Security

Security

What happens to the mail and keys you send us, where it runs, and how to report a problem.

Hosting

mailsocket runs on servers operated by Hetzner Online in Germany (EU). The website, dashboard and API are served through Cloudflare. Inbound mail for in.inboxpipe.net is received directly by our own mail server.

Encryption

  • The website, dashboard and API are served only over HTTPS (TLS), with HSTS. Plain HTTP requests are redirected.
  • Webhooks are delivered only to HTTPS URLs and are signed with HMAC-SHA256 so you can verify they came from us.
  • Inbound SMTP does not require TLS, so mail can arrive at our server unencrypted, as with most receiving mail servers. Do not send anything to an inbox you would not put in an ordinary email.

Data handling

  • Mail. Each message is stored, then parsed for the OTP and magic link. We store the raw message so it can be reprocessed if parsing fails. Mail is never sold, shared or used to train models.
  • API keys. Stored as a keyed hash (HMAC-SHA256); the full key is shown once, when you create it. Keys can be revoked at any time and can carry an expiry date.
  • Access. Inboxes and messages are visible only to API keys and dashboard users of the account that owns them. An id that belongs to another account returns 404, the same as an id that does not exist.
  • Magic links. We extract links; we never open or follow them.

Retention and deletion

  • Messages are deleted after your plan's retention window: 1 day on Free, 7 days on Pro, 30 days on Scale and 90 days on Business. A scheduled job runs every hour.
  • Database backups are kept for up to 14 days, so deleted data leaves backups within 14 days.
  • If our application is unavailable, the mail server holds incoming mail in its queue and retries delivery for up to 5 days.
  • Deleting your account from Settings permanently erases the account, its inboxes and messages.

Subprocessors

ProviderPurposeLocation
Hetzner Online GmbHServers that run the application, database and mail server.Germany
Cloudflare, Inc.DNS, TLS termination and proxying for the website and API, privacy-friendly web analytics, and forwarding of mail sent to our own addresses.Global
Lemon SqueezyPayments and subscription billing (merchant of record). We never see your card number.United States

Reporting a vulnerability

Email security@mailsocket.app with a description, steps to reproduce and the affected URL or endpoint. We will confirm receipt and keep you updated until it is fixed.

Please test only against accounts and inboxes you own, do not access or modify other users' data, and give us reasonable time to fix an issue before disclosing it. We will not take legal action against good-faith research that follows these rules. Our security.txt has the same contact.

Abuse of an inbox address (spam, phishing) goes to abuse@inboxpipe.net. Privacy requests go to privacy@mailsocket.app.