xmr.club
EN 中文 ES RU
★ FRONT-PAGEASageSwap— Anonymous swap — no KYC, no AML hold, no IP logging, declines law-enforcement requests.
/email · verified 2026-08-12

Neir

B-

Zero-signup encrypted mailbox — no email, no phone, no captcha. Browser-side OpenPGP for outbound message bodies; server sees inbound SMTP plaintext like every non-fully-E2E provider. Full XMR payment support (6 confs). Onion mirror advertised.

At a glance

Grade
B- ()
KYC posture
no kyc · no email · no account
Fees
Free (100 MB) · Pro $4.25–$4.99/mo · XMR + BTC + 18 other assets
Last verified
2026-08-12
Operating since
2024 · 2y — ~22 months since Wayback first-snapshot 2024-09-10.
Tor mirror
http://itlmjjwnpraaxvm5gkjeebwhjy5zycildwyg2u3lyrfigz5e6hntdqqd.onion
B- Why grade B-?

B-shape signal but tenure has not yet validated the publishable claims under stress. Used for high-loss-asymmetric categories (exchanges, casinos, custodial mixers) where the operator surface looks B-grade but the service has been operating < 12 months. Drops to C if tenure does not accumulate; promotes to B once it does.

Full rubric + 7-step verification walkthrough at /methodology.

curator verdict · bottom line

Curator Verdict & OpSec Breakdown

THE BOTTOM LINE

Neir is a verified, functional private email that performs solidly for day-to-day use, provided readers account for its specific operational trade-offs.

Proven Strengths

  • Strict No-KYC posture: zero identity verification required across all standard tiers.
  • Tor-native accessibility: active, verified .onion hidden service mirror available.

OpSec Trade-offs & Caveats

  • Standard counterparty risk: always verify deposit addresses and test small amounts first.

Review

Disclosure honesty update (2026-08-12). Neir's own privacy policy was revised (last observed 2026-08-09 via our weekly monitor) to spell out three things the earlier language implied more loosely. These are clarifications, not service changes:

  • Server sees inbound SMTP in plaintext at the ingest step — true for every non-fully-E2E email provider (Proton, Tuta, Mailfence all have this shape). Neir's *browser-side OpenPGP* still applies to outbound bodies and to reader-composed mail; it does not and cannot apply to inbound mail from a plaintext sender.
  • 14-day IP log in the operational journal for anti-abuse. Reasonable retention window; comparable to what other privacy-first mail providers publish.
  • Optional open-tracking pixels on messages that include them (sender-side toggle, off by default).

ToS update simultaneously introduced a *"Private anti-abuse proof"* signup step — a bounded cryptographic proof, non-bypassable, no-KYC in nature. This is a friction addition, not a privacy regression.

Because the changes are honesty improvements rather than service regressions, the grade moved up to B- (from C) — the earlier grade had been carrying two feature tags (`e2e_bodies`, `no_pii`) that overstated the trust picture. Tags corrected; review recalibrated to the operator's actual posture.

What you trust. Browser-side PGP key generation — private key never leaves the client in plaintext; encrypted before send with a key derived from the Account Key. Message bodies are opaque to the server. Metadata is NOT opaque — treat sender/recipient/subject as visible to Neir. Zero-signup design means recovery hinges on the Account Key + recovery phrase; lose both and the account is unrecoverable (there is no email fallback, no support-side reset).

TOS quote. From the Terms page: *"Neir does not and will never require identity verification or know-your-customer (KYC) checks to create or use an account."* The Terms contain no counter-clauses about reserved-right-to-request-ID or law-enforcement cooperation — a clean statement of posture.

Log policy. The Privacy Policy states *"We do not log or store your IP address or geographic location against your account."* The claim is self-attested — no third-party audit, no published bug-bounty programme, no open-source client to inspect the browser-side PGP flow.

Operator identity. *"Based in Sweden"* per the footer. No named legal entity, no team / about page, no PGP fingerprint published for the operator. Contact via `hello@neir.io` and Telegram `@neir_io`. Warrant canary exists at `/canary` with the four standard statements (no NSL, no gag order, no backdoor, no seizure), but the "Last updated" field renders blank and the canary is not PGP-signed. That combination — canary present but neither signed nor dated — is a real gap worth watching.

Tenure. Wayback earliest snapshot 2024-09-10 (~22 months). Not an aged-domain re-brand — no evidence of prior unrelated use.

Onion mirror. `itlmjjwnpraaxvm5gkjeebwhjy5zycildwyg2u3lyrfigz5e6hntdqqd.onion` — advertised on the clearnet homepage footer, byte-identical response to the clearnet HTML at the same path. Real Tor mirror, not a proxy.

Peer directories. kycnot.me lists Neir at 8/10 (Privacy 100 / Trust 62), *"Guaranteed no KYC"*, "Listed, but not yet reviewed by the team" — a community-contributed listing with a positive score, weaker signal than a team-reviewed one. monerica.com lists under the 2026-07-30 additions batch. Privacy Guides does not include it in the recommended-email shortlist (which is Proton / Tuta / Mailbox.org today).

Pricing. Free tier at 100 MB storage. Pro tier at $4.99/mo month-to-month, down to $4.25/mo on the 12-month prepay. Payments accepted across 31 currency/network combos including XMR on the Monero network with a 6-confirmation requirement — first-class alongside BTC, LTC, ETH, USDT-on-6-networks. Payment surface reads as third-party crypto-processor integration (NOWPayments / CoinPayments style) rather than native XMR wallet; typical for a boutique provider.

Fees. Free tier: none. Pro: monthly + prepay pricing above; no per-message fees, no per-alias fees, no storage overage fees disclosed.

Positioning. Full-mailbox provider (not alias-only like AnonAddy / SimpleLogin, not classic-IMAP like Cock.li / Disroot). Zero-signup-friction places Neir closer to Cock.li's ethos with Tuta's browser-side E2E approach. The metadata-plaintext limitation puts it below Proton/Tuta on the encrypted-metadata axis. Free tier + XMR-native + no-signup-data is the differentiator.

Grade C — what it means here. Acceptable with the caveats above named. Real signup posture, real E2E for bodies, real XMR payment, real onion mirror, honest metadata disclosure. What holds the grade below B: no named legal entity, no operator PGP fingerprint, canary is present but unsigned + undated, no independent audit or open-source client to verify the browser-side PGP claim. The path up needs those gaps closed plus 6+ months of clean operation on the watchlist.

Useful when. You want a full mailbox with zero identifying data at signup, accept metadata-plaintext as the tradeoff, and pay in XMR. You are comfortable with a small operator whose canary + identity surface is thinner than Proton/Tuta. For PGP-encrypted body correspondence only, this is genuinely low-friction; recovery discipline (Account Key + recovery phrase) matters more than usual because there is no email-based reset path.

Caveats. The unsigned + undated canary is the most-immediate gap — a canary that isn't demonstrably fresh isn't doing canary work. Legal entity + jurisdictional recourse: "Sweden" without a named legal entity is thinner than Proton's Swiss corporate transparency. Metadata plaintext is honest but material — if your threat model treats subject lines as sensitive, a fully-metadata-encrypted alternative (Proton, Tuta) is a closer fit.

Fees

Free (100 MB) · Pro $4.25–$4.99/mo · XMR + BTC + 18 other assets

Links

Audit trail — receipts for the editorial claim

  • UPSTREAM Up · HTTP 200 · 46ms · checked 21h ago
  • ONION Listed but operator doesn't advertise it (expected for Tor-only services + some clearnets) — itlmjjwnpraaxvm5gkjeebwhjy5zycildwyg2u3lyrfigz5e6hntdqqd.onion
  • MANUAL Last manual verification 2026-08-12 (<90d)

Reviews — moderated · rules

No community reviews yet. Be the first below.

Add a review

Honest, brand-neutral feedback welcome. A curator approves before it appears here. No JS required.

Required: review body. Honest, descriptive reviews get approved within a day. Marketing copy, slurs, or invective get rejected. Per-day cap of 5 submissions per IP.