UK-Registered Infrastructure Provider — FortisRelay Ltd

Secure, Compliance-First
Messaging Infrastructure

Enterprise transactional email and SMTP relay infrastructure built for regulated industries. Strict anti-spam enforcement, UK GDPR compliance, and dedicated deliverability operations.

99.4%
Delivery Rate
<0.3%
Bounce Rate
100%
Opt-in Traffic Only
UK GDPR Compliant
PECR Adherence
TLS Encrypted Transit
Mandatory KYC Review
Real-time Abuse Monitoring
CAN-SPAM Compliant

Infrastructure Built for Compliance

FortisRelay provides enterprise-grade messaging relay infrastructure. Every account undergoes manual compliance review before activation.

โœ‰

Transactional Email Infrastructure

High-throughput relay infrastructure designed exclusively for system-generated, transactional messages. No bulk or marketing traffic permitted.

๐Ÿ”’

Secure SMTP Relay

Hardened SMTP endpoints with mandatory TLS enforcement, authenticated relay access, and per-client credential isolation.

โšก

Communication API

RESTful API with comprehensive sending, status querying, and webhook delivery. Full audit logging on all API operations.

๐Ÿ›ก

Domain Authentication

SPF, DKIM, and DMARC configuration support. Mandatory domain verification before any sending is permitted on the platform.

๐Ÿ“Š

Delivery Analytics

Real-time delivery dashboards, bounce categorisation, complaint tracking, and exportable compliance reports for audit purposes.

๐Ÿ”„

Enterprise Failover

Multi-region routing with automatic failover, dedicated IP pool management, and priority queue separation for critical message streams.

Our Acceptable Use Policy is Non-Negotiable

FortisRelay operates under strict acceptable use standards. Misuse of our infrastructure results in immediate account suspension.

  • โœ“
    Opt-in communications only

    All recipients must have provided verified, documented consent prior to any message being sent via the FortisRelay platform.

  • โœ“
    Zero tolerance for unsolicited email

    Sending of any unsolicited bulk email, promotional mass mailings, or harvested recipient lists is strictly prohibited and will result in permanent suspension.

  • โœ“
    Manual compliance review

    Every new account application undergoes a manual review by our compliance team before any sending access is granted.

  • โœ“
    KYC identity verification required

    All clients must complete KYC verification including business registration documents and authorised signatory identification.

  • โœ“
    Automated abuse detection

    Our systems continuously monitor complaint rates, bounce patterns, and sending behaviour. Anomalies trigger automatic throttling and compliance review.

  • โœ“
    UK GDPR & PECR compliant operations

    Our infrastructure and operational procedures are designed to support our clients' obligations under UK GDPR and the Privacy and Electronic Communications Regulations.

Compliance-First from Day One

FortisRelay does not offer self-serve account creation. All clients are onboarded through a structured compliance process.

1

Application Review

Submit your account application including business registration details and intended use case.

2

KYC Verification

Our compliance team conducts identity and business verification in accordance with our KYC procedures.

3

Domain Authentication

Configure SPF, DKIM, and DMARC records. Verification is required before any sending access is granted.

4

Account Activation

Upon successful review, your account is activated with monitored sending access and ongoing compliance oversight.

Built on Infrastructure Integrity

FortisRelay Ltd is a London-registered communication infrastructure provider, incorporated in 2021 with a single mandate: deliver secure, compliance-first messaging infrastructure to organisations that cannot afford operational or reputational risk.

Infrastructure You Can Trust with Regulated Data

We exist to serve organisations for whom messaging infrastructure is a critical operational dependency, not a commodity. FortisRelay was founded by infrastructure and compliance professionals who identified a significant gap in the market: the majority of email relay providers were either consumer-grade services dressed in enterprise clothing, or deeply complex self-hosted solutions with no compliance guidance.

FortisRelay bridges this gap. We operate dedicated, isolated infrastructure with a compliance team that genuinely understands UK GDPR, PECR, and the deliverability consequences of poor sending practices.

We serve SaaS platforms, financial services firms, regulated healthcare applications, and enterprise software vendors across the United Kingdom and Europe. Every client relationship begins with a rigorous compliance and identity review.


2021
Founded in London
EU+UK
Regional Coverage
2021 โ€” Founding

FortisRelay Ltd Incorporated

Incorporated at Companies House, London. Initial infrastructure provisioned with a dedicated compliance framework.

2022 โ€” Platform Launch

Production Platform Goes Live

First client cohort onboarded through structured KYC review. SMTP relay and API v1 released.

2023 โ€” Compliance Expansion

GDPR & PECR Framework Formalised

Full UK GDPR data processing agreements and PECR compliance documentation made available to all clients. DPA register established.

2024 โ€” Infrastructure Scaling

Dedicated IP Pool Expansion

IP infrastructure expanded to support dedicated sending pools for enterprise clients. Multi-region routing launched.

2025 โ€” API v2

Enhanced API & Dashboard Release

API v2 launched with full audit logging, real-time delivery webhooks, and enhanced compliance reporting.

Senior Management

Our leadership team brings extensive experience in infrastructure operations, compliance, and enterprise software.

JH

James Hartley

Chief Executive Officer

Infrastructure and cloud services specialist with prior experience at UK-based hosting and network providers. Oversees strategic direction and client relationships.

SC

Sarah Calloway

Chief Compliance Officer

Data protection and regulatory compliance specialist. Responsible for UK GDPR, PECR, and internal risk assessment procedures. Qualified CIPP/E.

RO

Ravi O'Brien

Chief Technology Officer

Systems architect with deep expertise in high-availability mail infrastructure, DNS, and large-scale delivery operations. Leads all technical platform development.

Company Information

Registered Details

Legal NameFortisRelay Ltd
Company Number14271835
VAT NumberGB 412 8830 51
JurisdictionEngland and Wales
Incorporated11 March 2021

Registered Office

FortisRelay Ltd
4th Floor, 86 โ€“ 90 Paul Street
London
EC2A 4NE
United Kingdom


Phone+44 (0)20 3951 4780

Platform Capabilities

A complete set of infrastructure services for organisations that require reliable, compliant transactional messaging.

โœ‰

Transactional Email Infrastructure

Purpose-built relay infrastructure for system-generated transactional messages. Account confirmations, password resets, order notifications, and security alerts. No promotional or bulk traffic permitted on shared infrastructure.

  • โœ“High-throughput queue management
  • โœ“Priority message classification
  • โœ“Per-stream sending configuration
  • โœ“Real-time delivery event callbacks
๐Ÿ”’

Secure SMTP Relay

Hardened SMTP relay endpoints with mandatory TLS enforcement. Per-client credential isolation, IP allowlisting, and SMTP AUTH requirement. Compatible with all major programming languages and mail libraries.

  • โœ“STARTTLS and SMTPS (port 465/587)
  • โœ“SMTP AUTH PLAIN / LOGIN / XOAUTH2
  • โœ“IP allowlist enforcement
  • โœ“Per-credential sending limits
โšก

Communication API (v2)

RESTful JSON API for programmatic message dispatch, status querying, and operational management. Full audit trail on all API operations. Supports webhook delivery for real-time event processing.

  • โœ“Synchronous and asynchronous sending modes
  • โœ“Delivery status webhooks
  • โœ“Batch message submission
  • โœ“Full audit log API access
๐Ÿ›ก

Domain Authentication Support

Comprehensive guidance and tooling for SPF, DKIM, and DMARC configuration. Domain authentication is mandatory for all sending on the FortisRelay platform. Unauthenticated domains cannot be activated.

  • โœ“SPF record generation and validation
  • โœ“DKIM key management and rotation
  • โœ“DMARC policy configuration guidance
  • โœ“MX and reverse DNS verification
๐Ÿ“Š

Delivery Analytics & Reporting

Comprehensive reporting infrastructure for delivery performance, bounce analysis, and complaint monitoring. All data retained in accordance with UK GDPR data minimisation principles.

  • โœ“Real-time delivery dashboards
  • โœ“Bounce categorisation (hard/soft)
  • โœ“Complaint rate monitoring
  • โœ“Exportable compliance reports
๐Ÿ”„

Suppression List Management

Automatic and manual suppression list management. Unsubscribe, bounce, and complaint events are automatically processed and suppressed. Cross-client bounce data is isolated and never shared between accounts.

  • โœ“Automatic bounce suppression
  • โœ“Complaint feedback loop processing
  • โœ“Manual suppression list API
  • โœ“GDPR deletion request support

Sectors We Serve

FortisRelay serves regulated and compliance-sensitive industries across the UK and Europe where messaging infrastructure must meet exacting standards.

Banking, Fintech & Insurance

FCA-regulated firms and financial technology platforms require messaging infrastructure that meets FCA operational resilience expectations and supports audit trail requirements. FortisRelay provides dedicated IP allocation, full audit logging, and data processing agreements suitable for financial services compliance teams.

Common use cases: Trade confirmations, KYC verification messages, account alerts, two-factor authentication, statement delivery, fraud notifications.

Enterprise & Mid-Market Software

Software platforms with high transactional message volumes require reliable infrastructure with predictable deliverability. FortisRelay's dedicated sending pools and priority queue management ensure time-critical transactional messages are not affected by shared infrastructure congestion.

Common use cases: Account creation, password reset, in-app notifications, billing alerts, user invitations, system status updates.

Digital Health & Medical Services

Healthcare applications operating under UK GDPR and NHS data standards require infrastructure providers who can enter into appropriate data processing agreements and demonstrate compliance with data protection obligations. FortisRelay supports DPA signing and data residency considerations.

Common use cases: Appointment reminders, prescription notifications, patient portal credentials, care coordination messages.

Law Firms & Regulated Advisers

Law firms and regulated professional services organisations require infrastructure with clear data lineage, confidentiality assurances, and compliance support. FortisRelay's isolated client infrastructure and full audit logging meets the expectations of legal sector compliance teams.

Common use cases: Client portal access, document notifications, secure message delivery, time-sensitive legal correspondence.

Online Retail & Marketplace Platforms

Retail platforms with significant order volumes require high-throughput transactional infrastructure with strong bounce management and ISP relationships. Only transactional order and account messaging is permitted; promotional mailings require separate compliant platforms.

Common use cases: Order confirmations, despatch notifications, returns processing, account verification.

Local Authorities & Public Bodies

Public sector bodies require infrastructure that supports their obligations under UK GDPR as data controllers and the Government Functional Standard GovS 007. FortisRelay can provide infrastructure documentation suitable for procurement and security accreditation processes.

Common use cases: Service notifications, appointment confirmations, document issuance, citizen portal communications.

Transparent, Volume-Based Pricing

All plans include mandatory compliance review and onboarding. No self-serve account creation. Access is granted following successful KYC verification.

โ„น All prices exclude VAT. UK VAT at the prevailing rate will be applied to invoices for UK-registered clients. Annual commitment discounts are available upon request from our sales team.
Professional

For growing SaaS platforms and development teams.

ยฃ89
per month + ยฃ0.42 per 1,000 messages
  • โœ“ Up to 500,000 messages/month
  • โœ“ 3 verified sending domains
  • โœ“ Shared IP pool (compliance-screened)
  • โœ“ SMTP + API access
  • โœ“ Delivery & bounce analytics
  • โœ“ Email support (1 business day)
  • โœ“ Standard KYC onboarding
  • โ€” Dedicated IP allocation
  • โ€” Dedicated account manager
Request Access
Enterprise

For regulated enterprises with custom volume and compliance requirements.

Custom
volume-based pricing, billed monthly or annually
  • โœ“ Unlimited message volume
  • โœ“ Unlimited sending domains
  • โœ“ Dedicated IP allocation (custom pool)
  • โœ“ Full API access + custom integration support
  • โœ“ Advanced compliance reporting
  • โœ“ 1-hour SLA, named support contacts
  • โœ“ Full KYC & legal onboarding
  • โœ“ Data Processing Agreement
  • โœ“ Dedicated account manager
Contact Sales

All plans include:

โœ“Manual compliance review
โœ“KYC identity verification
โœ“TLS encryption in transit
โœ“Abuse monitoring
โœ“Suppression list management
โœ“SPF/DKIM/DMARC support
โœ“UK GDPR data handling
โœ“99.9% uptime SLA

Developer Reference

Technical documentation for FortisRelay's SMTP relay and REST API. All integrations require an approved account.

Getting Started with FortisRelay

โš  FortisRelay does not support self-serve account registration. All accounts are provisioned following a successful compliance review. Contact sales@fortisrelay.co.uk to begin the onboarding process.

FortisRelay provides two integration methods: a standards-compliant SMTP relay endpoint and a RESTful JSON API. Both methods require an approved account with verified sending domains.

Prerequisites

Before you can begin sending via FortisRelay, the following requirements must be satisfied:

  • Completed KYC identity and business verification
  • At least one sending domain verified with SPF and DKIM records
  • DMARC policy published on your sending domain (p=none minimum)
  • Signed FortisRelay Acceptable Use Policy and Data Processing Agreement

Authentication

All API requests are authenticated using an API key passed in the Authorization header as a Bearer token.

POST /v2/messages Host: api.fortisrelay.co.uk Authorization: Bearer fr_live_xxxxxxxxxxxxxxxxxxxx Content-Type: application/json { "from": "noreply@yourdomain.co.uk", "to": ["recipient@example.com"], "subject": "Your account confirmation", "html": "<p>Thank you for registering.</p>", "text": "Thank you for registering." }

API Response

Successful submissions return a 202 Accepted response with a message ID for status tracking.

{ "id": "msg_01j8x4vr2k000000abcdef12", "status": "queued", "queued_at": "2025-11-14T09:32:11Z" }

SMTP Configuration

ParameterValue
Hostsmtp.fortisrelay.co.uk
Port587 (STARTTLS) or 465 (SMTPS)
AuthenticationRequired (SMTP AUTH)
UsernameYour API key (fr_live_...)
PasswordYour account password
EncryptionTLS required โ€” plaintext connections are rejected

Message Parameters

ParameterTypeRequiredDescription
fromstringYesVerified sender address
toarrayYesRecipient addresses (max 50)
subjectstringYesMessage subject line
htmlstringNo*HTML body content
textstringNo*Plain text body content
reply_tostringNoReply-To address
tagsarrayNoMessage classification tags

* At least one of html or text is required.

Security by Design

FortisRelay's infrastructure and operational procedures are designed around security and compliance as foundational requirements, not optional features.

Technical Security Controls

TLS Encryption in Transit

All data transmitted to and from FortisRelay infrastructure is encrypted using TLS 1.2 or TLS 1.3. Plaintext connections are refused at the protocol level. SMTP relay endpoints enforce STARTTLS; port 25 (unencrypted) is disabled.

Dedicated Infrastructure Isolation

Enterprise and Business plan clients are allocated dedicated sending infrastructure. Client sending queues, credentials, and data are fully isolated. Shared resources are segmented at the application and network level.

Mandatory Domain Authentication

SPF, DKIM, and DMARC are mandatory requirements before any sending domain may be activated. Unauthenticated domains are blocked at the platform level. DKIM signatures use 2048-bit RSA keys minimum.

IP Reputation Management

Dedicated IP pools are managed by our deliverability operations team. Reputation is monitored across major blocklist databases in real time. IP pools are pre-warmed before client activation and monitored continuously.

Real-time Abuse Monitoring

Automated systems continuously monitor complaint rates, bounce rates, sending velocity anomalies, and content patterns. Thresholds that indicate potential abuse trigger automatic rate throttling and internal review escalation.

Access Control & Credential Security

API keys and SMTP credentials are scoped and rotatable. All authentication events are audit logged. Administrative access to infrastructure requires multi-factor authentication and is restricted to authorised personnel.

Compliance Framework

UK GDPR

FortisRelay operates as a Data Processor under Article 28 UK GDPR when processing personal data on behalf of clients. Data Processing Agreements are available for all plan tiers. We maintain a Record of Processing Activities and conduct Data Protection Impact Assessments for high-risk processing activities.

PECR โ€” Privacy and Electronic Communications Regulations

FortisRelay's platform is designed exclusively for transactional messaging to recipients who have provided explicit opt-in consent or have a legitimate interest under applicable regulations. Our Acceptable Use Policy prohibits all unsolicited electronic communications.

CAN-SPAM Act Compliance

For clients sending to US-based recipients, our platform enforces CAN-SPAM compliant header requirements. Clients are required to ensure their transactional messages comply with applicable laws in all destination jurisdictions.

Compliance-First Onboarding

Every client account undergoes a structured onboarding process that includes business identity verification, review of intended use case, assessment of sending infrastructure, and sign-off by our compliance team. No account is activated without this review.

Internal Risk Assessment

Our compliance team conducts periodic internal risk assessments of client sending patterns. Accounts exhibiting risk indicators โ€” such as elevated complaint rates, unusual geographic patterns, or volume anomalies โ€” are reviewed and may be suspended pending investigation.

Immediate Suspension Policy

Accounts found to be in breach of the Acceptable Use Policy are suspended immediately and without prior notice. FortisRelay reserves the right to retain evidence of policy violations for reporting to relevant authorities where applicable.

Get in Touch

Our team typically responds within one business day. All access requests are subject to compliance review.

Send Us a Message

โ„น This is a demonstration form. In production, submissions would be processed by our sales and compliance team.
By submitting this form you agree to our Privacy Policy. Personal data submitted will be processed in accordance with UK GDPR.

Contact Details

General Enquiries

hello@fortisrelay.co.uk

Technical Support

support@fortisrelay.co.uk

Available to active clients. 1 business day response on Professional; 4-hour SLA on Business and Enterprise.

Sales

sales@fortisrelay.co.uk

For new account requests, pricing discussions, and enterprise enquiries.

Compliance & Legal

compliance@fortisrelay.co.uk

For GDPR data subject requests, DPA enquiries, and abuse reports.

Registered Office

FortisRelay Ltd
4th Floor, 86 โ€“ 90 Paul Street
London, EC2A 4NE
United Kingdom

+44 (0)20 3951 4780

FortisRelay Ltd ยท Company No. 14271835 ยท Privacy Policy

Overview

Acme Corp Ltd  ยท  Last 30 days  ยท  Updated: 20 Feb 2026, 09:41 UTC

Operational
Delivery Rate
99.4%
โ†‘ +0.1% vs previous period
Bounce Rate
0.3%
โ†“ โˆ’0.05% vs previous period
Complaint Rate
0.01%
โ†“ Within threshold
Messages Processed
284,761
โ†‘ +12,440 vs previous period

API Usage โ€” Messages Sent (Last 14 Days)

Compliance Health Score

97
/ 100 โ€” Excellent
Delivery Rateโœ“
Bounce Rateโœ“
Complaint Rateโœ“
Domain Authโœ“
Suppression Listโœ“

Authenticated Sending Domains

  • mail.acmecorp.co.uk
    SPF DKIM DMARC Active
  • transact.acmecorp.co.uk
    SPF DKIM DMARC Review
  • noreply.acmecorp.io
    SPF DKIM DMARC Active

Dedicated IP Pool โ€” Reputation

185.92.144.201
Primary Pool ยท Score: 98/100
Clean
185.92.144.202
Primary Pool ยท Score: 97/100
Clean
Monitored across MXToolbox, Spamhaus, Barracuda, SORBS. Last checked: 2 minutes ago.

Recent Activity Log

  • 09:41Delivered284,761 messages processed โ€” monthly total updated
  • 09:12APIAPI key fr_live_...a9f2 authenticated โ€” 1,240 messages submitted
  • 08:55DomainDKIM signature verified for mail.acmecorp.co.uk
  • 08:30ReviewDMARC policy on transact.acmecorp.co.uk is p=none โ€” recommend upgrading to p=quarantine
  • 07:14Bounce14 hard bounces auto-suppressed โ€” list updated
  • 06:00SystemScheduled IP reputation check completed โ€” all IPs clean
  • YesterdayComplianceMonthly compliance report generated โ€” available for download