Questions & answers
Everything people ask us.
Grouped roughly in the order it tends to come up. If your question isn't here, ask it when you request access — we answer properly, not with a knowledge-base link.
The basics
What is send25, in one sentence?
A mail relay: your equipment hands us the messages it needs to send, and we deliver them properly signed so they reach the inbox instead of the junk folder.
Why did our scanner stop emailing in the first place?
Microsoft and Google switched off the old, simple way of sending mail — a plain username and password over an unencrypted connection, or no credentials at all. Modern authentication replaced it. Your copier was configured years ago and has no idea any of that happened; it keeps trying the only way it knows.
Nothing broke on your end. The rules changed underneath you.
Do we have to change our email provider or mailboxes?
No. We only handle mail your equipment sends. Your mailboxes, your Microsoft 365 or Google accounts, and everything people send to you are completely untouched.
Will mail still look like it's from us?
Yes — it comes from your domain, your address. We sign it cryptographically as you, which is the part that makes it trustworthy to Gmail and Outlook. Recipients never see our name, and replies come straight back to you.
How long does setup take?
Most sites are sending the same day. The work is: we approve your account, you publish three DNS records, and someone changes the SMTP settings on the device. The DNS records are the slow part, and only because DNS takes a few minutes to propagate.
Do you serve customers outside Newfoundland?
Yes. The equipment can be anywhere — the relay just needs to be reachable over the internet. Being in St. John's matters for where your data lives and for being able to get a human on the phone, not for where your copier sits.
Equipment
Our copier only does old encryption, or none at all. Will it work?
Yes, and this is the entire reason we exist. We accept plain connections and older encryption on port 25 — then re-send everything onward using modern encryption. The old machine never has to change.
Every large email platform refuses these connections outright. We don't.
We don't have a static IP address. Is that a problem?
Not at all. We issue a username and password per device instead, and those work on any connection. A fixed IP just saves you typing credentials into a control panel.
How many devices can we connect?
As many as you need. We recommend a separate credential for each one — it costs nothing and means a single compromised device can be cut off without disturbing the others.
What about alarm panels, door systems and other odd equipment?
If it speaks SMTP, it works. Building and security systems are often the oldest, least flexible senders in a building, and they're squarely who this is for.
Can our line-of-business application use it?
Yes — accounting packages, ERPs, practice-management systems, custom in-house apps, websites. Anything with SMTP settings. See the setup guide.
Can our own mail server relay through you?
Yes. There's a worked Postfix example in the technical reference.
DNS & deliverability
Why do we need to add DNS records?
Because otherwise Gmail and Outlook have no way to tell your mail apart from someone forging your company's name. The records let us sign your mail as you — that signature is what puts it in the inbox rather than the junk folder.
We generate the exact values, show you what to paste, and then check them against live DNS so you're not guessing whether it worked.
We don't manage our own DNS. Now what?
Whoever does — your web developer, IT provider, or domain registrar — can add them in a couple of minutes. We give you a page you can forward to them with the exact records on it.
Will this affect our existing email?
No. The records we add are additional, not replacements. Your existing mail flow keeps working exactly as it does now. If you already have an SPF record we merge into it rather than overwrite it — and we show you the merged result before you publish anything.
Our mail is landing in junk. Can you fix that?
Usually yes, and usually it's DNS. Your console has a page per domain that checks your live records and tells you precisely what's missing. Beyond that we watch the sending reputation of the service as a whole and act on problems before they reach you.
What happens when we email an address that no longer exists?
We notice, and stop sending to it automatically. Repeatedly mailing dead addresses is one of the fastest ways to damage a sender's reputation, so we suppress them for you. You can see the list and remove anything you know is valid again.
Security & privacy
Can another customer send email pretending to be our company?
No. Every account is locked to the domains it has proven it owns, and we check that on both the technical sending address and the visible From address a recipient sees. An attempt to send as someone else's domain is rejected outright and logged.
Before any domain can send at all, you publish a one-time record proving you control it. Approval alone isn't enough — that's what stops someone signing up claiming a domain that isn't theirs.
Do you read or store our messages?
No. We keep delivery records — who it went to, when, how big, and whether it arrived — not the contents. Enough to answer "did that invoice actually go out on the 3rd?", and nothing more.
How long do you keep it?
Thirty days. After that the delivery records are deleted automatically — a job runs every night and removes anything older, so it happens whether or not anyone remembers.
We keep it short deliberately. Data we no longer hold cannot be lost in a breach, handed over, or sold. If you need a longer record than that, your own sent items are the right place for it — not our database.
Where does our data physically live?
On our own hardware in St. John's. Your mail doesn't leave the province on its way out. Most email platforms process everything in the United States or Europe regardless of where you are.
Is the admin console secure?
Two-factor authentication is required for every account, sign-in is restricted by region, repeated failed attempts are blocked automatically, and every administrative action is recorded in an audit trail you can read and export.
What if one of our devices is compromised and starts spamming?
It hits your sending limit and stops — and because limits are per-customer, it can't spend anyone else's capacity or damage anyone else's delivery. We're alerted before you'd notice. Any single device can be cut off individually without disturbing the rest.
Limits & cost
What does it cost?
It depends on how much you send and how many devices you have. Request access and we'll tell you plainly — there's no charge to get set up, and no long contract.
What are the sending limits?
Hourly, daily and monthly, set to suit your normal traffic — generous enough never to interrupt an ordinary office, tight enough to cap a device stuck in a loop. You can see your current usage against your limit in the console at any time.
What happens if we go over?
Mail is held and retried, not thrown away. Your device gets a temporary response and tries again later, so nothing is lost. We're alerted, and if the new volume is legitimate we raise the limit.
This matters more than it sounds: several large platforms silently discard mail once you pass a quota. Your device reports success and the message simply never arrives.
How big can attachments be?
25 MB per message including attachments — comfortably more than a long duplex colour scan.
Switching, and switching away
What do we need to do to move to you?
Request access, publish three DNS records, and change the SMTP settings on your equipment. Nothing about your mailboxes or existing email changes.
What if we want to leave later?
Point the equipment somewhere else and remove the DNS records. There's no lock-in and nothing of yours is held hostage — the domain, the DNS and the equipment are all yours. We'd rather you stayed because it works.
Can you help us set it up, or do we do it ourselves?
Either. The console walks you through it, and the setup guide covers the common brands. If you'd rather someone did it for you, that's a conversation — say so when you request access.