What we ship that your agent can’t build
Your agent handles the reply. We handle the security and identity layer underneath.
Features
Every feature page
Per-agent addresses, injection scanning, reputation tracking, MCP-native distribution, optional fast-routing classification, and dedicated IPs on request. What each part of mails.ai does, and how your agent uses it.
Inbound replies
Every reply arrives as a structured payload — sender, subject, reply text, attachments. Injection score + sender reputation always included. Webhook (HMAC-signed) or SDK reactor.
Per-agent reputation graph
Real engagement signals, not synthetic warmup. Suppression applies across all your agents.
MCP server
npx @mailsai/mcp-server is live on npm today — drop-in for Claude Code, Cursor, Cline, Continue, Windsurf, OpenAI Agents SDK, Anthropic SDK. Runs client-side, no server to host.
Classification (opt-in)
Extract intent + entities + urgency on first-contact inbound via our 2-call classifier. Opt-in per agent on paid plans, no extra charge. Skip if your agent runs its own LLM on every reply — you’d be paying twice for the same extraction.
Dedicated IP add-on
Available on request on Scale. Reputation isolated from the shared pool — worth it at volume, and a handicap below it, since an IP only earns standing from sustained traffic.
Webhooks
Every reply, inbound message, delivery and bounce pushed to your endpoint as it happens, signed, retried, and replayable from the dashboard or the API.
CLI
The whole API from your terminal: mails login signs in through your browser, and mails receiving listen prints replies as they land.
Email API
One API to send, reply, forward and schedule from your agent’s own address, from TypeScript, Python or plain HTTP.
Agent skills
Three open-source Agent Skills that teach your coding agent to send, receive and safely act on email with mails.ai.
“Replies come back as events with an injection score already on them. We deleted a whole layer of parsing code the week we switched, and we gate on the quarantine flag, so our agent never sees the ones that look like attacks.”
“Moving our agent onto our own domain was a few DNS records at the registrar. No nameserver move, and our existing mail kept working. Replies to the agent still come back to its inbox, threaded with the message they answer.”
“The 422 on cold outreach is the feature I didn’t know I wanted. An agent can’t talk itself into emailing strangers.”
“Our tests send to the test address and wait for the real reply, so the whole loop is covered before a customer ever writes in. It answers in about a second, which keeps the suite fast.”
“Adding the MCP server was one JSON block. Claude Code could send and read its own inbox a minute later.”
“A reputation score per agent tells us exactly which one needs attention, instead of one number for the whole account. It comes from each agent’s own replies, bounces and complaints, and we read it from the API.”
“Sends and replies have separate allowances, so a busy inbox never eats our sending quota. Pricing was the easy part.”
“Half our agents are LangGraph in Python and half are Node. Both SDKs make the same calls, so the team doesn’t have to think about it.”
“Signed webhooks, retries with backoff and an event id to dedupe on. The boring plumbing, done properly.”
“We signed up, made a key and sent our first message without talking to anyone, and the free tier never asked for a card. That’s how infrastructure should feel.”
Give your first agent an inbox
Free covers 3,000 emails and 3,000 inbound replies a month, with no card. Upgrade when your agents get busy.
Get your API key








