Why specialized .cursorrules matter for autonomous email systems
When generating code with Cursor Composer or Windsurf Cascade, AI models frequently suggest deprecated libraries (such as unmaintained Nodemailer transports without TLS verification), omit idempotency keys, or hardcode root API credentials directly into tool functions.
By providing a project-specific .cursorrules or .windsurfrules file in your repository root, you force the LLM to adhere to strict TypeScript interfaces, Zod schema validation, and SadaSend hardware-enforced containment boundaries.
| Engineering Pattern | Default AI Generation | Enforced by SadaSend .cursorrules |
|---|---|---|
| Transport Protocol | Legacy SMTP or heavy polyfill packages | Native zero-dependency fetch or sadasend |
| Idempotency | Omitted (duplicate sends on timeout) | Mandatory Idempotency-Key header on every POST |
| Tool Argument Validation | Loose string parameters | Strict Zod / Pydantic schemas with domain regex |
| Deliverability Compliance | Missing headers | Automated RFC 8058 List-Unsubscribe injection |
| Credential Scope | Root admin API keys | Scoped agent keys with recipient domain allowlists |
Production .cursorrules configuration template
Place this .cursorrules file in your project root to align AI code completions with production email infrastructure standards:
# SadaSend Email Engineering Rules for Cursor & Windsurf
You are an expert email infrastructure and TypeScript engineer.
When generating email sending code, background jobs, or AI agent tools:
1. API Client Standards:
- Always use native `fetch` or `sadasend` with strict TypeScript types.
- Enforce cryptographic idempotency keys on every outbound send (`Idempotency-Key: <uuid>`).
- Wrap all API requests with explicit error handling for 403 (Allowlist Denied) and 429 (Rate Limited).
2. Security & Guardrails:
- Never hardcode API keys or secret tokens. Access via `process.env.SADASEND_AGENT_KEY`.
- Ensure all email tools validate recipient input with Zod or Pydantic before network dispatch.
- Enforce the Human-in-the-Loop pattern: isolate drafting logic from execution logic.
3. Deliverability Compliance:
- When generating marketing or digest emails, always include `List-Unsubscribe` and `List-Unsubscribe-Post` headers (RFC 8058).
- Ensure multipart alternative plain-text bodies are generated alongside HTML bodies.Windsurf Cascade configuration (.windsurfrules)
For Windsurf users, duplicate the instructions into a .windsurfrules file in the workspace root. Windsurf’s Cascade engine respects markdown rule files and will enforce typed parameter schemas during multi-file agent workflows.
// Example type-safe tool generated by Cursor following the rules:
import { z } from 'zod';
export const SendEmailToolSchema = z.object({
to: z.string().email(),
subject: z.string().min(5).max(100),
html: z.string().min(10),
text: z.string().min(10),
});
export async function executeSendEmail(input: z.infer<typeof SendEmailToolSchema>) {
const res = await fetch('https://api.sadasend.com/emails', {
method: 'POST',
headers: {
'Authorization': `Bearer ${process.env.SADASEND_AGENT_KEY}`,
'Content-Type': 'application/json',
'Idempotency-Key': crypto.randomUUID(),
},
body: JSON.stringify(input),
});
return res.json();
}Automated verification & testing workflow in IDE
With these rules committed to your repository, your team can prompt the IDE to build end-to-end email pipelines, and the generated code will pass TypeScript compiler checks and pre-flight security audits on the first attempt.
Building AI agents that send email?
Scoped API keys, per-key recipient allowlists, approval mode and a hosted MCP server with ten tools — on the free plan, without a card.