Demo on requestCold email automation platform for AI agents
Cold outreach, run by an agent. With guardrails.
An agent finds leads, plans the sequence and handles replies. You set the limits, budgets and approvals. The server enforces them, not a prompt.
Works with Claude, Cursor and any MCP client
How it works
One loop, from lead to reply
Cold email automation from the first list to the last reply, with sending infrastructure, sequences and an inbox in one place.
- 01
Leads
Import a CSV, pull from LinkedIn or let the agent build a list from your criteria.
- 02
Domains & mailboxes
Cold email infrastructure: separate sending domains with DNS checked before the first send.
- 03
Sequences
Steps, delays and variables planned by the agent, reviewed by you.
- 04
Channels
Email, LinkedIn, WhatsApp and Telegram in one sequence.
- 05
Replies
Replies sorted by intent. Out-of-office and bounces stop the sequence.
- 06
Report
Sent, delivered, replied and spent. Counted, not estimated.
Three things we do differently
Outbound sales automation an AI agent can run without being trusted with the limits.
Guardrails in code
Caps, budgets and approvals are checked by the server on every send. An agent cannot talk its way past them.
One loop from lead to reply
Leads, mailboxes, sequences and replies live in one place, so the agent sees the whole picture and so do you.
Honest metrics and pricing
No inbox-placement promises. Reports show what was sent, delivered and replied, and add-ons are priced in the open.









Leads
Lists you can trust before the first send
Bring your own leads. The agent de-duplicates, verifies and drops anyone on your suppression list.
CSV import
Map columns once, reuse the mapping on the next file.
Suppression list
Unsubscribes and complaints are never contacted again. This rule cannot be turned off.
Email verification
Risky and invalid addresses flagged before they hurt a domain.
Enrichment
Company and role data from providers you connect.
For agents · Email MCP server
Your agent already knows how to use it
Connect Claude or Cursor to the Dooxout email MCP server. Every tool call goes through the same limits as the console.
// list running campaigns, then read replies that wait for a decision
call campaigns.list({ status: "running" })
→ [{ id: "…", name: "Fintech CTOs, EU", status: "running",
step_count: 3, audience_summary: { enrollment_count: … } }]
call inbox.list_pending({ limit: 10 })
→ { data: [{ thread_id: "…", lead_email: "m.novak@…",
classification: "interested" }], next_cursor: null } - campaigns.list
- inbox.list_pending
- campaigns.preflight
- suppression.add
Guardrails
Limits the agent can read, but not change
Set a policy once. Every send is checked against it on the server, so an AI outbound sales agent stays inside your limits.
| Policy | Example setting |
|---|---|
| Cap per mailbox | 40 / day |
| Cap per domain | 120 / day |
| Cap per channel | email 300 / day |
| Budget | €200 / month |
| Approvals | first step, all replies |
| Kill switch | stops all sends |





Multichannel outreach
Four channels, one sequence, one inbox
Multichannel outreach from a single sequence, with replies from every channel landing in the same inbox.
- EmailGoogle, Microsoft, SMTP, Amazon SES
- LinkedInVisits, invites, messages
- WhatsAppMessages and follow-ups
- TelegramMessages and follow-ups
Limits and caveats. Messenger platforms can restrict accounts that send cold messages. Our limits are conservative defaults, not a guarantee that an account stays unrestricted.







Replies
Start more conversations, keep the ones that matter
Every reply lands in one inbox, across all mailboxes and channels. The agent sorts by intent and drafts answers; you approve what goes out.
- Google and Microsoft mailboxes over IMAP
- Bounces, out-of-office and unsubscribes stop the sequence
- Reply classifier is optional and off by default
For agencies
Run outreach for every client, under your brand
Each client gets a separate workspace with its own budget, domains and policy. One client's mistakes never touch another's reputation.
Client workspaces
Roles and per-client budgets.
Your brand
Logo, colours and your own domain.
Client reports
Shareable, read-only, white-label.
Own domain
Clients log in at your address.






Integrations
Plugs into the stack you already run
- REST API
- MCP
- HubSpot
- Pipedrive
- Slack
- Calendly
- Zapier
- Make
- Amazon SES
- SMTP
- IMAP
- Gmail
- Outlook
Demo
See it run on your own leads
A call with an engineer, then a workspace you keep.
- 01
A workspace with your domain
We check DNS and connect a mailbox together.
- 02
Your agent, connected over MCP
Claude or Cursor plans a first sequence on a sample of your leads.
- 03
A policy that fits your risk
Caps, budget and approvals set before anything is sent.
Request received
Demo access is granted on request. We reply within one business day.
Questions
How does demo access work?
Fill in the short form. An engineer replies within one business day, walks you through the product and sets up a workspace you keep.
What is cold email infrastructure?
It is everything on the sending side: separate sending domains, mailboxes with SPF, DKIM and DMARC in place, per-mailbox caps and monitoring. In Dooxout the DNS is checked before the first send, and new mailboxes start with low caps. See security for how limits are enforced.
Can an AI agent run cold email through MCP?
Yes. Claude, Cursor or any MCP client can list campaigns, read replies, request approvals and read the policy through the Dooxout MCP server. Every tool call goes through the same server-side limits as the console, and the agent cannot change them. Start with the MCP quickstart.
Is there warm-up?
No. Automated warm-up networks fake engagement and mailbox providers detect them. New mailboxes start with low caps that rise slowly instead.
Does it support multichannel outreach?
Yes. Email, LinkedIn, WhatsApp and Telegram run in one sequence with one inbox for the replies. Messenger platforms can restrict accounts that send cold messages, so the limits are conservative defaults, not a guarantee.
Who is responsible for messenger and mailbox limits?
You are, as the account owner. LinkedIn, WhatsApp, Telegram and mailbox providers can restrict accounts. Our defaults are conservative, but they are not a guarantee.
Where does my data live?
In the EU. Secrets such as mailbox passwords and API keys are encrypted at rest, and every action is written to an audit log.
What does the reply classifier do with reply text?
It reads replies only to sort them by intent and draft answers. It is optional and off by default.
Can the agent change my limits?
No. Agents can read caps and budgets through MCP, but changing them requires a person with the right role in the console.
Which mail providers can I connect?
Gmail and Google Workspace, Outlook and Microsoft 365, any SMTP and IMAP server, and Amazon SES for sending. The full list is on the integrations page.
How does pricing work?
One plan price plus add-ons billed by a single unit each: domains, mailboxes, leads and agent tokens. Ask for exact numbers in the demo, or read how pricing is structured.
Hand outreach to an agent. Keep the keys.
Demo access is granted on request. We reply within one business day.