
Design preview · no live service action
Secure by default
Mail credentials stay server-side
The planned browser boundary uses only an opaque application session. Mailbox, SMTP, Mailcow and identity-provider secrets are designed to remain within reviewed server-side services.