PythonReactViteCloudflareGitLab CIEntra ID
September 28, 2026MailKeeper

Internal tool built at work. Details are kept general.
When a company sends email from hundreds of domains across two Mailgun regions, problems hide in the noise: a domain quietly bouncing, a misconfigured DNS record, a dedicated IP losing reputation. MailKeeper pulls everything from the Mailgun API, computes the rates correctly, surfaces issues worst-first and walks an operator through fixing each one.
How it works
Python pipeline ──(Mailgun API, both regions)──> snapshot JSON ──> React static build ──> Cloudflare Pages
- Pipeline (Python, standard library only): a scheduled job pulls every domain, setting, IP and 30 days of metrics, detects issues and writes a single snapshot. The browser never calls Mailgun.
- Honest numbers: rates are computed from raw counts and clamped to 0–100%. Bounces and permanent failures are kept separate and both shown, so they’re never mixed up.
- Portal (React 19 + Vite): health bars, trends, IP health, suppressions, region split and a fix wizard. Assigning or removing a dedicated IP calls Mailgun for real, behind a confirm step.
- Alerts: a change digest sent by email when something moves.
DevOps and security
- A GitLab CI schedule refreshes the snapshot, sends alerts, rebuilds and deploys to Cloudflare Pages daily with no manual steps.
- The whole site sits behind Cloudflare Access (Zero Trust), with Microsoft Entra ID as the identity provider and a network restriction on top. Every request is checked at the edge, including static assets and the data file.
- The worker adds a second check on API routes as defence in depth.