Docs

Email MCP server quickstart

The Dooxout email MCP server lets Claude, Cursor or any MCP client run cold outreach: manage campaigns and lead lists, work the inbox and read results. It uses Streamable HTTP and a bearer token, and every call is limited by the token's role, its sending domains and your workspace policy.

Quickstart

  1. 01

    Get a workspace

    Request a demo. Demo access is granted on request and the workspace is yours to keep.

  2. 02

    Create an access token

    Create a token in the console. The agent uses it as a bearer token, so it can only do what the token's role, its domains and the workspace policy allow.

  3. 03

    Add the MCP server to your client

    Use the server URL and token from your workspace. The example below uses placeholders.

  4. 04

    Ask the agent

    For example: how is my campaign doing, and draft replies to anyone interested. Replies that need a decision wait for your approval.

Sample

// example for a client that accepts a remote MCP server (for instance Cursor)
{
  "mcpServers": {
    "dooxout": {
      "url": "<MCP server URL from your workspace>",
      "headers": { "Authorization": "Bearer <your access token>" }
    }
  }
}

// 1. who is this token, and which domains can it use?
call whoami({})

→ { role: "operator", domains: [{ id: "…", domain: "…" }], scopes: [ … ] }

// 2. running campaigns
call campaigns.list({ status: "running" })

→ [{ id: "…", name: "…", status: "running", schedule: { … } }]

// 3. check a campaign before it starts (no side effects)
call campaigns.preflight({ campaign_id: "…" })

→ { ok: false, blocking: [ … ] }

// 4. replies waiting for a decision
call inbox.list_pending({ limit: 10 })

→ { data: [{ thread_id: "…", lead_email: "…", classification: "…" }],
     next_cursor: null }

Ellipses stand for values your workspace returns.

Tools

The tools an agent can call, grouped by task, with the minimum role each needs.

MCP tools
ToolsRoleWhat they do
campaigns.list
campaigns.get
campaigns.create
campaigns.set_steps
campaigns.attach_audience
campaigns.preflight
OperatorRead and create campaigns, replace steps, attach lead lists and run launch checks with no side effects.
campaigns.start
campaigns.pause
campaigns.resume
campaigns.stop
ManagerControl a running campaign. These need the manager role.
lead_lists.create
lead_lists.list
lead_lists.import
lead_lists.import_status
lead_lists.verify
OperatorCreate lists, import CSV text, follow the import and queue address verification.
leads.search
leads.get
leads.upsert
leads.set_briefing
OperatorSearch, read and upsert leads, and set the briefing used to personalise a message.
inbox.list_pending
inbox.claim
inbox.get_thread
inbox.reply
OperatorList unhandled threads, claim one, read it, and draft or send a reply.
generation.list_pending
generation.claim
generation.submit
generation.skip
OperatorLet the agent write personalised content for pending jobs, or skip one and use the fallback template.
whoami
domains.list
events.tail
suppression.add
OperatorSee the token's role and domains, tail delivery events, and suppress an email or domain.

Authentication and roles

Send requests to the MCP endpoint with Authorization: Bearer <token>. Each token belongs to a user, inherits that user’s role (admin, manager or operator) and sending-domain access, and can be narrowed further. Call whoami first to see what the token can do. You can revoke a token in the console at any time.

Limits and errors

The default rate limit is 120 requests per minute per token. Errors use the JSON-RPC error envelope, and data.kind tells your agent what to do next:

  • auth: the token is missing, expired or revoked.
  • forbidden: the role or domain access does not allow this call.
  • rate_limited: wait, then retry.
  • validation, not_found and conflict: fix the input or re-read the record.

An outreach MCP with guardrails: approvals

Limits are checked by the server, not by the agent’s prompt. Before a campaign goes out, campaigns.preflight reports what would block it, and a bad deliverability result blocks the launch for an agent.

When an action falls under an approval gate, such as the first campaign or a purchase, the server does not run it. It records an approval request that a person reviews in the console, and the action runs only after they approve. For replies, the domain’s agent-reply mode decides whether inbox.reply saves a draft for a person or sends the message.

Caps, budgets and approval rules are read-only for the agent. More in security, and budgets are explained on pricing.

What to ask your agent

  • “List my running campaigns and show anything that failed preflight.”
  • “Show pending replies and draft an answer for anyone interested.”

See integrations, agencies, compare, the blog and the home page.

MCP questions

What is an email MCP server?

It is a server that exposes email outreach actions as tools an AI agent can call over the Model Context Protocol. The Dooxout email MCP server covers campaigns, lead lists, leads, the inbox, events and suppression.

Which MCP clients can connect?

Any client that supports remote MCP servers over Streamable HTTP and lets you set an Authorization header, for example Claude or Cursor. The URL and token come from your workspace.

What are the rate limits?

The default is 120 requests per minute per token. Over the limit, the server returns an error of kind rate_limited.

Can the agent send email without my approval?

Only inside the limits you set. Starting a campaign needs a manager role, the first campaign needs a person's approval, and the policy checks caps and budgets on every action. See security.

Connect an agent to a real workspace

Demo access is granted on request. We reply within one business day.

Request a demo