Public inboxes

TinyMail does not authenticate inbox readers. Anyone who knows or guesses an address can view messages through the web or API. These are public temporary inboxes, not private mailboxes.

Sanitizing incoming HTML

Email HTML is sanitized on receipt: scripts, forms, images, styles, and unsafe links are removed. The web interface displays sanitized HTML in a sandboxed iframe without running scripts; plain-text messages are assigned using textContent.

The message-list API does not return message bodies; only the detail response includes body and sanitized html_body.

Rate and resource limits

The API rate-limits by IP address and endpoint group (reading inboxes, checking/adding domains, deleting messages). SMTP limits concurrent connections, connections per IP, recipients per message, and message size. Per-inbox message quotas and overall storage limits apply; new messages are rejected when limits are exceeded.

Data retention

Emails are automatically deleted after 3 days. TinyMail only receives email and does not send it, so it does not maintain an outgoing mail queue. Do not use TinyMail for long-term secrets.

The 3-day retention period applies to the live service. Backups may retain copies longer; deletion from every copy is not guaranteed at that time. Custom-domain inboxes use the same public access model.

Responsible vulnerability disclosure

TinyMail does not publish a dedicated security mailbox on this page. When describing an issue, use publicly observable behavior (web, API, incoming SMTP) and do not send tokens, passwords, message contents, or internal addresses.

This page does not list internal server addresses, keys, or private deployment details.