MojoPad

Mail Drop

Some things arrive as email, and that is where they die. A confirmation you will want the reference number from in eight months. A colleague’s PDF. A thought you had on a train, with your laptop at home. Getting any of it into a wiki means opening the wiki, finding the page and pasting — which is why it does not happen.

Mail Drop gives one of your wikis an email address. Send to it and what you sent becomes a page. From a phone with nothing installed, from somebody else’s computer, from a colleague who has never heard of MojoPad and only needs to know an address.

What it is good for

  • Capture from a phone. No app, no account, no sync — the mail client you already have is the capture tool.
  • Forwarding. A receipt, a booking, a newsletter worth keeping. Forward it and it lands as a page, with the sender and the date written at the top.
  • Letting somebody else file into your wiki. A colleague sends a PDF to the address; it becomes a page, and the file becomes a page of its own, without them having access to anything of yours.
  • A dictated note. Talk into your phone’s mail app, send it, and it is in today’s journal by the time you sit down.

Where a message lands

The subject line decides, and there are only three things to learn:

  • A subject becomes a new page with that name. Re: and Fwd: are stripped, so a forward lands under the original subject.
  • A subject starting with + is added to the end of the page already called that. +Reading list appends to Reading list.
  • No subject at all goes to today’s note in the Journal.

The page says who sent it and when, at the top, because that is what you want when you find it a year later.

Setting it up on Fastmail

Fastmail is the easiest, because an alias there can file itself and you never write a rule. Four steps, once.

1 — Make the folder. A folder called MojoPad in your mailbox. This folder is the boundary of the whole feature: MojoPad reads it and nothing else.

2 — Make the address, and point it at the folder. Settings › My email addresses › Add address › Create an alias, and choose the address you want. Then open the alias you just made and set Delivery options to Move to a folder, choosing your MojoPad folder. Mail to that address now skips your inbox and waits there.

3 — Make an app password. Settings › Privacy & Security › Connected apps & API tokens › Manage app passwords and access › New app password. Name it MojoPad so you will recognise it later, and generate it. Copy it now — Fastmail will not show it to you again.

4 — Fill in the pane. Settings › Mail Drop. Choose Fastmail as the provider and the server and port fill themselves in. Then:

  • Sign in asyour account’s own address, the one you log in to Fastmail with. Not the alias. An alias receives mail; it is not a login, and using it here is the commonest way to get a refused sign-in.
  • Password — the app password from step 3.
  • FolderMojoPad, spelled exactly as you made it.
  • Which wiki — the document things should land in.
  • Put pages in — a folder in that wiki. It starts as Emailed Items, and is made for you the first time something arrives. Everything one message brings goes in together: the note and any files with it. Clear the box and pages land at the top level instead.
  • Who may write — see below. Nothing arrives until somebody is on that list.

Then tick the box at the top. Nothing is fetched, and no password is asked for, until you do.

The same four steps are in the pane itself, so you do not have to keep the manual open beside it.
Said in the pane rather than only here: what an app password actually opens, and what MojoPad does with it.

The four places people get stuck

Every one of these came out of somebody setting it up for the first time with the instructions in front of them.

  • The alias is not a login. You sign in as your account’s own address — the one you type into Fastmail — and the alias is only what receives the mail. Using the alias in Sign in as gets a refused sign-in with no explanation, and MojoPad then switches itself off rather than trying again. This is the commonest one by a distance.
  • Aliases are not under a menu called Aliases. They live in Settings › My email addresses, behind Add address. If you go looking for the word alias in the settings list you will not find it.
  • App passwords are not under Passwords. They are in Privacy & Security, in a section called Connected apps & API tokens — which does not have the words “app password” in its name.
  • Nothing happens until the box is ticked. Filling in every field and closing Settings does nothing at all: Read a mail folder and file what arrives, at the top of the pane, is what starts it. That is deliberate — no password is asked for and no connection is made before you switch it on — but it is easy to fill in a form and assume you are finished.

If Fastmail has moved any of these since this was written, their own help pages are the place to check: theirs stay current and ours cannot.

On other providers

iCloud works: make a Hide My Email address, make a folder, and write one rule sending that address to it. The app-specific password comes from your Apple account.

A personal Gmail address works, with two catches. The only alias you get is [email protected], which anyone can guess from your address alone — so who may write matters more there than anywhere else. And an app password needs two-step verification switched on first.

Outlook.com, Microsoft 365 and Google Workspace accounts cannot be used, and no setting in MojoPad will change that: all three withdrew password sign-in for other programs. Any provider that still accepts a password over IMAP will work, including one you host yourself.

Who may write, and why it is not optional

Only addresses on your list can write to your wiki. Anything else is turned away, marked read, and never mentioned again. The sender is told nothing at all — a bounce would confirm to a stranger that the address is real and watched.

A whole domain works as @yourcompany.com, which admits everybody there. A suffix is not a match: listing @example.com does not admit [email protected].

An empty list means nobody, and MojoPad will not even connect. That is deliberate: the safe way round is the one that does nothing until you have said who.

Files that come with a message

Attachments are kept. Each becomes a page of its own — a PDF you can read and search inside, a picture you can see — and the message page lists what came with it, with sizes. A picture pasted into the message stays in the writing, where it was put.

Programs are not kept. Anything that could run — an installer, a script, an application — is refused by name, as is anything past the size you allow. Nothing is dropped in silence: the page says what did not come through, and the message is still in your mailbox if you want it.

What an emailed page will never do

This is the only way into your wiki where the person choosing the page name may be a stranger. Three rules hold, whatever arrives.

It cannot run. A page called Event: Open normally runs when the document is opened. One that arrived by email is marked as having come from outside, and pages marked that way never execute — MojoPad does not even ask you about it. The same holds for text added to a page you wrote: if what arrives carries runnable code, none of it is added.

It cannot fetch anything. Pictures kept on somebody else’s server are not loaded. A remote picture in mail is a read receipt — it tells the sender you opened the message, when, and roughly from where, and a wiki page is opened again every time you search. The page says how many were held back, and their addresses are kept in case you want them.

It cannot damage what is already there. A board’s contents are a layout rather than writing, so mail aimed at one is refused rather than pasted into it. Pages that hold code are refused for the same reason.

When nothing arrives

  • Look in the mail folder first. If the message is not sitting in your MojoPad folder, the problem is the alias or the rule, not MojoPad.
  • “The mail server refused that sign-in.” Nearly always one of two things: Sign in as is the alias rather than your account’s own address, or the password is your ordinary one rather than an app password. MojoPad switches itself off rather than trying again, because repeated failures get accounts locked.
  • It arrived, but nothing happened. Check the sender is on your list. A message from anywhere else is turned away silently, by design.
  • MojoPad looks when you are using it — when a window comes to the front, when the Mac wakes, and every fifteen minutes while it runs. It is not a background service: if MojoPad is not running, nothing is fetched, and what is waiting stays waiting.

The cost, said plainly

An app password opens the whole mailbox, not one folder. No provider we know of will narrow one to a single folder — Fastmail’s cover mail, contacts and calendars together. MojoPad only ever reads the folder you name, and only ever reads: it never sends, never deletes, never looks anywhere else. But that is a promise in this program’s code, not a fence your provider enforces, and it deserves to be weighed as such.

What MojoPad does with it: the password is stored encrypted by macOS, never written into a document, never carried in a settings export, and never sent anywhere except to your own mail server. Make an app password for MojoPad alone, so you can revoke that one without disturbing anything else.