Mail that runs on your own server.

Carte Mail is a complete mail platform you install on hardware you control. IMAP, SMTP, DKIM, DMARC, MTA-STS, spam scoring, storage. Your domains, your reputation, your message bodies.

Onboarding the first mailboxes by hand while the self-serve parts are built.

carte verify carte-mail.app
  • SPF pass a: and ip6:, both families
  • DKIM pass selector "carte", 2048-bit
  • DMARC pass p=quarantine, rua set
  • MTA-STS pass mode: testing, id matches
  • PTR pass forward-confirmed
  • TLS pass renews on a timer
6 of 6 passing checked from outside

What you stop paying for

A sending service bills you for each message, forever, and keeps your deliverability in a pool you do not control. Owning the server changes the shape of the cost and the shape of the risk.

Rented sending

  • Billed per thousand messages, indefinitely
  • Delivery depends on a shared pool and someone else’s reputation
  • Message bodies rest in storage you cannot inspect
  • Their outage is your outage, with no recourse but a status page
  • Leaving means re-publishing every DNS record you set up

Mail you run

  • One server, priced by capacity rather than by message count
  • Your own address, your own PTR, your own reputation to build
  • Bodies in your object storage, under your retention rules
  • An outage you can log into and fix
  • DNS, DKIM keys and the policy record stay yours

How it works

Setup is four steps, and the second one is the one that matters: the panel reports what a receiving server sees, not what you typed into your DNS provider.

  1. 01

    Point DNS at your server

    Carte generates the exact MX, SPF, DKIM and DMARC records for your domain, with the DKIM key pair made on the server and the private half never leaving it.

  2. 02

    Verify from the outside

    Every record is checked against public resolvers and the mismatch that matters is reported by name — a key that differs by one character reads as a mismatch rather than as success.

  3. 03

    Add mailboxes

    Create addresses, set storage limits, and issue per-user app passwords. One address can be shared by several people with different roles.

  4. 04

    Connect a client

    IMAP over TLS on 993 and submission with STARTTLS on 587, so Thunderbird, Apple Mail and Outlook work without plugins or a bridge.

What it runs

The unglamorous parts are the ones that decide whether mail arrives, so they are the parts that got the attention.

Protocols

IMAP4rev1 over TLS on 993 with IDLE push, COPY, MOVE and EXPUNGE; SMTP submission on 465 and 587. Tested against a real desktop client, not only against the spec.

Inbound where port 25 is blocked

Many hosts cannot receive on 25 at all. Inbound can arrive through Cloudflare Email Routing and a Worker that hands the raw message to the server over HTTPS.

Deliverability

Per-domain DKIM signing, SPF covering both address families, DMARC with a quarantine cap so a strict sender policy never destroys legitimate mail, MTA-STS served properly over HTTPS, and TLS reporting.

Storage and retention

Message bodies in S3-compatible object storage, metadata in Postgres. Separate retention windows for junk, trash and everything, each purge recorded in the audit log.

Tenant isolation

Isolation is enforced by the database with row-level security rather than by remembering a WHERE clause, so a forgotten filter returns nothing instead of someone else’s mail.

Operations

Prometheus metrics for queue depth, storage and send rates; a health endpoint per service; an audit record for every delivery and configuration change.

What isn’t ready yet

You are being asked to move your correspondence onto this. You should know exactly what is missing before you decide, rather than finding out afterwards.

  • Webmail does not exist. You read your mail in Thunderbird, Apple Mail or Outlook. There is no browser client yet, so the answer to “can I check my mail on a borrowed laptop” is currently no.
  • Signup is not self-serve. Mailboxes are provisioned by hand. That is fine for the first few customers and not fine at a hundred.
  • There is no billing system. Which is to say nothing is charged yet. It also means there is no plan to outgrow and no invoice to dispute.
  • One server, no failover. Mail runs on a single host with a managed single-node database. Backups are taken and the restore path is tested; automatic failover is not implemented.
  • No independent security review. The authentication, transport and tenancy paths have tests and negative controls, but nobody outside this project has tried to break them.

Start with one domain.

Send a message and we will set the records up with you, verify them from the public resolvers, and hand over the first mailbox. If it does not work, you still have your mail and you have lost an afternoon.

Request access