How it works
Connect a mailbox, then just ask.
Mailbox MCP is a remote MCP server, so there's nothing to install and nothing running on your computer. You connect a mailbox you already own, add one URL to your AI app, and the mail tools appear.
- Set-up time About 2 minutes
- To install Nothing
- Works with Any MCP client

Set-up
The 3 steps
Connect a mailbox, add one URL to your AI app, then ask for what you want done.

-
Connect the mailbox you already own
Sign in to the control panel and add a mailbox. Microsoft 365 takes one Microsoft sign-in. Gmail takes an app password. Anything else takes the IMAP settings your mail app already uses.
Each has its own guide, and each guide is honest about the awkward parts: Microsoft 365, Gmail, or any IMAP host.
-
Add the server to your AI client
The panel gives you a URL. Add it to your AI app as a connector, and the mail tools appear in the list of things it can use.
That's the whole integration. There's no download, no local process, and no key file on your laptop that stops working when you get a new one.
Claude and ChatGPT are where most people start, so they're the 2 this site names. The same URL works anywhere else that speaks MCP.
-
Ask for what you would have done yourself
There are no commands and no syntax to learn. You describe the outcome, and your assistant uses the tools to get there.
Find the thread with Hollis about the March invoice, reply attaching the revised quote from my Drafts, and file the original under Clients.
It searches the mailbox and opens the thread. It writes the reply with the right headers, so it lands inside the conversation rather than beside it. Then it attaches the file, sends, and moves the original. Afterwards, the mailbox looks as if you'd done it yourself.
And a question you ask every morning can stop being one you ask: set it once as a routine and your AI asks it for you.
New: routines
Then set it once: an email routine asks for you
Step 3 is a question you type. A routine is the same kind of question, asked for you, at the time you chose, by your own Claude or ChatGPT. Add one from the mailbox's Routines tab, confirm it in your AI, and this is what happens each time it is due. Nothing about connecting changes: a routine reaches your mailbox through the same connection, at the same level, and no further.

-
Morning brief, 07:00
Your AI starts the task
Claude or ChatGPT starts it in its own scheduler, at the time you chose, whether or not your computer is on.
-
list_identitiesIt checks in
Its first call asks which addresses this mailbox may use. That makes sure it is in the right mailbox, and it is how the routine's card knows it ran.
-
catch_upIt does the job
One call answers "what has come in?", and a message is opened only when its preview is not enough. A Replies waiting routine also saves its drafts in your Drafts folder.
-
On its card: ran today
You read the result
The brief is in your AI app, as any scheduled task's result is, and its card on the Routines tab says when it ran and how many calls it made.
Tool surface
Every tool your AI client gets, and what each one does
37 email tools, grouped by what they're for, and every mailbox gets all of them. This is the whole list, so you can judge it before you connect anything. Each one is a deliberate action, taken because you asked for something that needs it.
If the idea is new, here's what an email MCP server actually is. The complete tool reference groups the same tools by what your AI app will stop and ask you about, with what each one refuses as well as what it does. The plain-English version, with what you control, is on the features page.

Read 11 tools
Search, threads, attachments, who really sent it
list_mailboxeslist_emailsread_emailread_attachmentread_threadcatch_upwaiting_onowed_repliessearch_emailsselect_emailsfind_contact
Send 7 tools
As any of your addresses, or as a real draft
draft_emaildraft_replydraft_forwardupdate_draftlist_identitiessend_emailsend_draft
Reply 1 tool
In thread, carrying the right headers
reply_email
Forward 1 tool
With everything the original carried
forward_email
File 9 tools
Move, archive or junk 500 at once
create_upload_linkcreate_foldermove_emaildelete_emailarchive_emailmark_junknot_junkrename_folderdelete_folder
Flag 4 tools
Mark read, unread or flagged, on request
mark_readmark_unreadflag_emailunflag_email
Check 4 tools
Bounces, receipts, trust records, uploads
check_bouncescheck_deliverabilitycheck_uploadcheck_receipts
Marking read is an action, not a side effect
Reading a message through Mailbox MCP doesn't mark it read. That's a
separate tool, mark_read, used only when you ask for it.
It matters more than it sounds. An unread count that changes on its own stops meaning anything, and then you've lost a tool you relied on without noticing.
Connected separately
Calendar tools, and the mailboxes that get them
Connecting a mailbox doesn't connect a diary. They're separate services, so a calendar is a step of its own. Until you take it, you get the email tools and nothing else, which is worth knowing before you choose a plan rather than after.

There are 3 ways to connect one. A Microsoft 365 mailbox uses the first. Every other mailbox can take either of the other 2, whoever hosts the mail.
-
Microsoft 365: approve calendar access.
There's no second sign-in: a Microsoft 365 mailbox is asked for calendar access on the same sign-in as the mail. Approve it, and your AI app is handed all 21 calendar tools as well as the email ones.
-
Any other calendar: a CalDAV address.
IMAP is a mail protocol with no calendar inside it, at any host, so connecting the mail can't connect the diary. Most hosts run a separate calendar server speaking CalDAV. Give us its address and the calendar tools appear.
Fastmail, iCloud and Nextcloud all run one. On Fastmail and iCloud the same app password opens both, so it's usually one field.
-
Google Calendar: sign in with Google.
It's a sign-in rather than an address, and it works on any mailbox, not only a Gmail one. You choose an account, Google shows you what's being asked for before you approve, and it covers the diary only, never the mail.
The Google account doesn't have to match the mailbox's address. That matters more often than it sounds: plenty of people keep the work diary and the work mail in different places.
-
Why a Gmail app password can't open the diary.
An app password, the kind a Gmail mailbox connects with, is a mail credential: it opens IMAP and SMTP and nothing else. Google runs a CalDAV server too, and it refuses that same app password, so no amount of pasting would get you in.
A Google diary needs a Google permission, which is why there's a button rather than a field. You can withdraw it from your Google account at any time, and disconnecting it here hands the permission back rather than leaving it sitting on your account page.
-
Each CalDAV server is asked what it can do.
No 2 are quite alike: one sends invitations to other people and answers who's free, another only stores events. We open the account before anything is saved, and its answer decides which tools are registered. The panel names them, so what your app is offered is what will work on your calendar.
-
No calendar, no calendar tools.
Not tools that answer "this mailbox has no calendar", but none at all. A tool certain to refuse still spends a call from your daily allowance to say so, invites the model to try another way, and advertises something you didn't buy. The server reads what your connection covers and registers to match, so the list your app shows is the list that will work.
Read the diary 4 tools
A window of days, a search, one event in full
list_calendarslist_eventsread_eventsearch_events
Find a time 2 tools
Free/busy for several people, and the suggestions
check_availabilityfind_meeting_times
Book your own time 3 tools
Create, change and delete, with no email sent
create_eventupdate_eventdelete_event
Meet other people 4 tools
Invite, reschedule, cancel, forward
schedule_meetingupdate_meetingcancel_meetingforward_event
Answer invitations 2 tools
Accept, decline, or propose another time
respond_to_invitationpropose_new_time
Out of office 3 tools
Read it, set it for a period, turn it off
read_out_of_officeset_out_of_officeclear_out_of_office
Reminders and categories 3 tools
Snooze, dismiss, and the colours Outlook shows
list_categoriessnooze_reminderdismiss_reminder
Unknown is not the same answer as free
Asking when several people are free returns their busy and free blocks, never the subjects of their meetings.
When somebody's calendar can't be read at all (a different organisation, or permission never granted), that person comes back as unknown, and unknown is never shown as free. Microsoft reports those one attendee at a time, inside an otherwise successful response. That's exactly how an integration ends up booking a meeting over an afternoon it couldn't see.
Only with Team Access
Team Access tools, where the account holds it
These appear only where the account holds Team Access, on every mailbox of that account and on no other.

-
Team Access is for named people.
It's a tier of 3, 5 or 10 named people, bought once for the account, on top of Pro on the mailboxes it shares. What a team gets, single sign-on first, is on the teams page.
-
Claims stop double replies, and approvals get drafts sent.
When 2 colleagues each have their own assistant, a claim says who's dealing with a message, so they don't both answer it.
A person whose connection may draft but not send can ask for approval, so the reply still gets out, through the owner.
-
The level on a connection decides which tools it reaches.
Every connection made by signing in carries one of 3 permission levels, chosen on the consent screen and changed in the control panel without reconnecting.
-
Read only changes nothing, and Draft and file never sends.
Read only reaches 16 of the email tools. Draft and file adds drafting and filing. Send and delete is everything.
-
The Team tools follow the same ladder.
A claim, a release, a hand-over and an approval request sit at Draft and file. Listing the drafts waiting for approval, and sending one, sit at Send and delete, because the person those 2 exist for is the approver.
-
Every mailbox has a limit of its own.
Its owner sets it, and no connection to the mailbox can exceed it. The tool reference has both, and lists every level's tools by name. The Team Access guide walks a claim and an approval through, end to end.
Claims 3 tools
Who is dealing with which message
claim_emailrelease_emailassign_email
Approvals 3 tools
A draft waits for the owner to send it
request_approvallist_pending_approvalsapprove_and_send
A claim is a keyword in the mailbox, and who holds it is a record of ours
Claiming a message puts one IMAP keyword on it, on your own mail server, and asking for approval puts one on the draft. Nothing is moved and nothing is marked read.
Who holds the message, or who asked, is a record naming the mailbox, the folder, the message and the person, never a subject, an address or a line of the body. If your mail server doesn't accept custom keywords, every one of these tools says so rather than pretending.
Connected separately
Contact tools, where the mailbox has an address book
Where a mailbox has an address book, your assistant can look people up in it, and add or correct cards where the book allows. How the book connects depends on where your contacts live.

-
A password mailbox doesn't bring its address book.
IMAP is a mail protocol with no contacts inside it, so on a mailbox that connects with a password, the book is a step of its own. Google contacts take a Google sign-in of their own. Most other hosts run a CardDAV contacts server, with an address you give us.
On Microsoft 365 there's nothing to connect: the Outlook contacts come with the mail.
How each kind of book connects
- A Microsoft 365 mailbox brings its Outlook contacts with the mail, on the same sign-in, so there is no address to give and nothing to connect. Microsoft 365 set-up
- Any mailbox that connects with a password, Gmail or any other IMAP host, one with no CardDAV server included, can bring its Google contacts with a Google sign-in of their own, from the mailbox's Connection tab in the control panel: the mail keeps its password, and a Google calendar on the same account is left as it was. Google contacts set-up
- Any other book is the address of a CardDAV contacts server, given on a mailbox that connects with a password. Fastmail, iCloud, Nextcloud and StackMail all publish one. Setting up CalDAV and CardDAV
- The CardDAV book is the list a phone or a desktop mail app syncs to. A contacts list that some webmail programs keep inside webmail, separate from it, isn't read, and importing a file is the way across.
-
A contact is looked up, then forgotten.
When you ask for a person, our server asks your contacts server, Microsoft or Google that one question. It keeps the answer in memory for about 10 minutes so the next question is quick, then lets it go.
Nothing about a contact is written to a database, a file or a log of ours. So there's no copy of your address book here to leak, to be subpoenaed, or to be sold in an insolvency.
What we do keep, and what happens to photos
- For a CardDAV book: its address and a credential for it, sealed as a calendar's are.
- For Outlook contacts: nothing beyond the grant the mailbox already had.
- For Google contacts: the token Google issued, sealed as the calendar's is.
- Photos are never read into an answer: a look-up doesn't request one. On a CardDAV card you ask it to correct, the photograph passes through in memory for that one request and is written back exactly as it was, never shown to the assistant and never held. On an Outlook or a Google contact, it's never requested at all.
-
Your assistant finds people in the book and in your mail.
Without a book, it finds addresses in the mail you've already sent and received, as it always has, and it keeps doing so once there is one. With a book,
find_contactreads it as well, and a person from the book comes back with every address, the phone numbers, the postal addresses with their postcodes, the employer and the job title.The mailbox half of a find_contact search reads each folder's most recent 3,000 messages, and says so in one sentence when a folder held more; a person last in touch with before that is not in the mailbox half of the result, and the book still has them if they are in it.
-
A card is written to your own book, once, and only where you asked.
Where the book lets your sign-in write to it, as Outlook contacts and Google contacts always do, a connection at Draft and file can add a card, correct one and import a contacts file. One at Send and delete can delete one. A CardDAV book that can only be read offers none of those.
Each write goes to your own contacts server, your Outlook contacts or your Google contacts, and shows in your phone and your mail app exactly as if you'd typed it there.
How each book adds and imports cards
- On a CardDAV book a new card is written under a fresh id of its own, with a precondition that nothing already sits at that address, so it can never write over a card that is there.
- On Outlook contacts a new card is one request to Microsoft, which mints the card's id, so there is nothing to be already taken and nothing to write over.
- On Google contacts a new card is one request to Google, which mints the card's id, so there is nothing to be already taken and nothing to write over.
- The import takes a vCard export that's already in the mailbox: email the file to yourself, or drop it on an upload link your assistant makes, then ask for the import.
- On a CardDAV book each imported card is written once under the id the export gave it or, where the export wrote none, a fingerprint of the card's own text, so a card already in the book is skipped and running the same file again adds nothing.
- On Outlook contacts an imported card is skipped where the folder already holds its first email address (Microsoft mints the ids, so there is no card id to land on twice), a card with no email address is added every time, and a group card is not imported.
- On Google contacts an imported card is skipped where the book already holds its first email address (Google mints the ids, as Microsoft does), a card with no email address is added every time, a group card is not imported, and the rest go to Google in batches rather than one at a time.
- On a Microsoft mailbox the fields this server names come across (name, emails, phones, postal addresses, company, job title, note); a birthday, a photo, a web address or the categories in the export do not, and a card with two postal addresses of one type keeps the first of each, since Outlook holds one home, one work and one other address.
- On Google contacts the same named fields come across, each email address and phone number keeping its type; a birthday, a photo, a web address or the categories in the export do not.
-
Nothing is written over a change made somewhere else.
A correction or a delete lands on the card exactly as it was just read, on every route. If your phone changed the card in the meantime, the write is refused rather than written over.
A correction touches only the fields it names, so the photo and the birthday your contacts app put there stay as they were.
-
Every write was checked in a real contacts app first.
Each one was checked against the deployed release before this page said so, and the test was the one above: the change shows up exactly as if you'd typed it there.
Where each write was checked
- The CardDAV writes in Thunderbird.
- The Outlook ones in Outlook's People, on a real Microsoft 365 mailbox, where a card added from ChatGPT appeared, took a correction and was removed, each step seen in People before the next was run.
- The Google ones at contacts.google.com, on a real Google account, where a card was corrected, deleted and created again, each step seen there first.
The tool reference puts the 3 kinds of address book side by side, question by question.
Find a person, read a card 1 tool
In your own address book, never copied
read_contact
Add, correct, delete 3 tools
Written to your own book, where your phone sees it
create_contactupdate_contactdelete_contact
Import a contacts file 1 tool
A webmail export into the book, each card once
import_contacts
Measured
What it leaves untouched
This is the promise the whole product is built on: your mailbox goes on looking and behaving exactly as you left it. We checked each of these against a live mailbox, rather than assuming it from an API response.

- Unread flags when reading unchanged
- Reply threading In-Reply-To + References
- Sent Items after a send 1 copy, ID matched
- Attachment bytes SHA-256 identical
- Folders it invents none
Architecture
Why it is a remote server
Plenty of MCP servers run on your own computer. That's a perfectly good design, with one property that rules it out here: it only works while your computer is on, not locked, and running the process.
A remote server means the connection belongs to your account, not to a computer. You can move between devices, use Claude from your phone, and replace a laptop without reconnecting anything.
There's no local install to keep up to date, either. On a mail integration that matters more than usual: the awkward parts of mail are provider changes like the 2 described in the set-up guides, and those get handled on the server without you doing anything.
The trade is that we hold your mailbox credentials rather than you, and that's a real trade, not a detail. The security page sets out what we hold, how, and what we won't do with it.

Compatibility
Which AI clients it works with
MCP is an open protocol, not one company's feature, and Mailbox MCP is an ordinary MCP server. It's reached over HTTPS, it accepts a bearer token (the key your AI app holds), and it offers a set of mail tools. Nothing in it knows which assistant is on the other end.
So it works with Claude on the web, in the desktop app and in Claude Code, and just as well with Cursor, VS Code in agent mode, Zed, Cline, Goose, LibreChat, Microsoft Copilot Studio, and any agent you've written yourself against an MCP SDK.
The one requirement
Your app has to support remote MCP servers, not only local ones. Some apps were built to launch an MCP server as a process on your own computer and talk to it over standard input and output, and a hosted server can't be reached that way.
If yours is one of those, a small local proxy such as
mcp-remote bridges the 2, and the connection behaves
normally after that.
An assistant with no MCP support at all can't connect, and we can't work around that from our side. If the difference between a server your app launches and a server your app calls is new to you, that guide covers it properly.
Which products support MCP changes month to month. So check your own app's connector settings rather than trusting any list, including one on a supplier's website.
Why the site names Claude and ChatGPT
Because they're what most people asking for this already use, and a concrete example is more useful than a category. It isn't a restriction: there's no separate licence, plan or price for using Mailbox MCP with anything else.

Limits
What it does not do
-
A calendar has to be connected separately
Connecting a mailbox does not connect a diary, because they are separate services. A Microsoft 365 mailbox is asked for calendar access on the same sign-in as the mail.
Every other mailbox has 2 routes and can use either: sign in to Google for a Google calendar, or give the address of a CalDAV calendar server, which most mail hosts run alongside the mail one. A mailbox with none of them is handed no calendar tools at all rather than tools that would refuse.
-
20 MB a message
Attachments are capped at 20 MB for the whole message rather than per file, so 3 files of 7 MB each are refused. That ceiling is ours rather than a provider's, and forwarding a message counts the files it was already carrying.
-
A file the assistant writes itself
Only this one is small.
A file already in the mailbox, a file at a web address, a file you upload through a one-off link, and in ChatGPT a file in the conversation (an image it generated, a document it made, one you dropped in) are all streamed at send time and never pass through the model, so the 20 MB message ceiling is the only limit on them.
A file an assistant has to write out as output, where its client offers no other way, is capped at a few tens of kilobytes.
-
No send-later of its own, and no rules
The server schedules nothing itself and never holds a message to send later. Every tool acts when an assistant calls it: in a conversation, or in a scheduled task your own Claude or ChatGPT runs, which can send a draft at a set time with send_draft when you have asked it to.
A routine from the Routines tab reads, saves drafts or flags and never sends.
Connect a mailbox and try it.
5 calls a day, free, on any mailbox. Pro is £2.92 a month per mailbox, paid annually at £34.99 + VAT, when you want more.