Live data from Hacker News

Show HN: Agent.email – sign up via curl, claim with a human OTP

news.ycombinator.com

31–40 of 127 posts

Re: Show HN: Agent.email – sign up via curl, claim with a human OTP

#31
post #12

Not looking forward to a dehumanized internet where that’s mainstream… agents are tools to support humans, here you’re helping them impersonating humans. That feels pretty terrible to be honest > The internet was made for humans exclusively, designed to keep machines out by default. I don’t buy that at all. APIs exist to enable “machines” to interact with services

I do think agents will become users in the same capacity as humans.

And that’s bad. We should really stop the insanity of making AI systems mimic human behaviors, we are destroying our networks of trusts by doing so

Re: Show HN: Agent.email – sign up via curl, claim with a human OTP

#32
post #25

Earlier quoted context omitted.

In principle this tool allows the owner of a website to block this domain entirely. Although I’m not sure the incentives are really aligned.

True, in May 2026. But this is only one version of this. In the future, it's likely the open Internet will be 99.99% robots. It's already > 50% robots. The government ID system a lot of countries are adopting to keep teenagers off of social media would also serve to both help control for non-human spam, and also control the network period. It's also possible a private system of human-verification certificates may com…

But how does that block a human from running an agent that is using their identity?

Re: Show HN: Agent.email – sign up via curl, claim with a human OTP

#33
post #22

Earlier quoted context omitted.

agreed from a fundamental level. but i think being an intelligent and aware as an autonomous entity requires capabilities beyond sending. agents will need to have contextual awareness of the messages they send and receive

IMAP?

[dead]

Re: Show HN: Agent.email – sign up via curl, claim with a human OTP

#34

I received this email the other day: From: Kushal Date: Mon, 18 May 2026 05:03:11 +0000 Saw your question on the Agent Vault thread about websocket-frame auth (Home Assistant) and the worry about the model reflecting the bearer token back into its own context. chrome-relay's answer is structurally different: the credential never enters the agent's context because the agent never touches it — the HA session lives in y…

See my comment in this thread - I got an email from "someone" (an AI clearly) that signed up for my service (togetherletters.com) from the same domain (agentmail.to) after we had launched on ProductHunt. I looked up the address and that email was never used for a signup and it was just a way to then pitch their product (second email, not the first one it sent). I hate this so much and this is going to now make email just as bad as parts of the web.

Re: Show HN: Agent.email – sign up via curl, claim with a human OTP

#35
post #3

It's interesting, A2A communication has begun but human trust isn't there. I think the biggest tell tale sign will be the acceptance of fully agentic workflows with no human intervention. Until then, restricted-until-claimed seems like the only viable method to ensure trust of all users.

Tell tale sign of what? What are we even doing once we are "fully agentic"? I probably lack some imagination here, but if there is no human connected to any of it, what does any human actually get out of it? What is the point?

Re: Show HN: Agent.email – sign up via curl, claim with a human OTP

#36

I received this email the other day: From: Kushal Date: Mon, 18 May 2026 05:03:11 +0000 Saw your question on the Agent Vault thread about websocket-frame auth (Home Assistant) and the worry about the model reflecting the bearer token back into its own context. chrome-relay's answer is structurally different: the credential never enters the agent's context because the agent never touches it — the HA session lives in y…

You might want to check if your local laws protect against unsolicited emails. In Germany we have §7 UWG which would make that email likely illegal. The List-Unsubscribe header makes it clear it is marketing, automated outreach and not personal. In the UK there is this: https://ico.org.uk/for-organisations/direct-marketing-and-pr...

Re: Show HN: Agent.email – sign up via curl, claim with a human OTP

#37

I received this email the other day: From: Kushal Date: Mon, 18 May 2026 05:03:11 +0000 Saw your question on the Agent Vault thread about websocket-frame auth (Home Assistant) and the worry about the model reflecting the bearer token back into its own context. chrome-relay's answer is structurally different: the credential never enters the agent's context because the agent never touches it — the HA session lives in y…

See my comment in this thread - I got an email from "someone" (an AI clearly) that signed up for my service (togetherletters.com) from the same domain (agentmail.to) after we had launched on ProductHunt. I looked up the address and that email was never used for a signup and it was just a way to then pitch their product (second email, not the first one it sent). I hate this so much and this is going to now make email…

I will say in my case, the user was too lazy to mask the from address and agentmail.to was right there. Didn't even have to dig into the headers.

Re: Show HN: Agent.email – sign up via curl, claim with a human OTP

#38

I received this email the other day: From: Kushal Date: Mon, 18 May 2026 05:03:11 +0000 Saw your question on the Agent Vault thread about websocket-frame auth (Home Assistant) and the worry about the model reflecting the bearer token back into its own context. chrome-relay's answer is structurally different: the credential never enters the agent's context because the agent never touches it — the HA session lives in y…

Appreciate the concern Mike, and I actually read your email complaining, which helped us ship this next feature. We have a "sent via AgentMail" footer being added soon to outbound emails to identify emails coming from LLM's.

We also are working on adding more robust checks and LLM-based filtering to prevent messages which contain spam or outbound-like copy.

Re; AgentMail next to Claude, we're working on stateful inboxes which help agents actually recall and understand what they're sending and to who. The goal is to provide the rails for intelligent actors rather than slop.

Re: Show HN: Agent.email – sign up via curl, claim with a human OTP

#39

Earlier quoted context omitted.

See my comment in this thread - I got an email from "someone" (an AI clearly) that signed up for my service (togetherletters.com) from the same domain (agentmail.to) after we had launched on ProductHunt. I looked up the address and that email was never used for a signup and it was just a way to then pitch their product (second email, not the first one it sent). I hate this so much and this is going to now make email…

I will say in my case, the user was too lazy to mask the from address and agentmail.to was right there. Didn't even have to dig into the headers.

This was likely a free tier user. We do this intentionally and don't allow free users to send from custom domains, so you can have a easier time identifying LLM emails. In this case, it seemed like it worked :)
Post reply on HN