Agent questions

Can an AI agent safely read 2FA codes from your email?

It can if it checks who sent the code. Most ways of giving an agent email access hand it whatever message says "your code is 482913", and the line saying who sent that message is written by the sender.

Two ways a code goes wrong

A forged code comes in. Anyone can send you a message whose From line reads noreply@github.com. An agent that matches on the From address takes that message's code. Usually the login the agent is working on just fails. In a device-code sign-in, though, typing an attacker's code on the real site signs the attacker's device into your account. Microsoft reported Storm-2372 using that technique against people in February 2025, with the codes sent in fake Teams invitations.

A real code goes out. In August 2026 Zenity showed hidden instructions in an email turning Claude in Chrome into a relay: the agent watched Gmail for verification codes and passed them to the attacker, who used them to take over Slack and X accounts (SecurityWeek's write-up).

What Envelope checks before it hands over a code

envelope code waits for a message from the sender you name and returns the code in it. Before returning anything, it reads the authentication results your mail provider recorded when the message arrived. It needs DMARC to have passed for the domain in the From line, or DKIM to have passed with a signing domain that matches it while DMARC didn't fail. SPF alone isn't enough, because SPF checks the envelope sender, which can differ from the From line you see.

The harder part is knowing which results your provider wrote. Authentication-Results is an ordinary header, and a sender can include one that says dmarc=pass. RFC 8601 tells a receiving server to delete forged copies that carry its own name; copies carrying any other name pass through. Envelope counts results only when they carry your provider's domain and sit above the provider's own Received line, the point where the message entered its servers. Anything below that line arrived with the message, and Envelope treats it as unverifiable.

A message that fails these checks is skipped and the wait continues. If no authenticated code arrives before --wait runs out, the command ends with sender_unauthenticated or sender_unverifiable and lists the senders it skipped, without their codes. Every result includes a sender_auth field saying what Envelope found.

Which mailboxes pass today

Gmail works with no setup. Microsoft 365 records its results without naming the server that wrote them, and Migadu records them below its own Received line. In both cases a real result looks the same as one a sender wrote, so codes come back sender_unverifiable. For any other provider, run envelope code once with --json and read sender_auth.

If your provider receives mail under a different domain from its IMAP server, you can name that domain. If you accept the risk for an account, you can let it take unverified senders, and codes accepted that way report "unverifiable". Both settings are refused while an agent token is set, and no MCP tool changes them, so an agent can't switch the check off for itself.

envelope config set threat.receiver_domain you@example.com=<domain>
envelope config set otp.allow_unverified_senders you@example.com

Setup

Run the first three commands in your own terminal, so your password and the agent's token never pass through the agent. The last one is what the agent runs.

# Install on macOS or Linux
curl -fsSL https://u1f4e7.com/install.sh | bash

# Add the mailbox and create a token for the agent
envelope accounts add --email you@gmail.com
envelope agent create claude-code

# The agent waits up to two minutes for an authenticated code
envelope code --account you@gmail.com --from noreply@github.com --wait 120 --json

--from is required. Use the exact address the service sends codes from.

What Envelope doesn't cover

Envelope controls what leaves through Envelope. With an agent token, the agent can't email a code anywhere beyond what its send policy allows, and new agents start at draft-only, so anything they write waits for you. It also can't add a rule that posts mail to a webhook unless you grant rules.webhook by name. An agent that also drives a browser or has your shell has other ways to pass a code along, and Envelope can't see those. Give that kind of agent the narrowest access you can, and have it read codes only for logins you expected.