Hardening
Security
Protect the API boundary, secrets, sender policy, and container runtime.
Protect secrets
Keep API keys and SMTP passwords in a secret manager or protected environment file. Never commit them, print them in logs, or expose the API key in frontend applications. Rotate both API and SMTP credentials on a schedule and immediately after suspected exposure.
Minimize network exposure
- Bind to
127.0.0.1or a private address by default. - Use HTTPS whenever requests cross a public or untrusted network.
- Restrict ingress by source IP, security group, or network policy where possible.
- Do not rely on an obscure URL or port as access control.
Constrain senders
Keep ALLOWED_FROM_DOMAINS narrow and limited to provider-authorized domains. Remember that it is a local guardrail, not ownership verification.
Production operations
- Set
DISABLE_DOCSwhen interactive API documentation is unnecessary on a public production deployment. - Pin and update container versions regularly after testing.
- Use a read-only filesystem, drop capabilities, and run as non-root.
- Review SMTP-provider activity, bounces, complaints, and reputation metrics.
- Monitor authentication failures and unexpected sending volume.