MySMTP ApS
Denmark · www.mysmtp.com · 15 vendors
Resilience scores
- Digital Sovereignty: 47
- Digital Resilience: 5
- Financial Resilience: 6
Technology vendors
- Cookiebot (Cybot A/S) — Technology — Denmark
- Netlify, Inc. — Technology — United States
- Open Source Matters, Inc. — Technology — United States
- and 12 more
Services catalogue
4 services in catalogue across 2 categories; runs on 15 sub-vendors.
- SMTP Relay Service
- Dedicated SMTP Service
- MySMTP.com Email Delivery
Insights
Last updated 2026-09-01 · revision 16
15 direct vendors, 201 subvendors
Direct vendors by controlling owner country (sample)
- Romania: 1
- Germany: 3
- Australia: 2
Subvendors by controlling owner country (sample)
- Portugal: 1
- Belgium: 1
- Switzerland: 3
Migration Readiness: 4/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
MySMTP ApS exhibits moderate migration readiness, leaning towards the lower end due to several key factors. The reliance on 'EU-based dedicated data center infrastructure' and 'dedicated SMTP servers' strongly suggests a traditional, non-cloud-native architecture. Migrating such an infrastructure to modern cloud-native, containerized, or microservices environments typically involves substantial effort, cost, and time. A significant challenge is the lack of financial stability data (revenue concentration, growth history), which makes it impossible to assess the company's capacity to fund a potentially large-scale migration. Furthermore, the 'Vendor Lock-in Risk' is unknown, which is a critical concern; high vendor lock-in could severely impede or complicate migration efforts. While the geographic diversity of vendor HQ countries (6 unique countries) is a positive, the actual number of unique vendors is not provided, preventing a clear assessment of vendor concentration and its impact on lock-in. On the positive side, no explicit data residency requirements or complex regulatory environments are specified, which could simplify migration if these factors remain minimal, though GDPR compliance is implied by its EU presence.
Compliance
7 in-scope frameworks identified; showing 3.
ISO 27001 (source) — Assessment Required
ISO 27001 is the international standard for Information Security Management Systems (ISMS) and is highly relevant for a cloud SMTP relay provider that processes customer email data, manages dedicated IP infrastructure, and stores email logs. No ISO 27001 certification has been publicly disclosed by MySMTP ApS. Risk is Medium because: (1) the company processes sensitive business communications and customer data at scale; (2) ISO 27001 certification is increasingly expected by enterprise and public sector customers in Europe; (3) the Danish market and EU regulatory environment (including NIS2) increasingly align with ISO 27001 as a baseline security standard; (4) absence of certification may limit enterprise sales opportunities. However, the company does demonstrate some security practices (TLS, SPF/DKIM/DMARC, EU hosting) that align with ISO 27001 controls, even without formal certification.
Evidence: https://www.mysmtp.com, https://www.mysmtp.com/privacy-policy, https://www.iso.org/standard/27001
SOC 2 (source) — Assessment Required
MySMTP ApS is a cloud-based SMTP relay and email delivery service provider — precisely the type of organization for which SOC 2 (Type I or Type II) reports are most relevant and increasingly expected by enterprise customers. SOC 2 is not a legal requirement but is a widely demanded trust framework for cloud service providers, particularly when serving business customers who need assurance over security, availability, processing integrity, confidentiality, and privacy of their data. The absence of a publicly disclosed SOC 2 report represents a commercial and reputational risk, especially as the company targets business and enterprise customers. Risk is Medium because: (1) enterprise customers increasingly require SOC 2 reports as a vendor qualification criterion; (2) the company processes customer email data including potentially sensitive business communications; (3) no SOC 2 report has been found, which may limit the company's ability to win larger enterprise contracts. However, SOC 2 is not legally mandated, and many SME-scale cloud providers operate without it.
Evidence: https://www.mysmtp.com, https://www.mysmtp.com/privacy-policy, https://www.aicpa-cima.com/resources/landing/system-and-organization-controls-soc-suite-of-services
Danish Marketing Practices Act — Partially Compliant
MySMTP ApS provides email marketing infrastructure services to customers who send bulk commercial emails. As an email service provider (ESP), MySMTP has both direct obligations (for its own marketing communications) and indirect obligations (as an infrastructure provider enabling customer email campaigns). The Danish Marketing Practices Act (Consolidated Act No. 426 of 3 May 2017, as amended) and the EU ePrivacy Directive (2002/58/EC, implemented in Denmark via the Electronic Communications Act) govern commercial electronic communications. MySMTP's Sending Policy and anti-spam measures are relevant here. Risk is Medium because: (1) the company's infrastructure can be used to send bulk commercial email, creating reputational and legal exposure if customers violate anti-spam laws; (2) the company's own newsletter marketing must comply with consent requirements; (3) the company explicitly references SPF/DKIM/DMARC compliance and has a spam reporting mechanism, indicating awareness of these obligations.
Evidence: https://www.mysmtp.com/sending-policy, https://www.mysmtp.com/report-spam, https://www.mysmtp.com/privacy-policy, https://www.retsinformation.dk/eli/lta/2017/426, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32002L0058
Financials
Three-year financials
- null:
Financial Resilience Score: 6/10
mySMTP ApS demonstrates qualitative financial resilience through its long operating history of approximately 18 years since 2007, having survived multiple economic cycles and the entry of major competitors such as SendGrid/Twilio, Mailgun, Postmark, Amazon SES, and Brevo. Its subscription-based revenue model with monthly and annual plans typically produces predictable, ARR-like cash flows with high gross margins characteristic of SMTP relay services. The business is low capital intensity, relying on co-located mail servers and IPs, which keeps scaling costs modest. The company benefits from differentiated positioning as an independent, EU-hosted, GDPR-compliant SMTP provider, which is increasingly valuable in the post-Schrems II environment where European customers seek non-US SaaS alternatives. Multiple product tiers spanning transactional, marketing, small business, and outsourced SMTP diversify the customer base. However, resilience is constrained by very small scale relative to hyperscale competitors, key-person/owner-managed risk typical of a small ApS, exposure to deliverability and blacklisting events, commoditisation pressure from AWS SES and others, and limited public disclosure that reduces external visibility. No official revenue, EBIT, or equity figures were retrievable in this session, so the score reflects structural/qualitative assessment only.
Key strengths: Long operating history of ~18 years since 2007, Recurring subscription revenue model with predictable cash flow, EU-hosted, GDPR-compliant differentiation appealing to European customers, Low capital intensity infrastructure, Diversified product tiers (transactional, marketing, small business, outsourced SMTP, MailWizz bundling), Founder-owned, self-funded ApS with no external funding dependencies
Risk factors: Very small scale relative to competitors (SendGrid, AWS SES, Mailgun, Brevo), Key-person / owner-managed risk with small team, Deliverability and IP blacklisting risk, Commoditisation and pricing pressure from hyperscalers, Limited public financial disclosure reduces enterprise vendor due diligence transparency, Minor FX risk from EUR pricing vs DKK cost base (mitigated by DKK/EUR peg)
Revenue by geography
- International / Rest of World: 0%
- Europe (incl. Denmark/Nordics): 0%
Revenue by product/service
- MailWizz Bundled Solutions: 0%
- Small Business / Individual SMTP Subscriptions: 0%
- Marketing & Transactional SMTP (Dedicated IP Plans): 0%
- Outsourced / Managed SMTP and Deliverability Expert Services: 0%
Workforce by country
- Denmark: 0
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.