All documentation
On this page

Features

Everything it can do, and why each one matters

The rest of these docs get a mailbox connected. This page is what you get once it is. Every feature below is something an ordinary mail client does and most email integrations do not, with the reason it matters beside it, and the limit stated in the same breath wherever there is one.

Every feature at a glance

Twenty-eight tools, which group into 7 things you can ask for. If you only read one part of this page, read the right-hand column.

What it doesWhy that matters to you
Four ways to attach a file A 6 MB PDF costs the assistant nothing to send
Replies carry thread headers Your reply appears in the conversation, not beside it
Forwards keep their contents Attachments and inline images travel with it
Every address on the mailbox Each with its own name and signature
Whole conversations in one call It answers what was said, not just the last message
Bounces, classified Permanent means fix the address; temporary means wait
Read receipts, requested and read Asked on the way out, found when they come back
Up to 500 messages in one call Filing a year of newsletters is one action
Reading never marks read Your unread count still means something
Deletes go to Trash Recoverable, exactly as in your mail client

Attachments that cost nothing to send

This is the feature that separates a mail integration that works from one that gives up halfway. A file can reach a message from four places:

The four ways a file can be attached: from the mailbox itself, from a web address, from your own computer, and one the assistant writes, all arriving at a single message.
Four routes in, one message. Only the last costs the assistant anything.
  • Already in your mailbox. The invoice somebody sent you last week, the photo, the signed contract. The assistant opens the message it is attached to and carries the file straight across.
  • At a web address. A SharePoint, OneDrive, Google Drive or Dropbox share link, or any direct link to a document. The server fetches it itself. The link has to open without signing in, because a link that asks for a login gives us a sign-in page and that is what would be attached.
  • Off your own computer. A one-off upload link that needs no sign-in and no password. Your assistant can upload to it directly if it can run commands; otherwise it hands you the link and you drop files on it. Everything that arrives goes onto the message in one go.
  • Written by the assistant itself. A calendar invite, a small CSV, an image it just drew. Something that exists nowhere else.

The first three never pass through the assistant. The bytes go from wherever they live into the message while it is being built. The assistant never sees them and never has to write them out.

Why that is the whole point

The obvious way to attach a file is to have the AI encode it and hand it over as text. That works for a logo and fails for anything real. An encoded file is a third larger than the original and the assistant has to type every character of it, so a one megabyte attachment is somewhere around 450,000 words of output. It is slow, it is expensive, and past a certain size the assistant simply runs out of room and sends the message without the file. We have watched that happen.

Because the first three routes never involve the assistant, a 6 MB PDF costs it about as much as a sentence and arrives in seconds. Several files can go on one message. The only ceiling is 10 MB for the whole message, which is our limit rather than your provider's.

The exception is the fourth route, and it is honest about itself: a file the assistant composes has to fit in its own output, so it is capped at a few tens of kilobytes. That is the right tool for an invite and the wrong one for a brochure.

Getting a file off your own computer

That third route is the one worth explaining, because it is the only one where you might have to do anything. The assistant asks for a one-off upload link, and then takes whichever of two paths is open to it.

Two ways a file from your own computer reaches the mailbox: the assistant posting it directly, or files sent from your own laptop, both arriving through the same one-off link.
Either it uploads the file for you, or you drop files on the link. Both end in your own Drafts.
  • It uploads the file itself, if it is the kind of assistant that can run commands or make web requests. You do nothing at all beyond saying which file you meant.
  • It hands you the link, if it is not. You open it, choose your files, and tell it you have finished. No sign-in and no password, and it takes several files at once.

Whichever path it takes, what arrives lands in your own Drafts folder as an ordinary draft you can see in Outlook. The link stops working after half an hour, and the holding draft removes itself once the files are attached to a real message, so there is nothing for you to tidy up.

Files come back out as well as in. Every attachment on a message you read comes with a private, short-lived download link, so an assistant that cannot hand you bytes can still hand you the file.

For example, you might say:

Reply to Hollis about the March invoice and attach the signed contract from the email Dawn sent me last Tuesday.

It searches for Dawn's message, finds the contract on it, and attaches that file to a reply that lands in the Hollis thread. The file never passes through the conversation, so its size is irrelevant and you are not charged for it in tokens.

Replies that land in the thread

A reply is not a new message with Re: in front of it. Mail clients decide where a reply belongs by reading two headers on it, and a reply sent without them arrives as a stray message sitting next to the conversation it belongs to. Nobody reports that as a bug. They just find the thread confusing.

Replies here carry In-Reply-To and References, so the reply nests under the original in Outlook and Gmail exactly as it would if you had written it yourself. The original is marked answered, so it shows the reply arrow in your own client.

It can also read the whole conversation first, in one call. That matters more than it sounds: an assistant working from the last message alone answers the last message alone, which is how you get a polite reply that misses the thing agreed three messages earlier.

A reply-all subtracts every address on your mailbox, so you are never copied in on your own thread. And a Reply-To pointing somewhere the message did not come from is refused until the address is named explicitly, because that is what a redirected reply looks like.

For example, you might say:

Read the whole thread with the architect about the planning application, then reply agreeing to the Thursday site visit and copy in Sam.

It reads every message in the conversation before writing anything, replies inside that thread, adds Sam to the copy line, and marks the original as answered so your own mail client shows the reply arrow against it.

Forwards that arrive intact

Forwarding is where integrations quietly lose things. The message goes on, the attachments do not, and the person at the other end asks where the drawing is.

A forward here carries the original's attachments and inline images, under the forwarded-message block a real mail client produces. You can send it to several people and copy others in, exactly as you would yourself, and attach files of your own alongside the original's rather than instead of them.

Everything still has to fit the 10 MB ceiling for the whole message. If something will not fit, it is named as skipped rather than dropped in silence, so you find out before the recipient does.

For example, you might say:

Forward the surveyor's report to the client and copy in our solicitor, with a line saying the roof section is the part that matters.

The report arrives with its own attachments and any images that were embedded in it, under the forwarded-message block a mail client produces, with your note above it and the solicitor on the copy line.

Send as any of your addresses

If your mailbox can send as more than one address, so can this. Each alias carries its own display name and its own signature, set in your account rather than by the AI client, so a message sent as your sales address is signed as your sales address.

Exactly one copy is filed in Sent Items, with the same Message-ID the recipient received, so your sent folder stays a true record rather than gaining a second copy of everything.

A message can also be saved as a real draft instead of being sent, carrying its files. It lands in your actual Drafts folder, so you can open it in Outlook, change a sentence and send it yourself.

Ask for a change and it rewrites that draft rather than saving a second one. IMAP cannot edit a message in place, so what actually happens is that the new version is saved and the old one removed, which is exactly what your own mail client does when you edit a draft. It matters because the obvious alternative leaves every version you rejected sitting in your bin. Attachments and the headers that hold a reply in its conversation both survive the rewrite.

For example, you might say:

Draft a reply to this enquiry from our sales address, attach the current price list, and leave it in Drafts for me to check.

It composes the message as your sales address, with that address's own signature rather than your personal one, attaches the file, and files it in Drafts. Nothing is sent. You open it in your own mail client and decide.

Finding out whether it arrived

A send being accepted does not mean a message was delivered. Acceptance is the relay saying yes; delivery happens minutes later on somebody else's machine. Two features close that gap, and they answer different halves of it.

Bounces, classified

It finds messages that came back undelivered, in your Inbox and your Junk folder, and says whether each failure is permanent or temporary. That distinction is the whole value: a permanent failure means the address is wrong and resending changes nothing, while a temporary one means the receiving server was busy and yours is already retrying, so resending delivers the message twice.

Read receipts

A send, a reply, a forward or a draft can ask for a read receipt on the way out. It is the same tick box Outlook offers. Afterwards, a separate tool finds what came back.

What a read receipt actually tells you

Less than the phrase suggests, and we would rather say so here than have you find out later. A read receipt is a request to the recipient, not a measurement of them. Their mail program decides what to do with it, and most either ask them first or ignore it: consumer Gmail never returns one, Google Workspace only if an administrator has enabled it, and Apple Mail only behind a setting that ships switched off.

So a receipt that arrives means the message was opened and somebody agreed to say so. A receipt that never arrives means nothing at all: not that the message was unread, not that it failed. The tool says exactly that in its own results, because the one thing this feature must never do is let silence be read as being ignored.

There is no delivery-receipt option, and that is measured rather than missing: it needs an SMTP feature that none of the mail providers this connects to offer, so asking for one would look like it had worked and do nothing.

For example, you might say:

I sent a quote to that new supplier on Friday and have heard nothing. Did it actually get there?

It looks for a bounce first, and says whether any failure is permanent or temporary. Then it looks for a confirmation. If it finds neither, it tells you that plainly rather than implying you were ignored, because with most mail programs there was never going to be a receipt either way.

There is a third feature in the same family: it can check the SPF, DKIM, DMARC and MX records on your own domain, and tell you when a DMARC record is published but set to do nothing. That is the difference between mail that reaches inboxes and mail that reaches spam folders.

Filing, in bulk, on request

Up to 500 messages move between folders in a single call, which turns "file a year of newsletters" from an afternoon into one request. Folders can be created, renamed, or moved under a different parent with their sub-folders. Messages can be marked read, unread or flagged, up to 500 at a time.

A new folder is subscribed when it is created, which sounds like a detail and is the difference between a folder appearing in Outlook and a folder that exists but is invisible.

Deleting moves a message to Trash, exactly as clicking delete in your mail client does, so it is recoverable. Nothing on this surface erases mail permanently.

For example, you might say:

Make a folder called Suppliers 2026 and move everything from Brightwell and Kesteven into it, going back to January.

It creates the folder, subscribes it so it actually appears in Outlook, searches for both senders across the period, and moves the lot in a single operation rather than one message at a time.

The feature you never see

The hardest part of this was not adding capabilities. It was making sure that after an assistant has been through your mailbox, you cannot tell from Outlook that anything but you had been in it.

  • Reading never marks anything read. Marking read is an action you ask for, never a side effect of an assistant looking at something. Your unread count still means what it meant this morning.
  • One Sent copy, not two. Some providers file a copy themselves and some do not; filing blindly leaves you with everything twice.
  • Special folders are found by their flag, never by name. Your Sent folder might be called Sent Items, Envoyés, or something your host chose. Guessing at names is how integrations create a second "Sent" folder beside your real one.
  • Nothing is invented. No folders you did not ask for, no labels, no tags, no signature of ours appended to your mail.

Those behaviours were checked by looking at the mailbox in a mail client afterwards, rather than by trusting what our own code reported. The results are on how it works, measured against a live mailbox of 26,930 messages.

What it deliberately does not do

A feature list that admits nothing is a feature list nobody believes.

  • Attachments are capped at 10 MB per message in total across every file attached, which is our limit rather than a provider's.
  • Only a file the assistant composes itself is small. Files already in the mailbox, at a web address, or uploaded through a one-off link are streamed at send time and never pass through the model.
  • It does not archive, back up or export a mailbox, and it is not a migration tool.
  • Calendar tools appear once a diary is connected, which is its own step: calendar access approved on a Microsoft 365 sign-in, a Google sign-in for Google Calendar, or the address of a CalDAV calendar server. A mailbox with none of the three gets the email tools and no calendar tools at all.
  • It does not manage a contacts list or a file store. Addresses are resolved from the mailbox's own history rather than from an address book, and attachments are handled as mail rather than as documents.
  • When somebody's calendar cannot be read, the answer is unknown rather than free. Free/busy across organisations depends on an arrangement between them, and a name that comes back blank has told you nothing.
  • Reading or searching the diary needs a start and an end. A diary has no end, so there is no "everything" to return, and the answer always names the window it looked in.
  • It cannot list the meeting rooms an organisation has. Reading a room directory needs a permission only an IT administrator can approve, and asking every customer for that to power one convenience is the wrong trade. A room with an email address can still be invited and its free/busy checked, exactly like a person.
  • Files attached to a calendar event are not read or written yet. Attachments on email are, and event attachments are a separate piece of work rather than an oversight.
  • It cannot recover mail that has already been deleted.
  • Shared and delegated mailboxes are not supported. A shared CALENDAR is a different thing and is supported on Microsoft 365: one that has been shared with you can be read, and written to where the person who shared it allowed that.
  • It cannot schedule a send. Everything happens when you ask for it, and nothing runs while you are away.
  • Search results and long threads are capped. The response reports the total, the number returned and whether it capped, but a very broad search will meet the cap.
  • Search is substring matching over IMAP. There is no stemming and no ranking, so a search for invoices does not find a message that only ever says invoice.
  • The deliverability check reads the connected mailbox's own domain only. It will not look up a customer's domain, or a competitor's.
  • Deleting a folder is refused while it still holds messages or has sub-folders inside it. There is no Trash to recover a folder from, and what reaches this tool is a model acting on a sentence rather than a person looking at the folder.
  • It can ask for a read receipt but not a delivery receipt. A delivery receipt needs an SMTP feature the mail providers it connects to do not offer, so asking for one would do nothing while appearing to have worked. A read receipt is only ever a request: most mail programs never answer it, so a missing one is not evidence a message went unread.
  • There is no phone line. Support is by email, deliberately.
  • Stored credentials are encrypted at rest with AES-256, and the server keeps no copy of your messages.
  • Both plans have a daily ceiling on MCP calls: 5 a day on Free and 1,000 a day on Pro, per mailbox. Pro is a published limit, not an unlimited plan.
  • These limits describe the tools this server registers. Another vendor's mail MCP server has a different list, and the only way to know theirs is to read it.

If one of those is a dealbreaker, it is better that you know now than after connecting a mailbox. The complete tool reference goes further and lists what each individual tool refuses to do.

Frequently asked questions

Can an AI attach a file to an email it sends?

Yes, from four different places, and three of them cost the assistant nothing. It can attach a file that is already in your mailbox, such as an invoice somebody sent you. It can attach a file at a web address, like a SharePoint or Drive share link, which the server fetches itself. It can attach a file from your own computer through a one-off upload link that needs no sign-in. And it can attach something it wrote itself, such as a calendar invite. The first three are streamed into the message when it is built and never pass through the assistant, so it never has to encode them and a 6 MB PDF costs it about as much as a sentence. Several files can go on one message, up to 10 MB in total.

Why do other AI tools struggle to send attachments?

Because the obvious way to do it is to have the assistant encode the file and hand it over as text, and that only works for very small files. An encoded file is about a third larger than the original, and the assistant has to write out every character of it, so a one megabyte attachment runs to roughly 450,000 words of output. It is slow, it is expensive, and past a certain size the assistant runs out of room and sends the message without the file. Mailbox MCP avoids that entirely for any file that already exists somewhere: the bytes travel from wherever they are into the message, and the assistant only ever handles the reference to them.

Will a reply appear inside the original conversation?

Yes. A reply carries the In-Reply-To and References headers, which are what a mail client reads to decide where a reply belongs, so it nests under the original in Outlook or Gmail exactly as it would if you had written it. The original is marked answered too, so it shows the reply arrow in your own client. It can also read the whole thread before replying, in a single call, so the reply answers what was actually agreed rather than only the last message in the chain.

Does a forwarded message keep its attachments?

Yes. Attachments and inline images travel with a forward, under the forwarded-message block a real mail client produces, and you can copy other people in and add files of your own alongside the original's. Everything still has to fit the 10 MB ceiling for the whole message, and anything that will not fit is named as skipped rather than dropped silently, so you find out before the recipient does.

Can it request a read receipt when it sends an email?

Yes, on a send, a reply, a forward or a draft, and it is the same request Outlook makes when you tick the read receipt box. A separate tool then finds what came back. Be realistic about what that can prove: a read receipt is a request to the recipient rather than a measurement of them, and most mail programs either ask them first or ignore it. Consumer Gmail never returns one, Google Workspace only if an administrator enabled it, and Apple Mail only behind a setting that ships switched off. A receipt that arrives means the message was opened and somebody agreed to say so. A receipt that never arrives means nothing at all, and the tool says so in its own results rather than letting silence be read as being ignored.

Can it request a delivery receipt as well?

No, and the reason is worth knowing because it is not a gap we chose. A delivery receipt is requested at the SMTP level and needs the sending server to support an extension called DSN. Five submission endpoints across both of the SMTP providers this connects to were checked and none of them advertises it, and Microsoft 365 mailboxes do not send over SMTP at all. Adding the request anyway would look like it had worked and do nothing, which is worse than not offering it. If you want to know whether a message reached its destination, checking for bounces is the honest answer: failures are reported back, so no bounce after a few minutes is real evidence.

How many messages can it move or file at once?

Up to 500 in a single call, and the same ceiling applies to marking messages read, unread or flagged. That is what turns filing a year of newsletters into one request rather than an afternoon. Folders can be created, renamed, or moved under a different parent along with their sub-folders. A folder it creates is subscribed as well as created, which is the difference between a folder appearing in Outlook and one that exists but never shows up.

Does an assistant reading my mail mark it as read?

No. Reading never sets the read flag, on any tool, in any circumstance. Marking a message read is a separate action that happens only when you ask for it. That matters because an unread count you cannot trust is worse than no unread count: if an assistant quietly marked everything it looked at, you would lose the one signal that tells you what still needs your attention. The same principle runs through the rest of it, with deletes going to Trash rather than being erased and special folders found by their flag rather than guessed at by name.