Cloudsteading
Email Explorer Home

Email Explorer

Own-domain browser mailboxes backed by SQLite Durable Objects

Email Explorer is a self-hosted Fastmail/Gmail alternative built on Cloudflare (Durable Objects, R2, Workers). Paid services required. Inspect the source and license in the linked repository.

Source & license

Upstream license: MIT

License TL;DR

You can use it, change it, self-host it and sell it. Keep the original copyright and license notice with copies of the code. You don’t have to publish your changes. The authors don’t promise it will work.

Explain MIT in plain English →

Summary of the main license. Separate packages and assets can have different terms.

Inspect repository ↗Read this project’s actual license ↗

Repository owner

@G4brym

See the upstream repository for the original creator and contributors.

Maintain this project? Maintainer verification →

Cloudflare hosting

Paid services required

The complete receive-and-send path uses Workers Paid from $5 USD/account/month because arbitrary-recipient Email Service sending requires Paid. It includes 3,000 sends/month then $0.35/1,000, plus storage/compute overages. Receiving through Email Routing is available on Free; sending and email recovery are optional upstream features.

Hosting requirements
  • Deploy the template configuration, create your own domain/Routing rules, R2 bucket and SQLite MailboxDO. The development example is not the production topology.
  • The first-user admin setup and role claims are source documentation, not a runtime security audit. Password recovery requires configured outbound sending.
  • Source and configuration review establishes a deployment path and conditional costs; this candidate was not executed or load-tested.
Check current pricing ↗
Sources checked 01/10/2026

Repository snapshot: 8915b24. Hosting eligibility reflects the deployment documentation and listed assumptions.

  • gmail ↗

    Email Explorer is a full-stack, serverless email client that runs entirely on your own Cloudflare account. It provides a modern, fast, and secure way to manage your emails using Cloudflare's powerful infrastructure, including Workers, R2, Durable Objects, Email Routing, and Email Sending.

  • fastmail ↗

    Email Explorer is a full-stack, serverless email client that runs entirely on your own Cloudflare account. It provides a modern, fast, and secure way to manage your emails using Cloudflare's powerful infrastructure, including Workers, R2, Durable Objects, Email Routing, and Email Sending.

  • workers ↗

    ode_modules/wrangler/config-schema.json", "compatibility_date": "2025-11-28", "main": "src/index.ts", "name": "email-explorer", "upload_source_maps": true, "observability": { "enabled": true }, "compatibility_flags": ["nodejs_compat", "enable_email_sending_queuing"], "assets": { "directory": "node_modules/email-explorer/dashboard", "binding": "ASSETS", "html_handling": "auto-trailing-slash", "not_found_handling": "single-page-application", "run_worker_first": ["/api/*", "/docs", "/openapi.json"] }, "r2_buckets": [ { "binding": "BUCKET", "bucket

  • r2 ↗

    e-application", "run_worker_first": ["/api/*", "/docs", "/openapi.json"] }, "r2_buckets": [ { "binding": "BUCKET", "bucket_name": "email-explorer" } ], "send_email": [ { "name": "SEND_EMAIL" } ], "durable_objects": { "bindings": [ { "name": "MAILBOX", "class_name": "MailboxDO" } ] }, "migrations": [ { "tag": "v1", "new_sqlite_classes": ["MailboxDO"] } ] }

  • durable-objects ↗

    "email-explorer" } ], "send_email": [ { "name": "SEND_EMAIL" } ], "durable_objects": { "bindings": [ { "name": "MAILBOX", "class_name": "MailboxDO" } ] }, "migrations": [ { "tag": "v1", "new_sqlite_classes": ["MailboxDO"] } ] }

  • paid ↗

    /** * For more details on how to configure Wrangler, refer to: * https://developers.cloudflare.com/workers/wrangler/configuration/ */ { "$schema": "node_modules/wrangler/config-schema.json", "compatibility_date": "2025-11-28", "main": "index.ts", "name": "email-explorer", "upload_source_maps": true, "observability": { "enabled": true }, "compatibility_flags": ["nodejs_compat", "enable_email_sending_queuing"], "assets": { "directory": "node_modules/email-explorer/dashboard", "binding": "ASSETS", "html_handling": "auto-trailing-slash", "not_found_handling": "single-page-application", "run_worker_first": ["/api/*", "/docs", "/openapi.json"] }, "r2_buckets": [ { "binding": "BUCKET", "bucket_name": "email-explorer", "preview_bucket_name": "email-explorer", /

  • paid ↗

    The Workers Paid plan includes Workers, Pages Functions, Workers KV, Hyperdrive, and Durable Objects usage for a minimum charge of $5 USD per month for an account. The plan includes increased initial usage allotments, with clear charges for usage that exceeds the base plan. There are no additional charges for data transfer (egress) or throughput (bandwidth).

  • paid ↗

    | Storage | 10 GB-month / month |

  • paid ↗

    Durable Objects are available both on Workers Free and Workers Paid plans.

  • paid ↗

    | **Outbound emails (Email Sending)** | Not available | 3,000 included per month, then $0.35 per 1,000 emails |

  • paid ↗

    | Class A Operations | 1 million requests / month |

  • paid ↗

    | Class B Operations | 10 million requests / month |

  • paid ↗

    | SQL Stored data <sup>5</sup> | 5 GB (total) | 5 GB-month, + $0.20/ GB-month |

  • MIT ↗

    MIT License Copyright (c) 2025 Gabriel Massadas Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions: The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software. THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CO

  • architecture ↗

    /** * For more details on how to configure Wrangler, refer to: * https://developers.cloudflare.com/workers/wrangler/configuration/ */ { "$schema": "node_modules/wrangler/config-schema.json", "compatibility_date": "2025-11-28", "main": "src/index.ts", "name": "email-explorer", "upload_source_maps": true, "observability": { "enabled": true }, "compatibility_flags": ["nodejs_compat", "enable_email_sending_queuing"], "assets": { "directory": "node_modules/email-explorer/dashboard", "binding": "ASSETS", "html_handling": "auto-trailing-slash", "not_found_handling": "single-page-application", "run_worker_first": ["/api/*", "/docs", "/openapi.json"] }, "r2_buckets": [ { "binding": "BUCKET", "bucket_name": "email-explorer" } ], "send_email": [ { "name": "SEND_EMAIL" } ], "durable_objects": { "bindings": [ { "name": "MAILBOX", "class_name": "MailboxDO" } ] }, "migrations": [ { "tag": "v1", "new_sqlite_classes": ["MailboxD

  • architecture ↗

    ode_modules/wrangler/config-schema.json", "compatibility_date": "2025-11-28", "main": "src/index.ts", "name": "email-explorer", "upload_source_maps": true, "observability": { "enabled": true }, "compatibility_flags": ["nodejs_compat", "enable_email_sending_queuing"], "assets": { "directory": "node_modules/email-explorer/dashboard", "binding": "ASSETS", "html_handling": "auto-trailing-slash", "not_found_handling": "single-page-application", "run_worker_first": ["/api/*", "/docs", "/openapi.json"] }, "r2_buckets": [ { "binding": "BUCKET", "bucket

  • architecture ↗

    e-application", "run_worker_first": ["/api/*", "/docs", "/openapi.json"] }, "r2_buckets": [ { "binding": "BUCKET", "bucket_name": "email-explorer" } ], "send_email": [ { "name": "SEND_EMAIL" } ], "durable_objects": { "bindings": [ { "name": "MAILBOX", "class_name": "MailboxDO" } ] }, "migrations": [ { "tag": "v1", "new_sqlite_classes": ["MailboxDO"] } ] }

  • architecture ↗

    "email-explorer" } ], "send_email": [ { "name": "SEND_EMAIL" } ], "durable_objects": { "bindings": [ { "name": "MAILBOX", "class_name": "MailboxDO" } ] }, "migrations": [ { "tag": "v1", "new_sqlite_classes": ["MailboxDO"] } ] }

Upstream screenshot · G4brym/email-explorer repository contributors ↗. Depicts the upstream project. We have not deployed and tested a fresh installation here.

What it can replace

Compare the workflow you need. These mappings describe overlap; full feature parity requires a separate comparison.

Gmail logoGmail ↗

Own-domain browser email reading, organizing, attachments and optional sending; no claim of hosted-service parity, IMAP-server compatibility or account migration.

See supporting source ↗
Fastmail logoFastmail ↗

Own-domain browser email reading, organizing, attachments and optional sending; no claim of hosted-service parity, IMAP-server compatibility or account migration.

See supporting source ↗
external SaaS target
varies
external SaaS target
varies

How it works

The shape of Email Explorer on Cloudflare, and how it stacks up against the rented tools it replaces.

Architecture

Diagram of deployment declarations at the reviewed commit. Each app has its own entrypoint; declared resources do not prove runtime calls. Follow file and line sources below.

View upstream source ↗
Public interface
Configured entry points1
email-explorer
packages/worker/dev/wrangler.jsonc
↓
App
email-explorer
entry
Cloudflare Workers
Entrypoint: index.ts
↓

Configuration and workflow sources

Reviewed commit 8915b2479550. Files were read as data; upstream applications and CI jobs were not executed.

Deployment configuration · 2 files
packages/worker/dev/wrangler.jsonc ↗

Cloudflare Workers · compatibility 2025-11-28

email-explorer · default

Entrypoint: index.ts

Static assets: node_modules/email-explorer/dashboard · single-page-application · Worker first: ["/api/*","/docs","/openapi.json"]

  • BUCKET → R2
  • MAILBOX → Durable Objects · class MailboxDO
  • SEND_EMAIL → Send Email
  • ASSETS → Static assets
template/wrangler.jsonc ↗

Cloudflare Workers · example/template, excluded from overview · compatibility 2025-11-28

email-explorer · default

Entrypoint: src/index.ts

Static assets: node_modules/email-explorer/dashboard · single-page-application · Worker first: ["/api/*","/docs","/openapi.json"]

  • BUCKET → R2
  • MAILBOX → Durable Objects · class MailboxDO
  • SEND_EMAIL → Send Email
  • ASSETS → Static assets

Named environments are separate deployments. Bindings are shown only where declared. Configured routes are URL patterns, not verified application endpoints.

Runtime source · handlers, binding usage and workflow steps

Observed TypeScript/JavaScript declarations from Worker entrypoints and resolved relative imports. Calls and workflow steps may run conditionally; their listed order is not a proven end-to-end request flow. Router declarations may be mounted under a prefix or may not be registered. This shows code wiring, not a successful deployment or runtime test. Dynamic wiring, aliases and generated code may not resolve.

packages/worker/src/index.ts ↗
  • L1604 · app.use("/api/*")
  • L1804 · authApp.use("*")
  • L1831 · authApp.use("/api/v1/mailboxes/:mailboxId")
  • L1832 · authApp.use("/api/v1/mailboxes/:mailboxId/*")
  • L1835 · authApp.route("/")
  • L174 · slugify calls (conditional paths may differ): replace, toLowerCase, text.toString
  • L1543 · getSessionToken calls (conditional paths may differ): request.headers.get, authHeader.substring, cookie.match
  • L1561 · validateSession calls (conditional paths may differ): getSessionToken, env.MAILBOX.idFromName, env.MAILBOX.get, authDO.validateSession
  • L1580 · isPublicRoute calls (conditional paths may differ): publicRoutes.some, pathname.startsWith
  • L1594 · requiresSession calls (conditional paths may differ): authRoutes.some, pathname.startsWith
  • L1655 · streamToArrayBuffer calls (conditional paths may differ): stream.getReader, reader.read, result.set
  • L1670 · receiveEmail calls (conditional paths may differ): streamToArrayBuffer, parser.parse, crypto.randomUUID, env.BUCKET.head, env.BUCKET.put, JSON.stringify, ns.idFromName, ns.get, attachmentData.push, replace, s.replace, stripBrackets, map, filter, parsedEmail.references.split, stub.createEmail, toISOString
  • L1757 · EmailExplorer calls (conditional paths may differ): receiveEmail, isPublicRoute, requiresSession, validateSession, JSON.stringify, authApp.use, c.set, next, c.req.param, env.MAILBOX.idFromName, env.MAILBOX.get, authDO.getUserMailboxes, userMailboxes.some, c.json, authApp.route, authApp.fetch, app.fetch

Environment references: c.env.BUCKET · c.env.MAILBOX · c.env.SEND_EMAIL · c.env.config · env.MAILBOX · env.BUCKET · env.config

packages/worker/src/mime-builder.ts ↗
  • L21 · buildMimeMessage calls (conditional paths may differ): Date.now, substring, toString, Math.random, Array.isArray, to.join, toUTCString, crypto.randomUUID, join, references.map, content.substring
packages/worker/src/routes/auth.ts ↗
  • L59 · getAuthDO calls (conditional paths may differ): env.MAILBOX.idFromName, env.MAILBOX.get
  • L65 · getSessionToken calls (conditional paths may differ): c.req.header, authHeader.substring, cookie.match

Environment references: env.MAILBOX · c.env.config

packages/worker/src/routes/reply-forward.ts ↗

    Environment references: c.env.BUCKET · c.env.MAILBOX · c.env.SEND_EMAIL

    packages/worker/src/durableObject/index.ts ↗

      Environment references: env.MAILBOX

      Build and deployment pipeline · 3 GitHub Actions workflows

      Repository CI declarations, separate from runtime request processing. Job dependencies and conditions are shown as written; long commands are shortened with an ellipsis; a workflow file does not prove a recent successful run.

      Build · .github/workflows/build.yml ↗

      Triggers: push, pull_request

      build · no job dependencies declared

      1. actions/checkout@v6actions/checkout@v6
      2. Set up Node.jsactions/setup-node@v6
      3. Install pnpmnpm install -g pnpm
      4. Install dependenciespnpm install
      5. Check Lintpnpm lint
      6. Build everythingpnpm build
      7. Run Worker Testscd packages/worker && pnpm test
      8. Package artifactpnpm package
      9. Archive packageactions/upload-artifact@v7
      Changeset Check · .github/workflows/changeset-check.yml ↗

      Triggers: pull_request

      Require changeset · no job dependencies declared

      Condition: github.head_ref != 'changeset-release/main'

      1. actions/checkout@v6actions/checkout@v6
      2. actions/setup-node@v6actions/setup-node@v6
      3. pnpm/action-setup@v4pnpm/action-setup@v4
      4. Install dependenciespnpm install
      5. Check for changesetpnpx changeset status --since=origin/main
      Release · .github/workflows/release.yml ↗

      Triggers: push

      Release · no job dependencies declared

      1. actions/checkout@v6actions/checkout@v6
      2. actions/setup-node@v6actions/setup-node@v6
      3. pnpm/action-setup@v4pnpm/action-setup@v4
      4. Install dependenciespnpm install
      5. Check Lintpnpm lint
      6. Build everythingpnpm build
      7. Run Worker Testscd packages/worker && pnpm test
      8. Get current versionecho "version=$(jq -r .version packages/worker/package.json)" >> "$GITHUB_OUTPUT"
      9. Check if version is already publishedVERSION="${{ steps.pre.outputs.version }}" if npm view "email-explorer@${VERSION}" version >/dev/null 2>&1; then echo "published=true" >> "$GITHUB_OUTPUT" else echo "published=false" >> "$GITHUB_OUTPUT" fi
      10. Create Release Pull Request or Publishchangesets/action@v1
      11. Create GitHub ReleaseVERSION=$(jq -r .version packages/worker/package.json) TAG="v${VERSION}" if gh release view "$TAG" >/dev/null 2>&1; then echo "Release $TAG already exists, skipping." else CHANGELOG_FILE="packages/worker/CHANGELOG.md" BODY="" if [ -f "$CHANGELOG_FILE" ]; then BODY=$(awk "/^## ${VERSION}\$/{ found=1; next } /^## /{ if(found) exit } found" "$CHANGELOG_FILE") fi if [ -z "$BODY" ]; then BODY="See [CHANGELOG.md](https://github.com/G4brym/email-explorer/blob/main/packages/worker/CHANGELOG.md) for det…
      package.json ↗
      • build-dashboard: pnpm run --filter email-explorer-dashboard build
      • build-worker: pnpm run --filter email-explorer build
      • build: pnpm build-dashboard && pnpm build-worker
      • deploy-dev-worker: pnpm run --filter email-explorer-dev-worker deploy
      • publish-npm: pnpm run --filter email-explorer publish-npm
      packages/dashboard/package.json ↗
      • build: run-p type-check "build-only {@}" --
      • build-only: vite build
      packages/worker/package.json ↗
      • build: tsup src/index.ts --format esm --external cloudflare:workers --external cloudflare:email --dts && cp -R ../dashboard/dist/ dashboard/ && cp ../../README.md . && cp ../../LICENSE .
      • publish-npm: npm publish
      template/package.json ↗
      • deploy: wrangler deploy

      Full upstream document by @G4brym · README.md · snapshot 8915b24

      A modern, full-stack email client running entirely on Cloudflare Workers

      Email Explorer Commits Issues Software License

      Email Explorer

      Email Explorer is a full-stack, serverless email client that runs entirely on your own Cloudflare account. It provides a modern, fast, and secure way to manage your emails using Cloudflare's powerful infrastructure, including Workers, R2, Durable Objects, Email Routing, and Email Sending.

      Deploy to Cloudflare

      Table of Contents

      Overview

      Email Explorer gives you a private, self-hosted email solution with a user-friendly web interface. By leveraging the Cloudflare ecosystem, it offers a cost-effective and scalable alternative to traditional email hosting. All your data is stored securely in your own R2 buckets and Durable Objects, giving you full control over your information.

      Screenshots

      Email Explorer Home

      Mailbox management and email list view

      Email Composer

      Rich text email composer with formatting options

      Why Email Explorer?

      🔒 Privacy First

      • All data stays in YOUR Cloudflare account
      • No third-party tracking or analytics
      • You control your data completely

      💰 Cost-Effective

      • Runs on Cloudflare's generous free tier
      • Pay only for what you use beyond free limits
      • No monthly subscription fees

      ⚡ Performance

      • Built on Cloudflare's global edge network
      • Fast loading times worldwide
      • Serverless architecture scales automatically

      🎨 Modern Experience

      • Clean, intuitive interface
      • Rich text email composition
      • Mobile-responsive design

      🛠️ Easy Setup

      • Deploy with one click
      • Automatic mailbox creation
      • Smart authentication setup

      Note: To send emails, you need to have Cloudflare Email Sending enabled on your account. Receiving emails works through Cloudflare Email Routing.

      Note: When you first load your worker, there will be no mailboxes. They are automatically created when you start receiving emails.

      Key Features

      • 🔒 Secure & Private: Self-hosted on your Cloudflare account. No third-party tracking or data scanning.
      • 🔐 Smart Authentication: Automatic first-user admin setup with role-based access control and secure session management.
      • 👥 Multi-User Support: Admin panel for managing users and mailbox permissions with granular roles (Owner, Admin, Write, Read).
      • ✍️ Rich Text Editor: Full-featured WYSIWYG editor with formatting, colors, links, lists, and more - just like Gmail or Outlook.
      • ↩️ Reply & Forward: Reply to sender, reply all, or forward emails with automatic quoting and threading support.
      • ✉️ Email Management: Send, receive, and organize emails with a clean and intuitive interface.
      • 📁 Folder Organization: Create custom folders to organize your emails.
      • 📎 Attachment Support: View and download attachments directly in the browser.
      • 🔍 Search: Find emails quickly with full-text search across all your mailboxes.
      • 📧 Contacts: Manage your contacts with an integrated address book.
      • ⚡ Serverless Architecture: Each mailbox is its own Durable Object for optimal performance and isolation.

      Prerequisites

      Before deploying Email Explorer, make sure you have:

      • Cloudflare Account - Sign up for free
      • Domain Name - Added to your Cloudflare account
      • Email Routing - Enable Email Routing for receiving emails
      • Email Sending - Enable Email Sending for sending emails (optional but recommended)
      • Node.js 18+ - For local development (not required for deployment)

      Cloudflare Services Used:

      • Workers (Compute)
      • Durable Objects (State management)
      • R2 (Object storage)
      • D1 (SQL database via Durable Objects)
      • Email Routing (Receive emails)
      • Email Sending (Send emails)

      Most of these services have generous free tiers that are sufficient for personal use.

      Getting Started

      To deploy Email Explorer, you can use the "Deploy to Cloudflare" button above or run this command:

      npm create cloudflare@latest -- --template=https://github.com/G4brym/email-explorer/tree/main/template
      

      Or deploy manually:

      # Clone the repository
      git clone https://github.com/G4brym/email-explorer.git
      cd email-explorer
      
      # Install dependencies
      pnpm install
      
      # Deploy to Cloudflare
      pnpm --filter email-explorer deploy
      

      Configuration

      Email Explorer uses a factory function pattern for configuration. Edit src/index.ts:

      // Recommended: Smart Mode (Default)
      export default EmailExplorer({
        auth: {
          enabled: true
          // registerEnabled not specified = smart mode
        },
        accountRecovery: {
          fromEmail: 'noreply@yourdomain.com'  // Optional: enable password reset via email
        }
      })
      

      Smart Mode (Recommended):

      • First user to register automatically becomes admin
      • Registration closes after first user
      • Admins can create additional users via admin panel
      • Perfect for production deployments

      Other Modes:

      // Open Registration (Development/Testing)
      export default EmailExplorer({
        auth: {
          enabled: true,
          registerEnabled: true  // Anyone can register
        }
      })
      
      // No Authentication (Single User)
      export default EmailExplorer({
        auth: {
          enabled: false
        }
      })
      
      // With Account Recovery
      export default EmailExplorer({
        auth: {
          enabled: true
        },
        accountRecovery: {
          fromEmail: 'noreply@yourdomain.com'  // Email address to send password reset links from
        }
      })
      

      Configuration Options:

      Option Type Default Description
      auth.enabled boolean true Enable/disable authentication
      auth.registerEnabled boolean undefined (smart mode) Control user registration
      accountRecovery.fromEmail string undefined (disabled) Enable password recovery via email

      Account Recovery:

      First-Time Setup

      1. Deploy your worker with smart mode enabled (default)
      2. Visit your worker URL in a browser
      3. Register the first user - this becomes your admin account
      4. Log in with your admin credentials
      5. Manage additional users through the admin panel

      Admin Operations

      As an admin, you can:

      • Create new users
      • Grant/revoke mailbox access
      • Assign roles: owner, admin, write, or read
      • Promote users to admin status

      Documentation

      Comprehensive user guides are available for all features:

      For developers:

      • ROADMAP.md - Project roadmap and planned features
      • AGENTS.md - Technical architecture and development guide

      Architecture

      Email Explorer is built with modern web technologies:

      Backend (Worker):

      • Hono - Fast, lightweight web framework
      • Cloudflare Durable Objects - Distributed state management
      • Cloudflare R2 - Object storage for attachments
      • Cloudflare D1 - SQL database (via Durable Objects)
      • Cloudflare Email Routing - Email sending and receiving

      Frontend (Dashboard):

      • Vue.js 3 - Progressive JavaScript framework
      • TypeScript - Type-safe development
      • Tailwind CSS - Utility-first styling
      • TipTap - Rich text editor
      • Pinia - State management
      • Vite - Fast build tooling

      Production Ready Features

      ✅ Authentication & Security

      • Smart mode with automatic admin setup
      • Session-based authentication (30-day expiry)
      • Password hashing with Web Crypto API
      • HttpOnly, Secure, SameSite cookies
      • Role-based access control (RBAC)

      ✅ Email Capabilities

      • Send and receive emails
      • Reply and reply-all functionality
      • Forward emails to others
      • Rich text HTML composition
      • Email threading and conversation tracking
      • Attachment handling

      ✅ User Management

      • Admin panel for user creation
      • Granular mailbox permissions (Owner, Admin, Write, Read)
      • Multi-user support with isolation
      • Access grant and revoke capabilities

      ✅ Organization

      • Custom folder creation
      • Contact management
      • Full-text email search
      • Email filtering and organization

      Testing

      Email Explorer includes comprehensive integration tests:

      # Run all tests
      pnpm --filter email-explorer test
      
      # Run specific test suite
      pnpm --filter email-explorer test auth
      pnpm --filter email-explorer test endpoints
      
      # Watch mode for development
      pnpm --filter email-explorer test --watch
      

      Test Coverage:

      • ✅ Authentication flows (registration, login, sessions)
      • ✅ Admin operations (user management, access control)
      • ✅ Email operations (send, receive, folders)
      • ✅ Search and filtering
      • ✅ Contacts and attachments
      • ✅ Security validations

      Roadmap & Future Enhancements

      Planned features for future releases:

      • Email templates for quick responses
      • Two-factor authentication (2FA)
      • Email drafts auto-save
      • Conversation threading view
      • Emoji picker in composer
      • Table support in rich text editor
      • Image uploads and inline images
      • Email signatures (basic — single signature per mailbox)
      • Keyboard shortcuts
      • Mobile app (React Native)

      See ROADMAP.md for detailed planning and progress.

      Known Limitations

      Current Limitations:

      • No email draft auto-save (manual save only)
      • Image uploads not yet supported (URLs work)
      • Single mailbox per user account (multiple access supported)

      Optional Features:

      • Password reset via email requires accountRecovery.fromEmail configuration

      Browser Compatibility:

      • Modern browsers required (Chrome 90+, Firefox 88+, Safari 14+)
      • JavaScript must be enabled
      • Cookies must be enabled for authentication

      Please report any issues on our GitHub Issues page.

      Security

      Email Explorer takes security seriously:

      🔐 Authentication Security

      • Passwords hashed with Web Crypto API (SHA-256)
      • HttpOnly, Secure, SameSite cookies prevent XSS/CSRF
      • 30-day session expiry for automatic logout
      • Session tokens use cryptographic randomness

      🛡️ Data Protection

      • All data stored in YOUR Cloudflare account
      • Email content rendered in sandboxed iframes
      • No third-party data sharing
      • Role-based access control (RBAC)

      🔒 Best Practices

      • Always use HTTPS (automatic with Cloudflare)
      • Keep dependencies updated
      • Regular security audits via GitHub Dependabot
      • Comprehensive test coverage

      ⚠️ Security Recommendations

      • Use strong, unique passwords (8+ characters)
      • Enable Cloudflare's security features
      • Regularly review user access permissions
      • Log out from shared devices

      Report Security Issues: For security vulnerabilities, please email security issues privately rather than opening public issues.

      Contributing

      We welcome contributions from the community! Here's how you can help:

      🐛 Bug Reports

      • Use the GitHub Issues page
      • Include reproduction steps
      • Specify your environment (browser, Cloudflare setup)

      ✨ Feature Requests

      • Check existing issues first
      • Explain the use case and benefit
      • Consider submitting a PR if you can implement it

      💻 Code Contributions

      1. Fork the repository
      2. Create a feature branch (git checkout -b feature/amazing-feature)
      3. Make your changes with tests
      4. Commit your changes (git commit -m 'Add amazing feature')
      5. Push to the branch (git push origin feature/amazing-feature)
      6. Open a Pull Request

      📖 Documentation

      • Help improve user guides
      • Fix typos or clarify instructions
      • Add examples and use cases

      Development Setup:

      # Clone the repository
      git clone https://github.com/G4brym/email-explorer.git
      cd email-explorer
      
      # Install dependencies
      pnpm install
      
      # Run tests
      pnpm --filter email-explorer test
      
      # Start development
      pnpm --filter email-explorer dev
      pnpm --filter dashboard dev
      

      Support

      • 📖 Documentation: Check docs/features/ for user guides
      • 💬 Discussions: Use GitHub Discussions for questions
      • 🐛 Issues: Report bugs via GitHub Issues
      • 📧 Email: For security issues only

      License

      This project is licensed under the MIT License - see the LICENSE file for details.


      Made with ❤️ for the self-hosted community

      If you find Email Explorer useful, please consider giving it a ⭐ on GitHub!

      Frequently asked about Email Explorer

      What is Email Explorer?+

      Email Explorer is a self-hosted Fastmail/Gmail alternative built on the Cloudflare developer platform. Own-domain browser mailboxes backed by SQLite Durable Objects

      What does Email Explorer replace?+

      Email Explorer is listed as an alternative to Fastmail, Gmail. Compare the features and tradeoffs before migrating.

      What Cloudflare primitives does Email Explorer use?+

      Email Explorer is built on Durable Objects, R2, Workers.

      How much does Email Explorer cost to run?+

      The complete receive-and-send path uses Workers Paid from $5 USD/account/month because arbitrary-recipient Email Service sending requires Paid. It includes 3,000 sends/month then $0.35/1,000, plus storage/compute overages. Receiving through Email Routing is available on Free; sending and email recovery are optional upstream features. Deploy the template configuration, create your own domain/Routing rules, R2 bucket and SQLite MailboxDO. The development example is not the production topology. The first-user admin setup and role claims are source documentation, not a runtime security audit. Password recovery requires configured outbound sending. Source and configuration review establishes a deployment path and conditional costs; this candidate was not executed or load-tested. Check current Cloudflare pricing before deploying.

      Is Email Explorer open source?+

      The upstream repository declares the MIT license. Read its terms at https://raw.githubusercontent.com/G4brym/email-explorer/8915b2479550baf7a4f44227730b803e9df5814e/LICENSE. Source code and contributor credit are available at https://github.com/G4brym/email-explorer.

      Discussion · 0

      sign in to comment →
      No comments yet — be the first.