FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. Analytics
  4. Mailgun

Mailgun

AnalyticsWebsite

Related services

34SP.com

34SP.com is a digital analytics solution that helps businesses measure and understand their online performance through comprehensive data collection and analysis. It provides visitor tracking, behavioral insights, and conversion metrics across websites and applications. 34SP.com supports custom event tracking, audience segmentation, and automated reporting. With intuitive dashboards and visualization tools, 34SP.com enables informed decisions that improve experience and drive results.

Analytics
5

51.LA

51.LA is a digital analytics solution that helps businesses measure and understand their online performance through comprehensive data collection and analysis. It provides visitor tracking, behavioral insights, and conversion metrics across websites and applications. 51.LA supports custom event tracking, audience segmentation, and automated reporting. With intuitive dashboards and visualization tools, 51.LA enables informed decisions that improve experience and drive results.

Analytics

52Degrees

52Degrees is an analytics and measurement platform providing deep insights into digital ecosystem performance. It tracks user interactions, measures campaign effectiveness, and identifies optimization opportunities across web and mobile. 52Degrees offers customizable dashboards, automated alerts, and data export capabilities. By transforming raw data into actionable intelligence, 52Degrees empowers organizations to optimize strategy and maximize return on investment.

Analytics
A

a3 Lazy Load

a3 Lazy Load is a comprehensive e-commerce platform that provides businesses with all the tools needed to build, manage, and grow an online store. From product catalog management and secure payment processing to inventory tracking and order fulfillment, a3 Lazy Load delivers a complete commerce solution. It features responsive storefront themes, SEO-optimized product pages, and powerful marketing tools to help merchants increase visibility and drive sales across channels.

Analytics
A

Able CDP

Able CDP is a digital analytics solution that helps businesses measure and understand their online performance through comprehensive data collection and analysis. It provides visitor tracking, behavioral insights, and conversion metrics across websites and applications. Able CDP supports custom event tracking, audience segmentation, and automated reporting. With intuitive dashboards and visualization tools, Able CDP enables informed decisions that improve experience and drive results.

Analytics
A

Abralytics

Abralytics is an analytics and measurement platform providing deep insights into digital ecosystem performance. It tracks user interactions, measures campaign effectiveness, and identifies optimization opportunities across web and mobile. Abralytics offers customizable dashboards, automated alerts, and data export capabilities. By transforming raw data into actionable intelligence, Abralytics empowers organizations to optimize strategy and maximize return on investment.

Analytics
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does Mailgun do?

Mailgun is a transactional and marketing email API platform operated by Sinch Email Inc. (part of the Sinch group, Stockholm). Mailgun does not set cookies on website visitors. Open and click tracking in emails involve identifiers stored on the recipient device when images load, requiring consent for marketing emails.

What Mailgun is and how it sends email

Mailgun is a transactional and marketing email API platform founded in 2010. Today it is operated by Sinch Email Inc., part of the Sinch group based in Stockholm, Sweden. Customers send email by calling the Mailgun API server side or by SMTP relay. The platform also offers inbound routing, list management, address validation and analytics. Mailgun is widely used for password resets, order confirmations, abandoned cart emails and newsletters.

Cookies and identifiers set on recipients

Mailgun does not place any cookie on a website visitor (the platform is an email sender, not a web widget). When the customer enables open tracking, Mailgun adds an invisible 1x1 pixel served from email.mg.mailgun.net to outgoing emails, the recipient browser fetches it when reading the email and Mailgun records the open. When click tracking is enabled, links in the email are rewritten through events.mailgun.net so each click is logged. These tracking mechanisms link an open or a click to a recipient email address, which qualifies as personal data.

GDPR and ePrivacy implications

For transactional emails, Article 6(1)(b) GDPR (performance of a contract) typically covers the message itself. For marketing emails, the legal basis is consent (Article 6(1)(a)) or the soft opt in for existing customers depending on national rules. Open and click tracking implies storing identifiers and reading information from the recipient terminal, so the CNIL and other EU regulators consider it a tracking practice requiring informed consent for marketing campaigns. Transactional tracking can sometimes rely on legitimate interest if the purpose is documented in the privacy notice.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Data transfers and Schrems II

Provision Mailgun in the EU region (api.eu.mailgun.net) to keep email content, recipient addresses and event logs inside the EEA. The US region (mailgun.net) triggers a transfer covered by Standard Contractual Clauses and the EU US Data Privacy Framework. The Sinch parent company is based in Sweden, fully under GDPR. Some support and billing tools include US providers. Document all of this in the record of processing activities.

Practical compliance steps

Provision the project in the EU region. Sign the Mailgun DPA (under Sinch). Document Mailgun in your record of processing activities with region, retention and legal basis per campaign type. Disable open and click tracking for transactional emails when not strictly needed. For marketing emails, collect consent and provide an easy unsubscribe link. Include a privacy notice paragraph that explains the tracking pixel and the unsubscribe mechanism. Implement DSAR flows that can export and delete recipient data from Mailgun via the API.

GDPR consent category

Analytics

Websites using Mailgun must obtain user consent under GDPR regulations.

Legal basisArticle 6(1)(f) GDPR (legitimate interest) or Article 6(1)(a) (consent) for the email content itself depending on the marketing or transactional purpose. Open and click tracking via Mailgun pixels involve identifiers stored on the recipient device when they load images, so they require informed consent for marketing campaigns under ePrivacy and the EDPB guidelines on direct marketing.
Risk levelmedium
Applicable regulationsGDPR, ePrivacy Directive, DSGVO, RGPD, LSSI, CAN SPAM (US recipients), CASL (Canadian recipients), EU US Data Privacy Framework, French CNIL guidelines on email tracking

DPIA considerations

A DPIA is recommended when Mailgun is used for marketing email at scale or to send transactional messages with sensitive content (health, legal, financial). Document the EU region selection, the legal basis for each campaign, the retention period for events and logs (3 to 7 days for content, 30 to 90 days for events depending on plan), the opt out mechanism and the DSAR procedure.

Sample consent text

Our marketing emails are sent through Mailgun. When you open an email, Mailgun loads a small tracking pixel that informs us the email was opened. Links may be wrapped to track clicks. You can disable image loading in your email client to avoid the tracking pixel and unsubscribe at any time using the link at the bottom of each email.

Technical details

Tracking methodTransactional and marketing email API platform. Mailgun is invoked server side to send emails, validate addresses and receive inbound messages. Optionally Mailgun rewrites links in sent emails so that clicks are tracked through events.mailgun.net and adds a 1x1 open pixel from email.mg.mailgun.net. The recipient browser may then load tracking pixels and click trackers when reading the email or following a link, but no Mailgun cookie is set on a website visitor unless the customer site embeds a Mailgun analytics widget.
Server locationSinch Email Inc. (formerly Mailgun Technologies Inc.) operates Mailgun from the United States as part of the Sinch group (headquartered in Stockholm, Sweden). Customers can choose between the US region (mailgun.net, AWS US East 1) and the EU region (api.eu.mailgun.net, AWS EU West 1, Ireland). Both regions handle email content, recipient addresses, open and click events and logs.
Cookieless tracking availableYes

Third-party domains contacted

mailgun.netapi.mailgun.netapi.eu.mailgun.netemail.mg.mailgun.netevents.mailgun.netapp.mailgun.comapp.eu.mailgun.com

Cookies placed

NameTypeDurationPurpose
mg-sessionfirst-party (app.mailgun.com / app.eu.mailgun.com)SessionAuthentication session cookie for the Mailgun control panel used by the customer. Strictly necessary, never set on the public website that the customer operates.
mg_csrffirst-party (Mailgun control panel)SessionAnti CSRF token used by the Mailgun web application. Strictly necessary, only relevant for Mailgun account users.

Mailgun collects user analytics data — you legally need a consent banner. Try FlowConsent free.

Get started freeScan your site

Frequently asked questions

Does Mailgun set cookies on website visitors?

No. Mailgun is an email sending API and does not set cookies on a website. Tracking happens inside the email body via an invisible open pixel (email.mg.mailgun.net) and rewritten click links through events.mailgun.net. These artifacts only fire when a recipient opens an email or clicks a tracked link.

Do I need consent for Mailgun under GDPR and ePrivacy?

For transactional emails Article 6(1)(b) covers the message. For marketing emails consent is required under ePrivacy and national rules. Open and click tracking on marketing emails requires informed consent according to the EDPB and the CNIL.

What is the legal basis for processing data with Mailgun?

Article 6(1)(b) GDPR (performance of a contract) for transactional emails. Article 6(1)(a) (consent) for marketing emails and for open/click tracking on marketing campaigns. Article 6(1)(f) (legitimate interest) is possible for transactional delivery monitoring when documented. The customer is the controller, Sinch Email Inc. is the processor.

Does Mailgun transfer data to the United States?

Provision the project in the EU region (api.eu.mailgun.net) to keep email content, recipient addresses and events in the EEA. The US region (mailgun.net) triggers a transfer covered by SCCs and the EU US Data Privacy Framework. The Sinch parent company is in Sweden.

Is a DPIA required for Mailgun?

A DPIA is recommended for large scale marketing email programs or transactional flows with sensitive content. Document the EU region, the legal basis per campaign, the retention period, the tracking configuration and the DSAR procedure.

How do I implement Mailgun compliantly?

Pick the EU region at project creation, sign the Mailgun (Sinch) DPA, document the processor in your RoPA, collect consent for marketing emails, disable open and click tracking when not needed, include the tracking disclosure in your privacy notice and provide a clear unsubscribe link.

What are the alternatives to Mailgun?

Other email API providers include SendGrid (Twilio, US), Postmark (US), Amazon SES, SparkPost (Bird), Brevo formerly Sendinblue (France), Mailjet (Sinch), Mailtrap, Resend, Tipimail (FR) and self hosted options like Postal or Haraka.

How do I update the cookie policy for Mailgun?

Mailgun does not need to appear in the website cookie banner because it does not set web cookies. Update the privacy notice to disclose the email tracking pixel (open) and link rewriting (click), with the EU region used and the retention period. Include the unsubscribe and DSAR procedures.