Transport
TLS for the site, and TLS on SMTP and IMAP.
Security
Passwords are hashed with Argon2id. Mailbox secrets are encrypted at rest. API keys are shown once. Company addresses are indexed for our own support desk and are not readable through the public API.
TLS for the site, and TLS on SMTP and IMAP.
SPF, DKIM, and DMARC on mailbelo.com. They show a message is authentic. They do not force inbox placement.
Rate limits on sign-in, signup, and the API. The public API sends X-RateLimit-Limit: 120.
Account lockout after repeated failures. API keys are shown once.
Attachment and HTML limits keep a mailbox from becoming a file drop. Report a problem to [email protected] or the abuse form. We do not offer features whose purpose is to evade another company’s abuse systems. A new server still has to earn a reputation.