AI code editor
Updated
Add email to your Cursor app with Lumail
Cursor writes the code; Lumail sends the email from your own domain. Give the agent a prompt with the rules it tends to get wrong, keep the key in .env, and connect the Lumail MCP server so the agent can check domains and drafts without leaving the editor.
TL;DR
lumail.io/integration/install, installs the lumail package, creates a server-only client that reads LUMAIL_API_KEY from .env, and sends with lumail.emails.send({ from, to, subject, html }) plus an idempotency key. Add https://lumail.io/mcp to .cursor/mcp.json for the MCP tools.1. Prompt Cursor
Open the agent in Cursor and paste this. The last rule sends it to Lumail's machine-readable install guide, which detects your framework and wires the client the same way the guides on this site do.
2. Put the API key in the right place
Create a token in Lumail under API tokens; it starts with lum_ and belongs to one organization. Put it in .env at the project root, check that .env is in .gitignore, and commit only a placeholder in .env.example.
Cursor indexes your project, so if you keep secrets out of the agent's context, list .env in .cursorignore as well. The code reads the variable at runtime; the agent never needs the real value.
3. The code Cursor should generate
Whatever framework you use, the result should look like this: one server-only module that creates the client once, and a function that sends with an idempotency key and checks error. If the agent produced something different, the next sections tell you what to push back on.
For framework-specific code, compare against the Next.js, Node.js and TanStack Start guides.
4. Lumail MCP server and agent plugins
The Lumail MCP server lets Cursor's agent read your organization: domains and their DNS status, subscribers, campaigns and drafts. The OAuth endpoint https://lumail.io/mcp can read and write drafts but has no send or delete tools, which is the safe default inside an editor.
Add it per project in .cursor/mcp.json, approve the OAuth prompt, and keep one Lumail organization per project. Do not register the same URL twice in one scope. npx lumail setup can write this config for you.
- Lumail MCP in Cursor - Step-by-step setup and the tool list.
- Send a newsletter from Cursor - A full playbook using the MCP tools.
- Lumail for AI agents - Every way an agent can work with Lumail.
- In-app integration - One prompt that wires Lumail into a codebase.
- Claude Code plugin - MCP server and skill for Claude Code.
- Codex plugin - MCP server and skill for OpenAI Codex.
- ChatGPT app - Drive Lumail from a ChatGPT conversation.
- Lumail CLI - Terminal access for scripts and agents.
5. Verify your sending domain
Lumail only sends from a domain you have verified. Add the domain in your organization's Domains settings, then publish the SPF, DKIM and DMARC records it shows at your DNS provider. Until the domain verifies, every send fails with an error saying the domain is not authorized or verified.
Use a subdomain such as mail.yourdomain.com if your root domain already sends from another provider. Start DMARC at p=none, then tighten it once reports look clean.
- Email domains - Add a domain and the SPF, DKIM and DMARC records.
- Add a DMARC record - Publish a policy, then tighten it safely.
- Mail tester - Send a real email and check authentication and spam signals.
Common pitfalls
- Two configs for one server. Registering
https://lumail.io/mcpin both the global and projectmcp.jsoncan connect the agent to the wrong organization. Keep one entry per scope. - Client-side sends. If the AI imports
lumailin a React component or usesfetchto the Lumail API from the browser, the key ships to every visitor. Move it to a server route or function and rotate the token. - Unverified `from` domain. Sends from a domain that is not verified in the same organization are rejected with a 400 that names the domain. Verify it first, or use the exact address Lumail shows you.
- Treating `{ error }` as an exception. The SDK never throws on HTTP errors. Code that only wraps the call in
try/catchsilently drops failures. - Duplicate emails on retry. Without an idempotency key, a retried request or double-clicked button can send twice.
Frequently asked questions
Does Cursor need the Lumail MCP server to send email from my app?
No. Your app sends email through the lumail SDK or REST API with an API token. The MCP server is for the agent itself: checking domain status, reading subscribers and preparing drafts while you build.
Can Cursor's agent send emails through MCP?
Not through the OAuth endpoint at https://lumail.io/mcp, which has no send or delete tools. The token endpoint at https://lumail.io/api/mcp/sse exposes the full tool set, so only use it when you want the agent to be able to send.
Where should the API key live in a Cursor project?
In .env, read with process.env.LUMAIL_API_KEY in server code only. Keep .env git-ignored, add it to .cursorignore if you do not want it in the agent's context, and set the same variable on your host.
What is lumail.io/integration/install?
A plain-text install guide written for coding agents. It tells the agent how to detect your framework, install the SDK, create the client and send a first email, so the prompt stays short.
How do I test without emailing real users?
Send to fixture addresses such as [email protected] or any .test domain. Lumail runs the full send path and returns an id, but never delivers the message.
Keep building
- AI code editorAdd email to your Windsurf appA Cascade prompt for the Lumail SDK, the key in .env, and the Lumail MCP server in mcp_config.json.
- AI app builderAdd email to your Lovable appA Supabase Edge Function that sends with Lumail, with the API key stored as a function secret.
- AI app builderAdd email to your Bolt appA server route or function that sends with Lumail, with the key in .env and never behind VITE_.
- GuideSend emails from Next.jsThe hand-written version of what v0 should generate.
- GuideSend emails from Node.jsScripts, Express and batch sends.
- DocsSDK for AI agentsThe SDK reference written for coding agents.
- DocsTest-mode recipientsFixture addresses that never send real email.
- Free toolMail testerCheck SPF, DKIM, DMARC and spam signals on a real send.
Ship email from your Cursor app today.
3,000 emails a month free. Transactional and marketing email on one verified domain, with unlimited subscribers on every plan.