About spotmail

Verification mail should not outlive the task.

spotmail is receive-only verification infrastructure. It gives a person, test, or agent an address for one bounded task—and gives that address an exit time.

Verification task / operating envelope

address active

task-7f2c@spotmail.app

Direction
receive only
Useful output
code or action link
Hard stop
24 hours maximum

Use it with a clear boundary

Good for

  • Verification codes
  • One-off product trials
  • Low-risk downloads and registrations

Never for

  • Account recovery
  • Payments, orders, or receipts
  • Legal notices or anything needed later

The category

One short-lived primitive, used three ways.

The mailbox is not the destination. The task is complete when the expected message arrives, the useful evidence is returned, and the inbox can disappear.

For a person

Open one address in the browser, copy the code, and leave without creating an account.

For a test

Create a fresh inbox per run, wait for a matching sender, and assert the code or link.

For an agent

Delegate one verification task through a scoped token instead of handing over a permanent mailbox.

Inbox lifecycle

Temporary is enforced by the lifecycle.

An inbox lasts 1, 6, 12, or 24 hours. The maximum total lifetime is 24 hours.

  1. 01

    Create

    Choose a lifetime and receive a new address. A guest can keep one active inbox.

  2. 02

    Receive

    Messages appear in the workspace while the inbox remains active.

  3. 03

    Match

    Automation can apply a sender and artifact policy before returning a result.

  4. 04

    Use

    A person reads sandboxed HTML or text; automation receives structured evidence.

  5. 05

    Expire

    Server access ends and scheduled deletion begins. A local read-only snapshot may remain in this browser.

Three access models

The address is public. Control is not.

Guest inbox

A separate access token stays in this browser. The server stores only its hash, and the token is not placed in the page URL.

Signed-in inbox

Account ownership and your active session control access. Signing in also enables up to three active inboxes and cross-device restore.

Project Key

A scoped key creates Verification Runs; each run receives its own token for claim, completion, or cancellation.

Reader boundary

Contained, not magically risk-free.

Scripts and forms are blocked inside HTML mail. Tiny tracking images are filtered, but other HTTPS images and external links can still contact third parties. Plain text is the quieter option.

Operating facts

Availability
Free Web + Automation BETA
Mail direction
Receive only
Maximum inbox life
24 hours
Infrastructure
Cloudflare Workers and storage
Support
support@spotmail.app

Verification in. Evidence out. Inbox gone.

Give every verification task an inbox with an exit plan.

Open the workspace
spotmail

Short-lived verification inboxes for people, test automation, and AI agents.

Operating boundary

Include a Request ID, never a code or private link.

1Address issued
2Mail matched
3Evidence returned
4Expired
BETAReceive only1–24 hour inboxes

Do not use spotmail for account recovery, purchases, or mail you may need later.

Server inboxes are removed after expiry. This browser may keep read-only local history until you clear it.