Mailgun
United States · owned by Sinch (Sweden) · www.mailgun.com · 55 vendors
Mailgun is a transactional email API platform built for developers, enabling businesses to send, receive, track, and validate emails at scale. It offers tools for email deliverability optimization, email list validation, inbox placement testing, and email preview. Originally founded in 2010 and acquired by cloud communications provider Sinch in 2021, Mailgun serves hundreds of thousands of companies worldwide.
Resilience scores
- Digital Sovereignty: 11
- Digital Resilience: 8
- Financial Resilience: 7
Disruption prediction
Mailgun has a 100% probability of disruption in the next 6 months.
All systems operational (last checked 2026-09-18 14:55 UTC)
32 of Mailgun's 55 vendors monitored for disruptions.
Technology vendors
- Box, Inc. — Technology — United States
- Unbounce Inc. — Media & Marketing — Canada
- ZeroBounce — Technology — United States
- and 55 more
Services catalogue
24 services in catalogue across 6 categories; runs on 55 sub-vendors.
- MailAnyone
- Email Services
- Certified Sender
Insights
Last updated 2026-07-21 · revision 19
55 direct vendors, 419 subvendors
Direct vendors by controlling owner country (sample)
- Australia: 1
- France: 2
- Germany: 1
Subvendors by controlling owner country (sample)
- Spain: 2
- South Korea: 1
- Latvia: 1
Migration Readiness: 7/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Mailgun exhibits high migration readiness, largely due to its modern, cloud-native, and API-driven technical architecture, coupled with the explicit data indicating zero direct external vendor lock-in. The tech stack, featuring RESTful APIs, cloud-based infrastructure (including AWS, GCP, Rackspace), and a focus on developer-friendly integrations (SDKs, webhooks), provides a flexible and modular foundation for potential migrations. The explicit 'Total Vendors: 0' suggests minimal direct external vendor dependencies, which is a significant advantage for migration flexibility as it reduces the complexity of disentangling from third-party contracts and systems. As with resilience, it's acknowledged that this contradicts the stated use of major cloud providers, but the explicit 'Total Vendors: 0' is prioritized for direct vendor lock-in assessment. However, several factors introduce complexity and potential challenges for migration. Mailgun's comprehensive regulatory compliance (GDPR, ISO 27001, HIPAA-compliant infrastructure, PCI-compliant) and explicit data residency requirements (US and EU data centers, SCCs, DPF) mean any migration would require meticulous planning to ensure continuous adherence to these standards. The declining revenue trend from 2023 to 2025 (in SEK) could also limit the financial resources available for a large-scale migration project. Furthermore, Mailgun's deep integration with the 'Sinch Cloud Communications Platform (parent infrastructure)' suggests a significant internal dependency. While not an external vendor lock-in, migrating away from the Sinch ecosystem could present substantial technical and operational challenges. Despite these complexities, the modern architecture and low direct external vendor lock-in position Mailgun favorably for migration.
Compliance
9 in-scope frameworks identified; showing 3.
SOC 2 (source) — Compliant
Mailgun displays a CSA (Cloud Security Alliance) badge on its website footer alongside ISO and GDPR badges, indicating active participation in cloud security certification programs. The Sinch Trust Center (trust.sinch.com) is specifically dedicated to security and compliance documentation for Mailgun and other Sinch products, which is the standard mechanism for distributing SOC 2 reports to customers under NDA. SOC 2 is a baseline expectation for cloud/SaaS email service providers serving enterprise customers. Risk is Low because: (1) the existence of a dedicated Trust Center strongly indicates SOC 2 Type II compliance; (2) Mailgun serves 8 of the 10 largest tech companies globally, which would require SOC 2 as a procurement prerequisite; (3) Sinch AB as a publicly listed company has strong incentives to maintain SOC 2. Risk is not rated 'None' because the actual SOC 2 report is not publicly accessible without authentication.
Evidence: https://trust.sinch.com/?product=mailgun, https://www.mailgun.com/, https://www.mailgun.com/enterprise/
GDPR (source) — Compliant
Mailgun actively processes personal data of EU/EEA residents at scale as a transactional email API provider serving 150,000+ businesses globally, including EU customers. As a data processor under GDPR, Mailgun is exposed to significant regulatory risk if controls fail. However, the company has publicly documented extensive GDPR compliance measures: a DPA, appointed DPO, EU Standard Contractual Clauses (SCCs), data retention policies, sub-processor agreements, and self-service data subject rights tools. Risk is Medium rather than Low because: (1) Mailgun is a US-headquartered company transferring EU data internationally, which remains a scrutinized area post-Schrems II; (2) the GDPR page was last updated in August 2020, raising questions about whether documentation reflects current regulatory developments (e.g., updated SCCs from 2021); (3) enforcement of GDPR against cloud/SaaS processors has intensified across the EU. Risk is not High because of the substantial documented compliance program and parent company Sinch's broader compliance infrastructure.
Evidence: https://www.mailgun.com/gdpr/, https://sinch.com/legal/terms-and-conditions/other-sinch-terms-conditions/data-protection-agreement/, https://www.mailgun.com/legal/privacy-policy/, https://trust.sinch.com/?product=mailgun
NIS2 (source) — Assessment Required
Mailgun is a digital infrastructure/cloud service provider (transactional email API) that serves EU customers and is owned by Sinch AB, a Swedish company listed on Nasdaq Stockholm. NIS2 classifies 'digital providers' — including cloud computing services, online marketplaces, and online search engines — as Important Entities subject to NIS2 obligations. Mailgun's email API service could qualify as a 'managed ICT service' or 'digital provider' under NIS2 Annex II. Sinch AB (parent) is a large enterprise well above the 50-employee/€10M turnover thresholds. Risk is Medium because: (1) the classification of email API services under NIS2's specific digital provider categories requires legal interpretation; (2) NIS2 enforcement is still being transposed into national law across EU member states (deadline October 2024); (3) Sinch AB's Swedish operations are directly subject to NIS2 as transposed in Sweden. Risk is not High because Mailgun itself is US-incorporated, and NIS2 applicability to non-EU entities providing services to EU customers is still being clarified by regulators.
Evidence: https://www.mailgun.com/about/, https://trust.sinch.com/?product=mailgun, https://sinch.com/legal/
Financials
Three-year financials
- 2025: revenue SEK 27.08B, EBIT SEK 863M, equity SEK 22.74B
- 2024: revenue SEK 29.71B, equity SEK 29.03B
- 2023:
Financial Resilience Score: 7/10
Sinch Group (parent of Mailgun) demonstrates solid financial resilience anchored by scale (~SEK 27bn in net sales), diversification across SMS, RCS, voice, email, and verification channels, and a track record of profitability since founding in 2008. Adjusted EBITDA margin expanded from 11.3% in 2022 to 13.3% in 2025, and free cash flow (R12M ~SEK 1.9bn) supports a healthy net debt/adjusted EBITDA ratio of ~1.6x, well within the internal 2.5x target. The company serves >200,000 customers and handles 900bn+ interactions/year, with Mailgun specifically counting 8 of the 10 largest tech companies among its clients. However, organic growth has been sluggish (1–3%) versus the mid-term target of 7–9%, and reported revenue declined in 2025 due to significant FX headwinds (USD-dominant trading revenues translated into a strengthening SEK). Equity fell ~22% in 2025, primarily driven by >SEK 2.2bn in share buybacks and FX translation losses on goodwill (~SEK 18bn) and customer relationships (~SEK 9.8bn). A SEK 700m tax provision recognized in Q4 2024 (SEK 667m remaining) represents an unresolved contingent exposure. Regional weakness in APAC (–10% organic gross profit in Q1 2026) and margin pressure in the competitive email market (Twilio SendGrid, Amazon SES) add to the risk profile, though overall the balance sheet and cash generation remain robust.
Key strengths: Profitable since founding in 2008 with expanding adjusted EBITDA margin (11.3% → 13.3% from 2022 to 2025), Strong free cash flow generation (~SEK 1.9bn R12M) with 54% cash conversion, Debt discipline: net debt/adj. EBITDA of 1.6x, within 2.5x target, Diversified CPaaS portfolio spanning SMS, RCS, voice, email, verification, Blue-chip Mailgun customer base including Microsoft, Lyft, Wikipedia, Substack, American Express, Named 2026 Gartner Magic Quadrant Leader for CPaaS, Global footprint across 59 countries serving >200,000 customers
Risk factors: Significant FX exposure: USD-dominant revenues reported in SEK caused 11pp reported vs organic growth drag in Q1 2026, Organic growth (1–3%) well below mid-term target of 7–9%, Equity declined ~22% in 2025 due to buybacks and FX translation losses, Large goodwill (~SEK 18bn) and customer relationship (~SEK 9.8bn) intangibles pose impairment risk, SEK 667m unresolved tax provision on balance sheet as of Q1 2026, APAC regional weakness (–10% organic gross profit in Q1 2026), Intense competition in email from Twilio SendGrid, Amazon SES, Postmark, Margin pressure in Americas messaging business
Revenue by geography
- Americas: 63%
- EMEA: 24%
- APAC: 13%
Revenue by product/service
- API Platform (includes Mailgun/Email): 68%
- Network Connectivity: 20%
- Applications: 12%
Workforce by country
- Global (Sinch Group total): 4005
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.