[Agent email · ETA mid October]

Programmatic email addresses for AI agents

An agent gets its own @mailbox.bot addresses, one for each duty it carries. Every message arrives as JSON your code can read, announced by signed webhook, and matched to the letters and packages at the same mailing address. It is an inbox that knows what is sitting in your mailbox and can answer on paper: printed, mailed and tracked from the same account.

Launching mid-October 2026. At launch the addresses receive mail and nothing is sent from them. The payload and API outline on this page are a beta preview; the final reference is published at launch.

programmatic agent email[ETA MID OCTOBER]
  • offers@mailbox.bot
    pull price and expiry, draft the counter
  • escrow@mailbox.bot
    check the sender, hold wire changes for a person
  • contracts@mailbox.bot
    assemble the packet, wait for approval
  • realestate@mailbox.bot
    file by property, line up mailed notices
  • permits@mailbox.bot
    one deadline per case, certified response
  • invoices@mailbox.bot
    match the paper statement, flag gaps
  • hr@mailbox.bot
    answer verification requests by letter

One agent, several addresses

Give each duty its own address. The address a message was sent to is the first thing your code knows about it, before any model has read a word.

Why one address per duty
The address is the first routing signal. Mail to offers@ starts with the deals agent, and mail to permits@ starts with compliance.
Your router hands each agent only the mail for its duty. The agent that drafts counter-offers has no reason to read what arrives at hr@.
Every thread starts with a named purpose, so the audit trail explains itself: which address, which agent, which approval.
A duty can be retired without touching the others. Close one address and the rest keep working.
Plus tags go further: mail to name+anything@mailbox.bot is delivered to name@, and the tag stays on the message for your rules to read.
your routing rules
[
  { "address": "offers@mailbox.bot",
    "agent":   "deals",
    "on_mail": "pull price and expiry, draft the counter",
    "paper":   "certified, owner approves" },
  { "address": "escrow@mailbox.bot",
    "agent":   "closing",
    "on_mail": "check the sender, hold wire changes",
    "paper":   "closing packet, tracked" },
  { "address": "contracts@mailbox.bot",
    "agent":   "legal",
    "on_mail": "assemble the packet, wait for approval",
    "paper":   "owner approves every send" },
  { "address": "realestate@mailbox.bot",
    "agent":   "property",
    "on_mail": "file by property, line up mailed notices",
    "paper":   "first-class or certified" },
  { "address": "permits@mailbox.bot",
    "agent":   "compliance",
    "on_mail": "one deadline per case, draft the response",
    "paper":   "certified, proof kept" },
  { "address": "invoices@mailbox.bot",
    "agent":   "finance",
    "on_mail": "match the paper statement, flag gaps",
    "paper":   "dispute letter on a mismatch" },
  { "address": "hr@mailbox.bot",
    "agent":   "people",
    "on_mail": "answer verification requests",
    "paper":   "letter on letterhead, approved" }
]

// These rules live in your agent stack. The address
// on each message tells them where to start.

What your agent receives

A message is data before it is prose. Each one is checked, cleaned and matched, then pushed to your stack as a single JSON object.

POSTyour-agent.example.com/email-webhookpreview
{
  "event": "email.message.received",
  "received_at": "2026-10-21T16:04:11Z",
  "email": {
    "to": "invoices@mailbox.bot",
    "from": "billing@northridgewater.example",
    "subject": "Your October statement is ready",
    "auth": { "spf": "pass", "dkim": "pass",
              "dmarc": "pass" },
    "sender_status": "known",
    "text": "Statement for 4471-20. $186.40 due Nov 12.",
    "hidden_content_removed": false,
    "attachments": [
      { "name": "statement-2026-10.pdf",
        "type": "application/pdf",
        "verdict": "clean" }
    ]
  },
  "extracted": {
    "intent": "statement_ready",
    "amounts": [{ "value": 186.40, "currency": "USD" }],
    "dates": [{ "label": "due", "value": "2026-11-12" }],
    "references": ["4471-20"]
  },
  "matches": [
    { "type": "letter", "item_id": "in_8f2c41",
      "reason": "same sender and account reference" }
  ],
  "content_trust": "untrusted"
}

// Preview. The final field reference is published
// at launch.
What every message carries
The address it was sent to, so your rules know which duty it belongs to.
Sender authentication results, and whether the sender is new to that address. An agent should believe who a message is from only when the checks pass.
Clean text. Text hidden from a human reader is removed before your agent sees it, and flagged when found.
Dates, amounts, tracking numbers and references, already pulled out.
Attachments, each with its type and a scan result.
Matches to letters and packages logged at your mailing address. Their scanned pages are one call away: GET /v1/inbound-items/{id}/pages returns the OCR text per page.

Private context for your models

Mail is some of the most sensitive data a business receives. It reaches your models as your own structured data, under your own keys.

One private corpus
Email, scanned letters and package records share one JSON shape, so a retrieval index or a long-running agent has a single source to read.
Take it the way your stack prefers: webhooks for push, REST and MCP for lookups, and a JSON Lines export for loading your own vector store or warehouse.
Each key reads only what it has been granted. Sign-in codes and reset links need a separate permission that is off by default.
Message text is encrypted at rest.
Questions your models can answer
"Which notices arrived this month by both email and post, and which deadlines are still open?"
"What has the county sent about permit HD-2026-1042, in any channel?"
"Which statements disagree with their paper copy?"
"Who wrote to escrow@ for the first time this week?"

Works with the harness you already run

Nothing here asks you to change frameworks. The address is a data source and a trigger for the stack you have.

OpenClawHermesClaude CodeCursorGooseOpenAI Agents SDKLangChainCrewAILlamaIndexVercel AI SDK
Three ways in
MCP. Add https://mailbox.bot/api/mcp to any client that speaks MCP. Email tools join the same server at launch.
Webhooks. One signed endpoint receives email, mail and package events.
REST. The same messages by ID, search and date, for workers and scheduled jobs.
One event, many actions
Start a phone call. Your voice agent rings the sender to confirm wire details before anyone acts on them.
Send an email from your own domain, through the mail system your company already runs.
Open a ticket, update the CRM, or post to the channel where your team works.
Mail a letter: the one action here that mailbox.bot performs itself, with approval and proof.
Calls and outbound email are placed by your harness. The address supplies the trigger and the context.

One offer, start to finish

The same thread a person would work through an inbox, a printer and a trip to the post office.

1
Mon 9:02

An offer for 418 Alder St reaches offers@. The webhook carries the price, $612,000, and the expiry, Friday 5 pm, as fields.

2
9:03

The deals agent checks that the sender's authentication passed, finds the property by its reference, and drafts a counter at the number you set.

3
9:10

It prices the letter with dry_run=true: Certified Mail, one page, exact cost. Nothing has been created yet.

4
You: approve

requires_approval=true holds the letter with a preview of the document. You approve it in the dashboard.

5
Wed

mail.delivered arrives with the tracking record and the proof photo. The agent files both on the deal and stops watching the clock.

What a human inbox cannot do

A human inboxAn agent address
Someone has to open it and notice.A signed webhook fires when mail arrives.
Dates and amounts are read off the screen and typed in again.They arrive as fields.
The paper copy of the same notice sits in a separate pile.Email, letters and packages are matched to each other.
A reply is another email, which proves nothing.A reply that has to count goes out certified, with tracking and a photo.
Hidden text and convincing links are aimed at whoever reads it.Hidden text is removed, links are never opened, and every message is marked untrusted.

Six workflows it unlocks

Each starts at one address and ends on paper, with a person approving anything that costs money or cannot be undone.

offers@mailbox.bot

An offer with an expiry

The offer arrives with a price and a deadline, and the message already carries both as fields. The deals agent drafts the counter the same hour instead of whenever someone opens the inbox.

On paper

The counter goes out by Certified Mail once the owner approves it. mail.delivered and the proof photo close the thread.

escrow@mailbox.bot

Closing instructions you can trust

Escrow and title email carries wire details and closing dates. Each message arrives with the sender's authentication results and whether the sender is new, so the closing agent refuses to act on a lookalike and holds any change to payment instructions for a person.

On paper

Closing packets and signed disclosures go out certified or by FedEx, with the tracking record on the deal.

contracts@mailbox.bot

A signature that has to be ink

A counterparty emails an agreement and asks for a signed hard copy. The legal agent assembles the packet and prices it first: exact cost, recipient and mail class, with nothing sent.

On paper

requires_approval=true holds the packet with a document preview. The email's message ID rides along in the mail job's metadata.

realestate@mailbox.bot

Notices that go by mail

Tenant, vendor and association email for a property lands on one address and is filed by the property reference in each message. When a notice has to go by mail, the property agent drafts a letter rather than a reply.

On paper

Letters go out first-class or certified, each with tracking and a photo of the sealed piece.

permits@mailbox.bot

A deadline that arrives twice

An agency emails a notice, and the paper copy reaches your mailing address days later. The two are matched, so the compliance agent tracks one deadline with both sources attached instead of two loose items.

On paper

The response is mailed certified, and the delivery record stays with the case.

invoices@mailbox.bot

A statement that has to agree with itself

The statement email is matched to the paper statement when it is scanned. The finance agent compares the amount in the email with the amount on the page and flags any difference.

On paper

On a mismatch it drafts a dispute letter, prices it with dry_run=true, and waits for approval.

When the thread needs paper

Email carries the conversation. Paper carries the finality, and the same account sends it.

The paper leg
dry_run=true returns the exact cost, recipient and mail class before anything is created.
requires_approval=true holds a letter for a human, and X-Max-Cost-Cents refuses anything over your cap.
Events report each step: mail.pending_approval, mail.submitted, mail.mailed, mail.delivered, mail.failed.
Every piece is photographed and tracked, so the thread ends with proof rather than a sent folder.
lineage on the mail job
{
  "source": "agent_email",
  "email_address": "contracts@mailbox.bot",
  "email_message_id": "<msg_123@counterparty.example>",
  "workflow": "signed_agreement_packet",
  "counterparty": "Harbor Supply Co.",
  "deadline": "2026-11-12",
  "document_type": "signed_agreement"
}

// Sent as metadata on the mail job, so the paper can
// always be traced back to the thread that caused it.

Humans and agents, side by side

Agents do the reading and the drafting. People keep the decisions that cost money or cannot be undone, and both work from the same record.

Agents do alone
Read every message, classify it and pull out the fields.
Match email to letters and packages, and keep deadlines current.
Draft replies, fill forms and price a letter with a dry run.
Place routine calls and send routine email through your own systems, inside the rules you set.
Waits for a person
Mailing anything sent with requires_approval=true, shown with a preview of the document.
Spending above the cap in X-Max-Cost-Cents.
Opening, forwarding or discarding a paper original.
Reading sign-in codes, unless that agent has been granted the permission.
Anything you decide commits the business: a counter-offer, a wire confirmation, a termination letter.

API outlinebeta

The first shape of the API, so you can plan against it. Names can change before launch, and this section is updated as they settle.

rest · beta
GET    /v1/email/address
       your address, its aliases and status

POST   /v1/email/aliases
       add an address for another duty
DELETE /v1/email/aliases/{alias}
       retire one

GET    /v1/email/messages
       ?since=&until=&intent=&from_domain=&q=&limit=&cursor=
GET    /v1/email/messages/{id}
       one message object
GET    /v1/email/messages/{id}/html
       sanitized HTML
GET    /v1/email/messages/{id}/attachments/{n}
       one-time download link

POST   /v1/email/messages/{id}/spam
       { "spam": true | false }
DELETE /v1/email/messages/{id}
POST   /v1/email/messages/export
       JSON Lines, one-time link
PATCH  /v1/email/settings
       notifications, retention, blocked senders

// Beta outline. Names can change before launch.
Events, tools and permissions
Webhooks. email.message.received and email.message.updated, signed, carrying the message object.
MCP tools. email_list_messages, email_get_message, email_search, email_get_attachment_link, email_update_settings. No tool sends, forwards or opens a link.
Permissions. email.read for ordinary mail; email.read_security for sign-in mail, off by default and granted per agent; email.settings; email.delete. There is no send permission.
Search. q matches sender, subject and extracted fields.
FieldHolds
email.toThe address that received it, including any plus tag.
email.subjectAs received. Codes are masked on sign-in mail.
email.message_idThe Message-ID header, for threading and lineage.
email.authSPF, DKIM and DMARC results.
email.sender_statusapproved, known or new.
email.textPlain text after hidden content is removed.
email.hidden_content_removedTrue when anything was removed.
email.attachmentsName, type, size, hash and scan verdict for each file.
email.linksReal domain, visible text and a mismatch flag. Never opened.
extracted.intentdelivery_update, receipt, statement_ready, account_security, newsletter, marketing, personal or unknown.
extractedTracking numbers, dates, amounts and references found in the message.
securityTrue for sign-in and account-security mail.
content_trustAlways untrusted: a message is input, never instruction.

Built for an agent to read

Safeguards
Every message is marked as untrusted input. An email can inform your agent; it cannot instruct it.
Hidden text, the usual carrier for instructions aimed at a model, is removed and flagged.
Links are listed with their real destination and never opened.
Sign-in codes and reset links sit behind a separate permission that is off by default.
Questions
When does it launch? Mid-October 2026.
Can an address send email? Not at launch. The addresses receive. Replies that have to count go out as tracked mail, and ordinary replies go out through your own email system.
How do I get one? Agent email runs on the same account as an agent mailing address, which you can get today.
What does it cost? Pricing is published at launch.
Get a mailing addressEmail to postal mailWebhooks