# Choose who your agent can email

> Pick one of four outbound modes to decide who your agent can email. New agents start with an empty allowlist.

## Before you start

- You need the owner or admin role.

## Outbound modes

| Mode | Behavior |
|---|---|
| All | Sends to anyone. Limits, the suppression list, and content checks still apply. |
| Allowlist | Sends only to addresses and domains on the allowlist. Everything else is blocked. **The default for new agents.** |
| Blocklist | Blocks only people on the blocklist and sends to everyone else. |
| Block all | Sends to no one. Every send is denied. |

Mail to anyone outside the list is blocked without an approval request. If a message has several recipients and any one of them is blocked, the whole message isn't sent.

### 1. Open the Email screen

On the agent's screen, choose **Email**. On a narrow screen, pick the **Outbound** tab at the top.

### 2. Pick a mode

In the **Outbound** column, choose a mode. The mode in use is marked **Current**.

### 3. Save

Choose **Save** at the bottom of the column. Each save creates a new policy version and applies right away.

![The Outbound column on the Email screen](https://docs.atmark.ai/_img/07f1c30d1315306f/agent-email-en-light.webp)

> **Warning · Before you choose All**
>
> All means the agent can email anyone. If its token leaks, or the agent is tricked by instructions in an email, mail can go to strangers. If you know who it should write to, use the allowlist.

## Send results

Every send returns one result to the agent.

| Result | Meaning | What the agent should do |
|---|---|---|
| `sent` | It went out. | Nothing |
| `denied` | A policy or limit blocked it. A reason code comes with it. | Don't retry; tell the owner. |
| `pending_approval` | A person has to approve it. Only happens on old outbound modes. | Don't resend; wait. See [Approvals](https://docs.atmark.ai/en/email/approvals). |

Common denial reasons are listed in [When mail doesn't go out](https://docs.atmark.ai/en/help/troubleshooting-sending).

## What the agent can't do

The agent can only read its policy with `get_my_policy`. Only owners and admins change modes and lists, in the console.

---

Source: https://docs.atmark.ai/en/email/sending · Last updated 2026-09-27
