Exercise for the reader: avoid re-reading the PRNG state file on retries.
How about instead we just generate a uuid4, insert it into a sqlite file or Postgres database, and then the postzegelcode value is threefry(SECRET,uuid)?
I don't quite understand why programmers love minimalism more than reusing widely trusted and very easy solutions that are known to perform well.
It's a more standard setup, and enables better logging and later changes.
I think a Redis instance would be better. Assuming each mail intake device has a unique ID, and ID 0 is intended for un-redeemed postzegelcodes, you could have newly created postzegelcodes SETNX a key with value 0 and a TTL of 5 days, then when mail is being scanned, WATCH the key in a multi transaction, and if the value is 0, SET it to the ID of the intake device, while removing the TTL. The mail can then be rejected at intake if the transaction failed. Upon mail delivery then, you clear the key, which frees it for later re-use.