Skip to content
Exfiltration & Blast Radius DefenseZero-Trust Domain Control

Lock down outbound agent email to strictly approved recipient domain allowlists

Prevent prompt injection attacks from turning your autonomous AI agent into a data exfiltration pipeline. Enforce strict wildcard domain patterns and address lists directly at the API edge.

3,000 emails/month freeZero credit card requiredSub-20ms edge latency
Pre-flight
Edge Filter Latency
Allowlist checked before the message is accepted
6,000
Free Monthly Sends
Forever free quota
100%
Leakage Prevention
Fails closed by default
Developer Ergonomics

Drop into your application in under 60 seconds

Native typed interfaces with zero unnecessary dependencies. Built for standard fetch and modern edge runtimes.

$npm install sadasend
allowlist-agent.ts
typescript
TYPESCRIPT
import { SadaSend } from 'sadasend';

// Initialize with a restricted staging or internal agent key
// Key Policy in SadaSend Dashboard:
// - Allowed: "*@company.com", "*@partners.internal"
// - Blocked: All external public domains
const sadasend = new SadaSend(process.env.SADASEND_INTERNAL_AGENT_KEY!);

export async function forwardSummaryToTeam(teamMemberEmail: string, summary: string) {
  // Dispatches to team members succeed seamlessly
  // Dispatches to external unauthorized addresses fail at edge with HTTP 403
  return await sadasend.emails.send({
    from: 'ai-digest@company.com',
    to: teamMemberEmail,
    subject: 'Daily Executive Intelligence Summary',
    html: `<p>${summary}</p>`,
    tags: ['ai-agent', 'internal-digest']
  });
}
Core Infrastructure

Engineered for high deliverability and zero incident risk

Every layer from edge connection pooling to per-key rate limits is designed to keep critical transactional dispatches fast, reliable, and contained.

Edge-Level Enforcement

Recipient domain filtering executes at our Anycast edge proxy before message rendering or queueing, ensuring immediate rejection of unauthorized dispatches.

Wildcard Pattern Matching

Support flexible domain rules including exact addresses (ceo@company.com), team domains (*@company.com), and multi-tenant subdomains (*.clients.org).

Prompt Injection Defense

Neutralizes indirect prompt injection attacks where hidden email instructions try to forward confidential summaries to an external adversary.

Separate Staging & Prod Rules

Configure independent allowlists per API key, ensuring staging agents never accidentally contact real production customers during test runs.

Architectural Comparison

SadaSend vs Unrestricted Email Relays

Standard email relays blindly dispatch to whatever address the application provides. SadaSend enforces cryptographically bound recipient boundaries.

Feature & CapabilitySadaSendUnrestricted Email Relays
Per-Key Recipient Domain Whitelisting
Edge 403 Rejection on Violations
Security Audit Alert on Blocked Send
Wildcard Subdomain Support
Forever Free Tier
Transparent Economics

Start with 3,000 emails every month at zero cost

No artificial paywalls on security. Unlike legacy providers that reserve recipient allowlists or dedicated IP pools for high enterprise tiers, every SadaSend account receives full safety controls from day one.

3,000 dispatches monthly forever with zero credit card
All safety gates, allowlists, and velocity limits included
Scale seamlessly: Starter ($12/mo for 10k), Pro ($19/mo for 50k), Scale ($79/mo for 250k)
Free Developer Plan
$0 / mo

No credit card required

Create Free AccountCompare all paid plan tiers
Frequently Asked Questions

Everything you need to know about AI agent email allowlist

Clear, transparent answers on deliverability, API authentication, and rate limits.

The API immediately rejects the request with HTTP 403 Forbidden and error code recipient_not_allowlisted. The email is never sent, zero quota is consumed, and the security anomaly is logged.
Technical Deep Dives

Related developer guides and architectural tutorials

Explore step-by-step production implementation blueprints, benchmarks, and protocols.

Documentation

REST API Reference & Endpoints

Complete REST API reference for sending emails, managing API keys, tracking delivery events, and configuring recipient allowlists with low latency.

Read guide
Documentation

AI coding agent rules (AGENTS.md, Cursor, Claude)

Setup instructions and rule files for AI coding agents: AGENTS.md, .cursorrules, CLAUDE.md, and hosted MCP configuration.

Read guide
Deep Dive4 min read

Prevent Staging Email Leaks: Recipient Allowlist Guide

A single test script or database seed in staging can accidentally blast thousands of fake password resets to real customers. Here is how to engineer zero-leak staging pipelines.

Read tutorial
Deep Dive5 min read

Indirect Prompt Injection Defense in Email: Sanitizing Inbound Content for AI

Inbound emails processed by AI agents can contain hidden jailbreaks designed to hijack tools. Here is how to engineer a multi-layer prompt injection defense pipeline.

Read tutorial
Deep Dive3 min read

Indirect Prompt Injection via Email: Threat Models, Attack Vectors, and Prevention

When an AI agent reads incoming emails and holds a sending key, an attacker can embed invisible instructions. Here is how indirect prompt injection works and how to neutralize it.

Read tutorial
Deep Dive3 min read

How to Safely Let Agents Send Email: Defense-in-Depth for Autonomous Outbound

An engineering guide to defense-in-depth for autonomous email: preventing indirect prompt injection, infinite retry loops, and unverified recipient spam.

Read tutorial
Deep Dive5 min read

What actually happens when you give an AI agent your email API key

Every email MCP server on the market hands your agent the full platform. That is a capability claim with no control story — and it is the reason your engineering lead keeps saying no.

Read tutorial