OmniMail
Self-hosted webmail for several Cloudflare domains, with optional Gmail, Microsoft and QQ inboxes beside the domain mail
OmniMail Float panel showing the inbox, a received verification code and per-account tabs
OmniMail is one Cloudflare Worker that receives mail for domains on Cloudflare through Email Routing, parses it on a queue, stores it in D1 and R2, and serves the webmail. Users can also connect outside mailboxes. Sending goes through Resend or SendFlare when one is configured.
A catch-all Email Routing rule hands every message for the configured domains to the Worker. By default it accepts only addresses that exist in its database; an optional setting delivers mail for unassigned addresses on managed domains to the main administrator. Accepted messages are queued for parsing, and raw mail and attachments go to a private R2 bucket. One instance serves several domains and many addresses, with four roles: a main administrator, administrators, regular users and time-limited temporary users invited by link. The webmail has inbox, starred, sent and trash views, threaded conversations with batch actions on up to 50 messages, search across domain, address, sender, subject and body, and raw .eml downloads. Outgoing mail and replies go through Resend or SendFlare with per-user rate limits and up to five attachments. Admins get receive statistics, audit logs, storage quotas and optional daily backups of D1 and mail archives to a separate R2 bucket. Outside mailboxes include Gmail, Microsoft, QQ, NAVER and Yandex over IMAP with app passwords or OAuth, Linux DO Mail, and iCloud+ Hide My Email aliases. Their messages are indexed or fetched on demand instead of being copied into R2. Their credentials are encrypted with AES-GCM under a MAIL_CREDENTIALS_KEY secret. A cron trigger every five minutes queues the background syncs. A Chrome extension, OmniMail Float, and a preview Android client use the same API. Besides D1, R2 and two Queues, the Worker binds two Workflows for backup and cleanup, Workers AI for message translation, and static assets for the frontend. Turnstile protects open registration and multi-use invite links.
Built for: Individuals and small teams with domains on Cloudflare who want a self-hosted webmail for those domains
What you can use it for
- Run webmail for several domains hosted on Cloudflare DNS
- Give temporary users time-limited accounts through invite links
- Read Gmail, Microsoft and QQ inboxes next to domain mail
- Manage iCloud+ Hide My Email aliases from the same workspace
- Reply from a custom domain through Resend or SendFlare
Deploy
One-click · main path
Branch main
The button asks for SETUP_TOKEN and SUPER_ADMIN_EMAIL and runs D1 migrations through Workers Builds. Afterwards add a custom domain and point an Email Routing catch-all rule at the Worker.
Manual
Branch main
Fork the repository. In Workers & Pages, choose Create application, then Import a repository, and pick the fork. Use npm run build as the build command and npm run deploy as the deploy command; the deploy step also applies the D1 migrations. On the Worker, add SETUP_TOKEN as a secret and SUPER_ADMIN_EMAIL as a variable. Sync fork brings in later releases, and Workers Builds redeploys each new commit on main.
The deploy button provisions D1, R2 and Queues and asks for two values. You then add a custom domain, onboard each domain to Email Routing with a catch-all rule to the Worker, and add secrets for sending or outside mailboxes.
What it needs to run
- Workers AIAI
- D1 databasesDB
- Queues (consumer)omnimail-mail
- Queues (producer)omnimail-mail
- R2 bucketsomni-mail-backups, MAIL_BUCKET
- Workflowsomni-mail-backup, omni-mail-cleanup
Also uses
- Resend (optional): Sending and replying from the hosted domainsSource
Good to know
The README, homepage and deploy guide are mainly in Chinese; the webmail UI has Simplified Chinese and English. The README lists IMAP, POP3 and SMTP access for desktop mail clients, bulk sending, an address book, full spam filtering, virus scanning and a mail rule engine as not provided. Deploying does not change DNS, MX records or Email Routing. OmniMail is not end-to-end encrypted and is not a compliance archive. The README advises an independent security review, a backup plan and real mail-flow tests before it handles important mail. The one-click deploy creates a standalone copy without Sync fork, so later releases have to be merged by hand; the README suggests a fork for long-term use. The Android client is a 0.x preview.
Cost on Cloudflare
Likely fits the free plan
D1, R2, Queues, Workflows and Workers AI all have Workers Free allowances. Queues include 10,000 operations a day on the free plan; incoming mail parsing, outgoing sends and the five-minute mailbox sync jobs all use queue operations, so busy instances may outgrow it.
The estimate is based on Cloudflare’s documented limits and the app’s configuration. What you pay depends on your usage and plan.
Where this comes from
- Repositoryhttps://github.com/mibgb65-cloud/OmniMail
- App websitehttps://omnimail.aicnos.com
- Documentationhttps://omnimail.aicnos.com/deploy
An alternative to Gmail.
Listing history
- Oct 2, 2026 · OmniMail listed
Similar apps
All Email apps
Multi-mailbox email service for your own domain on Cloudflare Workers, with webmail, an admin console and Resend sending
- Deploy
- Manual
- License
- MIT
- GitHub stars
- 14.6k stars
- Last commit

Open-source web inbox for your own domain, with an AI agent that drafts replies and sends only after you confirm
- Deploy
- One-click
- License
- Apache-2.0
- GitHub stars
- 8.2k stars
- Last commit

Self-hosted webmail for your own domains, with routing rules, a calendar and an AI assistant whose drafts need approval
- Deploy
- One-click
- License
- AGPL-3.0
- GitHub stars
- 4.6k stars
- Last commit
