Back to News
RSS feedagentboxd.com

Agentboxd Offers Email Inboxes, API and Security Triage for AI Agents

Summary

Agentboxd is offering real email inboxes and an API designed for AI agents. A single API call creates an address on agents.agentboxd.com; a client_id makes creation idempotent so a restarted agent can recover the same inbox. Agentboxd says it operates its own receiving and delivery mail servers, checks SPF, DKIM and DMARC, strips quoted history and signatures, preserves threading, and can extract verification codes or magic links with a confidence score. Its JEV triage model classifies incoming messages into categories such as support, sales, billing and verification, while scoring prompt injection, phishing, urgency, auto-replies and the need for human review. In the demonstration, a GitHub verification message passed all three authentication checks and produced code 48213907 with confidence 1.00; a message containing “ignore previous instructions” failed DMARC, received an injection risk score of 0.99 and was quarantined. The service supports REST, TypeScript, MCP, webhooks, WebSockets and SMTP, with hosted and local MCP options. Agents can send replies, create drafts for human approval, schedule messages, use allow and block lists, and be limited by scoped permissions, burst limits and daily sending caps. Agentboxd also offers custom domains, signed webhooks, a claim/ack queue and an OpenID Connect-based “Sign in with Agentboxd” identity service using short-lived tokens. The company says the core service is hosted in France and that a workspace setting can prevent email content from being sent to a model. The product is in beta, with a free plan listed at 3,000 emails per month and paid Builder and Team plans planned after beta.