Managed listmonk hosting

BusinessOn-prem or sovereign site

Newsletters and mailing lists sent from your own domain, with the subscriber database in Switzerland, the EU or your own datacentre rather than with a marketing platform. Pilae runs it on your own servers, or in Zurich, Switzerland, and eleven other Pilae Cloud regions.

Talk to us about listmonk

Licence
AGPL-3.0
Runs on
Your own hardware, or any of twelve Pilae regions — six of them in Switzerland and the EU
Upgrades
Pinned, tested against your configuration, applied in your window
Upstream
listmonk.app

Running listmonk in production: what it takes

  1. Pin and deploy on PostgreSQL

    The single listmonk binary at a version we have run, with PostgreSQL beside it. The upstream compose file upgrades the schema whenever the container starts, so the image is pinned and a restart never changes the database.

  2. Keep the admin private, publish the reader paths

    The admin and API answer only on your private network, behind Keycloak or Entra ID over OpenID Connect. Subscription pages, unsubscribe and tracked links, campaign images, the archive and the bounce webhooks go out through the Pilae gate on port 443.

  3. Set up the domain, the relay and the bounces

    SPF, DKIM and DMARC aligned with your From address, one-click unsubscribe on, and a send rate and hourly cap set to what the relay accepts. Hard bounces and complaints are blocklisted on the first occurrence, soft bounces only after several.

  4. Restore with mail pointed at a sink

    Each day the database and the uploads directory are copied offsite, encrypted, and each month they are restored into a scratch instance where a campaign is opened. Its mail points at a sink, so a drill never reaches a subscriber.

  5. Upgrade between campaigns

    Releases can change the schema, and an upgraded database is not used with an older binary, so the rollback is the backup taken just before. The Pilae Agent tries the upgrade on a copy and, once you approve, applies it in your window, never while a campaign is sending.

What listmonk is, and who runs it

Self-hosted listmonk for newsletters and mailing lists

listmonk is a newsletter and mailing list manager: one Go binary with PostgreSQL behind it. It handles lists with single or double opt-in, segments written as SQL over subscriber attributes, campaigns built in a visual editor or as HTML, a public archive, and transactional messages over an API. It covers what most organisations use Mailchimp or Brevo for: the monthly newsletter, member announcements, the list people signed up to on the website. It does not run sequences such as a welcome series; where one matters, n8n drives it through the API.

The subscriber list lives on a dedicated machine on your premises or in whichever of our 12 Pilae Cloud regions your data-protection assessment allows, six of them in Switzerland and the EU. Subscribers, consent timestamps and every campaign sit in a database you can name. Subscribers can export or wipe their own data from the public subscription pages, and views and clicks are counted without being tied to a person unless you turn that on.

listmonk in production: the relay, the domain and the database

Sending is the hard part, and it is not listmonk’s part. listmonk passes each message to a relay, and the reputation of your domain decides whether it reaches the inbox. So the work is in the domain and the list: SPF, DKIM and DMARC aligned with your From address, the one-click unsubscribe header, a send rate the relay accepts, and bounces fed back from the Return-Path mailbox or the provider’s webhooks, so a dead address is mailed once and not on every campaign.

The admin can see the whole list and change every setting, so it and the API answer only on your private network, behind Keycloak or Entra ID. What subscribers touch has to be public: subscription pages, unsubscribe and tracked links and campaign images go out through the Pilae gate on port 443. The database and the uploads directory are backed up daily, encrypted, to your chosen country, and the monthly restore drill runs with outbound mail pointed at a sink. Probes check the public pages every 60 seconds and alert an engineer, and upgrades go through the Pilae Agent between campaigns.

listmonk licence and pricing

listmonk is AGPL-3.0, and there is one build: no paid edition and no fee per subscriber. OpenID Connect sign-on is in it. The cost outside our operation is the relay or sending provider, which you contract directly. Pricing for our operation is on request. Talk to us about the lists you send to.

listmonk system requirements

Before anything is deployed, this is what has to exist. We size it with you in the first session, and we say so when your own hardware is already enough.

CPU and memory
2 vCPU · 2 GBFor listmonk and PostgreSQL on one machine. The Go binary itself uses little; the memory goes to Postgres, where view and click records grow with every campaign.
Database
PostgreSQL 12+The only dependency, and upstream's minimum; we run a supported release. Subscribers, campaigns, templates and every setting, SMTP credentials included, live here, so this backup is the whole configuration.
Mail relay
SMTP, STARTTLS or TLSlistmonk neither delivers to recipients nor signs with DKIM. It hands every message to SMTP servers you configure, your own relay or a sending provider you contract, and the relay does the DKIM signing.
Sending domain
SPF, DKIM, DMARCAligned with the From address. Gmail and Yahoo have required all three from bulk senders since 2024, together with one-click unsubscribe, which listmonk sends as List-Unsubscribe and List-Unsubscribe-Post headers.
Bounce handling
POP3 mailbox or webhookA POP3 mailbox behind the Return-Path that listmonk scans on an interval, or webhooks from one of the sending providers listmonk supports. Without it, dead addresses keep being mailed and the domain's reputation pays for it.

Migrating from Mailchimp to listmonk

Subscribers come across; history does not. A Mailchimp audience export can come as a ZIP with one CSV file per contact status, and listmonk imports CSV with an email, a name and a JSON column of attributes. Merge fields, tags and the opt-in timestamps go into that column, so consent records survive and segments can be rebuilt as queries over them. Unsubscribed and cleaned contacts come across as well, as the suppression list. Open and click history stays in Mailchimp reports. Drag-and-drop templates cannot be exported and are rebuilt, and customer journeys have no equivalent in listmonk. The import is the easy part; the sending domain and the new relay are where the care goes.

  1. Export every audience, all four files

    Subscribed, unsubscribed, non-subscribed and cleaned contacts come out of Mailchimp as separate CSV files. The unsubscribed and cleaned files are the suppression list, and a migration that leaves them behind mails people who already said no.

  2. Reshape into listmonk's import format

    Each file is reshaped to email, name and attributes. Subscribed contacts go in as confirmed and, through the import API, unsubscribed ones as unsubscribed on the same list. Cleaned addresses go in blocklist mode.

  3. Rebuild the templates

    Custom-coded templates export as HTML and come across once merge tags such as *|FNAME|* become listmonk template expressions. Drag-and-drop templates are rebuilt in the visual builder, and a test campaign goes to a seed list before anything else.

  4. Move the sending, then close the account

    SPF, DKIM and DMARC for the new relay are published before the first campaign, which goes to the most engaged segment at a reduced rate. Campaign reports are exported from Mailchimp before the account closes.

An evening campaign, sent at the rate the relay accepts

listmonk · acme-news · zur19 lines

infostart processing campaign (October briefing)

info48,210 recipients on 3 lists, 4 workers at 5 messages/s each

infoscanning bounce mailbox mail.acme.internal

info96 hard bounces blocklisted, 17 soft bounces recorded

infomessages exceeded (30000) for the window (1h0m0s since 01 Oct 26 18:00 +0200). Sleeping for 35m0s.

infosending resumed, 18,210 recipients remaining

infocampaign (October briefing) finished

info64 one-click unsubscribes applied since 18:00, 0 send errors

infobackup database and uploads: verified offsite

An example evening for acme's monthly briefing. The send is capped per second and per hour at what the relay accepts, hard bounces are blocklisted as they come back, and one-click unsubscribes apply at once. The next campaign goes out on the reputation this one leaves behind.

What Pilae is responsible for

A pinned version

A version we have run, not whatever latest resolves to that day.

A runbook

What it depends on, how it fails, what to do about it. In your repository.

A restore drill

Backups restored on a schedule. A backup nobody has restored is a file.

A patch window

Security updates in a window you agreed, with a rollback ready.

Someone watching

Every endpoint probed on the minute. An alert reaches a person, not a dashboard nobody opens.

Where it runs
zur1, fra1, fal1, gra1, ams1, hel1, lon1, ash1, hil1, sin1, tok1, syd1, on-premZurich, Frankfurt, Falkenstein, Gravelines, Amsterdam, Helsinki, London, Ashburn, Hillsboro, Singapore, Tokyo, Sydney, Your own hardware
Who holds the credentials
You do. Ours are separate, named, logged and revocable with one command. We ask before anything changes outside an agreed window.
If you leave
The machine, the data, the compose files and the runbook are already yours. Nothing stops when our access does.

What drives the price of running listmonk

Pricing is on request: a fixed price for onboarding, then a monthly price for listmonk, quoted in writing within five business days. The plans set what every deployment includes; these are the inputs the quote is built from.

Instance size
The CPU, memory and, where a model runs, the GPUs the app needs for your users and your data.
High availability
One machine with tested restores, or a replicated setup that keeps serving when a node fails.
Storage and backups
How much data it holds, how long backups are kept, and point-in-time recovery for its database.
Plan and support
Essential, Business or Enterprise: support hours, response times in the contract and how often we review the service with you.
Region
Your own hardware, where the infrastructure is already yours, or a Pilae Cloud region, where it is passed through at cost plus a fixed margin.
Sign-on and integrations
Single sign-on, directory sync, mail relays and the other systems the app has to reach.

listmonk: common questions

Is listmonk open source?

Yes. It is AGPL-3.0, with no paid edition and no fee per subscriber or per message. It is one of Zerodha's open-source projects, created by Kailash Nadh. Running it unmodified for your own organisation places no obligations on you.

Where do our subscriber lists live?

In PostgreSQL on a dedicated machine, yours or one in a Pilae region such as Zurich or Amsterdam, in ISO 27001-certified datacentres. The relay you choose sees each recipient address and message as it sends, and the encrypted backup goes offsite in your chosen country. Nothing else about your lists leaves the machine.

Will our newsletters reach the inbox?

That depends on the sending domain and the list more than on listmonk. We publish SPF, DKIM and DMARC, keep one-click unsubscribe on, blocklist hard bounces and complaints, and send at a rate the relay accepts. A list that has not been mailed in a year, or was bought, will still damage your reputation, and we say so before the first send.

Can listmonk replace Mailchimp?

Yes, for newsletters, announcements and mailing lists, with double opt-in, segments, templates, a public archive and transactional messages over an API. It has no automated journeys or drip sequences, no landing-page builder and no CRM. Where a welcome series matters, a workflow tool drives it through the API.

Can staff sign in with our directory?

Yes. listmonk supports OpenID Connect single sign-on with any standard provider, which covers Keycloak and Microsoft Entra ID. Roles decide which lists each person sees, and sending a campaign is a permission of its own.

Also in business

Back to apps

Bring us your listmonk. We will tell you what it takes.

Thirty minutes on the deployment you already have, or the one you are about to start.