Skip to content
OwnSMTP

Hardening

Security

Protect the API boundary, secrets, sender policy, and container runtime.

Protect secrets

Keep API keys and SMTP passwords in a secret manager or protected environment file. Never commit them, print them in logs, or expose the API key in frontend applications. Rotate both API and SMTP credentials on a schedule and immediately after suspected exposure.

Minimize network exposure

  • Bind to 127.0.0.1 or a private address by default.
  • Use HTTPS whenever requests cross a public or untrusted network.
  • Restrict ingress by source IP, security group, or network policy where possible.
  • Do not rely on an obscure URL or port as access control.

Constrain senders

Keep ALLOWED_FROM_DOMAINS narrow and limited to provider-authorized domains. Remember that it is a local guardrail, not ownership verification.

Production operations

  • Set DISABLE_DOCS when interactive API documentation is unnecessary on a public production deployment.
  • Pin and update container versions regularly after testing.
  • Use a read-only filesystem, drop capabilities, and run as non-root.
  • Review SMTP-provider activity, bounces, complaints, and reputation metrics.
  • Monitor authentication failures and unexpected sending volume.