Academy → Messaging ChannelsOfficial documentation · Arabic guidance

Email

قناة البريد الإلكتروني

Intermediate to advanced6 min readLesson 115 questions✓ 2026-08-18
Before you read

What this page is, and what it holds.

This page covers Email. It carries a source warning and takes about 6 minutes to read. Open the channel to yourself first with an allowlist. An open channel means anyone can message your agent.

8sections
4code examples
3tables
3commands
1,026source words
The official one-line description

Set up Hermes Agent as an email assistant via IMAP/SMTP

What you will be able to do

Outcomes taken from this page, not a template.

  • Understand what بوابة المراسلة is and when you need it.
  • Run hermes gateway install and hermes gateway and understand what happens next.
  • Read the table and take only the row that applies to you.
  • Set EMAIL_ADDRESS in the right place.
Identifiers you will meet

Exactly as they appear in Hermes.

Commands
  • hermes gateway install
  • hermes gateway
  • hermes gateway setup
Environment variables
  • EMAIL_ADDRESS
  • EMAIL_PASSWORD
  • EMAIL_IMAP_HOST
  • EMAIL_SMTP_HOST
  • EMAIL_ALLOWED_USERS
  • EMAIL_IMAP_PORT
  • EMAIL_SMTP_PORT
  • EMAIL_POLL_INTERVAL
Page map

Jump to the part you need.

  1. 01Prerequisites
  2. 02Step 1: Configure Hermes
  3. 03Step 2: Start the Gateway
  4. 04How It Works
  5. 05Access Control
  6. 06Troubleshooting
  7. 07Security
  8. 08Environment Variables Reference
The full official page

Nothing summarised away.

The documentation body below is reproduced from the official source so commands and identifiers stay exact. Each section carries a short note describing what it contains.

Hermes can receive and reply to emails using standard IMAP and SMTP protocols. Send an email to the agent's address and it replies in-thread — no special client or bot API needed. Works with Gmail, Outlook, Yahoo, Fastmail, or any provider that supports IMAP/SMTP.

This is separate from the bundled Himalaya email skill, which lets the agent manage email through terminal commands and requires the external himalaya CLI plus a Himalaya config file.

Use caseWhat to configureExternal dependency
Let people email the Hermes agent and receive repliesEmail gateway adapter on this pageNone beyond an IMAP/SMTP email account
Let the agent inspect, compose, move, and manage mailbox messages from terminal toolsHimalaya email skillhimalaya CLI and ~/.config/himalaya/config.toml

---

Prerequisites

Explains the idea itself. Read it slowly; the later sections build on it.

  • A dedicated email account for your Hermes agent (don't use your personal email)
  • IMAP enabled on the email account
  • An app password if using Gmail or another provider with 2FA

Gmail Setup

  1. Enable 2-Factor Authentication on your Google Account
  2. Go to App Passwords ↗
  3. Create a new App Password (select "Mail" or "Other")
  4. Copy the 16-character password — you'll use this instead of your regular password

Outlook / Microsoft 365

  1. Go to Security Settings ↗
  2. Enable 2FA if not already active
  3. Create an App Password under "Additional security options"
  4. IMAP host: outlook.office365.com, SMTP host: smtp.office365.com

Other Providers

Most email providers support IMAP/SMTP. Check your provider's documentation for:

  • IMAP host and port (usually port 993 with SSL)
  • SMTP host and port (usually port 587 with STARTTLS)
  • Whether app passwords are required

---

Step 1: Configure Hermes

Ordered, practical steps. Run one and confirm it worked before moving on. Commands here: hermes gateway setup.

The easiest way:

Shell1 line
hermes gateway setup

Select Email from the platform menu. The wizard prompts for your email address, password, IMAP/SMTP hosts, and allowed senders.

Manual Configuration

Add to ~/.hermes/.env:

Shell14 lines
# Required
EMAIL_ADDRESS=hermes@gmail.com
EMAIL_PASSWORD=abcd efgh ijkl mnop    # App password (not your regular password)
EMAIL_IMAP_HOST=imap.gmail.com
EMAIL_SMTP_HOST=smtp.gmail.com

# Security (recommended)
EMAIL_ALLOWED_USERS=your@email.com,colleague@work.com

# Optional
EMAIL_IMAP_PORT=993                    # Default: 993 (IMAP SSL)
EMAIL_SMTP_PORT=587                    # Default: 587 (SMTP STARTTLS)
EMAIL_POLL_INTERVAL=15                 # Seconds between inbox checks (default: 15)
EMAIL_HOME_ADDRESS=your@email.com      # Default delivery target for cron jobs

---

Step 2: Start the Gateway

Ordered, practical steps. Run one and confirm it worked before moving on. Commands here: hermes gateway, hermes gateway install.

Shell3 lines
hermes gateway              # Run in foreground
hermes gateway install      # Install as a user service
sudo hermes gateway install --system   # Linux only: boot-time system service

On startup, the adapter:

  1. Tests IMAP and SMTP connections
  2. Marks all existing inbox messages as "seen" (only processes new emails)
  3. Starts polling for new messages

---

How It Works

Settings you configure once. Change one at a time so you can see what each does.

Receiving Messages

The adapter polls the IMAP inbox for UNSEEN messages at a configurable interval (default: 15 seconds). For each new email:

  • Subject line is included as context (e.g., [Subject: Deploy to production])
  • Reply emails (subject starting with Re:) skip the subject prefix — the thread context is already established
  • Attachments are cached locally:
  • Images (JPEG, PNG, GIF, WebP) → available to the vision tool
  • Documents (PDF, ZIP, etc.) → available for file access
  • HTML-only emails have tags stripped for plain text extraction
  • Self-messages are filtered out to prevent reply loops
  • Automated/noreply senders are silently ignored — noreply@, mailer-daemon@, bounce@, no-reply@, and emails with Auto-Submitted, Precedence: bulk, or List-Unsubscribe headers

Sending Replies

Replies are sent via SMTP with proper email threading:

  • In-Reply-To and References headers maintain the thread
  • Subject line preserved with Re: prefix (no double Re: Re:)
  • Message-ID generated with the agent's domain
  • Responses are sent as plain text (UTF-8)

File Attachments

The agent can send file attachments in replies. Include MEDIA:/path/to/file in the response and the file is attached to the outgoing email.

Skipping Attachments

To ignore all incoming attachments (for malware protection or bandwidth savings), add to your config.yaml:

YAML3 lines
platforms:
  email:
    skip_attachments: true

When enabled, attachment and inline parts are skipped before payload decoding. The email body text is still processed normally.

---

Access Control

Carries a warning. Read it before running anything here. The upstream warning appears below.

Email access is stricter by default than chat-style platforms:

  1. EMAIL_ALLOWED_USERS set → only emails from those addresses are processed
  2. No allowlist set → unknown senders are ignored silently
  3. EMAIL_ALLOW_ALL_USERS=true → any sender is accepted (use with caution)
  4. platforms.email.unauthorized_dm_behavior: pair → unknown senders receive a pairing code

---

Troubleshooting

A troubleshooting section. Find the symptom that matches yours rather than reading it end to end.

ProblemSolution
"IMAP connection failed" at startupVerify EMAIL_IMAP_HOST and EMAIL_IMAP_PORT. Ensure IMAP is enabled on the account. For Gmail, enable it in Settings → Forwarding and POP/IMAP.
"SMTP connection failed" at startupVerify EMAIL_SMTP_HOST and EMAIL_SMTP_PORT. Check that your password is correct (use App Password for Gmail).
Messages not receivedCheck EMAIL_ALLOWED_USERS includes the sender's email. Check spam folder — some providers flag automated replies.
"Authentication failed"For Gmail, you must use an App Password, not your regular password. Ensure 2FA is enabled first.
Duplicate repliesEnsure only one gateway instance is running. Check hermes gateway status.
Slow responseThe default poll interval is 15 seconds. Reduce with EMAIL_POLL_INTERVAL=5 for faster response (but more IMAP connections).
Replies not threadingThe adapter uses In-Reply-To headers. Some email clients (especially web-based) may not thread correctly with automated messages.

---

Security

Carries a warning. Read it before running anything here. The upstream warning appears below.

  • Use App Passwords instead of your main password (required for Gmail with 2FA)
  • Set EMAIL_ALLOWED_USERS to restrict who can interact with the agent
  • The password is stored in ~/.hermes/.env — protect this file (chmod 600)
  • IMAP uses SSL (port 993) and SMTP uses STARTTLS (port 587) by default — connections are encrypted

---

Environment Variables Reference

A lookup table. Do not read it all; find the row that applies to you.

VariableRequiredDefaultDescription
EMAIL_ADDRESSYes—Agent's email address
EMAIL_PASSWORDYes—Email password or app password
EMAIL_IMAP_HOSTYes—IMAP server host (e.g., imap.gmail.com)
EMAIL_SMTP_HOSTYes—SMTP server host (e.g., smtp.gmail.com)
EMAIL_IMAP_PORTNo993IMAP server port
EMAIL_SMTP_PORTNo587SMTP server port
EMAIL_POLL_INTERVALNo15Seconds between inbox checks
EMAIL_ALLOWED_USERSNo—Comma-separated allowed sender addresses
EMAIL_HOME_ADDRESSNo—Default delivery target for cron jobs
EMAIL_ALLOW_ALL_USERSNofalseAllow all senders (not recommended)
Knowledge check

5 questions answered by this page alone.

Every option is a real identifier from the Hermes documentation. The wrong ones are real too, just from other pages.

1. According to this lesson, which command does “Run in foreground”?
2. According to this lesson, which command does “Install as a user service”?
3. In this lesson's table, what is the “Solution” for “Messages not received”?
4. Which of these environment variables actually appears in this lesson?
5. Which warning does the source state in this lesson?