Mail that runs on your own server.
Carte Mail is a complete mail platform you install on hardware you control. IMAP, SMTP, DKIM, DMARC, MTA-STS, spam scoring, storage. Your domains, your reputation, your message bodies.
Onboarding the first mailboxes by hand while the self-serve parts are built.
- SPF pass a: and ip6:, both families
- DKIM pass selector "carte", 2048-bit
- DMARC pass p=quarantine, rua set
- MTA-STS pass mode: testing, id matches
- PTR pass forward-confirmed
- TLS pass renews on a timer
What you stop paying for
A sending service bills you for each message, forever, and keeps your deliverability in a pool you do not control. Owning the server changes the shape of the cost and the shape of the risk.
Rented sending
- Billed per thousand messages, indefinitely
- Delivery depends on a shared pool and someone else’s reputation
- Message bodies rest in storage you cannot inspect
- Their outage is your outage, with no recourse but a status page
- Leaving means re-publishing every DNS record you set up
Mail you run
- One server, priced by capacity rather than by message count
- Your own address, your own PTR, your own reputation to build
- Bodies in your object storage, under your retention rules
- An outage you can log into and fix
- DNS, DKIM keys and the policy record stay yours
How it works
Setup is four steps, and the second one is the one that matters: the panel reports what a receiving server sees, not what you typed into your DNS provider.
-
01
Point DNS at your server
Carte generates the exact MX, SPF, DKIM and DMARC records for your domain, with the DKIM key pair made on the server and the private half never leaving it.
-
02
Verify from the outside
Every record is checked against public resolvers and the mismatch that matters is reported by name — a key that differs by one character reads as a mismatch rather than as success.
-
03
Add mailboxes
Create addresses, set storage limits, and issue per-user app passwords. One address can be shared by several people with different roles.
-
04
Connect a client
IMAP over TLS on 993 and submission with STARTTLS on 587, so Thunderbird, Apple Mail and Outlook work without plugins or a bridge.
What it runs
The unglamorous parts are the ones that decide whether mail arrives, so they are the parts that got the attention.
Protocols
IMAP4rev1 over TLS on 993 with IDLE push, COPY, MOVE and EXPUNGE; SMTP submission on 465 and 587. Tested against a real desktop client, not only against the spec.
Inbound where port 25 is blocked
Many hosts cannot receive on 25 at all. Inbound can arrive through Cloudflare Email Routing and a Worker that hands the raw message to the server over HTTPS.
Deliverability
Per-domain DKIM signing, SPF covering both address families, DMARC with a quarantine cap so a strict sender policy never destroys legitimate mail, MTA-STS served properly over HTTPS, and TLS reporting.
Storage and retention
Message bodies in S3-compatible object storage, metadata in Postgres. Separate retention windows for junk, trash and everything, each purge recorded in the audit log.
Tenant isolation
Isolation is enforced by the database with row-level security rather than by remembering a WHERE clause, so a forgotten filter returns nothing instead of someone else’s mail.
Operations
Prometheus metrics for queue depth, storage and send rates; a health endpoint per service; an audit record for every delivery and configuration change.
What isn’t ready yet
You are being asked to move your correspondence onto this. You should know exactly what is missing before you decide, rather than finding out afterwards.
- Webmail does not exist. You read your mail in Thunderbird, Apple Mail or Outlook. There is no browser client yet, so the answer to “can I check my mail on a borrowed laptop” is currently no.
- Signup is not self-serve. Mailboxes are provisioned by hand. That is fine for the first few customers and not fine at a hundred.
- There is no billing system. Which is to say nothing is charged yet. It also means there is no plan to outgrow and no invoice to dispute.
- One server, no failover. Mail runs on a single host with a managed single-node database. Backups are taken and the restore path is tested; automatic failover is not implemented.
- No independent security review. The authentication, transport and tenancy paths have tests and negative controls, but nobody outside this project has tried to break them.
Start with one domain.
Send a message and we will set the records up with you, verify them from the public resolvers, and hand over the first mailbox. If it does not work, you still have your mail and you have lost an afternoon.