Agent Mail Gateway

io.github.dominikamannv0.1.4更新於 Oct 2, 2026

Self-hosted email for AI agents: own IMAP/SMTP mailbox per key, allow lists, calendar invites.

概覽

AI 產生的概覽

自架閘道,讓每個 AI 代理擁有自己的 IMAP/SMTP 信箱,支援允許清單、附件與行事曆邀請。

功能
Agent Mail Gateway 是一個自架 Docker 服務,介於代理與一般 IMAP/SMTP 信箱之間。每個代理取得一組只綁定單一信箱的 API 金鑰,可讀取郵件、寄送含附件的郵件,以及建立、更新或取消行事曆邀請。郵件內文會在 HTML 與 Markdown 之間雙向轉換,並以每個信箱的允許清單控管代理可收件與寄件的對象。它同時提供 REST API 與 MCP 伺服器,工具包括 list_messages、read_message、send_message、create_event 與 cancel_event 等。
適用情境
當代理需要真實電子郵件時使用:寄送報告、警示或摘要,接收任務或文件並在同一討論串回覆,或透過行事曆邀請安排會議。也適合在現有郵件伺服器上為多個代理分配獨立信箱而不向它們揭露信箱密碼,並把代理限制為只能與核准的聯絡人往來。
執行需求
需要本機 Docker 執行環境(或內附的 Node.js stdio 橋接),以及支援 TLS 的 IMAP/SMTP 信箱帳號。設定位於 config.yaml 與 .env,包含每個代理的 API 金鑰與選用的 webhook 密鑰。用戶端以 Authorization Bearer 標頭驗證,並需要連線郵件伺服器的網路。
安裝前請注意
閘道保存信箱憑證與 API 金鑰,請保護好 config.yaml 與 .env;若可從其他機器連線,應置於 TLS 反向代理之後。代理可代你寄信、刪除郵件與發送行事曆邀請,允許清單與寄送速率限制是主要防護。預設情況下,不在允許清單的郵件會被移到垃圾桶,webhook 以 HMAC 簽章。

安裝

在 SourceWeft 中

  1. 開啟 儀表板中的 Agent Mail Gateway,將其新增到工作區。
  2. 為需要使用其工具的對話啟用該服務。

Desktop only,透過 STDIO。 STDIO 服務會啟動本機處理程序,因此需要 SourceWeft 桌面主機。

其他 MCP 客戶端

參照 儲存庫 中的啟動說明。

README

Agent Mail Gateway

[CI] [License: MIT]

Give every AI agent its own email mailbox — without giving it the keys to that mailbox.

Agent Mail Gateway is a small self-hosted Docker service that sits between your agents and ordinary IMAP/SMTP mailboxes (Plesk, IONOS, Outlook, your own server — any provider). Each agent gets one API key bound to exactly one mailbox. Through the gateway it can read mail, send mail with attachments, and send, update or cancel calendar invitations. You decide who each agent may receive mail from and who it may write to; everything else is filtered out.

Mail bodies are delivered to the agent as Markdown (converted from HTML) and the agent writes Markdown that is sent as HTML — far fewer tokens than raw HTML email.

In short: a self-hosted email MCP server and REST API for AI agents — IMAP/SMTP mailbox access with sender/recipient allow lists, HTML-to-Markdown, attachments and calendar invites, packaged as one Docker container.

Typical use cases

  • An assistant agent that sends you daily reports, summaries or alerts by email.
  • Agents that receive tasks or documents by email and answer them in the same thread.
  • Agents that schedule, move and cancel meetings with you via calendar invitations.
  • Giving several agents separate mailboxes on your existing mail server (Plesk, IONOS, Outlook, Postfix/Dovecot, …) without exposing the mailbox passwords to them.
  • Locking an agent down so it can only talk to approved people — useful against prompt injection by email and against agents mailing the wrong people.

Works with any MCP client (for example Hermes Agent, Cursor, VS Code, n8n, LangChain/LangGraph MCP adapters) and with anything that can make HTTP requests.

Features

  • N mailboxes, one key each — a key can never reach another mailbox.
  • Allow lists per mailbox for receiving and sending (name@domain or *@domain).
  • Filtered mail is invisible — not listed, not readable, not even by guessing an id. Non-allowed mail is moved to Trash (default) or left untouched.
  • Spoofing protection — senders must pass SPF/DKIM/DMARC as reported by your mail server.
  • HTML ⇄ Markdown conversion in both directions.
  • Attachments in and out.
  • Calendar invites (iCalendar) that update or cancel cleanly in Outlook, Gmail and Apple Calendar.
  • REST API with OpenAPI docs at /docs, and an MCP server at /mcp with the same tools.
  • Webhooks (HMAC-signed) when an allowed message arrives; new mail is detected instantly via IMAP IDLE.
  • Send rate limit per mailbox and an audit log of every send, rejection and deletion.
  • Works with any IMAP/SMTP server: TLS on 993/465 or STARTTLS on 143/587.

How it works

 Agent ──REST/MCP + API key──▶ ┌──────────────────────────────────────┐                               │ Auth      key → exactly one mailbox  │ Agent ◀──signed webhook────── │ Policy    sender/recipient checks    │                               │ Converter HTML ⇄ Markdown            │                               │ Calendar  build/update/cancel .ics   │                               │ Mailbox   IMAP read + IDLE watcher   │──IMAP──▶ mail server                               │ Sender    SMTP + copy to Sent        │──SMTP──▶                               │ Store     SQLite (small state)       │                               └──────────────────────────────────────┘                                 config.yaml + .env (read-only)

The gateway stores no mail content; mail stays on your mail server.

Quick start

  1. Get the files:
    bash
    mkdir agent-mail-gateway && cd agent-mail-gatewaycurl -LO https://raw.githubusercontent.com/dominikamann/agent-mail-gateway/main/docker-compose.ymlcurl -L -o config.yaml https://raw.githubusercontent.com/dominikamann/agent-mail-gateway/main/config.example.yamlcurl -L -o .env https://raw.githubusercontent.com/dominikamann/agent-mail-gateway/main/.env.example
  2. Edit config.yaml: one entry per agent with its mailbox server, login and allow lists.
  3. Fill .env with the secrets referenced in config.yaml:
    bash
    openssl rand -hex 32   # an API key for each agentopenssl rand -hex 24   # a webhook secret (optional)
  4. Start it:
    bash
    docker compose up -dcurl http://localhost:8080/healthcurl -H "Authorization: Bearer $AGENT_API_KEY" http://localhost:8080/v1/mailbox

Every option is explained in docs/configuration.md.

Using it

REST — send a message:

bash
curl -X POST http://localhost:8080/v1/messages \  -H "Authorization: Bearer $AGENT_API_KEY" -H "Content-Type: application/json" \  -d '{"to":["[email protected]"],"subject":"Daily report","body_markdown":"All **green** today."}'

Read new mail:

bash
curl -H "Authorization: Bearer $AGENT_API_KEY" "http://localhost:8080/v1/messages?unread=true"

MCP — point any MCP client at http://<host>:8080/mcp with the header Authorization: Bearer <api key>. Tools: get_mailbox_info, list_messages, read_message, get_attachment, mark_message, delete_message, send_message, create_event, update_event, cancel_event, list_events.

stdio — clients that can only start local processes use the bundled bridge node dist/stdio.js with AGENT_MAIL_URL and AGENT_MAIL_API_KEY; see docs/stdio.md.

See docs/api.md for every endpoint, the webhook format and examples.

Hermes Agent — connect the MCP server in ~/.hermes/config.yaml and install the plugin that teaches your agents to use their mailbox safely:

bash
hermes plugins install dominikamann/agent-mail-gateway/integrations/hermes/agent-mail-gateway --enable

Step by step: docs/hermes.md.

Documentation

Security

Run the gateway behind a TLS reverse proxy when it is reachable from other machines. Report vulnerabilities privately as described in SECURITY.md.

License

MIT


Proudly provided by amannlabs.eu

來源:README.md,提交 6821eea

工具

0
工具後設資料尚未被收錄。

版本歷史

1
  1. v0.1.4最新Oct 2, 2026