[{"data":1,"prerenderedAt":886},["ShallowReactive",2],{"search":3,"content-guide\u002Fsealed-mail":478,"surround-\u002Fguide\u002Fsealed-mail":881},[4,8,12,16,20,24,28,32,36,40,44,48,52,56,60,64,68,72,76,80,84,88,92,96,100,104,108,112,116,120,124,128,132,136,140,144,148,152,156,160,164,168,172,176,180,184,188,192,196,200,204,208,212,216,220,224,228,232,236,240,244,248,252,256,260,264,268,272,276,280,284,288,292,296,300,304,308,312,316,320,324,328,332,336,340,344,348,352,356,359,363,367,371,375,379,383,387,391,395,399,403,407,411,415,419,423,427,431,435,439,443,447,451,455,459,462,466,470,474],{"path":5,"title":6,"description":7},"\u002Fguide","Guide","Product guides for Owlat — a modular, self-hosted email platform. Learn how to send campaigns, run a personal mailbox, manage a team inbox, and more.",{"path":9,"title":10,"description":11},"\u002Fguide\u002Fgetting-started","Welcome to Owlat","Set up your Owlat workspace and send your first email — from deploying the stack to verifying a domain, building your audience, and launching a campaign.",{"path":13,"title":14,"description":15},"\u002Fguide\u002Fcontact-properties","Contact Properties","Custom fields that extend built-in contact data with your own values for segmentation.",{"path":17,"title":18,"description":19},"\u002Fguide\u002Ftopics","Topics","Topics are explicit audience groups you manage by hand — ideal for opt-in subscribers, imported cohorts, and organized contact buckets you target with campaigns.",{"path":21,"title":22,"description":23},"\u002Fguide\u002Fsegments","Segments","Build dynamic, rule-based contact groups from properties, email activity, and topic membership, re-evaluated from current data each time they're used.",{"path":25,"title":26,"description":27},"\u002Fguide\u002Fforms","Forms","Form Endpoints collect new contacts from your website or landing pages by exposing a public endpoint that accepts submissions and feeds them into a topic.",{"path":29,"title":30,"description":31},"\u002Fguide\u002Fcampaigns","Campaigns & Reporting","Build and send marketing campaigns to a topic or segment with the three-step wizard, optional A\u002FB testing, and full delivery reporting.",{"path":33,"title":34,"description":35},"\u002Fguide\u002Fab-testing","A\u002FB Testing","Compare two variants of a campaign on a test group, then automatically or manually send the winning version to the rest of your audience.",{"path":37,"title":38,"description":39},"\u002Fguide\u002Fautomations","Automations","Send emails automatically based on triggers, delays, and conditions — build welcome series, trial flows, and follow-ups once and let Owlat run them.",{"path":41,"title":42,"description":43},"\u002Fguide\u002Ftransactional","Transactional Emails","One-to-one emails your application triggers in response to a user action — password resets, order confirmations, welcome emails, and similar notifications.",{"path":45,"title":46,"description":47},"\u002Fguide\u002Fcreate-campaign","Create a Campaign","Walk through Owlat's three-step campaign wizard: Setup, Content, and Review & Send.",{"path":49,"title":50,"description":51},"\u002Fguide\u002Fsend-campaign","Send & Monitor a Campaign","How to send your campaign and track its performance with real-time metrics.",{"path":53,"title":54,"description":55},"\u002Fguide\u002Fquick-start","Quick Start","The fastest path from a blank Owlat workspace to a live email campaign, from your first template through sending and reviewing results.",{"path":57,"title":58,"description":59},"\u002Fguide\u002Ftransactional-setup","Transactional Email Setup","Set up and send transactional emails like password resets and order confirmations via the Owlat API and SDKs.",{"path":61,"title":62,"description":63},"\u002Fguide\u002Fdeliverability","Deliverability","Verify sending domains, manage your blocklist, monitor sending reputation, and stay compliant so your emails reach the inbox.",{"path":65,"title":66,"description":67},"\u002Fguide\u002Fapi-keys-webhooks","API Keys & Webhooks","Create API keys for programmatic access and set up outbound webhooks to receive real-time notifications for email and contact events.",{"path":69,"title":70,"description":71},"\u002Fguide\u002Ffeature-flags","Feature flags","Owlat is modular — every feature listed in this guide can be turned on or off. This page is the user-facing overview of how to do it.",{"path":73,"title":74,"description":75},"\u002Fguide\u002Fteam-permissions","Team & Permissions","Use role-based access to control what each member of your organization can do, with Owner, Admin, and Editor roles.",{"path":77,"title":78,"description":79},"\u002Fguide\u002Faudit-logs","Audit Logs","A chronological record of significant actions in your Owlat organization, so you can see who did what and when.",{"path":81,"title":82,"description":83},"\u002Fguide\u002Fshare-links","Share Links","Create temporary preview links to share email designs with stakeholders who don't have dashboard access.",{"path":85,"title":86,"description":87},"\u002Fguide\u002Fpostbox","Postbox — Personal Email","Per-user mailboxes with a webmail interface and native IMAP\u002FSMTP support. Run your own Gmail-equivalent personal mailbox on your Owlat instance.",{"path":89,"title":90,"description":91},"\u002Fguide\u002Fmigrate-from-google","Migrate from Google","Import your full Gmail history into Owlat over IMAP, and let your AI assistant learn from every imported conversation.",{"path":93,"title":94,"description":95},"\u002Fguide\u002Fteam-inbox","Team Inbox","Triage inbound email as a team: read AI-classified threads, approve, edit or reject agent drafts, work the review queue, and manage quarantine.",{"path":97,"title":98,"description":99},"\u002Fguide\u002Femail-editor","Email Editor","A block-based visual editor for building responsive emails that render consistently across desktop, mobile, Outlook, Gmail, and Apple Mail.",{"path":101,"title":102,"description":103},"\u002Fguide\u002Fai-agent","AI Agent & Autonomy","Configure the AI agent that classifies and drafts replies to inbound mail: auto-reply settings, the health dashboard, circuit breakers, autonomy rules, and the knowledge backfill.",{"path":105,"title":106,"description":107},"\u002Fguide\u002Fknowledge-graph","Knowledge Graph","Browse, search, and manage Owlat's typed organizational knowledge — the 7 entry types, source attribution, confidence decay, relations, and how entries are extracted from mail.",{"path":109,"title":110,"description":111},"\u002Fguide\u002Ffiles","Files","Upload, browse, search, tag, and version documents in the file library.",{"path":113,"title":114,"description":115},"\u002Fguide\u002Fchat","Team Chat","Use Owlat's built-in team chat: public and private channels, direct messages, mentions, attachments, and channels linked to an inbox conversation.",{"path":117,"title":118,"description":119},"\u002Fguide\u002Fcode-tasks","Code Tasks","Queue coding-agent tasks, watch them move from queued through review, and run the code-worker sidecar that opens the pull requests.",{"path":121,"title":122,"description":123},"\u002Fguide\u002Faudience-data","Audience Data: Identities, Relationships & Timeline","Unify a contact across email, phone, and messaging channels, merge duplicates, map relationships, and read the cross-channel interaction timeline.",{"path":125,"title":126,"description":127},"\u002Fguide\u002Fimporting-contacts","Importing & Exporting Contacts","Bring contacts into Owlat from a CSV or from Mailchimp and Stripe, export them back out, and run bulk operations on your audience.",{"path":129,"title":130,"description":131},"\u002Fguide\u002Faccount","Your Account & Data","Export your data as JSON or CSV, request account deletion with a 30-day grace period, and use the onboarding checklist and the public preference center.",{"path":133,"title":134,"description":135},"\u002Fguide\u002Fchannels","Communication Channels","Configure SMS, WhatsApp, and generic-webhook channels, monitor channel health, and understand which channels are fully live today.",{"path":137,"title":138,"description":139},"\u002Fguide\u002Fdesktop-app","Desktop App","Install the Owlat desktop app, connect one or more workspaces, switch between them, and use native notifications, the dock\u002Ftaskbar unread badge, shortcuts, and deep links.",{"path":141,"title":142,"description":143},"\u002Fguide\u002Femail-templates","Email Templates","Reusable email designs that define the structure, content, and personalization of every campaign and transactional message you send in Owlat.",{"path":145,"title":146,"description":147},"\u002Fguide\u002Fai-assistant","AI Assistant","Owlat's multi-turn, streaming, tool-calling AI assistant — a private chat surface that can search your workspace and draft copy, plus @assistant replies inside team chat.",{"path":149,"title":150,"description":151},"\u002Fguide\u002Fsecurity-scanning","Sending Security & Scanning","Owlat's security scanning: a content check for spam and phishing, an attachment scan for malware, and a Google Safe Browsing URL check. Suspicious content goes to a review queue.",{"path":153,"title":154,"description":155},"\u002Fguide\u002Fsystem-updates","System & Updates","The owner-only System & Updates screen: your current Owlat version, container health, LLM spend, and the in-app one-click updater with history.",{"path":157,"title":158,"description":159},"\u002Fguide\u002Foperating-modes","Operating Modes","The different ways to run Owlat at a company — read external mailboxes over IMAP, send transactional or marketing email through a delivery provider, host your own mail server, or run a team inbox with AI — and the rules that keep each combination coherent.",{"path":161,"title":162,"description":163},"\u002Fguide\u002Freply-queue","Reply Queue","A task list of emails waiting on your reply — Postbox detects unanswered asks, ranks them by urgency and age, and clears them the moment you respond.",{"path":165,"title":166,"description":167},"\u002Fguide\u002Fsmart-inbox","Smart Inbox","Split your Postbox inbox into People, Newsletters, Notifications, and Receipts — a deterministic classifier first, AI refinement for the ambiguous middle, off by default, and a per-sender override that's remembered.",{"path":169,"title":170,"description":171},"\u002Fguide\u002Fpostbox-settings","Postbox settings reference","Every Postbox behavior toggle in one place — auto-advance, reply defaults, density, writing suggestions, auto-summaries, notifications, the on-device cache, and the send sound — with what each does and its default.",{"path":173,"title":174,"description":175},"\u002Fguide\u002Fcalendar-availability","Calendar Availability for Scheduling Replies","Point Owlat at a read-only calendar feed so AI scheduling replies propose your real open times instead of only echoing the sender's.",{"path":177,"title":178,"description":179},"\u002Fguide\u002Fconnect-your-ai","Connect your AI","Pick the AI backend every Owlat AI feature uses — a hosted provider via an API key (OpenAI, Anthropic, Google, Azure OpenAI, OpenRouter) or a model you host yourself (Ollama, vLLM, llama.cpp) — plus the local-by-default embeddings that make retrieval work under any choice.",{"path":181,"title":182,"description":183},"\u002Fguide\u002Fsealed-mail","Sealed Mail — End-to-End Encryption","How Owlat encrypts personal mail end-to-end between Owlat workspaces, when a message auto-seals versus sends in the clear, and how to read the Sealed and sender-verified badges.",{"path":185,"title":186,"description":187},"\u002Fguide\u002Fsaved-blocks","Saved Blocks","Create reusable, linked content blocks you can drop into any email — edit one and every email that uses it updates automatically.",{"path":189,"title":190,"description":191},"\u002Fguide\u002Fsealed-mail-recovery-kit","Sealed Mail Recovery Kit","What a Sealed Mail recovery kit is, when it's offered, how to download and store it, how to restore access after a rebuild, and the blunt warning about losing it.",{"path":193,"title":194,"description":195},"\u002Fguide\u002Fmedia-library","Media Library","Manage, organize, search, and reuse images and files across your emails from one centralized hub.",{"path":197,"title":198,"description":199},"\u002Fguide\u002Femail-theme","Email Theme","Set your organization's default colors, font, and email width so every new template starts from a consistent baseline.",{"path":201,"title":202,"description":203},"\u002Fguide\u002Ftranslations","Translations","Send one email in multiple languages: add per-language translations to a single template and Owlat picks the right version for each recipient.",{"path":205,"title":206,"description":207},"\u002Fguide\u002Fcontacts","Contacts","How to add, view, organize, and manage contacts in Owlat, including sources, the contact detail tabs, and subscription compliance.",{"path":209,"title":210,"description":211},"\u002Fapi","API Overview","Owlat exposes authenticated API endpoints under your Convex site URL.",{"path":213,"title":214,"description":215},"\u002Fapi\u002Fwebhooks","Webhooks","Owlat supports both outbound customer webhooks and inbound provider webhooks.",{"path":217,"title":218,"description":219},"\u002Fapi\u002Fpublic-endpoints","Public Endpoints","These routes are public-facing and usually accessed from email links or embedded forms.",{"path":221,"title":222,"description":223},"\u002Fapi\u002Fwebhook-payloads","Webhook Payloads","The authoritative wire contract for outbound webhooks: envelope, signature headers, per-event data shapes, and payload versioning.",{"path":225,"title":226,"description":227},"\u002Fapi\u002Finbound-channels","Inbound Channel Webhooks","Provider webhook reference for inbound SMS, WhatsApp, and generic-channel messages, plus the MTA mailbox and credential callbacks.",{"path":229,"title":230,"description":231},"\u002Fapi\u002Fauthentication","Authentication","Secure API access with organization-scoped API keys.",{"path":233,"title":234,"description":235},"\u002Fapi\u002Fsdk","TypeScript SDK","Typed client for the Owlat API, usable from Node.js, Bun, Deno, or any server-side JavaScript runtime.",{"path":237,"title":238,"description":239},"\u002Fapi\u002Fsdk-java","Java SDK","The official `owlat-sdk` package provides a typed client for interacting with the Owlat API from any JVM application. Requires Java 11+.",{"path":241,"title":242,"description":243},"\u002Fapi\u002Fcontacts","Contacts API","Manage contacts for your organization.",{"path":245,"title":246,"description":247},"\u002Fapi\u002Ftopics","Topics API","Manage topic membership through authenticated endpoints.",{"path":249,"title":250,"description":251},"\u002Fapi\u002Fevents","Events API","Send contact events to drive segmentation and automation triggers.",{"path":253,"title":254,"description":255},"\u002Fapi\u002Ftransactional","Transactional API","Send published transactional templates to a recipient.",{"path":257,"title":258,"description":259},"\u002Fapi\u002Fforms","Forms API","Capture subscribers through public form endpoints.",{"path":261,"title":262,"description":263},"\u002Fdeveloper","Developer Guide","Technical architecture, feature-flag model, and provider abstractions used by Owlat.",{"path":265,"title":266,"description":267},"\u002Fdeveloper\u002Fmta-system","MTA System","Owlat's custom Mail Transfer Agent for direct SMTP delivery with intelligent rate limiting, bounce processing, and IP warming.",{"path":269,"title":270,"description":271},"\u002Fdeveloper\u002Ffeature-flags","Feature flags — developer reference","How the Owlat feature flag system works: single source of truth, dependency resolution, docker profile mapping, and how to add a new flag.",{"path":273,"title":274,"description":275},"\u002Fdeveloper\u002Fhow-email-works","How Email Works","A technical deep-dive into how email actually works — from SMTP and DNS to authentication, deliverability, and the differences between marketing and private email.",{"path":277,"title":278,"description":279},"\u002Fdeveloper\u002Femail-security","Email Security","Content scanning, attachment validation, URL reputation checking, and malware detection for outbound emails.",{"path":281,"title":282,"description":283},"\u002Fdeveloper\u002Fpostbox-architecture","Postbox Architecture","How the Postbox personal-mail feature is wired — schema, IMAP server, app-password auth, outbound relay, inbound delivery, and external mailboxes.",{"path":285,"title":286,"description":287},"\u002Fdeveloper\u002Fproviders","Providers","Pluggable provider abstractions for LLM, email sending, notifications, vector stores, and analytics, selected per-deployment so self-hosters can swap implementations without code changes.",{"path":289,"title":290,"description":291},"\u002Fdeveloper\u002Fcampaign-internals","Campaign Internals","How the campaign backend works: two status machines, send pre-flight, the send orchestrator, emailSends records, and the priority workpools.",{"path":293,"title":294,"description":295},"\u002Fdeveloper\u002Faudience-internals","Audience Internals","Backend reference for contact resolution, the double opt-in lifecycle, topic subscription, the conditions registry, and segment evaluation.",{"path":297,"title":298,"description":299},"\u002Fdeveloper\u002Fautomation-internals","Automation Internals","How the automation run engine works: the step walker, the lifecycle state machine, trigger fanout, the three step types, and the resilience cron.",{"path":301,"title":302,"description":303},"\u002Fdeveloper\u002Fdeliverability-infrastructure","Deliverability Infrastructure","The Convex-side deliverability backend: provider routing, health-aware failover, sending reputation with auto-enforcement, IP warming cache, the blocklist, and the content-scan gate.",{"path":305,"title":306,"description":307},"\u002Fdeveloper\u002Farchitecture","Architecture Overview","Owlat follows a modern serverless architecture with real-time capabilities.",{"path":309,"title":310,"description":311},"\u002Fdeveloper\u002Fplatform-operations","Platform Operations","Operator reference for abuse status and the sending gate, the platform-admin roster, content review, org deletion, in-app self-update, dev endpoints, crons, and migrations.",{"path":313,"title":314,"description":315},"\u002Fdeveloper\u002Fsealed-mail-at-rest","Sealed Mail: Bodies at Rest","How Owlat seals every stored message body with an instance data key, and the deliberate search-index exceptions that stay plaintext.",{"path":317,"title":318,"description":319},"\u002Fdeveloper\u002Ftransport-security","Transport Security","Operator guide to Sealed Mail's transport hardening: requiring TLS for inbound delivery, publishing MTA-STS, outbound TLS and DANE posture, TLS-RPT, and secrets at rest.",{"path":321,"title":322,"description":323},"\u002Fdeveloper\u002Fscopes","Scopes","What each app and package in the Owlat monorepo is responsible for.",{"path":325,"title":326,"description":327},"\u002Fdeveloper\u002Fself-hosting","Self-Hosting","Deploy Owlat on your own infrastructure with Docker Compose. Complete guide from first boot to production.",{"path":329,"title":330,"description":331},"\u002Fdeveloper\u002Fself-hosting-config","Self-Hosting Configuration","Complete reference for Docker environment variables, Convex backend variables, service topology, and volume persistence.",{"path":333,"title":334,"description":335},"\u002Fdeveloper\u002Fself-hosting-dns-email","DNS & Email Setup","Configure DNS records, DKIM signing, SPF, DMARC, and bounce handling for reliable email delivery.",{"path":337,"title":338,"description":339},"\u002Fdeveloper\u002Fself-hosting-production","Production Deployment","Secure your self-hosted Owlat instance with TLS, firewall rules, backups, and monitoring.",{"path":341,"title":342,"description":343},"\u002Fdeveloper\u002Fself-hosting-maintenance","Maintenance & Updates","Keep your self-hosted Owlat instance up to date, manage backups, scale performance, and troubleshoot common issues.",{"path":345,"title":346,"description":347},"\u002Fdeveloper\u002Fself-hosting-desktop","Desktop Installer","Install Owlat on a bare Linux VPS straight from the desktop app over SSH — no terminal — with a live, animated provisioning timeline.",{"path":349,"title":350,"description":351},"\u002Fdeveloper\u002Fsetup-cli","Setup CLI & Installer","Operator reference for the Owlat self-host tooling: the install.sh one-liner, the owlat-setup CLI, the convex-deploy flow, and admin bootstrap.",{"path":353,"title":354,"description":355},"\u002Fdeveloper\u002Fconvex","Convex Backend","Owlat uses Convex as its serverless backend, providing real-time subscriptions, ACID transactions, and TypeScript-first development.",{"path":357,"title":230,"description":358},"\u002Fdeveloper\u002Fauthentication","Owlat uses BetterAuth with the Convex adapter for authentication and organization (team) management.",{"path":360,"title":361,"description":362},"\u002Fdeveloper\u002Femail-system","Email System","Owlat's email system consists of a visual editor, template management, and multi-provider sending infrastructure.",{"path":364,"title":365,"description":366},"\u002Fdeveloper\u002Femail-renderer","Email Renderer","The @owlat\u002Femail-renderer package converts editor JSON blocks into production-ready HTML emails with cross-client compatibility, CSS inlining, dark mode, and Outlook VML fallbacks.",{"path":368,"title":369,"description":370},"\u002Fdeveloper\u002Fenvironment-variables","Environment Variables","Reference for every environment variable Owlat reads across the Convex backend, web app, MTA, IMAP server, and mail-sync worker.",{"path":372,"title":373,"description":374},"\u002Fdeveloper\u002Fcomponents","Component Library","Reference for the reusable, auto-imported Vue UI components shipped in the packages\u002Fui layer.",{"path":376,"title":377,"description":378},"\u002Fdeveloper\u002Fdecisions","Architectural Decision Records","The architectural decision records for the Owlat project, each capturing the context, the decision, and the trade-offs involved.",{"path":380,"title":381,"description":382},"\u002Fdeveloper\u002Fdecisions\u002F009-model-routing","ADR-009: Task-Based Model Routing","Why Owlat supports per-task LLM model selection instead of using a single model for all pipeline steps.",{"path":384,"title":385,"description":386},"\u002Fdeveloper\u002Fdecisions\u002F010-listing-engine","ADR-010: Listing Engine","Why Owlat replaced four incompatible list-query contracts with one generic listing engine driven by per-entity descriptors.",{"path":388,"title":389,"description":390},"\u002Fdeveloper\u002Fdecisions\u002F001-custom-email-renderer","ADR-001: Custom Email Renderer Over MJML","Why Owlat built a custom table-based HTML email renderer instead of using MJML, gaining full control over VML, dark mode, and per-client rendering.",{"path":392,"title":393,"description":394},"\u002Fdeveloper\u002Fdecisions\u002F002-convex-backend","ADR-002: Convex as Backend","Why Owlat chose Convex over PostgreSQL and Firebase for real-time reactivity, co-located TypeScript logic, and zero-config scaling.",{"path":396,"title":397,"description":398},"\u002Fdeveloper\u002Fdecisions\u002F003-notion-like-builder","ADR-003: Notion-like Email Builder","Why Owlat replaced the traditional 3-panel email editor with a Notion-like single-column canvas for inline WYSIWYG editing.",{"path":400,"title":401,"description":402},"\u002Fdeveloper\u002Fdecisions\u002F004-monorepo-bun-workspaces","ADR-004: Monorepo with Bun Workspaces","Why Owlat uses a monorepo with Bun workspaces and Turborepo for fast installs, atomic cross-package changes, and cached CI.",{"path":404,"title":405,"description":406},"\u002Fdeveloper\u002Fdecisions\u002F005-custom-mta","ADR-005: Custom MTA","Why Owlat built a custom Mail Transfer Agent instead of relying solely on third-party email providers.",{"path":408,"title":409,"description":410},"\u002Fdeveloper\u002Fdecisions\u002F006-self-hosted-convex","ADR-006: Self-Hosted Convex","Why Owlat uses the open-source Convex backend for self-hosting instead of migrating to a different database.",{"path":412,"title":413,"description":414},"\u002Fdeveloper\u002Fdecisions\u002F007-pluggable-llm","ADR-007: Pluggable LLM Provider","Why Owlat uses the Vercel AI SDK with a provider abstraction layer instead of hardcoding a single LLM vendor.",{"path":416,"title":417,"description":418},"\u002Fdeveloper\u002Fdecisions\u002F008-process-architecture","ADR-008: Agent Process Architecture","Why Owlat processes inbound messages with a self-scheduling step walker plus a lifecycle coordinator instead of one sequential function.",{"path":420,"title":421,"description":422},"\u002Fexamples","Examples","Copy-pasteable integration patterns for common Owlat use cases.",{"path":424,"title":425,"description":426},"\u002Fexamples\u002Fwelcome-email","Welcome Email","Send a personalized welcome email when a new user signs up.",{"path":428,"title":429,"description":430},"\u002Fexamples\u002Fbilling-email","Billing Email","Send a billing receipt with an invoice PDF attached after a successful payment.",{"path":432,"title":433,"description":434},"\u002Fexamples\u002Fevent-automation","Event Automation","Trigger automations with custom events for trial lifecycle, feature adoption, and more.",{"path":436,"title":437,"description":438},"\u002Fexamples\u002Fcontact-sync","Contact Sync","Sync contacts from your database to Owlat using upsert patterns and bulk operations.",{"path":440,"title":441,"description":442},"\u002Fexamples\u002Fwebhook-handler","Webhook Handler","Handle Owlat delivery webhooks with signature verification and event routing.",{"path":444,"title":445,"description":446},"\u002Fexamples\u002Fmultilingual-email","Multilingual Email","Send emails in the recipient's preferred language using template translations.",{"path":448,"title":449,"description":450},"\u002Fvision","Vision","Where Owlat is heading — from email platform to unified communication intelligence powered by AI agents.",{"path":452,"title":453,"description":454},"\u002Fvision\u002Fself-hosting","Self-Hosting Architecture","How Owlat runs as a fully self-hosted stack using Docker Compose — open-source Convex backend, custom MTA, and a pluggable LLM provider.",{"path":456,"title":457,"description":458},"\u002Fvision\u002Fagent-pipeline","Agent Pipeline","Technical architecture for the inbound email agent pipeline — step modules, the walker, security scanning, threading, and human review.",{"path":460,"title":106,"description":461},"\u002Fvision\u002Fknowledge-graph","Technical architecture for Owlat's typed knowledge storage — how organizational knowledge is stored, searched, decayed, and maintained.",{"path":463,"title":464,"description":465},"\u002Fvision\u002Fmulti-channel","Multi-Channel & CRM","Technical architecture for channel adapters, unified messaging, contact identity unification, and the CRM hub.",{"path":467,"title":468,"description":469},"\u002Fvision\u002Ffile-system","Semantic File System","Technical architecture for Owlat's semantic file storage — version tracking with provenance today, plus the planned embedding-based retrieval and auto-tagging layer.",{"path":471,"title":472,"description":473},"\u002Fvision\u002Fdesktop-app","Desktop App & Advanced Agents","Architecture of the Owlat desktop shell, visualization agent, adaptive dashboard, agent health, graduated autonomy, and coding agents.",{"path":475,"title":476,"description":477},"\u002Fvision\u002Froadmap","Roadmap","What's planned next for Owlat — the documented-but-unbuilt pieces still being wired, and the enhancements on our radar.",{"id":479,"title":182,"body":480,"description":183,"extension":875,"meta":876,"navigation":877,"path":181,"seo":878,"stem":879,"__hash__":880},"content\u002F1.guide\u002F49.sealed-mail.md",{"type":481,"value":482,"toc":861},"minimark",[483,492,499,530,535,546,553,557,564,567,639,642,661,665,668,673,676,715,722,726,729,770,773,776,787,796,803,807,814,838,842],[484,485,486,487,491],"p",{},"Sealed Mail encrypts your personal (Postbox) mail ",[488,489,490],"strong",{},"end-to-end"," when the people you write to can receive it — so the message body and its real subject are unreadable to anyone in between, including the servers that relay it. When a message can't be sealed, Owlat tells you plainly and sends it normally rather than pretending it was protected.",[484,493,494,495,498],{},"Sealing applies only to ",[488,496,497],{},"Postbox"," — everyday person-to-person email. Campaigns and transactional mail are never sealed; they stay plaintext by design.",[500,501,503],"callout",{"title":70,"type":502},"info",[484,504,505,506,509,510,513,514,517,518,522,523,517,526,529],{},"Sealed Mail ships ",[488,507,508],{},"on by default"," on any workspace that runs Postbox. It's controlled by two flags in ",[488,511,512],{},"Settings → Features",": ",[488,515,516],{},"Sender authenticity badges"," (",[519,520,521],"code",{},"senderAuthBadges",") and ",[488,524,525],{},"Sealed Mail (end-to-end encryption)",[519,527,528],{},"sealedMail","). Both require personal mail (Postbox) to be enabled — on a deployment without Postbox they simply stay off.",[531,532,534],"h2",{"id":533},"what-sealing-means","What sealing means",[484,536,537,538,541,542,545],{},"When a message is sealed, Owlat encrypts the ",[488,539,540],{},"entire original message"," — including its real ",[519,543,544],{},"Subject:"," line and body — before it leaves your workspace, and signs it with your address's key. Only the recipient's Owlat workspace holds a key that can open it.",[484,547,548,549,552],{},"Because the real subject is encrypted too, the message that travels on the wire carries a placeholder subject of just ",[519,550,551],{},"..."," and only the routing headers a mail server actually needs to deliver it. Your recipient sees the true subject once their workspace opens the message.",[531,554,556],{"id":555},"when-mail-auto-seals-versus-sends-in-the-clear","When mail auto-seals versus sends in the clear",[484,558,559,560,563],{},"Owlat can only seal a message when ",[488,561,562],{},"every"," recipient has a usable sealing key that it has discovered and trusts. This is all-or-nothing: if even one recipient can't receive sealed mail, the whole message is sent normally (a partially-sealed message would leak to the recipient who has no key).",[484,565,566],{},"The composer shows a lock indicator that tells you exactly what will happen before you send:",[568,569,570,586],"table",{},[571,572,573],"thead",{},[574,575,576,580,583],"tr",{},[577,578,579],"th",{},"Lock state",[577,581,582],{},"What it says",[577,584,585],{},"What happens",[587,588,589,603,622],"tbody",{},[574,590,591,597,600],{},[592,593,594],"td",{},[488,595,596],{},"Will seal",[592,598,599],{},"\"This message will be sealed\"",[592,601,602],{},"Everyone you're writing to can receive sealed mail, so Owlat encrypts the message before it leaves your workspace.",[574,604,605,610,613],{},[592,606,607],{},[488,608,609],{},"Key changed",[592,611,612],{},"\"A recipient's key changed\"",[592,614,615,616,621],{},"A recipient's key changed since you last sealed to them. Owlat won't seal until you review and confirm the new key (see ",[617,618,620],"a",{"href":619},"#key-change-alerts","Key-change alerts",").",[574,623,624,629,632],{},[592,625,626],{},[488,627,628],{},"Won't seal",[592,630,631],{},"\"This message won't be sealed\"",[592,633,634,635,638],{},"The message will be sent normally. The detail line explains why, and a distinct ",[488,636,637],{},"Send unsealed"," control appears — sending in the clear is always an explicit choice, never a silent fallback.",[484,640,641],{},"The exact \"won't seal\" reasons you may see, in plain language:",[643,644,645,649,652,655,658],"ul",{},[646,647,648],"li",{},"\"Some of your recipients can't receive sealed mail yet, so this message will be sent normally.\"",[646,650,651],{},"\"Sealed mail is turned off for your workspace, so this message will be sent normally.\"",[646,653,654],{},"\"Sealed mail is available for these recipients, but your workspace is set to ask before sealing, so this message will be sent normally.\"",[646,656,657],{},"\"This address doesn't have a sealing key yet, so this message will be sent normally.\"",[646,659,660],{},"\"Add a recipient to see whether this message can be sealed.\"",[531,662,664],{"id":663},"reading-the-badges-on-a-message","Reading the badges on a message",[484,666,667],{},"Sealed Mail surfaces two independent, honest badges on a message you receive. Each one only ever claims what was actually checked — an absent badge means Owlat couldn't confirm something, never that it silently passed.",[669,670,672],"h3",{"id":671},"the-sealed-badge-encryption","The Sealed badge (encryption)",[484,674,675],{},"Shows whether the message arrived encrypted, and whether its signature checked out:",[643,677,678,692,701],{},[646,679,680,683,684,687,688],{},[488,681,682],{},"\"Sealed — sender verified\""," — the message was encrypted end-to-end ",[488,685,686],{},"and"," Owlat confirmed it was really signed by the sender. Detail: ",[689,690,691],"em",{},"\"This message was encrypted end-to-end, and we confirmed it was really signed by the sender.\"",[646,693,694,697,698],{},[488,695,696],{},"\"Sealed — sender not verified\""," — the message was encrypted end-to-end, but Owlat couldn't confirm who signed it. Detail: ",[689,699,700],{},"\"This message was encrypted end-to-end, but we couldn't confirm who signed it.\"",[646,702,703,706,707,710,711,714],{},[488,704,705],{},"\"Encrypted — can't decrypt\""," — the message was encrypted just for its recipient, and this workspace holds no key that can open it. Detail: ",[689,708,709],{},"\"This message was encrypted just for its recipient, and Owlat doesn't hold a key that can open it.\""," This usually means the instance was rebuilt without importing the ",[617,712,713],{"href":189},"recovery kit",".",[484,716,717,718,721],{},"A plaintext message shows ",[488,719,720],{},"no"," Sealed badge at all.",[669,723,725],{"id":724},"the-sender-authenticity-badge","The sender-authenticity badge",[484,727,728],{},"Independently of encryption, Owlat checks whether a message's stated sender is authorized to send for its domain (using SPF, DKIM and DMARC), and renders one honest state:",[643,730,731,740,746,755,761],{},[646,732,733,736,737],{},[488,734,735],{},"\"Verified sender\""," — ",[689,738,739],{},"\"We confirmed this message really was sent for {domain}.\"",[646,741,742,745],{},[488,743,744],{},"\"Verified via forwarder\""," — a forwarding service you trust confirmed the message really was sent for the domain before passing it on (normal for mailing lists, whose own checks break in forwarding).",[646,747,748,736,751,754],{},[488,749,750],{},"\"Sender not authorized\"",[689,752,753],{},"\"Sent by {other-domain}, which is not authorized to send for {domain}.\""," The classic impersonation shape — treat it with suspicion.",[646,756,757,760],{},[488,758,759],{},"\"Failed sender check\""," — the message claims to be from a domain but failed that domain's authentication checks. Treat it as suspicious.",[646,762,763,736,766,769],{},[488,764,765],{},"\"Unverified sender\"",[689,767,768],{},"\"We couldn't confirm this message really came from {domain}.\""," Owlat simply doesn't know; it never upgrades \"don't know\" to \"verified\".",[484,771,772],{},"The badge's expandable detail may add plain-language warnings when something looks off — for example that the sender's domain uses look-alike characters, that replies would go to a different domain, or that this is the first message from this address.",[531,774,620],{"id":775},"key-change-alerts",[484,777,778,779,782,783,786],{},"Owlat pins each recipient's sealing key the first time it seals to them. If that key later changes ",[488,780,781],{},"without"," a signed statement from the recipient's workspace, Owlat keeps the old pin and ",[488,784,785],{},"stops sealing"," to that person until you confirm the change — it never silently adopts a new key. You'll see a banner in the thread:",[788,789,790],"blockquote",{},[484,791,792,795],{},[488,793,794],{},"This person's sealing key changed"," — The key Owlat uses to seal mail to {address} is different from the one you trusted before. Until you confirm the new key, messages to them are sent normally instead of sealed. Only accept it if you were expecting this change.",[484,797,798,799,802],{},"Accepting the new key requires an owner or admin (it re-pins the key for the whole workspace). If you're not an admin, the banner asks you to have one review it: ",[689,800,801],{},"\"Ask a workspace admin to review this key change before sealed mail resumes to this person.\""," Only accept a key change you were actually expecting — an unexpected change can be a sign someone is trying to intercept your mail.",[531,804,806],{"id":805},"the-workspace-sealing-policy","The workspace sealing policy",[484,808,809,810,813],{},"Owners and admins choose how eagerly the workspace seals, in ",[488,811,812],{},"Settings → Sealed Mail",". The choice (locked decision D2) is one of:",[643,815,816,826,832],{},[646,817,818,821,822,825],{},[488,819,820],{},"Seal automatically"," ",[689,823,824],{},"(recommended, the default)"," — when everyone you're writing to can receive sealed mail, Owlat encrypts the message before it leaves.",[646,827,828,831],{},[488,829,830],{},"Keep available, but never automatic"," — Owlat keeps discovering keys and shows when a message could be sealed, but never seals on its own; messages are sent normally until you switch back to automatic.",[646,833,834,837],{},[488,835,836],{},"Never seal"," — all Postbox mail is sent normally, even when a recipient could receive it sealed.",[531,839,841],{"id":840},"related","Related",[643,843,844,850,855],{},[646,845,846,849],{},[617,847,848],{"href":189},"Sealed Mail recovery kit"," — how to keep the keys that open your sealed history, and what happens if they're lost.",[646,851,852,854],{},[617,853,318],{"href":317}," — the operator-side transport hardening (MTA-STS, DANE, TLS reporting) that protects mail on the wire.",[646,856,857,860],{},[617,858,859],{"href":313},"Sealed Mail at Rest"," — how stored message bodies are sealed in the database.",{"title":862,"searchDepth":863,"depth":863,"links":864},"",2,[865,866,867,872,873,874],{"id":533,"depth":863,"text":534},{"id":555,"depth":863,"text":556},{"id":663,"depth":863,"text":664,"children":868},[869,871],{"id":671,"depth":870,"text":672},3,{"id":724,"depth":870,"text":725},{"id":775,"depth":863,"text":620},{"id":805,"depth":863,"text":806},{"id":840,"depth":863,"text":841},"md",{},true,{"title":182,"description":183},"1.guide\u002F49.sealed-mail","JnJG86CQuupXjAiKuYmyGqguH_vQNL07S1SoxqPFAm8",[882,884],{"title":178,"path":177,"stem":883,"children":-1},"1.guide\u002F48.connect-your-ai",{"title":186,"path":185,"stem":885,"children":-1},"1.guide\u002F5.saved-blocks",1784224023433]