Email sending services
Mailgun privacy rating
Email API and SMTP relay from Sinch for transactional and bulk email, with US and EU regions, event logs and optional open and click tracking.
Summary
Mailgun scores 50 out of 100 (grade D) on the email sending services criteria. It meets 5 of 12 criteria: no ads or data sales, TLS configuration, open and click tracking off by default, encrypted delivery can be enforced and EU data location. It partly meets independent audit, security headers and message content deleted after delivery. It does not meet open source and no trackers or telemetry. Still needing evidence: transparency report and tells users about requests. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade B.
Score 50 out of 100. How scoring works
Criteria
- No
-
No
No trackers or telemetry Weight 3 of 3
Are the website and apps free of third-party trackers, with any analytics anonymous and any telemetry off by default?
The privacy policy lists Google Analytics and Optimizely on the website.
-
Yes
No ads or data sales Weight 2 of 3
Is the product funded without advertising, ad targeting or selling user data?
Funded by paid plans. The privacy policy states personal data is not sold or used by third parties for their own interests without consent.
-
Partial
Independent audit Weight 2 of 3
Has an independent security or privacy audit been published within the last three years?
SOC 2 Type II and ISO 27001 certified, but the audit reports are not public.
-
Unknown
Transparency report Weight 2 of 3
Does the provider regularly publish how many government and legal requests it receives and how it responds?
Needs evidence. Add it
-
Unknown
Tells users about requests Weight 1 of 3
Does the provider promise to tell users about requests for their data, unless a court forbids it?
Needs evidence. Add it
-
Partial
Message content deleted after delivery Weight 3 of 3
Is the content of sent mail deleted once it has been delivered?
Messages are kept for up to 3 days by default, depending on the plan, and retention can be set to 0 days for each domain.
-
Yes
Open and click tracking off by default Weight 2 of 3
Are open tracking pixels and click tracking links off unless the sender turns them on?
Open, click and unsubscribe tracking are off until turned on for a domain.
-
Yes
Encrypted delivery can be enforced Weight 2 of 3
Can outbound mail be kept from being delivered without TLS?
TLS is opportunistic by default. A require-tls setting for each domain or message stops delivery without TLS.
-
Yes
EU data location Weight 1 of 3
Can message content and delivery logs be processed and stored only in the European Union?
Domains created in the EU region keep messages, event logs and statistics in the EU. Account and billing data is replicated globally.
Automated tests
-
Yes
TLS configuration Weight 2 of 3
Does the website pass the Qualys SSL Labs test with a grade of A or better?
Grade A
-
Partial
Security headers Weight 1 of 3
Does the website pass the Mozilla HTTP Observatory test with a grade of A or better?
Grade B (75/100+)
-
Not tested yet
Modern web standards Weight 1 of 3
Does the website score 90% or higher on the Internet.nl website test?
Not tested yet.