Skip to content

Built for accountable production

Mail that stays where you put it.

Ruzayo runs real mailboxes on names you own: direct recipient MX, Postfix and LMTP intake, durable raw and normalized storage, tenant-scoped credentials, and signed metadata webhooks.

Repository-backed product facts · reviewed 26 August 2026

Architecture and value

One house operates the servers, DNS state, mailbox record, and delivery route in eu-north-1 while preserving a documented export path.

Postfix edge

Postfix terminates recipient SMTP and hands accepted messages to the internal LMTP boundary.

Authoritative mailbox store

The mailbox service owns durable raw messages, normalized records, domain state, and export.

Signed event boundary

Downstream systems receive minimal signed projections rather than authority over the mailbox store.

Compare operating models

Expand the matrix. Choose by boundary and workflow, not slogans.

Ruzayo ↔ Postmark · official inbound and webhook docs reviewed 2026-08-26

Scroll sideways to read the full comparison.

Compare operating models
CriterionThis systemAlternative · Postmark
Primary jobAuthoritative mailboxes on customer-owned namesTransactional delivery plus inbound email processing
Deployment boundaryRuzayo receives directly as the domain’s recipient MXInbound address or forwarding domain is parsed and posted as JSON
Evidence modelDurable raw and normalized message with signed metadata webhooksWebhook payloads and message IDs; inbound signing is not documented
Operator controlTenant credentials, live DNS state, exportable mailbox custodyServer tokens, message streams, forwarding and webhook configuration
Integration surfaceMailbox API, SMTP/LMTP, signed webhook, exportEmail API/SMTP, inbound parsing, webhooks, SDKs

Technical invariants

Direct recipient MXRuzayo is the receiving MX; it does not require forwarding through a third-party parser.
Tenant-scoped authorityEvery domain, mailbox, message, credential, and export is resolved inside one tenant.
Signed webhooksWebhook consumers verify signature, timestamp, audience, and replay identity before acting.
Exit remains possibleDomains and mailbox data retain an explicit, owner-authorized export path.

Transparent access

Name under service

€3 / month

Published per-domain price; no charge is collected today.

Mailbox held

€3 / month

Published per-address price, independent of human seats; no meter runs today.

Storage above included 50 GB

€0.20 / GB

50 GB per name is planned as included; overage measurement is not built.

Current status. The request and mailbox path are real; the billing meter and 50 GB overage implementation are not running.

Frequently asked questions

What is the safest way to evaluate it?

Start with the architecture, reproduce the documented workflow, and verify the boundary against your own threat model.

Does the comparison include live third-party pricing?

No. Mutable vendor pricing is deliberately excluded. Verify current vendor terms before a purchase decision.

Where are limitations documented?

The status note, architecture page, and engineering articles state the current boundary and failure behaviour.