Compare

Email MCP servers, compared.

There are now several hosted MCP servers that put an AI on a real mailbox, and they are not the same product at different prices. This is what each one publishes about itself, read on one day and dated, including the two rows where somebody else wins.

  • Compared Four hosted MCP servers
  • Every cell From the vendor's own pages
  • Read on 4 September 2026

The comparison

Email MCP servers compared

An email MCP server connects the AI you already use to a mailbox you already own, which is a different proposition from the connectors built into Claude and ChatGPT. Those are covered separately on native connectors and MCP. This page is about the other hosted servers doing the same job as us: MailMCP, AnyMailMCP and MCP Emails.

Every competitor cell below was read from that company's own published pages on , and each page is linked at the foot of this one. Our own column comes from the tool catalogue that generates the tools page, which a build check counts against the running server, so it cannot claim something the software does not do.

What a cross means here

A cross means the capability is not in that product's published tool list or documentation on the date above. It does not mean the product cannot do it, and it is not a claim that the vendor refused to. Vendors publish what they choose to publish. If one of these documents something marked with a cross, this table is wrong and we would rather be told than left to look confident.

The robot holding up a clipboard of ticked-off checks beside an open mailbox wired to a small monitor.
Every cell checked against the vendor’s own page
Capabilities of four hosted email MCP servers, read from each vendor's published documentation on 4 September 2026.
Capability Mailbox MCP MailMCP AnyMailMCP MCP Emails
Any IMAP mailbox Yes Yes Yes Yes
A free plan with no card Yes Yes Yes Yes
Microsoft 365 through Microsoft's own sign-in Yes No No No
Gmail through Google's own sign-in No No No Yes
A calendar as well as the mail Yes Yes Yes No
Google Calendar or a Microsoft calendar, not CalDAV alone Yes No No No
Attach a file already in the mailbox, by reference Yes No No No
Attach a file from a web link or an upload link Yes No No No
Hand you a download link for an attachment Yes No Yes No
Replies carry In-Reply-To and References Yes No No No
Edit a draft that is already in the mailbox Yes No No No
A forward keeps the original attachments Yes No Yes No
Reading a message never marks it read Yes No No No
Check bounces, delivery and read receipts Yes No No No
Neutralises instructions hidden inside a message Yes No No No
Two-factor authentication on the account Yes No No No

The tool counts sit outside the table because a number is not a tick. Mailbox MCP publishes 28 mail tools, and up to 49 on a mailbox with a calendar connected. MailMCP states 15 tools plus attachments, AnyMailMCP states 18, and MCP Emails states 10. More tools is not automatically better, but it is the difference between a server that can file, flag and check a delivery and one that can read and send.

The difference you live with

It leaves a mailbox a person recognises

Anything can put a message on the wire. The question that decides whether you keep using a mail tool is what your mailbox looks like a week later, in Outlook, when the AI is nowhere near it.

A mail tool that can only list and send looks fine in a demonstration and leaves a mess behind. Replies arrive as loose messages sitting beside the conversation instead of inside it. Drafts exist somewhere the AI can see and your mail client cannot, so you open Outlook and the half-written message is not there. Forwards arrive stripped of the attachment that was the entire reason for forwarding. Reading a message quietly marks it read, so your unread count stops meaning anything. None of it is reported as a bug. People simply stop trusting the tool and go back to doing it themselves.

Mailbox MCP is built the other way round, and it is the founding rule of the engine rather than a feature on a list: you should not be able to tell, from your own mail client, that a message was handled by an assistant rather than by you. A reply threads. A draft sits in Drafts where you can open it, finish it and send it yourself, and editing it replaces it instead of leaving the old one behind. A forward carries its attachments and its inline images, and takes a Cc if you want one. Delete moves to Trash, so it is recoverable exactly as it would be if you had clicked Delete.

Everything you would do in Outlook yourself, your AI can do through the connector, and the mailbox it leaves behind is the one you would have left behind. That is the difference the table above keeps finding, row after row, and it is not a coincidence: it is one design decision showing up in nine places.

A reply nested beneath the message it answers, held up by the robot, the two joined at the corner.
A reply that lands where the conversation already is
  • A reply lands inside the thread In-Reply-To and References
  • A draft waits in Drafts APPENDed, flagged \Draft
  • Editing a draft replaces it no second copy left behind
  • A forward carries its attachments and its inline images
  • Reading leaves it unread flags untouched
  • Sent mail is filed once 1 copy, Message-ID matched
  • Deleting moves to Trash a move, never an expunge
  • A move keeps its dates IMAP MOVE, flags survive
  • A new folder shows up in Outlook created and subscribed

Each of those is checkable in your own mail client after the fact, which is the only test that counts: not our API response and not a green test run, but the mailbox opened in another program. Several were verified in Outlook rather than in a test harness, because a bug that files no Sent copy is invisible to a test written against the engine that failed to file it. The full behaviour is set out under features and what they are for, and the measured figures are on the home page.

Connections

Microsoft 365 and the app password problem

Most email MCP servers connect a mailbox the same way an old desktop client did: you hand over a host, a port, a username and a password, and the server logs in as you. For a mailbox on a web host that is completely fine and it is how our own IMAP route works too. For Microsoft 365 it is a route Microsoft has been closing for years, and the closing is not a prediction.

Microsoft's own guidance on the deprecation of Basic authentication in Exchange Online opens with a sentence that leaves no room in it:

Basic authentication is now disabled in all tenants.

We removed the ability to use Basic authentication in Exchange Online for Exchange ActiveSync (EAS), POP, IMAP, Remote PowerShell (RPS), Exchange Web Services (EWS), Offline Address Book (OAB), Autodiscover, Outlook for Windows, and Outlook for Mac.

Microsoft, Deprecation of Basic authentication in Exchange Online

The sentence worth noticing is the second one, because IMAP is named in it. The same document adds, in a note rather than a headline, that the deprecation of basic authentication also prevents the use of app passwords with apps that do not support two step verification. That is the mechanism most email MCP servers ask a Microsoft 365 customer to use, described by the vendor of the mailbox as something it has already withdrawn.

There is a legitimate answer, which is OAuth over IMAP: Microsoft released OAuth 2.0 support for POP, IMAP and SMTP AUTH in 2020, and a server can use it. None of the three competitors here documents doing so. What their pages describe is a host, a port and an app password.

Mailbox MCP connects Microsoft 365 through Microsoft's own sign-in. Your password is never typed into this site and never reaches us. What we receive is a token scoped to the permissions the consent screen listed, which you can withdraw from your Microsoft account without involving us, and which Microsoft can expire on its own terms. On that one row, the difference is not a feature. It is whether the connection is built on something its own vendor still supports.

A padlocked mailbox on one side and an open, lit mailbox on the other, with the robot holding up a plain access card and a shield carrying a tick.
A token you can withdraw, rather than a password we store

Diaries

Calendar support is not the same as CalDAV

Two of the three competitors offer a calendar, and both offer it over CalDAV. CalDAV is a good, open standard and it reaches a Fastmail, iCloud, Nextcloud or mailbox.org diary properly. What it does not reach, in the way a generic client needs, is a Google Calendar or a Microsoft 365 calendar, which between them are most business diaries in the country.

So "calendar included" on a feature list and "my calendar included" are different claims, and the gap between them is only visible once you have paid. Mailbox MCP connects all three: a Microsoft calendar arrives on the same sign-in as the mail, a Google Calendar through Google's own sign-in, and any CalDAV server by address. The calendar guide sets out which route your diary needs.

An open desk calendar with three days blocked out in blue and a reminder bell beside it, the robot pointing at one of them, a mailbox behind him.
A diary and a mailbox, looked after by the same connector

Files

Attachments that do not cost tokens

All four of these can put a file on a message. The question nobody's feature list answers is where the bytes travel, and it decides what you can actually send.

The obvious implementation has the assistant encode the file and hand it over as text. An encoded file is about a third larger than the original and the assistant has to write out every character, so a one megabyte attachment runs to roughly 450,000 words of output. It is slow, it is expensive, and past a certain size the assistant runs out of room and sends the message without the file.

Mailbox MCP fetches the file at send time instead. A file already in your mailbox is carried across by reference, a file at a web address is fetched by the server, and a file on your own computer arrives through a one-off upload link. None of those three passes through the conversation, so a 6 MB PDF costs the assistant about as much as a sentence, and the only ceiling is 10 MB for the whole message. The mechanism is set out in full under attachments that cost nothing to send.

Four cables running into one envelope: from a mailbox, from a cloud, from a laptop, and from a page held by the robot.
Four ways in, one message, and only the last costs the assistant anything

Safety

What happens when the email is the attack

Every product on this page gives an assistant three things at once: your private mail, a stream of text written by strangers, and the ability to send. Simon Willison named that combination the lethal trifecta, and the naming is the useful part, because each piece is harmless on its own and the danger is only in the set.

Access to your private data is one of the most common purposes of tools in the first place. Exposure to untrusted content means any mechanism by which text or images controlled by a malicious attacker could become available to your LLM.

Simon Willison, The lethal trifecta for AI agents, 16 June 2025

Read that against a mailbox and the point lands hard: an inbox is the purest source of untrusted content most people own. Anyone can put text in it without being invited, which is what email is. So a mail connector does not have an occasional prompt injection risk. It has a permanent one, by construction, and the only question is whether the server does anything about it.

Ours strips the instructions a message is carrying before the assistant reads them, and none of the three competitors documents doing anything of the kind. That is a cross for absence of published evidence rather than a finding of neglect, and it is exactly the sort of thing a buyer should ask about. What we do is written up on the security page, in enough detail to argue with.

The robot holding an opened letter at arm's length with a fish hook rising out of the envelope, a shield raised between himself and it.
A message can carry an instruction meant for the assistant reading it

The other side

Where we are not the best choice

We are not the cheapest, and it is not close. MailMCP advertises Pro from 1.99 euros a month and AnyMailMCP from 4.99 euros a month. Mailbox MCP is £34.99 + VAT a mailbox a year. If the deciding factor is the smallest monthly figure, one of them wins and you should take it. Our pricing page puts our number next to what it includes so the comparison is at least a fair one.

MCP Emails connects Gmail through Google's own sign-in and we do not. A Gmail mailbox here uses an app password you create in your own Google Account. That is independently revocable and never touches your Google password, so it is a reasonable arrangement rather than a broken one, but a Google sign-in is the better mechanism and they have it where we do not. It is a cross against us in the table for that reason.

Our Google Calendar connection is still in Google's verification queue. It works, and until Google completes the review a customer connecting one sees Google's "unverified app" screen on the way through. That is an unfinished thing rather than a hidden one, and it affects calendars only, not mail.

And every cross on this page is an absence of published evidence, not a test result. We have not installed three competing products and driven them against a real mailbox. If we had, the table would say so and would carry the numbers. It reports what four companies publish about themselves, on one day, which is a narrower and more honest thing.

The robot pointing openly at an empty open mailbox with a stack of papers beneath it.
The gaps, pointed at rather than left for you to find

Questions people ask

Which email MCP servers work with Microsoft 365?

Most of them will connect a Microsoft 365 mailbox over IMAP and SMTP with a password or an app password, and that route is closing. Microsoft removed Basic authentication for IMAP and POP in Exchange Online, and its own documentation notes that the same deprecation prevents the use of app passwords. Mailbox MCP connects Microsoft 365 through Microsoft's own sign-in instead, so the mailbox is reached with a token that Microsoft issues and that you can withdraw from your Microsoft account without involving us. If you are choosing a server for a Microsoft 365 mailbox specifically, that is the difference worth checking before you pay for anything.

Why does Microsoft 365 need a sign-in rather than an app password?

Because an app password is Basic authentication wearing a different name, and Microsoft has turned Basic authentication off. Its guidance is that the change requires customers to move from apps that use basic authentication to apps that use Modern authentication, which is OAuth 2.0. The practical consequence for a mail tool is that a connection built on a stored mailbox password is not a connection with a shorter life expectancy, it is one Microsoft has already ended for several protocols. A token is also narrower than a password: it carries only the permissions the consent screen listed, and revoking it does not mean changing the password you sign in with everywhere else.

Do any email MCP servers connect a Google Calendar?

The hosted email MCP servers we compared offer calendars over CalDAV, which reaches a Fastmail, iCloud or Nextcloud diary and does not reach a Google Calendar or a Microsoft 365 calendar, because neither of those speaks CalDAV in the way a generic client needs. Mailbox MCP connects all three: a Microsoft calendar on the same sign-in as the mail, a Google Calendar through Google's own sign-in, and any CalDAV server by address. If your diary is in Google Workspace or Microsoft 365, which between them is most business diaries, CalDAV support is not the same thing as calendar support.

Can an email MCP server attach a large file without using up the AI context?

It depends entirely on where the bytes travel. The obvious implementation has the assistant encode the file and hand it over as text, which is about a third larger than the original and has to be written out character by character, so a one megabyte attachment runs to roughly 450,000 words of output. It is slow, it is expensive, and past a certain size the assistant runs out of room and sends the message without the file. Mailbox MCP fetches the file at send time instead, from your mailbox, from a web address or from a one-off upload link, so the bytes never pass through the conversation and a six megabyte PDF costs the assistant about as much as a sentence.

What does a cross mean in the comparison table?

It means the capability is not in that product's published tool list or documentation on the date the page was read, which is stated above the table. It does not mean the product cannot do it, and it is not a claim that the vendor has refused to. Vendors publish what they choose to publish, and a capability can exist without being written down. That is why the date matters and why every source is linked at the foot of the page: if one of these products documents something the table marks with a cross, the table is wrong and we would rather be told.

Is Mailbox MCP the cheapest email MCP server?

No. MailMCP advertises Pro from 1.99 euros a month and AnyMailMCP from 4.99 euros a month, and both are cheaper per mailbox than we are. If price is the deciding factor, that is a real answer and you should take it. What the annual charge here buys is the capability column above: Microsoft 365 through Microsoft's own sign-in, Google and Microsoft calendars rather than CalDAV alone, attachments that never cross the conversation, and delivery checking after a send. Every one of those is in the table so you can decide whether they are worth the difference rather than taking our word for it.

Does anything here beat Mailbox MCP?

On price, yes, and on one capability. MCP Emails connects Gmail through Google's own OAuth sign-in, and Mailbox MCP does not: a Gmail mailbox here is connected with an app password you create in your own Google Account. An app password is independently revocable and does not disturb your Google password, so it is a reasonable arrangement rather than a broken one, but a Google sign-in is the better mechanism and they have it where we do not. It is marked against us in the table above for that reason.

How is this comparison kept accurate?

Every competitor cell comes from that vendor's own published pages, read on the date printed above the table and linked at the foot of it. Our own column is drawn from the same tool catalogue that generates the tools page here, which a build check compares against the running server, so our cells cannot quietly claim something the software does not do. Comparison tables age faster than anything else on a website, so this one carries a read date rather than pretending to be permanent, and it is rechecked when a competitor ships something or a reader tells us a cell is wrong.

Attribution

Sources

Every competitor cell above comes from one of these, read on . Our own column comes from this site's tool catalogue and the connection routes documented on our security and privacy pages.

  • MailMCP Tool count, CalDAV calendar, CardDAV address book, IMAP and SMTP provider list, free plan, and hosting in France.
  • MailMCP: best email MCP servers Their own comparison, used for how they describe their connection method and their tool set rather than for their view of anybody else.
  • AnyMailMCP AnyMailMCP states 18 tools, its IMAP provider list, CalDAV calendars, attachment download to 25 MB, and its plan limits and prices.
  • MCP Emails MCP Emails states Gmail OAuth 2.0, app passwords for other providers, ten published tools, no calendar, and its plan prices.
  • Microsoft: deprecation of Basic authentication in Exchange Online Basic authentication disabled in all tenants, the protocol list including IMAP, the note on app passwords, and OAuth 2.0 support for POP, IMAP and SMTP AUTH from 2020.
  • Simon Willison: the lethal trifecta for AI agents The quoted definition of private data, untrusted content and the ability to communicate externally.