Your mail. A new home. A clear way there.
An IMAP migration tool with a browser UI, a local client and a separate hosted worker.
Important
Release candidate, not a public-cloud launch. Real migrations work locally with imapsync and in controlled self-hosted deployments. The hosted API/worker is running in an invite-only pilot with verified HTTPS and worker egress. Public self-service still needs operational and launch gates. A separate website mockup is not proof of a live migration service.
| Start simply | Stay in control | Know what happened |
|---|---|---|
| Server name or IP, login and password | Select folders and a destination subfolder | Progress, counters and readable logs |
| Automatic TLS ports; local manual override | Preview changes or run preflight-only modes | Credential-free API job history |
| Browser UI throughout the migration | Copy by default; confirm destructive mirror | Tested recovery and documented limits |
- Built on imapsync: a UI, API and orchestration layer around the established engine.
- Local or self-hosted: our infrastructure is not required.
- Guest-first hosted design: no account wall for the planned free tier. Paid accounts, OAuth and billing remain roadmap work.
- Operational depth: encrypted envelopes, durable queues, bounded retries, key rotation and metadata-backup drills.
| Mode | Available today | Important |
|---|---|---|
| Windows | ZIP with launchers and a local browser UI | Install imapsync separately |
| Linux / macOS | Native launcher with the same UI; amd64 and arm64 | Install imapsync separately |
| Docker | Pinned imapsync runtime and hardened Compose setup | linux/amd64; private deployment first |
| Hosted worker | Separate API/worker, guest ownership and quotas | Closed pilot; public launch pending |
The planned free hosted tier admits a whole source mailbox up to 5 GB, not the first 5 GB of a larger mailbox. Local use has no MoveMailbox cloud-size cap; provider quotas and machine resources still apply. See quota behavior, including mailbox growth during a transfer.
Download Windows amd64 → extract the ZIP → run START-DEMO.cmd.
Demo mode contacts no mail servers. For real work, install imapsync and run START-REAL.cmd. Administrator privileges are not required.
Extract the matching archive from v0.5.0-rc.1, then run:
./movemailbox --demo --open=trueNative archives do not bundle imapsync. Previews are not signed/notarized. Compare downloads with SHA256SUMS.txt and inspect BUILD-INFO.txt. Checksums verify a match to the published file, not an independent publisher signature.
Go 1.25+ is required; go.mod pins the Go 1.27.0 toolchain.
git clone https://github.com/Anton-Babaskin/MoveMailbox.git
cd MoveMailbox
cd web
npm ci --ignore-scripts
npm run export
cd ..
go run ./cmd/mailbox-migrator --demo --openNode 24 is needed only to build the existing interface. npm run export puts it
in internal/web/out before Go embeds it; skipping this step produces an API-only
build with no homepage. Open http://127.0.0.1:8080. For real work, install
imapsync and omit --demo. Native release archives include the exported interface.
docker compose up --buildBuilds locally and binds the UI to 127.0.0.1:8080; it does not open a public service. For separate API/worker deployment, follow the worker guide.
Full setup · Configuration · VPS checklist
Mail passes through your computer or your worker server. The source does not push directly to the destination. The API creates credential envelopes; the worker holds the recipient private key. This is not browser-to-worker end-to-end encryption. In local mode, the UI and engine run on your machine.
Architecture · Credential boundaries
| Control | Behavior |
|---|---|
| Connection checks | Verify authentication and TLS on both endpoints |
| Folder selection | Choose source folders after discovery |
| Destination subfolder | Group imports under a name such as Imported mail |
| Dry run | Preview planned work without modifying mailboxes |
| Credentials / sizes / folders only | Check logins, estimate volume or create folders without copying messages |
| Start / stop / progress | Submit work, request cancellation and follow streamed events |
| Strict mirror | Delete destination-only messages in relevant folders; explicit acknowledgement required |
Caution
Strict mirror can permanently delete destination mail. Back up and inspect a dry run first. Destructive jobs are never automatically replayed after failure or interruption. Ordinary reruns still need verification; universal exactly-once delivery is not guaranteed across IMAP providers.
Scenario tests — not benchmarks, certifications or an uptime guarantee.
| Scenario | Recorded evidence |
|---|---|
| Disconnect inside APPEND / lose the final acknowledgement | Real IMAP fault-proxy drills; content and repeat-copy checks |
| API / worker restart | Durable recovery, guest ownership and bounded retry checks |
| Worker disk full | Bounded tmpfs tests; no false success during pending finalization |
| Mailbox grows after estimation | Runtime whole-message quota rejection; overshoot limitation documented |
| Credential rotation | Drained-queue guard; mismatched keys and stale tokens fail closed |
| Damaged or incomplete backup | Archive validation, encrypted round trip and fresh-volume demo restore |
Pilot evidence · Backup runbook · CI runs
- Verified IMAP certificate chains and peer names; no "ignore TLS errors" switch.
- Hosted guest ownership, CSRF checks, limits and restricted public targets.
- Credential-free API history; encrypted envelopes in the separate worker queue.
- Passwords passed through imapsync's child environment, not command-line arguments.
- Privileged host access can expose runtime secrets. Deletion does not securely erase WAL or backups.
- Docker hardening is not a per-job container guarantee or a substitute for a firewall.
Found a vulnerability? Use private reporting, not a public issue. Never attach passwords, cookies, tokens or message content.
| I want to… | Start here |
|---|---|
| Install or configure | Getting started · Configuration |
| Understand the system | Architecture · Worker |
| Operate a private pilot | VPS · Backups |
| See what shipped / what is next | Changelog · Roadmap |
| Report a bug or propose a change | Support · Contributing |
| Continue on another computer | Shared workflow · Handoff |
- Closed VPS pilot: HTTPS, egress enforcement, monitoring, retention and real off-site restore.
- Commercial layer: verified email, magic links and payment entitlements without registration for free transfers.
- Broader compatibility: provider coverage, OAuth, signing and business workflows.
The owner has not yet selected a license for MoveMailbox. Public source is not automatically open-source permission. Read licensing status before reusing or redistributing code.
imapsync is a separate project by Gilles Lamiral, under its own NO LIMIT PUBLIC LICENSE. Our third-party inventory does not relicense upstream software.
Created and maintained by Anton Babaskin
movemailbox.com · Built for the next home of your mail.