Permissions at every boundary
Organization membership and mailbox access are checked on the server. Shared mail separates read, write, management and send permissions. Platform administration does not automatically grant access to mailbox contents.
Understand how RelyPost controls account access, protects service credentials and handles email content.
Organization membership and mailbox access are checked on the server. Shared mail separates read, write, management and send permissions. Platform administration does not automatically grant access to mailbox contents.
Account passwords use Argon2id hashing. Multi-factor authentication supports authenticator codes and recovery codes. Native mail clients use separate app passwords, and API keys can be scoped and revoked.
Remote email images are blocked by default. Message HTML is sanitized for display, and attachments require authorized access. The upload pipeline integrates malware scanning. These controls reduce risk; they do not make every incoming message trustworthy.
Native IMAP and SMTP connections require TLS. Stored service credentials are encrypted. RelyPost processes message content to provide mail features, so this is not an end-to-end encrypted email service. Your own domain configuration and device security also matter.
Contact security@relypost.com. Describe the issue and provide the minimum details needed to reproduce it. Do not include passwords, recovery codes or private mailbox contents.
No. Receiving providers apply their own filtering and sender-reputation rules. Correct authentication and careful sending help, but neither SMTP acceptance nor a security feature guarantees inbox placement.
Start with your domain. Build a workspace around your team.