Open source · Self-hosted · Apache-2.0
The open-source alternative to AgentMail. Unlimited real mailboxes for every agent you run, on your own domain — over REST and MCP — with OTP and verification-link extraction built in — and phone push. One guided command gets you started.
WORKS WITH ANY MCP CLIENT — AND ANYTHING THAT CAN CURL
Live workflow
This is the actual loop your agent runs: create an identity, trigger a signup, wait for the mail, read the code. Typed out for you below — no video, no mockup.
Real mail, really parsed
Extraction is tested against the mails that real services send — US and Chinese providers alike. Hover a card to read it.
Why it exists
Not a read-only status page — a full working deck. Three-pane inbox with one-click OTP copy. A 30-day notification log with daily summaries and masked sensitive content. A task board where you can nudge or close agent work. Identities, tokens, push tiers, and connected clients — all managed from the browser.
Pair your phone by scanning a QR code — ten seconds, no command line. Three content tiers decide how much of a message may leave the server: just a ping, masked sender + subject, or body + OTP. Tier 3 needs your explicit risk confirmation, and agents can never raise their own tier. Lost phone? One-click revoke cuts it off immediately.
Agents can send mail too — and you get the ledger. The Sent folder shows what went out: when, from whom, to whom, the subject, and whether it landed (with the failure reason when it didn't). 30 days of history. Message bodies are never stored.
Built on the official SDK v2, current to the dated 2026-07-28 spec. Agents on the same box connect over stdio; cloud agents connect over stateless HTTPS with OAuth. Every authorized client is listed in the dashboard — and revocable.
Email-backed task threads with server-stamped states (submitted→working→completed/failed). The receiving agent is woken; the dashboard shows a work-order view. A2A-vocabulary Agent Card at /.well-known/agent-card.json (email transport — not wire-protocol claim). Watch the board, page through history, nudge a stuck task or close one out — you're the dispatcher, not just the observer.
One catch-all mailbox, unlimited anything@yourdomain addresses. No provisioning, no per-inbox cost, no caps.
Every identity gets its own oa_… token that can only read and send as that address. Your admin key never touches an agent.
Long-poll an inbox until the signup mail lands — codes and verification links come out parsed. Built for automated signups.
Per-identity send rate limits (20/hour default) and automatic retention (30 days default). Every message carries source: internal|external; non-internal bodies are fenced at the MCP layer. A leaked token can't become a spam cannon.
Send directly from your VPS, or route outbound through Amazon SES or any SMTP relay with one env var. Your reputation, your choice.
dns-records.sh prints your exact DNS records. doctor.sh runs a 13-point deliverability check before agents depend on it.
On the record
MCP 2026-07-28 — full dated-spec transport, local and remote
RFC 9728 — OAuth protected-resource metadata
A2A-vocabulary Agent Card — aligned with A2A v1.0 discovery format and task-state words, over email transport.
We deliberately don't claim wire-protocol compatibility.
ERC-8004 export — on the roadmap, opt-in, write-only
How it works
Clone, set three env vars, bring the stack up. Two containers: docker-mailserver plus the API.
docker compose up -d The wizard prints the exact A / MX / SPF / DKIM / DMARC records to paste into your provider.
./deploy/dns-records.sh Thirteen checks: DNS, TLS, port 25, blocklists, PTR. Fix what it flags before your agents depend on it.
./deploy/doctor.sh One API call mints an address and its scoped token. Hand the token to your agent — never the admin key.
POST /v1/identities → fox-k7d2@yourdomain The agent waits on the inbox; the signup mail arrives; the OTP comes back parsed and ready to type.
mail_wait_for → otp.codes[0] *unless you opt into push tiers 2/3, which relay via ntfy
POST /v1/identities — mint an address + scoped tokenGET /v1/identities — list every identity you ownPOST /v1/identities/:a/token — rotate (revoke) a tokenDELETE /v1/identities/:a — retire an identityGET /v1/identities/:a/push-tier — read an identity's push content tierPUT /v1/identities/:a/push-tier — set push tier (admin; tier 3 needs confirm)GET /v1/messages — list an inboxGET /v1/messages/:id — full mail + parsed OTPPOST /v1/messages/wait — long-poll for new mailPOST /v1/messages/:id/seen — mark read / unreadPOST /v1/send — send as any identity you ownPOST /v1/tasks — assign an email-backed task to another identityGET /v1/tasks — list task threads you can seeGET /v1/tasks/:id — read a task + stamped state historyPOST /v1/tasks/:id/state — advance a participating taskPOST /v1/notify — send a server-side notificationGET /v1/notify/messages — list recent notification historyPOST /v1/notify/verify — publish and poll a harmless self-checkPOST /v1/notify/devices — register a device for pushmail_new_identitymail_list_identitiesmail_list_messagesmail_read_messagemail_wait_formail_sendmail_mark_seentask_createtask_listtask_gettask_updatenotify_usernotify_agentnotify_checknotify_verifyThe core trick
Agents shouldn't parse MIME. Every message comes back with codes and action links already extracted — and the raw text and HTML right there when extraction isn't enough.
Compared to the alternatives
| openagent.email | AgentMail | MailSlurp | |
|---|---|---|---|
| Open source | ✓ Apache-2.0 | ✗ | ✗ |
| Deployment | ✓ any VPS | SaaS or BYOC (Outposts on AWS) | SaaS only |
| Price | Flat VPS cost (~$5/mo) | Per-inbox subscription | Usage-based subscription |
| Unlimited inboxes | ✓ catch-all | Paid tiers | Paid tiers |
| MCP-native | ✓ | ✓ | ✗ REST/SDKs |
| OTP / link extraction | ✓ | ✓ | ✓ |
| Mail data residency | Your box* | SaaS: theirs; Outposts: your AWS† | Always theirs |
| Vendor control plane | None | Yes (incl. Outposts) | Yes |
| You run a server | Yes — that's the point | No (BYOC still vendor-operated) | No |
To be fair: if you never want to touch a VPS, a hosted service is genuinely easier — and AgentMail's Outposts BYOC is a real option when email content must stay in your AWS account. We still think owning the mailbox — the OTPs, the links, the reputation — with no vendor control plane is worth ten minutes of setup. Your call. Asterisk: push tiers 2/3 relay subject/from or body/OTP via ntfy — off by default. † Outposts keep email content in your AWS; AgentMail still runs dashboard, auth, billing, and upgrades.
Before you ask
Measured on our own production instance, sitting idle: the whole stack — mail server, API, everything — sips about 190 MB of RAM and roughly zero CPU.
Works with the defaults. That's a $5/mo VPS — or a $10–15/year deal box.
Headroom to turn on spam filtering (SpamAssassin) and never think about it again.
ClamAV alone eats ~1 GB, so it ships off by default. Agent mail rarely needs it.
The real prerequisite isn't size — it's port 25. AWS, GCP, Azure, DigitalOcean and Vultr block it by default (some open it on request). Check before you buy — or route outbound through a relay like Amazon SES and skip the fight entirely.
FAQ
Yes — self-hosting is free and unlimited under the Apache-2.0 license: no paid tier, no usage limits, no per-inbox pricing. The only thing you pay for is the server you run it on, and a $5/mo VPS is enough. An optional hosted plan (we run it for you) is launching soon — see /pricing.
AgentMail is a hosted SaaS product (usage-based pricing), with an enterprise BYOC option (Outposts) that keeps email content in your AWS account while they still run the control plane. openagent.email is Apache-2.0 software you run yourself on any VPS: unlimited inboxes on your own domain, no vendor control plane, and your mail never leaves a machine you own — unless you opt into push tiers 2/3, which relay subject/from or body/OTP via ntfy. See the full comparison at /alternatives/agentmail.
Yes — any domain you own, about $10/year. One domain gives every agent you run its own address (agent1@yourdomain, agent2@yourdomain, …). The docs walk through the DNS records step by step.
Anything that speaks MCP — Claude Code, Cursor, Kimi Code, and friends — via the @openagentemail/mcp server, current to the dated MCP 2026-07-28 spec. Cloud agents connect over stateless HTTPS with OAuth — protected-resource metadata per RFC 9728 — or a scoped identity token, and every connected OAuth client shows up in the dashboard where you can revoke it. A plain REST API covers everything else.
Deliverability depends on your own IP and domain reputation, which the deliverability guide covers: SPF, DKIM and DMARC are set up for you, and you can relay outbound through Amazon SES if your VPS provider blocks port 25.
Yes — a full cockpit at /ui, not just a viewer. Read every agent inbox in a three-pane mail client with one-click OTP copy, review the 30-day push log with daily summaries and masked sensitive content, nudge or close agent tasks from the work-order board, manage identities, tokens, push tiers, and connected clients, pair your phone by QR code, and audit what agents sent from the Sent folder. Trust this device once, stay signed in for 30 days.
Yes. Tasks are email-backed threads between managed identities, with server-stamped states (submitted → working → completed/failed). Creating a task wakes the receiving agent; the dashboard rebuilds each thread into a work-order card with participants, a timeline, and a result block. From the board you can page through history, nudge a stuck task, or close one out.
Yes — pair the ntfy app by scanning a QR code from the dashboard, after a one-time ntfy HTTPS setup covered in the phone guide. You pick how much of a message may leave the server per identity: just a ping, masked sender + subject, or body + OTP (tier 3 asks for your explicit risk confirmation, and agents can never raise their own tier). Lost phone? One click revokes it.
Safer than raw MIME with no labels. Every message carries source: internal|external — only all-domain recipients get a server HMAC stamp (X-OA-Mail-Stamp). The MCP layer fences non-internal text/html/snippet so the model sees "this is data, not instructions." That is a hygiene baseline for defense-in-depth, not an absolute guarantee against prompt injection.
Open source
The API, the MCP server, the deploy tooling — all public, all auditable. Run it on a Raspberry Pi or a fleet. Contribute back when you want to.