Receipts, password resets, confirmations, notifications.
Sent over SMTP or API the instant your app calls. Webhooks for every event, templates, and real-time delivery logs.
- SMTP & API
- Webhooks
- Templates
- Delivery logs
Transactional & marketing email
Epostix sends your product email and your campaigns from the same place — one API, one dashboard, one set of sending domains. Servers are in the EU, and a data processing agreement comes as standard.
Free plan, no card required.
Sending for iGaming or other high-volume verticals?
Compliance and data residency,
included as standard.
One platform
Most providers do either transactional or marketing email, so teams end up running two services with two bills and two sending reputations to watch. Epostix handles both. Receipts, password resets and notifications go out over the API or SMTP; campaigns, segments and reporting run from the same dashboard, on the same domains.
Sent over SMTP or API the instant your app calls. Webhooks for every event, templates, and real-time delivery logs.
Run from the same dashboard, on the same domains and sending reputation as your transactional email.

Context
Three things shape whether an email actually arrives. Each is easier to ignore than to handle correctly. The sections below describe how Epostix handles them.
Gmail, Microsoft, Yahoo, and Apple each throttle, bounce, and filter differently. A delivery system that treats them identically hits limits it doesn’t understand.
Sender reputation isn’t per-email — it’s per-domain, accumulated over time. A bounce spike today can affect future placement. Most dashboards don’t surface this trajectory.
SPF, DKIM and reverse DNS have to line up for every sending domain. When they don’t, mailbox providers quietly treat your mail as suspect — a common, hard-to-spot cause of spam-foldering.
The platform
Deliverability
Mailbox providers don’t behave the same way. Gmail, Outlook and Yahoo each apply their own rate limits and filtering, so Epostix adjusts how it sends to each one rather than treating them as one queue. Every bounce is classified by type and cause, hard bounces are suppressed automatically, and sending pauses on its own if complaint or bounce rates climb past a threshold you can set.
Different mailbox providers have different rules. The delivery engine handles each one separately.

Problems with email sends tend to escalate fast. These safeguards catch them early.
Default thresholds: 2% hard-bounce, 0.3% complaint, 3× spike over 24h baseline. Configurable per workspace.

When an email bounces, the reason matters as much as the fact. The system classifies every bounce by type, cause, and provider.
Sender authentication is set up for each domain, and dedicated IPs are available when you want to manage your own reputation.

Transactional
Send password resets, receipts, confirmations, and notifications with per-email delivery tracking and automatic retry.
curl https://api.epostix.com/v1/emails \
-H "Authorization: Bearer $EPX_API_KEY" \
-H "Idempotency-Key: order_4821_welcome" \
-H "Content-Type: application/json" \
-d '{
"from": "[email protected]",
"to": "[email protected]",
"subject": "Welcome to Acme",
"html": "<h1>Welcome</h1><p>You're in.</p>",
"tags": ["welcome", "tier:pro"]
}'Per-email traceability
Every email has a detail page — sender, recipient, subject, send timestamp, current delivery status, and the rendered content as the recipient saw it.

Marketing
Run campaigns with pre-send validation, automatic safeguards, and engagement tracking across your full audience.
Contacts move between tiers based on opens, clicks, and recency. Cold and inactive contacts can be throttled or excluded automatically.

Architecture
The delivery engine, bounce classifier, provider handling rules, and circuit breaker logic are developed and maintained by the Epostix team.
When provider behavior changes, the rules are updated by the people who wrote them.
Data location
Email content, logs, analytics and contact data stay on servers in the EU. We include a data processing agreement by default and list our subprocessors publicly. If you have data-residency requirements, this keeps everything in one jurisdiction, so you’re not relying on transfer mechanisms like Standard Contractual Clauses or the EU–US Data Privacy Framework to move data abroad.
Email content, logs, analytics and contacts sit on servers in the European Union.
A data processing agreement is part of every plan, not just enterprise.
All subprocessors are EU-based and published, with notice before any change.
For developers
A REST API and standard SMTP, with an OpenAPI spec you can generate clients from. Idempotency keys so retries don’t create duplicates. Per-key permissions and IP allowlists. A sandbox for testing without spending quota, and webhooks for delivery, bounce, open, click and complaint events.

Generate clients in any language from the public spec.
Per-key permissions, per-key IP allowlists, rotate without downtime.
Safe to retry every send endpoint — duplicates are caught at the API layer.
Test sends without burning quota. Inspect every request and response.
TypeScript, Python, and Go — generated from the spec.
Real-time delivery, bounce, open, click, and complaint notifications.
Pricing
Every plan carries the same provider-specific sending, the same safeguards and the same bounce handling. The tier only sets the volume.
10,000emails / month
The free plan is fully functional — same sending, same safeguards. Domain verification typically completes within minutes.
Sending for iGaming or need dedicated IPs and managed warmup? See dedicated plans →
Scope
Inbox placement depends on many factors beyond any sending platform’s control. Epostix provides sending controls, bounce data, and reputation signals — placement decisions are made by receiving providers.
Domain verification is required before sending. The platform reviews sending patterns to maintain infrastructure quality.
Delivery data and safeguards help senders make better decisions. List hygiene, content quality, and audience management remain the sender’s responsibility.
Security
API and SMTP traffic runs over TLS. Email content is encrypted at rest, and backups are encrypted too. Accounts support two-factor authentication and role-based access, and public endpoints are rate-limited.
All API and SMTP traffic over modern TLS. Forward secrecy on every connection.
TOTP-based 2FA on every account. Recovery codes. Session revocation across devices.
IP whitelisting, expiration dates, and last-used tracking. Tokens hashed at rest — never stored in plain text.
Owner, admin, and user roles. Per-domain access controls. Team invitations only.
Email content stored encrypted at rest. Database backups encrypted.
Rate limiting on every public endpoint. Turnstile on login, signup, and password reset.
Data protection
End users can request their data or have it deleted, and deletion cascades through audiences, history and engagement records. Consent — method, date and source — is recorded per contact. Every campaign includes one-click unsubscribe. A standard DPA is available on every plan, not just enterprise.
End users can request complete deletion. Cascades across audiences, history, and engagement records.
Full contact data export on demand in machine-readable format. No support ticket required.
Opt-in method, date, and source recorded per contact. Audit trail available for every subscriber.
One-click unsubscribe (RFC 8058) on every campaign email — compliant with current sender requirements.
All subprocessors EU-based and listed publicly. Updates ship with 30-day notice.
Standard Data Processing Agreement available for every workspace, no enterprise tier required.
Sign up, verify a domain, and send a test in a few minutes. The free plan doesn’t need a card, and there’s no sales call to get started.
Free plan · no card required