User Manual
1. Getting Started • 2. Email Provider Compatibility • 3. Reading Email • 4. Composing Email • 5. Managing Email • 6. Quick Rules • 7. Spam & Malware Protection • 8a. Malware & Attachment Scanning • 8. Backup & Recovery • 9. Calendar • 10. Contacts & Rules • 11. Privacy & Security • 12. Keyboard Shortcuts • 13. Settings • 14. Troubleshooting
1. Getting Started
Creating Your First Account (IMAP/SMTP Settings, Test Connection)
Go to File → Add Email Account. Enter your IMAP/SMTP settings and use the Test Connection button to verify before saving.
App Password Setup for Yahoo, Gmail, AOL (2FA Required First)
Yahoo, Gmail, and AOL require app-specific passwords (not your regular password). Enable two-factor authentication on your account first, then generate an app password in your provider’s security settings.
Initial Sync (Newest 500 Messages First)
The newest 500 messages are fetched first for immediate access. Remaining messages sync in the background while you work.
Background Sync Progress
A progress indicator in the status bar shows sync progress with estimated time remaining.
Navigating the Interface (Three-Pane Layout)
The main window uses a three-pane layout: folders on the left, message list in the center, and reading pane on the right. Switch between Mail and Calendar views using the toggle buttons at the bottom of the folder pane.
2. Email Provider Compatibility
GravesMail works with any email provider that supports standard IMAP/SMTP access.
- Yahoo Mail — app-specific password required. Enable 2FA first.
- Gmail / Google Workspace — app-specific password. Enable 2-Step Verification.
- AOL Mail — app-specific password, same process as Yahoo.
- Outlook.com / Hotmail / Live — OAuth2 authentication. Enable IMAP in settings.
- IONOS / 1&1 — standard password, no app password needed.
- Proton Mail — requires paid plan (Plus or higher) with Proton Bridge running locally.
- iCloud Mail — app-specific password from appleid.apple.com.
- FastMail — app-specific password from Settings → Privacy & Security.
Large Mailboxes (10,000+ Messages)
- Two-phase sync: newest 500 messages fetched first, then background download
- Pause and resume at any time — progress is saved if you close the app
- Progress indicator in the status bar with estimated time remaining
3. Reading Email
Selecting Messages
Click a message in the message list to view it in the reading pane. The message is automatically marked as read when selected.
Reading Pane
Shows the message header (from, to, date, subject), spam analysis summary, message body, and attachment cards.
Opening Messages in a New Window
Double-click a message to open it in a separate pop-out reader window with its own toolbar (Reply, Forward, Archive, Delete, Junk, Flag, Print, Save As).
External Image Blocking
Remote images are blocked by default to prevent IP address tracking. Click “Load External Images” to show them. A warning explains that loading images may reveal your IP address to the sender.
Tracking Pixel Detection
GravesMail detects and strips invisible tracking pixels (1×1 images used by senders to track when you open an email). Click “Load Tracking Pixels” if you want to allow them. A warning explains this may send a read receipt to the sender.
External images and tracking pixels are independent controls — you can load one without the other.
Show Detailed Analysis
Click to expand a per-layer spam score breakdown showing each layer’s raw score and the threshold at which it alarms. Scores are never weighted or averaged together — each layer is judged against its own threshold (see Protection Layers).
Zoom
Use Ctrl+MouseWheel or the −/+ buttons in the status bar to zoom in and out. Press Ctrl+0 to reset zoom to 100%.
4. Composing Email
New message: Click Compose or press Ctrl+N.
Reply, Reply All, Forward
Reply (Ctrl+R) replies to the sender. Reply All (Ctrl+Shift+R) replies to all recipients. Forward (Ctrl+Shift+F) creates a new message with the original text and attachments.
Adding Recipients
Type directly in the To/CC/BCC fields, or click the contact picker button to browse your contacts.
Contact Auto-Complete
Starts suggesting after 2 characters. Learns from sent mail to improve suggestions over time.
Attachments
Click the Add Attachment button or use the file picker to attach files.
Priority
Set message priority to High, Normal, or Low.
Signatures
Your default signature is automatically appended. Edit via Settings → Edit Signature.
Encrypted Email (OpenPGP)
GravesMail supports OpenPGP, the open standard for end-to-end encrypted and signed email. You can exchange private mail with anyone who uses PGP on any mail system — Proton Mail, Thunderbird, gpg, and others — not just other GravesMail users.
Setting up your key
Open the PGP Key Manager (Tools → PGP Key Manager on desktop; Settings → PGP Keys on mobile) and choose Generate my key. Enter your name and email and pick an algorithm: Ed25519 / Curve25519 is recommended, and RSA-4096 is offered for maximum compatibility with older PGP software.
If you lose your secret key, every message ever encrypted to it becomes permanently unrecoverable — no one, including me, can recover it. After generating, use Back up secret key to save a password-protected backup (a .gmpgpbak file) somewhere safe, and remember the password.
Restoring a key. To bring a backed-up key onto a new or reinstalled device, use Restore secret key (right next to Back up). Pick your .gmpgpbak file and enter its password; GravesMail imports the key and confirms which key was restored by showing its identity and fingerprint. If the key is already present it simply refreshes it, with no duplicate. A wrong password gives a clear “incorrect password” message, and a file that isn’t a GravesMail backup is reported plainly — restore never fails silently.
Sharing and verifying keys
- Export public key shares your public key so others can encrypt to you.
- Import key (.asc) adds a contact’s public key.
- After importing, the manager shows the key’s fingerprint. Confirm it with the contact out-of-band — a call, or in person — then choose Mark verified. A verified key shows a green badge; an unverified key still works but stays flagged.
Keys are identified by fingerprint, not email. It is normal to have more than one key for the same address (an older and a newer one, or different types). Every action in the Key Manager — export, back up, use-for-signing, delete — acts on the key you have selected, so always select the exact key first. If you have several of your own keys, select one and choose Use for signing to set which signs your outgoing mail.
Linking a key to a contact
Open a contact and use its PGP keys section to Link a key from your keyring to that person, Unlink it (which only removes the link — the key stays in your Key Manager), or Verify it. Linking lets encryption to that contact just work without hunting through the Key Manager. A contact can have more than one key, and encryption goes to all of them. Linking a key does not turn encryption on — you still choose it per message.
Sending
In Compose, set the Security control to Sign, Encrypt, or Sign + Encrypt (recommended for private mail). It defaults to off, so ordinary mail is unaffected. If a recipient has a linked key on their contact, GravesMail uses it automatically once you choose to encrypt.
If you choose to encrypt but a recipient has no usable key, GravesMail stops and asks. It will never quietly send your message unencrypted. You can cancel, or explicitly choose “Send UNENCRYPTED” — a deliberate second step that names the at-risk recipients. There is no path through the app where choosing encryption silently produces a plaintext send.
When you send encrypted mail, GravesMail also encrypts it to your own key, so the copy in your Sent folder (and anything you move to Archive) stays readable by you. This is always on.
Reading
Encrypted mail is decrypted automatically and shows a closed padlock 🔒 and an Encrypted badge, in the message list and on the message itself, for mail received and sent. Unencrypted mail shows no icon, so the list stays uncluttered — the padlock’s presence means encrypted, its absence means not. Signed mail shows its signature status: verified key, unverified key, or, shown loudly, an invalid signature. A message encrypted to a key you don’t have on that device shows an explicit notice rather than a blank body.
Deleting a key
Select a key and choose Delete key. Removing a public-only (contact) key just forgets it — you can re-import it later. Removing one of your own secret keys is irreversible and makes any mail encrypted to it permanently unrecoverable, so GravesMail shows an escalated warning and asks you to confirm. Make sure you have a backup first.
What PGP does and does not protect
PGP encrypts the message body and attachments. It does not hide the subject line, the To/From/Cc, or when a message was sent — those travel in the clear. That is the same limit every PGP/MIME system has, including Proton.
PGP protects your mail in flight, from interception and from your mail provider. It is not an anti-forensics tool: once decrypted, mail is cached in GravesMail’s local encrypted database so you can search and read it offline.
GravesMail does not do automatic keyserver or WKD lookup and has no web-of-trust — you import and verify keys yourself. Inline clearsigned messages are shown as readable text but their signatures are not verified; GravesMail displays them rather than claiming a signature it hasn’t checked.
Interoperability. GravesMail’s PGP is verified in both directions against GnuPG, the reference OpenPGP implementation, for both Ed25519 and RSA-4096 keys, by an automated test suite. Proton Mail is confirmed as well — tested by hand, with real encrypted mail sent and read in both directions against a live Proton account. Thunderbird has not been tested for PGP specifically; it is a standard OpenPGP client and should work, but that isn’t claimed here.
Password-Protected Email (No Key Needed)
Use this when your recipient does not use PGP — which is most people. Tick Password-protect (no key needed) in Compose. Your message and all its attachments are sealed inside a real, standard AES-256 encrypted ZIP that the recipient opens with free, ordinary software on any platform — no GravesMail, no account, and no keys needed on their end.
Sending one
- Write your message and attach files as usual, then press Send.
- GravesMail asks you to set a strong password: at least 12 characters with lower-case, upper-case, two digits, and two symbols. A live checklist ticks off each rule as you type, and you enter it twice. Send is blocked until every rule is met and both entries match, so a weak password or a typo can never lock your recipient out.
- After the message goes out, GravesMail shows the password once with a Copy button.
- Share the password out-of-band — by phone, text, or encrypted chat. Never in the same email. GravesMail will not offer to email it for you, and never saves or sends it anywhere.
What goes out is one attachment, protected-message.zip. Your real message (as message.html) and every attachment are encrypted inside it; the visible email body contains only plain-language instructions for opening it. Attachment names are replaced inside the archive with neutral placeholders (attachment-01, attachment-02, …), and their real names live in an encrypted manifest the recipient sees after entering the password — so the names don’t leak either.
How your recipient opens it
These instructions are written into every protected email GravesMail sends, so your recipient always has them. It uses the industry-standard WinZip AES-256 (AE-2) format, proven to open with real standard archiver software and pinned to that format by automated test — so it is a genuinely standard file, not a GravesMail-only container.
Windows’ built-in ZIP support does not handle strong AES-256 encryption — it will look like it opens and then fail with an empty folder or an error. Use one of the free tools below instead.
- Windows — install 7-Zip from 7-zip.org (the official site only; “download portal” copies often bundle adware). Right-click the ZIP → 7-Zip → Extract Here, then enter the password. PeaZip is a clean alternative.
- macOS — the built-in Archive Utility is unreliable with AES-256. Install Keka or The Unarchiver (Mac App Store), open the ZIP with it, and enter the password.
- iPhone / iPad — install Password Zip (free) from the App Store.
- Android — install RAR by RARLAB (free) from Google Play.
After opening, open message.html in a web browser to read the message. Any files are listed there with their real names; on disk they sit next to message.html under the placeholder names, so rename each one to the real name shown.
GravesMail can also open a password-protected message it receives, in place, on every platform — if both people use GravesMail, no archiver is needed.
If the password is refused
It is almost always a typo introduced by a messaging app — smart quotes, auto-correct, a stray copied space, or wrong capitalisation. Retype it by hand exactly as the sender gave it.
Being honest about what this protects
The entire security is the password. Choose a good one and share it over a different channel than the email. There is no expiry and no “self-destruct” — those are unenforceable without a server, and GravesMail is local-first. The ZIP encrypts file contents, not the archive’s structure: anyone who intercepts the message can still see how many files are inside and their rough sizes and timestamps, though not their names or contents. And the email’s subject, To/From, and timing still travel in the clear, as with any email.
5. Managing Email
Moving messages: Right-click → Move to Folder, press Ctrl+M, or drag-drop on Windows.
Deleting: Press Delete or use the toolbar button. Messages move to Trash.
Flagging: Press Ctrl+Shift+G to toggle the flag.
Marking read/unread: Right-click → Mark as Read or Mark as Unread.
Archiving: Press Ctrl+E to move to the Archive folder.
Searching
Press Ctrl+F to focus the search box. Choose scope: All, Subject, From, or Body. Clear with the X button or press Escape.
Sorting
Sort by Date, From, Subject, Size, Importance, or Flagged. Click the direction arrow to toggle ascending/descending.
Conversation Threading
Use View → Group by Thread or press Ctrl+T. Expand/collapse thread groups to see all messages in a conversation.
6. Quick Rules — Intelligent Email Triage
Quick Rules are your own triage rules. Each rule catches matching messages and sets them aside, moves them, or deletes them. On the desktop each rule also gets its own button in the Quick Rules toolbar.
Spam is where the spam engine files unwanted mail. The Spam Trap is where your own Quick Rules set messages aside for later review instead of deleting them — open it with Review Spam Trap. Held describes attachments that were scanned and held back because they looked dangerous; those live in Held Attachments.
Your Rules Take Precedence Over the Spam Filter
A message matched by one of your Quick Rules is filed by your rule, before the spam filter can divert it. A sender you have written a rule for will not be wrongly sent to Spam even if the filter would have scored the message as junk. The filter still runs and still scores every message — you can see its verdict in Properties — it just doesn’t override where your rule files the message. The one exception is malware: the malware scan always wins, so a rule can never deliver a message with a dangerous attachment to your Inbox.
Creating a Rule
- Click “+” in the Quick Rules toolbar, or right-click a message → “Create Quick Rule from Message…” — which opens the editor already filled in from that sender and scans the message’s folder so existing matching mail is caught too, with a count of how many were applied
- Choose match type: sender address, sender domain, sender contains, subject contains, subject starts with
- Add multiple match values — paste comma/semicolon-separated lists or add individually
- Choose an action: send to the Spam Trap (review later), Move to folder, Delete permanently, or Auto-delete after X days (7–1,000)
- Choose whether the rule marks Legitimate or Spam mail. You must pick one — the editor won’t save until you do. This tells the spam filter how to learn from what the rule catches, and the filter learns best when shown clearly-labelled examples of both kinds of mail. A filter fed only spam, with no “this is legitimate” examples to weigh against, gets worse rather than better — which is why the choice is required.
- Enable “Auto-apply during sync” to catch matching messages before they reach your Inbox
Using Rules
- Select a message → click a rule button → the message is filed by that rule, and the sender is auto-added to it
- Right-click → Apply Rule → select which rule
- Each application to a new sender automatically adds that sender to the rule’s match list
Scanning Folders
- Right-click rule button → Scan Current Folder or Scan All Folders
- Right-click a folder → Scan with Rule → select rule
- Catches matching messages in bulk to reduce storage
Reviewing What Your Rules Caught
The Quick Rule Review window shows each rule’s caught messages and matched senders. The Filtered tab shows everything caught across all rules within a rolling time window — set it to 1, 6, 24 (the default), 48, 72, or 96 hours with the “Show filtered mail from the last” dropdown; your choice is remembered per device.
- Right-click rule button → Review to see that one rule’s catches
- Full message properties (Safe Preview, General, Headers, Spam Analysis, Attachments, URLs, Tracking Pixels, Body)
- Restore individual messages or all of them to their original folders (Restore is shown in green — recovering mail is a safe action)
- Delete individual messages or purge everything a rule caught
- Matched Senders tab: view, add, edit, remove match values
- The Rules, Filtered, and Spam review lists each have a search box that filters what’s shown as you type. Click a column header to sort; your sort choice is remembered per device.
Safe Preview — Read and Answer a Caught Message Without Restoring It
Open any caught message’s Properties — from the Filtered list or from Review Spam Trap — and the first tab is Safe Preview. It shows the message as it would look in your reading pane, but rendered safely: scripts and active content are neutered, tracking pixels are always blocked, and remote images load only if the sender is trusted. That lets you read a caught message and decide what it is without putting it back in your Inbox.
Safe Preview also has Reply, Reply All, and Forward buttons. You do not have to restore a caught message just to answer it — these open the normal compose window, pre-filled exactly as a reply or forward from the Inbox would be, with attachments available and the same encryption handling (you are never sent in plaintext to a contact you have set to always encrypt). The message stays where it is; your reply is a normal outgoing message.
Zoom applies to the preview too (the − / % / + controls at the bottom, or pinch-to-zoom on mobile). Safe Preview is a clean reading surface — the spam-reason breakdown lives on the Spam Analysis tab, not here. On mobile, tapping any caught message opens this Properties view directly with Safe Preview showing first.
Naming note: the cross-rule review previously called Today’s Catches (and the short Catches button) is now simply Filtered. Same list — only the name changed.
Managing Rules
- Right-click → Edit Rule, Disable/Enable Rule, Delete Rule
- Delete offers: Restore All to Inbox, Delete All Permanently, Cancel
- Disabled rules appear grayed out, don’t auto-apply but stay visible
Auto-Delete Expiry
- Configure auto-delete after 7–1,000 days
- Expired messages purged on startup and after sync
- Nearing-expiry messages highlighted in review
7. Spam & Malware Protection
GravesMail examines every message with seven independent Protection Layers. Each layer looks for a different kind of problem and decides on its own. If any single layer raises an alarm, the message is treated as spam — there is no averaging and no combined score that has to be reached. One alarm is enough (the “7-layer OR” model).
- Domain Validation — does the sender’s domain exist and have real mail servers? Is its TLD (.shop, .top, .click, .xyz) one commonly abused by spam?
- Bayesian Filter — a learned judgment of how spam-like the message’s words are. Ships pre-trained, then learns from what you teach it.
- Header Authentication — SPF, DKIM, and DMARC, the standard checks that prove a sender is who they claim to be.
- Heuristic Scoring — 41 detectors covering content and header patterns: disguised words (H0ME, S4LE), advance-fee and inheritance-scam wording, forged headers, date anomalies, and sender country of origin.
- Reputation — your safe and blocked lists, sender history, and cross-message campaign tracking that catches a spammer rotating sender domains while reusing the same originating server, payload host, or unsubscribe link.
- Malware: System AV — on Windows, your installed antivirus via AMSI (Defender, Norton, Bitdefender, Kaspersky, and others). Not available on macOS, Linux, or mobile, where it reports “not available” rather than a clean result it never produced.
- Malware: YARA — pattern rules scanning attachments and message bodies against community malware signatures. Detects trojans, ransomware, malicious macros, PDF exploits, and phishing documents. Every platform.
Tuning the Engine (Tools → Security Engine)
The Security Engine screen gives each of the seven layers its own sensitivity slider, from 0% to 100%. 0% turns a layer off; 100% is the most sensitive. You tune each layer on its own — there is no single global aggressiveness control. Changes take effect right away. The same screen shows:
- Malware Scanner Status — the live state of both malware layers, including which antivirus product is active on Windows and how many YARA rules are loaded.
- Country Policy — mark countries Safe or Threat for the geolocation check. Both lists start empty, so ordinary international mail is never penalized until you choose a policy.
- Detector Inventory — a read-only list of each layer’s detectors and how strongly each counts (Strong, Standard, or Weak).
Seeing Why a Message Was Sorted
Open a message’s Properties for a per-layer breakdown: each layer’s raw score, the threshold at which it alarms, and its state — Alarmed, Clean, or Not available. Not available is never shown as Clean.
Reviewing Spam
Spam → Review Spam shows messages the engine sorted as spam. This is separate from Review Spam Trap, which shows mail your own Quick Rules set aside.
Training the Filter
- Mark as Spam — moves the message to Spam, teaches the filter, and adds the sender and their domain to your blocked list.
- Mark as Not Spam — rescues the message and teaches the filter that mail like this is wanted.
- Block Sender — adds a sender to your blocked list without moving the message or teaching the filter.
Changing your mind is safe. If you mark a message Spam and later mark it Not Spam (or the reverse), GravesMail undoes the earlier lesson and applies the new one. Going back and forth settles on your final choice; it never piles up or drifts the filter’s accuracy.
Spam training is per device. GravesMail does not yet sync between your devices, so each device learns on its own — as does your blocked-sender list.
Safe Senders and Blocked Senders
Managed in Settings → Advanced Settings.
8a. Malware & Attachment Scanning
How It Works
Every attachment is scanned automatically during ingest using two engines:
- YARA Scanner — matches attachment bytes against community signatures covering malware families, ransomware, RATs, Office macro exploits, PDF exploits, and phishing documents. Works on all platforms.
- System AV — on Windows, submits each attachment to your installed antivirus via AMSI (Defender, Norton, Bitdefender, Kaspersky, Malwarebytes, CrowdStrike, and others are auto-detected). Not available on macOS, Linux, or mobile, where YARA does the scanning and the AV layer honestly reports “not available.”
What Happens on Detection
- Message is moved to the Malware folder (separate from Spam)
- Dangerous attachments are stripped from the message and held
- Attachment data is preserved locally — nothing is silently destroyed
- Message body is retained — you can see who sent it
- Full explanation shown in message properties: which rule triggered, which file was affected, and what action was taken
Held Attachments
Held Attachments (on the Tools menu; View Held Attachments from the Guard screen on mobile) shows every held item with date, filename, size, threat name, and scan engine, along with why it was held. You can save an item to disk if you trust it, or permanently delete it. Held items are kept until you decide — they are never lost silently.
Manual Scan
Right-click any attachment → Scan for Malware to run an on-demand scan. The result shows which engines were used and whether a threat was detected.
YARA Rule Updates
Settings → Update Rules Now downloads the latest signatures from the Neo23x0/signature-base community repository. Auto-update checks weekly by default (configurable 1–30 days). The app ships with an embedded baseline ruleset that works without an internet connection.
Rule sources include: ransomware families, APT toolkits, generic droppers and downloaders, malicious Office macros, PDF exploits, PowerShell cradles, web shells, and phishing document patterns.
8. Backup & Recovery
GravesMail automatically protects your whole profile with encrypted backups — not just your mail, but your contacts, calendar, rules, safe and blocked lists, tuned thresholds, sender reputation, trained spam filter, PGP keyring, and saved account credentials. Files that ship with the app and are replaced when you update (the geographic lookup table, the baseline spam model) are deliberately excluded.
Automatic Backups
- Full backups (a complete profile copy) and lightweight differentials (only what changed since the last full) — restoring a differential automatically walks back through the chain to the last full
- Pre-operation snapshot before any destructive operation (Quick Rules scan, purge, delete rule, clear trash)
- All backups AES-256 encrypted under a key GravesMail manages for you — no password needed day to day
- Runs silently in the background after the app loads — never blocks your work
- Forgiving of gaps: after a holiday or a laptop left closed for weeks, GravesMail takes one backup if one is due. It never tries to catch up with a flood of backups, and a long absence is never an error.
Recovery Passphrase (required — set once)
Automatic and manual device-local backups are sealed with a Backup Master Key the app manages. That key is stored only in wrapped form, and it is wrapped two ways: under your device’s secure keystore (so routine backups never prompt you) and under a recovery passphrase you choose (which opens the same backups on any machine, with no keystore involved). This is what makes these backups device-independent — earlier versions could only restore them on the machine that made them.
- GravesMail asks for the passphrase the first time you make a backup. It is required, not skippable — the backup will not complete until one is set, so you can never end up with backups you cannot recover.
- Because it is set at your first backup, a brand-new install has no automatic backups until you make that first one. Scheduled backups are quietly skipped until then rather than failing with an error.
- After it is set, backups run with no further prompt.
- It meets the same requirements as the backup password below, entered twice with the same live checklist.
- You can change it at any time from the Backup Manager. Changing it keeps all existing backups restorable.
Keep it safe — it cannot be recovered for you. Your recovery passphrase is the only way to recover device-local backups on a new or reset device. There is no reset link and no back door, by design. If you forget it and lose the device, those backups cannot be opened.
Portable Password Backup — the one you make yourself
This is the backup to keep if you might lose, replace, or migrate your device. Choose File → Portable Password Backup… (on mobile, Guard → Backup → Portable Password Backup), pick a password, and GravesMail writes a single password-sealed .gravesmail-backup file containing your entire profile — restorable on any device. Copy it somewhere safe off the device.
Choosing the password
Because this one file can rebuild your whole mailbox on a stranger’s machine, GravesMail asks for a genuinely strong password: at least 12 characters, including an uppercase letter, a lowercase letter, at least two digits, and at least two special characters. You will not have to guess at it — the dialog ticks each requirement off live as you type, and you enter the password twice. The Create button stays disabled until every requirement is met and both entries match, so a typo or a weak choice can never lock you out of your own backup. Long passphrases are welcome; there is no restrictive maximum. The password protects the file with PBKDF2-SHA256 key stretching at 600,000 iterations, recorded inside the file so future versions can still open today’s backups.
Without the password the file cannot be opened — not by me, not by anyone. There is no recovery path, which is the point. Store it somewhere you trust.
What travels with it
By default a Portable Password Backup also carries your existing backup history, so moving to a new device brings everything with it and nothing is left behind. This is opt-out: you can exclude the accumulated backups so only the current app data travels, or split the backup into two files — one for the app and its data, one for the backup history — and move them separately. Both files are labelled clearly.
Restoring
You can restore a Portable Password Backup on a fresh device from the first-run screen, before setting up any account. Restore first verifies the backup is complete and intact before touching anything you already have — a truncated or damaged file is refused, with your current data left untouched — then reports what came back, dataset by dataset. Restart GravesMail once when it finishes.
Restoring replaces everything currently in GravesMail on that device. On a new install there is nothing to lose; if you have already been using GravesMail there, its current data is overwritten.
Portable Password Backup replaces two older, overlapping options — a device-local manual backup and a separate Backup for Migration. They had converged into the same thing, so they are now one feature. As a result, old .gravesmail-migration files and pre-existing device-local manual backups are not restorable by this version — make a fresh Portable Password Backup. Your automatic daily backups are unaffected and still restore normally.
No Size Limit
GravesMail backs up and restores mailboxes of any size — tens or hundreds of gigabytes and beyond. Backup and restore stream from disk to disk, so a very large mailbox never has to fit in memory and there is no 2 GB ceiling. Large archives are stored without compression to keep them fast, so the file may be a little larger by design.
Backup Manager (Tools → Backup Manager)
- View all backups with dates, sizes, types
- Browse any backup’s contents instantly via metadata catalog
- Search across ALL backups for specific messages
- Compare backup with current database to find missing messages
- Selective recovery: check individual messages and recover just those
Recently Deleted Messages (Tools → Recently Deleted Messages)
- Every deleted message is captured with full body content
- Browse, search, and preview deleted messages
- One-click recovery to original folder — no backup file needed
- Retained for 90 days by default (configurable in Settings)
Backup Settings
Sensible defaults are already set; the Backup Manager exposes the controls if you want them.
- Schedule mode — choose Interval or Weekly. The two are mutually exclusive; only the one you pick is followed.
- Interval mode — automatic backups Off, Daily, Weekly, or a custom interval in hours, plus “full backup every N days” (the backups in between are differentials).
- Weekly mode — a seven-day grid, Monday to Sunday. Set each day to None, Full, or Differential in any combination. A Differential day with no earlier full to build on is automatically promoted to a full. If you switch to Weekly but leave every day set to None, GravesMail quietly falls back to your Interval schedule rather than leaving you with no backups — and keeps your grid exactly as you set it.
- Retention — how many full, differential, and pre-operation snapshot backups to keep. The minimum is 1; retention will never delete your only copy of something.
- Full Backup Now / Differential Backup Now — take an immediate device-local backup into GravesMail’s own history on this device. These are not the Portable Password Backup, which lives on the File menu.
- Deletion log retention — 30–365 days.
Changes take effect immediately and persist across restarts.
9. Calendar
Switching Views
Switch between Mail and Calendar views using the toggle at the bottom of the folder pane.
Monthly Calendar
Monthly calendar grid with day navigation. Click a date to see events for that day.
Creating and Editing Events
Click “+ New Event” to create an event. Double-click an existing event to edit it.
Meeting Invitations from Email
When GravesMail detects a calendar invitation (.ics attachment or VCALENDAR content), a green banner appears with Accept, Tentative, and Decline buttons. Accepted meetings are added to your calendar. Meeting links (Teams, Zoom, Google Meet, WebEx) are detected automatically.
Reminders
Events can include reminders that notify you before the event starts.
10. Contacts & Rules
Managing Contacts
Tools → Contacts opens the contact manager. Contacts support full business card fields: name, company, job title, multiple emails and phones, addresses, categories, and notes. Contacts can be exported to CSV.
Contact Auto-Discovery
Contacts are added automatically from people you send mail to and from message headers in your inbox. No manual entry needed for frequent contacts.
Importing Contacts
CardDAV (Yahoo, iCloud, Outlook.com): Tools → Contacts → Import CardDAV connects directly to your provider’s contact server using your stored IMAP credentials. Supported providers are detected automatically — no URL required.
.vcf File (Google Contacts, any provider): Tools → Contacts → Import .vcf File imports a vCard file. Use this for Gmail, which requires a manual export because Google does not allow direct CardDAV access without OAuth2.
How to export from Google Contacts:
- Go to contacts.google.com
- Click Export in the left sidebar
- Select “vCard (for iOS Contacts)”
- Click Export — a .vcf file downloads
- In GravesMail: Tools → Contacts → Import .vcf File
How to export from iCloud Contacts:
- Go to icloud.com and open Contacts
- Select all (Edit → Select All)
- Click the gear icon → Export vCard
- In GravesMail: Tools → Contacts → Import .vcf File
Duplicates are skipped automatically during import.
Creating Mail Rules
Tools → Mail Rules lets you create automatic rules. Rules can match on From, Subject, Body, To, attachments, and importance level. Actions include: Move to folder, Mark as read, Delete, Flag, and Set importance.
Quick Rules
See the dedicated Quick Rules section above for full details.
Signatures
Settings → Edit Signature lets you create a default email signature. Per-account signature overrides are also supported.
11. Privacy & Security
- Local-first — all mail stored on YOUR computer, not the cloud.
- Encrypted at rest — the whole database is encrypted: every message, subject, sender, and attachment, plus your contacts, calendar, rules, lists, filter training, and security settings.
- No cloud dependency — works fully offline with cached messages.
- Delete from server — optional, removes mail from provider after fetch.
- Credential encryption — your saved credentials and the database key are held in your device’s secure keystore: DPAPI on Windows, Keychain on macOS/iOS, Keystore on Android, the system secret store on Linux.
- Diagnostic logs — never record full email addresses or subjects.
- External images blocked by default — prevents IP tracking.
- Tracking pixels stripped by default — prevents read receipt tracking.
- Backups AES-256 encrypted — device-local backups under the app-managed Backup Master Key (recoverable elsewhere with your recovery passphrase); Portable Password Backups under a password you choose.
- Obfuscated code and encrypted training data in release builds.
- Opt-in telemetry only — Community Spam Intelligence is off by default. If enabled, only anonymized spam filter token scores are shared — never email content, addresses, or personal information. A random contributor ID with no connection to your identity is generated on opt-in. You can preview exactly what would be sent before enabling it. Toggle in Settings → Community → Share Spam Intelligence.
12. Keyboard Shortcuts
13. Settings
Account management: File → Add/Remove account.
Sync frequency.
Spam filter sensitivity — tuned per layer on the Security Engine screen, not here: each of the seven layers has its own 0–100% slider. There is no single global aggressiveness setting. See Protection Layers.
Delete from server toggle.
YARA Malware Scanning — enable/disable, update rules, auto-update interval.
Community Spam Intelligence (opt-in, off by default) — share anonymized filter scores to help improve detection for all users.
Backup frequency and retention.
Deletion log retention.
Storage management: message count, database size, clear trash/spam.
14. Troubleshooting
“Offline — showing cached messages”
Check your internet connection. GravesMail will sync when reconnected.
Messages not appearing after sync
Try Refresh (F5) or switch folders.
Compose saves to Drafts instead of sending
SMTP connection failed. Check your outgoing mail settings.
macOS: Right-click not working
System Settings → Mouse → enable “Click Right Side”.
High spam scores on legitimate email
Mark Not Spam, add to Safe Senders.
Quick Rule not catching
Check if disabled (grayed out). Verify Matched Senders tab.
Backup failed
Check disk space. Ensure no other instance of GravesMail is running.
Recently deleted message not found
Check deletion retention setting in Settings.
About
GravesMail v1.0.0
Developer: Luke Graves
Website: gravesmail.net
© 2026 Luke Graves. All rights reserved.