Email QA starts with
the real message.
Capture staging and test emails through an authenticated SMTP relay on port 2525 or a dedicated inbound MX address. Safely inspect MIME headers, extract OTP codes in CI/CD, and simulate visual rendering across 21 real email clients.
Dedicated Architecture
1 Sandbox = 1 Dedicated Ingestion Mode
No conflicting setups. Choose the ingestion mode tailored to your environment when creating each sandbox inbox.
Email Address Sandbox
A private receiving address dedicated to receiving mail from third-party platforms, webhooks, and transactional providers. Requires zero SMTP configuration.
- Managed Auth testing: Route confirmation emails from Supabase Auth, Auth0, Clerk, or Firebase.
- Transactional receipts: Intercept Stripe, Paddle, or GitHub webhooks.
- Manual testing: Send real test emails from Gmail, Outlook, or Apple Mail to verify incoming rendering.
- Instant address rotation: Re-roll tokens in one click if an address receives unwanted noise.
Authenticated SMTP Relay
Connect your backend mailer directly to Emailens. Outbound emails are captured in staging and never reach real customer mailboxes.
- Framework support: Native drop-in for Nodemailer, Laravel, Django, Ruby on Rails, and Go.
- STARTTLS enforced: Mandatory TLS 1.2+ encryption for all authenticated relay sessions.
- Per-service credentials: Issue isolated credentials per developer, environment, or microservice.
- Zero-downtime rotation: Rotate passwords in place without breaking in-flight tests.
Beyond Standard Browser Iframes
Four Pillars of Modern Email QA
Emailens doesn't just capture emails. It extracts tokens for automation and audits cross-client rendering.
Automatic Token & OTP Extraction
Parses 6-digit verification codes, alphanumeric tokens, and primary CTA URLs so CI tests don't need fragile regexes.
21-Client Rendering Simulation
Handoff any captured email to the visual engine to simulate Outlook Word quirks, Gmail Android dark mode, and Apple Mail.
Spam & Deliverability Scoring
Instant check of SpamAssassin heuristics, SPF / DKIM / DMARC authentication headers, and Gmail 102KB clipping limits.
Zero-Downtime Credential Rotation
Generate and rotate isolated SMTP credentials without breaking active runners. Passwords are safe with SHA-256 hashing.
Technical Comparison
Emailens vs Mailtrap vs MailHog
See why engineering teams choose Emailens for unified email delivery QA.
| Feature | Emailens Sandbox | Mailtrap | MailHog / Mailpit |
|---|---|---|---|
| Dedicated Ingestion Modes (Direct MX + SMTP) | Yes (both) | SMTP only (Sandbox) | SMTP only |
| Cross-Client Visual Rendering (21 engines) | Full DOM Simulation | Browser iframe only | Browser iframe only |
| Automatic OTP & Magic Link Extraction | Built-in regex engine | Manual HTML parsing | Manual HTML parsing |
| CI/CD Long-Polling Endpoint (/wait) | Single HTTP request | Requires polling loops | Requires polling loops |
| AI Coding Agent (MCP Server) Support | Hosted MCP Tools | None | None |
| Zero-Downtime SMTP Credential Rotation | One-click in UI / API | Static shared token | Unauthenticated / Static |
Fast Integration
Connect Your Staging Environment in Minutes
No proprietary SDKs required. Standard SMTP protocol, clean REST APIs, and remote MCP.
Send via Nodemailer Relay
Connect on port 2525 with STARTTLS. Messages are quarantined securely in your sandbox.
import nodemailer from "nodemailer";
const mailer = nodemailer.createTransport({
host: "smtp.emailens.dev",
port: 2525, // Or port 587
secure: false, // Upgrades automatically via STARTTLS
requireTLS: true,
auth: {
user: process.env.EMAILENS_SMTP_USER, // e.g. esmtp_staging_clx9
pass: process.env.EMAILENS_SMTP_PASS, // Generated per-service password
},
});
await mailer.sendMail({
from: '"Acme Auth" <auth@myapp.com>',
to: "user@example.com", // Safely captured; never escapes to real recipient
subject: "Your verification code: 492810",
html: "<p>Your code is <b>492810</b>. Click <a href='https://myapp.com/verify?code=492810'>here</a> to verify.</p>",
}); Wait for OTP in Playwright
Long-poll the /wait endpoint until the email arrives and extract the code in milliseconds.
import { test, expect } from "@playwright/test";
test("signup flow extracts OTP and finishes onboarding", async ({ page }) => {
const inboxId = process.env.EMAILENS_INBOX_ID;
const apiKey = process.env.EMAILENS_API_KEY;
// 1. Trigger signup in your web UI
await page.goto("https://myapp.com/signup");
await page.fill('input[name="email"]', "test-runner@try.emailens.dev");
await page.click('button[type="submit"]');
// 2. Long-poll Emailens Sandbox until the confirmation email arrives
const waitRes = await fetch(
`https://app.emailens.dev/api/sandbox/v1/messages/wait?inboxId=${inboxId}&timeout=30&subject=verification`,
{ headers: { Authorization: `Bearer ${apiKey}` } }
);
expect(waitRes.ok).toBeTruthy();
const { message } = await waitRes.json();
// 3. Immediately use the regex-extracted OTP code
expect(message.otp).toBeDefined(); // e.g. "492810"
await page.fill('input[name="code"]', message.otp);
await page.click('button[type="submit"]');
await expect(page).toHaveURL("https://myapp.com/welcome");
}); Laravel Mailer Configuration
Standard .env configuration for Laravel 10/11 with TLS encryption.
# In your .env file:
MAIL_MAILER=smtp
MAIL_HOST=smtp.emailens.dev
MAIL_PORT=2525
MAIL_USERNAME=esmtp_laravel_worker
MAIL_PASSWORD=your_secure_password
MAIL_ENCRYPTION=tls
MAIL_FROM_ADDRESS="no-reply@myapp.local"
MAIL_FROM_NAME="My App Dev" Cursor & Claude MCP Server
Allow autonomous AI agents to query test inboxes, read OTPs, and verify email rendering.
{
"mcpServers": {
"emailens": {
"url": "https://app.emailens.dev/api/mcp",
"headers": {
"Authorization": "Bearer ek_live_..."
}
}
}
} Frequently Asked Questions
Everything You Need to Know About the Sandbox
How does the Emailens SMTP relay work?
The Emailens SMTP relay operates on smtp.emailens.dev over port 2525 (or port 587) with mandatory STARTTLS encryption. You configure your application or backend mailer (such as Nodemailer, Laravel, Django, or Rails) with dedicated per-service credentials. All outbound emails are quarantined inside your test inbox and are never relayed to external recipients.
What is the difference between Direct Email Inbound and the SMTP Relay?
Direct Email Inbound provides dedicated @try.emailens.dev receiving addresses to capture emails sent from external third-party services like Supabase, Auth0, Stripe, or personal email clients. The SMTP Relay allows your backend code to directly connect via standard SMTP on port 2525. Each Emailens sandbox inbox is dedicated to one ingestion type to guarantee zero configuration confusion.
How does Emailens differ from Mailtrap or local MailHog?
Mailtrap and MailHog only display emails inside standard browser preview iframes, which fail to catch rendering quirks in Outlook desktop (Microsoft Word engine), Gmail app dark mode color inversions, or mobile clipping. Emailens couples safe SMTP capture with an authentic 21-client cross-client visual rendering engine, automatic OTP token extraction for CI/CD, and an MCP server for AI coding assistants.
How do I extract OTP codes and magic links in Playwright or Cypress?
Emailens provides a long-polling wait endpoint: GET /api/sandbox/v1/messages/wait?inboxId=...&timeout=30. When an email arrives, Emailens automatically parses the MIME payload and extracts the 6-digit OTP code, hyphenated verification tokens, and primary CTA URLs, returning them as structured JSON so your end-to-end test can continue immediately.
How does zero-downtime SMTP credential rotation work?
Each SMTP inbox supports generating multiple isolated credentials. When rotating credentials, Emailens provisions a new username and password while allowing the previous credential to remain active during your service restart. Once your mailer is updated with the new secret, the old credential can be revoked in one click with immediate termination.
Can AI coding agents like Claude or Cursor access the sandbox?
Yes. Emailens includes a remote Model Context Protocol (MCP) server. By connecting Cursor, Windsurf, or Claude Desktop to https://app.emailens.dev/api/mcp, AI agents can autonomously list test inboxes, inspect captured emails, extract login links, and verify authentication loops.
Stop guessing how emails look in staging.
Capture real staging messages, finish CI authentication runs, and simulate 21 email client engines in one platform.