All solutions
Solutions

Email for AI Agents: Send, Receive, and Reply Without an SMTP Rabbit Hole

Each agent gets its own address, sends transactional mail, and reads replies as JSON events — no IMAP, no MIME.

Email for AI agents is a bidirectional stack: each agent gets a dedicated address to send from and receive to, every inbound message arrives as a structured event with an injection score instead of raw MIME, and cold outreach is blocked at the API so the sending reputation your agents build stays intact. Mails.ai provides the email API for AI agents that handles exactly this — per-agent identity, event-driven receiving, and a firewall in both directions.

Send and receive under one API key

The minimal email setup for an AI agent is a send API. It works — until the customer replies. At that point you need inbound parsing, threading, and a way to route the reply back to the agent that sent the original message. That is the gap a plain SMTP relay cannot fill:

import { createClient } from "@mailsai/sdk";
const mails = createClient({ apiKey: process.env.MAILS_API_KEY });

// Sending: one call, no DNS to configure, no domain to verify upfront.
await mails.messages.send({
  from: "hello",             // the agent every workspace gets at signup
  to: "customer@example.com",
  subject: "Your invoice #441 is ready",
  body_text: "Invoice #441 for August is attached — reply with any questions.",
});
// → sent from hello.yourworkspace@send.mails.ai, SPF/DKIM/DMARC aligned

// Receiving: replies arrive as typed events, already parsed and injection-scanned.
mails.agent("hello").onReply(async (event) => {
  // event.data.extracted_text — the reply's plain text, quoted history stripped
  // event.thread_id  — stable across the whole conversation
  // event.injection_score — 0.0–1.0; quarantined from 0.95
  // event.source_message_id — the received message, to reply to
  // Hold for a person: quarantined, not scanned (no score), or 0.5 and up
  if (event.quarantined || typeof event.injection_score !== "number" || event.injection_score >= 0.5) {
    return flagForReview(event);
  }
  if (!event.source_message_id) return;

  // Reply in the same thread — no Message-ID wrangling.
  await mails.messages.reply(event.source_message_id, {
    body_text: "Got it — I'll process that and follow up by end of day.",
  });
});

Reputation stays per agent, not per account

A shared sending domain fails when one sender misbehaves and the whole domain takes the bounce or complaint hit. Here, each AI email agent has its own reputation score. An agent whose complaint rate drifts above 0.3 % — below the upstream threshold of 0.5 % — is suspended automatically before the damage propagates. Your other agents keep sending unless the workspace’s mail as a whole crosses the same line.

For consistent high volume, around 300,000 messages a month, a dedicated IP is available on request on the Scale plan. It warms with your real mail, not a manual warmup schedule: see automated dedicated IP warm-up.

Custom domain, same model

By default agents send from an address on the shared sending domain, such as hello.yourworkspace@send.mails.ai — working email in one API call, no DNS required. When your agents need to carry your brand, connect a custom domain and every agent on it sends as agent@yourcompany.com, authenticated end to end. Custom domain email for AI agents covers the DNS steps — they’re generated for you and verified automatically.

The email API: one key, both directions

The email API for AI agents wraps sending, receiving, and classification into a single integration. You authenticate once with an API key, create agents programmatically, and every reply arrives as a structured event — no IMAP poll loop, no MIME parser, no OAuth refresh token. The API ships with TypeScript and Python SDKs, an MCP server for agent IDE integration, and a plain REST interface for everything else. The email API for AI agents solution page has code examples in both languages, or read the full email API comparison for 2026 to see how Mails.ai stacks up against Resend, SendGrid, Postmark, and Mailgun for agent use cases.

What it costs

The free tier covers 3,000 emails and 3,000 inbound replies a month with one agent — no card required. Beyond that, Pro is $20 a month for 50,000 emails and 50,000 inbound replies across five agents, and Scale is $99 for 250,000 emails and 500,000 inbound replies with unlimited agents. Both include the injection scan on every inbound and opt-in intent/entity classification of first-contact mail at no extra charge, and yearly billing is two months free. No per-seat fee. For the full management layer — routing, classification, and per-agent reputation — see AI email management.

Frequently asked questions

Can’t I just use a standard email API like SendGrid or Postmark?
For fire-and-forget sends, yes. The gap appears the moment your agent needs to read a reply: SendGrid’s Inbound Parse and Postmark’s inbound webhook hand you the message’s body, headers and attachments, and threading it and screening it for injection are left to your code. Mails.ai wraps both directions — send and receive — under one API key, with replies delivered as typed JSON events.
What does 'per-agent identity' mean in practice?
Each agent you create gets its own email address: on the shared domain it receives mail at agent.yourworkspace@in.mails.ai and sends from agent.yourworkspace@send.mails.ai, and with a custom domain it sends as agent@yourdomain.com. SPF, DKIM, and DMARC are provisioned for you. Reputation signals — bounce rate, complaint rate, engagement — are tracked per agent, so one misbehaving agent can’t drag down the reputation of others in the same account.
How does the injection-scan protect my agent?
Every inbound message within your plan’s limits is scanned for prompt-injection patterns before it reaches your code. The score arrives on the event alongside the parsed body, so your agent branches on a number — at 0.5 or more, or with no score, hold the message for a person — rather than relying on the LLM to notice it’s being attacked inside the same prompt as the attack.
What email can my agents actually send?
Transactional mail: confirmations, receipts, OTPs, status updates, notifications, and genuine replies to messages the agent received. Cold outreach is refused at the API and never transmitted — by policy and by enforcement. That boundary keeps the shared sending infrastructure clean, which is why transactional mail from agents here inboxes reliably.
How is this different from a traditional email API?
A traditional email API handles outbound sends — password resets, receipts, notifications — and stops there. An email API for AI agents like Mails.ai adds the other direction: inbound parsing, thread reconstruction, prompt-injection scanning, and per-agent reputation. Your agent sends and receives under one API key, with replies arriving as structured JSON events instead of raw MIME.
Can I integrate this email API with any AI agent framework?
Yes. The email API works with any framework that can make HTTP calls — the REST API is framework-agnostic. For tighter integration, use the TypeScript SDK, Python SDK, or the MCP server (npx @mailsai/mcp-server) which drops into Claude Code, Cursor, Cline, Continue, Windsurf, OpenAI Agents SDK, and Anthropic SDK.

Explore the product

Give your first agent an inbox

Free covers 3,000 emails and 3,000 inbound replies a month, with no card. Upgrade when your agents get busy.

Get your API key