How Mailjet Sends 1.5 billion Emails a Month with Google Cloud - Build What's Next
Case Study

How Mailjet Sends 1.5 billion Emails a Month with Google Cloud

5742

Of your peers have already read this article.

3:30 Minutes

The most insightful time you'll spend today!

Leveraging Google Cloud, Mailjet sends 1.5 billion secure marketing and transactional emails every month, enabling its customers to obtain best-in-class delivery, open, and click rates.

Mailjet allows companies to create, send, and track millions of emails to their customers and prospects around the world each month. The company’s offerings range from routing these emails to tailor-made tools that allow clients to design and send marketing campaigns with messages related to sales, user clubs, coupons and discounts, and promotions, as well as transactional emails such as purchase confirmations, shipping confirmations, e-tickets, or password resets.

“All of our services are accessible through programming interfaces. We use the same APIs for ourselves and for our customers. This is part of our unique selling point, which is to make life easier for developers and marketers,” explains François Fanuel, IT Operations Manager at Mailjet.

Google Cloud Results

  • Provides development, testing, and distribution infrastructure for Mailjet
  • Smoothly absorbs up to 20X normal computing power
  • Offers technical and economic flexibility on a pay-per-use basis, depending on the computing power consumed

The company scrupulously monitors its service quality to help ensure that emails sent on behalf of its customers don’t trigger spam filters, and that they obtain the best possible open and click rates.

From hosting to the cloud

In its early years, Mailjet used hosted servers. This model had several disadvantages. It was impossible to instantly activate or deactivate computing power; the company could not be charged for actual, to-the-minute usage; and it lacked the flexibility to add disk space or scale servers in real time.

At the beginning of 2016, Mailjet decided to switch to the public cloud in order to improve technical and economic flexibility. “This two-year evolution required us to review our developments. If we use a virtual machine even for just one hour, our computer code must be able to support it in order to preserve the consistency and integrity of the data and processes,” says Fanuel.

“We needed a way to port our IP addresses to Google Compute Engine. In less than a month, the feature had been developed by Google engineers. This reactivity really impressed us and was definitely a deciding factor.”

François Fanuel, IT Operations Manager, Mailjet

Mailjet and Google were already partners. The marketing and transactional email specialist is one of only three providers in the world, and the only one in Europe, accredited by Google to send bulk emails through Google Cloud Platform. The choice—based on three main factors—was obvious.

Financial and technical considerations

Factor 1: the right price proportionality. “We are able to activate Google Compute Engine virtual machines on demand, without needing to reserve these instances. While the machine remains active, a sliding-scale price is applied, which is particularly attractive to us,” explains Fanuel.

Factor 2: the quality and level of technical communication. Mailjet has direct access to Google Cloud Platform engineers when required. The company has its own IP addressing infrastructure, which is the foundation of its service quality. “We needed a way to port our IP addresses to Google Compute Engine. In less than a month, the feature had been developed by Google engineers. This reactivity really impressed us and was definitely a deciding factor.” Since then, via specific tunnels, Mailjet IP addresses have been ported directly into Google Compute Engine.

Factor 3: conformity to international data regulations. Mailjet is the only email service provider to be ISO 27001 certified and GDPR-ready, enabling the company to offer its clients the highest level of data security and privacy. Google Cloud Platform is also ISO 27001 certified, which was an important factor for Mailjet.

Power through minimalism

In mid-2016, Mailjet replaced its 30 or so email sending servers installed at a hosting company with smaller Google Compute Engine virtual machines, using the automatic load-balancing function. “Using smaller virtual machines—but more of them—optimized our computing power.” This precision mechanism accompanied an increase in activity for the company, with the number of emails sent doubling every year. As for the company’s some 300 TB of data, this is stored in Google Cloud Storage.

The flexibility and power of Google Cloud Platform helps ensure that Mailjet can adapt to peaks in activity that can reach up to 20 times the normal flow—our customers usually send their messages at the same times and during the same peak periods. “Previously, we had to reserve a lot of computing power with our hosting company, equivalent to 150 servers. Moving to an on-demand infrastructure means we can avoid paying a disproportionate fixed annual cost.”

Google Cloud Platform also provides Mailjet with the infrastructure needed to process events centrally, which facilitates technical support. A new analytics dashboard in the making will provide customers access to their campaigns’ key metrics in real time—a circulation report, open rates, and click-through rates, as well as invalid email addresses— regardless of the volume of emails at stake.

From distribution to development

Following routing operations, the development environment is currently being ported to Google Cloud Platform, and will eventually represent 100 virtual servers. “The addition of any new code is iteratively tested in Google Cloud Platform. We benefit from machines that are custom made for our needs, from machines with one core and 3 gigabytes of memory, up to machines with 64 cores.”

Mailjet uses the Google Cloud Interconnect virtual private network to tailor sending flows by geographical location. “For customers who only use our routing service, we will soon have worldwide load balancers. This will help ensure their API requests are received and their emails are sent to Europe and America from one single IP point, thus avoiding transatlantic latency issues.”

Mailjet also uses the Google Identity Aware Proxy authentication tool. All its employees around the world benefit from unique, more secure access, whether they use Google Sites intranets, or the development, or production environment. “Google Cloud Platform delivers on all the promises of a public cloud: service customization, real-time computing power adjustment during periods of high and low demand, and instant activation of computing resources. For us, it’s the best possible ratio between price, performance, availability, and quality,” concludes Fanuel.

Blog

Confidential Computing: Google Cloud Security, Project Zero and AMD Come Together to Secure Sensitive Workloads

4558

Of your peers have already read this article.

3:00 Minutes

The most insightful time you'll spend today!

Confidential Computing (CC) products based on Google Cloud's AMD are expanding the security horizons for enterprises without compromising on the performance. The collaboration between Google Cloud and AMD are critical to adoption of CC!

At Google Cloud, we believe that the protection of our customers’ sensitive data is paramount, and encryption is a powerful mechanism to help achieve this goal. For years, we have supported encryption in transit when our customers ingest their data to bring it to the cloud. We’ve also long supported encryption at rest, for all customer content stored in Google Cloud.

To complete the full data protection lifecycle, we can protect customer data when it’s processed through our Confidential Computing portfolio. Confidential Computing products from Google Cloud protect data in use by performing computation in a hardware isolated environment that is encrypted with keys managed by the processor and unavailable to the operator. These isolated environments help prevent unauthorized access or modification of applications and data while in use, thereby increasing the security assurances for organizations that manage sensitive and regulated data in public cloud infrastructure.

Secure isolation has always been a critical component of our cloud infrastructure; with Confidential Computing, this isolation is cryptographically reinforced. Google Cloud’s Confidential Computing products leverage security components in AMD EPYC™ processors including AMD Secure Encrypted Virtualization (SEV) technology.

Building trust in Confidential Computing through industry collaboration


Part of our mission to bring Confidential Computing technology to more cloud workloads and services is to make sure that the hardware and software used to build these technologies is continuously reviewed and tested. We evaluate different attack vectors to help ensure Google Cloud Confidential Computing environments are protected against a broad range of attacks. As part of this evaluation, we recognize that the secure use of our services and the Internet ecosystem as a whole depends on interactions with applications, hardware, software, and services that Google doesn’t own or operate.

The Google Cloud Security team, Google Project Zero, and the AMD firmware and product security teams collaborated for several months to conduct a detailed review of the technology and firmware that powers AMD Confidential Computing technology. This review covered both Secure Encrypted Virtualization (SEV) capable CPUs, and the next generation of Secure Nested Paging (SEV-SNP) capable CPUs which protect confidential VMs against the hypervisor itself. The goal of this review was to work together and analyze the firmware and technologies AMD uses to help build Google Cloud’s Confidential Computing services to further build trust in these technologies.

This in-depth review focused on the implementation of the AMD secure processor in the third generation AMD EPYC processor family delivering SEV-SNP. SNP further improves the posture of confidential computing using technology that removes the hypervisor from the trust boundary of the guest, allowing customers to treat the Cloud Service Provider as another untrusted party. The review covered several AMD secure processor components and evaluated multiple different attack vectors. The collective group reviewed the design and source code implementation of SEV, wrote custom test code, and ran hardware security tests, attempting to identify any potential vulnerabilities that could affect this environment.

PCIe hardware pentesting using an IO screamer

Working on this review, the security teams identified and confirmed potential issues of varying severity. AMD was diligent in fixing all applicable issues and now offers updated firmware through its OEM channels. Google Cloud’s AMD-based Confidential Computing solutions now include all the mitigations implemented during the security review.

“At Google, we believe that investing in security research outside of our own platforms is a critical step in keeping organizations across the broader ecosystem safe,” said Royal Hansen, vice president of Security Engineering at Google. “At the end of the day, we all benefit from a secure ecosystem that organizations rely on for their technology needs and that is why we’re incredibly appreciative of our strong collaboration with AMD on these efforts.”

“Together, AMD and Google Cloud are continuing to advance Confidential Computing, helping enterprises to move sensitive workloads to the cloud with high levels of privacy and security, without compromising performance,” said Mark Papermaster, AMD’s executive vice president and chief technology officer. ”Continuously investing in the security of these technologies through collaboration with the industry is critical to providing customer transformation through Confidential Computing. We’re thankful to have partnered with Google Cloud and the Google Security teams to advance our security technology and help shape future Confidential Computing innovations to come.”

Reviewing trusted execution environments for security is difficult given the closed-source firmware and proprietary hardware components. This is why research and collaborations such as this are critical to improve the security of foundational components that support the broader Internet ecosystem. AMD and Google believe that transparency helps provide further assurance to customers adopting Confidential Computing, and to that end AMD is working toward a model of open source security firmware.

With the analysis now complete and the vulnerabilities addressed, the AMD and Google security teams agree that the AMD firmware which enables Confidential Computing solutions meets an elevated security bar for customers, as the firmware design updates mitigate several bug classes and offer a way to recover from vulnerabilities. More importantly, the review also found that Confidential VMs are protected against a broad range of attacks described in the review.

Google Cloud’s Confidential Computing portfolio


The Google Cloud Confidential VMs, Dataproc Confidential Compute, and Confidential GKE Nodes have enabled high levels of security and privacy to address our customers’ data protection needs without compromising usability, performance, and scale. Our mission is to make this technology ubiquitous across the cloud. Confidential VMs run on hosts with AMD EPYC processors which feature AMD Secure Encrypted Virtualization (SEV). Incorporating SEV into Confidential VMs provide benefits and features including:

Isolation: Memory encryption keys are generated by the AMD Secure Processor during VM creation and reside solely within the AMD Secure Processor. Other VM encryption keys such as for disk encryption can be generated and managed by an external key manager or in Google Cloud HSM. Both sets of these keys are not accessible by Google Cloud, offering strong isolation.

Attestation: Confidential VMs use Virtual Trusted Platform Module (vTPM) attestation. Every time a Confidential VM boots, a launch attestation report event is generated and posted to customer cloud logging, which gives administrators the opportunity to act as necessary.

Performance: Confidential Computing offers high performance for demanding computational tasks. Enabling Confidential VM has little or no impact on most workloads.

The future of Confidential Computing and secure platforms


While there are no absolutes in computer security, collaborative research efforts help uncover security vulnerabilities that can emerge in complex environments and help to prevent Confidential Computing solutions from threats today and into the future. Ultimately, this helps us increase levels of trust for customers.

We believe Confidential Computing is an industry-wide effort that is critical for securing sensitive workloads in the cloud and are grateful to AMD for their continued collaboration on this journey.

To read the full security review, visit this page.

Acknowledgments 

We thank the many Google security team members who contributed to this ongoing security collaboration and review, including James Forshaw, Jann Horn and Mark Brand.

We are grateful for the open collaboration with AMD engineers, and wish to thank David Kaplan, Richard Relph and Nathan Nadarajah for their commitment to product security. We would also like to thank AMD leadership: Ab Nacef, Prabhu Jayanna, Hugo Romero, Andrej Zdravkovic and Mark Papermaster for their support of this joint effort.

Blog

Go Green with Google’s Latest Tool and Pick the Most Sustainable Cloud Region

5662

Of your peers have already read this article.

1:30 Minutes

The most insightful time you'll spend today!

Google's sustainability initiative to turn carbon-free by 2030 is followed by the release of its latest tool. The tool helps pick a cloud region, taking into consideration variables such as price, latency and lowest CO2 levels.

As a Google Cloud customer, your carbon footprint is already carbon neutral: Google first achieved carbon neutrality in 2007, and has been purchasing enough solar and wind energy to match 100% of its global electricity consumption since 2017. Now, Google is targeting a new sustainability goal: operating on carbon-free energy (CFE) 24/7, everywhere, by 2030. 

We want to empower you to make more sustainable decisions and progress with us towards this 24/7 carbon-free future. Earlier this year, we published the carbon characteristics of our Google Cloud regions. Later, we introduced a simple tool to help you pick a Google Cloud region, taking variables like price, latency and sustainability into account. Our next question was: what’s the best way to surface that sustainability info when you’re actually picking a region for your cloud resources? 

Starting today, we are indicating regions with the lowest carbon impact inside Cloud Console location selectors. Available today for Cloud Run and Datastream, you’ll see it roll out to more Google Cloud offerings over time:

Cloud Run region selector.jpg
Click to enlarge

Regions that feature the “Lowest CO2” and the leaf have a CFE% of at least 75%, or, if the information is not available for this region yet, a grid carbon intensity of maximum 200 gCO2eq/kWh. You can read more about how we calculate these metrics in our documentation.

Before releasing this feature, we ran experiments to measure its impact: Users who were exposed to the enhanced region picker were 19% more likely to select a “low carbon” region for their Cloud Run service—a significant lift. These results show that by displaying carbon information in context of when you make the decision of picking a region, we are helping you make more sustainable decisions.

By sharing and displaying carbon information of Google Cloud regions, together we’re making tangible progress towards our goal of a carbon-free future. Learn more about Carbon free energy for Google Cloud regions.

3363

Of your peers have already watched this video.

2:00 Minutes

The most insightful time you'll spend today!

Case Study

Twitter Charts #HybridCloud Journey With Google Cloud

Social media giant Twitter needs no introduction. The 24/7 live platform, which crunches massive volumes of data every second, was using its data centers for a lot of its infrastructure and used the cloud for some of what it does.

However, it needed ever more storage and compute resources and looked at the cloud. The task involved transferring an estimated 300-400 petabytes of data to the cloud.

So, Twitter embarked on a rigorous evaluation process to determine if that was even possible. It did in-depth analysis with many engineers over many months. Finally, the company went to Google and it became obvious that this was a high-performance, high-quality cloud. When Twitter aggregated the network differences, the savings from having more flexible resources, the resulting difference was dramatic.

As a result, Twitter was impressed with Google Cloud’s performance, the flexibility it offered in scaling both storage and compute independently, and the suite of products that Google provided.

See how this move enabled Twitter to separate compute and storage needs and merge enthusiastically into a hybrid cloud strategy for the future.

3240

Of your peers have already watched this video.

20:00 Minutes

The most insightful time you'll spend today!

Webinar

The Transformative Journeys of Financial Firms on Google Cloud: Watch Video

The reliance on cloud-based architectures, high performance computing, big data and more are accelerating in the banking, capital, insurance and financial services industries. Google Cloud had a strong role in transforming many businesses especially in the pandemic to smoothly transition into the digital space and understand their customers. Two years since then, financial firms have been able to design better products based on intelligent, real-time insights and leverage many capabilities of Google Cloud to deliver tailored experiences. So, how big of an impact Google Cloud has on the future of the financial services? The answer is huge and endless.

Watch this video to dive into the state of global financial services companies that leveraged modern cloud architecture for their sensitive data, platforms, devices and products while they increase revenues, stay compliant and curb costs.

Blog

What Our Google Cloud Experts Say About Multi-cloud Journey

3436

Of your peers have already read this article.

1:30 Minutes

The most insightful time you'll spend today!

Discussion on multi-cloud journey along with 4 experts at Google Cloud offers 5 important takeaways. If you are kickstarting your multi-cloud journey, here are some key considerations. Read now!

Do you want to fire up a bunch of techies? Talk about multicloud! There is no shortage of opinions. I figured we should tackle this hot topic head-on, so I recently talked to four smart folks—Corey Quinn of Duckbill Group, Armon Dadgar of Hashicorp, Tammy Bryant Butow of Gremlin, and James Watters of VMware—about what multicloud is all about, key considerations, and why you should (or shouldn’t!) do it.

Five important insights came out of these discussions. If you’re on a multicloud journey or considering one, keep reading.

Do: Choose to do multicloud for the right reasons

Don’t do multicloud because Gartner says so, implores Corey Quinn. Before embarking on a multicloud, define a “why” focused on business value journey, says Armon Dadger. For example, you might want to use services from each public cloud because of their differentiated services, according to Tammy Bryant Butow. Armon also calls out regulatory reasons, existing business relationships, and accommodating mergers and acquisitions. On the topic of M&A, Corey points out that if you acquire a company that uses another cloud, it’s usually expensive and difficult to consolidate. It can be smarter to stay put.

Don’t: Over-engineer for workload or data portability

Thinking that you’ll build a system that moves seamlessly among the various cloud providers? Hold up, says our group of experts. Armon points out that aspects of your toolchain or architecture may be multicloud—think of some of your workflows or global network routing—but that shifting workloads or data is far from simple. Corey says that trying to engineer for “write once, run anywhere” can slow you down, and ignores the inherent uniqueness that’s part of each platform. Specifically, Corey calls out the per-cloud stickiness of identity management, security features, and even network functionality. And data gravity is still a thing, says James, that causes some to dismiss multicloud outright.

If you’re using multiple public clouds, you take advantage of the distinct value each offers, Armon says. Use native cloud services where possible so that you see the benefits from useful innovations, built-in resilience, and baked-in best practices. The value from that cloud-infused workload may outweigh the benefits of seamless portability.

Do: Recognize different stakeholder interests and needs

James smartly points out that many multicloud debates happen because people are arguing from different perspectives. Context matters. If you’re an infrastructure engineer who invests heavily in a given cloud’s identity and access management model, multicloud looks tricky. Or if you’re a data engineer with petabytes of data homed in a particular cloud, multicloud may look unrealistic. James highlights that many developers default to multicloud because their local tools—where all the work happens—are multicloud. A developer’s IDE and preferred code framework(s) aren’t tied to any given cloud. Be aware that groups within your organization will come at multicloud from distinct directions. And this may impact your approach!

Don’t: Go it alone

Corey talks about the importance of asking others what worked, and what didn’t. Tammy offers her best practices around sharing results from experiments. It’s about sharing knowledge and tapping into it for community benefit. Others have probably tried what you’re trying, and can help you avoid common pitfalls. If you’ve just made an architectural choice that didn’t work out, share it, and help others avoid the pain. 

Read research from analysts, go to conferences or watch videos to observe case studies, and join online communities that offer a safe place to share mistakes and learn from others.

Do: Experiment first using techniques like multi-region deployments

If you think you can operate systems across clouds, how about you first try doing it across regions in a specific cloud, suggests Corey. Getting a system to properly work across cloud regions isn’t trivial, he says, and that experience can help you uncover where you have architectural or operational constraints that will be even worse across cloud providers.

This is great guidance if your multicloud aspirations involve using multiple clouds to power one application—versus the more standard definition of multicloud where you use different clouds for different applications—but can also surface issues in your support process or toolchain that fail when faced with distributed systems. Start with muti-region deployments and chaos engineering experiments before aggressively jumping into multicloud architectures.

The Google Cloud take

Do the things above. It’s great advice. I’ll add three more things that we’ve learned from our customers.

  1. Don’t fear multicloud. You’re already doing it. You don’t single-source everything. As Corey mentioned, you probably already have one cloud for productivity tools, another for source code, another for cloud infrastructure. You’ll use software and application services from a mix of providers for a single app. You have that experience in your team and have been doing that for decades. What people do rightly worry about is using more than one infrastructure service beneath an application, as that can introduce latency, security, and logistical hurdles. Make sure you know which model your team is considering.
  2. Embrace the right foundational components, including Kubernetes. Will everything run on Kubernetes? Of course not. Don’t try to do that. But it also represents the closest thing we have to a multicloud API. Companies are using Kubernetes to stripe a consistent experience across clouds. And this isn’t just to orchestrate containers, but also to manage infrastructure and cloud-native services. Also, consider where you need other fundamental consistency across clouds, including areas like provisioning and identity federation.
  3. Use Google Cloud as your anchor. Here’s a fundamental question you have to decide for yourself: Are you going to bring your on-premises technology and practices to the cloud, or bring cloud technology and practices on-prem? We sincerely believe in the latter. Anchor to where you’re trying to get to. We offer Anthos as a way to build and run distributed Kubernetes fleets in Google Cloud and across clouds. By using a cloud-based backplane instead of an on-prem one, you’re offloading toil, leveraging managed services for scale and security, and introducing modern practices to the rest of your team.

We learned a lot about multicloud through these discussions, and it seems like others did too. That’s why we’re going to do a second round of interviews with a new crop of experts so that we can keep digging deeper into this topic. Stay tuned!

More Relevant Stories for Your Company

Blog

A New Milestone: Istio Comes Closer to Cloud-native Ecosystem

Today we are excited to announce that Google and the Istio Steering Committee have submitted the Istio project for consideration as an incubating project within the Cloud Native Computing Foundation (CNCF). This is a significant milestone for Istio and its community, and we are thrilled to reach this next step

Case Study

If You Run Your Country’s Largest Retail Franchise, How Do You Pull Together, in Sync?

In 1984, Mario Maio set up a small business manufacturing electrical transformers in his Johannesburg garage. Over the next two decades, the ACDC Dynamics company he created came to dominate manufacturing, import, and distribution in South Africa’s electrical goods sector. Then, in 2007, Mario’s son, Ricardo Maio, founded a retail arm to

E-book

The Future of Cloud Computing

Increasingly, technology, data, and human interactions will follow a new model of real-time inputs, enabling change without interruption and positive iteration. Cloud computing powers an important shift for information technology, and it will usher in new and better ways to serve customers, make discoveries, and build great products and services.

Blog

Rethinking retail with Google Cloud Retail Search

Cloud Retail Search, part of Discovery Solutions For Retail portfolio, helps retailers significantly improve the shopping experience on their digital platform with ‘Google-quality’ search. Cloud Retail Search offers advanced search capabilities such as better understanding user intent and self-learning ranking models that help retailers unlock the full potential of their

SHOW MORE STORIES