Skip to main content
March 2025

SMTP Relay

Relay your existing SMTP traffic through mailkube. Change the host, port and credentials in your mailer configuration, and nothing else.

Point your mailer at smtp.mailkube.com and authenticate with a credential created against a verified domain. The mail it was already sending is relayed from then on. A framework mailer, an old internal service and a no-code tool all take the same four settings.

SMTP and the REST API produce the same message. The delivery logs, the quota and the webhook events are all the same ones. There is no second surface to check.

Tags, topics and templates as headers

X-Mailkube-Tags, X-Mailkube-Topic and the X-Mailkube-Template-* set carry over SMTP what the REST API takes as JSON fields. All of them are stripped before the message reaches the recipient. An application you would rather not touch can still label its sends and render server-side templates.

Message tags are the labels you filter logs and dashboards by, documented for both transports under tags(opens in a new tab) and SMTP tags(opens in a new tab) . Templates are rendered server-side from an id and a version, with the header form in SMTP templates(opens in a new tab) . Topics carry the subscription a message belongs to and drive the unsubscribe surface, covered in topics(opens in a new tab) and SMTP topics(opens in a new tab) .

Connecting an SMTP client

  1. Create an SMTP credential in the dashboard under Credentials, against a verified domain
  2. Set your host to smtp.mailkube.com and your port to 587
  3. Use the credential’s username followed by its domain, myapp01@example.com rather than myapp01
  4. Send one message and find it in your logs before moving the rest of your traffic

The username carries the domain. Everything after the @ names the verified domain the session sends for.

UsernameResult
myapp01@example.comsigns in
myapp015.7.8

The From address has to use that same domain. Anything else is refused with a 550 naming the domain required.

Port 587 upgrades to STARTTLS before authenticating, and credentials are encrypted before they leave your client.