sendrules
Home
Product
  • Overview
    How sendrules fits between your app and every provider.
  • SMTP Proxy
    One endpoint. Every provider you already trust.
  • Grid & Rules
    Six routing strategies. Coverage warnings. Failover.
  • Quality Gate
    Verify recipients before the send, not after the bounce.
  • ISP Routing
    Route by the recipient's live MX record — not domain strings.
  • Ramp-up
    Auto-advancing cap with bounce/complaint safety gates.
  • Limits & Queue
    Four-tier caps. Queue, don't drop. Midnight-UTC release.
  • Webhooks
    Signed and verifiable. Retried on schedule. Replayable.
  • Activity
    Seven filtered inboxes. Sparklines. Share links.
  • Inbound
    Receive + classify replies, bounces, and OOOs.
  • Autoresponder Parser
    Harvest contacts from OOO replies into lists — webhook or CSV.
  • REST API
    Every UI action has an endpoint. Scoped, rotatable keys.
  • Teams and roles
    Fine-grained RBAC across 30 resource types + audit trail.
Deliverability
  • Overview
    The suite most vendors sell separately.
  • DMARC Monitoring
    DMARC aggregate reports ingested with per-source breakdowns.
  • Auth Check
    SPF / DKIM / DMARC, graded A through F.
  • Postmaster Tools
    Google Postmaster data in per-domain views.
  • Blocklists
    Continuous blocklist + seed-list inbox placement.
  • Free Tools
    Email validation, spam check, DMARC generator — free on every plan.
How it Works
Industries
  • All industries
    Every segment sendrules fits — and why.
  • B2B SaaS
    Transactional at scale. Failover across ESPs.
  • E-commerce & Retail
    One rule per ISP — Gmail buyers routed differently to Yahoo.
  • Marketing Agencies
    Per-client rules on your clients' own provider accounts.
  • Sales Development
    Verify every address. Parse every autoresponder for referrals.
  • Recruitment & Staffing
    OOO replies are full of decision-maker names — capture them.
  • Real Estate & Lead Gen
    Inquiry email hygiene + reply-source enrichment.
  • Financial Services
    DMARC compliance, audit log, signed webhooks.
  • Healthcare & Life Sciences
    Reliable patient comms with a full audit trail.
  • EdTech & Education
    Enrollment-week bursts absorbed by queue-don't-drop.
  • Nonprofit & Fundraising
    Donor-appeal deliverability without a deliverability team.
  • Publishers & Media
    Newsletter deliverability + list hygiene at every send.
  • Government & Public Sector
    IP allow-list at AUTH, DMARC-first, tenant isolation.
PricingProduct Demo
Sign inStart free
Security

Security posture, published in full.

Role-based access, a complete audit trail, IP allow-listing at SMTP AUTH, brand-pin enforcement on outbound headers, and per-tenant encryption of message content and credentials. We publish what we do — and what we don't do yet.

Start freeSee the pricing
Sound familiar?

“Show me every message sent to that recipient last quarter.”

The auditor asks a simple question. You open your ESP. The dashboard shows the last 30 days. The rest is in monthly PDFs somewhere. There’s no way to say who on your team sent what through which provider — the events log doesn’t retain actor identity, and the SMTP credentials all resolve to the samesender@ address.

sendrules keeps the full route log — every recipient, every provider, every check, every response — for as long as your retention window says. Every mutation to the configuration (a rotated password, an added provider, a paused ramp) is captured with actor, timestamp and diff. The audit answers itself.

Access

Role-based access, per workspace.

Roles
Owner, Admin, and Sender by default, plus custom roles you define per workspace. Every role maps to a documented permission matrix across all 30 resource types (providers, rules, ramps, inboxes, parsers, DMARC domains, webhooks, and more).
Multi-factor
Password-based sign-in with TOTP MFA available to every member. SSO/SAML is a paid-tier feature (see the pricing table).
Audit trail
Every privileged action — a rotated SMTP password, an added provider, a paused ramp, a member invited — captured with actor, timestamp, source IP and diff. Retained for the full audit window, not just 30 days.
Session control
Session cookies scoped per workspace with configurable idle timeout. Sign-out invalidates on every device.
Transport

TLS on submission. Network-range controls at AUTH.

SMTP submission
TLS on submission with a real Let’s Encrypt certificate on smtp.sendrules.net — no self-signed workaround. Both STARTTLS (port 587) and implicit TLS (port 465) are supported.
Credential scoping
Each SMTP credential can be locked to a specific list of network ranges (CIDR blocks). A leaked password from outside your infrastructure cannot authenticate, even with the correct value.
HTTP dispatch
Outbound HTTP webhooks are signed and cryptographically verifiable. The signing secret is scoped per webhook so a compromise of one endpoint’s secret does not compromise the others.
Inbound MX
Inbound mail (replies, bounces, autoresponders, DMARC reports) arrives on a dedicated hostname isolated from marketing traffic. Both TLS-on-receive and opportunistic TLS are supported.
Data handling

Per-tenant encryption. Configurable retention.

Content at rest
Message bodies encrypted at rest, per tenant. Credentials for the providers you attach (SMTP passwords, API keys) encrypted with a separate per-tenant key — even a compromise of the database file cannot reveal them without the key.
Data residency
All primary data is stored in the United Kingdom. We do not transfer personal data outside the UK / EEA except where necessary to route mail to an upstream provider you have chosen.
Retention
Each workspace sets its own retention window (14 to 360 days depending on plan). Curated data — suppression lists, quality-check failures, bounce ledger, parsed contact lists — is never auto-purged; it’s yours until you delete it.
Backups
Daily encrypted backups with a documented restore procedure and periodic restore drills. Backup retention matches the workspace retention window.
Deletion
Full data-export before deletion, and a data-erasure request for any data subject we hold on your behalf. See the Data Processing Addendum for the mechanics.
Product security

Controls the platform enforces on your behalf.

Brand pin
The From-name on outgoing mail can be pinned per workspace (Free / Preferred / Strict). A compromised application credential cannot rewrite your sender identity when Strict mode is on.
Quality gate
Every recipient is checked before send — syntax, suppression, disposable domain, role account, typo correction, live mailbox check. Bad addresses are blocked with a reason recorded in the route log; a compromised credential can’t burn your reputation by sending to obvious junk.
Cross-tenant isolation
Every query, every event, every webhook dispatch is scoped by tenant at the database layer. There is no shared “send” queue across tenants; one workspace’s traffic can never be delivered on behalf of another.
Webhook egress
Outbound webhooks refuse to dispatch to private-network addresses or unresolvable hosts, defeating SSRF-style attacks that use webhooks as an internal-network probe.
Compliance

What we have. What we don’t. In one place.

sendrules follows UK GDPR and the Data Protection Act 2018. Our Data Processing Addendum, Privacy Policy, Terms, and Acceptable Use Policy are published in full and available to sign as-is.

What we have
GDPR-aligned data handling, published DPA available to sign as-is, audit-trail evidence for internal reviews, UK data residency for primary storage, per-tenant encryption of content and credentials.
What we don't have yet
SOC 2 and ISO 27001 certifications. We do not display badges we haven’t earned; when a report exists we’ll link it here, not before. Cyber Essentials is on the near-term shortlist. If you’re a prospective customer whose procurement requires one of these, tell us — that signal shapes our certification order.
Sub-processors
A named list of the parties who process data on our behalf (the hosting provider, the email-transport provider for our own outbound mail, the CDN) is available on request from the DPA. We do not add sub-processors without updating the list.

Ready to send through your own providers, with these controls on from day one?

Start freeSee the pricing
sendrules

One SMTP endpoint across 15 providers. Verify recipients before the send, route by real MX, and monitor DMARC in the same product.

Sign inStart free

Product

  • SMTP Proxy
  • Grid & Rules
  • Quality Gate
  • ISP Routing
  • Ramp-up
  • Limits & Queue
  • Webhooks
  • Activity
  • Inbound
  • Autoresponder Parser
  • REST API
  • Teams and roles
  • Integrations

Deliverability

  • DMARC Monitoring
  • Auth Check
  • Postmaster Tools
  • Blocklists
  • Free Tools
  • Providers

Solutions

  • How it Works
  • Industries
  • Customers
  • Pricing
  • Contact

Company

  • About
  • Security
  • Terms
  • Privacy
  • DPA
  • Acceptable Use

© 2026 sendrules.com