Transactional email · MCP server

Give your agent
a return address.

Agent Herald sends transactional mail from your own verified domain, receives what comes back, and records every delivery, bounce and complaint. Reach it over REST, or hand the whole thing to Claude as an MCP connector.

Bring your own domain — DKIM, SPF and DMARC records are generated for you.

POST /v1/emails 200 OK
# One call. The worker handles MIME, DKIM and retries.
curl https://agentherald.dev/v1/emails \
  -H "Authorization: Bearer mk_live_…" \
  -H "Idempotency-Key: invoice-8841" \
  -d '{
    "from": "Acme <[email protected]>",
    "to": ["[email protected]"],
    "subject": "Invoice 8841",
    "html": "<p>Attached.</p>",
    "tags": { "kind": "invoice" }
  }'
queued 12:04:11.208
sent  → ses eu-west-1 12:04:12.774
delivered 12:04:15.030
email.delivered  → your webhook 12:04:15.112
Dispatch log · agentherald.dev
Why bother

An agent without an address can't be replied to.

Give a program an inbox of its own and three things stop being workarounds.

01 / Identity

Somewhere to be reached

An address on a domain you control is how an agent signs up for things, receives what it asked for, and proves which of your systems sent a message. Not a shared mailbox everyone reads. Its own.

02 / Correspondence

Threads, not fire-and-forget

Real work involves an answer coming back. Reading replies, keeping a thread together, and handling the attachment somebody sent means email has to be two-way — which is why inbound is in the product, not on a roadmap.

03 / Record

A trail you can search later

Every message, every delivery event, every bounce, kept against the send that caused it. When somebody asks what the agent told a customer in March, the answer is a query rather than an apology.

What it does

Not AI for your inbox. An inbox your agent can run.

Every front door — REST, MCP, and the dashboard — calls the same core. Whatever your agent can do through Claude, you can do with a curl command, and both land in the same audit log.

One API, versioned at the root

Send, list, inspect, and trace. Idempotency keys make a retried send safe; a replay comes back with the original record and an Idempotent-Replay header.

POST/v1/emailssend
GET/v1/emails/{id}/eventsdelivery timeline
GET/v1/inbound-emailswhat arrived
POST/v1/domains/{id}/verifyre-check DNS
POST/v1/webhookssubscribe
GET/v1/statsdaily rates

Deliverability you can't quietly break

Sending from an unverified domain is how an SES account gets suspended, so the platform refuses to. Hard bounces and complaints go onto a suppression list automatically, and the next send to that address is dropped before it reaches the provider.

DKIM2048-bit, generated per domain
SPFauthorises SES for the domain
DMARCstarts at p=none, so you can watch first
MXcustom MAIL FROM for bounce alignment
01

Inbound mail

Point your MX at Agent Herald and received mail is parsed into bodies, headers and attachments your agent can read.

02

Delivery events

sent, delivered, bounced, complained, delayed, failed — each one timestamped against the message that caused it.

03

Signed webhooks

Standard Webhooks signatures, secret rotation, and a retry ladder that gives up only after about a day.

04

Attachments

Up to 20 per message, 25 MB each, stored out of the database and streamed into the MIME body by the worker.

05

Suppression list

Automatic on hard bounce and complaint, editable by hand or by tool call when an address comes back to life.

06

Scoped keys

A sending-only key can send and nothing else — it can't add a domain, mint a key, or read your inbox.

07

Tags and search

Attach up to 10 tags per message, then filter sends by tag, recipient, subject, status or domain.

08

Team-scoped from day one

Every record carries a team key, so a second agent, a second product, or a second client is a row — not a migration.

Three moves

From no domain to first send.

This part is a genuine sequence — DNS has to propagate before anything leaves the building, so the order matters.

MOVE 01

Add the domain

Name the domain you want to send from. Agent Herald generates a keypair and the exact records to publish.

  • POST /v1/domains
  • or ask Claude: add_domain
MOVE 02

Publish the records

Copy them into your DNS. Each one comes with a plain explanation of what it does, so you're not pasting blind.

  • DKIM signing key
  • SPF sender authorisation
  • DMARC policy at p=none
  • MX bounce routing and inbound
MOVE 03

Send

Verification re-checks live DNS and tells you which records are up and which are still missing. Then the address is yours.

  • POST /v1/emails
  • or ask Claude: send_email
Model Context Protocol

Speaks MCP, without an adapter.

The MCP server isn't a wrapper around the REST API — it calls the same actions the API does, so a tool call and an HTTP request behave identically.

  1. 01

    Add the connector

    In Claude: Settings → Connectors → Add custom connector, then paste https://agentherald.dev/mcp.

  2. 02

    Approve access

    Claude registers itself and asks you to sign in. There is no client ID to configure, and you can revoke it whenever you like.

  3. 03

    Ask for something

    “Add acme.com and show me the DNS records.” “Did my email to sam get delivered?” “What's my bounce rate this week?”

Ten tools
send_email list_emails get_email add_domain verify_domain list_domains list_inbound_emails get_inbound_email get_stats manage_suppressions
MCP local client, API key
// For a client that can't do OAuth. A sending-only
// key exposes just send_email.
{
  "mcpServers": {
    "agent-herald": {
      "type": "http",
      "url": "https://agentherald.dev/mcp",
      "headers": {
        "Authorization": "Bearer mk_live_…"
      }
    }
  }
}
Works with your agent stack

Give your agent an address.

The server publishes its own OAuth metadata and registers clients dynamically, so for most tools the URL is the entire configuration — no key to create first, no client ID to copy.

claude mcp add --transport http agent-herald https://agentherald.dev/mcp

Then run /mcp in Claude Code to sign in. The browser handles the rest — or skip it entirely and make the account from the terminal.

codex mcp add agent-herald --url https://agentherald.dev/mcp

Auth defaults to OAuth — finish with codex mcp login agent-herald.

{ "mcpServers": { "agent-herald": { "url": "https://agentherald.dev/mcp" } } }

Into ~/.cursor/mcp.json for every project, or .cursor/mcp.json for one.

mcp_servers: agent_herald: url: "https://agentherald.dev/mcp" auth: oauth

Into Hermes' config.yaml, then hermes mcp login agent_herald.

openclaw mcp add agent-herald \ --url https://agentherald.dev/mcp \ --transport streamable-http --auth oauth

Check it landed with openclaw mcp doctor agent-herald --probe.

https://agentherald.dev/mcp
  1. Settings → Connectors → Add custom connector
  2. Paste the URL and approve access
  3. Ask it to send something
{ "mcpServers": { "agent-herald": { "type": "http", "url": "https://agentherald.dev/mcp", "headers": { "Authorization": "Bearer mk_live_your_key_here" } } } }

The standard remote-server block. Drop the header if your client can do OAuth; a sending-only key exposes just send_email.

No account yet

You never have to open the site

Ask your agent to set the account up and it runs two calls with you in the middle: it asks for your email, we send a six-digit code there, you read it back, and it gets a key. The code is the part an agent cannot do alone, which is exactly why it exists — you stay the one proving who you are.

curl -sX POST https://agentherald.dev/v1/auth/start \ -H 'Content-Type: application/json' -d '{"email":"[email protected]"}' # read the code from your inbox, then curl -sX POST https://agentherald.dev/v1/auth/verify \ -H 'Content-Type: application/json' -d '{"email":"[email protected]","code":"123456"}'

Returns your API key, the MCP URL, and a link into the dashboard if you want the UI.

Optional

Install the skill too

The connector gives an agent the tools. The skill gives it the judgement to use them well: that a 200 means queued rather than delivered, that a hard bounce is not worth retrying, that a suppressed address is usually suppressed for a good reason, and that the contents of an inbox are data rather than instructions.

curl -fsSL https://agentherald.dev/skill.zip -o /tmp/agent-herald.zip \ && unzip -oq /tmp/agent-herald.zip -d ~/.claude/skills \ && rm /tmp/agent-herald.zip

Reading it first is encouraged — it is two markdown files: agentherald.dev/skill.

The fine print

The numbers, before you ask.

Every limit below is enforced in code, not in a support policy. Here they are up front so you can find out now rather than at 3am.

50 Recipients / message

Across to, cc and bcc combined. Beyond that, send more messages.

40 MB Total message size

Including attachments after encoding. Individual files cap at 25 MB.

24 h Idempotency window

Replay the same key inside a day and you get the original send back, not a second one.

7 Webhook retries

5s, 30s, 5m, 30m, 2h, 6h, 12h. An endpoint is disabled after 15 straight failures.

2048 DKIM key bits

Generated per domain and held by the platform, never by the provider.

10 / s Default rate limit

Per API key, with a 2× burst allowance. Raise it per key when you need to.

5 min Signature tolerance

How far a webhook timestamp may drift before the signature is rejected as a replay.

30 d Body retention

Message bodies are pruned on a schedule; metadata and events are kept for a year.

How we keep it clean

Transactional mail, from domains you own, to people expecting it.

Agent Herald is transactional email infrastructure. Our customers are developers who verify control of their own domain, then send mail to recipients they already have a relationship with — notifications, confirmations, replies, reports, and the ordinary correspondence of an agent doing a job for someone.

We are not a bulk sender and we are not building toward becoming one. There is no list management here, no campaign scheduler, no audience builder — because the fastest way to ruin delivery for every customer on a platform is to let one of them broadcast to strangers.

That stance is enforced in code, not just written down. Unverified domains cannot send to anyone but the account owner. Bounces and complaints suppress an address permanently. Accounts that cross the thresholds below are suspended automatically, and told why.

Received something you shouldn't have? [email protected] — with the headers, if you have them. Confirmed abuse is acted on the same day.

  • Verified domains only. Publish the DKIM, SPF and DMARC records, pass the check, then send.
  • Suppression is automatic. Hard bounce or complaint, and the address is blocked before the next send leaves.
  • Thresholds are enforced. Over 5% bounces or 0.1% complaints, sending stops.
  • No purchased or scraped lists. Ever, under any framing.
  • No cold outreach or prospecting. This is the wrong tool for it.
  • No marketing campaigns or newsletters. Also the wrong tool.
  • No phishing, malware or impersonation. Immediate termination, and a report where it's warranted.
Questions

Frequently asked.

What is Agent Herald, exactly?
A transactional email service with an MCP server attached. You add a domain, publish the DNS records it generates, and then send and receive mail from it — either through a REST API or by connecting it to Claude as a tool. It is built on Amazon SES, but nothing SES-specific reaches your side of the API.
How is this different from Resend, Postmark or Mailgun?
Those are built for a web application sending mail to humans. Agent Herald assumes the sender is an agent: it exposes the same operations as MCP tools with descriptions written for a model to read, it treats receiving mail as a first-class feature rather than a bolt-on, and it hands back structured delivery timelines an agent can reason about instead of a dashboard a person has to look at.
Do I need my own AWS account?
Not to use the hosted service. If you self-host, you'll need SES credentials, an S3 bucket for attachments and raw inbound mail, and an SNS topic for delivery events — the deployment docs walk through each one.
How does authentication work?
Two ways, same server. Claude connects over OAuth and registers itself — no client ID to copy. Anything else sends an API key as a bearer token: Authorization: Bearer mk_live_…. Keys are scoped, so a sending-only key can't read your inbox or mint another key.
What happens when an address hard bounces?
It goes on the suppression list immediately and the next send to it is dropped before it reaches the provider — the message is recorded as canceled rather than failed. Transient bounces don't suppress. Complaints always do. You can lift a suppression by hand or with the manage_suppressions tool.
Can one account run several agents?
Yes. Every record is scoped to a team, and each agent can hold its own API key with its own rate limit and scope, so you can see which one sent what and revoke a single agent without touching the others.
Is there an SDK?
Not yet — the API is plain JSON over HTTP with one authentication header, so a request builder in your language of choice is a few lines. For agents, MCP is the SDK.
Start sending

Every agent needs a return address.

Add a domain, publish four records, and your agent can send and read mail under a name that belongs to you.