mirror of
https://github.com/dreamhunter2333/cloudflare_temp_email.git
synced 2026-08-06 05:53:36 +08:00
e499211197b8bf034ef2f3ad74e94d33e012caf0
* feat: add setting to disable auto-loading external images in emails Adds a privacy setting (default off) that blocks remote images in email content until the user explicitly loads them per message. Blocked images are replaced with a placeholder; a banner allows one-click loading. Closes #1073 Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * fix(frontend): block remote content with DOMPurify and an allowlist policy Address review on the blocking logic. The first pass matched quoted `<img src="http...">` with a regex, which left unquoted src, srcset, `<source>`, CSS background-image, SVG `<image href>` and entity-encoded schemes fetching as usual, and replaced only `src` on an element that also carried `srcset` -- so the browser still had a remote candidate to prefer while the UI claimed the image was blocked. Two changes rather than a wider regex: Sanitising is delegated to DOMPurify, which is already a dependency. The hard part here is not enumerating attributes but surviving the parser: a hand-written pass over a DOMParser tree still missed that `<noscript>` is parsed as markup where scripting is off and as raw text where it is on, so a `</noscript>` smuggled into an attribute value reopens the document at render time and revives an `<img>` the cleaner never saw. Elements that fetch by themselves or change how relative URLs resolve -- base, meta, script, link, iframe, object, embed, noscript -- are dropped in this mode. `<style>` is kept so layout survives, with its url(), image-set() and @import references filtered. URL classification is an allowlist. Asking "does this look remote?" means enumerating every disguise -- backslash authorities, tab/newline/control characters the URL parser strips, CSS escapes, schemes with no slashes -- and losing to the first one not thought of. Asking "can I prove this is local?" fails closed instead: cid:, data:image/, blob: and relative paths are kept, everything else is blocked. Relative paths are only safe because `<base>` is removed, which is what stopped it re-pointing them at a tracker. The blocked URL is discarded rather than parked in a data-* attribute, so "the cleaned body contains no remote URL at all" is directly assertable; restoring images re-renders from the untouched source. Also: blob: is added to the allowed schemes -- DOMPurify's default list omits it, and email-parser rewrites cid: attachments into blob: URLs, so without it every inline image would be stripped along with the trackers. The policy lives in its own module with its own tests (30 attack vectors, 7 preservation cases); email-parser.js goes back to MIME parsing only. The per-mail override no longer initialises from the global setting, and the banner reports the blocked count as the PR description promised. Refs #1073 Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
…
…
…
…
…
…
…
…
…
…
…
Cloudflare Temp Email - Free Temporary Email Service
中文文档 | English Document | 日本語ドキュメント
This project is for learning and personal use only. Please do not use it for any illegal activities, or you will be responsible for the consequences.
A fully-featured temporary email service!
- Completely Free - Built on Cloudflare's free services with zero cost
- High Performance - Rust WASM email parsing for extremely fast response
- Modern UI - Responsive design with multi-language support and easy operation
- Address Password - Support setting individual passwords for email addresses to enhance security
- Agent-friendly - Built-in mailbox
skillfor AI agents - Mobile admin - Community client CloudMail for Android admin and mailbox management
Deployment Documentation - Quick Start
Documentation | Github Action Deployment Guide
Changelog
See CHANGELOG for the latest updates.
Live Demo
Try it now → https://mail.awsl.uk/
Table of Contents (Click to expand/collapse)
Core Features
Core Features Details (Click to expand/collapse)
Email Processing
- Use
rust wasmto parse emails, with fast parsing speed. Almost all emails can be parsed. Even emails that Node.js parsing modules fail to parse can be successfully parsed by rust wasm - AI Email Recognition - Use Cloudflare Workers AI to automatically extract verification codes, authentication links, service links and other important information from emails
- Support optional random second-level subdomain mailbox creation for selected base domains
- Support sending emails with
DKIMverification - Support multiple sending methods such as
SMTPandResend - Add attachment viewing feature with support for displaying attachment images
- Support S3 attachment storage and deletion
- Spam detection and blacklist/whitelist configuration
- Email forwarding feature with global forwarding address support
User Management
- Use
credentialsto log in to previously used mailboxes - Add complete user registration and login functionality. Users can bind email addresses and automatically obtain email JWT credentials to switch between different mailboxes after binding
- Support
OAuth2third-party login (Github, Authentik, etc.) - Support
Passkeypasswordless login - User role management with support for multi-role domain and prefix configuration
- User inbox viewing with address and keyword filtering support
Admin Features
- Complete admin console
- Create mailboxes without prefix in
adminbackend - Admin user management page with user address viewing feature
- Scheduled cleanup function with support for multiple cleanup strategies
- Get mailboxes with custom names,
admincan configure blacklist - Add access password for use as a private site
Multi-language & Interface
- Both frontend and backend support multi-language
- Modern UI design with responsive layout
- Google Ads integration support
- Use shadow DOM to prevent style pollution
- Support URL JWT parameter auto-login
Integration & Extensions
- Complete
Telegram Botsupport,Telegrampush notifications, and Telegram Bot mini app - Add
SMTP proxy serversupportingSMTPfor sending emails andIMAPfor viewing emails - Webhook support and message push integration
- Support
CF TurnstileCAPTCHA verification - Rate limiting configuration to prevent abuse
- Agent-friendly: bundled
cf-temp-mail-agent-mailskill lets AI agents consume a mailbox directly, see docs - Community mobile admin client: CloudMail is built with Expo / React Native for this project's compatible API, providing an Android admin console, address management, inbox/sent/unknown mail, quick verification-code copy, OLED black theme, and local grouping.
Technical Architecture
Technical Architecture Details (Click to expand/collapse)
System Architecture
- Database: Cloudflare D1 as the main database
- Frontend Deployment: Deploy frontend using Cloudflare Pages
- Backend Deployment: Deploy backend using Cloudflare Workers
- Email Routing: Use Cloudflare Email Routing
Tech Stack
- Frontend: Vue 3 + Vite + TypeScript
- Backend: TypeScript + Cloudflare Workers
- Email Parsing: Rust WASM (mail-parser-wasm)
- Database: Cloudflare D1 (SQLite)
- Storage: Cloudflare KV + R2 (optional S3)
- Proxy Service: Python SMTP/IMAP Proxy Server
Main Components
- Worker: Core backend service
- Frontend: Vue 3 user interface
- Mail Parser WASM: Rust email parsing module
- SMTP Proxy Server: Python email proxy service
- Pages Functions: Cloudflare Pages middleware
- Documentation: VitePress documentation site
Important Notes
- When adding domain records in Resend, if your DNS provider is hosting your 3rd level domain a.b.com, please remove the 2nd level domain prefix b from the default name generated by Resend, otherwise it will add a.b.b.com, causing verification to fail. After adding the record, you can verify it using:
nslookup -qt="mx" a.b.com 1.1.1.1
Join the Community
Languages
TypeScript
62.9%
Vue
27.2%
Python
5.2%
JavaScript
3.8%
Rust
0.4%
Other
0.4%