Case study
How Mailroom was built
Mailroom is a free email app for Mac. Anton wrote the brief, from the sync rules to the security model, and built it with Claude Code in a day, one tested milestone at a time.
What it does
One inbox for every IMAP account, with Gmail-style conversations and shortcuts, search, tags, Undo Send, and changes made offline that go out in order. A calendar and contacts sync over CalDAV and CardDAV. AI summarizes, translates, and drafts replies only when asked.
How it works
YouThe windowReact in a sandbox, no system access
macOSMain processKeychain, notifications, and a check on every message
Mail serversSync workerIMAP, SMTP, CalDAV, and CardDAV
SQLCipherMail, calendar, and contacts, encrypted with a key in the Keychain
A release
- A version tag starts a build on GitHub's Mac runners
- It's signed with the Developer ID, notarized by Apple, and checked
- Installed copies download it from the website and check the signature
- Three processes. The window is React in a sandbox with no access to the system. The main process handles the Keychain, notifications, and menus, and checks every message from the window against a schema. A sync worker in its own process does all the IMAP, SMTP, CalDAV, and database work.
- Sync: two IMAP connections per account, one waiting for new mail and one for fetching and actions. Changes show at once, wait out an undo window, and replay in order after time offline.
- Storage: SQLite encrypted with SQLCipher, its key kept in the macOS Keychain, with a full-text index for search.
- Email is treated as hostile: cleaned with DOMPurify and shown in a sandboxed frame with no scripts, with remote images blocked until allowed.
- Releases: GitHub's Mac runners sign each version with Anton's Developer ID, and Apple notarizes it. The website, a Cloudflare Worker, serves downloads and update checks from R2, and installed copies update themselves.
Decisions that shaped it
- No Mailroom account and no Mailroom server. The Mac talks straight to the mail provider.
- Play well with other devices. Flags, folders, drafts, and tags live on the server, and Mailroom never sends a bare EXPUNGE that could delete another app's mail.
- Keep secrets on the Mac. Passwords and sign-in tokens are encrypted with the Keychain, and Google, Microsoft, and Yahoo tokens only go to their own mail servers.
- AI only on a click, with the model of your choice, including one running locally.
- The signing key never touches a laptop. It lives in a password manager and the build's secrets.
How it came together
- October 3, 2026: the brief, then a plan with the folder structure and database schema, approved before any code.
- October 4, overnight and morning: the app shell, read-only sync, actions with undo and push, compose and send, and tags and search, each tested against mail servers running in Docker.
- October 4, afternoon: the calendar, testing on a real Purelymail account, the first installable build, then print, translation, summaries, invitations, and contacts.
- October 4, evening: sign-in with Google, Microsoft, and Yahoo, settings detection, appearance settings, Developer ID signing and notarization, a website with downloads, and automatic updates.
- Along the way: 263 unit tests, and 58 integration tests against Dovecot, Mailpit, and Radicale.
Where it is now
Live at mailroom.anatolilabs.com, free for macOS 13 or later on Apple silicon and Intel.