Security
How we protect your domains, keys and email.
A plain account of how toSend keeps your account and email safe. If you find a problem, tell us and we'll fix it.
Your domains
- A DKIM key for your team alone
- New domains are signed with a key unique to your team. DNS records left behind after a domain is removed carry that key, so they can't be used to verify the domain in anyone else's account.
- One domain, one account
- A domain can only be added to one toSend account at a time, and nothing sends from it until its DNS records are verified.
- Clean-up when you leave
- When you delete a verified domain, we email you the DNS records that can now be removed.
Keys and access
- Keys are shown once
- API keys are displayed a single time, when you create them. We store only a hash of each key, so nobody, including our team, can read one back. Sending keys can be limited to one domain and revoked at any time.
- Scoped admin keys, stored hashed
- Admin API keys carry only the permissions you choose, and nothing is granted by default. We store them hashed, so nobody, including our team, can read one back. There is no API that creates an admin key, so a leaked key can't create its own replacement.
- Client teams can't reach each other
- A key made for a client team works only for that team. It can't reach the main account or any other client.
Sending
- Encrypted in transit
- The API is served over HTTPS only. The SMTP relay requires TLS 1.2 or newer and refuses to accept a password before the connection is encrypted.
- Signed webhooks
- Give a webhook a secret and every request is signed with HMAC-SHA256, so you can check it came from us.
- Reputation kept per team
- Each team's sending is tracked separately, so another sender's bounces and complaints don't affect your delivery.
- Bad addresses stopped
- Addresses that bounce or complain are suppressed automatically, and throwaway addresses and domains with no mail server are caught before sending.
Your data
- Stored in the EU
- Email logs, email content, suppression lists and dashboard data are stored in the European Union for every team. A short-lived cache and request handling run worldwide. The data location page has the full breakdown.
- Deleted after 14 days
- Email content and logs are kept for 14 days, then deleted. Webhook delivery logs are kept for 7 days.
- Private keys encrypted
- The private half of each team's DKIM key is encrypted at rest with AES-256-GCM.
- No card data on our side
- Payments are handled by Stripe. Card numbers never reach our servers.
Reporting a vulnerability
Email support@tosend.com with the details and how to reproduce it. A person on the engineering team reads every report. Please give us a chance to fix the issue before sharing it publicly, and don't access other customers' data or send email through accounts that aren't yours while testing.
To report spam sent through toSend, write to the same address with the message headers.