Status
Stability
Section titled “Stability”Carrier is on version 0.0.0. Until 1.0, a minor release can change the public API, so pin the version you test against.
Limits and errors
Section titled “Limits and errors”Errors.
CarrierErrorhas acodeofinvalid_input,conflictorunavailable. Its message never includes email bodies, tokens or raw provider errors.- Post throws
PostErrorfor an unknown route or a conflicting key. - Inspection raises
DeliveryInspectionError("invalid_query")for bad bounds and the sanitizedDeliveryInspectionError("unavailable")for invalid stored evidence or a storage failure. Inspection keys are limited to 256 characters and provider receipt IDs to 1,024.
Logs. Every failed, unknown or refused email delivery emits one
console.error line, "Carrier delivery failed", with the submission id,
class, sanitized cause, resulting status and, for provider rejections, the
attempt. No content, address or provider message is logged.
Policy numbers.
- Recipient cap: 5 accepted Emails per normalized recipient address per rolling hour, counted per Carrier store.
- Email retries: a temporary rejection retries after 30 seconds, doubling,
capped at 15 minutes, for up to 6 provider attempts. Then the Email is
rejected. - Post retries: 2 seconds, doubling, capped at 5 minutes, over 20 receiver attempts.
- Post attempts: preparation and receiver I/O share a ten-second deadline.
Guarantees and gaps.
- There is no exactly-once delivery promise.
outcome_unknownis final, and a new ID for the same email can duplicate it. - Recipient Messages stay
unconfirmed. Carrier does not ingest provider delivery events or correlate them with receipts, and it does not expire terminal receipts. - Run exactly one owner per store at a time. Simultaneous owners of the same store are unsupported.
- The test suite does not exercise real mail delivery, provider MIME generation or actual BCC secrecy.
Contribute and license
Section titled “Contribute and license”Carrier is MIT licensed. See LICENSE.