Urgent.News

What's breaking now, across thousands of outlets.

AI

I Ran 50 Emails Through AI Agents. 12 SMTP Bounces Hit.

ai, #api, #security, #sideprojects The 50-email experiment On August 12, I handed an AI agent a CSV of fifty email addresses and an SMTP tool. Thirty-eight minutes later, twelve of them had bounced. I wasn't trying to break anything. I was testing whether a local agent could handle a simple outreach task end-to-end: read a list, draft a short note, send it. The model I used was Muse Glimmer,…

On August 12, the author ran 50 emails through an AI agent using the Muse Glimmer model, an open-weights agent model from Meta. The experiment aimed to test whether the local agent could handle a simple outreach task end-to-end, from reading a list of email addresses to drafting and sending short notes.

The agent processed the CSV of email addresses and sent them out via an SMTP tool. After 38 minutes, the experiment resulted in 12 bounces, with the remaining 38 emails successfully delivered. The agent approached the task with the understanding that "send_email" was merely another function call, without considering the validity, trustworthiness, or security of the email addresses.

The author then implemented a gatekeeper system to prevent the agent from sending emails to potentially risky addresses. The gatekeeper utilized a RapidAPI email validation service, which provided a comprehensive response for each email. The response included various attributes such as whether the email was valid, disposable, free, associated with a specific provider, and if it had been involved in any breaches.

One notable example was the email "test@gmail.com", which passed the SMTP verification but failed the trust assessment due to three recorded breaches between 2014 and 2023. The gatekeeper's decision to block this email was based on the composite trust score, which indicated that the email was not trustworthy despite being deliverable according to SMTP checks.

The author emphasized that relying solely on SMTP verification for email outreach is insufficient, as it does not guarantee the safety or trustworthiness of the email addresses. The increasing autonomy of AI models and the growing potential for AI worms and malicious activity underline the need for additional security measures. By incorporating a gatekeeper that considers factors beyond SMTP, such as breach history, free email status, and provider information, the author aimed to enhance the security and reliability of AI-driven email communication workflows.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in AI

Your AI-generated post-mortem is just a fancy way of hiding the truth

I read a post on Lobste.rs last week about dreading our LLM-written incident report future, and it hit a massive nerve. We've reached a point where the moment production stops burning, our next…

  • AI-generated incident reports gloss over human aspects
  • Human elements provide valuable lessons for future incidents
  • Relying on AI undermines authentic insights and learning

From 30 Tools to 3: Designing a Token-Efficient MCP Tool Surface

Modern agentic applications rarely suffer from a lack of tools. They suffer from too many of them . As an AI agent grows, it is common to connect it to Jira, GitLab, Confluence, Sentry, Elasticsearch…

  • Introduce action discriminator as tool router
  • Consolidate domain operations into single tools
  • Group operations by semantic boundaries

More from Saturday 15 August →