Why This Matters for SMEs Right Now
By 2026, the email address has long since become more than just a communication channel; it's the central anchor point for a company's digital identity. Whether cloud services, banking, or customer communication — almost everything runs through the inbox. The BSI emphasizes that with an estimated 150 million active addresses in Germany, email remains cybercriminals' favorite target.
For SMEs, the threat landscape is particularly precarious. Around 12% of cybercrime victims in 2024 reported being affected by phishing. A successful attack here can lead not only to data loss but to a complete operational standstill. The call for "Security by Design" and "Security by Default" in email programs is therefore no longer a theoretical discussion, but an economic necessity.
The Central Role of the Email Client in the Company
An email client is far more than just a user interface. It manages credentials, consolidates multiple accounts, and structures all communication across different devices. For an SME, it functions as both archive and control center. In the second quarter of 2025, the BSI identified a total of 26 products on the market and subjected the 12 most relevant — from Apple Mail to Tuta Mail — to an in-depth analysis.
The goal of this study is to establish a foundation for digital consumer protection. It shows that email security doesn't end at sending — it begins with choosing the tool used to process it.
Encryption: The Shield for Trade Secrets
The confidentiality of messages is the top priority. The BSI draws a strict distinction here between transport and content encryption.
Transport Encryption (TLS)
All 12 programs examined support transport encryption via TLS. This secures the path of data between the program and the server (point-to-point). Without this foundation, every email would be like a postcard that any mail carrier could read.
End-to-End Encryption (E2EE)
Only E2EE offers true security for sensitive data. Here, the content is encrypted on the sender's device and can only be decrypted again by the recipient — not even the email provider has access.
- S/MIME: A certificate-based standard that primarily ensures authenticity and integrity in commercial environments.
- OpenPGP: A decentralized model ("web of trust") that operates without a central authority.
The BSI found that 9 out of 12 programs enable E2EE use, although integration (native vs. plugin) varies significantly. Programs like Thunderbird, Betterbird, and eM Client offer exemplary native support here.
Phishing and Spam Protection: Technical Barriers Against Fraud
Phishing targets identity theft and the installation of malware. While spam is often just annoying, phishing is an existential threat to SMEs.
The study found that nearly all programs (11 out of 12) have junk filters. However, the quality of warnings for suspicious links or attachments varies dramatically:
- Warning mechanisms: Only some programs actively scan incoming mail for known fraud patterns and explicitly warn users before they open a risky link.
- Attachment scanning: Only 3 out of 12 programs check attachments (e.g., for file type or malicious patterns) and display warnings or use quarantine folders.
SMEs should prefer programs that analyze metadata in the header to better identify spoofed sender addresses.
Data Sovereignty: Local Storage vs. Cloud Dependency
An often-underestimated factor is where emails and credentials are stored.
"The chosen storage location determines who bears responsibility for security. Local storage requires you to implement your own protective measures, while cloud solutions increase dependency on the provider."
- Local storage: Most programs (e.g., Thunderbird, Apple Mail, eM Client) store emails locally. This allows full control but requires the SME to handle its own disk encryption and antivirus protection.
- Cloud processing: Programs like the new Outlook use cloud infrastructure. Here, email content and account data are processed on the provider's servers. This offers synchronization benefits but carries risks in terms of data protection and dependency.
Tracking Prevention: How to Stop Spying in Your Inbox
Tracking pixels in HTML emails let senders find out when, how often, and from where an email was opened. This isn't just a data protection risk — it can also be exploited for targeted social engineering attacks.
The BSI recommends that programs block external images by default or use a proxy connection to mask the recipient's IP address. Plain text format also offers a significant security advantage, as it prevents embedded scripts and tracking from the outset.
Consequences of the Software Choice for Data Protection in SMEs
Choosing a software is a decision about the level of protection for the entire company. Ineffective security measures lead to:
- Economic pressure: Data loss results in high compliance costs and fines.
- Reputational damage: A successful phishing attack that spreads via the company's email damages trust with partners and customers.
- Loss of data sovereignty: If emails are synchronized with cloud infrastructures without proper review, the SME may lose exclusive control over sensitive information.
Strategic Recommendations for IT Decision-Makers
When choosing a secure email program for business use, the following criteria should be met:
- Require encryption: Use E2EE (S/MIME or OpenPGP) for internal and external communication of sensitive content.
- Security by default: Choose programs that block external content by default.
- Account protection: Use programs that support modern authentication methods like OAuth2, enabling multi-factor authentication (MFA).
- Use a master password: If credentials are stored locally, a master password is essential to make it harder for malware to read them.
- Ensure you stay up to date: Enable automatic updates to benefit from vendors' ongoing security improvements.
Conclusion: Responsibility Through Technology Choices
The 2026 BSI report makes it clear: there's no "perfect" program, but there are informed decisions. While cloud-based services offer convenience, locally installed open-source solutions like Thunderbird or KMail enable greater data sovereignty. For SMEs, transparency about data flows is the prerequisite for security. Those who do their homework when choosing an email program build a robust foundation for their company's digital future.
FAQ
Why is the distinction between transport and content encryption important?
Why is the distinction between transport and content encryption important?
Transport encryption only secures the transmission path. Only content encryption (E2EE) ensures that the message remains protected on the server and at the provider as well.
Do existing employees also need to be informed about new security requirements?
Do existing employees also need to be informed about new security requirements?
Yes, technical protection measures can be circumvented through social engineering. Regular awareness-raising is just as important as software configuration.
Are open-source programs more secure?
Are open-source programs more secure?
Open-source programs (such as Thunderbird or KMail) allow independent review of the source code for security vulnerabilities, which increases transparency and trust.
What happens if my program doesn't support E2EE?
What happens if my program doesn't support E2EE?
In this case, users often have to switch to external add-on software or browser-based solutions, which can limit usability.






