AI agents can browse websites, write code, call APIs and operate business software. But give one an email account, and things can get surprisingly awkward.
Most email infrastructure was built around a fairly basic assumption: somewhere on the other end is a person. That person signs into Gmail or Outlook, reads messages, opens attachments, manages threads and decides what to do next. Agents do not work that way. They need messages exposed as structured data, APIs instead of buttons, webhooks instead of repeatedly checking an inbox, attachments accessible through APIs and permissions that can limit what an individual agent is allowed to see or send.
A small but increasingly visible group of companies is now building around that distinction. AgentMail raised $6 million in March to develop email infrastructure specifically for AI agents. Hostinger introduced Agentic Mail this year with a similar premise. Mailtrap, a company that has spent years building email infrastructure for developers, is extending its platform in the same direction with agent inboxes, APIs and MCP integrations.
What looks at first like a niche email feature may be the beginning of another layer in the agentic software stack.
The Agent Has Tools. Its Inbox Is Still Built for You
Developers have found plenty of ways to connect agents to email already. Gmail APIs, OAuth, IMAP, SMTP, forwarding rules and shared mailboxes can all be made to work. The problem is that they often require translating infrastructure designed for humans into workflows designed for software.
“When people started looking for ways for AI agents to talk to each other, email turned out to be a surprisingly good fit. Give each agent an address, and they can communicate quickly using a tool that already works everywhere,” said Julia Romanenkova, Product Lead at Mailtrap.
That difference is starting to influence the architecture of email products built for agents. Hostinger’s Agentic Mail exposes mailboxes through REST APIs and sends events through webhooks when messages arrive. AgentMail provides inboxes that agents can create and operate through APIs, including support for threading, parsing, labels, search and replies.
AgentMail raised a $6 million seed round led by General Catalyst in March. CEO Haakam Aujla told TechCrunch that the idea was essentially to provide agents with the functionality people expect from Gmail or Outlook without requiring the agent to operate a human interface.
But there may be a bigger reason email is attracting attention from AI infrastructure companies. An email address is already accepted almost everywhere on the internet. It receives account notifications, customer requests, invoices, password resets, alerts, documents, scheduling messages and software-generated events. It also frequently serves as an identity layer for online services.
“Inbound email used to be mostly about automating human-to-business communication,” Romanenkova said. With AI agents, it’s getting a second life: email is a natural way for agents to receive information and act on it.”
Giving an agent an inbox, therefore, gives it a bridge into an enormous amount of existing infrastructure without requiring every SaaS vendor, supplier or customer to build a dedicated agent interface. That helps explain why email is suddenly becoming interesting again.
When the Mailbox User Is Software
An agent-native inbox does not necessarily have to look much like an inbox at all. Consider a customer support agent. A customer sends an email with a PDF attached. Instead of a worker opening the message, downloading the attachment and copying information into another system, an incoming-mail event can be sent directly to the agent. The email can already be parsed into fields, while the attachment can be passed to another tool for processing.
The agent might classify the request, search an internal knowledge base, draft a response and update the ticketing system. Depending on the permissions it has been given, it could either send the reply automatically or hand it to a person for approval. The same architecture could handle invoices, appointment requests, sales inquiries, system alerts or developer notifications.
At that point, email stops being merely something an agent reads, and the inbox becomes part of the workflow. A message can trigger an accounting process, create a GitHub issue, schedule a meeting, update a CRM record or launch another agent.
“The really interesting part starts when agents are allowed to reply. If an agent is sending email from your business address, you need to be very clear about what it can and cannot do, “ said Romanenkova.
That is a fairly substantial change in what developers expect from email infrastructure. The inbox becomes less of a destination and more of an input into an automated system.
Mailtrap Is Turning Inbound Email Into an Agent Interface
The market is beginning to converge around a common set of requirements for agent email: programmatic inbox creation, structured message parsing, real-time event delivery, attachment access, thread-aware replies and controls that isolate individual agents or workflows. Mailtrap is growing into that market from an established base in developer-focused email infrastructure, adapting capabilities already used to test and deliver email for a new class of software-operated inboxes.
Its Agent Inbox lets developers create dedicated inboxes for agents or workflows, receive parsed messages through REST APIs and webhooks, access bodies, headers and attachments as structured data, and reply programmatically within the same thread. Mailtrap also exposes email functions through Model Context Protocol integrations for compatible AI clients and development environments, allowing email to operate as another tool in an agent’s workflow rather than as a screen somebody must monitor.
Permissions Matter More When Nobody Is Reading the Screen
There is an obvious complication. Giving an autonomous system an email account potentially gives it access to a large amount of sensitive information and a communications channel capable of reaching people outside the organisation. That makes permissions unusually important.
A human employee using a company inbox normally operates inside layers of organisational controls. An agent needs equivalent boundaries implemented in software.
“The possibilities for AI agents using inbound email are almost endless: from processing incoming requests and replying to customers to much more complex workflows where agents communicate with each other over email,” added Romanenkova.
You can separate dedicated agent inboxes by agent, project or workflow, and assign different permissions depending on which inboxes or folders each agent needs to access. While fine-tuning the workflow, developers can also route agent-generated emails to Mailtrap’s Email Sandbox, where they can review the output before allowing messages to reach real recipients.
AgentMail takes a similar approach with permissions, allowlists and separate API keys, while Hostinger’s Agentic Mail includes allow and block lists along with mailbox-level controls designed around automated clients.
These controls will probably become more important as agents gain greater autonomy. An agent that can read every company’s mailbox and email anyone on the internet is very different from one that can access a dedicated support inbox and respond only within a defined workflow.
Testing may become particularly important because an autonomous agent can make mistakes at machine speed. A poorly configured human mailbox creates one kind of risk. Software capable of interpreting incoming messages, taking actions and automatically sending responses creates another.
The security question, therefore, is not simply whether an agent can use email. It is which email it can access, which recipients it can contact, which actions it can perform, and under whose authority.
Email Has Something New Protocols Do Not
There are plenty of attempts underway to create new ways for agents to communicate with software and with one another. Some will undoubtedly succeed. Email, however, has one enormous advantage over all of them: deployment happened decades ago.
Nearly every business already has it. Customers understand it. SaaS platforms generate it. Vendors accept it. Governments use it. Account systems recognise it. There is also no requirement for the other side of the interaction to know that an agent is involved.
An AI purchasing agent does not necessarily need a supplier to expose an agent-specific protocol if the supplier already accepts purchase orders by email. A scheduling agent does not need every doctor’s office to deploy an MCP server if appointment requests can already arrive through an inbox.
That makes email an unusually practical compatibility layer between autonomous software and an internet still largely designed around humans.
AgentMail appears to see that opportunity particularly clearly. Aujla has argued that email could ultimately function as an identity layer for agents because so much of the internet already recognises an email address.
The idea raises an interesting possibility. The infrastructure agents need may not always require inventing something new. Sometimes, the larger opportunity is making an old protocol usable by machines.
The Next Question Is What Becomes Standard
It is too early to know whether “agent email” ultimately becomes a distinct software category or simply a set of capabilities incorporated into existing email platforms. But the pieces are starting to look consistent: programmatic inbox creation, structured message parsing, webhooks, attachment handling, thread-aware replies, agent-specific credentials, fine-grained permissions, MCP connectivity, sandboxes and observability.
Those are not features people normally consider when choosing a personal mailbox. They make considerably more sense when the mailbox user is software.
AgentMail’s funding, Hostinger’s Agentic Mail launch and Mailtrap’s expansion into agent inboxes are three different bets on the same underlying change: agents are beginning to interact with the outside world continuously rather than only while somebody is chatting with them.
Once that happens, the communication infrastructure becomes part of the agent infrastructure. And one of the oldest protocols on the internet may end up being one of the most useful.
Community Discussion
Join the conversation. Ask questions, share solutions, and help others.
Be the first to start the discussion!
