Create a read-only credential
Create the credential in Postmark with the minimum read scope, paste it into devguard, and the connection is live. The integration page in the product spells out the exact permissions.
Read-only checks on Postmark verify the domains your transactional email leaves from: DKIM verified, Return-Path confirmed, and sender signatures in order.
4 read-only checks, run on a schedule. Each failure becomes a finding linked to a control — every check is listed, none are “coming soon”.
Connectivity check: confirms the account token authenticates and lists domains (HTTP 200). A non-200 (e.g. 401 or 422) indicates an invalid or wrong-type token.
account-connectivity
Fails if any Postmark domain does not have DKIM verified. Also fails if no domains are returned, to avoid a vacuous pass. Reads up to 500 domains in one page (the endpoint uses count/offset paging, which the check DSL cannot express).
domains-dkim-verified
Fails if any Postmark domain does not have its custom Return-Path (bounce) domain verified, which is needed for bounce handling and DMARC alignment. Also fails if no domains are returned, to avoid a vacuous pass.
return-path-verified
Fails if any Postmark sender signature (from-address) is not confirmed. Also fails if no sender signatures are returned, to avoid a vacuous pass. Reads up to 500 signatures in one page (count/offset paging, not expressible in the check DSL).
sender-signatures-confirmed
Bring your current platform's test list — we'll map it against these checks, gap by gap
Setup is minutes, not a migration project — and every step stays on your side
Create the credential in Postmark with the minimum read scope, paste it into devguard, and the connection is live. The integration page in the product spells out the exact permissions.
The first run starts right after connecting, then repeats on a schedule. Results are timestamped, so your evidence has a history, not a snapshot.
Passing results attach as evidence to the controls they support; failures become findings you triage. When the audit comes, the proof is already connected.
Open any page for its full check register.
You create and scope every credential yourself, and you can revoke it at any time. Checks only read; results and evidence are stored in Switzerland and stay exportable.
Yes. The checks authenticate with a credential you create and scope yourself, and only ever read configuration. devguard holds no write access to Postmark and remediates nothing silently.
A failed check becomes a finding linked to the control it supports, with the evidence attached. You decide the treatment — nothing pages your engineers and nothing is auto-remediated.
Checks run from Swiss infrastructure, and results and evidence are stored in Switzerland. Everything is exportable — your evidence stays yours.
20 minutes on how you run certification today. Bring your current test or control list and we'll map it against these checks — honestly, gap by gap.