AI Briefing
KOSign in

Open-source email engine provides local agents with replayable event logs and safety controls

·2026.10.07 05:09

Key point

The Apache-2.0 licensed engine syncs IMAP/JMAP accounts into an event log and exposes actions via HTTP, SSE, webhooks, and MCP without including an internal model.

Details

A new open-source engine enables local AI agents to interact with email accounts by syncing IMAP, JMAP, or forwarded mail into an ordered event log. The system exposes actions through HTTP, SSE, webhooks, and MCP, allowing integration with various backends such as Ollama, n8n, or custom scripts.

Safety and Control Features

The engine is designed with specific safeguards for agent interactions:

  • Scoped Access: Agents operate with scoped tokens that define allowed folders, verbs, and whether writes are executed immediately or proposed for human approval.
  • Idempotency and Undo: All actions are idempotent using client keys to prevent duplicate sends, and every action is journaled to allow for undo operations.
  • Trust Levels: Messages are assigned trust levels based on DMARC results, enabling agents to refuse actions on suspicious emails.
  • Data Masking: Message content is treated strictly as data, not instructions. Sensitive information like OTPs and card numbers are masked before the body leaves the engine.

Deployment and Status

The project is released under the Apache-2.0 license with no CLA requirement and runs as a single Docker container. It is currently in beta and has been tested on Dovecot and Stalwart mail servers.

This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.

Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.