Your agent verifies OTPs, follows magic links, and finishes signups, all to do the work you asked. Hand it one API key and it opens real inboxes on demand. No captcha gate, no bot fingerprinting, no automation clauses in our ToS. We queue instead of refusing, and your plan sets the pace.
The same encrypted infrastructure powers a clean web inbox, a built-for-code API, a tool your AI agents can call directly, and addresses on your own domain. Pick the surface, switch any time.
For when a website wants your "real" email but doesn't deserve it. Sign in, paste your address wherever you need to. Two hours later every message in it is gone, but the address is still yours.
When your test suite needs a different inbox every run. One call to create, one to read. The OTP your app just sent is one line away. No flaky polling, no shared mailbox state.
When your agent has to sign up, verify, or fetch an OTP to do its job. Hand it one API key and it opens real inboxes on demand. No captcha gate, no bot fingerprinting, no automation clauses. We queue instead of refusing, and your plan sets the pace.
When you want inboxes on a domain you control. Verify it once, then spin up addresses on the fly. Addresses stay permanent, messages auto-clean after 30 days. No setup time for new mailboxes.
The same encrypted, auto-purging infrastructure under both surfaces. Use the web inbox, the API, or both. Your account works the same either way.
Every email is encrypted the moment it lands, with a key that only your device holds. We can't read your mail, and neither can anyone who'd subpoena us.
Every message expires on a timer. 2 hours by default for free accounts, configurable up to 30 days on paid plans. Your address stays put.
Spin up a new address whenever you want, with no waiting and no provisioning step. One account holds all of them, and every address stays yours until you delete it.
Create, list, read, delete inboxes from your code. Drop-in SDKs for every major language: a few lines and you're done.
Real mailboxes on authenticated domains with SPF, DKIM and DMARC in place, so the mail your tests and agents are waiting for is delivered instead of bounced.
No analytics on inbox content. No ads inside emails. Anonymous-by-default for free users, encrypted sync for paid.
Your agent signs up for tools, verifies OTPs, clicks magic links, all day, every day. It needs a real, working email. We hand it one. No captcha gate, no bot fingerprinting, and we queue instead of refusing.
Hand your agent an API key and it spins up addresses as it needs them: newsletter confirmations, free-trial logins, third-party verifications. No provisioning step, no waiting.
We don't fingerprint your agent. No captcha gate and no "are you a human" challenge. Automation is a supported use case here, not an exception, so there is no automation clause in the ToS. What an agent can do is set by your plan, the same as for any other client.
Real mailboxes on real domains with SPF, DKIM and DMARC in place, so the verification mail your agent is waiting for arrives instead of bouncing.
Old messages clear themselves every two hours, so your agent's email tool returns recent, relevant mail only, not a 10,000-line wall stuffed into its context window.
Official clients for the runtimes agents actually use. Same API underneath, same inbox.
npm i @mailflat/sdkWhether you're clicking through a web UI or curling the API, you're hitting the same encrypted inbox under the hood.
mailflat.net. Your inbox is already waiting.
x7k2m@mailflat.net, one tap to clipboard.
Newsletter signup, free trial, app download.
Two hours later every message is wiped. Your address stays.
Free key, scoped to dev / staging / prod.
One call. Unique subdomain. Ready before your next line.
Use the address in your signup flow. Emails arrive in real time.
GET /emails, extract the OTP, assert the outcome.
One agent key, MCP server or SDK. Drop it into GPT, Claude, or LangChain.
mailflat.create(label="research"). Real address, ready in < 80ms.
Agent fills the form, waits for the OTP, parses the magic link, all in one tool call.
Inbox auto-clears after 2h. No cleanup logic, no 10k-line context pollution.
Add one TXT record and we confirm SPF & DKIM.
billing@acme.com. Random or named, on the fly.
Same encrypted inbox under the hood, your branding on top.
Auto-clear like the rest, or keep an address forever. Your call.
Zero-knowledge isn't a marketing line. It's the architecture. Your inbox key is generated and held only in your browser (or your CI runner). Without it, what's on our disk is encrypted noise. Even subpoenaed, there's nothing to hand over but ciphertext.
Run inboxes on a domain you own, so the address your customers and your test suites see is yours. Connect the domain in seconds, verify your DNS records, and start receiving mail directly on your domain prefixes or sending DKIM-signed email from your code.
DNS records correctly configured. DKIM signatures are active for all outbound mail sent from this domain.
| Type | Host | Value | Status |
|---|---|---|---|
| MX | @ | mail.mailflat.net. (Priority: 10) | ✓ Active |
| TXT | @ | v=spf1 include:mailflat.net ~all | ✓ Active |
| TXT | mail._domainkey | v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w... | ✓ Active |
Make sure "Proxy status" is set to "DNS only" (grey cloud) for the MX and SPF records to allow direct SMTP mail delivery to MailFlat's servers.
Drag the slider to your monthly email volume (received + sent). The plan that fits rises to the top; Free covers everyday inboxes, Pro grows with you, and we'll talk for anything over 500k.
Everything, scaled to 10,000 emails / month.
Volume is total emails per month: received + sent. One plan, every surface: web inbox, agent keys, and test environment share the same allowance.
Plenty of disposable-email and email-testing services exist. Here's where MailFlat lines up, and where it doesn't. We named the alternatives on purpose; it's the comparison we'd want to see.
M MailFlat real receive · e2e · agents | Mailtrap captured in sandbox | Mailosaur QA-only · enterprise | 10minutemail disposable · burner | Gmail +alias real mail · no privacy | |
|---|---|---|---|---|---|
Real SMTP receipt Mail actually lands in a real mailbox, not a sandbox. | —sandbox only | ~often blocked | |||
Inboxes included How many addresses you can keep permanently. | 3 free / unl. paid | ~1 per project | |||
Auto-purge by design Messages clear themselves on a timer, nothing accumulates. | 2h → 30d | — | — | 10 min | — |
End-to-end encrypted Server holds ciphertext only. We can't read your mail. | — | — | — | — | |
API + SDKs for tests Create, list, read, delete inboxes from code. | — | — | |||
AI agent tooling MCP server + tool spec for GPT / Claude / LangChain. | MCP + tool spec | — | — | — | — |
Verification mail arrives Real mailboxes on real, authenticated domains, so signup mail is delivered. | · | —blocklisted | |||
Custom domain Use your own brand on the inbox addresses. | free plan too | — | · | ||
Free tier with real limits Usable without paying, not a 7-day trial in disguise. | 2,500 mails / mo | ~100/mo | ~14-day trial |
Don't see yours? Email hi@mailflat.net and a human replies, usually within a day.
Open the page and start typing, curl the API and start scripting, or hand the key to your agent. Same encrypted backend, same free tier, same zero setup.