Forward Email
United States · forwardemail.net · 13 vendors
Forward Email is a free and open-source email service offering custom domain email forwarding, hosting with IMAP, POP3, and SMTP, and encrypted mailbox storage. Founded in 2017, the company emphasizes privacy and security, serving over 1.6 million domains globally. It provides a comprehensive email platform with features like spam and phishing protection, unlimited aliases, and a developer API.
Resilience scores
- Digital Sovereignty: 62
- Digital Resilience: 6
- Financial Resilience: 6
Technology vendors
- Canonical Ltd. — Technology — United Kingdom
- GoDaddy Inc. — Technology — United States
- Stripe, Inc. — Financial Services — United States
- and 10 more
Services catalogue
2 services in catalogue across 1 category; runs on 13 sub-vendors.
- Email Service
- Forward Email
Insights
Last updated 2026-08-04 · revision 1
13 direct vendors, 142 subvendors
Direct vendors by controlling owner country (sample)
- United States: 8
- United Kingdom: 3
- Germany: 2
Subvendors by controlling owner country (sample)
- Norway: 1
- Japan: 2
- Netherlands: 2
Migration Readiness: 8/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Forward Email exhibits high migration readiness. The internal tech stack is modern, featuring Node.js, Redis, and MongoDB, which are highly suitable for cloud-native and microservices architectures. The company's use of automation tools like Ansible and process managers like PM2 indicates mature operational practices conducive to migration. A significant strength is the existing leverage of multiple cloud/hosting providers (DigitalOcean, Vultr), suggesting experience with multi-cloud environments and reducing lock-in to a single IaaS provider. The availability of a 'Self-hosted option' for products further implies a portable architecture. Furthermore, no specific data residency requirements or complex regulatory environments are noted, which simplifies potential migration efforts. However, the use of SQLite, even with encryption, could present challenges for horizontal scaling in a fully distributed, cloud-native migration, potentially requiring re-architecting or alternative database solutions for certain components. Financial data (revenue concentration, growth history) is missing, making it impossible to assess the company's financial capacity to fund a significant migration project. The 'Vendor Lock-in Risk: Unknown' means potential hidden complexities with existing service contracts cannot be evaluated, though the named providers are generally flexible.
Compliance
8 in-scope frameworks identified; showing 3.
SOC 2 (source) — Partially Compliant
Forward Email is a cloud-based email service provider — a category for which SOC 2 Type II is a widely expected industry standard, particularly for enterprise and government customers. The company's security page explicitly states 'SOC 2 Type II audited processes' under the Compliance section, and notes that infrastructure is hosted in 'SOC 2 compliant data centers.' However, there is no publicly disclosed SOC 2 Type II audit report, no AICPA certification seal, and no attestation letter available on the website. The distinction between 'SOC 2 compliant data centers' (referring to their hosting providers) and a SOC 2 audit of Forward Email's own systems is important. Risk is Medium because: (1) the company claims SOC 2 Type II audited processes but provides no verifiable report; (2) enterprise and government customers (US Naval Academy, Linux Foundation, Canonical) likely require SOC 2 evidence; (3) absence of a public report creates uncertainty about scope and findings.
Evidence: https://forwardemail.net/en/security, https://forwardemail.net/pentest-report_forward-email.pdf, https://forwardemail.net/technical-whitepaper.pdf
GDPR (source) — Compliant
Forward Email is a US-based company (Forward Email LLC) that explicitly processes personal data of EU/EEA residents as part of its global email service (500K+ users, 1.6M+ domains). GDPR is therefore fully applicable. The company has proactively addressed GDPR compliance with a dedicated GDPR page, a Data Processing Agreement (DPA), appointed EU and UK Article 27 representatives (via Osano International Compliance Services Limited in Dublin, Ireland and Osano UK Compliance LTD in Belfast), and published a detailed privacy policy. Risk is rated Medium rather than Low because: (1) the company relies on several sub-processors (DataPacket, DigitalOcean, Vultr, PayPal) that are NOT Data Privacy Framework (DPF) certified, creating residual international transfer risk; (2) as a small company, ongoing GDPR operational compliance (DSARs, breach notifications, DPO appointment) may be resource-constrained; (3) no independent third-party GDPR audit has been publicly disclosed. The open-source codebase and zero-knowledge architecture significantly reduce the risk of data misuse.
Evidence: https://forwardemail.net/en/gdpr, https://forwardemail.net/dpa, https://forwardemail.net/en/privacy, https://forwardemail.net/en/security, https://gdpr-info.eu/art-27-gdpr/
ECPA — Compliant
Forward Email's zero-knowledge architecture is specifically designed to prevent the company itself from accessing user email content, which aligns with ECPA's protections against unauthorized interception of electronic communications. The company processes email in-memory and does not persistently store content unless required for IMAP/POP3. The open-source codebase allows independent verification of these claims. Risk is Low because the technical architecture minimizes the company's access to communications content.
Evidence: https://forwardemail.net/en/security, https://forwardemail.net/en/privacy, https://github.com/forwardemail/forwardemail.net
Financials
Three-year financials
- 2025:
- 2024:
- 2023:
Financial Resilience Score: 6/10
Forward Email LLC is a privately held, bootstrapped US company with no publicly disclosed financial statements, making a precise resilience score difficult. However, qualitative indicators suggest moderate-to-good resilience. The company has operated for 9+ years (since 2017), which is notable in the email industry where the company itself acknowledges 80% failure rates. It appears to be founder-owned with no known outside investors, meaning no debt servicing or dilution pressure, and it controls its own runway. The recurring SaaS subscription model with tiers at $3, $9, and $250/month provides predictable cash flow, and the customer base is extremely diversified across 1.6M+ domains and 500,000+ users with no apparent single-customer concentration risk. High-profile reference customers span government (US Naval Academy, Government of South Australia), technology (Canonical/Ubuntu, Netflix Games, Linux Foundation, jQuery), education (Cambridge, Univ. of Maryland, Tufts), and media (Fox News Radio, Disney Ad Sales), signaling trust and product-market fit. Infrastructure cost discipline is evident from migration to bare-metal servers (Vultr, Digital Ocean, DataPacket) rather than expensive hyperscaler cloud. Independent validation includes a Cure53 security audit (June 2026) and a Trustpilot rating of 4.9/5. Key risks temper the score: complete absence of financial transparency creates due-diligence hurdles for enterprise buyers; key-person concentration on founder Nicholas Baugh with a very small team; free-tier infrastructure cost drag; and intense competition from Google Workspace, Microsoft 365, Proton Mail, Fastmail, Zoho, and free Cloudflare Email Routing that caps pricing power. Single-vendor infrastructure dependency at each migration stage and no visible succession plan add operational risk.
Key strengths: Bootstrapped, founder-owned with no external debt or VC dilution pressure, Recurring SaaS subscription revenue model with predictable cash flow, Highly diversified customer base of 1.6M+ domains and 500,000+ users, Marquee enterprise/government/education customers (US Naval Academy, Canonical, Cambridge, Netflix Games), 9+ year operating history in an industry with high failure rates, Infrastructure cost discipline via bare-metal server strategy, Independent Cure53 security audit and Trustpilot 4.9/5 rating, Global reach with 25+ language support
Risk factors: Zero financial transparency (no audited financials disclosed), Key-person concentration on founder Nicholas Baugh, Very small team (likely single-digit to low double-digit headcount), Free-tier infrastructure cost drag with reliance on conversion economics, Intense competition from Google, Microsoft, Proton, Fastmail, Zoho, and free Cloudflare Email Routing, Low price ceiling on consumer tiers ($3-$9/month), Email forwarding services vulnerable to spam/phishing abuse, Single-vendor infrastructure dependency at each migration stage, No visible succession or business continuity plan
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.