15663 domains tracked
Report
⚑ Sovereignty Finding
17 / 17 — Every scanned EU institution
routes email through a US company
17 EU bodies use Proofpoint Inc. (Sunnyvale, California) as their primary email security provider.
What is Proofpoint?

Proofpoint Inc. is a US-based cybersecurity company headquartered in Sunnyvale, California, providing email security, anti-phishing, and mail routing services. When an organisation uses Proofpoint, all inbound and outbound email is routed through Proofpoint's infrastructure before reaching the recipient. Proofpoint has full access to email content and metadata for every message processed. Proofpoint was acquired by Thoma Bravo (a US private equity firm) in 2021 and operates as a private company incorporated under US law.

What the US CLOUD Act means

The US Clarifying Lawful Overseas Use of Data (CLOUD) Act of 2018 requires US companies to disclose data stored or processed on their infrastructure to US government agencies upon valid legal demand — regardless of where the data physically resides. Because Proofpoint is a US company, all email routed through its systems is subject to this authority. EU institutions using Proofpoint have no contractual mechanism to prevent access under the CLOUD Act. This is an infrastructure observation, not a legal determination.

All 17 affected domains
Domain / Organisation
Email provider
Hosting
F
cinea.ec.europa.eu
CINEA — Climate & Energy
Proofpoint
Non-EU
C
eacea.ec.europa.eu
EACEA — Education & Culture
Proofpoint
EU
F
eismea.ec.europa.eu
EISMEA — SME & Innovation
Proofpoint
Non-EU
F
epso.europa.eu
EPSO — Personnel Selection
Proofpoint
Non-EU
F
ercea.ec.europa.eu
ERCEA — Research Council
Proofpoint
Unknown
C
eeas.europa.eu
EU External Action Service
Proofpoint
EU
C
europa.eu
EU Portal
Proofpoint
EU
F
euiss.europa.eu
EUISS — Security Studies
Proofpoint
Unknown
F
eur-lex.europa.eu
EUR-Lex Legal Database
Proofpoint
Non-EU
C
ec.europa.eu
European Commission
Proofpoint
EU
F
satcen.europa.eu
European Union Satellite Centre
Proofpoint
Unknown
F
hadea.ec.europa.eu
HaDEA — Health & Digital
Proofpoint
Non-EU
F
joinup.ec.europa.eu
Joinup (EU Digital)
Proofpoint
Non-EU
F
publications.europa.eu
Publications Office
Proofpoint
Non-EU
F
eusatcen.europa.eu
SatCen — Satellite Centre
Proofpoint
Unknown
F
sn-ju.europa.eu
Smart Networks & Services JU
Proofpoint
Unknown
F
ted.europa.eu
TED — EU Tenders
Proofpoint
Non-EU
Methodology: Email provider is determined by querying the MX DNS records of each domain and cross-referencing the mail exchanger hostname against a curated database of known provider signatures. A domain is classified as using Proofpoint when its MX records resolve to hostnames in the pphosted.com domain or other known Proofpoint exchanger patterns. Reproduce with: dig <domain> MX This is a factual infrastructure report. It is not a legal determination of regulatory violation. Full methodology →