I’ve tried giving screenshots of phishing emails to a local Qwen instance and so far it always correctly detected it as scam, even points out the exact elements that it based its judgement on. Sending screenshots to it ad-hoc isn’t too scalable for family and friends. I’d like to be able to either forward emails for screening, or perhaps have it screen everything from a mailbox.
Has anyone done anything like this? Is there anything self-hostable that does this?
I’d be pretty concerned about prompt injection risks with feeding a LLM unsanitized data. You definitely need a good harness around it…
Good point. It’ll have to have no access to the internet or anything local outside of its container. Just text in, text out.
Yeah if it’s just a basic input with a function call for spam or not spam the risk is low. What’s the worst case outcome, it tricks it into saying no it isn’t a scam and you have to delete it manually? Hahaha
If your email service offers an MCP connection (Google does), you can have your AI connect and examine emails and manipulate them. You can hook that up to qwen using maybe lmstudio. I haven’t tried it self-hosted, but it sounds pretty straightforward.
LLM plugins should be available in standard spamfilters like Rspamd. Some mail servers like Stalwart have it as well. You pick a prompt and provide it with an OpenAI-compatible endpoint and it’ll ask the AI for every mail. Can be a local model.
Not sure if it’s in the Email clients as well. I found a few Thunderbird addons, but that was just a quick Google search.
Probably better to ask this in an ai community. However fwiw there are a few skills for generic imap checking. I’ve set up a local openclaw gateway and model with an automated task to check my email in the morning and basically prod me into replying. The same concept should be applicable to spam detection too.




