Frequently asked questions
Questions
Answers for the person who has to decide whether this is worth their domain. Where the answer is “no” or “not yet”, it says so.
The product
Is Keelpost hosting my email?
No. Keelpost is a client. You own the domain, you run the Cloudflare account, and Email Routing under your control delivers mail into the app. We do not sell you addresses, we do not run MX for you, and we are not in the position of holding your domain hostage — you change your routing and it stops.
What do I actually need to run it today?
A domain you control, a Cloudflare account with Email Routing configured for that domain, and your own keys. That is the only supported way mail gets in right now.
Can I connect my Gmail, Outlook, Zoho or IMAP account?
No. Not partially, not in beta, not behind a flag. Those connections are on the roadmap and none of them is built. If that is the feature you need, the honest answer is that Keelpost is not usable for you yet.
GmailPlanned — not built yetOutlookPlanned — not built yetZohoPlanned — not built yetIMAPPlanned — not built yet
Can I send mail?
Not with any confidence yet. The outbound path is written and it is written carefully — the message is stored before any delivery job is published, delivery runs as a durable background job with bounded retries and a dead-letter queue — but it has not been verified against a live provider. We do not count sending as working, and neither should you until this page says otherwise.
Sending in productionPlanned — not built yet
The agent
What stops the agent from doing something destructive?
It cannot perform a state change at all. Moves, sends, deletes and read-marks halt and render an approval card that a person has to accept, and approving is what performs the action. The card is drawn by the server from the stored message, so it shows the real message and the real change rather than the model’s description of them. There is no setting that turns this off and no allow-list that skips it.
What if an incoming email contains instructions aimed at the agent?
Inbound mail is scanned for prompt injection before the drafting model sees it, and a flagged message gets no automatic draft. If the scanner errors, the message is treated as flagged — it fails closed.
Be clear on the limit: the scan gates automatic drafting only. A flagged message is not quarantined, so if you or an MCP client ask the agent to read it, its content reaches the model. Beyond that, the structural answer is the one above: even a fully manipulated agent has no way to move, send or delete anything without a person clicking approve, and the auto-draft path has no send capability at all.
Which model reads my mail, and where does the content go?
The agent runs on Cloudflare Workers AI, inside the same Cloudflare account boundary as the rest of the deployment. Message content is sent to that model when you use the agent or when auto-drafting runs on a new message. There is no other model provider in the path.
Access and control
How do I stop a colleague seeing a mailbox?
Remove their grant. Operators and viewers only ever see mailboxes granted to them individually; owners and admins see the workspace’s mailboxes. Removal takes effect on the session they have open — their next action, in the client or through the agent, fails rather than waiting for a logout.
Is the MCP endpoint as constrained as the in-app agent?
It is constrained differently, and today it is constrained harder. An MCP client is stopped by scope first: it holds an OAuth 2.1 token with PKCE, gated to specific tools, and it can never exceed the mailbox grants of the account that authorised it. On top of that, the six tools that would change something — send_email, send_reply, move_email, mark_email_read, delete_email and discard_draft — refuse on every mailbox, because a scope proves which client is calling and not that a person saw the change. So a client you granted mail:send cannot send. The eight read and draft tools work, and a draft is inert until you send it from the app. Owners and admins create the clients, dynamic registration is off, and consent can be revoked and secrets rotated.
Access, cost and provenance
Are you SOC 2, ISO 27001 or HIPAA compliant?
No. We hold no certification of any kind, we have not been audited, and we are not going to display a badge we did not earn. See the “what we do not claim” section on the security page for the full list of things we are not asserting.
What does it cost?
There is no price, because there is no plan, no billing and no way to buy it. If you see a price for Keelpost anywhere, it did not come from us.
How do I get access?
Join the waitlist. Sign-ups are closed, there is no invite code circulating, and no trial. You get one email when sign-ups open.
Is Keelpost open source?
Keelpost is derived from Cloudflare’s Agentic Inbox, which is licensed under Apache 2.0; that attribution stays in our footer and in the source headers where it belongs. We have not published our own repository and we are not promising when or whether we will.
What happens to my mail if I stop using Keelpost?
The routing is yours, so the first step is entirely in your hands: repoint the domain and delivery stops. For what happens to data already stored, we will publish the exact behaviour before sign-ups open rather than describe something today that has never been exercised with a real account.
Still deciding?
Leave an address and read the roadmap while you wait. Sign-ups are closed; the list is the only thing to join, and it gets one email when they open.
We store the address you type, plus a hashed form of your IP address so the form can be rate-limited. One email when sign-ups open, and nothing after that. We do not share the list, and there is no analytics or third-party script on this site.