Docs
Email MCP server quickstart
The Dooxout email MCP server lets Claude, Cursor or any MCP client run cold outreach: manage campaigns and lead lists, work the inbox and read results. It uses Streamable HTTP and a bearer token, and every call is limited by the token's role, its sending domains and your workspace policy.
Quickstart
- 01
Get a workspace
Request a demo. Demo access is granted on request and the workspace is yours to keep.
- 02
Create an access token
Create a token in the console. The agent uses it as a bearer token, so it can only do what the token's role, its domains and the workspace policy allow.
- 03
Add the MCP server to your client
Use the server URL and token from your workspace. The example below uses placeholders.
- 04
Ask the agent
For example: how is my campaign doing, and draft replies to anyone interested. Replies that need a decision wait for your approval.
Sample
// example for a client that accepts a remote MCP server (for instance Cursor)
{
"mcpServers": {
"dooxout": {
"url": "<MCP server URL from your workspace>",
"headers": { "Authorization": "Bearer <your access token>" }
}
}
} // 1. who is this token, and which domains can it use?
call whoami({})
→ { role: "operator", domains: [{ id: "…", domain: "…" }], scopes: [ … ] }
// 2. running campaigns
call campaigns.list({ status: "running" })
→ [{ id: "…", name: "…", status: "running", schedule: { … } }]
// 3. check a campaign before it starts (no side effects)
call campaigns.preflight({ campaign_id: "…" })
→ { ok: false, blocking: [ … ] }
// 4. replies waiting for a decision
call inbox.list_pending({ limit: 10 })
→ { data: [{ thread_id: "…", lead_email: "…", classification: "…" }],
next_cursor: null } Ellipses stand for values your workspace returns.
Tools
The tools an agent can call, grouped by task, with the minimum role each needs.
| Tools | Role | What they do |
|---|---|---|
campaigns.listcampaigns.getcampaigns.createcampaigns.set_stepscampaigns.attach_audiencecampaigns.preflight | Operator | Read and create campaigns, replace steps, attach lead lists and run launch checks with no side effects. |
campaigns.startcampaigns.pausecampaigns.resumecampaigns.stop | Manager | Control a running campaign. These need the manager role. |
lead_lists.createlead_lists.listlead_lists.importlead_lists.import_statuslead_lists.verify | Operator | Create lists, import CSV text, follow the import and queue address verification. |
leads.searchleads.getleads.upsertleads.set_briefing | Operator | Search, read and upsert leads, and set the briefing used to personalise a message. |
inbox.list_pendinginbox.claiminbox.get_threadinbox.reply | Operator | List unhandled threads, claim one, read it, and draft or send a reply. |
generation.list_pendinggeneration.claimgeneration.submitgeneration.skip | Operator | Let the agent write personalised content for pending jobs, or skip one and use the fallback template. |
whoamidomains.listevents.tailsuppression.add | Operator | See the token's role and domains, tail delivery events, and suppress an email or domain. |
Authentication and roles
Send requests to the MCP endpoint with Authorization: Bearer <token>. Each token belongs to a user, inherits that user’s role (admin, manager or operator) and sending-domain access, and can be narrowed further. Call whoami first to see what the token can do. You can revoke a token in the console at any time.
Limits and errors
The default rate limit is 120 requests per minute per token. Errors use the JSON-RPC error envelope, and data.kind tells your agent what to do next:
auth: the token is missing, expired or revoked.forbidden: the role or domain access does not allow this call.rate_limited: wait, then retry.validation,not_foundandconflict: fix the input or re-read the record.
An outreach MCP with guardrails: approvals
Limits are checked by the server, not by the agent’s prompt. Before a campaign goes out, campaigns.preflight reports what would block it, and a bad deliverability result blocks the launch for an agent.
When an action falls under an approval gate, such as the first campaign or a purchase, the server does not run it. It records an approval request that a person reviews in the console, and the action runs only after they approve. For replies, the domain’s agent-reply mode decides whether inbox.reply saves a draft for a person or sends the message.
Caps, budgets and approval rules are read-only for the agent. More in security, and budgets are explained on pricing.
What to ask your agent
- “List my running campaigns and show anything that failed preflight.”
- “Show pending replies and draft an answer for anyone interested.”
See integrations, agencies, compare, the blog and the home page.
MCP questions
What is an email MCP server?
It is a server that exposes email outreach actions as tools an AI agent can call over the Model Context Protocol. The Dooxout email MCP server covers campaigns, lead lists, leads, the inbox, events and suppression.
Which MCP clients can connect?
Any client that supports remote MCP servers over Streamable HTTP and lets you set an Authorization header, for example Claude or Cursor. The URL and token come from your workspace.
What are the rate limits?
The default is 120 requests per minute per token. Over the limit, the server returns an error of kind rate_limited.
Can the agent send email without my approval?
Only inside the limits you set. Starting a campaign needs a manager role, the first campaign needs a person's approval, and the policy checks caps and budgets on every action. See security.
Connect an agent to a real workspace
Demo access is granted on request. We reply within one business day.