Auth-DNS Limited
United Kingdom · www.auth-dns.com · 10 vendors
Resilience scores
- Digital Sovereignty: 20
- Digital Resilience: 6
- Financial Resilience: 6
Technology vendors
- AuthSMTP — Technology — United Kingdom
- Google LLC — Technology — United States
- Looker — Technology — United States
- and 7 more
Services catalogue
1 service in catalogue across 1 category; runs on 10 sub-vendors.
- Auth-DNS
Insights
Last updated 2026-07-19 · revision 1
10 direct vendors, 159 subvendors
Direct vendors by controlling owner country (sample)
- Germany: 1
- Denmark: 2
- United States: 5
Subvendors by controlling owner country (sample)
- Australia: 4
- Switzerland: 1
- France: 1
Migration Readiness: 5/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Auth-DNS Limited exhibits a medium level of migration readiness, leaning towards the lower end of this range. The presence of a RESTful HTTPS/XML web API (v1.01 and v2 Beta) is a significant enabler for integration and potential re-platforming efforts, supporting various programming languages. The company's adherence to PCI compliance standards also suggests a structured approach to data security and governance, which can streamline compliance aspects of a migration. However, several factors indicate potential challenges. The internal tech stack, while including modern elements like HTTPS/SSL/TLS and RESTful services, also lists technologies such as PHP, Perl, C#/.NET, and XML, without explicit mention of cloud-native architectures, containerization (e.g., Docker, Kubernetes), or microservices. This suggests a potentially more traditional, possibly monolithic, application architecture that could require substantial refactoring for a successful cloud migration. The lack of specified data residency requirements is an unknown that could become a significant constraint depending on the target migration environment. Furthermore, the financial stability (ability to fund a migration) is unclear due to missing revenue and growth data. Vendor lock-in risk is also unknown; while there's geographic diversity in vendor countries for 13 services, the actual number of distinct vendors and the complexity of these relationships are not provided, making it difficult to assess potential dependencies that could complicate migration.
Compliance
7 in-scope frameworks identified; showing 3.
UK PECR — Assessment Required
PECR is directly relevant to AuthSMTP as a UK-based electronic communications service provider and email relay operator. PECR implements the EU ePrivacy Directive in UK law and covers: electronic marketing, cookies, security of public electronic communications services, and traffic/location data. As an SMTP relay service, AuthSMTP processes electronic communications traffic data and may be subject to PECR's security obligations for public electronic communications services. The company's cookie policy and marketing opt-out mechanisms are documented, suggesting awareness of PECR. Risk is Medium because: (1) the company operates in a sector directly regulated by PECR; (2) the company's customers use the service to send marketing emails, creating potential PECR exposure; (3) no PECR-specific compliance assessment has been publicly disclosed.
Evidence: https://www.authsmtp.com/documentation/privacy-policy.html, https://www.authsmtp.com/documentation/acceptable-usage-policy.html, https://www.legislation.gov.uk/uksi/2003/2426/contents/made, https://ico.org.uk/for-organisations/direct-marketing-and-privacy-and-electronic-communications/guide-to-pecr/
UK NIS Regulations 2018 — Assessment Required
The UK NIS Regulations 2018 (SI 2018/506), as amended by the Network and Information Systems (Amendment) Regulations 2022, apply to operators of essential services and relevant digital service providers (RDSPs) in the UK. RDSPs include online marketplaces, online search engines, and cloud computing services. An SMTP relay service could be classified as a digital service provider under the regulations. The ICO is the competent authority for digital service providers under UK NIS. Risk is Medium because: (1) the company operates digital infrastructure that could fall within scope; (2) the company is ICO-registered; (3) however, the specific classification of SMTP relay services under UK NIS has not been publicly confirmed; (4) size thresholds and sector classification require formal assessment.
Evidence: https://www.legislation.gov.uk/uksi/2018/506/contents/made, https://ico.org.uk/for-organisations/the-guide-to-nis/, https://www.authsmtp.com/documentation/gdpr-statement.html
ISO 27001 (source) — Assessment Required
ISO 27001 is highly relevant for a cloud email infrastructure provider that processes business-sensitive email content and personal data on behalf of B2B customers. The absence of ISO 27001 certification is a notable gap for a company that: (1) operates 24/7 email relay infrastructure; (2) processes potentially sensitive email content; (3) serves a global B2B customer base; (4) explicitly markets security as a key feature. Risk is Medium because the company has implemented several security controls (PCI-compliant DCs, TrustWave scans, SSL/TLS, firewalls, IDS) that align with ISO 27001 principles, but without formal certification there is no independent verification of the completeness or effectiveness of the ISMS. Enterprise customers in regulated sectors may require ISO 27001 certification as a procurement condition.
Evidence: https://www.authsmtp.com/features.php, https://www.authsmtp.com/documentation/gdpr-statement.html, https://www.iso.org/standard/27001, https://sealserver.trustwave.com/cert.php?customerId=6403d31bfaee4647a897d2c899d6a9e4
Financials
Financial Resilience Score: 6/10
Auth-DNS Limited, operating under the AuthSMTP brand, demonstrates apparent financial resilience through its longevity (20+ years in operation since 2003) and recurring subscription-based revenue model, which provides predictable cash flow. The business appears bootstrapped and owner-operated with no known external funding, suggesting disciplined financial management. Its niche focus on SMTP relay creates sticky customer relationships due to embedded infrastructure switching costs. However, the company faces significant competitive pressure from well-capitalized players like SendGrid/Twilio, Amazon SES, Mailgun, and Postmark, which benefit from scale advantages in compliance and anti-abuse tooling. As a small UK private company, it likely has fewer than 10 employees and carries key-person/concentration risk. The lack of public financial disclosure (only micro-entity accounts likely filed at Companies House) limits transparency for counterparty assessment. Deliverability risks, evolving email authentication requirements (Gmail/Yahoo 2024 bulk-sender mandates), and GDPR compliance also demand ongoing engineering investment that may be challenging at small scale.
Key strengths: 20+ years of continuous operation since 2003, Recurring subscription revenue model provides predictable cash flow, Niche specialization in SMTP relay with high switching costs, Bootstrapped, no known external funding required, Custom-built redundant network infrastructure with Tier-1 connections, Global sales across USD, GBP, and EUR markets
Risk factors: Intense competition from well-capitalized players (SendGrid, Amazon SES, Mailgun, Postmark), Scale disadvantages in compliance and anti-abuse tooling, Key-person/concentration risk typical of small private companies, Deliverability and IP reputation risks, Evolving email authentication mandates (Gmail/Yahoo 2024 requirements), Minimal public financial disclosure limits transparency, GDPR and UK Data Protection Act regulatory burden, Single-product concentration (SMTP relay only)
Revenue by product/service
- SMTP Email Relay Service: 100%
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.