Secure by design. Verifiable by anyone.
Delivr's safest data is the data it never keeps. Here's exactly what the client and the server do to protect your mail — and how to check it yourself.
Where your data lives
Delivr sits between your browser and your mail server — and is deliberately forgetful in the middle.
Your device
Delivr Web (PWA)
- Your session cookie
- Sanitized HTML rendering
- Remote content blocked by default
Your Delivr instance
Delivr API
- Encrypted IMAP/SMTP credentials
- Hashed session tokens & API keys
- Preferences — but no mail
Your mail server
Any IMAP/SMTP provider
- All of your mail, exactly as before
- Your folders and flags
- Your sent items and drafts
How Delivr protects you
No marketing hand-waving: these are the mechanisms in the code, which you can read on GitHub.
Credentials encrypted at rest
- IMAP/SMTP credentials are encrypted with AES-256-GCM, using a fresh random IV for every record.
- The key is derived from DLA_ENCRYPTION_KEY, which lives in your environment — never in the database.
- A leaked database backup alone does not reveal anyone's mail password.
Sessions & API keys
- Tokens are 256-bit random secrets with recognizable prefixes (dla_sess_, dla_apikey_) for secret scanners.
- Only Argon2id hashes are stored — the plaintext token is shown exactly once.
- Sessions expire after 7 days; API keys can expire and can be revoked any time.
- Changing your username, email address, or password requires your current password.
Brute-force protection
- Sign-in attempts are limited to five per client and username, and fifteen per username overall, in any five-minute window.
- Unknown usernames take as long to reject as wrong passwords, so attackers can't probe which accounts exist.
No mail at rest
- Messages are fetched live from IMAP and parsed in memory. There is no mail cache or search index on the server.
- Attachments are re-fetched on demand and streamed with Cache-Control: no-store and X-Content-Type-Options: nosniff.
- Only IMAP connections are pooled — never message data.
Safe rendering
- Every HTML email is sanitized with DOMPurify before it is displayed.
- Remote images and other external content are blocked until you allow them, per sender or per domain.
- Inline preview is limited to inert types (PDF and raster images — not SVG or HTML), enforced in both the browser and the server.
API hygiene
- CORS only admits the origin configured in DLA_APP_URL.
- Errors return generic messages — no stack traces or validation internals.
- The interactive API reference can be switched off in production with one variable.
Phishing signals
- Senders with a valid BIMI record show their verified brand logo, making look-alike senders easier to spot.
- BIMI is resolved from DNS metadata only; the logo is never fetched or stored by the server.
Transparent development
- All code is public and changes land through reviewed pull requests.
- Every change runs type-checking and an integration test suite against mock IMAP/SMTP servers.
- Container images are built by GitHub Actions and published to the GitHub Container Registry.
Self-hosting means you hold the keys
Running your own instance gives you full control — and a few responsibilities. The hardening guide walks you through each of them.
Production hardening guide- Serve Delivr only over HTTPS, behind a reverse proxy
- Generate a long, random DLA_ENCRYPTION_KEY and keep it out of version control
- Back up the database and the encryption key — separately
- Keep the container images up to date
- Expose only your reverse proxy to the internet
- Disable the API reference with DLA_DISABLE_DOCS if you don't need it
Security on the roadmap
Security work never stops. These features are planned or being explored for upcoming releases.
Responsible disclosure
Found a vulnerability? Thank you — please tell us privately first. Don't open a public issue or pull request for security problems.
- Email support@delivr.email with “Security” in the subject.
- Include the affected component and version, steps to reproduce, and the impact you see.
- Give us a reasonable amount of time to ship a fix before disclosing publicly.
We'll confirm we received your report, keep you updated while we work on a fix, and credit you in the release notes if you'd like.
Ready to take your inbox back?
Open source, self-hostable, and built to play nicely with the email server you already have.