OAuth, one sign-in
Microsoft 365
Password access to these mailboxes has been impossible since 2022, so Mailbox MCP goes through Microsoft Graph instead. Sending goes through Graph too, which means no Authenticated SMTP and no ticket to IT.
Remote MCP server
Mailbox MCP is a remote MCP server that gives your AI real read and write access to a mailbox you already own: Gmail, Microsoft 365, or any IMAP host. It reads, searches, drafts, sends and files mail away, and it leaves the mailbox exactly as you left it.
Connect
You connect the mailbox you already have. There is no new address, no forwarding rule and nothing to migrate.
OAuth, one sign-in
Password access to these mailboxes has been impossible since 2022, so Mailbox MCP goes through Microsoft Graph instead. Sending goes through Graph too, which means no Authenticated SMTP and no ticket to IT.
App password
Sixteen characters from your Google account, and IMAP is already on whether you can find the setting or not. The guide covers the reason the app password screen may refuse to appear for you.
Host, port, password
Fastmail, Zoho, cPanel, a mailbox your host set up years ago. If it speaks IMAP and SMTP over TLS, it connects with the details already in your mail client.
Works with
MCP is an open protocol, not one company's feature, and this is an ordinary MCP server. Connect a mailbox once and reach it from whichever assistant, editor or agent you actually work in. No extra licence, and no second price.
What it does
Most email integrations can list messages and send plain text. The difference shows up on the ordinary jobs: attaching the invoice that is already in your inbox, replying so the reply lands in the thread, and forwarding something with everything it arrived with. Connect a calendar as well and the same connector runs your diary: your week, other people's free time, and the meetings themselves.
What came in overnight that actually needs me?
Worked for 184ms
list_emails
Reading the last 12 messages in INBOX
184ms
Seven unread. Three of them want something from you today:
The rest can wait: a Companies House reminder with 14 days on it, an uptime alert that already resolved itself after four minutes, a newsletter, and Tom at Northgate holding four packs of the discontinued card stock for you.
One call. Ten messages read, seven unread, sorted by what wants an answer. Read the detail
Reply to Sarah saying Thursday works, and send her signed agreement back to her.
Worked for 121ms
search_emails
Searching INBOX for mail from harbourlane.co.uk
12ms
read_email
Opening "Signed agreement attached"
40ms
draft_reply
Drafting a reply carrying 1 attachment
69ms
Drafted, not sent. It is sitting in your Drafts folder on the same thread as her chase, so it will group properly when it goes.
I have attached Harbour-Lane-Agreement-signed.pdf back to her. That file came straight out of her original message - it never passed through this chat, and I never had to ask you to find it.
Open it in Outlook, change anything you like, and send it yourself.
The attachment moved mailbox to mailbox. It was never uploaded, pasted, or re-typed. Read the detail
Find the invoice from the printers. I think it was August?
Worked for 61ms
search_emails
Searching for "invoice" since 1 July
17ms
read_email
Opening "Invoice NP-4471 - August print run"
44ms
Close. It is Invoice NP-4471 from Tom Bexley at Northgate Print, and it landed on 29 July - the subject line says "August print run", which is probably where August came from.
It covers 2,000 A5 leaflets and the reprint of the folded cards, at £486 plus VAT on 30 day terms, with NP-4471.pdf attached.
Worth knowing: he says the card stock used for those cards is being discontinued, and he emailed again an hour ago holding four packs of it for you.
Five weeks back, in a mailbox of any size. Nothing had to be pasted into the chat for it to be searchable. Read the detail
Recorded on 5 September 2026 against a real mailbox. The tool names, the results and the timings are measured; the correspondents are invented, because real mail from real people does not belong on a public page.
Four ways to attach a file: one already in the mailbox, one at a web address, one off your own computer through a one-off link, or one the assistant writes itself. The first three never pass through the assistant, so it never has to spell the file out. That is the difference between a 6 MB PDF costing you a sentence and arriving in seconds, and it being encoded a character at a time into the conversation until the assistant runs out of room and sends the message without it. Several files at once, and the whole message can run to 10 MB.
A reply carries the headers a mail client uses to nest it under the original, so it appears in the conversation rather than as a stray new message. It can read the whole thread first, so it answers what was actually said and not just the last message. The original is marked answered, exactly as if you had replied yourself.
Attachments and inline images travel with a forward, under the forwarded-message block a real client produces. Copy other people in, add files of your own alongside the original's, and anything the size ceiling will not take is named rather than dropped quietly. A forward can be saved to Drafts instead of sent, which matters more here than anywhere else, because the part being passed on is somebody else's.
Every alias on the mailbox, each with its own display name and signature, set in your account rather than by the AI. A reply-all subtracts every address you own, so you are never copied in on your own thread. Exactly one copy is filed in Sent Items, and any message can be saved as a real draft instead of sent, carrying its files, so you open it in Outlook and press Send yourself. Ask for a change and it rewrites that draft rather than leaving the version you rejected in your bin.
Request a read receipt on the way out, the same tick box Outlook offers, on a send, a reply or a forward. Afterwards it finds what came back: a bounce, a delivery confirmation, or a receipt saying the message was opened. It tells you plainly that a missing receipt proves nothing, because most mail programs never send one.
Move up to 500 messages in one go, archive them where your own Archive button would put them, report spam so the filter learns, create and rename folders, mark things read or flagged. Reading never marks anything read and nothing is filed unless you ask, so your unread count still means what it did this morning. It can also hand you a one-off link for getting a file off your own computer into the mailbox, where it lands in Drafts for you to keep or delete.
It reads your week, finds when a group of people are free, books time, invites and reschedules, and answers invitations. Connecting a mailbox does not connect a calendar, so it is one extra step: Microsoft 365 asks on the same sign-in, and anything else takes a Google sign-in or the address of a CalDAV server. On Microsoft it sets your out-of-office too.
The founding rule
Every tool above was built under one constraint: open your mailbox in Outlook afterwards and it should look exactly as it would if you had done the work yourself. Not similar. The same.
Why it decides everything
This is the rule that decides whether a mail tool survives contact with a real week of email, and it is invisible in a demonstration. Anything can send a message. The damage from the easy implementation turns up later and somewhere else: a reply that arrives beside the conversation instead of inside it, a draft the AI can see and Outlook cannot, a forward that lost the attachment it existed to carry, a delete that took the message away for good rather than to Trash.
Nobody reports any of that as a bug. They just find their mailbox slightly wrong, stop trusting the thing that did it, and go back to doing it by hand. So the convenient implementation is reliably the wrong one here, and the mail client is the only judge that counts: not our API response, not a green test run, but your mailbox opened in another program a week later.
Everything you would do in Outlook yourself, your AI can do through Mailbox MCP, and it leaves behind the mailbox you would have left behind.
Worth calling out
None of the other hosted email MCP servers publishes threading behaviour, a way to edit a draft that is already in your mailbox, or what a forward does with the original's attachments. Email MCP servers compared sets the four of us side by side, every competitor cell taken from that vendor's own pages and dated, including the two rows where somebody else wins.
Known traps
Neither of these is a mistake you made. Both are recent changes at the provider, and both are still described incorrectly in most set-up guides you will find.
Microsoft
Microsoft disabled Basic Authentication for IMAP in Exchange Online. Username and password access to those mailboxes ended for every client at once, and it is not a setting anyone can turn back on.
Now no one (you or Microsoft support) can re-enable Basic authentication in your tenant
So it is not a policy your administrator forgot or a tool that has not caught up. Anything asking for your Microsoft password to read your mail is describing a world that stopped existing three years ago. Mailbox MCP asks you to sign in with Microsoft instead, which takes one screen.
Source: Microsoft Learn, deprecation of Basic authentication in Exchange Online.
Still current
App passwords need 2-Step Verification backed by a phone or an authenticator app. A passkey on its own does not qualify, even though Google reports 2-Step Verification as ON. Google now steers new accounts towards passkeys, so this is the default route into the dead end rather than an unusual one.
The setting that you are looking for is not available for your account
Add a phone number or an authenticator app to 2-Step Verification and the setting appears. While you are there: do not go looking for the IMAP toggle, because Google removed it in January 2025 and IMAP is now always on.
Measured
These are not targets or design intentions. Each was taken while building the product, against a live mailbox of 26,930 messages, and each is checkable against your own mailbox once you connect it.
Worth calling out
Graph is documented with a 4 MB message limit. The largest message it actually accepted from us was 18,684,476 base64 bytes, from a 14 MB message, and it answered 202. We cap attachments at 10 MB a message anyway, which is our decision rather than the provider's.
How it works
One server in the middle. Your mailbox on one side, whichever AI client you work in on the other, and a fixed set of things it can do in between.
Sign in to Microsoft, paste a Gmail app password, or enter IMAP details from your existing mail client. One mailbox takes a couple of minutes; the set-up guides cover the awkward parts honestly.
Mailbox MCP is a remote MCP server, so there is nothing to install and nothing running on your machine. You add one URL and the mail tools appear. Claude is the obvious place to start, but the same URL works in Cursor, VS Code, Zed and anything else that speaks MCP.
Find the thread with the supplier, reply to it, attach the revised quote, file the original under Clients. Claude does it in your mailbox, and your unread count, your Sent folder and your conversation threads all still mean what they meant before.
Limits
Worth knowing before you connect anything, rather than after.
Attachments are capped at 10 MB per message in total across every file attached, which is our limit rather than a provider's.
It does not back up, export or migrate a mailbox, and there is no tool that copies your mail anywhere. Archiving a message files it in your own Archive folder, which is filing rather than a backup.
Calendar tools appear once a diary is connected, which is its own step: calendar access approved on a Microsoft 365 sign-in, a Google sign-in for Google Calendar, or the address of a CalDAV calendar server. A mailbox with none of the three gets the email tools and no calendar tools at all.
It cannot recover mail that has already been deleted.
Shared and delegated mailboxes are not supported. A shared CALENDAR is a different thing and is supported on Microsoft 365: one that has been shared with you can be read, and written to where the person who shared it allowed that.
There is no phone line. Support is by email, deliberately.
Pricing
The same number on every page of this site, and the same number in the control panel. One account holds as many mailboxes as you like, and Pro is bought per mailbox, so a Pro mailbox and five free ones is a normal way to use it.
Free
£0 every mailbox, no card required
Pro
£2.92 a month Per mailbox, paid annually at £34.99 + VAT
Questions
Yes. Mailbox MCP is a remote MCP server that connects a mailbox you already own to Claude, so Claude can list, search and read messages, draft and send them, reply in thread, move mail between folders, archive it, report spam and flag it. Nothing in the server is specific to Claude, so the same mailbox works from Cursor or any other MCP client. It is your mailbox on your existing provider. Nothing is copied to a new address and there is nothing to migrate.
Yes, and this is the part most tools get wrong. Microsoft disabled Basic Authentication for IMAP on 1 October 2022, so a username and password cannot open a Microsoft 365 mailbox at all any more, no matter which client is asking. Mailbox MCP connects through Microsoft Graph with a single Microsoft sign-in instead. Sending goes through Graph too, which means you do not need Authenticated SMTP switched on and you do not need to involve your IT department to get it.
Because app passwords require 2-Step Verification backed by a phone or an authenticator app. Google documents the option as unavailable when 2-Step Verification is set up only for security keys, and a passkey behaves the same way: both replace the sign-in rather than adding a second step to it. Your account still reports 2-Step Verification as ON throughout, which is what makes this so hard to diagnose. That mismatch is what produces the message "The setting that you are looking for is not available for your account". Google now steers new accounts towards passkeys, so this is the default route into the dead end rather than an edge case. Add a phone number or an authenticator app to 2-Step Verification and the setting appears.
No, and you will not find the toggle if you go looking. Google removed it in January 2025 and IMAP is now always on for every Gmail account. Any guide still telling you to turn it on was written before that change and has not been revisited since.
Any AI client that supports remote MCP servers. Mailbox MCP is an ordinary MCP server reached over HTTPS with a bearer token, and nothing in it is specific to one assistant. It works in Claude on the web, the desktop app and Claude Code, and equally in Cursor, VS Code with agent mode, Zed, Cline, Goose, LibreChat, Microsoft Copilot Studio, or an agent you have written yourself against the MCP SDK. The one requirement is that your client can connect to a REMOTE MCP server rather than only a local one; clients limited to local servers can still reach it through a small proxy such as mcp-remote. Assistants with no MCP support at all cannot connect, and that list changes month to month, so check whether yours supports MCP connectors rather than trusting anyone's table of it.
No. Reading a message through Mailbox MCP leaves the unread flag exactly as it was, so your unread count is still yours and still means something. Marking a message read is a separate action that happens only when you ask for it.
They appear in Sent Items once, with the same Message-ID the recipient received, so your sent folder is a true record. Replies carry the In-Reply-To and References headers, which is what makes them land inside the existing conversation in Outlook or Gmail rather than starting a new one alongside it. Both behaviours were checked by comparing the folder before and after each send rather than assumed from the API response.
Yes, and this is where most email integrations fall down. A file can come from four places: one already in your mailbox, such as an invoice somebody sent you; one at a web address, like a SharePoint, Drive or Dropbox link; one from your own computer, through a one-off upload link that needs no sign-in; or one the assistant writes itself. The first three are streamed into the message when it is built and never pass through the assistant at all, so it does not have to encode the file, and a 6 MB PDF costs it no more than a sentence. That matters because the alternative is the assistant writing the whole file out as text, which is slow, expensive, and runs out of room long before the file does. Several files can go on one message, up to 10 MB in total. Only a file the assistant composes itself has to be written out, and only that one is limited to a few tens of kilobytes. A forward carries the original's own attachments and inline images as well.
Yes. A send, a reply, a forward or a draft can carry a read-receipt request, which is the same tick box Outlook offers, and a separate tool finds what came back afterwards. Be clear about what that can tell you, because the honest answer is less than people expect: a read receipt is a request to the recipient, not a measurement of them. Their mail program decides what to do with it, and most either ask them first or ignore it outright. Consumer Gmail never returns one, Google Workspace only if an administrator has enabled it, and Apple Mail only behind a setting that ships switched off. So a receipt that arrives means the message was opened and somebody agreed to say so, and a receipt that never arrives means nothing at all. The tool says exactly that in its own results rather than letting silence be read as being ignored. A delivery receipt is a different thing and is not offered: it needs an SMTP feature none of the mail providers this connects to support, so requesting one would appear to work and do nothing.
Every mailbox starts free with 5 MCP calls per day. Pro is £2.92 a month per mailbox, paid annually at £34.99 + VAT, renewing annually and paid by card through Stripe, and raises that ceiling to 1,000 calls per day. One account holds as many mailboxes as you like and Pro is bought per mailbox, so you can run one Pro mailbox alongside several free ones. You can stop the renewal on any mailbox at any time and Pro then runs to the end of the period you have paid for.
You can attach several files to a single message, but 10 MB is the total across all of them rather than a per-file allowance, so three 4 MB files are refused. That ceiling is ours rather than your provider's, and it applies whether the file is already in your mailbox, at a web address, or uploaded from your computer through a one-off link: none of those passes through the model. A file the assistant writes itself has to fit in its own output and is therefore far smaller, a few tens of kilobytes. It does not back up, export or migrate your mailbox, and nothing copies your mail anywhere; archiving a message files it in your own Archive folder rather than keeping a copy of it. It does not manage contacts or files. A calendar is reached only where one has been connected, which is its own step on top of connecting the mailbox, and there is a route for every mailbox: approving calendar access on a Microsoft 365 sign-in, signing in to Google for a Google calendar, or giving the address of a CalDAV server, which Fastmail, iCloud, Nextcloud and most hosts run. A mailbox with no calendar connected reads and writes mail and nothing beyond that, and is handed no calendar tools at all rather than tools that would refuse.
Nothing, is the answer we are claiming. The free tier is 5 calls a day on any mailbox, which is enough to check that for yourself before you pay anything.