Work through these in order. The first section is the only one that is urgent — everything after it can be read as you go. Sections are ordered from most to least important.
Your system ships with default passwords. Change both of them now, before you add a single mailbox. Until you do, anyone who finds your address can open the dashboard and read every alert in it.
a. Change the portal password — this is the one on the lock screen.
The default is admin. Go to Manage & Devices → Security → Portal password, enter the current password, then your new one twice. You are signed out of other devices when it changes, which is intended — sign back in with the new password.
b. Change the export password — this is a second, separate password.
The default is export. Change it under Manage & Devices → Security → Export password. It is deliberately not the same as the portal password, because it guards the things that would hurt most if they leaked: downloading your accounts with their mailbox passwords, revealing webmail logins, exporting the leads bucket, and registering a device for biometric unlock. Make it different from the portal password and keep it somewhere safe — you will be asked for it rarely, which is exactly why people forget it.
c. Check the licence shows active — the key pill at the top of the screen should read licence active.
d. Optional but recommended — turn on biometric unlock. Under Manage & Devices → Biometric unlock, press Register this device. You will be asked for the export password once, then your fingerprint, face or device PIN. After that you unlock with a touch instead of typing. Register a second device too, so losing one is never a lockout. Your passwords always keep working.
One thing that catches people out: passkeys are tied to the exact web address you registered on. Always reach the dashboard by the same address.
Go to Manage & Devices → Accounts → Add account. For each mailbox you need the email address, the mailbox password, and the IMAP host — usually something like imap.yourprovider.com on port 993 with SSL.
Press Test before saving. A green result means the login worked and the folders were read; if it fails, the message tells you whether it was the host, the port or the credentials.
Two things worth knowing. Gmail and Outlook accounts with two-factor authentication need an app password, not your normal one. And monitoring is forward-only — mail that arrived before you added the mailbox is never scanned, so add accounts before you need them, not after.
The account list is searchable, and each account can be given a group name so you can filter by client or by region later.
This is the general monitor and the one you will live in. It watches every mailbox you have added and raises an alert the moment one of your keywords appears.
Add keywords under Manage & Devices → Keywords. Think in terms of the words a real enquiry contains: quotation, purchase order, proforma, RFQ, tender, the product names you sell.
Where it looks. Four separate channels, each switchable under What to match on:
• Subject line — the fastest and least noisy. Start here.
• Attachment filename — catches Purchase Order 8841.pdf even when the email says nothing.
• Inside attachments — PDFs, Word, Excel, HTML, CSV and text files are opened and their text is read.
• Email body — the widest net, and the noisiest. Body hits get their own Email Body tab so they do not bury your Inbox and Sent tabs.
Where results appear. Inbox for mail you received, Sent for mail you sent, Email Body for body-only matches. An email that matches in two ways appears in both places — that is deliberate, not a duplicate.
This engine is not a second keyword monitor, and it is not for prospecting. It watches specific domains and alerts you on every email exchanged with them, regardless of content. It exists for companies you have already started doing business with — an active client, a supplier mid-order, a freight agent on a live shipment — where you want nothing from them to be missed, whatever it says.
Keep it small. This is the important part. The domain engine is far heavier than the keyword engine: it examines every message in every folder of every mailbox attached to it, rather than looking for a short list of words. The more mailboxes you attach, the more work every polling cycle does, and the slower everything becomes — including your keyword alerts.
Rule of thumb: attach only business-active mailboxes to the domain monitor. The one or two boxes where live trade actually happens — sales, orders, operations. Do not attach archive boxes, personal boxes, catch-all boxes, or mailboxes you added "just in case". Every extra one costs you speed for no benefit.
Adding a mailbox to it. In Manage & Devices → Accounts, press ⇒ DM on the account you want. You will be asked which domains to watch — enter the domain only, like client.com, and subdomains are covered automatically. Separate several with commas. The copy will not proceed without at least one domain, because a domain-monitored mailbox with no domains watches nothing and tells you nothing.
Adding a mailbox by hand. You do not have to copy one across. In the Domain tab open Manage & Devices → Accounts → Add account and enter the mailbox exactly as you would for the keyword monitor: email address, mailbox password, IMAP host, port 993 with SSL. Press Test first. Then add the domains you want watched under Watched domains in the same panel — domain only, like client.com, one per line or comma separated. A mailbox with no domains attached watches nothing.
Watching one address instead of a whole domain. Enter a full address — john@gmail.com — and only that mailbox is caught, not everyone else at that provider. This is how you follow a contact who uses Gmail, Outlook or Yahoo, where watching the domain itself would flood you. Domains and addresses can be mixed freely in the same list.
The Account–domain map shows which domains belong to which mailbox. Check it after adding, so you can see the link was recorded.
Watching one address instead of a whole domain. Enter a full address — john@gmail.com — and only that mailbox is watched, not everyone else at that provider. This is how you follow a contact who uses Gmail, Outlook or Yahoo, where watching the domain itself would flood you. Domains and addresses mix freely in the same list.
Remove finished business — this is not optional housekeeping. The moment a deal is closed, an order is delivered or a partner goes quiet for good, delete that mailbox from the domain monitor and remove its domains. Every mailbox left attached keeps costing you scanning time on every cycle, forever, for a relationship that has ended. A domain monitor that only ever grows will eventually slow the whole system down. Prune it the same week the business finishes.
The dashboard is not something you have to sit and watch. Set up the alerts and let it come to you.
Phone push (recommended). Install the free ntfy app, invent a private topic name that nobody could guess, and enter it under Manage & Devices → Notifications for each tab you care about. Alerts are pushed the instant they are found, day and night, whether or not any browser is open — this runs on the server, not in your browser.
Choose your topic name like a password. Anyone who knows it can read your alerts.
Browser notifications. Press the 🔔 icon at the top of the screen to allow them. These only work while the dashboard is open in a tab.
Sound. Each tab has a speaker icon to mute it. Right-click the speaker to preview the chime.
The watchdog. Give it its own ntfy topic. It tells you when a mailbox stops working — a changed password, an expired app password, a provider blocking the connection. This is the alert that matters most, because a silent mailbox looks exactly like a quiet one.
Tap a card to open the email. From the open card you can:
• Translate the whole message, or highlight a passage and translate just that.
• Move it to another folder on the mail server — a real move, visible in your webmail.
• Note — attach a note or a reminder to the email, and jump back to the email from the note later.
• ⏰ Remind — set a reminder about this email in one tap; it defaults to tomorrow morning.
• 💼 Log job — record the business in this email in Jobs at hand.
• ✏️ beside the webmail address — correct that mailbox's webmail URL without leaving the email.
• Webmail login — reveal the credentials for that mailbox when you need to reply properly.
• Ignore domain — stop that sender's domain from generating future alerts.
• Previous / Next to move through the list without closing.
On a phone or tablet, swipe left and right on the open email to move between messages, and swipe a card in the list to mark it read or delete it.
Marking an email read in Inbox or Sent also marks the same message read in the Email Body tab, so you never process the same email twice.
A ledger of the business actually in flight: who is paying, who is receiving, who is handling it, how much, and when it is due. It is a record you keep — nothing here affects monitoring.
Logging a job from an email. Open the email and press 💼 Log job in the header. Mason reads the companies straight off the message and offers them: by default the other company pays and yours receives, and either can be changed before saving. Companies are stored as domains — acme.com, not sales@acme.com — because the job belongs to the company, not to whoever happened to send that email. The Cc line is offered too, which is usually where the agent or freight forwarder appears.
Three fields are required and the job will not save without them: assigned handler, amount and due date. A row you cannot chase is not worth keeping. Your last handler and currency are remembered, so the next job is faster.
Working the list. Each row has:
• ✓ Paid — the business went through. It stops counting towards value in play.
• ✕ Failed — it did not go through. Kept for the record, and asks first.
• ↩ Reopen — put a closed job back in flight.
• ⏰ — set an EXTRA reminder at a time of your choosing. You do not need one for the deadline itself: every ongoing job rings on its own due date automatically, at 9am, through the same 24/7 push. A job marked paid or failed stops chasing you.
• ✉ — jump back to the email the job came from.
• ✏️ edit · 🗑 delete.
The due-invoice alarm. The Jobs at hand card on the dashboard watches your deadlines for you. It turns amber when something falls due within three days and red once anything is late, with a count on the corner and a line naming the worst one — "late.com · 4d late · USD 12,500" — so you know what to chase without opening the tab. Overdue always wins over due-soon: if something is late, that is what you are shown. The colour stays visible with Power saver on and for reduced-motion users; only the pulse stops.
The four figures at the top. Ongoing, successful, failed, and the total value still in play — counted per currency, and counting only ongoing jobs, because money already paid or written off is not money you are waiting on.
Due dates colour themselves as they approach: amber within three days, red once overdue with the number of days late. Filter by status, search across company, handler and note, and export the whole log to CSV for your accountant.
You can also log a job that did not arrive by email — press + New job and fill it in directly.
Adding a job by hand. Press + New job for business that did not arrive by email. The company fields let you pick from a list or simply type — enter newclient.com, or paste sales@newclient.com and it is reduced to the company for you.
Choosing the companies. The two dropdowns list every address on the message — sender, recipients and Cc — each labelled with the role it played, so you can tell sales@acme.com from accounts@acme.com at a glance. You pick by address; what gets saved is the domain, because the job belongs to the company. Companies already in your log are offered underneath, so a repeat job is two taps.
Backing it up. ⬆ Export saves the whole log as JSON and ⬇ Import restores it — the same pattern as the other tabs. Importing MERGES: rows already present are updated rather than duplicated, so importing the same file twice is safe. ⬇ CSV is the spreadsheet version for your accountant. The log lives in data/jobs.json, and unlike alerts it is data you typed rather than data that can be fetched again — so include it in whatever backup you keep.
Mason can translate an email into your language, either the whole message or just a passage you highlight. Both buttons sit at the bottom of the open email.
You need your own DeepL API key. Translation is not included with Mason — it uses your DeepL account, so the characters are yours and nothing passes through us.
Getting a key
1. Go to deepl.com and sign up for a free API account — the developer one, not the website subscription.
2. Copy the authentication key it gives you. A free key ends in :fx; Mason detects that automatically, so there is nothing else to configure.
3. Paste it into Manage & Devices → Translation and save.
The free allowance, and what to do when it runs out. A free DeepL API account currently comes with 1,000,000 characters in total — that is a one-time allowance, not a monthly one. It does not reset. Older free accounts were 500,000 characters per month instead, so check which kind yours is on DeepL's usage page.
When the allowance is gone, translation simply stops and Mason tells you the quota is exhausted — nothing else breaks and no mail is missed. You then have two choices: register another free DeepL API account and paste in the new key, or take a paid DeepL subscription if you translate constantly and would rather not keep swapping keys.
Keeping the characters for what matters. A long HTML email can be tens of thousands of characters. If you only need the gist of one paragraph, highlight it and use Selection rather than translating the entire message — it costs a fraction as much. Mason also skips translating an email that is already in your language, so nothing is spent on those.
You can see what is left at any time in Manage & Devices → Translation, which reads the usage figure straight from DeepL.
A monitor that cries wolf gets ignored. Three tools, in the order you should reach for them:
Ignore domains. Newsletters, no-reply senders, your own suppliers' marketing. Ignored mail is not deleted — it is filed quietly in the Ignored tab and never pushed to your phone.
Noise control. Exclude terms that appear in mail you do not want, and switch on whole words only so bid stops matching forbidden. These rules only ever suppress an alert that was already found; they can never cause a missed email.
VIP. The opposite tool — make the important things louder. Flag senders and keywords so their cards stand out. VIP keywords match whole words only, in any language including Arabic and Chinese.
Every address seen on a matched email is collected automatically into Leads, with the date first seen and where it came from. Export it as CSV whenever you want it. Addresses you never want collected go in the leads exclusion list.
Leads are still collected from ignored domains. Ignoring a domain means "do not interrupt me", not "pretend this contact does not exist".
Use Export in the Inbox/Sent and Domain panels to download your accounts, keywords, domains, VIP lists and noise rules. Keep the file somewhere off the server. Import restores it onto a fresh install.
Exports that include mailbox passwords ask for the export password. Treat that file exactly like a password list — it is one.
Take a fresh export whenever you make a meaningful change: a batch of new accounts, a keyword overhaul, a new set of watched domains.
Devices. Every signed-in device is listed under Manage & Devices. Revoke any you do not recognise, and revoke a device the moment it is lost.
How emails open. Under Manage & Devices, each tab can open its email in the reading pane (a split view beside the list, on wide screens) or a pop-up. This is now set per device: your desktop can use the pane while your phone uses the pop-up, and changing one no longer changes the other. On a wide monitor the reading pane uses the full screen rather than a centred column.
Tablet mode. Under Appearance → Layout. Turn it on when using a tablet: it fits the email view to the screen, gives you the compact tab strip, and enables swipe. Phone and desktop are unaffected — the setting applies to the device you switch it on.
Power saver. Under Appearance → Power saver, and on automatically on phones and tablets. It removes blurred backgrounds and looping animations, which are what make a device run warm. Purely visual — alert checking, sounds, notifications and the refresh all continue exactly the same.
Biometric unlock. Register a device under Manage & Devices to unlock with a fingerprint or face instead of typing. Registering needs the export password, so only you can add one, and passwords always keep working.
Appearance. Themes, light and dark, and effects. In a dark theme, PDFs and documents are shown dark too. Cosmetic only; nothing here changes what is monitored.
• Forward-only. Mail that arrived before an account or keyword was added is never scanned.
• Scanned PDFs. A photographed or scanned page contains no text, so its contents cannot be matched — the filename still can.
• Very large emails. Attachments inside messages over 15 MB skip content scanning.
• Deleted mail. If a message is moved or deleted on the server, opening its card searches your other folders for it, including Trash. Only a permanently purged message is truly gone.
• Keep the domain monitor lean. If the dashboard feels slow, this is the first place to look.
Clear the monitor regularly — around 6,000 cards. Alerts are kept until you remove them, and they live in memory. On a 4 GB RAM VPS, roughly 6,000 cards is the point to start clearing; leave it far beyond that and the server begins to struggle and the dashboard slows for everyone using it.
Use Clear viewed to drop everything you have already read, or Clear oldest… to remove a chosen number of the oldest cards. Export first if you want a record. The counter in each tab header tells you where you stand, and the dashboard warns you as the total climbs. A bigger VPS raises the number — the rule of thumb is per 4 GB of RAM.
No alerts arriving. Check the mailbox is still connected in Manage & Devices, and that the tab is not muted. Then check the watchdog topic — a failing mailbox reports itself.
Alerts on screen but nothing on the phone. The ntfy topic is missing or misspelt for that tab.
Too many alerts. Turn body matching off first, then add exclude terms, then ignore the domains behind the noise.
Everything feels slow. Two causes, in order. First, too many mailboxes attached to the domain monitor — remove any whose business has finished. Second, too many stored cards: on a 4 GB VPS start clearing at about 6,000, using Clear viewed or Clear oldest.
Locked out. Your passwords always work even when biometrics are registered. If you have lost the portal password, it can be reset on the server.
Mason watches every configured mailbox around the clock, checking for new mail every 30 seconds. An alert is raised the moment a monitored keyword appears in any of four places: the subject line, an attachment's filename, inside an attachment (PDF, Word, Excel, HTML, CSV and plain-text files are opened and their text is scanned), or the email body itself. Matching is case-insensitive and tolerant of encoded or oddly-split subjects — if the keyword is there, it is caught.
Each of those four channels can be switched on or off independently under Manage & Devices → What to match on. Body matches get their own Email Body tab so the Inbox/Sent tabs stay focused on subject and attachment hits; an email that matches both ways appears in both places.
Limits to know: mail that arrived before a keyword or account was added is not scanned (monitoring is forward-only), scanned/photo PDFs contain no readable text so their contents can't be matched (their filename still can), and attachments inside very large messages (over 15 MB) skip content scanning.
A full index of what the suite can do, tab by tab. Everything listed here is available in the current build.
📥 Inbox & 📤 Sent keyword monitoring
🌐 Domain monitoring
📝 Email Body matches
🎯 Leads Bucket
📖 Reading a message
🚫 Ignored
🔍 Search
📝 Notes & ⏰ Reminders
⚙️ Manage & Devices
🎨 Appearance
🔒 Security
Two live feeds: mail received by your accounts and mail sent from them, each card showing who, what, when, which keyword hit, and where it hit (subject / attachment name / attachment content). Cards arrive in real time — no refresh needed.
Above each list: a search box, read/unread filter, account filter, and “✓ All read” which marks everything currently matching your filters as read in one click. Click any card to open the full email.
Clearing tools sit in each panel header: Clear viewed, Clear oldest… (choose how many of the oldest cards to drop) and Clear all. ⬇ CSV exports the current feed, and the speaker icon mutes that tab (right-click it to preview the chime).
Keyword matches found in the message body no longer appear here — they have their own 📝 Email Body tab. An email that matches both ways shows up in both places.
On the Home and Domain tabs (when not typing in a box):
j / k — move the highlight down / up the list
Enter — open the highlighted email
r — mark it read / unread
i — open it and jump straight to the ignore-domain picker
s — switch the highlight between Inbox and Sent (Home tab)
In the email viewer: ← / → move to the previous / next alert, ↑ / ↓ scroll the open message, Esc closes.
Opens the full message safely (links open in a new tab; nothing runs). Inline images, CC recipients and highlighted keyword hits are all shown; body hits appear in the header beside the subject hits.
Footer buttons: 📝 Note saves a note about this email — pre-filled and permanently linked back to it. 🚫 Ignore domain silences a sender's whole domain, and then asks whether that domain should also be excluded from the Leads Bucket (answer No to keep collecting its addresses). 🗑 Remove deletes the alert. ← / → walk through your alerts without closing, and ↑ / ↓ scroll the open message.
Attachments are listed with type icons and sizes. View previews in-browser — PDF, Word, Excel, HTML, text and images — including files sent with no filename, which are identified by their content type and magic bytes. Save downloads the original.
Translation: translate the whole message with one click, or simply select any text in the message for an instant pop-up translation (needs a DeepL key in Manage).
Separate from keywords: add whole domains (e.g. rival-bank.com) and get an alert whenever any mail arrives from them, keyword or not. Same cards, filters, viewer, clearing tools, CSV export and “All read” as the Home tab.
Domain accounts are managed separately from keyword accounts, and every address seen on a domain alert also feeds the Leads Bucket.
Domains you've ignored stop raising alerts, but their mail isn't lost — it's collected in the Ignored tab so you can audit what's being filtered and un-ignore a domain at any time. Push notifications are suppressed for ignored domains, and you can clear ignored cards separately from your main feeds.
When you ignore a domain from the email viewer you're also offered the option to exclude it from the Leads Bucket — choose Yes to stop collecting its addresses and remove any already stored, or No to ignore the alerts only.
Keywords found in the text of the message get their own tab, so your Inbox and Sent feeds stay focused on subject and attachment hits. Both the plain-text and HTML versions of the body are read (HTML tags are stripped first, so you match what a human sees, not markup).
If an email matches on the body and on the subject or an attachment, you get a card in both places — one here and one in the originating tab — each tracked separately for read state and deletion.
The tab has everything the keyword tabs have: counters, search, read and account filters, mark-all-read, the clearing tools, CSV export and the full email viewer. It also has its own push-notification switch and its own ntfy topics, so you can silence body alerts without touching the others — cards still collect quietly while it's off.
Body matching is switched on and off under Manage & Devices → What to match on.
Every sender, recipient and Cc address seen on a keyword or domain alert is collected here automatically, as a compact list built to hold very large numbers of contacts. Leads are stored independently of your alerts, so they remain even after you delete the cards they came from.
Addresses are deduplicated automatically — seeing one again updates its sighting count rather than adding a second row. Your own monitored mailboxes are never collected.
Exclusion keywords skip an address when any part of it — the name before the @ or the domain — contains one of your words. It is strictly per address: if a sender is excluded, the recipients on that same email are still collected. Adding a word also removes matching leads already stored. The list is kept alphabetical and tucked into a collapsible section; the add box sits below it.
Tools: search by address, name or account; filter by role (sender / recipient / Cc / manual) and by source; add addresses by hand; remove one with a confirmation; Deduplicate to merge any mixed-case duplicates from imports; and Delete all, which requires your export password.
Export & import: download as JSON or CSV (both password-protected, with the full record preserved), and import to merge a bucket back in without overwriting what you already have.
Email subjects are deliberately not stored, to keep the file small enough for very large lists.
Notes live in the Notes tab; the floating ✏️ button (bottom-right) opens a quick-note popup from anywhere. Both support:
📷 Images — attach up to 4 (or just paste a screenshot straight into the text box). Click a thumbnail to view full-size.
⏰ Timer — set a date & time and the note becomes a reminder: banner, ring, browser notification and phone push when due.
📧 Linked email — notes created from the viewer's 📝 button carry a chip that reopens the original email.
Pin 📌, edit ✏️, copy ⧉ or delete 🗑 from each note card.
Standalone reminders with quick chips (+1h, +3h, tomorrow…). When one is due you get the on-screen banner and ring, a browser notification, and — if you set an ntfy topic in the panel — a push straight to your phone, 24/7, even with the browser closed (the server does the pushing). Snooze or acknowledge from the banner.
Add mail accounts (address + app password), toggle inbox/sent checking per account, and maintain the keyword list. New keywords take effect on the next 30-second poll — no restart. Keywords match as substrings: invoice also hits REINVOICED.
Editing an account keeps its place in the mail stream, so changing a label, host, port, folder, webmail URL or password will not re-scan old mail. Changing the email address itself points the account at a different mailbox, so it starts fresh from that moment. Leave the password blank when editing to keep the stored one.
What to match on — four independent switches decide which channels may raise an alert: subject, attachment name, attachment content and email body. Turning one off only stops it raising alerts; it never changes which mail is scanned, and forward-only behaviour is unaffected. At least one must stay on.
Notifications — set ntfy topics per tab (Inbox, Sent, Domain, Email Body and Reminders), send a test push to verify delivery, and set your dashboard URL so notifications open the right card when tapped.
Translation — add your DeepL key and target language here.
Import / export — accounts, keywords, domains and notes can be exported and re-imported; every export and destructive bulk action is protected by your export password. Devices lists everything that has unlocked the dashboard, each revocable individually.
The 🎨 button opens themes (dozens, incl. 4 signature typographic ones and Liquid Glass with its own shade picker), accent colors, summary-card styles and motion toggles — including the card entrance animation if you prefer things perfectly still. 🌙 flips light/dark.
Accent colors can be set per section — Inbox, Sent, Domain, Email body, Leads, Notes and Reminders — either from dozens of ready-made presets or with the individual color pickers. Save your own combination as a named preset, and hide any built-in presets you never use.
Stat cards have several display types and card styles. Whichever you choose, every figure stays on one line and remains fully readable up to six digits and beyond.
Everything else in this suite watches your mail. This watches the monitoring. An account can stop being polled without any error you would notice — an expired app password, a renamed folder, IMAP throttling — and the matching engine keeps working perfectly while that mailbox is invisible.
Three states: Failing means polls are erroring (the IMAP error is shown). Stalled means polls are not even being attempted. Quiet means polls succeed but nothing has matched for a long time, which is how an empty or renamed folder looks. Accounts you have switched off are never flagged.
The threshold scales with your account and worker counts, so a deep but healthy poll queue is never mistaken for a fault. A pill appears in the topbar only when something needs attention — if you cannot see it, nothing is wrong.
Watchdog notifications use their own ntfy topics, deliberately separate from keyword alerts, so you can be told when monitoring breaks without turning on any keyword push. If no topic is set there, no watchdog push is sent and the panel tells you so. The watchdog is read-only and runs in its own thread — it can never affect polling or matching.
Alert volume over time, stacked by source, plus the hour of day alerts tend to arrive (converted from UTC to your local time). Range 7 / 30 / 90 days, filterable to a single source.
Top drivers lists the keywords, domains, senders and accounts producing the most alerts — useful for spotting a keyword that fires constantly and is never opened, which is a candidate for an exclude term.
Noise control suppresses alerts you have already caught. Exclude terms drop an alert if the term appears anywhere in the scanned text. Whole words only stops "bid" matching inside "forbidden".
These rules run after matching and are purely subtractive — they can only ever remove an alert that was already found, never change what gets scanned. If a rule is misconfigured it simply suppresses nothing. The master switch keeps your terms while turning the rules off entirely.
VIP senders flag important addresses (ceo@client.com) or whole domains (client.com, including subdomains). Their alerts get a ⭐ badge, and every tab has a VIP filter. This is presentational only — it never affects whether an email is caught.
The same email reaching several monitored accounts raises one alert per account. With collapsing on, those share a single card tagged "seen on N accounts". Click the tag to expand the group and see every copy separately.
Marking a collapsed card read, or deleting it, applies to all the alerts it stands for — the count on the button tells you how many. Tab counters always show every stored alert, never the collapsed count.
Two alerts only share a card when their Message-ID, subject, sender and matched keywords are all identical. Some bulk mailers reuse one Message-ID across different emails, so matching on it alone could hide a real message. Nothing is ever deleted or hidden without a way to expand it.
Saved views store a filter combination as a one-tap chip above the alert list. Tap to apply, tap again to clear. Editing a filter by hand deselects the chip, so the highlight never lies about what you are looking at. Views sync across your devices.
Multi-select (☑ Select) lets you tick several cards and mark them read or unread, or delete them together. Under duplicate collapsing the bar shows both figures — "2 selected (4 alerts)".
Global search (🔎 in the topbar) searches every tab at once, or one tab at a time. Previous / Next inside the email then move through the search results, even across tabs, and closing the email returns you to your results rather than the dashboard.
On a phone: swipe a card right to toggle read, left to delete (always with a confirmation). Vertical scrolling always takes priority, and swiping is disabled while selecting.
Current version: V17.0 (August 8th 2026)
New in V17 — Monitoring health (watchdog): watches the monitoring itself and warns when an account stops being polled (failing / stalled / quiet), with its own ntfy topics kept completely separate from keyword alerts, and a topbar pill that only appears when something needs attention. Analytics tab: volume over time, hour-of-day distribution and top keywords / domains / senders / accounts, with range and source filters. Noise control: exclude terms and whole-word matching, applied only after a match is found so they can never cause a miss. VIP senders: flag important addresses or domains, with a badge on the card and a VIP filter on every tab. Duplicate collapsing: the same message reaching several accounts shows as one card you can expand. Saved views, multi-select bulk actions, swipe to read or delete on mobile, global search across every tab, and a mark-unread button in the email header.
Previously in V16: Email Body match tab with its own notifications · Leads Bucket with exclusions, dedupe, CSV/JSON export & import · per-channel match toggles (subject / attachment name / attachment content / body) · account editing that preserves your place in the mail stream · precise "where it matched" notifications · login brute-force protection · faster leads persistence for very large lists · numerous mobile layout and stat-card fixes.
This project was brought to life after the concept was initiated by MasonX0X, January 2026.
Rocinente — created the first stable version of this dashboard, February 2026 (kicked off as Domain monitor only). Not active.
MasonX0X — daily improvements & tweaks after proof of concept, to date (see this help section for all functions).
Alpha_Linux — appearance mods, multi-language keyword matching, project tester from version 1 to date. Active.
Almighty-Coded — attachment scanning feature & active tester.
Report any bug, improvement suggestion or request directly to support @Masonnx.
🔒 locks the portal instantly; the password unlocks it. While locked, monitoring continues at full speed — the lock screen even shows a live feed of what's being caught. Alerts, read-state, notes, reminders, leads and settings all survive restarts (stored in data/ on the server).
Each device that unlocks gets its own signed token, listed under Manage & Devices and revocable individually without disturbing your other devices. A separate export password guards every export and destructive bulk action.
Brute-force protection: repeated wrong passwords lock that IP address out temporarily, with the delay increasing on repeat attempts. The limiter reads the real client IP behind Cloudflare or a reverse proxy, so one attacker can't lock everyone else out.
Credentials never leave your server, and the dashboard only ever talks to your own monitor process.
Matches the From or To address, subdomains included. Cards keep all their data — remove a domain and its alerts return to the main sections.
| Company paying | Payment recipient | Handler | Amount | Due date | Status / note | Actions |
|---|
These topics ring your phone when a reminder is due, even with no browser open.
ceo@client.com) or a bare domain (client.com, subdomains included).:fx — paid keys don't; both are detected automatically.
Your key is stored on your server and never shown again after saving.Removing a device forces the portal password on its next visit. Your current device is marked.
New or unrecognized devices must enter the portal password before they can read or manage alerts. Live alerts remain visible (read-only) on the lock screen.
Update the password used to unlock this portal. You'll stay signed in on this device; the new password applies to future unlocks.
This password is required to export account files that include saved email passwords. Changing it here needs the current export password and does not affect portal login.
Personalize the name shown in the header, the browser tab, and the lock screen. Leave blank to reset to the default.
Set your dashboard's public address so tapping an ntfy notification on your phone opens that alert directly. Leave blank if you only monitor from the same machine.