Coming soon
Developer library · .NET · C# and VB.NET
Bastion Mail Sdk
POP3, IMAP and SMTP for .NET, built to the RFCs.
Three mail clients that share one MIME engine and one MailMessage type. Real TLS, real SASL, OAuth 2.0 for Gmail and Microsoft 365, and the protocol traps handled for you — with no third-party dependencies in any shipped client assembly.
3
protocols — POP3, IMAP and SMTP — over one shared core
8
target frameworks from .NET Framework 4.6.2 to .NET 10, one identical API
0
third-party dependencies in the four client assemblies
14
runnable samples, every one in both C# and VB.NET
Receive, send and parse, in a dozen lines
Every operation is async and cancellable. Write it in C# or VB.NET — the API reads naturally in both, and every sample ships in both.
VB.NET
Using client As New Pop3Client()
Await client.ConnectAsync("pop.example.net", 995)
Await client.AuthenticateAsync(user, password)
For Each entry In Await client.GetUniqueIdsAsync()
Dim msg = Await client.GetMessageAsync(entry.MessageNumber)
Console.WriteLine(msg.Subject)
Next
Await client.DisconnectAsync()
End Using
C#
using var client = new Pop3Client();
await client.ConnectAsync("pop.example.net", 995);
await client.AuthenticateAsync(user, password);
foreach (var entry in await client.GetUniqueIdsAsync())
{
var msg = await client.GetMessageAsync(entry.MessageNumber);
Console.WriteLine(msg.Subject);
}
await client.DisconnectAsync();
Prefer IMAP or SMTP? Swap the client. A message fetched over IMAP can be handed straight to SmtpClient with no conversion.
Why teams choose it
One core, three protocols
The MIME engine, MailMessage, the TLS transport and the SASL authenticators live in one shared assembly. Learn it once; use it for all three protocols.
Async first, event rich
Every client raises the same connection, security, authentication, progress and message events, with the same names across all three libraries.
Secure by default
Implicit TLS and STARTTLS on every protocol, a TLS 1.2 floor, certificate identity checks, and PLAIN, LOGIN, XOAUTH2 and OAUTHBEARER for modern providers.
Sends exactly once
SMTP reports per-recipient outcomes as they happen, and an IsInDoubt flag tells you when a retry could duplicate a message — so your retry logic never sends twice.
Thread safe by contract
Each client owns one connection. Many instances run concurrently against the same or different servers — and that is proved by test, not promised.
Tested for real
TLS handshakes are tested with real certificates on every framework in the matrix, and a live suite runs a full send-and-fetch round trip against an independent server implementation.
What is in the box
Four client assemblies with no third-party dependencies, plus one optional local store.
| Bastion.Mail.Core | MIME parsing and building, MailMessage, encoded-word and parameter decoding, the TLS transport and SASL mechanisms. |
Bastion.POP3 · Pop3Client | UIDL-driven synchronisation, TOP for headers only, STLS, CAPA, SASL AUTH, and deletion-commit tracking so you know when a delete is truly permanent. |
Bastion.IMAP · ImapClient | Folders by special-use role, UID-only addressing, SEARCH and ESEARCH, MIME structure without download, IDLE, MOVE, UIDPLUS, APPEND and flags. A real tokeniser, not regex. |
Bastion.SMTP · SmtpClient | Submission on 465 or 587, STARTTLS, PIPELINING, SIZE, 8BITMIME, SMTPUTF8, DSN, enhanced status codes and the LIMITS extension. |
| Bastion.Mail.Store.Sqlite (optional) | Keeps downloaded messages in a local SQLite database for offline reading and search, storing the exact octets the server sent. The only package with third-party dependencies (Microsoft.Data.Sqlite.Core and SQLitePCLRaw); targets net48 and net8.0. |
| Documentation | CHM and WebHelp: an API reference generated from the source plus a hand-written cookbook, every recipe in C# and VB.NET. Read it online. |
Built against the standards
Each library was implemented from a written specification that maps every behaviour to its RFC.
| Area | Documents followed |
|---|---|
| Message format | RFC 5322, 2045, 2047, 2231, 6532 |
| Security | RFC 8314 (implicit TLS), 8997 (TLS 1.2 floor), 7817 (server identity), 2595 (STARTTLS/STLS), 4616 (PLAIN), 7628 (OAUTHBEARER), plus XOAUTH2 |
| POP3 | RFC 1939, 1957, 2449, 5034, 3206, 6856 |
| IMAP | RFC 3501 (IMAP4rev1), 9051 (IMAP4rev2), 4466, 2177 (IDLE), 6851 (MOVE), 4315 (UIDPLUS), 6154 (SPECIAL-USE), 4731 (ESEARCH), 4959 (SASL-IR), 7888 (LITERAL+) |
| SMTP | RFC 5321, 6409, 3207, 4954, 1870, 6152, 2920, 3461 (DSN), 6531 (SMTPUTF8), 2034, 3463, 5248, 9422 (LIMITS), 7504 |
Where a standard has been obsoleted, the current document is followed: RFC 5034 replaces 1734, RFC 7888 replaces 2088, and RFC 9051 sits beside 3501 because most deployed servers still advertise only IMAP4rev1.
It fits where your application already runs
| Frameworks | Windows only · .NET Framework 4.6.2 and 4.8 · .NET 8, 9 and 10, including WinForms and WPF |
| Languages | C# and VB.NET, with every sample and every cookbook recipe in both |
| Visual Studio | SDK-style projects for 2022 and later, plus a classic solution that opens in 2015 to 2017 |
| Samples | Seven samples in each language — quick starts, fetch-and-forward, and full WinForms POP3, IMAP and compose windows. Each starts a throwaway mail server on loopback, so all fourteen run with no account and no network. |
| Dependencies | None in the client assemblies |
How it compares
Capability and licensing matrix for commercial .NET mail client libraries, compiled September 2026 from each vendor’s published documentation. A ? means the capability was not stated either way — it is not a claim that the product lacks it.
Bastion Mail Sdk is deliberately focused on the Internet mail protocols. If you need S/MIME or Exchange-specific APIs today, the alternatives above offer them.
OEM licensing
One licence type, priced for commercial software teams. Every Bastion Mail Sdk licence is an OEM licence: build it into your product and ship that product to as many customers as you like, on as many machines as they like.
- Royalty-free redistribution inside your own applications
- Desktop, server, cloud and SaaS deployment — no per-server or per-instance fees
- Perpetual licence with 12 months of updates; renewals at 35% of list
- Every build, .NET Framework to .NET 10, and every sample in C# and VB.NET
- Everything in Developer OEM
- $199 per developer
- Everything in Developer OEM
- No developer count to track as the team grows
- Source-code escrow available, priced on request
Launch prices in US dollars. Final pricing is confirmed at release.
Try it properly first
A thirty-day evaluation of the complete component. Nothing removed and no limits — you evaluate exactly what you would buy.
Because the trial is the whole product, sales are final, and accepting the terms and conditions of sale is part of completing a purchase. The one exception: report a serious defect and, if we cannot fix it and release an update within thirty days, we refund you in full.
Need more than the component? Custom development and integration work built on it is available, remotely or on site — talk to us.
Get notified when Bastion Mail Sdk is released
Tell us what you are building. We will let you know the moment the evaluation is available — and answer plainly whether it fits.