Mail API · by WebXIO

One request. Your mail is on its way.

SMTP-Relay takes your application's mail through a REST API, fills in the template in the right language and delivers it through your own mail account: Microsoft 365, Google or any SMTP server. With a queue, retries and a log, operated by WebXIO in Europe.

admin.smtp.webxio.at — api/v1/send

Request

curl -X POST https://admin.smtp.webxio.at/api/v1/send \
  -H "Authorization: Bearer $SMTP_RELAY_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "to": "anna@example.com",
    "templateId": 7,
    "language": "de-AT",
    "variables": { "firstName": "Anna" }
  }'

Response

HTTP/1.1 202 Accepted
X-RateLimit-Limit: 60
X-RateLimit-Remaining: 59

{ "id": 42, "status": "queued", "language": "de" }

SMTP-Relay in numbers

Endpoint
POST /api/v1/send
Delivery attempts
up to 5
Languages per template
up to 50
Hosting
Europe, self-hosted

01How it works

From request to inbox.

Your application sends one request, the relay does the rest: check, render, queue, deliver.

  1. Your application

    Sends recipients, template and variables as JSON, authenticated with its project's API key.

    Bearer srk_…
  2. Checks

    Key, rate limit and content are checked. As soon as the mail is queued, the API answers with an ID.

    202 Accepted
  3. Template

    The template is rendered in the matching language: the exact one, then the base language, then English, then German.

    Handlebars
  4. Queue

    Up to 5 attempts with growing pauses. Permanent errors such as an unknown recipient are not retried.

    BullMQ · Valkey
  5. Your mail account

    Mail goes out through your project's SMTP account: Microsoft 365, Google or any other server, over SSL, TLS or STARTTLS if you like.

    SMTP
  6. Inbox

    The status changes to “sent”, with message ID and timestamp. Available through the API and in the log.

    status: sent

Mail is sent through your own account: sender address, SPF and DKIM stay with your mail provider.

02Features

Everything between your app and the inbox.

What your application would otherwise have to build itself is part of the relay, managed in the admin UI.

Templates

Subject, HTML and text with placeholders, conditions and loops. In the admin UI with a visual editor and live preview.

  • Syntax errors show up when you save, not when you send
  • Values are escaped in HTML automatically
  • Plain-text version in one click from the content
  • Handlebars
  • HTML + Text

Multilingual

Up to 50 translations per template. You send the language along, the relay picks the matching translation.

  • BCP 47 language codes, such as de-AT
  • Fallback: exact, base language, English, German
  • The response names the language used
  • BCP 47
  • de-AT → de → en

Queue & retries

Every mail goes into the queue first. If sending fails, the relay tries up to 5 times.

  • Pauses: 30 s · 1 min · 2 min · 4 min
  • Permanent errors (SMTP 5xx) are not retried
  • 503 instead of silent loss when the queue is down
  • BullMQ
  • Valkey

Your own mail accounts

Several SMTP accounts per project, one of them the default. Pick another one per mail with accountId.

  • Connection test right in the admin UI
  • Encryption: none, SSL, TLS or STARTTLS
  • Credentials stored encrypted (AES-256-GCM)
  • Microsoft 365
  • Google
  • SMTP

API keys & rate limit

Every project gets its own named keys, for production and testing for example. Revoking takes one click.

  • A key is shown once, only its hash is stored
  • 60 by default, at most 100 mails per minute and project
  • 429 with Retry-After when exceeded
  • Bearer srk_…
  • 429 + Retry-After

Log & dashboard

Every mail with status, attempts and last error, filterable by project, status and free text.

  • Sent, failed, delivery rate, queue
  • Daily history over 7 to 90 days
  • Busiest projects and recent failures at a glance
  • queued
  • sending
  • sent
  • failed
Planned

Not available yet, but on the way:

  • Attachments
  • Webhooks
  • Bounce handling
  • DKIM / SPF
  • Open and click tracking

03API

One endpoint. No SDK required.

A POST with JSON is all it takes, from any language and any framework. Look up the status of every mail by its ID.

Two ways to send

  1. With a template

    templateId, variables and optionally language. Content and translations live in the admin UI, your code stays lean.

  2. Without a template

    subject plus html and/or text right in the request, for mail whose content your application generates itself.

Error codes

400
Invalid request, such as an address or language code
401
API key missing, invalid or revoked
422
Template or mail account not linked or inactive, rendering failed
429
Rate limit reached, respect Retry-After
503
Queue unavailable, mail not accepted

Limits

Recipients
up to 50 each in to, cc and bcc
Request
up to 2 MB of JSON
Subject
up to 998 characters
Rate limit
60 per minute, up to 100

Use the API key on the server only, never in the browser.

Delivery — mail 42
  1. curl …/api/v1/messages/42
  2. queued id 42 · template 7 · de
  3. sending attempt 1 of 5
  4. queued 421 try again later · retry in 30 s
  5. sending attempt 2 of 5
  6. sent 250 OK · messageId <5f1c…@example.com>
GET /api/v1/messages/42

Look up the status

{
  "id": 42,
  "status": "sent",
  "attempts": 2,
  "language": "de",
  "messageId": "<5f1c…@example.com>",
  "sentAt": "2026-09-29T09:14:03.000Z",
  "error": null
}

04Operations

No mail gets lost silently.

The relay is built to be traceable: every accepted mail has an ID, a status and a history.

Principles

  1. Accepted means queued

    The API only answers once the mail is safely in the queue. Otherwise you get a 503, and your application knows.

  2. Encrypted credentials

    SMTP passwords are stored AES-256-GCM encrypted, API keys only as a SHA-256 hash.

  3. Separate accounts

    Every user only sees their own mail accounts, templates and projects.

  4. Your sender stays yours

    Mail goes out through your own account. Sender address, reputation, SPF and DKIM stay with your provider.

  5. European infrastructure

    Operated by WebXIO on its own infrastructure in Europe, built and shipped through its own GitLab.

  6. We use it ourselves

    The relay sends its own sign-in mails through itself, as well as the contact forms of webxio.at and this site.

Under the hood

Europe

A lean stack of proven, open building blocks.

API & admin
admin.smtp.webxio.at
Backend
NestJS · PostgreSQL
Queue
BullMQ · Valkey
Delivery
Nodemailer · SMTP
Admin UI
Vue · German & English
Location
Europe, self-hosted

05FAQ

What it is, and what it isn't.

Straight answers to the most common questions.

Is SMTP-Relay an SMTP server?

No. There is no port for mail clients to connect to. Your application talks to an HTTPS API, and the relay then sends through an SMTP account.

Do I need my own mail account?

Yes, mail is sent through an SMTP account, such as Microsoft 365, Google Workspace or your host's. If you don't have one yet, choose “advice wanted” in the form.

Does the relay handle SPF, DKIM and DMARC?

Not yet. Those records belong to your domain and your mail provider, which signs the mail. DKIM support in the relay is planned.

Are there attachments, webhooks or bounce handling?

Not yet. All three are planned, as are open and click tracking. Until then, look up the delivery status with GET /api/v1/messages/:id.

Is there an SDK?

It's not needed: one HTTP request does it, from any language. The admin UI shows a ready-made curl call for every project.

How much can I send?

60 mails per minute per project by default, at most 100. Your mail provider's limits apply too: Microsoft 365, for example, allows 30 per minute.

Is it suitable for newsletters?

No. Without unsubscribe links and bounce handling, the relay is meant for transactional mail: confirmations, notifications, contact forms.

How do I get access?

Through the form below. Accounts are created by a person, there is no self sign-up. Then you set up your mail account, templates and project in the admin UI, together with us if you like.

06Access

Request access.

Accounts are set up by a person, not a machine. Tell us briefly what you need the relay for.

What happens next

  1. You briefly describe your application and your mail account.
  2. We get back to you and clarify scope and setup.
  3. You get access to the admin UI and set up mail account, templates and API key, together with us if you like.

Optional, e.g. https://example.com

Your mail is sent through this account.

Which application, which mails? At least 10 characters.