Cloudsteading
Cloudflare Temp Email administration interface showing account and mail counts, mailbox tabs and address lookup. Author-supplied screenshot; its running version and sample-data status are unknown. Not a fresh Cloudsteading deployment.
Cloudflare Temp Email administration interface showing account and mail counts, mailbox tabs and address lookup. Author-supplied screenshot; its running version and sample-data status are unknown. Not a fresh Cloudsteading deployment.

Cloudflare Temp Email

Run temporary inboxes on your own domain, with a Vue client and Cloudflare Email Routing backend.

Cloudflare Temp Email is a self-hosted Temp Mail alternative built on Cloudflare (D1, Email Workers, Pages, Workers). Free tier eligible within limits. Inspect the source and license in the linked repository.

Source & license

Upstream license: MIT

License TL;DR

You can use it, change it, self-host it and sell it. Keep the original copyright and license notice with copies of the code. You don’t have to publish your changes. The authors don’t promise it will work.

Explain MIT in plain English →

Summary of the main license. Separate packages and assets can have different terms.

Inspect repository ↗Read this project’s actual license ↗

Repository owner

@dreamhunter2333

See the upstream repository for the original creator and contributors.

Maintain this project? Maintainer verification →

Cloudflare hosting

Free tier eligible within limits

Small inbound-only temporary inboxes can fit Cloudflare Workers/Pages and D1 Free allowances. A domain and Email Routing setup are required. Arbitrary-recipient outbound mail through Cloudflare requires Workers Paid; optional providers and features have separate costs. This is source-reviewed eligibility, not a tested deployment.

Hosting requirements
  • Workers Free has 100,000 requests per day shared across the account and 10 ms CPU per invocation. Measure CPU-heavy parsing, authentication and rendering; this review is not a load test.
  • D1 Free has 5 million rows read/day, 100,000 rows written/day and 5 GB total storage. Queries, polling, indexes and retained data consume allowances. Provision and migrate your own database.
  • Pages Functions share Workers request and CPU allowances. The selected Pages configuration connects its BACKEND service binding to cloudflare_temp_email; build and deploy the backend and frontend separately.
  • You need a domain whose DNS is on Cloudflare, Email Routing DNS records, a verified destination and catch-all routing to the Worker. Domain registration is a separate cost; a Worker URL alone cannot receive mail.
  • Replace JWT_SECRET = "xxx" with a strong private signing secret, configure administrator passwords and keep DISABLE_ADMIN_PASSWORD_CHECK off. Optional site passwords, Turnstile and creation controls should match your privacy and abuse requirements.
  • The selected Worker template has D1 enabled. KV, Workers AI, send_email, cron and static assets are commented examples; they are not required active bindings in this baseline.
  • Enable KV for features that require it, such as registration email verification, Telegram and webhooks. AI extraction, S3/R2 attachments, OAuth and Resend require their own resources, credentials and cost review.
  • Inbound Email Routing is available on Workers Free; its processing consumes Worker quotas. Cloudflare sending to arbitrary recipients requires Workers Paid. Sending to verified account destinations has separate free compatibility rules.
  • The optional Python SMTP/IMAP proxy runs outside this Cloudflare Worker deployment. Its server cost is not included in the free baseline.
  • No domain, catch-all rule, mailbox, sending key or login was provisioned or tested. The upstream README is displayed in full, including its broader free-service claims; this hosting assessment narrows those claims to the inbound baseline.
Check current pricing ↗
Review findings & limitations
  • Reviewed the pinned source, two deployment configurations, nine GitHub Actions workflows and 113 JavaScript/TypeScript files. Vue components and English deployment documentation were also collected as source text. No upstream code, workflow or mail delivery was executed.
  • The selected Worker configuration is a manual-installation template, not a completed account deployment. The frontend Pages deployment is a separate target linked through its BACKEND service binding. GitHub Actions writes actual backend configuration from BACKEND_TOML, so the deployed secret configuration can differ from the public template.
  • The public template contains example domain names, database IDs and JWT_SECRET = "xxx". Replace them before exposing an installation. Administrator authentication can be explicitly disabled by a setting; this review does not recommend enabling that bypass.
  • The root LICENSE grants MIT terms and credits Dream Hunter. README requests learning and personal use; the original text is preserved. Inspect both documents rather than assuming the README heading is the license.
  • The administrator screenshot is a real author-supplied UI view. Its running version, capture date and sample-data status are unknown. It is not proof of a fresh Cloudsteading installation.
  • Receiving inboxes and arbitrary-recipient sending have different costs. The optional SMTP/IMAP Python server is outside the Cloudflare baseline, and cloud/email provider availability was not functionally tested.
  • The Temp Mail relation describes disposable inbox workflow overlap, not identical service, privacy, mobile clients or delivery guarantees.
Sources checked 01/10/2026

Repository snapshot: be7ba25. Hosting eligibility reflects the deployment documentation and listed assumptions.

  • temp-mail ↗

    **A fully-featured temporary email service!**

  • workers ↗

    name = "cloudflare_temp_email" main = "src/worker.ts"

  • pages ↗

    name = "temp-email-pages" pages_build_output_dir = "../frontend/dist"

  • d1 ↗

    [[d1_databases]] binding = "DB"

  • email-workers ↗

    Mail reception in this project is **entirely dependent on** Cloudflare Email Routing.

  • free-tier-eligible ↗

    | **Free** | 100,000 per day | No charge for duration | 10 milliseconds of CPU time per invocation |

  • free-tier-eligible ↗

    | Rows read | 5 million / day | First 25 billion / month included + $0.001 / million rows |

  • free-tier-eligible ↗

    Requests to your Functions are billed as Cloudflare Workers requests.

  • free-tier-eligible ↗

    Sending to arbitrary recipients requires the Workers Paid plan.

  • MIT ↗

    Permission is hereby granted, free of charge, to any person obtaining a copy

  • architecture ↗

    cd worker pnpm install cp wrangler.toml.template wrangler.toml

  • architecture ↗

    export default { fetch: app.fetch, email: email, scheduled: scheduled, }

  • architecture ↗

    [[services]] binding = "BACKEND" service = "cloudflare_temp_email"

Upstream screenshot · dreamhunter2333/cloudflare_temp_email repository contributors ↗. Depicts the upstream project. We have not deployed and tested a fresh installation here.

What it can replace

Compare the workflow you need. These mappings describe overlap; full feature parity requires a separate comparison.

Temp Mail logoTemp Mail ↗

For receiving disposable email into browser inboxes that you operate on your own domain. This is an editorial workflow comparison; it does not include Temp Mail hosted infrastructure, its domain pool or native mobile apps, and no migration or deliverability parity was tested.

See supporting source ↗
external SaaS target
varies
→ D1 + Email Workers + Pages

How it works

The shape of Cloudflare Temp Email on Cloudflare, and how it stacks up against the rented tools it replaces.

Diagram target: worker/wrangler.toml.template, pages/wrangler.toml. Other repository deployments are listed in the source evidence below; they are not required by this target.

Architecture

Diagram of deployment declarations at the reviewed commit. Each app has its own entrypoint; declared resources do not prove runtime calls. Follow file and line sources below.

View upstream source ↗
Public interface
Configured entry points2
temp-email-pages
pages/wrangler.toml
cloudflare_temp_email
worker/wrangler.toml.template
↓
App
temp-email-pages
entry
Cloudflare Pages
cloudflare_temp_email
entry
Cloudflare Workers
Entrypoint: src/worker.ts
↓

Configuration and workflow sources

Reviewed commit be7ba25a574e. This configuration evidence comes from reading source files. Execution checks, when available, appear in the project's runtime review.

Deployment configuration · 2 files
pages/wrangler.toml ↗

Cloudflare Pages · compatibility 2024-05-13

temp-email-pages · default

  • BACKEND → Worker service · service cloudflare_temp_email
worker/wrangler.toml.template ↗

Cloudflare Workers · documented installation template; operator setup required · compatibility 2025-04-01

Selected from the upstream installation instructions ↗. This is a template to configure in your account; no fresh deployment is established.

cloudflare_temp_email · default

Entrypoint: src/worker.ts

  • DB → D1

Named environments are separate deployments. Bindings are shown only where declared. Configured routes are URL patterns, not verified application endpoints.

Runtime source · handlers, binding usage and workflow steps

Observed TypeScript/JavaScript declarations from Worker entrypoints and resolved relative imports. Calls and workflow steps may run conditionally; their listed order is not a proven end-to-end request flow. Router declarations may be mounted under a prefix or may not be registered. This shows code wiring, not a successful deployment or runtime test. Dynamic wiring, aliases and generated code may not resolve.

frontend/src/api/user-access-token-interceptor.js ↗
  • L27 · loadUserSettings calls (conditional paths may differ): client.get, safeHeaderValue, Object.assign
  • L40 · refreshUserSettings calls (conditional paths may differ): pendingRefreshes.has, pendingRefreshes.get, loadUserSettings, pendingRefreshes.set, pendingRefreshes.delete
  • L51 · resolveAccessToken calls (conditional paths may differ): safeHeaderValue, config.headers.get, refreshUserSettings, mailboxPaths.has, getPathname
frontend/src/config.ts ↗

    Environment references: env.VITE_API_BASE · env.VITE_DEFAULT_LANG · env.VITE_CF_WEB_ANALY_TOKEN · env.VITE_IS_TELEGRAM · env.VITE_GOOGLE_AD_CLIENT · env.VITE_GOOGLE_AD_SLOT

    frontend/src/utils/__tests__/remote-content-policy.test.js ↗
    • L7 · leaks calls (conditional paths may differ): document.createElement, host.querySelectorAll, a.name.startsWith, test, f.push
    frontend/src/utils/composables.js ↗
    • L3 · useIsMobile calls (conditional paths may differ): useBreakpoint, useMemo
    frontend/src/utils/email-parser.js ↗
    • L3 · humanFileSize calls (conditional paths may differ): Math.floor, Math.log, parseFloat, toFixed, Math.pow
    • L8 · processItem calls (conditional paths may differ): parse_message, URL.createObjectURL, item.message.replace, substring, toString, Math.random, humanFileSize, console.log, console.error, PostalMime.parse
    • L78 · getDownloadEmlUrl calls (conditional paths may differ): URL.createObjectURL
    frontend/src/utils/mail-actions.js ↗
    • L6 · escapeHtml calls (conditional paths may differ): String, replaceAll, text.replaceAll
    • L19 · sanitizeContent calls (conditional paths may differ): DOMPurify.sanitize, escapeHtml
    • L35 · buildReplyModel calls (conditional paths may differ): emailRegex.exec, sanitizeContent
    • L62 · buildForwardModel calls (conditional paths may differ): sanitizeContent
    frontend/src/utils/remote-content-policy.js ↗
    • L41 · decodeCssEscapes calls (conditional paths may differ): value.replace, Number.parseInt, String.fromCodePoint
    • L55 · normalizeCssFetchIdentifiers calls (conditional paths may differ): value.replace, identifier.includes, decodeCssEscapes, CSS_FETCH_IDENTIFIERS.has, decoded.toLowerCase
    • L77 · provablyLocal calls (conditional paths may differ): trim, String, test
    • L95 · srcsetIsLocal calls (conditional paths may differ): every, filter, map, split, String, candidate.trim
    • L108 · blockCssUrls calls (conditional paths may differ): normalizeCssFetchIdentifiers, CSS_FETCHES.test, normalizedCssText.replace, provablyLocal, onBlocked
    • L134 · getPurifier calls (conditional paths may differ): DOMPurify, purifier.addHook, URL_ATTRIBUTES.has, NAVIGATION_HREF_ELEMENTS.has, srcsetIsLocal, provablyLocal, node.setAttribute, blockCssUrls, node.getAttribute
    • L201 · blockRemoteContent calls (conditional paths may differ): sanitize, getPurifier
    pages/functions/_middleware.js ↗
    • L11 · onRequest calls (conditional paths may differ): some, API_PATHS.map, reqPath.startsWith, context.env.BACKEND.fetch, context.next

    Environment references: context.env.BACKEND

    worker/src/address_auth.ts ↗

      Environment references: c.env.DB · c.env.JWT_SECRET

      worker/src/admin_api/account_settings_api.ts ↗

        Environment references: c.env.KV · c.env.SEND_MAIL

        worker/src/admin_api/address_api.ts ↗

          Environment references: c.env.DB · c.env.JWT_SECRET · c.env.ENABLE_ADDRESS_PASSWORD

          worker/src/admin_api/address_sender_api.ts ↗

            Environment references: c.env.DB

            worker/src/admin_api/admin_mail_api.ts ↗

              Environment references: c.env.DB

              worker/src/admin_api/admin_user_api.ts ↗

                Environment references: c.env.KV · c.env.DB

                worker/src/admin_api/ai_extract_settings.ts ↗
                • L10 · getAiExtractSettings calls (conditional paths may differ): getJsonSetting, c.json
                • L18 · saveAiExtractSettings calls (conditional paths may differ): c.req.json, saveSetting, JSON.stringify, c.json
                worker/src/admin_api/cleanup_api.ts ↗

                  Environment references: c.env.DB

                  worker/src/admin_api/db_api.ts ↗

                    Environment references: c.env.DB

                    worker/src/admin_api/index.ts ↗
                    • L26 · api.get("/admin/address")
                    • L27 · api.post("/admin/new_address")
                    • L28 · api.delete("/admin/delete_address/:id")
                    • L29 · api.delete("/admin/clear_inbox/:id")
                    • L30 · api.delete("/admin/clear_sent_items/:id")
                    • L31 · api.get("/admin/show_password/:id")
                    • L32 · api.post("/admin/address/:id/reset_password")
                    • L35 · api.get("/admin/mails")
                    • L36 · api.get("/admin/mails_unknow")
                    • L37 · api.get("/admin/mails/:id")
                    • L38 · api.delete("/admin/mails/:id")
                    • L41 · api.get("/admin/address_sender")
                    • L42 · api.post("/admin/address_sender")
                    • L43 · api.delete("/admin/address_sender/:id")
                    • L46 · api.get("/admin/sendbox")
                    • L47 · api.delete("/admin/sendbox/:id")
                    • L50 · api.get("/admin/statistics")
                    • L53 · api.get("/admin/account_settings")
                    • L54 · api.post("/admin/account_settings")
                    • L57 · api.post("/admin/cleanup")
                    • L58 · api.get("/admin/auto_cleanup")
                    • L59 · api.post("/admin/auto_cleanup")
                    • L62 · api.get("/admin/user_settings")
                    • L63 · api.post("/admin/user_settings")
                    • L64 · api.get("/admin/users")
                    • L65 · api.delete("/admin/users/:user_id")
                    • L66 · api.post("/admin/users")
                    • L67 · api.post("/admin/users/:user_id/reset_password")
                    • L68 · api.get("/admin/user_roles")
                    • L69 · api.post("/admin/user_roles")
                    • L70 · api.get("/admin/role_address_config")
                    • L71 · api.post("/admin/role_address_config")
                    • L72 · api.get("/admin/users/bind_address/:user_id")
                    • L73 · api.post("/admin/users/bind_address")
                    • L76 · api.get("/admin/user_oauth2_settings")
                    • L77 · api.post("/admin/user_oauth2_settings")
                    • L80 · api.get("/admin/webhook/settings")
                    • L81 · api.post("/admin/webhook/settings")
                    • L84 · api.get("/admin/mail_webhook/settings")
                    • L85 · api.post("/admin/mail_webhook/settings")
                    worker/src/admin_api/ip_blacklist_settings.ts ↗
                    • L10 · getIpBlacklistSettings calls (conditional paths may differ): getJsonSetting, c.json
                    • L31 · saveIpBlacklistSettings calls (conditional paths may differ): i18n.getMessagesbyContext, c.req.json, c.text, Array.isArray, Number, isNaN, filter, settings.blacklist.map, pattern.trim, settings.asnBlacklist.map, settings.fingerprintBlacklist.map, test, sanitizedWhitelist.push, saveSetting, JSON.stringify, c.json
                    worker/src/admin_api/mail_webhook_settings.ts ↗
                    • L9 · getWebhookSettings calls (conditional paths may differ): c.env.KV.get, c.json
                    • L16 · saveWebhookSettings calls (conditional paths may differ): c.req.json, c.env.KV.put, JSON.stringify, c.json
                    • L24 · testWebhookSettings calls (conditional paths may differ): i18n.getMessagesbyContext, catch, c.req.json, Array.isArray, c.text, Number.isSafeInteger, first, bind, c.env.DB.prepare, resolveRawEmail, commonParseMail, sendWebhook, getWebhookAttachments, c.json

                    Environment references: c.env.KV · c.env.DB · c.env.FRONTEND_URL

                    worker/src/admin_api/oauth2_settings.ts ↗
                    • L7 · getUserOauth2Settings calls (conditional paths may differ): getJsonSetting, c.json
                    • L12 · saveUserOauth2Settings calls (conditional paths may differ): c.req.json, c.text, saveSetting, JSON.stringify, c.json
                    worker/src/admin_api/send_mail.ts ↗

                      Environment references: c.env.SEND_MAIL

                      worker/src/admin_api/sendbox_api.ts ↗

                        Environment references: c.env.DB

                        worker/src/admin_api/statistics_api.ts ↗

                          Environment references: c.env.DB

                          worker/src/admin_api/webhook_settings.ts ↗
                          • L5 · getWebhookSettings calls (conditional paths may differ): c.env.KV.get, c.json
                          • L10 · saveWebhookSettings calls (conditional paths may differ): c.req.json, c.env.KV.put, JSON.stringify, c.json

                          Environment references: c.env.KV

                          worker/src/admin_api/worker_config.ts ↗

                            Environment references: c.env.DEFAULT_LANG · c.env.TITLE · c.env.ANNOUNCEMENT · c.env.ALWAYS_SHOW_ANNOUNCEMENT · c.env.PREFIX · c.env.ADDRESS_CHECK_REGEX · c.env.ADDRESS_REGEX · c.env.MIN_ADDRESS_LEN · c.env.MAX_ADDRESS_LEN · c.env.FORWARD_ADDRESS_LIST · c.env.SUBDOMAIN_FORWARD_ADDRESS_LIST · c.env.ENABLE_CREATE_ADDRESS_SUBDOMAIN_MATCH · c.env.RANDOM_SUBDOMAIN_LENGTH · c.env.DOMAIN_LABELS · c.env.JWT_SECRET · c.env.ADMIN_USER_ROLE · c.env.USER_DEFAULT_ROLE · c.env.NO_LIMIT_SEND_ROLE · c.env.ADMIN_CONTACT · c.env.ENABLE_USER_CREATE_EMAIL · c.env.DISABLE_ANONYMOUS_USER_CREATE_EMAIL · c.env.ENABLE_USER_DELETE_EMAIL · c.env.ENABLE_MAIL_READ_STATUS · c.env.ENABLE_REDEEM_CODE · c.env.REDEEM_CODE_URL · c.env.ENABLE_AUTO_REPLY · c.env.COPYRIGHT · c.env.ENABLE_WEBHOOK · c.env.DISABLE_SHOW_GITHUB · c.env.DISABLE_SHOW_GITHUB_FOR_USER · c.env.DISABLE_ADMIN_PASSWORD_CHECK · c.env.ENABLE_CHECK_JUNK_MAIL · c.env.JUNK_MAIL_CHECK_LIST · c.env.JUNK_MAIL_FORCE_PASS_LIST · c.env.REMOVE_EXCEED_SIZE_ATTACHMENT · c.env.REMOVE_ALL_ATTACHMENT · c.env.ENABLE_ANOTHER_WORKER

                            worker/src/commom_api.ts ↗
                            • L11 · api.get("/open_api/settings")
                            • L76 · api.get("/open_api/a/:mail_id/:index/:expires/:signature")

                            Environment references: c.env.SMTP_IMAP_PROXY_CONFIG · c.env.TITLE · c.env.ANNOUNCEMENT · c.env.ALWAYS_SHOW_ANNOUNCEMENT · c.env.PREFIX · c.env.ADDRESS_REGEX · c.env.MIN_ADDRESS_LEN · c.env.MAX_ADDRESS_LEN · c.env.DOMAIN_LABELS · c.env.ADMIN_CONTACT · c.env.ENABLE_USER_CREATE_EMAIL · c.env.DISABLE_ANONYMOUS_USER_CREATE_EMAIL · c.env.DISABLE_CUSTOM_ADDRESS_NAME · c.env.ENABLE_USER_DELETE_EMAIL · c.env.ENABLE_MAIL_READ_STATUS · c.env.ENABLE_AUTO_REPLY · c.env.ENABLE_INDEX_ABOUT · c.env.COPYRIGHT · c.env.CF_TURNSTILE_SITE_KEY · c.env.ENABLE_WEBHOOK · c.env.DISABLE_SHOW_GITHUB · c.env.DISABLE_SHOW_GITHUB_FOR_USER · c.env.DISABLE_ADMIN_PASSWORD_CHECK · c.env.ENABLE_ADDRESS_PASSWORD · c.env.ENABLE_AGENT_EMAIL_INFO · c.env.ENABLE_REDEEM_CODE · c.env.REDEEM_CODE_URL · c.env.STATUS_URL

                            worker/src/common.ts ↗
                            • L243 · updateAddressUpdatedAt calls (conditional paths may differ): getBooleanValue, c.executionCtx.waitUntil, run, bind, c.env.DB.prepare, console.warn
                            • L267 · updateUserAddressesUpdatedAt calls (conditional paths may differ): getBooleanValue, c.executionCtx.waitUntil, run, bind, c.env.DB.prepare, console.warn
                            • L838 · sendWebhook calls (conditional paths may differ): formatWebhookBody, fetch, JSON.parse, console.log
                            • L855 · triggerWebhook calls (conditional paths may differ): getBooleanValue, c.env.KV.get, webhookList.push, first, bind, c.env.DB.prepare, String, commonParseMail, webhookList.some, settings.body.includes, getWebhookAttachments, sendWebhook, console.error
                            • L923 · triggerAnotherWorker calls (conditional paths may differ): getAnotherWorkerList, getBooleanValue, parsedText.toLowerCase, console.log, keywords.some, parsedTextLowercase.includes, keyword.toLowerCase, bodyObj.headers.forEach, JSON.stringify, method, console.error

                            Environment references: c.env.RESEND_TOKEN · c.env.SMTP_CONFIG · c.env.SEND_MAIL · c.env.SEND_MAIL_DOMAINS · c.env.MIN_ADDRESS_LEN · c.env.MAX_ADDRESS_LEN · c.env.RANDOM_SUBDOMAIN_LENGTH · c.env.ENABLE_CREATE_ADDRESS_SUBDOMAIN_MATCH · c.env.ADDRESS_CHECK_REGEX · c.env.ADDRESS_REGEX · c.env.DISABLE_ADDRESS_UPDATED_AT · c.env.DB · c.env.ENABLE_ADDRESS_PASSWORD · c.env.PREFIX · c.env.CREATE_ADDRESS_DEFAULT_DOMAIN_FIRST · c.env.JWT_SECRET · c.env.CLEANUP_BATCH_SIZE · c.env.ENABLE_USER_DELETE_EMAIL · c.env.KV · c.env.ENABLE_WEBHOOK · c.env.FRONTEND_URL · c.env.ENABLE_ANOTHER_WORKER

                            worker/src/email/ai_extract.ts ↗
                            • L99 · extractWithCloudflareAI calls (conditional paths may differ): env.AI.run, JSON.parse
                            • L151 · saveExtractMetadata calls (conditional paths may differ): JSON.stringify, toISOString, run, bind, env.DB.prepare, console.error
                            • L171 · decodeHtmlEntities calls (conditional paths may differ): Number.isFinite, String.fromCodePoint, text.replace, entity.toLowerCase, normalized.startsWith, Number.parseInt, normalized.slice, decodeCodePoint
                            • L202 · htmlToTextForAi calls (conditional paths may differ): trim, replace, decodeHtmlEntities, html.replace
                            • L218 · getEmailContentForExtract calls (conditional paths may differ): htmlToTextForAi
                            • L230 · isAddressInAiAllowlist calls (conditional paths may differ): Array.isArray, settings.allowList.some, pattern.includes, replace, pattern.replace, test
                            • L258 · extractEmailInfo calls (conditional paths may differ): getBooleanValue, resolveExtractMode, console.error, getJsonSetting, isAddressInAiAllowlist, commonParseMail, getEmailContentForExtract, joinSubjectAndBody, extractCode, saveExtractMetadata, console.log, runLocalExtract, emailContent.substring, extractWithCloudflareAI

                            Environment references: env.AI_EXTRACT_MODEL · env.AI · env.DB · env.ENABLE_AI_EMAIL_EXTRACT · env.AI_EXTRACT_MODE

                            worker/src/email/auto_reply.ts ↗
                            • L10 · matchSender calls (conditional paths may differ): sourcePrefix.startsWith, sourcePrefix.endsWith, sourcePrefix.slice, regex.test, console.error, from.startsWith

                            Environment references: env.ENABLE_AUTO_REPLY · env.DB

                            worker/src/email/black_list.ts ↗

                              Environment references: env.BLACK_LIST · env.KV

                              worker/src/email/check_attachment.ts ↗

                                Environment references: env.REMOVE_ALL_ATTACHMENT · env.REMOVE_EXCEED_SIZE_ATTACHMENT

                                worker/src/email/check_junk.ts ↗

                                  Environment references: env.ENABLE_CHECK_JUNK_MAIL · env.JUNK_MAIL_CHECK_LIST · env.JUNK_MAIL_FORCE_PASS_LIST

                                  worker/src/email/extract_code.ts ↗
                                  • L150 · joinSubjectAndBody calls (conditional paths may differ): join, filter
                                  • L154 · extractCode calls (conditional paths may differ): normalizeText, text.slice, findCode, VERIFY_CONTEXT.test
                                  • L172 · normalizeText calls (conditional paths may differ): replace, text.replace, String.fromCharCode, ch.charCodeAt
                                  • L186 · findCode calls (conditional paths may differ): text.matchAll, find, match.slice, isPlausibleCode
                                  • L195 · isPlausibleCode calls (conditional paths may differ): test, looksLikeDate
                                  • L208 · looksLikeDate calls (conditional paths may differ): parseInt, digits.slice
                                  worker/src/email/extract_mode.ts ↗
                                  • L21 · resolveExtractMode calls (conditional paths may differ): toLowerCase, value.trim
                                  worker/src/email/forward.ts ↗
                                  • L13 · safeRegexTest calls (conditional paths may differ): console.warn, pattern.substring, regex.test, console.error
                                  • L31 · matchSourcePatterns calls (conditional paths may differ): sourcePatterns.every, safeRegexTest, sourcePatterns.some
                                  • L55 · forwardToGlobalAddresses calls (conditional paths may differ): getEnvStringList, message.forward, console.error
                                  • L72 · forwardByRules calls (conditional paths may differ): getJsonObjectValue, getJsonSetting, getMailDomain, matchSourcePatterns, rule.domains.map, normalizedDomains.some, message.forward, isDomainOrSubdomain, console.error
                                  • L132 · forwardEmail calls (conditional paths may differ): forwardToGlobalAddresses, forwardByRules

                                  Environment references: env.FORWARD_ADDRESS_LIST · env.SUBDOMAIN_FORWARD_ADDRESS_LIST

                                  worker/src/email/index.ts ↗
                                  • L17 · email calls (conditional paths may differ): normalizeAddressDomain, isBlocked, message.setReject, console.log, text, check_if_junk_mail, message.headers.get, console.error, getJsonSetting, first, bind, env.DB.prepare, remove_attachment_if_need, catch, then, storeRawMail, forwardEmail, extractEmailInfo, sendMailToTelegram, triggerWebhook

                                  Environment references: env.DB

                                  worker/src/email/storage.ts ↗

                                    Environment references: env.DB · env.ENABLE_MAIL_GZIP · env.ENABLE_MAIL_READ_STATUS

                                    worker/src/gzip.ts ↗
                                    • L8 · compressText calls (conditional paths may differ): pipeThrough, stream, arrayBuffer
                                    • L13 · decompressBlob calls (conditional paths may differ): pipeThrough, stream, text
                                    • L21 · resolveRawEmail calls (conditional paths may differ): decompressBlob, console.error
                                    • L37 · resolveRawEmailRow calls (conditional paths may differ): resolveRawEmail
                                    • L46 · resolveRawEmailList calls (conditional paths may differ): Promise.all, rows.map, resolveRawEmailRow
                                    worker/src/i18n/index.ts ↗

                                      Environment references: c.env.DEFAULT_LANG

                                      worker/src/ip_blacklist.ts ↗
                                      • L23 · looksLikeRegex calls (conditional paths may differ): test
                                      • L47 · isBlacklisted calls (conditional paths may differ): value.trim, blacklist.some, pattern.trim, looksLikeRegex, regex.test, normalizedValue.includes, includes, normalizedValue.toLowerCase, normalizedPattern.toLowerCase, console.warn
                                      • L93 · isWhitelisted calls (conditional paths may differ): value.trim, whitelist.some, pattern.trim, test, normalizedPattern.includes, looksLikeRegex, regex.test, console.warn
                                      • L144 · getIpBlacklistSettings calls (conditional paths may differ): getJsonSetting
                                      • L161 · checkIpWhitelist calls (conditional paths may differ): console.warn, c.text, isWhitelisted
                                      • L186 · checkFingerprintBlacklist calls (conditional paths may differ): c.req.raw.headers.get, isBlacklisted, console.warn, c.text
                                      • L204 · checkIpAsnBlacklist calls (conditional paths may differ): isBlacklisted, console.warn, c.text
                                      • L232 · checkDailyLimit calls (conditional paths may differ): slice, toISOString, parseInt, c.env.KV.get, console.warn, c.text, c.env.KV.put, toString
                                      • L264 · checkAccessControl calls (conditional paths may differ): getIpBlacklistSettings, c.req.raw.headers.get, checkIpWhitelist, checkFingerprintBlacklist, checkIpAsnBlacklist, checkDailyLimit, console.error

                                      Environment references: c.env.KV

                                      worker/src/mails_api/address_auth.ts ↗

                                        Environment references: c.env.ENABLE_ADDRESS_PASSWORD · c.env.DB · c.env.JWT_SECRET

                                        worker/src/mails_api/auto_reply.ts ↗

                                          Environment references: c.env.ENABLE_AUTO_REPLY · c.env.DB

                                          worker/src/mails_api/index.ts ↗
                                          • L14 · api.get("/api/auto_reply")
                                          • L15 · api.post("/api/auto_reply")
                                          • L18 · api.get("/api/webhook/settings")
                                          • L19 · api.post("/api/webhook/settings")
                                          • L20 · api.post("/api/webhook/test")
                                          • L23 · api.get("/api/attachment/list")
                                          • L24 · api.post("/api/attachment/delete")
                                          • L25 · api.post("/api/attachment/put_url")
                                          • L26 · api.post("/api/attachment/get_url")
                                          • L29 · api.get("/api/mails")
                                          • L30 · api.get("/api/mail/:mail_id")
                                          • L31 · api.delete("/api/mails/:id")
                                          • L32 · api.patch("/api/mails/:id/read")
                                          • L35 · api.get("/api/parsed_mails")
                                          • L36 · api.get("/api/parsed_mail/:mail_id")
                                          • L39 · api.get("/api/settings")
                                          • L40 · api.post("/api/new_address")
                                          • L41 · api.delete("/api/delete_address")
                                          • L42 · api.delete("/api/clear_inbox")
                                          • L43 · api.delete("/api/clear_sent_items")
                                          • L46 · api.post("/api/address_change_password")
                                          • L47 · api.post("/api/address_login")
                                          worker/src/mails_api/mails_crud.ts ↗

                                            Environment references: c.env.ENABLE_MAIL_READ_STATUS · c.env.DB · c.env.ENABLE_USER_DELETE_EMAIL

                                            worker/src/mails_api/new_address.ts ↗

                                              Environment references: c.env.DISABLE_ANONYMOUS_USER_CREATE_EMAIL · c.env.ENABLE_USER_CREATE_EMAIL · c.env.DISABLE_CUSTOM_ADDRESS_NAME

                                              worker/src/mails_api/parsed_mail_api.ts ↗

                                                Environment references: c.env.DB

                                                worker/src/mails_api/s3_attachment.ts ↗

                                                  Environment references: c.env.S3_ENDPOINT · c.env.S3_ACCESS_KEY_ID · c.env.S3_SECRET_ACCESS_KEY · c.env.S3_BUCKET · c.env.S3_URL_EXPIRES

                                                  worker/src/mails_api/send_balance.ts ↗

                                                    Environment references: c.env.DEFAULT_SEND_BALANCE · c.env.DB · c.env.NO_LIMIT_SEND_ROLE

                                                    worker/src/mails_api/send_mail_api.ts ↗
                                                    • L18 · api.post("/api/request_send_mail_access")
                                                    • L251 · api.post("/api/send_mail")
                                                    • L263 · api.post("/external/api/send_mail")
                                                    • L291 · api.get("/api/sendbox")
                                                    • L297 · api.delete("/api/sendbox/:id")

                                                    Environment references: c.env.SEND_MAIL · c.env.RESEND_TOKEN · c.env.SMTP_CONFIG · c.env.DB · c.env.ENABLE_USER_DELETE_EMAIL

                                                    worker/src/mails_api/webhook_settings.ts ↗
                                                    • L10 · getWebhookSettings calls (conditional paths may differ): i18n.getMessagesbyContext, c.get, c.env.KV.get, c.text, c.json
                                                    • L24 · saveWebhookSettings calls (conditional paths may differ): i18n.getMessagesbyContext, c.get, c.env.KV.get, c.text, c.req.json, c.env.KV.put, JSON.stringify, c.json
                                                    • L38 · testWebhookSettings calls (conditional paths may differ): i18n.getMessagesbyContext, catch, c.req.json, Array.isArray, c.text, Number.isSafeInteger, c.get, first, bind, c.env.DB.prepare, resolveRawEmail, commonParseMail, sendWebhook, getWebhookAttachments, c.json

                                                    Environment references: c.env.KV · c.env.DB · c.env.FRONTEND_URL

                                                    worker/src/open_api/auth.ts ↗
                                                    • L10 · api.post("/open_api/site_login")
                                                    • L28 · api.post("/open_api/admin_login")
                                                    • L46 · api.post("/open_api/credential_login")
                                                    worker/src/open_api/webhook_attachment.ts ↗

                                                      Environment references: c.env.ENABLE_WEBHOOK · c.env.DB · c.env.JWT_SECRET

                                                      worker/src/redeem_api/index.ts ↗
                                                      • L9 · api.use("/redeem_api/*")
                                                      • L10 · api.post("/redeem_api/query")
                                                      • L11 · api.post("/redeem_api/result")
                                                      • L12 · api.post("/redeem_api/redeem")
                                                      worker/src/redeem_api/redeem_code.ts ↗

                                                        Environment references: c.env.JWT_SECRET · c.env.ADMIN_USER_ROLE · c.env.MAX_ADDRESS_LEN · c.env.DB · c.env.ENABLE_REDEEM_CODE · c.env.USER_DEFAULT_ROLE · c.env.DISABLE_CUSTOM_ADDRESS_NAME

                                                        worker/src/redeem_api/redeem_code_query.ts ↗

                                                          Environment references: c.env.DB

                                                          worker/src/redeem_api/redeem_result_query.ts ↗

                                                            Environment references: c.env.DB

                                                            worker/src/scheduled.ts ↗
                                                            • L8 · scheduled calls (conditional paths may differ): console.log, getJsonSetting, JSON.stringify, cleanup, executeCustomSqlCleanup, console.error
                                                            worker/src/telegram_api/common.ts ↗

                                                              Environment references: c.env.RATE_LIMITER · c.env.DISABLE_CUSTOM_ADDRESS_NAME · c.env.KV · c.env.TG_MAX_ADDRESS · c.env.JWT_SECRET

                                                              worker/src/telegram_api/index.ts ↗
                                                              • L13 · api.use("/telegram/*")
                                                              • L24 · api.use("/admin/telegram/*")
                                                              • L35 · api.post("/telegram/webhook")
                                                              • L50 · api.post("/admin/telegram/init")
                                                              • L63 · api.get("/admin/telegram/status")
                                                              • L71 · api.get("/admin/telegram/settings")
                                                              • L72 · api.post("/admin/telegram/settings")
                                                              • L73 · api.post("/telegram/get_bind_address")
                                                              • L74 · api.post("/telegram/new_address")
                                                              • L75 · api.post("/telegram/bind_address")
                                                              • L76 · api.post("/telegram/unbind_address")
                                                              • L77 · api.post("/telegram/get_mail")

                                                              Environment references: c.env.TELEGRAM_BOT_TOKEN · c.env.KV

                                                              worker/src/telegram_api/miniapp.ts ↗
                                                              • L63 · getTelegramBindAddress calls (conditional paths may differ): c.req.json, checkTelegramAuth, c.env.KV.get, verifyAddressToken, res.push, console.error, c.json, c.text
                                                              • L86 · newTelegramAddress calls (conditional paths may differ): c.req.json, i18n.getMessagesbyContext, checkCfTurnstile, c.text, checkTelegramAuth, tgUserNewAddress, getBooleanValue, c.json
                                                              • L112 · bindAddress calls (conditional paths may differ): c.req.json, i18n.getMessagesbyContext, checkTelegramAuth, bindTelegramAddress, c.json, c.text
                                                              • L125 · unbindAddress calls (conditional paths may differ): c.req.json, checkTelegramAuth, unbindTelegramAddress, c.json, c.text
                                                              • L137 · getMail calls (conditional paths may differ): c.req.json, i18n.getMessagesbyContext, checkIsAdmin, first, bind, c.env.DB.prepare, c.text, c.json, resolveRawEmailRow, checkTelegramAuth, c.env.KV.get, jwtListToAddressData

                                                              Environment references: c.env.TELEGRAM_BOT_TOKEN · c.env.KV · c.env.DB

                                                              worker/src/telegram_api/settings.ts ↗
                                                              • L23 · getTelegramSettings calls (conditional paths may differ): c.env.KV.get, c.json
                                                              • L29 · saveTelegramSettings calls (conditional paths may differ): c.req.json, c.env.KV.put, JSON.stringify, c.json

                                                              Environment references: c.env.KV

                                                              worker/src/telegram_api/telegram.ts ↗
                                                              • L134 · newTelegramBot calls (conditional paths may differ): getJsonObjectValue, bot.use, getTgMessages, ctx.reply, c.env.KV.get, settings.allowList.includes, userId.toString, next, console.error, bot.command, trimLower, getDomains, getTelegramCommands, JSON.stringify, join, commands.map, tgUserNewAddress, bindTelegramAddress, unbindTelegramAddress, deleteTelegramAddress
                                                              • L429 · initTelegramBotCommands calls (conditional paths may differ): bot.telegram.setMyCommands, getTelegramCommands
                                                              • L467 · sendMailToTelegram calls (conditional paths may differ): c.env.KV.get, first, bind, c.env.DB.prepare, newTelegramBot, parseMail, toUTCString, url.searchParams.set, buttons.push, Markup.button.webApp, url.toString, bot.telegram.sendMessage, Markup.inlineKeyboard, getBooleanValue, sendTelegramAttachments, i18n.getMessages, buildAndSend, getTgMessages

                                                              Environment references: c.env.TG_ALLOW_USER_LANG · c.env.DEFAULT_LANG · c.env.KV · c.env.TG_BOT_INFO · c.env.PREFIX · c.env.DB · c.env.TELEGRAM_BOT_TOKEN · c.env.ENABLE_TG_PUSH_ATTACHMENT

                                                              worker/src/telegram_api/tg_file_upload.ts ↗
                                                              • L3 · sendTelegramAttachments calls (conditional paths may differ): attachments.filter, console.log, toFixed, validAttachments.slice, media.push, formData.append, JSON.stringify, fetch, res.text, console.error, text.substring
                                                              worker/src/user_api/bind_address.ts ↗

                                                                Environment references: c.env.DB · c.env.JWT_SECRET

                                                                worker/src/user_api/index.ts ↗
                                                                • L14 · api.get("/user_api/open_settings")
                                                                • L15 · api.get("/user_api/settings")
                                                                • L18 · api.get("/user_api/mails")
                                                                • L19 · api.delete("/user_api/mails/:id")
                                                                • L22 · api.get("/user_api/address/:address_id/settings")
                                                                • L23 · api.post("/user_api/address/:address_id/request_send_mail_access")
                                                                • L24 · api.post("/user_api/address/:address_id/send_mail")
                                                                • L25 · api.get("/user_api/sendbox")
                                                                • L26 · api.delete("/user_api/sendbox/:mail_id")
                                                                • L29 · api.post("/user_api/login")
                                                                • L30 · api.post("/user_api/verify_code")
                                                                • L31 · api.post("/user_api/register")
                                                                • L34 · api.get("/user_api/oauth2/login_url")
                                                                • L35 · api.post("/user_api/oauth2/callback")
                                                                • L38 · api.get("/user_api/bind_address")
                                                                • L39 · api.post("/user_api/bind_address")
                                                                • L40 · api.get("/user_api/bind_address_jwt/:address_id")
                                                                • L41 · api.post("/user_api/unbind_address")
                                                                • L42 · api.post("/user_api/transfer_address")
                                                                • L45 · api.get("/user_api/passkey")
                                                                • L46 · api.post("/user_api/passkey/rename")
                                                                • L47 · api.delete("/user_api/passkey/:passkey_id")
                                                                • L48 · api.post("/user_api/passkey/register_request")
                                                                • L49 · api.post("/user_api/passkey/register_response")
                                                                • L50 · api.post("/user_api/passkey/authenticate_request")
                                                                • L51 · api.post("/user_api/passkey/authenticate_response")
                                                                worker/src/user_api/oauth2.ts ↗

                                                                  Environment references: c.env.DB · c.env.USER_DEFAULT_ROLE · c.env.JWT_SECRET

                                                                  worker/src/user_api/passkey.ts ↗

                                                                    Environment references: c.env.DB · c.env.JWT_SECRET · c.env.TITLE

                                                                    worker/src/user_api/settings.ts ↗

                                                                      Environment references: c.env.DB · c.env.ADMIN_USER_ROLE · c.env.JWT_SECRET

                                                                      worker/src/user_api/user.ts ↗

                                                                        Environment references: c.env.KV · c.env.DB · c.env.USER_DEFAULT_ROLE · c.env.JWT_SECRET

                                                                        worker/src/user_api/user_mail_api.ts ↗

                                                                          Environment references: c.env.ENABLE_USER_DELETE_EMAIL · c.env.DB

                                                                          worker/src/user_api/user_send_mail_api.ts ↗

                                                                            Environment references: c.env.ENABLE_USER_DELETE_EMAIL · c.env.DB

                                                                            worker/src/utils.ts ↗

                                                                              Environment references: c.env.DB · c.env.DEFAULT_DOMAINS · c.env.DOMAINS · c.env.RANDOM_SUBDOMAIN_DOMAINS · c.env.USER_ROLES · c.env.ANOTHER_WORKER_LIST · c.env.PASSWORDS · c.env.ADMIN_PASSWORDS · c.env.ENABLE_GLOBAL_TURNSTILE_CHECK · c.env.CF_TURNSTILE_SITE_KEY · c.env.CF_TURNSTILE_SECRET_KEY

                                                                              worker/src/utils/webhook.ts ↗

                                                                                Environment references: env.BACKEND_URL · env.JWT_SECRET

                                                                                worker/src/worker.ts ↗
                                                                                • L317 · fetch handler exported
                                                                                • L318 · email handler exported
                                                                                • L319 · scheduled handler exported
                                                                                • L34 · app.use("/*")
                                                                                • L41 · app.use("/*")
                                                                                • L158 · app.use("/api/*")
                                                                                • L185 · app.use("/user_api/*")
                                                                                • L232 · app.use("/admin/*")
                                                                                • L287 · app.route("/")
                                                                                • L288 · app.route("/")
                                                                                • L289 · app.route("/")
                                                                                • L290 · app.route("/")
                                                                                • L291 · app.route("/")
                                                                                • L292 · app.route("/")
                                                                                • L293 · app.route("/")
                                                                                • L294 · app.route("/")
                                                                                • L311 · app.get("/")
                                                                                • L312 · app.get("/health_check")
                                                                                • L313 · app.all("/*")

                                                                                Environment references: c.env.ASSETS · c.env.DEFAULT_LANG · c.env.RATE_LIMITER · c.env.KV · c.env.ENABLE_WEBHOOK · c.env.DB · c.env.JWT_SECRET · c.env.ADMIN_API_IP_WHITELIST · c.env.ADMIN_USER_ROLE · c.env.DISABLE_ADMIN_PASSWORD_CHECK

                                                                                Build and deployment pipeline · 9 GitHub Actions workflows

                                                                                Repository CI declarations, separate from runtime request processing. Job dependencies and conditions are shown as written; long commands are shortened with an ellipsis; a workflow file does not prove a recent successful run.

                                                                                Deploy Backend · .github/workflows/backend_deploy.yaml ↗

                                                                                Triggers: workflow_run, push, workflow_dispatch

                                                                                deploy · no job dependencies declared

                                                                                1. Checkoutactions/checkout@v6
                                                                                2. Install Node.jsactions/setup-node@v6
                                                                                3. Install pnpmpnpm/action-setup@v5
                                                                                4. Deploy Backend for ${{ github.ref_name }}export use_worker_assets=${{ secrets.USE_WORKER_ASSETS }} export use_worker_assets_with_telegram=${{ secrets.USE_WORKER_ASSETS_WITH_TELEGRAM }} if [ -n "$use_worker_assets" ]; then cd frontend/ pnpm install --no-frozen-lockfile if [ -n "$use_worker_assets_with_telegram" ]; then echo "Building with telegram pages" pnpm build:telegram:pages else echo "Building with normal pages" pnpm build:pages fi cd .. fi export debug_mode=${{ secrets.DEBUG_MODE }} export use_mail_wasm_parser=${{ secrets.BACKEN…
                                                                                Deploy Docs · .github/workflows/docs_deploy.yml ↗

                                                                                Triggers: workflow_run, workflow_dispatch

                                                                                deploy · no job dependencies declared

                                                                                Condition: github.event_name == 'workflow_dispatch' || (github.event.workflow_run.conclusion == 'success' && startsWith(github.event.workflow_run.head_branch, 'v'))

                                                                                1. Checkoutactions/checkout@v6
                                                                                2. Install Node.jsactions/setup-node@v6
                                                                                3. Install pnpmpnpm/action-setup@v5
                                                                                4. Deploy Docscd vitepress-docs/ wget https://github.com/dreamhunter2333/cloudflare_temp_email/releases/latest/download/frontend.zip -O docs/public/ui_install/frontend.zip pnpm install --no-frozen-lockfile if TAG_NAME=$(gh release view --json tagName --jq '.tagName' 2>/dev/null); then echo "Using release tag $TAG_NAME" else TAG_NAME="${WORKFLOW_RUN_HEAD_BRANCH:-${GITHUB_REF_NAME:-main}}" echo "No GitHub release found for this repo; fallback TAG_NAME=$TAG_NAME" fi echo "Deploying docs for tag $TAG_NAME" expor…
                                                                                End-to-End Tests · .github/workflows/e2e.yml ↗

                                                                                Triggers: pull_request, workflow_dispatch

                                                                                e2e · no job dependencies declared

                                                                                1. actions/checkout@v6actions/checkout@v6
                                                                                2. Run E2E testscd e2e docker compose up --build --abort-on-container-exit --exit-code-from e2e-runner
                                                                                3. Upload test resultsactions/upload-artifact@v6Condition: always()
                                                                                4. Cleanupcd e2e docker compose down -vCondition: always()
                                                                                Deploy Frontend · .github/workflows/frontend_deploy.yaml ↗

                                                                                Triggers: workflow_run, push, workflow_dispatch

                                                                                deploy-frontend · no job dependencies declared

                                                                                1. Checkoutactions/checkout@v6
                                                                                2. Install Node.jsactions/setup-node@v6
                                                                                3. Install pnpmpnpm/action-setup@v5
                                                                                4. Deploy Frontend for ${{ github.ref_name }}cd frontend/ echo "${{ secrets.FRONTEND_ENV }}" > .env.prod pnpm install --no-frozen-lockfile export frontend_branch="${{ secrets.FRONTEND_BRANCH }}" if [ -n "$frontend_branch" ]; then echo "Deploying branch $frontend_branch" pnpm run deploy:actions --project-name=$FRONTEND_NAME --branch $frontend_branch else echo "Deploying branch production" pnpm run deploy --project-name=$FRONTEND_NAME fi echo "Deployed for tag ${{ github.ref_name }}"Condition: ${{ env.FRONTEND_NAME != '' }}

                                                                                deploy-telegram-frontend · no job dependencies declared

                                                                                1. Checkoutactions/checkout@v6
                                                                                2. Install Node.jsactions/setup-node@v6
                                                                                3. Install pnpmpnpm/action-setup@v5
                                                                                4. Deploy Telegram Frontend for ${{ github.ref_name }}cd frontend/ echo "${{ secrets.FRONTEND_ENV }}" > .env.prod pnpm install --no-frozen-lockfile export frontend_branch="${{ secrets.FRONTEND_BRANCH }}" if [ -n "$frontend_branch" ]; then echo "Deploying telegram mini app branch $frontend_branch" pnpm run deploy:actions:telegram --project-name=$TG_FRONTEND_NAME --branch $frontend_branch else echo "Deploying telegram mini app branch production" pnpm run deploy:telegram --project-name=$TG_FRONTEND_NAME fi echo "Deployed telegram mini app for ${{ git…Condition: ${{ env.TG_FRONTEND_NAME != '' }}
                                                                                Deploy Frontend with page function · .github/workflows/frontend_pagefunction_deploy.yaml ↗

                                                                                Triggers: workflow_run, push, workflow_dispatch

                                                                                check · no job dependencies declared

                                                                                1. Check PAGE_TOMLif [ -n "$PAGE_TOML" ]; then echo "has_config=true" >> $GITHUB_OUTPUT else echo "has_config=false" >> $GITHUB_OUTPUT fi

                                                                                deploy · after check

                                                                                Condition: ${{ needs.check.outputs.has_config == 'true' }}

                                                                                1. Checkoutactions/checkout@v6
                                                                                2. Install Node.jsactions/setup-node@v6
                                                                                3. Install pnpmpnpm/action-setup@v5
                                                                                4. Deploy Frontend for ${{ github.ref_name }}cd frontend/ pnpm install --no-frozen-lockfile pnpm build:pages cd ../pages/ echo '${{ secrets.PAGE_TOML }}' > wrangler.toml pnpm install --no-frozen-lockfile pnpm run deploy echo "Deploying production for ${{ github.ref_name }}"
                                                                                Codium PR Agent · .github/workflows/pr_agent.yml ↗

                                                                                Triggers: pull_request, issue_comment

                                                                                Run pr agent on every pull request, respond to user comments · no job dependencies declared

                                                                                Condition: ${{ github.event.sender.type != 'Bot' }}

                                                                                1. PR Agent action stepqodo-ai/pr-agent@main
                                                                                SMTP Proxy Server Docker Image CI · .github/workflows/smtp_proxy_server.yml ↗

                                                                                Triggers: push, workflow_dispatch

                                                                                build-and-push-image · no job dependencies declared

                                                                                1. actions/checkout@v6actions/checkout@v6
                                                                                2. Log in to the Container registrydocker/login-action@v4
                                                                                3. Set up QEMUdocker/setup-qemu-action@v4
                                                                                4. Set up Docker Buildxdocker/setup-buildx-action@v4
                                                                                5. Set lowercase repository nameecho "REPO_LOWER=${GITHUB_REPOSITORY,,}" >> $GITHUB_ENV
                                                                                6. Build and push Docker imagesdocker/build-push-action@v7
                                                                                Upstream Sync · .github/workflows/sync.yaml ↗

                                                                                Triggers: schedule, workflow_dispatch

                                                                                Sync latest commits from upstream repo · no job dependencies declared

                                                                                Condition: ${{ github.event.repository.fork }}

                                                                                1. Sync upstream changesgh repo sync ${{ github.repository }} --source dreamhunter2333/cloudflare_temp_email --branch main
                                                                                Tag Build CI · .github/workflows/tag_build.yml ↗

                                                                                Triggers: push

                                                                                build-frontend · no job dependencies declared

                                                                                1. Checkoutactions/checkout@v6
                                                                                2. Install Node.jsactions/setup-node@v6
                                                                                3. Install pnpmpnpm/action-setup@v5
                                                                                4. Build Frontendcd frontend && pnpm install --no-frozen-lockfile && pnpm build:release
                                                                                5. Zip Frontend distcd frontend/dist/ && zip -r frontend.zip * && mv frontend.zip ../
                                                                                6. Upload artifactactions/upload-artifact@v7

                                                                                build-telegram-frontend · no job dependencies declared

                                                                                1. Checkoutactions/checkout@v6
                                                                                2. Install Node.jsactions/setup-node@v6
                                                                                3. Install pnpmpnpm/action-setup@v5
                                                                                4. Build Telegram Frontendcd frontend && pnpm install --no-frozen-lockfile && pnpm build:telegram:release
                                                                                5. Zip Telegram Frontend distcd frontend/dist/ && zip -r telegram-frontend.zip * && mv telegram-frontend.zip ../
                                                                                6. Upload artifactactions/upload-artifact@v7

                                                                                build-backend · no job dependencies declared

                                                                                1. Checkoutactions/checkout@v6
                                                                                2. Install Node.jsactions/setup-node@v6
                                                                                3. Install pnpmpnpm/action-setup@v5
                                                                                4. cp wrangler.tomlcd worker && cp wrangler.toml.template wrangler.toml
                                                                                5. Build Backendcd worker && pnpm install --no-frozen-lockfile && pnpm build
                                                                                6. Move worker.jscd worker/dist && mv worker.js ../
                                                                                7. Build Worker with wasm mail parsercd worker echo "Using mail-parser-wasm-worker" pnpm add mail-parser-wasm-worker git apply ../.github/config/mail-parser-wasm-worker.patch echo "Applied mail-parser-wasm-worker patch" pnpm build zip -r worker-with-wasm-mail-parser.zip dist/worker.js dist/*.wasm
                                                                                8. Upload worker.jsactions/upload-artifact@v7
                                                                                9. Upload wasm workeractions/upload-artifact@v7

                                                                                release · after build-frontend, build-telegram-frontend, build-backend

                                                                                1. Checkoutactions/checkout@v6
                                                                                2. Download all artifactsactions/download-artifact@v8
                                                                                3. Upload Assets to Releasegh release upload "${{ github.ref_name }}" \ artifacts/frontend/frontend.zip \ artifacts/telegram-frontend/telegram-frontend.zip \ artifacts/worker-js/worker.js \ artifacts/worker-wasm/worker-with-wasm-mail-parser.zip \ --clobber
                                                                                frontend/package.json ↗
                                                                                • build: vite build -m prod --emptyOutDir
                                                                                • build:release: vite build -m example --emptyOutDir
                                                                                • build:pages: vite build -m pages --emptyOutDir
                                                                                • build:pages:nopwa: VITE_PWA_DISABLED=true vite build -m pages --emptyOutDir
                                                                                • build:telegram: VITE_IS_TELEGRAM=true vite build -m prod --emptyOutDir
                                                                                • build:telegram:pages: VITE_IS_TELEGRAM=true vite build -m pages --emptyOutDir
                                                                                • build:telegram:release: VITE_IS_TELEGRAM=true vite build -m example --emptyOutDir
                                                                                • deploy:telegram: npm run build:telegram && wrangler pages deploy ./dist --branch production
                                                                                • deploy:actions:telegram: npm run build:telegram && wrangler pages deploy ./dist
                                                                                • deploy:preview: npm run build && wrangler pages deploy ./dist --branch preview
                                                                                • deploy: npm run build && wrangler pages deploy ./dist --branch production
                                                                                • deploy:actions: npm run build && wrangler pages deploy ./dist
                                                                                pages/package.json ↗
                                                                                • deploy: wrangler pages deploy --branch production
                                                                                vitepress-docs/package.json ↗
                                                                                • build: vitepress build docs
                                                                                • deploy: npm run build && wrangler pages deploy ./docs/.vitepress/dist --project-name=temp-mail-docs --branch production
                                                                                worker/package.json ↗
                                                                                • deploy: wrangler deploy --minify
                                                                                • build: wrangler deploy --dry-run --outdir dist --minify

                                                                                Full upstream document by @dreamhunter2333 · README.md · snapshot be7ba25

                                                                                Cloudflare 临时邮箱 - 免费搭建临时邮件服务

                                                                                docs MIT License GitHub contributors GitHub top language

                                                                                Featured|HelloGitHub

                                                                                中文文档 | English Document | 日本語ドキュメント

                                                                                本项目仅供学习和个人用途,请勿将其用于任何违法行为,否则后果自负。

                                                                                一个功能完整的临时邮箱服务!

                                                                                • 完全免费 - 基于 Cloudflare 免费服务构建,零成本运行
                                                                                • 高性能 - Rust WASM 邮件解析,响应速度极快
                                                                                • 现代化界面 - 响应式设计,支持多语言,操作简便
                                                                                • 地址密码 - 支持为邮箱地址设置独立密码,增强安全性
                                                                                • Agent 友好 - 内置邮箱 skill,方便 AI agent 使用邮箱
                                                                                • 移动端管理 - 社区客户端 CloudMail,支持 Android 管理后台和邮箱管理

                                                                                部署文档 - 快速开始

                                                                                部署文档 | Github Action 部署文档

                                                                                Deploy to Cloudflare Workers

                                                                                更新日志

                                                                                查看 CHANGELOG 了解最新更新内容。

                                                                                在线体验

                                                                                立即体验 → https://mail.awsl.uk/

                                                                                服务状态监控(点击收缩/展开)
                                                                                Backend Deploy Backend Production
                                                                                Frontend Deploy Frontend
                                                                                Star History(点击收缩/展开) Star History Chart
                                                                                目录(点击收缩/展开)

                                                                                核心功能

                                                                                核心功能详情(点击收缩/展开)
                                                                                邮件处理
                                                                                • 使用 rust wasm 解析邮件,解析速度快,几乎所有邮件都能解析,node 的解析模块解析邮件失败的邮件,rust wasm 也能解析成功
                                                                                • AI 邮件识别 - 使用 Cloudflare Workers AI 自动提取邮件中的验证码、认证链接、服务链接等重要信息
                                                                                • 支持为指定基础域名创建随机二级域名邮箱地址,更适合收件隔离场景
                                                                                • 支持发送邮件,支持 DKIM 验证
                                                                                • 支持 SMTP 和 Resend 等多种发送方式
                                                                                • 增加查看 附件 功能,支持附件图片显示
                                                                                • 支持 S3 附件存储和删除功能
                                                                                • 垃圾邮件检测和黑白名单配置
                                                                                • 邮件转发功能,支持全局转发地址
                                                                                用户管理
                                                                                • 使用 凭证 重新登录之前的邮箱
                                                                                • 添加完整的用户注册登录功能,可绑定邮箱地址,绑定后可自动获取邮箱JWT凭证切换不同邮箱
                                                                                • 支持 OAuth2 第三方登录(Github、Authentik 等)
                                                                                • 支持 Passkey 无密码登录
                                                                                • 用户角色管理,支持多角色域名和前缀配置
                                                                                • 用户收件箱查看,支持地址和关键词过滤
                                                                                管理功能
                                                                                • 完整的 admin 控制台
                                                                                • admin 后台创建无前缀邮箱
                                                                                • admin 用户管理页面,增加用户地址查看功能
                                                                                • 定时清理功能,支持多种清理策略
                                                                                • 获取自定义名字的邮箱,admin 可配置黑名单
                                                                                • 增加访问密码,可作为私人站点
                                                                                多语言与界面
                                                                                • 前后台均支持多语言
                                                                                • 现代化 UI 设计,支持响应式布局
                                                                                • 支持 Google Ads 集成
                                                                                • 使用 shadow DOM 防止样式污染
                                                                                • 支持 URL JWT 参数自动登录
                                                                                集成与扩展
                                                                                • 完整的 Telegram Bot 支持,以及 Telegram 推送,Telegram Bot 小程序
                                                                                • 添加 SMTP proxy server,支持 SMTP 发送邮件,IMAP 查看邮件
                                                                                • Webhook 支持,消息推送集成
                                                                                • 支持 CF Turnstile 人机验证
                                                                                • 限流配置,防止滥用
                                                                                • Agent 友好:内置 cf-temp-mail-agent-mail skill,AI agent 可直接消费邮箱,详见 文档
                                                                                • 社区移动端管理客户端:CloudMail 基于 Expo / React Native,面向本项目兼容 API,提供 Android 管理员后台、地址管理、收件/发件/未知邮件、验证码快捷复制、OLED 黑主题和本地分组。

                                                                                技术架构

                                                                                技术架构详情(点击收缩/展开)
                                                                                系统架构
                                                                                • 数据库: Cloudflare D1 作为主数据库
                                                                                • 前端部署: 使用 Cloudflare Pages 部署前端
                                                                                • 后端部署: 使用 Cloudflare Workers 部署后端
                                                                                • 邮件转发: 使用 Cloudflare Email Routing
                                                                                技术栈
                                                                                • 前端: Vue 3 + Vite + TypeScript
                                                                                • 后端: TypeScript + Cloudflare Workers
                                                                                • 邮件解析: Rust WASM (mail-parser-wasm)
                                                                                • 数据库: Cloudflare D1 (SQLite)
                                                                                • 存储: Cloudflare KV + R2 (可选 S3)
                                                                                • 代理服务: Python SMTP/IMAP Proxy Server
                                                                                主要组件
                                                                                • Worker: 核心后端服务
                                                                                • Frontend: Vue 3 用户界面
                                                                                • Mail Parser WASM: Rust 邮件解析模块
                                                                                • SMTP Proxy Server: Python 邮件代理服务
                                                                                • Pages Functions: Cloudflare Pages 中间件
                                                                                • Documentation: VitePress 文档站点
                                                                                提醒
                                                                                • 在Resend添加域名记录时,如果您域名解析服务商正在托管您的3级域名a.b.com,请删除Resend生成的默认name中二级域名前缀b,否则将会添加a.b.b.com,导致验证失败。添加记录后,可通过
                                                                                nslookup -qt="mx" a.b.com 1.1.1.1
                                                                                

                                                                                进行验证。

                                                                                加入社区

                                                                                Frequently asked about Cloudflare Temp Email

                                                                                What is Cloudflare Temp Email?+

                                                                                Cloudflare Temp Email is a self-hosted Temp Mail alternative built on the Cloudflare developer platform. Run temporary inboxes on your own domain, with a Vue client and Cloudflare Email Routing backend.

                                                                                What does Cloudflare Temp Email replace?+

                                                                                Cloudflare Temp Email is listed as an alternative to Temp Mail. Compare the features and tradeoffs before migrating.

                                                                                What Cloudflare primitives does Cloudflare Temp Email use?+

                                                                                Cloudflare Temp Email is built on D1, Email Workers, Pages, Workers.

                                                                                How much does Cloudflare Temp Email cost to run?+

                                                                                Small inbound-only temporary inboxes can fit Cloudflare Workers/Pages and D1 Free allowances. A domain and Email Routing setup are required. Arbitrary-recipient outbound mail through Cloudflare requires Workers Paid; optional providers and features have separate costs. This is source-reviewed eligibility, not a tested deployment. Workers Free has 100,000 requests per day shared across the account and 10 ms CPU per invocation. Measure CPU-heavy parsing, authentication and rendering; this review is not a load test. D1 Free has 5 million rows read/day, 100,000 rows written/day and 5 GB total storage. Queries, polling, indexes and retained data consume allowances. Provision and migrate your own database. Pages Functions share Workers request and CPU allowances. The selected Pages configuration connects its BACKEND service binding to cloudflare_temp_email; build and deploy the backend and frontend separately. You need a domain whose DNS is on Cloudflare, Email Routing DNS records, a verified destination and catch-all routing to the Worker. Domain registration is a separate cost; a Worker URL alone cannot receive mail. Replace JWT_SECRET = "xxx" with a strong private signing secret, configure administrator passwords and keep DISABLE_ADMIN_PASSWORD_CHECK off. Optional site passwords, Turnstile and creation controls should match your privacy and abuse requirements. The selected Worker template has D1 enabled. KV, Workers AI, send_email, cron and static assets are commented examples; they are not required active bindings in this baseline. Enable KV for features that require it, such as registration email verification, Telegram and webhooks. AI extraction, S3/R2 attachments, OAuth and Resend require their own resources, credentials and cost review. Inbound Email Routing is available on Workers Free; its processing consumes Worker quotas. Cloudflare sending to arbitrary recipients requires Workers Paid. Sending to verified account destinations has separate free compatibility rules. The optional Python SMTP/IMAP proxy runs outside this Cloudflare Worker deployment. Its server cost is not included in the free baseline. No domain, catch-all rule, mailbox, sending key or login was provisioned or tested. The upstream README is displayed in full, including its broader free-service claims; this hosting assessment narrows those claims to the inbound baseline. Check current Cloudflare pricing before deploying.

                                                                                Is Cloudflare Temp Email open source?+

                                                                                The upstream repository declares the MIT license. Read its terms at https://raw.githubusercontent.com/dreamhunter2333/cloudflare_temp_email/be7ba25a574edbf567f57d1f97b21cb200ee84b9/LICENSE. Source code and contributor credit are available at https://github.com/dreamhunter2333/cloudflare_temp_email.

                                                                                Community rating

                                                                                No ratings yet. Tried this project? Share your experience.

                                                                                One rating per verified account. You can change or remove yours. Accounts are email verified; use of the software is self-reported.

                                                                                Discuss your experience ↓
                                                                                Sign in to rate

                                                                                Discussion · 0

                                                                                sign in to comment →
                                                                                No comments yet — be the first.