Private development · Waitlist open
Your mail, reduced to decisions.
We are building Keelpost: every account in one place, and twice a day a briefing that says what happened, what matters, and what it proposes to do about it — a reply ready to send, a stack to archive, a rule to adopt. You approve; it acts. Nothing it cannot take back ever happens without you.
Sign-ups are closed while we build. Leave an address and we will write once, when they open — one email, and nothing else.
BriefingFri 8 Aug 07:003 accounts4 need you
Replyfrom you@consultco.exampleSends mail
From the server
Nina Okafor — Q3 contract: can you confirm scope by Friday?
From the model
A draft that confirms the scope, flags the licensing carve-out and proposes a call on Friday.
Archive · 12 messages
From the server
Deploy notices, payment receipts, newsletter digests.
From the model
All twelve are from senders you have archived unread before. Everything here can be undone.
- Filed 14 → Newsletters · Review 3 · Undo
Next briefing 19:00
Your inbox was never a list of messages
It is a queue of decisions with a great deal of noise stacked on top of it. Mail software has spent thirty years getting better at showing you the noise: faster lists, tighter threading, cleverer search. Four things in this morning’s forty actually need you, and every product you have used made you find them yourself.
Keelpost is being built to hand you those four. Twice a day it reads everything that arrived across every account you have connected, writes one short briefing, and puts a proposal on each thing that needs a decision — a reply already drafted, a stack of twelve to archive, a rule worth adopting. You approve, and it acts. Everything else is summarised in a line, filed, and offered back in a sample so you can correct it.
Under the briefing there is a full mail client — folders, threaded conversations, search, compose — for the days you want to work unsupervised. That part runs today. It is not the product; it is where you go when the product has done its job.
Two ways mail gets in
Your own domain. Route a domain you already own into Keelpost with Cloudflare Email Routing, under your own Cloudflare account. The DNS is yours, the routing rules are yours, and turning Keelpost off is a change you make on your side rather than a ticket you file with us. This is the door that works today.
The account you already have. Google Workspace and Microsoft 365, connected with their own sign-in and read through their own APIs. This is the door most people will use, and it is not built yet — there is nothing to connect and no beta to ask for.
What it is not
- Not a mail host. We do not run MX for you and we do not sell you addresses.
- Not an autonomous assistant. If you never open the briefing, your mail goes unanswered — Keelpost makes responding fast, it does not respond for you.
- Not a front end for Gmail, Microsoft 365 or IMAP today. Two of those are on the roadmap and one may never be.
- Not open for sign-up. The only thing you can do here is join the waitlist.
The line it cannot cross
This is the part worth reading carefully, and it is the part that already exists. Software that acts on your mail and tells you afterwards is easy to build. The whole design here is the pause before the action — and the pause is running code, not a plan.
Move an email
Proposed by the agent
From the server
- msg_7Kd2QpXr
- Sender
- billing@northharbour.example
- Recipient
- you@yourdomain.example
- Subject
- Invoice 4471 — February
- Body preview
- Please find invoice 4471 attached…
- Current folder
- Inbox (inbox)
- Current state
- Unread
- Attachments
- 1
revision 7 · re-verified
From the model
- Requested destination
- Accounts (accounts)
Inboxmoved to Accounts
Shown from the stored message, not from the agent’s summary. Re-checked against the server the moment you click.
The circle and rule between the two blocks is the revision fence. The card is built from the server’s copy of the message at a known revision; if that message changes before you click, the change no longer matches what you were shown and approval is blocked rather than applied to something else.
The dividing line is reversibility, not capability
What an agent is allowed to do alone should not be decided by how clever it is. It should be decided by whether you can undo the result.
- Files, labels, summarises
- It does it, tells you it did, and you can put it back.
- Drafts a reply
- It writes it, shows it to you, and waits.
- Sends. Deletes.
- Never without your approval of that exact action — that message, that recipient, that day. Not a category you agreed to once, and never as part of an “approve all”. Twelve archives can be one click. Two sends are two decisions.
Today Keelpost is stricter than that table, and the difference is worth stating plainly: it stops and asks before every change, reversible or not. Acting on the reversible things and reporting them afterwards is the design we are building toward, and undo ships before the loosening does. An agent that asks about everything trains you to stop reading, which is how a boundary becomes a formality.
How it behaves, step by step
-
You ask for something, or a briefing runs
“Find everything from the shipping vendor this month and file it.” The agent searches the mailbox with the same search that the client uses.
-
It reads only what you can read
Every turn and every tool call re-checks your live grants against the server, not against whatever was true when the conversation started. If your access to that mailbox was revoked a minute ago, the next step fails.
-
It proposes, and stops
Anything the agent can change — writing a draft, revising one, discarding one, a move, a read-mark — halts and renders an approval card. It has no send tool and no tool that deletes a message you have received. The card is drawn by the server from the stored message, not from the agent’s description of it. If the agent misread the message, the card still shows what is actually there.
-
You approve, and the server acts
Approval is what performs the action. The permission check runs again at that moment. Deny and nothing happens; the agent is told no and carries on.
-
New mail gets a draft, never a send
When a message arrives, Keelpost can write a reply and leave it in drafts, unsent, for you to edit or bin. That path has no ability to deliver anything at all.
There is no setting that turns a required approval off, and no “always allow this kind of action”. An MCP client may read mail and create a new, inert draft. Seven of the fourteen tools — sending a message, sending a reply, deleting a message, discarding a draft, overwriting a draft, moving a message and marking a message read — use the exact approval flow described on the security page. When sending is verified, approving a send will send it — after a short, visible delay with a cancel, so that one click stays one click and a mistake stays recoverable. The full mechanism — including how inbound mail is scanned for prompt injection first — is set out on the security page.
Ever learning, in the open
The reason to put a person in front of every consequential action is not only safety. It is that a decision is a labelled example and an undo is not. An undo says something went wrong; it never says what should have happened instead.
It will propose rules, not acquire habits
“You have archived eleven Substack digests unopened this month — file these automatically?” Approve it and the rule joins a list you can read, edit and delete a line from, written as the literal predicate it will run. When the agent does something baffling in month four there is a specific line to point at rather than a mood to argue with.
It will hand three of them back
If forty messages are filed and nobody ever looks in the folder, nothing learns it was wrong about any of them — and it grows most confident about exactly the cases nobody checked. So the briefing offers three back, not forty, and a correction from that sample counts for far more than an ordinary one.
It will start from your last ninety days
The first briefing arrives to somebody who has not yet decided to trust it, so it cannot be the worst one. Before the first run it reads the history: who gets a reply within the hour, who never does, what was archived unread, which threads you started.
Whatever it learns about your mail is yours, and it will be exportable. That looks like giving away the lock-in and is not: six months of accumulated policy is a switching cost either way, and being free to leave is exactly what makes it reasonable to invest in teaching it. None of this paragraph is built yet; it is what the approval gate is for.
What it will cost
No prices are set, so there are none here. The shape is set, and the shape is the whole argument: you are not billed per message, per mailbox or per clever feature. The meter is how often the briefing runs.
- Free
- The briefing runs every twelve hours, and you can always pull it early by hand.
- Paid
- The same briefing, more often.
- Yours
- Connect your own Cloudflare account and run it as often as you like. The inference is then yours, so it costs us nothing and we intend to charge you nothing for it.
Working today, and what is not
Everything in the first column has been exercised by running the application. Everything in the second is unfinished, unverified or not started — including the briefing this page is largely about. We would rather you find that out here than after you have moved a domain.
Runs today
Your own domainLive
- Receiving mail on a domain you control, through Cloudflare Email Routing.
- The web client: folders, threading, search operators, rich-text compose, drafts, reply and forward, attachments, per-mailbox settings.
- Workspaces, four roles, per-mailbox grants, invitation-only membership, and revocation that takes effect on a session already in use.
- The per-mailbox agent: read, search, triage, draft — with an approval card on every state change.
- Prompt-injection scanning of inbound mail, gating automatic drafting and failing closed.
- The MCP endpoint: 14 scope-gated tools over OAuth 2.1 with PKCE — reading and drafting work outright. The seven that change something ask a person first, over the protocol's own confirmation round-trip.
- Installing it as a web app: it adds to a home screen and launches without re-fetching the interface. No mail is stored on the device, so with no connection it says it is offline rather than showing you a stale mailbox.
Not there yet
Sending in productionNext — being worked on, not built yetThe briefingPlanned — not built yetMicrosoft 365Planned — not built yetGmailPlanned — not built yetPricingPlanned — not built yet
- The briefing itself. Designed, drawn on this site, and not written. Every sentence about it here is in the future tense on purpose.
- Sending in production. The outbound path is written — the message is persisted before anything is published to a queue, with durable jobs, bounded retries and dead-letter queues — but it has not been verified against a live provider. Until it has, treat sending as unproven.
- Google Workspace and Microsoft 365. Not built. Not partially built. IMAP and POP may never be, and the reason is architectural.
- Undo, and the reversibility tiers above. Today every change asks.
- Certifications. No SOC 2, no ISO, no HIPAA, no audit of any kind.
- Pricing. None set, so there is nothing to quote.
Join the waitlist
Keelpost is in private development. There is no free tier to try, no trial to start and no price to compare, because none of those exist yet. If a mailbox that hands you four decisions instead of forty messages is the thing you want, leave an address. We will write once, when sign-ups open, and that is the only thing the list is for.
We store the address you type, plus a hashed form of your IP address so the form can be rate-limited. One email when sign-ups open, and nothing after that. We do not share the list, and there is no analytics or third-party script on this site.
There are common questions about access and pricing on the FAQ.