Mailsac MCP server: test inboxes for AI coding agents

Give Your AI Coding Agent a Test Inbox: the Official Mailsac MCP Server

By Mailsac Engineering. Written for @mailsac/mcp 0.1.0.

AI coding agents can now build a sign-up flow in minutes. Checking that it works is still awkward: the last step happens in an inbox the agent can’t see. So the agent stops and asks you to open your email, or it marks the task done without knowing whether the confirmation email arrived, whether the link works, or whether the code is six digits or five.

The official Mailsac MCP server closes that gap. It gives any agent that speaks the Model Context Protocol (Claude Code, Cursor, VS Code, Claude Desktop and others) its own disposable test inboxes. The agent creates an address, uses it in your app, waits for the email, and reads the link or code itself.

What the agent can do

Tool What it does
create_test_address Makes a new unique address, such as signup-mf3k2a1b-9c41d2@mailsac.com. It can receive mail immediately; there is nothing to create first.
wait_for_email Waits for the email to arrive (optionally matching a subject, sender or time), then returns the subject, text, every link, the link most likely to confirm, reset or log in (actionLink), and any one-time codes.
list_emails / read_email Lists what arrived, and reads one email as text, HTML, raw source or headers.
delete_emails Cleans up after a test.
list_domains Shows your private domains, so the agent can use one instead of a public address.

Set it up in a minute

Create a free Mailsac account and an API key, then add the server.

Claude Code

claude mcp add mailsac -e MAILSAC_API_KEY=your-key -- npx -y @mailsac/mcp

Cursor (.cursor/mcp.json) or Claude Desktop

{
  "mcpServers": {
    "mailsac": {
      "command": "npx",
      "args": ["-y", "@mailsac/mcp"],
      "env": { "MAILSAC_API_KEY": "your-key" }
    }
  }
}

VS Code (.vscode/mcp.json)

{
  "servers": {
    "mailsac": {
      "type": "stdio",
      "command": "npx",
      "args": ["-y", "@mailsac/mcp"],
      "env": { "MAILSAC_API_KEY": "your-key" }
    }
  }
}

The documentation lists every setting, including MAILSAC_DOMAIN for private domains.

What it looks like

Ask the agent to check a flow the way a person would:

Sign up on http://localhost:3000 with a fresh test address and confirm the account by email.

The agent calls create_test_address, fills in your form, then calls wait_for_email. When the email arrives, the tool hands back something like this (from our own test run):

{
  "subject": "Confirm your Example account",
  "from": "no-reply@example.test",
  "actionLink": "https://example.test/verify?token=e2e-abc123",
  "codes": ["731905"],
  "polls": 1
}

The agent opens actionLink (or types the code), checks that the account is confirmed, and reports back, including when something is wrong: no email within a minute, a link pointing at the wrong host, or a code the form rejects. delete_emails then tidies up.

The same works for password resets, magic-link logins, invitations and two-factor codes.

Turn the check into a test

An agent’s check proves the flow works today. A test keeps it working. Once the agent has seen the email, ask it to write an end-to-end test for the flow. Our Playwright CI example shows the pattern it can follow: a unique address per test, polling with a timeout, and assertions on the link and code, in GitHub Actions and GitLab CI. For Cypress there is @mailsac/cypress, and any language can use the REST API.

Public addresses and private domains

Addresses at @mailsac.com are public: anyone who guesses the address can read the mail. They are perfect for made-up test data and need no setup, which is why the server uses them by default. For a staging environment that sends real names or data, use a private domain: your own subdomain or a zero-setup yourteam.msdc.co subdomain. Set MAILSAC_DOMAIN and every new address uses it. Mail to a private domain is visible only to your account.

What it costs

Each API call uses one Mailsac operation. wait_for_email checks every three seconds, so an email that arrives within a few seconds typically costs two to five operations, and creating an address costs nothing. The free plan includes 1,500 operations a month, enough for a few hundred agent checks; paid plans start at 25,000.

Open source

The server is MIT-licensed on GitHub and published to npm as @mailsac/mcp. Requests from it identify themselves with a Mailsac-Client: mcp header, so we can count how many people use Mailsac through AI agents. We never look at your email content for that. Issues and pull requests are welcome.

Email preview security update for browser automation

On September 17, 2026, we updated Mailsac’s email previews to isolate email HTML from the surrounding application. This was an intentional change to improve Mailsac’s security. If your automated tests inspect email content through the Mailsac website, you may need to update how they locate that content.

What changed

  • Expanded HTML messages in the standard inbox now render inside a sandboxed iframe.
  • The full HTML preview at /dirty/{inbox}/{id} now also uses a sandboxed iframe.
  • Unified Inbox already used an iframe; its preview now has additional sandbox restrictions.

The sandbox blocks scripts inside emails and prevents the surrounding page from directly accessing the email’s document. This keeps email content separate from the Mailsac application.

Updating browser tests

Use your test framework’s iframe support to locate elements inside the email preview. A selector that searches only the top-level page will no longer find content inside the frame.

The current preview iframe titles are:

  • Standard inbox: Email message
  • Full HTML preview: Email HTML preview
  • Unified Inbox: Email message body

Select the relevant preview frame, then apply your existing email-content locators within it. If several messages are expanded, scope the frame selector to the message you are testing or keep only that message expanded.

For framework-specific guidance, see Playwright’s frame locators or Selenium’s frame switching. Direct access through the parent page’s contentDocument is intentionally restricted by the sandbox.

Tests that retrieve email content through the API do not need iframe selectors; the frame-selection steps above apply to browser UI tests.

Communication and support

We should have communicated this compatibility change when it shipped. We’re sorry for the extra investigation this caused.

If you need help adapting a test, contact Mailsac support with the view you use and your automation framework.

May 2026 Major Release

This release focuses on improving team account management, inbox performance, and frontend reliability across the Mailsac web app.

Summary

  • New “elevate to root” permission for safer admin delegation
  • Inbox UI rewritten with improved pagination and clarity
  • Faster debugging tools and message analytics
  • MFA enforcement tightened for account security

Features

Elevate to Root User

Team users can now be granted an “elevate to root” permission. This allows a user to temporarily assume root-level privileges within their session without exposing root account credentials.

Use cases:

  • Safer offboarding (no shared root access to rotate)
  • Delegating admin tasks without sharing credentials

Elevation is session-scoped and requires re-authentication.

Individual Inbox Refresh

The inbox UI has been rewritten on the new frontend framework.

Improvements:

  • Faster, more complete pagination and message navigation
  • Clearer indication of public vs private inboxes
  • Reduced UI latency when loading large inboxes

General Improvements

Continued migration to the new frontend framework across multiple app pages.

Faster loading for inbound message debugging and message count charts.

Direct access to forwarded inboxes from the Enhanced Addresses list.

POP3 settings consolidated into the Enhanced Address Management screen.

Security & Fixes

MFA is now required, as an additional security step, to remove MFA from both team and root accounts.

Fixed an issue where some inbound mail was not tracked correctly. As a result, Ops usage may increase for affected accounts.

Removed the spam feature due to low usage.

Upgraded frontend dependencies to address known security vulnerabilities.

Behavior Changes

Spam feature removed – account.disableSpam property no longer present.

Inbound message tracking corrected (may increase Ops usage as noted above).

March 2026 Release

We continue to enhance the Mailsac platform and have improved the performance of the throttling engine that is at the heart of our inbound email service. It helps us separate non-customer email from spam.

November Release: Load Testing Feature + Performance Boosts

We are excited to announce upgrades to the Mailsac Platform, recently deployed in November 2024.

Load Testing Feature

Mailsac is the first QA Disposable Email Platform which allows Load Testing or Burn Testing of SMTP sender servers. You can safely send enormous amounts of test email to Mailsac after creating a Load Test Subdomain in the Mailsac Dashboard. When we receive these emails to a special subdomain, they are not subject to the (already high) throttling limits of the main platform. Note that emails are not saved/indexed as normal, so this is a feature specifically for testing your capacity to send high volume email campaigns.

More tutorials for Load Testing email will be coming soon.

Improved Account Analytics Performance

We overhauled the backend systems for usage and analytics. You may have noticed sluggishness in the past on these features, but that should be gone for good. There’s also an updated user interface for debugging inbound mail and webhooks.

November 2023 Release Notes

Throttling notices in every inbox

Custmers will start seeing informational messages in the inbox view https://mailsac.com/inbox/{{ email address }} when there has been throttling imposed on the inbox or sender to the inbox.

Paying customers will very rarely experience throttling. In almost all cases, throttling happens because they were sending to a public inbox, not a custom domain or private address.

We only throttle incoming messages to protect the stability of our service for all of our customers. These protections have been in place for years, but were not transparent to customers.

If you are on a paid plan and you are seeing throttling messages, reach out to [email protected], we can help you configure a custom domain or private addresses. These both can be done in seconds with no need for DNS changes.

If you are on our free tier and seeing these messages, this is a nudge for you to sign up for a paid plan. We would love to have you as a customer.

Updates and Fixes For October 2023

Unified Inbox, UI Modernization Efforts, and Maintenance Notifications

We do our best to be customer-focused by listening to our customer feedback and making sure your issues are addressed.

This month, we focused on UI issues that customers reported or we noticed when we were using our service.

Improved Maintenance Notifications

During a major database upgrade in September we noticed our maintenance notification on the website wasn’t always working properly. This resulted in customers seeing an unfriendly error.

From now on, customers will see a friendlier error page or API message when we are down for maintenance. That’s typically rare – once a year on average. We deploy often. Mailsac’s architecture has several load balancers and caches, and redundancies – we avoid stop-the-world events. But sometimes that’s unavoidable, and we hope it won’t be confusing.

Unified Inbox

The navigation bar for the Unified Inbox now works properly under Safari. It should no longer be cut-off (missing pagination buttons) in other browsers while viewing a message.

Starred messages for non-owned inboxes will now appear in the Unified Inbox.

UI Modernization

As noted in previous posts, we are migrating the entire Mailsac user interface to React and Next.js. After all pages are migrated, we will give the styling a facelift.

For now the migration should look seamless – perhaps slightly faster and more solid (thank you static typing and pre-compilation).

The account details page has been converted over to Next.js.

A bug that didn’t allow a customer to remove an invoice email was fixed.

The password reset and account deletion functions were moved to their own pages.

We added many more integration tests to account management features.

Backend upgrades

On a weekly basis we patch, upgrade and improve the many backend systems of Mailsac across several environments. Typically this involves making small change to ansible, terraform, docker, code dependencies, or other infra-as-code. We often migrate portions of the 12+ year old Node.js JavaScript codebase to TypeScript or Go. If we’re luckily, we can delete unnecessary code or remove a dependency.

To run this SaaS smoothly, every day we get onto the software treadmill. We we enjoy running this service immensely, and hope you enjoy using it.

Updates and Fixes In August and September 2023

Mailsac remains committed to continuous improvement. Every day we improve the product based on customer feedback and SaaS best practices.

Here’s a summary of the latest enhancements.

  • New homepage and header navigation enhancements.
  • SAML Configuration Fix: enabled customer-supported account deletion when SAML is configured.
  • Testing: refactored and extended test coverage to payment processing.
  • Database: A series of database upgrades have been applied. This will continue through October to ensure we are leveraging the latest fixes and performance improvements.
  • Next.js: we continue overhauling the entire site using Next.js, in anticipation of a major restyle in 2024.

There are no breaking changes to any public API in these releases.

For further inquiries, please contact [email protected]

Mailsac Enhances Free Tier: Introduces One Free Private Address for Improved Privacy and Advanced Email Testing Capabilities

We’re delighted to announce a significant enhancement to our free tier plan, specifically tailored to meet the needs of Quality Assurance (QA) teams and automated testers. Effective immediately, all free Mailsac users will have access to one free private address, enabling them to maintain confidentiality during email testing and ensure privacy for sensitive testing communications.

The addition of the free private address empowers QA teams and automated testers with an extra layer of control over their email testing activities. With the free private address, they can separate and safeguard their testing correspondence, ensuring the confidentiality of valuable testing data. By seamlessly managing both public and private email addresses within a single Mailsac account, QA teams and automated testers can streamline their workflow and simplify the management of their testing environments.

“At Mailsac, we understand the critical importance of data privacy and confidentiality in the testing process. We are excited to offer QA teams and automated testers the advantage of one free private address to enhance their email testing capabilities,” stated Michael Mayer, managing executive at Mailsac. “This enhancement is a testament to our commitment to empowering professionals in the QA field with robust email solutions that prioritize privacy and security.”

In addition to the free private address, Mailsac’s free tier plan includes a comprehensive range of features designed to cater to the unique needs of QA teams and automated testers. These features include rolling message storage space, customizable email addresses, and reliable email forwarding and routing capabilities. The ability to forward emails to various testing integrations environments, via Slack, webhooks, websockets, and other Mailsac addresses, facilitates seamless communication and collaboration within a company’s testing ecosystem. Furthermore, Mailsac provides a robust REST API, enabling QA teams and automated testers to check and manage email messages with ease during their testing cycles.

To benefit from enhanced privacy, advanced email testing capabilities, and a comprehensive range of features, QA teams and automated testers can sign up for Mailsac’s free tier plan at https://mailsac.com/pricing. The inclusion of the free private address and the expanded email testing options demonstrate Mailsac’s commitment to meeting the specific requirements of QA professionals, enabling them to conduct thorough and secure email testing.

About Mailsac: Mailsac is the leading provider of secure and flexible email testing services, catering to the needs of individuals, small businesses, and organizations worldwide. With a strong emphasis on user privacy and data protection, Mailsac empowers QA teams and automated testers to conduct rigorous and secure email testing while maintaining control over their digital identities. From the free tier plan to enterprise offerings, Mailsac delivers unmatched email solutions and exceptional customer support.

For media inquiries, please contact: Michael Mayer Email: [email protected]

Unveiling Mailsac’s New API Endpoint Feature: Inbox Filter

A look at filtering email messages with the Mailsac API

Mailsac has rolled out a new API endpoint feature, dubbed “inbox filter.”

It limits email messages using the to, from, and subject fields. Say goodbye to the conventional OR logic of /api/inbox-search and embrace the power of logical AND.

The Inbox Filter Endpoint: Technical Breakdown

The /api/inbox-filter API endpoint accepts the following optional query parameters:

  1. andSubjectIncludes: Filter messages by text included in the subject line
  2. andFrom: Filter messages by text included in the FROM envelope
  3. andTo: Filter messages by text included in the TO envelope

This endpoint delivers results only when at least one query condition is specified, otherwise, expect a 400 error. The response is capped at 100 results, so adjust your query or prune your account accordingly.

JavaScript Unit Test with Mocha and Axios

To illustrate the usage of the /inbox-filter API endpoint, here’s a JavaScript unit test using Mocha and Axios:

const axios = require('axios');
const assert = require('assert');

describe('Inbox Filter API Endpoint Test', () => {
  it('should return filtered messages', async () => {
    const mailsacApiKey = 'your-api-key-here';
    const endpoint = 'https://mailsac.com/api/inbox-filter';
    const andSubjectIncludes = 'Important';
    const andFrom = '[email protected]';
    const andTo = '[email protected]';

    const response = await axios.get(endpoint, {
      headers: { 'Mailsac-Key': mailsacApiKey },
      params: { andSubjectIncludes, andFrom, andTo },
    });

    assert.strictEqual(response.status, 200);
    assert.strictEqual(Array.isArray(response.data.messages), true);
    response.data.messages.forEach((message) => {
      assert.strictEqual(message.subject.includes(andSubjectIncludes), true);
      assert.strictEqual(message.from[0].address.includes(andFrom), true);
      assert.strictEqual(message.to[0].address.includes(andTo), true);
    });
  });
});

Looking for a robust email testing solution that can simplify your workflow and improve efficiency? Look no further, friends. Mailsac offers powerful features like this new inbox filter API endpoint and many more, tailored to meet the needs of developers, testers, and businesses alike. Discover the benefits of Mailsac today and elevate your email management game. Try Mailsac for free or learn more about our plans and join our growing community of satisfied users at forum.mailsac.com.