Configuration
Complete configuration reference for all bridge components.
Environment Variables
Common Variables
Inbound Service
SMTP Mode
Mailgun Mode
Outbound Service
SMTP Provider
Mailgun Provider
NIP-05 Service
Example Configurations
Minimal Self-Hosted Setup
# .env
INBOUND_PRIVATE_KEY=<your-hex-key>
BRIDGE_PRIVATE_KEY=<your-hex-key>
RELAYS=wss://relay.damus.io,wss://nos.lol
OUTBOUND_PROVIDER=smtp
FROM_DOMAIN=mail.yourdomain.com
SMTP_HOST=localhost
SMTP_PORT=25
Mailgun Setup
# .env
INBOUND_PRIVATE_KEY=<your-hex-key>
BRIDGE_PRIVATE_KEY=<your-hex-key>
MAILGUN_API_KEY=key-xxxxxxxxxx
MAILGUN_DOMAIN=mail.yourdomain.com
MAILGUN_WEBHOOK_SECRET=xxxxxxxxxx
RELAYS=wss://relay.damus.io,wss://nos.lol
OUTBOUND_PROVIDER=mailgun
FROM_DOMAIN=mail.yourdomain.com
HTTP_PORT=3001
With Plugin Filtering
# .env
INBOUND_PRIVATE_KEY=<your-hex-key>
RELAYS=wss://relay.damus.io,wss://nos.lol
PLUGIN_PATH=/opt/nostr-mail/plugins/uid_ovh
Docker Compose
The repository ships a docker-compose.yml that runs the four services
together. Fill in .env and start it:
cp .env.example .env
docker compose up -d
# .env
INBOUND_PRIVATE_KEY=
BRIDGE_PRIVATE_KEY=
BRIDGE_PUBKEY=
FROM_DOMAIN=mail.example.com
# PLUGIN_PATH=/app/plugins/whitelist.js
DKIM keys live in ./dkim-keys, the NIP-05 user store in ./nip05-data.
Back up both.
DNS Configuration
Mail that is not authenticated goes to spam, so treat these as required rather than optional.
Also set the reverse DNS of your server IP to mail.yourdomain.com. Many
receivers reject mail from an address that does not resolve back.
NIP-05 discovery
The bridge is discovered over HTTPS, not DNS: serve its pubkey under _smtp in
https://yourdomain.com/.well-known/nostr.json. That is what nip05-service
does.