Email MCP server for AI agents
mail-mcp is an open-source MCP server written in Rust that lets AI agents read, search, send and organize email. It speaks IMAP, SMTP, Microsoft Graph and Exchange Web Services, so it works with Gmail, Microsoft 365, Outlook.com, iCloud, Zoho, Fastmail and any standard mail server.
- 31 tools
- OAuth2 (XOAUTH2)
- Multi-account
- Linux, macOS, Windows
- MIT license
- v0.4.16
What it does
Connect mail-mcp to Claude Code, Claude Desktop, Cursor or any MCP client and the agent can work with your inbox: find a thread, summarize it, draft and send a reply with the right threading headers, file messages into folders, or clean up hundreds of messages in one call. It runs on your machine and talks directly to your mail provider, so credentials and messages never pass through a third party.
Read and search
Search by sender, subject, date or full text, with cursor pagination. Get parsed messages with text, sanitized HTML and attachment metadata.
Send, reply, forward
Plain text and HTML, CC and BCC, attachments from disk, and replies that keep the conversation threaded.
Organize at scale
Move, copy, flag and delete messages, manage folders, and run bulk operations on up to 500 messages at once.
Microsoft without SMTP
Personal Microsoft accounts block SMTP. mail-mcp sends through Microsoft Graph or EWS instead, with one OAuth2 token.
Supported email providers
| Provider | IMAP | SMTP | Graph API | EWS | OAuth2 |
|---|---|---|---|---|---|
| Microsoft 365 | Yes | Admin-dependent | Yes | Yes | Yes |
| Outlook.com / Hotmail | Yes | Blocked by Microsoft | Yes | Yes | Yes |
| Gmail | Yes | Yes | — | — | Yes |
| Apple iCloud | Yes | Yes | — | — | — |
| Zoho Mail | Yes | Yes | — | — | — |
| Fastmail | Yes | Yes | — | — | — |
| Any IMAP/SMTP server | Yes | Yes | — | — | — |
All accounts can be configured at once; every tool takes an account_id.
Install
Linux and macOS
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/tecnologicachile/mail-mcp/releases/latest/download/mail-mcp-installer.sh | sh
Windows (PowerShell)
powershell -ExecutionPolicy Bypass -c "irm https://github.com/tecnologicachile/mail-mcp/releases/latest/download/mail-mcp-installer.ps1 | iex"
Docker
docker run --rm -i --env-file .env ghcr.io/tecnologicachile/mail-mcp
From source
git clone https://github.com/tecnologicachile/mail-mcp.git
cd mail-mcp && cargo build --release
Add it to your MCP client
Example for Gmail with an app password. The same block works in Claude Code, Claude Desktop, Cursor and other MCP clients.
{
"mcpServers": {
"mail": {
"command": "mail-mcp",
"env": {
"MAIL_IMAP_DEFAULT_HOST": "imap.gmail.com",
"MAIL_IMAP_DEFAULT_USER": "you@gmail.com",
"MAIL_IMAP_DEFAULT_PASS": "your-app-password",
"MAIL_SMTP_DEFAULT_HOST": "smtp.gmail.com",
"MAIL_SMTP_DEFAULT_PORT": "587",
"MAIL_SMTP_DEFAULT_USER": "you@gmail.com",
"MAIL_SMTP_DEFAULT_PASS": "your-app-password",
"MAIL_SMTP_DEFAULT_SECURE": "starttls",
"MAIL_IMAP_WRITE_ENABLED": "true",
"MAIL_SMTP_WRITE_ENABLED": "true"
}
}
}
}
For Microsoft 365 and Outlook.com, see the account setup guide for the EWS and Graph device-code flow.
31 MCP tools
Read
list_all_accountsaccounts and their capabilitiesimap_list_accountsimap_verify_accounttest connection and authimap_list_mailboxeslist foldersimap_mailbox_statusmessage countsimap_search_messagessearch with paginationimap_get_messageparsed messageimap_get_message_rawRFC 822 sourceimap_get_attachmentsave an attachment to disk
Write and organize
imap_update_message_flagsimap_copy_messagealso across accountsimap_move_messageimap_delete_messageimap_create_mailboximap_delete_mailboximap_rename_mailboximap_append_messageimap_bulk_moveup to 500 messagesimap_bulk_deleteup to 500 messagesimap_bulk_update_flagsup to 500 messagesimap_search_and_moveimap_search_and_delete
Send
smtp_send_messagesmtp_reply_messagethreaded repliessmtp_forward_messagesmtp_verify_accountgraph_send_messageMicrosoft Graph
Exchange Web Services
ews_search_messagesews_get_messageews_send_message
Setup
get_setup_guidestep-by-step account configuration
Full input and output contract: docs/tool-contract.md.
Security by default
Read-only until you say so
Write operations need MAIL_IMAP_WRITE_ENABLED=true, sending needs MAIL_SMTP_WRITE_ENABLED=true, and deletes require confirm: true.
Secrets stay secret
Passwords and tokens are held as secret strings, never logged and never returned by any tool.
TLS everywhere
All connections use TLS. Message HTML is sanitized and every output is size-bounded.
Attachment scope
MAIL_ATTACHMENT_UPLOAD_DIR confines which local files a send tool may attach, so a prompt-injected agent cannot exfiltrate keys.
Frequently asked questions
How do I give Claude access to my email?
Install mail-mcp, add it as an MCP server in Claude Code, Claude Desktop or any MCP client, and configure your account with environment variables. The agent then gets tools to search, read, send, reply, forward and organize email.
Does mail-mcp work with Outlook.com, Hotmail and Microsoft 365?
Yes. Microsoft blocks SMTP on personal accounts, so mail-mcp sends through Microsoft Graph API or Exchange Web Services (EWS) instead. EWS is the simplest option: one OAuth2 token covers reading and sending, and it works on tenants that block Graph and IMAP.
Can the AI agent send email, or only read it?
Both. Reading is enabled by default. Moving, deleting and sending stay disabled until you set MAIL_IMAP_WRITE_ENABLED=true and MAIL_SMTP_WRITE_ENABLED=true, and deletes also require confirm: true.
Does mail-mcp support Gmail, iCloud, Zoho and Fastmail?
Yes. Any provider that offers IMAP and SMTP works, including Gmail (with an app password or OAuth2), Apple iCloud, Zoho, Fastmail and self-hosted mail servers.
Does it support OAuth2?
Yes. mail-mcp implements XOAUTH2 natively for IMAP and SMTP, plus OAuth2 for Microsoft Graph and EWS, with cached tokens that refresh automatically.
Is there a Docker image?
Yes: ghcr.io/tecnologicachile/mail-mcp. Prebuilt binaries for Linux, macOS and Windows are also available on GitHub Releases.
Is mail-mcp free?
Yes. mail-mcp is open source under the MIT license and runs on your own machine, so your credentials and mail never go through a third-party service.