Skip to content

Transactional and certified email · Mexico

Mailack sends your transactional email from owned infrastructure in Mexico and keeps proof of every step: the destination server's exact answer, the full bounce if there is one, and a legally valid seal any third party can verify without depending on us.

We work closely with the first organizations that join, before opening general access. Request yours.

NOM-151 preservation certificate issued by PSC Codex

Message receiptmsg_01JQ4T7BWM6Z

Canonicalized message

9f2c41ab7d0e5b83c6a1f4e29d7b0c58ea3419f7d62b8c05a7e1f39b4c8d20a6

Merkle tree leaf

leaf 0x00 · index 3412 / 10000

SMTP response on delivery

250 2.0.0 OK 1753812004 d9-20020a17090a — queue id 4bK9Qz3Yx1z

Root sealed with PSC Codex

3a71e08cd4f9b26517ac0de83b45f912c7d60e4ab198f253c60ad7e194bf82c1

NOM-151 sealedSerial 04:9C:2F · 2026-07-29 11:04:16 CST
Sample receipt. Values are illustrative.
01Why it exists

A managed relay hands you the conclusion, not the proof.

When a delivery has to hold up in front of a third party, two things fail at once.

The bounce arrives pre-interpreted

The provider parses the DSN and hands you JSON with its reading of it. The original RFC 3464 message — the document — is not preserved. What remains is the provider's opinion about what happened.

The sending IP is neither yours nor local

A shared pool changes IP and jurisdiction without notice. If your contract or your regulator requires Mexican residency, there is no way to evidence it.
The portal

Every send, its status and its evidence in plain sight.

Messages, seals, quota and Merkle root in a single console. What you see here is exactly what the API returns: the panel is a view, not the source.

portal.mailack.com/mensajesPRODUCTION
MensajesLa bitácora de todo lo que ha enviado, con el estado de entrega y la evidencia.
  • MLK-9F2C-4187legal@acme.mx09:41
  • MLK-7A1D-9023ops@nova-logistica.com09:12
  • MLK-3E8B-5561finanzas@grupoorion.mx08:57
  • MLK-6C4F-2208rh@constructora-anda.mx08:30

raíz Merkle verificadab3:91:0c:4e:…:f7:2a

02Who it is for

Where an email has consequences.

Three operations where the send gets questioned later, and what stays on record in each one.

Legal and compliance

Notices, demands and disclosures where content, timing and destination must be evidenced.

  • NOM-151 certificate
  • WORM preservation
  • Offline verification

Fintech and collections

Statements, reminders and payment notices at volume, with traceability required.

  • Idempotent ingestion
  • Raw RFC 3464 DSN
  • Per-tenant suppression

HR and payroll

Payslips and employment communications that leave no room for “it never arrived”.

  • Literal delivery transcript
  • VERP correlation
  • mx-monterrey-1 residency
03Raw evidence

What the destination answered, untranslated.

The DSN is archived whole before parsing. This is what stays on file for each delivery attempt.

RFC 3464 · DSN
Reporting-MTA: dns; mail-out-01.mailack.comArrival-Date: Wed, 29 Jul 2026 11:04:14 -0600Final-Recipient: rfc822; user@domain.comAction: deliveredStatus: 2.0.0Remote-MTA: dns; mx.domain.comDiagnostic-Code: smtp; 250 OK  queue id 4bK9Qz3Yx1z

Raw evidence exactly as archived, before parsing. The original .eml is preserved in WORM storage; what you see is its literal content.

04How it works

Four moments, four records.

Nothing is re-serialized or reconstructed afterwards. What happened is preserved, at the moment it happened.

  1. Ingest

    The message is fixed

    The API accepts the send with an idempotency key, fixes Message-ID and Date, and hashes the exact byte stream that will go over the wire.

    POST /v1/messages · Idempotency-Key

  2. Seal

    Batched and sealed

    Hashes enter a Merkle tree (RFC 6962) in windows of one hour or ten thousand leaves. The root is sealed with PSC Codex, not each message: same proof at a fraction of the cost.

    batch · root + NOM-151 certificate

  3. Deliver

    The literal SMTP response is kept

    The owned MTA delivers and preserves the literal SMTP response from the delivery conversation, with its queue id. Not a translated code: the line itself.

    250 2.0.0 OK · queue id

  4. Return

    The raw DSN is archived

    The VERP return-path correlates every bounce with its message. The .eml is archived before parsing and preserved in WORM storage.

    bounce+<uuid>@mailack.com

05Residency

It leaves from Mexico, under its own IP and name.

Owned MTA on dedicated Oracle Cloud VMs in Monterrey, not a shared pool: fixed egress IP and its own HELO.

RegionOCI mx-monterrey-1 (Monterrey, N.L.)
OutboundKumoMTA · fixed egress IP
InboundPostfix · own MX for DSN and ARF
PreservationObject Storage with WORM retention

The distinction that actually matters

The Mexican IP is data residency and a contractual argument. Evidentiary value comes exclusively from the NOM-151 preservation certificate issued by PSC Codex. They are two different things and we treat them as such.

06Operations

Deliverability is run by an agent. On a short leash.

Warm-up, throttling, suppression and failover run on their own. A model does the diagnosis; code authorizes the dangerous decision.

The LLM is never in the delivery path. If the agent goes down, the MTA keeps sending at the last known good rate.

Full autonomy — all of these reduce risk

  • Lower the sending rate, down to a pause
  • Fail over to the backup provider
  • Pull an IP from the pool
  • Suppress an address
  • Freeze warm-up and open an incident

Behind a deterministic gate — all of these raise risk

  • Raise the sending rate
  • Resume after a block
  • Add a new IP to the pool
  • Move up a warm-up step
07Questions

What people ask before the demo.

What sending options are there?

Four. Ordinary email is delivered with an SMTP transcript and DSN, but no seal. Certified email seals content and delivery with a NOM-151 certificate. With attachments, the files travel inside the message and are covered by the same certificate. And reliable notification and reading hosts the document and seals every access: which bytes were served, to which address and when.

Does a certificate over the Merkle root cover my message?

In plain terms: yes, delivered as two pieces that travel together. The certificate attests that the root existed at that instant; the inclusion proof attests that your message was part of that tree. Both ship together in the proof bundle (the downloadable evidence package). For litigation we also issue an individual certificate for the message, on demand.

Can I verify without connecting to Mailack?

In plain terms: yes, with a file we give you and a tool you run yourself, without depending on our servers. The proof bundle carries the canonical hash, the inclusion path and the certificate. The command-line tool checks the hash and the inclusion proof offline, without querying our servers. The certificate itself is issued and backed by PSC Codex.

What happens to deliverability if I switch providers?

There is no cutover. Sending is split by percentage between your current provider and Mailack during warm-up, with deterministic per-ISP rules.

Is it for marketing?

No. Marketing traffic never shares an IP pool with transactional and legal mail. Mailack is built for the latter.