ProtonMail vs Tuta 2026: Which Encrypted Email Wins?
ProtonMail and Tuta are the two dominant encrypted email providers. Here's how they compare on privacy, features, pricing, and usability in 2026.
ProtonMail and Tuta (formerly Tutanota) have been competing for the same users for years: people who want email that isn’t mined for advertising and want genuine end-to-end encryption. Both deliver on that core promise. The differences lie in the details.
The Core Privacy Promise
Both providers use end-to-end encryption for messages sent between users on their own platform. If you send a ProtonMail-to-ProtonMail message, the content is encrypted in a way that Proton’s servers cannot read it. Same for Tuta-to-Tuta. This is the baseline you should expect from any serious encrypted email provider.
Where it gets more interesting — and where the providers differ — is what happens when you send to outside addresses, how metadata is handled, and what’s encrypted beyond message body.
ProtonMail: The More Feature-Complete Option
ProtonMail has been around since 2013 and has grown into a full privacy suite. The email service is joined by ProtonVPN, Proton Drive, Proton Calendar, and Proton Pass (password manager). If you’re building a privacy stack, there’s a case for keeping it in the Proton ecosystem.
Encryption model: ProtonMail uses PGP under the hood. This means you can export your keys and use them elsewhere. When sending to non-Proton addresses, you can either send unencrypted (like regular email), or send with a password that the recipient uses to decrypt via a link. PGP compatibility is also possible with external tools.
Metadata: ProtonMail encrypts the message body but the subject line is not encrypted by default (though you can set it). Sender, recipient, and timestamp metadata is retained in server logs for a limited period for abuse prevention. Switzerland jurisdiction means GDPR application and Swiss privacy law, which is among the stricter regimes.
Custom domains: Available on paid plans. Setup is standard: add MX records, verify ownership, configure DKIM and SPF, all of which our SPF, DKIM, and DMARC guide covers record by record.
Pricing: Free tier allows 1 GB storage, one address, limited features. Paid plans start around $4/month and scale up for the full ecosystem bundle.
Desktop client: No native desktop app. You can use ProtonMail Bridge (paid feature) to connect ProtonMail to standard email clients like Thunderbird or Apple Mail via IMAP. This is a significant convenience trade-off for users who want a native app.
Tuta: More Radical Encryption
Tuta takes a stricter approach to encryption. Where ProtonMail uses PGP, Tuta uses its own hybrid encryption scheme that encrypts the subject line, message body, and attachments — and extends that encryption to the local calendar and contacts. The result is that Tuta can read even less of your data than ProtonMail.
Encryption model: Tuta’s scheme is not PGP-compatible. You cannot export Tuta keys and use them in GPG. When sending to external addresses, you set a shared password. The recipient receives a link and decrypts using the password you share out-of-band. This is similar to ProtonMail’s approach but there’s no option for PGP to external users. Per Tuta’s own security documentation, the service has also moved from AES-256 and RSA-2048 to a post-quantum scheme combining ECDH (X25519) with Kyber-1024, and encrypts “all data by default: Email, calendars, contacts,” including subject lines, calendar entries, and attachment metadata — categories ProtonMail leaves exposed.
Metadata: Tuta encrypts the subject line by default — this is a notable differentiator. Sender/recipient metadata is still visible to Tuta, as it has to be for routing purposes, but the subject and body are protected even from their servers.
Custom domains: Available on paid plans.
Pricing: Free tier is generous: 1 GB storage, one address. Paid plans start around €3/month. Generally slightly cheaper than Proton equivalents.
Desktop client: Tuta has native desktop apps (Windows, macOS, Linux) built with Electron. No bridge required. For users who want a standalone app, this is a real advantage over ProtonMail’s bridge-required approach.
How They Handle Outside Mail
This is where most people’s real-world usage hits a wall. If you switch to an encrypted email provider but your contacts use Gmail, most of your email still isn’t end-to-end encrypted — because it’s crossing from your encrypted provider to an unencrypted one.
Both ProtonMail and Tuta handle this the same way at the conceptual level: for external addresses, you can send an encrypted message protected by a password, with the recipient accessing it via a link. This is fine for occasional sensitive communication but impractical as a default.
For standard email to Gmail, Yahoo, or Outlook addresses, both providers send it as regular SMTP email. The message is encrypted in transit (TLS) but not end-to-end. Proton and Tuta’s servers can see the plaintext, and so can the destination server.
This is not a failure of these providers — it’s a limitation of email as a protocol. Truly end-to-end encrypted communication requires both parties to use compatible tools.
Jurisdiction: Switzerland vs Germany, and what it actually means
If your threat model includes a subpoena, a stalker with a lawyer, or a government records request, jurisdiction matters more than pricing or desktop apps. Both countries have relatively strong data protection law by global standards, but “strong privacy law” and “cannot be compelled to disclose data” are different claims, and both providers have a paper trail showing exactly where their protection ends.
Proton has stated it “cannot legally comply with foreign requests that are not supported by Swiss authorities,” and that under Article 271 of the Swiss Criminal Code it may not transmit data directly to a foreign government. In practice this routes foreign law-enforcement requests through Swiss authorities and mutual legal assistance treaties rather than blocking them. Proton’s own transparency report shows the volume that produces: Proton Mail received 9,301 legal orders in 2025 and complied with 8,313; in 2024 it received 11,023 and complied with 10,368. Proton VPN, by contrast, denied all 59 orders it received in 2025 because it keeps no activity logs to hand over — a useful reminder that “no-logs” and “responds to legal orders” are not contradictory when there is genuinely nothing stored.
That treaty pathway is not theoretical. In a case reported by 404 Media, investigators sent a request through Swiss authorities for subscriber and payment information tied to a Proton Mail address linked to the “Defend the Atlanta Forest” movement. Swiss authorities supplied a payment identifier in January 2024, which the FBI used to trace and identify the account holder. Message content stayed encrypted; the payment metadata, which sits outside end-to-end encryption because a payment provider processes it under financial-regulation requirements, did not.
Tuta’s jurisdiction produced a different outcome in its one high-profile test. A German regional court in Cologne ordered Tuta to monitor a specific account in a blackmail investigation, under a telecommunications law requiring providers to support lawful intercepts, as reported by CyberScoop. Tuta could comply only for the portion of that account’s traffic that was not already end-to-end encrypted. Mail encrypted between Tuta users was not something Tuta held keys to decrypt, court order or not. The distinction matters: Tuta can be compelled to build monitoring capability, and was. What it cannot do is decrypt ciphertext it never had the key for.
The honest reading of both records: jurisdiction reduces exposure to unilateral foreign requests but does not eliminate it, and both companies comply with lawful process in their home country at a high rate when it does not involve breaking encryption they do not control. If your threat model is “keep my email content unreadable by the provider,” both hold up, and neither has ever produced decrypted message content because neither has ever held the keys. If your threat model includes “an investigator with legitimate legal process wants to identify me through metadata, payment records, or a recovery address,” neither Swiss nor German incorporation stops that.
Which One to Choose
Choose ProtonMail if:
- You want PGP compatibility for advanced use cases
- You’re building a broader privacy stack (VPN, Drive, Calendar)
- You need to integrate with existing email clients via IMAP
- You prefer a more established product with a longer track record
Choose Tuta if:
- Subject-line encryption matters to you
- You want a native desktop app without a bridge
- You’re comfortable with Tuta’s proprietary encryption scheme
- Price is a consideration (Tuta is slightly cheaper)
Either works if:
- You primarily communicate within your chosen provider’s ecosystem
- Your main goal is escaping Google/Microsoft’s advertising data collection
- You want a Swiss or German jurisdiction (Proton is Swiss, Tuta is German)
Neither is a silver bullet for email privacy. Both protect you from the provider reading your content. Neither protects metadata fully. Neither solves the fundamental problem of sending email to people who don’t use encrypted providers.
A Note on Switching
Switching email providers is more disruptive than switching most services. Consider running both in parallel during a transition period; our Gmail to ProtonMail migration plan sets out that parallel period as a sequence of phases rather than a single cutover. Most people find it practical to move new account signups and sensitive correspondence to the encrypted provider while keeping an existing address for legacy contacts and low-stakes mail.
If your primary goal is anonymity against a well-resourced adversary rather than day-to-day privacy from advertisers and casual snooping, treat either provider as one layer, not the whole strategy. Pair it with separation between your real identity and the account’s payment method and recovery contact, because those two remain outside end-to-end encryption on every mainstream provider.
FAQ
Does ProtonMail encrypt subject lines?
Not by default. ProtonMail encrypts the message body while the subject line remains readable to Proton’s infrastructure, and sender, recipient, and timestamp metadata is retained in server logs for a limited period for abuse prevention. Tuta encrypts the subject line by default as part of a scheme that also covers calendar entries, contacts, and attachment metadata. Subject-line exposure is the clearest single difference between the two services.
Is Tuta compatible with PGP?
No. Tuta uses its own hybrid encryption scheme rather than PGP, so keys cannot be exported and used in GPG or any other external PGP toolchain. ProtonMail uses PGP under the hood, which allows key export and interoperability with outside tools. Anyone who already corresponds using PGP keys will find ProtonMail the compatible choice; Tuta’s scheme is self-contained by design.
Has ProtonMail ever handed data to law enforcement?
Yes, through lawful process. Proton’s own transparency report records 9,301 legal orders received in 2025 with 8,313 complied with, and 11,023 received in 2024 with 10,368 complied with. In one reported case, Swiss authorities supplied a payment identifier tied to a Proton Mail account, which investigators then used to identify the account holder. Message content stayed encrypted throughout, because Proton does not hold the keys.
Does Swiss or German jurisdiction protect an account better?
Neither eliminates legal exposure. Proton states it cannot legally comply with foreign requests unsupported by Swiss authorities, which routes those requests through mutual legal assistance treaties rather than blocking them. A German court separately ordered Tuta to monitor a specific account under telecommunications intercept law, and Tuta complied for the traffic that was not already end-to-end encrypted. Both resist unilateral foreign requests; neither resists domestic lawful process.
Can either provider send encrypted email to a Gmail address?
Only through a password-protected link. Both ProtonMail and Tuta let the sender protect an external message with a shared password, which the recipient uses to decrypt through a browser. That works for occasional sensitive correspondence but is impractical as a default. Ordinary mail to Gmail, Yahoo, or Outlook goes out as standard SMTP, encrypted in transit by TLS but readable at the destination server. What Google can see on its side of that exchange is set out in Proton Mail vs Gmail on privacy.
Where to Go From Here
If this comparison has not settled it, the encrypted email provider matcher applies your hard requirements as knockout filters rather than preferences, which usually resolves the decision faster than reading another table.
Once you have chosen: the ProtonMail setup guide and the Tuta setup guide cover account creation on each side, and the Proton Mail settings reference covers the configuration that comes after — Sentinel, address verification, Bridge server settings, and custom-domain DMARC.
Sources
Related
Best Encrypted Email Providers 2026: Proton Mail vs Tuta
The best encrypted email providers of 2026 compared: Proton Mail for ecosystem depth, Tuta for encryption coverage, Mailfence for PGP interoperability.
Best Free Encrypted Email Account: Tuta vs Proton Mail
The best free encrypted email accounts for 2026: Tuta for encryption depth, Proton Mail for ecosystem breadth, and Mailfence for PGP interoperability.
Tuta Setup Guide: Getting Started with Encrypted Email
A step-by-step guide to setting up Tuta, formerly Tutanota: account creation, the privacy settings worth changing, and migrating your existing mail.