Security

Security and privacy by default.

Email carries some of the most sensitive things your product sends. Mailhuset is built to keep that data in region, encrypted, and authenticated end to end.

EU data residency

Your mail is sent from, and your data is stored in, the European Union by default. There is no US round-trip to opt out of.

Encrypted in transit and at rest

Traffic to the API is served over TLS, opportunistic TLS is used for delivery where the receiving server supports it, and stored data is encrypted at rest.

Authenticated sending

Every verified domain is set up with SPF, DKIM and DMARC, and each message is signed and aligned so recipients and mailbox providers can trust it.

Scoped API keys

Keys are scoped to what they need, so a sending key cannot manage your account. Rotate or revoke any key at any time.

Signed webhooks

Outbound webhooks are HMAC-signed and timestamped, so your systems can verify a payload came from us and reject replays.

Access and audit

Sensitive account actions are recorded, and access to your data is limited to what is needed to run and support the service.

Privacy and suppression

Bounces and complaints are suppressed automatically, and unsubscribes are honoured, so you keep to the people who want your mail.

Responsible disclosure

If you believe you have found a security issue, contact us so we can investigate and fix it. We appreciate coordinated disclosure.

Send with data residency built in

Verify a domain and send from the EU by default, encrypted and authenticated from the first message.