Skip to content

Status

Carrier is on version 0.0.0. Until 1.0, a minor release can change the public API, so pin the version you test against.

Errors.

  • CarrierError has a code of invalid_input, conflict or unavailable. Its message never includes email bodies, tokens or raw provider errors.
  • Post throws PostError for an unknown route or a conflicting key.
  • Inspection raises DeliveryInspectionError("invalid_query") for bad bounds and the sanitized DeliveryInspectionError("unavailable") for invalid stored evidence or a storage failure. Inspection keys are limited to 256 characters and provider receipt IDs to 1,024.

Logs. Every failed, unknown or refused email delivery emits one console.error line, "Carrier delivery failed", with the submission id, class, sanitized cause, resulting status and, for provider rejections, the attempt. No content, address or provider message is logged.

Policy numbers.

  • Recipient cap: 5 accepted Emails per normalized recipient address per rolling hour, counted per Carrier store.
  • Email retries: a temporary rejection retries after 30 seconds, doubling, capped at 15 minutes, for up to 6 provider attempts. Then the Email is rejected.
  • Post retries: 2 seconds, doubling, capped at 5 minutes, over 20 receiver attempts.
  • Post attempts: preparation and receiver I/O share a ten-second deadline.

Guarantees and gaps.

  • There is no exactly-once delivery promise. outcome_unknown is final, and a new ID for the same email can duplicate it.
  • Recipient Messages stay unconfirmed. Carrier does not ingest provider delivery events or correlate them with receipts, and it does not expire terminal receipts.
  • Run exactly one owner per store at a time. Simultaneous owners of the same store are unsupported.
  • The test suite does not exercise real mail delivery, provider MIME generation or actual BCC secrecy.

Carrier is MIT licensed. See LICENSE.