Mailsac vs Mailinator
Mailsac vs Mailinator
Mailinator alternative for disposable inboxes and email testing
Mailsac does the two jobs people use Mailinator for. Any @mailsac.com address is a free public inbox you can read without an account. For QA and engineering teams, private test domains and a REST API check the sign-up confirmations, password resets and one-time codes your app sends. Here is how the two compare, where Mailinator is the better fit, and how to move existing tests.
Reviewed September 2026 against both vendors’ public pricing and documentation.
Just need a throwaway address? Send mail to any name@mailsac.com and read it at mailsac.com/inbox/name, no account needed. The free plan adds an API key, one private address and 1,500 Ops a month, with no expiry. Jump to the full comparison or see how to move from Mailinator.
At a glance
Free public inbox
Mailsac Any @mailsac.com address; mail kept up to 4 days
Mailinator Any @mailinator.com address; mail deleted after a few hours
Free API access
Mailsac Free account: API key and 1,500 Ops a month
Mailinator Verified Pro: $0 after verification, individuals only, 60 reads a day
Entry paid plan
Mailsac Indie, $18 a month or $169 a year
Mailinator Business, $99 a month, or $79 a month billed yearly
Private test domain
Mailsac Every paid plan, from $18 a month; one private address free
Mailinator Verified Pro (with limits) and every paid plan
SAML single sign-on
Mailsac Business, $89 a month
Mailinator Pricing page lists it on Business; docs say Enterprise
SMS, TOTP and test identity provider
Mailsac Not offered
Mailinator Yes; SMS numbers cost extra
Which should you choose?
Both work the same way at heart: every address on a domain already exists, so there is nothing to create before your app sends. Both have a public domain anyone can read and private domains for paying customers, and both are receive-only. They differ in what the free tiers include, how usage is counted, whether mail is pushed to you, and what else they test.
Choose Mailsac if
- You want a public inbox that keeps mail for days, not hours. Public
@mailsac.commessages are kept for up to 4 days (busy inboxes recycle sooner) and attachments can be downloaded over the API. Public Mailinator messages are deleted after a few hours and attachments are stripped. - You want to read inboxes from a script without paying. A free Mailsac account includes an API key and 1,500 Ops a month. Mailinator’s public system has no API, and its $0 Verified Pro tier is for independent users only, with 60 reads a day.
- Your team needs a private domain at a published price. Indie ($18 a month) includes one domain; Business ($89 a month) includes 5 domains, 5 users and SAML single sign-on. Mailinator’s Business is $99 a month, or $79 a month billed yearly, with 1 domain and 5 seats.
- You would rather be pushed than poll. Webhooks, Slack forwarding and WebSockets are on every Mailsac plan. Mailinator forwards mail to a webhook through routing rules and has no WebSocket API for messages.
- You want to capture a staging app’s outgoing mail over SMTP, with no DNS changes and no real sending provider in the loop. Email Capture is on every plan. Mailinator only receives mail delivered to its domains.
- Procurement wants published prices all the way up: Business+ at $1,900 a year or Enterprise from $7,500 a year, by invoice, purchase order or resellers SHI and SoftwareOne. Mailinator’s Enterprise starts at $699 a month with a custom quote.
Choose Mailinator if
- You also test SMS codes with real phone numbers. Mailinator rents 10-digit numbers on Business and up, at $50 a month or $500 a year per number with 500 messages a month. Mailsac is email only.
- You test SSO or TOTP logins. Mailinator’s Universal IDP is a test OpenID Connect identity provider, and its Authenticator feature reads TOTP codes. Mailsac has neither.
- You want an official client in Java, C#, Go, Ruby or Python, a CLI, or an MCP server for AI-agent workflows. Mailinator documents all of these. Mailsac has a JavaScript/TypeScript client and a Cypress plugin; other languages use the REST API.
- You inject messages by HTTP POST instead of sending email, for example from Twilio or Zapier, so email, SMS and webhook payloads land in the same inboxes and rules. Mailsac only accepts mail over SMTP.
- You are one person and Verified Pro’s limits suit you: $0 after identity verification, with a private domain, API access and routing rules, capped at 60 reads a day and 10 MB of storage.
- Your team already uses Mailinator for throwaway addresses and wants the private version from the same vendor. Business comes with a two-week free trial.
Mailsac vs Mailinator: features and prices
Prices are list prices in US dollars, before tax, as each vendor shows them. Mailsac counts Ops; Mailinator counts emails received per month, per day and per second, plus storage in megabytes. The units are not directly comparable, so compare by the job you need done.
| Mailsac | Mailinator | |
|---|---|---|
| Plans and prices | ||
| Free, no account | Any @mailsac.com inbox, readable by anyone at mailsac.com/inbox/<name> |
Any @mailinator.com inbox, readable by anyone on mailinator.com. No API, webhooks or attachments |
| Free with an account | Free plan with no expiry: API key, 1 private address, 50 stored messages, 1,500 Ops a month, WebSocket and webhook forwarding on the private address | Verified Pro: $0 after identity verification, for independent users only. 1 private domain, API, webhooks and routing rules, 10 MB storage, 60 reads a day, 1,000 emails a month on the plan page (the annual pricing page says 2,000). Companies with 3 or more accounts may be required to pay |
| Entry paid plan | Indie: $18 a month, or $169 a year. 25,000 Ops, 1 user, 1 custom domain, 50 private addresses, 1,000 stored messages | Business: $99 a month, or $79 a month billed yearly. 100,000 emails a month, 3,333 a day, 20 a second, 5 team seats, 1 private domain, 50 MB storage, attachments. Two-week free trial |
| Team plan | Business: $89 a month, or $840 a year. 500,000 Ops, 5 users, 5 domains, SAML single sign-on, multiple named API keys. Business+: $199 a month, or $1,900 a year. 2 million Ops, 10 users, 10 domains | Business Plus: $199 a month, or $159 a month billed yearly. 300,000 emails a month, 10,000 a day, 100 a second, 10 team seats, 3 private domains, 100 MB storage, phone support |
| Enterprise | From $7,500 a year (2 million Ops a month), or $799 a month by card, with a published ladder up to 20 million Ops. 25 users. Invoice, purchase order, ACH or wire; also sold by resellers SHI and SoftwareOne | From $699 a month, custom quote. 3 million or more emails a month, up to 500 a second, 5 or more domains, custom seats and storage, load testing, custom terms |
| Yearly billing | Yearly prices published; about 20% less than paying monthly | Monthly and yearly prices published; yearly is 20% less |
| What usage is counted | Ops. One Op is an API call, a message received at a private address or domain, or a webhook, Slack or WebSocket push. Mail to public @mailsac.com inboxes is not counted, but reading it over the API is. A polled test typically uses 3 to 6 Ops; pushed mail uses 1 |
Emails received, capped per month, per day and per second, plus storage in megabytes. API reads are rate-limited (10 a second and 60 a day on Verified Pro) rather than counted monthly |
| Public inboxes | ||
| Address | Anything @mailsac.com. Nothing to create |
Anything @mailinator.com, up to 50 characters. Nothing to create |
| Reading it | On the website without an account, or GET /api/addresses/{email}/messages with a free API key |
On the website without an account. The API reads public inboxes only with a subscription token |
| How long mail stays | Up to 4 days; only the most recent few messages in each inbox are kept, so busy inboxes recycle sooner. Star a message to keep it | A few hours, then deleted for good |
| Attachments | Kept; download them over the API (not shown on the website for public addresses) | Not delivered, or stripped before delivery |
| Limits | Public addresses are throttled at a lower threshold than paid domains | “Usage limits apply”; rate-limited; may be filtered or blocked for abuse prevention |
| Private domains and addresses | ||
| A private address without a domain | Yes. 1 on Free, 50 on Indie, 250 on Business, 500 on Business+. Reserve one with POST /api/addresses/{email} |
No. Privacy comes with a private domain |
| Domain with no DNS changes | A yourteam.msdc.co subdomain you name, ready immediately, on Indie and up |
A you-yourcompany.testinator.com subdomain assigned when the subscription starts, on Verified Pro and up |
| Your own domain | Add a TXT record to verify ownership, then MX records | Point the domain’s MX records at Mailinator |
| Domains included | 1 on Indie, 5 on Business, 10 on Business+, 12 or more on Enterprise. Extra domains $7 a month | 1 on Verified Pro and Business, 3 on Business Plus, 5 or more on Enterprise |
| Whole-domain view | Unified inbox on the website; GET /api/domains/{domain}/messages; delete all mail on a domain |
“Super inbox” of every message to the domain; * as the inbox in the API; delete by domain |
| Who can read private mail | Your account and team users; a named API key per person or pipeline on Business and up | Team members you add: 1 on Verified Pro, 5 on Business, 10 on Business Plus |
| API and test automation | ||
| Base URL and auth | https://mailsac.com/api with a Mailsac-Key header (or _mailsacKey query parameter) |
https://api.mailinator.com/api/v2 with the team token in an Authorization header (or token query parameter) |
| Official client libraries | @mailsac/api (JavaScript/TypeScript) and the @mailsac/cypress plugin. Any other language over REST |
Java, JavaScript (mailinator-client on npm), C#, Go, Ruby and Python, plus a CLI and an MCP server. Guides for Cypress, Playwright and Postman |
| Waiting for new mail | Poll GET /api/addresses/{email}/messages (newest first), or have a private address or domain push each message to a webhook or WebSocket. The Cypress plugin waits for you |
Poll GET /domains/{domain}/inboxes/{inbox}; the docs recommend polling for tests. A routing rule can POST each message to your webhook |
| Codes and links | Every message carries a links array of URLs found in its text and HTML. Plain text at /api/text/. Codes are matched in your test, or with extractCode in the Cypress plugin |
GET .../messages/{id}/links returns the URLs. The body is in the message’s parts[]; codes are matched in your test |
| Inject a message without sending email | Not offered. Mail arrives over SMTP, or through Email Capture | POST /domains/{domain}/inboxes/{inbox} with JSON; inbound webhook URLs with separate webhook tokens; a Twilio mapping |
| Rate limits | No per-second API limit published. Inbound mail to paid domains is rarely throttled; Business and up add an IP allowlist so your senders are never throttled | Receiving is capped at 10, 20, 100 or 500 emails a second by plan, with daily caps. Verified Pro allows 10 API reads a second and 60 a day |
| Retention and storage | ||
| Private mail retention | Kept up to the plan’s stored-message limit: 50 on Free, 1,000 on Indie, 5,000 on Business, 10,000 on Business+. The oldest are recycled after that; starred messages are kept. More storage $10 a month per 5,000 | Kept until the plan’s storage fills: 10 MB on Verified Pro, 50 MB on Business, 100 MB on Business Plus, custom on Enterprise. New mail then pushes out the oldest |
| Logs | Message logs for 20 minutes on Free and Indie, 2 weeks or more on Business and up | An SMTP transaction log is stored with each message; subscriber usage activity is kept up to 6 weeks |
| Webhooks, WebSockets and SMTP capture | ||
| Webhooks and Slack | Every plan, per private address or for a whole custom domain; Slack forwarding too | Routing rules on Verified Pro and up: match the destination inbox (exact or prefix) and POST the message as JSON to a URL, or drop it. The website also describes rules that click every link |
| WebSockets | Per address on every plan; for a whole domain on Business and up. Endpoint wss://sock.mailsac.com/incoming-messages |
No WebSocket API for messages. The web UI has a WebSocket-backed streaming feed of message summaries |
| Inbound webhooks | Not offered | Yes, into private domains, with tokens separate from the API token |
| SMTP capture for staging | Email Capture on every plan: point a staging app’s SMTP at capture.mailsac.com:5587 (STARTTLS; your username and API key). Mail to any recipient lands in that recipient’s Mailsac inbox. Public unless private capture is on or the recipient is on your custom domain |
Not offered. Mail has to be delivered to a Mailinator domain |
| Sending mail | Receive only. New mail can be forwarded to a webhook, WebSocket, Slack or another Mailsac address | Receive only |
| Beyond email | ||
| SMS and phone numbers | Not offered | Business and up. Real 10-digit numbers procured on request: $50 a month or $500 a year per number, including 500 messages a month. Read with the same inbox endpoints |
| 2FA and SSO testing | Not offered | Authenticator reads TOTP codes; Universal IDP is a test OpenID Connect identity provider, in public mode at idp.mailinator.com or with your private domain |
| Load testing | Business and up: a temporary domain active for 8 hours; each email counts as an Op. Burst throughput on request on Enterprise | Enterprise only |
| Team, security and buying | ||
| Users | 1 on Free and Indie, 5 on Business, 10 on Business+, 25 or more on Enterprise | 1 on Verified Pro, 5 on Business, 10 on Business Plus, custom on Enterprise |
| Single sign-on | SAML on Business and up (Okta, Azure AD, Google) | SAML. The pricing page lists “Supports SSO” on Business and up; the documentation and security page say SSO is for Enterprise subscriptions. Confirm with their sales team |
| Hosting and certifications | Runs on AWS in the United States. No certification published. Enterprise includes help with SIG and CyberGRX questionnaires | Hosted at Linode and DigitalOcean data centres in the United States, whose provider certifications include SOC 2; yearly penetration tests; security documentation on request. No company-level SOC 2 report stated |
| Billing | Card. Invoice or purchase order on annual Business+ and Enterprise; resellers SHI and SoftwareOne | Card. Pay by invoice on Business and up; custom terms on Enterprise |
Reviewed September 28, 2026. Mailinator’s plans count emails received per month, per day and per second; Mailsac’s count Ops per month, including API calls. Check each vendor’s current pricing before you buy.
Sources: Mailinator annual pricing, monthly pricing, Verified Pro, SMS testing, FAQ, security details, API documentation and feature documentation. Mailsac pricing, API reference, message storage, custom domains and Email Capture.
Moving from Mailinator
A Mailinator test sends to an inbox on your private domain, polls the inbox endpoint, fetches the message by ID and reads its parts or links. A Mailsac test has the same shape. What changes is the paths, the auth header and the message object. Here is the mapping for the calls in the Mailinator API documentation.
| Mailsac | Mailinator | |
|---|---|---|
| Authenticate | Send Mailsac-Key: $MAILSAC_API_KEY on every request to https://mailsac.com/api |
Send Authorization: $MAILINATOR_TOKEN (or ?token=) on every request to https://api.mailinator.com/api/v2 |
| Get a test address | Make one up: signup-${Date.now()}@yourteam.msdc.co, or @mailsac.com for a public inbox. Nothing to create |
Make one up: signup-${Date.now()}@yourteam.testinator.com. Nothing to create |
| List an inbox | GET /api/addresses/{email}/messages. A bare array, newest first; each item has _id, subject, received and links |
GET /domains/{domain}/inboxes/{inbox}. An object with msgs[]; each item has id, subject and time |
| List a whole domain | GET /api/domains/{domain}/messages |
GET /domains/{domain}/inboxes/*, or private as the domain for all your domains |
| Read the body | GET /api/text/{email}/{messageId} for plain text; /api/body/ for sanitized HTML; /api/dirty/ for the original HTML; /api/raw/ for the whole SMTP message |
GET /domains/{domain}/inboxes/{inbox}/messages/{id}, then read parts[], each with headers and body |
| Extract links | The links array on GET /api/addresses/{email}/messages/{messageId}, found in both text and HTML |
GET .../messages/{id}/links |
| Extract a code | Match it in your test: text.match(/\b\d{6}\b/). In Cypress, extractCode from @mailsac/cypress |
Match it in your test against the text part, as the Mailinator guides do |
| Attachments | GET /api/addresses/{email}/messages/{messageId}/attachments, then /attachments/{md5} to download |
GET .../messages/{id}/attachments, then /attachments/{name} to download |
| Clean up | DELETE /api/addresses/{email}/messages/{messageId}; DELETE /api/addresses/{email}/messages for an inbox; POST /api/domains/{domain}/delete-all-domain-mail for a domain |
DELETE .../inboxes/{inbox}/messages/{id}; DELETE .../inboxes/{inbox} for an inbox; DELETE /domains/{domain}/inboxes/ for a domain |
| Push to a webhook | PUT /api/private-address-forwarding/{email} with {"webhook": url} on a private address, or turn on forwarding for the domain in the dashboard. WebSockets: wss://sock.mailsac.com/incoming-messages |
A routing rule with a WEBHOOK action: POST /domains/{domain}/rules/ |
| Inject a message, read SMS | No equivalent. Send real mail, or capture it with Email Capture. SMS is not offered | POST /domains/{domain}/inboxes/{inbox}; GET /domains/{smsDomain}/inboxes/{number} |
The wait step in TypeScript, with no client library · Node.js 18 or later · a standalone version of the loop in tests/inbox.ts in the CI example repository
const headers = { 'Mailsac-Key': process.env.MAILSAC_API_KEY! };
const inbox = encodeURIComponent(address); // e.g. signup-1790000000000@yourteam.msdc.co
async function waitForEmail(timeoutMs = 60_000) {
const deadline = Date.now() + timeoutMs;
while (Date.now() < deadline) {
const res = await fetch(`https://mailsac.com/api/addresses/${inbox}/messages`, { headers });
const messages: Array<{ _id: string; subject: string; links?: string[] }> = await res.json();
if (messages.length) {
const m = messages[0]; // newest first
const text = await (await fetch(`https://mailsac.com/api/text/${inbox}/${m._id}`, { headers })).text();
return { id: m._id, subject: m.subject, text, links: m.links ?? [] };
}
await new Promise((r) => setTimeout(r, 2_000));
}
throw new Error(`No email for ${address} within ${timeoutMs / 1000}s`);
}
const email = await waitForEmail();
const code = email.text.match(/\b\d{6}\b/)?.[0]; // one-time code
const link = email.links.find((l) => l.includes('/verify')); // confirmation link
Two habits to keep. Mailinator’s own guides recommend a fresh inbox per test and polling against a deadline; both carry over unchanged. Use a new address for every test so parallel runs and retries never read each other’s mail, and match the message you expect rather than taking whatever is newest. The playwright-signup-ci example generates a unique address per test, matches on the subject and deletes the message afterwards; the Playwright tutorial also filters by the time the email was triggered.
Public and private inboxes
Mailsac and Mailinator share the same public model: every address on the vendor’s domain already exists, mail to it appears in an inbox anyone can open, and nobody owns the address. Mail to name@mailsac.com shows up at mailsac.com/inbox/name; mail to name@mailinator.com shows up on mailinator.com. The differences are retention and access. Mailsac keeps public mail for up to 4 days and lets you download attachments over the API; Mailinator deletes public mail after a few hours and strips attachments. Any Mailsac API key can read a public inbox; Mailinator’s API needs a subscription. Public inboxes on either service are fine for made-up data and for trying things out.
For password-reset links, codes and anything else that works on a real account, use something private. On Mailsac that is a private address (the free plan includes one) or a custom domain on Indie and up: a yourteam.msdc.co subdomain that is ready immediately, or your own domain once DNS is verified. Only your account and team can read that mail, and every address on the domain works with nothing to create first, which is the same thing a Mailinator private domain gives you. On Mailinator, privacy starts with the Verified Pro domain for individuals and the Business plan for teams.
The same rule applies to Email Capture: captured mail is public unless you turn on private capture or capture to a custom domain.
Public inboxes are for synthetic test data. If a reset link or code would work on a real account, or the email holds real personal data, use a private address or a verified private custom domain.
Frequently asked questions
Is Mailsac a free alternative to Mailinator?
Yes, for public inboxes. Send mail to any address @mailsac.com and open mailsac.com/inbox/ followed by the name; there is no account and no address to create, the same as Mailinator. A free Mailsac account adds what Mailinator’s public system does not have: an API key, one private address, and 1,500 Ops a month with no expiry.
How long does mail stay in a public inbox?
Mailsac keeps public mail for up to 4 days, though only the most recent few messages in each inbox are kept, so busy inboxes recycle sooner; starring a message keeps it. Mailinator deletes public mail after a few hours. Mail on a private Mailsac address or domain is kept up to your plan’s stored-message limit; mail on a private Mailinator domain is kept until its storage in megabytes fills.
Can I get a private test domain for free, like Mailinator’s Verified Pro?
Not a domain, but a private address: the free Mailsac plan includes one, and it can forward to a webhook, Slack or a WebSocket. A domain starts on Indie at $18 a month, or $169 a year, and includes a yourteam.msdc.co subdomain with no DNS work. Mailinator’s Verified Pro is $0 after identity verification and includes a private domain, but it is for independent users only, allows 60 reads a day, and Mailinator says companies with 3 or more accounts may be required to convert to a paid plan.
Is Mailsac a drop-in replacement for the Mailinator API?
No. The endpoints, the auth header and the message JSON are different, so the code that lists an inbox, fetches a message and reads the body needs rewriting. The mapping above covers every message call in Mailinator’s documentation. Your app and its email sending do not change; only the recipient domain and the code that reads the mail.
How do Mailsac Ops compare with Mailinator’s emails per month?
They measure different things, so there is no exact conversion. Mailinator counts emails received, with monthly, daily and per-second caps. Mailsac counts Ops: each message received at a private address or domain, each API call, and each webhook, Slack or WebSocket push. A test that polls for one email and reads it typically uses 3 to 6 Ops, and a pushed email uses 1, so Indie’s 25,000 Ops cover several thousand tests a month and Business’s 500,000 cover roughly 150,000 test emails. Mail to public @mailsac.com inboxes is not counted at all.
Does Mailsac test SMS, TOTP or SSO logins?
No. Mailsac receives email and hands it to your tests over the API, webhooks or WebSockets. Mailinator reads SMS from real phone numbers on Business and up (at an extra charge per number), reads TOTP codes with its Authenticator feature, and offers a test OpenID Connect identity provider. If those are part of your suite, Mailinator is the better fit.
Which works better in CI with Playwright or Cypress?
Both run the same trigger, wait, check loop over HTTP. Mailsac has a @mailsac/cypress plugin that waits for matching messages, verifies links and extracts one-time codes, a Playwright tutorial against the REST API, and the playwright-signup-ci example that runs in GitHub Actions and GitLab CI. Mailinator publishes Cypress, Playwright and Postman guides and official clients in six languages. What Mailsac adds for CI is push delivery: a WebSocket or webhook per address on every plan, so tests can wait on one connection instead of polling.
Try Mailsac with your next email test
Send mail to any @mailsac.com address and open the inbox, or create a free account, generate an API key and run the wait step above. Plans with a private test domain start at $18 a month.
Comparing other tools? Read Mailsac vs Mailosaur, Mailsac vs Mailtrap, Mailsac vs MailSlurp and Mailsac vs Mailpit and MailHog. New to Mailsac? See how the email testing API works.