Agent Mail Gateway

io.github.dominikamannv0.1.4更新于 Oct 2, 2026

Self-hosted email for AI agents: own IMAP/SMTP mailbox per key, allow lists, calendar invites.

概览

AI 生成的概览

自托管网关,为每个 AI 代理提供独立的 IMAP/SMTP 邮箱,支持允许列表、附件和日历邀请。

功能
Agent Mail Gateway 是一个自托管 Docker 服务,位于代理与普通 IMAP/SMTP 邮箱之间。每个代理获得一个仅绑定一个邮箱的 API 密钥,可以读取邮件、发送带附件的邮件,以及创建、更新或取消日历邀请。邮件正文在 HTML 与 Markdown 之间双向转换,按邮箱配置的允许列表控制代理可以接收和发送给谁。它同时提供 REST API 和 MCP 服务器,工具包括 list_messages、read_message、send_message、create_event 和 cancel_event 等。
适用场景
当代理需要真实电子邮件时使用:发送报告、告警或摘要,接收任务或文档并在同一会话中回复,或通过日历邀请安排会议。它也适合在现有邮件服务器上为多个代理分配独立邮箱而不向其暴露邮箱密码,并把代理限制为只能与获准联系人通信。
运行要求
需要本地 Docker 运行环境(或自带的 Node.js stdio 桥接),以及支持 TLS 的 IMAP/SMTP 邮箱账号。配置位于 config.yaml 和 .env,包括每个代理的 API 密钥和可选的 webhook 密钥。客户端使用 Authorization Bearer 请求头认证,并需要访问邮件服务器的网络。
安装前请注意
网关保存邮箱凭据和 API 密钥,请保护好 config.yaml 与 .env;若可从其他机器访问,应置于 TLS 反向代理之后。代理可以代你发送邮件、删除邮件和发送日历邀请,允许列表和发送速率限制是主要防护措施。默认情况下,不在允许列表中的邮件会被移入垃圾箱,webhook 使用 HMAC 签名。

安装

在 SourceWeft 中

  1. 打开 控制台中的 Agent Mail Gateway,将其添加到工作区。
  2. 为需要使用其工具的对话启用该服务。

Desktop only,通过 STDIO。 STDIO 服务会启动本地进程,因此需要 SourceWeft 桌面宿主。

其他 MCP 客户端

参照 仓库 中的启动说明。

README

Agent Mail Gateway

[CI] [License: MIT]

Give every AI agent its own email mailbox — without giving it the keys to that mailbox.

Agent Mail Gateway is a small self-hosted Docker service that sits between your agents and ordinary IMAP/SMTP mailboxes (Plesk, IONOS, Outlook, your own server — any provider). Each agent gets one API key bound to exactly one mailbox. Through the gateway it can read mail, send mail with attachments, and send, update or cancel calendar invitations. You decide who each agent may receive mail from and who it may write to; everything else is filtered out.

Mail bodies are delivered to the agent as Markdown (converted from HTML) and the agent writes Markdown that is sent as HTML — far fewer tokens than raw HTML email.

In short: a self-hosted email MCP server and REST API for AI agents — IMAP/SMTP mailbox access with sender/recipient allow lists, HTML-to-Markdown, attachments and calendar invites, packaged as one Docker container.

Typical use cases

  • An assistant agent that sends you daily reports, summaries or alerts by email.
  • Agents that receive tasks or documents by email and answer them in the same thread.
  • Agents that schedule, move and cancel meetings with you via calendar invitations.
  • Giving several agents separate mailboxes on your existing mail server (Plesk, IONOS, Outlook, Postfix/Dovecot, …) without exposing the mailbox passwords to them.
  • Locking an agent down so it can only talk to approved people — useful against prompt injection by email and against agents mailing the wrong people.

Works with any MCP client (for example Hermes Agent, Cursor, VS Code, n8n, LangChain/LangGraph MCP adapters) and with anything that can make HTTP requests.

Features

  • N mailboxes, one key each — a key can never reach another mailbox.
  • Allow lists per mailbox for receiving and sending (name@domain or *@domain).
  • Filtered mail is invisible — not listed, not readable, not even by guessing an id. Non-allowed mail is moved to Trash (default) or left untouched.
  • Spoofing protection — senders must pass SPF/DKIM/DMARC as reported by your mail server.
  • HTML ⇄ Markdown conversion in both directions.
  • Attachments in and out.
  • Calendar invites (iCalendar) that update or cancel cleanly in Outlook, Gmail and Apple Calendar.
  • REST API with OpenAPI docs at /docs, and an MCP server at /mcp with the same tools.
  • Webhooks (HMAC-signed) when an allowed message arrives; new mail is detected instantly via IMAP IDLE.
  • Send rate limit per mailbox and an audit log of every send, rejection and deletion.
  • Works with any IMAP/SMTP server: TLS on 993/465 or STARTTLS on 143/587.

How it works

 Agent ──REST/MCP + API key──▶ ┌──────────────────────────────────────┐                               │ Auth      key → exactly one mailbox  │ Agent ◀──signed webhook────── │ Policy    sender/recipient checks    │                               │ Converter HTML ⇄ Markdown            │                               │ Calendar  build/update/cancel .ics   │                               │ Mailbox   IMAP read + IDLE watcher   │──IMAP──▶ mail server                               │ Sender    SMTP + copy to Sent        │──SMTP──▶                               │ Store     SQLite (small state)       │                               └──────────────────────────────────────┘                                 config.yaml + .env (read-only)

The gateway stores no mail content; mail stays on your mail server.

Quick start

  1. Get the files:
    bash
    mkdir agent-mail-gateway && cd agent-mail-gatewaycurl -LO https://raw.githubusercontent.com/dominikamann/agent-mail-gateway/main/docker-compose.ymlcurl -L -o config.yaml https://raw.githubusercontent.com/dominikamann/agent-mail-gateway/main/config.example.yamlcurl -L -o .env https://raw.githubusercontent.com/dominikamann/agent-mail-gateway/main/.env.example
  2. Edit config.yaml: one entry per agent with its mailbox server, login and allow lists.
  3. Fill .env with the secrets referenced in config.yaml:
    bash
    openssl rand -hex 32   # an API key for each agentopenssl rand -hex 24   # a webhook secret (optional)
  4. Start it:
    bash
    docker compose up -dcurl http://localhost:8080/healthcurl -H "Authorization: Bearer $AGENT_API_KEY" http://localhost:8080/v1/mailbox

Every option is explained in docs/configuration.md.

Using it

REST — send a message:

bash
curl -X POST http://localhost:8080/v1/messages \  -H "Authorization: Bearer $AGENT_API_KEY" -H "Content-Type: application/json" \  -d '{"to":["[email protected]"],"subject":"Daily report","body_markdown":"All **green** today."}'

Read new mail:

bash
curl -H "Authorization: Bearer $AGENT_API_KEY" "http://localhost:8080/v1/messages?unread=true"

MCP — point any MCP client at http://<host>:8080/mcp with the header Authorization: Bearer <api key>. Tools: get_mailbox_info, list_messages, read_message, get_attachment, mark_message, delete_message, send_message, create_event, update_event, cancel_event, list_events.

stdio — clients that can only start local processes use the bundled bridge node dist/stdio.js with AGENT_MAIL_URL and AGENT_MAIL_API_KEY; see docs/stdio.md.

See docs/api.md for every endpoint, the webhook format and examples.

Hermes Agent — connect the MCP server in ~/.hermes/config.yaml and install the plugin that teaches your agents to use their mailbox safely:

bash
hermes plugins install dominikamann/agent-mail-gateway/integrations/hermes/agent-mail-gateway --enable

Step by step: docs/hermes.md.

Documentation

Security

Run the gateway behind a TLS reverse proxy when it is reachable from other machines. Report vulnerabilities privately as described in SECURITY.md.

License

MIT


Proudly provided by amannlabs.eu

来源:README.md,提交 6821eea

工具

0
工具元数据尚未被收录。

版本历史

1
  1. v0.1.4最新Oct 2, 2026