Skip to content
Writing
NewCursorWindsurfDevToolsTypeScriptPrompt Engineering

Cursor and Windsurf Rules for AI Email Agent Development (.cursorrules Guide)

Supercharge your AI-assisted development workflow with battle-tested Cursor and Windsurf rules tailored for transactional email and MCP integrations.

Why specialized .cursorrules matter for autonomous email systems

When generating code with Cursor Composer or Windsurf Cascade, AI models frequently suggest deprecated libraries (such as unmaintained Nodemailer transports without TLS verification), omit idempotency keys, or hardcode root API credentials directly into tool functions.

By providing a project-specific .cursorrules or .windsurfrules file in your repository root, you force the LLM to adhere to strict TypeScript interfaces, Zod schema validation, and SadaSend hardware-enforced containment boundaries.

Engineering PatternDefault AI GenerationEnforced by SadaSend .cursorrules
Transport ProtocolLegacy SMTP or heavy polyfill packagesNative zero-dependency fetch or sadasend
IdempotencyOmitted (duplicate sends on timeout)Mandatory Idempotency-Key header on every POST
Tool Argument ValidationLoose string parametersStrict Zod / Pydantic schemas with domain regex
Deliverability ComplianceMissing headersAutomated RFC 8058 List-Unsubscribe injection
Credential ScopeRoot admin API keysScoped agent keys with recipient domain allowlists

Production .cursorrules configuration template

Place this .cursorrules file in your project root to align AI code completions with production email infrastructure standards:

MARKDOWN
# SadaSend Email Engineering Rules for Cursor & Windsurf

You are an expert email infrastructure and TypeScript engineer.
When generating email sending code, background jobs, or AI agent tools:

1. API Client Standards:
   - Always use native `fetch` or `sadasend` with strict TypeScript types.
   - Enforce cryptographic idempotency keys on every outbound send (`Idempotency-Key: <uuid>`).
   - Wrap all API requests with explicit error handling for 403 (Allowlist Denied) and 429 (Rate Limited).

2. Security & Guardrails:
   - Never hardcode API keys or secret tokens. Access via `process.env.SADASEND_AGENT_KEY`.
   - Ensure all email tools validate recipient input with Zod or Pydantic before network dispatch.
   - Enforce the Human-in-the-Loop pattern: isolate drafting logic from execution logic.

3. Deliverability Compliance:
   - When generating marketing or digest emails, always include `List-Unsubscribe` and `List-Unsubscribe-Post` headers (RFC 8058).
   - Ensure multipart alternative plain-text bodies are generated alongside HTML bodies.

Windsurf Cascade configuration (.windsurfrules)

For Windsurf users, duplicate the instructions into a .windsurfrules file in the workspace root. Windsurf’s Cascade engine respects markdown rule files and will enforce typed parameter schemas during multi-file agent workflows.

TYPESCRIPT
// Example type-safe tool generated by Cursor following the rules:
import { z } from 'zod';

export const SendEmailToolSchema = z.object({
  to: z.string().email(),
  subject: z.string().min(5).max(100),
  html: z.string().min(10),
  text: z.string().min(10),
});

export async function executeSendEmail(input: z.infer<typeof SendEmailToolSchema>) {
  const res = await fetch('https://api.sadasend.com/emails', {
    method: 'POST',
    headers: {
      'Authorization': `Bearer ${process.env.SADASEND_AGENT_KEY}`,
      'Content-Type': 'application/json',
      'Idempotency-Key': crypto.randomUUID(),
    },
    body: JSON.stringify(input),
  });
  return res.json();
}

Automated verification & testing workflow in IDE

With these rules committed to your repository, your team can prompt the IDE to build end-to-end email pipelines, and the generated code will pass TypeScript compiler checks and pre-flight security audits on the first attempt.

Free plan

Building AI agents that send email?

Scoped API keys, per-key recipient allowlists, approval mode and a hosted MCP server with ten tools — on the free plan, without a card.