Sample CodemacOSReviewed 2026-07-21View on Apple Developer

Build Mail App Extensions

At a glance

Item Summary
Purpose Create app extensions that block content, perform message and composing actions, and help message security.
App architecture A Swift sample with the source-visible chain AppDelegateComposeSessionViewControllerComposeSessionHandlerMailKit APIs.
Main patterns Delegate or data-source callbacks
Project style 11 scanned source file(s) across Swift, organized around ranked entry, type, and file boundaries.
Execution model Source-visible boundaries: async declaration or closure; none alone proves a background thread.
State/event model No structured observation or publisher-scheduling marker indexed.
Key frameworks/packages MailKit, Cocoa, Foundation; these are source dependencies, not architecture labels.

Project structure

Source bundle/
├── MailExtensions/
│   ├── MailExtensions/
│   │   ├── AppDelegate.swift
│   │   └── ViewController.swift
│   └── SampleMailExtensions/
│       ├── Compose Session/
│       │   ├── ComposeSessionHandler.swift
│       │   └── ComposeSessionViewController.swift
│       ├── Message Security/
│       │   ├── MessageSecurityHandler.swift
│       │   ├── ExampleSigningViewController.swift
│       │   └── MockEncoder.swift
│       ├── SpecialProjectHandler.swift
│       ├── Message Actions/
│       │   └── MessageActionHandler.swift
│       ├── Content Blocker/
│       │   └── ContentBlocker.swift
│       └── MailExtension.swift
└── Configuration/
    └── SampleCode.xcconfig

Structure observations

  • Architecturally prominent files are ranked from entry points and role-named declarations; resource-only paths are omitted.
  • Primary languages: Swift.
  • The verified tree contains 9 project/configuration file(s) and 15 source declaration(s).

Overall architecture

Reference code

MailExtensions/MailExtensions/AppDelegate.swift:10 — architecture anchor

@main
class AppDelegate: NSObject, NSApplicationDelegate {

    func applicationDidFinishLaunching(_ aNotification: Notification) {}

    func applicationWillTerminate(_ aNotification: Notification) {}

}

Interpretation

The arrows summarize the source-visible entry, role-named types or folders, and framework direction; when nodes come from structural folders, the sequence is a high-level interpretation rather than proof that every adjacent node calls the next. Ownership is claimed only where the next section cites a stored property or assignment. The diagram is intentionally limited to the dominant path into MailKit.

Ownership and state

Ownership evidence

MailExtensions/SampleMailExtensions/Message Security/MessageSecurityHandler.swift:12 — stored dependency or nearest verified ownership anchor

class MessageSecurityHandler: NSObject, MEMessageSecurityHandler {
    // ...
    static let shared = MessageSecurityHandler()
    // ...
}
Owner Object or state Relationship Mutation authority
MessageSecurityHandler MessageSecurityHandler (shared) creates and retains Initialized by the owner; the binding is immutable
SpecialProjectHandler SpecialProjectHandler (sharedHandler) creates and retains Initialized by the owner; the binding is immutable
SpecialProjectHandler Array (verifiedEmails) owns value state Initialized by the owner; the binding is immutable
SpecialProjectHandler SpecialProject (selectedSpecialProject) stores or receives App/module collaborators

Composition arrows indicate a source-visible construction expression or locally owned value state; aggregation means the owner stores or receives a dependency without proving exclusive lifetime ownership.

Concurrency, scheduling, and thread safety

Evidence limit: actor isolation, async/await, or Task creation does not by itself prove background-thread execution; Sendable conformance alone does not prove thread-safe mutation.

Concern Source mechanism Verified placement or handoff Evidence
Suspension boundary async declaration or closure The source declares or crosses an asynchronous boundary; it does not by itself establish background execution. MailExtensions/SampleMailExtensions/Compose Session/ComposeSessionHandler.swift:22

@MainActor/MainActor.run, DispatchQueue.main, and RunLoop.main are reported as distinct isolation, queue, and event-loop mechanisms. A plain Task is kept separate from Task.detached; neither is labeled as a background thread.

Reference code

MailExtensions/SampleMailExtensions/Compose Session/ComposeSessionHandler.swift:22 — representative execution boundary

    func annotateAddressesForSession(_ session: MEComposeSession) async -> [MEEmailAddress: MEAddressAnnotation] {
        var annotations: [MEEmailAddress: MEAddressAnnotation] = [:]
        // ...
    }

State propagation, frameworks, and dependencies

Evidence limit: an import proves a source-level compilation dependency at the cited line; it does not prove runtime use, architectural adoption, or whether a Swift package is a direct application dependency.

Category Mechanism or module Verified role Evidence
Source import MailKit The cited file imports this module; runtime use and architectural role are not inferred. MailExtensions/SampleMailExtensions/Compose Session/ComposeSessionHandler.swift:8
Source import Cocoa The cited file imports this module; runtime use and architectural role are not inferred. MailExtensions/MailExtensions/AppDelegate.swift:8
Source import Foundation The cited file imports this module; runtime use and architectural role are not inferred. MailExtensions/SampleMailExtensions/Message Security/MockEncoder.swift:11

receive(on:) describes downstream delivery scheduling, while subscribe(on:) describes upstream subscription/request/cancel scheduling. An import Combine alone establishes neither behavior nor a Store, reducer, Redux, or other application architecture.

Class and protocol design

MailExtensions/MailExtensions/AppDelegate.swift:11 — representative type boundary

@main
class AppDelegate: NSObject, NSApplicationDelegate {
    // ...
    func applicationDidFinishLaunching(_ aNotification: Notification) {}
    // ...
}
Type Responsibility Depends on or conforms to
AppDelegate Receives callback-driven events NSObject, NSApplicationDelegate
ComposeSessionHandler Handles callbacks or feature events NSObject, MEComposeSessionHandler
MessageSecurityHandler Handles callbacks or feature events NSObject, MEMessageSecurityHandler
SpecialProjectHandler Handles callbacks or feature events Concrete collaborators/imported frameworks
ViewController View lifecycle, callbacks, and feature coordination NSViewController
ComposeSessionViewController View lifecycle, callbacks, and feature coordination MEExtensionViewController
MessageActionHandler Handles callbacks or feature events NSObject, MEMessageActionHandler
ExampleSigningViewController View lifecycle, callbacks, and feature coordination MEExtensionViewController
ComposeSessionError Represents feature failure conditions LocalizedError
MessageSecurityError Represents feature failure conditions Error

No local protocol conformance is claimed as protocol-oriented design; external framework conformances are listed only as dependencies.

Access control

Symbol Access Verified effect Likely rationale
shouldEncode (MailExtensions/SampleMailExtensions/Message Security/MockEncoder.swift:16) private Use is restricted to the lexical declaration and same-file extensions allowed by Swift. Inference: hide an implementation step that is not part of the collaboration surface.
ComposeSessionHandler (MailExtensions/SampleMailExtensions/Compose Session/ComposeSessionHandler.swift:8) implicit internal No explicit modifier means the Swift declaration is internal to the module. Inference: app-target collaboration needs no exported library surface.

Reference code

MailExtensions/SampleMailExtensions/Message Security/MockEncoder.swift:16 — representative boundary

    private func shouldEncode(_ message: MEMessage) -> Bool {
        true
    }

Swift declarations without a modifier are internal; explicit private, fileprivate, private(set), public, or open entries above are interpreted by language semantics. Objective-C/C samples instead rely on header and implementation boundaries, which are not equivalent to Swift lexical privacy.

Logic ownership and placement

Logic Owning type or file Placement rationale
View lifecycle, callbacks, and feature coordination ComposeSessionViewController, ExampleSigningViewController, ViewController The source’s Controller suffix makes this role explicit.
Receives callback-driven events AppDelegate The source’s Delegate suffix makes this role explicit.
Handles callbacks or feature events ComposeSessionHandler, MessageActionHandler, MessageSecurityHandler, SpecialProjectHandler The source’s Handler suffix makes this role explicit.

Design patterns

Pattern Source evidence Purpose or tradeoff
Delegate or data-source callbacks MailExtensions/MailExtensions/AppDelegate.swift:11 Callback protocols invert event delivery back into the sample’s owner.

Naming conventions

  • Types: Controller: ComposeSessionViewController, ExampleSigningViewController, ViewController; Delegate: AppDelegate; Handler: ComposeSessionHandler, MessageActionHandler, MessageSecurityHandler, SpecialProjectHandler.
  • Protocols: no local protocol declaration in the scanned source.
  • Methods: applicationDidFinishLaunching, applicationWillTerminate, mailComposeSessionDidBegin, mailComposeSessionDidEnd, annotateAddressesForSession, viewController, additionalHeaders, allowMessageSendForSession.
  • Files: MailExtensions/MailExtensions/AppDelegate.swift, MailExtensions/SampleMailExtensions/Compose Session/ComposeSessionHandler.swift, MailExtensions/SampleMailExtensions/Message Security/MessageSecurityHandler.swift, MailExtensions/SampleMailExtensions/SpecialProjectHandler.swift, MailExtensions/MailExtensions/ViewController.swift, MailExtensions/SampleMailExtensions/Compose Session/ComposeSessionViewController.swift.

Architecture takeaways

  • AppDelegate is the main source-visible entry or composition anchor for this sample.
  • Framework work reaches MailKit, Cocoa through a deliberately small high-level chain; the detailed API graph remains inside the cited implementation files.
  • Stored-property evidence identifies lifecycle collaboration; it does not by itself prove exclusive object ownership.
  • Access-control conclusions separate verified language visibility from the likely design rationale.
  • The source does not justify labeling the design protocol-oriented.

Source map

Source file Relevant symbols
MailExtensions/MailExtensions/AppDelegate.swift Cited implementation, AppDelegate, Cocoa
MailExtensions/SampleMailExtensions/Message Security/MessageSecurityHandler.swift Cited implementation, MessageSecurityHandler, MessageSecurityError
MailExtensions/SampleMailExtensions/Message Security/MockEncoder.swift Cited implementation, Foundation, MockEncoder, ExampleDecoder
MailExtensions/SampleMailExtensions/Compose Session/ComposeSessionHandler.swift ComposeSessionHandler, async declaration or closure, MailKit, ComposeSessionError
MailExtensions/SampleMailExtensions/SpecialProjectHandler.swift SpecialProjectHandler, SpecialProject
MailExtensions/MailExtensions/ViewController.swift ViewController
MailExtensions/SampleMailExtensions/Compose Session/ComposeSessionViewController.swift ComposeSessionViewController
MailExtensions/SampleMailExtensions/Message Actions/MessageActionHandler.swift MessageActionHandler
MailExtensions/SampleMailExtensions/Message Security/ExampleSigningViewController.swift ExampleSigningViewController
MailExtensions/SampleMailExtensions/Content Blocker/ContentBlocker.swift ContentBlocker
MailExtensions/SampleMailExtensions/MailExtension.swift MailExtension