mailsac

Mailsac vs MailSlurp

Mailsac vs MailSlurp

MailSlurp alternative for email testing

Mailsac gives QA and engineering teams test inboxes and a REST API for checking the email their apps send: sign-up confirmations, password resets and one-time codes. Here is how it compares with MailSlurp, including where MailSlurp is the better fit, and how to move existing tests.

Reviewed September 2026 against both vendors’ public pricing and documentation.

Free plan: an API key, public inboxes, one private address and 1,500 Ops a month, with no expiry. Jump to the full comparison or see how to move from MailSlurp.

At a glance

Free option

Mailsac Free plan, no expiry: 1,500 Ops a month

MailSlurp Free plan: 500 emails received and 100 inbox creations a month

Entry price

Mailsac Indie, $18 a month or $169 a year

MailSlurp Starter, $19.99 a month

Your own test domain

Mailsac Every paid plan, from $18 a month

MailSlurp Pro, $49.99 a month

Inbox model

Mailsac Any address receives mail; nothing to create first

MailSlurp Create an inbox first; creations are capped per month on Free and Starter

SAML single sign-on

Mailsac Business, $89 a month

MailSlurp Enterprise, custom quote

SMS, previews, AI extraction

Mailsac Not offered

MailSlurp Yes, metered on top of the plan

Which should you choose?

Both let automated tests receive the email your app sends and check what is in it. They differ in how inboxes work, what usage is counted, what else they test, and how they are bought.

Choose Mailsac if

  • Every test should use a fresh address without creating an inbox first. Any @mailsac.com address or any address on your domain receives mail, and there is no monthly cap on how many addresses you use.
  • You want test addresses on your own domain, or on a subdomain you name such as yourteam.msdc.co with no DNS changes, from $18 a month. On MailSlurp a custom domain starts on Pro at $49.99 a month.
  • Your suites receive a lot of mail. Business is $89 a month for 500,000 Ops (about 150,000 test emails) and 5 users; MailSlurp’s Pro and Growth plans include 5,000 emails received a month, then bill by usage.
  • You need SAML single sign-on at a published price. Business includes it with 5 team logins.
  • Procurement wants published prices: Business+ at $1,900 a year or Enterprise from $7,500 a year, payable by invoice or purchase order, or through resellers SHI and SoftwareOne.

Choose MailSlurp if

  • You also test SMS codes with real phone numbers. MailSlurp rents numbers on Pro and up; Mailsac is email only.
  • You want an official SDK in your language that waits for the message and pulls out links and matches for you. MailSlurp lists SDKs for about 25 languages, including Java, C#, Python, PHP, Ruby, Go, Rust, Swift and Kotlin. Mailsac has a JavaScript/TypeScript client and a Cypress plugin; other languages use the REST API.
  • Your tests also send email, reply, or need device previews, inbox placement tests, email warm-up or AI extraction. Mailsac only receives.
  • Your security review asks for a SOC 2 report, SCIM provisioning, OpenID Connect sign-on or audit logs. MailSlurp states SOC 2 Type I and offers these on Enterprise. Mailsac publishes no certification and its single sign-on is SAML only.
  • You want Zapier or Google Sheets automations on incoming mail.

Mailsac vs MailSlurp: features and prices

Prices are list prices in US dollars, before tax, as each vendor shows them. The plans measure usage in different units, so compare by the job you need done.

Mailsac MailSlurp
Plans and prices
Free option Free plan with no expiry: API key, public inboxes, 1 private address, 1,500 Ops a month Free plan, “$0 forever”: 500 emails received a month, 100 inbox creations a month (fixed cap), 50 retained inboxes, 200 MB storage, 1 user
Entry plan Indie: $18 a month, or $169 a year. 25,000 Ops, 1 user, 1 custom domain Starter: $19.99 a month. 1,000 emails received a month, 250 inbox creations (fixed cap), 100 retained inboxes, 1 user. No custom domains
First plan with your own domain Indie, $18 a month Pro: $49.99 a month. 5,000 emails received a month, 1,000 inbox creations then usage billing, 1 custom domain, 1 user
Team plan Business: $89 a month, or $840 a year. 500,000 Ops, 5 users, 5 domains, SAML single sign-on. Business+: $199 a month, or $1,900 a year. 2 million Ops, 10 users, 10 domains Growth: $129.99 a month. 5,000 emails received a month then usage billing, 5,000 inbox creations then usage billing, 1 custom domain, 2 users (more sold separately)
Enterprise From $7,500 a year (2 million Ops a month), or $799 a month by card. Published. 25 users. Invoice, purchase order, ACH or wire; also sold by resellers SHI and SoftwareOne Custom quote. Custom capacity and invoicing, MSA, SAML or OIDC single sign-on, SCIM, roles and audit logs, isolated environments, regional hosting
Yearly billing Yearly prices published; about 20% less than paying monthly A yearly option is offered in the billing selector on the pricing page; yearly prices are not listed here
What usage is counted Ops. One Op is an API call, a message received at a private address or domain, or a webhook, Slack or WebSocket push. A polled test typically uses 3 to 6 Ops; pushed mail uses 1 Emails received a month, plus caps on inbox creations, retained inboxes and storage. Device renders, inbox placement tests and AI tokens are metered separately
Inboxes and domains
Test address with no setup Any @mailsac.com address (public) or any address on your custom domain (private). Nothing to create before your app sends Create an inbox first with createInbox(). The address is random at mailslurp.com, or at a pool domain such as mailslurp.xyz with useDomainPool. You can name the address on a verified custom domain
Inbox lifetime Public inbox mail is temporary and may be recycled quickly. Private addresses and domains keep mail up to the plan’s stored-message limit: 1,000 on Indie, 5,000 on Business, 10,000 on Business+ Paid plans use permanent inboxes by default; set expiresAt or expiresIn for temporary ones. Free and Starter cap retained inboxes at 50 and 100; deleting an inbox frees capacity
Your own receiving domain Indie and up: 1, 5, 10 or 12+ domains. Your own domain, or a yourteam.msdc.co subdomain that needs no DNS changes. Extra domains $7 a month Pro and up: 1 custom domain included; more sold separately
Who can read the mail @mailsac.com inboxes: anyone. Private addresses and custom domains: your account and team only Inboxes are created in your account and read with your API key
Test automation
API key header Mailsac-Key x-api-key
Official client libraries @mailsac/api (JavaScript/TypeScript) and the @mailsac/cypress plugin. Any other language over REST mailslurp-client on npm and SDKs listed for about 25 languages, including Java, C#, Python, PHP, Ruby, Go, Rust, Swift and Kotlin; cypress-mailslurp. Guides for Playwright, Selenium, WebdriverIO, TestCafe, CodeceptJS, Pytest and Robot Framework
Waiting for new mail Poll GET /api/addresses/{email}/messages (newest first) on any plan, or have a private address or domain push new mail to a WebSocket or webhook. The Cypress plugin waits for you waitForLatestEmail(inboxId, timeout) waits on the server; waitController adds options such as unreadOnly
Codes and links Every message carries a links array of URLs found in its text and HTML. Codes are matched in your test, or with extractCode in the Cypress plugin getEmailLinks parses HTML (returns a validation error for non-HTML mail); getEmailContentMatch runs a regex on the server; AI extraction is metered in tokens
Webhooks and WebSockets Webhooks and Slack forwarding on every plan. WebSockets per address on every plan; for a whole domain on Business and up Webhooks on every plan, including Free. Zapier on Starter and up
SMTP capture for staging Email Capture on every plan: point a staging app’s SMTP at capture.mailsac.com:5587 (STARTTLS; your username and API key). Mail to any recipient lands in that recipient’s Mailsac inbox. Public unless private capture is on or the recipient is on your custom domain SMTP delivery to inboxes created with the SMTP_INBOX type (mailslurp.mx:587), plus IMAP access. SMTP inboxes cannot send
Sending mail Receive only. New mail can be forwarded to a webhook, WebSocket, Slack or another Mailsac address 1,000 sandbox sends a month to your own inboxes on Free; 500 external sends a month on Pro and Growth
Beyond receiving email
SMS and phone numbers Not offered Pro and up; number rentals and messages priced separately
Previews, placement, warm-up, AI Not offered Device renders, inbox placement tests, email warm-up and AI extraction, included in small amounts then metered
Team, security and buying
Users 1 on Free and Indie, 5 on Business, 10 on Business+, 25 or more on Enterprise 1 on Free, Starter and Pro; 2 on Growth, more sold separately
Single sign-on SAML on Business and up SAML or OpenID Connect, with SCIM, on Enterprise
Certifications and hosting None published. Runs on AWS in the United States. Enterprise includes help with SIG and CyberGRX security questionnaires States SOC 2 Type I, GDPR and CCPA. Enterprise adds roles, audit logs, isolated environments and regional hosting
Billing Card. Invoice or purchase order on annual Business+ and Enterprise; resellers SHI and SoftwareOne Card self-serve. Custom invoicing and MSA on Enterprise

Reviewed September 28, 2026. MailSlurp’s plans count emails received and inbox creations per month; Mailsac’s count Ops per month, including API calls. Check each vendor’s current pricing before you buy.

Sources: MailSlurp pricing, inboxes, SMTP and IMAP, API reference, SDKs and homepage. Mailsac pricing, API reference, custom domains and Email Capture.

Moving from MailSlurp

A MailSlurp test creates an inbox, waits for its latest email and extracts a link or code. The same test in Mailsac skips the first step. Here is the mapping for the common calls in mailslurp-client.

Mailsac MailSlurp
Authenticate Send Mailsac-Key: $MAILSAC_API_KEY on every request new MailSlurp({ apiKey }); the header is x-api-key
Get a test address Make one up: signup-${Date.now()}@yourteam.msdc.co. Nothing to create. To fix one private address instead: POST /api/addresses/{email} const inbox = await mailslurp.createInbox(), then use inbox.emailAddress
Wait for the latest email Poll GET /api/addresses/{email}/messages every couple of seconds until it returns a message, up to a deadline. The array is newest first const email = await mailslurp.waitForLatestEmail(inbox.id, 60000)
Read the body GET /api/text/{email}/{messageId} for plain text; /api/body/ for sanitized HTML; /api/dirty/ for the original HTML email.body
Extract links The links array on GET /api/addresses/{email}/messages/{messageId}, found in both text and HTML mailslurp.emailController.getEmailLinks({ emailId: email.id })
Extract a code Match it in your test: text.match(/\b\d{6}\b/). In Cypress, extractCode from @mailsac/cypress mailslurp.emailController.getEmailContentMatch({ emailId, contentMatchOptions: { pattern } })
Clean up DELETE /api/addresses/{email}/messages/{messageId}, or DELETE /api/addresses/{email}/messages for the whole inbox Delete the inbox to free retained capacity
Cypress @mailsac/cypress: cy.mailsacWaitForMessage() cypress-mailslurp

The wait step in TypeScript, with no client library · Node.js 18 or later · a standalone version of the loop in tests/inbox.ts in the CI example repository

const headers = { 'Mailsac-Key': process.env.MAILSAC_API_KEY! };
const inbox = encodeURIComponent(address); // e.g. signup-1790000000000@yourteam.msdc.co

async function waitForEmail(timeoutMs = 60_000) {
  const deadline = Date.now() + timeoutMs;
  while (Date.now() < deadline) {
    const res = await fetch(`https://mailsac.com/api/addresses/${inbox}/messages`, { headers });
    const messages: Array<{ _id: string; subject: string; links?: string[] }> = await res.json();
    if (messages.length) {
      const m = messages[0]; // newest first
      const text = await (await fetch(`https://mailsac.com/api/text/${inbox}/${m._id}`, { headers })).text();
      return { id: m._id, subject: m.subject, text, links: m.links ?? [] };
    }
    await new Promise((r) => setTimeout(r, 2_000));
  }
  throw new Error(`No email for ${address} within ${timeoutMs / 1000}s`);
}

const email = await waitForEmail();
const code = email.text.match(/\b\d{6}\b/)?.[0];               // one-time code
const link = email.links.find((l) => l.includes('/verify'));   // confirmation link

Two habits to keep. Use a new address for every test so parallel runs and retries never read each other’s mail, and match the message you expect rather than taking whatever is newest. The CI example repository generates a unique address per test, matches on the subject and deletes the message afterwards; the Playwright tutorial also filters by the time the email was triggered.

Public and private inboxes

A MailSlurp inbox belongs to your account from the moment you create it. Mailsac works the other way round: mail to an @mailsac.com address is public by default. Anyone can view a public inbox on the Mailsac website without an account, and any Mailsac API key can read it. Public inboxes are temporary, and they are fine for trying things out with made-up data.

For password-reset links, codes and anything else that works on a real account, use a private address (the free plan includes one) or a custom domain: a msdc.co subdomain, or your own domain once it is verified. Only your account and team can read that mail. A custom domain is the closest match to how MailSlurp inboxes work, and it lets every test use its own address with nothing to create first.

The same applies to Email Capture: captured mail is public unless you turn on private capture or capture to a custom domain.

Public inboxes are for synthetic test data. If a reset link or code would work on a real account, or the email holds real personal data, use a private address or a verified private custom domain.

Frequently asked questions

Is Mailsac a drop-in replacement for MailSlurp?

No. The inbox model is different, so the create, wait and extract steps of each test need rewriting. The mapping above covers the calls most tests use. Your app and its email sending do not change; only the recipient addresses and the code that reads the mail.

Do I have to create an inbox before my app sends to it?

No. Any @mailsac.com address, and any address on a custom domain in your account, receives mail with nothing set up first. Reserve a private address only when you want one fixed address that stays private and can forward mail.

Which free plan is bigger?

They count different things. MailSlurp’s Free plan allows 500 emails received and 100 inbox creations a month, so a suite that creates a fresh inbox per test gets 100 tests a month. Mailsac’s free plan allows 1,500 Ops a month with no expiry; a polled test typically uses 3 to 6 Ops, so a few hundred tests a month, using as many addresses as you like. Public inboxes on the free plan are readable by anyone, so keep the data synthetic.

Can I keep test email private on Mailsac?

Yes. Use a private address (one is included free) or a custom domain, on Indie and up. A yourteam.msdc.co subdomain is ready immediately; your own domain works once DNS is verified. Mail on either is visible only to your account and team.

Can I run email tests in parallel?

Yes. Give each test its own address, for example with a timestamp and random suffix, and each worker reads only its own inbox. There is no inbox-creation cap to plan around, but each received message and API call counts as an Op.

Does Mailsac send email or test SMS?

No. Mailsac receives email and hands it to your tests over the API, webhooks or WebSockets. If you need to send from test accounts, or read SMS codes from real phone numbers, MailSlurp offers both.

Is there a Playwright or Cypress integration?

The @mailsac/cypress plugin waits for matching messages, verifies links and extracts one-time codes. For Playwright, the Playwright email testing tutorial uses the REST API directly, and the CI example repository runs the same test in GitHub Actions and GitLab CI.

Where is data stored, and can Mailsac complete our security review?

Mailsac runs on AWS in the United States. Enterprise plans include help with security questionnaires such as SIG and CyberGRX. Mailsac publishes no SOC 2 or ISO report; if your review requires one, MailSlurp states SOC 2 Type I.

Try Mailsac with your next email test

Create a free account, generate an API key and run the wait step above against any address. Plans with a private test domain start at $18 a month.

Also comparing Mailosaur or Mailtrap? Read Mailsac vs Mailosaur and Mailsac vs Mailtrap. New to Mailsac? See how the email testing API works.