Skip to content

Frequently asked questions

Your questions about Duva, with precise answers.

What Duva does, what it does not do, and what to set up before sending. A figure that may change points to the page that keeps it up to date.

Getting started

What is Duva, and who is it for?

Duva sends your application's transactional emails: the ones a person expects because they just did something (confirmation, receipt, password reset, alert). You send them through an API from your own domains, with your own DKIM signature, then you follow each delivery: status per recipient, events, signed webhooks and statistics.

Duva is for businesses and professionals; it is not offered to consumers. The servers are hosted in Canada, in Beauharnois (Quebec), and the encrypted backups are kept in a Canadian data centre.

Transactional email hosted in Canada

Can I send newsletters or marketing email?

No, not by default. Duva is a transactional service: it is not a newsletter or mass-mailing tool. The terms of use prohibit sending newsletters, promotions or bulk messages, unless we have agreed to it in writing beforehand (section 4).

If your need falls outside this scope, write to us before sending: only a prior written agreement can make an exception.

Read the terms of use · Contact us

Why is my account in the sandbox, and how do I go live?

Every new account starts in the sandbox: a free, limited mode for trying Duva. Its current limits:

  • 100 emails per month;
  • 50 emails per day;
  • at most 5 recipients per message;
  • no attachments.

The limits that apply to your account are shown on the "Go live" page of the dashboard.

To go live, have the DNS of at least one domain verified, then request production access from that page (depending on your role in the account). The request includes a short form (how you will use Duva, types of email, expected volume, where the addresses come from) that helps us assess it. A member of the Duva team reviews the request and may accept or refuse it; we promise no turnaround time. During the review, the sandbox limits stay in force, and the change of state appears in the banner at the top of the dashboard. Subscribing to a paid plan does not replace this validation.

See the plans

What do I need to set up on my domain?

Two DNS records are required to verify a domain:

  • the DKIM key: a TXT record at <selector>._domainkey.your-domain, which lets Duva sign your emails in your name;
  • the return CNAME: a CNAME at bounce.your-domain, pointing to the target shown, through which bounces and complaints come back.

Optional (recommended, not required to send): the SPF record at the domain root, DMARC, and the tracking CNAME track.your-domain (see the question about tracking). If your domain already has an SPF record, do not create a second one: a domain can have only one, and the DNS screen shows what to add to the existing one.

The DNS screen of each domain, in the dashboard, gives the exact values to copy at your DNS host and lets you request a new check once the records are published. DNS propagation can take some time.

Should I tighten my DMARC policy (quarantine, reject)?

DMARC is optional for sending with Duva. A record with p=none blocks nothing: it asks providers to send you reports, which Duva gathers in the DMARC screen of each domain in the dashboard.

Tightening the policy (quarantine, then reject) asks providers to quarantine or refuse messages that spoof your domain. It also targets your own badly configured sending tools: tightening too early loses real mail.

  • Duva only suggests a step when its reports show that known mail passes DMARC, and it never changes your DNS: the change is made at your DNS host.
  • One step at a time, at least a week apart, watching the DMARC screen: share of Duva's mail that passes, unaligned sources, messages quarantined or rejected.
  • A source you recognize must be configured in its tool before tightening; an unknown source is probably spoofing.
  • To go back, put the previous value back in the record; the effect depends on the record's time to live (TTL).

Avoid the pct tag to proceed by percentages: the current DMARC standard (RFC 9989, May 2026) removed it, because providers applied it unevenly except at 0 and 100. This is not professional advice, and tightening the policy is not a guarantee of delivery.

Plans, billing, cancellation: how does it work?

Each paid plan has a fixed monthly price, in Canadian dollars, plus taxes (GST, QST). The prices and limits of each plan are on the Plans page. If a limit is reached, sends are refused: nothing extra is billed, and unused volume does not carry over.

A subscription is paid monthly in advance and renews automatically until it is cancelled. Payment is processed by Stripe: Duva neither receives nor keeps your card number. There is no trial period; the sandbox, however, is free.

You can cancel at any time from the billing portal (Billing page of the dashboard). Cancellation takes effect at the end of the paid period and you keep access until then; the account then returns to the free sandbox.

See the plans · Terms of Service

Sending and tracking your emails

My email did not arrive: what should I check?

Duva accepts your email and then passes it to the recipient's server; that server accepts it, sorts it or refuses it. Duva does not guarantee delivery or inbox placement. Here is what to check, in order:

  1. The message status, on the Messages page of the dashboard or through the API (GET /v1/{domain}/messages/{id}): queued (waiting to be sent), sent (handed to the sending server, delivery in progress), delivered (accepted by the recipient's server), bounced (permanent refusal), failed (abandoned) or suppressed (never sent, see below).
  2. The message events: a bounce (bounced) gives the refusal code from the recipient's server; a temporary failure (deferred) will be retried; a message can expire (expired) after 24 hours of attempts; a complaint (complained) means the recipient reported the message.
  3. The domain's suppression list: an address that bounced permanently because of the address itself, or that complained, is no longer contacted, and the message shows the suppressed status. Remove an address from the list only if you are certain it is valid.
  4. The recipient's spam folder: a delivered message was accepted by the recipient's server, which does not say which folder it was placed in.
  5. Your account limits: beyond the limits of the plan (or of the sandbox), sending is refused with an error. For an unusual volume, a message can also stay queued while it is checked before being sent.

See the full API reference

What happens if my bounce or complaint rates are too high?

For each account and each domain, Duva measures complaint and bounce rates over accepted emails, over 24 hours or 7 days, from 100 accepted emails. The thresholds published in the terms of use (section 4) are:

  • complaints: 0.10% or more triggers an alert, 0.30% or more is critical;
  • bounces: 5.00% or more triggers an alert, 10.00% or more is critical.

An alert leads to a written notice and a period to fix the problem (generally 5 business days). A critical rate can lead to suspension without notice, because the sending addresses are shared among all customers. A suspension can be reviewed by a person if you ask in writing (answer within 3 business days).

A rate below these thresholds is not a guarantee: a rate higher than what the major email providers tolerate can also be treated as a breach. To reduce them, stop writing to addresses that bounce or complain, and keep your lists accurate.

Read the terms of use

Can I track opens and clicks?

Yes, on request: tracking is off by default and is enabled domain by domain. You publish a CNAME track.your-domain pointing to the target shown on the domain's DNS screen, then request activation from that screen; the Duva team accepts or refuses it. After that, each message that wants tracking asks for it (opens, clicks, or both) and must have an HTML body.

Tracking is not exact: an email client that preloads images or a security gateway that opens links counts as an open or a click. Treat these numbers as indications. Nothing is kept about the visitor: no IP address, no user agent, no referrer.

See the full API reference

Attachments: what are the limits?
  • at most 10 attachments per message;
  • at most 5 MB in total, measured once the files are decoded (their real size, before base64 encoding);
  • executable extensions (.exe, .bat, .js, .vbs, .scr, .msi, etc.) are refused;
  • a sandbox account cannot send any.

Attachments are never returned by the API and are deleted together with the message body, 30 days after sending.

Data and security

Where is my data, and how long is it kept?

Duva's servers are in Beauharnois (Quebec), at OVHcloud, and the encrypted backups are in a Canadian data centre. Let's be precise: web traffic to Duva goes through Cloudflare's network, Stripe processes payments, these providers may process information elsewhere (notably in the United States), and emails are delivered to recipients all over the world.

The content of emails (text, HTML and attachments) is deleted 30 days after sending. Information about sends (sender, recipients, subject, statuses and events) is kept longer: the privacy policy gives the duration for each category of information. Do not rely on Duva to archive your emails: keep your own copy.

Read the privacy policy

How do I secure my account and my API keys?
  • Mandatory second factor: signing in requires a code from your authenticator app, in addition to the password. Keep your recovery codes in a safe place.
  • A secret is shown only once: the secret of an API key (like that of a webhook) is displayed only when it is created. Copy it then into a secrets manager. Duva keeps only an irreversible fingerprint of an API key: it cannot read it back, nor give it to you again.
  • One key per domain: a key only opens the domain it was created for. Keep it on the server side (environment variable), never in a web page or a distributed application.
  • Optional expiry: when creating a key, you can give it a validity of 30, 90 or 180 days, or one year. After that date, the key stops working as if it had been revoked. You can also revoke a key at any time.
  • Trusted devices: if the option is offered, the "Remember this device" box in the two-step verification avoids asking for the code again on that browser for a limited time; the password is always required. All these devices are forgotten when you change your password or your second factor, and you can forget them yourself on the Account security page.
  • If in doubt: if a key or an access is lost or compromised, revoke the key and let us know without delay.

For developers

Webhooks: what are they for and how do I verify them?

A webhook lets Duva call your application as soon as an event occurs: delivered, bounced, deferred, expired, complained, opened or clicked. You choose the address (over HTTPS, on the public Internet) and the event types, and the signing secret (whsec_...) is shown to you only once, when it is created.

Each request is signed in the "Standard Webhooks" format: the webhook-id, webhook-timestamp and webhook-signature headers carry an HMAC-SHA256 signature computed over the raw body with your secret. Verify the signature on the raw body, before decoding it, and reject a timestamp older than 5 minutes: that is what protects against the replay of an intercepted request. The official libraries do this verification for you.

Delivery is at least once: the same event can arrive several times, so deduplicate on webhook-id, and the order of events is not guaranteed. Reply with a 2xx code once the signature is verified; any other response, a timeout or a connection error leads to further attempts at increasing intervals, and a webhook that keeps failing is disabled.

See the full API reference

Which official libraries are there?

Duva publishes an official library for Node.js, one for Python, one for Ruby, one for Go and one for PHP. Their source code is open. None is required: the API is a simple JSON POST, and the OpenAPI specification lets you generate a client in the language of your choice.

Official client libraries · OpenAPI specification

Can I send by SMTP instead of the API?

Yes. Duva also accepts messages by SMTP, on smtp.duva.ca (port 587 with STARTTLS, or port 465 with implicit TLS). The username is your sending domain and the password is that domain's API key; encryption is mandatory. It is the simplest route for software that can only send by SMTP (a framework, WordPress, an authentication provider).

A message sent by SMTP follows the same rules as an API message: verified domain, quotas, sandbox, suppressed addresses. The 250 reply means "accepted for delivery", not "delivered": read the status through the API, events and webhooks, and Duva sends no bounce email back to the sender.

See the full API reference