AI Outreach Automation

Which email APIs have an MCP server in 2026?

Five of the ten email sending APIs we checked publish an official MCP server that can send mail. Here is which ones, how an agent connects, and what their own documentation says limits it.

By WarmySender Team September 28, 2026 8 min read

Direct answer. Five of the ten email sending APIs we checked publish an official MCP server that can send email: AgentiSend, Resend, Postmark, Mailgun and MailerSend. Brevo and Mailjet publish official servers that do not document a transactional send, Twilio's official server for SendGrid searches documentation only, Amazon SES has a general AWS server and a sample that is not meant for production, and we found none for SparkPost. The bigger difference is what limits an agent once it is connected: AgentiSend is the only one that documents a send budget, repeat-send protection and an account-wide stop on the MCP path itself.

MCP (Model Context Protocol) is how an agent such as Claude, ChatGPT, Cursor, Codex, OpenClaw, Hermes Agent or any agent that speaks MCP gets tools it can call. For an email API, that usually means the agent can send mail on your behalf, so the useful questions are: is the server published by the vendor, where does it run, how does the agent sign in, and what stops it sending too much.

Key takeaways

The table

Every cell comes from the vendor's own published pages, read on 28 September 2026. "Not documented" means we could not find it on a public vendor page, not that it does not exist.

APIOfficial MCP serverHosted or localSign-inSends emailDocumented limits on agent sendsVendor's own caveat
AgentiSendYes, 82 toolsHostedAPI key or OAuthYesPer-key send budget and per-minute ceiling the key can only lower; repeat sends refused and held; account-wide stop only a person can lift; approval queueNone stated
ResendYesHosted, or a local packageOAuth or API keyYesSend-only keys, optionally limited to one domainNone stated
PostmarkYesLocalServer tokenYes, single and batchTools marked read-only or destructive, so the client can ask before actingNever configure auto-approval for sending in untrusted environments
MailgunYesLocal onlyAPI keyYesNo delete operations; the loaded tools can be limitedNo client-side rate limiting; warns about prompt injection
MailerSendYes, more than 100 toolsHostedOAuth loginYesNot documentedNone stated
BrevoYesHostedMCP tokenTransactional send not listedPer-module endpoints narrow the tool setThe token grants full read/write access to the account
MailjetYesLocalAPI key and secretNot documentedNot documentedNone stated
SendGrid (Twilio)No sending server; Twilio's official server searches documentationHostedNoneNoNot applicablePublic Beta
Amazon SESNo SES-specific server; a general AWS server and an SES sampleGeneral server hosted; sample localAWS credentialsSample onlyAWS access policies and audit loggingThe sample is not intended for production
SparkPostNone foundNot applicableNot applicableNot applicableNot applicableNot applicable

Hosted or local, and why it matters

A hosted server lives at a URL the vendor runs. You add the address to your agent, sign in (often through OAuth, so no key is pasted anywhere), and the vendor keeps the server up to date. A local server is a package you install and run on your own machine, with an API key in its configuration. Local servers suit teams that want everything on their own hardware; hosted servers suit agents that run in the cloud or in a chat app that cannot start a local process.

Neither is safer by default. What matters is what the key or sign-in can do, and whether anything below the agent limits volume.

What stops a runaway agent

An agent that retries, re-runs or loops can send the same email again and again, and a scoped key does not help with that: it limits which actions are allowed, not how many. Here is what each vendor documents for the MCP path:

Whatever the API, keep the guard below the agent. Here is how to stop an AI agent sending the same email in a loop, and how to hand an agent an email key without handing it your reputation.

Install only the official package

Because MCP servers run with your email credentials, an impostor package can read or send mail as you. Two vendors address this directly: Postmark asks users to confirm they are running its official server, and Twilio advises against running community servers alongside its official ones. The safe habit is simple: install from the link in the vendor's own documentation, and check that the package is published by the vendor's own organisation.

Vendor notes

AgentiSend

Hosted server with 82 tools, reached by API key or OAuth. It sends single, batch and reply messages, and every tool that changes something accepts an idempotency key. Per-key limits on tool calls are published: 120 reads, 60 writes and 30 sends a minute. See the AgentiSend MCP guide or agentisend.com.

Resend

Hosted server plus an open-source local package built from the same code. Sign in with OAuth or an API key. Beyond sending, it covers logs, domains, contacts, broadcasts and webhooks, and it can create, update and remove API keys.

Postmark

An official local server that sends single and batch messages. Its documentation asks you to confirm you are using the official package and not to configure auto-approval for sending in untrusted environments.

Mailgun

An official local server covering sending, statistics, domains, suppressions and templates. Mailgun states that it does not currently offer a hosted version.

MailerSend

A hosted server with a long tool list, including sending single and bulk email, SMS, and creating API tokens with scopes. You connect by URL and sign in through a login flow.

Brevo

A hosted server split into modules, each with its own endpoint. Its module list covers creating and managing campaigns; a transactional send is not listed. Brevo notes that the MCP token grants full read/write access to the account.

Mailjet

An official local server published on npm. Its documentation does not describe sending email.

SendGrid, Amazon SES and SparkPost

Twilio's official MCP server searches its documentation and does not make API calls, so it cannot send through SendGrid. AWS publishes a general MCP server for its services and a separate SES sample that it says is not intended for production. We found no official server for SparkPost.

Where WarmySender fits

This roundup covers APIs that send the mail your product or agent triggers. Outreach is a different job. WarmySender runs its own MCP server at warmysender.com/mcp, so Claude, ChatGPT, Cursor, Codex, OpenClaw, Hermes Agent and any agent that speaks MCP can build, launch and manage cold email, LinkedIn and Instagram campaigns, verify emails and tune warmup in plain language. The agent never sends a message directly and can never raise a limit; WarmySender's scheduler paces every action. Here is how to connect an AI agent to your outreach tools, and how the same APIs compare on budgets, loop protection and deliverability.

How we checked

We counted a server as official only when the vendor publishes it on its own documentation, its own code organisation or its own package scope. Everything was read on 28 September 2026. Tool counts and features change often, so treat the counts as a snapshot, and check the vendor's page before you connect an agent.

Frequently asked questions

Is a hosted MCP server safer than a local one?

Not by itself. A hosted server saves you installing and updating anything and often lets the agent sign in without a pasted key; a local one keeps everything on your machine. Safety comes from what the credential can do and what limits sit below the agent.

Can an agent raise its own send limit through MCP?

On AgentiSend, no: a key can lower its own limits but not raise them. The other APIs we checked do not document a per-key send budget for MCP at all, so the practical limit is your account plan.

Does a scoped API key cap how much an agent can send?

No. A send-only or domain-restricted key limits what the agent can do, not how many messages it sends. Volume needs a budget or ceiling enforced by the sending API.

How do I tell an official MCP package from an impostor?

Install from the link in the vendor's own documentation and check that the package or repository belongs to the vendor's organisation. Postmark and Twilio both warn against unofficial servers.

Can an email MCP server create new API keys?

Some can. Resend's server can create, update and remove API keys, and MailerSend's can create tokens with scopes. Check the tool list before you connect an agent with full access.

Does SendGrid have an MCP server?

Twilio publishes an official MCP server that searches its documentation, but it does not make API calls, so it cannot send email through SendGrid.

Sources

All pages read 28 September 2026.

Topics: ai agents mcp transactional email email api