Compare
Email MCP servers for your own inbox, compared row by row.
Several hosted MCP servers now put an AI on a real mailbox, and they aren't the same product. Here's what Mailbox MCP does, row by row, beside what each of the others publishes about the same thing, read on a stated day.
- Compared 4 hosted MCP servers
- Every cell From the vendor's own pages
- Read between 4 September and 1 October 2026
Start here
Which kind of email MCP server do you need?
Most "best email MCP server" lists are about sending email from an app. That's a different job from letting an AI work the inbox you already have, and the servers built for one don't do the other. This page is about the second.
- An AI working your own inbox, in Gmail, Outlook, iCloud or a mailbox on your own domain, reading, filing, drafting and sending as you: that's this page, and the table below.
- Email sent from your app or agent, receipts, alerts or campaigns from an address that isn't a person's: sending services, not compared here.
- An inbox of an AI agent's own, separate from any person's: not compared here.
- A server on your own computer: self-hosted, open source servers aren't compared either. Remote and local MCP servers explains the difference.
- The connectors built into Claude and ChatGPT: the free Gmail and Outlook connectors, compared job by job.
The comparison
Email MCP servers compared
4 hosted email MCP servers, row by row. Every other server's cell comes from its own published pages, with the date it was read.

The best email MCP server for you depends on whose inbox it opens. An email MCP server for your own inbox connects the AI you already use to a mailbox you already own, and this page compares the other hosted servers doing that job: MailMCP, AnyMailMCP and MCP Emails. New to the term? What an email MCP server is explains it first.
The connectors built into Claude and ChatGPT are a different thing, and they have a page of their own: the free Gmail and Outlook connectors compared.
Every competitor cell comes from that company's own published pages. They were read on , unless a row says otherwise: a row added later, or read again because a vendor changed something, carries its own date beside its name. Each page is linked at the foot of this one.
- : a re-reading moved 8 cells in the other servers' favour.
- : 1 more, because MCP Emails opened a Microsoft sign-in to everyone on 26 September.
- : 4 rows added, and AnyMailMCP's address book cell moved to a tick.
- : the table now lists what Mailbox MCP does, so those 4 rows left it, and 5 rows were added for our routine tools, read on all 3 vendors' pages that day. What we don't do is set out further down.
Our own column comes from the tool catalogue behind the tools page. A build check counts it against the running server, so it can't claim something the software doesn't do.
What a cross means here
The capability isn't in that product's published tool list or documentation on the date its row was read. That's all. It doesn't mean the product can't do it, and it doesn't mean the vendor refused to. Vendors publish what they choose to publish.
If one of them documents something marked with a cross, this table is wrong, and we'd rather be told than look confident.
| Capability | Mailbox MCP | MailMCP | AnyMailMCP | MCP Emails |
|---|---|---|---|---|
| Any IMAP mailbox | Yes | Yes | Yes | Yes |
| A free plan with no card | Yes | Yes | Yes | Yes |
| Microsoft 365 through Microsoft's own sign-in Read | Yes | Yes | No | Yes |
| A calendar as well as the mail | Yes | Yes | Yes | No |
| Google Calendar or a Microsoft calendar, not CalDAV alone | Yes | No | No | No |
| Attach a file already in the mailbox, by reference Read | Yes | No | No | Yes |
| Attach a file from a web link Read | Yes | Yes | No | No |
| Attach a file through an upload link you drop files on Read | Yes | No | No | No |
| Attach an image or file ChatGPT has just made, straight from the chat Read | Yes | No | No | No |
| Read the text inside an attachment Read | Yes | No | No | Yes |
| Read Word, Excel, PowerPoint and scanned pages Read | Yes | No | No | No |
| Download an attachment's file, not only its name Read | Yes | No | Yes | Yes |
| A forward keeps the original attachments Read | Yes | No | Yes | Yes |
| Replies carry In-Reply-To and References Read | Yes | No | No | Yes |
| Edit a draft that is already in the mailbox Read | Yes | No | No | Yes |
| Reading a message never marks it read Read | Yes | No | No | Yes |
| Check bounces, delivery and read receipts | Yes | No | No | No |
| Ready-made email routines your own Claude or ChatGPT runs on a schedule Read | Yes | No | No | No |
| A routine's card shows whether its scheduled run happened Read | Yes | No | No | No |
| Catch up on new mail in one call, people kept apart from newsletters Read | Yes | No | No | No |
| A tool that lists the people still waiting on a reply from you Read | Yes | No | No | No |
| A tool that lists what you sent that nobody has answered Read | Yes | No | No | No |
| Names and fences instructions hidden inside a message Read | Yes | No | No | No |
| Two-factor authentication on the account | Yes | No | No | No |
| A connection can be held to read only, enforced by the server Read | Yes | No | Yes | Yes |
| An address book as well as the mail, by its CardDAV address Read | Yes | Yes | Yes | No |
| Google contacts, through Google's own sign-in Read | Yes | No | No | No |
How many tools each email MCP server publishes
The counts sit outside the table above, because a number isn't a tick. More tools isn't automatically better. But it's the difference between a server that can file, flag and check a delivery and one that can read and send.
| Server | Tools it publishes | Where the count comes from |
|---|---|---|
| Mailbox MCP | 37 mail tools. Up to 63 on a Microsoft 365 mailbox with its calendar and its Outlook contacts, and up to 69 where the account also holds Team Access | Our tool catalogue, which a build check counts against the running server |
| MailMCP | 15 | Its getting-started page, read on 1 October 2026. It stated 15 plus attachments on 4 September 2026 |
| AnyMailMCP | 30, with its calendar, its address book and a watch for new mail among them | Its home page, read on 1 October 2026. It stated 18 on 4 September 2026 |
| MCP Emails | 17, or 23 where a key has every scope | Its documentation, read on 30 September 2026. It stated 10 on 4 September 2026 |
A read-only connection: 3 ticks, 3 different mechanisms
The row on holding a connection to read only has 3 ticks, and they aren't the same thing. Here's what each server states.
| Server | How a connection is held to read only | Set for |
|---|---|---|
| Mailbox MCP | A permission level (Read only, Draft and file, Send and delete), chosen when you approve the connection and changed in the control panel without reconnecting. A limit on the mailbox, which no connection to it can go above. The server enforces both on every call, before the call is counted. | Each connection, capped by the mailbox |
| AnyMailMCP | 3 access levels, which it states are enforced on its servers | Each mailbox |
| MCP Emails | A token or an API key is scoped to the permissions approved for it, from a list of 9 scopes | Each token or key |
| MailMCP | No level published: one client ID and secret per mailbox | Nothing published |
Attachments
How each email MCP server handles attachments
All 4 of these servers can put a file on a message, and most feature lists stop there. What decides what you can actually send is where the file travels.
The obvious way has the AI write the file out as base64 text. That's a third bigger than the file, and roughly 900,000 tokens of output for every megabyte on OpenAI's models and 1.3 million on Claude's, measured on real files. Past a certain size the AI runs out of room, and the message goes without the file.
Of the 4 email MCP servers compared here, only Mailbox MCP publishes all 5 ways to attach a file: one already in the mailbox, a web link, an upload link you drop files on, a file straight from a ChatGPT chat (an image it has just made, say), and base64 as a last resort, for a small file the AI made itself.
The server fetches the first 4 itself while it builds the message. So the AI never has to write a file out, and the length of the conversation sets no limit. The only ceiling is 20 MB for the whole message. Reading and saving files, and the free connectors too, are covered on AI email attachments.
Where a file goes
- A file you upload waits in your own Drafts
- A download link streams from your mail server
- The link stops working after 15 minutes
- A file being read opens in a process of its own
- Copies kept on our servers none
-
A file already in the mailbox
The invoice somebody sent, the quote that went out last week. The server copies it across from the message it arrived in.
-
A file at a web address
A shared Drive, Dropbox or SharePoint link, or any https address. The server fetches it while the message is built.
-
A file on your own computer
The AI hands you a one-off upload link and you drop the files on it. They wait in your own Drafts folder, not on our servers, until they are attached.
-
A file in your ChatGPT conversation
An image ChatGPT has just made, a document it built, a file you dropped into the chat. ChatGPT hands the server a link and it is fetched like any other, so nothing is downloaded first.
-
A small file the AI writes itself
An invitation, a short CSV. The AI writes it out as base64, so it is kept under about 50 KB, and anything bigger goes by upload link instead.
What the other 3 email MCP servers publish
Read on . None of the 3 publishes an upload link. On 28 September 2026, none published a way to attach a file from a ChatGPT chat.
-
MCP Emails: by reference, or base64.
It attaches a file already in the mailbox by reference, and otherwise takes base64.
-
MailMCP: the AI supplies the file, or a web link.
The AI supplies the file's contents, in chunks for a big one. Its changelog added a web-link route that same day.
-
AnyMailMCP: none for a new message.
It publishes no way to attach a file to a new message.
Reading what is inside an attachment
Ask what an attached invoice comes to, and Mailbox MCP opens the file on the server and hands the AI what it says:
- a PDF, page by page, and a scanned page with no text on it as a picture of the page;
- a Word document, and a slide deck slide by slide;
- a spreadsheet sheet by sheet, with its formulas worked out;
- text, CSV and HTML, and a photo as a picture.
We tried it on files real correspondents had sent: a 5-page invoice, a 16-sheet spreadsheet and an 8-page scanned letter, through the live service on .
An attachment can come from a stranger, so each file opens in a process of its own, with a memory ceiling and a time limit. What a file is comes from its bytes, not its name.
Word, Excel, PowerPoint and scanned pages are read here and by none of the other 3, going by what each publishes. MCP Emails publishes the nearest thing: an extract action for text files, JSON, CSV and TSV, HTML, and PDFs with a text layer. It says it does no OCR (reading the words in a picture of a page). AnyMailMCP's read_email gives attachment metadata, and MailMCP's lists a message's attachments.
Reusing a file you received
A forward carries the original's attachments and inline images. MCP Emails and AnyMailMCP publish a forward that keeps them too.
A file you received can also go onto a new message, a reply or a draft by reference, without anybody downloading it first.
Every attachment also comes back with a download link for you, streamed from your mail server. AnyMailMCP and MCP Emails publish a download of the file itself, up to 25 MB, which MCP Emails hands to the AI as base64 or an embedded resource.
Nothing kept on our systems
A file being sent or read passes through memory on its way, and isn't written anywhere here. An upload waits in your own Drafts folder until it's attached. A download streams straight from your mailbox to you.
The mechanism is set out under reading what is inside an attachment, and what's kept at all is on the privacy page.
The difference you live with
It leaves a mailbox you recognise in Outlook
Anything can put a message on the wire. What decides whether you keep using a mail tool is what your mailbox looks like a week later, in Outlook, when the AI is nowhere near it.

A mail tool that can only list and send looks fine in a demo, and leaves a mess behind:
- Replies arrive as loose messages beside the conversation, not inside it.
- Drafts sit somewhere the AI can see and your mail client can't, so you open Outlook and the half-written message isn't there.
- Forwards arrive without the attachment that was the whole reason for forwarding.
- Reading a message quietly marks it read, so your unread count stops meaning anything.
None of it gets reported as a bug. People just stop trusting the tool and go back to doing it themselves.
Mailbox MCP is built the other way round. It's the founding rule of the engine, not a feature on a list: you shouldn't be able to tell, from your own mail client, that an assistant handled a message rather than you.
A reply threads. A draft sits in Drafts, where you can open it, finish it and send it yourself, and editing it replaces it rather than leaving the old one behind. A forward carries its attachments and inline images, and takes a Cc if you want one. Delete moves to Trash, so it's recoverable exactly as if you'd clicked Delete.
Everything you'd do in Outlook yourself, your AI can do through the connector, and it leaves behind the mailbox you'd have left. That's the difference the table keeps finding, row after row. It isn't a coincidence: it's one design decision, showing up in 9 places.
- A reply lands inside the thread In-Reply-To and References
- A draft waits in Drafts saved with the Draft flag
- Editing a draft replaces it no second copy left behind
- A forward carries its attachments and its inline images
- Reading leaves it unread flags untouched
- Sent mail is filed once 1 copy, Message-ID matched
- Deleting moves to Trash a move, never an erase
- A move keeps its dates and its flags
- A new folder shows up in Outlook created and subscribed
-
You can check every one of those in your own mail client afterwards.
That's the only test that counts: not our API response, not a green test run, but the mailbox opened in another program.
-
Several were checked in Outlook, not in a test harness.
A bug that files no Sent copy is invisible to a test written against the engine that failed to file it. The full behaviour is under everything the AI can do with your email, and the measured figures are on the home page.
Connections
Microsoft 365 and the app password problem
Microsoft has switched off password sign-in for IMAP. 3 of these 4 servers now use Microsoft's own sign-in instead, and the difference left between them is how they send.

Most email MCP servers connect a mailbox the way an old desktop client did. You hand over a host, a port, a username and a password, and the server logs in as you.
For a mailbox on a web host that's fine, and it's how our own IMAP route works too. For Microsoft 365, it's a route Microsoft has been closing for years, and the closing isn't a prediction. Microsoft's own guidance on the deprecation of Basic authentication in Exchange Online opens like this:
Basic authentication is now disabled in all tenants.
We removed the ability to use Basic authentication in Exchange Online for Exchange ActiveSync (EAS), POP, IMAP, Remote PowerShell (RPS), Exchange Web Services (EWS), Offline Address Book (OAB), Autodiscover, Outlook for Windows, and Outlook for Mac.
Microsoft, Deprecation of Basic authentication in Exchange Online
The sentence to notice is the second, because it names IMAP. The same document adds, in a note rather than a headline, that the deprecation of basic authentication also prevents the use of app passwords with apps that don't support 2 step verification.
That's the mechanism most email MCP servers ask a Microsoft 365 customer to use. The company that runs the mailbox describes it as something it has already withdrawn.
Signing in with Microsoft instead
There's a legitimate answer: OAuth (Microsoft's own sign-in) over IMAP. Microsoft released OAuth 2.0 support for POP, IMAP and SMTP AUTH in 2020, and a server can use it. Here's where the other 3 stand:
| Server | Signs in with Microsoft | What it publishes |
|---|---|---|
| MailMCP | Yes, since | Its changelog records a "Connecter avec Microsoft" button that day, over OAuth2 and XOAUTH2 for IMAP and SMTP, so the table gives it the tick |
| MCP Emails | Yes, open to everyone since | Its home page, read again on , offers "Microsoft sign-in (OAuth 2.0) for Outlook / Microsoft 365" |
| AnyMailMCP | It still names none | It connects every mailbox by host, port and app password |
The difference left: how the mail is sent
One difference remains under the sign-in, and it's the one an IT department notices. MailMCP's own Outlook page says it "routes through standard IMAP/SMTP (outlook.office365.com:993 / smtp.office365.com:587)".
Sending with XOAUTH2 over SMTP needs SMTP AUTH. Microsoft's page on it says that where security defaults are on, "SMTP AUTH is already disabled in Exchange Online".
Mailbox MCP sends through Microsoft Graph instead, so nobody has to ask for SMTP AUTH to be switched on. So does MCP Emails: its README says "Outlook uses Microsoft Graph with 'Sign in with Microsoft', not IMAP".
What we hold for a Microsoft 365 mailbox
Mailbox MCP connects Microsoft 365 through Microsoft's own sign-in. Your password is never typed into this site and never reaches us.
What we receive is a token (a key that works only for what you agreed to), scoped to the permissions the consent screen listed. You can withdraw it from your Microsoft account without involving us, and Microsoft can expire it on its own terms.
On that one row, the difference isn't a feature. It's whether the connection is built on something its own vendor still supports.
Diaries
Calendar support is not the same as CalDAV
2 of the 3 competitors offer a calendar, and both offer it over CalDAV. CalDAV is a good, open standard, and it reaches a Fastmail, iCloud, Nextcloud or mailbox.org diary properly.
What it doesn't reach, in the way a generic client needs, is a Google Calendar or a Microsoft 365 calendar. Between them, those are most business diaries in the country.
So "calendar included" on a feature list and "my calendar included" are different claims, and you only see the gap once you've paid.
Mailbox MCP connects all 3. A Microsoft calendar comes on the same sign-in as the mail, a Google Calendar through Google's own sign-in, and any CalDAV server by its address. The calendar guide shows which route your diary needs.

Safety
What happens when the email is the attack
Anyone can put text in your inbox. What matters is whether the server does anything about the instructions hidden in it.

Every product on this page gives an assistant 3 things at once: your private mail, a stream of text written by strangers, and the ability to send. Simon Willison named that combination the lethal trifecta.
The name is the useful part. Each piece is harmless on its own, and the danger is only in the set.
Access to your private data is one of the most common purposes of tools in the first place. Exposure to untrusted content means any mechanism by which text or images controlled by a malicious attacker could become available to your LLM.
Simon Willison, The lethal trifecta for AI agents, 16 June 2025
Read that against a mailbox and the point lands hard: an inbox is the purest source of untrusted content most people own. Anyone can put text in it without being invited. That's what email is.
So a mail connector doesn't have an occasional prompt injection risk (an instruction hidden in a message, aimed at the AI reading it). It has a permanent one, by construction. The only question is whether the server does anything about it.
Ours does 3 things with every message it hands the assistant:
- marks what the message says as content, not instruction, before the assistant reads it;
- carries the receiving server's verdict on who really sent it;
- reports any writing a person wouldn't have seen.
Read again on , MCP Emails now publishes the first of those: its documentation says that in an interactive session "the content is marked as untrusted data". None of the 3 documents naming hidden writing or carrying the sender verdict, and MailMCP and AnyMailMCP document none of it.
That's a cross for a lack of published evidence, not a finding of neglect. It's exactly the sort of thing a buyer should ask about. What we do is written up on the security page and, attack by attack, in the threat model, in enough detail to argue with.
Limits
What Mailbox MCP doesn't do
The table shows what Mailbox MCP does. Here's what it doesn't, in one place, so nothing comes as a surprise after you've connected a mailbox.
Where there's another way to get the same result with Mailbox MCP, it's beside the limit.

-
One connector opens one mailbox.
3 mailboxes are 3 connectors, each signed in on its own. Each gets its own permission level, so one can be held to read only while another sends. The multiple accounts guide walks through it.
-
No send-later held on our server.
An email goes when your AI sends it. To send one at a set time, your AI saves a draft and sends it from a scheduled task in its own app.
-
Nothing runs without an AI.
There are no rules or new-mail alerts on our server. Everything is done by an assistant: in a conversation, or in a routine your own Claude or ChatGPT runs on a schedule.
-
Gmail connects with an app password.
It needs 2-Step Verification with a phone or an authenticator app. It can be withdrawn on its own and never touches your Google password. Google Calendar and Google contacts connect through Google's own sign-in, set out on the Gmail page.
-
No review card inside the chat.
On a shared mailbox, a draft waiting for approval is listed by the owner's assistant and sent when they say so. It's approved in the conversation, not on a card drawn inside the chat.
-
Pro is priced per mailbox.
Each mailbox on Pro is £2.92 a month, paid annually at £34.99 + VAT, with 1,000 calls a day. A free mailbox costs nothing and has 5 calls a day, and one account holds as many as you like. See pricing.
Questions people ask
Which email MCP servers work with Microsoft 365?
Microsoft has turned off Basic authentication for IMAP and POP in Exchange Online, and notes that this also stops app passwords. 3 of the 4 we compared sign in with Microsoft instead: Mailbox MCP, MailMCP since 17 September 2026, and MCP Emails since 26 September 2026. MailMCP sends over SMTP, which needs SMTP AUTH, already off wherever security defaults are on. Mailbox MCP and MCP Emails send through Microsoft Graph, so IT has nothing to switch on.
Do any email MCP servers connect a Google Calendar?
2 of the other 3 servers we compared offer a calendar, both over CalDAV. That reaches a Fastmail, iCloud or Nextcloud diary, but not a Google Calendar or a Microsoft 365 calendar, because neither speaks CalDAV the way a generic client needs. Mailbox MCP connects all 3: a Microsoft calendar on the same sign-in as the mail, a Google Calendar through Google's own sign-in, and any CalDAV server by address. CalDAV support isn't calendar support.
Which email MCP servers can send and read attachments?
All 4 can put a file on a message, but only Mailbox MCP publishes all 5 ways in: a file already in the mailbox, a web link, an upload link, a file from a ChatGPT chat, and base64 for a small file the AI wrote. The server fetches the first 4, so the only ceiling is 20 MB a message. It also reads Word, Excel, PowerPoint and scanned pages, which none of the other 3 publishes.
Do email MCP servers store my attachments?
Mailbox MCP doesn't. A file being sent or read is handled only on its way, and isn't written anywhere on our systems. An upload waits in your own Drafts folder until it's attached, and a download link streams the file from your mail server and stops working after 15 minutes. So the file stays in your mailbox, whichever way it travels.
What does a cross mean in the comparison table?
It means the capability isn't in that product's published tool list or documentation on the date its row was read: 4 September 2026, unless a later date is printed beside the row. It doesn't mean the product can't do it, or that the vendor refused to. Every source is linked at the foot of the page. If a product documents something marked with a cross, the table is wrong, and we'd rather be told.
How much does Mailbox MCP cost?
Every mailbox starts free, with 5 MCP calls a day and no card. Pro is £2.92 a month per mailbox, paid annually at £34.99 + VAT, with 1,000 calls a day. One account holds as many mailboxes as you like, so you can put one on Pro and keep the others free. Routines work on every plan, free included.
What doesn't Mailbox MCP do?
One connector opens one mailbox, so 3 mailboxes are 3 connectors. It holds no send-later on its own server: your AI sends a draft at a set time from its own scheduled task. Nothing runs without an AI, so there are no rules or new-mail alerts on the server; a routine your own Claude or ChatGPT runs on a schedule is how mail gets looked at while you're away. And Gmail connects with an app password, while Google Calendar and contacts use Google's own sign-in.
How is this comparison kept accurate?
Every competitor cell comes from that vendor's own pages, dated, and linked at the foot of the page. Our own column comes from the tool catalogue behind our tools page, which a build check compares with the running server. We read the table again when a competitor ships something or a reader says a cell is wrong: on 24 September 2026 that moved 8 cells their way, and on 6 October 2026 every other server's cell in 5 new rows for our routine tools was read on its own pages.
Attribution
Sources
Every competitor cell above comes from one of these pages. Each was read on , or on the later date printed beside its row:
- for the read-only row;
- for every row read again that day, the attachment rows among them;
- for the row on attaching a file ChatGPT has just made;
- for the Microsoft row;
- for the 2 contacts rows and 2 of the tool counts;
- for the 5 routine rows.
Where a page states a permission mechanism, its note quotes it. Our own column comes from this site's tool catalogue, and the connection routes set out on our security and privacy pages.
The address book cell comes from the CalDAV and CardDAV page, where connecting one is set out. The Google contacts cell comes from the Google contacts section of the Gmail page, where connecting them is.
-
MailMCP
- Tool count, CalDAV calendar, CardDAV address book, IMAP and SMTP provider list, free plan, and hosting in France.
- No permission level or read-only mode is stated here, on its getting-started documentation or on its comparison page.
- The address book tick is the row "CardDAV address book" in its own feature table, under "Comparison".
- Read with its getting-started documentation for the Google contacts row: the address books it names are CardDAV ones, and nothing reaches Google contacts.
- Both contacts rows read again, with the same result.
-
MailMCP: getting started
- Its published tool list: read_email, send_email "with CC", and draft_email "Save as draft", with no tool that edits a draft and no forward or download tool. Nothing on threading headers, the read flag or reading an attachment's contents.
- Still "15 tools", the count in the table of published tools.
- The same 15 tools, none of which lists the mail you owe a reply, the mail you sent that nobody answered, or what came in since you last looked. "Follow up in 3 days if no reply" is an example under its delayed sending.
-
MailMCP: changelog
In French.
- On 17 September 2026, a "Connecter avec Microsoft" button over OAuth2 and XOAUTH2 for IMAP and SMTP, which is the Microsoft 365 tick.
- On 24 September 2026, attachments by link, "l'IA donne une URL, MailMCP télécharge le fichier" (the AI gives a URL and MailMCP downloads the file), which is the web link tick.
-
MailMCP: Outlook MCP vs native connector
- How its Microsoft route sends: "MailMCP routes through standard IMAP/SMTP (outlook.office365.com:993 / smtp.office365.com:587)."
- MailMCP: best email MCP servers Their own comparison, used for how they describe their connection method and their tool set, not for their view of anybody else.
-
AnyMailMCP
- 18 tools, its IMAP provider list, CalDAV calendars, attachment download to 25 MB, and its plan limits.
- Under "You set the permissions": "Read-only, read & organize, or full access", chosen per mailbox and "enforced on our servers no matter what the agent asks."
- For the address book row: no address book, CardDAV or contacts feature is stated anywhere on the page.
- Still no contacts feature, for the Google contacts row.
- For the attachment rows: get_attachment, "Download any attachment, up to 25 MB."; forward_email, "Forward with the original attachments intact."; read_email, "Full message body and attachment metadata."; send_email, "Send via your own SMTP, plain-text or HTML.", with nothing about attaching.
- For the familiarity rows: create_draft, with no tool that edits a draft. And no Microsoft sign-in.
- "Thirty tools, one connection", among them list_address_books, "CardDAV address books on your account.", which is the address book tick.
- The same 30 tools: watch_inbox and search_emails, and none that lists unanswered mail, mail waiting on a reply, or runs a routine.
- A free plan of "15 calls/day · 45/week · 150/month"; and, of Microsoft, "Outlook and Microsoft 365 are next."
-
MCP Emails
- App passwords for IMAP providers, no calendar, and its plans.
- For the Google contacts row: contact_search is described as "Find people by name or email with a live scan of recent matching mail. Nothing is stored.", a search of the mail rather than of Google contacts.
- For the Microsoft row: "Microsoft sign-in (OAuth 2.0) for Outlook / Microsoft 365 (a work or school account may need its IT admin to approve the app once)".
-
MCP Emails: documentation
- Under "OAuth connection": "Tokens are scoped to exactly the permissions you approve", followed by its 9 scopes. An API key is created with "the scopes your agent needs".
- For the address book row: its contact_search tool is described as "Find correspondents by name or email with a live scan of your mailbox: there is no stored contact list", a search of the mail rather than an address book. CardDAV appears nowhere on the page.
- 6 cells moved in its favour that day, and a new row on reading an attachment's text gave it 1 more tick. The 3 readings below are the ones behind them.
- Attachments: email_compose takes an attachment as inline base64 or "a reference to a file already in this inbox", which "the server copies across without the bytes passing through the model". A forward relays "the original byte for byte (HTML, inline images and attachments intact)".
- Reading a file: email_read can download an attachment "as base64", up to 25 MB, or extract "readable text from one selected attachment" from text, JSON, CSV/TSV, HTML and text-layer PDFs, with no OCR.
- Replies, drafts and safety: a reply sets threading headers "automatically"; the draft tool can "update" a draft in the Drafts folder; reading marks nothing read unless mark_as_read is set, "Default false"; and in an interactive session "the content is marked as untrusted data".
- The tool count: "17 tools", and "A full-scope key sees 23 tools in tools/list".
- "Clients that support MCP prompts can offer built-in routines for careful inbox triage, open-loop review, reply-draft preparation, organization proposals, and scheduled-send review. Prompts never grant permissions or run automatically." Prompts, not routines that run, and no tool that lists mail owed or waiting a reply.
- Its contact_search still reads "there is no stored contact list", for the address book row.
-
MCP Emails: GitHub README
- How its Microsoft route works: "Outlook uses Microsoft Graph with 'Sign in with Microsoft', not IMAP", with the Outlook permissions Mail.ReadWrite and Mail.Send.
- The file's history dates the change: until 26 September 2026 it described the Outlook sign-in as "built, gated pending verification" and "hidden from the connect UI", and that day's commit launched it.
- Microsoft: deprecation of Basic authentication in Exchange Online Basic authentication disabled in all tenants, the protocol list including IMAP, the note on app passwords, and OAuth 2.0 support for POP, IMAP and SMTP AUTH from 2020.
-
Microsoft: enable or disable SMTP AUTH in Exchange Online
- "If security defaults is enabled in your organization, SMTP AUTH is already disabled in Exchange Online."
- Simon Willison: the lethal trifecta for AI agents The quoted definition of private data, untrusted content and the ability to communicate externally.