Checked
Sendtier vs Postmark: storage location and features
Compare Sendtier's public preview with Postmark on data location, sending features, limits, and pricing.
Postmark stores customer and message data in the United States and says it has no plans to add servers in the EU. Sendtier, a public preview, stores message data in AWS Frankfurt and sends through Amazon SES.
Live sending is limited during the public preview. The comparison was checked on 7 October 2026.
Data location
Postmark's GDPR FAQ states that it stores customer data, including data processed for customers, in the United States.
The EU privacy page says "Postmark's primary data and servers are hosted at Deft's data center (located outside of Chicago), and Amazon Web Services (AWS). We currently don't have plans to add servers in the EU (GDPR does not require physical servers in the EU)."
The sub-processor table on that page lists Deft for infrastructure hosting and Amazon Web Services for cloud infrastructure hosting. Those rows name a purpose and do not name a country. The GDPR FAQ says "All sub-processors we use (as per 2021), are based in the US."
The terms name AC PM, LLC and are governed by the laws of the State of Illinois. They provide for binding arbitration in Cook County, Illinois. The DPA says AC PM "has certified its compliance to the EU-U.S. Data Privacy Framework Principles", including the UK Extension and the Swiss-U.S. Data Privacy Framework. Where a transfer needs them, it uses the 2021 Standard Contractual Clauses under Module Two and the UK Addendum.
MB Tobuli operates Sendtier in AWS eu-central-1 (Frankfurt). The API, workers, Postgres database, automated backups, and queues stay in that region, and email is sent through Amazon SES there. AWS is a subprocessor, and the subprocessor list is still a draft. The database stores the sender, recipients, subject, HTML and text bodies, tags, status, and delivery events. Raw MIME is not stored. Emails, events, and webhook deliveries are kept 30 days by default, in daily partitions, then removed. Organization owners can export the data and delete the organization, with a 30-day restore window. See retention.
Postmark keeps email content, events, and metadata for 45 days by default, then deletes that content and related metadata for delivered messages. Aggregated statistics stay, including bounces and spam complaints. The pricing file lists an add-on from $5 a month, on Pro plans or higher, from 7 to 365 days.
Postmark routes SMTP connections to nearby AWS endpoints, according to its SMTP guide. The guide does not specify endpoint regions or document region selection. That routing is not where the data is stored: transactional mail uses smtp.postmarkapp.com, and broadcast mail uses smtp-broadcasts.postmarkapp.com.
Comparison
The pricing file lists a free plan at $0 a month for 100 emails, with no overages, and says "Use it for however long you need, it doesn't expire." It also says there is no tier between 100 emails a month and 10,000. Sendtier's Pro and Scale plans are planned and not on sale. See pricing.
Both services count recipients toward sending volume. Postmark's Messages API groups a multi-recipient send as one message; that is a reporting distinction. The pricing file bills emails sent and received, and sandbox sends count toward the monthly volume. Sendtier counts recipients, not messages, so ten recipients on one message count as 10, and its allowances reset at 00:00 UTC.
| Feature | Postmark | Sendtier (public preview) |
|---|---|---|
| Data storage location | United States. Deft, outside Chicago, and AWS. The EU privacy page says there are no plans to add servers in the EU. The AWS region is not named. | AWS eu-central-1 (Frankfurt). Sender, recipients, subject, HTML, text, tags, status, and delivery events. Raw MIME is not stored. Backups stay in the region. |
| Free tier | $0/month for 100 emails. No overages. The plan does not expire. Pricing file. | 3 000 recipients a month and 100 a day. Live sending is limited during the public preview. |
| Paid plans | At 10,000 emails a month: Basic $15.00, Pro $16.50, Platform $18.00. Unlimited emails a day. Overage from 10,000 to 125,000 is $1.80, $1.30, and $1.20 per 1,000. Pricing file. | Pro and Scale are planned and not on sale. |
| Recipient counting | Each recipient counts toward sending volume. Inbound and sandbox messages also count. Monthly pricing. | Each recipient counts, not each message. |
| Testing before domain verification | A sandbox server will never send messages to a recipient. Activity still shows Delivered, the sends count toward monthly volume, and the server type cannot be changed later. Postmark live sending requires a confirmed Sender Signature or a verified sending domain. DKIM and Return-Path are not absolutely mandatory for that signature. Domain verification requires a DKIM record. Sandbox, getting started. | A test key accepts a send from a domain you have added, before DNS is verified. The email is never delivered. Cap: 1 000 recipients a day. A live key needs a verified domain. Live sending is limited during the public preview. |
| Bounce details | Details on the bounce API, with an example that begins smtp;554 delivery error. Delivery Details is the destination server's response line. An example begins 250 2.0.0 OK. Bounce API, delivery webhook. | SES bounce type, plus the receiving server's reply when Amazon SES reports one. |
| Automatic suppressions | Hard bounce, spam complaint, unsubscribe, or manual suppression, on that message stream. Postmark will not let you reactivate a spam complaint in the product. Subscription change, spam complaint. | Permanent bounces and complaints add the address. Transient and undetermined bounces do not. A later send returns 422 recipient_suppressed. |
| Webhooks and their security | No HMAC. HTTPS, HTTP Basic Auth in the URL, and IP allowlisting. Overview retries cover 5xx, 408, 429, and network failures, after 1, 5, 10, 10, 10, and 15 minutes. Other 4xx responses are dropped. The bounce page retries any non-2xx response, or a timeout. Overview, bounce webhook. | Sendtier-Signature: t=<unix seconds>,v1=<hex HMAC-SHA256> over the timestamp, a period, and the raw body. Tolerance is 5 minutes. The previous secret stays valid 24 hours, with two v1 values. Retries: 30 seconds, 1 minute, 5 minutes, 15 minutes, 30 minutes, 1 hour, 2 hours, 4 hours, 8 hours, for up to 24 hours. |
| Message streams | Transactional and broadcast streams, kept apart, including IP ranges. MessageStream defaults to outbound. Getting started. | No stream field on the send request. |
| Cc, Bcc, and Reply-To | Cc, Bcc, and ReplyTo. To, Cc, and Bcc together allow 50 recipients. Email API. | Not supported. |
| Attachments | Supported through the Email API, using Name, base64 Content, ContentType, and optional ContentID. | Not supported. |
| Custom headers | A Headers array of name and value. Email API. | Not supported. |
| Templates | TemplateId or TemplateAlias, plus TemplateModel, on /email/withTemplate. Templates API. | Not supported. |
| SMTP relay | Ports 25, 2525, and 587, with STARTTLS. Server token, or an access key and secret. SMTP guide. | Not supported. |
| Published SDKs | TypeScript, Node.js, Python, Ruby, Rails, PHP, .NET, and Java, plus a CLI and plugins. Libraries. | Not published. TypeScript, Go, and PHP source exists in the repository. Use HTTP. |
| Batch size | Up to 500 messages and 50 MB, including attachments. HTTP 200 can still contain a failed message. Email API. | 1 to 100 messages. Body cap 10 MiB. |
| Dedicated IPs | $50 per IP per month, from 300,000 messages a month, on Pro or higher. Another IP is described at 100,000 messages a day. Dedicated IPs, pricing file. | Not supported. |
Bounce details
Postmark will not let you reactivate a spam complaint in the product, though you can ask support to review one.
Sendtier stores Permanent, Transient, or Undetermined, the subtype, and, when Amazon SES includes them, the action, a status such as 5.1.1, and the diagnostic code. That code is the receiving server's reply when the server returns one.
SES can omit the code. The reporting MTA and remote MTA IP are stored when SES sends them, and a delivery event keeps the SMTP response and the remote MTA. The SES type decides suppression, not the SMTP digits: permanent bounces and complaints add the address, and transient and undetermined bounces do not. You can add, list, and remove suppressions through the API. A send to an address still on the suppression list returns 422 recipient_suppressed. See suppressions and errors.
Webhook signatures
The overview says "Postmark does not currently support HMAC webhook signature verification." It recommends HTTPS, HTTP Basic Auth in the URL, and an IP allowlist. Its retry list, in the table, does not match the bounce webhook page, which says "Postmark retries on any non-2xx response or when your endpoint times out." Read both before you depend on a retry. Postmark also documents subscription-change and inbound webhooks in its overview.
Sendtier signs the raw body with Sendtier-Signature, so reject a timestamp more than five minutes off. The webhooks guide shows the constant-time compare. Rotation keeps the previous secret for 24 hours, and you can inspect a delivery and send it again. Provider events are email.delivered, email.bounced, email.complained, email.delayed, and provider failures.
Where Postmark is the better choice
Postmark is a better fit when your application needs SMTP, published libraries, templates, or other features listed below.
- Postmark live servers send to recipients. Live sending is limited during the public preview.
- Postmark publishes client libraries. The libraries page says they are "maintained by the developers at Postmark."
- Postmark has SMTP,
Cc,Bcc,ReplyTo, attachments, custom headers, templates, separate streams, and 500-message batches. - Sandbox activity shows Delivered. Paid plans include unlimited emails a day, and dedicated IPs are $50 per IP per month.
- 45-day content retention, with an add-on from 7 to 365 days. Sendtier's default is 30 days.
- A bounce dump, per-stream suppressions, inbound webhooks, and a sender signature that can send before DKIM is in place. Domain verification still requires the DKIM record.
Where Sendtier fits
Sendtier is an option for evaluating an HTTP email API with message data stored in AWS Frankfurt.
A test key accepts a send before DNS is verified, and those emails are never delivered. Each key allows 10 requests a second, with a burst of 20. A request over that limit returns 429 rate_limited with Retry-After. See rate limits.
scheduled_at accepts a time up to 72 hours ahead. The scheduling article says "It is not possible to schedule emails to be sent at a later time through Postmark." An Idempotency-Key replays the stored response, and a changed body returns 409 idempotency_conflict. The idempotency article says "Postmark does not currently support an idempotency key feature." Sendtier signs its webhooks. See sending.
Switching from Postmark
The migration guide has the field list. Live sending is limited during the public preview. Rollback means pointing the code back at Postmark: the URL, the token, the field mapping, and the webhook check.
Change the host and the key
Replace POST https://api.postmarkapp.com/email and X-Postmark-Server-Token with POST https://api.sendtier.com/emails and Authorization: Bearer st_test_… or st_live_…. The API overview says "Postmark has two types of API tokens", and it documents POSTMARK_API_TEST for a validity check. Add your domain, send from an address on it, and use your own test key. A test key accepts the call while DNS is pending, and that message is not delivered.
Change the body
Map HtmlBody to html and TextBody to text, and send at least one. To becomes an array of 1 to 50 addresses. Cc, Bcc, ReplyTo, Headers, Attachments, template fields, and MessageStream are absent, so change that code first. Map Postmark's Tag to a named entry such as tags.category. Copy string-valued Metadata entries into tags. Split batches into requests containing an emails array of 1–100 messages, within 10 MiB. Sendtier returns HTTP 202 with a data array. If any item fails validation, none is queued. Use a distinct idempotency key for each new send or batch. Reuse that key and the identical request body when retrying.
Change the webhook check
Follow the webhooks guide to verify Sendtier-Signature, because Basic Auth in the old URL does not check that signature. Export the suppression list from each Postmark Message Stream, then add the addresses you need to keep blocked through the suppressions API.
DNS
The records are listed on the domains page. The usual return-path host is pm-bounces, a CNAME to pm.mtasv.net. Sendtier uses send.<domain>, MX 10 feedback-smtp.eu-central-1.amazonses.com, and TXT v=spf1 include:amazonses.com ~all. If Postmark already uses send.<domain> for its Return-Path, its CNAME conflicts with Sendtier's MX and TXT records. The SPF article says "You cannot have both a CNAME and a TXT record (for SPF) on your subdomain at the same time."
How these facts were checked
Public Postmark pages were checked on 7 October 2026, and the Sendtier product facts were checked against the code. Delivery speed, inbox placement, and uptime were not measured, and the Data Privacy Framework registry was not opened. Both webhook retry descriptions are included above.
Start free with a test key. Test messages are not delivered, and the quickstart shows the request.
Sources
- GDPR FAQ
- EU privacy
- Terms of service
- Data processing addendum
- Message retention
- SMTP guide
- Pricing file
- Monthly pricing
- Sandbox servers
- Messages API
- Getting started
- Bounce API
- Delivery webhook
- Subscription change webhook
- Spam complaint webhook
- Webhooks overview
- Bounce webhook
- Email API
- Templates API
- Official libraries
- Dedicated IPs
- Scheduling
- Idempotency
- API overview
- Custom return path
- SPF setup