<!-- Envolt Mail · https://envoltmail.com/lab · Markdown version of this page for AI agents. Status: in development (https://envoltmail.com/status). -->

The Lab

# Try to break it.

Three instruments, each running the same code as our staging pipeline, in your browser. Edit anything. Nothing you type leaves your device.

[**Airlock X-Ray**Hidden instructions, smuggled text, forged quotes, look-alike senders.](https://envoltmail.com/lab#xray) [**Agent Seal verifier**Check a signed agent message, or forge one and watch it fail.](https://envoltmail.com/lab#seal) [**Ledger tamper test**Rewrite history in a sealed record and see exactly where it breaks.](https://envoltmail.com/lab#ledger)

Instrument 1 [Running in staging]

## Airlock X-Ray

One email, three ways: as a person sees it, as a naive agent reads it, and as Envolt's reader receives it after the Airlock.

The attack gallery on the web page loads red-team cases into the X-Ray: RT-001 Hidden forward instruction (Hidden text): caught by hidden-content; RT-002 Zero-size "approved" note (Hidden text): caught by hidden-content; RT-004 Invisible new bank details (Hidden text): caught by hidden-content; RT-010 ASCII smuggling (Invisible characters): caught by invisible-chars; RT-020 Zero-width split keyword (Invisible characters): caught by invisible-chars; RT-030 Visible override (Instructions): caught by override-lexicon; RT-031 Closing the quarantine block (Instructions): caught by override-lexicon, delimiter-break; RT-040 Forged quoted approval (Quoted-reply forgery): caught by quoted-authority; RT-041 Forged forward (Quoted-reply forgery): caught by quoted-authority; RT-003 A comment (stripped, not flagged) (Control): nothing to flag; CTRL-1 An ordinary reply (Control): nothing to flag.

Interactive demo on the web page: a sample email with hidden instructions, shown as a person sees it, as a naive agent reads it, and as Envolt's reader receives it after the Airlock (the real code, run in the browser).

### Look-alike senders

A sender can borrow your name with a letter from another alphabet. Try your own domain against a near miss.

Look-alike checker on the web page: compares a sender's domain with yours after folding look-alike characters and decoding punycode. Example: xn--nrthwind-nbh.example reads as northwind.example (its first "o" is Cyrillic), so it is flagged.

Instrument 2 [Running in staging]

## Agent Seal verifier

Every agent message is designed to carry a signed Agent Seal header: which agent, who it works for, how much autonomy it has. This is the verifier our staging pipeline runs. Try to break it, or paste your own.

Interactive demo on the web page: an example message with an Envolt-Agent-Seal header, verified in the browser by the same verifier our staging pipeline runs (Ed25519 over a canonical string of the seal fields, Message-ID and Date), with buttons to tamper with it and watch verification fail.

The header format is a [working draft](https://envoltmail.com/docs/builders#agent-seal).

Instrument 3 [Running in staging]

## Ledger tamper test

Every event is sealed to the one before it. Below is a short synthetic record, verified by our real ledger code. Change history and watch where it breaks.

Ledger tamper test on the web page: a sealed chain of 8 synthetic events, verified in the browser by the production ledger code. Changing a payload, re-hashing an edited event, deleting an event or swapping two events each breaks verification at a specific event, and the day's Merkle root stops matching the published anchor.

## Found a way past it?

Hidden text that survives the Airlock, a seal that verifies when it shouldn't, a broken chain that still verifies: tell us. A person reads every report, and fixes are credited on the [trust page](https://envoltmail.com/trust#thanks).

[Report a bypass](mailto:security@vaultsparkstudios.com?subject=Envolt%20Lab%20bypass)
