Woodpecker.co
Woodpecker is one of the oldest cold mail platforms still trading under its own name, and it has spent eleven years compounding the unglamorous half of the category.
The product is a sequencing and deliverability engine. Multi step campaigns branch on whether a prospect replied, opened or did nothing. Sending is spread across as many connected mailboxes as a buyer wants at no extra cost, paced adaptively, randomised to resemble manual typing, matched to the recipient's mail provider, and held to daily ceilings the operator sets. Warm up runs free. Catch all verification runs free on every prospect contacted. Duplicate sending detection stops the same person being reached twice across campaigns.
Commercially it is a meter rather than a set of tiers. Seven dollars buys a hundred contacted prospects, and every extension carries its own published rate, down to the marginal cost of one more training session.
The legal and infrastructure layer is the outlier. Woodpecker publishes a processing addendum with standard contractual clauses, a transfer policy, a processors list, a disaster recovery policy naming a six hour recovery ceiling, a vulnerability disclosure programme, a sending policy, an ethical code of conduct and a public status page carrying its own incident history.
A developer surface covering an interface, webhooks, a model context server and a command line tool exists, and sits behind a paid add on.
The operator is Woodpecker.co S.A., a Polish joint stock company in Wroclaw with published investor relations.
Capability Axes
Three narrow features attached to a product that was complete a decade before any of them existed.
The features are real and named: a writer that drafts message copy, interest level detection that classifies incoming replies, and sorting of the inbox by that classification. All three are useful and all three are peripheral.
The company was founded in 2015 and everything that makes it worth buying predates the model era entirely. Warm up, inbox rotation, adaptive sending, provider matching, condition based branching, verification, the deliverability monitor, the domain audit, the agency panel. Remove the three model features and the product loses copy assistance and reply triage, and keeps its entire reason for existing.
The pricing page settles it. Every add on is metered individually, down to a dollar per domain and five dollars per extra warm up, and the model features are not metered at all. A vendor that prices inference does so because inference costs it money at volume. This one does not, which places the feature closer to a convenience than to the engine.
Independent reviewers reach the same conclusion, one noting plainly that buyers wanting current model capability will find newer entrants further along.
What the company built instead, and built well, is a developer surface, a command line tool and a model context server that let an external assistant operate the platform. The intelligence is expected to arrive from outside rather than to live inside.
Ask which model writes the copy, because two passes could not establish it.
Bounded automation with pre send guardrails that most of the category does not build.
What runs alone is conventional and documented. Campaigns branch on prospect behaviour, adaptive sending adjusts pacing on its own reading of conditions, out of office replies are filtered automatically, and workflows chain steps without intervention. Each of these has a help centre article explaining the mechanism rather than a marketing line.
Two controls act as genuine brakes before a message leaves, and they are unusual. Empty custom field detection catches sends where a merge field has no value, which is the failure that produces the greeting addressed to a blank space. Duplicate sending detection catches the same person being contacted from two campaigns. Both prevent the specific errors that damage a sender rather than merely logging them afterwards.
Operator controls are extensive and adjustable: daily sending ceilings, custom intervals between messages, timezone aware scheduling, preview and test before sending, domain blacklisting, and a global blacklist across an agency's clients.
Manual task steps exist as first class campaign elements for calls, messages and network actions, which means the sequence stops and waits for a person by design rather than by omission.
The privacy policy carries an explicit statement that no automated decisions producing legal or similarly significant effects are taken on personal data, and that no profiling occurs.
The unaddressed area is the model layer. Two passes located no approval gate between generated copy and sending, and no description of how interest level classification reaches its judgement or what happens when it misreads a reply.
A binding commitment about what the models may not do, and silence on which models they are.
The commitment is the strong half and it is drafted with care. The privacy policy states that prospect personal data processed by Woodpecker as a processor is not used to train or improve models, except in anonymised or aggregated form that does not permit identification of any individual. That carve out is written into the document that governs the relationship rather than asserted in marketing, and it addresses the question a buyer's counsel actually asks.
Two further statements sit alongside it. No automated decision making producing legal or similarly significant effects. No profiling, with cookies used only to present content matched to customer needs.
The silent half is the model itself. Two passes located no provider name, no model version, no statement of where generation or classification executes, and no indication of whether message content or prospect fields are transmitted to a third party to produce a draft. The features are described by what they do and never by what runs them.
A processors list is published as a standing document, which is the correct place for a model provider to appear, and the disclosure would be complete if one were named there and referenced from the feature description.
The contrast within the same company is instructive. Its data suppliers are named openly, with verification attributed to one named partner and warm up to another. The model supplier receives no equivalent treatment.
Naming the provider on the feature page would move this grade with very little effort.
Checkable logos, a named reference with figures, four published case studies and a review base large enough to mean something.
The customer names are the kind that can be verified independently rather than asserted: a mail marketing platform, a contact data vendor, a prediction market, a social listening tool, a live chat company, a development consultancy, a venue marketplace and a recruitment platform. Several are recognisable European technology companies, which is coherent for a Polish vendor rather than aspirational.
The reference material carries numbers and attribution. An agency founder is quoted by name and title claiming roughly a thousand appointments booked monthly, more than 150 in a month for a single client, at half the cost of a representative. A software chief executive is quoted by name on the personalisation claim. Four case studies are published as full articles with named companies rather than as pull quotes.
The independent layer is the part that separates this from most of the category. One review platform records 4.5 across 104 responses as of July 2026, another 4.3, and a third publishes reviewer demographics showing 97 percent small business concentration. Several 2026 reviews state their verification method explicitly, one naming the five sources it checked and the month it checked them.
A public status page retains the incident history rather than resetting it, and the vendor says openly that it keeps past difficulties visible.
The gap is at the aggregate level. Two passes located no published benchmark for reply rate, bounce rate or inbox placement carrying a sample, a period and a method. The outcome evidence is testimonial and independent rather than measured and self reported.
A published document set that includes two artefacts almost nobody in this category produces.
The legal index carries a sending policy and an ethical code of conduct as standing published documents, alongside the terms, the privacy policy, a processing addendum, a transfer policy, a processors list, a data protection commitment and a legal questions page. Recording their existence rather than their contents here, because a vendor in cold outreach publishing a code of conduct at all is a signal worth noting on its own.
The allocation of responsibility is stated properly rather than dodged. The customer is designated Data Controller for prospect data and warrants that it was legally acquired and is processed on a lawful basis. The customer undertakes not to insert special category data. Woodpecker acts as Processor for that data and commits to process it only on the controller's instructions, and only where those instructions are lawful.
Enforcement has teeth in the drafting. Breach of the agreement through spam or prohibited content permits suspension or cancellation subject to notice provisions, and the vendor reserves remedies including compensation and indemnity extending to third parties harmed by a customer's breach.
Product controls support it: domain blacklisting, a global blacklist across an agency's clients, duplicate sending detection, spam word and link checking, adjustable daily ceilings, and free unlimited verification of every prospect contacted.
Both major privacy regimes are addressed with named routes, a data protection officer and a named supervisory authority.
The blemish is marketing rather than substance. The feature list claims full compliance with two regulations as absolutes, and no compliance function anywhere would sign a claim phrased that way.
A current policy that publishes the documents other vendors reference and never produce.
The standing document set is the case for this grade. A data processing addendum incorporating standard contractual clauses, published as a page rather than offered on request. A personal data transfer policy. A full processors list naming each company, the data it handles and the purpose. A data protection commitment. All linked from every legal page, all reachable before signing anything.
The policy itself was last revised in July 2026 and does the thing that matters most in this category: it defines the controller and processor split precisely. Woodpecker is controller for customer and user data and processor for prospect data, and it tells the customer plainly that this makes them the controller with the obligations that follow.
The specifics are unusually complete. Every European data right enumerated. A data protection officer appointed and contactable. The supervisory authority named with its street address. European citizens' data guaranteed on European servers. Standard contractual clauses for third country transfers. Prospect data carved out of model training except where anonymised beyond identification. No profiling and no automated decisions with legal effect. Special categories excluded. A sixteen year minimum age. Californian rights handled separately with a statement that data is not sold.
The provision that separates it from every comparable vendor examined is the notice commitment. Material changes adverse to a customer require at least seven days notice by mail or in the application before taking effect.
One sentence spoils an otherwise exceptional document, advising visitors that private browsing will keep them anonymous, which the same policy contradicts by listing the server side logging it performs.
Suppliers named where the product buys services, and nothing published where it sells data.
The named part is real and worth credit. Verification runs through a named external provider and the vendor says so in its own help documentation rather than presenting it as proprietary. Warm up runs through a different named provider on the same basis. The integrations list names further data companies in the surrounding ecosystem, so a buyer assembling a stack can see who is upstream of what.
For the core of the product this is the cleanest possible posture, because the customer supplies the prospect data and is designated its controller. Woodpecker holds it as processor, commits to act only on instruction, and pushes the lawful basis question to the party that actually made the collection decision. That is correct rather than evasive.
The gap opens where the vendor stops being a pipe and starts being a source. A lead finding feature ships with credits included at every level and additional credits sold from ten dollars per five hundred, which means Woodpecker supplies contact records. Two passes located no provenance statement for that database: no collection method, no lawful basis, no supplier, no refresh cadence, no accuracy or bounce figure, and no route for a person in it to request removal.
That silence sits oddly against a legal layer that is otherwise the most complete in this category, and against a privacy policy that carefully explains the controller position for data the customer brings.
A buyer using only their own lists inherits none of this. A buyer using the lead finder inherits all of it undocumented, and should ask where those records come from before the first campaign.
The mail platform obligations are met with a named credential, and the network automation add on carries none.
On the side that matters most, this is the strongest posture recorded in the sweep. The vendor holds a tier two certification under the cloud application security assessment scheme, which is the assessment a mail provider requires before granting the restricted mailbox access this product needs. It states compliance with that provider's user data policy including the limited use requirements, in its own words, on its own security page. It describes itself as a compliant partner operating through the modern authorisation standard, and offers native integration with both dominant mail platforms plus standard protocols for everything else.
The privacy policy adds a general undertaking to comply with all compliance policies and integration requirements published by any mail provider whose accounts are connected to the service.
A vendor synchronising customer mailboxes and publishing exactly which policy governs it, plus the certification that proves it was assessed, has closed the question that most of this category leaves open.
The unaddressed exposure is the professional network outreach add on, sold at 29 dollars per connected account. That network prohibits automated access in its user agreement, and two passes located no equivalent compliance statement, no certification and no risk disclosure for that feature. It is priced and listed like any other line item.
Human like sending randomisation sits in an ambiguous position. Against a mail provider it functions largely as throttling, which is legitimate. Against a recipient it functions as concealment.
A buyer running mail only inherits very little here. A buyer adding network automation inherits the standard exposure of that category with none of the surrounding documentation.
Stewardship of customer and prospect data is documented to a standard the category rarely reaches, and the model layer is undescribed.
The training carve out anchors it and it is contractual rather than promotional. Prospect personal data held as processor is excluded from model training and improvement except in anonymised or aggregated form that permits no identification. Alongside it sit an explicit no profiling statement and an explicit statement that no automated decision producing legal or similarly significant effects is taken.
The surrounding stewardship apparatus is published rather than asserted. Personnel are trained in data processing, bound to confidentiality, and limited to the minimum access needed to run and maintain the service. Breach procedures commit to reporting to the supervisory authority, investigating actual and suspected incidents, mitigating effects and informing data subjects or the customer where law requires. Risk assessments are described as regular. A vulnerability disclosure programme is published with its own page, which is a standing invitation to be told about defects and is rare at this size.
A disaster recovery policy is published in full, and the data protection officer is offered by name as the contact for a buyer conducting their own risk assessment.
The model layer receives none of this treatment. Two passes located no acceptable use policy governing what the writer may produce, no guardrails on generated content, no accuracy statement or error rate for interest level classification, and no description of what a misclassified reply costs an operator who trusts the sorting.
The asymmetry is consistent across this vendor: obligations that existed when the documents were drafted are handled thoroughly, and the features added since have not been written into them.
Authentic sender identity with published suppression tooling, working against randomisation designed to look manual.
Identity is genuine and technically verified. Messages leave the customer's own mailbox through native integration with either dominant mail platform or through standard protocols, and a domain audit checks that sender authentication records are correctly published before campaigns run. Inbox rotation spreads volume across mailboxes the customer owns rather than across fabricated personas. Nothing here impersonates anyone.
Suppression capability is real and disclosed. Domains can be blacklisted. Agencies get a global blacklist applying across every client. Duplicate sending detection prevents the same person receiving the same approach twice from different campaigns. An ethical code of conduct is published as a standing document, noted here as an artefact rather than characterised.
What the recipient is not told runs the other way and one feature states it plainly. Human like sending randomisation exists to make automated dispatch resemble a person typing, which makes indistinguishability a published product objective rather than a side effect. Copy may be model generated with no marking. Opens and clicks are recorded with no recipient notice. Rotation means a single campaign can reach one person from several addresses belonging to the same sender.
The recipient's route out depends entirely on the customer honouring it, since the blacklist is operated by the sender and the vendor holds the data as processor.
Sending in the prospect's own timezone is worth noting on both sides of the ledger: it is a courtesy toward the recipient and it also makes the message land as though composed locally.
One of the most developer accessible platforms in the index, with the whole surface behind a paywall.
The breadth is genuine and documented on a dedicated developer subdomain rather than behind a login. A programmatic interface, webhooks, a model context server and a command line tool, each with published documentation, plus a named connector page for a specific assistant. Two way synchronisation with two named record systems rather than one directional pushes. A third record system, a scheduling tool, spreadsheets, an orchestration service, a data enrichment platform and several named mail infrastructure and warm up providers.
The model context server and command line tool together put this among the small group in the sweep building for machine operation rather than only for humans, and it is the fifth such record.
The marketplace handles consent properly, transferring data to a third party only on activation and halting it when the integration is deleted, with changes taking effect at the next billing period.
The catch is structural and a buyer should price it. The entire integrations, interface, webhooks, model context and command line surface is a single paid add on at twenty dollars monthly. A customer on the base meter has no programmatic access to their own campaigns at all. Most vendors in this category include the interface and charge for volume.
The enterprise record system that dominates large accounts appears in third party integration lists and does not appear as a two way synchronisation on the vendor's own feature list, which is consistent with a buyer base concentrated well below enterprise.
A free infrastructure calculator published as a public tool tells buyers how many mailboxes and domains a target volume requires, which is ecosystem guidance given away rather than sold.
The most specific infrastructure disclosure recorded in this sweep, published in a document five years out of date.
What is named would satisfy most security reviews. The hosting provider is identified by name with its certification linked. Primary servers sit in France. Proxy infrastructure sits in Canada, the United States and Australia, named individually rather than described as global. European customers are assigned automatically to European storage centres. Storage centres are stated to sit within sixty kilometres of each other to limit geographic correlation, with exact locations withheld and the reason for withholding them given.
The operational detail continues past where most vendors stop. Triple encrypted backups. Hourly database dumps and six hourly copies of web hosting. Protection against denial of service, firewalling and private addressing. Administrators monitoring continuously. A published disaster recovery policy naming the tooling used to rebuild, describing traffic redirection, and committing to a full recovery ceiling of six hours in the event of complete database failure. A public status page carrying historical incidents and offering subscription. An uptime figure of 99.9 percent stated for the agency product.
A named recovery ceiling is the rarest item on that list and it is the one a buyer's continuity assessment actually needs.
Two problems hold the grade. The encryption statement says data is partially encrypted at rest and partially in transit, which is candid and is also a material gap for a system holding prospect databases, and the sentence carrying it is garbled with a duplicated verb. And the document was last revised in August 2021, five years behind a privacy policy revised in July 2026, so a buyer cannot tell which parts still describe the current estate.
One credential the vendor holds, one it correctly attributes to someone else, and a set of published artefacts standing in for a trust portal.
The held credential is a tier two certification under the cloud application security assessment scheme, stated with the scheme named and the tier named. That assessment is what a major mail provider requires before granting the restricted mailbox access this product depends on, so it is scoped to the thing that matters most here and a buyer can locate the scheme and understand what it covers.
The inherited credential is handled with a precision worth recording, because the failure mode is common. The feature list says certified storage rather than claiming the certification, the security page attributes the information security certification to the named hosting provider, and it links to that provider's own certification page. A reader is told exactly whose credential it is. That is the correct treatment of an inherited certification and the direct opposite of heading a clause with a standard's name and then qualifying it away.
In place of a modern trust portal the vendor publishes the underlying artefacts: a security document, a disaster recovery policy with a recovery ceiling, a vulnerability disclosure programme, a processors list, a processing addendum with standard contractual clauses, a status page with incident history, and a data protection officer offered specifically as the contact for a buyer's own risk assessment.
What is absent is any examination in the vendor's own name. Two passes located no service organisation control report, no information security certification held by Woodpecker itself, no penetration test summary and no questionnaire response library.
The security document dates to 2021, and the feature list claims full compliance with two privacy regulations as absolutes, which is the one place the language outruns the evidence.
A meter with a calculator, every extension priced individually, and the counting rules explained where they actually catch people.
The base is one number: seven dollars per hundred prospects contacted, on a slider running from five hundred to unlimited, in twelve currencies, with tax stated as excluded and an annual discount applied on screen.
Every add on carries a rate rather than an invitation to talk. Network accounts at 29 dollars each. Extra warm ups at 5 dollars. Mailboxes at 6 dollars from the major providers or 4 dollars from four named alternatives. Domains at about a dollar. Domain transfer at a dollar. Dedicated servers at 59 dollars. Domain hosting at 20 dollars. The developer surface at 20 dollars. Agency clients at 27 dollars each with white labelling at 5 dollars. Training at 2,000 dollars for four two hour sessions, with additional sessions at 500 dollars each.
Publishing the marginal price of one more training session is a level of disclosure almost nobody offers, because it lets a buyer scope an engagement instead of accepting a package.
The inclusions are stated as free and scale upward with volume: unlimited mailboxes, unlimited team members, unlimited catch all verification, warm ups and lead finding credits.
The counting rules are the part that earns the grade. Contacted prospects reset on the billing date and stored prospects never reset. One person across five campaigns counts once against storage and five times against contact. Exceeding a limit stops sending rather than upgrading the account automatically, stated in those words.
The trial is fourteen days or a hundred messages, whichever arrives first, with every feature, no card, extension on request and continued access afterwards.
One inconsistency: the annual saving appears as 33 percent on the billing toggle and 25 percent beside the meter.
Enforceable statutory rights and real technical routes, with the routes sold separately and the timeline unstated.
The rights are properly enumerated and properly staffed. Access, rectification, erasure, restriction, portability and objection are each listed, with a named contact address for deletion, return, modification, access or restriction requests, a data protection officer behind it and a supervisory authority named with its address if the vendor fails to act. That is a portability right a customer can actually enforce rather than a promise.
The technical routes are good where they exist. Two way synchronisation with two named record systems means the working data can live continuously in a system the buyer already owns rather than being retrieved at the end. A programmatic interface, webhooks, a model context server and a command line tool all provide egress. Data can be partially deleted and modified directly in the interface. Integrations can be revoked from the marketplace to halt further transfer.
Two problems keep this mid band. The whole programmatic surface sits behind a paid add on, so a customer on the base meter must add a subscription line to extract their own data efficiently, which is the wrong moment to be asked for money. And two passes located no stated post cancellation retention window, no export format, no bulk workspace export covering campaigns, sequences and reply history, and no commitment on how long anything survives termination.
The contrast with the same vendor's other disclosures is what makes the gap noticeable. A company that publishes a six hour recovery ceiling and a seven day notice period for policy changes has clearly thought in terms of stated timelines, and the one governing a departing customer is missing.
A buyer should establish the export window in writing and keep the record system synchronisation live throughout.
Eleven years of accumulated sending craft, published in full and given away in part.
The control set is the deepest recorded in this sweep. Warm up included free through a named provider. Inbox rotation across unlimited mailboxes at no extra cost. Adaptive sending. Matching between sender and recipient mail providers. Human like randomisation. Adjustable daily ceilings and customisable intervals. Spam word and link checking before send. A domain audit verifying sender authentication records. A deliverability monitor. Timezone aware delivery. Out of office filtering so an automatic bounce is not read as a reply. Duplicate sending detection. Empty custom field detection.
The inclusion that matters most costs nothing. Catch all verification runs unlimited and free on every prospect contacted, and bounces are the fastest way to destroy a sending domain. Competitors routinely meter this.
Supporting infrastructure is sold openly and cheaply rather than bundled opaquely: domains, mailboxes from five named providers at published rates, dedicated servers, and warm up capacity by the unit. A buyer can see and control every component of their sending estate.
The artefact that best demonstrates the posture is free and public. An infrastructure calculator tells a buyer how many mailboxes and domains a given volume requires, which frequently means telling them to send less per mailbox than they intended. Publishing a tool that constrains volume, from a vendor billing by prospects contacted, is an argument against its own short term revenue.
The deliverability position is underwritten by the mail platform compliance posture, including a named security assessment tier and a stated commitment to limited use requirements.
What is missing is measurement. Two passes located no bounce rate, complaint rate or placement benchmark carrying a method, sample or period.
Four named buyers with dedicated pages, and one of them served by a genuinely separate product.
The stated segments are sales teams, lead generation agencies, recruiters and business owners, each with its own solution page rather than a shared page with the noun swapped.
The agency segment is where the coverage becomes real rather than claimed. A separate prospect database per client. Centralised billing across clients. View only client access. Clients connecting their own mailboxes without handing over passwords, which removes the credential sharing that this category normally requires. Automated domain audits per client. A global blacklist spanning every client. Bulk campaign and mailbox operations. An outreach calendar across the book. White labelling at five dollars per client. That is a distinct operating model with its own economics, priced per active client, and it is the deepest agency tooling recorded in this sweep.
Size coverage is unusually wide because the meter has no tiers. A solo operator contacting five hundred people and an agency contacting a million buy the same product with the same features, which removes the common trap of the capability a team needs sitting above the price they evaluated at.
Twelve billing currencies and European establishment with published residency make this a natural fit for European buyers with data location requirements.
The practical centre of gravity sits well below what the meter implies. Independent review demographics put the base at 97 percent small business, the customer logos skew to European technology companies, and the enterprise record system that dominates large accounts is absent from the vendor's own two way synchronisation list.
No enterprise tier, procurement motion or security examination in its own name exists to serve buyers above that line.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
| Entry Price | Pricing Basis | Data Processing Terms | Implementation | Source |
|---|---|---|---|---|
|
7 dollars per 100 prospects contacted, with every add on priced separately
$7 baseline
|
Usage metered at 7.00 dollars per 100 prospects contacted per month, selectable on a slider from 500 to unlimited, in twelve currencies, with tax excluded and applied at billing. An annual billing option is offered, displayed as a 33 percent saving on the billing toggle and as a 25 percent saving beside the meter line. Included free at every level and scaling with volume: unlimited email accounts, unlimited team members, unlimited catch all email verification, warm ups and lead finder credits, with monthly email volume and stored prospect allowances rising with the tier selected. Add ons are individually priced: professional network connected accounts at 29 dollars monthly each; additional lead finder credits from 10 dollars per 500; additional warm ups at 5 dollars monthly per email account; email addresses at 6 dollars monthly each from the two major providers or 4 dollars monthly each from four named alternative providers; new domains at approximately 1 dollar monthly billed annually; domain transfer at 1 dollar monthly billed annually; dedicated servers at 59 dollars monthly each; cloud domain hosting at 20 dollars monthly per domain; integrations, programmatic interface, webhooks, model context server and command line tool together at 20 dollars monthly; agency panel at 27 dollars monthly per active client; white labelling at 5 dollars monthly per active client; outbound workshops at 2,000 dollars for four two hour sessions with additional two hour sessions at 500 dollars each. Trial is 14 days or 100 cold emails, whichever limit is reached first, with all features, no credit card required, extendable on request, and account access retained afterwards. Plans do not upgrade automatically when limits are reached; sending to new prospects stops instead. Contacted prospect limits renew on the billing date and stored prospect limits do not renew. One prospect used across five campaigns counts as one stored prospect and five contacted prospects. | A data processing addendum incorporating standard contractual clauses is published as a standing document on the legal index, reachable before signup rather than offered on request or negotiated individually. A personal data transfer policy and a full processors list naming each third party, the data it handles and the purpose are published alongside it. The security page additionally invites customers wanting a signed processing agreement to contact support. Woodpecker is designated controller for customer and user data and processor for prospect data, with the split stated explicitly in the privacy policy, and it commits to process prospect data only on the controller's instructions where those instructions are lawful. European citizens' data is committed to European servers, with standard contractual clauses covering any third country transfer. A data protection officer is appointed and is offered by name as the contact for a buyer conducting its own risk assessment. For a buyer whose procurement requires processing terms in place before signature, everything needed is published in advance. | None charged, and the free inclusions are unusually substantial. Unlimited mailboxes, unlimited team members and unlimited catch all verification cost nothing at any volume, and warm ups and lead finding credits are included and scale upward with the meter. The trial runs fourteen days or one hundred messages, whichever arrives first, includes every feature, requires no card, can be extended by asking in chat, and access to the account continues after it ends. Onboarding support is free and extensive: a help centre, published developer documentation, a cold email course, guides, ebooks, webinars, templates and a newsletter, plus free public tools including an infrastructure calculator that sizes a buyer's mailbox and domain requirement, a message preview tool, a sender authentication record checker and a signature generator. An expert programme connects customers with practitioners who help configure the service. Paid assistance exists and is priced rather than bundled: outbound workshops at 2,000 dollars for four two hour sessions covering the full outbound process, with additional two hour sessions at 500 dollars each, booked through support. The costs a buyer should model beyond the meter are the developer surface at 20 dollars monthly if they intend to integrate, mailboxes and domains if they are building sending infrastructure from scratch, and the agency panel per active client if they run outreach on behalf of others. | Vendor Published |
A meter with a calculator, and the counting rules published where they actually catch people.
The base rate is a single number that scales continuously rather than stepping between tiers, which removes the trap this category is built on. There is no feature sitting one tier above where a buyer evaluates. Unlimited mailboxes, unlimited team members, unlimited catch all verification, warm ups and lead finding credits are included at every level and grow with volume, and the page enumerates them as free rather than leaving them to be discovered.
What separates this from good pricing pages generally is the second layer. Every extension carries a published rate, and the list runs to thirteen items covering network accounts, warm ups, mailboxes from six named providers at two price points, domains, domain transfers, dedicated servers, domain hosting, the developer surface, agency clients, white labelling and training. Publishing the marginal cost of one additional training session lets a buyer scope an engagement rather than accept a package, and almost nobody does that.
The consumption rules are the sharpest disclosure on the page. Contacted prospects reset on the billing date and stored prospects never reset. The same person across five campaigns counts once against storage and five times against contact. Hitting a limit stops sending rather than upgrading the account automatically. Those three sentences answer the questions that generate surprise invoices everywhere else in this category.
Two things a buyer should still check. The annual saving is shown as 33 percent on the billing toggle and 25 percent beside the meter, which do not obviously reconcile. And the entire programmatic surface, meaning the interface, webhooks, model context server and command line tool, is a paid add on rather than an inclusion, so the real monthly figure for any team that integrates is 20 dollars above the meter.
Third party directories carry figures ranging from 20 to 188 dollars against a pricing page updated in June 2026. That spread is directory staleness rather than vendor opacity.