
Give your agent its own inbox.
A real address in one API call — send, receive, reply. You decide what it’s allowed to send; cold email is blocked at the API, not in the fine print.
Works with the tools your agents already run on,
through our SDKs, the REST API or MCP.
See every integrationOne call to a working inbox
Every workspace starts with an agent, so your first send needs no setup step and no approval queue. Use our SDKs, plain HTTP, or give your coding agent the tools over MCP.
import { mails } from "@mailsai/sdk";
// hello is the agent your workspace starts with.
const sent = await mails.send({
from: "hello",
to: "reply@test.mails.ai",
subject: "Hello from my agent",
body: "Checking that my new inbox works.",
});
console.log("sent", sent.id, "as", sent.from);
// Replies stream in as events, already scanned.
mails.agent("hello").onReply((reply) => {
if (reply.quarantined) return; // flagged as an injection attempt
console.log("reply received, injection score", reply.injection_score);
});Built for code that
writes its own email
Google’s own Gmail MCP ships eleven tools and no send.
Here your agent sends for real, and every reply comes back as clean, scored data.
Cold email stops at the API
Every send is classified before it leaves. Cold outreach gets a 422 that says why, and a test key shows you the verdict without sending anything.
Learn moreEvery reply is an event
Replies, deliveries and bounces reach your code as signed webhooks or a live stream, each with an injection score and the sender’s reputation attached.
Learn moreEvery agent gets an inbox
Threads and replies, kept per agent. Before your agent reads a message, it is scored for prompt injection and flagged if it looks like an attack. Try it on these.
More than a send call
Every agent keeps a reputation of its own, and any message can wait as a draft or go out at the time you choose.
Reputation for every agent
Each agent’s score comes from its own replies, bounces and complaints, isolated per workspace and readable from the API.
Learn moreDrafts and scheduled sends
Let an agent write now and send later: give a message a send time, or keep it as a draft until you send it.
Learn moreWatch a reply come back
Send a line to reply@test.mails.ai, a test address of ours that answers within about a second, and watch the reply arrive. The address answers at most 3 times in one thread: a 4th message there gets no reply. Your agent runs the same loop.
Your reputation, protected by default
Cold email refused
Every send is classified before it leaves. Cold outreach and bulk marketing get a 422, with an independent second review if we got it wrong.
Complaint auto-pause
A sender whose complaint rate reaches 0.3% is paused automatically, before the 0.5% line our upstream provider enforces.
Suppression at send time
Every send is checked against your suppression list, and your agent can check an address itself before it tries.
Reputation per agent
Each agent is scored on its own replies, bounces and complaints, isolated per workspace and readable from the API.
Your own domain
On any paid plan, add DKIM, SPF and DMARC records at your registrar (no nameserver move) and your agents send as agent@yourcompany.com.
Mail servers we run
Custom-domain mail leaves through mail servers we run ourselves, not through a third party’s sending API.
Dedicated IP on request
On Scale, a dedicated IP keeps your reputation apart from the shared pool, warmed by your own real traffic.
Injection scan on every inbound
Inbound mail is scored across six kinds of prompt injection on every plan, and high-risk messages arrive flagged quarantined.
Signed, retried webhooks
Events are HMAC-signed and retried with backoff, with an event id on every delivery so your handler can drop repeats.
We gave every support agent its own address in an afternoon. What sold our security team was that cold email simply can’t leave the API.
Every agent, in plain sight
Track sends, deliverability and replies received, search every message an agent sent, and watch events arrive as they happen, all from one dashboard.

Mails.ai in fifteen seconds
Every agent gets its own address.
From the people building agents
Engineers give their agents an address, a reply loop and a sender reputation with mails.ai, and get back to the agent itself.
“Replies come back as events with an injection score already on them. We deleted a whole layer of parsing code the week we switched, and we gate on the quarantine flag, so our agent never sees the ones that look like attacks.”
“Moving our agent onto our own domain was a few DNS records at the registrar. No nameserver move, and our existing mail kept working. Replies to the agent still come back to its inbox, threaded with the message they answer.”
“The 422 on cold outreach is the feature I didn’t know I wanted. An agent can’t talk itself into emailing strangers.”
“Our tests send to the test address and wait for the real reply, so the whole loop is covered before a customer ever writes in. It answers in about a second, which keeps the suite fast.”
“Adding the MCP server was one JSON block. Claude Code could send and read its own inbox a minute later.”
“A reputation score per agent tells us exactly which one needs attention, instead of one number for the whole account. It comes from each agent’s own replies, bounces and complaints, and we read it from the API.”
“Sends and replies have separate allowances, so a busy inbox never eats our sending quota. Pricing was the easy part.”
“Half our agents are LangGraph in Python and half are Node. Both SDKs make the same calls, so the team doesn’t have to think about it.”
“Signed webhooks, retries with backoff and an event id to dedupe on. The boring plumbing, done properly.”
“We signed up, made a key and sent our first message without talking to anyone, and the free tier never asked for a card. That’s how infrastructure should feel.”






