
HostShield
Per-property compliance reports for short-term rentals
TL;DR: We added real inbound email to our Rails app (Host Shield) today: Postfix on the server pipes mail to Rails Action Mailbox, we route contact@ and catch-all, store everything in the DB, and admins get a simple inbox with filters. No third-party inbound API, no extra monthly bill. Here’s the gist.
What we built
- Receive — Mail for *@gethostshield.com hits our server; Postfix runs a small script that POSTs the raw message to our app’s Action Mailbox relay endpoint (with a shared secret). Rails ingests it.
- Route — contact@ goes to a “contact” mailbox; everything else goes to “catch-all.” Both write to our own inbound_emails table (from, to, subject, body, status).
- Admin inbox — At /admin/inbound_emails we list messages (newest first), filter by mailbox type and status (new/read/archived), open one to read the body, and mark read or archive. No forwarding to Gmail; it’s all in-app.
Why it matters for us
We’re a tiny team. We already had vendor for outbound (and could have forwarded to Gmail), but we wanted replies and contact-form-style mail inside the product: one place to triage, no extra services, and a path to automate (e.g. “contact” → ticket or notification -> AI action) later. Rails Action Mailbox + a relay gave us that with minimal code.
Rough stack
- Rails 8 Action Mailbox (relay ingress).
- Postfix on the same box: virtual domain for our domain, transport = pipe to a script that curl POSTs to the relay URL with Basic auth.
- Our app stores normalized rows in inbound_emails and serves the admin inbox with filters.
Time
About half a day: migrations, mailbox classes, Postfix/setup script, relay script, admin controller + views, and a quick sanity check with a real send.
If you’re on Rails and already have a server that can receive mail, you can get “real” inbound in a few hours and own the pipeline. Worth it for indie apps that want to keep support and contact in one place.
— Host Shield · gethostshield.com · Know your local short-term rental rules.
Most short-term rental compliance advice is generic.
“Check your city’s rules” sounds reasonable until you realize legality often depends on the exact property—zoning, unit type, registration status—and that requirements change quietly.
Hosts end up bookmarking links, saving PDFs, and hoping they didn’t miss something. The anxiety usually only goes away after a warning, a fine, or hours of research.
After seeing how often hosts got stuck or surprised by this, I started building.
I’m working on GetHostShield to turn this into something concrete: one clear compliance report per property, summarized from official sources, with permits, taxes, and a place to track what’s done. Optional monitoring flags changes so nothing slips by.
Still early, but curious how other hosts or operators handle this today.
1 Like
Comment
About
Most STR compliance advice is generic. “Check your city’s rules” doesn’t work when legality depends on the exact property and rules change quietly. Hosts end up guessing and hoping they didn’t miss something.

Comment