Mailsac vs Mailisk
Mailsac vs Mailisk
Mailisk alternative for email testing in CI
Mailsac and Mailisk both receive your app’s test email at addresses that exist without setup and hand it to Playwright, Cypress or plain HTTP tests. Mailisk adds SMS and TOTP testing and an API that waits for the message. Mailsac adds public inboxes, your own domain, push delivery over webhooks and WebSockets, and retention counted in messages rather than days. Here is how they compare, where Mailisk is the better fit, and how to move existing tests.
Reviewed September 2026 against both vendors’ public pricing and documentation.
Just need an inbox right now? Send mail to any name@mailsac.com and read it at mailsac.com/inbox/name, no account needed. The free plan adds an API key, one private address and 1,500 Ops a month, with no expiry. Jump to the full comparison or see how to move from Mailisk.
At a glance
Free plan
Mailsac API key, 1 private address, 1,500 Ops a month, no expiry; public @mailsac.com inboxes need no account
Mailisk 500 received emails a month, 1-day retention, one random namespace that expires a month after creation
Entry paid plan
Mailsac Indie, $18 a month or $169 a year: 25,000 Ops, one custom domain, 1 user
Mailisk $9 a month or $90 a year: 20,000 received emails, 3-day retention, 10 namespaces, unlimited team members
Your own domain
Mailsac Every paid plan: a TXT record and MX records, or a zero-setup msdc.co subdomain
Mailisk Not documented; every address is under a namespace on mailisk.net
Getting the email
Mailsac Poll the inbox, or have it pushed to a webhook, Slack or WebSocket on every plan
Mailisk The search request waits until a matching email arrives; no webhooks or WebSockets documented
How long mail is kept
Mailsac Private mail up to a message count (1,000 on Indie), oldest recycled; public mail up to 4 days
Mailisk 1 day on Free; 3, 10 or 15 days on paid tiers; longer on request
SMS and TOTP testing
Mailsac Not offered
Mailisk Yes; one SMS number included from the $29 tier, TOTP on every paid tier
Which should you choose?
Both are built for QA and engineering teams, both give you addresses that exist before your app sends, and both have a Node client and a Cypress plugin. They differ in where the addresses live (your own domain or a public @mailsac.com inbox, versus a namespace under mailisk.net), how you get the mail (poll or push, versus an API that waits), how long it is kept, how usage is counted, and whether SMS and TOTP are in scope.
Choose Mailsac if
- You want test addresses on your own domain, or a public inbox with no account. Mailsac verifies your domain with a TXT record and MX records, or gives you a
yourteam.msdc.cosubdomain with no DNS work, and any@mailsac.comaddress is a public inbox. Mailisk addresses are always under a namespace on mailisk.net; its documentation describes no way to bring your own domain. - You would rather be pushed than poll or hold a request open. Webhooks, Slack forwarding and WebSockets are on every Mailsac plan, including Free. Mailisk documents no webhooks or WebSockets; its search endpoint waits for a match instead.
- You want mail kept until you delete it, not for a fixed number of days. Private Mailsac mail stays up to your plan’s stored-message count (1,000 on Indie, 5,000 on Business), starred messages are kept, and there are delete calls per message, per inbox and per domain. Mailisk deletes each email at its expiry, 1 day on Free and 3 to 15 days on paid tiers, and documents no delete endpoint.
- You want to capture a staging app’s outgoing mail over SMTP, with no DNS changes and no sending provider in the loop. Email Capture is on every plan. Mailisk receives only mail delivered to its namespace addresses.
- Your company buys through procurement. Business ($89 a month) includes SAML single sign-on and 5 users; annual Business+ and Enterprise take invoices and purchase orders, or go through resellers SHI and SoftwareOne, and Enterprise has a published ladder up to 20 million Ops. Mailisk’s tiers stop at 1,000,000 received emails a month, above which it says “Contact us”, and it publishes no invoice or purchase-order terms.
- You want a free plan that stays put. The Mailsac free plan does not expire. Mailisk’s free namespace expires one month after it is created, deleting its mail and releasing the subdomain, though you can create a new random one.
Choose Mailisk if
- You test SMS one-time codes with real numbers. Tiers from $29 a month include one US, UK or Canadian number and 200 to 2,400 inbound texts a month, and there is a virtual-SMS call for injecting a text without using the quota. Mailsac is email only.
- You test TOTP or authenticator-app MFA. Mailisk generates codes from a shared secret or a saved virtual device, including custom digits, period and algorithm. Mailsac has nothing like it.
- You want an API that waits.
GET /api/emails/{namespace}/inbox?wait=trueholds the request open until a matching email exists, and the Node, Python and Cypress clients wait by default with a 5-minute timeout, looking only at the last 15 minutes. On Mailsac you write a short polling loop (below) or turn on push. - You want to send test email from the same tool. Paid Mailisk tiers send from a namespace to verified addresses or domains (1,000 to 50,000 messages a month by tier), reply to and forward inbound mail, and generate a deliverability report (SPF, DKIM, DMARC, DNS, header and content checks) for a received message. Mailsac is receive only.
- Your usage is mostly received email and you want the lowest entry price with the whole team on it. $9 a month buys 20,000 received emails, 10 namespaces you name, and unlimited team members with OIDC single sign-on and SCIM. Extra volume is by request from $0.25 per 1,000 emails. Mailsac’s entry plan is $18 a month for one user.
- You need EU data residency. Mailisk stores messages on EU-based servers (Hetzner) with attachments in Backblaze B2. Mailsac runs on AWS in the United States.
- You want an official Python client or a hosted MCP server for coding agents. Mailisk has both. Mailsac has a JavaScript/TypeScript client and a Cypress plugin; other languages use the REST API.
Mailsac vs Mailisk: features and prices
Prices are list prices in US dollars, before tax, as each vendor shows them. Mailsac counts Ops: messages received, API calls and pushes. Mailisk counts emails received a month, with separate allowances for sent emails and SMS, and rate-limits API calls per hour rather than metering them. The units are not directly comparable, so compare by the job you need done. Mailisk’s pricing page is a volume slider with no plan names; the tiers below are read off that slider.
| Mailsac | Mailisk | |
|---|---|---|
| Plans and prices | ||
| Free plan | No expiry. API key, 1 private address, 50 stored messages, 1,500 Ops a month, webhook and WebSocket forwarding on the private address. Any @mailsac.com inbox is public and needs no account |
No card needed. 500 received emails a month, 1-day retention, one random namespace under mailisk.net with unlimited addresses. The namespace expires a month after creation and can be replaced. No custom namespace name, sending to outside addresses, SMS, team members or SSO |
| Entry paid plan | Indie: $18 a month, or $169 a year. 25,000 Ops, 1 user, 1 custom domain, 50 private addresses, 1,000 stored messages | First paid tier: $9 a month, or $90 a year. 20,000 received emails, 1,000 sent, no SMS, 3-day retention, 10 namespaces you name, unlimited team members with SSO and SCIM |
| Team plans | Business: $89 a month, or $840 a year. 500,000 Ops, 5 users, 5 domains, SAML single sign-on, multiple named API keys. Business+: $199 a month, or $1,900 a year. 2 million Ops, 10 users, 10 domains | $29 a month: 100,000 received, 5,000 sent, 200 SMS, 10-day retention. $49: 200,000 received, 10,000 sent, 600 SMS, 15-day retention. $79: 500,000 received, 20,000 sent, 1,200 SMS. $119: 1,000,000 received, 50,000 sent, 2,400 SMS, unlimited namespaces. All with 10 namespaces (unlimited on the top tier) and unlimited team members |
| Enterprise | From $7,500 a year (2 million Ops a month), or $799 a month by card, with a published ladder to 20 million Ops ($24,000 a year). 25 users. Invoice, purchase order, ACH or wire; also sold by resellers SHI and SoftwareOne | “Contact us” above 1,000,000 received emails a month. No price published |
| Yearly billing | Yearly prices published; about 20% less than paying monthly | Yearly is 10 times the monthly price (“2 months free”): $90 to $1,190 a year |
| What usage is counted | Ops. One Op is an API call, a message received at a private address or domain, or a webhook, Slack or WebSocket push. Mail to public @mailsac.com inboxes is not counted, but reading it over the API is. A polled test typically uses 3 to 6 Ops; pushed mail uses 1. Warnings at 80% and 100%; service continues to 125% |
Emails received a month, with separate monthly allowances for sent emails and SMS. API calls are not metered; the default limit is 3,600 requests per API key per hour. Paid plans “can have temporary egress without any hard limits”; extra volume by request from $0.25 per 1,000 emails a month, SMS from $0.05 a message |
| Inboxes, namespaces and domains | ||
| Address model | Any address on a domain you own, on your msdc.co subdomain, or @mailsac.com. Nothing to create |
Any address under a namespace: anything@{namespace}.mailisk.net. Nothing to create |
| Public inbox, no account | Any @mailsac.com address, readable by anyone at mailsac.com/inbox/<name> |
Not offered. Every namespace belongs to an account |
| Private address without a domain | Yes. 1 on Free, 50 on Indie, 250 on Business, 500 on Business+. Reserve one with POST /api/addresses/{email} |
Not needed: every namespace is private to your account, including the free random one |
| Domain with no DNS changes | A yourteam.msdc.co subdomain you name, ready immediately, on Indie and up |
A yourteam.mailisk.net namespace you name on paid tiers; free accounts get a random name |
| Your own domain | Add a TXT record to verify ownership, then MX records | Not documented. The “verified domains” in Mailisk’s docs are destinations for outbound test email |
| Domains or namespaces included | 1 domain on Indie, 5 on Business, 10 on Business+, 12 or more on Enterprise. Extra domains $7 a month | 1 namespace on Free, 10 on the $9 to $79 tiers, unlimited on the $119 tier |
| Whole-domain view and isolation | Unified inbox on the website; GET /api/domains/{domain}/messages; delete all mail on a domain |
One inbox per namespace, searched with recipient, sender, subject and time filters. A per-namespace quota can cap how much of the month’s volume one project uses |
| API and test automation | ||
| Base URL and auth | https://mailsac.com/api with a Mailsac-Key header (or _mailsacKey query parameter) |
https://api.mailisk.com/api with an X-Api-Key header |
| Official client libraries | @mailsac/api (JavaScript/TypeScript) and the @mailsac/cypress plugin (Cypress 16). Any other language over REST |
mailisk for Node.js 18 or later, cypress-mailisk for Cypress 15.10 or later, and mailisk on PyPI for Python 3.9 or later. Playwright uses the Node client. Example repositories for Playwright, Cypress and Selenium |
| Waiting for new mail | Poll GET /api/addresses/{email}/messages (newest first), or have a private address or domain push each message to a webhook or WebSocket. cy.mailsacWaitForMessage() waits for you in Cypress |
GET /api/emails/{namespace}/inbox with wait=true holds the request until a match exists and never times out on its own, so set a timeout in the test. The clients wait by default with a 5-minute timeout |
| Finding the right message | One inbox per address, so the recipient is the path. Match subject and received in your test |
to_addr_prefix, from_addr_includes, subject_includes, from_timestamp and to_timestamp; 1 to 20 results per request. The clients default to the last 15 minutes |
| Codes and links | Every message carries a links array of URLs found in its text and HTML. Plain text at /api/text/. Codes are matched in your test, or with extractCode in the Cypress plugin |
text and html come back in the search response; Mailisk’s examples match a URL or code with a regular expression. Its MCP tools extract code and link candidates for agents |
| Attachments | GET .../messages/{messageId}/attachments, then /attachments/{md5} to download. Public-inbox attachments are available over the API only |
attachments metadata on every message; GET /api/emails/{emailId}/attachments or GET /api/attachments/{id} returns a download URL. Kept until the email expires |
| Deleting mail | DELETE per message or per inbox; POST /api/domains/{domain}/delete-all-domain-mail |
No delete endpoint documented. Each email is removed at its expires_timestamp |
| Rate limits | No per-second API limit published; Ops are the meter. Business and up add an IP allowlist for your senders | 3,600 requests per API key per hour by default; higher on paid plans on request |
| Largest message | 2.5 MB | 10 MB |
| Retention and storage | ||
| Private mail retention | Counted in messages: 50 on Free, 1,000 on Indie, 5,000 on Business, 10,000 on Business+. The oldest are recycled after that; starred messages are kept. 5,000 more for $10 a month | Counted in days: 1 on Free, 3 on the $9 tier, 10 on the $29 tier, 15 on the $49 tier and up; longer on request. Retention can be set per namespace. Attachments go with the email; SMS is kept 30 days |
| Public mail retention | Up to 4 days; only the most recent few messages in each inbox are kept, so busy inboxes recycle sooner | No public inboxes |
| Logs and raw source | /api/raw/ and /api/headers/ per message; message logs for 20 minutes on Free and Indie, 2 weeks or more on Business and up |
Full headers on every message and a raw EML download URL; no separate delivery log documented |
| Webhooks, WebSockets and SMTP capture | ||
| Webhooks and Slack | Every plan, per private address or for a whole custom domain; Slack forwarding too | Not documented. The wait flag on the search endpoint is the alternative |
| WebSockets | Per address on every plan; for a whole domain on Business and up. Endpoint wss://sock.mailsac.com/incoming-messages |
Not documented |
| SMTP capture for staging | Email Capture on every plan: point a staging app’s SMTP at capture.mailsac.com:5587 (STARTTLS; your username and API key). Mail to any recipient lands in that recipient’s Mailsac inbox. Public unless private capture is on or the recipient is on your custom domain |
Not offered. Mail has to be delivered to a mailisk.net namespace address |
| Sending mail | Receive only. New mail can be forwarded to a webhook, WebSocket, Slack or another Mailsac address | Paid tiers send from a namespace to verified addresses or domains (1,000 to 50,000 a month by tier, up to 4 recipients a message), and reply to or forward inbound mail. Free accounts send only within their own namespace |
| MCP server for coding agents | No official MCP server | Hosted at https://api.mailisk.com/mcp on every plan, with scoped keys for namespaces, inbound email, sending and SMS |
| Beyond email | ||
| SMS and phone numbers | Not offered | Tiers from $29 include one US, UK or Canadian number, requested from the dashboard and approved first; 200 to 2,400 inbound texts a month by tier. More numbers from $1; other countries cost extra. Virtual-SMS call to inject a text; 30-day retention |
| TOTP and MFA | Not offered | Generate a code from a Base32 secret without saving it, or save virtual authenticator devices, including custom digits, period and algorithm |
| Deliverability checks | No report. The API has a deny-list lookup for a domain or IP | Per-message deliverability report: SPF, DKIM, DMARC, DNS, header and content signals |
| Load testing | Business and up: a temporary domain active for 8 hours; each email counts as an Op. Burst throughput on request on Enterprise | No load-testing feature documented; paid plans allow temporary overage |
| Team, security and buying | ||
| Users | 1 on Free and Indie, 5 on Business, 10 on Business+, 25 or more on Enterprise | 1 on Free; unlimited team members on every paid tier |
| Single sign-on | SAML on Business and up (Okta, Azure AD, Google) | OpenID Connect (Okta, Azure AD and others) with optional domain enforcement, plus SCIM 2.0 provisioning. The pricing slider lists SSO and SCIM on every paid tier |
| Hosting and certifications | Runs on AWS in the United States. No certification published. Enterprise includes help with SIG and CyberGRX questionnaires | EU-based servers (Hetzner), attachments in Backblaze B2, GDPR wording on the security page. No certification published |
| Billing | Card. Invoice or purchase order on annual Business+ and Enterprise; resellers SHI and SoftwareOne | Card, processed by Paddle. No invoice or purchase-order terms published |
Reviewed September 29, 2026. Mailisk’s tiers count emails received, sent and SMS a month; Mailsac’s count Ops a month, including API calls. Check each vendor’s current pricing before you buy.
Sources: Mailisk homepage and pricing slider, security page, and documentation for email testing, SMS testing, rate limits, SSO, SCIM, MCP, the email, SMS, TOTP and outbound email API references and the Cypress guide. Mailsac pricing, API reference, message storage, custom domains and Email Capture.
Moving from Mailisk
A Mailisk test sends to an address under your namespace, calls searchInbox with a recipient prefix and a subject filter, and reads text or html from the response. A Mailsac test has the same shape, with two changes: the address is on your own domain or msdc.co subdomain (or a public @mailsac.com inbox), and you poll that address’s inbox against a deadline, or have the message pushed, instead of asking the server to wait. Here is the mapping for the calls in Mailisk’s API reference.
| Mailsac | Mailisk | |
|---|---|---|
| Authenticate | Send Mailsac-Key: $MAILSAC_API_KEY on every request to https://mailsac.com/api |
Send X-Api-Key: $MAILISK_API_KEY on every request to https://api.mailisk.com/api |
| Get a test address | Make one up: signup-${Date.now()}@yourteam.msdc.co, or @mailsac.com for a public inbox. Nothing to create |
Make one up under a namespace: signup-${Date.now()}@qa-team.mailisk.net. Nothing to create |
| Wait for the email | Poll GET /api/addresses/{email}/messages (a bare array, newest first) until the message you expect appears, or forward the address to a webhook or WebSocket. In Cypress, cy.mailsacWaitForMessage() |
GET /api/emails/{namespace}/inbox?wait=true, or searchInbox() and cy.mailiskSearchInbox(), which wait by default with a 5-minute timeout |
| Pick the right message | One inbox per address, so the recipient filter is the path. Match subject and received in your test, as the snippet below does |
to_addr_prefix, subject_includes, from_addr_includes, from_timestamp (the clients default to the last 15 minutes) |
| Read the body | GET /api/text/{email}/{messageId} for plain text; /api/body/ for sanitized HTML; /api/dirty/ for the original HTML; /api/raw/ for the whole SMTP message |
text and html are in the search response; GET /api/emails/{emailId} fetches one message; a raw EML download URL is also available |
| Extract links and codes | The links array on each message, found in both text and HTML. Codes: text.match(/\b\d{6}\b/), or extractCode and extractLink in @mailsac/cypress |
Match them in your test with a regular expression on text, as the Mailisk examples do |
| Attachments | GET /api/addresses/{email}/messages/{messageId}/attachments, then /attachments/{md5} to download |
attachments on each message; GET /api/emails/{emailId}/attachments or GET /api/attachments/{id} for a download URL |
| List a whole domain or namespace | GET /api/domains/{domain}/messages |
GET /api/emails/{namespace}/inbox with no recipient filter |
| Clean up | DELETE /api/addresses/{email}/messages/{messageId}; DELETE /api/addresses/{email}/messages for an inbox; POST /api/domains/{domain}/delete-all-domain-mail for a domain |
No delete endpoint documented. Each email is removed at its expires_timestamp |
| Push to a webhook | PUT /api/private-address-forwarding/{email} with {"webhook": url} on a private address, or turn on forwarding for the domain in the dashboard. WebSockets: wss://sock.mailsac.com/incoming-messages |
Not documented |
| Read SMS, generate TOTP, send mail | No equivalent. Send real mail to Mailsac, or capture it with Email Capture. SMS and TOTP are not offered | GET /api/sms/{number}/messages; POST /api/devices/otp; POST /api/emails/send |
The wait step in TypeScript, with no client library · Node.js 18 or later · the same loop as tests/inbox.ts in the CI example repository, with the subject and time filters a Mailisk test passes to searchInbox
const headers = { 'Mailsac-Key': process.env.MAILSAC_API_KEY! };
const address = `signup-${Date.now()}@yourteam.msdc.co`; // any address on your domain; nothing to create
const inbox = encodeURIComponent(address);
const startedAt = Date.now();
// Mailisk: mailisk.searchInbox(namespace, { to_addr_prefix, subject_includes }) waits for you.
// Mailsac: poll the address's inbox against a deadline, then read the plain text.
async function waitForEmail(subjectIncludes: string, timeoutMs = 60_000) {
const deadline = Date.now() + timeoutMs;
while (Date.now() < deadline) {
const res = await fetch(`https://mailsac.com/api/addresses/${inbox}/messages`, { headers });
const messages: Array<{ _id: string; subject: string; received: string; links?: string[] }> = await res.json();
const m = messages.find((x) => x.subject.includes(subjectIncludes) && Date.parse(x.received) >= startedAt - 60_000);
if (m) {
const text = await (await fetch(`https://mailsac.com/api/text/${inbox}/${m._id}`, { headers })).text();
return { id: m._id, subject: m.subject, text, links: m.links ?? [] };
}
await new Promise((r) => setTimeout(r, 2_000));
}
throw new Error(`No "${subjectIncludes}" email for ${address} within ${timeoutMs / 1000}s`);
}
const email = await waitForEmail('Verify your account');
const code = email.text.match(/\b\d{6}\b/)?.[0]; // one-time code
const link = email.links.find((l) => l.includes('/verify')); // confirmation link
Two habits to keep. Mailisk’s clients filter by recipient and subject and only look at the last 15 minutes; both habits carry over. Use a new address for every test so parallel runs and retries never read each other’s mail, and match the message you expect rather than taking whatever is newest. The playwright-signup-ci example generates a unique address per test, matches on the subject, ignores mail received before the test started and deletes the message afterwards; the Playwright tutorial walks through the same loop. Keep the test machine’s clock in sync if you filter by time.
Public and private inboxes, and Mailisk namespaces
Mailisk has no public inboxes. Every address is under a namespace, anything@{namespace}.mailisk.net, and each namespace belongs to one account: free accounts get one random namespace, which expires a month after it is created, and paid tiers get 10 namespaces (unlimited on the top tier) with names you choose that do not expire. Every address under a namespace exists without setup, only your account and team can read it, and a per-namespace quota can cap how much of the month’s volume one project uses. It is a clean model if all your test mail can live under mailisk.net.
Mailsac has both public and private. Mail to name@mailsac.com shows up at mailsac.com/inbox/name, readable by anyone without an account and by any API key, kept up to 4 days, and never counted against your Ops when received. That is the right place for throwaway addresses and made-up data. For password-reset links, codes and anything else that works on a real account, use something private: a private address (the free plan includes one, and it can forward to a webhook, Slack or a WebSocket) or a custom domain on Indie and up. The yourteam.msdc.co subdomain is the closest thing to a Mailisk namespace: you name it, it is ready immediately, every address on it works with nothing to create, and only your account and team can read it. Your own domain works the same way once a TXT record and MX records are in place, which Mailisk does not offer.
The same rule applies to Email Capture: captured mail is public unless you turn on private capture or capture to a custom domain.
Public inboxes are for synthetic test data. If a reset link or code would work on a real account, or the email holds real personal data, use a private address or a verified private custom domain.
Frequently asked questions
Is Mailsac a free alternative to Mailisk?
Both have a free plan, measured differently. Mailisk’s gives you 500 received emails a month in one random namespace, kept for 1 day, and the namespace expires after a month. Mailsac’s gives you an API key, one private address and 1,500 Ops a month with no expiry, plus public @mailsac.com inboxes that need no account at all and are not counted when mail arrives. At 3 to 6 Ops per polled test, the free Mailsac plan covers roughly 250 to 500 test runs a month on private addresses, and far more if the address pushes to a webhook.
What is the Mailsac equivalent of a Mailisk namespace?
A custom domain. On Indie and up, a yourteam.msdc.co subdomain is ready immediately with no DNS work, every address on it exists without setup, and only your account and team can read it, which is what a Mailisk namespace gives you. Unlike Mailisk, you can also verify your own domain with a TXT record and MX records, so test addresses look like signup-123@qa.yourcompany.com. Indie includes one domain, Business five and Business+ ten; extra domains are $7 a month. If you only need one fixed private address, the free plan includes it.
Mailisk’s API waits for the email. Does Mailsac’s?
Not on the server. Mailisk’s wait flag holds the request open until a matching email exists, and its clients do that by default with a 5-minute timeout. On Mailsac you either poll GET /api/addresses/{email}/messages in a short loop with a deadline, as in the snippet above and the playwright-signup-ci example, or let Mailsac push: a private address or custom domain can forward every message to a webhook or WebSocket on every plan, so the test waits on one connection and uses one Op per email. In Cypress, cy.mailsacWaitForMessage() from @mailsac/cypress does the waiting for you.
How do Mailsac Ops compare with Mailisk’s received emails?
They measure different things, so there is no exact conversion. Mailisk counts emails received a month, with separate allowances for sent emails and SMS, and limits API calls to 3,600 an hour per key rather than counting them. Mailsac counts Ops: each message received at a private address or domain, each API call, and each webhook, Slack or WebSocket push. A test that polls for one email and reads it typically uses 3 to 6 Ops, and a pushed email uses 1, so Indie’s 25,000 Ops cover several thousand tests a month and Business’s 500,000 cover roughly 150,000 test emails. Mail to public @mailsac.com inboxes is not counted at all.
Does Mailsac test SMS or TOTP codes?
No. Mailsac receives email and hands it to your tests over the API, webhooks or WebSockets. Mailisk includes one US, UK or Canadian SMS number on tiers from $29 a month, reads inbound texts through the same kind of search call, and generates TOTP codes from a shared secret or a saved virtual authenticator device. If SMS or authenticator-app MFA is part of your suite, Mailisk is the better fit.
How long is test mail kept?
Mailisk keeps each email for a fixed time: 1 day on the free plan and 3, 10 or 15 days on paid tiers, with longer retention on request; attachments are deleted with the email, and there is no delete call, so cleanup is automatic. Mailsac keeps private mail up to your plan’s stored-message count (1,000 on Indie, 5,000 on Business, 10,000 on Business+), recycling the oldest first and keeping anything you star, and you can delete a message, an inbox or a whole domain’s mail on demand. Public @mailsac.com mail is kept up to 4 days, and only the most recent few messages per inbox.
Is Mailsac a drop-in replacement for the Mailisk API?
No. The endpoints, the auth header and the message JSON are different, and Mailsac has no server-side wait, so the code that finds and reads the email needs rewriting. The mapping above covers every inbound-email call in Mailisk’s API reference. Your app and its email sending do not change; only the recipient domain and the code that reads the mail. Tests that depend on Mailisk’s SMS, TOTP or outbound sending have no Mailsac equivalent.
Try Mailsac with your next email test
Send mail to any @mailsac.com address and open the inbox, or create a free account, generate an API key and run the wait step above. Plans with a private test domain start at $18 a month.
Other comparisons: Mailsac vs Mailtrap, Mailsac vs Mailosaur, Mailsac vs MailSlurp, Mailsac vs Mailinator, Mailsac vs Mailpit and MailHog and Mailsac vs testmail.app. New to Mailsac? See how the email testing API works, or how to load test with thousands of emails.