What does data residency actually mean for email service providers?

You send a transactional email to a customer in Germany. It arrives seconds later. But was it processed in Europe—or stored in a data center in the U.S.? That’s the real question behind data residency.

It’s not just about where an email is sent from. It’s about where your customer’s data lives—on servers, in logs, in metadata—and whether that location complies with local laws like GDPR, HIPAA, or CCPA.

For email service providers, data residency affects where your infrastructure is located, how long logs are kept, and whether you can prove compliance when audited. Transparency here isn’t optional. It’s a requirement for trust, legal compliance, and inbox placement.

Key takeaways

  • Data residency determines the physical location of customer data and is governed by regional regulations like GDPR and CCPA.
  • Providers must disclose their infrastructure locations to ensure compliance with data sovereignty laws.
  • Resend and Postmark both offer data residency options, with Postmark emphasizing SOC 2 compliance and geographic data routing.

Why SOC 2 matters when choosing an email provider

SOC 2 reports aren’t a seal of approval you apply for—they’re independent audits of a provider’s security controls, showing whether they protect your data through strict standards for confidentiality, availability, processing integrity, and privacy. If you’re sending sensitive messages, especially at scale, a provider with a valid SOC 2 report proves they’re not just making promises—they’re held accountable.

What SOC 2 actually is (and isn’t)

SOC 2 is not a certification. It’s an audit report issued by a licensed CPA firm after evaluating a service provider’s internal controls. The report is built on five trust service criteria: security, availability, processing integrity, confidentiality, and privacy. Not all providers have one. Those that do have undergone rigorous scrutiny. You can verify the authenticity of a SOC 2 report through the AICPA’s official repository.

Let’s be clear: having a SOC 2 report doesn’t mean you’re immune to breaches. But it does mean the provider has documented, tested, and maintained controls to reduce risk. For example, it’s common for providers to use encryption in transit and at rest, enforce access management policies, and log critical events—all of which are part of a SOC 2 evaluation.

Why you can’t just trust a vendor’s word

Many email providers claim to be secure. But without a third-party audit, you don’t know if those claims are backed by real systems or just marketing. A SOC 2 report is like a financial audit—it gives you objective evidence of internal reliability.

For companies handling customer data—the kind that gets sent in emails—you need more than claims. You need proof. SOC 2 helps you do that. If a provider doesn’t publish their report, it’s a red flag. Transparency here isn’t optional—it’s foundational to trust.

At MailTester, we don’t just claim strong security. Our platform, including our bulk verification, real-time API, and inbox placement testing, is designed with data protection at its core. We’re built on the same principles that underlie SOC 2: accountability, transparency, and continuous improvement. Want to see what’s possible with verified, trusted data? Explore our pricing or test a list with zero risk using our integrations with platforms like SendGrid and HubSpot.

Resend vs Postmark: Data residency and SOC 2 compliance — real details, no hype

Neither Resend nor Postmark offers full transparency into their global data center locations, but both claim compliance with GDPR and CCPA via SOC 2 Type II reports. Postmark publishes its SOC 2 Type II report publicly; Resend does not. Neither provides region-specific routing controls, and actual data residency depends on the provider’s internal infrastructure choices, not user config.

What’s public — and what’s not

Resend states it operates globally with data centers in the US, Europe, and Asia, but it doesn’t publish exact facility locations. This lack of detail prevents you from verifying whether your European data actually remains in the EU. Postmark, in contrast, maintains a public SOC 2 Type II report, which is rare among email services, but only confirms US-based data centers. There’s no public evidence of EU or Asian facilities, though it may use third-party infrastructure in those regions.

Let’s be clear: neither platform lets you choose which region your data resides in. You can’t route emails to a specific data center or enforce storage within the EU for GDPR purposes. If compliance depends on physical data location, the default setup may not meet strict regulatory requirements — especially for high-risk verticals like healthcare or finance.

Compliance: what the report says vs how it’s applied

Both Resend and Postmark claim compliance with GDPR and CCPA based on their SOC 2 attestation. The SOC 2 Type II report covers controls around security, availability, processing integrity, confidentiality, and privacy — an industry-standard verification. However, the report certifies the provider’s internal controls, not the actual location or handling of your data.

For example, a SOC 2 report doesn’t guarantee that your customer emails never leave the EU if Resend routes via a US node. It only verifies that the company has defined security processes. The difference between a technical compliance claim and real-world data residency is significant. According to the European Data Protection Board, data processing must be governed by actual geographic controls — not just policy statements.

If you’re managing sensitive data, this gap matters. You can’t fully trust a SOC 2 report alone to confirm compliance — especially when the underlying infrastructure is opaque. Always validate against your own risk threshold. For example, if you’re sending emails to EU recipients, verify that the provider’s actual data paths align with GDPR requirements, not just their self-declared scope.

At MailTester, we help teams confirm deliverability and infrastructure integrity before sending at scale. Our bulk verification tool detects invalid, risky, and disposable emails — reducing bounce risk and protecting sender reputation. For real-time checks, use our verification API. Test inbox placement with our inbox tester to see if your messages land in the primary inbox. All integrations are available via our integrations page — no credit card needed for our 100 free verifications.

How to verify data residency claims from email providers

You can’t trust a provider’s data residency claims unless you review their full, current SOC 2 Type II report. This document, audited by an independent firm, details where data is stored, how it’s handled, and who has access—providing real proof, not marketing. Don’t rely on summaries or sales materials.

What to look for in a SOC 2 report

  • Ask for the full auditor’s report—not a summary or self-declaration. A genuine Type II report includes tested controls and real findings over a period, like 12 months.
  • Check for explicit mentions of infrastructure regions (e.g., "data centers in Frankfurt, Germany" or "AWS US-East-1"). If the report doesn’t list specific locations, the provider is not transparent.
  • Look for documented data handling procedures, especially around encryption at rest and in transit, data deletion policies, and cross-border data transfers.
  • Verify that access controls are properly described—especially how admin access is granted, monitored, and restricted by geography.
  • Ensure the audit period includes your compliance window. A report covering only 2023–2024 won’t satisfy a 2025–2026 policy review.

How to validate the auditor’s credibility

  • Confirm the auditing firm is independent, licensed, and globally recognized (e.g., BDO, PwC, KPMG). These firms are subject to oversight by professional bodies like the PCAOB or IFAC.
  • Check if the auditor’s name appears on the report’s certification page and cross-reference it with the firm’s official website.
  • Be wary of providers that offer a "SOC 2" claim without naming the auditor or the report type. A Type II report implies ongoing compliance testing—Type I does not.
  • For reference, the AICPA defines SOC 2 standards and the required elements for each report type, including the auditor's role and report structure.
Real data residency isn’t claimed—it’s proven by audited documentation. If a provider won’t share the full report, question everything.

When verifying email infrastructure, use tools that test actual delivery and inbox placement to validate your provider’s claims—your compliance depends on more than just promises. MailTester helps you check list health and deliverability risk with 98.9% accuracy, so you know when a provider’s data practices are failing in practice, not just in theory.

For real-time verification of email addresses—including those tied to suspicious or foreign infrastructure—try the MailTester API. Or, test entire send lists with bulk verification. If you're integrating with marketing platforms, see how MailTester works with Mailchimp, HubSpot, Klaviyo, and SendGrid.

What's missing from most email provider compliance claims

Most email providers claim SOC 2 compliance lightly — often relying on outdated Type I reports or omitting key details like whether encryption at rest and in transit are verified. Even with a Type II report, access controls for logs, APIs, and support teams may lack real-time monitoring. Transparency is the real gap: few publish the full audit scope, making it hard to know what’s actually tested. You’re not just trusting a label — you’re trusting what that label covers.

The SOC 2 gap: Type I vs. Type II, and what’s not checked

Many providers show a SOC 2 Type I report, which only confirms controls were in place at a single point in time — not that they worked consistently. A Type II report, which evaluates controls over six to twelve months, is the industry standard for serious compliance. Yet even when present, the report’s scope is rarely published. Without it, you don’t know if encryption, access logging, or incident response were actually tested.

For example, the AICPA’s Trust Services Criteria specify that organizations must test controls across all systems where data resides. But without a published scope, you can’t verify whether that includes your data in transit or if cloud storage encryption is validated. A provider might claim compliance while still allowing third-party access to raw logs without audit trails.

Even with a solid SOC 2 report, third-party access — by support teams, subcontractors, or even internal developers — can remain poorly monitored. You might be compliant on paper, but if someone from a partner team can pull your logs or trigger API actions without logs or alerts, you’re exposed. This is especially risky for sensitive data like customer emails or transactional records.

Let’s be clear: compliance isn’t a checkbox. It’s a continuous process. Many providers treat compliance as a one-time sale item — a PDF sent in an email — rather than an evolving security contract. You need to ask: What’s in the report? Who gets access? How often are logs reviewed? You can’t trust what you can’t see.

With MailTester, you verify email lists before sending — reducing risk before it reaches your inbox. Our bulk verification catches invalid or risky addresses early, preventing delivery failures and protecting sender reputation. Real-time checks with our API help ensure only valid emails are processed. For end-to-end visibility, test deliverability with our inbox placement tool, and integrate seamlessly with your stack via our integrations.

When you verify data, you’re not just cleaning a list — you’re building the foundation of reliable, compliant communication. That starts with knowing what your provider actually guarantees.

How MailTester helps teams verify compliance-ready email lists

You can verify and clean your email lists with 98.9% accuracy using MailTester’s real-time API and bulk tools, flagging disposable, role, and catch-all addresses that hurt deliverability. By removing these before sending, you reduce bounce rates, avoid spam traps, and strengthen sender reputation—key parts of compliance with email deliverability standards like those upheld by major providers such as Google and Microsoft. This proactive cleaning ensures your messages land in inboxes, not quarantines.

Validation that aligns with deliverability best practices

When you verify an email address, MailTester checks both syntax and domain health—validating the existence of an MX record, assessing whether the domain allows incoming mail, and probing for known disposable domains. These checks go beyond basic parsing, catching addresses that may technically be valid but are inherently risky. For example, Spamhaus identifies many disposable domains as high-risk, and sending to them can trigger automated spam filters.

Integrate verification into your workflow

Let’s say you’re using SendGrid to send transactional emails or Mailchimp for campaigns—MailTester integrates directly with both. You can plug our API into your sign-up flow or run bulk verification on your entire list via our bulk tool. This means you’re not just checking accuracy; you’re building a list that complies with inbox placement expectations and reduces the risk of being flagged as spam, even during high-volume sends.

Our system reports outcomes clearly: valid, invalid, catch-all, or risky. Catch-all addresses, for instance, accept mail without verification, but can signal low-quality data to providers. Role accounts like admin@ or sales@ often go unanswered and inflate spam complaints. Disposable domains—used for short-term sign-ups—are a red flag for deliverability teams, meaning their inclusion can harm your sender reputation over time.

By using MailTester, you’re not just cleaning data; you’re preparing lists that meet industry standards. This isn’t just about compliance—it’s about inbox placement. The more your list mirrors the behavior of trusted senders, the more likely your messages will reach inboxes, not filters.

For teams managing large-scale sends, we also offer inbox placement testing to simulate real delivery conditions. This gives you insight into how your messages might perform across major email providers—useful before a major launch or campaign rollout.

The real impact of poor data hygiene on compliance and deliverability

You can’t claim compliance or trustworthiness if your email list includes role accounts, disposable domains, or invalid addresses. Even one bad address can trigger spam traps, raise bounce rates, and hurt your sender reputation — undermining any SOC 2 or data residency claims you make. If your list is broken, your security and deliverability are broken too.

Role accounts and disposable domains degrade sender reputation

Role accounts like sales@, admin@, or info@ often bypass spam checks, but ISPs know they’re not real people. Sending to them inflates your bounce rate and signals poor list quality. Disposable email domains (like mailinator.com or temp-mail.org) are used almost exclusively for one-time signups and are rarely opened. ISPs treat these as high-risk — if your list has many, you’re seen as a low-quality sender.

According to a Spamhaus report, senders with high volumes of non-deliverable addresses are more likely to be flagged by major ISPs. Even if your provider is SOC 2 compliant or claims data residency in the EU, your sending behavior still gets judged on real-world metrics — and reputation is built on performance, not paperwork.

Invalid data erodes compliance and deliverability

One spam trap or invalid address in your list can lead to an ISP blocking your domain. Spam traps are dormant addresses set by ISPs to catch senders with poor hygiene. If you hit one, even once, it can trigger reputation penalties or cause inclusion in blocklists.

Even if your email service provider (ESP) is SOC 2 certified, your data hygiene determines your actual safety. Compliance is a process, not a shield. If your list contains thousands of role accounts or disposable domains, your sender reputation will suffer — regardless of your provider’s certifications. Deliverability depends on real-time performance, not theoretical controls.

Let’s be clear: you can’t verify compliance with bad data. Before you even think about SOC 2 or data residency, clean your list. Use tools like MailTester’s bulk verification to detect invalid addresses, catch-all domains, and disposable emails before they harm your reputation.

How to use MailTester to pre-validate lists before sending via Resend or Postmark

You can prevent bounces, spam traps, and delivery issues by verifying your email list before sending through Resend or Postmark. MailTester checks each address in real time or bulk, flagging invalid, disposable, catch-all, and risky addresses so you only send to valid, deliverable inboxes — improving inbox placement and preserving sender reputation. It’s a direct way to align with industry best practices like those outlined in RFC 5321 and RFC 5322.

  1. Upload your list to MailTester using the bulk verification tool or integrate the real-time verification API. You can process thousands of addresses in minutes. The system validates syntax, domain existence, and mailbox responsiveness.
  2. Review the verification verdicts for each email: Valid (ready to send), Invalid (syntax or domain error), Catch-all (accepts all emails, likely spam trap), Risky (high bounce or complaint likelihood), or Disposable (temporary address). These signals are based on SMTP-level checks and real-world delivery behavior.
  3. Filter out unwanted addresses before sending to Resend or Postmark. Remove Invalid, Disposable, and Risky emails entirely. You may also choose to exclude catch-all domains, as they are commonly used in list scraping or spam campaigns. This reduces your bounce rate and protects your sender reputation.
  4. Use the in-app AI assistant to clean large files or refine rules based on your historical bounce patterns. It identifies recurring issues—like typo-ridden domains or common disposable patterns—and suggests automated filters tailored to your sending behavior.

Why this matters for deliverability

Even with strong authentication (SPF, DKIM, DMARC), sending to invalid or risky addresses harms deliverability. Major providers like Gmail, Outlook, and Apple evaluate sender reputation based on engagement and feedback loops. High bounce rates — even from a few hundred bad addresses — trigger throttling or filtering.

According to RFC 5321, MX records and valid SMTP responses are the foundation of email delivery. MailTester checks both. Using it upfront means you’re not guessing. Every send to Resend or Postmark starts with an address confirmed as valid and likely to land in the inbox.

MailTester doesn’t require you to choose between data residency in the U.S. or Europe — you can use it regardless of your underlying provider’s configuration. Its verification process doesn’t store or transmit your data after processing, aligning with SOC 2 principles on data integrity and confidentiality.

Once you’ve cleaned your list, upload it to Resend or Postmark with confidence. For further testing, you can run an inbox placement test via MailTester’s inbox placement tool to simulate real-world delivery across major inboxes and domains.

What to check when integrating email tools for compliance

When integrating email tools, verify data residency, encryption standards, auditability, and retention controls. Ask: Is your data stored in your region? Are encryption and access logs verified in a SOC 2 report? Can you disable or limit retention? These checks confirm compliance with regional laws like GDPR or CCPA and reduce exposure to audit risk.

Core compliance checks

  • Confirm the provider stores data in your region of operation—specifically the EU, US, or other jurisdiction with relevant privacy laws. Ask for their data center locations and ensure they align with your legal requirements.
  • Verify that encryption at rest and in transit is enforced by default. Check that the provider’s SOC 2 report includes a section on security controls for data protection, and review the audit scope to ensure it covers the full data lifecycle.
  • Ensure API access logs are retained for at least 90 days and can be exported or audited on demand. This is critical for detecting and investigating unauthorized access, especially when integrated with internal security tools.
  • Check whether you can disable or limit data retention for specific use cases—like email verification on test lists or campaign debugging. The ability to delete or suppress data after a defined period reduces compliance risk and supports data minimization principles.

What SOC 2 tells you—and what it doesn’t

SOC 2 reports are standardized, but only cover specific controls. A 2019 AICPA guidance clarifies that the report is only valid for the date and scope stated—and it does not verify performance, only process adherence. You can’t assume a SOC 2 compliance badge means data is safe; always read the specific control descriptions.

For example, a provider’s SOC 2 may confirm encryption is enforced, but not how keys are managed or who can access them. Always cross-check against your internal risk profile. If you manage PII, ask for proof of data access logging and retention policies.

How MailTester supports compliance

If you’re verifying email data across multiple regions, MailTester helps. Our bulk verification ensures you don’t send to invalid or risky addresses—which reduces data exposure. Our real-time verification API supports low-latency integration with automated retention policies and audit-ready logs. Use the inbox placement checker to verify deliverability without exposing sensitive data. Integrations with Mailchimp, HubSpot, Klaviyo, and SendGrid ensure verified data flows securely between systems. All credits are lifetime, so you can verify data without worrying about expiration. Learn more at our pricing page.

Why accuracy and reputation matter more than provider claims

Just because a provider has a SOC 2 report doesn’t mean your emails land in inboxes. SOC 2 validates infrastructure compliance, but deliverability depends on list accuracy, sender reputation, and engagement — not compliance checkboxes. Even with secure, audited systems, sending to invalid or unengaged addresses hurts your reputation and triggers filters.

Reputation isn’t built in a compliance report

MailTester’s verification engine checks real-time SMTP response, domain health, and role-account patterns — not just whether a provider passes a security audit. A SOC 2 report confirms a provider’s internal controls, but it doesn’t tell you if your recipients actually want your emails. Email providers like Google and Apple use inbox placement algorithms that prioritize engagement, not vendor compliance.

Let’s be clear: no audit prevents a high bounce rate. If your list has 30% invalid addresses, even a SOC 2-certified system can’t save your deliverability. High bounce rates and low engagement signal spam to ISPs. And once a sender’s reputation degrades, recovery is hard.

Accuracy trumps infrastructure claims

Providers like Resend and Postmark offer strong infrastructure, including SOC 2 Type II reports, which are industry-standard for cloud service providers. But a compliant stack doesn’t fix a poor-quality list. Your sender reputation is built on real-world behavior: who opens, clicks, and marks as spam. That’s why list hygiene matters more than compliance labels.

To test how your emails are seen by real inboxes, run inbox placement tests. See for yourself how close your emails land to the inbox vs spam folder. MailTester’s inbox tests analyze real email clients using live inboxes (not simulations). Use the inbox tester to check your campaigns before sending.

Data residency and SOC 2 are necessary for enterprise trust, but they don’t guarantee inbox delivery. What does? A clean list, consistent engagement, and a reputation built over time through responsible sending. You can use tools like the bulk verification or the real-time verification API to ensure your list is accurate before you send, and measure delivery with live inbox testing. If your list is full of disposable domains, role accounts, or dormant addresses, no amount of compliance will help.

Final take: choose tools based on real data protection and clean sending practices

SOC 2 compliance is a baseline, not a finish line. Even if a provider claims SOC 2, the full report reveals what’s actually verified—controls, scope, and auditor independence. Always review the actual report, not just a marketing claim.

Data residency matters only when you can enforce where data is stored and processed. A label like “EU-only” is meaningless without clear technical controls and audit trails. Real control comes from transparency and configuration options.

Even the most compliant infrastructure fails if the data sent is poor. Invalid, outdated, or fake addresses harm sender reputation and trigger filters. Clean data—verified, accurate, and up to date—is the single strongest factor in inbox placement, regardless of provider compliance.

Sources

Keep reading

Ready to put this into practice? MailTester verifies emails with 98.9% accuracy — start with 100 free verifications.

Frequently asked questions

Does Resend have a SOC 2 report?

Yes, Resend provides a SOC 2 Type II report, but the full document is not publicly available — it must be requested via their trust page.

Is Postmark SOC 2 compliant?

Yes, Postmark maintains a publicly available SOC 2 Type II report and confirms compliance with GDPR and CCPA.

Can I control where my email data is stored with Resend or Postmark?

Neither provider currently offers regional routing controls or data storage selection at the account level.

Are disposable email addresses a compliance risk?

Yes — disposable addresses are often associated with spam traps and high bounce rates. They weaken sender reputation and can trigger abuse flags.

How does list hygiene improve deliverability?

Clean lists reduce bounces, avoid spam traps, and improve engagement — all of which strengthen sender reputation and inbox placement.

Does MailTester offer compliance reports?

No — MailTester does not issue compliance reports. It verifies addresses and cleans lists for accuracy and deliverability.

What's the difference between SOC 2 Type I and Type II?

Type I confirms controls were in place at a point in time. Type II verifies effectiveness over a period, typically six months to a year.

Can I verify a list before sending via Resend?

Yes — use MailTester’s bulk verification or API to clean the list first. Then send via Resend with a reduced risk of bounces or spam flags.

How accurate is MailTester’s email verification?

MailTester delivers 98.9% accuracy across all verification types, including catch-all and risky addresses.

Do purchased MailTester credits expire?

No — credits never expire, and you get 100 free verifications upon sign-up.

How does MailTester integrate with Postmark and Resend?

MailTester integrates with SendGrid, Mailchimp, HubSpot, and Klaviyo. You can verify lists before importing into Postmark or Resend.

Why is data residency important for EU customers?

It ensures compliance with GDPR, which requires data processing within the EU or with approved transfer mechanisms.