The draft is sitting there and it is good — better organized than what you would have written at this hour, and it says roughly what you meant. You are still hesitating, and the hesitation is not about the prose.
"Is this safe?" is the right instinct attached to the wrong question — not because the answer is reassuring, but because safe is carrying four questions at once, with four different answers. Separating them is most of the work.
The four: accuracy (the model states something wrong under your name), attribution (the reader cannot tell your position from the model's), access (what the drafting tool can see and do in your accounts), and autonomy (whether anything can leave without you reading it). Most arguments about AI and email are two people confidently answering different ones.
Accuracy: confidently wrong, in your voice
The failure is a number, a date, a claim about what a third party said, or a detail about your own situation the model supplied because the sentence needed a value. Sent under your name, it is your claim. "The model wrote it" is not a position anyone enjoys defending in the reply.
What makes this worse than an ordinary typo: fluency suppresses re-reading. A clumsy draft gets scrutinized. A polished one gets skimmed, because polish used to signal care and nobody updated the heuristic.
Mitigation, no tooling required: verify anything factual you would be held to. The test is not "does this sound right" — it is "would I defend this sentence in three weeks, to someone who kept the email." Numbers, dates, commitments and characterizations of other people's positions get checked one at a time. The rest is prose.
No product fixes this, RelayLink included. Structure can tell a reader who wrote a sentence, not whether it is true.
Attribution: the reader cannot tell which parts are you
This failure is quieter and does more long-term damage. The recipient acts on a position you never took, or banks a concession your assistant improvised, and neither of you finds out until it matters. Nothing in the text separates the two: same voice, same confidence.
Mitigation: own the parts that bind. The ask, every commitment, anything personal — write those yourself, even if the model wrote everything around them. A blanket "AI-assisted" footer does not help; applied to every message, it distinguishes none of them.
Structurally: this is the job of RelayLink's provenance labels. Assumptions carry stated by sender or inferred by sender's AI. The sender's note is marked verbatim, human-authored only when the wording genuinely differs from the AI's draft — approving one unchanged is recorded as approval, not authorship, and the label is earned rather than asserted.
Access: what the tool can reach while it works
This risk has nothing to do with the writing. An assistant can send mail when you connect it to something that sends mail, and what you granted is whatever that connection's scope allows — usually broader than the one feature you wanted. A standing mailbox grant typically means read access to everything in the account, often the right to send as you, and it persists until you revoke it.
The combination that matters is read-plus-send: one process ingesting text written by strangers while holding an outbound channel — the shape of agent exfiltration, and the reason those two powers belong in separate hands.
Mitigation: prefer narrow, revocable, forward-only or per-message grants over standing full-mailbox access, and check what you actually agreed to rather than what the setup screen emphasized. Revoke what you stopped using; the longer version of that trade-off is here.
Structurally: RelayLink never touches your mailbox. It is a separate channel, so the powers an assistant needs for correspondence are not granted over the account holding your password resets, and relayed content is neutralized — links and images are defused before any assistant or browser sees them, so nothing auto-fetches. The honest limits: it does nothing about the mail you already receive, and there is no end-to-end encryption claim to make, since the relay renders the email and web views and both ends are hosted models.
Autonomy: what can leave without you
The last risk is the multiplier. If drafting and sending are one motion, every failure above ships by itself, at machine speed, to people who will act on it.
Mitigation: never wire composition straight to delivery. Keep the send somewhere you have to look at the final text — not a summary of it, the text. That is a habit, and habits erode under deadline; if the system can hold the line, let it.
Structurally: the RelayLink send is two steps with no third option. draft_package parks a draft server-side, you review it rendered exactly as it will arrive, and confirm_send from the same account releases it; cancel_draft discards it beforehand. No single call composes and delivers, so there is no auto-send path to be talked into. The flip side, stated plainly: there is no unsend after delivery. The review step is the undo, which is why it is not optional.
Two limits worth naming
Two concessions. Prompt injection is made rare and low-yield by neutralized content and a required human confirmation — not impossible; no design achieves that. And consent, on the receiving end, is structural rather than promised — contact pairs, a hard daily cap on new contacts, and a one-click block that binds at the relay, derived in full in the consent layer.
The four risks above are the ones you weigh before sending. For the ones you diagnose after a message has already landed badly, the six failure modes is the fuller map.
The short answer
Letting AI write your email is about as safe as letting it write anything else you sign. The drafting was never the risky part. The risk is what you stop reading, what you stop owning, what the tool can reach, and what can leave without you.
Three of the four have structural answers. The first one is yours and stays yours. If you would rather the other three ran on mechanism than on memory, connect your assistant and send one message you would otherwise have agonized over.