Mail icon with notification bubble

Company updates

Secure API sending to trusted IPs with Allowlisting

We are releasing a new security setting in our UI called IP Allowlisting. Securing sending is essential when sending emails through Postmark. IP Allowlisting adds a new layer of protection for API sending. You define the IP ranges allowed to send email through the Postmark API and sending requests sent from outside those ranges are rejected with a 403 status code.

Show details

Here's how it works — You can add up to 10 IP ranges (in IPv4 CIDR format) that are allowed to send email using the Postmark API. Send requests originating from outside these ranges will be rejected with a 403 status code.

You can set this at two levels:

  • Account — applies to every email sent on your account.
  • Servers — applies to a single Server. When a Server has its own allowlist, it overrides the account-level setting for that Server. Otherwise, the account-level ranges apply.

A few things to know before you turn it on:

  • Allowlisting is designed to protect API sends. Please be aware that SMTP isn't checked against your ranges.
  • It's configured in the UI by design. Keeping allowlist changes out of the API adds another layer of control over who can touch your sending protections.
  • Allowlisting is not a Firewall/WAF replacement. It controls which IPs can send email through your account. It doesn't change or override any network-level security rules, and an IP on your allowlist can still be blocked by other security measures outside of Postmark's send path. Think of it as one specific control — who can send — not a general-purpose network shield.

May, 2022

Postmark has been acquired by ActiveCampaign

We’re excited to share that Postmark and DMARC Digests have been acquired by ActiveCampaign. With the support of ActiveCampaign, we’ll have the resources to make Postmark even better—and we can’t wait to take you along for the ride.

Read more on the blog →

Show details

What does this mean for me as a Postmark customer?

We know you might have some questions. Like…

  • Will Postmark’s pricing change? (No.)

  • Will Postmark continue to be available as a standalone product or will you integrate into ActiveCampaign? (Yes and yes.)

  • Will Postmark stay yellow? (Oh yes!)

We’re answering these questions and more in our public and ever-evolving FAQ. Do you have a question we didn’t cover? Let us know and we’ll get it added (and give you an answer, obviously.)

Read the FAQ


December, 2021

Update on the recent Log4j vulnerability

As you are most likely aware by now, the recent Log4j vulnerability has affected many companies. After the exploit was made public on December 10th, our engineers immediately began a thorough investigation to determine if our systems were vulnerable.

Show details

We do not use Java or Log4j in our products, including Postmark. We did, however, identify an internal system that was vulnerable. A component of our logging system uses Log4j to ingest logs and transfer them to a searchable database that is used internally by our staff. We immediately shut down this system and rebuilt it with a version of Log4j that is not vulnerable.

This logging system does not have access to customer credentials (including passwords and payment information), API keys, or templates, although some log messages do include headers from emails sent by Postmark. That said, we conducted a deep review of the affected system over the past few days and there is no evidence that suggests unauthorized access of any kind.

We will continue to remain vigilant and investigate this incident further, and will update this post if we find any additional information or evidence of unauthorized access. If you have any questions, please reach out at any time. We’re here to help.

December, 2017

New lower pricing and monthly plans

Postmark now offers monthly plans instead of credits, and the new plans will likely save you money. Here's everything you should know about Postmark's new pricing model.

August, 2017

Huge updates to the support home page

We’ve really expanded our documentation. More guides, help docs, blog posts, open source projects, and developer docs. Unfortunately, that proliferation led to fragmentation. So we set aside time to unify all of our documentation into a single home and make it all searchable.