Attachments
Email attachments your AI can actually send and read.
Most AI email connectors cannot touch attachments, and the ones that can make your AI type the whole file out as code first. Mailbox MCP sends files from your mailbox, the web, your own computer or, in ChatGPT, the chat itself, reads what is inside them, and hands them back to you, with no encoding at all.
- Encoding Your AI never has to
- Per email Up to 20 MB
- Reads PDF, Word, Excel, slides, scans

The short version
AI email attachments fail in most connectors because the AI has to type the file out as base64, about 900,000 tokens for every megabyte on OpenAI's models and more on Claude's. Here it never has to. It points at the file and the server fetches it. In ChatGPT that includes an image it has just made. It can also read what is inside, and give you the file back. Claude's own Gmail connector is documented as "metadata only" for attachment content; our test of it shows what that means in practice.
The problem
Why AI email attachments usually fail
An email can only carry text, so every attachment travels inside it as base64: the file rewritten as plain letters and numbers. Your mail program does that for you, instantly. Most AI email connectors hand that job to the AI instead, and ask it to write the whole file out, character by character, as part of its reply.
That is expensive before it starts, because base64 is bigger than the file. The standard that defined it for email says so plainly:
"The encoding and decoding algorithms are simple, but the encoded data are consistently only about 33 percent larger than the unencoded data."
For a mail program, a third bigger costs nothing. For an AI, it's the whole problem. Every one of those characters has to be written as output, and output is the slowest, dearest part of anything an AI does.
A 1 MB PDF becomes about 900,000 tokens of text to type without a single mistake on OpenAI's models, and about 1.3 million on Claude's, measured on real files.
We used to say about 450,000 here. That was our own estimate, never measured, and it was 2 to 3 times too low.

- A 10 KB file about 9,000
- A 100 KB file about 90,000
- A 1 MB PDF about 900,000
- A 5 MB file about 4,500,000
- Any of them, via Mailbox MCP 0 tokens: the server fetches the file
It burns your tokens
Every character of the file is output the AI has to produce, on your plan or your bill, before it has done anything useful.
It takes ages
An AI writes output a few words at a time. Typing out a whole document that way can take minutes, where a mail program takes a blink.
Then it fails anyway
Past a small file the AI simply cannot write that much in one go. The message goes without the attachment, or not at all.
We have watched it happen. On 30 August 2026, testing an early version of our own server, we asked ChatGPT to make an image and email it. It tried twice to attach the file as base64, was refused both times, and sent the email without it. Nothing warned the recipient that a picture was meant to be there. That test is why the rest of this page exists.
On 28 September 2026 we ran the same test again, with ChatGPT handing us the file itself. It made an image, and the 2.8 MB picture went out attached to a real email. Then it went on a reply, a forward and 4 drafts, each one read back from the mailbox with the picture in it.
Nothing was downloaded and nothing was typed out. The next day we ran it once more, a birthday card this time, and photographed both ends:
Sending
How to send an email attachment with AI, without base64
Connect your mailbox to Claude, ChatGPT or any AI that uses MCP, then ask the way you would ask a person: "reply to Sam and attach the invoice he sent last week". Your AI never writes the file out. It says where the file is, and our server fetches it while the message is built, straight from where it lives.
Connecting takes a couple of minutes, for Gmail, Microsoft 365 and Outlook or any other mailbox. If you use ChatGPT, what ChatGPT can do with your email covers the set-up there.
A file can come from 4 places, and each goes straight in; one of them is ChatGPT's own conversation. The last route is only for a small file your AI has to write out itself:
-
A file already in the mailbox
The invoice somebody sent, the quote that went out last week. The server copies it across from the message it arrived in.
-
A file at a web address
A shared Drive, Dropbox or SharePoint link, or any https address. The server fetches it while the message is built.
-
A file on your own computer
The AI hands you a one-off upload link and you drop the files on it. They wait in your own Drafts folder, not on our servers, until they are attached.
-
A file in your ChatGPT conversation
An image ChatGPT has just made, a document it built, a file you dropped into the chat. ChatGPT hands the server a link and it is fetched like any other, so nothing is downloaded first.
-
A small file the AI writes itself
An invitation, a short CSV. The AI writes it out as base64, so it is kept under about 50 KB, and anything bigger goes by upload link instead.
Why it matters
Why keeping the file out of the conversation matters
The people who build Claude make the same point about any tool that passes big data through the model. Writing about agents in November 2025, 2 of Anthropic's engineers put it like this:
"Every intermediate result must pass through the model. In this example, the full call transcript flows through twice. For a 2-hour sales meeting, that could mean processing an additional 50,000 tokens. Even larger documents may exceed context window limits, breaking the workflow."
An attachment is exactly that kind of intermediate result, and a heavier one than a transcript. "Breaking the workflow" is the base64 route in 3 words. Fetching the file on the server is how you keep it out of the conversation completely, so the size of the file never reaches your AI and the only ceiling is 20 MB for the whole email.

Attach the next file somebody asks you for from your own AI. The free plan covers it, and the file never has to be typed out.
Reading
Can Claude read email attachments? Here, yes
Not through Claude's own Gmail connector: Claude's help centre says it gives "attachment metadata (not attachment content)". Connect your mailbox through Mailbox MCP and your AI can ask what is inside any attachment. The server opens the file and hands the AI what it says, so a question like "what does this invoice come to?" gets an answer rather than a filename.
We tested it on real mail from real correspondents on 12 September 2026: a 5-page invoice, a 16-sheet spreadsheet and an 8-page scanned letter, read through the live service. Each came back as text, figures or pages the AI could work with.

- PDF
PDFs
Read page by page. A scanned page with no text on it comes back as a picture of the page, so it can still be read.
- DOCX
Word documents
The text of the document, for a contract clause, a CV or the terms somebody sent over.
- XLSX
Spreadsheets
Sheet by sheet, with the formulas worked out, so the totals are the totals.
- PPTX
Slide decks
Slide by slide, for the proposal or the board pack attached to a meeting request.
- JPG
Photos and scans
As pictures, for a receipt somebody photographed or a label on a parcel.
- CSV
Text, CSV, HTML
As they are, for exports, reports and anything a system sent automatically.
A stranger's file, handled as one
An attachment comes from whoever sent it, so it is treated as a stranger's file. Each one is opened in a process of its own with a memory ceiling and a time limit, its type comes from its contents rather than its name, and nothing is kept on our servers afterwards. More on that in whether it is safe to give an AI your email.
Saving
Save email attachments to your computer
Every attachment your AI looks at comes with a private download link, streamed straight from your own mail server. Ask for the file and your AI gives you the link. It lasts 15 minutes, it opens that one file and nothing else, and no copy is ever made on our side.
If your AI can run commands on your computer, as Claude Code, Cursor and similar coding tools can, it can go one step further: fetch that link itself and file the attachment in a folder you name. "Save every invoice from this month into my Accounts folder" becomes one request. Chat apps like claude.ai cannot reach your disk, so there you click the link.
And a file you received can go straight onto a new message, a reply or a draft by reference, without anybody downloading it first. A forward keeps the original's attachments and inline pictures, exactly as your mail program would.

Compared
Email connectors and attachments compared
Every cell for another product comes from that company's own published pages, read on and listed in the sources. Of the email connectors we compared, Mailbox MCP is the only one that lets your AI send a file from your own computer without encoding it, and the only one that publishes reading Word, Excel, PowerPoint and scanned pages.
A cross means the product's own pages do not state it on that date. It is not a test result, and if a vendor publishes something we have marked with a cross, we would rather be told. The fuller picture is on the email MCP servers compared and the free Gmail and Outlook connectors compared.
| Attachments | Mailbox MCP | MCP Emails | MailMCP | AnyMailMCP | Google Gmail MCP | Claude Microsoft 365 |
|---|---|---|---|---|---|---|
| Attach a file from your own computer, no base64 | Yes | No | No | No | No | No |
| Attach a file already in the mailbox, no base64 | Yes | Yes | No | No | No | No |
| Attach a file from a web link | Yes | No | Yes | No | No | No |
| Attach a file straight from a ChatGPT chat | Yes | No | No | No | No | No |
| Attach anything to an email at all | Yes | Yes | Yes | No | Yes | No |
| Read PDF text and plain text inside an attachment | Yes | Yes | No | No | No | No |
| Read Word, Excel, PowerPoint and scanned pages | Yes | No | No | No | No | No |
Google's Gmail MCP server
Takes an attachment only as base64 content, and the same page says creating drafts with attachments is not supported yet.
Claude's Microsoft 365 connector
Rejects attachments in every write tool, in Anthropic's own words: sending, forwarding and drafting alike.
MCP Emails
Attaches a file already in the mailbox by reference, and extracts text from text files and PDFs with a text layer, with no OCR.
MailMCP
Has the AI supply the file's contents, in chunks for a big one, and added a web link route on 24 September 2026.
AnyMailMCP
Downloads and forwards attachments, and publishes no way to attach a new file to an email.
Mailbox MCP
All 4 ways in without encoding, ChatGPT's own chat among them, and reads PDFs, Word, Excel, slides and scans, up to 20 MB an email.
Tested
Claude's Gmail connector and attachments: our test
We tested Claude's own Gmail connector with real attachments on 6 October 2026, on a Gmail account kept for testing, with Claude Opus 5.5 and nothing else connected. Google builds that connector now, and it has no tool for opening or attaching a file. Here's what Claude managed anyway.
| Asked to | A 1 KB invoice PDF | A 1.6 MB PDF |
|---|---|---|
| Read what's inside | Yes, in about 2 minutes, by pulling the whole raw email into the chat and decoding it | No: "no tool for fetching an attachment" |
| Forward the email with it | Not tried | Yes: Gmail copied the file on Google's side |
| Attach it to a new email | Only by writing the whole file out as base64 in the chat | Not tried; Claude said it would fail without the file's bytes |
In Claude's words
On the bigger file Claude's answer was plain: "The Gmail connector has no tool for fetching an attachment by its ID. It can see the attachment ID but has nothing to pass it to."
On the small one it found a way round, and said where that stops: "a large PDF in RAW format would be bulky and could hit size limits." That matches Anthropic's own wording, attachment metadata and not attachment content, for anything bigger than a receipt.
The picture is the part this page is about. To attach even a 1 KB invoice to a new email, Claude had to write the PDF out character by character before it could ask to send it.
Try it
Things to ask your AI about email attachments
Plain words work. These are the requests people actually make once attachments stop being a problem:
"What does the latest invoice in my inbox come to?"
Finds the message, opens the PDF, reads the total.
"Reply to Sam and attach the quote we sent him last month."
Takes the file from your Sent folder by reference and threads the reply.
"Email the brochure on our website to Priya."
Fetches the file from its web address while the email is built.
"Make a birthday card for Jo and email it to her."
In ChatGPT, draws the picture and attaches it straight from the chat.
"I need to send Alex these 3 photos from my laptop."
Gives you a private upload link; you drop the photos on it; they go on the email.
"Which of this week's emails have a signed contract attached?"
Reads inside the attachments, not just their names.
"Save this month's receipts into my Expenses folder."
In an AI that can run commands, downloads each one into the folder you named.
Every one of those works on the free plan, in Claude, ChatGPT or any AI that speaks MCP.
The other side
What attachments here do not do
The ceiling, the one exception, what depends on the AI app you use, and what each file costs on the free plan.

-
There's a ceiling of 20 MB an email.
That's for all the files together. Your own mail server can set a lower one.
When it does, the message is refused before it's sent, with the server's own figure named, rather than going out without the file.
-
Outside ChatGPT, a file your AI makes itself is the one exception.
A small invitation or a short CSV it has just written can go as base64, and that route is kept under about 50 KB. Anything bigger goes by upload link instead.
So your AI still never has to encode a file. It just sometimes chooses to for a tiny one.
-
Nothing saves itself to your computer.
An AI in a chat window gives you a download link to click. Only an AI that can run commands on your machine can put the file in a folder for you.
-
Every free plan call counts.
Each file read or sent is one call, and the free plan has 5 a day per mailbox. Pro has 1,000 a day for £34.99 + VAT a mailbox a year.
-
Only ChatGPT hands over a file from its own chat.
ChatGPT's link to the file lasts only a few minutes, so the email has to be sent or drafted in the same turn. If it lapses, asking again is enough.
-
Claude gets there another way, and it depends on one setting.
Claude makes the file in its own workspace, asks for an upload link and uploads the file itself, then attaches it. On it made a PDF chart and sent it that way in 18 seconds, with nobody downloading anything.
That needs Claude's workspace to be allowed to reach
mcp.mailbox-mcp.com. In Claude, go to Settings, Capabilities, and under code execution turn on network egress and allow that address or all domains. On a Team or Enterprise plan, the Owner adds it under Admin settings, Capabilities.Where it isn't allowed, Claude gives you the link to drop the file on, and says which setting to change.
Questions about AI email attachments
Can Claude read email attachments?
Not through Claude's own Gmail connector: Claude's help centre says it gives attachment metadata, not attachment content. With Mailbox MCP connected, yes. Claude can read a PDF page by page, a Word document, a spreadsheet sheet by sheet with its formulas worked out, a slide deck, and a scanned page or a photo as a picture. The file is opened on our server and Claude gets what it says.
Can ChatGPT read and send email attachments in Gmail or Outlook?
ChatGPT's Outlook app can list and fetch attachments, but its help page says nothing about attaching a file to an email it sends. With Mailbox MCP, ChatGPT reads attachments in any Gmail, Microsoft 365 or IMAP mailbox, Word, Excel, PowerPoint and scans included, and sends files too. Even an image it has just generated, or a document it made, goes on a send, reply, forward or draft: ChatGPT hands it over as a link, and nothing is downloaded first.
How do I get Claude to send an email with an attachment?
Connect Mailbox MCP to Claude and ask: "reply to Sam and attach the invoice he sent last week". A file in your mailbox goes by reference, a web file by its link, and one on your computer by a private upload link. Claude uploads and attaches a PDF or chart it makes itself, if its network egress setting allows mcp.mailbox-mcp.com. Claude never has to copy a file out, so size is no problem up to 20 MB an email.
Why can't Claude attach files to an email?
Usually because the connector won't let it. Claude's help centre says of its Microsoft 365 connector that attachments are not supported in any write tool, and Google's Gmail MCP server takes an attachment only as base64 text. Base64 makes the AI type the whole file out: about 900,000 tokens a megabyte on OpenAI's models and about 1.3 million on Claude's, measured on real files. So anything bigger than a small file fails. Mailbox MCP fetches the file itself instead.
Is there an MCP server that can send and read email attachments?
Yes: Mailbox MCP sends files from your mailbox, the web, your own computer or a ChatGPT chat, and reads PDFs, Word, Excel, slides and scans. Of the email connectors we compared on 27 September 2026, it's the only one that lets your AI send a file from your own computer without encoding it, and the only one that publishes reading Word, Excel, PowerPoint and scanned pages.
How big an attachment can an AI send by email?
With Mailbox MCP, up to 20 MB an email, for all the files together. Your own mail server can set a lower limit, and if it does the message is refused before it is sent, with the server's figure named. Through a connector that needs base64, the real limit is far smaller: a file has to be typed out by the AI, and much past 50 KB that stops working.
Can AI read PDF, Word and Excel attachments in my inbox?
Yes, with Mailbox MCP. It reads PDFs page by page, scanned pages as pictures of the page, Word documents, spreadsheets sheet by sheet with formulas worked out, PowerPoint slide by slide, text, CSV and HTML, and photos as pictures. We tested it on a 5-page invoice, a 16-sheet spreadsheet and an 8-page scanned letter from a live mailbox.
Is it safe to let an AI read my email attachments?
An attachment comes from whoever sent it, so treat what is inside as untrusted. Each file here is opened in a process of its own with a memory ceiling and a time limit, its type is judged from its contents rather than its name, and nothing is kept on our servers afterwards. Your AI is told that what it reads is data from somebody else, never instructions to follow.
Attribution
Sources on email attachments and base64
Every sentence about another product comes from one of these, read on . Our own side comes from the tool catalogue behind the tools page, which a build check counts against the running server, and from our own tests, dated where they are described.
- RFC 2045: MIME Part One, section 6.8 The base64 transfer encoding for email, and the quoted sentence on its 33 percent overhead.
- Anthropic: code execution with MCP Adam Jones and Conor Kelly, published 4 November 2025. The quoted passage on intermediate results passing through the model.
- Claude help centre: use Google Workspace connectors "Access email metadata, including attachment metadata (not attachment content)", and "Attachment content is not directly accessible through Gmail (metadata only)."
- Claude help centre: the Microsoft 365 connector "Attachments aren't supported in any write tool: sending, forwarding, and drafting all reject messages with attachments." (The page's own dash is shown here as a colon.)
- Google: Gmail MCP server, create_draft An attachment's content is "Required. The base64-encoded content of the attachment."; the same page says "Creating drafts with attachments is not supported yet."
- OpenAI: the Outlook email and calendar apps in ChatGPT list_attachments and fetch_attachment for reading; attaching a file to an outgoing email is not stated.
- MCP Emails: documentation email_compose takes inline base64 or "a reference to a file already in this inbox", which "the server copies across without the bytes passing through the model"; extract reads text, JSON, CSV/TSV, HTML and text-layer PDFs, with no OCR; no upload route is published.
- MailMCP: changelog In French. Attachments supplied as content, in chunks through upload_attachment_chunk; on 24 September 2026, "l'IA donne une URL, MailMCP télécharge le fichier" (the AI gives a URL and MailMCP downloads the file).
- AnyMailMCP get_attachment, "Download any attachment, up to 25 MB."; forward_email, "Forward with the original attachments intact."; send_email, "Send via your own SMTP, plain-text or HTML.", with nothing about attaching.
- Claude Code issue 96149 A user's report of the base64 wall: past about 5 MB the encoded string exceeds the practical parameter size, so files Gmail itself accepts cannot be sent.
- Our threat model How a file from a stranger is opened: its own process, a memory ceiling, a time limit, its type from its bytes.
-
OpenAI Apps SDK reference
The mechanism behind attaching a file from a ChatGPT chat: a tool lists its file inputs in
openai/fileParams, and "Each field receives { download_url, file_id, mime_type?, file_name? }".
Send your next attachment from your AI.
Connect a mailbox in a couple of minutes, ask your AI to attach something, and check the email in your own mail program. The free plan covers it.