Posthaste is a transactional email API for developers — password resets, receipts, verification codes. We run our own mail servers, so we sign your email, deliver it straight to the recipient’s server, and hand you every response it gave back.
Ways in
Write code against the API, point an app you already run at SMTP, or give an AI agent an MCP server. Same checks, same signing, same delivery record, whichever you choose.
curl https://api.posthastemail.dev/v1/emails \
-H 'Authorization: Bearer ph_live_...' \
-H 'Content-Type: application/json' \
-d '{
"from": "[email protected]",
"to": "[email protected]",
"subject": "Your receipt",
"text": "Thanks - the receipt is attached."
}'
# 202, and the id you read the delivery record with.DocsSend an emailTypeScript SDKSMTP relayMCP serverNodemailer, Django, Rails, Laravel
Each recipient counts as one send, and the From address must be on a domain you have verified. That second rule is why an agent’s mail is worth trusting: we own the mail servers, so it goes out signed with your own domain key and onto the same tamper-evident record as everything else you send.
How it works
Most providers show you a status. We show you the conversation that produced it.
Unverified domain, suppressed recipient, header injection — refused straight away with a reason, not queued and quietly failed an hour later.
Every message is signed with your own domain key, so receivers can prove it genuinely came from you.
Straight to the recipient's mail server over an encrypted connection. Nobody sits in the middle taking a cut.
Delivered, delayed or refused — you get the receiving server's own words, kept on a record you can verify.
The record
Every message ends in one of four states. Each one is a fact we can show you the evidence for, and the evidence is the receiving server’s own words.
EHLO mta1.posthastemail.dev
250-mx.example-mail.com at your service
MAIL FROM:<bounce+dK4x…@bounce.posthastemail.dev>
250 2.1.0 OK
RCPT TO:<[email protected]>
250 2.1.5 OK
DATA
354 Go ahead
250 2.0.0 OK 1755871333 — accepted for deliveryEach entry carries the fingerprint of the one before it, so editing or removing an event breaks the chain from that point on. You can check it yourself, and what each state means is written out in full.
What you get
Four worth seeing before the list. All of them are shipped, documented and on every plan.
Publish an MX record and claim an address. Mail sent to it reaches your endpoint as a signed webhook. SPF, DKIM, DMARC, spam and antivirus checks are already done by the time you see it, so you can act on the message instead of working out whether to trust it.
Receiving mailQueue a message for later and cancel it any time before it goes. Every check runs again on the day it actually sends, so a message queued last Tuesday cannot slip past a suppression you added on Thursday.
Scheduled sendsA filterable stream of every event, by tag, by stream, by status. It resumes from Last-Event-ID, so if the connection drops you carry on from where you stopped rather than starting again with a gap you cannot see.
Live tailMail a code, then check it back. Attempt caps, expiry, resend throttling and keeping the code out of the subject line are all built. Run out of attempts and the code is burned, so the cap protects the account rather than just counting.
VerifyExpires in 9:422 attempts left
Every line is a link to the page that documents it. Nothing here is on a roadmap.
Pricing
No charge for seats, webhooks, or keeping your own records. Your daily cap starts at 50 and climbs to 100,000 as your sending stays clean.
Compare all plansFree for 750 emails a month, which is enough to prove it works. One DNS record to set up. No card needed.
Start sending free