Skip to content

Repository files navigation

MoveMailbox — email migration, without the terminal. Local client and self-hosted worker powered by imapsync.

MoveMailbox

Your mail. A new home. A clear way there.

An IMAP migration tool with a browser UI, a local client and a separate hosted worker.

Website · Download candidate · Documentation · Русский

CI Preview Go toolchain Engine License status

Important

Release candidate, not a public-cloud launch. Real migrations work locally with imapsync and in controlled self-hosted deployments. The hosted API/worker is running in an invite-only pilot with verified HTTPS and worker egress. Public self-service still needs operational and launch gates. A separate website mockup is not proof of a live migration service.

Why MoveMailbox?

Start simply Stay in control Know what happened
Server name or IP, login and password Select folders and a destination subfolder Progress, counters and readable logs
Automatic TLS ports; local manual override Preview changes or run preflight-only modes Credential-free API job history
Browser UI throughout the migration Copy by default; confirm destructive mirror Tested recovery and documented limits
  • Built on imapsync: a UI, API and orchestration layer around the established engine.
  • Local or self-hosted: our infrastructure is not required.
  • Guest-first hosted design: no account wall for the planned free tier. Paid accounts, OAuth and billing remain roadmap work.
  • Operational depth: encrypted envelopes, durable queues, bounded retries, key rotation and metadata-backup drills.

Choose where it runs

Mode Available today Important
Windows ZIP with launchers and a local browser UI Install imapsync separately
Linux / macOS Native launcher with the same UI; amd64 and arm64 Install imapsync separately
Docker Pinned imapsync runtime and hardened Compose setup linux/amd64; private deployment first
Hosted worker Separate API/worker, guest ownership and quotas Closed pilot; public launch pending

The planned free hosted tier admits a whole source mailbox up to 5 GB, not the first 5 GB of a larger mailbox. Local use has no MoveMailbox cloud-size cap; provider quotas and machine resources still apply. See quota behavior, including mailbox growth during a transfer.

Get started

Windows

Download Windows amd64 → extract the ZIP → run START-DEMO.cmd.

Demo mode contacts no mail servers. For real work, install imapsync and run START-REAL.cmd. Administrator privileges are not required.

Linux & macOS

Extract the matching archive from v0.5.0-rc.1, then run:

./movemailbox --demo --open=true

Native archives do not bundle imapsync. Previews are not signed/notarized. Compare downloads with SHA256SUMS.txt and inspect BUILD-INFO.txt. Checksums verify a match to the published file, not an independent publisher signature.

From source

Go 1.25+ is required; go.mod pins the Go 1.27.0 toolchain.

git clone https://github.com/Anton-Babaskin/MoveMailbox.git
cd MoveMailbox
cd web
npm ci --ignore-scripts
npm run export
cd ..
go run ./cmd/mailbox-migrator --demo --open

Node 24 is needed only to build the existing interface. npm run export puts it in internal/web/out before Go embeds it; skipping this step produces an API-only build with no homepage. Open http://127.0.0.1:8080. For real work, install imapsync and omit --demo. Native release archives include the exported interface.

Docker / private deployment

docker compose up --build

Builds locally and binds the UI to 127.0.0.1:8080; it does not open a public service. For separate API/worker deployment, follow the worker guide.

Full setup · Configuration · VPS checklist

How mail moves

Hosted topology: browser to API over HTTPS; API submits encrypted credentials and commands to worker. Worker runs imapsync, reading source and writing destination over TLS. API metadata and encrypted worker queue have separate stores.

Mail passes through your computer or your worker server. The source does not push directly to the destination. The API creates credential envelopes; the worker holds the recipient private key. This is not browser-to-worker end-to-end encryption. In local mode, the UI and engine run on your machine.

Architecture · Credential boundaries

Migration controls

Control Behavior
Connection checks Verify authentication and TLS on both endpoints
Folder selection Choose source folders after discovery
Destination subfolder Group imports under a name such as Imported mail
Dry run Preview planned work without modifying mailboxes
Credentials / sizes / folders only Check logins, estimate volume or create folders without copying messages
Start / stop / progress Submit work, request cancellation and follow streamed events
Strict mirror Delete destination-only messages in relevant folders; explicit acknowledgement required

Caution

Strict mirror can permanently delete destination mail. Back up and inspect a dry run first. Destructive jobs are never automatically replayed after failure or interruption. Ordinary reruns still need verification; universal exactly-once delivery is not guaranteed across IMAP providers.

Reliability with evidence

Scenario tests — not benchmarks, certifications or an uptime guarantee.

Scenario Recorded evidence
Disconnect inside APPEND / lose the final acknowledgement Real IMAP fault-proxy drills; content and repeat-copy checks
API / worker restart Durable recovery, guest ownership and bounded retry checks
Worker disk full Bounded tmpfs tests; no false success during pending finalization
Mailbox grows after estimation Runtime whole-message quota rejection; overshoot limitation documented
Credential rotation Drained-queue guard; mismatched keys and stale tokens fail closed
Damaged or incomplete backup Archive validation, encrypted round trip and fresh-volume demo restore

Pilot evidence · Backup runbook · CI runs

Security, plainly

  • Verified IMAP certificate chains and peer names; no "ignore TLS errors" switch.
  • Hosted guest ownership, CSRF checks, limits and restricted public targets.
  • Credential-free API history; encrypted envelopes in the separate worker queue.
  • Passwords passed through imapsync's child environment, not command-line arguments.
  • Privileged host access can expose runtime secrets. Deletion does not securely erase WAL or backups.
  • Docker hardening is not a per-job container guarantee or a substitute for a firewall.

Found a vulnerability? Use private reporting, not a public issue. Never attach passwords, cookies, tokens or message content.

Documentation & project

I want to… Start here
Install or configure Getting started · Configuration
Understand the system Architecture · Worker
Operate a private pilot VPS · Backups
See what shipped / what is next Changelog · Roadmap
Report a bug or propose a change Support · Contributing
Continue on another computer Shared workflow · Handoff

Next milestones

  1. Closed VPS pilot: HTTPS, egress enforcement, monitoring, retention and real off-site restore.
  2. Commercial layer: verified email, magic links and payment entitlements without registration for free transfers.
  3. Broader compatibility: provider coverage, OAuth, signing and business workflows.

License & credits

The owner has not yet selected a license for MoveMailbox. Public source is not automatically open-source permission. Read licensing status before reusing or redistributing code.

imapsync is a separate project by Gilles Lamiral, under its own NO LIMIT PUBLIC LICENSE. Our third-party inventory does not relicense upstream software.


Created and maintained by Anton Babaskin

movemailbox.com · Built for the next home of your mail.

About

IMAP email migration with a browser UI. Local clients, self-hosted workers, encrypted credentials and tested recovery. Powered by imapsync. Preview.

Topics

Resources

Contributing

Security policy

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages