jcoffey-dev d9a6db025b
ci / fork-checks (pull_request) Successful in 48s
ci / build (pull_request) Successful in 9m4s
Explain this: the local model reads delivery failures, verdicts, logs and settings
A new method, inbuxa:Explanation/set, asks the node's local model for a
short plain-words reading of one thing an administrator is looking at:
a failed recipient in the queue, a Classify verdict, a log line or trace
event, or one setting with its saved value. The server builds the prompt
itself from stored data and the registry schema, never from text the
console sends, and grounds SMTP replies in RFC 3463 and RFC 5321.

What the model is never shown: secrets (including ones nested inside a
setting, like an AI model's HTTP auth), raw protocol events, and the
contents of any other event. A tag name that doesn't have a tag's shape is
refused before a model is asked.

Calls share the AI gate with spam classification, but mail always keeps
its slot, and Explain has its own hourly count per account and its own
on/off switch in inbuxa:AiLimits. The permission is sysAiExplain,
superuser only; tenant administrators can't use it. The session carries
an aiExplain flag so a console knows when to offer the button.

An install whose roles were stored before the permission existed gets it
added once, at start-up, to the roles that are administrators' alone,
not the User role their defaults share with every account. An operator
who removes it later isn't overruled.

Tests: unit tests in inbuxa-features and jmap, and ai_explain_tests
(run with --ignored) covering the acceptance tests and the upgrade.
2026-09-26 00:52:51 -07:00
2026-09-18 10:21:56 -07:00

inbuxa

A complete mail and collaboration server, every feature included, under the AGPL


inbuxa is a mail and collaboration server: JMAP, IMAP, POP3, SMTP, CalDAV, CardDAV and WebDAV, in one Rust binary, with ihasmail as its web front end. It is a fork of Stalwart. Project site: inbuxa.org. Documentation: docs.inbuxa.org.

Stalwart ships some features only in a paid Enterprise Edition: multi-tenancy, masked email, undelete and others. inbuxa ships everything to everybody under the AGPL-3.0, rebuilding those features independently and without using any of Stalwart's Enterprise code.

What's different from Stalwart

  • Every feature, one edition. No license key, no edition checks, no upsell. See docs/spec/SPEC.md §4 for the features being rebuilt, and docs/spec/features/ for each one's specification.
  • Webmail and administration by ihasmail, as a separate service that can run beside the server or elsewhere. Stalwart's own web interface is removed, so there's no web front end on the mail host.
  • Clean-room rebuilds. Enterprise-only code is stripped from every upstream release before it's imported. The rebuilt features are written from specifications that use only public sources (docs/spec/SPEC.md §3).

How the fork is kept

Upstream releases arrive as stripped snapshots, never with upstream's git history, which contains Enterprise code. tools/fork/strip.py builds each snapshot on top of upstream's own ossify.py, then verifies it independently. The report for every import is in docs/fork/strip-reports/. See docs/spec/SPEC.md §2.

Building

cargo build --release -p inbuxa          # the binary is target/release/inbuxa
docker build -t inbuxa .                 # or the container image

Settings are read from INBUXA_* environment variables. An existing Stalwart install's STALWART_* variables aren't read: the server stops at startup and names each one to rename. New installs keep their data in /var/lib/inbuxa and logs in /var/log/inbuxa. Existing installs keep the paths their configuration already names, so none of their data moves.

License and credits

inbuxa is free software under the GNU Affero General Public License, version 3.

It is a fork of Stalwart, copyright © Stalwart Labs LLC, modified by Coffey Labs in 2026. Upstream's copyright notices are kept on every file they cover, and every upstream file this fork changed says so in its header, under the notice it came with. Stalwart's files are dual-licensed AGPL-3.0-only or Stalwart's Enterprise License, and inbuxa takes them under the AGPL-3.0 only. A few of those files also carry code from other projects under MIT or BSD licenses, which stays under those licenses; THIRD-PARTY.md lists it with its notices. "Stalwart" is Stalwart Labs' name. inbuxa isn't affiliated with or endorsed by Stalwart Labs.

The inbuxa mark reuses ihasmail's cat-and-envelope artwork.

S
Description
A complete mail and collaboration server in one Rust binary: JMAP, IMAP, POP3, SMTP, CalDAV, CardDAV and WebDAV, every feature included, under the AGPL.
Readme
26 MiB
2026-10-01 02:09:23 +00:00
Languages
Rust 97%
Python 2.2%
HTML 0.7%