Skip to content

Releases: codextde/dispatch

Release list

Dispatch 1.0.0

Choose a tag to compare

@danielehrhardt danielehrhardt released this 27 Sep 20:34

The first public release of Dispatch: an open-source collaborative inbox for teams on top of Gmail, Outlook or any IMAP mailbox. Licensed under AGPL-3.0, free to self-host, and available as hosted Dispatch Cloud.

Shared inboxes

  • Connect Gmail / Google Workspace and Outlook / Microsoft 365 via OAuth, or any IMAP/SMTP mailbox
  • Shared team inboxes with per-user and per-team access (read, reply, manage), plus personal inboxes
  • Labels, snooze, send later and undo send
  • Rich-text composer with signatures, attachments and canned responses with variables
  • Full-text search across conversations
  • Sandboxed email rendering with remote-image blocking

Collaboration

  • Internal comments with @mentions on any conversation
  • Assignments with an "Assigned to me" view
  • Realtime presence, typing indicators, collision detection and shared drafts
  • In-app and email notifications for mentions and assignments
  • Team chat with group chats and direct messages
  • Tasks with assignees and due dates, standalone or linked to conversations
  • Contacts built automatically from your mail

Automation & insights

  • Rules with conditions and actions: label, assign, move, archive, notify, call a webhook
  • Analytics for volume, first-reply time, resolution time and workload
  • AI assistant for summaries and drafts with your own Anthropic or OpenAI key
  • Keyboard shortcuts and a command palette

Administration

  • Multiple workspaces per instance, each with its own admin area
  • Custom roles and permissions, teams and an audit log
  • Passwordless magic-link sign-in, sessions valid for a year on any number of devices
  • Super-admin panel for instance settings: email delivery (SMTP, Amazon SES), OAuth apps, storage (local or S3), AI, branding, security and legal pages
  • Optional Stripe billing for operators who host Dispatch for others

Developers

  • REST API with workspace API keys
  • Signed webhooks for conversation, message, comment and task events

Self-hosting

  • Docker image for linux/amd64 and linux/arm64 (ghcr.io/codextde/dispatch)
  • Docker Compose deployment whose .env only needs DOMAIN. All secrets are generated on first boot.
  • Works on Coolify with the bundled compose file
  • First-run setup wizard protected by a one-time setup code from the server logs, automatic database migrations, health endpoint at /api/health

Security

  • Tenant isolation on every query; inbox access per user and team; personal inboxes stay private (never in workspace webhooks, rules or the shared address book)
  • Credentials encrypted with AES-256-GCM; secrets never leave the server
  • Hashed, single-use magic links (clicked, not prefetched) and rate-limited 6-digit codes
  • Hardened email rendering: CSS-tokenizing sanitizer, sandboxed iframe, remote-image blocking, no-referrer
  • Nonce-based Content Security Policy with strict-dynamic, HSTS and strict framing rules
  • SSRF protection for IMAP/SMTP, webhooks and AI endpoints (always on in SaaS mode)
  • Robust ingest against malicious mail (MIME-part limits, parse deadlines, safe storage paths, regex budgets)
  • Scoped API keys with read permissions, audit log for security-relevant actions

Quick start

curl -fsSLO https://raw.githubusercontent.com/codextde/dispatch/main/docker-compose.yml
echo "DOMAIN=mail.example.com" > .env
docker compose up -d

Then open https://mail.example.com/setup and enter the setup code from docker compose logs app. See docs/self-hosting.md and docs/coolify.md.