Refresh
Your domains, one DKIM key each, one sending account

One sending platform for every domain you own.

Refresh is a multi-domain email API and deliverability console. Add a domain, publish the DNS, and send transactional and broadcast mail from all of your brands through one account.

Drop-in compatible with the API your apps already call. Change a base URL and a key, or point an SMTP client at port 465.

POST /emails
curl https://api.f5send.com/emails \
  -H "Authorization: Bearer f5s_live_9Tq..." \
  -H "Idempotency-Key: order-4192-receipt" \
  -d '{
    "from": "receipts@drpromotions.org",
    "to": "customer@example.com",
    "subject": "Your receipt",
    "html": "<p>Thanks for your order.</p>"
  }'
201{ "id": "msg_01J8ZK4RQ", "status": "queued" }

Every domain, one console

Illustrative example

DomainOrganizationDKIMDMARC30-day sendsBounce
drpromotions.orgDR PromotionsVerifiedp=reject18,4020.11%
reroutehq.comReroute HQVerifiedp=quarantine6,9150.04%
benpdf.appBenPDFVerifiedp=reject2,2380.00%
tnhimports.comTNH ImportsAwaiting DNSp=none0n/a

Why teams move

One account per domain stops working at about the third domain.

Separate logins, separate keys, separate suppression lists, and no way to see whether a brand you have not looked at in a month is still authenticating. Refresh folds all of it into one control plane behind a single API.

With Refresh
Domains per accountUnlimited, grouped by organization
DKIM private keyOne per domain, encrypted under a key dedicated to your organization; removing its DNS record revokes it
Customer isolationEach organization sends through its own SES tenant, with its own suppression list and pause state
Suppression listShared across every domain in the organization, with a reason
DMARC reportingAggregate and TLS-RPT reports parsed per domain, on every plan
Regional outagePer-domain failover to a second sending region, same DKIM keys
SMTPPort 465 with the same keys, limits and logs as the API
Client separationOrganizations with admin, member and viewer roles, in the same console

The platform

Everything above SMTP, owned by you.

Refresh is the control plane: domains, keys, DNS, templates, contacts, suppression, events and logs. Delivery is a setting, not an architecture decision you make once and live with.

Domain and DNS lifecycle

Generate DKIM keys, audit SPF against the ten lookup limit, get the exact records to publish, and get told when a record drifts. MTA-STS and TLS-RPT are part of setup, not a separate project.

Send API and SMTP relay

POST the body your apps already send. Send an idempotency key and a retry returns the original message instead of a second one, so a retrying cron cannot double send. An SMTP relay on port 465 covers anything that cannot speak HTTP, with the same keys, limits and logs.

Keys scoped to the job

A key belongs to one organization, the domains you name, and one permission: send, full or admin. Hashed at rest, shown once, with last use and expiry tracked so a forgotten key is visible instead of dangerous.

Suppression that is actually shared

Hard bounces, complaints and unsubscribes suppress across every domain in the organization, with the reason and the source recorded. When a send is dropped, the message log shows which addresses were suppressed.

Broadcasts and audiences

Contacts with custom properties, topics and saved segments. Broadcasts throttle to a domain's warm-up curve, and one-click unsubscribe under RFC 8058 is on every broadcast rather than an option you can forget.

Events, webhooks and logs

Signed with HMAC-SHA256 and a timestamp, retried with backoff, filtered per endpoint and replayable from the console. Every message keeps its full timeline, searchable by recipient or subject.

How it works

Three steps to move a domain.

  1. 1

    Add the domain

    Refresh generates a DKIM key pair and the full record set: DKIM, SPF, a custom Return-Path, a tracking CNAME, and a DMARC record with a report address that belongs to your account.

  2. 2

    Publish the records

    Paste the records at your DNS provider. A verifier keeps checking and names exactly what is still missing.

  3. 3

    Point your app at it

    Change the base URL and the API key. The request body stays the same, so the diff in most applications is two lines and one environment variable.

beforehttps://api.vendor.com/emailsafterhttps://api.f5send.com/emails

Deliverability

Authentication you can prove, not assume.

Most domains sit at p=none for years because nobody has the evidence to move them. Refresh takes the DMARC reports into your own account, parses them per domain, and shows you what is passing before you tighten the policy.

Start sending
DMARC

Aggregate reports land in your account instead of a provider's. Per-domain alignment, sources you did not expect, and a policy recommendation backed by the last 30 days.

SPF

The auditor counts DNS lookups against the limit of ten, flags includes it does not recognise, and proposes a clean record to publish.

TLS

MTA-STS policy hosting and TLS-RPT intake are part of adding a domain, so transport security is a record on the zone rather than a task nobody owns.

ALERT

Thresholds on bounce rate, complaint rate, DNS drift and DMARC failures, so you hear about a problem from Refresh and not from a mailbox provider throttling you.

FAILOVER

Each domain can name a second sending region. When the primary pauses, a mailbox provider holds your mail for hours, or delivery keeps failing, sending switches on its own and switches back the same way. The keys are the same in both regions, so alignment never changes, and every switch shows on the public status page.

Questions

Straight answers.

Something not covered here? Email hello@f5send.com.

What is Refresh?

Refresh is a multi-domain email platform. It manages sending domains, DKIM keys, DNS records, API keys, templates, contacts, suppression lists and delivery events for many brands in a single console, and sends the mail on your behalf.

Am I locked in to your delivery?

No. Transport is a per-domain setting, and switching delivery region or transport inside Refresh keeps the same DKIM key and DNS records. Leaving means publishing another provider's records, the same as any move.

Who holds the DKIM private keys?

Refresh generates a key pair for each domain. The public half goes in your DNS. The private half is encrypted at rest under a key dedicated to your organization, and the sending service holds a copy to sign your mail. Changing region or transport inside Refresh keeps the same key, so nothing in DNS changes.

How much work is migrating an app that already sends email?

Usually two lines. The send API takes the same request body as the hosted APIs most apps already call, so the app changes its base URL and its key. You can dual-run against your old provider while you watch the logs.

Can I send over SMTP instead of the API?

Yes. Point the client at port 465 with implicit TLS, use the API key id as the username and the key as the password. Each message goes through the same limits, suppression and logs as an API call, and a Test key simulates instead of delivering. WordPress, Postfix and any language's mail library work without code changes.

What happens when the delivery provider has an outage?

Refresh sends from two regions. A domain with failover enabled moves to the second region within seconds of a pause or a run of errors and moves back when the primary recovers. DKIM keys are the same in both, so nothing about authentication changes, and the switch is logged and visible on the status page.

Can I send on behalf of clients?

Yes. Every domain, contact, key, suppression and log line belongs to an organization, marked internal or client, with admin, member and viewer roles. Nothing crosses an organization boundary, so a client can be given the console for their own brand and see only that.

What does it cost?

Transactional email starts at $20 a month for 50,000 emails, and marketing is billed separately by contacts stored, starting at $40 a month for 5,000 contacts. Sending domains are unlimited on every plan, because charging per domain is the problem this exists to solve. The full ladder is on the pricing page.

Where is my data held?

In the United States. Message body retention is set per organization and can be turned off entirely, so you decide whether the contents of a message are kept at all once it has been sent.

Bring your first domain over this week.

Add a domain, publish the records, and send a test message. If it does not authenticate cleanly, the console tells you which record is wrong.