Built around containment
SMTPBox accepts messages for inspection in a sandbox and does not forward them to their original recipient addresses. This reduces the chance that a development, staging or automated-test environment contacts a real customer.
Transport and access
- Encrypted transport. SMTP connections support TLS; dashboard and API traffic use HTTPS.
- Authenticated access. Dashboard users sign in, while integrations use generated SMTP credentials or API keys.
- Scoped credentials. Teams can separate access between inboxes and integrations.
- Workspace controls. Teams can restrict access to members who need it and remove it when roles change.
Data lifecycle
Messages are held for the plan's retention period—currently 7 days on Free and 30 days on Unlimited—and can be deleted sooner. SMTPBox is not permanent storage. Operational security records may be retained separately where needed to protect the service and meet legal obligations.
Your security responsibilities
Use synthetic data where possible. Do not include production secrets, unnecessary personal data or live payment information in test messages. Keep credentials outside source control, rotate exposed secrets, separate environments and remove users who no longer need access.
Report a vulnerability
Email security@smtpbox.dev with the affected feature, reproduction steps, potential impact and supporting details with secrets removed. Do not access other users' data, change or delete data, interrupt the service, use social engineering, perform denial-of-service tests or run excessive automated scans. Give us reasonable time to investigate before disclosure.
Think a credential is exposed?
Revoke or rotate it immediately, then tell us the approximate exposure time and affected workspace. Never email the exposed secret.
Email security →