Untrusted senders
When you download from the Email browser, GeoInbox checks the sender against your trust rules. If the sender is not trusted, you must confirm before any file is saved to disk.
Trust modes
Trusted accounts
Explicit email addresses (colleagues, known field teams) that may send attachments without prompts.
Network trusted (CIDR)
Trust senders from IP ranges or domains on your organisation network.
GISimple auto-trust
When connected to GISimple, members of your group can be treated as trusted for shared datasets.
Trust all
Skips confirmation for every sender. Convenient only in isolated lab setups — not recommended for production mailboxes.
Configure these in the GeoInbox Settings tab. See also Settings & configuration.
Credentials
- Email and database passwords are stored in the QGIS Credential Manager (encrypted by QGIS).
- GISimple login uses token-based auth; tokens refresh in the background while QGIS is open.
- Standalone IMAP/POP3 accounts can be stored in the plugin’s local SQLite configuration when not using GISimple auth.
Safe practices
Review before you open in QGIS
GIS attachments are normal files on disk. Only open data from senders you recognise. ZIP archives are extracted under your download folder — inspect contents if the message looks suspicious.