Refresh

Company

Trust and security

What to check before you send real mail through Refresh, and where to verify each answer.

Who runs it

Refresh is operated by Obsidian Heron, 30 N Gould St Ste R, Sheridan, WY 82801. It has been in production since August 2026, sending mail for the operator's own brands before it opened to other senders. Delivery runs on Amazon SES in the United States. Questions go to hello@f5send.com.

Your mail is isolated from other customers

  • Each organization sends through its own Amazon SES tenant, with its own suppression list and its own pause state. SES can pause one tenant without touching the others.
  • Bounce and complaint alerts can pause one organization, or one domain, before SES has to act.
  • Each domain can name a second sending region, with the same DKIM keys, that takes over if the primary region pauses. Failovers appear on the public status page.

DKIM keys: who holds them, and how you revoke them

  • Refresh generates an RSA-2048 key pair for each domain. The public half goes in your DNS; the private half is stored encrypted.
  • A client organization's keys are encrypted under its own AWS KMS key, and every decryption is recorded in AWS CloudTrail. Amazon SES keeps a copy of the key to sign your mail.
  • A DKIM key signs for your domain only while your DNS publishes its public half. Remove that TXT record and the key stops working once DNS caches expire, with no action needed from us.
  • Keys rotate between two selectors without downtime. Deleting an organization schedules its KMS key for deletion; after 30 days its encrypted data is unreadable by anyone.

Who can reach production

Only named operators, each with multi-factor authentication, and only for support you asked for, an incident, or maintenance. The Data Processing Addendum sets this out, with the sub-processors in its annex.

Message content

  • Body retention is set per organization, from 0 to 90 days. At 0, the body is deleted as soon as the message is sent, and the API log keeps only the length of the content.
  • Stored bodies are encrypted; a client organization's under its own KMS key. Deleting an organization deletes its stored bodies.
  • The data protection guide lists every kind of data, where it lives and for how long.

If you leave, or if we stop

  • Contacts and suppressions export as CSV from the console at any time.
  • To move a domain elsewhere, publish the new provider's records and remove ours. Our DKIM key stops working the moment its record is gone; there is nothing else to hand back.
  • The Terms commit to 30 days' notice before we end the service for any reason other than a policy breach or non-payment, and 30 days' notice of a price change.

Pilot it safely

  1. Start with a Test key: it runs the full pipeline and simulates delivery, so nothing reaches a real inbox.
  2. Move one low-stakes domain first. In a received message, check that the Authentication-Results header shows dkim=pass for your own domain, and that SPF and DMARC pass.
  3. Set body retention to 0 and confirm the message timeline keeps events but no content.