Releases: codextde/dispatch
Releases · codextde/dispatch
Release list
Dispatch 1.0.0
The first public release of Dispatch: an open-source collaborative inbox for teams on top of Gmail, Outlook or any IMAP mailbox. Licensed under AGPL-3.0, free to self-host, and available as hosted Dispatch Cloud.
Shared inboxes
- Connect Gmail / Google Workspace and Outlook / Microsoft 365 via OAuth, or any IMAP/SMTP mailbox
- Shared team inboxes with per-user and per-team access (read, reply, manage), plus personal inboxes
- Labels, snooze, send later and undo send
- Rich-text composer with signatures, attachments and canned responses with variables
- Full-text search across conversations
- Sandboxed email rendering with remote-image blocking
Collaboration
- Internal comments with @mentions on any conversation
- Assignments with an "Assigned to me" view
- Realtime presence, typing indicators, collision detection and shared drafts
- In-app and email notifications for mentions and assignments
- Team chat with group chats and direct messages
- Tasks with assignees and due dates, standalone or linked to conversations
- Contacts built automatically from your mail
Automation & insights
- Rules with conditions and actions: label, assign, move, archive, notify, call a webhook
- Analytics for volume, first-reply time, resolution time and workload
- AI assistant for summaries and drafts with your own Anthropic or OpenAI key
- Keyboard shortcuts and a command palette
Administration
- Multiple workspaces per instance, each with its own admin area
- Custom roles and permissions, teams and an audit log
- Passwordless magic-link sign-in, sessions valid for a year on any number of devices
- Super-admin panel for instance settings: email delivery (SMTP, Amazon SES), OAuth apps, storage (local or S3), AI, branding, security and legal pages
- Optional Stripe billing for operators who host Dispatch for others
Developers
- REST API with workspace API keys
- Signed webhooks for conversation, message, comment and task events
Self-hosting
- Docker image for
linux/amd64andlinux/arm64(ghcr.io/codextde/dispatch) - Docker Compose deployment whose
.envonly needsDOMAIN. All secrets are generated on first boot. - Works on Coolify with the bundled compose file
- First-run setup wizard protected by a one-time setup code from the server logs, automatic database migrations, health endpoint at
/api/health
Security
- Tenant isolation on every query; inbox access per user and team; personal inboxes stay private (never in workspace webhooks, rules or the shared address book)
- Credentials encrypted with AES-256-GCM; secrets never leave the server
- Hashed, single-use magic links (clicked, not prefetched) and rate-limited 6-digit codes
- Hardened email rendering: CSS-tokenizing sanitizer, sandboxed iframe, remote-image blocking, no-referrer
- Nonce-based Content Security Policy with
strict-dynamic, HSTS and strict framing rules - SSRF protection for IMAP/SMTP, webhooks and AI endpoints (always on in SaaS mode)
- Robust ingest against malicious mail (MIME-part limits, parse deadlines, safe storage paths, regex budgets)
- Scoped API keys with read permissions, audit log for security-relevant actions
Quick start
curl -fsSLO https://raw.githubusercontent.com/codextde/dispatch/main/docker-compose.yml
echo "DOMAIN=mail.example.com" > .env
docker compose up -dThen open https://mail.example.com/setup and enter the setup code from docker compose logs app. See docs/self-hosting.md and docs/coolify.md.