Skip to main content

About Gork Mail

Gork Mail is programmable email infrastructure for AI agents. We build the piece that lets a model act on the world without borrowing a human’s identity to do it.

Why this exists

Software agents need email for the same reason people do: to be told something, to prove who they are, and to reach someone who has never heard of them. Verifying an account, closing a support ticket, and following up with a vendor all still run over email.

The usual answer is to point an agent at a shared human mailbox and hope. That fails in specific ways. Replies arrive addressed to a person, so the agent cannot tell its own thread from anyone else’s. Forwarding rules lose headers, so threading breaks. And an inbox with no reputation history of its own gets filtered the moment it starts sending.

Gork gives each agent a real, isolated identity with its own sending reputation — and exposes it over a REST API, a set of signed webhooks, and 13 Model Context Protocol tools so the same capability is reachable from an HTTP client, a webhook handler, or a tool-using model.

What we run on

Four systems, each doing one job. Here is the actual stack, not a summary of it.

Amazon SES
Outbound and inbound mail
SES is the only transport. Outbound goes through the SES v2 API; inbound arrives through an SES receipt rule that writes to S3 and fans out over SNS. Keeping a single provider behind one EmailProvider interface is deliberate — the reliability logic never couples to SDK specifics, but there is exactly one implementation to reason about.
Cloudflare Workers
API runtime and edge delivery
Both the API and this site run on Workers. Queues handle inbound mail and webhook delivery with dead-letter queues, so a failing endpoint retries with backoff instead of dropping an event. A cron sweep retries stuck deliveries every 10 minutes and clears 30-day-old data daily.
Neon PostgreSQL
Tenancy, messages and metering
Serverless Postgres holding organizations, inboxes, messages and 64-bit counters. Tenant isolation is enforced in the application layer: every query resolves the caller’s organization dynamically through organization_members. There is no hardcoded default org to fall back on.
Cloudflare R2
MIME archives and attachments
Raw MIME and oversized HTML bodies are offloaded to object storage with no egress charge. Keeping full threads retrievable is what makes an inbox useful to an agent that wakes up days later.

How we build it

Untrusted payloads by default
Email content is hostile input. Inbound HTML is sanitized server-side — scripts, frames, inline event handlers and javascript: URLs are stripped — payloads are capped at 15 MB, and nested multipart and archive expansion is guarded against. Signed webhooks are verified with HMAC-SHA256 before any handler acts.
Versioned and backwards-compatible
Every public endpoint lives under /v1. Adding capability never means breaking a client, because an agent that provisioned an inbox six months ago still works against today’s API.
Guardrails against runaway agents
An autonomous loop that emails itself can burn a sender reputation in an afternoon. Gork caps daily sends per plan, pauses a workspace that reaches 50 new recipients in 10 minutes, suppresses addresses that bounce or complain, and suspends sending when trailing complaints pass 0.3% or hard bounces pass 5%.
Secrets are never stored raw
API keys are persisted only as salted SHA-256 hashes. A database leak yields nothing usable, and webhook secrets are shown once at creation.

The product in numbers

PropertyValue
Native MCP tools13
Webhook event types5
Public API versions/v1
Inbound payload cap15 MB
Recipients per message50
Webhook retry attempts5

Talk to us

Support questions go to support@gork.email, and anything about volume, custom domains or invoicing to sales@gork.email. Security reports have their own address and disclosure policy on the security page.

The rest of the surface is public and worth reading directly: the feature set, pricing, the subprocessor list, and what shipped and when.