Catalogue › Communication › MailPoppy
MailPoppy
Your own private email, in your own cloud.
Download AgentsPoppy to get MailPoppy
The AgentsPoppy app is free, and runs on macOS, Windows and Linux. MailPoppy installs from inside it — the app asks your permission, shows exactly what will be created in your cloud, and can remove all of it later.
Screenshots
What you'd be asked to approve
Before MailPoppy can touch your AWS account, AgentsPoppy shows this exact grant and waits for your yes. This preview is computed from the poppy's reviewed package by the same assessor code the app runs — it is the approval screen, shown early.
- cloudformationIts own
Can create, change and delete only CLOUDFORMATION resources named arn:aws:cloudformation:*:*:stack/MailpoppyMailStack/* — it cannot change or delete any CLOUDFORMATION resource with a different name.
13 actions
CreateStack · UpdateStack · DeleteStack · DescribeStacks · DescribeStackEvents · DescribeStackResources · ListStackResources · GetTemplate · CreateChangeSet · DescribeChangeSet · ExecuteChangeSet · DeleteChangeSet · TagResource - cloudformationBroad
Can read any CLOUDFORMATION resource in your account — not just its own.
2 actions
ValidateTemplate · GetTemplateSummary - iamIts own
Can create, change and delete IAM identities and permissions named arn:aws:iam::*:role/MailpoppyMailStack-* — this controls who can do what in your account.
15 actions
CreateRole · DeleteRole · GetRole · TagRole · UntagRole · AttachRolePolicy · DetachRolePolicy · PutRolePolicy · DeleteRolePolicy · GetRolePolicy · ListRolePolicies · ListAttachedRolePolicies · PassRole · PutRolePermissionsBoundary · DeleteRolePermissionsBoundary - iamBroad
Can read any IAM resource in your account — not just its own.
1 action
SimulatePrincipalPolicy - lambdaIts own
Can create, change and delete only LAMBDA resources named arn:aws:lambda:*:*:function:MailpoppyMailStack-* — it cannot change or delete any LAMBDA resource with a different name.
12 actions
CreateFunction · DeleteFunction · GetFunction · GetFunctionConfiguration · UpdateFunctionCode · UpdateFunctionConfiguration · AddPermission · RemovePermission · InvokeFunction · TagResource · UntagResource · ListTags - lambdaIts own
Can create, change and delete only LAMBDA resources named arn:aws:lambda:*:*:function:CrewPoppyRunner — it cannot change or delete any LAMBDA resource with a different name.
1 action
InvokeFunction - dynamodbIts own
Can create, change and delete only DYNAMODB resources named arn:aws:dynamodb:*:*:table/MailpoppyMailStack-* — it cannot change or delete any DYNAMODB resource with a different name.
20 actions
CreateTable · DeleteTable · DescribeTable · UpdateTable · DescribeContinuousBackups · UpdateContinuousBackups · DescribeTimeToLive · UpdateTimeToLive · TagResource · UntagResource · ListTagsOfResource · GetItem · BatchGetItem · PutItem · UpdateItem · DeleteItem · Query · Scan · BatchWriteItem · ConditionCheckItem - dynamodbIts own
Can read only DYNAMODB resources named arn:aws:dynamodb:*:*:table/MailpoppyMailStack-*/index/*.
2 actions
Query · Scan - logsIts own
Can create, change and delete only LOGS resources named arn:aws:logs:*:*:log-group:/aws/lambda/MailpoppyMailStack-* — it cannot change or delete any LOGS resource with a different name.
5 actions
CreateLogGroup · DeleteLogGroup · DescribeLogGroups · PutRetentionPolicy · TagResource - snsIts own
Can create, change and delete only SNS resources named arn:aws:sns:*:*:MailpoppyMailStack-* — it cannot change or delete any SNS resource with a different name.
9 actions
CreateTopic · DeleteTopic · Subscribe · Unsubscribe · GetTopicAttributes · SetTopicAttributes · GetSubscriptionAttributes · TagResource · UntagResource - eventsIts own
Can create, change and delete only EVENTS resources named arn:aws:events:*:*:rule/MailpoppyMailStack-* — it cannot change or delete any EVENTS resource with a different name.
8 actions
PutRule · DeleteRule · DescribeRule · PutTargets · RemoveTargets · ListTargetsByRule · TagResource · UntagResource - apigatewayIts own
Can create, change and delete only APIGATEWAY resources named arn:aws:apigateway:*::/apis* — it cannot change or delete any APIGATEWAY resource with a different name.
5 actions
POST · GET · PATCH · PUT · DELETE - apigatewayIts own
Can create, change and delete only APIGATEWAY resources named arn:aws:apigateway:*::/v2/apis* — it cannot change or delete any APIGATEWAY resource with a different name.
5 actions
POST · GET · PATCH · PUT · DELETE - apigatewayIts own
Can create, change and delete only APIGATEWAY resources named arn:aws:apigateway:*::/tags* — it cannot change or delete any APIGATEWAY resource with a different name.
5 actions
POST · GET · PATCH · PUT · DELETE - s3Its own
Can create, change and delete only S3 resources named arn:aws:s3:::mailpoppy* — it cannot change or delete any S3 resource with a different name.
16 actions
CreateBucket · DeleteBucket · PutBucketPolicy · GetBucketPolicy · DeleteBucketPolicy · PutEncryptionConfiguration · GetEncryptionConfiguration · PutBucketPublicAccessBlock · GetBucketPublicAccessBlock · PutBucketTagging · PutLifecycleConfiguration · GetLifecycleConfiguration · PutBucketCORS · GetBucketCORS · ListBucket · HeadBucket - s3Its own
Can create, change and delete only S3 resources named arn:aws:s3:::mailpoppy*/* — it cannot change or delete any S3 resource with a different name.
3 actions
GetObject · PutObject · DeleteObject - s3Broad
Can read any S3 resource in your account. AWS offers no way to narrow this: this action accepts no resource limit at all, so this is the tightest form the grant can take.
1 action
ListAllMyBuckets - cognito-idpBroad
Can create new COGNITO-IDP resources in your account, but cannot change or delete anything that already exists. Its tag writes are compiled with conditions: it can only claim or release its own label, never another resource's.
8 actions
CreateUserPool · CreateUserPoolClient · DescribeUserPool · DescribeUserPoolClient · GetUserPoolMfaConfig · TagResource · UntagResource · ListUsers - cognito-idpIts own
Can create, change and delete only COGNITO-IDP resources tagged as its own — it cannot change or delete any COGNITO-IDP resource with a different tag.
8 actions
DeleteUserPool · UpdateUserPool · DeleteUserPoolClient · UpdateUserPoolClient · SetUserPoolMfaConfig · AdminCreateUser · AdminSetUserPassword · AdminDeleteUser - sesUnscoped
Can create, change and delete any SES resource in your account — not just its own.
19 actions
CreateReceiptRuleSet · CreateReceiptRule · DeleteReceiptRule · DeleteReceiptRuleSet · DescribeReceiptRuleSet · DescribeActiveReceiptRuleSet · SetActiveReceiptRuleSet · CreateEmailIdentity · GetEmailIdentity · DeleteEmailIdentity · ListEmailIdentities · GetAccount · GetSendStatistics · PutAccountDetails · PutEmailIdentityMailFromAttributes · SendEmail · SetIdentityNotificationTopic · SetIdentityHeadersInNotificationsEnabled · DeleteSuppressedDestination - route53Unscoped
Can create, change and delete any ROUTE53 resource in your account — not just its own.
3 actions
ListHostedZonesByName · ListResourceRecordSets · ChangeResourceRecordSets - guarddutyUnscoped
Can create, change and delete any GUARDDUTY resource in your account — not just its own.
8 actions
CreateMalwareProtectionPlan · GetMalwareProtectionPlan · UpdateMalwareProtectionPlan · DeleteMalwareProtectionPlan · ListMalwareProtectionPlans · TagResource · UntagResource · ListTagsForResource - stsBroad
Can read any STS resource in your account. AWS offers no way to narrow this: this action accepts no resource limit at all, so this is the tightest form the grant can take.
1 action
GetCallerIdentity
Nothing can be approved from a web page. The real Approve lives in the AgentsPoppy app on your machine, where this grant meets your actual AWS account — and where you can reject it, or tear down everything it created, at any time.
Evaluating MailPoppy for a company? Its vendor security package is audit-ready documentation for your SOC 2 or vendor-risk process — generated from the same reviewed package, with a machine-readable copy for procurement tooling.
About MailPoppy
MailPoppy deploys a complete, end-to-end encrypted mail backend into your own AWS account — your email lives on infrastructure you own, with no provider in between.
What you get
Included, free
- ✓Unlimited mailboxesOne price per domain — add as many addresses as you need, with no per-seat charge.
- ✓Bring your old mail acrossImport from AWS WorkMail, Yahoo, Fastmail, iCloud, or any provider that speaks IMAP.
- ✓Send and receive on your own domainSPF, DKIM, DMARC and a custom MAIL FROM are set up for you, so your mail is trusted.
- ✓Spam and virus filteringAmazon's own verdicts, plus optional malware scanning of every attachment.
- ✓Mail rules and retentionAllow and block lists, what to do with spam, and how long mail is kept.
- ✓Per-mailbox storage limitsCap any mailbox. Over-quota mail is bounced back to the sender, never silently lost.
- ✓Remove everything in one clickTeardown deletes every resource MailPoppy created in your account, and shows you the proof.
Paid features
- ★Mobile and web accessRead and send from the iPhone and Android apps. Sold per domain, unlimited mailboxes.
Pricing
Prices are read live from the developer's own listing. Whatever this poppy costs, the cloud resources it creates are billed by AWS directly to you — AgentsPoppy never marks them up. Paid features are bought inside the app; the developer is the merchant of record.
Data & privacy
Nothing leaves your cloud. The developer declared that no data this poppy handles is ever sent outside the AWS account it runs in. You can verify that claim yourself — the source is public.
Developer & support
| Developer | MailPoppy |
|---|---|
| Website | https://mailpoppy.com |
| Source code | https://github.com/leonct74/mailpoppy-public-sourcePublic by requirement — you or your AI can audit exactly what it does before installing. |
| Support | support@mailpoppy.com |
| Privacy policy | https://mailpoppy.com/privacy |
| Age rating | Everyone |
| Runs on | macOS, Windows and LinuxNeeds AgentsPoppy 0.3.1 or newer. |
| Where it runs | Your own AWS account.AgentsPoppy holds no copy of your data and cannot read it. Cloud usage is billed to you by AWS at their prices. |
Support for the poppy itself comes from its developer. For the AgentsPoppy app, see Security or our terms.
Ready to run MailPoppy in your own cloud?
Download the free AgentsPoppy app for macOS, Windows or Linux, connect your AWS account once, and install MailPoppy from the catalogue inside it.