mail provider was never going to solve that part alone.

I keep this updated as pricing and audit reports change. More comparisons like it live on the blog.

Written by Xavier Fok

disclosure: this article may contain affiliate links. if you buy through them we may earn a commission at no extra cost to you. verdicts are independent of payouts. last reviewed by Xavier Fok on 2026-09-15.

from the team
Want a real mobile IP, not a datacenter VPN endpoint?

Shared VPN exit nodes get flagged and blocked. Singapore Mobile Proxy runs real 4G/5G mobile IPs that give you a residential-grade address carriers still trust.

see how it works →
read on
More from The Privacy Wire

VPN and tool reviews, realistic opsec guides, and privacy news for people who want to protect their data.

browse all articles →