Mason Portal

This device isn't recognized. Enter the portal password to continue.
Live monitoring · read-only while locked
🔒 Unlock to view activity.
Alerts keep arriving in the background. Unlock to read, manage, or configure.
🔒
Licence inactive
Your data has not been deleted. Every account, alert, note and lead is exactly where you left it, and will be here when the licence is restored.
Please contact support to restore access.
Mason Email Intelligence
connecting…
💼 Add to Jobs at hand
Pick a company or type a new one. Domains are stored, not addresses — a job belongs to the company.
📘 Instructions — set up and run Mason ×

Work through these in order. The first section is the only one that is urgent — everything after it can be read as you go. Sections are ordered from most to least important.

🔐 1. FIRST LOGIN — do this before anything else

Your system ships with default passwords. Change both of them now, before you add a single mailbox. Until you do, anyone who finds your address can open the dashboard and read every alert in it.

a. Change the portal password — this is the one on the lock screen.

The default is admin. Go to Manage & Devices → Security → Portal password, enter the current password, then your new one twice. You are signed out of other devices when it changes, which is intended — sign back in with the new password.

b. Change the export password — this is a second, separate password.

The default is export. Change it under Manage & Devices → Security → Export password. It is deliberately not the same as the portal password, because it guards the things that would hurt most if they leaked: downloading your accounts with their mailbox passwords, revealing webmail logins, exporting the leads bucket, and registering a device for biometric unlock. Make it different from the portal password and keep it somewhere safe — you will be asked for it rarely, which is exactly why people forget it.

c. Check the licence shows active — the key pill at the top of the screen should read licence active.

d. Optional but recommended — turn on biometric unlock. Under Manage & Devices → Biometric unlock, press Register this device. You will be asked for the export password once, then your fingerprint, face or device PIN. After that you unlock with a touch instead of typing. Register a second device too, so losing one is never a lockout. Your passwords always keep working.

One thing that catches people out: passkeys are tied to the exact web address you registered on. Always reach the dashboard by the same address.

📬 2. Add your mailboxes

Go to Manage & Devices → Accounts → Add account. For each mailbox you need the email address, the mailbox password, and the IMAP host — usually something like imap.yourprovider.com on port 993 with SSL.

Press Test before saving. A green result means the login worked and the folders were read; if it fails, the message tells you whether it was the host, the port or the credentials.

Two things worth knowing. Gmail and Outlook accounts with two-factor authentication need an app password, not your normal one. And monitoring is forward-only — mail that arrived before you added the mailbox is never scanned, so add accounts before you need them, not after.

The account list is searchable, and each account can be given a group name so you can filter by client or by region later.

🔑 3. Keyword monitor — your main engine

This is the general monitor and the one you will live in. It watches every mailbox you have added and raises an alert the moment one of your keywords appears.

Add keywords under Manage & Devices → Keywords. Think in terms of the words a real enquiry contains: quotation, purchase order, proforma, RFQ, tender, the product names you sell.

Where it looks. Four separate channels, each switchable under What to match on:

Subject line — the fastest and least noisy. Start here.
Attachment filename — catches Purchase Order 8841.pdf even when the email says nothing.
Inside attachments — PDFs, Word, Excel, HTML, CSV and text files are opened and their text is read.
Email body — the widest net, and the noisiest. Body hits get their own Email Body tab so they do not bury your Inbox and Sent tabs.

Where results appear. Inbox for mail you received, Sent for mail you sent, Email Body for body-only matches. An email that matches in two ways appears in both places — that is deliberate, not a duplicate.

🌐 4. Domain monitor — only for partners you already trade with

This engine is not a second keyword monitor, and it is not for prospecting. It watches specific domains and alerts you on every email exchanged with them, regardless of content. It exists for companies you have already started doing business with — an active client, a supplier mid-order, a freight agent on a live shipment — where you want nothing from them to be missed, whatever it says.

Keep it small. This is the important part. The domain engine is far heavier than the keyword engine: it examines every message in every folder of every mailbox attached to it, rather than looking for a short list of words. The more mailboxes you attach, the more work every polling cycle does, and the slower everything becomes — including your keyword alerts.

Rule of thumb: attach only business-active mailboxes to the domain monitor. The one or two boxes where live trade actually happens — sales, orders, operations. Do not attach archive boxes, personal boxes, catch-all boxes, or mailboxes you added "just in case". Every extra one costs you speed for no benefit.

Adding a mailbox to it. In Manage & Devices → Accounts, press ⇒ DM on the account you want. You will be asked which domains to watch — enter the domain only, like client.com, and subdomains are covered automatically. Separate several with commas. The copy will not proceed without at least one domain, because a domain-monitored mailbox with no domains watches nothing and tells you nothing.

Adding a mailbox by hand. You do not have to copy one across. In the Domain tab open Manage & Devices → Accounts → Add account and enter the mailbox exactly as you would for the keyword monitor: email address, mailbox password, IMAP host, port 993 with SSL. Press Test first. Then add the domains you want watched under Watched domains in the same panel — domain only, like client.com, one per line or comma separated. A mailbox with no domains attached watches nothing.

Watching one address instead of a whole domain. Enter a full address — john@gmail.com — and only that mailbox is caught, not everyone else at that provider. This is how you follow a contact who uses Gmail, Outlook or Yahoo, where watching the domain itself would flood you. Domains and addresses can be mixed freely in the same list.

The Account–domain map shows which domains belong to which mailbox. Check it after adding, so you can see the link was recorded.

Watching one address instead of a whole domain. Enter a full address — john@gmail.com — and only that mailbox is watched, not everyone else at that provider. This is how you follow a contact who uses Gmail, Outlook or Yahoo, where watching the domain itself would flood you. Domains and addresses mix freely in the same list.

Remove finished business — this is not optional housekeeping. The moment a deal is closed, an order is delivered or a partner goes quiet for good, delete that mailbox from the domain monitor and remove its domains. Every mailbox left attached keeps costing you scanning time on every cycle, forever, for a relationship that has ended. A domain monitor that only ever grows will eventually slow the whole system down. Prune it the same week the business finishes.

🔔 5. Getting alerted when you are not looking

The dashboard is not something you have to sit and watch. Set up the alerts and let it come to you.

Phone push (recommended). Install the free ntfy app, invent a private topic name that nobody could guess, and enter it under Manage & Devices → Notifications for each tab you care about. Alerts are pushed the instant they are found, day and night, whether or not any browser is open — this runs on the server, not in your browser.

Choose your topic name like a password. Anyone who knows it can read your alerts.

Browser notifications. Press the 🔔 icon at the top of the screen to allow them. These only work while the dashboard is open in a tab.

Sound. Each tab has a speaker icon to mute it. Right-click the speaker to preview the chime.

The watchdog. Give it its own ntfy topic. It tells you when a mailbox stops working — a changed password, an expired app password, a provider blocking the connection. This is the alert that matters most, because a silent mailbox looks exactly like a quiet one.

📖 6. Working through alerts

Tap a card to open the email. From the open card you can:

Translate the whole message, or highlight a passage and translate just that.
Move it to another folder on the mail server — a real move, visible in your webmail.
Note — attach a note or a reminder to the email, and jump back to the email from the note later.
⏰ Remind — set a reminder about this email in one tap; it defaults to tomorrow morning.
💼 Log job — record the business in this email in Jobs at hand.
✏️ beside the webmail address — correct that mailbox's webmail URL without leaving the email.
Webmail login — reveal the credentials for that mailbox when you need to reply properly.
Ignore domain — stop that sender's domain from generating future alerts.
Previous / Next to move through the list without closing.

On a phone or tablet, swipe left and right on the open email to move between messages, and swipe a card in the list to mark it read or delete it.

Marking an email read in Inbox or Sent also marks the same message read in the Email Body tab, so you never process the same email twice.

💼 7. Jobs at hand — your work log

A ledger of the business actually in flight: who is paying, who is receiving, who is handling it, how much, and when it is due. It is a record you keep — nothing here affects monitoring.

Logging a job from an email. Open the email and press 💼 Log job in the header. Mason reads the companies straight off the message and offers them: by default the other company pays and yours receives, and either can be changed before saving. Companies are stored as domainsacme.com, not sales@acme.com — because the job belongs to the company, not to whoever happened to send that email. The Cc line is offered too, which is usually where the agent or freight forwarder appears.

Three fields are required and the job will not save without them: assigned handler, amount and due date. A row you cannot chase is not worth keeping. Your last handler and currency are remembered, so the next job is faster.

Working the list. Each row has:

✓ Paid — the business went through. It stops counting towards value in play.
✕ Failed — it did not go through. Kept for the record, and asks first.
↩ Reopen — put a closed job back in flight.
— set an EXTRA reminder at a time of your choosing. You do not need one for the deadline itself: every ongoing job rings on its own due date automatically, at 9am, through the same 24/7 push. A job marked paid or failed stops chasing you.
— jump back to the email the job came from.
✏️ edit · 🗑 delete.

The due-invoice alarm. The Jobs at hand card on the dashboard watches your deadlines for you. It turns amber when something falls due within three days and red once anything is late, with a count on the corner and a line naming the worst one — "late.com · 4d late · USD 12,500" — so you know what to chase without opening the tab. Overdue always wins over due-soon: if something is late, that is what you are shown. The colour stays visible with Power saver on and for reduced-motion users; only the pulse stops.

The four figures at the top. Ongoing, successful, failed, and the total value still in play — counted per currency, and counting only ongoing jobs, because money already paid or written off is not money you are waiting on.

Due dates colour themselves as they approach: amber within three days, red once overdue with the number of days late. Filter by status, search across company, handler and note, and export the whole log to CSV for your accountant.

You can also log a job that did not arrive by email — press + New job and fill it in directly.

Adding a job by hand. Press + New job for business that did not arrive by email. The company fields let you pick from a list or simply type — enter newclient.com, or paste sales@newclient.com and it is reduced to the company for you.

Choosing the companies. The two dropdowns list every address on the message — sender, recipients and Cc — each labelled with the role it played, so you can tell sales@acme.com from accounts@acme.com at a glance. You pick by address; what gets saved is the domain, because the job belongs to the company. Companies already in your log are offered underneath, so a repeat job is two taps.

Backing it up. ⬆ Export saves the whole log as JSON and ⬇ Import restores it — the same pattern as the other tabs. Importing MERGES: rows already present are updated rather than duplicated, so importing the same file twice is safe. ⬇ CSV is the spreadsheet version for your accountant. The log lives in data/jobs.json, and unlike alerts it is data you typed rather than data that can be fetched again — so include it in whatever backup you keep.

🌍 8. Translation — reading mail in any language

Mason can translate an email into your language, either the whole message or just a passage you highlight. Both buttons sit at the bottom of the open email.

You need your own DeepL API key. Translation is not included with Mason — it uses your DeepL account, so the characters are yours and nothing passes through us.

Getting a key

1. Go to deepl.com and sign up for a free API account — the developer one, not the website subscription.
2. Copy the authentication key it gives you. A free key ends in :fx; Mason detects that automatically, so there is nothing else to configure.
3. Paste it into Manage & Devices → Translation and save.

The free allowance, and what to do when it runs out. A free DeepL API account currently comes with 1,000,000 characters in total — that is a one-time allowance, not a monthly one. It does not reset. Older free accounts were 500,000 characters per month instead, so check which kind yours is on DeepL's usage page.

When the allowance is gone, translation simply stops and Mason tells you the quota is exhausted — nothing else breaks and no mail is missed. You then have two choices: register another free DeepL API account and paste in the new key, or take a paid DeepL subscription if you translate constantly and would rather not keep swapping keys.

Keeping the characters for what matters. A long HTML email can be tens of thousands of characters. If you only need the gist of one paragraph, highlight it and use Selection rather than translating the entire message — it costs a fraction as much. Mason also skips translating an email that is already in your language, so nothing is spent on those.

You can see what is left at any time in Manage & Devices → Translation, which reads the usage figure straight from DeepL.

🔇 9. Cutting the noise

A monitor that cries wolf gets ignored. Three tools, in the order you should reach for them:

Ignore domains. Newsletters, no-reply senders, your own suppliers' marketing. Ignored mail is not deleted — it is filed quietly in the Ignored tab and never pushed to your phone.

Noise control. Exclude terms that appear in mail you do not want, and switch on whole words only so bid stops matching forbidden. These rules only ever suppress an alert that was already found; they can never cause a missed email.

VIP. The opposite tool — make the important things louder. Flag senders and keywords so their cards stand out. VIP keywords match whole words only, in any language including Arabic and Chinese.

🧲 10. The leads bucket

Every address seen on a matched email is collected automatically into Leads, with the date first seen and where it came from. Export it as CSV whenever you want it. Addresses you never want collected go in the leads exclusion list.

Leads are still collected from ignored domains. Ignoring a domain means "do not interrupt me", not "pretend this contact does not exist".

💾 11. Backups — do not skip this

Use Export in the Inbox/Sent and Domain panels to download your accounts, keywords, domains, VIP lists and noise rules. Keep the file somewhere off the server. Import restores it onto a fresh install.

Exports that include mailbox passwords ask for the export password. Treat that file exactly like a password list — it is one.

Take a fresh export whenever you make a meaningful change: a batch of new accounts, a keyword overhaul, a new set of watched domains.

📱 12. Devices, tablet mode and appearance

Devices. Every signed-in device is listed under Manage & Devices. Revoke any you do not recognise, and revoke a device the moment it is lost.

How emails open. Under Manage & Devices, each tab can open its email in the reading pane (a split view beside the list, on wide screens) or a pop-up. This is now set per device: your desktop can use the pane while your phone uses the pop-up, and changing one no longer changes the other. On a wide monitor the reading pane uses the full screen rather than a centred column.

Tablet mode. Under Appearance → Layout. Turn it on when using a tablet: it fits the email view to the screen, gives you the compact tab strip, and enables swipe. Phone and desktop are unaffected — the setting applies to the device you switch it on.

Power saver. Under Appearance → Power saver, and on automatically on phones and tablets. It removes blurred backgrounds and looping animations, which are what make a device run warm. Purely visual — alert checking, sounds, notifications and the refresh all continue exactly the same.

Biometric unlock. Register a device under Manage & Devices to unlock with a fingerprint or face instead of typing. Registering needs the export password, so only you can add one, and passwords always keep working.

Appearance. Themes, light and dark, and effects. In a dark theme, PDFs and documents are shown dark too. Cosmetic only; nothing here changes what is monitored.

⚠️ 13. Limits worth knowing before you ask

Forward-only. Mail that arrived before an account or keyword was added is never scanned.
Scanned PDFs. A photographed or scanned page contains no text, so its contents cannot be matched — the filename still can.
Very large emails. Attachments inside messages over 15 MB skip content scanning.
Deleted mail. If a message is moved or deleted on the server, opening its card searches your other folders for it, including Trash. Only a permanently purged message is truly gone.
Keep the domain monitor lean. If the dashboard feels slow, this is the first place to look.

Clear the monitor regularly — around 6,000 cards. Alerts are kept until you remove them, and they live in memory. On a 4 GB RAM VPS, roughly 6,000 cards is the point to start clearing; leave it far beyond that and the server begins to struggle and the dashboard slows for everyone using it.

Use Clear viewed to drop everything you have already read, or Clear oldest… to remove a chosen number of the oldest cards. Export first if you want a record. The counter in each tab header tells you where you stand, and the dashboard warns you as the total climbs. A bigger VPS raises the number — the rule of thumb is per 4 GB of RAM.

🆘 14. If something looks wrong

No alerts arriving. Check the mailbox is still connected in Manage & Devices, and that the tab is not muted. Then check the watchdog topic — a failing mailbox reports itself.

Alerts on screen but nothing on the phone. The ntfy topic is missing or misspelt for that tab.

Too many alerts. Turn body matching off first, then add exclude terms, then ignore the domains behind the noise.

Everything feels slow. Two causes, in order. First, too many mailboxes attached to the domain monitor — remove any whose business has finished. Second, too many stored cards: on a 4 GB VPS start clearing at about 6,000, using Clear viewed or Clear oldest.

Locked out. Your passwords always work even when biometrics are registered. If you have lost the portal password, it can be reset on the server.

📖 Mason's Dashboard — Complete Guide ×
🎯 What Mason Operation Dashboard does

Mason watches every configured mailbox around the clock, checking for new mail every 30 seconds. An alert is raised the moment a monitored keyword appears in any of four places: the subject line, an attachment's filename, inside an attachment (PDF, Word, Excel, HTML, CSV and plain-text files are opened and their text is scanned), or the email body itself. Matching is case-insensitive and tolerant of encoded or oddly-split subjects — if the keyword is there, it is caught.

Each of those four channels can be switched on or off independently under Manage & Devices → What to match on. Body matches get their own Email Body tab so the Inbox/Sent tabs stay focused on subject and attachment hits; an email that matches both ways appears in both places.

Limits to know: mail that arrived before a keyword or account was added is not scanned (monitoring is forward-only), scanned/photo PDFs contain no readable text so their contents can't be matched (their filename still can), and attachments inside very large messages (over 15 MB) skip content scanning.

📚 Complete feature list — every function in this suite

A full index of what the suite can do, tab by tab. Everything listed here is available in the current build.

📥 Inbox & 📤 Sent keyword monitoring

  • Polls every account every 30 seconds; unlimited keywords, shared by both tabs.
  • Matches on subject, attachment filename, attachment content and email body (each toggleable).
  • Content scanning reads PDF, DOCX, XLSX, DOC, XLS, HTML, HTM, CSV and TXT — including files sent with no filename, identified by content type and magic bytes.
  • Forward-only: only mail arriving after setup is scanned, so you are never flooded with history.
  • Per-card read/unread state shared across all your devices; counters for total, unread and read.
  • Search, filter by read state, filter by account, and mark-all-read for the current filter.
  • Clear viewed, clear a chosen number of oldest cards, or clear all.
  • CSV export of alerts; unlimited card storage with a configurable warning threshold.
  • Mute per tab, with a chime you can preview (right-click the speaker).

🌐 Domain monitoring

  • Watch specific sender/recipient domains rather than keywords, on their own accounts.
  • Same card, search, filter, export and clearing tools as the keyword tabs.

📝 Email Body matches

  • A dedicated tab for keywords found in the message text, kept separate from subject/attachment hits.
  • Its own push-notification switch and ntfy topics, independent of the other tabs.
  • Full parity with the keyword tabs: counters, search, filters, mark-all-read, clearing, CSV, reading modal.

🎯 Leads Bucket

  • Automatically collects every sender, recipient and Cc address seen across keyword and domain alerts.
  • Stored independently of alerts — leads survive even after you delete the cards they came from.
  • Deduplicated automatically: a repeat address updates its sighting count instead of adding a row.
  • Exclusion keywords skip an address when any part of it — the name or the domain — contains the word; other addresses on the same email are still collected.
  • Your own monitored mailboxes are never collected as leads.
  • Add addresses manually, remove individually (with confirmation), deduplicate on demand, or delete everything (export password required).
  • Search by address, name or account; filter by role (sender/recipient/Cc/manual) and by source.
  • Export as JSON or CSV with the full record preserved, and import to merge without overwriting.
  • Summary stats: total leads, distinct domains, senders, recipients and top domains.

📖 Reading a message

  • Full message viewer with inline images, CC recipients and highlighted keyword hits.
  • Attachments listed with icons and sizes; View opens in-browser, Save downloads.
  • Previews PDF, Office documents, images, HTML and text — including files sent with no filename.
  • One-click translation of the whole message, or select any text for an instant pop-up translation (DeepL).
  • Next/Previous navigation between cards without leaving the viewer.
  • Ignore a sender's domain straight from the footer, with the option to exclude it from the Leads Bucket too.

🚫 Ignored

  • Domains you have ignored are filed here instead of your main tabs — nothing is deleted.
  • Push notifications are suppressed for ignored domains; clear them separately at any time.

🔍 Search

  • Search across every stored alert by text, field, account and date range.
  • Recent searches remembered; results open in the same reading viewer.

📝 Notes & ⏰ Reminders

  • Server-stored notes shared across all your devices.
  • Reminders with quick chips, snooze and acknowledge, an on-screen banner, browser notification and phone push — the server pushes even with the browser closed.

⚙️ Manage & Devices

  • Add, edit and remove monitored accounts; test credentials before saving; reveal stored credentials behind a password.
  • Editing an account keeps its place in the mail stream — changing only the address resets it for a fresh start.
  • Choose which channels raise alerts (subject / attachment name / attachment content / body).
  • Per-tab ntfy push topics, a test-push tool, and a dashboard URL for tap-through links.
  • DeepL translation key and target language.
  • Import/export of accounts, keywords, domains and notes, protected by an export password.
  • Device list for everything that has unlocked the dashboard, with individual revoke.
  • Storage warning threshold for stored cards.

🎨 Appearance

  • Light and dark themes plus multiple finishes, including Liquid Glass with a shade picker.
  • Many stat-card display types and card styles; accent colours per section with dozens of presets, plus your own saved presets.

🔒 Security

  • Password-protected lock screen with signed per-device tokens you can revoke individually.
  • Login rate limiting to block brute-force attempts, aware of Cloudflare/proxy client IPs.
  • Separate export password guarding every export and destructive bulk action.
  • Credentials never leave your server; the dashboard talks only to your own monitor process.
🏠 Home — Inbox & Sent alerts

Two live feeds: mail received by your accounts and mail sent from them, each card showing who, what, when, which keyword hit, and where it hit (subject / attachment name / attachment content). Cards arrive in real time — no refresh needed.

Above each list: a search box, read/unread filter, account filter, and “✓ All read” which marks everything currently matching your filters as read in one click. Click any card to open the full email.

Clearing tools sit in each panel header: Clear viewed, Clear oldest… (choose how many of the oldest cards to drop) and Clear all. ⬇ CSV exports the current feed, and the speaker icon mutes that tab (right-click it to preview the chime).

Keyword matches found in the message body no longer appear here — they have their own 📝 Email Body tab. An email that matches both ways shows up in both places.

⌨️ Keyboard shortcuts

On the Home and Domain tabs (when not typing in a box):

j / k — move the highlight down / up the list
Enter — open the highlighted email
r — mark it read / unread
i — open it and jump straight to the ignore-domain picker
s — switch the highlight between Inbox and Sent (Home tab)

In the email viewer: ← / → move to the previous / next alert, ↑ / ↓ scroll the open message, Esc closes.

📧 The email viewer

Opens the full message safely (links open in a new tab; nothing runs). Inline images, CC recipients and highlighted keyword hits are all shown; body hits appear in the header beside the subject hits.

Footer buttons: 📝 Note saves a note about this email — pre-filled and permanently linked back to it. 🚫 Ignore domain silences a sender's whole domain, and then asks whether that domain should also be excluded from the Leads Bucket (answer No to keep collecting its addresses). 🗑 Remove deletes the alert. ← / → walk through your alerts without closing, and ↑ / ↓ scroll the open message.

Attachments are listed with type icons and sizes. View previews in-browser — PDF, Word, Excel, HTML, text and images — including files sent with no filename, which are identified by their content type and magic bytes. Save downloads the original.

Translation: translate the whole message with one click, or simply select any text in the message for an instant pop-up translation (needs a DeepL key in Manage).

🌐 Domain monitor

Separate from keywords: add whole domains (e.g. rival-bank.com) and get an alert whenever any mail arrives from them, keyword or not. Same cards, filters, viewer, clearing tools, CSV export and “All read” as the Home tab.

Domain accounts are managed separately from keyword accounts, and every address seen on a domain alert also feeds the Leads Bucket.

🚫 Ignored senders

Domains you've ignored stop raising alerts, but their mail isn't lost — it's collected in the Ignored tab so you can audit what's being filtered and un-ignore a domain at any time. Push notifications are suppressed for ignored domains, and you can clear ignored cards separately from your main feeds.

When you ignore a domain from the email viewer you're also offered the option to exclude it from the Leads Bucket — choose Yes to stop collecting its addresses and remove any already stored, or No to ignore the alerts only.

📝 Email Body matches

Keywords found in the text of the message get their own tab, so your Inbox and Sent feeds stay focused on subject and attachment hits. Both the plain-text and HTML versions of the body are read (HTML tags are stripped first, so you match what a human sees, not markup).

If an email matches on the body and on the subject or an attachment, you get a card in both places — one here and one in the originating tab — each tracked separately for read state and deletion.

The tab has everything the keyword tabs have: counters, search, read and account filters, mark-all-read, the clearing tools, CSV export and the full email viewer. It also has its own push-notification switch and its own ntfy topics, so you can silence body alerts without touching the others — cards still collect quietly while it's off.

Body matching is switched on and off under Manage & Devices → What to match on.

🎯 Leads Bucket

Every sender, recipient and Cc address seen on a keyword or domain alert is collected here automatically, as a compact list built to hold very large numbers of contacts. Leads are stored independently of your alerts, so they remain even after you delete the cards they came from.

Addresses are deduplicated automatically — seeing one again updates its sighting count rather than adding a second row. Your own monitored mailboxes are never collected.

Exclusion keywords skip an address when any part of it — the name before the @ or the domain — contains one of your words. It is strictly per address: if a sender is excluded, the recipients on that same email are still collected. Adding a word also removes matching leads already stored. The list is kept alphabetical and tucked into a collapsible section; the add box sits below it.

Tools: search by address, name or account; filter by role (sender / recipient / Cc / manual) and by source; add addresses by hand; remove one with a confirmation; Deduplicate to merge any mixed-case duplicates from imports; and Delete all, which requires your export password.

Export & import: download as JSON or CSV (both password-protected, with the full record preserved), and import to merge a bucket back in without overwriting what you already have.

Email subjects are deliberately not stored, to keep the file small enough for very large lists.

📝 Notes — images, timers, linked emails

Notes live in the Notes tab; the floating ✏️ button (bottom-right) opens a quick-note popup from anywhere. Both support:

📷 Images — attach up to 4 (or just paste a screenshot straight into the text box). Click a thumbnail to view full-size.
⏰ Timer — set a date & time and the note becomes a reminder: banner, ring, browser notification and phone push when due.
📧 Linked email — notes created from the viewer's 📝 button carry a chip that reopens the original email.

Pin 📌, edit ✏️, copy ⧉ or delete 🗑 from each note card.

⏰ Reminders & phone push

Standalone reminders with quick chips (+1h, +3h, tomorrow…). When one is due you get the on-screen banner and ring, a browser notification, and — if you set an ntfy topic in the panel — a push straight to your phone, 24/7, even with the browser closed (the server does the pushing). Snooze or acknowledge from the banner.

⚙️ Manage — accounts & keywords

Add mail accounts (address + app password), toggle inbox/sent checking per account, and maintain the keyword list. New keywords take effect on the next 30-second poll — no restart. Keywords match as substrings: invoice also hits REINVOICED.

Editing an account keeps its place in the mail stream, so changing a label, host, port, folder, webmail URL or password will not re-scan old mail. Changing the email address itself points the account at a different mailbox, so it starts fresh from that moment. Leave the password blank when editing to keep the stored one.

What to match on — four independent switches decide which channels may raise an alert: subject, attachment name, attachment content and email body. Turning one off only stops it raising alerts; it never changes which mail is scanned, and forward-only behaviour is unaffected. At least one must stay on.

Notifications — set ntfy topics per tab (Inbox, Sent, Domain, Email Body and Reminders), send a test push to verify delivery, and set your dashboard URL so notifications open the right card when tapped.

Translation — add your DeepL key and target language here.

Import / export — accounts, keywords, domains and notes can be exported and re-imported; every export and destructive bulk action is protected by your export password. Devices lists everything that has unlocked the dashboard, each revocable individually.

🎨 Appearance & effects

The 🎨 button opens themes (dozens, incl. 4 signature typographic ones and Liquid Glass with its own shade picker), accent colors, summary-card styles and motion toggles — including the card entrance animation if you prefer things perfectly still. 🌙 flips light/dark.

Accent colors can be set per section — Inbox, Sent, Domain, Email body, Leads, Notes and Reminders — either from dozens of ready-made presets or with the individual color pickers. Save your own combination as a named preset, and hide any built-in presets you never use.

Stat cards have several display types and card styles. Whichever you choose, every figure stays on one line and remains fully readable up to six digits and beyond.

🩺 Monitoring health — the watchdog

Everything else in this suite watches your mail. This watches the monitoring. An account can stop being polled without any error you would notice — an expired app password, a renamed folder, IMAP throttling — and the matching engine keeps working perfectly while that mailbox is invisible.

Three states: Failing means polls are erroring (the IMAP error is shown). Stalled means polls are not even being attempted. Quiet means polls succeed but nothing has matched for a long time, which is how an empty or renamed folder looks. Accounts you have switched off are never flagged.

The threshold scales with your account and worker counts, so a deep but healthy poll queue is never mistaken for a fault. A pill appears in the topbar only when something needs attention — if you cannot see it, nothing is wrong.

Watchdog notifications use their own ntfy topics, deliberately separate from keyword alerts, so you can be told when monitoring breaks without turning on any keyword push. If no topic is set there, no watchdog push is sent and the panel tells you so. The watchdog is read-only and runs in its own thread — it can never affect polling or matching.

📊 Analytics

Alert volume over time, stacked by source, plus the hour of day alerts tend to arrive (converted from UTC to your local time). Range 7 / 30 / 90 days, filterable to a single source.

Top drivers lists the keywords, domains, senders and accounts producing the most alerts — useful for spotting a keyword that fires constantly and is never opened, which is a candidate for an exclude term.

🔇 Noise control & ⭐ VIP senders

Noise control suppresses alerts you have already caught. Exclude terms drop an alert if the term appears anywhere in the scanned text. Whole words only stops "bid" matching inside "forbidden".

These rules run after matching and are purely subtractive — they can only ever remove an alert that was already found, never change what gets scanned. If a rule is misconfigured it simply suppresses nothing. The master switch keeps your terms while turning the rules off entirely.

VIP senders flag important addresses (ceo@client.com) or whole domains (client.com, including subdomains). Their alerts get a ⭐ badge, and every tab has a VIP filter. This is presentational only — it never affects whether an email is caught.

⧉ Duplicate collapsing

The same email reaching several monitored accounts raises one alert per account. With collapsing on, those share a single card tagged "seen on N accounts". Click the tag to expand the group and see every copy separately.

Marking a collapsed card read, or deleting it, applies to all the alerts it stands for — the count on the button tells you how many. Tab counters always show every stored alert, never the collapsed count.

Two alerts only share a card when their Message-ID, subject, sender and matched keywords are all identical. Some bulk mailers reuse one Message-ID across different emails, so matching on it alone could hide a real message. Nothing is ever deleted or hidden without a way to expand it.

🔖 Saved views, ☑ multi-select & 🔎 global search

Saved views store a filter combination as a one-tap chip above the alert list. Tap to apply, tap again to clear. Editing a filter by hand deselects the chip, so the highlight never lies about what you are looking at. Views sync across your devices.

Multi-select (☑ Select) lets you tick several cards and mark them read or unread, or delete them together. Under duplicate collapsing the bar shows both figures — "2 selected (4 alerts)".

Global search (🔎 in the topbar) searches every tab at once, or one tab at a time. Previous / Next inside the email then move through the search results, even across tabs, and closing the email returns you to your results rather than the dashboard.

On a phone: swipe a card right to toggle read, left to delete (always with a confirmation). Vertical scrolling always takes priority, and swiping is disabled while selecting.

👥 Credits & Version

Current version: V17.0 (August 8th 2026)

New in V17 — Monitoring health (watchdog): watches the monitoring itself and warns when an account stops being polled (failing / stalled / quiet), with its own ntfy topics kept completely separate from keyword alerts, and a topbar pill that only appears when something needs attention. Analytics tab: volume over time, hour-of-day distribution and top keywords / domains / senders / accounts, with range and source filters. Noise control: exclude terms and whole-word matching, applied only after a match is found so they can never cause a miss. VIP senders: flag important addresses or domains, with a badge on the card and a VIP filter on every tab. Duplicate collapsing: the same message reaching several accounts shows as one card you can expand. Saved views, multi-select bulk actions, swipe to read or delete on mobile, global search across every tab, and a mark-unread button in the email header.

Previously in V16: Email Body match tab with its own notifications · Leads Bucket with exclusions, dedupe, CSV/JSON export & import · per-channel match toggles (subject / attachment name / attachment content / body) · account editing that preserves your place in the mail stream · precise "where it matched" notifications · login brute-force protection · faster leads persistence for very large lists · numerous mobile layout and stat-card fixes.

This project was brought to life after the concept was initiated by MasonX0X, January 2026.

Rocinente — created the first stable version of this dashboard, February 2026 (kicked off as Domain monitor only). Not active.
MasonX0X — daily improvements & tweaks after proof of concept, to date (see this help section for all functions).
Alpha_Linux — appearance mods, multi-language keyword matching, project tester from version 1 to date. Active.
Almighty-Coded — attachment scanning feature & active tester.

Report any bug, improvement suggestion or request directly to support @Masonnx.

🔒 Lock, unlock & safety

🔒 locks the portal instantly; the password unlocks it. While locked, monitoring continues at full speed — the lock screen even shows a live feed of what's being caught. Alerts, read-state, notes, reminders, leads and settings all survive restarts (stored in data/ on the server).

Each device that unlocks gets its own signed token, listed under Manage & Devices and revocable individually without disturbing your other devices. A separate export password guards every export and destructive bulk action.

Brute-force protection: repeated wrong passwords lock that IP address out temporarily, with the delay increasing on repeat attempts. The limiter reads the real client IP behind Cloudflare or a reverse proxy, so one attacker can't lock everyone else out.

Credentials never leave your server, and the dashboard only ever talks to your own monitor process.

🎨 Appearance ×
🖼️ Theme
🗂️ Summary card style
🔢 Stat display type
🎨 Accent presets
🎚️ Custom accent colors
📥 Inbox
📤 Sent
🌐 Domain
📄 Email body
💼 Jobs at hand
🎯 Leads
⚙️ Manage & Devices
📝 Notes
⏰ Reminders
Saved presets appear in 🎨 Accent presets above, and can be deleted from there.
🔋 Power saver
Turns off blurred backgrounds and looping animations, which are what make a phone or tablet run warm. On automatically on phones and tablets. It is purely visual — alert checking, sounds, notifications and the 30-second refresh all keep running exactly the same.
📐 Layout
Keeps the full desktop layout — same sizes, same density, same columns. It only stops the open-email window from overflowing the screen, so the bottom of the message and the action bar stay in view. Applies to this device only.
✨ Motion & effects
🖥️ Focus mode — press F or Esc to exit
📥 Inbox keywords
00 unread
0 active0 issues
📤 Sent keywords
00 unread
0 active0 issues
🌐 Domain monitor
00 unread
0 active0 issues
💼 Jobs at hand
0
0 paid0 failed
📝 Email body
00 unread
0 active0 keywords
🎯 Leads bucket
00 domains
0 senders0 excluded
⚙️ Manage & Devices
0
0 active0 devices
📝 Notes & Reminders
0due now
0 upcoming0 notes
⏰ DUE
🌐 Translator
not set up
0 used0% of quota
📥
Inbox Monitor
Subject & attachment keywords in incoming mail
0
Total
0
Unread
0
Read
Inbox alerts 0
No inbox alerts yet.
📤
Sent Monitor
Subject & attachment keywords in sent mail
0
Total
0
Unread
0
Read
Sent alerts 0
No sent alerts yet.
🚫
Ignored Domains
Keyword alerts involving these domains are filed here — no sound, no push
Domains to ignore 0
Domains being ignored 0

Matches the From or To address, subdomains included. Cards keep all their data — remove a domain and its alerts return to the main sections.

📥
Inbox — Ignored
Filed quietly, fully viewable
Cards 0
Nothing ignored.
📤
Sent — Ignored
Filed quietly, fully viewable
Cards 0
Nothing ignored.
📄
Body — Ignored
Filed quietly, fully viewable
Cards 0
Nothing ignored.
🌐
Domain Monitor
Watches every folder for mail from your domains
0
Total
0
Unread
0
Read
0
Domains
Setup
Domain alerts 0
No domain alerts yet.
📝
Email Body Matches
Keywords found in the message text — separate from subject & attachment hits
0
Total
0
Unread
0
Read
0
Keywords
🔔 Body alert notifications
Turn off to stop push notifications for body matches only. Cards still appear here — the other tabs are unaffected.
📱 Mobile push · ntfy 0
Body alerts 0
No body matches yet.
🎯
Leads Bucket
Every sender & recipient seen across keyword and domain monitoring — kept even after cards are deleted
0
Leads
0
Domains
0
Senders
0
Recipients
🚫 Exclusion keywords 0 click to expand
Leads 0
EmailName RoleSource Last seen
No leads yet.
💼
Jobs at hand
Your work log — who is paying, who is receiving, who is handling it, and when it is due
Company payingPayment recipientHandler AmountDue dateStatus / noteActions
📝
Notes
Jot things down — saved across your devices
Your notes 0
No notes yet.
Reminders
Get pinged on your phone when they're due — 24/7
Quick set:
Upcoming & past 0
No reminders yet.
📱 Reminder push · ntfy 0

These topics ring your phone when a reminder is due, even with no browser open.

📊
Analytics
Volume, timing and what's driving your alerts
Range Source
Overview
📈 Alerts over time
🕐 When alerts arrive hour of day
🏆 Top drivers
👤
Keyword Accounts
Shared by Inbox & Sent monitoring
🩺 Monitoring health
Watches the monitoring itself, not your mail. An account can stop being polled without any error you'd notice — an expired app password, a renamed folder, IMAP throttling — and the engine would go on working perfectly while that mailbox is invisible. Failing means polls are erroring. Stalled means polls aren't even being attempted. Quiet means polls succeed but nothing has matched for a long time, which is how an empty or renamed folder looks.
🔔 Watchdog notifications 0 separate from keyword alerts
Flag as failing after failed polls · warn if no alert for days (0 = off)
Accounts 0
Connected accounts 0 ok0 off
Add account
Watched keywords 0 applies to both inbox & sent
Keywords being watched 0
🎯 What to match on applies to inbox & sent
Choose which parts of each email a keyword may match. Turning a channel off only stops it from raising alerts — it never changes which mail is scanned, and only mail arriving from now on is ever matched (existing mail is never re-scanned).
🔇 Noise control applied after matching
These rules only ever suppress an alert that was already found — they never change what gets scanned or caught. If a rule is misconfigured it simply suppresses nothing, so noise control can never cause a missed email.
If any of these appears anywhere in the scanned text, the alert is dropped. Case-insensitive.
🔐 Biometric unlock this device
Use Face ID, Touch ID, a fingerprint or Windows Hello instead of typing passwords. The key is created inside this device and never leaves it — the server only stores the public half and checks the signature. Adding a device requires the export password, so only you can enrol one. Your passwords always keep working as a fallback.
🔗 Body cards read state only
An email that matches in the subject and in the body produces a card in both places. With this on, reading it in Inbox/Sent also marks the same message's Body card read — matched by account, folder and UID, so it is never a different email. Nothing is deleted or hidden, and it never works the other way round: reading a Body card leaves the Inbox/Sent card untouched.
⭐ VIP senders & keywords priority flag only
Alerts are flagged so they stand out in the list — by sender, or by a keyword appearing on the card. Neither ever affects whether an email is caught; they only badge alerts that were already found.
A full address (ceo@client.com) or a bare domain (client.com, subdomains included).
0
Any card whose subject, sender, attachment filename or message body contains one of these is flagged. Whole words only — “order” won’t flag “reorder” or “borders”. Works in any script: Arabic (including الـ and بـ prefixes, harakat and tatweel), Chinese and Japanese (which have no word spaces), and accented Latin however it’s encoded. Case-insensitive; phrases like “purchase order” are fine.
🖥️ How emails open desktop only
On a wide screen a tab can either open messages in a reading pane beside the list, or as a popup over it. Choose per tab. Phones and narrow windows always use the popup, whatever is set here.
⧉ Duplicate collapsing display only
The same email reaching several monitored accounts raises one alert per account. With this on, those are shown as a single card tagged with how many accounts saw it. Nothing is deleted — the tab counters and stored-card totals still count every alert, and marking one read or removing it applies to the whole group.
Emails render in their own sandboxed frame, so your theme doesn't reach them by itself — which is why some messages show a white block on a dark theme. With this on, message backgrounds and text are forced to your current theme's colours (not black — whichever theme you're using), while images, logos and photos keep their real colours. Trade-off: an email's own brand colours are overridden. Turn it off to see mail exactly as the sender designed it.
🏷️ Account groups 0 filter only
Tag accounts by client, region or brand, then filter any tab to just that group. Type a new name to create a group, or pick an existing one. This is purely a dashboard filter — it never affects polling, matching or what gets caught.
📱 Keyword match push · ntfy Inbox & Sent scopes
Pushed when a keyword matches in a monitored mailbox — Inbox and Sent only. Domain and Email Body have their own topics on their own tabs, and monitoring failures use the separate Watchdog topics in Monitoring health.
🗄️
Alert Storage
Card storage is unlimited — nothing is ever dropped automatically. Set when the memory warning should appear.
⚠️ Memory warning threshold
When any section's stored cards reach this number, the warning banner appears (with quick clear actions). Cards are never removed automatically — use "Clear oldest…" / "Clear viewed" / "Clear all" to manage space.
🌐
Translation
Translate foreign-language emails to English with one click while reading
🔑 DeepL API key
Get a free key at deepl.com/pro-api (free tier: 500,000 characters/month). Free keys end in :fx — paid keys don't; both are detected automatically. Your key is stored on your server and never shown again after saving.
Checking…
Translate into:
🛡️
Security & Devices
Recognized devices for this portal
Trusted devices 0
No devices yet.

Removing a device forces the portal password on its next visit. Your current device is marked.

Portal lock

New or unrecognized devices must enter the portal password before they can read or manage alerts. Live alerts remain visible (read-only) on the lock screen.

🔑 Change portal password

Update the password used to unlock this portal. You'll stay signed in on this device; the new password applies to future unlocks.

🔐 Change export password

This password is required to export account files that include saved email passwords. Changing it here needs the current export password and does not affect portal login.

🏷️ Dashboard name

Personalize the name shown in the header, the browser tab, and the lock screen. Leave blank to reset to the default.

📲 ntfy click-through URL

Set your dashboard's public address so tapping an ntfy notification on your phone opens that alert directly. Leave blank if you only monitor from the same machine.

Reminder due