Scores
Article
Choosing one LinkedIn outreach tool, for an agency’s client roster or your own account, comes down to what you can build on it once the first campaign is running, and on that test Aimfox is the one I’d buy. A $49 seat (HeyReach charges $79, Expandi $99), free teammates, and the strongest API and MCP score of the five LinkedIn tools we’ve reviewed, with an MCP server whose 56 tools are listed in public. It runs your LinkedIn session from its own cloud, so you’re trusting Aimfox with a cookie or a password. Two product gaps stay too: email never lives inside the sequence, and a campaign the API creates still has to be finished by hand. Neither one changed my answer.
For
- A $49 seat, $30 under HeyReach and $50 under Expandi
- 56 published MCP tools, the biggest list in the category
- Every enrolled lead locked workspace-wide by default
- Voice notes and attachments as sequence steps
Against
- Email means a separate Instantly, Smartlead or EmailBison subscription
- The API builds a campaign shell the dashboard has to finish
- Your session sits in Aimfox’s cloud with no security page behind it
- The AI writes from a model Aimfox doesn’t name
Two-minute review
Aimfox is a cloud LinkedIn outreach platform sold by the seat, one per LinkedIn account, built for agencies first and developers a close second, and the developer surface is the part I didn’t expect at this price: a key you generate yourself with a read-only option, 72 routes, 18 webhook events with documented retries, and an MCP server whose 56-tool list I could count against 72 routes.
HeyReach names eight and publishes no list.
Targeting is the other place it pulls clear: every enrolled lead is locked to its campaign workspace-wide by default, where HeyReach gives you a toggle.
The costs are the four in the Against list; read the third one twice. Email inside the sequence sends you to Expandi or Dripify; a conditional builder, to Expandi. Everyone else is choosing between Aimfox and HeyReach, and Aimfox is $30 a seat cheaper.
What Aimfox costs
Every Aimfox price is a seat price, a seat being one LinkedIn account allowed to run campaigns, and the people using the seats cost nothing, which is why the agency arithmetic favours Aimfox.
Every price is a seat price
One Outreach seat runs $49 a month, or $390 for the year; only seated accounts send, and a seat can move. Agency starts at $499 a month for a pool of 20 seats, $20 per seat after that, spread across client workspaces under your own white-label domain, about $25 a seat. Avatars, the rented profiles, are $387 a month for three, no trial, in multi-month blocks that don’t refund.
You’ll still be paying LinkedIn too
Connection notes need LinkedIn Premium on every worker account, Sales Navigator campaigns need Sales Navigator on the searching account, and the pricing cards mention neither. The 14-day trial is a loose thread too: card-free on the pricing page and in the trial FAQ, card-required in the connection steps. Budget for being asked, and enjoy the surprise if you aren’t. The Agency plan’s “Branded knowledge base” is, on the white-label page, still coming soon.
Specs
| Category | Details |
|---|---|
| Price | $49/seat/mo or $390/yr; Agency $499/mo for 20 seats plus $20 a seat; Avatars $387/mo for three |
| Execution model | Cloud; Aimfox holds the session, logging in from a location you pick or your proxy |
| Account connection | Extension session handoff (primary); email and password (fallback); no API route |
| Sending limits | 10 to 200 a week per action (about 28 invites a day); 1 to 1,000 by API |
| Warm-up | Optional, 7, 14 or 30 days; never enforced |
| Sequencing logic | One branch, on invite acceptance; open profiles get free InMail; replies end it |
| Email channel | None native; Instantly, Smartlead or EmailBison lists |
| AI | AI Variables (prompt text from six profile fields), Auto-Translate; provider unnamed |
| API | 72 routes; self-serve key, read-only scope; 60 a minute; 18 webhook events with retries; unsigned |
| MCP | Official, OAuth, any plan; 56 tools published, 78% of routes |
| Certifications | None; no DPA, security page or subprocessor list |
| Trial | 14 days; card requirement stated both ways |
Inside the campaign builder
Targeting is the best thing Aimfox does and the sequence builder the most ordinary: a list from eleven places, sent through a flow that asks exactly one question, and an AI prompt box in the same builder.
Eleven sources and a lock you don’t have to set
The eleven: LinkedIn people search (1,000 per campaign), a Sales Navigator search URL (2,500), CSV to 10,000 rows, post likers, commenters and reposters, event attendees, group members, first-degree connections, Instantly, Smartlead and EmailBison lists, an RB2B visitor webhook, and the API. No saved Sales Navigator lists, and nothing refills itself.
Hygiene is where Aimfox beats HeyReach outright: a lead enrolled anywhere in the workspace is locked to that campaign, deleted campaigns included, and a blacklist of people and companies applies to everything. It stops at the workspace edge, so separate client workspaces get no dedup between them, and nothing checks your CRM first.
The flow only asks one question
Every flow starts with a profile view. An open profile gets a free InMail and stops; everyone else gets the connection request, and the builder’s one question is whether it was accepted: yes means up to ten follow-ups on delays you set, no means a withdrawal after a window you choose, and any reply ends the sequence. Aimfox lays the shape out in its Sales Navigator walkthrough, and POST /campaigns carries no steps at all. The flow is a corridor with one door in it, and Expandi’s ten conditions are where that starts to hurt, however many voice notes, attachments, reactions, endorsements and recipient-timezone windows Aimfox lets you hang on the walls.
Six profile fields go somewhere Aimfox won’t name
An AI Variable is a prompt inside a template that a model fills at send time from six facts about sender and target: first name, last name, occupation, location, current company and time there. The prompt is editable; nothing reads the output before it goes out, so a bad generation is a sent message.
The model doing the writing has no name anywhere Aimfox publishes: no DPA, no subprocessor list, and a privacy policy untouched since January 2023 that names twelve third parties and no AI provider. Six facts about your prospect leave for a processor with no name and no stated region, and an EU client will ask you where; you won’t have an answer.
How safe is Aimfox for your LinkedIn account?
As safe as a cloud LinkedIn tool gets on paper, and no safer. The session lives on Aimfox’s servers, and across 39 Trustpilot reviews (4.4) nobody reports a restriction, and G2’s 4.7 from 36 reviews is an aggregate I couldn’t open, a small sample rather than a clean bill. Account Safety comes in at 3.0, half a point under HeyReach, and since our overall is capped at Account Safety plus two, that 3.0 is what holds Aimfox at 5.0.
How the cookies get to the cloud
Two ways in. The primary one is a Chrome extension that copies your logged-in LinkedIn session to app.aimfox.com: cookies and tabs permissions on LinkedIn and Aimfox’s domains only, and 22 KB of scripts that read cookies, clear them and hook the Log out button so LinkedIn’s logout never reaches the session Aimfox is holding. After that Aimfox signs in from whichever country you picked or a proxy you bring.
The second is your LinkedIn email and password typed into Aimfox, the route for white-label clients and anyone the extension fails. The Terms make that password a requirement and say it’s “securely encrypted”. A help article on the same question says everything about your account is “always encrypted”, and the connection walkthrough says Aimfox “does not store your Login information” at all. A service that logs into LinkedIn as you every day has to hold something it can replay, a session or a password, so at least one of those three sentences is wrong. Which one, and how the real thing is stored, isn’t published anywhere I could find, and no security page or certification fills the gap. That’s the answer I’d want before connecting an account I couldn’t afford to lose.
Sliders to 200, an API route to 1,000
Three weekly sliders per account, for connection requests, message requests and InMails, run from 10 to 200; warm-up is optional; pending invites withdraw themselves after a window you set; and a LinkedIn throttle drops the account into a per-action Cooldown instead of freezing it.
Aimfox’s pricing page calls those “Hard-coded limits”, which is a bit rich. PATCH /accounts/:id/limits in the API reference takes any weekly value from 1 to 1,000, with 50 to 200 recommended. Five times the dashboard ceiling, one HTTP call away. So which ceiling do Aimfox’s servers enforce? It doesn’t say. Plan around 200, and if you run an agency, make sure a client’s engineer can’t quietly go higher.
The agency page and the Terms disagree
Aimfox’s agency page promises “Multi-layer protection to keep your accounts safe & secure at all times” and calls the setup “Cloud-based & untraceable”. Its Terms put every LinkedIn restriction on the customer, “at their own risk”, make a refund after losing LinkedIn access discretionary, and never mention Avatars. They can’t all be true, and the contract is the one that binds you. To its credit, the Terms carry no indemnity or anti-benchmarking clause, unlike HeyReach’s.
Rented profiles and an unpublished ban rate
Aimfox will rent you LinkedIn profiles from inside the product, which no other tool here offers: profiles it created and warmed up itself, replaced inside two business days when LinkedIn bans one, at $387 a month for three, no trial, no refund. The ban rate isn’t published, and each Avatar is capped at 100 connection requests a week, half an owned seat. Useful to an agency whose clients won’t hand over more accounts; no part of why Aimfox wins here.
What you can build on the API
This section decides the RevOps column, where Aimfox scores 5.9, its best persona. Agencies get provisioning by script and developers get a wide surface with a published MCP list; both hit the same wall: a LinkedIn account and a runnable campaign still need a human in the dashboard.
A seat pool you can provision by script
An agency holds its seats in one pool and deals them out to client workspaces, with a client tier that logs in through your white-label domain and never sees billing, integrations, keys or webhooks. With a master key a script can create the workspace, seat it, create the client and mint their login link, which the white-label guide chains to Stripe for hands-off onboarding. Multi-account campaigns batch one list across worker accounts and reassign unstarted targets when one drops out, the rotation HeyReach’s blog review of Aimfox says doesn’t exist. No audit log or approval step.
Fifty-six MCP tools you can read before you connect
The REST side is 72 routes in 13 groups behind a Bearer key you scope to “All” or “Read-only”. Webhooks fire on 18 events and retry six times on a schedule that widens from a minute to a day, which no rival here writes down. The MCP server is official, behind OAuth, included on any plan, and its tool list is public: 56 tools (yes, I counted), 78% of the routes, send-capable with no approval gate described. HeyReach names eight tools and publishes no list; Waalaxy publishes all four of its; Expandi’s is a waitlisted beta; Dripify has none.
The two things a script can’t do
Connecting a LinkedIn account has no route, so every new sender still means the extension or a white-label login link, where HeyReach’s API accepts credentials or cookies. And POST /campaigns makes a shell, a campaign with a name and nothing inside; audience, schedule and flows are dashboard work, so leads can pour in by API, webhook or n8n all day and a campaign that sends still needs a click through the builder. The rest is the usual roughness: no OpenAPI spec, SDK, changelog or versioning policy, unsigned webhooks, 11 of 30 on our docs rubric against HeyReach’s 13 and Dripify’s 17, and a one-way CRM push to HubSpot and Pipedrive.
Should you buy Aimfox?
For most people reading a LinkedIn tool review, this is the one; it gets interesting once you need email in the sequence, a conditional builder, or a campaign launched from code.
Buy Aimfox if…
You’d like the category’s best score without HeyReach’s price. A 5.0 overall that ties it, a 7.5 on targeting that beats it, and $30 a seat saved.
Your seats belong to clients. A pool of 20 for $499, free teammates and client logins, and a client role that never sees billing.
Something else in your stack needs to drive it. The second-widest API in the group and the biggest published MCP tool list and the biggest published MCP tool list.
Don’t buy Aimfox if…
Email has to sit inside the sequence. Aimfox ends the flow at any reply and leaves email to a separate Instantly or Smartlead bill; Expandi and Dripify build it in.
A script has to take a campaign live. POST /campaigns stops at a shell and no route connects an account; HeyReach’s API can at least do the second part.
One LinkedIn account is your whole pipeline. The full product for $49, and the cloud-custody trade taken alone, from a company that describes its credential storage three different ways.
Also consider
HeyReach (5.0 overall) costs $79 a sender, edges Aimfox on Account Safety (3.5 to 3.0), alone connects an account by API, and names eight MCP tools to Aimfox’s 56.
Expandi (4.0 overall) has the builder Aimfox doesn’t (8.3 on sequencing, ten conditions, native email) for $99 an account, with an API of three reversed webhooks (3.0) and a login that takes your password and 2FA secret.
Waalaxy (2.5 overall) is the cheap seat, from 19 euros a month on yearly billing, with strong targeting (8.0) and the lowest Account Safety we’ve given (0.5): password and 2FA secret required, plus a VPN IP shared by up to five users.
Dripify (4.0 overall) starts at $39 a seat on annual billing, beats Aimfox on sequencing (7.0) with native email through Gmail or Outlook, and has the group’s best API docs (17 of 30) on ten mostly read-only endpoints; no MCP and no campaign control by API put its composability at 2.0.
Everything else we’ve scored in outreach lives in the Outreach & Sales Engagement hub.
How we researched this review
- All 85 help articles, the 72-route API reference, the Terms, the privacy policy and the extension listing
- The extension unpacked and its four scripts read
- 72 ledger claims, Aimfox’s and HeyReach’s, checked against Aimfox’s own pages; 39 Trustpilot reviews and G2’s aggregate from 36
- HeyReach, Expandi, Waalaxy and Dripify scored from their own dossiers
Everything here is desk research, no demo, no affiliate link, no campaign of my own: I read what Aimfox publishes, captured and archived on September 3, 2026, and score what holds up. What the method can’t measure (restriction rates, Avatar ban rates, AI output quality) I’ve flagged rather than guessed at. The full protocol is in Inside our LinkedIn review protocol. Aimfox has a right of reply; any response goes here.
FAQ
Is Aimfox safe to use, or can my LinkedIn account get restricted?
Aimfox documents real controls: weekly caps of 10 to 200 per action in the dashboard, an optional warm-up with 7, 14 or 30 day ramps, automatic withdrawal of pending invites, a user-selected login location from its IP pool, and a per-action Cooldown state when LinkedIn limits an account (help articles captured 2026-09-03). The same corpus says LinkedIn can detect lingering third-party tools, the API allows the cap to be raised to 1,000 per week, and the Terms state the customer uses the Service at their own risk and that Aimfox is not responsible for LinkedIn restrictions. No restriction-recovery article exists. Actual restriction rates are not measurable under this method.
Does Aimfox need my LinkedIn password or session cookie?
One of the two. The primary path is a Chrome extension that reads your logged-in LinkedIn session cookies and hands them to app.aimfox.com, after which Aimfox runs the account from its own login location; the fallback is typing your LinkedIn email and password into Aimfox, which the Terms describe as required and stored encrypted. Three vendor documents describe storage differently (not stored, always encrypted, securely encrypted) and none explains where or how. The extension itself is scoped to LinkedIn and Aimfox domains and contains no automation code (bundle inspected 2026-09-03).
Are Aimfox Avatars real LinkedIn accounts, and does LinkedIn allow them?
Aimfox's own help centre states the rented profiles were created by Aimfox and are not associated to real people, that they are warmed and confined to the platform, and that a banned Avatar is replaced within 1 to 2 business days; no ban rate is published. LinkedIn's Prohibited software page states that fake accounts are not permitted. Avatars cost $387 per month for three profiles, carry no trial, and are sold in multi-month non-refundable blocks (captured 2026-09-03).
Are Aimfox's limits really hard-coded?
No. The pricing page says 'Hard-coded limits' and a help article says Aimfox enforces its own 200 per week ceiling, but the dashboard lets each account be set between 10 and 200 per week for connection requests, message requests and InMails, and the API route PATCH /accounts/:id/limits accepts values from 1 to 1,000 per week with a recommendation of 50 to 200. Aimfox computes the daily spread from whatever weekly figure is set (docs and help captured 2026-09-03).
Does Aimfox have a real API and MCP server?
Yes, with limits. The API has 72 documented routes, a self-serve key with read-only scoping on any paid plan, a 60 requests per minute limit, 18 webhook events with documented retries, and an official OAuth MCP server whose published tool list covers 56 tools, about 78% of the routes. The gaps: no OpenAPI spec or SDK (documentation scores 11 of 30 on our rubric), webhooks are not signed, no route connects a LinkedIn account, and a campaign created by API still needs its audience, flow and schedule finished in the dashboard (captured 2026-09-03).
Which AI model does Aimfox use, and is my data used for training?
Not disclosed. AI Variables send six profile fields for the sender and the target (name, occupation, location, current company, time at company) plus your prompt to a language model that no help, legal or marketing page names. Aimfox publishes no DPA and no subprocessor list, and its privacy policy, last updated 17 January 2023, lists twelve third parties with no AI provider among them and says nothing about training. Output quality is not measurable under this method.
Is the trial really free, and what happens with refunds?
The trial is 14 days on the Outreach Seat plan with unlimited campaigns; the pricing page and the free-trial article say no payment method is needed, while the connect-account article says a payment method is required (captured 2026-09-03). The Terms treat refunds case by case, make multi-month plans non-refundable, and leave refunds for loss of LinkedIn access to the Company's sole discretion. Among 39 Trustpilot reviews, two in 2026 cite billing inflexibility or a refused refund and three cite support delays of days.
Is Aimfox GDPR compliant for prospecting data?
The corpus does not let a buyer establish that. There is no DPA, no subprocessor list, no security page and no certification; the privacy policy covers the marketing website, states servers in the USA and Serbia with no region choice, offers Standard Contractual Clauses on request, and provides no erasure path for the LinkedIn members whose profiles are mirrored into the Leads database. The only compliance statement is a help-centre sentence that Aimfox complies with all relevant data protection regulations (captured 2026-09-03).