Design preview · no live service action

Secure by default

Mail credentials stay server-side

The planned browser boundary uses only an opaque application session. Mailbox, SMTP, Mailcow and identity-provider secrets are designed to remain within reviewed server-side services.