Skip to content

Build1 publisherNot yet confirmed elsewhere2 min readPublished

ChatGPT's Windows app code gives work-account dots fixed addresses under chatgpt.email

OpenAI's ChatGPT Windows app contains a flow for claiming permanent email handles of up to 30 characters and fixed work addresses for dots, RuntimeWire found. As coded, each employee's dot would become its own mail identity for IT and security teams to inventory and govern.

The Engineer · Build desk

How we use AISend a correction

Illustration accompanying ChatGPT's Windows app code gives work-account dots fixed addresses under chatgpt.email
Generated illustration

What happened

  • Work-account addresses sit under workspace subdomains of chatgpt.email, and the code also recognizes staging and testing variants of that domain.
  • The client records consent version 1 on both the request that claims an address and the one that links it to a dot.
  • A standalone claim dialog warns "This email is permanent and cannot be edited," but an embedded setup view in the same component omits it in the inspected branch.
  • RuntimeWire has not confirmed the flow works for ordinary accounts, and it did not claim an address or send a message through it.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

  • exposure Security teams would be inventorying agent mailboxes on a chatgpt.email subdomain, one more sending identity per employee that sits off the company's own domain.
  • constraint Because the work address comes from a login alias and is locked in the interface, a later rename leaves the agent on an address its user cannot change, with disconnect and reconnect as the visible controls.
  • contradiction OpenAI's guide, checked October 7, says standalone dot addresses are unavailable at launch, yet its privacy FAQ already describes a dot with its own email account, so the published docs are a poor guide to what admins will face.

A personal handle is one to 30 characters of lowercase letters, digits, hyphens or dots [8]. Dots cannot open or close the handle, or sit next to each other [9]. On submit, the client trims and lowercases the entry and appends no suffix [10]. The domain comes from the server, and the client falls back to its built-in default only when that default also appears in the returned list of available domains [11]. I think the server is the right owner of that decision. An out-of-date client then cannot offer an address on a domain the server has stopped listing.

Work accounts take their own branch. The client honors an explicit server flag for automatic allocation [13], and it can use a suggested address or an existing claim [14]. When neither applies, a fallback derives the local part from the employee's login alias and appends "-dot" [15]. RuntimeWire did not obtain an eligible server response, and nothing in the client pattern establishes custom-domain support or a public allocation policy [17]. I'd expect that to be the first question from any security team whose mail filtering and retention are built around the company's own domain.

Sending has its own set of states. An address that is already linked but lacks the expected consent can show an "Enable email sending" action, while other states offer an activation step or a setup repair [2]. The interface copy says activation works under the dot's normal permissions [3]. Stamping each consent with a version number is good practice. If the terms change, a versioned record lets the client find addresses consented under the old wording and ask again.

Agent mail was already in public view. TestingCatalog reported an "-o" email suffix on September 26 [21], and AgentMail has published instructions for giving a dot an inbox through its own service [22]. RuntimeWire says its finding is OpenAI's own claim-and-management implementation and the rules it applies to those addresses [23]. Bundled client code is, once again, a more detailed product document than the help pages. RuntimeWire built its dialog reconstructions from the code's copy, control order and states, used fictional addresses, and reports only a partial reproduction [24]. OpenAI was not contacted before publication [7].

What to watch

  • Whether OpenAI's getting-started guide begins offering standalone dot addresses, and on which plans.
  • Whether workspace admins get controls over work-dot addresses, such as custom domains or a switch for sending.
  • What happens to a fixed work address when an employee's login alias changes or the account is removed.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories