Misralo Announcer
Email your customers actually receive.
Password resets, receipts, alerts — the mail your product cannot afford to lose. Announcer sends it from your own domain and signs every message, so mailbox providers can tell it really came from you.
100 messages a day on the free plan. No card.
Why it matters
Anyone can put your address in a From line.
That is why mailbox providers ignore it and look for proof instead. Announcer's job is to produce that proof on every message you send, without you becoming an email expert.
It reaches the inbox
Every message is signed with a key that belongs to your domain alone. Gmail and Outlook can verify it, so your mail is judged on its own reputation instead of being filed as suspicious.
You keep your domain
Mail goes out as you, not as us — no "via" line, no shared sending address. The only thing you publish is one DNS record that says we may sign on your behalf.
You find out what happened
Delivered, bounced, marked as spam — every message keeps its own timeline, and dead addresses are blocked automatically before they damage your reputation.
Privacy
The mail you send is not ours to read.
Password resets, receipts, invitations — transactional mail is some of the most sensitive text your product ever writes. Most providers keep a copy so you can read it back in their dashboard, which means they can read it too. We built it the other way round.
We never store what you wrote
Message bodies are assembled, signed and handed to the mail server. There is no column in our database that could hold one. We keep the envelope — who it went to and what happened to it — and the subject line, so you can tell your messages apart.
No pixels, no rewritten links
We do not track opens or clicks, because doing it means putting an invisible image in your mail and pointing your links at us first. Your recipients are not measured, and your links stay yours.
One country, three companies
Everything runs on a single server in Stockholm. The only other companies that can touch your data are our host, our DNS provider, and — if you choose it — whoever you sign in with. The whole list is on one page and it fits in a paragraph.
Leaving takes one click
Close your account from the dashboard and it is deleted on the spot: domains, keys, history, suppression list. No email to support, no retention offer, no waiting period.
The details, including what we do keep and for how long, are in the privacy policy — written to be read, not to be survived.
Getting started
Three steps, and the first message is signed.
Most people are through this in about ten minutes, most of which is waiting for DNS.
Add your domain
We generate a signing key that exists for your domain and nothing else. The private half never leaves our servers.
Publish one DNS record
Copy the record we show you into your DNS provider. This is what lets receivers check our signature against a key you control.
Send
One API call from your app. Until the record actually resolves we refuse to send rather than quietly letting unsigned mail out under your name.
For developers
An HTTP API and nothing to install.
No SDK required and no SMTP credentials to rotate. If your language can make an HTTPS request, it can send. For Node.js, Python, Go and .NET there are official SDKs as well.
Register a domain
# Returns the DNS record to publish.
curl -X POST https://mail.misralo.com/v1/domains \
-H "Authorization: Bearer $ANNOUNCER_KEY" \
-H "Content-Type: application/json" \
-d '{"domain": "your-company.com"}'
Send a message
curl -X POST https://mail.misralo.com/v1/emails \
-H "Authorization: Bearer $ANNOUNCER_KEY" \
-H "Content-Type: application/json" \
-d '{
"from": "billing@your-company.com",
"to": "customer@example.net",
"subject": "Your receipt",
"text": "Thanks for your order."
}'
Errors are RFC 9457 problem documents. Webhooks are signed with HMAC-SHA256 so you can
prove a delivery came from us. Health is unauthenticated at
/healthz.
For agents
An agent can wire this up nearly on its own.
More and more often the thing reading the docs is not a person with a browser open. So Announcer describes itself in the formats those clients already look for: an assistant can find the API, get its own key and send a message without anyone pasting curl commands into a chat window.
It gets its own key
Through the RFC 8628 device grant — the same ceremony as
gh auth login. The agent shows you a code, you approve it
in the dashboard, and it receives a scoped key of its own. Your password never
passes through it. The whole procedure is written down for them at
auth.md.
MCP and A2A, not only REST
The same operations are an MCP server and an A2A agent, both taking that same key and granting nothing it does not already grant. Neither has a tool for minting keys, deleting a domain or opening your billing.
Instructions, not guesswork
Three written skills — send a message, verify a domain, work out why one never arrived — say what must be true first and what each refusal means. And every page here, this one included, answers in plain markdown for a client that would rather not parse a layout.
Discovery starts at llms.txt or the AI catalog, and the API is specified in OpenAPI 3.1. The one step that stays human is publishing the DNS record: nothing should be able to sign mail as your domain because a model decided it was fine.
Pricing
Free while you are getting started.
The free plan is a real plan, not a trial that expires. When you outgrow it, Pro is €19 a month with a written 99.5% uptime commitment.
See the plans