Foreword

The core design philosophy of DeepSeek Harness is “everything is a plugin.” When building agents that need to access external data, email systems are one of the high-frequency scenarios. However, since September 2024, Microsoft has stopped supporting IMAP basic authentication (username + password) for personal Outlook.com accounts, accepting only OAuth2. Most email plugins on the market (including the marketplace version dsh-email) still rely on password login, which prevents developers from reading Outlook emails through those plugins. DSH-EmailReader is designed to fill this gap by providing DSH with native OAuth2-supported email reading capabilities.

Introduction

DSH-EmailReader is the DeepSeek Harness IMAP email reading plugin (OAuth2 version). The project is maintained by huaxiren6, categorized as an online tool, and licensed under the MIT License. The plugin is based on the imapflow library to connect to any IMAP mailbox, enabling the model to read emails.

Core Features

The plugin provides three core tools, all registered with the ol_email_ prefix to ensure no conflicts with marketplace plugins:

  1. ol_email_list: Lists the most recent emails in the inbox. Returned information includes sender, subject, time, and flags.
  2. ol_email_read: Reads the full content of a single email. Supports automatic MIME parsing and is compatible with Outlook servers.
  3. ol_email_search: Performs server-side IMAP full-text search. Search results are ordered by newest first.

Other features include multi-account support, OAuth2 authentication, HTTP/SOCKS proxy support, and a unified { ok, ... } return format that never throws exceptions.

Installation

Install using the official command:

dsh plugin --profile web add dsh-email-reader

Configuration

The plugin supports both OAuth2 and password authentication, and provides environment variable configuration options.

Suitable for mailboxes that enforce OAuth, such as Microsoft’s. The configuration must include refreshToken, clientId, and tokenUrl.

- insert:
    - id: email-reader
      name: dsh-email-reader
      config:
        accounts:
          - id: outlook
            host: outlook.office365.com
            port: 993
            user: you@outlook.com
            refreshToken: "从 OAuth 授权流程获取"
            clientId: "你的应用 Client ID"
            tokenUrl: "https://login.microsoftonline.com/common/oauth2/v2.0/token"
            mailbox: INBOX

Password Authentication

Suitable for IMAP servers that still support password login.

- insert:
    - id: email-reader
      name: dsh-email-reader
      config:
        host: imap.example.com
        port: 993
        user: you@example.com
        pass: your-app-password
        tls: true
        mailbox: INBOX

Proxy Settings

If you encounter network restrictions (such as accessing Gmail from an education network), you can configure a proxy.

- insert:
    - id: email-reader
      name: dsh-email-reader
      config:
        accounts:
          - id: gmail
            host: imap.gmail.com
            port: 993
            user: you@gmail.com
            pass: your-app-password
            proxy: "http://127.0.0.1:7892"
            mailbox: INBOX

Environment Variables

If you want to avoid persisting credentials to disk, you can use environment variables:
DSH_IMAP_HOST, DSH_IMAP_PORT, DSH_IMAP_USER, DSH_IMAP_PASS, DSH_IMAP_TLS, DSH_IMAP_MAILBOX, DSH_IMAP_OAUTH_REFRESH, DSH_IMAP_CLIENT_ID, DSH_IMAP_TOKEN_URL, DSH_IMAP_PROXY.

Usage Examples

To complete email operations in DSH, call the following tools:

  1. View the email list: Call ol_email_list.
  2. Read email content: Call ol_email_read.
  3. Search emails: Call ol_email_search.

Notes

  • The plugin can coexist with the marketplace version dsh-email; the tool name prefix is ol_email_* to avoid naming conflicts.
  • It is suitable for scenarios where Microsoft enforces OAuth after September 2024.
  • The plugin runs using the permissions of the current DSH process; it is recommended to check the source code and license before installation.

Summary

This plugin solves the email access challenge in the OAuth2 era and provides developers with stable, compatible email reading capabilities. Complete documentation and source code can be found in the project directory and GitHub repository.