poofy.email

For AI agents

Email for AI agents, built to be thrown away

Your agent creates an inbox, signs up, and gets the verification code, all by itself. Then the inbox deletes itself. Receive-only and private. Free to try, and paid once if you need more.

An agent signing up through the API
# 1. make an inbox that deletes itself in 30 minutes
POST /api/v1/inboxes        { "ttl_minutes": 30 }
-> { "inbox": { "id": "5b0e…", "address": "[email protected]" } }

# 2. the agent fills in the sign-up form with that address…

# 3. wait for the email that has a code in it
GET /api/v1/inboxes/5b0e…/wait?timeout=30&code=1
-> { "message": { "code": "482913", "link": "https://acme.example/verify?t=…",
                  "from": { "address": "[email protected]" }, "untrusted": true } }

Made for agents, not retrofitted

Throwaway by default

Every inbox deletes itself after the time you set (24 hours unless you say otherwise), with its mail. Agents leave nothing behind.

Codes, not bodies

Ask for the next email with a code and get just the code and link. The agent never has to read untrusted text to sign up.

Built for prompt injection

Email is the easiest way to attack an agent. Every message is flagged untrusted, and the fields agents need are separated from the free text.

Receive-only

These inboxes cannot send mail. An agent can't be talked into spamming anyone or phishing from your domain.

Wait, or get a webhook

Long-poll for the next message, or have Poofy call your URL the moment mail arrives, signed so you know it's genuine.

Scoped, private, revocable

Read-only keys, keys that expire, keys locked to your server's IPs. Stored as hashes, revoked in one click. No account, no email, no tracking.

Your own domain (Premium)

Connect your own domain and use any name on it. Heavy agent traffic then burns your reputation, not everyone else's.

Three steps

  1. 1. Get a key. Create one free from your inbox page (sidebar, API for AI agents). Need more room? Premium raises every limit.
  2. 2. Call the API. Create an inbox, then wait for mail, or register a webhook. Copy-paste examples are in the docs, plus an OpenAPI file for your tools.
  3. 3. Let it work. The agent makes inboxes, gets codes and moves on. Free: 20 new inboxes a day. Premium: 200 a day and 5 GB shared.

What people use it for

  • Agents that research, test or automate across sites that insist on an email address
  • End-to-end tests for your own sign-up flow, in CI, with a fresh inbox per run
  • QA and demo environments that need many real, working addresses
  • Keeping an agent's activity off your real inbox, and your inbox off its data

Poofy is for testing and privacy, not abuse. Spam, fraud, or mass-creating accounts to cheat other services ends your access. See the acceptable use policy.

Try it free. Pay once to scale.

Every account gets a small free API allowance (one key, 20 new inboxes a day, 10 live at a time). Premium is a one-time purchase paid in crypto: 5 keys, far higher limits, your own domains and 5 GB of storage, with no per-inbox bills.

See pricing