Concepts

Security model

How Squadmail isolates workspaces, renders untrusted mail and protects credentials.

Untrusted HTML

Email HTML is hostile by default. Squadmail:

  1. strips scripts, frames, forms, event handlers and javascript: URLs on ingest,
  2. renders mail in a sandboxed iframe without scripts or same-origin access,
  3. applies a strict CSP inside the frame and blocks remote images until you click Load images (no tracking pixels),
  4. inlines cid: images as data URIs, so the frame never needs your session.

Attachments are served with content-disposition: attachment and a sandboxing CSP.

Credentials

  • Passwords are hashed by Better Auth; sessions are HTTP-only cookies.
  • API keys are random 30-byte secrets, stored only as SHA-256 hashes, shown once, revocable, optionally expiring.
  • OAuth tokens for MCP clients are managed by @cloudflare/workers-oauth-provider (hashed in KV). Consent requires a signed-in user who picks the workspace and scopes. Grants are re-checked against current membership on every call.
  • Webhook payloads are signed with HMAC-SHA256 (t=…,v1=…) using a per-endpoint secret.

Isolation

Every query is scoped by workspace id derived from the credential — API keys cannot address another workspace’s inboxes, even by address.

Abuse controls

Sender allow/block lists, per-inbox and per-sender flood limits, daily quotas, Turnstile-ready sign-ups and invite-only mode by default.

Reporting

Please report vulnerabilities privately via GitHub Security Advisories on the repository.

Edit this page on GitHub