Mailtrap Email Integration

SkillCommunication

This skill guides an agent through adding transactional email sending to an application with Mailtrap's Email API. It covers sandbox testing, domain verification, and API authentication so the agent can wire up email features and debug delivery issues. It also helps set up safe development and staging email testing.

Use Mailtrap Email Integration in Claude, ChatGPT or Ahel Desktop

Free. Sign in, add Mailtrap Email Integration and connect your AI. About a minute.

Also: Claude Code · Cursor · Codex

Then ask your AI: use the Mailtrap Email Integration skill

Details

Instructions available. Your AI can read the instructions. Execution depends on the setup they require.

Obtain a Mailtrap account and an API token with sending permissions.

Mailtrap Email IntegrationStart free

What your AI can do with it

  • Integrate Mailtrap's Email API for transactional email sending
  • Configure sandbox testing for development and staging
  • Verify a sending domain with SPF, DKIM, and DMARC records
  • Set up bearer-token authentication for the API
  • Flag anti-patterns like hardcoding tokens or using production in dev

Getting started

  1. Obtain a Mailtrap account and an API token with sending permissions.
  2. Add the API token to your application's environment configuration.
  3. Configure the Mailtrap Email API endpoint for your environment.
  4. Verify your sending domain by adding the required SPF, DKIM, and DMARC DNS records.
  5. Test email sending in the sandbox before switching to production.

What this skill tells your AI

The instructions your AI receives, as published by affaan-m/ecc in skills/mailtrap-email-integration/SKILL.md and read by ahel’s review.

Patterns for adding transactional email sending to an application using Mailtrap's Email API and Sandbox, covering authentication, environment separation, and common delivery pitfalls.

When to Activate

  • Implementing a "send email" feature (signup confirmation, password reset, notifications, receipts)
  • Debugging why emails aren't arriving in dev/staging
  • Setting up a project's first email-sending integration
  • Reviewing code that calls an email API directly without sandbox separation

Core Concepts

Sandbox vs. Production separation. Mailtrap provides a Sandbox API that captures emails without delivering them, used for dev/staging so test emails never reach real inboxes. Production sending uses a separate, verified-domain endpoint. Never point a dev environment at the production sending endpoint.

Authentication. Requests use a Bearer token in the Authorization header. Tokens are scoped per project; sandbox and production typically use different tokens.

Domain verification. Production sending requires verifying a sending domain via DNS records (SPF, DKIM, DMARC) before Mailtrap will deliver to real recipients. Skipping this causes silent delivery failures or spam-folder placement.

Code Examples

// Sending via Mailtrap's Email API (production)
async function sendEmail(to: string, subject: string, html: string) {
  const response = await fetch("https://send.api.mailtrap.io/api/send", {
    method: "POST",
    headers: {
      "Authorization": `Bearer ${process.env.MAILTRAP_API_TOKEN}`,
      "Content-Type": "application/json",
    },
    body: JSON.stringify({
      from: { email: "no-reply@yourverifieddomain.com", name: "Your App" },
      to: [{ email: to }],
      subject,
      html,
    }),
  });

  if (!response.ok) {
    throw new Error(`Email send failed: ${response.status}`);
  }
  return response.json();
}
// Same call, routed to Sandbox in non-production environments
const MAILTRAP_ENDPOINT = process.env.NODE_ENV === "production"
  ? "https://send.api.mailtrap.io/api/send"
  : `https://sandbox.api.mailtrap.io/api/send/${process.env.MAILTRAP_INBOX_ID}`;

Anti-Patterns

Anti-PatternWhy It's a ProblemInstead
Using the production sending endpoint in dev/testReal test emails reach real inboxes, risking spam complaints and leaked test dataRoute non-production environments to the Sandbox endpoint
Hardcoding API tokens in sourceCredential leak risk if committed to version controlLoad tokens from environment variables / secrets manager
Sending before domain verification completesEmails silently fail or land in spamVerify SPF/DKIM/DMARC records before enabling production sending
No retry/error handling on send failuresSilent notification failures (e.g., user never gets password reset email)Check response status, log failures, surface actionable errors

Best Practices

  • Keep sandbox and production tokens in separate environment variables, never share one token across environments
  • Verify sending domain DNS records before any production launch involving email
  • Log delivery failures with enough context to debug (recipient, template, timestamp, response code)
  • Treat email sending as a fallible network call: wrap in try/catch, never assume success

Related Skills

api-and-interface-design, security-and-hardening, ci-cd-and-automation

Signals

GitHub stars
270k
Forks
40k
Last commit
Sep 2026

Questions

How do I set up safe dev/staging email testing?
Use Mailtrap's sandbox endpoint for development and staging. Keep production credentials out of those environments and never point dev at the production endpoint.
How do I verify a sending domain?
Add the SPF, DKIM, and DMARC DNS records that Mailtrap provides for your domain, then confirm verification before sending live email.
How does API authentication work?
The skill covers bearer-token authentication. Store the token in environment configuration rather than hardcoding it in source.
Can I use this for marketing email campaigns?
No. This skill is for transactional email sending via Mailtrap's Email API, not marketing campaigns.
Advanced
Item type
skill
Key
mailtrap-email-integration
Source
github.com/affaan-m/ecc