AboutReputation first. Public changelog.

Cold outreach that
protects your reputation.

Muster CRM brings warmup, campaigns, the inbox and the CRM together, with safety defaults that keep your mailboxes out of spam. Same surface area as the big suites, fewer black boxes.

Why Muster exists

Cold outreach deserves straight answers.

For years, the dominant tools in this category have charged near a hundred dollars per inbox, per month, while keeping their warmup logic, sending heuristics, and abuse-detection thresholds completely closed. You paid for throughput. You did not get to see how decisions were made on your behalf.

When deliverability breaks, you should be told why. Not left to ask support, then wait.

We started Muster to remove that opacity. Health bands, quarantine thresholds and suppression reasons are shown in the dashboard and published on this site, so you can see why a mailbox was throttled or pulled.

The positioning is straightforward. Founders, agencies, sales teams, recruiters, and fundraisers get one platform for warmup, sending, replies and pipeline, priced per plan rather than per inbox.

We are a small team. We do not invent metrics. We do not pretend to be larger than we are. The changelog shows what we ship, when we ship it.

Platform shape

Two planes. One rule per lane.

The backend decides. The workers execute. They communicate through a NATS message bus and the backend's internal API, never the database. This separation is the reason we can scale send volume by adding small workers instead of growing one giant runtime.

Control plane
4 components
Backend + consumer

Owns the relational state. Decides which mailbox sends what, when, and on which worker. Reads Postgres. Speaks to Stripe and object storage. Never opens an SMTP socket itself.

cmd/backendcmd/consumerPostgresNATS producer
Execution plane
4 components
Workers

One process per machine. One IP per worker. Receives commands on a worker-specific NATS subject. Sends, syncs, validates, heartbeats. State is disposable. A crashed worker is replaced by another reading the same durable stream.

cmd/workerNATS consumerRedis cacheObject storage
NATS spinePer-worker command and result subjects on a durable stream. Replayable. Workers fetch keys and message data from the backend's internal API.
worker commands · worker results
Build philosophy

Six rules we will not bend.

These are not marketing values. They are constraints written into the codebase and the migrations. If a feature breaks one of them, we do not ship it.

01
Reputation over volume.

Defaults favor sender reputation over send volume: 50 cold emails per mailbox per day out of the box, warmup alongside every campaign, and a shared pool that quarantines early.

02
Mailbox-first safety, not worker-first.

A worker is not a flat send limit. Its safe daily volume is the sum of its mailbox budgets, full stop. We will not ship a feature that bypasses the per-mailbox cap to make a chart look better.

03
Many workers, many IPs.

Sending is intentionally distributed. No central choke-point that becomes a single reputation liability. Adding volume means adding mailboxes and workers, not cranking a few harder.

04
Quarantine before providers do.

Our thresholds for the shared paid warmup pool are stricter than what Google, Microsoft, or SES will tolerate. We act in the warning band, not the catastrophe band. By the time a provider penalises you, we have already pulled the mailbox.

05
Encrypted by design.

Mailbox credentials are encrypted before they are stored. Integration tokens and data passed between services use a per-organization key, sealed by a master key held outside the database. AES-GCM at the field level.

06
No black-box scoring.

Every health band, every suppression entry, every pool block has a reason you can read in the dashboard. The product owes you an explanation, not a score.

What is different

Built differently.

A factual comparison of posture, not a feature audit. Other tools in this category may match individual capabilities.

Muster
Typical suites
Sending architecture
Distributed workers, one IP each, per-mailbox caps.
Typically opaque. You buy throughput, not architecture.
Abuse and quarantine logic
Thresholds published on the trust page. Stricter than provider enforcement.
Undocumented. You find out when your reputation is gone.
Changelog
Public, dated changelog in plain wording.
Internal. Released on announcement cadence.
Pricing posture
Flat plans with mailboxes included: 3 on Starter, 20 on Professional.
Per-inbox license fees that scale with team size.

Comparison reflects how Muster is built. We do not speak for any other vendor's plans or pricing.

The team

Small team. Straight answers.

We are a small group of engineers. We will not pretend to be a global enterprise. Bug reports are read by the people writing the code. Contact emails reach a person, not a queue.

Because the team is small, the constraints we put on the codebase have to do the heavy lifting. Safe defaults, conservative warmup, layered abuse controls, encryption everywhere we touch user secrets. We would rather ship one fewer feature than ship a feature that puts your sending reputation at risk.

You can follow what ships on the changelog, dated and in plain wording.

Cold outreach that protects your reputation.

7 days of Professional, no credit card.