Grok Bot's Windows app ALSO contains a gated email-address workflow
The client includes mail.grokbot.com address creation and a multiple-inbox view that exposes another creation control while fewer than 10 addresses are listed. RuntimeWire found the workflow shortly after reporting a similar email-address setup flow in ChatGPT code; access and delivery remain unverified in both cases.
By Ryan Merket · Published
RUNTIMEWIRE INVESTIGATION — Original analysis
Original reporting by RuntimeWire, based on reverse engineering, testing.
Why it matters
The Windows client contains gated paths for requesting email addresses, but the package does not establish whether users can obtain one, what access rules apply or whether mail delivery works.
Reporting record
Finding
RuntimeWire's static inspection of a verified Windows x64 package found client-side code for creating and listing @mail.grokbot.com inboxes, including a multiple-inbox creation control shown while fewer than 10 addresses are listed.
How we verified
Methods: reverse engineering, testing.
Original reverse-engineering report submitted by a RuntimeWire writer agent; editor review required.
Technical testing and reverse engineering documented in the linked internal reporting record.
Tested versions: Grok Bot Windows x64 0.68.1 (statically inspected; not run).
Reproduction
RuntimeWire partially reproduced the finding.
Reverse engineer binary and CNTRL-F 'new features'
Company response
The company was not contacted before publication.

Grok Bot includes a gated email-address workflow in its Windows client, with address creation at mail.grokbot.com and a second interface that offers another inbox while fewer than 10 are listed. RuntimeWire found the implementation in a verified Windows x64 package during an October 7th inspection. The code establishes that the client is built to request and display inboxes; it does not establish that users can claim an address or send and receive mail.
There is a small irony in the timing: RuntimeWire had just reported that ChatGPT's Windows app contains a native email-address setup flow for its dots, including permanent personal handles and fixed work-account addresses. That report found claim and activation controls in ChatGPT's code. Grok Bot's inspected client shows inbox-listing and address-creation paths, while successful access and delivery remain unverified. Two AI assistants now have email workflows visible in their Windows code; neither finding confirms that users can use the feature.
xAI's Grok Bot documentation describes Grok Bot as a set of AI teammates working on a persistent cloud computer with access to a browser, files and connected tools. An inbox could give an agent a separate communications identity for tasks involving registrations, correspondence or support queues. The inspected address-creation request contains no agent identifier, however, so the code does not show that each Bot gets its own mailbox.
What the client contains
In the single-inbox view, Grok Bot loads the account's inbox list. If the list is empty, the client presents an "Email address" form with the placeholder "Choose a name," the fixed @mail.grokbot.com suffix and a "Create address" button. Before submitting, it trims spaces from the requested name and converts it to lowercase. If an address is returned, the client can display it.

A separate feature gate selects a multiple-inbox view. That screen lists returned addresses and exposes another creation control while the displayed count is below 10. The predicate is part of the inspected interface; it is not evidence of a server-enforced quota, account eligibility rule or price.
The client code connects the form to desktop request handlers named ListGrokBotEmailInboxes and CreateGrokBotEmailInbox. The creation handler expects the service to return an inbox and raises an error if it does not; server refusal messages also have an error path. A team-policy field, agentEmailAllowed, separately affects whether the email feature appears. Both email-related feature gates have fallback defaults set to off in the bundled catalog. Those defaults describe the fallback configuration, not the live values xAI's service may return.

RuntimeWire downloaded the official Windows package, verified its Anysphere signatures and statically inspected the extracted application without installing or running it. No feature was activated, no account was accessed, and no address was claimed. The package also names methods for sending email and retrieving threads. Method names establish contract definitions, not functioning service behavior; address listing and creation have a more complete client path, while successful mail delivery remains untested.
The package does not date the feature
The package identifies itself as version 0.68.1, but that does not date the email implementation. RuntimeWire had no earlier package for comparison, so the code may have appeared before this build. The finding describes what was present in the inspected client, not a newly announced release or a confirmed launch.
A feature can be present in a signed package while gates, team policy or server-side eligibility keep it out of users' hands. The client-side limit also says little about the service's actual policy. The inspection did not establish who operates the mail service, how addresses are authenticated, what happens to mailbox data, or whether sending requires approval.
Grok Bot users already have ways to connect agents to email. On September 2nd, Aaron Makelky published a Cloudflare-based setup built around a domain he controls, describing an approach that keeps the email system outside Grok Bot. A community AgentMail guide also documents a third-party inbox option. These are existing alternatives, not evidence that the native workflow is available. Cloudflare's agent email documentation describes how developers can configure agents to send, receive and route email through its services.
A native address form could reduce setup for users who want an identity for an agent without assembling a separate provider and domain. The inspection did not claim an address or test whether a Bot could use one.