Attachments

Email attachments your AI can actually send and read.

Most AI email connectors cannot touch attachments, and the ones that can make your AI type the whole file out as code first. Mailbox MCP sends files from your mailbox, the web, your own computer or, in ChatGPT, the chat itself, reads what is inside them, and hands them back to you, with no encoding at all.

  • Encoding Your AI never has to
  • Per email Up to 20 MB
  • Reads PDF, Word, Excel, slides, scans
Sending an email with attachments from an AI: the robot carrying a PDF page, a spreadsheet and a photo, clipped together with a giant paperclip, straight into an open mailbox.

The short version

AI email attachments fail in most connectors because the AI has to type the file out as base64, about 900,000 tokens for every megabyte on OpenAI's models and more on Claude's. Here it never has to. It points at the file and the server fetches it. In ChatGPT that includes an image it has just made. It can also read what is inside, and give you the file back. Claude's own Gmail connector is documented as "metadata only" for attachment content; our test of it shows what that means in practice.

The problem

Why AI email attachments usually fail

An email can only carry text, so every attachment travels inside it as base64: the file rewritten as plain letters and numbers. Your mail program does that for you, instantly. Most AI email connectors hand that job to the AI instead, and ask it to write the whole file out, character by character, as part of its reply.

That is expensive before it starts, because base64 is bigger than the file. The standard that defined it for email says so plainly:

"The encoding and decoding algorithms are simple, but the encoded data are consistently only about 33 percent larger than the unencoded data."

For a mail program, a third bigger costs nothing. For an AI, it's the whole problem. Every one of those characters has to be written as output, and output is the slowest, dearest part of anything an AI does.

A 1 MB PDF becomes about 900,000 tokens of text to type without a single mistake on OpenAI's models, and about 1.3 million on Claude's, measured on real files.

We used to say about 450,000 here. That was our own estimate, never measured, and it was 2 to 3 times too low.

Why an AI writing out an email attachment as base64 goes wrong: the robot knee-deep in coils of paper tape covered in code, trying to feed it into a narrow slot, while the small page it came from sits on a stand.
One small file, typed out as base64
Output tokens an AI must write to attach a file by base64 About 0.9 of a token per byte on OpenAI's tokeniser, measured on real files; Claude's takes about 1.3, so every bar here is a floor
  1. A 10 KB file about 9,000
  2. A 100 KB file about 90,000
  3. A 1 MB PDF about 900,000
  4. A 5 MB file about 4,500,000
  5. Any of them, via Mailbox MCP 0 tokens: the server fetches the file

It burns your tokens

Every character of the file is output the AI has to produce, on your plan or your bill, before it has done anything useful.

It takes ages

An AI writes output a few words at a time. Typing out a whole document that way can take minutes, where a mail program takes a blink.

Then it fails anyway

Past a small file the AI simply cannot write that much in one go. The message goes without the attachment, or not at all.

We have watched it happen. On 30 August 2026, testing an early version of our own server, we asked ChatGPT to make an image and email it. It tried twice to attach the file as base64, was refused both times, and sent the email without it. Nothing warned the recipient that a picture was meant to be there. That test is why the rest of this page exists.

On 28 September 2026 we ran the same test again, with ChatGPT handing us the file itself. It made an image, and the 2.8 MB picture went out attached to a real email. Then it went on a reply, a forward and 4 drafts, each one read back from the mailbox with the picture in it.

Nothing was downloaded and nothing was typed out. The next day we ran it once more, a birthday card this time, and photographed both ends:

ChatGPT asked for a bright birthday card picture for Alex draws a smiling robot holding colourful balloons; asked, with the 365i Mailbox connector, to email it to test@365i.co.uk, it replies that it was sent with the picture attached and a copy filed in Sent.
In ChatGPT: the picture it drew, then "Sent!"
The delivered message's attachment card in webmail: joyful_robot_balloon_celebration.png, about 2.0 MB, showing the same robot-and-balloons picture with Show and Download links.
In the recipient's webmail: the same picture, attached, 2 MB

Sending

How to send an email attachment with AI, without base64

Connect your mailbox to Claude, ChatGPT or any AI that uses MCP, then ask the way you would ask a person: "reply to Sam and attach the invoice he sent last week". Your AI never writes the file out. It says where the file is, and our server fetches it while the message is built, straight from where it lives.

Connecting takes a couple of minutes, for Gmail, Microsoft 365 and Outlook or any other mailbox. If you use ChatGPT, what ChatGPT can do with your email covers the set-up there.

A file can come from 4 places, and each goes straight in; one of them is ChatGPT's own conversation. The last route is only for a small file your AI has to write out itself:

  1. A file already in the mailbox

    The invoice somebody sent, the quote that went out last week. The server copies it across from the message it arrived in.

    Never through the conversation

    MCP Emails publishes this route too.

  2. A file at a web address

    A shared Drive, Dropbox or SharePoint link, or any https address. The server fetches it while the message is built.

    Never through the conversation

    MailMCP publishes this route, in its changelog.

  3. A file on your own computer

    The AI hands you a one-off upload link and you drop the files on it. They wait in your own Drafts folder, not on our servers, until they are attached.

    Never through the conversation

    No other connector we compared publishes one.

  4. A file in your ChatGPT conversation

    An image ChatGPT has just made, a document it built, a file you dropped into the chat. ChatGPT hands the server a link and it is fetched like any other, so nothing is downloaded first.

    Never through the conversation

    No other connector we compared publishes one.

  5. A small file the AI writes itself

    An invitation, a short CSV. The AI writes it out as base64, so it is kept under about 50 KB, and anything bigger goes by upload link instead.

    Through the conversation

    MCP Emails, MailMCP and Google's Gmail server all take files this way. For a file on your computer, it is the only way they offer.

One message

20 MB of attachments, every file on the message together

The first 4 are fetched by the server while the message is built, so a file's size never reaches the conversation and there is no limit from the conversation's length. Only the last passes through it.

Why it matters

Why keeping the file out of the conversation matters

The people who build Claude make the same point about any tool that passes big data through the model. Writing about agents in November 2025, 2 of Anthropic's engineers put it like this:

"Every intermediate result must pass through the model. In this example, the full call transcript flows through twice. For a 2-hour sales meeting, that could mean processing an additional 50,000 tokens. Even larger documents may exceed context window limits, breaking the workflow."

An attachment is exactly that kind of intermediate result, and a heavier one than a transcript. "Breaking the workflow" is the base64 route in 3 words. Fetching the file on the server is how you keep it out of the conversation completely, so the size of the file never reaches your AI and the only ceiling is 20 MB for the whole email.

Attaching a file from your computer to an email without base64: documents lifting off a laptop screen into a glowing drop tray, a cable carrying them into an open mailbox, the robot giving a thumbs-up.
From your computer straight into the email

Attach the next file somebody asks you for from your own AI. The free plan covers it, and the file never has to be typed out.

Reading

Can Claude read email attachments? Here, yes

Not through Claude's own Gmail connector: Claude's help centre says it gives "attachment metadata (not attachment content)". Connect your mailbox through Mailbox MCP and your AI can ask what is inside any attachment. The server opens the file and hands the AI what it says, so a question like "what does this invoice come to?" gets an answer rather than a filename.

We tested it on real mail from real correspondents on 12 September 2026: a 5-page invoice, a 16-sheet spreadsheet and an 8-page scanned letter, read through the live service. Each came back as text, figures or pages the AI could work with.

An AI reading inside an email attachment: the robot reading a document through a magnifying glass, a spreadsheet and a slide spread out beside him, what he reads flowing to a tablet.
What is inside, not just the filename
  • PDF

    PDFs

    Read page by page. A scanned page with no text on it comes back as a picture of the page, so it can still be read.

  • DOCX

    Word documents

    The text of the document, for a contract clause, a CV or the terms somebody sent over.

  • XLSX

    Spreadsheets

    Sheet by sheet, with the formulas worked out, so the totals are the totals.

  • PPTX

    Slide decks

    Slide by slide, for the proposal or the board pack attached to a meeting request.

  • JPG

    Photos and scans

    As pictures, for a receipt somebody photographed or a label on a parcel.

  • CSV

    Text, CSV, HTML

    As they are, for exports, reports and anything a system sent automatically.

A stranger's file, handled as one

An attachment comes from whoever sent it, so it is treated as a stranger's file. Each one is opened in a process of its own with a memory ceiling and a time limit, its type comes from its contents rather than its name, and nothing is kept on our servers afterwards. More on that in whether it is safe to give an AI your email.

Saving

Save email attachments to your computer

Every attachment your AI looks at comes with a private download link, streamed straight from your own mail server. Ask for the file and your AI gives you the link. It lasts 15 minutes, it opens that one file and nothing else, and no copy is ever made on our side.

If your AI can run commands on your computer, as Claude Code, Cursor and similar coding tools can, it can go one step further: fetch that link itself and file the attachment in a folder you name. "Save every invoice from this month into my Accounts folder" becomes one request. Chat apps like claude.ai cannot reach your disk, so there you click the link.

And a file you received can go straight onto a new message, a reply or a draft by reference, without anybody downloading it first. A forward keeps the original's attachments and inline pictures, exactly as your mail program would.

Saving an email attachment to your own computer: the robot filing a paperclipped document from a mailbox into an open desk drawer, beside a laptop showing folders.
From the email into your own folders

Compared

Email connectors and attachments compared

Every cell for another product comes from that company's own published pages, read on and listed in the sources. Of the email connectors we compared, Mailbox MCP is the only one that lets your AI send a file from your own computer without encoding it, and the only one that publishes reading Word, Excel, PowerPoint and scanned pages.

A cross means the product's own pages do not state it on that date. It is not a test result, and if a vendor publishes something we have marked with a cross, we would rather be told. The fuller picture is on the email MCP servers compared and the free Gmail and Outlook connectors compared.

What 6 email connectors publish about attachments, read from each vendor's own pages on 27 September 2026
Attachments Mailbox MCP MCP Emails MailMCP AnyMailMCP Google Gmail MCP Claude Microsoft 365
Attach a file from your own computer, no base64 Yes No No No No No
Attach a file already in the mailbox, no base64 Yes Yes No No No No
Attach a file from a web link Yes No Yes No No No
Attach a file straight from a ChatGPT chat Yes No No No No No
Attach anything to an email at all Yes Yes Yes No Yes No
Read PDF text and plain text inside an attachment Yes Yes No No No No
Read Word, Excel, PowerPoint and scanned pages Yes No No No No No
  • Google's Gmail MCP server

    Takes an attachment only as base64 content, and the same page says creating drafts with attachments is not supported yet.

  • Claude's Microsoft 365 connector

    Rejects attachments in every write tool, in Anthropic's own words: sending, forwarding and drafting alike.

  • MCP Emails

    Attaches a file already in the mailbox by reference, and extracts text from text files and PDFs with a text layer, with no OCR.

  • MailMCP

    Has the AI supply the file's contents, in chunks for a big one, and added a web link route on 24 September 2026.

  • AnyMailMCP

    Downloads and forwards attachments, and publishes no way to attach a new file to an email.

  • Mailbox MCP

    All 4 ways in without encoding, ChatGPT's own chat among them, and reads PDFs, Word, Excel, slides and scans, up to 20 MB an email.

Tested

Claude's Gmail connector and attachments: our test

We tested Claude's own Gmail connector with real attachments on 6 October 2026, on a Gmail account kept for testing, with Claude Opus 5.5 and nothing else connected. Google builds that connector now, and it has no tool for opening or attaching a file. Here's what Claude managed anyway.

What Claude's Gmail connector did with a small and a real-sized PDF attachment, tested on 6 October 2026
Asked toA 1 KB invoice PDFA 1.6 MB PDF
Read what's insideYes, in about 2 minutes, by pulling the whole raw email into the chat and decoding itNo: "no tool for fetching an attachment"
Forward the email with itNot triedYes: Gmail copied the file on Google's side
Attach it to a new emailOnly by writing the whole file out as base64 in the chatNot tried; Claude said it would fail without the file's bytes

In Claude's words

On the bigger file Claude's answer was plain: "The Gmail connector has no tool for fetching an attachment by its ID. It can see the attachment ID but has nothing to pass it to."

On the small one it found a way round, and said where that stops: "a large PDF in RAW format would be bulky and could hit size limits." That matches Anthropic's own wording, attachment metadata and not attachment content, for anything bigger than a receipt.

The picture is the part this page is about. To attach even a 1 KB invoice to a new email, Claude had to write the PDF out character by character before it could ask to send it.

Claude Gmail attachments as base64: Claude's approval card, Claude wants to use Send email message from Gmail, to test@365i.co.uk, subject T12 check: invoice KS-1182 attached, and under Attachments 0 content several lines of base64 text beginning JVBERi0xLjQK, with Decline, Send email and Always allow buttons.
Claude's Gmail connector attaching a 1 KB PDF on 6 October 2026: the file goes in as base64 text, shown here before sending. A real-sized file doesn't fit.

Try it

Things to ask your AI about email attachments

Plain words work. These are the requests people actually make once attachments stop being a problem:

  • "What does the latest invoice in my inbox come to?"

    Finds the message, opens the PDF, reads the total.

  • "Reply to Sam and attach the quote we sent him last month."

    Takes the file from your Sent folder by reference and threads the reply.

  • "Email the brochure on our website to Priya."

    Fetches the file from its web address while the email is built.

  • "Make a birthday card for Jo and email it to her."

    In ChatGPT, draws the picture and attaches it straight from the chat.

  • "I need to send Alex these 3 photos from my laptop."

    Gives you a private upload link; you drop the photos on it; they go on the email.

  • "Which of this week's emails have a signed contract attached?"

    Reads inside the attachments, not just their names.

  • "Save this month's receipts into my Expenses folder."

    In an AI that can run commands, downloads each one into the folder you named.

Every one of those works on the free plan, in Claude, ChatGPT or any AI that speaks MCP.

The other side

What attachments here do not do

The ceiling, the one exception, what depends on the AI app you use, and what each file costs on the free plan.

What AI email attachments here do not do: the robot pointing openly at an empty open mailbox with a stack of papers beneath it.
The limits, pointed at rather than left for you to find
  • There's a ceiling of 20 MB an email.

    That's for all the files together. Your own mail server can set a lower one.

    When it does, the message is refused before it's sent, with the server's own figure named, rather than going out without the file.

  • Outside ChatGPT, a file your AI makes itself is the one exception.

    A small invitation or a short CSV it has just written can go as base64, and that route is kept under about 50 KB. Anything bigger goes by upload link instead.

    So your AI still never has to encode a file. It just sometimes chooses to for a tiny one.

  • Nothing saves itself to your computer.

    An AI in a chat window gives you a download link to click. Only an AI that can run commands on your machine can put the file in a folder for you.

  • Every free plan call counts.

    Each file read or sent is one call, and the free plan has 5 a day per mailbox. Pro has 1,000 a day for £34.99 + VAT a mailbox a year.

  • Only ChatGPT hands over a file from its own chat.

    ChatGPT's link to the file lasts only a few minutes, so the email has to be sent or drafted in the same turn. If it lapses, asking again is enough.

  • Claude gets there another way, and it depends on one setting.

    Claude makes the file in its own workspace, asks for an upload link and uploads the file itself, then attaches it. On it made a PDF chart and sent it that way in 18 seconds, with nobody downloading anything.

    That needs Claude's workspace to be allowed to reach mcp.mailbox-mcp.com. In Claude, go to Settings, Capabilities, and under code execution turn on network egress and allow that address or all domains. On a Team or Enterprise plan, the Owner adds it under Admin settings, Capabilities.

    Where it isn't allowed, Claude gives you the link to drop the file on, and says which setting to change.

Questions about AI email attachments

Can Claude read email attachments?

Not through Claude's own Gmail connector: Claude's help centre says it gives attachment metadata, not attachment content. With Mailbox MCP connected, yes. Claude can read a PDF page by page, a Word document, a spreadsheet sheet by sheet with its formulas worked out, a slide deck, and a scanned page or a photo as a picture. The file is opened on our server and Claude gets what it says.

Can ChatGPT read and send email attachments in Gmail or Outlook?

ChatGPT's Outlook app can list and fetch attachments, but its help page says nothing about attaching a file to an email it sends. With Mailbox MCP, ChatGPT reads attachments in any Gmail, Microsoft 365 or IMAP mailbox, Word, Excel, PowerPoint and scans included, and sends files too. Even an image it has just generated, or a document it made, goes on a send, reply, forward or draft: ChatGPT hands it over as a link, and nothing is downloaded first.

How do I get Claude to send an email with an attachment?

Connect Mailbox MCP to Claude and ask: "reply to Sam and attach the invoice he sent last week". A file in your mailbox goes by reference, a web file by its link, and one on your computer by a private upload link. Claude uploads and attaches a PDF or chart it makes itself, if its network egress setting allows mcp.mailbox-mcp.com. Claude never has to copy a file out, so size is no problem up to 20 MB an email.

Why can't Claude attach files to an email?

Usually because the connector won't let it. Claude's help centre says of its Microsoft 365 connector that attachments are not supported in any write tool, and Google's Gmail MCP server takes an attachment only as base64 text. Base64 makes the AI type the whole file out: about 900,000 tokens a megabyte on OpenAI's models and about 1.3 million on Claude's, measured on real files. So anything bigger than a small file fails. Mailbox MCP fetches the file itself instead.

Is there an MCP server that can send and read email attachments?

Yes: Mailbox MCP sends files from your mailbox, the web, your own computer or a ChatGPT chat, and reads PDFs, Word, Excel, slides and scans. Of the email connectors we compared on 27 September 2026, it's the only one that lets your AI send a file from your own computer without encoding it, and the only one that publishes reading Word, Excel, PowerPoint and scanned pages.

How big an attachment can an AI send by email?

With Mailbox MCP, up to 20 MB an email, for all the files together. Your own mail server can set a lower limit, and if it does the message is refused before it is sent, with the server's figure named. Through a connector that needs base64, the real limit is far smaller: a file has to be typed out by the AI, and much past 50 KB that stops working.

Can AI read PDF, Word and Excel attachments in my inbox?

Yes, with Mailbox MCP. It reads PDFs page by page, scanned pages as pictures of the page, Word documents, spreadsheets sheet by sheet with formulas worked out, PowerPoint slide by slide, text, CSV and HTML, and photos as pictures. We tested it on a 5-page invoice, a 16-sheet spreadsheet and an 8-page scanned letter from a live mailbox.

Is it safe to let an AI read my email attachments?

An attachment comes from whoever sent it, so treat what is inside as untrusted. Each file here is opened in a process of its own with a memory ceiling and a time limit, its type is judged from its contents rather than its name, and nothing is kept on our servers afterwards. Your AI is told that what it reads is data from somebody else, never instructions to follow.

Attribution

Sources on email attachments and base64

Every sentence about another product comes from one of these, read on . Our own side comes from the tool catalogue behind the tools page, which a build check counts against the running server, and from our own tests, dated where they are described.

  • RFC 2045: MIME Part One, section 6.8 The base64 transfer encoding for email, and the quoted sentence on its 33 percent overhead.
  • Anthropic: code execution with MCP Adam Jones and Conor Kelly, published 4 November 2025. The quoted passage on intermediate results passing through the model.
  • Claude help centre: use Google Workspace connectors "Access email metadata, including attachment metadata (not attachment content)", and "Attachment content is not directly accessible through Gmail (metadata only)."
  • Claude help centre: the Microsoft 365 connector "Attachments aren't supported in any write tool: sending, forwarding, and drafting all reject messages with attachments." (The page's own dash is shown here as a colon.)
  • Google: Gmail MCP server, create_draft An attachment's content is "Required. The base64-encoded content of the attachment."; the same page says "Creating drafts with attachments is not supported yet."
  • OpenAI: the Outlook email and calendar apps in ChatGPT list_attachments and fetch_attachment for reading; attaching a file to an outgoing email is not stated.
  • MCP Emails: documentation email_compose takes inline base64 or "a reference to a file already in this inbox", which "the server copies across without the bytes passing through the model"; extract reads text, JSON, CSV/TSV, HTML and text-layer PDFs, with no OCR; no upload route is published.
  • MailMCP: changelog In French. Attachments supplied as content, in chunks through upload_attachment_chunk; on 24 September 2026, "l'IA donne une URL, MailMCP télécharge le fichier" (the AI gives a URL and MailMCP downloads the file).
  • AnyMailMCP get_attachment, "Download any attachment, up to 25 MB."; forward_email, "Forward with the original attachments intact."; send_email, "Send via your own SMTP, plain-text or HTML.", with nothing about attaching.
  • Claude Code issue 96149 A user's report of the base64 wall: past about 5 MB the encoded string exceeds the practical parameter size, so files Gmail itself accepts cannot be sent.
  • Our threat model How a file from a stranger is opened: its own process, a memory ceiling, a time limit, its type from its bytes.
  • OpenAI Apps SDK reference The mechanism behind attaching a file from a ChatGPT chat: a tool lists its file inputs in openai/fileParams, and "Each field receives { download_url, file_id, mime_type?, file_name? }".

Send your next attachment from your AI.

Connect a mailbox in a couple of minutes, ask your AI to attach something, and check the email in your own mail program. The free plan covers it.