Skip to main content
Emailens
Dedicated Email Sandbox & SMTP Relay ยท Updated October 2026

Email QA starts with
the real message.

Capture staging and test emails through an authenticated SMTP relay on port 2525 or a dedicated inbound MX address. Safely inspect MIME headers, extract OTP codes in CI/CD, and simulate visual rendering across 21 real email clients.

SMTP: smtp.emailens.dev:2525 (STARTTLS)
MX: inbox+...@{token}.try.emailens.dev

Dedicated Architecture

1 Sandbox = 1 Dedicated Ingestion Mode

No conflicting setups. Choose the ingestion mode tailored to your environment when creating each sandbox inbox.

Direct Inbound MX try.emailens.dev

Email Address Sandbox

A private receiving address dedicated to receiving mail from third-party platforms, webhooks, and transactional providers. Requires zero SMTP configuration.

  • Managed Auth testing: Route confirmation emails from Supabase Auth, Auth0, Clerk, or Firebase.
  • Transactional receipts: Intercept Stripe, Paddle, or GitHub webhooks.
  • Manual testing: Send real test emails from Gmail, Outlook, or Apple Mail to verify incoming rendering.
  • Instant address rotation: Re-roll tokens in one click if an address receives unwanted noise.
Address: inbox+clx9...@try.emailens.dev
SMTP Gateway port 2525 / 587

Authenticated SMTP Relay

Connect your backend mailer directly to Emailens. Outbound emails are captured in staging and never reach real customer mailboxes.

  • Framework support: Native drop-in for Nodemailer, Laravel, Django, Ruby on Rails, and Go.
  • STARTTLS enforced: Mandatory TLS 1.2+ encryption for all authenticated relay sessions.
  • Per-service credentials: Issue isolated credentials per developer, environment, or microservice.
  • Zero-downtime rotation: Rotate passwords in place without breaking in-flight tests.
Relay: smtp.emailens.dev:2525

Beyond Standard Browser Iframes

Four Pillars of Modern Email QA

Emailens doesn't just capture emails. It extracts tokens for automation and audits cross-client rendering.

Automatic Token & OTP Extraction

Parses 6-digit verification codes, alphanumeric tokens, and primary CTA URLs so CI tests don't need fragile regexes.

21-Client Rendering Simulation

Handoff any captured email to the visual engine to simulate Outlook Word quirks, Gmail Android dark mode, and Apple Mail.

Spam & Deliverability Scoring

Instant check of SpamAssassin heuristics, SPF / DKIM / DMARC authentication headers, and Gmail 102KB clipping limits.

Zero-Downtime Credential Rotation

Generate and rotate isolated SMTP credentials without breaking active runners. Passwords are safe with SHA-256 hashing.

Technical Comparison

Emailens vs Mailtrap vs MailHog

See why engineering teams choose Emailens for unified email delivery QA.

Feature Emailens Sandbox Mailtrap MailHog / Mailpit
Dedicated Ingestion Modes (Direct MX + SMTP) Yes (both) SMTP only (Sandbox) SMTP only
Cross-Client Visual Rendering (21 engines) Full DOM Simulation Browser iframe only Browser iframe only
Automatic OTP & Magic Link Extraction Built-in regex engine Manual HTML parsing Manual HTML parsing
CI/CD Long-Polling Endpoint (/wait) Single HTTP request Requires polling loops Requires polling loops
AI Coding Agent (MCP Server) Support Hosted MCP Tools None None
Zero-Downtime SMTP Credential Rotation One-click in UI / API Static shared token Unauthenticated / Static

Fast Integration

Connect Your Staging Environment in Minutes

No proprietary SDKs required. Standard SMTP protocol, clean REST APIs, and remote MCP.

Node.js / TypeScript

Send via Nodemailer Relay

Connect on port 2525 with STARTTLS. Messages are quarantined securely in your sandbox.

send-test-email.ts
19 lines
import nodemailer from "nodemailer";

const mailer = nodemailer.createTransport({
  host: "smtp.emailens.dev",
  port: 2525, // Or port 587
  secure: false, // Upgrades automatically via STARTTLS
  requireTLS: true,
  auth: {
    user: process.env.EMAILENS_SMTP_USER, // e.g. esmtp_staging_clx9
    pass: process.env.EMAILENS_SMTP_PASS, // Generated per-service password
  },
});

await mailer.sendMail({
  from: '"Acme Auth" <auth@myapp.com>',
  to: "user@example.com", // Safely captured; never escapes to real recipient
  subject: "Your verification code: 492810",
  html: "<p>Your code is <b>492810</b>. Click <a href='https://myapp.com/verify?code=492810'>here</a> to verify.</p>",
});
E2E Automation

Wait for OTP in Playwright

Long-poll the /wait endpoint until the email arrives and extract the code in milliseconds.

auth.spec.ts
26 lines
import { test, expect } from "@playwright/test";

test("signup flow extracts OTP and finishes onboarding", async ({ page }) => {
  const inboxId = process.env.EMAILENS_INBOX_ID;
  const apiKey = process.env.EMAILENS_API_KEY;

  // 1. Trigger signup in your web UI
  await page.goto("https://myapp.com/signup");
  await page.fill('input[name="email"]', "test-runner@try.emailens.dev");
  await page.click('button[type="submit"]');

  // 2. Long-poll Emailens Sandbox until the confirmation email arrives
  const waitRes = await fetch(
    `https://app.emailens.dev/api/sandbox/v1/messages/wait?inboxId=${inboxId}&timeout=30&subject=verification`,
    { headers: { Authorization: `Bearer ${apiKey}` } }
  );
  expect(waitRes.ok).toBeTruthy();
  const { message } = await waitRes.json();

  // 3. Immediately use the regex-extracted OTP code
  expect(message.otp).toBeDefined(); // e.g. "492810"
  await page.fill('input[name="code"]', message.otp);
  await page.click('button[type="submit"]');

  await expect(page).toHaveURL("https://myapp.com/welcome");
});
PHP / Laravel

Laravel Mailer Configuration

Standard .env configuration for Laravel 10/11 with TLS encryption.

.env
9 lines
# In your .env file:
MAIL_MAILER=smtp
MAIL_HOST=smtp.emailens.dev
MAIL_PORT=2525
MAIL_USERNAME=esmtp_laravel_worker
MAIL_PASSWORD=your_secure_password
MAIL_ENCRYPTION=tls
MAIL_FROM_ADDRESS="no-reply@myapp.local"
MAIL_FROM_NAME="My App Dev"
AI Coding Agents

Cursor & Claude MCP Server

Allow autonomous AI agents to query test inboxes, read OTPs, and verify email rendering.

.cursor/mcp.json
10 lines
{
  "mcpServers": {
    "emailens": {
      "url": "https://app.emailens.dev/api/mcp",
      "headers": {
        "Authorization": "Bearer ek_live_..."
      }
    }
  }
}

Frequently Asked Questions

Everything You Need to Know About the Sandbox

How does the Emailens SMTP relay work?

The Emailens SMTP relay operates on smtp.emailens.dev over port 2525 (or port 587) with mandatory STARTTLS encryption. You configure your application or backend mailer (such as Nodemailer, Laravel, Django, or Rails) with dedicated per-service credentials. All outbound emails are quarantined inside your test inbox and are never relayed to external recipients.

What is the difference between Direct Email Inbound and the SMTP Relay?

Direct Email Inbound provides dedicated @try.emailens.dev receiving addresses to capture emails sent from external third-party services like Supabase, Auth0, Stripe, or personal email clients. The SMTP Relay allows your backend code to directly connect via standard SMTP on port 2525. Each Emailens sandbox inbox is dedicated to one ingestion type to guarantee zero configuration confusion.

How does Emailens differ from Mailtrap or local MailHog?

Mailtrap and MailHog only display emails inside standard browser preview iframes, which fail to catch rendering quirks in Outlook desktop (Microsoft Word engine), Gmail app dark mode color inversions, or mobile clipping. Emailens couples safe SMTP capture with an authentic 21-client cross-client visual rendering engine, automatic OTP token extraction for CI/CD, and an MCP server for AI coding assistants.

How do I extract OTP codes and magic links in Playwright or Cypress?

Emailens provides a long-polling wait endpoint: GET /api/sandbox/v1/messages/wait?inboxId=...&timeout=30. When an email arrives, Emailens automatically parses the MIME payload and extracts the 6-digit OTP code, hyphenated verification tokens, and primary CTA URLs, returning them as structured JSON so your end-to-end test can continue immediately.

How does zero-downtime SMTP credential rotation work?

Each SMTP inbox supports generating multiple isolated credentials. When rotating credentials, Emailens provisions a new username and password while allowing the previous credential to remain active during your service restart. Once your mailer is updated with the new secret, the old credential can be revoked in one click with immediate termination.

Can AI coding agents like Claude or Cursor access the sandbox?

Yes. Emailens includes a remote Model Context Protocol (MCP) server. By connecting Cursor, Windsurf, or Claude Desktop to https://app.emailens.dev/api/mcp, AI agents can autonomously list test inboxes, inspect captured emails, extract login links, and verify authentication loops.

Stop guessing how emails look in staging.

Capture real staging messages, finish CI authentication runs, and simulate 21 email client engines in one platform.