Attachments

Email attachments your AI can actually send and read.

Most AI email connectors cannot touch attachments, and the ones that can make your AI type the whole file out as code first. Mailbox MCP sends files from your mailbox, the web or your own computer, reads what is inside them, and hands them back to you, with no encoding at all.

  • Encoding Your AI never has to
  • Per email Up to 20 MB
  • Reads PDF, Word, Excel, slides, scans
The robot carrying a PDF page, a spreadsheet and a photo, clipped together with a giant paperclip, straight into an open mailbox.

The short version

AI email attachments fail in most connectors because the AI has to type the file out as base64, about 450,000 tokens for every megabyte. Here it never has to. It points at the file and the server fetches it. It can also read what is inside, and give you the file back.

The problem

Why AI email attachments usually fail

An email can only carry text, so every attachment travels inside it as base64: the file rewritten as plain letters and numbers. Your mail program does that for you, instantly. Most AI email connectors hand that job to the AI instead, and ask it to write the whole file out, character by character, as part of its reply.

That is expensive before it starts, because base64 is bigger than the file. The standard that defined it for email says so plainly:

"The encoding and decoding algorithms are simple, but the encoded data are consistently only about 33 percent larger than the unencoded data."

For a mail program, a third bigger costs nothing. For an AI it is the whole problem, because every one of those characters has to be written as output, and output is the slowest, dearest part of anything an AI does. A 1 MB PDF becomes about 450,000 tokens of text to type without a single mistake.

The robot knee-deep in coils of paper tape covered in code, trying to feed it into a narrow slot, while the small page it came from sits on a stand.
One small file, typed out as base64
Output tokens an AI must write to attach a file by base64 About 0.45 of a token per byte: base64 writes 4 characters for every 3 bytes, plus line breaks, at roughly 3 characters per token
  1. A 10 KB file about 4,500
  2. A 100 KB file about 45,000
  3. A 1 MB PDF about 450,000
  4. A 5 MB file about 2,250,000
  5. Any of them, via Mailbox MCP 0 tokens: the server fetches the file

It burns your tokens

Every character of the file is output the AI has to produce, on your plan or your bill, before it has done anything useful.

It takes ages

An AI writes output a few words at a time. Typing out a whole document that way can take minutes, where a mail program takes a blink.

Then it fails anyway

Past a small file the AI simply cannot write that much in one go. The message goes without the attachment, or not at all.

We have watched it happen. On 30 August 2026, testing an early version of our own server, we asked ChatGPT to make an image and email it. It tried twice to attach the file as base64, was refused both times, and sent the email without it. Nothing warned the recipient that a picture was meant to be there. That test is why the rest of this page exists.

Sending

How to send an email attachment with AI, without base64

Connect your mailbox to Claude, ChatGPT or any AI that uses MCP, then ask the way you would ask a person: "reply to Sam and attach the invoice he sent last week". Your AI never writes the file out. It says where the file is, and our server fetches it while the message is built, straight from where it lives.

Connecting takes a couple of minutes, for Gmail, Microsoft 365 and Outlook or any other mailbox. If you use ChatGPT, what ChatGPT can do with your email covers the set-up there.

A file can come from 3 places, and each goes straight in. The fourth route is only for a small file your AI has just made itself:

  1. A file already in the mailbox

    The invoice somebody sent, the quote that went out last week. The server copies it across from the message it arrived in.

    Never through the conversation

    MCP Emails publishes this route too.

  2. A file at a web address

    A shared Drive, Dropbox or SharePoint link, or any https address. The server fetches it while the message is built.

    Never through the conversation

    MailMCP publishes this route, in its changelog.

  3. A file on your own computer

    The AI hands you a one-off upload link and you drop the files on it. They wait in your own Drafts folder, not on our servers, until they are attached.

    Never through the conversation

    No other connector we compared publishes one.

  4. A small file the AI writes itself

    An invitation, a short CSV. The AI writes it out as base64, so it is kept under about 50 KB, and anything bigger goes by upload link instead.

    Through the conversation

    MCP Emails, MailMCP and Google's Gmail server all take files this way. For a file on your computer, it is the only way they offer.

One message

20 MB of attachments, every file on the message together

The first 3 are fetched by the server while the message is built, so a file's size never reaches the conversation and there is no limit from the conversation's length. Only the fourth passes through it.

Why it matters

Why keeping the file out of the conversation matters

The people who build Claude make the same point about any tool that passes big data through the model. Writing about agents in November 2025, 2 of Anthropic's engineers put it like this:

"Every intermediate result must pass through the model. In this example, the full call transcript flows through twice. For a 2-hour sales meeting, that could mean processing an additional 50,000 tokens. Even larger documents may exceed context window limits, breaking the workflow."

An attachment is exactly that kind of intermediate result, and a heavier one than a transcript. "Breaking the workflow" is the base64 route in 3 words. Fetching the file on the server is how you keep it out of the conversation completely, so the size of the file never reaches your AI and the only ceiling is 20 MB for the whole email.

Documents lifting off a laptop screen into a glowing drop tray, a cable carrying them into an open mailbox, the robot giving a thumbs-up.
From your computer straight into the email

Attach the next file somebody asks you for from your own AI. The free plan covers it, and the file never has to be typed out.

Reading

Can Claude read email attachments? Here, yes

Not through Claude's own Gmail connector: Claude's help centre says it gives "attachment metadata (not attachment content)". Connect your mailbox through Mailbox MCP and your AI can ask what is inside any attachment. The server opens the file and hands the AI what it says, so a question like "what does this invoice come to?" gets an answer rather than a filename.

We tested it on real mail from real correspondents on 12 September 2026: a 5-page invoice, a 16-sheet spreadsheet and an 8-page scanned letter, read through the live service. Each came back as text, figures or pages the AI could work with.

The robot reading a document through a magnifying glass, a spreadsheet and a slide spread out beside him, what he reads flowing to a tablet.
What is inside, not just the filename
  • PDF

    PDFs

    Read page by page. A scanned page with no text on it comes back as a picture of the page, so it can still be read.

  • DOCX

    Word documents

    The text of the document, for a contract clause, a CV or the terms somebody sent over.

  • XLSX

    Spreadsheets

    Sheet by sheet, with the formulas worked out, so the totals are the totals.

  • PPTX

    Slide decks

    Slide by slide, for the proposal or the board pack attached to a meeting request.

  • JPG

    Photos and scans

    As pictures, for a receipt somebody photographed or a label on a parcel.

  • CSV

    Text, CSV, HTML

    As they are, for exports, reports and anything a system sent automatically.

A stranger's file, handled as one

An attachment comes from whoever sent it, so it is treated as a stranger's file. Each one is opened in a process of its own with a memory ceiling and a time limit, its type comes from its contents rather than its name, and nothing is kept on our servers afterwards. More on that in whether it is safe to give an AI your email.

Saving

Save email attachments to your computer

Every attachment your AI looks at comes with a private download link, streamed straight from your own mail server. Ask for the file and your AI gives you the link. It lasts 15 minutes, it opens that one file and nothing else, and no copy is ever made on our side.

If your AI can run commands on your computer, as Claude Code, Cursor and similar coding tools can, it can go one step further: fetch that link itself and file the attachment in a folder you name. "Save every invoice from this month into my Accounts folder" becomes one request. Chat apps like claude.ai cannot reach your disk, so there you click the link.

And a file you received can go straight onto a new message, a reply or a draft by reference, without anybody downloading it first. A forward keeps the original's attachments and inline pictures, exactly as your mail program would.

The robot filing a paperclipped document from a mailbox into an open desk drawer, beside a laptop showing folders.
From the email into your own folders

Compared

Email connectors and attachments compared

Every cell for another product comes from that company's own published pages, read on and listed in the sources. Of the email connectors we compared, Mailbox MCP is the only one that lets your AI send a file from your own computer without encoding it, and the only one that publishes reading Word, Excel, PowerPoint and scanned pages.

A cross means the product's own pages do not state it on that date. It is not a test result, and if a vendor publishes something we have marked with a cross, we would rather be told. The fuller picture, with prices and everything else, is on the email MCP servers compared and the free Gmail and Outlook connectors compared.

What 6 email connectors publish about attachments, read from each vendor's own pages on 27 September 2026
Attachments Mailbox MCP MCP Emails MailMCP AnyMailMCP Google Gmail MCP Claude Microsoft 365
Attach a file from your own computer, no base64 Yes No No No No No
Attach a file already in the mailbox, no base64 Yes Yes No No No No
Attach a file from a web link Yes No Yes No No No
Attach anything to an email at all Yes Yes Yes No Yes No
Read PDF text and plain text inside an attachment Yes Yes No No No No
Read Word, Excel, PowerPoint and scanned pages Yes No No No No No
  • Google's Gmail MCP server

    Takes an attachment only as base64 content, and the same page says creating drafts with attachments is not supported yet.

  • Claude's Microsoft 365 connector

    Rejects attachments in every write tool, in Anthropic's own words: sending, forwarding and drafting alike.

  • MCP Emails

    Attaches a file already in the mailbox by reference, and extracts text from text files and PDFs with a text layer, with no OCR.

  • MailMCP

    Has the AI supply the file's contents, in chunks for a big one, and added a web link route on 24 September 2026.

  • AnyMailMCP

    Downloads and forwards attachments, and publishes no way to attach a new file to an email.

  • Mailbox MCP

    All 3 ways in without encoding, and reads PDFs, Word, Excel, slides and scans, up to 20 MB an email.

Try it

Things to ask your AI about email attachments

Plain words work. These are the requests people actually make once attachments stop being a problem:

  • "What does the latest invoice in my inbox come to?"

    Finds the message, opens the PDF, reads the total.

  • "Reply to Sam and attach the quote we sent him last month."

    Takes the file from your Sent folder by reference and threads the reply.

  • "Email the brochure on our website to Priya."

    Fetches the file from its web address while the email is built.

  • "I need to send Alex these 3 photos from my laptop."

    Gives you a private upload link; you drop the photos on it; they go on the email.

  • "Which of this week's emails have a signed contract attached?"

    Reads inside the attachments, not just their names.

  • "Save this month's receipts into my Expenses folder."

    In an AI that can run commands, downloads each one into the folder you named.

Every one of those works on the free plan, in Claude, ChatGPT or any AI that speaks MCP.

The other side

What attachments here do not do

There is a ceiling of 20 MB an email, for all the files together. Your own mail server can set a lower one. When that happens the message is refused before it is sent, with the server's own figure named, rather than going out without the file.

A file your AI makes itself is the one exception. A small invitation or a short CSV it has just written can go as base64, and that route is kept under about 50 KB. Anything bigger goes by upload link instead, so your AI still never has to encode a file. It just sometimes chooses to for a tiny one.

Nothing saves itself to your computer. An AI in a chat window gives you a download link to click; only an AI that can run commands on your machine can put the file in a folder for you. And every free plan call counts: each file read or sent is one call, and the free plan has 5 a day per mailbox. Pro has 1,000 a day for £34.99 + VAT a mailbox a year.

The robot pointing openly at an empty open mailbox with a stack of papers beneath it.
The limits, pointed at rather than left for you to find

Questions about AI email attachments

Can Claude read email attachments?

Not through Claude's own Gmail connector: Claude's help centre says it gives attachment metadata, not attachment content. With Mailbox MCP connected, yes. Claude can read a PDF page by page, a Word document, a spreadsheet sheet by sheet with its formulas worked out, a slide deck, and a scanned page or a photo as a picture. The file is opened on our server and Claude gets what it says.

Can ChatGPT read email attachments in Gmail or Outlook?

ChatGPT's Outlook app can list and fetch attachments, and its help page says nothing about attaching a file to an email it sends. Connect Mailbox MCP to ChatGPT and it can read attachments in any Gmail, Microsoft 365 or IMAP mailbox, including Word, Excel, PowerPoint and scanned pages, and send files as well.

How do I get Claude to send an email with an attachment?

Connect your mailbox to Claude through Mailbox MCP, then ask in plain words, for example "reply to Sam and attach the invoice he sent last week". A file already in your mailbox goes by reference, a file on the web by its link, and a file on your computer through a private upload link Claude gives you. Claude never has to copy the file out, so size is not a problem up to 20 MB an email.

Why can't Claude attach files to an email?

Usually because the connector will not let it. Claude's help centre says of its Microsoft 365 connector that attachments are not supported in any write tool, and Google's Gmail MCP server takes an attachment only as base64 text. Base64 makes the AI type the whole file out, about 450,000 tokens for every megabyte, so anything bigger than a small file fails. Mailbox MCP fetches the file itself instead.

Is there an MCP server that can send and read email attachments?

Yes, a few, and they differ a lot. Of the email connectors we compared on 27 September 2026, Mailbox MCP is the only one that lets your AI send a file from your own computer without encoding it, and the only one that publishes reading Word, Excel, PowerPoint and scanned pages. MCP Emails attaches a file already in the mailbox by reference and reads text and PDFs with a text layer.

How big an attachment can an AI send by email?

With Mailbox MCP, up to 20 MB an email, for all the files together. Your own mail server can set a lower limit, and if it does the message is refused before it is sent, with the server's figure named. Through a connector that needs base64, the real limit is far smaller: a file has to be typed out by the AI, and much past 50 KB that stops working.

Can AI read PDF, Word and Excel attachments in my inbox?

Yes, with Mailbox MCP. It reads PDFs page by page, scanned pages as pictures of the page, Word documents, spreadsheets sheet by sheet with formulas worked out, PowerPoint slide by slide, text, CSV and HTML, and photos as pictures. We tested it on a 5-page invoice, a 16-sheet spreadsheet and an 8-page scanned letter from a live mailbox.

Is it safe to let an AI read my email attachments?

An attachment comes from whoever sent it, so treat what is inside as untrusted. Each file here is opened in a process of its own with a memory ceiling and a time limit, its type is judged from its contents rather than its name, and nothing is kept on our servers afterwards. Your AI is told that what it reads is data from somebody else, never instructions to follow.

Attribution

Sources on email attachments and base64

Every sentence about another product comes from one of these, read on . Our own side comes from the tool catalogue behind the tools page, which a build check counts against the running server, and from our own tests, dated where they are described.

  • RFC 2045: MIME Part One, section 6.8 The base64 transfer encoding for email, and the quoted sentence on its 33 percent overhead.
  • Anthropic: code execution with MCP Adam Jones and Conor Kelly, published 4 November 2025. The quoted passage on intermediate results passing through the model.
  • Claude help centre: use Google Workspace connectors "Access email metadata, including attachment metadata (not attachment content)", and "Attachment content is not directly accessible through Gmail (metadata only)."
  • Claude help centre: the Microsoft 365 connector "Attachments aren't supported in any write tool: sending, forwarding, and drafting all reject messages with attachments." (The page's own dash is shown here as a colon.)
  • Google: Gmail MCP server, create_draft An attachment's content is "Required. The base64-encoded content of the attachment."; the same page says "Creating drafts with attachments is not supported yet."
  • OpenAI: the Outlook email and calendar apps in ChatGPT list_attachments and fetch_attachment for reading; attaching a file to an outgoing email is not stated.
  • MCP Emails: documentation email_compose takes inline base64 or "a reference to a file already in this inbox", which "the server copies across without the bytes passing through the model"; extract reads text, JSON, CSV/TSV, HTML and text-layer PDFs, with no OCR; no upload route is published.
  • MailMCP: changelog In French. Attachments supplied as content, in chunks through upload_attachment_chunk; on 24 September 2026, "l'IA donne une URL, MailMCP télécharge le fichier" (the AI gives a URL and MailMCP downloads the file).
  • AnyMailMCP get_attachment, "Download any attachment, up to 25 MB."; forward_email, "Forward with the original attachments intact."; send_email, "Send via your own SMTP, plain-text or HTML.", with nothing about attaching.
  • Claude Code issue 96149 A user's report of the base64 wall: past about 5 MB the encoded string exceeds the practical parameter size, so files Gmail itself accepts cannot be sent.
  • Our threat model How a file from a stranger is opened: its own process, a memory ceiling, a time limit, its type from its bytes.

Send your next attachment from your AI.

Connect a mailbox in a couple of minutes, ask your AI to attach something, and check the email in your own mail program. The free plan covers it.