AuthSMTP
United Kingdom · www.authsmtp.com · 14 vendors
AuthSMTP is an outgoing SMTP email service that provides email deliverability solutions for e-commerce websites, mailing lists, and email applications. It enables users to send high volumes of email reliably and securely, offering features like instant setup, flexible pricing, and responsive support. The service is designed for performance and availability, utilizing high-performance and redundant systems.
Resilience scores
- Digital Sovereignty: 29
- Digital Resilience: 5
- Financial Resilience: 6
Disruption prediction
AuthSMTP has an estimated 11% probability of disruption in the next 6 months.
3 of AuthSMTP's 14 vendors monitored for disruptions.
Technology vendors
- Cogent Communications — Telecommunications — United States
- CSC — Other — United States
- Google LLC — Technology — United States
- and 11 more
Services catalogue
3 services in catalogue across 2 categories; runs on 14 sub-vendors.
- AuthSMTP
- Personal Data Processing
- SMTP Relay Service
Insights
Last updated 2026-07-19 · revision 12
14 direct vendors, 194 subvendors
Direct vendors by controlling owner country (sample)
- Denmark: 2
- India: 2
- Germany: 1
Subvendors by controlling owner country (sample)
- United States: 135
- Singapore: 1
- United Kingdom: 5
Migration Readiness: 3/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
AuthSMTP exhibits low migration readiness. The primary challenge stems from its internal technology stack, specifically the reliance on "custom-built, proprietary hardware" and "PCI-compliant data centre infrastructure," which strongly suggests an on-premise or co-located environment rather than a cloud-native architecture. The tech stack, while functional (PHP, Perl, C#), does not indicate modern cloud-native patterns like containerization or microservices, implying a potentially monolithic application that would be complex to refactor and migrate. The regulatory environment also presents complexities. While GDPR compliant, the dual requirements of UK and EU GDPR post-Brexit, coupled with specific data residency requirements (primary data in the UK, with some US website data transferred to the UK), necessitate careful planning for cloud region selection and data transfer mechanisms during migration. The absence of SOC2 and ISO 27001 certifications means that achieving these would likely be a significant part of any migration project, adding scope and cost. Financial stability, crucial for funding a potentially large-scale migration, is unknown due to missing revenue data. Regarding vendor relationships, the data states "Total Vendors: 0," which is ambiguous given the listing of "Vendor HQ Countries" and "Vendor Geographic Diversity." If interpreted strictly, it would mean no external vendor lock-in, which is a positive. However, the proprietary hardware itself represents a form of internal lock-in, requiring significant re-engineering to move to a standard cloud platform. The "Vendor Lock-in Risk: Unknown" further complicates this assessment. Overall, the foundational infrastructure and application architecture are significant barriers to a straightforward migration.
Compliance
6 in-scope frameworks identified; showing 3.
ISO 27001 (source) — Assessment Required
ISO 27001 is the internationally recognised standard for information security management systems (ISMS). As a cloud-based email relay service handling customer communications, AuthSMTP operates in a domain where ISO 27001 certification is increasingly expected by enterprise customers and is a strong signal of mature security governance. The company describes robust security practices (PCI-compliant data centres, TrustWave/VikingCloud scans, layered firewalls, intrusion detection, encryption, physical access controls) but no ISO 27001 certification has been found. Risk is Medium because: (a) the company handles sensitive customer email traffic; (b) no independent security certification has been identified; (c) the security measures described are consistent with ISO 27001 controls but have not been independently verified; (d) the company's likely SMB customer base may not mandate ISO 27001, reducing immediate commercial pressure.
Evidence: https://www.authsmtp.com/features.php, https://www.authsmtp.com/documentation/gdpr-statement.html, https://sealserver.trustwave.com/cert.php?customerId=6403d31bfaee4647a897d2c899d6a9e4&size=105x54&style=invert
SOC 2 (source) — Assessment Required
AuthSMTP is a cloud-based SMTP relay service — precisely the type of service for which SOC 2 (Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, Privacy) is designed. The company serves business customers who relay potentially sensitive email communications through its infrastructure. Many enterprise and mid-market customers now require SOC 2 Type II reports from their cloud service providers as part of vendor due diligence. The absence of a publicly available SOC 2 report represents a competitive and compliance risk, particularly for customers in regulated industries. Risk is Medium because: (a) the company is a cloud service provider handling customer data; (b) no SOC 2 report has been found; (c) enterprise customers may require this as a procurement condition; (d) however, the company's customer base appears to be primarily SMBs where SOC 2 is less commonly mandated. The risk would be High if the company is targeting enterprise customers.
Evidence: https://www.authsmtp.com/features.php, https://sealserver.trustwave.com/cert.php?customerId=6403d31bfaee4647a897d2c899d6a9e4&size=105x54&style=invert
UK Electronic Commerce — Assessment Required
As a UK-based online service provider offering subscription services to consumers and businesses, AuthSMTP is subject to UK e-commerce and consumer protection regulations. The company's terms of service, money-back guarantee, and pricing transparency suggest awareness of these obligations. Risk is Low because the company appears to operate a straightforward B2B-focused subscription model with transparent pricing and a documented money-back guarantee, reducing consumer protection risk. The Digital Markets, Competition and Consumers Act 2024 introduces new consumer protection enforcement powers but is unlikely to materially affect a B2B-focused SMTP relay service.
Evidence: https://www.authsmtp.com/documentation/terms-of-service.html, https://www.authsmtp.com/documentation/acceptable-usage-policy.html, https://www.authsmtp.com/auth-smtp/money-back-guarantee.html, https://www.legislation.gov.uk/uksi/2002/2013/contents/made
Financials
Three-year financials
- null:
Financial Resilience Score: 6/10
AuthSMTP, operated by GetOnline Ltd, demonstrates strong qualitative financial resilience through longevity (28+ years of continuous trading since 1997, with AuthSMTP running since 2003) and a subscription-based recurring revenue model that provides predictable cash flow. The business appears to be organically funded and bootstrapped, with no evidence of external venture capital, acquisitions, or debt-driven expansion, suggesting disciplined cash-flow-financed growth. Low capital intensity of the SMTP relay business model and diversified product mix (domains, hosting, email, AuthSMTP) further support resilience. However, the score is moderated by significant risks. As a small UK private company filing abridged accounts, there is minimal public financial disclosure—no revenue, EBIT, or profitability data is available, limiting external visibility. The company competes against hyperscale, well-funded competitors (SendGrid/Twilio, Mailgun, Amazon SES, Postmark, Brevo, Mailjet) with superior infrastructure, APIs, and pricing at scale. Small-scale operations limit investment capacity in AI-driven deliverability, DMARC/BIMI compliance, and geo-redundant infrastructure. Regulatory changes such as Google/Yahoo bulk-sender rules (2024) raise compliance costs disproportionately for smaller providers. Overall, resilience is supported by longevity and recurring revenue, but competitive positioning is the primary long-run risk.
Key strengths: 28+ years of continuous trading (since 1997), 22+ years of AuthSMTP operation (since 2003), Subscription-based recurring revenue model, Low capital intensity of SMTP relay business, Diversified product mix (AuthSMTP, domains, hosting, email), Global customer base with multi-currency pricing (USD, GBP, EUR), Organic, bootstrapped, cash-flow-financed growth
Risk factors: Intense competition from hyperscale providers (SendGrid, Mailgun, Amazon SES, Postmark), Small-scale operator with limited investment capacity, Key-person / founder concentration risk, Regulatory pressure from Google/Yahoo bulk-sender rules (2024) and DMARC/BIMI, Opacity due to abridged accounts filing (small company exemption), Limited ability to invest in AI-driven deliverability and geo-redundant infrastructure
Revenue by geography
- United Kingdom: 0%
- International (USD/EUR markets): 0%
Revenue by product/service
- Web hosting: 0%
- Email hosting: 0%
- Domain registration: 0%
- AuthSMTP (SMTP relay): 0%
- Custom high-volume email / e-commerce solutions: 0%
Workforce by country
- United Kingdom: 0
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.