Let an AI agent run cold email infrastructure via MCP
Connect Claude or Cursor to EmailPal with npx -y @emailpal/mcp: 75 tools for domains, mailboxes, warming, verification and campaigns, with a read-only mode.
The short answer
The EmailPal MCP server gives an AI agent 75 tools to provision and manage cold email infrastructure: domains, pre-warmed inboxes, mailboxes, warming, the inbox, list verification, campaigns and the CRM. You add one config block that runs npx -y @emailpal/mcp with an API key, in Cursor or Claude Desktop. It runs locally on your machine, there is no hosted endpoint, and setting EMAILPAL_MCP_READ_ONLY=true removes every tool that writes.
Create an API key, paste a six-line JSON block into your client, and the agent can search and buy domains, create mailboxes, turn warming on, verify lists and launch campaigns through the same REST API you would use by hand. Every tool is one API call, so plan limits, scopes, billing and the hourly request budget (1,000 on every current plan) all apply. Start with a read key or read-only mode. Tools that spend money, send mail or cannot be undone are marked destructive, but whether you are asked to confirm depends on your MCP client, not on EmailPal.
How it works, step by step
Step 1
Create an API key with the narrowest scope that works
Open API keys in the dashboard and create a key. Read lets the agent inspect domains, warming, campaigns and replies and cannot change or spend anything. Write lets it create and change things, including buying domains and launching campaigns. Admin adds exporting mailbox passwords and topping up the domain balance. The secret starts with ep_live_ and is shown once.
Step 2
Add the server to Cursor or Claude Desktop
In Cursor, put the block in .cursor/mcp.json or Settings, MCP. In Claude Desktop, put the same block in claude_desktop_config.json. The API keys page in the dashboard can copy this block with your key already in it.
.cursor/mcp.json or claude_desktop_config.jsonjson{ "mcpServers": { "emailpal": { "command": "npx", "args": ["-y", "@emailpal/mcp"], "env": { "EMAILPAL_API_KEY": "ep_live_..." } } } }Step 3
Turn on read-only mode for the first session
Add EMAILPAL_MCP_READ_ONLY set to true to the env block, or pass --read-only as an argument. Every tool that writes disappears from the tool list and only the inspection tools remain.
Read-only configjson{ "mcpServers": { "emailpal": { "command": "npx", "args": ["-y", "@emailpal/mcp"], "env": { "EMAILPAL_API_KEY": "ep_live_...", "EMAILPAL_MCP_READ_ONLY": "true" } } } }Step 4
Ask the agent to start with get_account
emailpal_get_account returns the plan, what has been used against the limits, the monthly warming cost and the prepaid domain balance in one call. Asking it to check before creating anything avoids a failed batch.
Step 5
Remove read-only and widen the key only when the agent should act
To let it provision, swap in a write key and drop the read-only flag. Keep an admin key out of the config unless the agent really needs to export credentials or top up the balance.
Step 6
Have it poll jobs instead of assuming success
Most writes return a job_id because they involve a registrar, public DNS or a mail server. The agent should call emailpal_get_job until terminal is true, and emailpal_list_jobs with status failed to answer whether anything went wrong.
01
The 75 tools, by area
Tool names are prefixed emailpal_, for example emailpal_create_mailboxes, so they do not collide with another server’s list_domains. The count is 75: 35 for infrastructure and compliance, and 40 for campaigns, leads, the CRM and replies.
Account (2): get_account, top_up_balance. Domains (10): list_domains, get_domain, search_domains, purchase_domains, connect_domains, verify_dns, rotate_dkim, set_domain_redirect, clear_domain_redirect, release_domain. Pre-warmed (2): browse_prewarmed, lease_prewarmed. Mailboxes (6): list_mailboxes, get_mailbox, create_mailboxes, update_mailbox, delete_mailbox, export_mailboxes. Warming (2): get_warming, set_warming. Inbox (6): list_inbox, get_message, send_email, mark_message, delete_message, refresh_inbox. Compliance (4): verify_list, get_list, list_suppressions, suppress. Jobs (3): list_jobs, get_job, retry_job.
Campaigns (11): list_campaigns, get_campaign, create_campaign, update_campaign, delete_campaign, duplicate_campaign, campaign_preflight, launch_campaign, pause_campaign, resume_campaign, get_campaign_analytics. Campaign leads (3): list_campaign_leads, add_campaign_leads, manage_campaign_leads. Sequences (8): list_campaign_steps, add_campaign_step, update_campaign_step, delete_campaign_step, reorder_campaign_steps, add_step_variant, update_step_variant, delete_step_variant. Leads (8): list_leads, get_lead, create_lead, update_lead, set_lead_status, add_lead_note, list_lead_statuses, list_lead_lists. Pipeline (5): list_pipelines, list_opportunities, create_opportunity, update_opportunity, move_opportunity. Tasks (3): list_tasks, create_task, update_task. Replies (2): list_replies, label_reply.
02
Which tools cost money, send mail or cannot be undone
These tools spend money: purchase_domains takes the whole batch off the prepaid domain balance up front and a registration cannot be undone; lease_prewarmed charges $3/mo per inbox with a 90-day minimum; create_mailboxes bills mailboxes beyond the plan allowance at $1/mo each and starts warming at $0.60 per inbox per month; set_warming with enable adds the same warming charge. In set_warming, disable stops the charge but pause keeps billing. verify_list uses one verification credit per address from the daily allowance included in the plan.
These tools send mail or destroy something: send_email, launch_campaign and resume_campaign put real email on the wire; release_domain is irreversible and not refunded; delete_mailbox discards warming history; delete_message deletes from the mail server; suppress is permanent and platform-wide; delete_campaign and the step deletes cannot be undone. top_up_balance charges nothing itself: it returns a payment URL that you open and pay, needs an admin key, and accepts $20 to $5,000.
purchase_domains, lease_prewarmed, release_domain, delete_mailbox, send_email, delete_message, suppress, delete_campaign, launch_campaign and resume_campaign are annotated destructive. create_mailboxes and set_warming are not, even though they add recurring charges, so do not rely on the annotation alone to catch spend.
03
Read-only mode, key scope and what each one enforces
EMAILPAL_MCP_READ_ONLY=true is applied inside the MCP process: any tool flagged as mutating is never registered, so the agent cannot call it. Key scope is applied by the API, and it is the boundary that holds if the process is misconfigured. Use both. A read key with read-only mode lets an agent report on warming, DNS, campaign results and replies and nothing else.
export_mailboxes is not flagged as mutating, so it remains in the tool list in read-only mode. It returns plaintext SMTP and IMAP passwords as CSV, and the API only allows it with an admin key, so a read or write key gets a 403. Do not put an admin key in a config you share.
verify_list is flagged as mutating, because it submits a list and takes credits, so it is hidden in read-only mode and needs a write key.
04
Example prompts
Check capacity: "Call get_account and tell me how many mailboxes and domain slots I have left, what warming costs per month, and my domain balance. Do not create anything."
Audit health: "List mailboxes with status failed or paused, check warming for the last 14 days, and list failed jobs. Summarise what needs attention."
Provision: "Search for five available domains from the seed northworks, show me prices and stop. After I confirm, buy the ones I pick, wait for them to be ready, and create three mailboxes on each with the first.last pattern."
Triage replies: "List replies from the last three days and label the ones that ask for a meeting. Do not send anything."
The server also tells the model to confirm before spending money or sending, and never to launch a campaign on its own initiative. That is guidance in the model’s instructions, not an enforced gate.
05
Where it runs and what it is not
The server is a local process that your MCP client starts. It holds no credentials of its own and has no database access. It is a thin wrapper over the public REST API, using your key, so the plan limits, scopes and rate limits apply as they would to any other integration. EmailPal does not host an MCP endpoint; the API key goes in the config you control.
For a remote agent or a container that cannot spawn a process, the package has an optional HTTP mode: set EMAILPAL_MCP_PORT, or pass --http, and it serves streamable HTTP on loopback (for example http://127.0.0.1:8765/mcp with the port set to 8765) for you to host and secure yourself. It takes the API key from each request’s Authorization: Bearer header, binds to loopback, and if you put it behind a proxy you should terminate TLS there and leave EMAILPAL_API_KEY unset.
MCP drives EmailPal itself: provisioning, warming, verification, campaigns and replies. It does not operate another vendor’s campaign interface. If you send from Smartlead or Instantly, an agent can still provision the mailboxes and export credentials in their format.
06
What the Terms allow
Section 9 of the Terms (effective 6 October 2026) allows you to embed list verification and mailbox and domain provisioning in your own product or service and supply them to your own end customers through the REST API or MCP server, under your own account and your own name. You remain responsible for those end users’ compliance with the acceptable use policy, and keys must not be shared between organisations. White-labelling the Service or using the EmailPal brand as your own needs written agreement.
Limits, prices and names, in one table
The figures this page relies on, so you do not have to hunt for them.
| Tools | 7535 infrastructure and compliance, 40 campaigns, leads, CRM and replies |
| Install command | npx -y @emailpal/mcpEMAILPAL_API_KEY in the env block |
| Read-only switch | EMAILPAL_MCP_READ_ONLY=trueOr --read-only; hides every mutating tool |
| Key scopes | read, write, adminAdmin exports mailbox passwords and tops up the balance |
| API base URL default | https://www.emailpal.ioEMAILPAL_API_URL; use the www host |
| Request timeout default | 60,000 msEMAILPAL_MCP_TIMEOUT_MS; list verification queues, so it does not block |
| Hourly API budget | 1,000 requestsEvery current plan; each tool call is one API call |
| Starter plan | $69/mo50 mailboxes, 50 domain slots, 500 verification checks a day |
| Extra mailbox / warming | $1/mo / $0.60 per inbox per month |
| Pre-warmed lease | $3/mo per inbox90-day minimum |
| Hosted MCP endpoint | NoneRuns locally; optional loopback HTTP mode you host yourself |
Checked against the product and the API on . Plans and limits change, so confirm in the docs before you build on them.
This is not for you if
- You want a hosted MCP URL you can add to a client without installing anything. EmailPal has no hosted MCP endpoint; the server runs locally with npx.
- You rely on your MCP client to stop the agent before it spends money. Destructive tools are annotated, but a client that does not ask for confirmation will not, and create_mailboxes and set_warming carry recurring charges without the annotation. Use a read key or read-only mode instead.
- You want the agent to find leads. There is no built-in lead database; leads come from your own files, and the verification tools check addresses you already have.
- You want the agent to connect Google Workspace or Microsoft 365 mailboxes. EmailPal has no OAuth sign-in to those mailboxes; it provisions its own SMTP and IMAP mailboxes.
- You want the agent to operate Smartlead, Instantly or another sequencer. MCP drives EmailPal only.
Common questions
How do I install the EmailPal MCP server?
Add a server named emailpal to your client config with command npx, args -y and @emailpal/mcp, and an env value EMAILPAL_API_KEY set to your ep_live_ key. In Cursor the file is .cursor/mcp.json and in Claude Desktop it is claude_desktop_config.json. The dashboard’s API keys page generates the block with your key in it.
Is there a hosted MCP server I can connect to by URL?
No. The server runs locally on your machine and calls the EmailPal REST API with your key. The package has an optional HTTP mode that binds to 127.0.0.1 for remote agents or containers, but you run and secure that process yourself. EmailPal does not operate an MCP endpoint.
What does read-only mode hide?
Setting EMAILPAL_MCP_READ_ONLY=true, or passing --read-only, removes every tool flagged as mutating from the tool list, including purchase_domains, create_mailboxes, send_email, launch_campaign and verify_list. The inspection tools stay, such as get_account, list_domains, get_warming and list_replies. export_mailboxes is not flagged as mutating, so it stays listed, but it only works with an admin key.
Which MCP tools charge money?
purchase_domains charges the prepaid domain balance, lease_prewarmed charges $3/mo per inbox, create_mailboxes bills overage at $1/mo per mailbox beyond the plan allowance and starts warming at $0.60 per inbox, and set_warming enable adds the warming charge. top_up_balance charges nothing itself; it returns a payment link. EmailPal does not bypass billing for MCP: calls cost what they cost in the dashboard.
Can the agent launch campaigns without asking me?
Only if your key and client allow it. launch_campaign and resume_campaign need a write key, are annotated destructive, and run the same pre-flight as the dashboard button, failing with launch_blocked when something needs fixing. The server instructs the model never to launch on its own initiative, but that is guidance. A read key or read-only mode makes launching impossible.
How many tools does the MCP server have?
Seventy-five. Thirty-five cover account, domains, pre-warmed inboxes, mailboxes, warming, the inbox, compliance and jobs. Forty cover campaigns, sequences, leads, the pipeline, tasks and replies. All names are prefixed emailpal_.
Build it on infrastructure that holds up
Domains, mailboxes, warming and verification over one REST API and MCP server, with the sequencer, Unibox and CRM on every plan.
No card to start — cancel any time.