Introducing IP Allowlisting
Blog post from Postmark
Postmark has introduced IP Allowlisting, a free security feature available on all plans that restricts API email-sending requests to up to 10 specified CIDR IP ranges, adding origin-based protection alongside token scoping and rotation. Allowlists can be configured at either the Server level, where they cover all Message Streams and override account settings, or the account level, where they apply across all Servers; requests from unapproved addresses receive a 403 response identifying the detected source IP. The feature is best suited to organizations with known, stable egress addresses, such as static servers, NAT gateways, or governed on-premise networks, but may be impractical for changing or unenumerated environments such as serverless workloads or CI runners. Postmark recommends testing broader ranges first on a noncritical Server before enforcing rules more widely, since an omitted address can block legitimate sending. Allowlisting applies only to API email-sending endpoints, not SMTP or other API functions, is managed through the UI, and does not function as a firewall or affect external network protections. It also differs from Postmark’s shared and dedicated sending IPs, which determine the addresses recipients see and influence sender reputation, whereas IP Allowlisting controls the IP addresses from which customers’ API requests originate.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Serverless | 1 | 156 | 54 | 28 | -80% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.