Mail that behaves like mail.
Real IMAP mailboxes on a domain you own, read in a client that treats a message as evidence rather than as a page to render. Tracking pixels do not load, brand logos come from us rather than the sender, and every message shows what actually authenticated. Rules run when you open the mailbox, and the last section says so.
- Views
- Inbox
- Starred
- Sent
- Scheduled
- Drafts
- Archive
- Spam
- Trash
- Search understands
- from:
- to:
- cc:
- label:
- folder:
- is:unread
- is:starred
- has:attachment
Opening a message tells the sender nothing.
Most mail clients tell the sender the moment you open a message, twice over: a remote image is a request to their server the instant it renders, and the “verified brand” logo beside the name is usually fetched from the brand. Either one is a read receipt nobody asked you about. Here the images are rewritten before the message reaches the browser, the logo is resolved on our side and served from our origin, and no receipt header is written at all — so there are three arrows and none of them leave.
A real mailbox
- 01
IMAP underneath, not a veneer over it
Every address is a maildir on Postfix and Dovecot with its own credentials — not a forwarding rule, and not an alias pointing at an inbox somewhere else. A folder you make in Thunderbird appears here, and one you make here appears in Thunderbird, because there is only ever one folder.
- 02
Every address at once, or one at a time
Read every address on the account at once with the counts added up, or narrow to one. Switching is a filter on the same view rather than a different product, so nothing has to be learned twice.
- 03
Threads that survive other people's clients
Conversations are built from the Message-ID, In-Reply-To and References headers, so a thread holds together across clients and across people whose mail client replies badly. Read it as stacked cards or as a chat transcript — an account preference, not two products.
- 04
Your existing client keeps working
Apple Mail, Outlook, Thunderbird, or anything else, over IMAP on 993 and submission on 465 — both implicit TLS. Each mailbox gets its own app password, so revoking one client does not disturb the rest.
Triage that keeps up
- 05
Instant, and durable if the tab dies
Archive, star, move and mark-read paint immediately and batch behind the scenes. The pending batch is written to the browser's own storage before the request leaves, so closing a laptop mid-action does not lose it — the next load replays what was owed.
- 06
What is never replayed
Only actions that name a destination are queued that way, because those are the ones that are safe to repeat. A send is never in the outbox: replaying one would mean sending twice, and a mail client that occasionally sends twice is worse than one that occasionally waits.
- 07
Sorted, with you outranking the model
Six categories — Primary, Social, Promotions, Newsletters, Transactions and Updates — as tabs above the list. Your own choice beats your rule, your rule beats the model, and an unconfident answer falls back to Primary, because a person's mail filed under Promotions is mail they never see.
- 08
Noticed in seconds, not on a minute's timer
New mail is noticed by polling one integer per mailbox every few seconds rather than re-reading folders on a timer. It is the cheapest read in the product, which is what makes it affordable to do often.
What it refuses to tell the sender
- 09
Tracking pixels do not load by default
Every remote image is rewritten on the server before the message reaches your browser, and a notice says how many were held. A tracking pixel that loads automatically tells the sender you opened it, when, and roughly from where; here it loads when you say so, or never.
- 10
Brand logos, served from us and never from them
A sender who passes DMARC and publishes BIMI artwork gets their real logo — resolved on our side, cached, and served from our own origin. Opening a message never fetches anything from the sender, so a brand logo cannot double as a read receipt.
- 11
Sanitised HTML and defanged attachments
Inbound HTML is run through an allowlist before it renders: scripts stripped, javascript: URLs removed, links forced to open without handing the destination a reference back. Attachments are served as inert binaries unless the declared type is plainly safe, and around fifty-five executable extensions earn a visible warning anchored on the final extension — which is how invoice.pdf.exe gets caught.
- 12
Provenance you can actually check
Per message: who it was mailed by, who signed it with DKIM, whether the last hop used TLS, and the SPF, DKIM and DMARC verdicts — read from the Authentication-Results header the receiving server wrote, not guessed from a display name.
Finding and organising
- 13
One search across everything
One field over mail, calendar, contacts and tasks, with operators for sender, recipient, label, folder and state — and dates written the way people say them, so “last June” is a range rather than an error.
- 14
Keyword always, meaning when it helps
Keyword search always works. Where an embedding provider is configured, meaning-based results are fused with it by rank rather than replacing it, and the parser decides whether a query is even worth an embedding — so exact search stays exactly as fast.
- 15
Labels that are not a private construct
Labels are IMAP keywords with a name and colour, so a message can carry several and a client that has never heard of Ruber still sees them. Clicking a label narrows the folder you are in rather than navigating away.
- 16
Rules, filters and blocked senders
One condition — sender, recipient or subject — and one action: move, star, mark read, or label. Blocked senders take an address or a whole domain and are never told. Both run on a sweep when the mailbox is opened rather than at delivery, which is the honest shape of it.
Sending
- 17
Undo send that is not a race
Send waits five seconds before it goes, so undo cancels a request that was never made rather than trying to recall a message that has already left. That is why it always works.
- 18
The Sent copy is the message
The message is composed once and submitted as raw bytes, so the copy filed in Sent shares its Message-ID and MIME boundaries exactly with the one delivered. Most clients rebuild it, which is why replies sometimes fail to thread against it.
- 19
Schedule send, cancellable until it goes
Write it now and send it Monday, with presets or a picker up to a month out, and cancel any time before it goes. Each due message is claimed with a row lock before sending, so two overlapping runs cannot send it twice.
- 20
Send as any address you own, enforced at the server
The From picker offers every address you own, including aliases — but the choice is a request, not an instruction. The mail server re-validates the sender against the credentials that authenticated and rejects a mismatch, so a bug in the dashboard cannot forge a From address.
What it does not do
Every page like this one lists what a product is good at, which is why that list tells you nothing. These are the limits, named before you find them.
- 01
Rules run when you open the mailbox
Filters, forwarding, auto-reply and blocked senders are applied when a mailbox is read, not when mail arrives. A forwarding rule on a mailbox that nothing ever opens forwards nothing. Providers that run rules server-side at delivery do this differently, and the difference is worth knowing before you depend on it.
- 02
No snooze
There is no snooze. The button exists in three places and is visibly disabled, because nothing behind it is built — no column, no schedule, no return path. It is listed rather than quietly omitted because a disabled control invites the question.
- 03
Mail and tasks are not joined up
A conversation cannot become a task. The two surfaces are neighbours rather than one thing: tasks carry no reference to a message or a thread, and the only route from mail to tasks is a link in the sidebar. Anything on this site that said otherwise before today was wrong.
- 04
Nothing reaches you with the browser closed
Notifications arrive while a tab is open and not otherwise. There is no web push, no service worker and no app to receive one, so a closed browser is a silent one. Where the background runner is connected, email reminders cover some of that gap.
- 05
Import and export have hard limits
Import takes mbox and .eml a batch at a time — twenty-five megabytes and five hundred messages per run — so a full Gmail Takeout has to be split by hand. Export covers the standard folders and not custom ones. Both are real and both are smaller than you would like.
- 06
Some edges need a mail client
Folders can be created here but renaming and deleting one has to be done from a connected mail client, and a mailbox can be suspended but not deleted. Neither is a decision we are defending; both are simply not built.
It is included with every mailbox — there is nothing else to turn on.
Open Mail