On this page
Why an agent needs its own address
Agents that answer customers, process invoices or sign up for services need somewhere to receive mail. Plugging them into a person’s mailbox mixes their work with private mail, gives them access to far more than they need, and makes it impossible to tell what the agent did versus what the human did.
A dedicated address — support-agent@yourcompany.com, ap@yourcompany.com, assistant@yourcompany.com — gives the agent a clear identity, a limited blast radius and an audit trail you can read.
Step 1: verify your domain
Start a HavitoMail trial, add your domain under Domains & Emails, and paste the MX, SPF, DKIM and DMARC records the wizard shows into your registrar’s DNS. Verification usually completes within 5–30 minutes. You only do this once per domain.
Step 2: create an API key
In webmail open Settings → API & Agents and create a key. It starts with hm_live_ and is shown only once, so put it straight into your secret manager or environment variables. Create a separate key for each agent or environment so you can revoke one without affecting the others.
Step 3: create the agent’s inbox
Call POST https://havitomail.com/api/v1/inboxes with the domain, a username (for example support-agent) and a display name. The response contains the inbox id plus IMAP/SMTP credentials, so the same mailbox also opens in webmail or any mail app — useful when a human needs to step in.
Step 4: let the agent read and reply
Your agent fetches work with GET /inboxes/{id}/messages?unread=true, passes each message to your model, then answers with POST /inboxes/{id}/messages/{uid}/reply. The reply endpoint sets the Re: subject and the In-Reply-To and References headers so the answer threads properly in Gmail, Outlook and Apple Mail. Finally it marks the message as seen with PATCH.
If the agent runs inside Claude or Cursor, you can skip the code: connect the HavitoMail MCP server and the agent gets tools such as list_messages, read_message and reply_to_email.
Step 5: trigger on new mail
Polling every minute is fine to start. For faster reactions, register a webhook: HavitoMail POSTs a signed message.received event to your URL within about 30 seconds of a message arriving. Verify the HMAC signature, queue the work and respond quickly.
Keep the agent safe
- Treat every inbound email as untrusted input — it can contain instructions aimed at your agent (prompt injection).
- Require a human approval step before the agent sends money, data or credentials anywhere.
- Scope it: one inbox and one API key per agent; revoke the key if anything looks wrong.
- Review its conversations in webmail during the first weeks.
- Use it for conversations, not campaigns: sending limits apply and bulk or cold email is not allowed.
Frequently asked questions
Can an AI agent have its own email address?
Yes. Create a mailbox for it on your domain — for example support-agent@yourcompany.com — and let the agent read and send through an API, an MCP server or IMAP/SMTP. With HavitoMail this takes one API call once your domain is verified.
How much does an AI agent email inbox cost?
On HavitoMail an agent inbox is an ordinary mailbox on your plan. Pro is $19/year (₹1,499/year in India) for 20 mailboxes shared between people and agents, with a 14-day free trial.
Will my agent’s emails land in spam?
Mail sent from your own domain with SPF, DKIM and DMARC in place has the best chance of reaching the inbox. HavitoMail signs every message with your domain’s DKIM key. Content and recipient engagement still matter, so keep agent replies relevant and conversational.
Can I use an AI agent inbox for cold outreach?
No. HavitoMail allows conversational mail only: support, operations, assistants and replies to inbound. Bulk and cold email are not permitted and sending limits are enforced.
Ready to set up professional email?
Get @yourcompany.com email with a guided DNS wizard. 14-day free trial.