← All poppies

CatalogueCommunicationMailPoppy

MailPoppy

Your own private email, in your own cloud.

5.0(1)5.0 out of 5 stars, from 1 rating

FeaturedFree Lite versionPro upgrades in-appCommunicationVersion 0.1.26Data stays in your cloudEveryone

Download AgentsPoppy to get MailPoppy

The AgentsPoppy app is free, and runs on macOS, Windows and Linux. MailPoppy installs from inside it — the app asks your permission, shows exactly what will be created in your cloud, and can remove all of it later.

Screenshots

What you'd be asked to approve

Before MailPoppy can touch your AWS account, AgentsPoppy shows this exact grant and waits for your yes. This preview is computed from the poppy's reviewed package by the same assessor code the app runs — it is the approval screen, shown early.

At least one grant can change or delete resources beyond MailPoppy's own. The app flags this in red — read each line before approving.
  • cloudformationIts own

    Can create, change and delete only CLOUDFORMATION resources named arn:aws:cloudformation:*:*:stack/MailpoppyMailStack/* — it cannot change or delete any CLOUDFORMATION resource with a different name.

    13 actionsCreateStack · UpdateStack · DeleteStack · DescribeStacks · DescribeStackEvents · DescribeStackResources · ListStackResources · GetTemplate · CreateChangeSet · DescribeChangeSet · ExecuteChangeSet · DeleteChangeSet · TagResource
  • cloudformationBroad

    Can read any CLOUDFORMATION resource in your account — not just its own.

    2 actionsValidateTemplate · GetTemplateSummary
  • iamIts own

    Can create, change and delete IAM identities and permissions named arn:aws:iam::*:role/MailpoppyMailStack-* — this controls who can do what in your account.

    15 actionsCreateRole · DeleteRole · GetRole · TagRole · UntagRole · AttachRolePolicy · DetachRolePolicy · PutRolePolicy · DeleteRolePolicy · GetRolePolicy · ListRolePolicies · ListAttachedRolePolicies · PassRole · PutRolePermissionsBoundary · DeleteRolePermissionsBoundary
  • iamBroad

    Can read any IAM resource in your account — not just its own.

    1 actionSimulatePrincipalPolicy
  • lambdaIts own

    Can create, change and delete only LAMBDA resources named arn:aws:lambda:*:*:function:MailpoppyMailStack-* — it cannot change or delete any LAMBDA resource with a different name.

    12 actionsCreateFunction · DeleteFunction · GetFunction · GetFunctionConfiguration · UpdateFunctionCode · UpdateFunctionConfiguration · AddPermission · RemovePermission · InvokeFunction · TagResource · UntagResource · ListTags
  • lambdaIts own

    Can create, change and delete only LAMBDA resources named arn:aws:lambda:*:*:function:CrewPoppyRunner — it cannot change or delete any LAMBDA resource with a different name.

    1 actionInvokeFunction
  • dynamodbIts own

    Can create, change and delete only DYNAMODB resources named arn:aws:dynamodb:*:*:table/MailpoppyMailStack-* — it cannot change or delete any DYNAMODB resource with a different name.

    20 actionsCreateTable · DeleteTable · DescribeTable · UpdateTable · DescribeContinuousBackups · UpdateContinuousBackups · DescribeTimeToLive · UpdateTimeToLive · TagResource · UntagResource · ListTagsOfResource · GetItem · BatchGetItem · PutItem · UpdateItem · DeleteItem · Query · Scan · BatchWriteItem · ConditionCheckItem
  • dynamodbIts own

    Can read only DYNAMODB resources named arn:aws:dynamodb:*:*:table/MailpoppyMailStack-*/index/*.

    2 actionsQuery · Scan
  • logsIts own

    Can create, change and delete only LOGS resources named arn:aws:logs:*:*:log-group:/aws/lambda/MailpoppyMailStack-* — it cannot change or delete any LOGS resource with a different name.

    5 actionsCreateLogGroup · DeleteLogGroup · DescribeLogGroups · PutRetentionPolicy · TagResource
  • snsIts own

    Can create, change and delete only SNS resources named arn:aws:sns:*:*:MailpoppyMailStack-* — it cannot change or delete any SNS resource with a different name.

    9 actionsCreateTopic · DeleteTopic · Subscribe · Unsubscribe · GetTopicAttributes · SetTopicAttributes · GetSubscriptionAttributes · TagResource · UntagResource
  • eventsIts own

    Can create, change and delete only EVENTS resources named arn:aws:events:*:*:rule/MailpoppyMailStack-* — it cannot change or delete any EVENTS resource with a different name.

    8 actionsPutRule · DeleteRule · DescribeRule · PutTargets · RemoveTargets · ListTargetsByRule · TagResource · UntagResource
  • apigatewayIts own

    Can create, change and delete only APIGATEWAY resources named arn:aws:apigateway:*::/apis* — it cannot change or delete any APIGATEWAY resource with a different name.

    5 actionsPOST · GET · PATCH · PUT · DELETE
  • apigatewayIts own

    Can create, change and delete only APIGATEWAY resources named arn:aws:apigateway:*::/v2/apis* — it cannot change or delete any APIGATEWAY resource with a different name.

    5 actionsPOST · GET · PATCH · PUT · DELETE
  • apigatewayIts own

    Can create, change and delete only APIGATEWAY resources named arn:aws:apigateway:*::/tags* — it cannot change or delete any APIGATEWAY resource with a different name.

    5 actionsPOST · GET · PATCH · PUT · DELETE
  • s3Its own

    Can create, change and delete only S3 resources named arn:aws:s3:::mailpoppy* — it cannot change or delete any S3 resource with a different name.

    16 actionsCreateBucket · DeleteBucket · PutBucketPolicy · GetBucketPolicy · DeleteBucketPolicy · PutEncryptionConfiguration · GetEncryptionConfiguration · PutBucketPublicAccessBlock · GetBucketPublicAccessBlock · PutBucketTagging · PutLifecycleConfiguration · GetLifecycleConfiguration · PutBucketCORS · GetBucketCORS · ListBucket · HeadBucket
  • s3Its own

    Can create, change and delete only S3 resources named arn:aws:s3:::mailpoppy*/* — it cannot change or delete any S3 resource with a different name.

    3 actionsGetObject · PutObject · DeleteObject
  • s3Broad

    Can read any S3 resource in your account. AWS offers no way to narrow this: this action accepts no resource limit at all, so this is the tightest form the grant can take.

    1 actionListAllMyBuckets
  • cognito-idpBroad

    Can create new COGNITO-IDP resources in your account, but cannot change or delete anything that already exists. Its tag writes are compiled with conditions: it can only claim or release its own label, never another resource's.

    8 actionsCreateUserPool · CreateUserPoolClient · DescribeUserPool · DescribeUserPoolClient · GetUserPoolMfaConfig · TagResource · UntagResource · ListUsers
  • cognito-idpIts own

    Can create, change and delete only COGNITO-IDP resources tagged as its own — it cannot change or delete any COGNITO-IDP resource with a different tag.

    8 actionsDeleteUserPool · UpdateUserPool · DeleteUserPoolClient · UpdateUserPoolClient · SetUserPoolMfaConfig · AdminCreateUser · AdminSetUserPassword · AdminDeleteUser
  • sesUnscoped

    Can create, change and delete any SES resource in your account — not just its own.

    19 actionsCreateReceiptRuleSet · CreateReceiptRule · DeleteReceiptRule · DeleteReceiptRuleSet · DescribeReceiptRuleSet · DescribeActiveReceiptRuleSet · SetActiveReceiptRuleSet · CreateEmailIdentity · GetEmailIdentity · DeleteEmailIdentity · ListEmailIdentities · GetAccount · GetSendStatistics · PutAccountDetails · PutEmailIdentityMailFromAttributes · SendEmail · SetIdentityNotificationTopic · SetIdentityHeadersInNotificationsEnabled · DeleteSuppressedDestination
  • route53Unscoped

    Can create, change and delete any ROUTE53 resource in your account — not just its own.

    3 actionsListHostedZonesByName · ListResourceRecordSets · ChangeResourceRecordSets
  • guarddutyUnscoped

    Can create, change and delete any GUARDDUTY resource in your account — not just its own.

    8 actionsCreateMalwareProtectionPlan · GetMalwareProtectionPlan · UpdateMalwareProtectionPlan · DeleteMalwareProtectionPlan · ListMalwareProtectionPlans · TagResource · UntagResource · ListTagsForResource
  • stsBroad

    Can read any STS resource in your account. AWS offers no way to narrow this: this action accepts no resource limit at all, so this is the tightest form the grant can take.

    1 actionGetCallerIdentity

Nothing can be approved from a web page. The real Approve lives in the AgentsPoppy app on your machine, where this grant meets your actual AWS account — and where you can reject it, or tear down everything it created, at any time.

Evaluating MailPoppy for a company? Its vendor security package is audit-ready documentation for your SOC 2 or vendor-risk process — generated from the same reviewed package, with a machine-readable copy for procurement tooling.

About MailPoppy

MailPoppy deploys a complete, end-to-end encrypted mail backend into your own AWS account — your email lives on infrastructure you own, with no provider in between.

What you get

Included, free

  • Unlimited mailboxesOne price per domain — add as many addresses as you need, with no per-seat charge.
  • Bring your old mail acrossImport from AWS WorkMail, Yahoo, Fastmail, iCloud, or any provider that speaks IMAP.
  • Send and receive on your own domainSPF, DKIM, DMARC and a custom MAIL FROM are set up for you, so your mail is trusted.
  • Spam and virus filteringAmazon's own verdicts, plus optional malware scanning of every attachment.
  • Mail rules and retentionAllow and block lists, what to do with spam, and how long mail is kept.
  • Per-mailbox storage limitsCap any mailbox. Over-quota mail is bounced back to the sender, never silently lost.
  • Remove everything in one clickTeardown deletes every resource MailPoppy created in your account, and shows you the proof.

Paid features

  • Mobile and web accessRead and send from the iPhone and Android apps. Sold per domain, unlimited mailboxes.

Pricing

Install MailPoppyNothing to pay to install it.Free
Domain access7-day free trial, then it renews until you cancel.$14.99 / year

Prices are read live from the developer's own listing. Whatever this poppy costs, the cloud resources it creates are billed by AWS directly to you — AgentsPoppy never marks them up. Paid features are bought inside the app; the developer is the merchant of record.

Data & privacy

Nothing leaves your cloud. The developer declared that no data this poppy handles is ever sent outside the AWS account it runs in. You can verify that claim yourself — the source is public.

Developer & support

DeveloperMailPoppy
Websitehttps://mailpoppy.com
Source codehttps://github.com/leonct74/mailpoppy-public-sourcePublic by requirement — you or your AI can audit exactly what it does before installing.
Supportsupport@mailpoppy.com
Privacy policyhttps://mailpoppy.com/privacy
Age ratingEveryone
Runs onmacOS, Windows and LinuxNeeds AgentsPoppy 0.3.1 or newer.
Where it runsYour own AWS account.AgentsPoppy holds no copy of your data and cannot read it. Cloud usage is billed to you by AWS at their prices.

Support for the poppy itself comes from its developer. For the AgentsPoppy app, see Security or our terms.

Ready to run MailPoppy in your own cloud?

Download the free AgentsPoppy app for macOS, Windows or Linux, connect your AWS account once, and install MailPoppy from the catalogue inside it.

Download AgentsPoppy
← All poppies