Live mirror of what is wired vs stubbed vs pending. Last reviewed 2026-08-26 against the deployed Worker and a live probe of the mail host.
| Component | State | Notes |
|---|---|---|
| Worker entry + routing | Done | src/index.ts with /healthz, /login, /callback, /api/* |
| MAD Login OAuth (PKCE) | Done | Client registered; live /healthz reports mad_login_oauth:true and mad_login_secret_set:true |
| Session (HMAC cookie) | Done | 14-day signed cookies; set SESSION_SIGNING_KEY for prod |
| IMAP proxy | Done | Real IMAP4rev1 client in src/imap-core.ts over cloudflare:sockets. TLS 993 and STARTTLS 143, LOGIN and XOAUTH2, LIST with special-use roles, SELECT, UID SEARCH, paged ENVELOPE fetch with snippets, BODYSTRUCTURE walk, decoded text and HTML parts, attachments, flags, move, trash, APPEND, connection pooling. Mock data removed. |
| Mailbox reachability (madmonkey.media) | Blocked | Needs Miguel. mail.madmonkey.media:993 serves a certificate that expired 2025-08-27 (CN www.partners.madmonkey.media). Workers always validate certificates and cannot be told to skip. Renew it in cPanel and the inbox fills with no code change. See the callout below. |
| SMTP send | Partial | Direct SMTP submission over TLS 465 in src/smtp-client.ts, per-connection credentials resolved from the mailbox store, Resend fallback when the origin will not accept. Blocked on the same certificate as IMAP. STARTTLS submission on 587 is not implemented and 587 is never probed as implicit TLS. |
| Triad classifier | Done | Rules engine: domain + subject + header hints |
| Signup / cPanel UAPI | Done | Live /healthz reports cpanel_token_set:true. Email::add_pop runs for real; the onboarding wizard attaches the new mailbox in the same step. |
| Multi-account linking | Done | src/mailbox-store.ts stores up to 10 mailboxes per user in KV with the password sealed AES-256-GCM. /api/account/add live-tests the mailbox before writing anything and no route can read the credential back out. Onboarding wizard at /connect.html. |
| Bring-your-own IMAP onboarding | Done | Two explicit branches. A new @madmonkey.media mailbox asks for a name and a password and nothing else. An outside mailbox is autodiscovered from the address (src/provider-presets.ts), told which credential its provider actually accepts, and verified live before it is saved. |
| Gmail / Outlook unified inbox | Partial | IMAP AUTHENTICATE XOAUTH2 is implemented and the onboarding wizard routes Gmail and Microsoft addresses to the OAuth branch instead of showing a password box, because neither provider accepts a password over IMAP any more. Needs Miguel: a Google Cloud OAuth client and an Azure app registration, then GOOGLE_OAUTH_* and MICROSOFT_OAUTH_* as Worker secrets. |
| Folders, search, flags, move, trash | Done | /api/mail/folders, /api/mail/search, /api/mail/flag, /api/mail/move, /api/mail/trash, /api/mail/attachment/.... Trash is always an IMAP move into the Trash folder, never a purge. |
| Mailbox diagnostics | Done | /api/mail/diagnose probes every attached mailbox and names the real cause. An expired origin certificate reports as tls_certificate_invalid with the fix, not as a blank inbox. |
| Component | State | Notes |
|---|---|---|
| Three-pane webmail | Done | Folder list / message list / preview with light theme default |
| Dark mode toggle | Done | Stored in localStorage, opt-in |
| Compose modal | Done | Reply / reply-all / forward prefill, Cmd+Enter to send |
| Triad tabs (Imbox / Reading Room / Receipts) | Done | Accent-blue active state per dual-token system |
| On-device AI summarize | Done | transformers.js lazy-loaded from CDN, distilbart-cnn-6-6 (~80 MB first run) |
| On-device AI smart reply | Stubbed | Still a template reply. Next in line after the mail host certificate is renewed, since a reply model is worth nothing while the inbox cannot be read. |
| Honest empty-inbox states | Done | The list no longer shows a blank pane on failure. It distinguishes no mailbox connected, wrong password, host unreachable, and expired certificate, each with the next step. |
| Onboarding wizard | Done | /connect.html, light theme default, two-branch fork, live connection test, per-provider app-password guidance. |
| Signup page | Done | /signup.html with tier comparison + managed-service upsell |
| Login overlay | Done | MAD Login button + magic-link placeholder |
| Item | State | Notes |
|---|---|---|
| wrangler.toml | Done | Both KV namespace IDs are real and bound. |
| Webapp host | Done | inbox.madmonkey.media is the webapp, pinned as a custom domain in wrangler.toml. mail.madmonkey.media is the InMotion mailserver and must not be repointed. |
| Mail host TLS certificate | Blocked | The one thing standing between this build and a working inbox. Probed 2026-08-26: notAfter=Aug 27 17:42:49 2025 GMT, verify code 10, certificate has expired. The SAN already covers *.madmonkey.media, so no purchase is needed: run AutoSSL for the domain, or install the existing wildcard against the Exim and Dovecot service certificates in WHM. |
| OAuth client at accounts.madmonkey.media | Done | Registered; redirect is https://inbox.madmonkey.media/callback. |
| Resend domain verification | Done | Live /healthz reports resend_set:true; used as the outbound fallback. |
| cPanel API token | Done | Promoted. Live /healthz reports cpanel_token_set:true. |
| Provider OAuth apps (Google, Microsoft) | TODO | Needs Miguel. Register a Google Cloud OAuth client and an Azure app, then push GOOGLE_OAUTH_CLIENT_ID, GOOGLE_OAUTH_CLIENT_SECRET, MICROSOFT_OAUTH_CLIENT_ID, MICROSOFT_OAUTH_CLIENT_SECRET. Until then, Gmail and Outlook mailboxes cannot be attached at all. |
connect() from cloudflare:sockets opens real TCP, and MAD Inbox now speaks IMAP over it directly. No HTTP bridge and no Stalwart or Cyrus-JMAP deployment is required.
mail.madmonkey.media serves a TLS certificate that expired on 2025-08-27, on every mail port (993, 465, 995) and on 443. Cloudflare's connect() always validates the certificate and offers no way to skip validation, so the Worker's TLS handshake fails before a single IMAP command is sent. That is why a successful sign-in still shows an empty inbox: the login is MAD Login OAuth and works fine, and the mailbox read is a separate connection that never completes.
webmail. and cpanel. are Cloudflare-proxied and hand back a healthy edge certificate, while mail. has to be unproxied (IMAP and SMTP are not HTTP) and so exposes the origin's own expired certificate. Every uptime check was green the whole time.
Open MAD Inbox · Add a mailbox · Free signup · /healthz JSON