{
  "slug": "mailgun",
  "category": "email-sending",
  "name": "Mailgun",
  "description": "Email API and SMTP relay from Sinch for transactional and bulk email, with US and EU regions, event logs and optional open and click tracking.",
  "website": "https://www.mailgun.com",
  "license": null,
  "platforms": [],
  "jurisdiction": {
    "code": "US",
    "name": "United States",
    "eyes": "Five Eyes",
    "eu": false,
    "gdpr": false,
    "cloud_act": "provider"
  },
  "pick": false,
  "pick_reason": null,
  "disclosure": null,
  "grade": "D",
  "score": 50,
  "coverage": 88,
  "summary": "Mailgun scores 50 out of 100 (grade D) on the email sending services criteria. It meets 5 of 12 criteria: no ads or data sales, TLS configuration, open and click tracking off by default, encrypted delivery can be enforced and EU data location. It partly meets independent audit, security headers and message content deleted after delivery. It does not meet open source and no trackers or telemetry. Still needing evidence: transparency report and tells users about requests. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
  "url": "https://privacyratings.com/email-sending/mailgun/",
  "markdown": "https://privacyratings.com/email-sending/mailgun/index.md",
  "answers": {
    "open_source": {
      "title": "Open source",
      "weight": 3,
      "answer": "no",
      "evidence": null,
      "note": "Closed source."
    },
    "no_trackers": {
      "title": "No trackers or telemetry",
      "weight": 3,
      "answer": "no",
      "evidence": "https://www.mailgun.com/legal/privacy-policy/",
      "note": "The privacy policy lists Google Analytics and Optimizely on the website."
    },
    "no_ads": {
      "title": "No ads or data sales",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://www.mailgun.com/legal/privacy-policy/",
      "note": "Funded by paid plans. The privacy policy states personal data is not sold or used by third parties for their own interests without consent."
    },
    "independent_audit": {
      "title": "Independent audit",
      "weight": 2,
      "answer": "partial",
      "evidence": "https://www.mailgun.com/security/",
      "note": "SOC 2 Type II and ISO 27001 certified, but the audit reports are not public."
    },
    "transparency_report": {
      "title": "Transparency report",
      "weight": 2,
      "answer": "unknown",
      "evidence": null,
      "note": null
    },
    "user_notice": {
      "title": "Tells users about requests",
      "weight": 1,
      "answer": "unknown",
      "evidence": null,
      "note": null
    },
    "tls": {
      "title": "TLS configuration",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=mailgun.com&hideResults=on",
      "note": "Grade A+"
    },
    "security_headers": {
      "title": "Security headers",
      "weight": 1,
      "answer": "partial",
      "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=mailgun.com",
      "note": "Grade B (75/100+)"
    },
    "web_standards": {
      "title": "Modern web standards",
      "weight": 1,
      "answer": "pending",
      "evidence": null,
      "note": "Not tested yet."
    },
    "content_retention": {
      "title": "Message content deleted after delivery",
      "weight": 3,
      "answer": "partial",
      "evidence": "https://help.mailgun.com/hc/en-us/articles/8841411163035-Adjusting-a-domain-s-message-retention-settings",
      "note": "Messages are kept for up to 3 days by default, depending on the plan, and retention can be set to 0 days for each domain."
    },
    "tracking_off_by_default": {
      "title": "Open and click tracking off by default",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://documentation.mailgun.com/docs/mailgun/user-manual/tracking-messages/tracking-messages",
      "note": "Open, click and unsubscribe tracking are off until turned on for a domain."
    },
    "enforced_tls": {
      "title": "Encrypted delivery can be enforced",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://mailgun-docs.redoc.ly/docs/mailgun/user-manual/tls-sending/",
      "note": "TLS is opportunistic by default. A require-tls setting for each domain or message stops delivery without TLS."
    },
    "eu_data_location": {
      "title": "EU data location",
      "weight": 1,
      "answer": "yes",
      "evidence": "https://documentation.mailgun.com/docs/mailgun/api-reference/api-overview",
      "note": "Domains created in the EU region keep messages, event logs and statistics in the EU. Account and billing data is replicated globally."
    }
  },
  "tests": {
    "ssllabs": "A+",
    "observatory": "B",
    "internetnl_web": null,
    "internetnl_mail": null,
    "trackers": [
      {
        "name": "Google Analytics",
        "host": "inline code",
        "effect": "no"
      },
      {
        "name": "Google DoubleClick",
        "host": "pubads.g.doubleclick.net",
        "effect": "no"
      },
      {
        "name": "Google Tag Manager",
        "host": "www.googletagmanager.com",
        "effect": "no"
      },
      {
        "name": "LinkedIn Insight",
        "host": "snap.licdn.com",
        "effect": "no"
      },
      {
        "name": "Microsoft Clarity",
        "host": "www.clarity.ms",
        "effect": "no"
      },
      {
        "name": "OneTrust",
        "host": "cdn.cookielaw.org",
        "effect": "none"
      },
      {
        "name": "Segment",
        "host": "inline code",
        "effect": "no"
      }
    ],
    "tested_at": "2026-10-01T10:59:37.440Z"
  },
  "last_modified": "2026-10-01T11:14:42Z"
}