Security

Security starts with boring mail fundamentals.

KasaPost focuses on authenticated sending, encrypted transport, account controls, and clear operational visibility before making larger compliance claims.

Domain authentication

SPF, DKIM, and DMARC are expected for production domains. KasaPost checks alignment before real volume starts.

Transport security

HTTPS protects the control center. SMTP transport uses TLS where receiving servers support it.

Sender controls

Transactional API keys can be scoped, rotated, revoked, and tied to domain-level sending policy.

Abuse controls

Suppression lists, DMARC reports, abuse contacts, and queue visibility help reduce unwanted or risky mail.

Account protection

Admin access is separated from mailbox use. Strong passwords and two-factor authentication are recommended for all operators.

Roadmap

Formal security docs, public incident history, SSO options, and independent security review are planned as the platform matures.