No security program eliminates all risk. MailerZ uses risk-based controls and continuously improves them as threats, standards, and the service evolve.
Security principles
- Verify domain control before enabling receiving or sending.
- Restrict SMTP sending to authenticated users and approved identities.
- Limit access according to role and operational need.
- Record important authentication, configuration, delivery, and security events.
- Store incoming messages before confirming acceptance when recovery requires it.
- Minimize retention and access to message content while preserving required reliability and abuse controls.
Transport and credentials
MailerZ supports encrypted transport using current TLS mechanisms where compatible with the communicating server or client. Passwords, SMTP credentials, API keys, and session tokens must be protected from unauthorized access. We may require credential rotation or block outdated or unsafe connection methods.
Infrastructure and operations
Controls may include network filtering, rate limits, authentication safeguards, least-privilege access, configuration review, logging, backups, monitoring, dependency maintenance, abuse detection, and recovery procedures. Details that would materially weaken security are not published.
Customer security duties
- Use unique strong passwords and multi-factor authentication where offered.
- Protect domain registrar, DNS, inbox, SMTP, API, and team credentials.
- Remove access promptly when a user or integration no longer needs it.
- Review aliases, forwarding destinations, sending identities, and activity records regularly.
- Notify MailerZ promptly about suspected compromise, unexpected routing, credential exposure, or abusive sending.
Incident response
We assess credible security events, contain affected systems, preserve relevant evidence, restore safe operation, and notify affected customers or authorities when required by applicable law or contract. Customers must provide timely information needed to investigate incidents involving their accounts or data.
Responsible disclosure
Send suspected vulnerabilities to support@mailerz.net with the subject “Security Report.” Include clear reproduction steps, affected component, impact, and safe evidence. Do not access other users’ data, disrupt service, send spam, perform denial-of-service testing, use automated high-volume scanning, or publicly disclose an unresolved issue. We will acknowledge valid reports and coordinate remediation based on severity.
Security boundaries
Customers remain responsible for their domains, DNS providers, registrars, inboxes, devices, users, applications, content, and legal sending practices. MailerZ cannot guarantee the security or availability of third-party networks or recipient systems.
Questions about this policy?
Email support@mailerz.net and include the policy name in your subject line.