--- id: netease-youdao/LobsterAI/imap-smtp-email version: "642b7681" license: MIT install: manual updated: 2026-07-28 --- # imap-smtp-email — This skill enables agents to connect to IMAP-compatible email servers for reading, searching, and retrieving messages. It provides core email access capabilities for building intelligent workflows that interact with standard email protocols and inbox management tasks. Publisher: netease-youdao · Stars: 5704 · Updated: 2026-07-28 Install (manual): `git clone https://github.com/netease-youdao/LobsterAI` ## SKILL.md # IMAP/SMTP Email Tool Read, search, and manage email via IMAP protocol. Send email via SMTP. Supports Gmail, Outlook, 163.com, vip.163.com, 126.com, vip.126.com, 188.com, vip.188.com, and any standard IMAP/SMTP server. ## Important: Configuration is Pre-configured The `accounts.json` configuration file is automatically managed by LobsterAI Settings (邮箱设置). Legacy `.env` configuration is still supported as a fallback for older users. **Do NOT ask the user to create or edit these files — just run the commands directly.** If credentials are wrong, the scripts will return a clear error message; only then should you inform the user to check their email settings. The configuration files are located in this skill's directory (same folder as this SKILL.md file). The scripts load them automatically via absolute paths, regardless of the current working directory. Use the provided scripts as the only email transport interface. Do not write temporary IMAP/SMTP scripts, do not use raw sockets, OpenSSL, `net`, `tls`, or alternate mail clients, and do not inspect `.env`, `accounts.json`, or script source unless the official command output explicitly reports missing configuration and the user asks you to diagnose it. If an official command fails or times out, report that command result and suggest checking LobsterAI Settings; do not implement a fallback protocol client. Do not claim that `node-imap`, `nodemailer`, or another dependency is broken unless an official script or verified stack trace proves it. A successful command means the configured email account works; a timeout means the current command timed out, not that the dependency is defective. Command results intentionally redact account metadata. In user-facing replies, use the redacted account label/email from the JSON result and do not repeat full configured email addresses unless the user explicitly asks for the exact address. Email content fields such as sender, subject, and message body may still be shown when they are the requested result. Never ask the user to send an email authorization code, app password, account password, or other credential in chat. If an account is disabled, incomplete, or has invalid credentials, ask the user to enable or update it in LobsterAI Settings > Email Settings, then rerun the official command. For multi-account setups: - Run `node scripts/imap.js accounts` or `node scripts/smtp.js accounts` to list configured account IDs without exposing secrets. - Omit `--account` to use the default enabled account. - Pass `--account ` to use a specific account. - Pass `--all-accounts` only for read/list commands that support fan-out (`check`, `search`, `list-mailboxes`). - JSON results for read/list commands include `success`, redacted account metadata, `command`, `count`, and result arrays such as `messages` or `mailboxes`. For sending email, always review recipient, subject, sender account, and body with the user first. Sending is blocked unless `--confirmed` is passed. For SMTP send results, `success: true` means the sending SMTP server accepted the message for processing. Do not claim final delivery or inbox receipt. Report it as "submitted to the SMTP server" and mention that the recipient provider may still reject it later via a bounce message. If `rejected` or `pending` recipients are present, call them out explicitly. Never use a redacted account email such as `ab***@example.com` as a recipient address. If the user asks to send to another configured email account, use that account's `id` with `--to-account ` so the script resolves the real address internally without exposing it. ## Configuration Reference Create `.env` in the skill folder or set environment variables: ```bash # IMAP Configuration (receiving email) IMAP_HOST=imap.gmail.com # Server hostname IMAP_PORT=993 # Server port IMAP_USER=your@email.com IMAP_PASS=your_password IMAP_TLS=true # Use TLS/SSL connection IMAP_REJECT_UNAUTHORIZED=true # Set to false for self-signed certs IMAP_MAILBOX=INBOX # Default mailbox # SMTP Configuration (sending email) SMTP_HOST=smtp.gmail.com # SMTP server hostname SMTP_PORT=587 # SMTP port (587 for STARTTLS, 465 for SSL) SMTP_SECURE=false # true for SSL (465), false for STARTTLS (587) SMTP_USER=your@gmail.com # Your email address SMTP_PASS=your_password # Your password or app password SMTP_FROM=your@gmail.com # Default sender email (optional) SMTP_REJECT_UNAUTHORIZED=true # Set to false for self-signed certs ``` ## Common Email Servers | Provider | IMAP Host | IMAP Port | SMTP Host | SMTP Port | |----------|-----------|-----------|-----------|-----------| | 163.com | imap.163.com | 993 | smtp.163.com | 465 | | vip.163.com | imap.vip.163.com | 993 | smtp.vip.163.com | 465 | | 126.com | imap.126.com | 993 | smtp.126.com | 465 | | vip.126.com | imap.vip.126.com | 993 | smtp.vip.126.com | 465 | | 188.com | imap.188.com | 993 | smtp.188.com | 465 | | vip.188.com | imap.vip.188.com | 993 | smtp.vip.188.com | 465 | | yeah.net | imap.yeah.net | 993 | smtp.yeah.net | 465 | | Gmail | imap.gmail.com | 993 | smtp.gmail.com | 587 | | Outlook | outlook.office365.com | 993 | smtp.office365.com | 587 | | QQ Mail | imap.qq.com | 993 | smtp.qq.com | 587 | **Important for 163.com:** - Use **authorization code** (授权码), not account password - Enable IMAP/SMTP in web settings first ## IMAP Commands (Receiving Email) ### accounts List configured email accounts without exposing passwords. ```bash node scripts/imap.js accounts ``` ### check Check for new/unread emails. ```bash node scripts/imap.js check [--limit 10] [--mailbox INBOX] [--recent 2h] node scripts/imap.js check --all-accounts [--limit 10] ``` Options: - `--account `: Use a specific configured account - `--all-accounts`: Check every enabled account - `--limit `: Max results (default: 10) - `--mailbox `: Mailbox to check (default: INBOX) - `--recent