# 0.96.0 — Real email receiving

Supported browser studies can now give each participant a fresh AgentMail inbox.
The application sends normally; participants open their own inbox, read the email
and follow its confirmation link. Local capture remains a separate option for
apps whose send configuration can point at a test catch.

Connections checks authentication after hidden key entry and offers lab
configuration and pending cleanup. Lab configuration previews a separate ignored
copy, preserves the original, checks for stale previews and launches by exact
selected path. Agents have matching `comms check`, `comms configure` and
`comms recover` commands.

Provider credentials remain on the host. Participants receive isolated loopback
mail surfaces with original/plain views, supported inline raster images and a
consistent allowed-origin link policy. Remote images and active HTML are blocked;
missing content is explicit. Collection and publication are bounded and distinct
from a participant reading mail. Later reads can fill temporarily missing content.

Fresh mailbox ownership is recorded privately before acquisition. Normal teardown
saves evidence and confirms provider deletion. Interrupted runs have explicit,
project/account-bound recovery; mutable recording IDs cannot authorize deletion.
Evidence-write failures retain the inbox as unresolved.

Real mail may reach hosted desktops, actor/analysis models and recordings. These
runs have a durable `local_only` publication restriction; blurring screenshots
does not make them shareable. Immediate analysis uses the run's temporary scrub
registry for generated narration, without saving raw secret values. Later analysis
cannot reconstruct that registry and remains subject to the same publication gate.

This release supports hosted computer-use app-url, clone and local-tree routes,
including concurrent shared worlds. It rejects local-agent and unsupported routes
before allocation. SMS, outbound participant mail, borrowed inboxes, arbitrary
attachments and raw-MIME fallback remain unavailable.

See [setup, behavior and recovery](../architecture/real-email-receiving.md) for
configuration, processing disclosures and limits.

Validation includes captured provider-wire contracts, crash/recovery and credential
isolation tests, outer-runner tests for clone/local-tree and concurrent shared-world
routes, inbox browser checks at desktop/phone widths, and hidden-key TUI proof.
A retained live app-url study, `real-email-57ed0512-218d-4e58-9f76-c540541d0b56`,
had two concurrent participants receive separate emails, follow their own links,
reach the target dashboard and finish automatic analysis. Provider absence was
confirmed for both participant inboxes and the synthetic sender. Raw mail and
recordings remain private. This does not establish delivery for every target app
or live-provider coverage of every execution route.
