Mail and notifications

Use System > Communication > Mail Server when a tenant should send transactional messages through its own SMTP account or Postmark. Workspace keeps external delivery disabled until an authorized person completes the activation workflow.

Activate a tenant-bound Postmark transport

You need a Postmark server token and a transactional message stream. outbound is the default. If the tenant should also send newsletters, provide a separate Postmark Broadcast stream.

  1. Select Postmark and enter the sender domain, sender address, server token, and transactional message stream. Enter the Broadcast stream as well if the tenant should use bulk delivery.
  2. Save the draft. Workspace then shows a DNS TXT record for the sender domain.
  3. Publish the TXT record in your DNS and start the DNS check in Workspace.
  4. Test the connection. Workspace checks the server token, every configured stream, and the authenticated Postmark callbacks.
  5. Request the activation message. Workspace sends it to the verified email address of the acting administrator.
  6. Open the link from that message and activate the verified draft.

Workspace stores the server token encrypted and does not display it again. Delivery, bounce, and spam-complaint events remain bound to the activated transport revision. Recipient and tenant authority always come from the local dispatch, not from provider callback fields.

The setup is complete when the connection test succeeds, the activation message has been confirmed, and Workspace shows External delivery is active. Workspace does not create a Postmark account or change provider DNS records.

First production Postmark activation

Run the first production activation as an accompanied pilot. Reserve a shared window for a tenant administrator, the person responsible for the sender domain's DNS, and the operator of the publicly reachable Workspace installation.

The pilot is complete when:

  • Workspace has verified the published TXT proof;
  • Postmark has reached and verified the delivery, bounce, and complaint webhooks for the transactional stream through the public HTTPS address;
  • the intended transport revision is active;
  • one explicitly authorized transactional test message appears as a Workspace dispatch;
  • the authenticated delivery callback has changed that dispatch to delivered; and
  • the recipient has confirmed receipt.

A direct API test against the Postmark account is insufficient for this acceptance. It verifies provider access and delivery, but not the complete Workspace flow with DNS proof, webhook verification, and a pinned transport revision. The pilot does not need to generate a real complaint; Postmark's successful verification of the complaint endpoint is sufficient.

Record only the tenant, transport, and revision identifiers, timestamps, statuses, and failure codes. Do not record the Server Token, activation token, recipient address, subject, body, or raw webhook payload. The nucli skills show mail workflow keeps response fields required by later steps in a protected temporary directory instead of console logs.

Activate bulk delivery

Bulk delivery is a separate, server-controlled capability. A Staff Admin can activate it only when all of these conditions are met:

  • the tenant has an active mail.bulk license grant;
  • external delivery uses an active, verified transport revision;
  • the seven-day probation period has ended;
  • the last seven UTC days remain below the two-percent bounce threshold;
  • no unresolved provider complaint has suspended bulk delivery; and
  • a Postmark transport has a separate verified Broadcast stream. SMTP does not require an additional provider stream.

Workspace shows the current blockers in the Mail Server view. The activation action cannot override them. Newsletter campaigns enter the bulk queue only after activation. Removing the license grant or deactivating bulk delivery suppresses pending bulk work without blocking transactional messages.

A Postmark spam complaint suspends bulk delivery for the originating tenant and adds the locally recorded recipient to the tenant's suppression list. The provider callback cannot supply a different recipient or tenant. Review and resolve the complaint before planning a new activation; a suspended state is not cleared automatically.

Verify normal operation

Send one transactional test message to a controlled recipient. Check the mail delivery view after Postmark reports the result. A delivered message should move to its delivered state; bounces and spam complaints should remain visible as delivery outcomes without exposing provider payloads or credentials.

Keep external delivery disabled while the sender domain, token, or callback check is incomplete. Create a new revision when you rotate the token or change the message stream, then repeat the verification and activation workflow.