Domain and DNS lifecycle
Generate DKIM keys, audit SPF against the ten lookup limit, get the exact records to publish, and get told when a record drifts. MTA-STS and TLS-RPT are part of setup, not a separate project.
Refresh is a multi-domain email API and deliverability console. Add a domain, publish the DNS, and send transactional and broadcast mail from all of your brands through one account.
Drop-in compatible with the API your apps already call. Change a base URL and a key, or point an SMTP client at port 465.
curl https://api.f5send.com/emails \
-H "Authorization: Bearer f5s_live_9Tq..." \
-H "Idempotency-Key: order-4192-receipt" \
-d '{
"from": "receipts@drpromotions.org",
"to": "customer@example.com",
"subject": "Your receipt",
"html": "<p>Thanks for your order.</p>"
}'Illustrative example
| Domain | Organization | DKIM | DMARC | 30-day sends | Bounce |
|---|---|---|---|---|---|
| drpromotions.org | DR Promotions | Verified | p=reject | 18,402 | 0.11% |
| reroutehq.com | Reroute HQ | Verified | p=quarantine | 6,915 | 0.04% |
| benpdf.app | BenPDF | Verified | p=reject | 2,238 | 0.00% |
| tnhimports.com | TNH Imports | Awaiting DNS | p=none | 0 | n/a |
Why teams move
Separate logins, separate keys, separate suppression lists, and no way to see whether a brand you have not looked at in a month is still authenticating. Refresh folds all of it into one control plane behind a single API.
| With Refresh | |
|---|---|
| Domains per account | Unlimited, grouped by organization |
| DKIM private key | One per domain, encrypted under a key dedicated to your organization; removing its DNS record revokes it |
| Customer isolation | Each organization sends through its own SES tenant, with its own suppression list and pause state |
| Suppression list | Shared across every domain in the organization, with a reason |
| DMARC reporting | Aggregate and TLS-RPT reports parsed per domain, on every plan |
| Regional outage | Per-domain failover to a second sending region, same DKIM keys |
| SMTP | Port 465 with the same keys, limits and logs as the API |
| Client separation | Organizations with admin, member and viewer roles, in the same console |
The platform
Refresh is the control plane: domains, keys, DNS, templates, contacts, suppression, events and logs. Delivery is a setting, not an architecture decision you make once and live with.
Generate DKIM keys, audit SPF against the ten lookup limit, get the exact records to publish, and get told when a record drifts. MTA-STS and TLS-RPT are part of setup, not a separate project.
POST the body your apps already send. Send an idempotency key and a retry returns the original message instead of a second one, so a retrying cron cannot double send. An SMTP relay on port 465 covers anything that cannot speak HTTP, with the same keys, limits and logs.
A key belongs to one organization, the domains you name, and one permission: send, full or admin. Hashed at rest, shown once, with last use and expiry tracked so a forgotten key is visible instead of dangerous.
Hard bounces, complaints and unsubscribes suppress across every domain in the organization, with the reason and the source recorded. When a send is dropped, the message log shows which addresses were suppressed.
Contacts with custom properties, topics and saved segments. Broadcasts throttle to a domain's warm-up curve, and one-click unsubscribe under RFC 8058 is on every broadcast rather than an option you can forget.
Signed with HMAC-SHA256 and a timestamp, retried with backoff, filtered per endpoint and replayable from the console. Every message keeps its full timeline, searchable by recipient or subject.
How it works
Refresh generates a DKIM key pair and the full record set: DKIM, SPF, a custom Return-Path, a tracking CNAME, and a DMARC record with a report address that belongs to your account.
Paste the records at your DNS provider. A verifier keeps checking and names exactly what is still missing.
Change the base URL and the API key. The request body stays the same, so the diff in most applications is two lines and one environment variable.
Deliverability
Most domains sit at p=none for years because nobody has the evidence to move them. Refresh takes the DMARC reports into your own account, parses them per domain, and shows you what is passing before you tighten the policy.
Start sendingAggregate reports land in your account instead of a provider's. Per-domain alignment, sources you did not expect, and a policy recommendation backed by the last 30 days.
The auditor counts DNS lookups against the limit of ten, flags includes it does not recognise, and proposes a clean record to publish.
MTA-STS policy hosting and TLS-RPT intake are part of adding a domain, so transport security is a record on the zone rather than a task nobody owns.
Thresholds on bounce rate, complaint rate, DNS drift and DMARC failures, so you hear about a problem from Refresh and not from a mailbox provider throttling you.
Each domain can name a second sending region. When the primary pauses, a mailbox provider holds your mail for hours, or delivery keeps failing, sending switches on its own and switches back the same way. The keys are the same in both regions, so alignment never changes, and every switch shows on the public status page.
Refresh is a multi-domain email platform. It manages sending domains, DKIM keys, DNS records, API keys, templates, contacts, suppression lists and delivery events for many brands in a single console, and sends the mail on your behalf.
No. Transport is a per-domain setting, and switching delivery region or transport inside Refresh keeps the same DKIM key and DNS records. Leaving means publishing another provider's records, the same as any move.
Refresh generates a key pair for each domain. The public half goes in your DNS. The private half is encrypted at rest under a key dedicated to your organization, and the sending service holds a copy to sign your mail. Changing region or transport inside Refresh keeps the same key, so nothing in DNS changes.
Usually two lines. The send API takes the same request body as the hosted APIs most apps already call, so the app changes its base URL and its key. You can dual-run against your old provider while you watch the logs.
Yes. Point the client at port 465 with implicit TLS, use the API key id as the username and the key as the password. Each message goes through the same limits, suppression and logs as an API call, and a Test key simulates instead of delivering. WordPress, Postfix and any language's mail library work without code changes.
Refresh sends from two regions. A domain with failover enabled moves to the second region within seconds of a pause or a run of errors and moves back when the primary recovers. DKIM keys are the same in both, so nothing about authentication changes, and the switch is logged and visible on the status page.
Yes. Every domain, contact, key, suppression and log line belongs to an organization, marked internal or client, with admin, member and viewer roles. Nothing crosses an organization boundary, so a client can be given the console for their own brand and see only that.
Transactional email starts at $20 a month for 50,000 emails, and marketing is billed separately by contacts stored, starting at $40 a month for 5,000 contacts. Sending domains are unlimited on every plan, because charging per domain is the problem this exists to solve. The full ladder is on the pricing page.
In the United States. Message body retention is set per organization and can be turned off entirely, so you decide whether the contents of a message are kept at all once it has been sent.
Add a domain, publish the records, and send a test message. If it does not authenticate cleanly, the console tells you which record is wrong.