{
  "slug": "postmark",
  "category": "email-sending",
  "name": "Postmark",
  "description": "Email API and SMTP service from ActiveCampaign for transactional and broadcast email, with separate message streams and 45 days of message history by default.",
  "website": "https://postmarkapp.com",
  "license": null,
  "platforms": [],
  "jurisdiction": {
    "code": "US",
    "name": "United States",
    "eyes": "Five Eyes",
    "eu": false,
    "gdpr": false,
    "cloud_act": "provider"
  },
  "pick": false,
  "pick_reason": null,
  "disclosure": null,
  "grade": "F",
  "score": 27,
  "coverage": 79,
  "summary": "Postmark scores 27 out of 100 (grade F) on the email sending services criteria. It meets 2 of 12 criteria: TLS configuration and open and click tracking off by default. It partly meets message content deleted after delivery and encrypted delivery can be enforced. It does not meet open source, no trackers or telemetry, no ads or data sales, security headers and EU data location. Still needing evidence: independent audit, transparency report and tells users about requests. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade C-.",
  "url": "https://privacyratings.com/email-sending/postmark/",
  "markdown": "https://privacyratings.com/email-sending/postmark/index.md",
  "answers": {
    "open_source": {
      "title": "Open source",
      "weight": 3,
      "answer": "no",
      "evidence": null,
      "note": "Closed source."
    },
    "no_trackers": {
      "title": "No trackers or telemetry",
      "weight": 3,
      "answer": "no",
      "evidence": null,
      "note": "The website loads Google Tag Manager and Google Analytics."
    },
    "no_ads": {
      "title": "No ads or data sales",
      "weight": 2,
      "answer": "no",
      "evidence": "https://www.activecampaign.com/legal/privacy-policy",
      "note": "The ActiveCampaign privacy policy covers Postmark and discloses personal information to data enrichment providers and shares it with advertising networks for cross-context behavioral advertising."
    },
    "independent_audit": {
      "title": "Independent audit",
      "weight": 2,
      "answer": "unknown",
      "evidence": null,
      "note": null
    },
    "transparency_report": {
      "title": "Transparency report",
      "weight": 2,
      "answer": "unknown",
      "evidence": null,
      "note": null
    },
    "user_notice": {
      "title": "Tells users about requests",
      "weight": 1,
      "answer": "unknown",
      "evidence": null,
      "note": null
    },
    "tls": {
      "title": "TLS configuration",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=postmarkapp.com&hideResults=on",
      "note": "Grade A"
    },
    "security_headers": {
      "title": "Security headers",
      "weight": 1,
      "answer": "no",
      "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=postmarkapp.com",
      "note": "Grade C- (45/100+)"
    },
    "web_standards": {
      "title": "Modern web standards",
      "weight": 1,
      "answer": "pending",
      "evidence": null,
      "note": "Not tested yet."
    },
    "content_retention": {
      "title": "Message content deleted after delivery",
      "weight": 3,
      "answer": "partial",
      "evidence": "https://postmarkapp.com/support/article/can-i-hide-or-turn-off-saving-of-message-content-in-my-activity-page",
      "note": "Message content is kept for 45 days by default and cannot be turned off. A paid add-on sets retention between 7 and 365 days."
    },
    "tracking_off_by_default": {
      "title": "Open and click tracking off by default",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://postmarkapp.com/developer/user-guide/tracking-links",
      "note": "Link tracking is off by default for all servers and messages, and open tracking is turned on per server or message."
    },
    "enforced_tls": {
      "title": "Encrypted delivery can be enforced",
      "weight": 2,
      "answer": "partial",
      "evidence": "https://postmarkapp.com/security",
      "note": "Outbound mail uses opportunistic TLS. No setting to require TLS is documented."
    },
    "eu_data_location": {
      "title": "EU data location",
      "weight": 1,
      "answer": "no",
      "evidence": "https://postmarkapp.com/eu-privacy",
      "note": "Data is hosted in a data center near Chicago and on Amazon Web Services outside the EU."
    }
  },
  "tests": {
    "ssllabs": "A",
    "observatory": "C-",
    "internetnl_web": null,
    "internetnl_mail": null,
    "trackers": [
      {
        "name": "Google Analytics",
        "host": "ssl.google-analytics.com",
        "effect": "no"
      },
      {
        "name": "Google Tag Manager",
        "host": "www.googletagmanager.com",
        "effect": "no"
      }
    ],
    "tested_at": "2026-10-01T07:27:29.076Z"
  },
  "last_modified": "2026-10-01T07:44:20Z"
}