How it works

Connect a mailbox, then just ask.

Mailbox MCP is a remote MCP server, so there's nothing to install and nothing running on your computer. You connect a mailbox you already own, add one URL to your AI app, and the mail tools appear.

  • Set-up time About 2 minutes
  • To install Nothing
  • Works with Any MCP client

Reviewed and listed by Anthropic and OpenAI

Set-up

The 3 steps

Connect a mailbox, add one URL to your AI app, then ask for what you want done.

Adding Mailbox MCP to an AI app: the robot kneeling to plug a single glowing cable from an open mailbox into the port of a screen.
One URL, and the mail tools appear
  1. Connect the mailbox you already own

    Sign in to the control panel and add a mailbox. Microsoft 365 takes one Microsoft sign-in. Gmail takes an app password. Anything else takes the IMAP settings your mail app already uses.

    Each has its own guide, and each guide is honest about the awkward parts: Microsoft 365, Gmail, or any IMAP host.

  2. Add the server to your AI client

    The panel gives you a URL. Add it to your AI app as a connector, and the mail tools appear in the list of things it can use.

    That's the whole integration. There's no download, no local process, and no key file on your laptop that stops working when you get a new one.

    Claude and ChatGPT are where most people start, so they're the 2 this site names. The same URL works anywhere else that speaks MCP.

  3. Ask for what you would have done yourself

    There are no commands and no syntax to learn. You describe the outcome, and your assistant uses the tools to get there.

    Find the thread with Hollis about the March invoice,
    reply attaching the revised quote from my Drafts,
    and file the original under Clients.

    It searches the mailbox and opens the thread. It writes the reply with the right headers, so it lands inside the conversation rather than beside it. Then it attaches the file, sends, and moves the original. Afterwards, the mailbox looks as if you'd done it yourself.

    And a question you ask every morning can stop being one you ask: set it once as a routine and your AI asks it for you.

New: routines

Then set it once: an email routine asks for you

Step 3 is a question you type. A routine is the same kind of question, asked for you, at the time you chose, by your own Claude or ChatGPT. Add one from the mailbox's Routines tab, confirm it in your AI, and this is what happens each time it is due. Nothing about connecting changes: a routine reaches your mailbox through the same connection, at the same level, and no further.

A routine, the same job at the same time: the robot pinning an envelope into the last of five columns on a week board, each column with a clock at the top showing the same time and an envelope pinned beneath it.
  1. Morning brief, 07:00

    Your AI starts the task

    Claude or ChatGPT starts it in its own scheduler, at the time you chose, whether or not your computer is on.

  2. list_identities

    It checks in

    Its first call asks which addresses this mailbox may use. That makes sure it is in the right mailbox, and it is how the routine's card knows it ran.

  3. catch_up

    It does the job

    One call answers "what has come in?", and a message is opened only when its preview is not enough. A Replies waiting routine also saves its drafts in your Drafts folder.

  4. On its card: ran today

    You read the result

    The brief is in your AI app, as any scheduled task's result is, and its card on the Routines tab says when it ran and how many calls it made.

Tool surface

Every tool your AI client gets, and what each one does

37 email tools, grouped by what they're for, and every mailbox gets all of them. This is the whole list, so you can judge it before you connect anything. Each one is a deliberate action, taken because you asked for something that needs it.

If the idea is new, here's what an email MCP server actually is. The complete tool reference groups the same tools by what your AI app will stop and ask you about, with what each one refuses as well as what it does. The plain-English version, with what you control, is on the features page.

The 37 Mailbox MCP tools explained: a robot pointing at a board listing them, with a mailbox wired to the board beside him.
37 email tools on every mailbox, up to 21 more with a calendar, 6 more with Team Access, 5 more with an address book, and nothing that is not on these lists

Read 11 tools

Search, threads, attachments, who really sent it

  • list_mailboxes
  • list_emails
  • read_email
  • read_attachment
  • read_thread
  • catch_up
  • waiting_on
  • owed_replies
  • search_emails
  • select_emails
  • find_contact

Send 7 tools

As any of your addresses, or as a real draft

  • draft_email
  • draft_reply
  • draft_forward
  • update_draft
  • list_identities
  • send_email
  • send_draft

Reply 1 tool

In thread, carrying the right headers

  • reply_email

Forward 1 tool

With everything the original carried

  • forward_email

File 9 tools

Move, archive or junk 500 at once

  • create_upload_link
  • create_folder
  • move_email
  • delete_email
  • archive_email
  • mark_junk
  • not_junk
  • rename_folder
  • delete_folder

Flag 4 tools

Mark read, unread or flagged, on request

  • mark_read
  • mark_unread
  • flag_email
  • unflag_email

Check 4 tools

Bounces, receipts, trust records, uploads

  • check_bounces
  • check_deliverability
  • check_upload
  • check_receipts

Marking read is an action, not a side effect

Reading a message through Mailbox MCP doesn't mark it read. That's a separate tool, mark_read, used only when you ask for it.

It matters more than it sounds. An unread count that changes on its own stops meaning anything, and then you've lost a tool you relied on without noticing.

Connected separately

Calendar tools, and the mailboxes that get them

Connecting a mailbox doesn't connect a diary. They're separate services, so a calendar is a step of its own. Until you take it, you get the email tools and nothing else, which is worth knowing before you choose a plan rather than after.

A calendar connected to Mailbox MCP as well as a mailbox: the robot pointing at one of 3 days blocked out in blue on an open desk calendar, a reminder bell on the page, a mailbox on its post behind him.
The diary is a connection of its own

There are 3 ways to connect one. A Microsoft 365 mailbox uses the first. Every other mailbox can take either of the other 2, whoever hosts the mail.

  • Microsoft 365: approve calendar access.

    There's no second sign-in: a Microsoft 365 mailbox is asked for calendar access on the same sign-in as the mail. Approve it, and your AI app is handed all 21 calendar tools as well as the email ones.

  • Any other calendar: a CalDAV address.

    IMAP is a mail protocol with no calendar inside it, at any host, so connecting the mail can't connect the diary. Most hosts run a separate calendar server speaking CalDAV. Give us its address and the calendar tools appear.

    Fastmail, iCloud and Nextcloud all run one. On Fastmail and iCloud the same app password opens both, so it's usually one field.

  • Google Calendar: sign in with Google.

    It's a sign-in rather than an address, and it works on any mailbox, not only a Gmail one. You choose an account, Google shows you what's being asked for before you approve, and it covers the diary only, never the mail.

    The Google account doesn't have to match the mailbox's address. That matters more often than it sounds: plenty of people keep the work diary and the work mail in different places.

  • Why a Gmail app password can't open the diary.

    An app password, the kind a Gmail mailbox connects with, is a mail credential: it opens IMAP and SMTP and nothing else. Google runs a CalDAV server too, and it refuses that same app password, so no amount of pasting would get you in.

    A Google diary needs a Google permission, which is why there's a button rather than a field. You can withdraw it from your Google account at any time, and disconnecting it here hands the permission back rather than leaving it sitting on your account page.

  • Each CalDAV server is asked what it can do.

    No 2 are quite alike: one sends invitations to other people and answers who's free, another only stores events. We open the account before anything is saved, and its answer decides which tools are registered. The panel names them, so what your app is offered is what will work on your calendar.

  • No calendar, no calendar tools.

    Not tools that answer "this mailbox has no calendar", but none at all. A tool certain to refuse still spends a call from your daily allowance to say so, invites the model to try another way, and advertises something you didn't buy. The server reads what your connection covers and registers to match, so the list your app shows is the list that will work.

Read the diary 4 tools

A window of days, a search, one event in full

  • list_calendars
  • list_events
  • read_event
  • search_events

Find a time 2 tools

Free/busy for several people, and the suggestions

  • check_availability
  • find_meeting_times

Book your own time 3 tools

Create, change and delete, with no email sent

  • create_event
  • update_event
  • delete_event

Meet other people 4 tools

Invite, reschedule, cancel, forward

  • schedule_meeting
  • update_meeting
  • cancel_meeting
  • forward_event

Answer invitations 2 tools

Accept, decline, or propose another time

  • respond_to_invitation
  • propose_new_time

Out of office 3 tools

Read it, set it for a period, turn it off

  • read_out_of_office
  • set_out_of_office
  • clear_out_of_office

Reminders and categories 3 tools

Snooze, dismiss, and the colours Outlook shows

  • list_categories
  • snooze_reminder
  • dismiss_reminder

Unknown is not the same answer as free

Asking when several people are free returns their busy and free blocks, never the subjects of their meetings.

When somebody's calendar can't be read at all (a different organisation, or permission never granted), that person comes back as unknown, and unknown is never shown as free. Microsoft reports those one attendee at a time, inside an otherwise successful response. That's exactly how an integration ends up booking a meeting over an afternoon it couldn't see.

Only with Team Access

Team Access tools, where the account holds it

These appear only where the account holds Team Access, on every mailbox of that account and on no other.

A Team Access approval on a shared mailbox: the robot holding a letter up to a tall screen that shows a single blue tick, with 3 stamped letters waiting in a tray beside him.
A draft approved before it goes
  • Team Access is for named people.

    It's a tier of 3, 5 or 10 named people, bought once for the account, on top of Pro on the mailboxes it shares. What a team gets, single sign-on first, is on the teams page.

  • Claims stop double replies, and approvals get drafts sent.

    When 2 colleagues each have their own assistant, a claim says who's dealing with a message, so they don't both answer it.

    A person whose connection may draft but not send can ask for approval, so the reply still gets out, through the owner.

  • The level on a connection decides which tools it reaches.

    Every connection made by signing in carries one of 3 permission levels, chosen on the consent screen and changed in the control panel without reconnecting.

  • Read only changes nothing, and Draft and file never sends.

    Read only reaches 16 of the email tools. Draft and file adds drafting and filing. Send and delete is everything.

  • The Team tools follow the same ladder.

    A claim, a release, a hand-over and an approval request sit at Draft and file. Listing the drafts waiting for approval, and sending one, sit at Send and delete, because the person those 2 exist for is the approver.

  • Every mailbox has a limit of its own.

    Its owner sets it, and no connection to the mailbox can exceed it. The tool reference has both, and lists every level's tools by name. The Team Access guide walks a claim and an approval through, end to end.

Claims 3 tools

Who is dealing with which message

  • claim_email
  • release_email
  • assign_email

Approvals 3 tools

A draft waits for the owner to send it

  • request_approval
  • list_pending_approvals
  • approve_and_send

A claim is a keyword in the mailbox, and who holds it is a record of ours

Claiming a message puts one IMAP keyword on it, on your own mail server, and asking for approval puts one on the draft. Nothing is moved and nothing is marked read.

Who holds the message, or who asked, is a record naming the mailbox, the folder, the message and the person, never a subject, an address or a line of the body. If your mail server doesn't accept custom keywords, every one of these tools says so rather than pretending.

Connected separately

Contact tools, where the mailbox has an address book

Where a mailbox has an address book, your assistant can look people up in it, and add or correct cards where the book allows. How the book connects depends on where your contacts live.

An address book connected to Mailbox MCP beside the mailbox: the robot holding up a contact card and a calendar page, a glowing cable running from each of them and from the mailbox beside him into one screen.
The book has a cable of its own
  • A password mailbox doesn't bring its address book.

    IMAP is a mail protocol with no contacts inside it, so on a mailbox that connects with a password, the book is a step of its own. Google contacts take a Google sign-in of their own. Most other hosts run a CardDAV contacts server, with an address you give us.

    On Microsoft 365 there's nothing to connect: the Outlook contacts come with the mail.

    How each kind of book connects
    • A Microsoft 365 mailbox brings its Outlook contacts with the mail, on the same sign-in, so there is no address to give and nothing to connect. Microsoft 365 set-up
    • Any mailbox that connects with a password, Gmail or any other IMAP host, one with no CardDAV server included, can bring its Google contacts with a Google sign-in of their own, from the mailbox's Connection tab in the control panel: the mail keeps its password, and a Google calendar on the same account is left as it was. Google contacts set-up
    • Any other book is the address of a CardDAV contacts server, given on a mailbox that connects with a password. Fastmail, iCloud, Nextcloud and StackMail all publish one. Setting up CalDAV and CardDAV
    • The CardDAV book is the list a phone or a desktop mail app syncs to. A contacts list that some webmail programs keep inside webmail, separate from it, isn't read, and importing a file is the way across.
  • A contact is looked up, then forgotten.

    When you ask for a person, our server asks your contacts server, Microsoft or Google that one question. It keeps the answer in memory for about 10 minutes so the next question is quick, then lets it go.

    Nothing about a contact is written to a database, a file or a log of ours. So there's no copy of your address book here to leak, to be subpoenaed, or to be sold in an insolvency.

    What we do keep, and what happens to photos
    • For a CardDAV book: its address and a credential for it, sealed as a calendar's are.
    • For Outlook contacts: nothing beyond the grant the mailbox already had.
    • For Google contacts: the token Google issued, sealed as the calendar's is.
    • Photos are never read into an answer: a look-up doesn't request one. On a CardDAV card you ask it to correct, the photograph passes through in memory for that one request and is written back exactly as it was, never shown to the assistant and never held. On an Outlook or a Google contact, it's never requested at all.
  • Your assistant finds people in the book and in your mail.

    Without a book, it finds addresses in the mail you've already sent and received, as it always has, and it keeps doing so once there is one. With a book, find_contact reads it as well, and a person from the book comes back with every address, the phone numbers, the postal addresses with their postcodes, the employer and the job title.

    The mailbox half of a find_contact search reads each folder's most recent 3,000 messages, and says so in one sentence when a folder held more; a person last in touch with before that is not in the mailbox half of the result, and the book still has them if they are in it.

  • A card is written to your own book, once, and only where you asked.

    Where the book lets your sign-in write to it, as Outlook contacts and Google contacts always do, a connection at Draft and file can add a card, correct one and import a contacts file. One at Send and delete can delete one. A CardDAV book that can only be read offers none of those.

    Each write goes to your own contacts server, your Outlook contacts or your Google contacts, and shows in your phone and your mail app exactly as if you'd typed it there.

    How each book adds and imports cards
    • On a CardDAV book a new card is written under a fresh id of its own, with a precondition that nothing already sits at that address, so it can never write over a card that is there.
    • On Outlook contacts a new card is one request to Microsoft, which mints the card's id, so there is nothing to be already taken and nothing to write over.
    • On Google contacts a new card is one request to Google, which mints the card's id, so there is nothing to be already taken and nothing to write over.
    • The import takes a vCard export that's already in the mailbox: email the file to yourself, or drop it on an upload link your assistant makes, then ask for the import.
    • On a CardDAV book each imported card is written once under the id the export gave it or, where the export wrote none, a fingerprint of the card's own text, so a card already in the book is skipped and running the same file again adds nothing.
    • On Outlook contacts an imported card is skipped where the folder already holds its first email address (Microsoft mints the ids, so there is no card id to land on twice), a card with no email address is added every time, and a group card is not imported.
    • On Google contacts an imported card is skipped where the book already holds its first email address (Google mints the ids, as Microsoft does), a card with no email address is added every time, a group card is not imported, and the rest go to Google in batches rather than one at a time.
    • On a Microsoft mailbox the fields this server names come across (name, emails, phones, postal addresses, company, job title, note); a birthday, a photo, a web address or the categories in the export do not, and a card with two postal addresses of one type keeps the first of each, since Outlook holds one home, one work and one other address.
    • On Google contacts the same named fields come across, each email address and phone number keeping its type; a birthday, a photo, a web address or the categories in the export do not.
  • Nothing is written over a change made somewhere else.

    A correction or a delete lands on the card exactly as it was just read, on every route. If your phone changed the card in the meantime, the write is refused rather than written over.

    A correction touches only the fields it names, so the photo and the birthday your contacts app put there stay as they were.

  • Every write was checked in a real contacts app first.

    Each one was checked against the deployed release before this page said so, and the test was the one above: the change shows up exactly as if you'd typed it there.

    Where each write was checked
    • The CardDAV writes in Thunderbird.
    • The Outlook ones in Outlook's People, on a real Microsoft 365 mailbox, where a card added from ChatGPT appeared, took a correction and was removed, each step seen in People before the next was run.
    • The Google ones at contacts.google.com, on a real Google account, where a card was corrected, deleted and created again, each step seen there first.

The tool reference puts the 3 kinds of address book side by side, question by question.

Find a person, read a card 1 tool

In your own address book, never copied

  • read_contact

Add, correct, delete 3 tools

Written to your own book, where your phone sees it

  • create_contact
  • update_contact
  • delete_contact

Import a contacts file 1 tool

A webmail export into the book, each card once

  • import_contacts

Measured

What it leaves untouched

This is the promise the whole product is built on: your mailbox goes on looking and behaving exactly as you left it. We checked each of these against a live mailbox, rather than assuming it from an API response.

What Mailbox MCP leaves untouched in your mailbox: the robot carefully replacing a letter in a mailbox and resetting its flag, leaving everything as he found it.
Everything put back as it was
  • Unread flags when reading unchanged
  • Reply threading In-Reply-To + References
  • Sent Items after a send 1 copy, ID matched
  • Attachment bytes SHA-256 identical
  • Folders it invents none

Architecture

Why it is a remote server

Plenty of MCP servers run on your own computer. That's a perfectly good design, with one property that rules it out here: it only works while your computer is on, not locked, and running the process.

A remote server means the connection belongs to your account, not to a computer. You can move between devices, use Claude from your phone, and replace a laptop without reconnecting anything.

There's no local install to keep up to date, either. On a mail integration that matters more than usual: the awkward parts of mail are provider changes like the 2 described in the set-up guides, and those get handled on the server without you doing anything.

The trade is that we hold your mailbox credentials rather than you, and that's a real trade, not a detail. The security page sets out what we hold, how, and what we won't do with it.

Why Mailbox MCP is a remote server rather than a local one: the robot weighing up a laptop against a server, with a question in a thought bubble.
Belongs to your account, not to a machine

Compatibility

Which AI clients it works with

MCP is an open protocol, not one company's feature, and Mailbox MCP is an ordinary MCP server. It's reached over HTTPS, it accepts a bearer token (the key your AI app holds), and it offers a set of mail tools. Nothing in it knows which assistant is on the other end.

So it works with Claude on the web, in the desktop app and in Claude Code, and just as well with Cursor, VS Code in agent mode, Zed, Cline, Goose, LibreChat, Microsoft Copilot Studio, and any agent you've written yourself against an MCP SDK.

The one requirement

Your app has to support remote MCP servers, not only local ones. Some apps were built to launch an MCP server as a process on your own computer and talk to it over standard input and output, and a hosted server can't be reached that way.

If yours is one of those, a small local proxy such as mcp-remote bridges the 2, and the connection behaves normally after that.

An assistant with no MCP support at all can't connect, and we can't work around that from our side. If the difference between a server your app launches and a server your app calls is new to you, that guide covers it properly.

Which products support MCP changes month to month. So check your own app's connector settings rather than trusting any list, including one on a supplier's website.

Why the site names Claude and ChatGPT

Because they're what most people asking for this already use, and a concrete example is more useful than a category. It isn't a restriction: there's no separate licence, plan or price for using Mailbox MCP with anything else.

The AI clients Mailbox MCP works with: the robot at the centre with lit cables running from him to 2 mailboxes and 3 screens, a monitor, a tablet and a laptop.
One server, any client that speaks the protocol

Limits

What it does not do

  • A calendar has to be connected separately

    Connecting a mailbox does not connect a diary, because they are separate services. A Microsoft 365 mailbox is asked for calendar access on the same sign-in as the mail.

    Every other mailbox has 2 routes and can use either: sign in to Google for a Google calendar, or give the address of a CalDAV calendar server, which most mail hosts run alongside the mail one. A mailbox with none of them is handed no calendar tools at all rather than tools that would refuse.

  • 20 MB a message

    Attachments are capped at 20 MB for the whole message rather than per file, so 3 files of 7 MB each are refused. That ceiling is ours rather than a provider's, and forwarding a message counts the files it was already carrying.

  • A file the assistant writes itself

    Only this one is small.

    A file already in the mailbox, a file at a web address, a file you upload through a one-off link, and in ChatGPT a file in the conversation (an image it generated, a document it made, one you dropped in) are all streamed at send time and never pass through the model, so the 20 MB message ceiling is the only limit on them.

    A file an assistant has to write out as output, where its client offers no other way, is capped at a few tens of kilobytes.

  • No send-later of its own, and no rules

    The server schedules nothing itself and never holds a message to send later. Every tool acts when an assistant calls it: in a conversation, or in a scheduled task your own Claude or ChatGPT runs, which can send a draft at a set time with send_draft when you have asked it to.

    A routine from the Routines tab reads, saves drafts or flags and never sends.

Connect a mailbox and try it.

5 calls a day, free, on any mailbox. Pro is £2.92 a month per mailbox, paid annually at £34.99 + VAT, when you want more.