🔒 NexoraMail is transactional email only — cold email and bulk marketing are strictly prohibited. View Acceptable Use Policy
Home
Platform
Security & Compliance
Pricing
Dashboard
Terms of Service
Privacy Policy
Acceptable Use Policy
Anti-Spam Policy
Data Processing Agreement
Contact
🔒 SOC 2 Ready · CAN-SPAM Compliant · GDPR Compliant

Enterprise Transactional
Email Infrastructure

NexoraMail delivers mission-critical transactional emails — password resets, account notifications, order confirmations, and system alerts — with enterprise-grade reliability for SaaS applications, fintech platforms, and e-commerce systems.

TLS 1.3 Encrypted
AWS SES Infrastructure
99.9% Uptime SLA
Opt-In Only Policy
GDPR & CAN-SPAM
99.4%
Average delivery rate
<0.08%
Complaint rate maintained
850ms
Average time-to-inbox
100%
Transactional use only
Use Cases

Built for Transactional Workflows

NexoraMail handles system-triggered, user-expected email — never cold outreach, bulk marketing, or unsolicited messages.

🔑
Authentication Emails
Password resets, magic link logins, two-factor authentication codes, and account verification emails requiring immediate, reliable delivery.
🛒
Order Notifications
Order confirmations, shipping updates, delivery receipts, and return authorizations for e-commerce and marketplace platforms.
💳
Financial Alerts
Transaction receipts, payment confirmations, invoice delivery, account balance alerts, and fraud notifications for fintech applications.
🔔
System Notifications
Platform alerts, service status updates, API quota warnings, deployment notifications, and infrastructure monitoring alerts.
👤
Account Lifecycle
Welcome emails for new users who signed up, subscription renewal notices, account suspension warnings, and data export ready notifications.
📅
Scheduled Digests
Weekly usage summaries, invoice delivery on billing cycles, scheduled report delivery, and digest notifications explicitly requested by users.
🚫
What NexoraMail Does NOT Support
NexoraMail is a transactional email infrastructure platform exclusively. We do not support, permit, or enable: cold email outreach, bulk marketing campaigns, newsletters to purchased lists, promotional blasts, affiliate email programs, or any email sent to recipients who have not explicitly opted in to that specific communication. Accounts attempting to use NexoraMail for non-transactional purposes are suspended immediately without refund.
Infrastructure

Everything You Need for Reliable Delivery

A complete suite of enterprise email infrastructure tools, built on AWS best practices and designed for high-stakes transactional use cases.

📡
SMTP Relay
High-throughput SMTP relay with TLS enforcement and connection pooling.
REST API
JSON-based RESTful API with SDK support for Python, Node.js, PHP, and Go.
🔐
SPF / DKIM / DMARC
Guided domain authentication setup with automated verification checks.
📊
Real-Time Monitoring
Per-message delivery tracking with live bounce and complaint dashboards.
🚫
Suppression Lists
Automatic suppression of bounced, complained, and unsubscribed addresses.
🔗
Webhooks
Real-time event webhooks for delivery, bounce, open, and complaint events.
⚙️
Rate Limiting
Configurable sending rates with burst protection and queue management.
🤖
Abuse Detection
Automated pattern detection that flags and restricts anomalous sending behavior.
Compliance First

Designed Around Regulatory Requirements

NexoraMail adheres to major international regulations governing electronic messaging and data privacy.

🇺🇸
CAN-SPAM Act Compliance
All outbound messages comply with the U.S. Controlling the Assault of Non-Solicited Pornography And Marketing Act. We enforce sender identification, honest subject lines, and clear opt-out mechanisms on all applicable message types.
🇪🇺
GDPR Data Processing
Our Data Processing Agreement (DPA) covers all EU-originating email data. We process recipient data only as directed by the controller, maintain data minimization standards, and support your GDPR Article 28 obligations.
☁️
AWS Sending Best Practices
Built on AWS infrastructure and designed in accordance with AWS SES sending guidelines. We enforce domain verification, monitor complaint rates against AWS thresholds, and immediately action accounts that risk shared IP reputation.
Onboarding

Up and Running in Four Steps

1
Request Access
Submit your application with your company details and intended use case for compliance review.
2
Verify Your Domain
Add SPF, DKIM, and DMARC DNS records. Sending is disabled until domain authentication is confirmed.
3
Configure API or SMTP
Integrate with your application using our REST API or standard SMTP credentials.
4
Monitor & Scale
Track delivery performance in real time. Expand volume as your application grows.
Developer-First

Simple API,
Powerful Delivery

Send transactional emails with a single API call. Our SDK handles authentication, retries, and error handling. Your application focuses on logic — we handle deliverability.

Python SDK Node.js SDK PHP SDK Go SDK REST API SMTP Relay
send_email.py
import nexoramail
 
# Initialize client
client = nexoramail.Client(
  api_key="nm_live_xK9..."
)
 
# Send transactional email
response = client.send({
  "to": "user@example.com",
  "from": "noreply@yourdomain.com",
  "subject": "Your password reset link",
  "template_id": "pwd-reset-v2"
})
 
# ✓ Message queued: msg_4xK7JmNp...
>>>

Ready for Production-Grade Email?

Join companies that rely on NexoraMail for their most critical transactional communications.

Platform

Complete Email Infrastructure for Developers

Every component your application needs to send transactional emails reliably, securely, and at scale — from SMTP relay to advanced deliverability monitoring.

📡 SMTP Relay

High-Throughput SMTP Relay Service

Connect your application to NexoraMail via standard SMTP with TLS 1.3 enforcement. Our relay service handles connection pooling, automatic retry logic, and queue management — so your application never needs to worry about transient delivery failures.

  • TLS 1.3 enforced on all connections
  • STARTTLS support for legacy integrations
  • Port 587 (submission) and 2525 available
  • Connection pooling for high-volume apps
  • Automatic retry with exponential backoff
SMTP Configuration
# SMTP Connection Settings
SMTP_HOST=smtp.nexoramail.us
SMTP_PORT=587
SMTP_USER=apikey
SMTP_PASS=nm_live_xK9mP2...
SMTP_TLS=STARTTLS
 
# From address must match verified domain
FROM_ADDRESS=no-reply@yourdomain.com
 
✓ Domain verified
✓ DKIM signing active
✓ Sending enabled
POST /v1/messages
// Request
POST https://api.nexoramail.us/v1/messages
Authorization: Bearer nm_live_xK9...
 
{
  "to": ["alice@company.com"],
  "from": "orders@yourapp.com",
  "subject": "Order #8821 confirmed",
  "template_id": "order-confirm",
  "variables": { "order_id": "8821" }
}
 
// Response 200 OK
{ "id": "msg_4xK7JmNpRq", "status": "queued" }
⚡ RESTful API

Fully-Featured RESTful API

Our JSON REST API provides programmatic access to all NexoraMail features. Authenticate with API keys, send messages, manage templates, retrieve delivery logs, and administer suppression lists — all over HTTPS.

  • JSON request/response format
  • Bearer token authentication
  • Idempotency key support
  • Batch send endpoint (up to 1,000/request)
  • OpenAPI 3.0 specification available
All Features

Full Infrastructure Feature Set

🔐
Domain Authentication (SPF/DKIM/DMARC)
Guided setup wizard walks through DNS record configuration. Automated verification checks run every 15 minutes. Sending is blocked until SPF and DKIM are confirmed. DMARC policy enforcement strongly recommended. All authenticated domains display a verified badge in the dashboard.
📊
Real-Time Delivery Monitoring
Live dashboards track every message through the delivery pipeline: queued → submitted → accepted → delivered. Per-domain and per-campaign delivery rate graphs refresh every 60 seconds. Delivery failure reasons are categorized (DNS failure, mailbox full, policy reject, etc.) and surfaced in the event log.
🚨
Bounce & Complaint Tracking
Hard bounces are automatically added to the suppression list and will never be delivered to again. Complaint feedback loops (FBL) from major ISPs are processed in real time. If your complaint rate exceeds 0.08%, an alert is triggered. At 0.1%, sending is automatically restricted until manual review.
🚫
Suppression List Management
Centralized suppression list automatically populated from bounces, complaints, and manual unsubscribes. Import existing suppression data via CSV or API. Any send attempt to a suppressed address is silently dropped and logged. Suppressed addresses are retained indefinitely across account resets.
🔗
Webhook Event Delivery
Subscribe to real-time events: delivered, bounced, complained, opened, clicked, unsubscribed. Signed HMAC payloads verify authenticity. Retry logic with exponential backoff ensures delivery. Webhook logs show delivery history for the past 30 days with manual replay capability.
⚙️
Rate Limiting & Queue Management
Per-account and per-domain send rate limits protect your reputation. Burst allowances handle traffic spikes. Messages that exceed instantaneous rate limits are queued rather than rejected. Configurable queue depth and priority classes ensure critical emails (password resets, fraud alerts) are never delayed.
🤖
Automated Abuse Detection
Machine learning models analyze sending patterns in real time. Anomalies — sudden volume spikes, unusual recipient domains, high invalid-address rates — trigger automatic account reviews. Repeat violations result in permanent suspension. All abuse reports are investigated by our Trust & Safety team within 24 hours.
📝
Template Engine
Manage transactional email templates directly in the dashboard or via API. Support for HTML and plain-text versions. Variable substitution with safe defaults. Template versioning with rollback capability. Preview rendering across major email clients via integrated testing.
🔑
API Key Management
Create scoped API keys with granular permissions (send-only, full-access, read-only). Set expiration dates and IP allowlists per key. Rotate keys without downtime via overlap period. Full audit log of every API key action: creation, usage, rotation, and revocation.

Explore the Full Platform

Request access and see NexoraMail's dashboard with your own transactional data.

Security & Compliance

Built for the Strictest Compliance Requirements

Infrastructure security, regulatory compliance, and anti-abuse enforcement are not optional add-ons at NexoraMail — they are foundational requirements embedded in every layer of our platform.

🇺🇸
CAN-SPAM Compliant
Enforced at the platform level for all outbound messages.
🇪🇺
GDPR Ready
Data Processing Agreement available. EU data handling documented.
🔒
TLS 1.3 Everywhere
All API calls and SMTP connections require TLS. No plaintext allowed.

Infrastructure Security

🌐
Network Architecture
NexoraMail operates on AWS infrastructure distributed across multiple availability zones. All services run within private VPCs with no direct public internet exposure. Public endpoints are fronted by Web Application Firewalls (WAF) with DDoS mitigation. All internal service-to-service communication is encrypted. Network access control lists (NACLs) restrict traffic to necessary ports and protocols only.
🔑
Data Encryption
All data at rest is encrypted using AES-256 via AWS KMS-managed keys. All data in transit is protected with TLS 1.3 minimum. API keys and SMTP credentials are stored using PBKDF2 key derivation with unique salts per credential. Email content is stored transiently during delivery and purged within 72 hours of final delivery status. Log data is retained for 90 days and encrypted at rest.
🔐
Access Control
Multi-factor authentication (MFA) is required for all dashboard access. Role-based access control (RBAC) supports Admin, Developer, and Viewer roles. API keys are scoped by permission set and can be further restricted to specific IP ranges. All administrative actions are recorded in an immutable audit log retained for 12 months. Privileged infrastructure access requires dual authorization and is logged to a separate, read-only audit store.
🏢
Physical & Organizational Security
All compute infrastructure runs on AWS, which maintains SOC 1/2/3 certifications and ISO 27001 compliance for physical data center security. NexoraMail personnel with infrastructure access are subject to background screening and least-privilege access policies. Security incident response procedures are tested quarterly. Vulnerability scanning is conducted continuously with critical patches applied within 24 hours.

GDPR Compliance

🇪🇺
General Data Protection Regulation (GDPR) – EU 2016/679
NexoraMail acts as a data processor under GDPR when processing email-related personal data on behalf of our customers (who are data controllers). We process recipient email addresses, delivery metadata, and engagement events only as instructed by the controller and only for the purpose of email delivery. Our Data Processing Agreement (DPA) is available upon request and covers all obligations under GDPR Article 28, including sub-processor disclosure, security measures, breach notification, and data subject rights assistance.
Data Minimization
We collect only the data necessary for email delivery: recipient address, message headers, and delivery timestamps. Message body content is not indexed, analyzed for commercial purposes, or retained beyond the delivery window.
Data Subject Rights
We assist controllers in honoring data subject requests for erasure, portability, and access. Suppression list entries can be exported or deleted via API. Erasure requests for delivery logs can be submitted to support@nexoramail.us.
Data Transfers
EU-originating data is processed in AWS us-east-1 (N. Virginia) under Standard Contractual Clauses (SCCs). We do not transfer personal data to countries without adequate protection frameworks without documented controller consent.

Anti-Spam Enforcement Policy

⚠️
Zero Tolerance for Spam
NexoraMail has a strict zero-tolerance policy for spam and unsolicited email. Any account found sending unsolicited messages will be suspended immediately and permanently without refund. We actively monitor sending patterns and recipient feedback to detect and prevent abuse. Attempts to circumvent these policies using false registration information will be reported to relevant authorities.
Complaint Rate Thresholds
We enforce strict complaint rate limits aligned with industry standards and AWS SES guidelines:

0.05% — Warning Alert: Dashboard warning and email notification sent to account owner.

0.08% — Automatic Review: Account flagged for compliance review. Sending continues with monitoring.

0.10% — Automatic Restriction: Sending suspended pending manual compliance review. Account owner must remediate.

0.20%+ — Permanent Suspension: Account permanently suspended with no reinstatement.
Prohibited Sending Practices
The following practices result in immediate account suspension:

• Sending to purchased, rented, or harvested email lists
• Sending to scraped or third-party-sourced addresses
• Cold outreach of any kind
• Bulk marketing campaigns or newsletters without documented opt-in
• Sending to recipients who have not explicitly requested the communication
• Disguising the true sender identity or using deceptive subject lines
• Repeatedly mailing to known-invalid addresses
• Affiliate email marketing of any kind

Sending Requirements

Domain Verification Required Before First Send
All sending domains must complete SPF and DKIM verification before any message can be dispatched. DMARC policy is strongly recommended. Unverified domains are blocked at the API layer. Verification is automated and typically completes within 15 minutes of correct DNS record publication.
Explicit Opt-In Documentation Required
All recipient email addresses must have been explicitly collected through a confirmed opt-in process. Pre-checked consent boxes, double opt-in confirmations, and sign-up form documentation are examples of acceptable consent records. NexoraMail may request evidence of consent practices during onboarding review or compliance investigations.
Unsubscribe Mechanism Mandatory
All non-purely-transactional messages (such as scheduled digests, even those explicitly requested) must include a functioning one-click unsubscribe mechanism. Unsubscribe requests must be honored within 10 days. NexoraMail automatically processes list-unsubscribe headers and adds processed recipients to the account suppression list.
Accurate Sender Identification Required
The "From" header must accurately represent the sending organization. Display names must not impersonate other companies or brands. Return-Path domains must be domains owned by the account holder. Misleading or deceptive sender identification is grounds for immediate suspension and may constitute a CAN-SPAM violation.
List Hygiene Strongly Recommended
We recommend removing hard-bounced addresses promptly (NexoraMail does this automatically), suppressing recipients with long inactivity periods, and periodically re-confirming opt-in for recipient lists older than 12 months. Healthy sending lists correlate directly with delivery rate and inbox placement.
Pricing

Simple, Transparent Pricing

Predictable monthly pricing based on email volume. All plans include full platform access, domain authentication, real-time monitoring, and compliance enforcement.

Starter
$29/mo
Up to 10,000 emails/month
+$0.80 per 1,000 additional
  • SMTP Relay & REST API access
  • Up to 3 verified sending domains
  • SPF, DKIM, DMARC setup wizard
  • Real-time delivery dashboard
  • Bounce & complaint tracking
  • Automatic suppression list
  • 5 webhook endpoints
  • 7-day event log retention
  • Email support (48hr response)
Enterprise
Custom
Custom volume — manual approval required
Compliance review for all high-volume accounts
  • Everything in Growth, plus:
  • Unlimited verified domains
  • Dedicated sending infrastructure
  • Custom IP warm-up plan
  • SLA guarantee (99.9% uptime)
  • 90-day event log retention
  • Dedicated account manager
  • Custom webhook integrations
  • GDPR DPA & MSA included
  • Slack/Teams shared channel support
📋
High-Volume Account Compliance Review
High-volume accounts (Growth and Enterprise) require a compliance review before activation. This review evaluates your use case, recipient list acquisition methods, opt-in documentation, and sending history. Accounts that cannot demonstrate compliant sending practices will not be approved regardless of business size. This process protects all NexoraMail customers by maintaining shared IP reputation and deliverability standards.

Plan Comparison

Feature Starter Growth Enterprise
Monthly volume10,000100,000Custom
SMTP Relay
REST API
Verified domains310Unlimited
Dedicated IPsOn requestIncluded
Webhooks5 endpointsUnlimitedUnlimited + custom
Event log retention7 days30 days90 days
Bounce/complaint alerts✅ + auto-escalation
Suppression list
Template engine
GDPR DPAOn requestOn requestIncluded
SupportEmail 48hrPriority 12hrDedicated manager
Compliance review✅ (mandatory)
SLA guarantee99.9% uptime

Frequently Asked Questions

Can I use NexoraMail to send marketing newsletters?
No. NexoraMail is exclusively a transactional email infrastructure platform. We do not support marketing newsletters, promotional campaigns, or any form of bulk commercial messaging. If you require marketing email capabilities, we recommend dedicated marketing email platforms designed for that purpose. Accounts attempting to use NexoraMail for non-transactional sending will be suspended.
What counts as a "transactional" email?
Transactional emails are messages triggered by a specific user action or system event that the recipient is expecting. Examples include: password reset emails, account verification links, order confirmation and shipping notifications, payment receipts, invoice delivery, two-factor authentication codes, account activity alerts, and application-generated reports explicitly requested by the user. If an email is initiated by your marketing team rather than a user action, it is likely not transactional.
What happens if my complaint rate exceeds your threshold?
If your complaint rate reaches 0.05%, you receive an automatic warning notification. At 0.08%, your account is flagged for compliance review. At 0.10%, sending is automatically suspended and you must complete a compliance remediation process before resuming. At 0.20% or above, the account is permanently suspended. These thresholds protect all NexoraMail customers from shared infrastructure reputation damage.
How long does the compliance review take for Growth/Enterprise accounts?
Standard compliance reviews for Growth accounts are completed within 2 business days. Enterprise accounts with complex sending requirements may require up to 5 business days for a full review, including use case assessment, list hygiene evaluation, and infrastructure sizing. We will communicate with you via email throughout the review process.
Do you offer a free trial?
We offer a limited sandbox environment for development and integration testing. The sandbox allows up to 500 test sends per month to verified test recipient addresses only. Sandbox accounts cannot be used for production sending. To send to real recipients, you must upgrade to a paid plan and complete domain verification.

Start with a Compliance Review

Tell us about your use case and we'll find the right plan for your application.

Dashboard Overview
Last 30 days — acmecorp.com
All systems operational. Complaint rate 0.06% — within healthy range.
Emails Sent
84,291
↑ 12.4% vs last period
Delivery Rate
98.7%
↑ 0.3% vs last period
Bounce Rate
1.3%
↓ 0.2% vs last period
Complaint Rate
0.06%
↓ 0.01% vs last period
Volume by Email Type
30 Days
Password Resets34,120
Order Confirmations21,880
Account Verification17,340
Payment Receipts8,910
System Alerts2,041
Recent Activity
View all →
msg_4xK7JmNp — Delivered
to: u***@gmail.com · 2 min ago
delivered
msg_9pR2QwXv — Delivered
to: j***@outlook.com · 5 min ago
delivered
msg_3mT8LnKw — Bounced
to: t***@domain.io · 12 min ago
hard bounce
msg_6sA1DqPm — Delivered
to: m***@yahoo.com · 18 min ago
delivered
msg_7vB4EhYc — Queued
to: b***@company.com · 22 min ago
queued

Terms of Service

Last updated: February 1, 2025  |  Effective: February 1, 2025

Privacy Policy

Last updated: February 1, 2025

Acceptable Use Policy

Last updated: February 1, 2025

Anti-Spam Policy

Last updated: February 1, 2025

Data Processing Agreement

Last updated: February 1, 2025  |  GDPR Article 28 Compliant

Contact & Access Request

Get in Touch

Request platform access, ask compliance questions, or reach our support team. All accounts undergo a use-case review before activation.

Request Platform Access

Access to NexoraMail requires a use-case compliance review. Please describe your transactional email use case in detail below.
✉️
Email Support
For all inquiries including technical support, compliance questions, billing, and abuse reports:
support@nexoramail.us
Response time: Within 48 hours (12 hours for Growth/Enterprise)
🏢
Registered Business Address
NexoraMail Inc.
1209 Orange Street
Wilmington, DE 19801
United States
📋
Abuse Reports
To report spam or abuse originating from NexoraMail infrastructure, send full email headers to:
support@nexoramail.us
Subject: Abuse Report — [brief description]
⚖️
Legal & Compliance
For legal notices, GDPR inquiries, data subject requests, and DPA execution:
support@nexoramail.us
Subject: Legal — [brief description]