Security posture, published in full.
Role-based access, a complete audit trail, IP allow-listing at SMTP AUTH, brand-pin enforcement on outbound headers, and per-tenant encryption of message content and credentials. We publish what we do — and what we don't do yet.
“Show me every message sent to that recipient last quarter.”
The auditor asks a simple question. You open your ESP. The dashboard shows the last 30 days. The rest is in monthly PDFs somewhere. There’s no way to say who on your team sent what through which provider — the events log doesn’t retain actor identity, and the SMTP credentials all resolve to the samesender@ address.
sendrules keeps the full route log — every recipient, every provider, every check, every response — for as long as your retention window says. Every mutation to the configuration (a rotated password, an added provider, a paused ramp) is captured with actor, timestamp and diff. The audit answers itself.
Role-based access, per workspace.
TLS on submission. Network-range controls at AUTH.
smtp.sendrules.net — no self-signed workaround. Both STARTTLS (port 587) and implicit TLS (port 465) are supported.Per-tenant encryption. Configurable retention.
Controls the platform enforces on your behalf.
What we have. What we don’t. In one place.
sendrules follows UK GDPR and the Data Protection Act 2018. Our Data Processing Addendum, Privacy Policy, Terms, and Acceptable Use Policy are published in full and available to sign as-is.