InboxQ
Tidy your inbox once in Quox, and see it stay tidy in your normal mail client.
Overview
Most inbox tools are another overlay: a second place to check, sitting on top of a mailbox that itself stays exactly as messy as it always was. InboxQ is built the other way round. It connects read-only to a real IMAP mailbox, classifies and learns from what it sees, and then (when you turn it on) physically moves mail into real folders on the server.
The tidiness is not a Quox-only view, it shows up in Apple Mail, webmail, or whatever client you already use. Quox is the classification, training, and blocking brain. It is not another inbox to check.
How it works
InboxQ works in three steps:
- Connect, read-only. InboxQ opens the mailbox with IMAP
PEEKfetches. Nothing on the server changes on connect: no flags are set, no mail moves, no folders are created until you explicitly ask for that. - Classify into zones. Every message is scored into one of four zones: Focus (the important stuff), FYI, Auto (routine, low-priority), and Screened (likely unwanted). Classification is deterministic by default (see below).
- File into real folders (optional). When physical filing is turned on, InboxQ creates one nested parent folder,
InboxQ/, and moves mail under it:INBOXstays as Focus (IMAP's reserved INBOX cannot be renamed, and it is the one place you already look first), whileInboxQ/FYI,InboxQ/Auto,InboxQ/Screened, andInboxQ/Unsure to checkhold everything else. Deleting theInboxQ/parent is a full, reversible undo.
The classifier
The default classifier is deterministic: a set of rules and signal weights, not an LLM call. That means classification costs nothing and calls no model, by default, for every message. This is a real differentiator, not a marketing rounding: the code path short-circuits before any provider call unless you have explicitly selected one.
For messages the deterministic classifier can't confidently place, you can optionally select a model to break the tie, on a budget you control. This is a beta path: the picker and setting exist and work, but it has been lightly driven compared to the deterministic path.
Rules engine
Beyond the classifier, you can write explicit rules per account: match on sender address, domain, TLD, display name, or subject, and take an action (move to a folder, screen, or block). Rules apply on every sync. You can preview what a rule would do to your existing mail before applying it, so a new rule never surprises you on the next sync.
This is also where pattern spam gets handled. Individual blocked addresses are whack-a-mole (a spammer just registers a new one), but a display-name rule or a domain/TLD rule catches the pattern instead of the instance.
Blocking and reputation
Blocking a sender teaches InboxQ to screen future mail from that address. It is reputation learning inside InboxQ: the next message from a blocked sender is automatically routed to Screened (or straight to Junk for an explicit block) without you re-deciding each time.
Honest limit: today, "block" is Quox-side screening plus a best-effort move to the mailbox's Junk folder. It is not yet a real mail-server rule enforced by your provider. See "What's not built yet" below.
Physical filing
Physical filing is off by default. Turning it on is a deliberate, explicit step, not something that happens as a side effect of classification.
- Confidence-gated. Only high-confidence classifications move automatically (the default threshold is 0.75). Low-confidence mail is never silently misfiled or left mixed into INBOX: it goes to a dedicated
InboxQ/Unsure to checkfolder instead. - Dry-run preview. Before filing runs against your existing backlog, you get a preview: "on sync, these N messages will move to these folders," so you see the effect before anything actually moves.
- Screened is a review folder, not Junk. A false positive lands in
InboxQ/Screened, where a one-click "Confirm junk" moves it to your real Junk folder. Nothing you might actually want is silently discarded. - Overview surfaces the counts. The counts of Screened and Unsure-to-check mail are shown so nothing gets missed by sitting unopened in a folder you forgot exists.
Safety
- Read-only on connect. IMAP
PEEKfetches only; nothing moves until you explicitly enable filing. - Off by default, everywhere it matters. Sync mode defaults to Manual, folder scope defaults to INBOX only, and physical filing defaults to off.
- Org-scoped, multi-tenant isolation. Every account, message, rule, and folder is scoped to your org; a cross-org read attempt is refused.
- Cryptographically witnessed. InboxQ's actions (connect, sync, folder creation, proposal, proposal-applied, filing, and more) are AEE-witnessed as
quox.inbox.*evidence envelopes, the same evidence discipline the rest of the Quox platform uses. - Vault-stored credentials. Mailbox credentials are stored in the platform vault and require the
SECRETS_WRITEprofile; a service-key-only write is refused.
The inbox agent
You can ask an agent about your inbox from the sidebar: "what's in Screened right now," "block anything from this domain," "move these to FYI." Every action the agent proposes is approve-first: nothing executes on your say-so alone. A batch of proposed actions collapses into one frozen approval, so approving a bulk cleanup is one decision, not twenty.
Getting started
- Install InboxQ from the plugin store into your dashboard.
- Open the InboxQ tab and connect a mailbox (any IMAP account).
- Sync mode defaults to Manual, so nothing happens automatically until you trigger a sync or turn on scheduled sync yourself.
- Classification runs on sync. Physical filing stays off until you turn it on, and even then it only acts on high-confidence mail with a dry-run preview first.
What's not built yet
InboxQ is honest about maturity. These are planned, not shipped:
- Exportable blocklist (email, domain, IP as CSV). In development. The goal is to take your blocked-sender list to your own provider's filters, rather than relying on Quox-side screening alone.
- Provider-side auto-block (Sieve, Gmail filters, Microsoft 365). Planned. This would push a real server-side rule instead of Quox screening mail on sync. Deferred in favour of shipping the export path first.
- Compose, reply, and send with human-in-the-loop approval. Planned, deferred. InboxQ today sorts; you still read and reply in your own mail client.