Email over IMAP
Messages are fetched as RFC 5322 and streamed into the same sealed archive, folder
structure intact. By default every folder is taken except spam and trash;
--email-folders narrows that.
Use SAFEGRD_EMAIL_PASSWORD instead of --email-password.
A password passed as a flag shows up in shell history and in the process list.
Providers
| Provider | IMAP server | Password |
|---|---|---|
| Gmail and Google Workspace | imap.gmail.com:993 | An app password, made at myaccount.google.com/apppasswords. It needs 2-Step Verification on the account, and a Workspace administrator can turn app passwords off. |
| Fastmail | imap.fastmail.com:993 | An app password with IMAP access: Settings, Privacy & Security, Manage app passwords and access. |
| Microsoft 365 and Outlook.com | Not supported yet | Microsoft turned off password sign-in for IMAP, app passwords included, and requires OAuth. SafeGrd signs in with a password, so it cannot back these mailboxes up until it speaks OAuth. |
| Self-hosted (Dovecot, Cyrus and others) | Your server, port 993 | The mailbox's password. A certificate from an internal CA is covered below. |
Gmail labels
Gmail shows each label as a folder, so one message can appear in several. SafeGrd backs up Gmail's All Mail folder alone and records each message's labels next to it, so every message is downloaded and stored once. Spam and Trash are left out.
This needs All Mail visible over IMAP: in Gmail's settings, open the Labels tab and tick
Show in IMAP for All Mail. It is on by default. With it off, the backup falls
back to one folder per label, stores a message once for each label it has, and prints a
warning. A surface that lists its own folders backs up those folders as named.
Where the password comes from
- It stays on the host. The surface's
credentialblock saysfrom: envwith the variable'sname,from: commandwith a command whose output is the password, orfrom: file. SafeGrd learns the variable's name, never the password. This is the default. - SafeGrd holds it. The surface says
credential: {from: safegrd}and names nothing on the host. SafeGrd holds the password, encrypted, and gives it only to this surface's host when the mailbox is due; the daemon keeps it in memory for that run. Hand it over in the setup wizard or under Nodes → Credential.
An incomplete block, such as from: env with no name, is refused
rather than guessed at.
A mailbox behind a private CA
For a self-hosted server whose certificate chains to an internal CA, give the surface
ca_file: /etc/ssl/mail-ca.pem, a PEM bundle on the host. A one-off backup takes
--email-ca-file, and SAFEGRD_EMAIL_CA_FILE covers every email surface
on a host that names none. The bundle is added to the system roots, never used instead of them.
There is no option to turn certificate checks off: the mailbox password crosses this connection.
Restoring a mailbox
A mailbox comes back as a directory per folder, each message a standard RFC 5322
.eml file that any mail client or forensic tool can open or import.
A Gmail restore comes back as one All Mail directory. The labels are in
.safegrd-email-manifest.json at the top of the target directory: each message's
path with its labels, such as \Inbox or Work.
What a Fire Drill checks
The message count matches the manifest, every message parses as RFC 5322 mail, and every message's SHA-256 matches. A message in the archive that the manifest does not list, or one the manifest lists that is missing, fails the drill. Nothing is written to disk.