{
  "slug": "resend",
  "category": "email-sending",
  "name": "Resend",
  "description": "Email API for developers with SMTP support, React Email templates, broadcasts and webhooks.",
  "website": "https://resend.com",
  "license": null,
  "platforms": [],
  "jurisdiction": {
    "code": "US",
    "name": "United States",
    "eyes": "Five Eyes",
    "eu": false,
    "gdpr": false,
    "cloud_act": "provider"
  },
  "pick": false,
  "pick_reason": null,
  "disclosure": null,
  "grade": "D",
  "score": 46,
  "coverage": 88,
  "summary": "Resend scores 46 out of 100 (grade D) on the email sending services criteria. It meets 4 of 12 criteria: no ads or data sales, TLS configuration, open and click tracking off by default and encrypted delivery can be enforced. It partly meets independent audit, security headers and message content deleted after delivery. It does not meet open source, no trackers or telemetry and EU data location. Still needing evidence: transparency report and tells users about requests. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
  "url": "https://privacyratings.com/email-sending/resend/",
  "markdown": "https://privacyratings.com/email-sending/resend/index.md",
  "answers": {
    "open_source": {
      "title": "Open source",
      "weight": 3,
      "answer": "no",
      "evidence": null,
      "note": "Closed source."
    },
    "no_trackers": {
      "title": "No trackers or telemetry",
      "weight": 3,
      "answer": "no",
      "evidence": "https://resend.com/legal/privacy-policy",
      "note": "The privacy policy lists Plausible and Mixpanel, and the website loads PostHog."
    },
    "no_ads": {
      "title": "No ads or data sales",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://resend.com/legal/privacy-policy",
      "note": "Funded by paid plans. The privacy policy states personal information is not sold or rented."
    },
    "independent_audit": {
      "title": "Independent audit",
      "weight": 2,
      "answer": "partial",
      "evidence": "https://resend.com/security",
      "note": "States SOC 2 compliance and third-party audits, but no report is public."
    },
    "transparency_report": {
      "title": "Transparency report",
      "weight": 2,
      "answer": "unknown",
      "evidence": null,
      "note": null
    },
    "user_notice": {
      "title": "Tells users about requests",
      "weight": 1,
      "answer": "unknown",
      "evidence": null,
      "note": null
    },
    "tls": {
      "title": "TLS configuration",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=resend.com&hideResults=on",
      "note": "Grade A+"
    },
    "security_headers": {
      "title": "Security headers",
      "weight": 1,
      "answer": "partial",
      "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=resend.com",
      "note": "Grade B (75/100+)"
    },
    "web_standards": {
      "title": "Modern web standards",
      "weight": 1,
      "answer": "pending",
      "evidence": null,
      "note": "Not tested yet."
    },
    "content_retention": {
      "title": "Message content deleted after delivery",
      "weight": 3,
      "answer": "partial",
      "evidence": "https://resend.com/docs/knowledge-base/account-quotas-and-limits",
      "note": "Email content, metadata and logs are kept for 30 days on all plans. Other retention periods need an enterprise plan."
    },
    "tracking_off_by_default": {
      "title": "Open and click tracking off by default",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://resend.com/docs/dashboard/domains/tracking",
      "note": "Open and click tracking are off by default for all domains."
    },
    "enforced_tls": {
      "title": "Encrypted delivery can be enforced",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://resend.com/docs/api-reference/domains/create-domain",
      "note": "TLS is opportunistic by default and can be set to enforced for each domain."
    },
    "eu_data_location": {
      "title": "EU data location",
      "weight": 1,
      "answer": "no",
      "evidence": "https://resend.com/docs/dashboard/domains/regions",
      "note": "An EU sending region is offered, but customer data, logs and metadata stay in the United States."
    }
  },
  "tests": {
    "ssllabs": "A+",
    "observatory": "B",
    "internetnl_web": null,
    "internetnl_mail": null,
    "trackers": [
      {
        "name": "PostHog",
        "host": "us.i.posthog.com",
        "effect": "no"
      }
    ],
    "tested_at": "2026-10-01T07:28:24.576Z"
  },
  "last_modified": "2026-10-01T07:44:20Z"
}