Released September 12, 2026 — downloads for this release
Please update. A specially written HTML email could run its own JavaScript inside the component that displays message bodies, on nothing more than opening the message. Script that ran this way could read the message you were reading and send it elsewhere, and it could suppress the spoken confirmations QuickMail delivers from inside a message — the invitation RSVP result, and the link menu’s report when a copy fails — so that an action appeared to have succeeded when it had not.
Message bodies are displayed under a Content Security Policy that forbids script, and a stripping pass removes script blocks before they ever reach the display. Two flaws had to line up for either to be got past, and both are fixed: the policy is now always written into the part of the document where a browser reads it, and the stripping pass now recognises the ways of closing an element that it previously did not.
It affects QuickMail 0.7.0 and later. It was found by review rather than by anything going wrong, and was reported privately rather than published.
Create Rule from Message (Ctrl+Shift+T)
filled in the sender and the subject of the message you were
reading, and the rule editor had no way to say which of them the rule
was supposed to use. Both were conditions, both had to match, so “Rule
for someone@example.com” quietly became a rule that matched that sender
only when the subject was the exact line it was made from — in practice,
the one conversation you started from.
Each text condition in the editor now has its own checkbox in front of it: From addresses, Subject contains, and the four under Advanced conditions & actions (Sender contains, Sent to addresses, Subject or body contains, Body contains). A message has to satisfy every condition you checked, so leaving one unchecked is how you say “don’t care”. Clearing a checkbox keeps the text in its box — read-only and skipped by Tab, but one keystroke from being part of the rule again, rather than something you have to retype.
Creating a rule from a message uses that: the sender arrives checked, and the subject arrives unchecked with its text ready to switch on. So the rule you get by default is the one the name says — everything from that sender. (#665)
View → View Mode offers four choices — Messages, Conversations, From, To — but arrowing through them announced “1 of 8”, “2 of 8”, and so on. The menu actually held eight items: the four above plus the four calendar views (Agenda, Day, Week, Month), which were hidden rather than removed while you were reading mail. Hiding a menu item takes it off the screen but leaves it in the menu, so it still counted.
The menu now holds only the choices that apply: the four mail views while you are in a mail folder, and the four calendar views while the calendar is open. The count you hear matches what is there.
The View mode button on the toolbar
(Ctrl+Shift+V) drops the same list, so it is fixed the same
way — it was counting seven — and it gains Month, which
it had been missing while the calendar is open. Two View menu entries
are renamed to match what the toolbar button, the folder tree and the
user guide have always called them: By Sender and
By Recipient are now From and
To. Settings → General → View → Display
mode, which sets the same four modes, follows suit and reads
From (grouped by sender) and To (grouped by
recipient). (#663)
QuickMail had two Rules windows behind the scenes, and which one you got depended on how the account connected rather than on what it could actually do. An account connected through Microsoft 365 opened a fuller window — the one that can also show rules that run on the server; an account connected the ordinary IMAP way opened a simpler one.
A personal Outlook.com account connected through Microsoft 365 is the case that went wrong. It connects the same way a work or school account does, so it was handed the fuller window — but a personal account cannot have server-side rules, so in that window the Move Up and Move Down buttons never came to life, and creating a rule popped up a box telling you it had been saved as a client-side rule instead. Neither made sense for an account that was only ever going to run its rules inside QuickMail.
There is now a single Rules window for every account. It shows what the selected account supports — server-side rules for a work or school account, client-side rules for everyone else — and the window’s status line says which kinds the account can have, so an empty list is never a mystery. F6 cycles the panes — account list, rules, details, status line — so it reaches that status line and reads it back at any time.
That replaces a spoken message on every account you landed on, which meant arrowing down the account list said a sentence about each account you passed through on the way to the one you wanted. The pop-up box after saving a rule is gone as well; on an account that has no server rules there was never anything surprising to report.
One place still speaks up: on a work or school account, a rule that uses something only QuickMail can do — marking a message unread, say — is saved as a client-side rule rather than a server-side one, and because that account does also do server rules, QuickMail announces that when it happens. The rule’s own row reads on client regardless, so where it went is there to read with announcements off.
The single window also brings back a safeguard the old one had. A Move to folder or Delete rule must now have at least one condition before it can be saved: with none, a rule matches every message, and rules run on mail as it arrives and through Run on Existing Mail, so it would empty the Inbox. This covers server-side rules too, since Exchange treats a rule with no conditions the same way. A server-side rule made in Outlook with no conditions still runs, and can still be turned on or off from QuickMail, but QuickMail asks for a condition before it will save a change to it.
Which account a new rule belongs to is now decided by where you are. A new rule belongs to the account the Rules Manager is showing, and it opens on the account of the folder or view you are in; from a view that spans accounts, such as All Inboxes, it opens on your default account. Before, a profile with no Microsoft 365 account got a window that gave every new rule your default account, and a profile with one got a window that opened on whichever account you had last visited or read a message from.
In the rules list, Space on a rule reliably turns it on or off. And Test, which checks a rule against its own account’s messages in the message list, now says so instead of calling them your selected messages. (#550)
QuickMail cannot reach a shared mailbox’s server-side rules: signing in as yourself does not give access to another mailbox’s rules, and no permission QuickMail can ask for changes that. Opening the Rules Manager on a shared mailbox used to ask you to get an administrator to grant a permission that was already granted, and that would not have helped if granted again.
A shared mailbox is no longer in the Rules Manager’s Account list. If you open the Rules Manager from one, the window shows your default account instead, names it in the title, and says on its status line that the shared mailbox’s rules are managed in Outlook. Create Rule from Message is not in the context menu for a shared mailbox’s messages, and Ctrl+Shift+T and the command palette say why instead of making a rule. In the mailbox’s folders the rule summary on the status bar says its rules are managed in Outlook instead of counting rules. Everywhere else the summary now says it counts client-side rules, because server-side rules were never in its count. And a client-side rule saved on a shared mailbox by an earlier version is kept but no longer runs: it acted, from one person’s computer only, on mail everyone with access to the mailbox reads. (#678)
Pressing Delete on a message could produce a spoken “unavailable” before the next message was read, and the confirmation that followed could cut that reading off. Two separate faults, both now fixed.
The “unavailable” came from the order things happened in. The deleted row was taken out of the list while it still held keyboard focus, which leaves focus on a row that no longer exists — Windows then describes that row as a disabled control, and a screen reader says so. Focus now moves to the message you are about to land on before the deleted one leaves the list, so there is never a moment where the focused row is a row that has gone. Delete and Archive both do this.
The confirmation was the second half. Deleting one message announced “1 message deleted” a moment after the next message started being read — telling you something you had just been told, by interrupting the sentence that told you. A single delete or archive now says nothing. The row is gone and the next one is read: that is the confirmation.
What still speaks is anything you could not otherwise know: a count
when you acted on several at once (“3 messages deleted”), “Folder is now
empty” when the last one goes, and every failure. All of it still
appears in the status bar, and Ctrl+9 reads the status bar
on demand.
This is not the announcement setting doing its job — Settings → Accessibility → Announce delete, archive and move actions is still on by default and still controls the announcements that remain. Nothing to turn off, and nothing to turn back on. (#667)
Pressing Shift+F10 with focus in the message body moved focus out of the message and back to the message list. Nothing had closed, but there was no way to tell that from the outside: you were reading, and then you were on the list.
Windows reports “no element has focus” in two unrelated situations — at startup, before any pane has been focused, and whenever focus is inside the message body, which sits in a separate window of its own underneath. QuickMail had a piece of startup repair that read the second as the first, and moved focus to the message list to correct a problem that was not happening.
Reading a message is now told apart from having nothing focused, so focus stays where you are reading. On ordinary body text the key now does nothing, rather than doing the wrong thing; on a link it opens a menu — see a context menu on links in a message, below.
Shift+F10 and the Applications key on the message list, the folder tree, and the attachment list are unaffected and open the same menus as before, including on the first press after launch. (#672)
Pressing Shift+F10 or the Applications key on a link in a message did nothing. The link could be opened with Enter, but there was no way to copy where it went — or to find out where it went without going there.
Links in a message now have a context menu, reached with Shift+F10, the Applications key, or a right-click:
A copy that works says nothing — it did what you asked. A copy that fails writes a line at the end of the message, starting QuickMail:, and in the reading pane also puts it in the status bar where Ctrl+9 reads it back. That line is not usually spoken as it appears, because it is written just as the menu closes and your screen reader is already announcing its way back into the message; it is there to be found rather than to interrupt.
Copying the address is how you check where a link goes before following it, and comparing it with the link’s text is how you spot a link that does not go where it says it does.
Escape closes the menu and leaves you exactly where you were — on the link you opened it on, not at the top of the message and not back on the message list. The menu works the same way in the reading pane, in a message tab, and in a message window. It is offered for ordinary web and email links, and not for the Accept / Tentative / Decline buttons on a meeting invitation, which are internal to QuickMail; on ordinary body text the key does nothing, as before. (#671)
Pressing F6 while reading a message skipped ahead: instead of moving to the pane after the reading pane, it carried on from the toolbar and landed on the account list. Coming back the other way, focus was not returned to the message after changing the view mode.
Windows reports no focused element while the message body has focus — the message is drawn by a separate component with its own window, so the focus QuickMail can see has moved outside its own controls. Two pieces of code asked the question in a way that could not be true at the time they asked it, so the reading pane was never recognised as the pane you were in.
Both now use the same test, and it is one that works while you are reading. (#673)
Moving messages to another folder, or unwatching a conversation while the Watched Conversations folder is open, could make a screen reader say “unavailable” before the next message, as deleting did before 0.8.45. Focus now lands on the next message before the moved or unwatched ones leave the list. When the last message goes, focus goes to the empty list, instead of staying in a message that is no longer there. Unwatching a conversation from a message window, or from the Watched Conversations manager, no longer pulls focus into the main window.
Moving now speaks as deleting does. A single move says nothing, since the next message is being read, while moving several says the count, and emptying the folder says so. The setting that controls these is renamed Settings → Accessibility → Announce delete, archive and move actions. A move that fails is announced as a result, so you hear it even with that setting off. If you had turned that setting off but left Announce action results on, you will no longer hear how many messages a move moved: those counts used to be results. (#670)