Docs / Surfaces / Email

Email over IMAP

# any IMAP server that accepts a password: Gmail, Fastmail, self-hosted
export SAFEGRD_EMAIL_PASSWORD='your-app-password'
safegrd backup --email --email-host imap.example.com --email-user ops@example.com

Messages are fetched as RFC 5322 and streamed into the same sealed archive, folder structure intact. By default every folder is taken except spam and trash; --email-folders narrows that.

Use SAFEGRD_EMAIL_PASSWORD instead of --email-password. A password passed as a flag shows up in shell history and in the process list.

Providers

ProviderIMAP serverPassword
Gmail and Google Workspaceimap.gmail.com:993An app password, made at myaccount.google.com/apppasswords. It needs 2-Step Verification on the account, and a Workspace administrator can turn app passwords off.
Fastmailimap.fastmail.com:993An app password with IMAP access: Settings, Privacy & Security, Manage app passwords and access.
Microsoft 365 and Outlook.comNot supported yetMicrosoft turned off password sign-in for IMAP, app passwords included, and requires OAuth. SafeGrd signs in with a password, so it cannot back these mailboxes up until it speaks OAuth.
Self-hosted (Dovecot, Cyrus and others)Your server, port 993The mailbox's password. A certificate from an internal CA is covered below.

Gmail labels

Gmail shows each label as a folder, so one message can appear in several. SafeGrd backs up Gmail's All Mail folder alone and records each message's labels next to it, so every message is downloaded and stored once. Spam and Trash are left out.

This needs All Mail visible over IMAP: in Gmail's settings, open the Labels tab and tick Show in IMAP for All Mail. It is on by default. With it off, the backup falls back to one folder per label, stores a message once for each label it has, and prints a warning. A surface that lists its own folders backs up those folders as named.

Where the password comes from

An incomplete block, such as from: env with no name, is refused rather than guessed at.

A mailbox behind a private CA

For a self-hosted server whose certificate chains to an internal CA, give the surface ca_file: /etc/ssl/mail-ca.pem, a PEM bundle on the host. A one-off backup takes --email-ca-file, and SAFEGRD_EMAIL_CA_FILE covers every email surface on a host that names none. The bundle is added to the system roots, never used instead of them. There is no option to turn certificate checks off: the mailbox password crosses this connection.

Restoring a mailbox

safegrd restore --snapshot <id> --target-dir /restored/mailbox

A mailbox comes back as a directory per folder, each message a standard RFC 5322 .eml file that any mail client or forensic tool can open or import.

A Gmail restore comes back as one All Mail directory. The labels are in .safegrd-email-manifest.json at the top of the target directory: each message's path with its labels, such as \Inbox or Work.

What a Fire Drill checks

The message count matches the manifest, every message parses as RFC 5322 mail, and every message's SHA-256 matches. A message in the archive that the manifest does not list, or one the manifest lists that is missing, fails the drill. Nothing is written to disk.