Mail Caduceus for Openclaw

Mail Caduceus is an enterprise-grade automation skill that transforms a single Microsoft 365 mailbox into a multi-lane identity control plane using Cloudflare DNS.

lmtlssss
v1.0.3
Mar 6, 2026
0
0
0

Install & Download

1. ClawHub CLI

The fastest way to install a skill directly from the registry.

npx clawhub@latest install mail-caduceus-v1

2. Manual Installation

Copy the skill folder to one of these locations

Global
~/.openclaw/skills/
Workspace
<project>/skills/

Priority: Workspace > Local > Bundled

3. Prompt Installation

Copy this prompt to OpenClaw to install it automatically.

Help me install mail-caduceus-v1 using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).

Prefer to download?

Get the raw skill files in a ZIP archive.

What is Mail Caduceus?

Mail Caduceus is a powerful technical framework designed to manage sophisticated email operations from a minimal infrastructure footprint. By integrating Openclaw Skills with Microsoft 365 and Cloudflare, it allows a single mailbox to function as a control hub for numerous branded sender lanes. This eliminates the need for mailbox sprawl while maintaining professional sender identities across various subdomains.

This skill automates the complex coordination required between Entra ID authorization, Exchange transport rules, and Cloudflare DNS records. By utilizing Openclaw Skills to handle the lifecycle of email aliases, developers can ensure high deliverability and hardened security posture (SPF, MX, DMARC) for every outbound identity, whether they are reply-capable support channels or dedicated no-reply transactional lanes.

Mail Caduceus Use Cases

  • Creating branded outreach lanes with unique subdomain identities to protect root domain reputation.
  • Automating the setup of no-reply transactional email addresses with hardened DNS profiles.
  • Managing support aliases that automatically route back to a primary administrative mailbox.
  • Scaling personalized sales communication using unique sender identities for different campaigns.
  • Hardening domain security posture by auditing and enforcing SPF, MX, and DMARC defaults via Openclaw Skills.

How Mail Caduceus Works

  1. Authentication Bootstrap: The skill performs an interactive sign-in to grant Microsoft Graph and Exchange RBAC permissions.
  2. Infrastructure Audit: It audits the existing credential posture across Graph and Cloudflare token scopes to ensure secure operations.
  3. Posture Optimization: Root-domain mail records, including SPF, MX, and DMARC, are optimized with safe defaults to prevent spoofing and improve deliverability.
  4. Lane Provisioning: Specific identities are created as aliases under subdomains, with logic for either reply-capable or no-reply configurations.
  5. State Verification: The skill verifies lane readiness by checking accepted domains, alias attachment status, and DNS profile propagation.
  6. Lifecycle Control: Aliases are managed through their full lifecycle, including retirement with fallback continuity or secure hard-deletion.

Mail Caduceus Setup

To deploy this skill within the Openclaw Skills ecosystem, follow these steps:

  1. Prepare credentials by copying the templates:
cp credentials/entra.txt.template credentials/entra.txt
cp credentials/cloudflare.txt.template credentials/cloudflare.txt
  1. Configure your specific environment variables in the newly created .txt files.

  2. Execute the primary bootstrap script to initialize the control plane:

./scripts/mail-caduceus.sh --organization-domain "yourdomain.com"
  1. For headless steady-state operations, ensure ENTRA_CLIENT_SECRET is set and use the --skip-m365-bootstrap flag.

Mail Caduceus Data Schema & Taxonomy

Mail Caduceus organizes its configuration and operational state using a structured file system and metadata taxonomy:

Data Type Location Description
Credentials credentials/*.txt Strict KEY=VALUE pairs for Entra and Cloudflare access.
Intel/State MAIL_CADUCEUS_INTEL_DIR Directory containing atomic operation outputs and resumable state files.
Operations JSON Script Inputs JSON structures defining actions like alias.remove or provision-lane.
Environment .env (Optional) Persisted runtime keys and non-secret configuration toggles.

Mail Caduceus Advanced Features

  • Support for no-reply identities with specialized 'SPF -all' profiles to prevent inbound noise.
  • Automated reply fallback logic that ensures continuity even when a specific alias is retired.
  • Headless execution mode using Entra Client Secrets for integration into CI/CD or automated workflows.
  • Dry-run capability to simulate complex alias and DNS changes before committing to the provider.
  • Restrictive file permission enforcement (700/600) for all generated state and credential artifacts.
  • Multi-lane provisioning allowing one mailbox to serve dozens of distinct subdomains simultaneously.

SKILL.md


Loading

Related Openclaw Skills

METADATA

Requires
Bins bashpwshpython3jqrg
Github Stars: 0
forks: 0

Featured*