When a client brings up "encrypted email" or "private email," Tuta is one of the first names they will have encountered. The German email service, formerly called Tutanota until it rebranded in late 2023, has built a genuine following among privacy-conscious users and has crossed ten million accounts. For an MSP or hosting reseller, the more relevant question is not whether Tuta is a good service in the consumer sense. It is whether Tuta can be integrated into a managed email practice: provisioned through a billing system, supported through standard tools, and migrated to or from without manual steps. This article works through each of those questions with the answers Tuta's own architecture produces.

Table of Contents

Key Takeaways

Point Details
No IMAP, POP3, or SMTP on any plan Tuta blocks all standard protocols by design. Clients cannot use Outlook, Thunderbird, or Apple Mail regardless of plan tier.
EUR pricing, no reseller path Essential €6/user/month, Advanced €8/user/month, Unlimited €12/user/month (yearly). No wholesale tier, no partner program.
Migration out requires manual export Standard IMAP migration tools cannot connect to Tuta accounts. Moving a client off Tuta requires Tuta's own export step first.
Business admin console is functional Tuta Business includes password resets and a sign-in-as-user feature for support, which is more admin-accessible than some zero-knowledge services.
Narrow valid use case Tuta is the right recommendation for clients with genuine confidentiality requirements who accept proprietary app dependency. It is not a general-purpose MSP platform.

What Tuta Is and Why MSP Clients Ask About It

Tuta (previously Tutanota) is a German end-to-end encrypted email service based in Hanover. The rebrand from Tutanota to Tuta in late 2023 reflected the company's expansion beyond email into an encrypted communications platform covering calendar, contacts, and notes. End-to-end encryption is Tuta's defining feature: messages between Tuta users are encrypted on the sender's device before leaving it, so neither Tuta's servers nor anyone intercepting traffic can read the content. Messages sent from Tuta to non-Tuta recipients use a shared password mechanism for secure delivery instead of standard email encryption.

Coverage in privacy and technology media means the Tuta name circulates widely enough that business clients encounter it without MSP involvement. The practical result is a recurring support question: a client who has read about "encrypted email" asks whether their business should be using it. Answering that question well requires understanding what Tuta provides at the business tier and where the encryption architecture creates constraints that affect how an MSP can support and bill for it. Understanding what white-label email hosting actually means for the reseller side of that comparison helps frame what is different here.

Tuta's Business Plans and Pricing

Tuta's business offering comes in three tiers, all billed yearly and priced in euros. The pricing below is taken from Tuta's business page:

Plan Price (yearly billing) Storage per user Custom domains
Essential €6/user/month 50 GB 3
Advanced €8/user/month 500 GB 10
Unlimited €12/user/month 1 TB Unlimited

Each business plan includes an administration console with user management, password resets, multiple admin roles, and a sign-in-as-user feature that lets admins access a mailbox for direct support. That last capability is worth noting: unlike Proton Mail, where the zero-knowledge architecture means an admin cannot access user mailbox contents at all, Tuta Business explicitly provides this browser-based access path through its own panel. If admin support access is a concern, Tuta's business plans address it.

What is absent at every tier is a reseller or partner pricing program. Tuta sells directly to businesses. There is no wholesale rate, no distributor tier, no partner agreement, and no mechanism to bill clients through an MSP's own invoice with a margin attached. An MSP who sets a client up on Tuta has no revenue relationship with that subscription going forward. The client pays Tuta directly, in euros, and the MSP earns nothing from the recurring line item.

The Protocol Barrier: No Outlook, No Thunderbird

The constraint that most directly affects MSP deployments is Tuta's handling of standard email protocols. Tuta does not support IMAP, POP3, or SMTP access on any plan, personal or business. This is not a missing feature that a higher tier unlocks. It is an architectural decision built into how the encryption works: because Tuta encrypts messages on the client side before they reach the server, a server-side protocol like IMAP, which is designed to let any authorized client fetch and read messages stored on the server, cannot coexist with a zero-knowledge design.

The consequence for MSPs is direct: a client on Tuta cannot configure Outlook, Thunderbird, Apple Mail, or any other standard email client to send and receive through their Tuta account. Every user must use Tuta's own web app, desktop app, or mobile app exclusively. For businesses where every user is already comfortable with a specialized app and does not rely on Outlook, this is a manageable constraint. For most small business clients, Outlook or Apple Mail is the email client they already have and expect to keep. There is no configuration path that makes those work with Tuta.

The comparison to Proton Mail's approach to this same problem is instructive. Proton provides Proton Bridge, a local application that translates Proton's encrypted storage into a local IMAP/SMTP interface so Outlook and Thunderbird can connect. Tuta has no equivalent bridge application, and as of September 2026 has not announced one. For any client account where users rely on standard desktop email clients, this is a hard no rather than a configuration challenge.

The practical impact on an MSP's support queue is predictable. A client who cannot access their email in the application they normally use generates a support ticket immediately. The answer, "you need to use the Tuta app," resolves the technical issue but creates a workflow change the client did not anticipate, one that falls on the MSP to explain and manage.

The Migration Problem: What No IMAP Actually Costs You

The protocol limitation affects more than desktop client access. It also blocks standard migration tooling in both directions, which matters to any MSP who needs to move clients between providers as a routine operation.

Moving mail into Tuta from a conventional IMAP provider is workable. Tuta provides an importer in its own interface that accepts IMAP credentials from a source account and pulls messages across. An MSP migrating a client onto Tuta can use that path. The source provider just needs to support standard IMAP, which covers Gmail, Google Workspace, Microsoft 365, and any conventional hosted mail platform.

Moving mail out of Tuta is a different problem. Because Tuta provides no IMAP endpoint, any tool that works by connecting to the source account as an IMAP client cannot connect. That includes the built-in IMAP migration available in Atriomail, third-party migration services, and most manual approaches. A client who wants to move off Tuta must first use Tuta's own export function to download a local copy of their mail, and then work with the destination provider to import that data. That sequence requires coordinated manual steps from the client, which increases both friction and the risk of data loss compared to a direct IMAP pull. For MSPs managing email across multiple client domains, that dependency on the client completing a manual export step before migration can begin is a meaningful workflow constraint that does not exist with any IMAP-capable provider.

The Billing and Provisioning Gap

Beyond the protocol questions, Tuta has no native integration with WHMCS or Blesta, and no provisioning API documented for automated create, suspend, and terminate operations. An MSP who provisions a new client mailbox, bills for it on a consolidated invoice, and deprovisions it when the client churns needs to handle each step manually in Tuta's admin panel, then reconcile the client's billing separately in whatever system they use. The gap here is the same one that affects most direct-to-business email products: the platform is not designed for the create-many-manage-many workflow that automated billing in WHMCS and Blesta is built to handle.

The billing currency also runs in euros with no USD option. For MSPs billing their own clients in USD, that introduces currency exposure that an in-USD provider does not create. Tuta's pricing is published and stable, but for multi-client email managed under a single practice the combination of direct-to-client EUR billing and no WHMCS integration means Tuta cannot function as a white-label platform in the way that a reseller-designed product does.

This is not a product quality criticism. Tuta is designed and priced as a direct-to-consumer and direct-to-business product, which is exactly what its architecture and feature set reflect. The category mismatch is the issue: the requirements of a 1-15 person MSP managing 20 to 200 client mailboxes are structurally different from the requirements of a single business buying email seats for its own staff.

When Tuta Makes Sense for a Client

The architectural constraints above are real, but they exist for a deliberate reason. Tuta's design serves a specific set of clients well, and an honest assessment of the product says so clearly.

Tuta is a strong match for clients with genuine confidentiality requirements: journalists protecting sources, lawyers handling sensitive case materials, activists or NGO workers in environments where surveillance is a real concern, or individual executives with documented reasons to distrust third-party data access, including the email provider itself. For those clients, end-to-end encryption covering message bodies, subjects, and calendar events, combined with German jurisdiction under GDPR and no advertising-based data model, provides meaningful protection that a conventional email provider running SPF, DKIM, and DMARC cannot match. The threat model is different, and Tuta addresses it correctly.

Tuta also works well for self-sufficient individual users or technically capable small teams who are comfortable adopting proprietary apps and do not depend on Outlook or Apple Mail for existing workflows. The web and mobile applications are well-regarded in the privacy community and cover standard email functionality capably. For a small business where every user is a technical founder or a developer who prefers browser-based tools, the app-only constraint is not a constraint in practice.

The line is clear: if a client's interest in encrypted email is general unease rather than a specific threat model, and if they rely on Outlook or any non-Tuta client, the architectural constraints will produce more support friction than the privacy benefit justifies. Those clients are better served by strong authentication defaults on a conventional platform.

Where Atriomail Fits

When the business case is managed email for 20 to 200 client mailboxes, provisioned through a billing system, supported through standard tools, and migrated without manual export steps, the architecture that Tuta's privacy model prevents is exactly what a dedicated reseller platform is built to deliver.

Atriomail's wholesale price is $1.39 per mailbox per month, with 15 GB included and no contract. At 50 mailboxes, that is $69.50/month wholesale. Billed to clients at $5 per mailbox, the same 50-mailbox account generates $250/month, leaving $180.50/month in recurring margin. Tuta has no wholesale tier, so the client pays Tuta directly and the MSP earns $0/month from that subscription regardless of plan tier.

Tuta (no reseller program, client pays Tuta directly) $0/mo White-label email hosting ($5/mailbox billed) $180.50/mo $0 $50 $100 $150 $200
Monthly recurring margin on a 50-mailbox client. Tuta has no reseller program, so the margin is structural, not a pricing difference.

Each mailbox Atriomail provisions gets SPF, DKIM, and DMARC records published automatically across 15 supported DNS providers, so deliverability is handled at setup rather than added manually per domain. IMAP, POP3, and SMTP are all fully supported, so Outlook, Thunderbird, and Apple Mail connect immediately on any client device with no special application required. The built-in IMAP migration tool can pull from Gmail, Google Workspace, Microsoft 365, Yahoo, or any other IMAP source and deliver it to the new mailbox without a manual export step on either end.

WHMCS and Blesta native modules handle provisioning, suspension, and termination through the billing system, so each client mailbox creates and removes itself as a line item on the monthly invoice. The per-mailbox pricing model means the MSP's cost tracks exactly with the client's actual usage rather than a flat subscription that may be over or under capacity. White-label branding is an optional add-on for practices where the platform identity matters to the client relationship. Full pricing details and the margin calculator are on the pricing page.

For clients who specifically need end-to-end encrypted email for a documented confidentiality reason, Tuta or a comparable service is the right recommendation. For the broader book of small business clients who need professional email on their own domain, managed at scale through standard tooling, the per-mailbox model is the structure that fits that requirement. More on the operational side of running email across multiple client domains in the guide to white-label email for agencies.

Atriomail admin panel mailboxes screen showing per-mailbox management with IMAP access

Mailbox management in the Atriomail panel. Every mailbox supports IMAP, POP3, and SMTP, so Outlook and any standard client connect without additional applications.

Frequently Asked Questions

More on migration tools and billing setup in the full FAQ.

Can I resell Tuta to clients and earn a margin on it?

No. Tuta has no reseller or partner pricing program. The client pays Tuta directly in euros, and the MSP earns nothing from the recurring subscription. You can recommend Tuta for appropriate clients as a service, but the billing relationship is between Tuta and the client with no intermediary margin.

Can clients keep using Outlook or Apple Mail if they move to Tuta?

No. Tuta blocks IMAP, POP3, and SMTP by design across all plan tiers. Standard email clients cannot connect to Tuta accounts. Every user must access their email through Tuta's own web app, desktop application, or mobile app. There is currently no bridge application that creates a local IMAP interface the way Proton Bridge does for Proton Mail users.

If a client wants to leave Tuta later, can I migrate them with standard tools?

Not directly. Standard IMAP migration tools cannot connect to Tuta because Tuta provides no IMAP endpoint. The client must first use Tuta's own export feature to download a local copy of their mail data, which you then import at the destination provider. This adds manual client-facing steps that a direct IMAP-to-IMAP migration does not require, and it means the migration timeline depends on the client completing the export before you can proceed.

Does Tuta's business plan give admins any visibility into user mailboxes?

Yes, through Tuta's own admin panel. Tuta Business includes password resets and a sign-in-as-user feature that lets admins access a mailbox for support purposes. This is a browser-based flow through Tuta's interface and is separate from the IMAP/SMTP question: it does not create a protocol endpoint that third-party clients can connect to.

Latest from the blog