{"id":13622984,"url":"https://github.com/markushinz/aws-ses-pop3-server","last_synced_at":"2026-03-07T12:13:56.384Z","repository":{"id":36978707,"uuid":"255984316","full_name":"markushinz/aws-ses-pop3-server","owner":"markushinz","description":"The missing POP3 💌 server for Amazon Simple Email Service - written in golang.","archived":false,"fork":false,"pushed_at":"2026-03-01T10:03:25.000Z","size":1164,"stargazers_count":44,"open_issues_count":1,"forks_count":16,"subscribers_count":2,"default_branch":"main","last_synced_at":"2026-03-01T13:56:32.719Z","etag":null,"topics":["aws","aws-s3","aws-ses","email","go","golang","mail","pop3","pop3-server","ses"],"latest_commit_sha":null,"homepage":"","language":"Go","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/markushinz.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2020-04-15T17:06:06.000Z","updated_at":"2026-03-01T10:00:19.000Z","dependencies_parsed_at":"2026-03-01T12:13:31.909Z","dependency_job_id":null,"html_url":"https://github.com/markushinz/aws-ses-pop3-server","commit_stats":null,"previous_names":[],"tags_count":1027,"template":false,"template_full_name":null,"purl":"pkg:github/markushinz/aws-ses-pop3-server","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/markushinz%2Faws-ses-pop3-server","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/markushinz%2Faws-ses-pop3-server/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/markushinz%2Faws-ses-pop3-server/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/markushinz%2Faws-ses-pop3-server/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/markushinz","download_url":"https://codeload.github.com/markushinz/aws-ses-pop3-server/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/markushinz%2Faws-ses-pop3-server/sbom","scorecard":{"id":441188,"data":{"date":"2025-08-11","repo":{"name":"github.com/markushinz/aws-ses-pop3-server","commit":"6b553eedc838b36d74b8fee4ec2bfeff46b70fba"},"scorecard":{"version":"v5.2.1-40-gf6ed084d","commit":"f6ed084d17c9236477efd66e5b258b9d4cc7b389"},"score":5.5,"checks":[{"name":"Code-Review","score":-1,"reason":"Found no human activity in the last 30 changesets","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#code-review"}},{"name":"Maintained","score":10,"reason":"27 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#maintained"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#binary-artifacts"}},{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#dangerous-workflow"}},{"name":"Token-Permissions","score":0,"reason":"detected GitHub workflow tokens with excessive permissions","details":["Warn: no topLevel permission defined: .github/workflows/ci.yaml:1","Warn: no topLevel permission defined: .github/workflows/merge.yaml:1","Info: no jobLevel write permissions found"],"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#token-permissions"}},{"name":"Pinned-Dependencies","score":2,"reason":"dependency not pinned by hash detected -- score normalized to 2","details":["Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yaml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/markushinz/aws-ses-pop3-server/ci.yaml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yaml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/markushinz/aws-ses-pop3-server/ci.yaml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yaml:37: update your workflow using https://app.stepsecurity.io/secureworkflow/markushinz/aws-ses-pop3-server/ci.yaml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yaml:42: update your workflow using https://app.stepsecurity.io/secureworkflow/markushinz/aws-ses-pop3-server/ci.yaml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yaml:44: update your workflow using https://app.stepsecurity.io/secureworkflow/markushinz/aws-ses-pop3-server/ci.yaml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yaml:49: update your workflow using https://app.stepsecurity.io/secureworkflow/markushinz/aws-ses-pop3-server/ci.yaml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yaml:53: update your workflow using https://app.stepsecurity.io/secureworkflow/markushinz/aws-ses-pop3-server/ci.yaml/main?enable=pin","Warn: goCommand not pinned by hash: .github/workflows/ci.yaml:29","Info:   1 out of   2 GitHub-owned GitHubAction dependencies pinned","Info:   0 out of   6 third-party GitHubAction dependencies pinned","Info:   2 out of   2 containerImage dependencies pinned","Info:   0 out of   1 goCommand dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#pinned-dependencies"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#cii-best-practices"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#fuzzing"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: Apache License 2.0: LICENSE:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#license"}},{"name":"Security-Policy","score":0,"reason":"security policy file not detected","details":["Warn: no security policy file detected","Warn: no security file to analyze","Warn: no security file to analyze","Warn: no security file to analyze"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#security-policy"}},{"name":"Branch-Protection","score":-1,"reason":"internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration","details":null,"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#branch-protection"}},{"name":"Signed-Releases","score":0,"reason":"Project has not signed or included provenance with any releases.","details":["Warn: release artifact v1.11.530 not signed: https://api.github.com/repos/markushinz/aws-ses-pop3-server/releases/240142136","Warn: release artifact v1.11.529 not signed: https://api.github.com/repos/markushinz/aws-ses-pop3-server/releases/239855284","Warn: release artifact v1.11.528 not signed: https://api.github.com/repos/markushinz/aws-ses-pop3-server/releases/239546599","Warn: release artifact v1.11.527 not signed: https://api.github.com/repos/markushinz/aws-ses-pop3-server/releases/239546018","Warn: release artifact v1.11.526 not signed: https://api.github.com/repos/markushinz/aws-ses-pop3-server/releases/239233386","Warn: release artifact v1.11.530 does not have provenance: https://api.github.com/repos/markushinz/aws-ses-pop3-server/releases/240142136","Warn: release artifact v1.11.529 does not have provenance: https://api.github.com/repos/markushinz/aws-ses-pop3-server/releases/239855284","Warn: release artifact v1.11.528 does not have provenance: https://api.github.com/repos/markushinz/aws-ses-pop3-server/releases/239546599","Warn: release artifact v1.11.527 does not have provenance: https://api.github.com/repos/markushinz/aws-ses-pop3-server/releases/239546018","Warn: release artifact v1.11.526 does not have provenance: https://api.github.com/repos/markushinz/aws-ses-pop3-server/releases/239233386"],"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#signed-releases"}},{"name":"Packaging","score":10,"reason":"packaging workflow detected","details":["Info: Project packages its releases by way of GitHub Actions.: .github/workflows/ci.yaml:8"],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#packaging"}},{"name":"Vulnerabilities","score":6,"reason":"4 existing vulnerabilities detected","details":["Warn: Project is vulnerable to: GO-2022-0635","Warn: Project is vulnerable to: GO-2022-0646","Warn: Project is vulnerable to: GO-2025-3787 / GHSA-fv92-fjc5-jj9h","Warn: Project is vulnerable to: GO-2025-3553 / GHSA-mh63-6h87-95cp"],"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#vulnerabilities"}},{"name":"SAST","score":10,"reason":"SAST tool is run on all commits","details":["Info: all commits (30) are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#sast"}}]},"last_synced_at":"2025-08-19T05:37:04.990Z","repository_id":36978707,"created_at":"2025-08-19T05:37:04.990Z","updated_at":"2025-08-19T05:37:04.990Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":30212509,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-03-07T09:02:10.694Z","status":"ssl_error","status_checked_at":"2026-03-07T09:02:08.429Z","response_time":53,"last_error":"SSL_read: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["aws","aws-s3","aws-ses","email","go","golang","mail","pop3","pop3-server","ses"],"created_at":"2024-08-01T21:01:26.618Z","updated_at":"2026-03-07T12:13:56.361Z","avatar_url":"https://github.com/markushinz.png","language":"Go","funding_links":[],"categories":["Go"],"sub_categories":[],"readme":"# aws-ses-pop3-server 💌\n\n[![CI](https://github.com/markushinz/aws-ses-pop3-server/actions/workflows/ci.yaml/badge.svg)](https://github.com/markushinz/aws-ses-pop3-server/actions/workflows/ci.yaml)\n[![Quality Gate Status](https://sonarcloud.io/api/project_badges/measure?project=markushinz_aws-ses-pop3-server\u0026metric=alert_status)](https://sonarcloud.io/summary/new_code?id=markushinz_aws-ses-pop3-server)\n\nThe missing POP3 server for [Amazon Simple Email Service](https://aws.amazon.com/de/ses/) - written in golang.\nTested with Apple Mail 16.0 on macOS 26.2, Apple Mail on iOS 26.2 and Microsoft Outlook for Mac 16.104.\n\nAWS SES is powerful when it comes to sending emails but has only limited functionality to receive them.\nOfficially, only storing them in [Amazon S3](https://aws.amazon.com/de/s3/) and triggering [Amazon Lambda](https://aws.amazon.com/de/lambda/) functions is supported (in certain regions such as *eu-west-1*).\n\nThis implementation serves a fully compliant [RFC1939](https://tools.ietf.org/html/rfc1939) POP3 server backed with an S3 bucket for SES.\n\n### Docker 🐳 / docker-compose / Kubernetes\n\n[`markushinz/aws-ses-pop3-server`](https://hub.docker.com/r/markushinz/aws-ses-pop3-server/tags)\n\n### Linux / macOS\n\n```shell\nsudo curl -fsSL \"https://github.com/markushinz/aws-ses-pop3-server/releases/latest/download/aws-ses-pop3-server-$(uname -m)-$(uname -s)\" -o /usr/local/bin/aws-ses-pop3-server\nsudo chmod +x /usr/local/bin/aws-ses-pop3-server\naws-ses-pop3-server\n```\n\n## Usage\n\nFirst, follow the official tutorial [Receiving Email with Amazon SES](https://docs.aws.amazon.com/ses/latest/DeveloperGuide/receiving-email.html) to store emails in a S3 bucket.\n\nNext, create an IAM user that has read and write permissions to the desired S3 bucket.\n\n[Create a config file](#config) using one of the supported authentication/authorization ways (listed below) and start the server.\n\n\u003e Restrict access to your local machine or use TLS!\n\nFinally, configure your favorite email client 🥳.\nFollow the official tutorial [Using the Amazon SES SMTP Interface to Send Email](https://docs.aws.amazon.com/ses/latest/DeveloperGuide/send-email-smtp.html) to obtain SMTP credentials for sending emails.\n\n\n### 1) JSON Web Tokens (JWTs)\n\nProvide all required information the server needs to access an S3 bucket via a JWT.\nTo ensure that a malicious user cannot trick the server into authenticating against AWS with arbitrary credentials, the server checks the signature and the `exp` property of JWTs.\nIf `exp` is not specified tokens do not expire.\n\nTo use JWTs, provide a JWT secret via the config and provide `jwt` as user and the a signed JWT with the following content as password:\n\n```json\n{\n    \"awsAccessKeyID\": \"AKIAIOSFODNN7EXAMPLE\",\n    \"awsSecretAccessKey\": \"wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY\",\n    \"awsSessionToken\": \"...\",\n    \"region\": \"eu-central-1\",\n    \"bucket\": \"aws-ses-pop3-server\",\n    \"prefix\": \"\"\n}\n```\n\n`awsSessionToken` is only used for STS (short-term) credentials.\n\n\u003e This does not work with Gmail! Gmail enforces a maximum character length for POP3 credentials that is smaller than the expected length of JWTs.\n\n### 2) HTTP(S) basic auth\n\nPerform a GET request to retrieve all required information the server needs to access an S3 bucket.\nThe GET request transmits user and password via basic auth and expects the response to have status code 200 and a JSON body that follows the same format as the JWT content (see above).\n\n### 3) Static credentials\n\nJust accept one hardcoded pair or user and password.\nYou have to provide all information required to access one (!) S3 bucket via the config.\nIf no additional information is provided the server will behave like there are no emails.\n\n\u003e Change the default values for user and password!\n\n## Config\n\naws-ses-pop3-server can be configured using environment variables and / or a config file.\naws-ses-pop3-server looks for config files at the following locations and in the depicted order:\n\n* `/etc/aws-ses-pop3-server/config.yaml`\n* `$HOME/.aws-ses-pop3-server/config.yaml` (`~/.aws-ses-pop3-server/config.yaml`)\n* `$(pwd)/config.yaml` (present working directory)\n\nEnvironment variables use the prefix `POP3_` followed by the config key where `-` have to be replaced with `_`.\nEnvironment variables take precedence.\n\nCheck the following example `config.yaml` for possible keys:\n\n```yaml\n# GENERAL SETTINGS\nhost: \"localhost\" # optional, defaults to \"\" (or 0.0.0.0; [::];  listening on all NICs)\nport: 2110 # optional, defaults to 2110 (or 2995 if you specified tls-cert / tls-key or tls-cert-path / tls-key-path)\ntls-cert: |- # optional, only valid in combination with tls-key, takes precedence over tls-cert-path / tls-key-path\n  -----BEGIN CERTIFICATE-----\n  [ ... ]\n  -----END CERTIFICATE-----\ntls-key: |- # optional, only valid in combination with tls-cert, takes precedence over tls-cert-path / tls-key-path\n  -----BEGIN PRIVATE KEY-----\n  [ ... ]\n  -----END PRIVATE KEY-----\ntls-cert-path: \"etc/aws-ses-pop3-server/tls.crt\"  # optional, only valid in combination with tls-key-path\ntls-key-path: \"etc/aws-ses-pop3-server/tls\"  # optional, only valid in combination with tls-cert-path\nverbose: false # optional, defaults to false\n\n\n\n# JWT PROVIDER SETTINGS\njwt-secret: \"k2ya2iTNRdlsixVuTi00\" # optional\n\n\n\n# HTTP BASIC AUTH SETTINGS (only effictive if jwt-secret is not set)\nhttp-basic-auth-url: \"http://localhost\" # optional\nhttp-basic-auth-url-insecure: false # optional, defaults to false. If set to true non-localhost URLs using the insecure http protocol will not be rejected\n\n\n\n# STATIC CREDENTIALS SETTINGS (only effictive if neither jwt-secret nor http-basic-auth-url are set)\nuser: \"jane.doe@example.com\" # optional, defaults to \"user\"\npassword: \"6xRkiWA4mZBSaNmv\" # optional, defaults to \"changeit\". DO CHANGE IT!\n\n# The following aws-* keys are optional but required if you want to load emails\n# These values have to be set here and are not inferred from other envrionment variables or ~/.aws/credentials\n# aws-session-token is only used for STS-based keys\n# You need read and write permissions to the desired S3 bucket\naws-access-key-id: \"AKIAIOSFODNN7EXAMPLE\"\naws-secret-access-key: \"wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY\"\naws-session-token: \"...\"\n\n# The following aws-s3-* keys are required iff you set aws-access-key-id and aws-secret-access-key\naws-s3-region: \"eu-central-1\"\naws-s3-bucket: \"aws-ses-pop3-server\"\naws-s3-prefix: \"\" # optional, defaults to \"\" (set this if the emails are not stored in the root directory of the S3 bucket)\n```\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fmarkushinz%2Faws-ses-pop3-server","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fmarkushinz%2Faws-ses-pop3-server","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fmarkushinz%2Faws-ses-pop3-server/lists"}