Ephemera — Multi-Domain Inbound Email Platform
Project Description
Ephemera — a self-hosted multi-domain inbound email platform: disposable inboxes, real-time reception, a full REST API, an admin panel and built-in abuse controls. Fastify + Prisma + PostgreSQL + Redis, own SMTP ingest, React 19, Docker Compose, Prometheus/Grafana.
Overview
Ephemera is a self-hosted multi-domain inbound email platform with disposable inboxes, a modern web UI and a comprehensive API — a temp-mail solution for developers and teams who want to run their own infrastructure instead of depending on third-party services. Users create inboxes instantly on any domain, receive mail in real time, download attachments, and automate everything through the REST API.
Architecture & Technical Decisions
The system is a service monorepo: a Node.js + Fastify API with JWT auth, Prisma + PostgreSQL + Redis for data, SMTP ingest via smtp-server + mailparser (attachments stored on disk), a React 19 + Vite + TailwindCSS frontend, Caddy reverse proxy with automatic HTTPS, Prometheus + Grafana monitoring, and one-command Docker Compose packaging. The API separates public routes (/health always public; /ready and /metrics public in dev) from business routes that require a Bearer token; the canonical gateway is api.<domain> with an app.<domain>/api/* alias that is proxied and prefix-stripped. Domain management follows deliverability standards: a wizard surfaces SPF/DKIM/DMARC records plus MTA-STS/TLS-RPT and the TXT verification token. Abuse controls are designed in from the start: per-IP/domain/inbox SMTP rate limits, inbox quotas, CAPTCHA for /public/inboxes (off by default), MIME allowlists and attachment size caps, soft-delete with audit logging and a configurable retention sweep. Observability includes a Prometheus /metrics endpoint, a readiness probe that pings the DB, and structured Pino logging.
Key Features
- Disposable inboxes across unlimited custom domains with real-time delivery
- Full REST API: domains, inboxes, messages, search, attachment download
- Admin panel: user management, logs, reports, statistics
- DNS wizard surfacing SPF/DKIM/DMARC/MTA-STS/TLS-RPT and the TXT verification token
- Abuse controls: rate limits, quotas, CAPTCHA, attachment allowlist, sender blocklist
- One-command production deploy with extension-friendly CORS defaults; extension ZIP build
Status
The README declares it Production Ready with a live deployment listed (app/api/grafana.manhquy.id.vn); however, at link-audit time (2026-10-09) all three addresses returned 521 (origin down). Outbound mail (SES/Mailgun/SendGrid + DKIM signing) is explicitly listed as TODO — the platform currently receives mail only, it does not send.