Added - Compose messages in floating windows: several drafts side by side, minimized or full-screen, restored after a reload and synced across tabs - Mobile UI for the native apps: bottom navigation bar, swipe actions on threads, pull-to-refresh, drawer, formatting toolbar above the keyboard, haptics - Publish mobile OTA bundles from Scalingo deploys - Persist the last active mailbox and select it on the next visit - Clean snippet of the latest message in the thread list (`FEATURE_THREAD_SNIPPET`, after `backfill_thread_snippets`) and on folded messages - Allow domain admins to export mailboxes #789 - Provisioning endpoint listing the DNS records of all domains #780 - ARC relay trust: `arc` inbound_auth mode and `arc_verdict` spam rule #763 - Support internationalized email addresses (IDNA domains, ASCII-folded local parts) #785 - Keep Gmail labels, Thunderbird read/starred flags and sent/archived/spam/trashed states through MBOX export and import - Setup guides for the authentication provider and the identity provider - IP allowlist for the Django admin URL in the frontend Caddy proxy - Smoke test for the frontend production image (make test-front-distroless) - IP allowlist for the Keycloak admin console and master realm in the Keycloak image (Caddy) #793 - Smoke test for the Keycloak production image (make test-keycloak-image) #793 Changed - Migrate the frontend from Cunningham to the `@gouvfr-lasuite/ui-components` and `@gouvfr-lasuite/ui-tokens` packages - Upgrade Capacitor to 8.5 and adopt the iOS UIScene life cycle - Upgrade jmap-email to 0.3.0: an unparseable inbound message is abandoned instead of retried, a compose error on send returns a 400, a stored message the parser now refuses is flagged unreadable - Force-lowercase mailbox addresses #785 - Route mailbox export tasks to the imports queue #805 - Redirect to the inbox when switching mailbox - Thread a reply by its In-Reply-To even when its subject was rewritten #765 - Exclude spam and trashed messages from folder stats by default - Stop fetching stats for the Sent folder - Page titles follow "Mailbox - Folder - App name" - Harden pymta with new settings and limits, and improve its env vars, documentation and logging #777 #783 - Bump keycloak to 26.7.4 and Alpine to 3.24 in the Keycloak image #776 #784 #798 - Bump Caddy to 2.11.4 and lprobe to v0.2.0 in the frontend image - Keycloak image: Keycloak listens on 127.0.0.1:8081, Caddy serves port 8080 - Keycloak image: proxy headers are fixed to xforwarded from Caddy, which sends X-Forwarded-Proto https Removed - The mta-out service: relay mode now needs an external `MTA_OUT_RELAY_HOST` #785 - Scalingo buildpack for Keycloak (src/keycloak/buildpack, Procfile, system.properties) Fixed - Fix a draft update / send race that could re-send an already delivered email, and keep the autosave out of the send window - Add the channel to messages sent through the submit API #794 - Accept more valid SPF records by implementing the full RFC #782 - Ignore whitespace in DKIM keys in the DNS check #778 - Select IMAP folders whose unquoted name carried extra spaces, and stop retrying unselectable folders - Give nameless attachments the same name in the UI, downloads and drafts - Keep only BlockNote-supported colors in pasted content, drop unsupported blocks and embed external images again - Resize the mail iframe with a resize observer (Safari, width changes, lazy-loaded images) - Stretch the thread sender on a narrow thread panel - Fix file uploads outside a secure context (`crypto.randomUUID` fallback) - Fallback for avatar colors on browsers without `color-mix()` support - Mobile: send mutations through CapacitorHttp with an explicit Origin so an HTTPS backend's CSRF check accepts them - Grant view-realm to the Keycloak service account, needed by the 2FA toggle - Run make test-keycloak against a freshly imported Keycloak realm - List only assignable users and current assignees in the quick assign picker Security - Turn the direct access grant off on the Keycloak rest-api client - Deny API actions that don't declare an access check by default - Check mailbox access for mailbox_id on message list and thread search - Rate-limit the image proxy, restrict it to ports 80 and 443 and mark its responses private - SSRF-check per-domain relays (internal ones need SSRF_ALLOWED_HOSTS) - Validate the MailDomain custom_settings schema - Restrict IMAP import ports (MESSAGES_IMPORT_IMAP_ALLOWED_PORTS) - Use only the Referer hostname in widget message subjects - Scope the DNS check endpoint through the admin queryset - Refuse MTA requests with a 401 instead of a 500 when `MDA_API_SECRET` is unset - Scope the flag endpoint draft cascade to editable messages and suspend personal API keys of deactivated users #804 - Harden email parsing against hostile mail (forged sender, smuggled recipients, quadratic regexes) through jmap-email 0.3.0, and bound the reply-unquoting regexes
Chat on Matrix - Documentation - Roadmap - Getting started - Reach out
Messages : Collaborative Inbox
Messages is the all-in-one collaborative inbox for La Suite territoriale.
Why use Messages ❓
Messages is a full communication platform enabling teams to collaborate on emails through shared or personal mailboxes.
It features a MTA based on Postfix, a custom MDA built on top of Django Rest Framework and a frontend using Vite, TanStack Router and BlockNote.js.
Familiar messaging features
- 📝 Receive, draft and send emails.
- 🧵 Smart threading
- 📎 Upload and download attachments. Also works with Drive!
- 📩 Import emails from MBOX or IMAP
- 🔎 Full-text search with advanced filters
- ⏳️ Asynchronous, pluggable email processing (antispam, antivirus, ...)
- 🤖 AI Summaries, AI message composer, AI auto-labelling
- 🎨 Embeddable widgets for feedback
Collaboration at the core
- 👥 Share any inbox with multiple users
- 🧶 Share threads with other users
- (soon) 🕶 Private messages between users
- (soon) 💎 Realtime text editing
- (soon) 👉 Assign threads to specific users
Based on standards
- 🔑 OpenID Connect for all user accounts. Plug any identity provider, including Keycloak.
- 📬 SMTP in and out.
- ❌ No POP3 or IMAP client support, by design. We're building for the future, not the (unsecure) past!
- ✅ JMAP-inspired data model. Full support could be added.
Self-host
- 🚀 Messages is designed to be installed on the cloud or on your own servers.
- 🛠️ Configuration through environment variables for most settings
Getting started 🔧
Prerequisite
To test Messages on your own machine, you only need a recent version of Docker and Docker Compose:
$ docker -v
Docker version 27.5.1, build 9f9e405
$ docker compose version
Docker Compose version v2.32.4
⚠️ You may need to run the following commands with
sudobut this can be avoided by assigning your user to thedockergroup.
Project bootstrap
The easiest way to start working on the project is to use GNU Make:
$ make bootstrap
This command builds all required containers, installs dependencies, performs
database migrations and compiles translations. Later it's a good idea to run
make update each time you are pulling code from the project repository to avoid
dependency-related or migration-related issues.
Your Docker services should now be up and running 🎉
You can access the project by going to http://localhost:8900.
You will be prompted to log in. The default credentials are:
email: user{1,2,3}@example.local
password: user{1,2,3}
This means you can use user1@example.local / user1 for instance and switch users later to test collaboration.
In your development workflow, the main commands you should use are:
# Stop all containers
$ make stop
# Start all containers, without full bootstrap
$ make start
# View all available commands
$ make help
Development Services
When running the project, the following services are available:
| Service | URL / Port | Description | Credentials |
|---|---|---|---|
| Frontend | http://localhost:8900 | Main Messages frontend | user1@example.local / user1 |
| Backend API | http://localhost:8901 | Django REST API and Admin | admin@admin.local / admin |
| Keycloak | http://localhost:8902 | Identity provider admin | admin / admin |
| Celery UI | http://localhost:8903 | Task queue monitoring | No auth required |
| Mailcatcher | http://localhost:8904 | Email testing interface | No auth required |
| MTA-in (SMTP) | 8910 | Incoming email server | No auth required |
| PostgreSQL | 8912 | Database server | user / pass |
| Redis | 8913 | Cache and message broker | No auth required |
| OpenSearch | 8914 | Search engine | No auth required |
| OpenSearch PA | 8915 | Performance analyzer | No auth required |
| SOCKS Proxy | 8916 | SOCKS5 proxy | user1 / pwd1 |
| Mailcatcher (SMTP) | 8917 | SMTP server | No auth required |
| MPA (Rspamd) | 8918 | Spam filtering service | password |
OpenAPI client
The frontend API client is generated with Orval. It consumes the OpenAPI schema generated from the backend through drf-spectacular.
The JSON OpenAPI schema is located in
src/backend/core/api/openapi.json.
To update the schema then the frontend API client, run:
$ make api-update
You can also generate the schema only with:
$ make api-update-back
And the frontend API client only with:
$ make api-update-front
Sending test emails 📨
There are a couple ways of testing the email infrastructure locally.
These examples use swaks, a simple command-line SMTP client.
# First, make sure services are running
make start
# Send a test message to the MTA-in, which will relay it to the Django MDA.
# The domain must belong to a MailDomain with oidc_autojoin=True if you want the mailbox created automatically.
# You can then read it on the frontend at http://localhost:8900/ (login as user1/user1) and reply to it there.
# The replies will then be sent to the mailcatcher on http://localhost:8904/
swaks --to=user1@example.local --server localhost:8910
# Send a test message to the mailcatcher, then read it on http://localhost:8904/
swaks --to=user1@example.local --server localhost:8917
# Send an outbound message through Messages itself, relayed to mailcatcher
make shell-back
MTA_OUT_MODE=relay MTA_OUT_RELAY_HOST=mailcatcher:1025 python manage.py send_mail --to=user1@example.local --subject="Test" --body="Hello World"
⚠️ Most residential ISPs block the outgoing port 25, so you might not be able to send emails to outside servers from your localhost. This is why the mailcatcher is so useful locally.
Feedback 🙋♂️🙋♀️
We'd love to hear your thoughts, and hear about your experiments, so come and say hi on Matrix.
License 📝
This work is released under the MIT License (see LICENSE).
While Messages is a public-driven initiative, our license choice is an invitation for private sector actors to use, sell and contribute to the project.
Contributing 🙌
This project is intended to be community-driven, so please, do not hesitate to get in touch if you have any question related to our implementation or design decisions.
We also have a public roadmap.
You can help us with translations on Crowdin.
If you intend to make pull requests, see CONTRIBUTING for guidelines.
Gov ❤️ open source
Messages is currently led by the French ANCT for use in La Suite territoriale.
We are welcoming new partners and contributors to join us in this effort! So please get in touch if you want to help!