Misralo

Misralo Announcer

Email your customers actually receive.

Password resets, receipts, alerts — the mail your product cannot afford to lose. Announcer sends it from your own domain and signs every message, so mailbox providers can tell it really came from you.

100 messages a day on the free plan. No card.

Why it matters

Anyone can put your address in a From line.

That is why mailbox providers ignore it and look for proof instead. Announcer's job is to produce that proof on every message you send, without you becoming an email expert.

It reaches the inbox

Every message is signed with a key that belongs to your domain alone. Gmail and Outlook can verify it, so your mail is judged on its own reputation instead of being filed as suspicious.

You keep your domain

Mail goes out as you, not as us — no "via" line, no shared sending address. The only thing you publish is one DNS record that says we may sign on your behalf.

You find out what happened

Delivered, bounced, marked as spam — every message keeps its own timeline, and dead addresses are blocked automatically before they damage your reputation.

Privacy

The mail you send is not ours to read.

Password resets, receipts, invitations — transactional mail is some of the most sensitive text your product ever writes. Most providers keep a copy so you can read it back in their dashboard, which means they can read it too. We built it the other way round.

We never store what you wrote

Message bodies are assembled, signed and handed to the mail server. There is no column in our database that could hold one. We keep the envelope — who it went to and what happened to it — and the subject line, so you can tell your messages apart.

No pixels, no rewritten links

We do not track opens or clicks, because doing it means putting an invisible image in your mail and pointing your links at us first. Your recipients are not measured, and your links stay yours.

One country, three companies

Everything runs on a single server in Stockholm. The only other companies that can touch your data are our host, our DNS provider, and — if you choose it — whoever you sign in with. The whole list is on one page and it fits in a paragraph.

Leaving takes one click

Close your account from the dashboard and it is deleted on the spot: domains, keys, history, suppression list. No email to support, no retention offer, no waiting period.

The details, including what we do keep and for how long, are in the privacy policy — written to be read, not to be survived.

Getting started

Three steps, and the first message is signed.

Most people are through this in about ten minutes, most of which is waiting for DNS.

STEP 1

Add your domain

We generate a signing key that exists for your domain and nothing else. The private half never leaves our servers.

STEP 2

Publish one DNS record

Copy the record we show you into your DNS provider. This is what lets receivers check our signature against a key you control.

STEP 3

Send

One API call from your app. Until the record actually resolves we refuse to send rather than quietly letting unsigned mail out under your name.

For developers

An HTTP API and nothing to install.

No SDK required and no SMTP credentials to rotate. If your language can make an HTTPS request, it can send. For Node.js, Python, Go and .NET there are official SDKs as well.

Register a domain

# Returns the DNS record to publish.
curl -X POST https://mail.misralo.com/v1/domains \
  -H "Authorization: Bearer $ANNOUNCER_KEY" \
  -H "Content-Type: application/json" \
  -d '{"domain": "your-company.com"}'

Send a message

curl -X POST https://mail.misralo.com/v1/emails \
  -H "Authorization: Bearer $ANNOUNCER_KEY" \
  -H "Content-Type: application/json" \
  -d '{
        "from":    "billing@your-company.com",
        "to":      "customer@example.net",
        "subject": "Your receipt",
        "text":    "Thanks for your order."
      }'

Errors are RFC 9457 problem documents. Webhooks are signed with HMAC-SHA256 so you can prove a delivery came from us. Health is unauthenticated at /healthz.

Read the API docs

For agents

An agent can wire this up nearly on its own.

More and more often the thing reading the docs is not a person with a browser open. So Announcer describes itself in the formats those clients already look for: an assistant can find the API, get its own key and send a message without anyone pasting curl commands into a chat window.

It gets its own key

Through the RFC 8628 device grant — the same ceremony as gh auth login. The agent shows you a code, you approve it in the dashboard, and it receives a scoped key of its own. Your password never passes through it. The whole procedure is written down for them at auth.md.

MCP and A2A, not only REST

The same operations are an MCP server and an A2A agent, both taking that same key and granting nothing it does not already grant. Neither has a tool for minting keys, deleting a domain or opening your billing.

Instructions, not guesswork

Three written skills — send a message, verify a domain, work out why one never arrived — say what must be true first and what each refusal means. And every page here, this one included, answers in plain markdown for a client that would rather not parse a layout.

Discovery starts at llms.txt or the AI catalog, and the API is specified in OpenAPI 3.1. The one step that stays human is publishing the DNS record: nothing should be able to sign mail as your domain because a model decided it was fine.

Pricing

Free while you are getting started.

The free plan is a real plan, not a trial that expires. When you outgrow it, Pro is €19 a month with a written 99.5% uptime commitment.

See the plans