Agent Herald sends transactional mail from your own verified domain, receives what comes back, and records every delivery, bounce and complaint. Reach it over REST, or hand the whole thing to Claude as an MCP connector.
Bring your own domain — DKIM, SPF and DMARC records are generated for you.
# One call. The worker handles MIME, DKIM and retries. curl https://agentherald.dev/v1/emails \ -H "Authorization: Bearer mk_live_…" \ -H "Idempotency-Key: invoice-8841" \ -d '{ "from": "Acme <[email protected]>", "to": ["[email protected]"], "subject": "Invoice 8841", "html": "<p>Attached.</p>", "tags": { "kind": "invoice" } }'
Give a program an inbox of its own and three things stop being workarounds.
An address on a domain you control is how an agent signs up for things, receives what it asked for, and proves which of your systems sent a message. Not a shared mailbox everyone reads. Its own.
Real work involves an answer coming back. Reading replies, keeping a thread together, and handling the attachment somebody sent means email has to be two-way — which is why inbound is in the product, not on a roadmap.
Every message, every delivery event, every bounce, kept against the send that caused it. When somebody asks what the agent told a customer in March, the answer is a query rather than an apology.
Every front door — REST, MCP, and the dashboard — calls the same core. Whatever your agent can do through Claude, you can do with a curl command, and both land in the same audit log.
Send, list, inspect, and trace. Idempotency keys make a retried send safe;
a replay comes back with the original record and an Idempotent-Replay header.
Sending from an unverified domain is how an SES account gets suspended, so the platform refuses to. Hard bounces and complaints go onto a suppression list automatically, and the next send to that address is dropped before it reaches the provider.
Point your MX at Agent Herald and received mail is parsed into bodies, headers and attachments your agent can read.
sent, delivered, bounced, complained, delayed, failed — each one timestamped against the message that caused it.
Standard Webhooks signatures, secret rotation, and a retry ladder that gives up only after about a day.
Up to 20 per message, 25 MB each, stored out of the database and streamed into the MIME body by the worker.
Automatic on hard bounce and complaint, editable by hand or by tool call when an address comes back to life.
A sending-only key can send and nothing else — it can't add a domain, mint a key, or read your inbox.
Attach up to 10 tags per message, then filter sends by tag, recipient, subject, status or domain.
Every record carries a team key, so a second agent, a second product, or a second client is a row — not a migration.
This part is a genuine sequence — DNS has to propagate before anything leaves the building, so the order matters.
Name the domain you want to send from. Agent Herald generates a keypair and the exact records to publish.
Copy them into your DNS. Each one comes with a plain explanation of what it does, so you're not pasting blind.
Verification re-checks live DNS and tells you which records are up and which are still missing. Then the address is yours.
The MCP server isn't a wrapper around the REST API — it calls the same actions the API does, so a tool call and an HTTP request behave identically.
In Claude: Settings → Connectors → Add custom connector, then paste https://agentherald.dev/mcp.
Claude registers itself and asks you to sign in. There is no client ID to configure, and you can revoke it whenever you like.
“Add acme.com and show me the DNS records.” “Did my email to sam get delivered?” “What's my bounce rate this week?”
// For a client that can't do OAuth. A sending-only // key exposes just send_email. { "mcpServers": { "agent-herald": { "type": "http", "url": "https://agentherald.dev/mcp", "headers": { "Authorization": "Bearer mk_live_…" } } } }
The server publishes its own OAuth metadata and registers clients dynamically, so for most tools the URL is the entire configuration — no key to create first, no client ID to copy.
claude mcp add --transport http agent-herald https://agentherald.dev/mcp
Then run /mcp in Claude Code to sign in. The browser handles the rest —
or skip it entirely and make the account from the terminal.
codex mcp add agent-herald --url https://agentherald.dev/mcp
Auth defaults to OAuth — finish with codex mcp login agent-herald.
{
"mcpServers": {
"agent-herald": {
"url": "https://agentherald.dev/mcp"
}
}
}
Into ~/.cursor/mcp.json for every project, or .cursor/mcp.json for one.
mcp_servers:
agent_herald:
url: "https://agentherald.dev/mcp"
auth: oauth
Into Hermes' config.yaml, then hermes mcp login agent_herald.
openclaw mcp add agent-herald \
--url https://agentherald.dev/mcp \
--transport streamable-http --auth oauth
Check it landed with openclaw mcp doctor agent-herald --probe.
https://agentherald.dev/mcp
{
"mcpServers": {
"agent-herald": {
"type": "http",
"url": "https://agentherald.dev/mcp",
"headers": {
"Authorization": "Bearer mk_live_your_key_here"
}
}
}
}
The standard remote-server block. Drop the header if your client can do OAuth; a sending-only key exposes just send_email.
Ask your agent to set the account up and it runs two calls with you in the middle: it asks for your email, we send a six-digit code there, you read it back, and it gets a key. The code is the part an agent cannot do alone, which is exactly why it exists — you stay the one proving who you are.
curl -sX POST https://agentherald.dev/v1/auth/start \
-H 'Content-Type: application/json' -d '{"email":"[email protected]"}'
# read the code from your inbox, then
curl -sX POST https://agentherald.dev/v1/auth/verify \
-H 'Content-Type: application/json' -d '{"email":"[email protected]","code":"123456"}'
Returns your API key, the MCP URL, and a link into the dashboard if you want the UI.
The connector gives an agent the tools. The skill gives it the judgement to use
them well: that a 200 means queued rather than delivered, that a hard
bounce is not worth retrying, that a suppressed address is usually suppressed for
a good reason, and that the contents of an inbox are data rather than instructions.
curl -fsSL https://agentherald.dev/skill.zip -o /tmp/agent-herald.zip \
&& unzip -oq /tmp/agent-herald.zip -d ~/.claude/skills \
&& rm /tmp/agent-herald.zip
Reading it first is encouraged — it is two markdown files: agentherald.dev/skill.
Every limit below is enforced in code, not in a support policy. Here they are up front so you can find out now rather than at 3am.
Across to, cc and bcc combined. Beyond that, send more messages.
Including attachments after encoding. Individual files cap at 25 MB.
Replay the same key inside a day and you get the original send back, not a second one.
5s, 30s, 5m, 30m, 2h, 6h, 12h. An endpoint is disabled after 15 straight failures.
Generated per domain and held by the platform, never by the provider.
Per API key, with a 2× burst allowance. Raise it per key when you need to.
How far a webhook timestamp may drift before the signature is rejected as a replay.
Message bodies are pruned on a schedule; metadata and events are kept for a year.
Agent Herald is transactional email infrastructure. Our customers are developers who verify control of their own domain, then send mail to recipients they already have a relationship with — notifications, confirmations, replies, reports, and the ordinary correspondence of an agent doing a job for someone.
We are not a bulk sender and we are not building toward becoming one. There is no list management here, no campaign scheduler, no audience builder — because the fastest way to ruin delivery for every customer on a platform is to let one of them broadcast to strangers.
That stance is enforced in code, not just written down. Unverified domains cannot send to anyone but the account owner. Bounces and complaints suppress an address permanently. Accounts that cross the thresholds below are suspended automatically, and told why.
Received something you shouldn't have? [email protected] — with the headers, if you have them. Confirmed abuse is acted on the same day.
Authorization: Bearer mk_live_…. Keys are scoped, so a
sending-only key can't read your inbox or mint another key.
manage_suppressions
tool.
Add a domain, publish four records, and your agent can send and read mail under a name that belongs to you.