Security

Secure by design. Verifiable by anyone.

Delivr's safest data is the data it never keeps. Here's exactly what the client and the server do to protect your mail — and how to check it yourself.

At a glance

Where your data lives

Delivr sits between your browser and your mail server — and is deliberately forgetful in the middle.

Your device

Delivr Web (PWA)

  • Your session cookie
  • Sanitized HTML rendering
  • Remote content blocked by default
HTTPS

Your Delivr instance

Delivr API

  • Encrypted IMAP/SMTP credentials
  • Hashed session tokens & API keys
  • Preferences — but no mail
IMAP/SMTP + TLS

Your mail server

Any IMAP/SMTP provider

  • All of your mail, exactly as before
  • Your folders and flags
  • Your sent items and drafts
In detail

How Delivr protects you

No marketing hand-waving: these are the mechanisms in the code, which you can read on GitHub.

Credentials encrypted at rest

  • IMAP/SMTP credentials are encrypted with AES-256-GCM, using a fresh random IV for every record.
  • The key is derived from DLA_ENCRYPTION_KEY, which lives in your environment — never in the database.
  • A leaked database backup alone does not reveal anyone's mail password.

Sessions & API keys

  • Tokens are 256-bit random secrets with recognizable prefixes (dla_sess_, dla_apikey_) for secret scanners.
  • Only Argon2id hashes are stored — the plaintext token is shown exactly once.
  • Sessions expire after 7 days; API keys can expire and can be revoked any time.
  • Changing your username, email address, or password requires your current password.

Brute-force protection

  • Sign-in attempts are limited to five per client and username, and fifteen per username overall, in any five-minute window.
  • Unknown usernames take as long to reject as wrong passwords, so attackers can't probe which accounts exist.

No mail at rest

  • Messages are fetched live from IMAP and parsed in memory. There is no mail cache or search index on the server.
  • Attachments are re-fetched on demand and streamed with Cache-Control: no-store and X-Content-Type-Options: nosniff.
  • Only IMAP connections are pooled — never message data.

Safe rendering

  • Every HTML email is sanitized with DOMPurify before it is displayed.
  • Remote images and other external content are blocked until you allow them, per sender or per domain.
  • Inline preview is limited to inert types (PDF and raster images — not SVG or HTML), enforced in both the browser and the server.

API hygiene

  • CORS only admits the origin configured in DLA_APP_URL.
  • Errors return generic messages — no stack traces or validation internals.
  • The interactive API reference can be switched off in production with one variable.

Phishing signals

  • Senders with a valid BIMI record show their verified brand logo, making look-alike senders easier to spot.
  • BIMI is resolved from DNS metadata only; the logo is never fetched or stored by the server.

Transparent development

  • All code is public and changes land through reviewed pull requests.
  • Every change runs type-checking and an integration test suite against mock IMAP/SMTP servers.
  • Container images are built by GitHub Actions and published to the GitHub Container Registry.
Shared responsibility

Self-hosting means you hold the keys

Running your own instance gives you full control — and a few responsibilities. The hardening guide walks you through each of them.

Production hardening guide
  • Serve Delivr only over HTTPS, behind a reverse proxy
  • Generate a long, random DLA_ENCRYPTION_KEY and keep it out of version control
  • Back up the database and the encryption key — separately
  • Keep the container images up to date
  • Expose only your reverse proxy to the internet
  • Disable the API reference with DLA_DISABLE_DOCS if you don't need it
Coming next

Security on the roadmap

Security work never stops. These features are planned or being explored for upcoming releases.

Responsible disclosure

Found a vulnerability? Thank you — please tell us privately first. Don't open a public issue or pull request for security problems.

  1. Email support@delivr.email with “Security” in the subject.
  2. Include the affected component and version, steps to reproduce, and the impact you see.
  3. Give us a reasonable amount of time to ship a fix before disclosing publicly.

We'll confirm we received your report, keep you updated while we work on a fix, and credit you in the release notes if you'd like.

Ready to take your inbox back?

Open source, self-hostable, and built to play nicely with the email server you already have.