Running an agent with its own email inbox: field-tested practices
Jcoulaud · reddit · 2026-10-11
The author has run an agent with its own email address for a while (Grok bot just shipped the same idea) and shares lessons:
- Give it its own address, not yours — otherwise it reads everything including password resets.
- Use your own domain for customer-facing mail; shared agent domains share sending reputation with every other bot.
- Draft-only at first: anyone can email the address, and message text can masquerade as instructions. The author reviewed weeks of drafts before allowing sends.
- Make sure a human can open the inbox directly; "ask the bot what it sent" fails when a customer complains.
- Prefer webhooks over polling, and sign requests so nobody else can trigger your agent.
- Plus aliases (name+test@) don't always work on agent inboxes — check before signing up.
Open question: beyond draft-only plus a small allowlist, what works for prompt injection defense?
More from coding & agent
- Developer flags Claude web interface restriction on uploading new skills, multi-file skills blocked — strickvl · 2026-10-11
- Users want X Money integration to give AI agents dedicated, capped budget envelopes — RachelVT42 · 2026-10-11
- LangChain's CEO on the open question of identity for internal company agents — hwchase17 · 2026-10-11
- All of Science embedded and free: semantic search for your agents, 10 req/min — IgorCarron · 2026-10-11
- A personal AI agent architecture: local Llama router, whitelisted passwords, human-in-the-loop approvals — roamingandy · 2026-10-11
- Users report Codex outage overnight: 'all my agents walked off the job' — burhop · 2026-10-11