Which email APIs have an MCP server in 2026?
Five of the ten email sending APIs we checked publish an official MCP server that can send mail. Here is which ones, how an agent connects, and what their own documentation says limits it.
Direct answer. Five of the ten email sending APIs we checked publish an official MCP server that can send email: AgentiSend, Resend, Postmark, Mailgun and MailerSend. Brevo and Mailjet publish official servers that do not document a transactional send, Twilio's official server for SendGrid searches documentation only, Amazon SES has a general AWS server and a sample that is not meant for production, and we found none for SparkPost. The bigger difference is what limits an agent once it is connected: AgentiSend is the only one that documents a send budget, repeat-send protection and an account-wide stop on the MCP path itself.
MCP (Model Context Protocol) is how an agent such as Claude, ChatGPT, Cursor, Codex, OpenClaw, Hermes Agent or any agent that speaks MCP gets tools it can call. For an email API, that usually means the agent can send mail on your behalf, so the useful questions are: is the server published by the vendor, where does it run, how does the agent sign in, and what stops it sending too much.
Key takeaways
- Five official servers can send today: AgentiSend, Resend, Postmark, Mailgun and MailerSend.
- Hosted or local varies. AgentiSend, Resend, MailerSend and Brevo host a server you connect to by URL; Postmark, Mailgun and Mailjet run on your own machine.
- A scoped key limits what an agent can do, not how much. Only one API documents a send budget that applies to MCP sends.
- Install only the vendor's own package. Two vendors warn against unofficial servers in their own documentation.
- Some servers can manage API keys, so check the tool list before you give an agent full access.
The table
Every cell comes from the vendor's own published pages, read on 28 September 2026. "Not documented" means we could not find it on a public vendor page, not that it does not exist.
| API | Official MCP server | Hosted or local | Sign-in | Sends email | Documented limits on agent sends | Vendor's own caveat |
|---|---|---|---|---|---|---|
| AgentiSend | Yes, 82 tools | Hosted | API key or OAuth | Yes | Per-key send budget and per-minute ceiling the key can only lower; repeat sends refused and held; account-wide stop only a person can lift; approval queue | None stated |
| Resend | Yes | Hosted, or a local package | OAuth or API key | Yes | Send-only keys, optionally limited to one domain | None stated |
| Postmark | Yes | Local | Server token | Yes, single and batch | Tools marked read-only or destructive, so the client can ask before acting | Never configure auto-approval for sending in untrusted environments |
| Mailgun | Yes | Local only | API key | Yes | No delete operations; the loaded tools can be limited | No client-side rate limiting; warns about prompt injection |
| MailerSend | Yes, more than 100 tools | Hosted | OAuth login | Yes | Not documented | None stated |
| Brevo | Yes | Hosted | MCP token | Transactional send not listed | Per-module endpoints narrow the tool set | The token grants full read/write access to the account |
| Mailjet | Yes | Local | API key and secret | Not documented | Not documented | None stated |
| SendGrid (Twilio) | No sending server; Twilio's official server searches documentation | Hosted | None | No | Not applicable | Public Beta |
| Amazon SES | No SES-specific server; a general AWS server and an SES sample | General server hosted; sample local | AWS credentials | Sample only | AWS access policies and audit logging | The sample is not intended for production |
| SparkPost | None found | Not applicable | Not applicable | Not applicable | Not applicable | Not applicable |
Hosted or local, and why it matters
A hosted server lives at a URL the vendor runs. You add the address to your agent, sign in (often through OAuth, so no key is pasted anywhere), and the vendor keeps the server up to date. A local server is a package you install and run on your own machine, with an API key in its configuration. Local servers suit teams that want everything on their own hardware; hosted servers suit agents that run in the cloud or in a chat app that cannot start a local process.
Neither is safer by default. What matters is what the key or sign-in can do, and whether anything below the agent limits volume.
What stops a runaway agent
An agent that retries, re-runs or loops can send the same email again and again, and a scoped key does not help with that: it limits which actions are allowed, not how many. Here is what each vendor documents for the MCP path:
- AgentiSend documents a send budget and a per-minute ceiling on each key that the key can lower but not raise, refuses the fourth near-identical message to the same recipient within 60 minutes and holds it for a person, pauses every key on the account with one call that only a person can undo, and lets an agent put a send in an approval queue. Its documentation states that the same limits apply over MCP as over the regular API.
- Resend offers send-only keys that can be restricted to a single domain.
- Postmark marks tools as read-only or destructive so the client can ask before acting, and recommends a dedicated server because its tokens cannot be narrowed further.
- Mailgun exposes no delete operations and lets you load a subset of tools; it states that the server does not rate-limit calls itself.
- MailerSend, Brevo and Mailjet do not document send limits for their MCP servers.
Whatever the API, keep the guard below the agent. Here is how to stop an AI agent sending the same email in a loop, and how to hand an agent an email key without handing it your reputation.
Install only the official package
Because MCP servers run with your email credentials, an impostor package can read or send mail as you. Two vendors address this directly: Postmark asks users to confirm they are running its official server, and Twilio advises against running community servers alongside its official ones. The safe habit is simple: install from the link in the vendor's own documentation, and check that the package is published by the vendor's own organisation.
Vendor notes
AgentiSend
Hosted server with 82 tools, reached by API key or OAuth. It sends single, batch and reply messages, and every tool that changes something accepts an idempotency key. Per-key limits on tool calls are published: 120 reads, 60 writes and 30 sends a minute. See the AgentiSend MCP guide or agentisend.com.
Resend
Hosted server plus an open-source local package built from the same code. Sign in with OAuth or an API key. Beyond sending, it covers logs, domains, contacts, broadcasts and webhooks, and it can create, update and remove API keys.
Postmark
An official local server that sends single and batch messages. Its documentation asks you to confirm you are using the official package and not to configure auto-approval for sending in untrusted environments.
Mailgun
An official local server covering sending, statistics, domains, suppressions and templates. Mailgun states that it does not currently offer a hosted version.
MailerSend
A hosted server with a long tool list, including sending single and bulk email, SMS, and creating API tokens with scopes. You connect by URL and sign in through a login flow.
Brevo
A hosted server split into modules, each with its own endpoint. Its module list covers creating and managing campaigns; a transactional send is not listed. Brevo notes that the MCP token grants full read/write access to the account.
Mailjet
An official local server published on npm. Its documentation does not describe sending email.
SendGrid, Amazon SES and SparkPost
Twilio's official MCP server searches its documentation and does not make API calls, so it cannot send through SendGrid. AWS publishes a general MCP server for its services and a separate SES sample that it says is not intended for production. We found no official server for SparkPost.
Where WarmySender fits
This roundup covers APIs that send the mail your product or agent triggers. Outreach is a different job. WarmySender runs its own MCP server at warmysender.com/mcp, so Claude, ChatGPT, Cursor, Codex, OpenClaw, Hermes Agent and any agent that speaks MCP can build, launch and manage cold email, LinkedIn and Instagram campaigns, verify emails and tune warmup in plain language. The agent never sends a message directly and can never raise a limit; WarmySender's scheduler paces every action. Here is how to connect an AI agent to your outreach tools, and how the same APIs compare on budgets, loop protection and deliverability.
How we checked
We counted a server as official only when the vendor publishes it on its own documentation, its own code organisation or its own package scope. Everything was read on 28 September 2026. Tool counts and features change often, so treat the counts as a snapshot, and check the vendor's page before you connect an agent.
Frequently asked questions
Is a hosted MCP server safer than a local one?
Not by itself. A hosted server saves you installing and updating anything and often lets the agent sign in without a pasted key; a local one keeps everything on your machine. Safety comes from what the credential can do and what limits sit below the agent.
Can an agent raise its own send limit through MCP?
On AgentiSend, no: a key can lower its own limits but not raise them. The other APIs we checked do not document a per-key send budget for MCP at all, so the practical limit is your account plan.
Does a scoped API key cap how much an agent can send?
No. A send-only or domain-restricted key limits what the agent can do, not how many messages it sends. Volume needs a budget or ceiling enforced by the sending API.
How do I tell an official MCP package from an impostor?
Install from the link in the vendor's own documentation and check that the package or repository belongs to the vendor's organisation. Postmark and Twilio both warn against unofficial servers.
Can an email MCP server create new API keys?
Some can. Resend's server can create, update and remove API keys, and MailerSend's can create tokens with scopes. Check the tool list before you connect an agent with full access.
Does SendGrid have an MCP server?
Twilio publishes an official MCP server that searches its documentation, but it does not make API calls, so it cannot send email through SendGrid.
Sources
- AgentiSend, MCP guide: https://agentisend.com/docs/guides/mcp
- Resend, MCP server: https://resend.com/docs/mcp-server and https://github.com/resend/resend-mcp
- Resend, API key permissions: https://resend.com/docs/api-reference/api-keys/create-api-key
- Postmark, MCP server: https://postmarkapp.com/lp/mcp and https://github.com/ActiveCampaign/postmark-mcp
- Mailgun, MCP server: https://documentation.mailgun.com/docs/mailgun/mcp
- MailerSend, MCP server: https://developers.mailersend.com/mcp
- Brevo, MCP server: https://developers.brevo.com/docs/mcp-protocol and https://developers.brevo.com/docs/integration-guide
- Mailjet, MCP server: https://github.com/mailgun/mailjet-mcp-server
- Twilio, MCP server: https://www.twilio.com/docs/ai/mcp and https://github.com/twilio-labs/mcp
- AWS, MCP server: https://docs.aws.amazon.com/agent-toolkit/latest/userguide/mcp-server.html and SES sample https://github.com/aws-samples/sample-for-amazon-ses-mcp
All pages read 28 September 2026.