{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "mailtrap",
    "name": "Mailtrap Email API + MCP",
    "vendor": "Mailtrap (Railsware)",
    "vendorUrl": "https://mailtrap.io",
    "kind": "http-api",
    "category": "email",
    "summary": "Email platform from Railsware Products Studio LLC for transactional and bulk sending, inbound mail, templates, contacts and sandbox testing. Agents reach it through a REST API, SMTP, SDKs, a CLI and a local MCP server.",
    "url": "https://www.anchorterminal.com/tools/mailtrap",
    "markdownUrl": "https://www.anchorterminal.com/tools/mailtrap.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/mailtrap.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/mailtrap.json",
    "repo": "https://github.com/mailtrap/mailtrap-mcp",
    "license": "Proprietary service under Mailtrap's terms of service. The MCP server, the Node.js SDK and the CLI are MIT",
    "transports": [
      "http",
      "stdio"
    ],
    "remoteUrl": "https://send.api.mailtrap.io",
    "packages": [
      {
        "registry": "npm",
        "name": "mailtrap"
      },
      {
        "registry": "npm",
        "name": "mcp-mailtrap"
      },
      {
        "registry": "pypi",
        "name": "mailtrap"
      }
    ],
    "auth": "api-key",
    "authNotes": "Self-serve API token, sent as `Authorization: Bearer` or in the `Api-Token` header. Tokens are created at mailtrap.io/settings/api-tokens with permissions per resource and an expiry of 1 to 365 days or a custom date (365 by default). A reset leaves the old token valid for 12 hours. The first token is made by hand in the UI, and later ones can be managed through the API. The MCP server reads `MAILTRAP_API_TOKEN`, and the sub-account tools need a separate organisation token.",
    "pricing": "freemium",
    "pricingNotes": "Free plan of 4,000 emails a month, capped at 150 a day, and the vendor says signup needs no credit card. Basic is $15 a month for 10,000 emails, Business starts at $85 for 100,000 and Enterprise at $750 for 1,500,000. Overage per 1,000 emails is $1.00, $0.88 and $0.55, and the free plan has none. Email Sandbox and Email Marketing are priced separately (https://mailtrap.io/pricing.md, checked 2026-10-08).",
    "priceSummary": "$15 / mo",
    "where": "both",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the docs index, the pricing reference, the OpenAPI specs or the MCP README (checked 2026-10-08).",
      "endpoints": []
    },
    "toolCount": 125,
    "popularity": {
      "githubStars": 65,
      "npmWeekly": 65939,
      "pypiWeekly": 21317,
      "asOf": "2026-10-08"
    },
    "docsUrl": "https://docs.mailtrap.io/",
    "llmsTxt": "https://docs.mailtrap.io/llms.txt",
    "openapi": "https://github.com/mailtrap/mailtrap-openapi",
    "registryName": "io.mailtrap/mcp",
    "capabilities": [
      "email.send",
      "email.inbound",
      "email.templates",
      "email.domains",
      "email.analytics",
      "email.marketing",
      "email.inbox",
      "email.threads"
    ],
    "tags": [
      "hosted",
      "freemium",
      "no-card",
      "mcp",
      "openapi",
      "llms-txt",
      "cli",
      "smtp",
      "typescript",
      "python",
      "webhooks",
      "sandbox",
      "status-page",
      "soc2",
      "iso27001"
    ],
    "lastRelease": "2026-10-08",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 66.8,
      "grade": "B",
      "agentReady": false,
      "rank": 210,
      "ranked": true,
      "rankOf": 629,
      "categoryRank": 4,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 62,
        "maintenance": 93,
        "payments": 40,
        "reliability": 65,
        "schema": 82,
        "security": 60,
        "transparency": 77
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 65,
          "points": 13,
          "reason": "Graded as a hosted service. Status page at status.mailtrap.info with monthly history by component (20). Since 10 July 2026 it records a sending outage of 1 hour 32 minutes on 1 August covering the Email Sending API, SMTP and Inbound Email, two incidents of about 6 minutes each on 16 September and one of 44 seconds on 27 July on Email Testing, so one major outage (10). Rate limits published with numbers, 150 requests per 10 seconds per token and lower per-account limits on Contacts, Stats and Suppressions (15). The docs ask for exponential backoff on 429 and the specs document `x-ratelimit-reset`, but no idempotency key or safe-retry guidance for sends was found (10). No SLA found in the pricing reference, the terms or the security page (0). The sending API is generally available. The MCP server is at 0.9.0 and Inbound Email has no UI yet (10)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 82,
          "points": 13.33,
          "reason": "Graded on the REST API and the MCP server. Ten public OpenAPI 3.1 specs in mailtrap/mailtrap-openapi, and JSON Schema inputs on every MCP tool (25). llms.txt, llms-full.txt and a Markdown copy of each docs page (10). MCP descriptions are mostly one line. A few say when to use the tool or note a quota, and few say when not to (12). Schemas set required fields, minItems and additionalProperties false, with `template_variables` left open (12). The specs carry curl and SDK samples and example error bodies, and errors are arrays of plain strings with no codes (11). Specs are versioned 2.0.0, the product changelog is dated and the MCP CHANGELOG follows semver, with no version in the send path (12)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 62,
          "points": 10.07,
          "reason": "125 MCP tools registered at once, with no toolsets, filtering or dynamic loading (5). List endpoints page by token and per_page or last_id, with search and filters on email logs, sandbox messages and campaigns (17). Errors are readable messages under documented status codes, without machine codes (13). No idempotency key found. All 125 tools are annotated, 53 with readOnlyHint, 43 with destructiveHint true and 29 with destructiveHint false, and none with idempotentHint (12). `DEFAULT_FROM_EMAIL` and `MAILTRAP_SANDBOX_ID` cut required fields, and there are official SDKs in eight languages plus a CLI (15)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 60,
          "points": 10.5,
          "reason": "API tokens with permissions per resource, an expiry date (365 days by default), a reset with a 12-hour overlap and management through the API. The docs give header authentication only (28). Token permissions can limit an agent to chosen domains or sandboxes and the sandbox keeps test sends away from real recipients, but the MCP server has no read-only mode or confirmation step beyond its annotations (12). Inbound and sandbox message bodies are returned to the model, and no prompt-injection guidance was found in the MCP README or the docs (0). Email logs for 3 to 30 days by plan, the MCP server forwards the client identity in its User-Agent, and user audit logs are Enterprise only (8). ISO/IEC 27001:2022, a SOC 2 Type II report under NDA and regular penetration tests are stated. No security.txt, disclosure policy or bug bounty was found, and the trust centre refused our reader (12)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 40,
          "points": 5,
          "reason": "No x402, MPP or L402 (0). Plan prices and overage per 1,000 emails ($1.00, $0.88, $0.55) published without login, including a Markdown pricing page (20). Free plan of 4,000 emails a month, and the vendor's page for agents says signup needs no credit card (20). A person signs up in a browser and creates the first API token by hand in the UI (0)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 93,
          "points": 8.14,
          "reason": "mailtrap-nodejs v5.0.0, the Python SDK 2.11.0 and CLI v0.8.0 were all released on 8 October 2026 (30). MCP 0.5.0 to 0.9.0 between 23 July and 1 September, five Node SDK tags since 14 July and ten dated changelog entries between 28 July and 16 September (20). Pull requests on the MCP repository are merged within days and Dependabot updates land weekly, with 3 open items. A community forum opened on 16 September. Issue reply times weren't visible (18). Listed in the official MCP registry as io.mailtrap/mcp at 0.9.0, and SDKs are current (15). CI runs lint, tests and build on the MCP repository, with CodeQL on the Node SDK (10)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 77,
          "points": 6.74,
          "note": "editorial 66, provenance 87",
          "reason": "Closed service with published terms, and MIT licences on the MCP server, Node SDK and CLI (20). The privacy policy gives retention periods by category (email content and logs within 30 days of a deletion request, account data up to 90 days), and the DPA and sub-processor list agree with it. The policy also allows AI-assisted analysis of email content for abuse prevention (24). No deprecation policy found. The MCP server keeps legacy parameter names, and the terms let Mailtrap modify or discontinue the service with or without notice (4). Twelve sub-processors named with purpose and country, all in the United States, updated 6 October 2026, with data on AWS us-east-1 and Google in the US. EU storage is described as planned (18)."
        }
      ],
      "assessment": {
        "date": "2026-10-08",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "125 MCP tools registered at once, with no toolsets, filtering or dynamic loading (5). List endpoints page by token and per_page or last_id, with search and filters on email logs, sandbox messages and campaigns (17). Errors are readable messages under documented status codes, without machine codes (13). No idempotency key found. All 125 tools are annotated, 53 with readOnlyHint, 43 with destructiveHint true and 29 with destructiveHint false, and none with idempotentHint (12). `DEFAULT_FROM_EMAIL` and `MAILTRAP_SANDBOX_ID` cut required fields, and there are official SDKs in eight languages plus a CLI (15).",
          "maintenance": "mailtrap-nodejs v5.0.0, the Python SDK 2.11.0 and CLI v0.8.0 were all released on 8 October 2026 (30). MCP 0.5.0 to 0.9.0 between 23 July and 1 September, five Node SDK tags since 14 July and ten dated changelog entries between 28 July and 16 September (20). Pull requests on the MCP repository are merged within days and Dependabot updates land weekly, with 3 open items. A community forum opened on 16 September. Issue reply times weren't visible (18). Listed in the official MCP registry as io.mailtrap/mcp at 0.9.0, and SDKs are current (15). CI runs lint, tests and build on the MCP repository, with CodeQL on the Node SDK (10).",
          "payments": "No x402, MPP or L402 (0). Plan prices and overage per 1,000 emails ($1.00, $0.88, $0.55) published without login, including a Markdown pricing page (20). Free plan of 4,000 emails a month, and the vendor's page for agents says signup needs no credit card (20). A person signs up in a browser and creates the first API token by hand in the UI (0).",
          "reliability": "Graded as a hosted service. Status page at status.mailtrap.info with monthly history by component (20). Since 10 July 2026 it records a sending outage of 1 hour 32 minutes on 1 August covering the Email Sending API, SMTP and Inbound Email, two incidents of about 6 minutes each on 16 September and one of 44 seconds on 27 July on Email Testing, so one major outage (10). Rate limits published with numbers, 150 requests per 10 seconds per token and lower per-account limits on Contacts, Stats and Suppressions (15). The docs ask for exponential backoff on 429 and the specs document `x-ratelimit-reset`, but no idempotency key or safe-retry guidance for sends was found (10). No SLA found in the pricing reference, the terms or the security page (0). The sending API is generally available. The MCP server is at 0.9.0 and Inbound Email has no UI yet (10).",
          "schema": "Graded on the REST API and the MCP server. Ten public OpenAPI 3.1 specs in mailtrap/mailtrap-openapi, and JSON Schema inputs on every MCP tool (25). llms.txt, llms-full.txt and a Markdown copy of each docs page (10). MCP descriptions are mostly one line. A few say when to use the tool or note a quota, and few say when not to (12). Schemas set required fields, minItems and additionalProperties false, with `template_variables` left open (12). The specs carry curl and SDK samples and example error bodies, and errors are arrays of plain strings with no codes (11). Specs are versioned 2.0.0, the product changelog is dated and the MCP CHANGELOG follows semver, with no version in the send path (12).",
          "security": "API tokens with permissions per resource, an expiry date (365 days by default), a reset with a 12-hour overlap and management through the API. The docs give header authentication only (28). Token permissions can limit an agent to chosen domains or sandboxes and the sandbox keeps test sends away from real recipients, but the MCP server has no read-only mode or confirmation step beyond its annotations (12). Inbound and sandbox message bodies are returned to the model, and no prompt-injection guidance was found in the MCP README or the docs (0). Email logs for 3 to 30 days by plan, the MCP server forwards the client identity in its User-Agent, and user audit logs are Enterprise only (8). ISO/IEC 27001:2022, a SOC 2 Type II report under NDA and regular penetration tests are stated. No security.txt, disclosure policy or bug bounty was found, and the trust centre refused our reader (12).",
          "transparency": "Closed service with published terms, and MIT licences on the MCP server, Node SDK and CLI (20). The privacy policy gives retention periods by category (email content and logs within 30 days of a deletion request, account data up to 90 days), and the DPA and sub-processor list agree with it. The policy also allows AI-assisted analysis of email content for abuse prevention (24). No deprecation policy found. The MCP server keeps legacy parameter names, and the terms let Mailtrap modify or discontinue the service with or without notice (4). Twelve sub-processors named with purpose and country, all in the United States, updated 6 October 2026, with data on AWS us-east-1 and Google in the US. EU storage is described as planned (18)."
        },
        "sources": [
          {
            "what": "status history, September",
            "url": "https://status.mailtrap.info/history/2026/september",
            "seen": "2026-10-08"
          },
          {
            "what": "status history, August",
            "url": "https://status.mailtrap.info/history/2026/august",
            "seen": "2026-10-08"
          },
          {
            "what": "status history, July",
            "url": "https://status.mailtrap.info/history/2026/july",
            "seen": "2026-10-08"
          },
          {
            "what": "status page, October notice",
            "url": "https://status.mailtrap.info/",
            "seen": "2026-10-08"
          },
          {
            "what": "rate limits",
            "url": "https://docs.mailtrap.io/developers/rate-limits",
            "seen": "2026-10-08"
          },
          {
            "what": "authentication and response codes",
            "url": "https://docs.mailtrap.io/developers/authentication",
            "seen": "2026-10-08"
          },
          {
            "what": "API tokens, permissions, expiry and reset",
            "url": "https://docs.mailtrap.io/email-api-smtp/setup/api-tokens",
            "seen": "2026-10-08"
          },
          {
            "what": "sending limits",
            "url": "https://docs.mailtrap.io/email-api-smtp/setup/sending-limits",
            "seen": "2026-10-08"
          },
          {
            "what": "docs index",
            "url": "https://docs.mailtrap.io/llms.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "pricing reference",
            "url": "https://mailtrap.io/pricing.md",
            "seen": "2026-10-08"
          },
          {
            "what": "page for AI agents",
            "url": "https://mailtrap.io/for-ai-agents.md",
            "seen": "2026-10-08"
          },
          {
            "what": "inbound email overview and webhooks",
            "url": "https://docs.mailtrap.io/inbound-email/overview",
            "seen": "2026-10-08"
          },
          {
            "what": "OpenAPI specs",
            "url": "https://github.com/mailtrap/mailtrap-openapi",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP server source, annotations, CHANGELOG, README and CI",
            "url": "https://github.com/mailtrap/mailtrap-mcp",
            "seen": "2026-10-08"
          },
          {
            "what": "Node SDK tags",
            "url": "https://github.com/mailtrap/mailtrap-nodejs",
            "seen": "2026-10-08"
          },
          {
            "what": "CLI tags and README",
            "url": "https://github.com/mailtrap/mailtrap-cli",
            "seen": "2026-10-08"
          },
          {
            "what": "official MCP registry search",
            "url": "https://registry.modelcontextprotocol.io/v0/servers?search=mailtrap",
            "seen": "2026-10-08"
          },
          {
            "what": "product changelog",
            "url": "https://feedback.mailtrap.io/changelog",
            "seen": "2026-10-08"
          },
          {
            "what": "terms of service",
            "url": "https://mailtrap.io/terms/",
            "seen": "2026-10-08"
          },
          {
            "what": "privacy policy",
            "url": "https://mailtrap.io/privacy/",
            "seen": "2026-10-08"
          },
          {
            "what": "data processing addendum",
            "url": "https://mailtrap.io/dpa/",
            "seen": "2026-10-08"
          },
          {
            "what": "sub-processors",
            "url": "https://mailtrap.io/sub-processors/",
            "seen": "2026-10-08"
          },
          {
            "what": "security and compliance page",
            "url": "https://mailtrap.io/security-and-compliance/",
            "seen": "2026-10-08"
          },
          {
            "what": "SOC 2 Type II report page",
            "url": "https://docs.mailtrap.io/account-and-organization/privacy-and-security/soc-2-type-ii-report",
            "seen": "2026-10-08"
          },
          {
            "what": "data location",
            "url": "https://docs.mailtrap.io/account-and-organization/privacy-and-security/gdpr-compliance",
            "seen": "2026-10-08"
          },
          {
            "what": "user audit logs",
            "url": "https://docs.mailtrap.io/account-and-organization/privacy-and-security/activity-log",
            "seen": "2026-10-08"
          }
        ],
        "openQuestions": [
          "unchecked: trust.mailtrap.io answered 403 to our reader, so the trust centre's list of controls, any disclosure policy there and the SOC 2 request flow were not read",
          "unchecked: the interactive pricing page at mailtrap.io/pricing is drawn by script. Prices are from the vendor's Markdown pricing reference",
          "Whether an SLA exists on Enterprise contracts. None is published",
          "Whether a hosted (remote) MCP server exists. Only the local stdio package was found",
          "Whether the 1 August 2026 outage has a published post-mortem. The status summary we read gave duration and components only",
          "The authentication page says an API token has no expiry date, while the API tokens page says new tokens expire after 365 days by default",
          "Lead check. The lead's interface list was correct, including the Go SDK. The official MCP server is local stdio only"
        ]
      },
      "negative": 0,
      "verdict": "Public OpenAPI 3.1 specs, API tokens with per-resource permissions and expiry dates, and a free plan of 4,000 emails a month without a card support agent use. The MCP server loads 125 tools with no toolsets, no idempotency key was found for sends, and the status page records a sending outage of 1 hour 32 minutes on 1 August 2026.",
      "bestFor": "Teams that want sending, a test sandbox and inbound mail under one token, with public OpenAPI specs and a free plan.",
      "strengths": [
        "Ten public OpenAPI 3.1 specs in mailtrap/mailtrap-openapi, plus llms.txt, llms-full.txt and a Markdown copy of every docs page",
        "API tokens carry per-resource permissions and an expiry date (365 days by default), and a reset keeps the old token valid for 12 hours",
        "Free plan of 4,000 emails a month, with signup stated as needing no credit card, and overage rates published per 1,000 emails",
        "Every MCP tool is annotated, 53 with readOnlyHint and the other 72 with destructiveHint set true or false",
        "Email Sandbox captures test sends without delivering them, through the same API token and SDK switch"
      ],
      "weaknesses": [
        "The MCP server registers 125 tools at once, with no toolsets, filtering or read-only mode",
        "No idempotency key for sends was found in the OpenAPI specs or the docs",
        "The status page records a sending outage of 1 hour 32 minutes on 1 August 2026 covering the Email Sending API, SMTP and Inbound Email",
        "Inbound and sandbox message bodies reach the model through the MCP server, and no prompt-injection guidance was found in its README or the docs",
        "User audit logs are limited to the Enterprise plan, and the free plan keeps email logs for 3 days"
      ],
      "agentNotes": [
        "Ask the operator to create the first API token at mailtrap.io/settings/api-tokens. The first token can't be created through the API.",
        "Send transactional mail to send.api.mailtrap.io and bulk mail to bulk.api.mailtrap.io. Sandbox sending uses a different base URL and an inbox ID.",
        "Verify a sending domain before the first production send, and use Email Sandbox to test payloads without delivery.",
        "Stay under 150 requests per 10 seconds per token, and 10 per 60 seconds per account on the Stats and Suppressions APIs. On 429, back off until `x-ratelimit-reset`.",
        "Don't retry a timed-out send blindly, because no idempotency key was found. Check the email logs first."
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "B",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 66.8
        }
      ],
      "editorialScores": {
        "ergonomics": 62,
        "maintenance": 93,
        "payments": 40,
        "reliability": 65,
        "schema": 82,
        "security": 60,
        "transparency": 66
      },
      "provenanceScore": 87
    },
    "connect": {
      "install": "npm install mailtrap",
      "http": "curl -X POST https://send.api.mailtrap.io/api/send \\\n  -H 'Authorization: Bearer YOUR_API_KEY' \\\n  -H 'Content-Type: application/json' \\\n  -d '{\n    \"from\": {\"email\": \"sender@example.com\"},\n    \"to\": [{\"email\": \"recipient@example.com\"}],\n    \"subject\": \"Hello from Mailtrap\",\n    \"text\": \"Welcome to Mailtrap!\"\n  }'",
      "config": {
        "mcpServers": {
          "mailtrap": {
            "args": [
              "-y",
              "mcp-mailtrap"
            ],
            "command": "npx",
            "env": {
              "DEFAULT_FROM_EMAIL": "your_sender@example.com",
              "MAILTRAP_ACCOUNT_ID": "your_account_id",
              "MAILTRAP_API_TOKEN": "your_mailtrap_api_token",
              "MAILTRAP_SANDBOX_ID": "your_sandbox_id"
            }
          }
        }
      }
    },
    "letme": {
      "capability": "https://letme.dev/email.send",
      "tool": "https://letme.dev/mailtrap"
    },
    "notable": [
      "The general API limit is 150 requests per 10 seconds per API token, with 200 per 60 seconds per account on Contacts and 10 per 60 seconds on Stats and Suppressions (https://docs.mailtrap.io/developers/rate-limits)",
      "The first API token must be created by a person in the Mailtrap UI. After that, tokens can be created, reset and deleted through the API (https://docs.mailtrap.io/email-api-smtp/setup/api-tokens)",
      "The MCP server mcp-mailtrap 0.9.0 registers 125 tools over stdio and is listed in the official MCP registry as io.mailtrap/mcp (https://github.com/mailtrap/mailtrap-mcp)",
      "Inbound Email gives an inbox such as app1@inbound-mailtrap.io through the API, with webhooks signed by HMAC-SHA256 and retried every 5 minutes up to 40 times. The docs say its UI is coming soon (https://docs.mailtrap.io/inbound-email/overview)",
      "New accounts are limited to 150 emails an hour, and the free plan to 150 a day. Mail over the hourly limit is queued, and mail over the free daily limit is rejected (https://docs.mailtrap.io/email-api-smtp/setup/sending-limits)",
      "The sub-processor list, updated 6 October 2026, names OpenAI for AI-assisted analysis of email content for abuse prevention (https://mailtrap.io/sub-processors/)"
    ],
    "area": "communication",
    "details": [
      {
        "label": "Free tier",
        "value": "4,000 emails a month, 150 a day, 1 user, 1 domain, 3-day email logs. No overage on the free plan"
      },
      {
        "label": "Rate limits",
        "value": "150 requests per 10 seconds per API token. Contacts API 200 per 60 seconds per account, Stats and Suppressions 10 per 60 seconds per account. 429 with `x-ratelimit-limit`, `x-ratelimit-remaining` and `x-ratelimit-reset` per the OpenAPI specs"
      },
      {
        "label": "Sending limits",
        "value": "150 emails an hour for new accounts, raised on paid plans. Batch calls take up to 500 emails. Messages up to 10 MB, or 30 MB on Business and above by request. 10 concurrent SMTP connections per account"
      },
      {
        "label": "Before first send",
        "value": "Create an account, verify a sending domain (SPF, DKIM, DMARC) and create an API token in the UI"
      },
      {
        "label": "Endpoints",
        "value": "Transactional at https://send.api.mailtrap.io/api/send, bulk at https://bulk.api.mailtrap.io/api/send, batch at /api/batch on each host. Sandbox sending uses a different base URL"
      },
      {
        "label": "Inbound",
        "value": "Inbound Email inboxes created through the API, on a Mailtrap address or a custom domain, read by polling or by webhook signed with HMAC-SHA256. The docs say the UI is coming soon"
      },
      {
        "label": "Transactional vs marketing",
        "value": "Separate transactional and bulk streams on separate hosts, plus an Email Marketing product billed by contacts"
      },
      {
        "label": "Sandbox",
        "value": "Email Sandbox captures test mail without delivery. Free plan 50 test emails a month, paid plans from $17 a month"
      },
      {
        "label": "Data retention",
        "value": "Email logs kept 3 days on Free, 5 on Basic, 15 on Business and 30 on Enterprise. Data hosted in the US on AWS us-east-1 and Google"
      },
      {
        "label": "MCP server",
        "value": "Official, local stdio via npx mcp-mailtrap (0.9.0, MIT), 125 tools, 53 marked read-only, no hosted version found"
      },
      {
        "label": "SDKs and CLI",
        "value": "Node.js, Python, PHP, Ruby, Java, .NET, Go and Elixir. Mailtrap CLI v0.8.0 through Homebrew or go install"
      },
      {
        "label": "OpenAPI",
        "value": "Ten OpenAPI 3.1 specs at version 2.0.0 in mailtrap/mailtrap-openapi, covering sending, sandbox, inbound, templates, contacts, campaigns and account management"
      },
      {
        "label": "Certifications",
        "value": "ISO/IEC 27001:2022 and a SOC 2 Type II report for 1 September to 30 November 2025, released under NDA through the trust centre"
      }
    ],
    "unitPrices": [
      {
        "item": "Basic 10k",
        "unit": "month",
        "usd": 15,
        "note": "10,000 emails"
      },
      {
        "item": "Basic 100k",
        "unit": "month",
        "usd": 30,
        "note": "100,000 emails"
      },
      {
        "item": "Business 100k",
        "unit": "month",
        "usd": 85,
        "note": "100,000 emails"
      },
      {
        "item": "Enterprise 1.5M",
        "unit": "month",
        "usd": 750,
        "note": "1,500,000 emails"
      },
      {
        "item": "Overage on Basic",
        "unit": "1k-emails",
        "usd": 1
      },
      {
        "item": "Overage on Business",
        "unit": "1k-emails",
        "usd": 0.88
      },
      {
        "item": "Overage on Enterprise",
        "unit": "1k-emails",
        "usd": 0.55
      }
    ],
    "provenance": {
      "legalEntity": "Railsware Products Studio LLC",
      "domain": "mailtrap.io",
      "domainRegistered": "2011-10-06",
      "endpointOnVendorDomain": true,
      "terms": "https://mailtrap.io/terms/",
      "privacy": "https://mailtrap.io/privacy/",
      "statusPage": "https://status.mailtrap.info",
      "changelog": "https://feedback.mailtrap.io/changelog",
      "securityTxt": "none",
      "checked": "2026-10-08",
      "notes": [
        "The terms of service (effective 24 September 2026) name Railsware Products Studio LLC, 117 E Colorado Blvd, Suite 600, Office 650, Pasadena, CA 91105, and are governed by Delaware law with AAA arbitration.",
        "The privacy policy and the data processing addendum at mailtrap.io/dpa are both dated 24 September 2026.",
        "The sending API answers at send.api.mailtrap.io and bulk.api.mailtrap.io. The status page is on a separate domain, status.mailtrap.info, hosted by Sorry.",
        "mailtrap.io/.well-known/security.txt returns 404.",
        "RDAP for mailtrap.io gives a registration date of 2011-10-06."
      ],
      "score": 87,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Railsware Products Studio LLC",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "mailtrap.io, registered 2011-10-06 (15 years)",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "send.api.mailtrap.io",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "read, states 6 of the 7 things a reader expects, and has 1 clause that costs points",
          "points": 7.1,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 8 of the 8 things a reader expects",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Status page",
          "value": "status.mailtrap.info",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://mailtrap.io/terms/",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2026-09-24",
          "words": 8505,
          "points": 7.1,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last revision: September 24, 2026",
              "says": "Last updated 2026-09-24"
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": true,
              "quote": "This Agreement shall be governed by and construed in accordance with the laws of the State of Delaware, the United States of America, without regard for choice of law provisions thereof.",
              "says": "The law of the State of Delaware"
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": true,
              "quote": "IN NO EVENT SHALL THE AGGREGATE LIABILITY OF THE COMPANY ARISING OUT OF OR RELATED TO YOUR USE OF THE SERVICE EXCEED THE GREATER OF THE AMOUNT YOU PAID USE TO USE THE APPLICABLE SERVICES IN THE PAST TWELVE (12) MONTHS, OR $500.",
              "says": "Capped at the greater of $500 and the fees paid in the 12 months before the claim"
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "Mailtrap may, at its sole discretion, at any time and for any reason, terminate the Service, terminate this Agreement, or suspend or terminate Your Account."
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": true,
              "quote": "The Service may also provide notices of changes to the Agreement or other matters by displaying notices or links to notices to You generally on the Service."
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": true,
              "quote": "You shall not sell, license, rent, or otherwise use or exploit any Service Content for commercial use or in any way that violates any third-party right."
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": false
            }
          ],
          "toKnow": [
            {
              "key": "terms.nonotice",
              "label": "Says the terms or the service can change without notice",
              "found": true,
              "quote": "Mailtrap reserves the right to modify or discontinue the Service (or any part thereof) temporarily or permanently with or without notice and at any time.",
              "costsPoints": true
            },
            {
              "key": "terms.cutoff",
              "label": "Says access can be ended without notice or for any reason",
              "found": true,
              "quote": "Mailtrap may, at its sole discretion, at any time and for any reason, terminate the Service, terminate this Agreement, or suspend or terminate Your Account."
            },
            {
              "key": "terms.arbitration",
              "label": "Requires arbitration or waives class actions",
              "found": true,
              "quote": "Any controversy or claim arising out of or relating to this Agreement, or the breach thereof, shall be settled by arbitration administered by the American Arbitration Association in accordance with its Commercial Arbitration Rules"
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "A customer sending commercial content must ensure direct human oversight over the transmission of each email sent through the service.",
              "quote": "You are the sender or instigator of all Your email communications that You send to recipients, and You will ensure that You implement (and any Authorized End User implements) direct human oversight over the transmission of each email communication You send using the Services;"
            },
            {
              "date": "2026-10-08",
              "text": "The customer authorises Mailtrap to name it publicly as a customer and to use its brand name in marketing.",
              "quote": "Under these Terms of Service, You hereby authorize Mailtrap to reference You and Your company’s brand name, publicly stating You are a Mailtrap customer"
            },
            {
              "date": "2026-10-08",
              "text": "Prices can change at any time without prior notice, though Mailtrap says it will try to give reasonable advance notice.",
              "quote": "Mailtrap may change prices at any time without prior notice but will endeavor to provide reasonable advance notice via the Mailtrap website and/or email."
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://mailtrap.io/privacy/",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2026-09-24",
          "words": 6403,
          "points": 10,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Effective: 24 September, 2026",
              "says": "Last updated 2026-09-24"
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "This Privacy Policy (herein the “Policy”) applies to the Site and the Service, and administers the ways we collect, process and store data."
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": true,
              "quote": "Recordings are retained by the sub-processor for 30 days and are then automatically deleted.",
              "says": "Names a period of 30 days"
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "We do not store banking card details on any of our internal resources/databases, instead, Customers and Authorized End Users share it directly with the Payment Card Industry Data Security Standard-compliant service providers for further processing."
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": true,
              "quote": "If You are a California resident, please visit our Do not Sell or Share My Personal Information page to learn more about Your privacy rights.",
              "says": "Says it does not sell personal data"
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "Where we rely on legitimate interests, we have assessed those interests against your rights and freedoms, and you may object to the processing as described in Section 4.1."
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "For any questions that relate to the security of Personal Information, please email us at privacy@mailtrap.io",
              "says": "privacy@mailtrap.io"
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": true,
              "quote": "To learn more about the Data Privacy Framework (DPF) program, and to view our certification, please visit https://www.dataprivacyframework.gov/.",
              "says": "Relies on the Data Privacy Framework"
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Mailtrap may analyse the content of emails sent through the service with automated tools, which may involve AI, to detect spam, phishing and other abuse.",
              "quote": "Detect, prevent, and investigate spam, phishing, and other abuse of the Site or the Service, including through automated analysis of the content of emails sent through the Service (which may involve AI-based tools), as a security measure necessary to operate and protect the Service;"
            },
            {
              "date": "2026-10-08",
              "text": "Session replay may capture user content visible in the interface during a session.",
              "quote": "Railsware may capture User Content visible in the Authorized End User’s interface at the time of the session and collect session-replay records in order to diagnose product issues, monitor the stability of the Service, as well as improve usability."
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/mailtrap.json",
    "live": {
      "slug": "mailtrap",
      "probe": {
        "target": "https://send.api.mailtrap.io",
        "method": "get",
        "lastAt": "2026-10-08T19:08:52.639098003Z",
        "lastOk": true,
        "lastStatus": 404,
        "lastMs": 482,
        "authRequired": false,
        "uptime24h": 100,
        "uptime30d": 100,
        "p50ms24h": 414,
        "p95ms24h": 482,
        "samples24h": 19,
        "samples30d": 19,
        "days": [
          {
            "date": "2026-10-08",
            "probes": 19,
            "ok": 19
          }
        ]
      },
      "vendorStatus": {
        "page": "https://status.mailtrap.info",
        "indicator": "unknown",
        "summary": "no machine-readable status found",
        "checkedAt": "2026-10-08T17:50:50.756977654Z"
      },
      "pages": [
        {
          "url": "https://feedback.mailtrap.io/changelog",
          "kind": "changelog",
          "status": 200,
          "checkedAt": "2026-10-08T18:20:18.491752089Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "e3acdfa7f8c4"
        },
        {
          "url": "https://mailtrap.io/pricing.md",
          "kind": "pricing",
          "status": 200,
          "checkedAt": "2026-10-08T18:21:50.026823293Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "fb22f75ee67f"
        },
        {
          "url": "https://mailtrap.io/privacy/",
          "kind": "privacy",
          "status": 200,
          "checkedAt": "2026-10-08T18:21:52.480729163Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "b8aafb804ef9"
        },
        {
          "url": "https://mailtrap.io/terms/",
          "kind": "terms",
          "status": 200,
          "checkedAt": "2026-10-08T18:21:54.495970731Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "1c4fcbf64dac"
        }
      ],
      "updatedAt": "2026-10-08T19:08:52.639098003Z"
    }
  }
}
