Email APIs with EU data residency: the 2026 comparison
A 2026 comparison of email APIs with EU data residency: what SendGrid, Mailgun, Postmark, Resend, and Nuntly keep in Europe at rest, verified from primary sources.
Every transactional email your application sends carries personal data: a recipient address, a subject line, and a trail of delivery events with timestamps and IP addresses. If you need an email API with EU data residency, the real question is where all of that lives at rest. The answer varies far more between providers than their marketing pages suggest.
This comparison checks what SendGrid, Mailgun, Postmark, and Resend actually offer for EU data residency, verified against each vendor's own documentation on July 16, 2026. Every claim links to a primary source. Nuntly stores all email data in the EU by default on every plan, and this post holds that claim to the same standard.
What EU data residency means for an email API
EU data residency means all personal data your email provider processes on your behalf (recipient addresses, message content, delivery logs, analytics) is stored on infrastructure located in the European Union. Vendor pages blur three distinct concepts, and evaluating a provider means checking each one separately.
Sending region: the location of the servers that hand your message to recipient mail servers. It affects latency and routing, not storage. A provider can send from Ireland and store every log in Virginia.
Data residency: where your data sits at rest. For an email API, that covers message content, recipient addresses, delivery and engagement events, API request logs, and suppression lists.
Legal jurisdiction: which country's laws bind the provider's corporate entity, regardless of server location. This is where the US CLOUD Act enters the picture.
A provider that advertises "EU region" may be describing only the first item. The comparison table below separates all three.
The legal baseline: GDPR, the DPF, and the CLOUD Act
Three legal instruments shape this decision in 2026.
GDPR. Article 28 requires you to use only processors "providing sufficient guarantees" and to sign a data processing agreement (DPA) with them. Articles 44 and following restrict transfers of personal data outside the EEA unless a valid mechanism applies. Article 5(1)(c) requires data minimization: your provider should not retain more personal data than the service needs.
The EU-US Data Privacy Framework (DPF). The DPF adequacy decision is in force as of July 2026, but its history recommends caution. The EU General Court dismissed the first annulment action on September 3, 2025 (Case T-553/23), and an appeal is now pending before the Court of Justice as Case C-703/25 P. On June 29, 2026, the US Supreme Court ruled in Trump v. Slaughter that removal protections for FTC commissioners are unconstitutional, and the privacy group noyb has formally asked the European Commission to withdraw the adequacy decision because the DPF relies on the FTC as an independent enforcer. Both predecessor frameworks, Safe Harbor (2015) and Privacy Shield (2020, Schrems II), were struck down by the EU courts.
The US CLOUD Act. Enacted in 2018, it requires US providers to disclose data under US legal process:
"regardless of whether such communication, record, or other information is located within or outside of the United States" (18 U.S.C. § 2713)
The practical conclusion: storing email data in the EU does not depend on a transfer mechanism whose two predecessors were struck down in court and whose current version is under appeal. Residency is the hedge.
Which email delivery platforms offer EU data residency in 2026?
As of July 2026: Nuntly stores all email data in the EU by default on every plan. SendGrid offers EU data residency as an opt-in feature restricted to its Pro and Premier plans. Mailgun offers an opt-in EU region that keeps message data in Europe while replicating account data globally. Postmark and Resend store email data exclusively in the United States.
| Provider | EU data storage | Default or opt-in | Plan restrictions | What still leaves the EU |
|---|---|---|---|---|
| Nuntly | Yes: content, logs, events, analytics | Default, all plans | None | Nothing in the email path |
| SendGrid | Yes: PII, content, event data | Opt-in (EU subuser + EU endpoint + EU dedicated IP) | Pro and Premier only | Anonymized data, support and engineering access, deletion processing (up to 24h) |
| Mailgun | Partial: message data in EU region | Opt-in, per domain, chosen at creation | None documented | Account information, user accounts, billing, API keys, domain names (replicated globally) |
| Postmark | No | n/a | n/a | Everything (hosted near Chicago and on US cloud infrastructure) |
| Resend | No: EU sending region only | n/a | n/a | Everything at rest |
All rows verified against vendor documentation on July 16, 2026. Sources below.
SendGrid
Twilio SendGrid launched Data Residency for Email in the EU on July 15, 2025. It keeps "email recipients' personally identifiable information (PII), email content, and event data within data centers located in the European Union" (docs), using data centers in Frankfurt, Dublin, and Amsterdam.
It is not the default. You need a Pro or Premier plan, a regionally designated EU subuser, and an EU dedicated IP; sending through a parent or global subuser routes data through the global endpoint and outside the EU. Twilio's own FAQ warns: "If you configure accounts improperly, Twilio might store your data, process your data, or both outside of the EU." Marketing Campaigns, Email Activity, Validation, and Geostats are not supported in the EU environment, and anonymized data still transfers globally. If EU residency without plan gates is a requirement, see the SendGrid EU alternatives page.
Mailgun
Mailgun (a Sinch company) offers an EU region where message data "never leaves the region that it is processed by". You pick the region per domain at creation by using the EU API endpoint (api.eu.mailgun.net); the US endpoint is the default. According to Mailgun's help center, a domain's region cannot be changed later; migrating means deleting and recreating the domain.
The residency is partial by design. The same regions page states that account information, user accounts, billing details, API keys, and domain names are replicated globally, and the Sinch sub-processor list includes US group entities and US support tooling. The EU message stores run on Google Cloud data centers in Germany and Belgium. If your DPO wants the full data footprint in the EU, see the Mailgun EU alternatives page.
Postmark
Postmark has no EU data region. Its GDPR FAQ states it plainly:
"Postmark is a US-based company and we also store our data in the US, including personal data of our customers, and the data we process on behalf of our customers."
The same FAQ answers the question "since you don't have servers in the EU" by pointing to Standard Contractual Clauses in its DPA as the transfer mechanism, not an EU region. Its EU data protection page links to the GDPR, DPA, and sub-processor details, all of which describe US storage. If EU storage is a requirement, see the Postmark EU alternatives page.
Resend
Resend lets you choose an EU sending region (Ireland), which is often mistaken for data residency. Its own documentation is explicit:
"Region selection controls where your emails are routed and sent from. It does not control where customer data is stored."
The same page states: "All account data, including email metadata, logs, and API records, is stored in the United States regardless of the sending region you select." Resend's GDPR page confirms US storage with SCCs as the transfer mechanism, and its sub-processor list is entirely US-based, including Svix for webhook delivery and Vercel for hosting. For a full comparison, see Resend EU alternatives.
Choosing a SendGrid European alternative
The query "SendGrid European alternative" usually means one of two things: SendGrid's EU residency does not fit your plan or budget, or an opt-in residency model feels too fragile to bet compliance on. Before you switch, check four things on any candidate:
- Residency scope: does EU storage cover content, events, API logs, and suppression lists, or only some of them?
- Default vs opt-in: an opt-in model means one misconfigured subuser or endpoint silently moves data out of the EU. A default model removes that failure mode.
- Plan gating: SendGrid's EU residency requires Pro (from $89.95/month). On Nuntly, EU residency is included on the free plan.
- Sub-processor list: read who touches the data and where they are incorporated, not just where servers sit.
Nuntly covers the full scope by default on all plans, with pricing published up to 1.5M emails per month. The SendGrid comparison breaks down the feature-by-feature differences.
How to verify a residency claim from primary sources
All four checks above can be run from public pages, without a sales call. Three page types answer them for any provider: the region or data residency page in the vendor documentation (what is stored where, and what is excluded), the DPA (the transfer mechanism and its scope), and the sub-processor list (who else touches the data and where they are incorporated). Every row in the comparison table above was built from exactly those three page types. If a vendor's residency claim cannot be verified from its own public documentation, treat that as an answer in itself.
Email API for Germany: passwordless logins and strict DPOs
The short version: a passwordless login flow in Germany needs an email API that stores the authentication trail in the EU and delivers fast enough for a live login. Nuntly does both by default on every plan. SendGrid needs a Pro or Premier plan plus correct EU configuration. Mailgun's EU region covers message data only. Postmark and Resend store the trail in the US.
Germany is the strictest market for this decision. The German data protection authorities (DSK) accepted the DPF in their September 2023 application notes while spelling out exporter duties, and one state authority publicly dissented. In practice, many German DPOs and procurement teams simply require EU processing by policy, because it ends the transfer analysis instead of arguing it. France's CNIL takes the same structural position: the DPF only covers transfers to certified US entities; everything else still needs safeguards.
Passwordless login is where this bites hardest. Magic links and OTP emails are both time-critical and PII-dense: the email address, the login timestamp, and the delivery trail together document a person's authentication history. Sending them through a US-stored provider means that history accumulates outside the EU. Two requirements follow: EU residency for the event trail, and low latency so the login email arrives while the user is still watching the inbox.
import { Nuntly } from '@nuntly/sdk';const nuntly = new Nuntly({ apiKey: process.env.NUNTLY_API_KEY });// Reuse the login attempt id as the idempotency key: if the auth flow// retries the call, the API deduplicates instead of sending a second linkconst { id, status } = await nuntly.emails.send({from: 'login@yourapp.de',to: user.email,subject: 'Your sign-in link',html: `<p><a href="${magicLink}">Sign in to YourApp</a>. The link expires in 10 minutes.</p>`,},{ idempotencyKey: loginAttempt.id },);
The retry-safe pattern in this snippet is covered in depth in idempotency keys for email APIs. If your auth stack is Better Auth, the Better Email plugin routes magic links, OTP codes, and verification emails through one provider interface, so the residency decision is made once for all auth email types.
Mailgun alternative Deutschland: check the residency scope
The same logic applies to "Mailgun alternative Deutschland" searches. Mailgun's EU region does store message data in Google Cloud data centers in Germany and Belgium, which satisfies many teams. If your DPO also wants account data, API keys, and support flows out of global replication, compare the scope in detail: Nuntly vs Mailgun.
How Nuntly implements EU data residency
Nuntly runs its entire email path in the EU: email content, delivery and engagement events, API request logs, webhook delivery logs, and analytics are processed and stored in AWS Europe (Dublin, Ireland), as documented on the public sub-processor list. This applies to every plan, including the free tier (3,000 emails per month, no credit card). There is no residency add-on, no regional subuser to configure, and no endpoint choice that can silently route data elsewhere.
The compliance surface is self-serve: a DPA you can review without contacting sales, a published sub-processor list, a GDPR page, and a data request process for erasure and access requests. Logs are retained for 30 days, long enough to answer "where is the invoice email from last week", short enough to respect storage limitation. Internal operational logs apply data minimization: recipient addresses are redacted before anything is written.
One honest caveat, because it applies to nearly every provider in this comparison: Nuntly runs on US-owned cloud infrastructure in EU regions, as do SendGrid's EU environment and Mailgun's EU region. Full EU residency removes the routine storage and transfer of your recipients' personal data outside the EU, which is the part GDPR Chapter V regulates and the part you can verify. Jurisdiction over the underlying cloud provider is a shared residual across the industry; if your threat model excludes US-owned clouds entirely, your shortlist becomes EU-owned infrastructure providers, with the feature trade-offs that follow.
Everything above is verifiable from the data location feature page and the legal pages linked in this section.
FAQ
Which email delivery platform offers EU data residency?
As of July 2026: Nuntly (default, all plans), SendGrid (opt-in, Pro and Premier plans only), and Mailgun (opt-in per domain, message data only). Postmark and Resend store email data in the United States.
Does Resend store data in the EU?
No. Resend offers an EU sending region, but its documentation states that all account data, email metadata, logs, and API records are stored in the United States regardless of the sending region.
Does Postmark have EU servers?
No. Postmark has no EU data region and stores customer data in the US, with SCCs as the transfer mechanism.
Does SendGrid offer EU data residency?
Yes, since July 2025, as an opt-in feature on Pro and Premier plans. It requires an EU subuser, the EU API endpoint, and an EU dedicated IP. Twilio's own FAQ warns that improper configuration can store or process data outside the EU.
Does Mailgun store email data in the EU?
Partially. Mailgun's opt-in EU region keeps message data in Europe, but account information, billing details, API keys, and domain names are replicated globally. The region is chosen per domain at creation and cannot be changed afterwards.
Is EU data residency required by GDPR?
No. GDPR permits transfers with valid mechanisms (adequacy decisions like the DPF, or SCCs). EU residency is the option that does not depend on those mechanisms surviving court challenges, which both Safe Harbor and Privacy Shield failed to do.
Is an EU sending region enough for GDPR compliance?
A sending region only controls routing. Recipient addresses, delivery events, and logs stored outside the EU remain transfers under GDPR Chapter V and need their own legal basis.
Do I still need a DPA if data stays in the EU?
Yes. Article 28(3) GDPR requires a processing contract with any processor, wherever the data sits. Residency simplifies the transfer analysis, not the processor relationship.
The bottom line
EU data residency for email comes in three tiers in 2026: default and complete (Nuntly), opt-in with plan gates and configuration risk (SendGrid, Mailgun), and unavailable (Postmark, Resend). If your compliance posture depends on where email data lives, pick the tier where residency cannot be misconfigured away.
You can verify the claim in one afternoon: create a free account, send 3,000 emails a month at no cost, and read the DPA and sub-processor list before your DPO asks.
Ship emails, not infrastructure
Free plan available. No credit card required.
Start sending free