Security

How we protect your domains, keys and email.

A plain account of how toSend keeps your account and email safe. If you find a problem, tell us and we'll fix it.

Your domains

A DKIM key for your team alone
New domains are signed with a key unique to your team. DNS records left behind after a domain is removed carry that key, so they can't be used to verify the domain in anyone else's account.
One domain, one account
A domain can only be added to one toSend account at a time, and nothing sends from it until its DNS records are verified.
Clean-up when you leave
When you delete a verified domain, we email you the DNS records that can now be removed.

Keys and access

Keys are shown once
API keys are displayed a single time, when you create them. We store only a hash of each key, so nobody, including our team, can read one back. Sending keys can be limited to one domain and revoked at any time.
Scoped admin keys, stored hashed
Admin API keys carry only the permissions you choose, and nothing is granted by default. We store them hashed, so nobody, including our team, can read one back. There is no API that creates an admin key, so a leaked key can't create its own replacement.
Client teams can't reach each other
A key made for a client team works only for that team. It can't reach the main account or any other client.

Sending

Encrypted in transit
The API is served over HTTPS only. The SMTP relay requires TLS 1.2 or newer and refuses to accept a password before the connection is encrypted.
Signed webhooks
Give a webhook a secret and every request is signed with HMAC-SHA256, so you can check it came from us.
Reputation kept per team
Each team's sending is tracked separately, so another sender's bounces and complaints don't affect your delivery.
Bad addresses stopped
Addresses that bounce or complain are suppressed automatically, and throwaway addresses and domains with no mail server are caught before sending.

Your data

Stored in the EU
Email logs, email content, suppression lists and dashboard data are stored in the European Union for every team. A short-lived cache and request handling run worldwide. The data location page has the full breakdown.
Deleted after 14 days
Email content and logs are kept for 14 days, then deleted. Webhook delivery logs are kept for 7 days.
Private keys encrypted
The private half of each team's DKIM key is encrypted at rest with AES-256-GCM.
No card data on our side
Payments are handled by Stripe. Card numbers never reach our servers.

Reporting a vulnerability

Email support@tosend.com with the details and how to reproduce it. A person on the engineering team reads every report. Please give us a chance to fix the issue before sharing it publicly, and don't access other customers' data or send email through accounts that aren't yours while testing.

To report spam sent through toSend, write to the same address with the message headers.