Open source · Self-hosted · Apache-2.0

Email for your agents.
Owned by you.

The open-source alternative to AgentMail. One docker compose up on your own VPS gives every agent you run unlimited real mailboxes on your own domain — over REST and MCP — with OTP and verification-link extraction built in.

git clone …/openagentemail && cd openagentemail && docker compose up -d

WORKS WITH ANY MCP CLIENT — AND ANYTHING THAT CAN CURL

Claude Code Cursor Windsurf Docker ✦ Kimi Code ✦ Any MCP client ✦ Plain REST

Live workflow

From deploy to OTP, in one terminal.

This is the actual loop your agent runs: create an identity, trigger a signup, wait for the mail, read the code. Typed out for you below — no video, no mockup.

agent@your-vps — openagent.email

Real mail, really parsed

The formats your agent
will actually meet.

Extraction is tested against the mails that real services send — US and Chinese providers alike. Hover a card to read it.

From: noreply@github.com
Subject: [GitHub] Your launch code
Here's your GitHub launch code, @agent — paste it to finish signing up. It expires in 10 minutes.
59162834
otp.codes → ["59162834"] ✓
From: service@notice.aliyun.com
Subject: 【阿里云】验证码
您正在注册阿里云账号,验证码如下,请在 15 分钟内完成验证。工作人员不会索取验证码,请勿泄露。
509227
otp.codes → ["509227"] ✓
From: no-reply@accounts.google.com
Subject: Your Google verification code
G-482916 is your Google verification code. Don't share it with anyone.
G-482916
otp.codes → ["482916"] ✓

Why it exists

Everything an agent mailbox needs.
Nothing it doesn't.

01

Unlimited identities

One catch-all mailbox, unlimited anything@yourdomain addresses. No provisioning, no per-inbox cost, no caps.

02

Scoped tokens

Every identity gets its own oa_… token that can only read and send as that address. Your admin key never touches an agent.

03

wait_for + OTP extraction

Long-poll an inbox until the signup mail lands — codes and verification links come out parsed. Built for automated signups.

04

Safety rails

Per-identity send rate limits (20/hour default) and automatic retention (30 days default). A leaked token can't become a spam cannon.

05

Bring your own relay

Send directly from your VPS, or route outbound through Amazon SES or any SMTP relay with one env var. Your reputation, your choice.

06

DNS wizard + doctor

dns-records.sh prints your exact DNS records. doctor.sh runs a 13-point deliverability check before agents depend on it.

How it works

Ten minutes, five steps,
every one of them real.

Deploy

Clone, set three env vars, bring the stack up. Two containers: docker-mailserver plus the API.

docker compose up -d

DNS

The wizard prints the exact A / MX / SPF / DKIM / DMARC records to paste into your provider.

./deploy/dns-records.sh

Verify

Thirteen checks: DNS, TLS, port 25, blocklists, PTR. Fix what it flags before your agents depend on it.

./deploy/doctor.sh

Create an identity

One API call mints an address and its scoped token. Hand the token to your agent — never the admin key.

POST /v1/identities → fox-k7d2@yourdomain

Receive

The agent waits on the inbox; the signup mail arrives; the OTP comes back parsed and ready to type.

mail_wait_for → otp.codes[0]
0
REST endpoints
0
MCP tools
0
automated tests
0
bytes of mail leaving your infra

REST API

  • POST /v1/identities — mint an address + scoped token
  • POST /v1/identities/:a/token — rotate (revoke) a token
  • DELETE /v1/identities/:a — retire an identity
  • GET /v1/messages — list an inbox
  • GET /v1/messages/:id — full mail + parsed OTP
  • POST /v1/messages/wait — long-poll for new mail
  • POST /v1/send — send as any identity you own

MCP tools

  • mail_new_identity
  • mail_list_identities
  • mail_list_messages
  • mail_read_message
  • mail_wait_for
  • mail_send

Extraction corpus

  • Google, GitHub, Amazon, Microsoft, OpenAI, Discord
  • Aliyun, Tencent Cloud, NetEase
  • Verification / reset / magic links
  • Codes split across HTML tags

The core trick

Raw mail in. Structured OTP out.

Agents shouldn't parse MIME. Every message comes back with codes and action links already extracted — and the raw text and HTML right there when extraction isn't enough.

From: noreply@github.com To: fox-k7d2@yourdomain Subject: [GitHub] Verify your email Here's your GitHub launch code: 59162834 Or verify your email address directly: https://github.com/users/…/confirm_ verification/abc123?via_launch_… This code expires in 10 minutes.
{ "from": "noreply@github.com", "subject": "[GitHub] Verify your email", "otp": { "codes": ["59162834"], "links": [ "https://github.com/…/confirm_verification/…" ] } }

Compared to the alternatives

Different choices, made honestly.

openagent.email AgentMail MailSlurp
Open source Apache-2.0
Self-hosted
PriceFlat VPS cost (~$5/mo)Per-inbox subscriptionUsage-based subscription
Unlimited inboxes catch-allPaid tiersPaid tiers
MCP-native REST/SDKs
OTP / link extraction
Data leaves your infraNeverAlwaysAlways
You run a serverYes — that's the pointNoNo

To be fair: if you never want to touch a VPS, a hosted service is genuinely easier. We think owning the mailbox — the OTPs, the links, the reputation — is worth ten minutes of setup. Your call.

Before you ask

Runs on the smallest VPS
you can buy.

Measured on our own production instance, sitting idle: the whole stack — mail server, API, everything — sips about 190 MB of RAM and roughly zero CPU.

MINIMUM

1 vCPU · 1 GB · 10 GB

Works with the defaults. That's a $5/mo VPS — or a $10–15/year deal box.

COMFORTABLE

1 vCPU · 2 GB · 20 GB

Headroom to turn on spam filtering (SpamAssassin) and never think about it again.

WITH ANTIVIRUS

4 GB RAM

ClamAV alone eats ~1 GB, so it ships off by default. Agent mail rarely needs it.

The real prerequisite isn't size — it's port 25. AWS, GCP, Azure, DigitalOcean and Vultr block it by default (some open it on request). Check before you buy — or route outbound through a relay like Amazon SES and skip the fight entirely.

Open source

Yours to run, read, and fork.

The API, the MCP server, the deploy tooling — all public, all auditable. Run it on a Raspberry Pi or a fleet. Contribute back when you want to.

Apache-2.0

Ready to give your agents
their own inbox?