Skip to content
AI Agent & LLM Workflow ToolingOpenAPI 3.0 & Custom Tool

Safe transactional email tooling for Dify conversational agents

Empower Dify LLM workflows to send transactional notifications without risking prompt injection leaks. Built-in recipient allowlists, velocity tripwires, and approval gates.

3,000 emails/month freeZero credit card requiredSub-20ms edge latency
100% Server-Side
Guardrail Enforcement
Zero bypass by prompt manipulation
202 Accepted
Dispatch Latency
Queued durably before any provider call
6,000 / mo
Free Monthly Sends
Includes all safety tools
Developer Ergonomics

Drop into your application in under 60 seconds

Native typed interfaces with zero unnecessary dependencies. Built for standard fetch and modern edge runtimes.

$Dify Studio -> Tools -> Custom Tool -> Import OpenAPI
dify-sadasend-tool.yaml
yaml
YAML
openapi: 3.0.0
info:
  title: SadaSend Email Tool for Dify
  version: 1.0.0
servers:
  - url: https://api.sadasend.com
paths:
  /emails:
    post:
      summary: Send a safe transactional email
      operationId: sendEmail
      parameters:
        - name: Authorization
          in: header
          required: true
          schema:
            type: string
            example: Bearer ss_live_your_scoped_agent_key
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required: [from, to, subject, html]
              properties:
                from:
                  type: string
                  example: agent@yourdomain.com
                to:
                  type: string
                  example: user@company.com
                subject:
                  type: string
                  example: "Summary: Weekly Project Report"
                html:
                  type: string
                  example: "<p>Here is your weekly summary...</p>"

Import this OpenAPI 3.0 definition directly into Dify Custom Tools. Enable agents to dispatch emails while SadaSend server-side guardrails enforce recipient boundaries.

Core Infrastructure

Engineered for high deliverability and zero incident risk

Every layer from edge connection pooling to per-key rate limits is designed to keep critical transactional dispatches fast, reliable, and contained.

Prompt Injection Containment

Server-side recipient allowlists reject dispatches to unauthorized external addresses even if the LLM is hijacked by an injection attack.

Velocity Circuit Breakers

Stops recursive LLM loops and runaway agents by tripping automated rate ceilings before your domain reputation or wallet is impacted.

Native Human Approval Mode

Configure sensitive agent actions to require explicit human sign-off in the dashboard or via webhook before actual SMTP delivery.

Zero SDK Overhead in Dify

Connects seamlessly via native Dify OpenAPI custom tools with standard bearer authentication and predictable JSON responses.

Cryptographic Audit Trails

Every email dispatched by Dify agents is permanently logged with prompt tags, exact timestamps, and recipient metadata for auditing.

High-Reputation IP Pools

Outbound emails from verified custom domains achieve instant inbox placement with SPF, DKIM, and DMARC alignment.

Architectural Comparison

SadaSend vs Unrestricted LLM SMTP Tools

Compare SadaSend agent guardrails against giving Dify raw SMTP credentials.

Feature & CapabilitySadaSendUnrestricted LLM SMTP Tools
Prompt Injection ContainmentVulnerable to data exfiltration
Server-Side Recipient Allowlists
Loop Prevention Circuit Breaker
Human-in-the-Loop Approval HoldsRequires complex custom code
Instant OpenAPI Tool ImportManual configuration
Developer Free Tier6,000 sends foreverTrial or paywalled
Forever Free Tier
Transparent Economics

Start with 3,000 emails every month at zero cost

No artificial paywalls on security. Unlike legacy providers that reserve recipient allowlists or dedicated IP pools for high enterprise tiers, every SadaSend account receives full safety controls from day one.

3,000 dispatches monthly forever with zero credit card
All safety gates, allowlists, and velocity limits included
Scale seamlessly: Starter ($12/mo for 10k), Pro ($19/mo for 50k), Scale ($79/mo for 250k)
Free Developer Plan
$0 / mo

No credit card required

Create Free AccountCompare all paid plan tiers
Frequently Asked Questions

Everything you need to know about Dify email

Clear, transparent answers on deliverability, API authentication, and rate limits.

In Dify Studio, navigate to Tools -> Custom Tool, click "Import OpenAPI", paste our OpenAPI YAML specification, and set your Authorization header with your SadaSend API key.
Technical Deep Dives

Related developer guides and architectural tutorials

Explore step-by-step production implementation blueprints, benchmarks, and protocols.

Documentation

Model Context Protocol (MCP) Server

Connect AI agents directly to SadaSend via Model Context Protocol (MCP). Inspect tools, configure execution scopes, and enable human approval holds.

Read guide
Documentation

AI coding agent rules (AGENTS.md, Cursor, Claude)

Setup instructions and rule files for AI coding agents: AGENTS.md, .cursorrules, CLAUDE.md, and hosted MCP configuration.

Read guide
Documentation

REST API Reference & Endpoints

Complete REST API reference for sending emails, managing API keys, tracking delivery events, and configuring recipient allowlists with low latency.

Read guide
Deep Dive3 min read

Connecting Email Tools to AI Agents in Dify and Flowise with SadaSend

Giving visual AI agents unrestricted email access is an existential security risk. Here is how to connect SadaSend to Dify and Flowise with hardware-grade safety ceilings.

Read tutorial
Deep Dive5 min read

What actually happens when you give an AI agent your email API key

Every email MCP server on the market hands your agent the full platform. That is a capability claim with no control story — and it is the reason your engineering lead keeps saying no.

Read tutorial
Deep Dive3 min read

How to Safely Let Agents Send Email: Defense-in-Depth for Autonomous Outbound

An engineering guide to defense-in-depth for autonomous email: preventing indirect prompt injection, infinite retry loops, and unverified recipient spam.

Read tutorial
Deep Dive3 min read

LangChain Email Tool Calling: Safe Integration with Recipient Allowlists

Connecting LangChain agents to raw SMTP credentials risks uncontrolled outbound email. Here is the architectural guide to building safe email tools using Pydantic schemas and scoped credentials.

Read tutorial
Deep Dive5 min read

Indirect Prompt Injection Defense in Email: Sanitizing Inbound Content for AI

Inbound emails processed by AI agents can contain hidden jailbreaks designed to hijack tools. Here is how to engineer a multi-layer prompt injection defense pipeline.

Read tutorial