
Email Explorer
Own-domain browser mailboxes backed by SQLite Durable Objects
Email Explorer is a self-hosted Fastmail/Gmail alternative built on Cloudflare (Durable Objects, R2, Workers). Paid services required. Inspect the source and license in the linked repository.
Source & license
Upstream license: MIT
License TL;DR
You can use it, change it, self-host it and sell it. Keep the original copyright and license notice with copies of the code. You don’t have to publish your changes. The authors don’t promise it will work.
Explain MIT in plain English →Summary of the main license. Separate packages and assets can have different terms.
Inspect repository ↗Read this project’s actual license ↗Repository owner
See the upstream repository for the original creator and contributors.
Maintain this project? Maintainer verification →Cloudflare hosting
Paid services required
The complete receive-and-send path uses Workers Paid from $5 USD/account/month because arbitrary-recipient Email Service sending requires Paid. It includes 3,000 sends/month then $0.35/1,000, plus storage/compute overages. Receiving through Email Routing is available on Free; sending and email recovery are optional upstream features.
Hosting requirements
- Deploy the template configuration, create your own domain/Routing rules, R2 bucket and SQLite MailboxDO. The development example is not the production topology.
- The first-user admin setup and role claims are source documentation, not a runtime security audit. Password recovery requires configured outbound sending.
- Source and configuration review establishes a deployment path and conditional costs; this candidate was not executed or load-tested.
Sources checked 01/10/2026
Repository snapshot: 8915b24. Hosting eligibility reflects the deployment documentation and listed assumptions.
- gmail ↗
Email Explorer is a full-stack, serverless email client that runs entirely on your own Cloudflare account. It provides a modern, fast, and secure way to manage your emails using Cloudflare's powerful infrastructure, including Workers, R2, Durable Objects, Email Routing, and Email Sending.
- fastmail ↗
Email Explorer is a full-stack, serverless email client that runs entirely on your own Cloudflare account. It provides a modern, fast, and secure way to manage your emails using Cloudflare's powerful infrastructure, including Workers, R2, Durable Objects, Email Routing, and Email Sending.
- workers ↗
ode_modules/wrangler/config-schema.json", "compatibility_date": "2025-11-28", "main": "src/index.ts", "name": "email-explorer", "upload_source_maps": true, "observability": { "enabled": true }, "compatibility_flags": ["nodejs_compat", "enable_email_sending_queuing"], "assets": { "directory": "node_modules/email-explorer/dashboard", "binding": "ASSETS", "html_handling": "auto-trailing-slash", "not_found_handling": "single-page-application", "run_worker_first": ["/api/*", "/docs", "/openapi.json"] }, "r2_buckets": [ { "binding": "BUCKET", "bucket
- r2 ↗
e-application", "run_worker_first": ["/api/*", "/docs", "/openapi.json"] }, "r2_buckets": [ { "binding": "BUCKET", "bucket_name": "email-explorer" } ], "send_email": [ { "name": "SEND_EMAIL" } ], "durable_objects": { "bindings": [ { "name": "MAILBOX", "class_name": "MailboxDO" } ] }, "migrations": [ { "tag": "v1", "new_sqlite_classes": ["MailboxDO"] } ] }
- durable-objects ↗
"email-explorer" } ], "send_email": [ { "name": "SEND_EMAIL" } ], "durable_objects": { "bindings": [ { "name": "MAILBOX", "class_name": "MailboxDO" } ] }, "migrations": [ { "tag": "v1", "new_sqlite_classes": ["MailboxDO"] } ] }
- paid ↗
/** * For more details on how to configure Wrangler, refer to: * https://developers.cloudflare.com/workers/wrangler/configuration/ */ { "$schema": "node_modules/wrangler/config-schema.json", "compatibility_date": "2025-11-28", "main": "index.ts", "name": "email-explorer", "upload_source_maps": true, "observability": { "enabled": true }, "compatibility_flags": ["nodejs_compat", "enable_email_sending_queuing"], "assets": { "directory": "node_modules/email-explorer/dashboard", "binding": "ASSETS", "html_handling": "auto-trailing-slash", "not_found_handling": "single-page-application", "run_worker_first": ["/api/*", "/docs", "/openapi.json"] }, "r2_buckets": [ { "binding": "BUCKET", "bucket_name": "email-explorer", "preview_bucket_name": "email-explorer", /
- paid ↗
The Workers Paid plan includes Workers, Pages Functions, Workers KV, Hyperdrive, and Durable Objects usage for a minimum charge of $5 USD per month for an account. The plan includes increased initial usage allotments, with clear charges for usage that exceeds the base plan. There are no additional charges for data transfer (egress) or throughput (bandwidth).
- paid ↗
| Storage | 10 GB-month / month |
- paid ↗
Durable Objects are available both on Workers Free and Workers Paid plans.
- paid ↗
| **Outbound emails (Email Sending)** | Not available | 3,000 included per month, then $0.35 per 1,000 emails |
- paid ↗
| Class A Operations | 1 million requests / month |
- paid ↗
| Class B Operations | 10 million requests / month |
- paid ↗
| SQL Stored data <sup>5</sup> | 5 GB (total) | 5 GB-month, + $0.20/ GB-month |
- MIT ↗
MIT License Copyright (c) 2025 Gabriel Massadas Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions: The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software. THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CO
- architecture ↗
/** * For more details on how to configure Wrangler, refer to: * https://developers.cloudflare.com/workers/wrangler/configuration/ */ { "$schema": "node_modules/wrangler/config-schema.json", "compatibility_date": "2025-11-28", "main": "src/index.ts", "name": "email-explorer", "upload_source_maps": true, "observability": { "enabled": true }, "compatibility_flags": ["nodejs_compat", "enable_email_sending_queuing"], "assets": { "directory": "node_modules/email-explorer/dashboard", "binding": "ASSETS", "html_handling": "auto-trailing-slash", "not_found_handling": "single-page-application", "run_worker_first": ["/api/*", "/docs", "/openapi.json"] }, "r2_buckets": [ { "binding": "BUCKET", "bucket_name": "email-explorer" } ], "send_email": [ { "name": "SEND_EMAIL" } ], "durable_objects": { "bindings": [ { "name": "MAILBOX", "class_name": "MailboxDO" } ] }, "migrations": [ { "tag": "v1", "new_sqlite_classes": ["MailboxD
- architecture ↗
ode_modules/wrangler/config-schema.json", "compatibility_date": "2025-11-28", "main": "src/index.ts", "name": "email-explorer", "upload_source_maps": true, "observability": { "enabled": true }, "compatibility_flags": ["nodejs_compat", "enable_email_sending_queuing"], "assets": { "directory": "node_modules/email-explorer/dashboard", "binding": "ASSETS", "html_handling": "auto-trailing-slash", "not_found_handling": "single-page-application", "run_worker_first": ["/api/*", "/docs", "/openapi.json"] }, "r2_buckets": [ { "binding": "BUCKET", "bucket
- architecture ↗
e-application", "run_worker_first": ["/api/*", "/docs", "/openapi.json"] }, "r2_buckets": [ { "binding": "BUCKET", "bucket_name": "email-explorer" } ], "send_email": [ { "name": "SEND_EMAIL" } ], "durable_objects": { "bindings": [ { "name": "MAILBOX", "class_name": "MailboxDO" } ] }, "migrations": [ { "tag": "v1", "new_sqlite_classes": ["MailboxDO"] } ] }
- architecture ↗
"email-explorer" } ], "send_email": [ { "name": "SEND_EMAIL" } ], "durable_objects": { "bindings": [ { "name": "MAILBOX", "class_name": "MailboxDO" } ] }, "migrations": [ { "tag": "v1", "new_sqlite_classes": ["MailboxDO"] } ] }
Upstream screenshot · G4brym/email-explorer repository contributors ↗. Depicts the upstream project. We have not deployed and tested a fresh installation here.
What it can replace
Compare the workflow you need. These mappings describe overlap; full feature parity requires a separate comparison.
Own-domain browser email reading, organizing, attachments and optional sending; no claim of hosted-service parity, IMAP-server compatibility or account migration.
See supporting source ↗Own-domain browser email reading, organizing, attachments and optional sending; no claim of hosted-service parity, IMAP-server compatibility or account migration.
See supporting source ↗How it works
The shape of Email Explorer on Cloudflare, and how it stacks up against the rented tools it replaces.
Architecture
Diagram of deployment declarations at the reviewed commit. Each app has its own entrypoint; declared resources do not prove runtime calls. Follow file and line sources below.
View upstream source ↗Configuration and workflow sources
Reviewed commit 8915b2479550. Files were read as data; upstream applications and CI jobs were not executed.
Deployment configuration · 2 files
Cloudflare Workers · compatibility 2025-11-28
email-explorer · default
Entrypoint: index.ts
Static assets: node_modules/email-explorer/dashboard · single-page-application · Worker first: ["/api/*","/docs","/openapi.json"]
BUCKET→ R2MAILBOX→ Durable Objects · class MailboxDOSEND_EMAIL→ Send EmailASSETS→ Static assets
Cloudflare Workers · example/template, excluded from overview · compatibility 2025-11-28
email-explorer · default
Entrypoint: src/index.ts
Static assets: node_modules/email-explorer/dashboard · single-page-application · Worker first: ["/api/*","/docs","/openapi.json"]
BUCKET→ R2MAILBOX→ Durable Objects · class MailboxDOSEND_EMAIL→ Send EmailASSETS→ Static assets
Named environments are separate deployments. Bindings are shown only where declared. Configured routes are URL patterns, not verified application endpoints.
Runtime source · handlers, binding usage and workflow steps
Observed TypeScript/JavaScript declarations from Worker entrypoints and resolved relative imports. Calls and workflow steps may run conditionally; their listed order is not a proven end-to-end request flow. Router declarations may be mounted under a prefix or may not be registered. This shows code wiring, not a successful deployment or runtime test. Dynamic wiring, aliases and generated code may not resolve.
- L1604 · app.use("/api/*")
- L1804 · authApp.use("*")
- L1831 · authApp.use("/api/v1/mailboxes/:mailboxId")
- L1832 · authApp.use("/api/v1/mailboxes/:mailboxId/*")
- L1835 · authApp.route("/")
- L174 · slugify calls (conditional paths may differ): replace, toLowerCase, text.toString
- L1543 · getSessionToken calls (conditional paths may differ): request.headers.get, authHeader.substring, cookie.match
- L1561 · validateSession calls (conditional paths may differ): getSessionToken, env.MAILBOX.idFromName, env.MAILBOX.get, authDO.validateSession
- L1580 · isPublicRoute calls (conditional paths may differ): publicRoutes.some, pathname.startsWith
- L1594 · requiresSession calls (conditional paths may differ): authRoutes.some, pathname.startsWith
- L1655 · streamToArrayBuffer calls (conditional paths may differ): stream.getReader, reader.read, result.set
- L1670 · receiveEmail calls (conditional paths may differ): streamToArrayBuffer, parser.parse, crypto.randomUUID, env.BUCKET.head, env.BUCKET.put, JSON.stringify, ns.idFromName, ns.get, attachmentData.push, replace, s.replace, stripBrackets, map, filter, parsedEmail.references.split, stub.createEmail, toISOString
- L1757 · EmailExplorer calls (conditional paths may differ): receiveEmail, isPublicRoute, requiresSession, validateSession, JSON.stringify, authApp.use, c.set, next, c.req.param, env.MAILBOX.idFromName, env.MAILBOX.get, authDO.getUserMailboxes, userMailboxes.some, c.json, authApp.route, authApp.fetch, app.fetch
Environment references: c.env.BUCKET · c.env.MAILBOX · c.env.SEND_EMAIL · c.env.config · env.MAILBOX · env.BUCKET · env.config
- L21 · buildMimeMessage calls (conditional paths may differ): Date.now, substring, toString, Math.random, Array.isArray, to.join, toUTCString, crypto.randomUUID, join, references.map, content.substring
- L59 · getAuthDO calls (conditional paths may differ): env.MAILBOX.idFromName, env.MAILBOX.get
- L65 · getSessionToken calls (conditional paths may differ): c.req.header, authHeader.substring, cookie.match
Environment references: env.MAILBOX · c.env.config
Environment references: c.env.BUCKET · c.env.MAILBOX · c.env.SEND_EMAIL
Build and deployment pipeline · 3 GitHub Actions workflows
Repository CI declarations, separate from runtime request processing. Job dependencies and conditions are shown as written; long commands are shortened with an ellipsis; a workflow file does not prove a recent successful run.
Triggers: push, pull_request
build · no job dependencies declared
- actions/checkout@v6
actions/checkout@v6 - Set up Node.js
actions/setup-node@v6 - Install pnpm
npm install -g pnpm - Install dependencies
pnpm install - Check Lint
pnpm lint - Build everything
pnpm build - Run Worker Tests
cd packages/worker && pnpm test - Package artifact
pnpm package - Archive package
actions/upload-artifact@v7
Triggers: pull_request
Require changeset · no job dependencies declared
Condition: github.head_ref != 'changeset-release/main'
- actions/checkout@v6
actions/checkout@v6 - actions/setup-node@v6
actions/setup-node@v6 - pnpm/action-setup@v4
pnpm/action-setup@v4 - Install dependencies
pnpm install - Check for changeset
pnpx changeset status --since=origin/main
Triggers: push
Release · no job dependencies declared
- actions/checkout@v6
actions/checkout@v6 - actions/setup-node@v6
actions/setup-node@v6 - pnpm/action-setup@v4
pnpm/action-setup@v4 - Install dependencies
pnpm install - Check Lint
pnpm lint - Build everything
pnpm build - Run Worker Tests
cd packages/worker && pnpm test - Get current version
echo "version=$(jq -r .version packages/worker/package.json)" >> "$GITHUB_OUTPUT" - Check if version is already published
VERSION="${{ steps.pre.outputs.version }}" if npm view "email-explorer@${VERSION}" version >/dev/null 2>&1; then echo "published=true" >> "$GITHUB_OUTPUT" else echo "published=false" >> "$GITHUB_OUTPUT" fi - Create Release Pull Request or Publish
changesets/action@v1 - Create GitHub Release
VERSION=$(jq -r .version packages/worker/package.json) TAG="v${VERSION}" if gh release view "$TAG" >/dev/null 2>&1; then echo "Release $TAG already exists, skipping." else CHANGELOG_FILE="packages/worker/CHANGELOG.md" BODY="" if [ -f "$CHANGELOG_FILE" ]; then BODY=$(awk "/^## ${VERSION}\$/{ found=1; next } /^## /{ if(found) exit } found" "$CHANGELOG_FILE") fi if [ -z "$BODY" ]; then BODY="See [CHANGELOG.md](https://github.com/G4brym/email-explorer/blob/main/packages/worker/CHANGELOG.md) for det…
build-dashboard: pnpm run --filter email-explorer-dashboard buildbuild-worker: pnpm run --filter email-explorer buildbuild: pnpm build-dashboard && pnpm build-workerdeploy-dev-worker: pnpm run --filter email-explorer-dev-worker deploypublish-npm: pnpm run --filter email-explorer publish-npm
build: run-p type-check "build-only {@}" --build-only: vite build
deploy: wrangler deploy
build: tsup src/index.ts --format esm --external cloudflare:workers --external cloudflare:email --dts && cp -R ../dashboard/dist/ dashboard/ && cp ../../README.md . && cp ../../LICENSE .publish-npm: npm publish
deploy: wrangler deploy
Repository README
View original on GitHub ↗Full upstream document by @G4brym · README.md · snapshot 8915b24
A modern, full-stack email client running entirely on Cloudflare Workers
Email Explorer
Email Explorer is a full-stack, serverless email client that runs entirely on your own Cloudflare account. It provides a modern, fast, and secure way to manage your emails using Cloudflare's powerful infrastructure, including Workers, R2, Durable Objects, Email Routing, and Email Sending.
Table of Contents
- Overview
- Why Email Explorer?
- Key Features
- Prerequisites
- Getting Started
- Configuration
- Documentation
- Architecture
- Production Ready Features
- Testing
- Roadmap & Future Enhancements
- Known Limitations
- Security
- Contributing
- Support
- License
Quick Links
- 📖 User Guides - Complete documentation for all features
- 🚀 Getting Started - Deploy in minutes
- 🔐 Authentication - Setup your first account
- 🔑 Account Recovery - Password reset via email
- 👥 Admin Panel - Manage users and permissions
- ⚙️ Configuration - Customize your deployment
Overview
Email Explorer gives you a private, self-hosted email solution with a user-friendly web interface. By leveraging the Cloudflare ecosystem, it offers a cost-effective and scalable alternative to traditional email hosting. All your data is stored securely in your own R2 buckets and Durable Objects, giving you full control over your information.
Screenshots
Mailbox management and email list view
Rich text email composer with formatting options
Why Email Explorer?
🔒 Privacy First
- All data stays in YOUR Cloudflare account
- No third-party tracking or analytics
- You control your data completely
💰 Cost-Effective
- Runs on Cloudflare's generous free tier
- Pay only for what you use beyond free limits
- No monthly subscription fees
⚡ Performance
- Built on Cloudflare's global edge network
- Fast loading times worldwide
- Serverless architecture scales automatically
🎨 Modern Experience
- Clean, intuitive interface
- Rich text email composition
- Mobile-responsive design
🛠️ Easy Setup
- Deploy with one click
- Automatic mailbox creation
- Smart authentication setup
Note: To send emails, you need to have Cloudflare Email Sending enabled on your account. Receiving emails works through Cloudflare Email Routing.
Note: When you first load your worker, there will be no mailboxes. They are automatically created when you start receiving emails.
Key Features
- 🔒 Secure & Private: Self-hosted on your Cloudflare account. No third-party tracking or data scanning.
- 🔐 Smart Authentication: Automatic first-user admin setup with role-based access control and secure session management.
- 👥 Multi-User Support: Admin panel for managing users and mailbox permissions with granular roles (Owner, Admin, Write, Read).
- ✍️ Rich Text Editor: Full-featured WYSIWYG editor with formatting, colors, links, lists, and more - just like Gmail or Outlook.
- ↩️ Reply & Forward: Reply to sender, reply all, or forward emails with automatic quoting and threading support.
- ✉️ Email Management: Send, receive, and organize emails with a clean and intuitive interface.
- 📁 Folder Organization: Create custom folders to organize your emails.
- 📎 Attachment Support: View and download attachments directly in the browser.
- 🔍 Search: Find emails quickly with full-text search across all your mailboxes.
- 📧 Contacts: Manage your contacts with an integrated address book.
- ⚡ Serverless Architecture: Each mailbox is its own Durable Object for optimal performance and isolation.
Prerequisites
Before deploying Email Explorer, make sure you have:
- Cloudflare Account - Sign up for free
- Domain Name - Added to your Cloudflare account
- Email Routing - Enable Email Routing for receiving emails
- Email Sending - Enable Email Sending for sending emails (optional but recommended)
- Node.js 18+ - For local development (not required for deployment)
Cloudflare Services Used:
- Workers (Compute)
- Durable Objects (State management)
- R2 (Object storage)
- D1 (SQL database via Durable Objects)
- Email Routing (Receive emails)
- Email Sending (Send emails)
Most of these services have generous free tiers that are sufficient for personal use.
Getting Started
To deploy Email Explorer, you can use the "Deploy to Cloudflare" button above or run this command:
npm create cloudflare@latest -- --template=https://github.com/G4brym/email-explorer/tree/main/template
Or deploy manually:
# Clone the repository
git clone https://github.com/G4brym/email-explorer.git
cd email-explorer
# Install dependencies
pnpm install
# Deploy to Cloudflare
pnpm --filter email-explorer deploy
Configuration
Email Explorer uses a factory function pattern for configuration. Edit src/index.ts:
// Recommended: Smart Mode (Default)
export default EmailExplorer({
auth: {
enabled: true
// registerEnabled not specified = smart mode
},
accountRecovery: {
fromEmail: 'noreply@yourdomain.com' // Optional: enable password reset via email
}
})
Smart Mode (Recommended):
- First user to register automatically becomes admin
- Registration closes after first user
- Admins can create additional users via admin panel
- Perfect for production deployments
Other Modes:
// Open Registration (Development/Testing)
export default EmailExplorer({
auth: {
enabled: true,
registerEnabled: true // Anyone can register
}
})
// No Authentication (Single User)
export default EmailExplorer({
auth: {
enabled: false
}
})
// With Account Recovery
export default EmailExplorer({
auth: {
enabled: true
},
accountRecovery: {
fromEmail: 'noreply@yourdomain.com' // Email address to send password reset links from
}
})
Configuration Options:
| Option | Type | Default | Description |
|---|---|---|---|
auth.enabled |
boolean | true |
Enable/disable authentication |
auth.registerEnabled |
boolean | undefined (smart mode) |
Control user registration |
accountRecovery.fromEmail |
string | undefined (disabled) |
Enable password recovery via email |
Account Recovery:
- When configured, users can reset forgotten passwords via email
- The
fromEmailaddress must be a valid email on your Cloudflare account - Requires Cloudflare Email Sending to be enabled
- See Account Recovery Guide for more details
First-Time Setup
- Deploy your worker with smart mode enabled (default)
- Visit your worker URL in a browser
- Register the first user - this becomes your admin account
- Log in with your admin credentials
- Manage additional users through the admin panel
Admin Operations
As an admin, you can:
- Create new users
- Grant/revoke mailbox access
- Assign roles:
owner,admin,write, orread - Promote users to admin status
Documentation
Comprehensive user guides are available for all features:
- Feature Documentation - Complete user guides
- Authentication Guide - Account creation, login, and security
- Account Recovery Guide - Password reset via email
- Admin Panel Guide - User management and permissions
- Rich Text Editor Guide - Email formatting and composition
- Reply & Forward Guide - Email responses and threading
For developers:
- ROADMAP.md - Project roadmap and planned features
- AGENTS.md - Technical architecture and development guide
Architecture
Email Explorer is built with modern web technologies:
Backend (Worker):
- Hono - Fast, lightweight web framework
- Cloudflare Durable Objects - Distributed state management
- Cloudflare R2 - Object storage for attachments
- Cloudflare D1 - SQL database (via Durable Objects)
- Cloudflare Email Routing - Email sending and receiving
Frontend (Dashboard):
- Vue.js 3 - Progressive JavaScript framework
- TypeScript - Type-safe development
- Tailwind CSS - Utility-first styling
- TipTap - Rich text editor
- Pinia - State management
- Vite - Fast build tooling
Production Ready Features
✅ Authentication & Security
- Smart mode with automatic admin setup
- Session-based authentication (30-day expiry)
- Password hashing with Web Crypto API
- HttpOnly, Secure, SameSite cookies
- Role-based access control (RBAC)
✅ Email Capabilities
- Send and receive emails
- Reply and reply-all functionality
- Forward emails to others
- Rich text HTML composition
- Email threading and conversation tracking
- Attachment handling
✅ User Management
- Admin panel for user creation
- Granular mailbox permissions (Owner, Admin, Write, Read)
- Multi-user support with isolation
- Access grant and revoke capabilities
✅ Organization
- Custom folder creation
- Contact management
- Full-text email search
- Email filtering and organization
Testing
Email Explorer includes comprehensive integration tests:
# Run all tests
pnpm --filter email-explorer test
# Run specific test suite
pnpm --filter email-explorer test auth
pnpm --filter email-explorer test endpoints
# Watch mode for development
pnpm --filter email-explorer test --watch
Test Coverage:
- ✅ Authentication flows (registration, login, sessions)
- ✅ Admin operations (user management, access control)
- ✅ Email operations (send, receive, folders)
- ✅ Search and filtering
- ✅ Contacts and attachments
- ✅ Security validations
Roadmap & Future Enhancements
Planned features for future releases:
- Email templates for quick responses
- Two-factor authentication (2FA)
- Email drafts auto-save
- Conversation threading view
- Emoji picker in composer
- Table support in rich text editor
- Image uploads and inline images
- Email signatures (basic — single signature per mailbox)
- Keyboard shortcuts
- Mobile app (React Native)
See ROADMAP.md for detailed planning and progress.
Known Limitations
Current Limitations:
- No email draft auto-save (manual save only)
- Image uploads not yet supported (URLs work)
- Single mailbox per user account (multiple access supported)
Optional Features:
- Password reset via email requires
accountRecovery.fromEmailconfiguration
Browser Compatibility:
- Modern browsers required (Chrome 90+, Firefox 88+, Safari 14+)
- JavaScript must be enabled
- Cookies must be enabled for authentication
Please report any issues on our GitHub Issues page.
Security
Email Explorer takes security seriously:
🔐 Authentication Security
- Passwords hashed with Web Crypto API (SHA-256)
- HttpOnly, Secure, SameSite cookies prevent XSS/CSRF
- 30-day session expiry for automatic logout
- Session tokens use cryptographic randomness
🛡️ Data Protection
- All data stored in YOUR Cloudflare account
- Email content rendered in sandboxed iframes
- No third-party data sharing
- Role-based access control (RBAC)
🔒 Best Practices
- Always use HTTPS (automatic with Cloudflare)
- Keep dependencies updated
- Regular security audits via GitHub Dependabot
- Comprehensive test coverage
⚠️ Security Recommendations
- Use strong, unique passwords (8+ characters)
- Enable Cloudflare's security features
- Regularly review user access permissions
- Log out from shared devices
Report Security Issues: For security vulnerabilities, please email security issues privately rather than opening public issues.
Contributing
We welcome contributions from the community! Here's how you can help:
🐛 Bug Reports
- Use the GitHub Issues page
- Include reproduction steps
- Specify your environment (browser, Cloudflare setup)
✨ Feature Requests
- Check existing issues first
- Explain the use case and benefit
- Consider submitting a PR if you can implement it
💻 Code Contributions
- Fork the repository
- Create a feature branch (
git checkout -b feature/amazing-feature) - Make your changes with tests
- Commit your changes (
git commit -m 'Add amazing feature') - Push to the branch (
git push origin feature/amazing-feature) - Open a Pull Request
📖 Documentation
- Help improve user guides
- Fix typos or clarify instructions
- Add examples and use cases
Development Setup:
# Clone the repository
git clone https://github.com/G4brym/email-explorer.git
cd email-explorer
# Install dependencies
pnpm install
# Run tests
pnpm --filter email-explorer test
# Start development
pnpm --filter email-explorer dev
pnpm --filter dashboard dev
Support
- 📖 Documentation: Check docs/features/ for user guides
- 💬 Discussions: Use GitHub Discussions for questions
- 🐛 Issues: Report bugs via GitHub Issues
- 📧 Email: For security issues only
License
This project is licensed under the MIT License - see the LICENSE file for details.
Made with ❤️ for the self-hosted community
If you find Email Explorer useful, please consider giving it a ⭐ on GitHub!
Frequently asked about Email Explorer
What is Email Explorer?+
Email Explorer is a self-hosted Fastmail/Gmail alternative built on the Cloudflare developer platform. Own-domain browser mailboxes backed by SQLite Durable Objects
What does Email Explorer replace?+
Email Explorer is listed as an alternative to Fastmail, Gmail. Compare the features and tradeoffs before migrating.
What Cloudflare primitives does Email Explorer use?+
Email Explorer is built on Durable Objects, R2, Workers.
How much does Email Explorer cost to run?+
The complete receive-and-send path uses Workers Paid from $5 USD/account/month because arbitrary-recipient Email Service sending requires Paid. It includes 3,000 sends/month then $0.35/1,000, plus storage/compute overages. Receiving through Email Routing is available on Free; sending and email recovery are optional upstream features. Deploy the template configuration, create your own domain/Routing rules, R2 bucket and SQLite MailboxDO. The development example is not the production topology. The first-user admin setup and role claims are source documentation, not a runtime security audit. Password recovery requires configured outbound sending. Source and configuration review establishes a deployment path and conditional costs; this candidate was not executed or load-tested. Check current Cloudflare pricing before deploying.
Is Email Explorer open source?+
The upstream repository declares the MIT license. Read its terms at https://raw.githubusercontent.com/G4brym/email-explorer/8915b2479550baf7a4f44227730b803e9df5814e/LICENSE. Source code and contributor credit are available at https://github.com/G4brym/email-explorer.


Discussion · 0
sign in to comment →