Email Marketing & Newsletter
Mailingwork
EU-Made Report an errorPanel rating · 6 judges · How to read the stars
Category median
Sovereignty: 2 of 4 dimensions proven
0–5 in half steps. 5 means the rubric's top anchor is met on the evidence.
by mailingwork GmbH · www.mailingwork.de
Report an error on this page Is this your product? →
Read this page as one judge. Each weighs the same scores by what they care about.
The panel's verdict
Mailingwork, an email-marketing and newsletter platform from Positive Group Chemnitz GmbH in Chemnitz, drew tight scoring: weighted verdicts run 3.3 to 4.0, five of seven criteria show no spread, and the flagged split check reported none. Sovereignty is the strongest at 6 — a German contracting entity, servers hosted in Germany, and an explicit statement that newsletter recipient data sees no third-country transfer — kept short of the top band because the hosting claim sits in marketing copy and we found no public information on a subprocessor list for the sending chain or a named data-centre provider. Campaign and automation, consent and proof, and integrations each cluster at 4: multi-stage triggered campaigns, double opt-in with proof of consent, an open API with Zapier. Weakest is deliverability at 2: Certified Senders Alliance certification, whitelisting and mailing tests, and we found no public information on SPF, DKIM or DMARC setup. The one spread outside pricing is list data control, scored 2 to 3, weighing a documented sync API against silence on full export and exit. No prices are public.
Speaks for it
- Sovereignty scored 6, the highest mark any criterion received: a German contracting entity (Positive Group Chemnitz GmbH, Chemnitz), servers hosted in Germany, and a stated no-third-country-transfer position for newsletter recipient data.
- Double opt-in ships with checkboxes, unsubscribe links and proof of consent, and signup logging stores the IP address plus date and time.
- One- and multi-stage trigger campaigns — welcome series, cart reminders, transactional, birthday and anniversary mailings — are saved as reusable templates across email, SMS and postcard.
- An open API for CRM, CMS and shop systems creates subscribers, sends transactional mail and queries data, with Zapier for other apps.
- An internal data protection officer works with an external data-protection partner, and the vendor holds Certified Senders Alliance certification with whitelisting and mailing tests.
Held against it
- Deliverability scored 2 with no spread: we found no public information on SPF, DKIM or DMARC setup, bounce suppression, dedicated-IP options or warm-up.
- We found no public information on list segmentation, A/B testing or per-campaign revenue attribution; the only testing documented is functional campaign checking before activation.
- List data control scored 2 to 3: deletion after unsubscribe is stated, but we found no public information on full export including engagement history and unsubscribe state, or on a documented exit path.
- We found no public information on whether open and click tracking can be limited or switched off.
- The German hosting claim sits in marketing copy with no data-processing agreement excerpt captured; we found no public information on subprocessors for the sending chain or a named data-centre provider, and the captured pages give different company names for the contracting entity.
Best for
- You need a Germany-hosted email platform under a German contracting entity, with a stated no-third-country-transfer position for newsletter recipient data.
- You run lifecycle marketing — welcome series, cart reminders, transactional mailings — and want trigger-based multi-stage campaigns as a built-in capability.
- You build your own integrations and need a write-capable API surface — subscriber creation, transactional sending, data queries — to work against without a partner agreement.
- You must be able to evidence consent, with double opt-in, proof of consent and IP-plus-timestamp signup logging documented as product capabilities.
Avoid if
- Your deliverability practice depends on documented SPF, DKIM and DMARC setup, bounce suppression and warm-up — the public deliverability material consists of certification, whitelisting and mailing tests, and the criterion scored 2.
- Your optimisation loop needs segmentation and A/B testing with significance reporting — the only campaign testing documented is functional checking before activation.
- Your list must eventually leave with its engagement history and unsubscribe state — ask the vendor: the public pages we read do not show it
The scores
Campaigns & automation
Show reasoningHide reasoning
How this is scored
Building the mail and the journey around it: editor, templates, segmentation, triggered sequences, A/B testing.
0 — One-off broadcasts from a fixed template; no segmentation and no automation of any kind.
3 — A drag-and-drop editor and simple list segmentation, but automation is a single welcome mail and there is no testing.
5 — Reusable templates, attribute and behaviour segmentation, multi-step automations on common triggers, and subject-line A/B testing.
8 — A visual journey builder with branching on behaviour and data, dynamic content per segment, send-time optimisation, and testing that reports significance rather than raw counts.
10 — Journeys treat the whole lifecycle: event-driven entry from other systems, branching on any attribute or event, holdout groups for measurement, and automations a marketer can read months later without a diagram.
The CRM Manager
The campaign manager builds one- and multi-stage triggered series — welcome, cart reminder, birthday, transactional — saved as reusable templates with email, SMS and postcard building blocks. But we found no public information on segmentation by behaviour or attributes, and the only testing documented is functional campaign testing before activation, not A/B tests that report significance. 5 1
The Deliverability Engineer
Multi-stage automated campaigns are documented on named triggers — welcome series, cart reminders, transactional mailings, birthday and anniversary mailings — with reusable templates and personalization. I found no public information on A/B testing, journey branching or send-time optimisation, which keeps it below the mid anchor. 1 5
The Data Protection Officer
Multi-stage trigger-based campaigns are documented — welcome series, cart reminders, birthday and transactional mailings — with reusable templates and channel choice across email, SMS and postcard. The testing evidenced is functional checking of a campaign before activation rather than split testing, and we found no public information on visual journey branching, dynamic content per segment or significance reporting. 5 1
The Shop Owner
The campaign manager runs multi-step, trigger-based series, and the named campaign types — welcome series, abandoned-cart reminders, transactional mailings and product recommendations — map straight onto a shop's lifecycle. I found no public information on segmentation, subject-line A/B testing, or reporting that attributes revenue per campaign, so the journey machinery is evidenced but not the measurement. 1 5
The Integrator
The campaign manager builds one- and multi-stage automated series on triggers — welcome series, cart reminders, transactional mailings, birthday and anniversary mailings — with campaigns reusable as templates and pausable for testing. Personalization is marketed, but we found no public information on list segmentation or A/B testing, so the automation depth sits well above a single welcome mail without covering the full mid-level bundle. 1 5
The Skeptic
Triggered multi-step campaigns are real — welcome series, cart reminders, birthday and transactional mailings, saved as reusable templates — but the captured pages are silent on segmentation, and the only testing described is checking a campaign runs correctly, not split testing. Two of the four things a working automation stack needs to show are simply not evidenced. 5 1
Deliverability infrastructure
Show reasoningHide reasoning
How this is scored
Whether the mail arrives — authentication, sending reputation, bounce and complaint handling — judged on what the vendor documents rather than the inbox rate it advertises.
0 — No documentation of authentication or bounce handling; deliverability appears only as a marketing number.
3 — SPF and DKIM setup documented, but no DMARC guidance, no stated bounce policy and shared sending only.
5 — SPF, DKIM and DMARC documented with a custom sending domain, automatic hard-bounce suppression, and complaint-loop handling stated.
8 — The above plus dedicated-IP options with a documented warm-up, seed or inbox-placement testing, engagement-based sunsetting, and published guidance on list hygiene.
10 — Deliverability is operated as a service: reputation monitoring surfaced to the customer, per-domain and per-ISP diagnostics, enforced authentication before first send, and postmaster or blocklist handling the vendor documents doing on the customer's behalf.
The CRM Manager
Deliverability support appears as Certified Senders Alliance certification, whitelisting and mailing tests, which is a genuine German-market credential. We found no public information on SPF, DKIM or DMARC setup, bounce and complaint handling, or sending-domain and dedicated-IP options, so the case rests on the certification in marketing copy. 4
The Deliverability Engineer
Certified Senders Alliance certification, whitelisting and mailing tests are documented, and a third-party sender certification is more than a marketing number. But I found no public information on SPF, DKIM or DMARC setup, no stated bounce policy, and no dedicated-IP or warm-up documentation — the authentication story is not on the page. 4
The Data Protection Officer
The security page presents Certified Senders Alliance certification, whitelisting and mailing tests as trust signals, which is more than an inbox-rate number but is still a trust claim. We found no public information on SPF, DKIM or DMARC setup, bounce suppression policy, dedicated sending addresses or warm-up guidance. 4
The Shop Owner
Certified Senders Alliance certification together with whitelisting and mailing tests is a real, externally audited credential rather than an inbox-rate promise. I found no public documentation of SPF, DKIM or DMARC setup, no bounce policy and no dedicated-IP or warm-up guidance, so the mechanics behind the certification stay invisible to a buyer. 4
The Integrator
Deliverability rests on a Certified Senders Alliance certification, whitelisting and mailing tests — a third-party signal, but thinner than documentation of the mechanics. We found no public information on SPF, DKIM or DMARC setup, bounce suppression, dedicated-IP options or warm-up; the certification is asserted rather than documented. 4
The Skeptic
Deliverability appears as trust-page copy — CSA certification, whitelisting, "Mailingtests" — with no documented SPF, DKIM or DMARC setup, no stated bounce policy and no custom-domain or dedicated-IP guidance; the CSA badge is the one externally checkable item. Everything else is a claim about trustworthiness, not a setup or hygiene guide a sender can verify. 4
Consent, proof & tracking limits
Show reasoningHide reasoning
How this is scored
How subscribers arrive and what the sender can prove afterwards: double opt-in, logged consent, unsubscribe handling, and whether open and click tracking can be limited or switched off.
0 — Single opt-in with no consent record; tracking is always on and cannot be disabled.
3 — Double opt-in available but not the default, and the consent record is a timestamp without the source, IP or the wording consented to.
5 — Double opt-in as the documented default with a stored consent record including source and timestamp, one-click unsubscribe, and tracking that can be turned off per campaign.
8 — Consent is reproducible as evidence: the confirmation mail and form wording versioned and retrievable per subscriber, unsubscribe honoured across lists, tracking off-by-default available, and retention rules for inactive subscribers.
10 — Built for the burden of proof: a per-subscriber consent history an authority would accept, documented handling of Art. 15 access and Art. 17 erasure requests, pixel-free and link-tracking-free sending as a supported mode, and preference-centre granularity rather than all-or-nothing.
The CRM Manager
Double opt-in is presented as the standard with checkboxes, unsubscribe links and proof of consent, and signup logs the IP address with date and time of registration. We found no public information on whether open and click tracking can be turned off, on one-click unsubscribe, or on consent records versioned with the exact wording shown to the subscriber. 4 3
The Deliverability Engineer
Double opt-in is documented with an explicit claim of proof of consent, plus checkboxes and unsubscribe links. I found no public information on whether double opt-in is the default, what the stored consent record contains, one-click unsubscribe handling, or whether open and click tracking can be limited or switched off. 3 4
The Data Protection Officer
The vendor states double opt-in with checkboxes, unsubscribe links and proof of consent ("Nachweis der Einwilligung"), and the privacy policy shows IP address and timestamp logged at signup — a record with more than a bare timestamp. However, we found no public information on whether open and click tracking can be limited or switched off per campaign or by default, nor on versioned consent wording or handling of access and erasure requests. 4 3
The Shop Owner
Double opt-in with proof of consent, checkboxes and unsubscribe links is documented as a product capability, and the signup logging stores IP address plus date and time — more than a bare timestamp. I found no public information on tracking being switchable off per campaign, versioned form wording, or preference-centre granularity. 3 4
The Integrator
Double opt-in ships with checkboxes, unsubscribe links and explicit consent proof, and the privacy policy logs IP address plus date and time at signup — more than a bare timestamp. We found no public information on whether open and click tracking can be limited or switched off, on preference-centre granularity, or on retention rules for inactive subscribers. 3 4
The Skeptic
Double opt-in with proof of consent, checkboxes and unsubscribe links is stated, and their own newsletter signup logs IP address and timestamp — but we found no public information on whether double opt-in is the default, what the stored consent record contains, or whether open and click tracking can be limited or switched off. Tracking limits are the buyer's real exposure here, and the pages say nothing about them. 4 3
List ownership, import & exit
Show reasoningHide reasoning
How this is scored
Whether the list and its history remain the sender's: import with attributes intact, full export including engagement history, deletion that executes, and no metering that prices leaving out of reach.
0 — Export is addresses only; engagement history, segments and automations cannot leave.
3 — CSV import and export of subscriber fields, but engagement history and unsubscribe state are not exportable.
5 — Full subscriber export including custom attributes, subscription status and unsubscribe state, plus API access sufficient to sync elsewhere.
8 — Everything exportable in open formats — subscribers, engagement history, campaigns and templates — with documented deletion of a subscriber across all records, and no export throttling.
10 — Exit is a documented feature: full-fidelity export of the whole account, contractual data return, deletion that is evidenced rather than asserted, and migration tooling in both directions.
The CRM Manager
The open API creates subscribers, sends transactional mail and queries data, so the list is reachable programmatically in both directions, and the privacy policy states subscriber data is deleted from both parties' servers after unsubscribe. We found no public information on full export including engagement history, on import with custom attributes intact, or on documented deletion of a subscriber across all records on request. 5 3
The Deliverability Engineer
The open API is documented to create subscribers, query data and send transactional mail, which shows some two-way data flow. I found no public information on import or export formats, whether engagement history or unsubscribe state can leave, or documented deletion of a subscriber across the product's records. 5
The Data Protection Officer
The API is documented for creating subscribers, sending transactional mail and querying data, which gives a path to sync elsewhere, and the privacy policy states newsletter data is deleted from the vendor's servers upon unsubscribe. We found no public information on export of subscriber fields in open formats, engagement history, unsubscribe state, or full-account export and migration tooling on exit. 5 3
The Shop Owner
The API creates subscribers and queries data, so a two-way sync is plausible, and the privacy policy states subscriber data is deleted from the vendor's servers upon unsubscribe. I found no public information on full export including engagement history and unsubscribe state, or on a documented exit path — for a revenue-critical list that silence matters. 3 5
The Integrator
The API documents querying data, and the privacy policy states subscriber data is deleted from mailingwork's servers after unsubscribe. We found no public information on export formats or fidelity, on engagement history or unsubscribe state leaving the system, or on a documented full-account exit. 3 5
The Skeptic
The API is documented to create subscribers, send transactional mail and query data, which permits some syncing elsewhere; we found no public information on export of custom attributes, subscription and unsubscribe state, engagement history, or documented deletion of a customer's list. Whether the list's history can leave at all is not answered on the captured pages. 5
Integrations & API
Show reasoningHide reasoning
How this is scored
The connection surface a newsletter lives on: shop and CRM systems, events in and out, webhooks, and an API somebody can build against without a partner agreement.
0 — No API and no named integrations; the list is maintained by CSV upload.
3 — A handful of native integrations and a read-mostly API, with no webhooks and no documented rate limits.
5 — Named integrations for common shop and CRM systems, a documented REST API with keys, and webhooks for the core subscriber events.
8 — Maintained bidirectional integrations with named systems including at least one major shop platform, event webhooks with retries, documented rate limits, and a sandbox.
10 — The tool is a component rather than a destination: transactional and marketing sending on one API, events flowing both directions, versioned API with a deprecation policy, and integrations the vendor maintains rather than lists.
The CRM Manager
An open API covers CRM, CMS and shop-system integration plus subscriber creation, transactional sending and data queries, and Zapier links to numerous other apps. The pages name integration categories rather than maintained named systems, and we found no public information on webhooks, documented rate limits or a sandbox. 5
The Deliverability Engineer
An open API for CRM, CMS and shop systems with transactional sending on the same API, plus Zapier as a named connector. The integrations are described as categories rather than named systems, and I found no public information on webhooks, documented rate limits or a sandbox. 5
The Data Protection Officer
An open API for CRM, CMS and shop systems plus a Zapier connection is documented, and the API is write-capable — creating subscribers and sending transactional mail, not merely reading. But we found no public information on named shop or CRM integrations, webhooks, documented rate limits or a sandbox. 5
The Shop Owner
An open API is aimed at CRM, CMS and shop systems, covers creating subscribers, sending transactional mails and querying data, and Zapier bridges to other apps — transactional sending on the same API is the card that matters to me. But no specific shop platform is named, and I found no public information on webhooks, documented rate limits or a sandbox. 5
The Integrator
An open API with stated use cases — creating subscribers, sending transactional mail, querying data — and integration targets named by category for CRM, CMS and shop systems, which is a surface somebody can build against without a partner agreement. Zapier is the connector on offer, which I read as an outsourced integration, and we found no public information on webhooks, rate limits, a sandbox, a versioning or deprecation policy, or a single named integration the vendor maintains. 5
The Skeptic
An "offene API" with listed use cases plus Zapier is a workable surface, and transactional sending on the same API is a genuine plus; but the shop and CRM targets are named only as generic categories rather than systems, and we found no public information on webhooks, rate limits, a sandbox or versioning. Read the API claim as a door, not as a catalogue. 5
European sovereignty
panel opinion
Show reasoningHide reasoning
How this is scored
Where subscriber data and behavioural tracking live, who the contracting entity is, and which subprocessors touch the send. Independently sourced by the sovereignty pipeline; scored here as this buyer weighs it — which in this category is heavily.
0 — US vendor and contracting entity, US hosting, subprocessors unnamed; subscriber behaviour leaves the EU with no stated basis.
3 — EU hosting offered as an option or for storage only, while sending, tracking or support access remains non-EU, or the subprocessor list is absent.
5 — EU hosting as standard and an EU contracting entity, but parts of the chain — sending infrastructure, analytics, support tooling — are non-EU without an explained safeguard.
8 — EU or DACH hosting with a named data-centre provider, EU contracting entity, complete subprocessor list published, and any non-EU processing named with its legal basis.
10 — Sovereign end to end and evidenced: vendor, entity, hosting, sending and every subprocessor in the EU, certification published, and no transfer that needs a Schrems II argument to survive.
The CRM Manager
Contracting entity and controller are the German Positive Group Chemnitz GmbH, servers are hosted in Germany with a stated no third-country transfer of newsletter data, and the vendor is Certified Senders Alliance certified with an internal data protection officer plus an external partner. We found no public information naming the data-centre provider or the service's subprocessors, and the hosting statement sits in marketing copy without a captured processing agreement. 4 3 2
The Deliverability Engineer
German hosting is stated with an explicit no-third-country-transfer position for newsletter data, German register entries, and both an internal DPO and an external data-protection partner. The captured pages give different company names for the contracting entity, the subprocessor picture for the sending chain is unconfirmed, and no data-centre provider is named. 2 3 4
The Data Protection Officer
German contracting entity, German hosting, and an explicit statement that newsletter recipient data is stored in Germany with no transfer to third countries — the answer I want without a Schrems II argument. The residency claim sits in marketing copy with no processing-agreement excerpt captured, we found no public information on a subprocessor list for the product's own sending chain, and ownership is unconfirmed; the subprocessors named in the privacy policy relate to the vendor's own website. 4 3 2
The Shop Owner
German contracting entity, German hosting and an explicit statement that newsletter recipient data sees no third-country transfer, plus an internal data protection officer — solidly European where it counts. The hosting claim sits in marketing copy, the data-centre provider and the product's subprocessor list are not published, and ownership is unstated, so I cannot confirm the whole chain end to end. 2 3 4
The Integrator
The essentials are claimed: a German contracting entity, servers hosted in Germany, and an explicit statement that newsletter data sees no third-country transfer. The hosting claim sits in marketing copy with no data-processing agreement excerpt captured, the data-centre provider is unnamed, and we found no subprocessor list for the sending service itself — the named processors are website tracking tools — which is what keeps this short of the top band. 2 3 4
The Skeptic
German hosting is stated ("Wir hosten unsere Server in Deutschland"), the entity is a German GmbH in Chemnitz, and the privacy policy says newsletter data is stored in Germany with no third-country transfer — but the hosting claim sits in marketing copy with no data-processing agreement captured to confirm it, and we found no public information on a subprocessor list for the sending chain or a named data-centre provider. The tracking pixels on their own site (Meta, LinkedIn, Leadinfo) touch their marketing pages rather than the evidently customer chain; still, the German promise rests on the vendor's own word. 4 3 2
Pricing transparency
not rated — the vendor publishes no price
Show reasoningHide reasoning
How this is scored
Whether a sender can compute the real invoice for their list size and send volume — including overage, extra domains and automation limits — from public pages alone.
0 — No public prices at all; every tier is a sales conversation.
3 — A headline price per contact tier exists, but send limits, overage rates or the tier where automation begins are not stated.
5 — Contact-tier prices public with the billing period stated and send limits given, but at least one commonly needed capability sits in an unpriced tier or add-on.
8 — Every tier priced publicly with contact and volume limits, overage rates, feature boundaries and VAT treatment stated; only genuinely custom volume lacks a number.
10 — Complete price computability: a calculator producing the annual invoice for a given list size and send frequency, including overage, additional domains and dedicated IPs.
The CRM Manager
The only pricing-related content captured is a free demo and a live-demo booking; we found no public prices, contact tiers, send limits or overage rates anywhere on the captured pages. Every tier is a sales conversation, so the real invoice cannot be computed in advance. 1 5
The Deliverability Engineer
The captured pages offer only a free demo and a free consultation; I found no public information on any price, contact tier, send limit or overage rate. As far as public pages show, every tier is a sales conversation. 1 5
The Data Protection Officer
The captured pages offer a free demo, a live demo and a free consultation, and nothing else: we found no public prices, tiers, send limits, overage rates or VAT treatment. Computing an invoice requires a sales conversation. 1 5 4
The Shop Owner
Only a free demo and a free consultation appear on the public pages — I found no public information on prices, contact tiers, send limits or overage rates. For my list size I cannot compute even the first euro of an invoice without a sales conversation. 1 4
The Integrator
The captured pages publish no price figures at all; the way in is a free demo and a free consultation call, with documents sent on request. A buyer cannot compute any part of the invoice from public information. 1 4
The Skeptic
The only pricing-adjacent items on the captured pages are a free demo, a live demo and a free consultation; no tier prices, contact limits, send limits or overage rates are public anywhere captured. Every real invoice here is a conversation with a salesperson, which for a mid-market German vendor is normal — and still not transparent. 1 4 5
European sovereignty — proven facts
2 of 4 dimensions provenBuilt only from facts shown on the vendor's own pages. A dimension we could not prove is left open, not scored as zero.
| Legal entity | Incorporated in DE | 3/3 pts | 2 Report an error |
|---|---|---|---|
| Ownership | Not determined | — | uncited Report an error |
| Data residency | EU only ⚠ unverified | 3/3 pts | 4 Report an error |
| Subprocessors | Not determined ⚠ unverified | — | uncited Report an error |
Where this could be wrong
- Evidence ages. The oldest capture behind this page is from 15 Sep 2026. Vendors change pricing and policies without notice; every fact reflects its source as of the capture date shown in the registry.
- Weak sourcing — Data residency. The EU hosting statement sits in marketing copy on the security page, and no data-processing agreement excerpt was captured to confirm it as the contractual default.
- Weak sourcing — Subprocessors. Not confirmed on the vendor’s own pages as captured.
- AI can misread a source. Extraction and judgement are automated; a citation guarantees traceability, not infallibility. If something here is wrong, say so — no account needed, every report is decided within 5 business days, and accepted corrections are published.
What we left out
A claim that does not survive our checks costs us the claim, not the page. This is what was taken off this one.
- 7 product facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 6 subprocessors facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 1 compliance fact could not be confirmed on the vendor’s page as captured and was left out of this page and of the panel’s material. Know more? Tell us
- 1 legal fact could not be confirmed on the vendor’s page as captured and was left out of this page and of the panel’s material. Know more? Tell us
- 1 sovereignty dimension could not be confirmed on the vendor’s own pages and is shown as unknown. Know more? Tell us
Sources (5)
The pages every claim on this page was read from — each one checked, dated, and kept verifiable.
- 1 Vendor homepage www.mailingwork.de Checked 15 Sep 2026 Details →
- 2 Imprint www.mailingwork.de Checked 15 Sep 2026 Details →
- 3 Privacy policy www.mailingwork.de Checked 15 Sep 2026 Details →
- 4 Security / trust page — found from the homepage mailingwork.de Checked 30 Sep 2026 Details →
- 5 Campaigns & automation — found from sitemap mailingwork.de Checked 30 Sep 2026 Details →