Does Mailgun Work in China? PIPL Cross-Border, Recipient Data & Delivery Compliance
Mailgun runs no mainland-China region — it sends only from a US or EU region, so the recipient addresses, message content, and event logs your China email carries are processed and retained offshore, making every send a PIPL cross-border transfer of personal information. A compliance-first look at Mailgun's regions, retention, and the lawful in-country path.
Does Mailgun work in China?
Mailgun is reachable from mainland China, but it runs no China region — so every message you send to a China recipient hands their address and your content to an offshore service.
What you give Mailgun (Mailgun by Sinch) is the recipient's email address plus the message body, and it processes and retains that — along with event logs and suppression lists — only in its US (api.mailgun.net) or EU (api.eu.mailgun.net) region, never in China. That makes every send to a mainland recipient a PIPL cross-border transfer of personal information (Articles 38–40: notice, a separate consent, a transfer mechanism), with an Article 13/23 lawful basis and consent on top for marketing mail; the lawful lever is a compliant China-resident email path plus consent and data minimization, not making the offshore API reachable.
This is a risk map, not a verdict — settle the specifics with counsel. Our China team can map your exposure →
What Mailgun's own documentation says about China
| Fact | Primary source |
|---|---|
| Mailgun runs only a US and an EU region — there is no mainland-China region. Mailgun's Regions page tells you to "Choose which region (North America or Europe) you want your message data to be processed by," so the recipient addresses and content your China email carries are processed and retained offshore. | Mailgun, "Mailgun's Regions" (mailgun.com), retrieved 2026-10-10 |
| Recipient data, message content, event logs, and suppression lists are bound to that offshore region. Mailgun's API reference lists Messages, Event Logs, Suppressions, Mailing Lists, and Statistics as region-bound and states that "message data never leaves the region in which it is processed" — US domains call api.mailgun.net, EU domains call api.eu.mailgun.net. | Mailgun Documentation, "API Overview" (documentation.mailgun.com), retrieved 2026-10-10 |
| Sending to a China recipient from an offshore region is a cross-border transfer under PIPL. Uploading a recipient's email address and message content to Mailgun's US or EU region is a cross-border transfer of personal information under PIPL Articles 38–40 (notice, a separate consent, a transfer mechanism); marketing mail additionally needs an Article 13/23 lawful basis and a working opt-out. | PIPL Articles 38–40 and 13/23; see 21YunBox, "Cross-border data transfers under PIPL", retrieved 2026-10-10 |
| A critical information infrastructure operator has an in-country storage duty an offshore region can't meet. The Cybersecurity Law's Article 39 (formerly Article 37 — renumbered by the 2025 amendment in force January 1, 2026, substance unchanged) requires personal information collected in China to be stored in China, which Mailgun's US or EU region cannot satisfy. | Cybersecurity Law of the PRC, Article 39 (formerly Article 37); see 21YunBox, "China's Cybersecurity Law", retrieved 2026-10-10 |
Sources verified by the 21YunBox compliance team on 2026-10-10.
If your product emails users in mainland China, the usual first question about Mailgun is “can we even call the API from China?” — and that is the wrong place to look. Mailgun’s HTTP API and SMTP are reachable from the mainland. The decision that actually matters is what happens the moment you hand Mailgun your China recipients’ email addresses and each message body to deliver on your behalf. Mailgun (Mailgun by Sinch) sends only from a US or an EU region — there is no mainland-China region — so those recipient addresses, the message content, the event logs (opens, clicks, bounces), and the suppression lists it builds are all processed and retained offshore. That turns a China-facing email program into two compliance questions: a cross-border transfer of your recipients’ personal information, and whether your China mail is delivered and filed on a lawful footing.
Mailgun in China at a glance
| What decides it | In Mailgun's own terms — and China's law |
|---|---|
| What you hand Mailgun | The recipient's email address and the full message body — a one-time passcode, password reset, receipt, shipping notice, balance alert, or marketing send. For a recipient in the mainland, both the address and the content are personal information under China's PIPL. |
| Where it goes | Offshore. Mailgun (Mailgun by Sinch) offers only a North America (api.mailgun.net) and a Europe (api.eu.mailgun.net) region — there is no mainland-China region, and Mailgun's docs state that "message data never leaves the region in which it is processed." Sending to a China recipient from either region is a cross-border transfer (数据出境) of personal information under PIPL Articles 38–40. |
| Delivery into China — and the app's filing | Mail sent from offshore IP ranges to the big mainland mailbox providers meets filtering that senders outside China rarely encounter (an operational hurdle, not the legal test). And the app or site that triggers the mail is itself a public internet service in China, carrying an ICP filing (备案) duty. |
| What is retained — and the storage duty | Mailgun keeps event logs (opens, clicks, bounces), suppression lists, and message data region-bound in that offshore region. For a critical information infrastructure operator, the Cybersecurity Law's Article 39 (formerly Article 37) adds an in-country storage duty an offshore region cannot meet. Marketing mail additionally needs a PIPL Article 13/23 lawful basis, consent, and a working opt-out. |
| Reachability isn't the axis | The API resolves from the mainland, but that is not the decision. The lawful lever is a compliant, China-resident / China-deliverable email path plus consent and data minimization, with the triggering app delivered in-country on ICP-filed infrastructure. 21YunBox maps, localizes, and delivers; it never routes personal information out of China by stealth. |
What you actually hand it — your recipients’ contact data and content
Every message you route through Mailgun carries two things China’s law cares about: who it is going to, and what it says. The recipient’s email address is personal information; so is the content of a password reset, an order confirmation, a shipping update, a balance alert, or a marketing blast. Mailgun receives both, sends the message from its own infrastructure, and then keeps a trail — event logs of every open, click, bounce, and failure; suppression lists of addresses that bounced or unsubscribed; and the message data itself. Mailgun’s own documentation lists Messages, Event Logs, Suppressions, Mailing Lists, Statistics, and Routes as data bound to the region you chose when you created the sending domain, and the only regions it offers are North America and Europe. So for a China recipient, their address and your message are processed — and that activity trail is retained — on servers in the United States or the European Union. None of that is a reachability problem; it is a data problem, and it exists on the very first successful send.
It’s a cross-border transfer — and a question of consent and storage
The moment a recipient’s email address and your message content leave China for Mailgun’s US or EU region, you — the handler — have made a cross-border transfer of personal information under China’s Personal Information Protection Law. PIPL Articles 38–40 put the duty on you, not on Mailgun: you owe the recipient notice, a separate consent distinct from their agreement to receive your email, and one lawful transfer mechanism — a CAC security assessment, the CAC standard contract, or certification. If any of the mail is marketing or otherwise commercial, PIPL Articles 13 and 23 add a lawful basis and consent of their own, plus an opt-out you must honor. Above certain volumes, or where the data is sensitive or “important,” the transfer can also require China’s data-export security assessment (数据出境安全评估) before anything leaves. And if your organization is a critical information infrastructure operator, the Cybersecurity Law’s Article 39 (formerly Article 37 — the 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39, substance unchanged) requires personal information collected and generated in China to be stored in China — an in-country duty a Mailgun region in the US or EU cannot meet. Which of these bites depends on what you actually send and store.
Reaching the API isn’t the question — a compliant in-country delivery path is
Because Mailgun’s API resolves from the mainland, it is tempting to treat “it works” as the end of the analysis. It is the start of it. The compliant way to email users in China is not to make an offshore endpoint reachable; it is to stop quietly exporting your China recipients’ contact details on every send, and to move the China leg onto a path whose data stays in-country. For email that means a compliant, China-resident / China-deliverable relay for the mail you send to mainland recipients, with recipient data minimized, the Article 13/23 consent obtained for anything marketing, and a lawful cross-border basis kept for anything that still has to leave. There is an operational reason teams arrive at the same place: mail sent from offshore IP ranges to the big mainland mailbox providers meets filtering that senders outside China rarely see — and this page puts no figure on it, because a deliverability rate means nothing without a stated method, sample, and date. 21YunBox is a compliant overlay and partner here, not a competitor to Mailgun; the legal determinations — which consent, which transfer mechanism, whether a storage duty applies — are ones to settle with your counsel against what you actually send. This page is a risk map, not a verdict: settle the specifics with counsel.
The lawful path — map, localize, deliver
There is a lawful shape to running email for a China-facing product, and it has three moves. First, map: our China team inventories which of your messages go to recipients in the mainland, what contact data and content each one carries, where Mailgun processes and retains it (its US or EU region), what it keeps (event logs, suppression lists, message data), and the consent basis for anything you send as marketing. Then localize: route the China leg — the transactional and notification mail you send to mainland recipients — through a compliant, China-resident email path that keeps those addresses and message bodies in-country, while you keep Mailgun for the markets where it already serves you. Localizing means stopping the unconsented offshore send of your China contact data and moving China delivery onto a compliant in-country path — never a hidden route that ships the data offshore anyway. Then deliver: the app or site that triggers and renders those emails — the sign-up, the receipt, the reset — is itself a public internet service in China with an ICP filing (备案) duty, and it needs compliant, in-country delivery (the 21YunBox Optimizer) in front of the stack you already run, with no rebuild. The result is a China-facing email program that runs legally and compliantly for your users in China. 21YunBox never uses or suggests circumvention of any kind.
Related reading:
- Cross-border data transfers under PIPL
- China’s data-export security assessment
- China’s Cybersecurity Law (data localization, Article 39)
- How to get an ICP filing for China
