Mason watches every configured mailbox around the clock, checking for new mail every 30 seconds. An alert is raised the moment a monitored keyword appears in any of four places: the subject line, an attachment's filename, inside an attachment (PDF, Word, Excel, HTML, CSV and plain-text files are opened and their text is scanned), or the email body itself. Matching is case-insensitive and tolerant of encoded or oddly-split subjects — if the keyword is there, it is caught.
Each of those four channels can be switched on or off independently under Manage & Devices → What to match on. Body matches get their own Email Body tab so the Inbox/Sent tabs stay focused on subject and attachment hits; an email that matches both ways appears in both places.
Limits to know: mail that arrived before a keyword or account was added is not scanned (monitoring is forward-only), scanned/photo PDFs contain no readable text so their contents can't be matched (their filename still can), and attachments inside very large messages (over 15 MB) skip content scanning.
A full index of what the suite can do, tab by tab. Everything listed here is available in the current build.
📥 Inbox & 📤 Sent keyword monitoring
🌐 Domain monitoring
📝 Email Body matches
🎯 Leads Bucket
📖 Reading a message
🚫 Ignored
🔍 Search
📝 Notes & ⏰ Reminders
⚙️ Manage & Devices
🎨 Appearance
🔒 Security
Two live feeds: mail received by your accounts and mail sent from them, each card showing who, what, when, which keyword hit, and where it hit (subject / attachment name / attachment content). Cards arrive in real time — no refresh needed.
Above each list: a search box, read/unread filter, account filter, and “✓ All read” which marks everything currently matching your filters as read in one click. Click any card to open the full email.
Clearing tools sit in each panel header: Clear viewed, Clear oldest… (choose how many of the oldest cards to drop) and Clear all. ⬇ CSV exports the current feed, and the speaker icon mutes that tab (right-click it to preview the chime).
Keyword matches found in the message body no longer appear here — they have their own 📝 Email Body tab. An email that matches both ways shows up in both places.
On the Home and Domain tabs (when not typing in a box):
j / k — move the highlight down / up the list
Enter — open the highlighted email
r — mark it read / unread
i — open it and jump straight to the ignore-domain picker
s — switch the highlight between Inbox and Sent (Home tab)
In the email viewer: ← / → move to the previous / next alert, ↑ / ↓ scroll the open message, Esc closes.
Opens the full message safely (links open in a new tab; nothing runs). Inline images, CC recipients and highlighted keyword hits are all shown; body hits appear in the header beside the subject hits.
Footer buttons: 📝 Note saves a note about this email — pre-filled and permanently linked back to it. 🚫 Ignore domain silences a sender's whole domain, and then asks whether that domain should also be excluded from the Leads Bucket (answer No to keep collecting its addresses). 🗑 Remove deletes the alert. ← / → walk through your alerts without closing, and ↑ / ↓ scroll the open message.
Attachments are listed with type icons and sizes. View previews in-browser — PDF, Word, Excel, HTML, text and images — including files sent with no filename, which are identified by their content type and magic bytes. Save downloads the original.
Translation: translate the whole message with one click, or simply select any text in the message for an instant pop-up translation (needs a DeepL key in Manage).
Separate from keywords: add whole domains (e.g. rival-bank.com) and get an alert whenever any mail arrives from them, keyword or not. Same cards, filters, viewer, clearing tools, CSV export and “All read” as the Home tab.
Domain accounts are managed separately from keyword accounts, and every address seen on a domain alert also feeds the Leads Bucket.
Domains you've ignored stop raising alerts, but their mail isn't lost — it's collected in the Ignored tab so you can audit what's being filtered and un-ignore a domain at any time. Push notifications are suppressed for ignored domains, and you can clear ignored cards separately from your main feeds.
When you ignore a domain from the email viewer you're also offered the option to exclude it from the Leads Bucket — choose Yes to stop collecting its addresses and remove any already stored, or No to ignore the alerts only.
Keywords found in the text of the message get their own tab, so your Inbox and Sent feeds stay focused on subject and attachment hits. Both the plain-text and HTML versions of the body are read (HTML tags are stripped first, so you match what a human sees, not markup).
If an email matches on the body and on the subject or an attachment, you get a card in both places — one here and one in the originating tab — each tracked separately for read state and deletion.
The tab has everything the keyword tabs have: counters, search, read and account filters, mark-all-read, the clearing tools, CSV export and the full email viewer. It also has its own push-notification switch and its own ntfy topics, so you can silence body alerts without touching the others — cards still collect quietly while it's off.
Body matching is switched on and off under Manage & Devices → What to match on.
Every sender, recipient and Cc address seen on a keyword or domain alert is collected here automatically, as a compact list built to hold very large numbers of contacts. Leads are stored independently of your alerts, so they remain even after you delete the cards they came from.
Addresses are deduplicated automatically — seeing one again updates its sighting count rather than adding a second row. Your own monitored mailboxes are never collected.
Exclusion keywords skip an address when any part of it — the name before the @ or the domain — contains one of your words. It is strictly per address: if a sender is excluded, the recipients on that same email are still collected. Adding a word also removes matching leads already stored. The list is kept alphabetical and tucked into a collapsible section; the add box sits below it.
Tools: search by address, name or account; filter by role (sender / recipient / Cc / manual) and by source; add addresses by hand; remove one with a confirmation; Deduplicate to merge any mixed-case duplicates from imports; and Delete all, which requires your export password.
Export & import: download as JSON or CSV (both password-protected, with the full record preserved), and import to merge a bucket back in without overwriting what you already have.
Email subjects are deliberately not stored, to keep the file small enough for very large lists.
Notes live in the Notes tab; the floating ✏️ button (bottom-right) opens a quick-note popup from anywhere. Both support:
📷 Images — attach up to 4 (or just paste a screenshot straight into the text box). Click a thumbnail to view full-size.
⏰ Timer — set a date & time and the note becomes a reminder: banner, ring, browser notification and phone push when due.
📧 Linked email — notes created from the viewer's 📝 button carry a chip that reopens the original email.
Pin 📌, edit ✏️, copy ⧉ or delete 🗑 from each note card.
Standalone reminders with quick chips (+1h, +3h, tomorrow…). When one is due you get the on-screen banner and ring, a browser notification, and — if you set an ntfy topic in the panel — a push straight to your phone, 24/7, even with the browser closed (the server does the pushing). Snooze or acknowledge from the banner.
Add mail accounts (address + app password), toggle inbox/sent checking per account, and maintain the keyword list. New keywords take effect on the next 30-second poll — no restart. Keywords match as substrings: invoice also hits REINVOICED.
Editing an account keeps its place in the mail stream, so changing a label, host, port, folder, webmail URL or password will not re-scan old mail. Changing the email address itself points the account at a different mailbox, so it starts fresh from that moment. Leave the password blank when editing to keep the stored one.
What to match on — four independent switches decide which channels may raise an alert: subject, attachment name, attachment content and email body. Turning one off only stops it raising alerts; it never changes which mail is scanned, and forward-only behaviour is unaffected. At least one must stay on.
Notifications — set ntfy topics per tab (Inbox, Sent, Domain, Email Body and Reminders), send a test push to verify delivery, and set your dashboard URL so notifications open the right card when tapped.
Translation — add your DeepL key and target language here.
Import / export — accounts, keywords, domains and notes can be exported and re-imported; every export and destructive bulk action is protected by your export password. Devices lists everything that has unlocked the dashboard, each revocable individually.
The 🎨 button opens themes (dozens, incl. 4 signature typographic ones and Liquid Glass with its own shade picker), accent colors, summary-card styles and motion toggles — including the card entrance animation if you prefer things perfectly still. 🌙 flips light/dark.
Accent colors can be set per section — Inbox, Sent, Domain, Email body, Leads, Notes and Reminders — either from dozens of ready-made presets or with the individual color pickers. Save your own combination as a named preset, and hide any built-in presets you never use.
Stat cards have several display types and card styles. Whichever you choose, every figure stays on one line and remains fully readable up to six digits and beyond.
Everything else in this suite watches your mail. This watches the monitoring. An account can stop being polled without any error you would notice — an expired app password, a renamed folder, IMAP throttling — and the matching engine keeps working perfectly while that mailbox is invisible.
Three states: Failing means polls are erroring (the IMAP error is shown). Stalled means polls are not even being attempted. Quiet means polls succeed but nothing has matched for a long time, which is how an empty or renamed folder looks. Accounts you have switched off are never flagged.
The threshold scales with your account and worker counts, so a deep but healthy poll queue is never mistaken for a fault. A pill appears in the topbar only when something needs attention — if you cannot see it, nothing is wrong.
Watchdog notifications use their own ntfy topics, deliberately separate from keyword alerts, so you can be told when monitoring breaks without turning on any keyword push. If no topic is set there, no watchdog push is sent and the panel tells you so. The watchdog is read-only and runs in its own thread — it can never affect polling or matching.
Alert volume over time, stacked by source, plus the hour of day alerts tend to arrive (converted from UTC to your local time). Range 7 / 30 / 90 days, filterable to a single source.
Top drivers lists the keywords, domains, senders and accounts producing the most alerts — useful for spotting a keyword that fires constantly and is never opened, which is a candidate for an exclude term.
Noise control suppresses alerts you have already caught. Exclude terms drop an alert if the term appears anywhere in the scanned text. Whole words only stops "bid" matching inside "forbidden".
These rules run after matching and are purely subtractive — they can only ever remove an alert that was already found, never change what gets scanned. If a rule is misconfigured it simply suppresses nothing. The master switch keeps your terms while turning the rules off entirely.
VIP senders flag important addresses (ceo@client.com) or whole domains (client.com, including subdomains). Their alerts get a ⭐ badge, and every tab has a VIP filter. This is presentational only — it never affects whether an email is caught.
The same email reaching several monitored accounts raises one alert per account. With collapsing on, those share a single card tagged "seen on N accounts". Click the tag to expand the group and see every copy separately.
Marking a collapsed card read, or deleting it, applies to all the alerts it stands for — the count on the button tells you how many. Tab counters always show every stored alert, never the collapsed count.
Two alerts only share a card when their Message-ID, subject, sender and matched keywords are all identical. Some bulk mailers reuse one Message-ID across different emails, so matching on it alone could hide a real message. Nothing is ever deleted or hidden without a way to expand it.
Saved views store a filter combination as a one-tap chip above the alert list. Tap to apply, tap again to clear. Editing a filter by hand deselects the chip, so the highlight never lies about what you are looking at. Views sync across your devices.
Multi-select (☑ Select) lets you tick several cards and mark them read or unread, or delete them together. Under duplicate collapsing the bar shows both figures — "2 selected (4 alerts)".
Global search (🔎 in the topbar) searches every tab at once, or one tab at a time. Previous / Next inside the email then move through the search results, even across tabs, and closing the email returns you to your results rather than the dashboard.
On a phone: swipe a card right to toggle read, left to delete (always with a confirmation). Vertical scrolling always takes priority, and swiping is disabled while selecting.
Current version: V17.0 (August 8th 2026)
New in V17 — Monitoring health (watchdog): watches the monitoring itself and warns when an account stops being polled (failing / stalled / quiet), with its own ntfy topics kept completely separate from keyword alerts, and a topbar pill that only appears when something needs attention. Analytics tab: volume over time, hour-of-day distribution and top keywords / domains / senders / accounts, with range and source filters. Noise control: exclude terms and whole-word matching, applied only after a match is found so they can never cause a miss. VIP senders: flag important addresses or domains, with a badge on the card and a VIP filter on every tab. Duplicate collapsing: the same message reaching several accounts shows as one card you can expand. Saved views, multi-select bulk actions, swipe to read or delete on mobile, global search across every tab, and a mark-unread button in the email header.
Previously in V16: Email Body match tab with its own notifications · Leads Bucket with exclusions, dedupe, CSV/JSON export & import · per-channel match toggles (subject / attachment name / attachment content / body) · account editing that preserves your place in the mail stream · precise "where it matched" notifications · login brute-force protection · faster leads persistence for very large lists · numerous mobile layout and stat-card fixes.
This project was brought to life after the concept was initiated by MasonX0X, January 2026.
Rocinente — created the first stable version of this dashboard, February 2026 (kicked off as Domain monitor only). Not active.
MasonX0X — daily improvements & tweaks after proof of concept, to date (see this help section for all functions).
Alpha_Linux — appearance mods, multi-language keyword matching, project tester from version 1 to date. Active.
Almighty-Coded — attachment scanning feature & active tester.
Report any bug, improvement suggestion or request directly to support @Masonnx.
🔒 locks the portal instantly; the password unlocks it. While locked, monitoring continues at full speed — the lock screen even shows a live feed of what's being caught. Alerts, read-state, notes, reminders, leads and settings all survive restarts (stored in data/ on the server).
Each device that unlocks gets its own signed token, listed under Manage & Devices and revocable individually without disturbing your other devices. A separate export password guards every export and destructive bulk action.
Brute-force protection: repeated wrong passwords lock that IP address out temporarily, with the delay increasing on repeat attempts. The limiter reads the real client IP behind Cloudflare or a reverse proxy, so one attacker can't lock everyone else out.
Credentials never leave your server, and the dashboard only ever talks to your own monitor process.
Matches the From or To address, subdomains included. Cards keep all their data — remove a domain and its alerts return to the main sections.
These topics ring your phone when a reminder is due, even with no browser open.
ceo@client.com) or a bare domain (client.com, subdomains included).:fx — paid keys don't; both are detected automatically.
Your key is stored on your server and never shown again after saving.Removing a device forces the portal password on its next visit. Your current device is marked.
New or unrecognized devices must enter the portal password before they can read or manage alerts. Live alerts remain visible (read-only) on the lock screen.
Update the password used to unlock this portal. You'll stay signed in on this device; the new password applies to future unlocks.
This password is required to export account files that include saved email passwords. Changing it here needs the current export password and does not affect portal login.
Personalize the name shown in the header, the browser tab, and the lock screen. Leave blank to reset to the default.
Set your dashboard's public address so tapping an ntfy notification on your phone opens that alert directly. Leave blank if you only monitor from the same machine.