About Mail Mantis
A small, honest tool for people who send email from their own domain and want to know where it lands.
Why it exists
When you start sending from a new domain, Gmail has no history to go on. The usual advice is to send a few normal emails to people who will open and reply, check where they land, and fix authentication when they land in Spam. Doing that by hand means juggling an SMTP account, several Gmail tabs and a spreadsheet.
Mail Mantis puts that loop in one private dashboard. It deliberately stops short of automation: there are no schedules, no auto-replies and no message moving. Every send and every reply is a person’s decision, so what you measure is how Gmail treats a real sender.
Architecture
The dashboard is a static page that calls a single POST /api/app endpoint with an action. The API stores everything in Postgres and is the only part that talks to SMTP, Gmail and Gemini. Placement is found by searching the seed inbox for the exact Message-ID that was sent and reading its labels: SPAM, INBOX, and the tab category.
Tech stack
Security & privacy
- Single admin. Passwords are hashed with PBKDF2-SHA256 (310,000 rounds). Sessions use random tokens stored as hashes, in an
HttpOnly,SameSite=Strictcookie. Login attempts are rate-limited per IP. - Secrets encrypted at rest. SMTP keys, Google refresh tokens, the Gemini key and the OAuth client secret are encrypted with your
APP_ENCRYPTION_KEY. API responses never return them. - Narrow mailbox use. Placement checks only look up one message. Moving an email out of spam, marking it important, adding filters and sending replies only happen when you click.
- No telemetry. Your instance talks only to your database, your SMTP provider, Google’s Gmail and OAuth endpoints, and Gemini if you enable it.
- Not indexed. Dashboard pages send
noindexheaders and arobots.txtthat disallows crawling.
FAQ
Will this get my email into the inbox?
No tool can promise that. Mail Mantis shows you where mail lands and gives you a calm way to send real, varied emails and replies. Authentication (SPF, DKIM, DMARC), a reputable SMTP provider, and real recipients who engage matter most.
Does it send or reply automatically?
No. Every email and every reply is sent by you pressing Send. Placement checks run automatically while the dashboard is open, and they are read-only.
Can I use it for outreach or newsletters?
No. It sends one email at a time to inboxes you own and connect with Google. It has no lists, imports or campaigns.
Which inboxes are supported?
Gmail and Google Workspace (Google sign-in), Outlook.com and Microsoft 365 (Microsoft sign-in), and Yahoo, iCloud, AOL or any IMAP inbox with an app password. The sender can be any SMTP provider on ports 587 or 465.
Do I need Gemini?
No. You can write the business brief and every email and reply yourself. Gemini only saves time.
Credits
Built by David Karuri. Released under the MIT license. Fonts: Geist and Geist Mono by Vercel and basement.studio, under the SIL Open Font License.