Skip to content

EP Email Inbox

EP Email Inbox polls an IMAP mailbox and handles incoming email with AI. Useful for first-line support where most questions can be answered by an AI given your site context, and the remainder are routed to a human.

Published by ElmsPark Studio.

How it runs:

  1. IMAP polling against your support mailbox (e.g. [email protected]) on a configurable interval.
  2. For each new message, the plugin reads the sender, subject, and body.
  3. The message is sent to your configured AI provider with that mailbox’s instructions (its system prompt), and the AI drafts a reply.
  4. If your mail server verified the sender, the reply goes out through the mailbox’s own mail server (SMTP).
  5. If it could not verify the sender, the draft is emailed to you through EP Email instead, for you to check and send yourself.
  6. Mailing lists, bounces and automatic replies are skipped and never answered.

Every message, auto-replied or flagged, is logged with full transcript so you can audit what the AI did.

  • “What are your opening hours?” — context says so.
  • “How do I reset my password?” — standard instruction.
  • “Is feature X included in the Pro plan?” — pricing/features are site context.
  • “My download link expired, can I have another?” — plugin can check orders and send a new link.
  • Complaints. Always route to humans.
  • Legal questions. Always route to humans.
  • Technical questions specific to the customer’s setup. AI guesses; a human can check the actual server.
  • Anything where the customer is upset. The AI handles routine enquiries; emotion needs a person.
  • PageMotor 0.8.2b or later
  • EP Email (required)
  • EP Suite base class
  • An IMAP mailbox (your support email account)
  • An LLM provider API key (Anthropic, OpenAI, or any supported)
  • PHP IMAP extension installed on your server
  1. Install EP Email first.
  2. Download ep-email-inbox.zip from the EP Suite downloads page.
  3. Upload via Plugins → Manage Plugins. Activate.
  4. Open Plugin Settings → EP Email Inbox.
  • Server. IMAP host (e.g. imap.fastmail.com).
  • Port. 993 for SSL.
  • Username / Password. Mailbox credentials.
  • Mailbox folder. Usually INBOX.
  • Poll interval. 5, 15, 30, or 60 minutes.
  • Provider. Anthropic, OpenAI, etc.
  • API key. Provider credential.
  • Model. Pick one that balances quality and cost.
  • Confidence threshold. If the AI’s self-reported confidence is below this, flag for human instead of auto-replying. Default 80%.
  • Signature. Text appended to every auto-reply.
  • Always flag these keywords. Comma-separated. Messages containing any keyword are always routed to a human regardless of AI confidence. Good for “refund”, “complaint”, “urgent”, “lawyer”.
  • Site description. A paragraph about what your site does.
  • Product/service list. What you sell, with prices if relevant.
  • FAQ context. Paste your FAQs. The AI uses this to answer routine questions.
  • Brand voice. Tone guidance, e.g. “Friendly but professional. No emojis. Sign off with ‘Best, the team.’” The plugin’s default system prompt instructs the AI to match the customer’s English variant (preserves British, American, Australian, etc. — does not force a regional spelling). Override that default in this field if you want to force one variant.

Lists every message the plugin has processed:

  • Auto-replied (AI handled it; reply shown).
  • Flagged (awaiting human; AI’s reasoning shown).
  • Failed (error during processing).

For flagged messages, you can click Draft reply to generate a suggested reply the same way EP Email AI Reply does, or write your own. Either way, sending goes through EP Email.

Every AI interaction is logged:

  • Original message.
  • AI’s proposed reply.
  • Confidence score.
  • Whether auto-reply was sent or flagged.
  • Cost of the LLM call (for API-billed providers).

Logs are retained for 90 days by default.

Check:

  • Host and port are correct.
  • Username is the full email address.
  • App-specific password if your mail provider requires one (Gmail, Fastmail).
  • PHP IMAP extension installed (phpinfo() should list IMAP).

“Plugin polls but no messages are being processed”

Section titled ““Plugin polls but no messages are being processed””

Check the poll log on the settings page. If it shows “No new messages”, the mailbox is empty (or all messages are already marked as seen). IMAP polling only picks up new unseen messages.

“Auto-replies are going to the wrong people”

Section titled ““Auto-replies are going to the wrong people””

The plugin replies to the Reply-To header if present, otherwise the From. If someone emailed you from an alias, replies might go to the alias unless their mail system rewrites. Test with a colleague first.

“AI is confidently wrong about my products”

Section titled ““AI is confidently wrong about my products””

Tighten the site description and FAQ context. The AI only knows what you tell it. More context = fewer wrong answers. Also lower the confidence threshold to flag more messages for human review.

Rewrite the brand voice setting. “Friendly but professional” is generic. Be specific: “Reply in plain English. Short paragraphs. One clear answer per paragraph. No buzzwords.”

Switch to a smaller model (Haiku vs Opus). Or raise the poll interval to reduce frequency. Or add more keywords to the always-flag list so only straightforward messages hit the AI.

For a quick question about this plugin, EP Support inside your admin is the fastest option. The chat widget sits on every EP plugin settings page and knows which one you’re on, with starter questions and links preloaded for that exact screen.

For anything bigger — a bug report, a feature request, or a “how do I…” that needs a real reply — open a ticket at help.elmspark.com. A real person, helped by AI, writes the reply. Usually within a few hours. Tickets don’t disappear into the void.

  • A busy AI service no longer leaves an email unanswered. Until now, if Claude or OpenAI was overloaded, limiting requests or having a brief fault when a message was checked, that message was marked as failed and never got a reply. EP Email Inbox now tries again by itself, up to three tries in all, waiting as long as the service asks (up to 15 seconds).
  • An account that is out of credit, a wrong key or an email too long for the model is not retried, and still shows as failed under Recent Activity as before.
  • Nothing to do after updating.
  • Automatic mail is never answered, and you can see why. Newsletters and mailing lists (List-Id, List-Unsubscribe), bulk mail (Precedence: bulk, junk or list), bounces (an empty Return-Path), mail marked Auto-Submitted, mail asking for no automatic replies (X-Auto-Response-Suppress), and no-reply, mailer-daemon and postmaster senders are skipped. Recent Activity now shows the reason under each skipped, held or failed message.
  • No-reply senders are recognised in more forms, such as shop.noreply@, no-reply-orders@, do_not_reply@ and bounces+tag@.
  • The AI states only what your instructions say. A reply that gives a price, percentage, date, time, day or other number, or mentions a discount, refund, voucher, guarantee or similar, that is not in the mailbox’s instructions is not sent to the sender. It comes to your review address with the reasons listed, and you can send it on yourself. This also applies when the AI turns down a request politely (“we can’t offer a discount”), so expect the occasional reply to come to you for a check.
  • The AI never claims to be a person. A reply that says it is a human, or that carries From:, To: or Subject: lines, is held for you in the same way. Replies always go out from the mailbox’s own address and name.
  • Malformed AI answers are never sent. The AI must put its reply between two markers that change for every email. If they are missing, repeated, or anything is written outside them, nothing is sent and the message shows as failed with the reason.
  • Data from EP GDPR on a privacy@ mailbox is now treated as your information, not as part of the sender’s email.
  • Choose your mailbox’s outgoing mail server. Replies go out through the mailbox’s own SMTP server, which the plugin used to guess from the IMAP address (imap. changed to smtp., port 465). If yours is different, add "smtp_host", "smtp_port" and "smtp_encryption" to the mailbox: "ssl" for a secure connection from the start, or "tls" for STARTTLS on port 587. Mailboxes without them work exactly as before.
  • Clearer errors when sending fails. If the mail server refuses the login, or will not secure the connection, the plugin stops there and logs why. Your password is never sent over an unencrypted connection.
  • "validate_cert": false now applies to sending as well as reading mail, for a server with a self-signed certificate.
  • Microsoft 365 and Outlook.com mailboxes. Microsoft no longer accepts a password for reading mail over IMAP and requires its own sign-in method (OAuth), which EP Email Inbox does not support yet. The Mailboxes panel now says so beside any Microsoft mailbox, instead of the mailbox failing quietly.
  • Automatic replies work again when the Model setting is blank. The default model, Claude Sonnet 4 (claude-sonnet-4-20250514), has been retired by Anthropic and no longer answers, so every reply failed and the Recent Activity list showed “AI API call failed”. The default is now Claude Sonnet 5.5 (claude-sonnet-5-5).
  • If you typed a model into the Model setting yourself, it is still used. If you typed claude-sonnet-4-20250514, clear the field or change it to claude-sonnet-5-5.
  • Replies from current Claude models are read correctly. These models can return their reasoning before the reply, and the plugin could mistake that for an empty answer.
  • Replies are kept quick, and long ones are no longer cut short.
  • Drafts now reach you. When the AI holds a reply because the sender could not be verified, the draft is emailed to you through EP Email, as 1.1.10 intended. Until now these drafts, and the emails telling you a mail server had been learned or forgotten, were never sent. The Recent Activity list showed “draft not sent”.
  • Replies to your customers still go out through each mailbox’s own mail server, as they always have. They now also carry the headers that thread them under the customer’s message and mark them as automatic replies.
  • A privacy mailbox no longer stops the inbox when EP GDPR hits an error. The AI replies without the data summary, and the other mailboxes carry on.
  • Requests such as “please delete my data”, “erase”, “rectify” or “stop processing” are now recorded in EP GDPR as the right type. Before, many of them were recorded as access requests.
  • Visiting the admin login screen while signed out no longer starts a mailbox check. Checks on admin page loads now need a signed-in admin.
  • Sender Check now sets itself up. You no longer need to add "auth_server" to each mailbox. EP Email Inbox watches the mail each mailbox receives and learns which mail server checks it (usually after about 10 messages from 5 different senders). It emails you when it has, and from then on the AI replies by itself to senders that server has verified. Until then, drafts come to you as before. The Mailboxes panel shows how far it has got.
  • If your mail provider changes, the plugin notices (20 messages in a row checked by a different server), emails you, and learns again.
  • A mailbox’s "auth_server", if you have set one, is still used instead. A new Sender Check choice, Manual, turns learning off and uses only "auth_server".
  • Sender verification understands the form Microsoft writes. Microsoft’s mail servers write their checks without a server name. The Mailboxes panel now shows these as “untagged”, and "auth_server": "untagged" trusts them. (Microsoft 365 and Outlook.com mailboxes themselves cannot be read by this plugin: see 1.1.15.)
  • Important: the AI now replies automatically only to senders your mail server has verified. A message’s “From” address can be forged, so before this update a stranger could make your site send an AI-written reply to someone else. Now, when the sender cannot be verified (by DMARC, SPF or DKIM, checked by your own mail server), the AI’s draft is emailed to you instead (to “Send Drafts To”, or EP Email’s Default Recipient), and you can reply to the person yourself. Since 1.1.12 the plugin works out which mail server checks each mailbox by itself (see above), so there is nothing to set up; until it has, drafts come to you. To go back to replying to everyone, set Sender Check to Off.
  • Links written as bare domain names (for example “example.com/pay”) are now filtered like full links.
  • Automatic replies can no longer loop with another auto-responder. A new setting, Max Replies per Sender per Day (default 5), stops the AI replying to the same address more than that many times in 24 hours. Before, two auto-responders could answer each other up to the hourly limit, all day, every day.
  • No automatic replies to mailing lists, bounces or forged senders. Messages marked as bulk or list mail, bounce messages, senders who ask for no automatic replies, and messages your mail server reports as failing the sender’s own anti-forgery checks (DMARC or SPF) are now logged and skipped instead of answered. This stops a stranger using a forged “From” address to make your site send AI-written mail to someone else.
  • Replies are marked as automatic. Each reply now carries the standard “auto-replied” marker and threads under the customer’s message, so well-behaved mail systems at the other end do not answer it back. Replies go out through the mailbox’s own mail server, which passes the marker on.
  • A failed send is no longer recorded as replied.
  • Data protection requests now include the inbox. EP GDPR’s export now lists every message stored for a person, and erasure deletes them. Messages in the mailbox on your mail server are not touched.
  • Your API key and mailbox passwords are now stored encrypted. Both were saved in plain text and shown in full on the settings screen. They are encrypted automatically after the update; nothing to re-enter. In the Mailboxes box each password now shows as __saved__: leave that as it is to keep it, or type a new one to change it.
  • The mail server’s certificate is now checked. It never was, so anyone between your site and the mail server could have collected the mailbox password. If your mail server uses a self-signed certificate (usually only a local test server), add "validate_cert": false to that mailbox.
  • Switching the plugin off now stops the external cron too. Before, “off” only stopped checks on admin page loads, so a server cron kept replying.
  • Replies no longer go out under another business’s name. A mailbox with no From Name replied under a name left over from another site. It now uses EP Email’s From Name, or your site title.
  • A conversation can no longer be pulled in by someone outside it. A message that claimed to belong to another customer’s conversation (by quoting its message ID) got that conversation fed to the AI. Now a message only joins a conversation the sender is already part of.
  • Harder to hijack the AI by email. The email being answered is clearly marked off as the sender’s text, and the AI is told never to follow instructions inside it. Links in a reply are kept only if they point to your site, the mailbox’s own domain, or a site named in your own prompt; any other link is replaced with “[link removed]”.
  • New optional setting, Only Reply To. List addresses or @domains, one per line, and the AI will only answer those, plus people it has answered before. Everyone else is logged for you to deal with. Leave it blank to keep answering everyone.
  • Two checks can no longer reply to the same email twice. If an admin page load and the external cron ran at the same moment, both could answer one message. Only one check now runs at a time.
  • The cron token can be sent as a header (X-EP-Cron-Token), which keeps it out of your web server’s logs. The settings page shows the command. The old URL still works.
  • Data protection requests that arrive by email at a privacy@ mailbox are now logged in EP GDPR as unconfirmed (EP GDPR 1.1.49), so a forged sender cannot get one actioned without your check.
  • Settings language menu. The language menu in this plugin’s settings now lists only the languages it is actually translated into, plus English, so you can no longer pick a language that changes nothing.
  • The Docs link on the Plugins screen now opens this plugin’s page on documentation.elmspark.com.
  • Removes a function call that PHP 8.5 reports as deprecated, so it no longer fills your error log.
  • Fixes “Your session has expired. Please reload to ensure your security.” on PageMotor 0.11. The message appeared on this plugin’s admin screens even though you were signed in perfectly normally, and whatever you were doing failed to save.
  • Nothing was wrong with your session. PageMotor 0.11 started handling part of the security check that this plugin was already handling itself, and the two together made every save look invalid. The plugin now checks whether PageMotor has already done it.
  • Visitors who were not signed in were never affected, on any version.
  • There is nothing to reconfigure, and nothing else changed.