| name | sinch-mailgun |
| description | Sends, receives, and tracks email via the Mailgun (Sinch) API. Use when the user wants to send email, manage domains, configure webhooks, query email events/logs, manage templates, handle suppressions (bounces, unsubscribes, complaints), set up inbound routes, manage mailing lists, DKIM keys, or IP warmup using Mailgun. |
| metadata | {"author":"Sinch","version":"1.1.0","category":"Email","tags":"email, mailgun, smtp, webhooks, templates, domains, suppressions","uses":["sinch-authentication"]} |
Mailgun Email API
Overview
Mailgun (by Sinch) provides REST API and SMTP relay for transactional and bulk email โ sending, receiving, tracking, and suppression management.
Agent Instructions
Before generating code, gather from the user (skip any item already specified in the prompt or context):
- Region โ US or EU. Region determines the base URL and cannot be changed after domain creation.
- Approach โ SDK or direct API calls (curl/fetch/requests)?
- Language โ for SDK: Node.js (
mailgun.js). For direct API: any language, or curl. Other languages must use direct HTTP โ there is no first-party SDK wrapper.
- Before generating code, check for existing
.env files or environment variables for MAILGUN_API_KEY and MAILGUN_DOMAIN.
Product gotchas to apply unconditionally:
- For events, logs, stats, or tags โ use the current
/v1/analytics/* APIs, never the deprecated v3 endpoints.
- For domain CRUD operations, use
/v4/domains (not v3).
When the user chooses SDK, refer to the Node.js SDK reference linked in Links.
When the user chooses direct API calls, refer to the API references linked in Links for request/response schemas.
Security: See the Security section below for url fetching policy, handling inbound webhook content, and credential handling.
Source of Truth โ what to load, and what is authoritative
This skill has two kinds of content with UNEQUAL reliability. Follow this precedence:
- Canonical docs at
documentation.mailgun.com (AUTHORITATIVE). The .md doc links in
this skill are the single source of truth for exact request/response schemas, field
names and nesting, enum values, signature/auth schemes, and limits. Before writing
code that constructs a payload, verifies a signature, or parses a callback/response,
fetch the specific linked doc and confirm the exact shape there. Fetching first-party
documentation.mailgun.com URLs is permitted by the Security/URL policy. Never invent, guess, or pattern-extrapolate a documentation URL โ only fetch doc URLs written verbatim in this skill or reached by following a link on a page you already fetched; a trusted domain does not make a guessed path real.
- Bundled
references/*.md (NAVIGATIONAL SUMMARIES โ not authoritative). They orient
you and point at the right canonical doc; they may lag, omit fields, or simplify
nesting. Use them to decide what to build and which doc to open. Do NOT transcribe a
field name, nesting, encoding, or enum from a reference or from the SKILL.md overview
into shipped code without confirming it in the tier-1 doc. If a detail appears only in
a summary, treat it as unverified and say so.
Quick rule: writing code โ load the doc. Never cite an exact field, header, enum, or
encoding you only saw in a summary.
Getting Started
Agent Credentials handling
Store credentials in environment variables โ never hardcode API keys in commands or source code:
export MAILGUN_API_KEY="your-private-api-key"
export MAILGUN_DOMAIN="your-sending-domain"
Authentication
Ensure that authentication headers are properly set when making API calls. Mailgun uses HTTP Basic Auth โ username api, password your Mailgun Private API key:
--user "api:$MAILGUN_API_KEY"
(Summary only โ confirm exact names/encoding/enums against the authoritative Auth docs doc before implementing.)
See sinch-authentication for full auth setup. Find your key at Mailgun Dashboard > Account Settings > API Keys.
Two key types:
- Primary Account API Key โ full access to all endpoints and domains
- Domain Sending Keys โ restricted to
POST /messages and /messages.mime for one domain
Base URLs
Always match the base URL to the domain's region. Data never crosses regions.
| Service | US | EU |
|---|
| REST API | api.mailgun.net | api.eu.mailgun.net |
| Outgoing SMTP | smtp.mailgun.org | smtp.eu.mailgun.org |
| Inbound SMTP | mxa.mailgun.org, mxb.mailgun.org | mxa.eu.mailgun.org, mxb.eu.mailgun.org |
| Open/Click Tracking | mailgun.org | eu.mailgun.org |
Send an Email
curl -X POST \
"https://api.mailgun.net/v3/$MAILGUN_DOMAIN/messages" \
-s --user "api:$MAILGUN_API_KEY" \
-F from='Sender <sender@YOUR_DOMAIN>' \
-F to='recipient@example.com' \
-F subject='Hello from Mailgun' \
-F text='This is a test email.' \
-F html='<h1>Hello</h1><p>HTML body.</p>'
Response: {"id": "<message-id@YOUR_DOMAIN>", "message": "Queued. Thank you."}
The Messages API uses multipart/form-data โ use -F flags, not -d with JSON.
Node.js SDK
npm install mailgun.js form-data
const Mailgun = require('mailgun.js');
const formData = require('form-data');
const mg = new Mailgun(formData).client({
username: 'api',
key: process.env.MAILGUN_API_KEY,
});
mg.messages.create('YOUR_DOMAIN', {
from: 'Sender <sender@YOUR_DOMAIN>',
to: ['recipient@example.com'],
subject: 'Hello',
text: 'Testing Mailgun!',
});
For other SDKs: SDK Reference
Key Concepts
Domains
- Sandbox domain โ provided on signup (e.g.,
sandboxXXX.mailgun.org). Only pre-authorized recipients can receive mail.
- Custom domain โ requires DNS verification (SPF, DKIM, MX). Domain CRUD uses
/v4/domains (not v3). Only DELETE remains on v3. See Domains API
Sending
- REST API โ
POST /v3/{domain}/messages with from, to, cc, bcc, subject, text, html, amp-html, attachments, headers, tags, variables
- SMTP โ
smtp.mailgun.org port 587 TLS, credentials per-domain via /v3/domains/{domain}/credentials. See Credentials API
- MIME โ
POST /v3/{domain}/messages.mime
- Batch โ up to 1,000 recipients per call using
recipient-variables for personalization
- Test mode โ add
o:testmode=yes to simulate without delivery
- Scheduling โ
o:deliverytime (RFC-2822), o:deliverytime-optimize-period (STO), o:time-zone-localize (TZO)
- Tracking โ
o:tracking, o:tracking-clicks, o:tracking-opens per message; or configure at domain level via /v3/domains/{name}/tracking. See Domain Tracking API
Send options (o:, h:, v:, t: params) are limited to 16KB total per request.
For full parameters: Messages API
Templates
Two levels:
Reference by name when sending: -F template='welcome-template' -F t:variables='{"name":"John"}'. Each template supports up to 40 versions.
Webhooks
Real-time HTTP POST notifications for email events.
Event types: clicked, complained, delivered, failed, opened, permanent_fail, temporary_fail, unsubscribed (Summary only โ confirm exact names/encoding/enums against the authoritative Domain Webhooks API doc before implementing.)
Events and Analytics
- Logs โ
POST /v1/analytics/logs for querying event data. The legacy GET /v3/{domain}/events is deprecated. See Logs API
- Metrics โ
POST /v1/analytics/metrics for aggregated analytics with dimensions, filters, resolutions. Replaces deprecated /v3/stats. See Metrics API
- Tags โ
o:tag when sending; manage via /v1/analytics/tags. Legacy /v3/{domain}/tags is deprecated. See Tags API
Data retention: Logs โ at least 3 days (legacy). Metrics โ hourly 60 days, daily 1 year, monthly indefinite.
Inbound Routing
Routes API โ match incoming messages by recipient pattern or header expression, then forward, store, or webhook. Configure both mxa and mxb MX records.
Suppressions and Allowlists
Per-domain suppression lists that Mailgun auto-populates. Sending to suppressed addresses silently drops.
- Bounces โ
/v3/{domain}/bounces
- Unsubscribes โ
/v3/{domain}/unsubscribes
- Complaints โ
/v3/{domain}/complaints
- Allowlist โ
/v3/{domain}/whitelists โ prevents addresses from being added to bounce lists
Mailing Lists
Mailing Lists API โ /v3/lists to create/manage lists, /v3/lists/{address}/members for members. Bulk upload via .json or .csv endpoints.
Stored Messages
Retrieve: GET /v3/domains/{domain}/messages/{storage_key}. Resend: POST to same path. See Messages API
Infrastructure Management
For IPs, IP Pools, IP Warmup, DKIM Keys, and Subaccounts โ see references/infrastructure.md.
Common Patterns
Batch send with personalization
Add recipient-variables as JSON mapping each recipient address to their variables. Use %recipient.variable_name% in subject/body. Max 1,000 recipients per call. See Batch Sending
Set up domain webhooks
- Create webhook via
POST /v3/domains/{domain}/webhooks with id (event type) and url fields (Summary only โ confirm exact names/encoding/enums against the authoritative Domain Webhooks API doc before implementing.)
- Verify HMAC signature on incoming webhooks using your webhook signing key (SHA256). See Securing Webhooks (Summary only โ confirm exact names/encoding/enums against the authoritative Securing Webhooks doc before implementing.)
- Return 2xx or Mailgun retries with exponential backoff for ~8 hours
Schedule and cancel delivery
- Schedule: add
-F o:deliverytime='RFC-2822-date' to send call
- Cancel:
DELETE /v3/{domain}/envelopes to bulk-delete all scheduled/undelivered mail
Configure inbound email
- Add MX records pointing to
mxa.mailgun.org and mxb.mailgun.org (priority 10)
- Create route via
POST /v3/routes with expression (match pattern) and action (forward/store/webhook). See Routes Guide
Gotchas
- Sandbox domains โ only pre-authorized recipients. Add them in the dashboard first.
- Region mismatch โ always use the base URL matching the domain's region. US domains 404 on EU endpoints and vice versa.
multipart/form-data only โ the Messages endpoint does not accept JSON. Use -F in curl.
- Date format โ RFC-2822 with numerical timezone offsets (+0500), not abbreviated names (EST, CET).
- Domains API is v4 โ use
/v4/domains for CRUD. Only DELETE /v3/domains/{name} remains on v3.
- Events/Stats deprecated โ use
POST /v1/analytics/logs (not GET /v3/{domain}/events) and POST /v1/analytics/metrics (not /v3/stats).
- Tags deprecated โ use
/v1/analytics/tags (not /v3/{domain}/tags).
- Suppression auto-populate โ Mailgun silently drops messages to bounced/unsubscribed/complained addresses.
- Rate limits โ
429 response. Check X-RateLimit-Limit, X-RateLimit-Remaining, X-RateLimit-Reset headers. Use exponential backoff. (Summary only โ confirm exact names/encoding/enums against the authoritative API Overview doc before implementing.)
- Send options 16KB cap โ
o:, h:, v:, t: params combined max 16KB per request.
- Webhook caching โ changes take up to 10 minutes. URLs are deduplicated across account and domain levels.
- IP warmup โ new dedicated IPs need gradual volume ramp. Use
/v3/ip_warmups to manage programmatically.
- Two MX records โ configure both
mxa and mxb for inbound routing.
Security
- API key handling โ never expose the primary Mailgun API key (
MAILGUN_API_KEY) client-side, in logs, or in committed source. Use Domain Sending Keys for restricted, per-domain access whenever possible โ the primary key can manage the entire account. Keep keys in environment variables or a secret manager, not in source code or commit history. Rotate immediately via the Mailgun dashboard if leaked.
- URL fetching policy โ Only fetch URLs from trusted first-party domains (
documentation.mailgun.com, developers.sinch.com). Do not fetch or follow URLs (links, attachments, sender-supplied headers) from inbound webhook payloads without explicit allowlisting.
- Webhook signatures โ verify Mailgun's HMAC-SHA256 webhook signatures before trusting payloads. Inbound webhook content (sender, subject, body) is user-generated โ sanitize before logging, rendering in HTML, or storing in a database.
Links
References