Security
Security and privacy by default.
Email carries some of the most sensitive things your product sends. Mailhuset is built to keep that data in region, encrypted, and authenticated end to end.
EU data residency
Your mail is sent from, and your data is stored in, the European Union by default. There is no US round-trip to opt out of.
Encrypted in transit and at rest
Traffic to the API is served over TLS, opportunistic TLS is used for delivery where the receiving server supports it, and stored data is encrypted at rest.
Authenticated sending
Every verified domain is set up with SPF, DKIM and DMARC, and each message is signed and aligned so recipients and mailbox providers can trust it.
Scoped API keys
Keys are scoped to what they need, so a sending key cannot manage your account. Rotate or revoke any key at any time.
Signed webhooks
Outbound webhooks are HMAC-signed and timestamped, so your systems can verify a payload came from us and reject replays.
Access and audit
Sensitive account actions are recorded, and access to your data is limited to what is needed to run and support the service.
Privacy and suppression
Bounces and complaints are suppressed automatically, and unsubscribes are honoured, so you keep to the people who want your mail.
Responsible disclosure
If you believe you have found a security issue, contact us so we can investigate and fix it. We appreciate coordinated disclosure.
Documents and contact
For how we handle personal data as a processor, and what to do if you have a security concern.
Send with data residency built in
Verify a domain and send from the EU by default, encrypted and authenticated from the first message.