Transactional email EU hosting enterprise compliance

Custom Flowmailer integration development

Appfront builds custom Flowmailer integrations (since 2023 part of Spotler, now known as Spotler SendPro) for banks, insurers, government bodies, healthcare organisations and e-commerce merchants. Via the REST API at api.flowmailer.net, SMTP, SMPP or Inbox Source, we send transactional email with multi-brand templates, dynamic PDF attachments and real-time webhook feedback, fully EU-hosted and ISO 27001 certified.

What is a Flowmailer integration?

Flowmailer is a Rotterdam-based transactional email platform that has been part of Spotler Group since 2023 and is now commercially offered as Spotler SendPro. The API and domains remain active under the familiar flowmailer.net name, and developers still search for and integrate with "Flowmailer". The platform is built specifically for critical system email: order confirmations, invoices, policy documents, password resets, appointment reminders and security notifications. Not marketing campaigns, but triggered messaging that works when it needs to.

In practice, a custom integration means connecting your web app, ERP, CRM or back office to the Flowmailer REST API (or SMTP, SMPP for SMS, or Inbox Source as a relay), setting up templates with dynamic data and multi-brand Source Based Messaging, generating PDF attachments per message, configuring webhooks for delivery, open and bounce events, and passing them on to your own monitoring or archive. Everything falls under EU jurisdiction, with DKIM, SPF and DMARC configuration as the foundation.

Appfront builds in line with the official Flowmailer API documentation and the OWASP ASVS security standard. We use OAuth 2.0 client credentials with roles scoped per source system. Admin permissions are not needed to send messages, and you would not want them to be. In the event of peak volumes or outages, we retry via alternative IP addresses following Flowmailer's own best practices, so your critical email keeps getting through even when one of the endpoints falters.

Multi-brand templates

One set of templates, multiple brands or divisions via Source Based Messaging. Logo, tone of voice and branding per source system, ideal for banking groups, insurance groups and retailers with several labels that all want to send through the same platform.

Dynamic PDF attachments

A generated PDF per message (invoice, policy, account statement, calendar item or CSV export) as an attachment. Data from your back office is rendered into a template on demand. No separate document infrastructure needed, no manual processing.

€

REST, SMTP, SMPP or Inbox

Four connection methods: the REST API for new systems, SMTP as a drop-in replacement for your current mail server, SMPP for SMS, and Inbox Source as a relay where you do not want to rebuild existing email flows. Choose per source what fits, without compromising on deliverability or audit trail.

Our development process for Flowmailer integrations

We work to a proven method that removes uncertainty early and delivers a stable integration. From an initial analysis of your email flows, source systems and compliance requirements through to go-live and ongoing management, every step is aimed at transactional email that stays reliable, even when a migration or system change is involved.

1
Analysis & scope

We map which email flows need to go to Flowmailer, which source systems connect to it, which templates and brands are needed, whether PDF attachments and SMS sending are involved, and which compliance requirements apply (EU hosting, audit trail, DMARC policy).

2
Architecture

We design the source structure, the OAuth scopes per sending system, and the template and flow setup, and configure DKIM, SPF and DMARC before the first production email is sent.

3
Development

Implementation with automated tests, structured logging and monitoring. You see working builds along the way.

4
Go-live & management

Controlled go-live with data validation and a safety net, followed by ongoing management and further development.

What a Flowmailer integration concretely delivers

Each Flowmailer integration is tailored to your type of email flows, brands and adjacent systems. Below are the capabilities we most often deliver for organisations using Flowmailer as their central transactional email platform.

Source Based Messaging

Each source system receives its own credentials, scoped roles and its own sender identity. A single Flowmailer account serves multiple brands or divisions without them touching each other's credentials or data, with a clear audit trail per source.

Templates with data modelling

Transactional templates with advanced data modelling: loops, conditionals and per-language variants within a single template. One invoice layout works across all languages and entities, and maintenance stays with one central version instead of scattered copies per brand.

Dynamic on-demand attachments

PDF invoices, policy documents, CSV exports and calendar items are rendered per message from data in your backend. No separate document service is needed, and no manual fixes when an attachment is wrong; the attachment is assembled together with the email.

Webhooks & event stream

Real-time webhook callbacks for delivery, opens, clicks, bounces and spam reports, validated with HMAC signatures. Events flow directly into your backend to update statuses in your customer portal, trigger alerts on bounce spikes and feed your data warehouse.

Bounce and reputation management

Automatic classification of hard and soft bounces, retries for soft bounces and suppression of invalid addresses. DKIM, SPF and DMARC monitoring keeps your sender reputation intact, which is crucial for financial or government communication where an email must not land in spam.

SMS via SMPP and Inbox Source

Alongside email, Flowmailer supports SMS via SMPP, useful for two-factor authentication codes, appointment reminders and transaction notifications. Inbox Source acts as a relay for existing email flows, so legacy systems can benefit from centralised deliverability and logging without being rebuilt.

Typical use cases in practice

A Flowmailer integration looks different in each sector. We regularly see a number of recurring patterns, and for each we have a proven setup with attention to multi-brand templates, compliance requirements and the right mix of REST, SMTP, SMPP or Inbox Source.

CRM

Banks & insurers

Financial institutions sending monthly statements, policy documents, claims correspondence and security alerts. EU hosting is often a strict requirement; Source Based Messaging keeps brands within a holding separate; PDF attachments come from the same flow as the email. See also our API integrations.

Government and healthcare

Municipalities, UWV, health insurers and hospitals with appointment reminders, MijnOverheid-style notifications and secure communication. EU hosting and a strict audit trail make Flowmailer a logical alternative to US transactional platforms such as SendGrid or Postmark.

Telecoms and utilities

Telecom operators and energy and water companies sending monthly invoices, consumption overviews and tariff update notifications to millions of customers. High volumes, peaks around billing runs, and SMS via SMPP for outage or two-factor authentication messages, all through one platform.

E-commerce and multi-brand retail

Webshop groups with multiple labels, marketplaces and fulfilment partners sending order and shipping confirmations, return instructions and customer account emails. Each brand has its own sender domain and branding, with one central Flowmailer account as the backbone for all transactional flows.

Technology we use

We build Flowmailer integrations with the official REST API at api.flowmailer.net, plus SMTP, SMPP or Inbox Source where needed. For PHP and Symfony we use the official SDKs; for other languages we connect directly to the REST API. The precise choice depends on your source systems, volumes and multi-brand setup, so that your own team can manage or further develop the implementation.

Flowmailer REST API (api.flowmailer.net) OAuth 2.0 client credentials SMTP relay SMPP (SMS) Inbox Source Flowmailer PHP SDK (7.3 / 7.4 / 8.0 / 8.1+) Symfony Mailer bridge Magento 2 Connector PowerShell module Node.js / Python / .NET / Java / Ruby / Go via REST Source Based Messaging Advanced data modelling (templates) Dynamic PDF/CSV/iCal attachments DKIM / SPF / DMARC HMAC webhook validation GitHub Actions

Why choose Appfront for your Flowmailer integration?

Appfront has extensive experience building API integrations for a wide range of organisations in the Netherlands. We always start with a thorough analysis of your existing systems and processes. An integration should not only work technically, but also add practical value to the way you work.

For every integration, we write clear documentation and make sure your own team, or any future supplier, can understand and manage it. No black box, just transparent code and clear agreements on monitoring, alerting and maintenance.

You work with a dedicated point of contact who understands both the technical and the functional side. This keeps communication short, prevents misunderstandings and speeds up decisions when choices need to be made during development.

See also our wider services around API integrations, middleware, custom software development and web app development.

  • Experience with the Flowmailer REST API, SMTP, SMPP and Inbox Source
  • Specialists in multi-brand Source Based Messaging and scoped OAuth roles
  • Familiar with DKIM, SPF and DMARC configuration and deliverability tuning
  • Secure by default: API key rotation, webhook signature validation, scoped permissions
  • Structured error handling and retry mechanisms
  • Comprehensive logging and monitoring from day one
  • Clear documentation your team can read and manage
  • A fixed point of contact, no account managers passed around
  • Ongoing maintenance and proactive further development
  • A way of working aligned with your existing IT landscape

Security and privacy in Flowmailer integrations

Transactional email often contains personal data and sensitive business information — policy numbers, account details, invoice amounts, 2FA codes. Appfront builds in line with Flowmailer's own API guidelines and the OWASP ASVS. That means OAuth client credentials kept in secure vaults, separate credentials per source system with minimum privileges (no admin rights for sending processes), webhook signature validation, and retry logic that fails over to alternative IP addresses during API outages.

Flowmailer / Spotler SendPro is hosted in the EU, holds ISO 27001 certification, and is GDPR-compliant and WCAG-conformant. We document your data flows, templates, source systems and retention periods so your record of processing activities is complete and you can demonstrably meet the GDPR. We check DKIM, SPF and DMARC configuration per domain — a correct DMARC policy protects your brand against spoofing and prevents legitimate email from ending up in spam.

More on our security approach: information security policy and CVD policy.

  • GDPR-compliant data processing and data minimisation
  • Encryption in transit (TLS 1.2+) and at rest
  • Role-based access and least-privilege principles
  • Audit logs with traceable data flows
  • Automatic retries and dead-letter queues
  • Monitoring and alerting for anomalies
  • Secrets management in line with best practice
  • Documentation for your record of processing activities

Frequently asked questions about Flowmailer integrations

Answers to the questions we get asked most often about Flowmailer (Spotler SendPro) implementations.

A Flowmailer integration is a technical link between Flowmailer (part of Spotler since 2023, now sold as Spotler SendPro) and your own system: a web app, ERP, CRM, e-commerce platform or back office. Using the Flowmailer REST API at api.flowmailer.net, it sends transactional messages (order confirmations, invoices, password resets, account notifications), built from templates with dynamic data and optionally with generated PDF attachments. Webhooks pass on real-time status updates for delivery, opens, clicks and bounces. Alongside the REST API, Flowmailer also supports SMTP, SMPP (for SMS) and Inbox Source as a relay.

Flowmailer suits Dutch and European organisations that send business-critical transactional email and need EU hosting, Dutch-language support and enterprise-grade compliance. Typical users include banks, insurers, government bodies, healthcare organisations, telecom and energy companies, and larger e-commerce merchants with multi-brand portfolios. For US cloud-first stacks, SendGrid or Postmark may make more sense; for marketing email (newsletters, campaigns), Spotler Mail+ or ActiveCampaign is the better fit — Flowmailer is explicitly transactional, not a marketing platform.

A simple integration (a REST API link from one system, a handful of templates and standard bounce handling) can go live within a few weeks. More complex scenarios, such as multi-brand Source Based Messaging, dynamic PDF attachments, SMPP for SMS, migrating from another provider or feeding an archive, usually take longer. After an intake conversation, we give you a realistic estimate.

We work with the official Flowmailer REST API (api.flowmailer.net) using OAuth 2.0 client credentials, alongside the back-end stack that suits you: PHP (official SDK for PHP 7.3 to 8.1+), Node.js, Python, .NET, Java, Ruby or Go via direct REST calls. For Symfony projects we use the official Symfony Mailer bridge; for Magento 2 we use the official Flowmailer Magento 2 Connector. Where relevant, we connect via SMTP or SMPP instead of REST.

Costs depend on the complexity of the data flows, the number of systems to integrate, the number of templates and brands, and the amount of custom business logic. Ongoing management, monitoring and support also affect the total investment. We always provide a clear quote following a no-obligation review of your situation.

Yes. Flowmailer/Spotler SendPro is ISO 27001-certified, GDPR-compliant, WCAG-compliant and hosted in the EU, a clear advantage for banks, insurers, government bodies and healthcare organisations with strict data processing requirements. Appfront builds to OWASP ASVS: OAuth client credentials held in secure vaults, webhook signature validation, scoped roles per source system (no admin permissions for sending processes), separation between test and production environments, and TLS in transit. We document the data flows so that your record of processing activities is complete.

Yes. Appfront regularly takes over existing Flowmailer implementations, including for clients still working with the former brand or who are only now migrating to the Spotler SendPro name. We review the API credentials and scopes, source systems, templates, flows, bounce handling and webhook configuration, document the current setup and propose improvements. From that point on, we handle adjustments, extensions and monitoring, including timely OAuth credential rotation and DKIM/SPF/DMARC checks.

Flowmailer suits organisations that send business-critical transactional email where deliverability, EU hosting and an audit trail matter. Typical use cases include banking and insurance mailings (statements, policy documents, claims communication), government and healthcare notifications (appointment reminders, MijnOverheid-style communication), telecom and utility invoices, e-commerce order and shipping confirmations, and SaaS system emails (password resets, security alerts). It is less suited to organisations that primarily send marketing campaigns and newsletters, which is what Mail+ or Activate are built for.

Ready to build your Flowmailer integration?

Tell us which source systems need to connect to Flowmailer, which brands and templates are involved, and whether PDF attachments, SMS or migration from another provider are part of the picture. We are happy to advise on Source Based Messaging, deliverability and audit trail. A no-obligation first conversation will give you a clear picture of the possibilities within half an hour.

Edit content