Lacspace MailSign in

Documentation

How Lacspace Mail works, system by system.

No magic, no black box. Each section says what actually runs, where it lives in the app, the best way to use it, and the limits you should know. Read it top to bottom once, then keep it as a reference.

The shape of it

Your mailbox stays where it is. We add the brain.

Lacspace Mail signs in to the mailbox you already have over IMAP and SMTP, keeps a searchable copy in sync, runs classification, authentication checks, your automations and the scheduler on the server, and shows you the result on the web, as an installed app, and as push notifications. Nothing to migrate, no provider panels, and if you ever leave, your mail is exactly where it was.

  • Sync workerevery mailbox, every 90 s, live where possible
  • Classifiercategory + priority on arrival, no AI key needed
  • Automationsconditions → actions, logged, with webhooks
  • Schedulerevery 30 s: snoozes, follow-ups, sends, sequences, campaigns
  • Lumidrafts and summaries from the text you are viewing
  • Tokenssigned, scoped, expiring links for anything public
Your providerIMAP · SMTPLacspace Mailsync · classify · rulesYouweb · app · pushevery 90 s + live where the provider allowspassword encrypted, used only here

Foundations — How mail gets in, how it is sorted, how it stays safe.

Foundations

Sign in and sync

You sign in with the mailbox you already have. Nothing is migrated: the mail stays on your provider, and Lacspace Mail keeps a searchable copy in sync.

In the app: Settings → Mailboxes · open

Your providerIMAP · SMTPLacspace Mailsync · classify · rulesYouweb · app · pushevery 90 s + live where the provider allowspassword encrypted, used only here

What happens

  1. 1You enter your address and mailbox password. We look up the provider (Hostinger, Titan, GoDaddy, Google Workspace, Microsoft 365, Zoho, Yahoo, iCloud or any IMAP/SMTP host) and verify the password against its IMAP server. If the domain is not enabled for your workspace yet, sign-in stops there.
  2. 2The password is encrypted at rest and only ever used to talk to your provider. Your session is a Lacspace Mail token, not your mailbox password.
  3. 3A sync worker checks every mailbox every 90 seconds and keeps a live connection where the provider allows it. New messages are stored with their headers, text, HTML and attachments, then run through classification, authentication checks and your automations before you see them.
  4. 4Everything you do — read, flag, move, archive, delete — is written back to the provider over IMAP, so your phone and any other client agree.
  5. 5Sending goes out through your provider's SMTP server from your own address. Sent mail lands in your Sent folder like always.

Do this

  • Connect every company mailbox you own (sales@, support@, your own) — the inbox, search, leads and briefing work across all of them.
  • Share a mailbox with teammates from Settings instead of sharing the password.
  • If a provider rejects the password after a change, fix it in Settings → Mailboxes; sync pauses until then and nothing is lost.

Good to know

  • Providers with OAuth-only access (some Google Workspace and Microsoft 365 tenants) need an app password or IMAP enabled by the admin.
  • Very large mailboxes take a while on the first sync; recent mail arrives first.

Foundations

Smart categories and Focused

Every message is tagged as it lands — Team, Clients, Personal, Finance, Calendar, Recruiting, Newsletters, Notifications, Social, Promotions — and given a priority. Focused shows what needs a human.

In the app: Mail → Focused / category chips · open

ClientsTeamFinanceNewslettersPromotionsFocusedwhat needs you

What happens

  1. 1On arrival the classifier reads the sender, your relationship with them (do you reply to each other?), list headers, subject patterns and the body shape. It runs locally; no AI key is needed.
  2. 2Each message gets one category and a priority (Priority, Normal, Low). Focused is simply 'not bulk, not automated' plus anything you marked.
  3. 3When you change a category by hand, that choice sticks for the message and teaches the classifier for that sender.
  4. 4Automations can read the category and priority as conditions, so 'when a Finance mail arrives, tag it and notify the accountant' is one rule.

Do this

  • Live in Focused. Check Newsletters and Promotions once a day — they are still there, just quieter.
  • Correct a wrong category once; you rarely need to do it twice for the same sender.
  • Use Priority as your 'needs me today' list and let Today summarise it.

Foundations

Authentication and phishing checks

Every message carries an SPF, DKIM and DMARC verdict and plain-English warnings for the tricks people actually fall for.

In the app: Open any message → Authentication panel · open

SPFpassDKIMpassDMARCpassLook-alikelacspaсe.comReply-Todiffers

What happens

  1. 1We read the Authentication-Results headers your provider adds and, where they are missing or untrusted, check SPF and DKIM ourselves against the sending domain's DNS.
  2. 2On top of the verdicts, heuristics look for look-alike domains (lacspace vs lacspaсe), a Reply-To that points somewhere else, display names that impersonate a colleague, urgent payment language, and links whose text and destination disagree.
  3. 3A message that trips the checks is marked suspicious: a banner explains why in one sentence, remote images stay blocked, and 'is:suspicious' finds them all.
  4. 4HTML is sanitised before it is rendered — scripts, forms, trackers and dangerous CSS are stripped — and images load only when you ask.

Do this

  • Teach the team one rule: when the banner is red, call the person on a known number before paying anything.
  • Set up SPF, DKIM and DMARC for your own domain (Settings → Domains shows the records) so your mail passes the same checks at the other end.
  • Use an automation to move suspicious mail out of Focused automatically for shared mailboxes.

Good to know

  • Authentication says who sent the mail, not whether they are honest. A perfectly authenticated phishing mail from a fresh domain still exists — that is what the heuristics are for.

Automation — Things the server does for you while you are not looking.

Automation

Automations

When mail arrives and the conditions match, the server acts — move, tag, categorise, flag, snooze, forward, auto-reply, call a webhook, or notify you. Every run is logged.

In the app: Settings → Automations · open

Arrivesmatch?sender · category · riskyesno → inboxMoveTagNotifyWebhookevery run logged

What happens

  1. 1A rule is conditions plus actions. Conditions: sender or domain, recipient, subject or body words, category, priority, mailing list, has attachment, size, phishing risk. All or any.
  2. 2Rules run on the server as each message is stored — before you open the app, and even when it is closed.
  3. 3Actions run in order. Forward and auto-reply go out from the mailbox that received the mail; a webhook action POSTs a signed JSON payload to your URL so your own systems can react.
  4. 4Preview shows which recent messages a rule would have matched before you save it. The run log shows what each rule did, message by message.

Do this

  • Start with three rules: invoices to Finance and tagged; newsletters out of Focused; anything suspicious flagged and out of the shared inbox.
  • Use the webhook action to push client mail into your CRM or a Slack channel — the signature header lets you verify it is really us.
  • Keep auto-replies to specific senders or subjects; the out-of-office handles the general case.

Good to know

  • Rules see mail as it arrives; they do not re-run over history. Use search plus bulk actions for the backlog.

Automation

Snooze, follow-ups, scheduled send

Timing lives on the server, so every device agrees: snoozed mail returns, follow-ups fire only if nobody replied, and scheduled mail goes out while you sleep.

In the app: Message actions · Composer · open

Snooze → returnsFollow-up if silentScheduled sendscheduler checks every 30 s, on the server

What happens

  1. 1Snooze moves the message out and records the return time. The scheduler checks every 30 seconds; at the time, the message comes back unread and you get a notification.
  2. 2A follow-up reminder watches the thread. If a reply arrives from anyone on it, the reminder clears itself. If not, it surfaces in Today and in notifications at the time you chose.
  3. 3Scheduled send holds the message in the Outbox and sends it through your provider at the chosen minute. Undo send is the same mechanism with a short delay you set.
  4. 4Out of office replies once per sender per N days, never to mailing lists, bounces or automated senders, so it can never loop.

Do this

  • Snooze to a time you will actually act, not 'later'. Monday 9 am beats Sunday night.
  • Add a follow-up to every proposal you send; the ones that clear themselves are the good news.
  • Schedule outreach for the recipient's morning in their time zone.

Automation

Subscriptions and one-click unsubscribe

Every bulk sender in one list with how often you actually open it, and an unsubscribe that works without visiting their site.

In the app: Subscriptions · open

Weekly dealsopened0%Industry digestopened62%Product updatesopened18%Event invitesopened4%UnsubscribeRFC 8058from our serversor mute: files it away, sender not told

What happens

  1. 1Messages with list headers (List-Unsubscribe, List-Id, Precedence: bulk) are grouped by sender. We count how many you opened in the last months.
  2. 2Unsubscribe uses the sender's RFC 8058 one-click endpoint or their mailto: address, sent from our servers — you never load their page or reveal your browser.
  3. 3Mute keeps the subscription but files new mail away silently; the sender is not told.
  4. 4The same standard runs the other way: every campaign you send carries List-Unsubscribe and one-click headers, so Gmail and Yahoo show the unsubscribe button and your reputation stays intact.

Do this

  • Sort by 'never opened' once a month and clear the list.
  • Mute rather than unsubscribe when you might want the archive later.

Automation

Today and Insights

Today is your morning page: who is waiting on you, what you are waiting on, snoozes coming back, scheduled sends, invitations and anything risky. Insights is your mail by the numbers.

In the app: Today · Insights · open

TodayWed 7 OctWaiting on you3Waiting on them5Back from snooze2Scheduled1Risky1

What happens

  1. 1Today is assembled from live data: unanswered inbound in Focused, your sent mail without a reply, due follow-ups, snoozes returning today, the Outbox, calendar invitations and suspicious mail.
  2. 2Lumi summarises it into a few sentences when an AI key is configured; without one, the structured lists still work.
  3. 3Insights counts real events — volume per day, categories, top senders, hour-of-day arrival, your median reply time — from your own mail, not estimates.
  4. 4Campaign and lead numbers feed the same page as outreach grows.

Do this

  • Open Today before the inbox; it is the inbox already triaged.
  • Watch median reply time by mailbox for shared addresses — it is the honest service-level number.

Outreach — Design once, send well, know what happened next.

Outreach

Templates Studio and brand kit

Build emails from blocks with your brand applied, see the deliverability score as you type, and keep merge fields intact for sending.

In the app: Templates · open

HeaderTextButtonColumnsFooterbrandscore 94 / 100

What happens

  1. 1The brand kit holds your logo, colours, font, radius, address and socials. Every template inherits it, so changing the brand restyles everything.
  2. 2Blocks (header, text, image, button, columns, divider, quote, list, table, social, footer) render to table-based HTML that survives Outlook, Gmail and Apple Mail, with a dark-mode variant and a plain-text alternative.
  3. 3A lint pass scores the result: size, image ratio, alt text, link text vs destination, spam phrases, missing unsubscribe for bulk mail. Blocking issues stop a campaign from starting unless you override.
  4. 4Merge fields like {{firstName|there}} are left alone by the builder and filled per recipient at send time — so one template serves a campaign, a sequence step and a quick reply.
  5. 5Starters cover sales outreach, follow-up, quote, invoice, receipt, support reply, welcome, newsletter and festival greeting. Lumi can draft a template from a one-line brief.

Do this

  • Set the brand kit first; ten minutes there saves an hour per template.
  • Keep the footer block with the unsubscribe placeholder on every bulk template.
  • Send yourself a test to a Gmail and an Outlook address before the first campaign.

Outreach

Campaigns

One message to many people: per-recipient preview, A/B subjects, send windows, tracking that respects privacy, and a suppression list that is honoured forever.

In the app: Campaigns · open

Template+ recipientsSenderwindow · batchesopenedclickedrepliedbouncedunsubscribedsuppression list

What happens

  1. 1Pick a template, add recipients (paste, CSV, contacts, leads or a lead stage) — invalid, duplicate and suppressed addresses are counted and skipped.
  2. 2Choose the channel. Platform sender puts '<your brand> via Lacspace Mail' in From with your address in Reply-To and handles unsubscribe headers; your own mailbox is allowed for small lists within its daily ceiling.
  3. 3Every send gets a tracking pixel and wrapped links signed per recipient. Opens from Apple Mail Privacy Protection and scanners are classified and not counted as human.
  4. 4The scheduler sends in batches inside your window, pausing on bounce or complaint spikes. Replies, bounces and unsubscribes update the recipient row and the counts live.
  5. 5An unsubscribe — from the link, the one-click header or a reply — puts the address on the workspace suppression list; campaigns and sequences never mail it again.

Do this

  • Warm up: first campaigns small, to people who know you, then grow volume weekly.
  • A/B the subject on 20% and let the winner go to the rest.
  • Treat the suppression list as sacred — add complainers by hand too.

Good to know

  • Platform sending uses a shared sending domain today; a dedicated domain for your brand is a configuration we set up with you.
  • Open rates are directional, never exact — privacy proxies make sure of that.

Outreach

Sequences

Personal follow-ups from your own mailbox — step two goes out only if step one got no reply, threaded under the first message, within a daily ceiling that keeps your domain safe.

In the app: Campaigns → Sequences · open

Step 1day 0Step 2day 3 · if no replyStep 3day 7 · if no replyreply → stopsfrom your mailbox, same threadnever sentunder the mailbox ceiling: 20 / hour · 100 / day

What happens

  1. 1A sequence is ordered steps, each a template plus a delay (days or hours) and a condition like 'only if no reply'. A policy sets the send window, time zone, the per-hour and per-day ceilings, and what stops it: reply, bounce, unsubscribe, complaint.
  2. 2Enrol people from leads, contacts, a CSV or by typing addresses; suppressed and already-enrolled addresses are skipped.
  3. 3Each step is sent from your mailbox through your provider, as a reply in the same thread, so the recipient sees one conversation.
  4. 4When mail from an enrolled address arrives in that mailbox, the sync hook marks the enrolment replied and stops it. A bounce stops it and suppresses the address.
  5. 5The ceiling counts everything your mailbox sent in the hour and the day — manual mail included — so a sequence can never push you over the provider's limits.

Do this

  • Three steps, two to four days apart, each shorter than the last. Step three is one line.
  • Write step one as a real question; sequences that get replies are the ones that ask something.
  • Keep the ceiling at or below your provider's documented limit; the default of 20 an hour and 100 a day suits most business mailboxes.

Outreach

Leads board

A pipeline that lives next to the inbox. Any sender becomes a lead in one click, with the full mail history, enrichment from their website and a path into a sequence or campaign.

In the app: Leads · open

NewContactedQualifiedWon

What happens

  1. 1Open any message and choose 'Add to Leads'. The sender's name, company (from their domain) and website are filled in; the stage starts at New.
  2. 2The card's timeline is every message to or from that address across your mailboxes, plus sequence enrolments and whether they are on the suppression list.
  3. 3Enrich reads their public website — title, description, phone, socials — and their mail provider from DNS. For a lead without an email it looks for one on the site (mailto links, contact pages).
  4. 4A lead answers to several identities — email, phone, website, place — so imports and finder runs merge into the existing card instead of duplicating.
  5. 5Drag between stages; deal values roll up per stage. Select many for bulk stage, tag, verify, sequence, campaign or delete.

Do this

  • Move the stage when something real happens — a reply, a call, a quote — not when you hope it will.
  • Set a next action date on every open lead; 'due today' then becomes your call list.
  • Import a CRM export once, then let the inbox feed the board.

Outreach

Lead Finder

Name a business type and a city. The free lacspace-leads finder runs on your own computer, no API key, and streams every business it finds onto your board live.

In the app: Leads → Find leads · open

Your computerChrome walks the map--push · 24 h tokenYour boardCafe · 4.6★MX okClinic · 4.2★MX okStudio · 4.8★MX oknothing runs on our servers · dedupe by email, phone, website

What happens

  1. 1Save a search: business type, cities, areas, how many unique leads you want, and filters — only businesses without a website, must have a phone, minimum rating, find and verify emails.
  2. 2Press 'Get the command'. We mint a token that can only import leads into that one search, expires in 24 hours and can be revoked, and show one command with the token in an environment variable so your shell history never sees it.
  3. 3Run it in a terminal (Node 20+, Chrome or Edge). Chrome opens and walks Google Maps; a single search stops around 120 results, so the finder tiles the map outwards until it reaches your number. Ctrl-C saves.
  4. 4Each finished business is pushed to the portal in small numbered batches — a retried batch is recognised and ignored — and appears on the board within seconds: phone, website, rating, address, category, socials, and the email if one was found.
  5. 5The portal verifies every email's mail server (an MX lookup, nothing is sent) and marks it valid, no-MX or unknown. Leads without an email still get a card; 'Find email' or a phone call takes it from there.

Do this

  • Start with 'no website' plus 'has phone' in one area — that is the list that wants your help most.
  • Run the same search monthly; new businesses merge in, existing ones are untouched.
  • Mail only businesses that would reasonably expect your message, and keep the unsubscribe link in every campaign.

Good to know

  • The finder reads public listings in your browser; nothing runs on our servers, by design.
  • Google hides review counts from signed-out visitors, so 'reviews' is often empty.
  • Zero results usually means a CAPTCHA in the Chrome window — solve it once and the run continues.

Assist — AI where it helps, notifications where you are.

Assist

Lumi AI

Summaries, action items, draft replies in a chosen tone, translation, four-way rewrites, a pre-send review, template drafting and document summaries — with the basics working even without an AI key.

In the app: Open a message → Lumi · Composer · open

LumiSummary3 action itemsDraft reply · warmPre-send reviewonly the text you are viewing · nothing sent on its own

What happens

  1. 1Lumi receives the text of the message or thread you are looking at, never your whole mailbox, and never your password or credentials.
  2. 2With a configured AI key the model drafts and summarises; without one, extractive summaries and action items still run from built-in text analysis.
  3. 3Drafts land in the composer for you to edit; nothing is sent by Lumi on its own.
  4. 4Pre-send review reads your draft for tone, missing attachments you mentioned, unclear asks and risky phrasing, and suggests fixes.

Do this

  • Ask for a summary before opening a long thread you were copied on.
  • Use 'four ways' when you are stuck on tone — pick one and edit, do not send as is.
  • Let the pre-send review catch the attachment you forgot.

Good to know

  • Quality depends on the configured model and key. The provider's data terms apply to text sent for drafting.

Assist

Notifications, install and tones

Web Push for focused mail, returned snoozes, due follow-ups and lead replies even with the tab closed. Installs as an app on desktop and phone.

In the app: Settings → Preferences · open

Lacspace Maillive eventsdesktopphone · installedpush · counters · tones you choose

What happens

  1. 1A live connection streams events to open tabs: new mail, flags, campaign progress, lead replies, finder imports. The header counters and the notification centre update without reloading.
  2. 2Web Push delivers the important ones to the device when the app is closed — only the categories you turned on.
  3. 3Tones are generated on the device for mail, reminders, leads and campaigns; pick a sound and volume in Preferences.
  4. 4The service worker caches the shell so the app opens instantly and shows a useful offline page when the network is gone.

Do this

  • Install it on your phone and turn on push for Focused only; everything else can wait for the morning.
  • On a shared desk, mute tones and keep the bell.

Assist

The security model

Your mailbox credentials are encrypted and only used to talk to your provider. Per-user and per-address rate limits, signed tokens for every public link, and nothing rendered that could run code.

In the app: mail.lacspace.com/security · open

encrypted at restsigned tokenssanitised HTMLrate limited24 h import tokensaudit trail

What happens

  1. 1Mailbox passwords are encrypted at rest with a server-side key and decrypted only to open IMAP/SMTP sessions. They are never sent to the browser.
  2. 2Public links — unsubscribe, open pixel, click redirect, lead-finder import — are signed tokens scoped to one purpose; they cannot be forged or reused for anything else, and import tokens expire.
  3. 3HTML mail is sanitised; remote content is blocked until you allow it; attachments preview in a sandbox.
  4. 4Sign-in and public endpoints are rate-limited per user and per address, and every admin action is recorded.

Do this

  • Use an app password where your provider offers one, and rotate it if a device is lost.
  • Enable the allowed-domains list for your workspace so only your company's addresses can sign in.

The best we can do — eight habits that make the whole thing sing.

  1. 1

    Authenticate your own domain first

    SPF, DKIM and DMARC for the domain you send from. Settings → Domains shows the exact records. Without them, even a perfect campaign lands in spam.

  2. 2

    One-to-one from your mailbox, one-to-many from the platform

    Sequences are personal follow-ups and belong in your own Sent folder, under your ceiling. Campaigns are announcements and belong on the platform sender with unsubscribe headers.

  3. 3

    Warm up, then grow

    New domains and mailboxes earn reputation. Start with dozens, not thousands; keep bounces under two percent and complaints near zero before doubling.

  4. 4

    Always an unsubscribe

    Every bulk message carries a visible link and the one-click header. The lint blocks a campaign without one for a reason.

  5. 5

    Verify before you send

    Run 'Verify emails' on imported lists. No-MX addresses bounce, and bounces cost reputation.

  6. 6

    Let the suppression list grow

    Unsubscribes, bounces and complaints are honoured forever across campaigns and sequences. Never import around it.

  7. 7

    Three rules, then stop

    Finance to tagged, newsletters out of Focused, suspicious out of the shared inbox. Add more only when a real pattern repeats.

  8. 8

    Snooze to a decision

    Snooze to the moment you will act, add a follow-up to every ask, and let Today be the first page you open.

Glossary

SPF
A DNS record listing which servers may send mail for a domain. Fails when mail comes from somewhere else.
DKIM
A cryptographic signature on the message proving it was not altered and came from the signing domain.
DMARC
A policy telling receivers what to do when SPF and DKIM fail, and where to send reports.
MX
The DNS record naming a domain's mail servers. No MX usually means the address cannot receive mail.
RFC 8058
The standard for one-click unsubscribe over HTTPS that Gmail and Yahoo require from bulk senders.
IMAP / SMTP
The protocols for reading (IMAP) and sending (SMTP) mail with your provider. Lacspace Mail uses both; nothing proprietary.
Sequence
Ordered follow-up steps sent from your own mailbox that stop when the person replies.
Suppression list
Addresses your workspace must never mail again — unsubscribes, bounces, complaints, and anyone you add.
Ceiling
The per-hour and per-day send limit of a mailbox, counted across everything it sends.
Lead key
The identities a lead answers to — email, phone, website, place — used to merge duplicates.

See it with your own mailbox.

Sign in with your address and password. Nothing to migrate. Or read the full feature list and the security page first.