Checking who really sent an email
Anyone can type any name in the "From" line of an email. So the box never trusts the name. It checks the real address and a stamp the sender's mail provider adds, which a faker can't copy.
Where you see it
Mostly you don't. The one place it shows is the email-a-task door (an address the owner can email to hand the box a job). If a message there fails the check, it gets the label unverified, and the sender gets one fixed-text notice. That notice goes out at most once an hour.
Not every route asks for proof. A route that acts because of who sent the mail (a sign-up service, a known reply) must pass the check. An agent's own address takes mail from anyone. That mail is not trusted. The agent reads it only through the email quarantine.
Two ways to fake a sender
The display name. An email has two parts in its From line: a name, and the real address. The name is just text. Someone once sent mail whose name read like "a library's Support," but the real address was a stranger's. A lazy rule that checked "does the From line mention the library?" would have trusted it. The box's rules now match the real, parsed address, never the name, because of that email.
The address itself. A clever faker can even put someone else's address in the From line. That's where DMARC comes in.
What DMARC is, in plain words
DMARC (a sender-proof stamp) works like this. Each domain publishes a list of which mail providers may send for it. When mail arrives, the receiving side checks that the mail really came through one of those providers. Then it writes the result into the email's headers: dmarc=pass or not. A faker sending from their own server can't produce a pass for someone else's domain.
What happens, step by step
- An email arrives that claims to be from a trusted sender.
- The router reads the real address, not the display name.
- For routes that need proof, the router reads the first result stamp in the headers. Later stamps can be copied in by forwarding, so they don't count.
- That stamp must say
dmarc=passfor the exact domain in the From address. If not, the email is not trusted. - The email-a-task door is stricter still. The address must be one of the owner's own. DMARC must pass. The email must have exactly one From line. And the first stamp must come from the box's own incoming mail service, with a single clean pass.
- Mail that fails any of these gets no AI run at all. It is labeled
unverifiedand logged without ever printing its subject. The sender gets one fixed notice.
What powers it
| Part | What it does |
|---|---|
email_router.py | Matches real addresses and checks DMARC before waking an agent. |
email-routes.json | The list of routes and which ones need proof. |
watcher.py | The email-a-task door. Runs verify_sender before anything else. |
| The first result stamp | The mail provider's record of whether DMARC passed. |
Why it works this way
Most of the safety design splits the reader from the actor. See the email quarantine. But the email-a-task door can't work that way. Its whole job is to do what an email says, because the owner is the one writing it. So the reader and the actor are the same thing there.
When you can't split them, you have to be sure who is talking. That is why this door has the strictest sender checks in the system. If the check fails, no AI ever reads the email, so there is nothing to trick.
A pass proves the domain's mail provider sent it. It doesn't prove which person at that domain pressed send. That is a real gap, and Known limits says so.
Connected to
- Prompt injection and the email quarantine: how everyone else's mail is handled.
- Tasks from your phone: the owner's ways to hand the box a job.
- How an agent wakes: new mail is one of the things that wakes an agent.
- Known limits: the router does not check DKIM.