SECURITY AT SMTPBOX

Test email is still sensitive data.

SMTPBox is designed to keep non-production mail contained, limit access to authorised users and remove message data after a defined retention period.

TLSEncrypted connections
ScopedService credentials
7–30 daysMessage retention
SandboxedNo recipient delivery

Built around containment

SMTPBox accepts messages for inspection in a sandbox and does not forward them to their original recipient addresses. This reduces the chance that a development, staging or automated-test environment contacts a real customer.

Transport and access

  • Encrypted transport. SMTP connections support TLS; dashboard and API traffic use HTTPS.
  • Authenticated access. Dashboard users sign in, while integrations use generated SMTP credentials or API keys.
  • Scoped credentials. Teams can separate access between inboxes and integrations.
  • Workspace controls. Teams can restrict access to members who need it and remove it when roles change.

Data lifecycle

Messages are held for the plan's retention period—currently 7 days on Free and 30 days on Unlimited—and can be deleted sooner. SMTPBox is not permanent storage. Operational security records may be retained separately where needed to protect the service and meet legal obligations.

Your security responsibilities

Use synthetic data where possible. Do not include production secrets, unnecessary personal data or live payment information in test messages. Keep credentials outside source control, rotate exposed secrets, separate environments and remove users who no longer need access.

Report a vulnerability

Email security@smtpbox.dev with the affected feature, reproduction steps, potential impact and supporting details with secrets removed. Do not access other users' data, change or delete data, interrupt the service, use social engineering, perform denial-of-service tests or run excessive automated scans. Give us reasonable time to investigate before disclosure.

Think a credential is exposed?

Revoke or rotate it immediately, then tell us the approximate exposure time and affected workspace. Never email the exposed secret.

Email security →