Lock down outbound agent email to strictly approved recipient domain allowlists
Prevent prompt injection attacks from turning your autonomous AI agent into a data exfiltration pipeline. Enforce strict wildcard domain patterns and address lists directly at the API edge.
Drop into your application in under 60 seconds
Native typed interfaces with zero unnecessary dependencies. Built for standard fetch and modern edge runtimes.
import { SadaSend } from 'sadasend';
// Initialize with a restricted staging or internal agent key
// Key Policy in SadaSend Dashboard:
// - Allowed: "*@company.com", "*@partners.internal"
// - Blocked: All external public domains
const sadasend = new SadaSend(process.env.SADASEND_INTERNAL_AGENT_KEY!);
export async function forwardSummaryToTeam(teamMemberEmail: string, summary: string) {
// Dispatches to team members succeed seamlessly
// Dispatches to external unauthorized addresses fail at edge with HTTP 403
return await sadasend.emails.send({
from: 'ai-digest@company.com',
to: teamMemberEmail,
subject: 'Daily Executive Intelligence Summary',
html: `<p>${summary}</p>`,
tags: ['ai-agent', 'internal-digest']
});
}Engineered for high deliverability and zero incident risk
Every layer from edge connection pooling to per-key rate limits is designed to keep critical transactional dispatches fast, reliable, and contained.
Edge-Level Enforcement
Recipient domain filtering executes at our Anycast edge proxy before message rendering or queueing, ensuring immediate rejection of unauthorized dispatches.
Wildcard Pattern Matching
Support flexible domain rules including exact addresses (ceo@company.com), team domains (*@company.com), and multi-tenant subdomains (*.clients.org).
Prompt Injection Defense
Neutralizes indirect prompt injection attacks where hidden email instructions try to forward confidential summaries to an external adversary.
Separate Staging & Prod Rules
Configure independent allowlists per API key, ensuring staging agents never accidentally contact real production customers during test runs.
SadaSend vs Unrestricted Email Relays
Standard email relays blindly dispatch to whatever address the application provides. SadaSend enforces cryptographically bound recipient boundaries.
| Feature & Capability | SadaSend | Unrestricted Email Relays |
|---|---|---|
| Per-Key Recipient Domain Whitelisting | ||
| Edge 403 Rejection on Violations | ||
| Security Audit Alert on Blocked Send | ||
| Wildcard Subdomain Support |
Start with 3,000 emails every month at zero cost
No artificial paywalls on security. Unlike legacy providers that reserve recipient allowlists or dedicated IP pools for high enterprise tiers, every SadaSend account receives full safety controls from day one.
Everything you need to know about AI agent email allowlist
Clear, transparent answers on deliverability, API authentication, and rate limits.
Related developer guides and architectural tutorials
Explore step-by-step production implementation blueprints, benchmarks, and protocols.
REST API Reference & Endpoints
Complete REST API reference for sending emails, managing API keys, tracking delivery events, and configuring recipient allowlists with low latency.
AI coding agent rules (AGENTS.md, Cursor, Claude)
Setup instructions and rule files for AI coding agents: AGENTS.md, .cursorrules, CLAUDE.md, and hosted MCP configuration.
Prevent Staging Email Leaks: Recipient Allowlist Guide
A single test script or database seed in staging can accidentally blast thousands of fake password resets to real customers. Here is how to engineer zero-leak staging pipelines.
Indirect Prompt Injection Defense in Email: Sanitizing Inbound Content for AI
Inbound emails processed by AI agents can contain hidden jailbreaks designed to hijack tools. Here is how to engineer a multi-layer prompt injection defense pipeline.
Indirect Prompt Injection via Email: Threat Models, Attack Vectors, and Prevention
When an AI agent reads incoming emails and holds a sending key, an attacker can embed invisible instructions. Here is how indirect prompt injection works and how to neutralize it.
How to Safely Let Agents Send Email: Defense-in-Depth for Autonomous Outbound
An engineering guide to defense-in-depth for autonomous email: preventing indirect prompt injection, infinite retry loops, and unverified recipient spam.
What actually happens when you give an AI agent your email API key
Every email MCP server on the market hands your agent the full platform. That is a capability claim with no control story — and it is the reason your engineering lead keeps saying no.