Private development

The agent proposes. You decide.

Keelpost is an email client for a domain you already control. It reads, searches and triages your mail and writes drafts for you. Before it moves, files or deletes anything, it stops and shows you the exact message and the exact change, and waits.

Sign-ups are closed while we build. Leave an address and we will write once, when they open — one email, and nothing else.

A diagram of the approval step, not a screenshot. The field names, the two-block split and the revision re-check are the product’s; the visual styling is this site’s, and the message is fabricated sample data.

What it is

Keelpost is an email client, not a mail host. You bring a domain you already own, your own Cloudflare account and your own keys. We do not become your mail provider, and you can point the domain somewhere else the day you want to.

Today that works one way: you route a domain you control into Keelpost with Cloudflare Email Routing. Mail lands in a mailbox that belongs to your workspace, and everything else — the client, the roles, the agent — is built around that mailbox.

The point of it is the agent, and the point of the agent is that it cannot act alone. It reads what you can read and it proposes what it would like to do. A person approves every change.

What it is not

  • Not a mail host. We do not run MX for you.
  • Not a front end for Gmail, Outlook, Zoho or IMAP. Those connections are planned and not built.
  • Not a mobile app or a browser extension. Neither exists.
  • Not open for sign-up. The only thing you can do here is join the waitlist.

What is built

A complete mail client, not a demo

Folders and threaded conversations. Search with operators — from:, to:, subject:, in:, is:unread, is:starred, has:attachment, before:, after:, with quoted values. Rich-text compose, drafts, reply, reply-all and forward, inbound attachments, and settings per mailbox rather than one global blob.

Your domain, your Cloudflare account, your keys

Receiving runs on Cloudflare Email Routing under your own account. The DNS records are yours, the routing rules are yours, and the credentials are yours. Turning Keelpost off is a change you make on your side, not a support ticket you file with us.

Workspaces, roles and per-mailbox grants

Four roles: owner, admin, operator, viewer. Owners and admins see the workspace’s mailboxes; operators and viewers see only the mailboxes they have been granted, one at a time. Membership is invitation-only — nobody joins because they happen to have an address at your domain. Revoke a grant and the session that is open right now loses access on its next action.

An agent that lives in one mailbox

Each mailbox has its own agent. It can read, search, summarise, triage and draft, and it runs with your permissions, re-checked on every turn and every tool call. It cannot reach a mailbox you were not granted, and it cannot borrow someone else’s access to answer your question.

Untrusted mail is treated as untrusted

Every inbound message is scanned for prompt injection before the auto-draft model sees it. If the scan says a message is trying to steer the agent, or if the scan itself fails, automatic drafting is blocked for that message. It fails closed on purpose: a scanner that errors is treated the same as a scanner that says no. What the scan gates is that automatic path — a flagged message stays readable, so treat agent output over untrusted mail accordingly. The auto-draft assistant has exactly one thing it can do — write a draft. It has no send.

An MCP endpoint for your own tools

Fourteen scope-gated tools over OAuth 2.1 with PKCE, so a client you trust can list mailboxes, read and search mail, and manage drafts under scopes you granted: mailboxes:read, mail:read, mail:draft, mail:manage, mail:send, mail:delete. The six tools that would change something refuse on every mailbox today, because a scope proves which client is calling and not that a person saw the change. Clients are created by an owner or admin. Dynamic client registration is deliberately off, so nothing registers itself.

How the agent behaves

This is the part worth reading carefully. Agents that act on your mail and tell you afterwards are easy to build. The whole design here is the pause before the action.

  1. You ask for something

    “Find everything from the shipping vendor this month and file it.” The agent searches the mailbox with the same search that the client uses.

  2. It reads only what you can read

    Every turn and every tool call re-checks your live grants against the server, not against whatever was true when the conversation started. If your access to that mailbox was revoked a minute ago, the next step fails.

  3. It proposes, and stops

    Anything that changes state — move, send, delete, mark as read — halts and renders an approval card. The card is drawn by the server from the stored message, not from the agent’s description of it. If the agent misread the message, the card still shows what is actually there.

  4. You approve, and the server acts

    Approval is what performs the action. The permission check runs again at that moment. Deny and nothing happens; the agent is told no and carries on.

  5. New mail gets a draft, never a send

    When a message arrives, Keelpost can write a reply and leave it in drafts, unsent, for you to edit or bin. That path has no ability to deliver anything at all.

A diagram of the approval step, not a screenshot. The field names, the two-block split and the revision re-check are the product’s; the visual styling is this site’s, and the message is fabricated sample data.

The circle and rule between the two blocks is the revision fence. The card is built from the server’s copy of the message at a known revision; if that message changes before you click, the change no longer matches what you were shown and approval is blocked rather than applied to something else.

There is no setting that turns approval off, and no “always allow this kind of action”. If it changes state, it asks. The full mechanism — including how inbound mail is scanned for prompt injection first — is set out on the security page.

Working today, and what is not

Everything in the first column has been exercised by running the application. Everything in the second is either unfinished or unverified. We would rather you find that out here than after you have moved a domain.

Works today

Your own domainLive

  • Receiving mail on a domain you control, through Cloudflare Email Routing.
  • The web client: folders, threading, search operators, rich-text compose, drafts, reply and forward, attachments, per-mailbox settings.
  • Workspaces, four roles, per-mailbox grants, invitation-only membership, and revocation that takes effect on a session already in use.
  • The per-mailbox agent: read, search, triage, draft — with an approval card on every state change.
  • Prompt-injection scanning of inbound mail, gating automatic drafting and failing closed.
  • The MCP endpoint: 14 scope-gated tools over OAuth 2.1 with PKCE — the eight that read or draft. The six that change something refuse until MCP has a confirmation round-trip.

Not there yet

GmailPlanned — not built yetOutlookPlanned — not built yetZohoPlanned — not built yetIMAPPlanned — not built yetSending in productionPlanned — not built yet

  • Sending in production. The outbound path is written — the message is persisted before anything is published to a queue, with durable jobs, bounded retries and dead-letter queues — but it has not been verified against a live provider. Until it has, treat sending as unproven.
  • Gmail, Outlook, Zoho and generic IMAP. Not built. Not partially built.
  • Mobile app, browser extension. Neither exists.
  • Integrations, calendar, automation rules. None.
  • Certifications. No SOC 2, no ISO, no HIPAA, no audit of any kind.
  • Pricing. None set, so there is nothing to quote.

The full roadmap, in order

Join the waitlist

Keelpost is in private development. There is no free tier to try, no trial to start and no price to compare, because none of those exist yet. If what you have read sounds like the mail client you want, leave an address. We will write once, when sign-ups open, and that is the only thing the list is for.

We store the address you type, plus a hashed form of your IP address so the form can be rate-limited. One email when sign-ups open, and nothing after that. We do not share the list, and there is no analytics or third-party script on this site.

There are common questions about access and pricing on the FAQ.