# Egressif > Egressif gets a company's important email delivered, and proves it. We run email > sending, business mailboxes, and domain DNS on a network we own and operate - > or as an operating layer on top of the ESP you already use (SendGrid, Amazon > SES, Postmark, your own infrastructure), adding monitoring, ordered failover, > suppression, and per-message delivery evidence. Mail is engineered to reach the > inbox and backed by a deliverability team that works as an extension of our > clients'. We take security and anti-abuse seriously and align with email > deliverability best practices. ## Overlay - [Add Egressif on top of your ESP](https://egressif.io/overlay): Keep your current provider as one routed path and add the operating layer above it - monitoring, ordered failover, suppression, and per-message evidence, with no migration. The overlay connects over SMTP and usually the provider's API; because Egressif hosts the client's DNS and manages authentication (SPF/DKIM/DMARC), onboarding a provider is a guided setup rather than a paste-in-SMTP switch. Major ESPs (SendGrid, Amazon SES, Postmark, Mailgun, Google Workspace relay) and a client's own infrastructure all fit; there is no rigid supported-provider list. - [Overlay on SendGrid](https://egressif.io/overlay/sendgrid): Keep SendGrid and add monitoring, failover, suppression, evidence, and route engineering. - [Overlay on Amazon SES](https://egressif.io/overlay/amazon-ses): Keep SES's price and scale and add the deliverability operating layer it omits. - [Overlay on Postmark](https://egressif.io/overlay/postmark): Keep Postmark for transactional and unify your other streams under one view. - [Overlay on Mailgun](https://egressif.io/overlay/mailgun): Keep Mailgun's API and add the operations team it isn't. - [Overlay on the Google Workspace relay](https://egressif.io/overlay/google-workspace): Keep Workspace for people's mail and move product and bulk sending onto infrastructure built for it. - [Overlay on self-hosted SMTP](https://egressif.io/overlay/self-hosted-smtp): Keep your own Postfix/SMTP infrastructure and add monitoring, failover, suppression, and a team. - [Compare to your current setup](https://egressif.io/compare): How Egressif differs from ESPs, self-hosting, and point tools, and what stays vs. changes when you adopt the operating layer. ## Platform - [Platform overview](https://egressif.io/platform): DNS, mailboxes, delivery, control, and monitoring in one provider, or as a layer on top of your ESP. - [Managed DNS hosting](https://egressif.io/platform/dns): Authoritative DNS with correct SPF, DKIM, DMARC, and MX so email authentication passes. - [Business mailboxes](https://egressif.io/platform/mailboxes): Hosted, standards-based mailboxes with filtering and forwarding. We never read message content. - [Email delivery](https://egressif.io/platform/sending): Reliable inbox delivery with sender-reputation management, IP warming, authentication, and failover. - [Control & API](https://egressif.io/platform/console): Manage domains, mailboxes, routing, and access via console or API. - [Monitoring & insights](https://egressif.io/platform/observability): Real-time delivery events, monitoring, and proactive alerting. ## Services - [Managed Deliverability](https://egressif.io/services/managed-deliverability): An outsourced deliverability/mail-operations team for your sending. - [Deliverability Consulting](https://egressif.io/services/consulting): Expert guidance on authentication, reputation, and inbox placement. - [Custom Email Infrastructure](https://egressif.io/services/custom-infrastructure): Bespoke, resilient email infrastructure designed and operated for you. - [Deliverability Audits](https://egressif.io/services/audits): Prioritized assessment of authentication, infrastructure, and reputation. ## Solutions - [Transactional & operational email](https://egressif.io/solutions/transactional-email): Reliable delivery for resets, OTPs, receipts, alerts, and notifications. - [AI agents & automation](https://egressif.io/solutions/ai-agents): Authenticated sending identities, machine-speed rate guardrails, suppression enforcement, and delivery-event feedback loops for agentic workflows. - [SaaS & product email](https://egressif.io/solutions/saas-product-email): Protect critical product email and isolate sending reputation. - [Outreach platforms](https://egressif.io/solutions/sales-engagement): Multi-domain infrastructure for permission-based platforms. - [E-commerce & marketplaces](https://egressif.io/solutions/ecommerce-marketplaces): Order and shipping email on isolated reputation, peak-season capacity, and per-message delivery proof. - [Fintech & regulated industries](https://egressif.io/solutions/fintech-regulated): Provable delivery for statements, alerts, and notices, with enforcement-grade authentication and audit records. - [Forwarding & delegated sending](https://egressif.io/solutions/forwarding-products): DMARC-surviving forwarding, preserved reply paths, and per-user reputation isolation for send-on-behalf products. - [Agencies](https://egressif.io/solutions/agencies): Operate many client domains and mailboxes from one provider. - [Recruiting & staffing](https://egressif.io/solutions/recruiting): High-volume, reply-critical business email that lands. - [Deliverability & MailOps teams](https://egressif.io/solutions/deliverability-teams): Extra capacity, monitoring, and infrastructure for in-house experts. - [Platforms & product builders](https://egressif.io/solutions/platform-builders): Embed reliable sending into your product with per-customer isolation, programmatic provisioning, and delivery events, without building an email platform. - [Enterprise IT](https://egressif.io/solutions/enterprise-it): Consolidate scattered outbound email under one accountable operator, with provable delivery, enforcement-grade authentication, and an honest security posture. - [Lifecycle & marketing email](https://egressif.io/solutions/lifecycle-email): Separate transactional and campaign streams so a bad campaign can't sink critical mail; keep your ESP as a routed path. ## Trust - [Trust & security](https://egressif.io/trust): US data processing, SOC 2-certified datacenters and SOC 2 principles applied across the stack, third-party penetration testing, no AI training on your data, minimal personal data, 72-hour incident notice, and vulnerability disclosure. Egressif itself is not SOC 2 certified. - [Security, privacy & compliance](https://egressif.io/security): Owned network and IP space, resilient multi-node infrastructure, SOC 2-certified datacenters, no message-content access. - [Sub-processors](https://egressif.io/trust/subprocessors): The third-party sub-processors Egressif uses (Google Cloud, SendGrid, Cloudflare, PureVoltage, FiberState, Stripe, QuickBooks, Mercury), with purpose and US processing region. - [Data retention](https://egressif.io/trust/data-retention): How long each data type is kept - account details and mailboxes deleted on offboarding, mailbox contents ~1 month, delivery/webhook events 2 years, message bodies not stored. - [Acceptable Use Policy](https://egressif.io/trust/acceptable-use): Permission-based sending only; prohibited uses, sending standards, enforcement, and how to report abuse. - [Report abuse](https://egressif.io/report-abuse): Report spam, phishing, or other abuse involving Egressif. - [Terms of Service](https://egressif.io/terms-of-service) - [Privacy Policy](https://egressif.io/privacy-policy) ## Guides - [Email sending best practices](https://egressif.io/resources/guides/email-sending-best-practices): The combined master guide: authentication, sender rules, infrastructure, reputation, warming, list hygiene, suppression, monitoring, and compliance, linking to every deep reference. - [Email headers and the envelope](https://egressif.io/resources/guides/email-headers-and-envelope): A deep dive into the SMTP envelope vs message headers, with an annotated raw example: From/Sender/Reply-To, Message-ID, Received trace fields, Authentication-Results, DKIM-Signature, Return-Path, and more. - [Email forwarding and redirection](https://egressif.io/resources/guides/email-forwarding-and-redirection): Why forwarding breaks SPF and what survives, Sieve redirect, .forward/aliases, mailing-list DMARC breakage, SRS, and ARC. - [How to report email abuse](https://egressif.io/resources/guides/how-to-report-email-abuse): How to read headers to find the source, the abuse@ role mailbox, ARF, and where to report spam and phishing (provider tools, APWG, regulators, Spamhaus). - [Deliverability FAQ](https://egressif.io/resources/faq): 50 straight answers on inbox placement, sender rules, DMARC, SPF, DKIM, SMTP errors, bounces, spam filters, blocklists, and email law. - [Glossary](https://egressif.io/resources/glossary): 158 plain-language definitions across deliverability, authentication, reputation, blocklists, SMTP, transport security, suppression, spam filtering, and compliance. - [Sender requirements explained](https://egressif.io/resources/sender-requirements): What Gmail, Yahoo, and Microsoft require from senders (SPF, DKIM, DMARC, one-click unsubscribe, complaint thresholds) and how to stay ahead of enforcement. - [IP warming guide](https://egressif.io/resources/ip-warming): Why new sending IPs need warming, why calendar-based plans fail, and what demand-gated, outcome-driven ramps look like. - [Splitting transactional and marketing email](https://egressif.io/resources/transactional-marketing-split): Why receivers score senders rather than message types, symptoms of shared-reputation damage, and what a correct stream split involves. ## Reference library Deep, source-backed references. Every page cites its primary sources (RFCs, official provider/regulator/tool docs) and shows when it was last checked. ### Authentication - [Email authentication overview](https://egressif.io/resources/authentication/email-authentication-overview): How SPF, DKIM, DMARC, alignment, ARC, and BIMI fit together, and what each proves. - [DMARC in 2026 (RFC 9989/9990/9991)](https://egressif.io/resources/authentication/dmarc-2026): The obsolete RFC 7489 vs the current three-RFC DMARC standard, with tag changes, the DNS Tree Walk, and a migration path. - [SPF (RFC 7208)](https://egressif.io/resources/authentication/spf): Record format, mechanisms, qualifiers, the 10-lookup limit, why SPF breaks on forwarding, and DMARC alignment. - [DKIM (RFC 6376)](https://egressif.io/resources/authentication/dkim): Selectors, canonicalization, signing, key rotation, and why DKIM survives forwarding when SPF does not. - [ARC (RFC 8617)](https://egressif.io/resources/authentication/arc): How the Authenticated Received Chain preserves authentication across forwarders and mailing lists. - [BIMI](https://egressif.io/resources/authentication/bimi): Brand logos in the inbox, the enforced-DMARC prerequisite, SVG and VMC requirements. ### Sender requirements - [Provider rule tracker](https://egressif.io/resources/sender-requirements/provider-rule-tracker): Gmail, Yahoo, Microsoft, and Apple sender requirements compared side by side, with thresholds and effective dates. - [Gmail sender requirements](https://egressif.io/resources/sender-requirements/gmail): Google's bulk-sender rules, spam-rate targets, and Postmaster Tools. - [Yahoo sender requirements](https://egressif.io/resources/sender-requirements/yahoo): Yahoo/AOL requirements and Sender Hub. - [Microsoft sender requirements](https://egressif.io/resources/sender-requirements/microsoft): Outlook.com sender rules and high-volume enforcement. - [Apple Mail sender guidance](https://egressif.io/resources/sender-requirements/apple): What Apple iCloud Mail publishes, and Mail Privacy Protection's effect on open tracking. - [Orange / Wanadoo sender requirements](https://egressif.io/resources/sender-requirements/orange): France; mandatory SPF+DKIM+DMARC, connection limits, error-code table, SignalSpam feedback loops. - [GMX & WEB.DE sender requirements](https://egressif.io/resources/sender-requirements/gmx-webde): Germany; DKIM with alignment mandatory (SPF alone insufficient), double opt-in, M3AAWG/CSA. - [Comcast / Xfinity sender requirements](https://egressif.io/resources/sender-requirements/comcast-xfinity): US; rDNS, SenderScore rate limits, BL/RL codes, FBL, and the comcast.net-to-Yahoo migration. - [Fastmail sender requirements](https://egressif.io/resources/sender-requirements/fastmail): Score-based filtering, FCrDNS/HELO expectations, limited published bulk rules. - [Proton Mail sender requirements](https://egressif.io/resources/sender-requirements/proton): Encrypted provider; ML filtering, custom-domain auth, privacy implications for senders. ### SMTP errors and bounces - [Reading SMTP replies (RFC 5321)](https://egressif.io/resources/smtp-errors/reading-smtp-replies): Reply-code structure, 4xx vs 5xx, and retry behavior. - [Enhanced status codes (RFC 3463/5248)](https://egressif.io/resources/smtp-errors/enhanced-status-codes): The X.Y.Z code system and the most common codes senders see. - [Bounces and DSNs (RFC 3464/3461)](https://egressif.io/resources/smtp-errors/bounces-and-dsn): How a bounce is structured, hard vs soft classification, and DSN controls. ### Suppression and consent - [Suppression and consent](https://egressif.io/resources/suppression/suppression-and-consent): Suppression lists, one-click unsubscribe (RFC 8058), List-Unsubscribe (RFC 2369), and ARF feedback loops (RFC 5965/6650). ### Reputation and blocklists - [Sender reputation overview](https://egressif.io/resources/reputation/overview): What reputation is, how receivers build it, and what moves it. - [IP vs domain reputation](https://egressif.io/resources/reputation/ip-vs-domain-reputation): What attaches to the IP vs the domain, and what survives an IP change. - [Spamhaus blocklists](https://egressif.io/resources/reputation/spamhaus-blocklists): SBL, XBL, PBL, CSS, DBL, and ZEN, and how listings and delisting work. - [URI blocklists (SURBL/URIBL)](https://egressif.io/resources/reputation/uri-blocklists-surbl-uribl): Why a clean IP still gets filtered on a listed link or domain. - [DNSBL directory](https://egressif.io/resources/reputation/dnsbl-directory): How DNS blocklists work (RFC 5782/6471) and a compared directory of major lists (Spamhaus, SpamCop, Barracuda, Invaluement, 0spam, PSBL, UCEPROTECT) with how to use them responsibly. - [Deliverability frameworks and industry guidance](https://egressif.io/resources/reputation/m3aawg-sending-best-practices): An annotated map of who defines deliverability best practice - M3AAWG, CSA, IETF, Spamhaus, the mailbox providers, and the ESP vendor docs - and what each is best for. ### Transport security - [Encryption in transit overview](https://egressif.io/resources/transport-security/encryption-in-transit-overview): STARTTLS, opportunistic vs enforced TLS, the downgrade problem, and how MTA-STS and DANE fix it. - [MTA-STS](https://egressif.io/resources/transport-security/mta-sts): Requiring authenticated TLS for inbound mail (RFC 8461). - [TLS-RPT](https://egressif.io/resources/transport-security/tls-rpt): Reporting TLS delivery failures (RFC 8460). - [DANE for email](https://egressif.io/resources/transport-security/dane-for-email): TLSA records and the DNSSEC dependency (RFC 7672), and DANE vs MTA-STS. ### Postmaster tools - [Postmaster tools overview](https://egressif.io/resources/postmaster/overview): What Google, Microsoft, Yahoo, and Apple expose about your sending, and what they do not. - [Google Postmaster Tools](https://egressif.io/resources/postmaster/google-postmaster-tools): Domain/IP reputation, spam rate, and authentication as Gmail sees it. - [Microsoft SNDS and JMRP](https://egressif.io/resources/postmaster/microsoft-snds-jmrp): Outlook.com sending data and complaint feedback. - [Yahoo Sender Hub](https://egressif.io/resources/postmaster/yahoo-sender-hub): Yahoo's sender dashboard and complaint feedback loop (and Apple's limited surface). ### Spam filtering (receiver-side methods) - [Spam filtering overview](https://egressif.io/resources/spam-filtering/overview): How receiver-side filtering works end to end and why there is no single threshold. - [Bayesian spam filtering](https://egressif.io/resources/spam-filtering/bayesian-spam-filtering): Statistical filtering, training, and why list hygiene protects senders. - [Fuzzy hashing and near-duplicate detection](https://egressif.io/resources/spam-filtering/fuzzy-hashing-near-duplicate): How filters catch bulk mail that varies slightly per recipient. - [DCC, Pyzor, and Razor](https://egressif.io/resources/spam-filtering/dcc-pyzor-razor): Collaborative checksum networks and what they catch. - [SpamAssassin architecture](https://egressif.io/resources/spam-filtering/spamassassin-architecture): Rules, scores, and the score-combination model. - [Rspamd architecture](https://egressif.io/resources/spam-filtering/rspamd-architecture): Symbols, weights, and the action-threshold model. - [Greylisting and rate controls](https://egressif.io/resources/spam-filtering/greylisting-tarpitting-rate-controls): Temporary deferral, tarpitting, and rate limits (RFC 6647). - [Avoiding false positives](https://egressif.io/resources/spam-filtering/false-positives-ham-protection): What legitimate senders do so filters do not misclassify them. - [Spam corpora and evaluation](https://egressif.io/resources/spam-filtering/spam-corpora-and-evaluation): How filters are measured (TREC spam track, corpora, metrics). ### Legal compliance - [Email laws overview](https://egressif.io/resources/compliance/email-laws-overview): Consent models and requirements across the US, Canada, UK, EU, Australia, and Turkey. - [US CAN-SPAM](https://egressif.io/resources/compliance/us-can-spam): The opt-out model, honesty rules, physical address, and unsubscribe timeframe. - [Canada CASL](https://egressif.io/resources/compliance/canada-casl): Express vs implied consent and CRTC enforcement. - [UK PECR](https://egressif.io/resources/compliance/uk-pecr): Opt-in and soft opt-in under PECR and UK GDPR. - [EU GDPR and ePrivacy](https://egressif.io/resources/compliance/eu-gdpr-eprivacy): Consent, lawful basis, and the soft opt-in exception. - [Australia Spam Act](https://egressif.io/resources/compliance/australia-spam-act): Consent, identification, and functional unsubscribe. - [Turkey KVKK and ETK](https://egressif.io/resources/compliance/turkey-kvkk-etk): Commercial-message rules and the IYS system. - Note: compliance pages are general information, not legal advice. ### Standards - [Email RFC library](https://egressif.io/resources/rfc-library): A filterable catalog of ~475 RFCs that define email (SMTP, MIME, IMAP, POP3, JMAP, Sieve, DKIM, DMARC, DANE, MTA-STS, DNSSEC, S/MIME, calendaring and more), each marked current, informational, obsolete, or historical, sourced from the RFC Editor index. - [Standards & implementations (non-RFC)](https://egressif.io/resources/standards-and-implementations): The email machinery that is not RFC-defined: SpamAssassin, Rspamd, DCC, Pyzor, Razor, BIMI, SRS, blocklist operators, research corpora, provider rules, and the law. - [Methodology](https://egressif.io/resources/methodology): How these references are researched, verified, and cited. ## Company - [Why Egressif](https://egressif.io/why-egressif): Vertically integrated email infrastructure with a deliverability team that owns the outcome. - [How pricing works](https://egressif.io/pricing): Managed infrastructure priced per mailbox and per sending volume; custom builds and audits scoped per project; month-to-month terms. - [About](https://egressif.io/about): Our mission and approach to email deliverability. - [Contact](https://egressif.io/contact): Talk to our team. ## Notes - Egressif follows recognized email authentication and sender best practices. - Egressif does not read message content and does not store message bodies for delivery; where it hosts mailboxes, their contents are stored only to run the mailbox and are never read. - Egressif can operate as your whole stack or as an operating layer on top of an existing ESP (SendGrid, Amazon SES, Postmark, or your own network). - Egressif processes data in the United States and is not itself SOC 2 certified, though its infrastructure runs in SOC 2-certified datacenters. - Egressif enforces a strict acceptable-use and anti-abuse policy across its network.