MAD Mail - Build Status

Live mirror of what is wired vs stubbed vs pending. Last reviewed 2026-08-26 against the deployed Worker and a live probe of the mail host.

Done Stubbed (working with mock or fallback) Partial (env or DNS needed) TODO

Backend

ComponentStateNotes
Worker entry + routing Donesrc/index.ts with /healthz, /login, /callback, /api/*
MAD Login OAuth (PKCE) DoneClient registered; live /healthz reports mad_login_oauth:true and mad_login_secret_set:true
Session (HMAC cookie) Done14-day signed cookies; set SESSION_SIGNING_KEY for prod
IMAP proxy DoneReal IMAP4rev1 client in src/imap-core.ts over cloudflare:sockets. TLS 993 and STARTTLS 143, LOGIN and XOAUTH2, LIST with special-use roles, SELECT, UID SEARCH, paged ENVELOPE fetch with snippets, BODYSTRUCTURE walk, decoded text and HTML parts, attachments, flags, move, trash, APPEND, connection pooling. Mock data removed.
Mailbox reachability (madmonkey.media) BlockedNeeds Miguel. mail.madmonkey.media:993 serves a certificate that expired 2025-08-27 (CN www.partners.madmonkey.media). Workers always validate certificates and cannot be told to skip. Renew it in cPanel and the inbox fills with no code change. See the callout below.
SMTP send PartialDirect SMTP submission over TLS 465 in src/smtp-client.ts, per-connection credentials resolved from the mailbox store, Resend fallback when the origin will not accept. Blocked on the same certificate as IMAP. STARTTLS submission on 587 is not implemented and 587 is never probed as implicit TLS.
Triad classifier DoneRules engine: domain + subject + header hints
Signup / cPanel UAPI DoneLive /healthz reports cpanel_token_set:true. Email::add_pop runs for real; the onboarding wizard attaches the new mailbox in the same step.
Multi-account linking Donesrc/mailbox-store.ts stores up to 10 mailboxes per user in KV with the password sealed AES-256-GCM. /api/account/add live-tests the mailbox before writing anything and no route can read the credential back out. Onboarding wizard at /connect.html.
Bring-your-own IMAP onboarding DoneTwo explicit branches. A new @madmonkey.media mailbox asks for a name and a password and nothing else. An outside mailbox is autodiscovered from the address (src/provider-presets.ts), told which credential its provider actually accepts, and verified live before it is saved.
Gmail / Outlook unified inbox PartialIMAP AUTHENTICATE XOAUTH2 is implemented and the onboarding wizard routes Gmail and Microsoft addresses to the OAuth branch instead of showing a password box, because neither provider accepts a password over IMAP any more. Needs Miguel: a Google Cloud OAuth client and an Azure app registration, then GOOGLE_OAUTH_* and MICROSOFT_OAUTH_* as Worker secrets.
Folders, search, flags, move, trash Done/api/mail/folders, /api/mail/search, /api/mail/flag, /api/mail/move, /api/mail/trash, /api/mail/attachment/.... Trash is always an IMAP move into the Trash folder, never a purge.
Mailbox diagnostics Done/api/mail/diagnose probes every attached mailbox and names the real cause. An expired origin certificate reports as tls_certificate_invalid with the fix, not as a blank inbox.

Frontend

ComponentStateNotes
Three-pane webmail DoneFolder list / message list / preview with light theme default
Dark mode toggle DoneStored in localStorage, opt-in
Compose modal DoneReply / reply-all / forward prefill, Cmd+Enter to send
Triad tabs (Imbox / Reading Room / Receipts) DoneAccent-blue active state per dual-token system
On-device AI summarize Donetransformers.js lazy-loaded from CDN, distilbart-cnn-6-6 (~80 MB first run)
On-device AI smart reply StubbedStill a template reply. Next in line after the mail host certificate is renewed, since a reply model is worth nothing while the inbox cannot be read.
Honest empty-inbox states DoneThe list no longer shows a blank pane on failure. It distinguishes no mailbox connected, wrong password, host unreachable, and expired certificate, each with the next step.
Onboarding wizard Done/connect.html, light theme default, two-branch fork, live connection test, per-provider app-password guidance.
Signup page Done/signup.html with tier comparison + managed-service upsell
Login overlay DoneMAD Login button + magic-link placeholder

Infra / Handoff

ItemStateNotes
wrangler.toml DoneBoth KV namespace IDs are real and bound.
Webapp host Doneinbox.madmonkey.media is the webapp, pinned as a custom domain in wrangler.toml. mail.madmonkey.media is the InMotion mailserver and must not be repointed.
Mail host TLS certificate BlockedThe one thing standing between this build and a working inbox. Probed 2026-08-26: notAfter=Aug 27 17:42:49 2025 GMT, verify code 10, certificate has expired. The SAN already covers *.madmonkey.media, so no purchase is needed: run AutoSSL for the domain, or install the existing wildcard against the Exim and Dovecot service certificates in WHM.
OAuth client at accounts.madmonkey.media DoneRegistered; redirect is https://inbox.madmonkey.media/callback.
Resend domain verification DoneLive /healthz reports resend_set:true; used as the outbound fallback.
cPanel API token DonePromoted. Live /healthz reports cpanel_token_set:true.
Provider OAuth apps (Google, Microsoft) TODONeeds Miguel. Register a Google Cloud OAuth client and an Azure app, then push GOOGLE_OAUTH_CLIENT_ID, GOOGLE_OAUTH_CLIENT_SECRET, MICROSOFT_OAUTH_CLIENT_ID, MICROSOFT_OAUTH_CLIENT_SECRET. Until then, Gmail and Outlook mailboxes cannot be attached at all.
Correction to the old note on this page: "Cloudflare Workers cannot open raw outbound TCP" has not been true for a while. connect() from cloudflare:sockets opens real TCP, and MAD Inbox now speaks IMAP over it directly. No HTTP bridge and no Stalwart or Cyrus-JMAP deployment is required.
The one real blocker: mail.madmonkey.media serves a TLS certificate that expired on 2025-08-27, on every mail port (993, 465, 995) and on 443. Cloudflare's connect() always validates the certificate and offers no way to skip validation, so the Worker's TLS handshake fails before a single IMAP command is sent. That is why a successful sign-in still shows an empty inbox: the login is MAD Login OAuth and works fine, and the mailbox read is a separate connection that never completes.

It stayed invisible for a year because webmail. and cpanel. are Cloudflare-proxied and hand back a healthy edge certificate, while mail. has to be unproxied (IMAP and SMTP are not HTTP) and so exposes the origin's own expired certificate. Every uptime check was green the whole time.

Nothing needs to be bought and no code changes once it is fixed. Renew it, and the same build starts returning real mail.

Open MAD Inbox · Add a mailbox · Free signup · /healthz JSON

Latino-Owned Business | We Speak English & EspañolSe habla español.