Andrix.Ng
All Projects

API Mail

A standalone PHP microservice that handles transactional email delivery for static websites — secure, lightweight, and ready to deploy.

API Mail
My Role

Backend Developer

Project context

A secure PHP microservice to handle contact form submissions for static and JAMstack websites.

The problem

Static sites and JAMstack projects have no built-in server to process contact forms. Exposing SMTP credentials on the client side is a critical security risk that needed a clean backend solution.

Technical approach

Engineered a self-contained PHP 8 API with strict input sanitization, configurable CORS policies, and PHPMailer integration — deployable on shared hosting.

Design goal

Give static contact forms a dedicated server-side delivery boundary. The website collects the message, while the PHP service owns validation and SMTP delivery configuration. Credentials remain a server concern instead of becoming part of the published front-end bundle.

Service boundaries

The static website submits its contact data to a dedicated PHP endpoint. The service handles input validation and email delivery through PHPMailer, keeping SMTP credentials on the server. This separates the public form interface from the delivery configuration and allows the backend to be deployed independently of the website.

HTTP service boundary

The API receives contact submissions independently of the website hosting stack. This makes it suitable for static and JAMstack clients that have no built-in PHP execution environment. The calling interface and delivery service can be deployed and configured separately.

Validation and origin policy

Input sanitization handles the submitted fields, and configurable CORS defines which browser origins may access the endpoint. These controls serve different purposes. An allowed origin does not make the submitted content trustworthy, so input validation remains a responsibility of the service.

Validation and deployment

Input sanitization and configurable CORS policies define how requests enter the service. PHP 8 and PHPMailer provide a deployment model compatible with shared hosting. Deployment still requires the appropriate SMTP configuration and an origin policy that matches the calling website; these are environment settings rather than public client-side values.

PHPMailer delivery

PHPMailer provides the email integration inside the PHP 8 service. SMTP configuration belongs to the deployment environment, allowing the endpoint to use the chosen mail provider. Acceptance by a mail server and final arrival in the recipient’s inbox remain separate delivery stages.

Independent deployment

Compatibility with shared hosting makes the service deployable alongside an existing static site setup. The PHP runtime, SMTP settings, and CORS policy need to match the installation. Keeping these concerns on the backend avoids coupling mail credentials to each front-end release.

Key capabilities

  • Transactional email endpoint
  • Input validation and sanitization
  • Configurable CORS policies
  • PHPMailer integration

Outcome

Eliminated client-side SMTP exposure with a clean, deployable backend solution.

Operational considerations

The project provides an email-delivery endpoint, while final delivery also depends on the configured mail provider and domain. CORS does not replace abuse prevention. Public deployment should account for request limits, spam protection, and delivery monitoring according to the hosting environment and expected traffic.

Public endpoint considerations

A contact endpoint can receive unwanted traffic even when browser access is restricted. Rate limits, spam defenses, and delivery monitoring are operational considerations for a public deployment. These should be evaluated against the hosting environment rather than assumed to follow from CORS alone.