Multi-tenant email · Amazon SES · London

Every tenant authenticates as themselves, not as us.

Kind Relay sends broadcast and transactional email on behalf of UK small businesses and non-profits. Each customer organisation is a separate SES tenant with its own reputation and suppression list, sending from a subdomain of a domain they own, with SPF and DKIM aligned to that domain rather than to us.

You pay per message sent, never per contact stored — so keeping ten years of supporter history costs nothing. It is the reason most charities we speak to are looking to leave their current tool.

what a tenant's headers look like EXAMPLE
Received-SPF: pass (domain of  bounce.mail.your-charity.org designates  ... as permitted sender)DKIM-Signature: ... h=from:to:subject:  mime-version:content-type:list-unsubscribe:  list-unsubscribe-post:list-id:message-id:  date:feedback-id
Illustrative, using an example customer domain. The behaviour it shows is verified on a live sending domain: SPF passes against the tenant's own bounce subdomain rather than amazonses.com, and both List-Unsubscribe headers sit inside the DKIM h= tag — so RFC 8058 one-click unsubscribe cannot be stripped in transit.

01 / SENDING MODEL

Sending on behalf of others, declared up front

We operate a multi-tenant platform and say so plainly, in line with guidance for senders who send on behalf of multiple customers. The isolation below is the reason one tenant's mistake is not everyone's problem.

Tenancy One SES tenant per customer organisation Independent reputation metrics and an independent suppression list per tenant.
From domain A subdomain of a domain the customer owns Sending from a domain we own on a customer's behalf is not permitted for broadcast.
Authentication Easy DKIM plus a custom MAIL FROM subdomain SPF aligns to the customer, clearing the bar that a default SES configuration fails.
DNS Three CNAMEs into a zone we operate We read existing DMARC before provisioning and never touch a customer's root domain.
Unsubscribe RFC 8058 one-click, signed, plus a body link Honoured immediately, enforced at send time, and not removable by the customer.
Lists Consent declared and recorded at import Lawful basis under UK GDPR and PECR, source and approximate date. No purchased lists.

02 / THE AGENT

Thresholds set inside the provider review lines, and acted on automatically

Bounce, complaint and delivery-delay events stream in from SES. Delivery delay is the only signal that arrives during a send, which is what makes pausing a mailshot mid-flight possible rather than retrospective.

Signal Throttle Pause Provider review
Complaint rate0.05%0.08%0.10%
Bounce rate2.00%4.00%5.00%
Gmail spam rate0.20%0.28%0.30%
01

Reversible, autonomous

Slow a ramp, suppress a single confirmed address, pause a send in flight. No approval needed.

02

Destructive, proposed

Purging a segment, changing DNS, filing a delisting. Drafted for a human, never executed alone.

03

Protective meanwhile

While a proposal waits, throttles stay in force. Waiting is never the risky option.

04

Resume in your hands

In-flight pauses auto-resume at most twice. Manual resume is always visible, never gated behind support.

03 / RESIDENCY & ADMISSION

UK and EU throughout, with the first bulk send gated

Self-serve signup is open. The first bulk send is not: it clears a manual review of list provenance, domain authentication and an agreed volume ramp before it leaves.

Delivery Amazon SES, eu-west-2 (London) Per-tenant reputation and suppression confirmed available in-region.
Storage EU jurisdiction on every datastore Set at creation and irreversible afterwards, which is why it was decided before anything was built.
Agent access Aggregates only, never personal data The model sees rates and counts. It does not see your contacts.
Erasure Retention tiered by data class Suppression survives erasure, stored hashed, so a removed contact is not silently re-mailed.

Early access, opening to a small number of organisations

We are onboarding deliberately slowly. Our first tenant is a UK burial-fund charity with a roughly 100,000-supporter list, moving across from SendGrid in phases — transactional and warm segments first, appeal mailshots last.