My Mission & Story
My Mission
I built GravesMail because I was tired of email providers scanning my messages, tracking when I read them, and selling my data to advertisers. I wanted an email client that treats my email as mine — stored on my computer, analyzed locally, never uploaded anywhere.
GravesMail is my answer to that. It’s a privacy-first email client that uses IMAP purely as a transport layer. Your email is downloaded to your machine, analyzed by a 7-layer spam and malware detection engine running entirely on local compute, and then deleted from the provider’s server if you choose. No cloud service holds your mail. No analytics, and no tracking of how you use the app. No third party gets access to your messages.
The one thing that can ever leave your machine is Community Spam Intelligence, and only if you switch it on yourself — it is off by default, it shares anonymized filter scores and never email content, and you can preview exactly what would be sent before you enable it. I’d rather tell you that plainly than claim GravesMail transmits nothing at all, which would be a nicer sentence and a false one.
I’m one developer building this because I believe email privacy shouldn’t require a subscription or a PhD in security. GravesMail is available on Windows, macOS, Linux, iOS, and Android.
How GravesMail Started
GravesMail was never supposed to exist. It was born out of frustration, after every other option had been tried and failed.
First, I Asked the Email Providers for Help
It started the way most people would start. I contacted the major email providers — the companies whose platforms carry billions of messages every day — and asked them to do more. My inbox was being flooded with spam, and much of it wasn’t just unwanted marketing. It was malicious. Phishing attacks. Fraud attempts. Messages that were flat-out illegal for the sender to have sent in the first place.
I asked the providers to step up and protect their users. Not a single one responded. Not one.
Then, I Went to the Authorities
I contacted law enforcement and cybercrime agencies at every level I could reach — local, county, city, state, federal, and international. I didn’t just file vague complaints. I did the investigative work myself. I traced the bad actors to specific addresses, specific buildings, specific people. I found their names, their phone numbers, their social media profiles. I collected forensic data and laid out exactly what they were doing, step by step, in detail that would hold up as digital evidence.
Almost nobody responded. The few who did took no action. The evidence sat there, untouched.
Then, I Went After the Bad Actors Myself
I scanned their infrastructure. I traced their IP addresses and mapped their operations across data centers and cloud services. When they moved, I followed. I chased them from one hosting provider to another. But that’s the problem with playing defense against people who have nothing to lose — they just keep moving.
Finally, I Realized the Only Answer Was to Build Something
The providers won’t help because it doesn’t make them money. Law enforcement can’t or won’t act because the problem crosses too many borders. Confronting the criminals directly is an endless game of whack-a-mole. None of these approaches solve the problem.
So I sat down and asked a different question: What if the technology itself made spam and phishing obsolete?
Spam exists because it’s cheap to send and enough people fall for it to turn a profit. If you can break that equation — if the messages never get seen, never get clicked, and never generate a single cent of revenue — the economics collapse. The criminals don’t stop because someone asked them to. They stop because they can no longer afford to operate.
That’s the idea behind GravesMail. Every installation makes the network smarter. Every user who opts in to share anonymous data strengthens the filter for everyone else. The more GravesMail spreads, the more expensive it becomes for bad actors to succeed.
They die by cost.