Out-of-Office Replies, Autoresponders and Mail Loops: A Survival Guide for AI Agents
Automated mail is a trap for AI agents: answer a vacation notice and you may start an endless loop. How to detect auto-replies, use what they tell you, and never reply to a robot.
By Toan Nhu

Picture two helpful programs. Your agent sends a message. The recipient is on holiday, so their mail server sends back an out-of-office notice. Your agent, eager to help, replies to the notice. The server, following its rules, sends another notice. By morning there are hundreds of messages in both mailboxes, your sending quota is gone, and your domain looks like a spam source.
Mail loops are an old problem that AI agents have made new again. Humans ignore autoresponders without thinking. Agents have to be taught to.
The automated mail your agent will meet
- Out-of-office and vacation notices, often with a return date and an alternative contact.
- Ticket acknowledgements from helpdesks: we received your request, reference 12345.
- Bounce notices from mail servers, usually from MAILER-DAEMON or postmaster with an empty return path.
- Mailing list and newsletter traffic.
- Other agents. As more inboxes are run by software, your agent will increasingly be talking to a program that also wants to reply.
How to tell a robot from a person
Start with headers, because they are cheaper and more consistent than reading the body. The email standards for automatic responses (RFC 3834) define an Auto-Submitted header: any value other than no means the message was generated automatically, and automatic responders should not answer it. Other strong signals include a Precedence header of bulk, list or junk; List-Id or List-Unsubscribe headers, which mark mailing list traffic; Microsoft's X-Auto-Response-Suppress header; and an empty or null return path, which is typical of bounces.
Not every autoresponder sets these headers correctly, so add a content check as a second layer. Subjects beginning with Automatic reply, Out of office or Auto: are common, as are bodies that mention being away until a date. A language model is good at this classification, but treat its answer as a hint and combine it with the header checks rather than relying on it alone.
Mermail builds some of this in. The default email-response triager on every mailbox avoids replying to messages that look automated, including bulk mail, list mail and messages carrying auto-response suppression headers. If you run your own agent loop on top of Mermail through MCP or the API, apply the same discipline in your code.
Rules that prevent loops
- Never auto-reply to automated mail. If any automation signal is present, the agent may read and record the message, but it does not send a response.
- Cap replies per thread. Set a hard limit on how many messages the agent may send in one thread without a human looking, for example three.
- Cap replies per correspondent per day. One address should not be able to trigger dozens of sends.
- Never reply to yourself. Ignore messages from your own agent addresses and your own domain unless the task explicitly expects them.
- Deduplicate. Process each message ID once, even if it is delivered or listed twice.
Enforce these in the code that executes tools, not only in the prompt. A prompt instruction is a suggestion; a counter in your send function is a guarantee.
Use what the out-of-office tells you
An out-of-office notice is not noise. It says the address is valid and the person exists, and it often gives a return date. Useful things an agent can do without sending anything:
- Record the return date and pause any planned follow-up until a day or two after it.
- Note an alternative contact for a human to review. Do not automatically email that person; they did not ask to hear from you, and the notice may be meant only for existing customers or colleagues.
- Keep the thread open. The notice is not a reply, so do not mark the conversation as answered or count it as engagement in your metrics.
- Watch for permanent departures. A notice saying the person has left the company is closer to a bounce: stop mailing that address.
In Mermail, you can make this visible with a custom label, for example an Automated reply label whose rule covers out-of-office notices, ticket acknowledgements and delivery failures, and excludes any message written by a person. Labels are applied to new inbound mail as it arrives, so your agent or your team can filter that category and skip it.
When the other side is also an agent
Two well-behaved agents can still ping-pong politely forever: thanks for your message, you are welcome, happy to help. Per-thread caps catch this, but it also helps to give agents a clear definition of done. If a thread has reached its goal (a code received, a booking confirmed, a question answered), the agent should stop, even if the other party sends one more courtesy message.
Remember too that automated mail is still untrusted content. An autoresponder body can contain instructions, links or requests just like any other email, and an agent should never follow them simply because they arrived in its inbox.
Test it before it tests you
Turn on an out-of-office reply in a test account you control, have your agent email it, and confirm the agent records the notice and sends nothing back. Then send it a mailing list message and a fake bounce notice and check the same. Keep these as regression fixtures so a future prompt change cannot quietly reintroduce the loop.
Read: how to test an AI agent inbox
Give your agent an inbox with automated-mail safeguards built into its default triager. Create a Mermail inbox.


