Attachments
Email attachments your AI can actually send and read.
Most AI email connectors cannot touch attachments, and the ones that can make your AI type the whole file out as code first. Mailbox MCP sends files from your mailbox, the web or your own computer, reads what is inside them, and hands them back to you, with no encoding at all.
- Encoding Your AI never has to
- Per email Up to 20 MB
- Reads PDF, Word, Excel, slides, scans
The short version
AI email attachments fail in most connectors because the AI has to type the file out as base64, about 450,000 tokens for every megabyte. Here it never has to. It points at the file and the server fetches it. It can also read what is inside, and give you the file back.
The problem
Why AI email attachments usually fail
An email can only carry text, so every attachment travels inside it as base64: the file rewritten as plain letters and numbers. Your mail program does that for you, instantly. Most AI email connectors hand that job to the AI instead, and ask it to write the whole file out, character by character, as part of its reply.
That is expensive before it starts, because base64 is bigger than the file. The standard that defined it for email says so plainly:
"The encoding and decoding algorithms are simple, but the encoded data are consistently only about 33 percent larger than the unencoded data."
For a mail program, a third bigger costs nothing. For an AI it is the whole problem, because every one of those characters has to be written as output, and output is the slowest, dearest part of anything an AI does. A 1 MB PDF becomes about 450,000 tokens of text to type without a single mistake.
- A 10 KB file about 4,500
- A 100 KB file about 45,000
- A 1 MB PDF about 450,000
- A 5 MB file about 2,250,000
- Any of them, via Mailbox MCP 0 tokens: the server fetches the file
It burns your tokens
Every character of the file is output the AI has to produce, on your plan or your bill, before it has done anything useful.
It takes ages
An AI writes output a few words at a time. Typing out a whole document that way can take minutes, where a mail program takes a blink.
Then it fails anyway
Past a small file the AI simply cannot write that much in one go. The message goes without the attachment, or not at all.
We have watched it happen. On 30 August 2026, testing an early version of our own server, we asked ChatGPT to make an image and email it. It tried twice to attach the file as base64, was refused both times, and sent the email without it. Nothing warned the recipient that a picture was meant to be there. That test is why the rest of this page exists.
Sending
How to send an email attachment with AI, without base64
Connect your mailbox to Claude, ChatGPT or any AI that uses MCP, then ask the way you would ask a person: "reply to Sam and attach the invoice he sent last week". Your AI never writes the file out. It says where the file is, and our server fetches it while the message is built, straight from where it lives.
Connecting takes a couple of minutes, for Gmail, Microsoft 365 and Outlook or any other mailbox. If you use ChatGPT, what ChatGPT can do with your email covers the set-up there.
A file can come from 3 places, and each goes straight in. The fourth route is only for a small file your AI has just made itself:
-
A file already in the mailbox
The invoice somebody sent, the quote that went out last week. The server copies it across from the message it arrived in.
-
A file at a web address
A shared Drive, Dropbox or SharePoint link, or any https address. The server fetches it while the message is built.
-
A file on your own computer
The AI hands you a one-off upload link and you drop the files on it. They wait in your own Drafts folder, not on our servers, until they are attached.
-
A small file the AI writes itself
An invitation, a short CSV. The AI writes it out as base64, so it is kept under about 50 KB, and anything bigger goes by upload link instead.
Why it matters
Why keeping the file out of the conversation matters
The people who build Claude make the same point about any tool that passes big data through the model. Writing about agents in November 2025, 2 of Anthropic's engineers put it like this:
"Every intermediate result must pass through the model. In this example, the full call transcript flows through twice. For a 2-hour sales meeting, that could mean processing an additional 50,000 tokens. Even larger documents may exceed context window limits, breaking the workflow."
An attachment is exactly that kind of intermediate result, and a heavier one than a transcript. "Breaking the workflow" is the base64 route in 3 words. Fetching the file on the server is how you keep it out of the conversation completely, so the size of the file never reaches your AI and the only ceiling is 20 MB for the whole email.
Attach the next file somebody asks you for from your own AI. The free plan covers it, and the file never has to be typed out.
Reading
Can Claude read email attachments? Here, yes
Not through Claude's own Gmail connector: Claude's help centre says it gives "attachment metadata (not attachment content)". Connect your mailbox through Mailbox MCP and your AI can ask what is inside any attachment. The server opens the file and hands the AI what it says, so a question like "what does this invoice come to?" gets an answer rather than a filename.
We tested it on real mail from real correspondents on 12 September 2026: a 5-page invoice, a 16-sheet spreadsheet and an 8-page scanned letter, read through the live service. Each came back as text, figures or pages the AI could work with.
- PDF
PDFs
Read page by page. A scanned page with no text on it comes back as a picture of the page, so it can still be read.
- DOCX
Word documents
The text of the document, for a contract clause, a CV or the terms somebody sent over.
- XLSX
Spreadsheets
Sheet by sheet, with the formulas worked out, so the totals are the totals.
- PPTX
Slide decks
Slide by slide, for the proposal or the board pack attached to a meeting request.
- JPG
Photos and scans
As pictures, for a receipt somebody photographed or a label on a parcel.
- CSV
Text, CSV, HTML
As they are, for exports, reports and anything a system sent automatically.
A stranger's file, handled as one
An attachment comes from whoever sent it, so it is treated as a stranger's file. Each one is opened in a process of its own with a memory ceiling and a time limit, its type comes from its contents rather than its name, and nothing is kept on our servers afterwards. More on that in whether it is safe to give an AI your email.
Saving
Save email attachments to your computer
Every attachment your AI looks at comes with a private download link, streamed straight from your own mail server. Ask for the file and your AI gives you the link. It lasts 15 minutes, it opens that one file and nothing else, and no copy is ever made on our side.
If your AI can run commands on your computer, as Claude Code, Cursor and similar coding tools can, it can go one step further: fetch that link itself and file the attachment in a folder you name. "Save every invoice from this month into my Accounts folder" becomes one request. Chat apps like claude.ai cannot reach your disk, so there you click the link.
And a file you received can go straight onto a new message, a reply or a draft by reference, without anybody downloading it first. A forward keeps the original's attachments and inline pictures, exactly as your mail program would.
Compared
Email connectors and attachments compared
Every cell for another product comes from that company's own published pages, read on and listed in the sources. Of the email connectors we compared, Mailbox MCP is the only one that lets your AI send a file from your own computer without encoding it, and the only one that publishes reading Word, Excel, PowerPoint and scanned pages.
A cross means the product's own pages do not state it on that date. It is not a test result, and if a vendor publishes something we have marked with a cross, we would rather be told. The fuller picture, with prices and everything else, is on the email MCP servers compared and the free Gmail and Outlook connectors compared.
| Attachments | Mailbox MCP | MCP Emails | MailMCP | AnyMailMCP | Google Gmail MCP | Claude Microsoft 365 |
|---|---|---|---|---|---|---|
| Attach a file from your own computer, no base64 | Yes | No | No | No | No | No |
| Attach a file already in the mailbox, no base64 | Yes | Yes | No | No | No | No |
| Attach a file from a web link | Yes | No | Yes | No | No | No |
| Attach anything to an email at all | Yes | Yes | Yes | No | Yes | No |
| Read PDF text and plain text inside an attachment | Yes | Yes | No | No | No | No |
| Read Word, Excel, PowerPoint and scanned pages | Yes | No | No | No | No | No |
Google's Gmail MCP server
Takes an attachment only as base64 content, and the same page says creating drafts with attachments is not supported yet.
Claude's Microsoft 365 connector
Rejects attachments in every write tool, in Anthropic's own words: sending, forwarding and drafting alike.
MCP Emails
Attaches a file already in the mailbox by reference, and extracts text from text files and PDFs with a text layer, with no OCR.
MailMCP
Has the AI supply the file's contents, in chunks for a big one, and added a web link route on 24 September 2026.
AnyMailMCP
Downloads and forwards attachments, and publishes no way to attach a new file to an email.
Mailbox MCP
All 3 ways in without encoding, and reads PDFs, Word, Excel, slides and scans, up to 20 MB an email.
Try it
Things to ask your AI about email attachments
Plain words work. These are the requests people actually make once attachments stop being a problem:
"What does the latest invoice in my inbox come to?"
Finds the message, opens the PDF, reads the total.
"Reply to Sam and attach the quote we sent him last month."
Takes the file from your Sent folder by reference and threads the reply.
"Email the brochure on our website to Priya."
Fetches the file from its web address while the email is built.
"I need to send Alex these 3 photos from my laptop."
Gives you a private upload link; you drop the photos on it; they go on the email.
"Which of this week's emails have a signed contract attached?"
Reads inside the attachments, not just their names.
"Save this month's receipts into my Expenses folder."
In an AI that can run commands, downloads each one into the folder you named.
Every one of those works on the free plan, in Claude, ChatGPT or any AI that speaks MCP.
The other side
What attachments here do not do
There is a ceiling of 20 MB an email, for all the files together. Your own mail server can set a lower one. When that happens the message is refused before it is sent, with the server's own figure named, rather than going out without the file.
A file your AI makes itself is the one exception. A small invitation or a short CSV it has just written can go as base64, and that route is kept under about 50 KB. Anything bigger goes by upload link instead, so your AI still never has to encode a file. It just sometimes chooses to for a tiny one.
Nothing saves itself to your computer. An AI in a chat window gives you a download link to click; only an AI that can run commands on your machine can put the file in a folder for you. And every free plan call counts: each file read or sent is one call, and the free plan has 5 a day per mailbox. Pro has 1,000 a day for £34.99 + VAT a mailbox a year.
Questions about AI email attachments
Can Claude read email attachments?
Not through Claude's own Gmail connector: Claude's help centre says it gives attachment metadata, not attachment content. With Mailbox MCP connected, yes. Claude can read a PDF page by page, a Word document, a spreadsheet sheet by sheet with its formulas worked out, a slide deck, and a scanned page or a photo as a picture. The file is opened on our server and Claude gets what it says.
Can ChatGPT read email attachments in Gmail or Outlook?
ChatGPT's Outlook app can list and fetch attachments, and its help page says nothing about attaching a file to an email it sends. Connect Mailbox MCP to ChatGPT and it can read attachments in any Gmail, Microsoft 365 or IMAP mailbox, including Word, Excel, PowerPoint and scanned pages, and send files as well.
How do I get Claude to send an email with an attachment?
Connect your mailbox to Claude through Mailbox MCP, then ask in plain words, for example "reply to Sam and attach the invoice he sent last week". A file already in your mailbox goes by reference, a file on the web by its link, and a file on your computer through a private upload link Claude gives you. Claude never has to copy the file out, so size is not a problem up to 20 MB an email.
Why can't Claude attach files to an email?
Usually because the connector will not let it. Claude's help centre says of its Microsoft 365 connector that attachments are not supported in any write tool, and Google's Gmail MCP server takes an attachment only as base64 text. Base64 makes the AI type the whole file out, about 450,000 tokens for every megabyte, so anything bigger than a small file fails. Mailbox MCP fetches the file itself instead.
Is there an MCP server that can send and read email attachments?
Yes, a few, and they differ a lot. Of the email connectors we compared on 27 September 2026, Mailbox MCP is the only one that lets your AI send a file from your own computer without encoding it, and the only one that publishes reading Word, Excel, PowerPoint and scanned pages. MCP Emails attaches a file already in the mailbox by reference and reads text and PDFs with a text layer.
How big an attachment can an AI send by email?
With Mailbox MCP, up to 20 MB an email, for all the files together. Your own mail server can set a lower limit, and if it does the message is refused before it is sent, with the server's figure named. Through a connector that needs base64, the real limit is far smaller: a file has to be typed out by the AI, and much past 50 KB that stops working.
Can AI read PDF, Word and Excel attachments in my inbox?
Yes, with Mailbox MCP. It reads PDFs page by page, scanned pages as pictures of the page, Word documents, spreadsheets sheet by sheet with formulas worked out, PowerPoint slide by slide, text, CSV and HTML, and photos as pictures. We tested it on a 5-page invoice, a 16-sheet spreadsheet and an 8-page scanned letter from a live mailbox.
Is it safe to let an AI read my email attachments?
An attachment comes from whoever sent it, so treat what is inside as untrusted. Each file here is opened in a process of its own with a memory ceiling and a time limit, its type is judged from its contents rather than its name, and nothing is kept on our servers afterwards. Your AI is told that what it reads is data from somebody else, never instructions to follow.
Attribution
Sources on email attachments and base64
Every sentence about another product comes from one of these, read on . Our own side comes from the tool catalogue behind the tools page, which a build check counts against the running server, and from our own tests, dated where they are described.
- RFC 2045: MIME Part One, section 6.8 The base64 transfer encoding for email, and the quoted sentence on its 33 percent overhead.
- Anthropic: code execution with MCP Adam Jones and Conor Kelly, published 4 November 2025. The quoted passage on intermediate results passing through the model.
- Claude help centre: use Google Workspace connectors "Access email metadata, including attachment metadata (not attachment content)", and "Attachment content is not directly accessible through Gmail (metadata only)."
- Claude help centre: the Microsoft 365 connector "Attachments aren't supported in any write tool: sending, forwarding, and drafting all reject messages with attachments." (The page's own dash is shown here as a colon.)
- Google: Gmail MCP server, create_draft An attachment's content is "Required. The base64-encoded content of the attachment."; the same page says "Creating drafts with attachments is not supported yet."
- OpenAI: the Outlook email and calendar apps in ChatGPT list_attachments and fetch_attachment for reading; attaching a file to an outgoing email is not stated.
- MCP Emails: documentation email_compose takes inline base64 or "a reference to a file already in this inbox", which "the server copies across without the bytes passing through the model"; extract reads text, JSON, CSV/TSV, HTML and text-layer PDFs, with no OCR; no upload route is published.
- MailMCP: changelog In French. Attachments supplied as content, in chunks through upload_attachment_chunk; on 24 September 2026, "l'IA donne une URL, MailMCP télécharge le fichier" (the AI gives a URL and MailMCP downloads the file).
- AnyMailMCP get_attachment, "Download any attachment, up to 25 MB."; forward_email, "Forward with the original attachments intact."; send_email, "Send via your own SMTP, plain-text or HTML.", with nothing about attaching.
- Claude Code issue 96149 A user's report of the base64 wall: past about 5 MB the encoded string exceeds the practical parameter size, so files Gmail itself accepts cannot be sent.
- Our threat model How a file from a stranger is opened: its own process, a memory ceiling, a time limit, its type from its bytes.
Send your next attachment from your AI.
Connect a mailbox in a couple of minutes, ask your AI to attach something, and check the email in your own mail program. The free plan covers it.