For one person

Everything your AI can do with your email, and exactly how much you let it.

Connect the mailbox you already own and Claude, ChatGPT or any AI that speaks MCP can read it, answer it, file it and read the files on it, at a level you set per connection and under a limit no client can pass. This page is what one person gets. Putting a team on shared mail? See what a team gets.

  • Tools 32 email tools
  • Levels 3, per connection
  • Free 5 calls a day

What it does

What the AI does with your email

Everything an ordinary mail client does, done by the assistant you already pay for, on the mailbox you already have. This half is what Claude can do with your email once it is connected, and ChatGPT, Cursor or any other AI that speaks MCP the same. Each section names the thing it does, why that matters to you, and the limit in the same breath where there is one.

Reading

Reads your email the way you would, and marks nothing read

Ask what came in overnight and it lists the folder with the first line or 2 of every message, the quoted history and the signature stripped off, so the shortlist is built without opening anything. Ask for the invoice from the plumber and it searches the mailbox itself, as many as 25 folders in one call, matching the words you gave it. Ask to be caught up on the thread with the surveyor and it reads the whole conversation in one call, oldest first.

Reading never marks anything read. Marking a message read is an action you ask for, never a side effect of the AI looking at it, so your unread count still means what it meant this morning. That is one of 5 promises, each checked by opening the mailbox in a mail client afterwards rather than by trusting what our own code reported, on a live mailbox of 26,930 messages.

So the AI can go through your inbox for you, and you still open Outlook to the inbox you left, with nothing touched that you did not ask to be touched.

Reading email without marking it read: the robot carefully replacing a letter in a mailbox and resetting its flag, leaving everything as he found it.
Put back exactly as it was found
  • Unread flags when reading unchanged
  • Reply threading In-Reply-To + References
  • Sent Items after a send 1 copy, ID matched
  • Attachment bytes SHA-256 identical
  • Folders it invents none

Attachments

Reads what is inside an attachment: PDFs, spreadsheets, photos

The AI reads email attachments, not only the message around them. Ask what the invoice Hollis attached actually comes to and the server fetches the PDF from your mailbox and hands the AI its text, page by page. A Word document keeps its tables. A spreadsheet comes back as rows with the formulas already worked out and every sheet reachable by name, a slide deck slide by slide. A photo comes back as a picture the AI can look at, and a scanned letter as pictures of its pages, so it is read the way a person reads it. What a file is comes from its first bytes rather than from its name, so a program calling itself invoice.pdf is named as a program.

Read on real mail on , through the live service: a 5-page invoice, a 16-sheet spreadsheet and an 8-page scanned letter, from files real correspondents had sent. Reading a file never marks the message read, and nothing is kept afterwards. That is the difference from Claude's own Gmail connector, which reads attachment metadata only, per the Anthropic help centre page cited under the sources: it can tell you there is a PDF on the message and not what it says.

So the invoice, the contract and the scan are read rather than described, and a file that is not what it says it is gets named before anybody opens it.

An attachment identified by its bytes rather than its name: the robot holding up a see-through envelope with chrome cogs and a spring inside it instead of a letter, pointing at them.
What a file is comes from its bytes, not its name

Files go the other way just as cheaply. A file reaches a message from 4 places: already in your mailbox, at a web address, off your own computer through a one-off upload link that needs no sign-in, or written by the AI itself. The first 3 never pass through the AI at all: the bytes go from wherever they live into the message while it is being built, so a 6 MB PDF costs the AI about as much as a sentence and arrives in seconds. Only a file the AI writes itself has to fit in its own output, and only that one is small. Attachments are capped at 10 MB per message in total across every file attached, which is our limit rather than a provider's.

The 4 ways a file can be attached to an email: from the mailbox itself, from a web address, from your own computer, and one the assistant writes, all arriving at a single message.
4 routes into one message, and only the last costs the AI anything

So a file you want sent on goes without you doing the attaching, whatever its size, and without the AI ever having to spell it out.

Sending

Sends, replies and forwards in the thread, from any of your addresses

A reply carries the 2 headers a mail client reads to decide where it belongs, In-Reply-To and References, so it nests under the original in Outlook and Gmail exactly as if you had written it, and the original is marked answered so your own client shows the reply arrow. A forward carries the original's attachments and inline images under the forwarded-message block a real mail client produces. A reply-all subtracts every address on your mailbox, so you are never copied in on your own thread.

If your mailbox can send as more than one address, so can this, and each alias carries its own display name and signature, set in your account rather than by the AI. Exactly one copy is filed in Sent Items, with the same Message-ID the recipient received. Attachments arrive byte for byte: a real send of a JPEG and a ZIP came out SHA-256 identical at the far end. About 5 seconds to an external domain through Microsoft Graph, about 10 over SMTP, both timed.

So what your AI sends looks, threads and files exactly like what you send, and the person at the other end cannot tell the difference.

An email reply sent in the thread with In-Reply-To and References: the robot clipping a reply card directly beneath the original message it belongs to.
The reply clipped to the message it answers

Drafts

Writes drafts that Outlook and Gmail can open

Ask for a reply you want to read first and it is saved into your real Drafts folder, threaded and quoted, carrying its files, with the original left unmarked because it has not been answered yet. You open it in Outlook or Gmail, change a sentence, and press Send yourself. A forward can be drafted the same way, which is the message where checking first matters most, because the part being sent is not yours.

Ask for a change and it rewrites that draft rather than saving a second one, so a wording you went through 5 times leaves one message in Drafts and nothing in your bin. The files already attached and the headers that keep a reply in its conversation both survive the rewrite. At the Draft and file level, further down this page, this is as far as a connection can go: it prepares, and nothing leaves.

So the AI can do the writing while the sending stays a thing you do, in the program you already trust for it.

An email reply drafted by an AI and left for you to send: the robot holding a written page over an open Drafts tray, pausing rather than posting it.
Into Drafts first, out of the mailbox second

Filing

Files, flags, archives and junks, in bulk when you ask

Up to 500 messages move between folders in a single call, which turns "file a year of newsletters" from an afternoon into one request. Folders can be created, renamed, or moved under a different parent with their sub-folders, and a folder it creates is subscribed, which is the difference between a folder that appears in Outlook and one that exists but never shows up. Messages are marked read, unread or flagged in the same batches. Deleting moves a message to Trash, exactly as your own delete button does, so it is recoverable.

Archiving goes where your own Archive button would have put it, and that is a different place on each service: Microsoft 365 has a folder called Archive, most IMAP hosts have none until one is created, and Gmail has no archive folder at all, because archiving there means the message leaves the inbox and carries on living in All Mail. Reporting spam is the same move your spam button makes, which is what teaches your mail server's filter to catch the next one, and rescuing a message the filter got wrong returns it to the inbox with the date it originally arrived.

So the tidying happens the way you would have done it, and nothing is filed anywhere you would not have put it. The filing guide walks through a real clear-out.

Filing and flagging email from an AI client: the robot holding a letter with a blue flag tab at an open filing drawer full of folders.
Move, flag and mark, in the folders you already have

Checks

Tells you who really sent it, and whether yours arrived

Every message the AI reads carries what your own mail server concluded about the sender from SPF, DKIM, DMARC and ARC, as one verdict, and whether the From address is the mailbox's own. It also names any writing a person would not have seen: text styled invisible, hidden comments, invisible characters, an instruction aimed at the AI rather than at you, with the text quoted, reported and never acted on. The threat model sets out what that catches and what it does not.

Sent something and heard nothing? It finds the bounce, in Inbox and Junk, and says whether the failure is permanent, so the address is wrong and resending changes nothing, or temporary, so their server was busy and yours is already retrying. It finds the read receipts that came back, and says plainly that a missing one is evidence of nothing, because most mail programs never send one. It checks the SPF, DKIM, DMARC and MX records of your own domain, and tells you when a DMARC record is published but set to do nothing.

So "is this really from the bank" and "did my quote get there" are questions your AI answers from evidence rather than from the look of the message.

Checking who an email is really from: the robot holding a magnifying glass over the lit sender tag on an envelope, a small glowing panel beside him.
Who it is from is read, not assumed

Calendar

Your calendar too: Google, Microsoft 365 and CalDAV

Connecting a mailbox does not connect a diary. That is a separate step, and there are 3 routes to it: calendar access approved on a Microsoft 365 sign-in, a Google sign-in for Google Calendar on any mailbox, or the address of a CalDAV calendar server, which Fastmail, iCloud, Nextcloud and most mail hosts run beside the mail. Once one of them is connected, the AI reads the diary, checks who is free, finds a time that works, and books, moves and answers meetings, with the 21 calendar tools arriving in full on Microsoft 365 and in whatever set the other route supports.

Unknown is never rendered as free. When somebody's calendar cannot be read, a different organisation or a permission never granted, the answer for that person is unknown, and what comes back for other people is busy and free, never the subjects of their meetings.

So a meeting is booked into a slot the AI could actually see, and the invitation goes out in your name only at the level you allow. The scheduling guide covers a week of real bookings.

A calendar connected beside a mailbox: the robot pointing at one of 3 days blocked out in blue on an open desk calendar, a reminder bell on the page, a mailbox on its post behind him.
The diary as well as the post, once a calendar is connected

Works with

Works from Claude, ChatGPT, Cursor and the rest

Mailbox MCP is an ordinary remote MCP server, reached over HTTPS, and nothing in it knows which assistant is on the other end. Connect a mailbox once and reach it from whichever AI client you actually work in. The one requirement is that the client supports remote MCP connectors; a client that only runs local servers reaches it through the mcp-remote bridge. No extra licence, and no second price.

  • ChatGPT Assistant
  • Cursor Code editor
  • VS Code Code editor
  • Zed Code editor
  • Windsurf Code editor
  • Cline Coding agent
  • Goose Open agent

See every client and the one requirement

The control you keep

The control you keep over the AI

Every one of the things above is something you decide how much of to allow: AI email permissions set per client, a ceiling on the mailbox that none of them can exceed, and a record of every call any of them made. This is the half to read before connecting anything.

Permission levels

Read only, draft, or send: a permission level per connection

Every connection an AI client makes by signing in carries one of 3 permission levels, chosen on the consent screen when you approve it. Read only: looks, and changes nothing. Draft and file: prepares and tidies, and nothing leaves. Send and delete: everything, including what cannot be taken back. Each contains the one below it, and a calendar switch beside the level decides whether the diary comes with it.

It is per connection, not per mailbox. Claude on your laptop can be Read only while ChatGPT on your phone is Draft and file, on the same mailbox, and either is changed on the mailbox's Connector tab in the control panel without reconnecting, obeyed on that client's next call. Whether to let Claude send emails at all is the same choice: only Send and delete can. A connection below the top level is not shown the tools above it at all, so the model is never offered send_email and never spends a turn finding out it cannot use it. The tool reference lists every tool under the level that reaches it.

So AI email read-only access, "can I let it read my email but not send anything", is a setting you make once, per client, rather than a promise the client makes.

A permission level for each AI client connected to one mailbox: the robot at the centre with lit cables running from him to 2 mailboxes and 3 screens, a monitor, a tablet and a laptop.
Every screen on its own cable, and a connection for each

Anthropic's own Gmail connector, the one built into Claude, puts its safety in an approval step rather than in a level. Its help centre, read on , says:

Claude can send, reply to, and forward emails, but only does so with your explicit approval by default.

Anthropic help centre, Use Google Workspace connectors

"By default" is the phrase to notice, and the same page goes on to say that on Team and Enterprise plans an owner decides whether members can let those actions run without asking each time. That is a reasonable design, and it is a different kind of control from a level. An approval prompt asks you every time and lives in the client, where it can be switched off; a level is set on our server, per connection, and a client at Read only is never handed the send tool to ask about. The two are not in competition. Connect Mailbox MCP to Claude and you get both: Claude's own prompt before a tool it treats as destructive, and the level underneath it that decides which tools exist for that connection at all.

The mailbox limit

A limit under every connection that no AI client can exceed

Under every connection sits the mailbox's own limit, set by you on the same Connector tab: one of the same 3 levels and the calendar switch. It defaults to Send and delete with the calendar on, so nothing changes until you change it. What any connection can actually do is the lower of its own level and the limit, and it has the calendar only when both say so. A connection may be set below the limit, never above it.

It is enforced by the server, on every call, before the call is metered. A consent screen cannot be approved above it. A person you share the mailbox with cannot be given more than it. A pasted access token, the kind Cline, Goose, LibreChat and n8n take instead of signing in, takes the limit as its level. Lower the limit and every connection above it is capped on its next call; raise it again and each gets back exactly what was chosen, because nothing is rewritten.

So the most any AI can ever do with this mailbox is one setting, in a place only you can sign in to, and no client, no consent screen and no token can get past it.

The mailbox limit under every AI connection: the robot kneeling to fit a small gauge with a padlock hanging from it onto the cable that runs from a mailbox to a screen, the cable lit bright on the mailbox side.
A gauge on the cable, locked, and nothing downstream can pass it

Ivan Kuznetsov, who built a structurally read-only email server for his own 25 years of mail, put the objection to client-side settings in one line, writing on HackerNoon on :

A setting can be flipped, by a person or by a prompt.

Ivan Kuznetsov, How to Let Claude Search Your Email Without Letting It Send or Delete

He is right, and his answer was to remove the write path from the code entirely, which is the strongest guarantee there is and also means his server can never send a reply. Ours is a different trade, and it is worth being plain about the difference. The limit is a setting. What makes it more than a checkbox is who can flip it and from where: only the mailbox's owner, signed in to the control panel, with a second factor if the account requires one, and never from the AI side. A prompt cannot reach it, a client cannot reach it, and a consent screen that asks for more is refused by the server rather than by the screen. That is what lets one mailbox be read-only to one client and able to send from another, which a server that cannot write at all cannot offer.

The Connector tab of the Mailbox MCP control panel, showing your connections to this mailbox, 2 clients: A desktop MCP client at Read only, signed in 3 days ago and last renewed 7 hours ago; Claude on my laptop at Draft and file with the calendar, marked capped by the mailbox limit, signed in 6 September 2026; each with Change and Disconnect, and a note headed Two separate ways in beneath them.
Two connections to one mailbox at two levels, and the second is capped by the mailbox limit.
The mailbox limit card on the Connector tab, headed The most any AI client may do with this mailbox: 3 level cards, Send and delete, Draft and file, which is selected, and Read only, each with a one-line description; a ticked switch reading The calendar may be included; and a Save the limit button.
The limit card: this mailbox is limited to Draft and file, with the calendar included.

Refusals

A refused tool says what it is, so the AI stops asking

A client that calls a tool its level or the mailbox limit does not allow is refused as an ordinary tool result, before the call is metered, with one sentence naming what refused it and where to change it. When the limit is what refused it, the sentence names the limit rather than the connection, because the limit is the control you would have to change. This is the sentence a mailbox limited to Read only hands back to any client that tries to send from it:

This mailbox is limited to "Read only" in the control panel, so no connection can send from it. The mailbox owner can change that under the mailbox's Connector tab.

A tool no level has ever placed, a typo or a name the model made up, is answered with there is no tool called that on this connection, with the name quoted back. A refusal by the level or the limit is recorded on the Activity tab as a failed call, with Not allowed on this connection: in front of the reason, and the note ends (mailbox limit) where the limit was the wall.

So the AI is told, in words it can relay to you, what it may not do, instead of trying again or telling you something went wrong.

A tool the connection's level does not reach: the robot hugging a bundle of letters at a filing cabinet whose drawers have no handles.
No handle on the drawer, and a sentence saying why

Account security

A second factor, and a record kept for as long as you choose

One switch under Settings, Security requires a second factor of everyone on the account. While it is on, a person without a confirmed authenticator can do nothing in the control panel but set one up, cannot accept an invitation onto your mailboxes, and has every AI connection they made refused on its next call until they do. It cannot be switched on until your own authenticator is set up, and yours cannot be turned off while it is on. A pasted access token is the mailbox's credential rather than a person's sign-in, and is not gated by it.

The audit record of each call is kept 400 days by default, and you can shorten it under Settings to any whole number of days from 90 to 400. The shorter end, 90 days, is the least that still covers a charge, the statement after it and the time it takes anyone to ask. Nothing else about the record is yours to shorten, because nothing else is held: the record is the fact of the call and never its contents.

So the account the AI's access hangs off is one that needs more than a password to enter, and the record of what it did is kept for as long as you decide rather than for as long as we decide.

The Security card in the Mailbox MCP control panel: a switch, on, beside Everyone on this account must use a second factor to sign in, with its explanation; a field headed Keep the audit record for, empty and showing the default of 400 days, with the hint that it runs from 90 to 400 days; and a Save button.
The Security card: the second-factor switch, and the audit record kept for the days you choose.
  • Audit record kept, by default 400 days
  • Shortest period you can choose 90 days
  • Second factor of everyone off until you switch it on
  • A pasted access token not gated by the switch

The record

Every call the AI made, on the Activity tab

Every call any AI client makes to your mailbox is a row on the Activity tab: when, which tool, which mailbox, who made it, whether it worked, how long it took and the address it came from. Filter by period, mailbox, tool and outcome, and the chips count reads, writes and irreversible calls separately. A call that partly succeeded says how far it got rather than rounding itself up to a success.

The record holds the fact of the call, never the contents: no subject, no address, no line of a message, because none of that is stored anywhere. A refused call is recorded as failed, with the reason; a download or an upload is recorded as the message and a file count, never a filename. Until every row was recorded as a success whatever the tool returned, and the changelog says so rather than leaving you to trust the older rows.

So "what did the AI actually do in my mailbox last week" is a screen you open, an audit log of what the AI did, rather than a question you have to put to the AI.

The Activity tab of the Mailbox MCP control panel, filtered to one mailbox over the last 24 hours: 10 calls on info@lowsonparts.example, chips reading All 10, Read 7, Write 3 and Irreversible 0, and a table of when, tool, mailbox, who, outcome, took and from, with 8 rows by You and 2 by Harriet Moss, one marked Partly with the note 12 of 13 marked unread, 1 was no longer there, and a note beneath headed What is in this log.
A day of calls on one mailbox by 2 people, with one call that partly succeeded and says how far it got.

When something breaks

When a credential stops working, you are told once

A calendar credential the provider now refuses, a Google permission revoked or lapsed, or a calendar server refusing its app password, is shown in the control panel on the mailbox row, the calendar card and the overview, and you are emailed once, with the fix on the mailbox page. Mail is unaffected throughout. That has been so since ; before it, the calendar tools left the connection and nothing said so.

So a diary that has quietly gone dark is something you are told about, once, rather than something you discover when a meeting was never booked.

What it costs

Free is 5 calls a day, Pro is 1,000 a day per mailbox

Any mailbox connects free, with no card, and stays free until you decide otherwise. Both figures are published ceilings, and Pro is a limit rather than an unlimited plan.

  • Free, on any mailbox 5 calls a day
  • Pro, per mailbox 1,000 calls a day
  • Pro, per mailbox, a year £34.99 + VAT
  • Calls are counted over a rolling 24 hours

Pro is £2.92 a month, paid annually at £34.99 + VAT, per mailbox, and there is no per-client price: one mailbox on Pro serves however many AI clients you connect to it, each at its own level. On the client side, Anthropic's help centre says a free Claude plan can add one custom connector, which is one mailbox, so the free tier here and a free AI plan together are a working set-up that costs nothing. The pricing page for one person has both figures with what counts as a call, and Team Access is the page for putting other people on a mailbox you own.

Limits

What it deliberately does not do

A feature list that admits nothing is a feature list nobody believes. These are the ones people are disappointed by, listed before you connect rather than after.

  • Nothing of yours is kept

    Stored credentials are encrypted at rest with AES-256, and the server keeps no copy of your messages.

  • Not a backup tool

    It does not back up, export or migrate a mailbox, and there is no tool that copies your mail anywhere. Archiving a message files it in your own Archive folder, which is filing rather than a backup.

  • Attachments are not scanned for malware

    Nothing here scans an attachment for malware. A file is identified by its bytes rather than by its declared type, so an executable arriving as "invoice.pdf" is named as a program before anybody opens it, but a file that is what it claims to be is not checked against any signature database. Your mail provider almost certainly scanned it on arrival.

  • Search is literal

    Search is substring matching over IMAP. There is no stemming and no ranking, so a search for invoices does not find a message that only ever says invoice.

  • Results are capped

    Search results and long threads are capped. The response reports the total, the number returned and whether it capped, but a very broad search will meet the cap.

  • Your own domain only

    The deliverability check reads the connected mailbox's own domain only. It will not look up a customer's domain, or a competitor's.

If one of those is a dealbreaker, it is better that you know now than after connecting a mailbox. The tool reference goes further and lists what each individual tool refuses to do, and the security page sets out what is held for a connected mailbox and what is not.

Questions

Questions people ask before connecting

What can Claude or ChatGPT do with my email once it is connected?

Read it, the way you would: list a folder, search it, open a message, read a whole conversation in one go, and read what is inside a file attached to it. Answer it: send, reply and forward from any address on the mailbox, inside the thread, with attachments that never pass through the AI, or save the reply as a draft you finish in Outlook or Gmail. Tidy it: file, flag, archive and report spam, up to hundreds of messages in one request. Check it: who really sent a message according to your own mail server, whether one you sent bounced, and whether a read receipt came back. With a calendar connected, which is a separate step, it reads the diary, checks who is free and books meetings too. That is 32 email tools in all, and how many of them any one AI client gets is your choice, per connection.

Can I let the AI read my email but not send anything?

Yes. Every connection carries one of 3 permission levels, chosen on the consent screen when you approve it and changed at any time on the mailbox's Connector tab in the control panel: Read only, which lists, searches and reads and cannot change anything; Draft and file, which also files, flags and writes drafts but never sends or deletes; and Send and delete, which is everything. It is per connection, so Claude on your laptop can be Read only while ChatGPT is Draft and file on the same mailbox. A client below the top level is not shown the tools above its level at all, and a call for one is refused with a sentence that says which level the connection is on and where to change it.

Can it read the attachments in my email?

Yes, on any mailbox, however many files are on the message. A PDF, a Word document, a spreadsheet or a slide deck comes back as text, a photo as a picture the AI can look at, and a scanned page as a picture of the page, so a signed letter or a photographed receipt is read the way a person reads it. What a file is comes from its first bytes rather than from its name, so a program calling itself an invoice is named as a program. Reading a file never marks the message read, and nothing is kept afterwards. On the way out, attachments are capped at 10 MB per message in total across every file attached, which is our limit rather than a provider's.

Does my mail client see anything different?

No, and that is the promise the whole product is built around. Reading a message does not mark it read, so your unread count still means what it meant this morning. A reply carries the headers that keep it in its conversation. A send files exactly one copy in Sent Items, matched by its Message-ID. An attachment arrives byte for byte, checked by hash. Special folders are found by the flag your mail server puts on them, never guessed by name, and no folder, label or signature is invented. Each of those was checked by opening the mailbox in a mail client afterwards rather than by trusting what our own code reported, on a live mailbox of 26,930 messages.

What record is kept of what the AI did?

Every call any AI client makes to your mailbox is recorded: when, which tool, which mailbox, which connection or person made it, whether it succeeded, how long it took and where it came from. The Activity tab of the control panel shows it, filtered by day, mailbox, tool and outcome. The record holds the fact of the call and never the contents: no subject, no address, no line of a message. It is kept 400 days by default, and you can shorten that under Settings to any number of days from 90 up to 400; the shortest period is the least that still covers a charge, the statement after it and the time it takes anyone to ask.

What stops a client doing more than I set?

Every mailbox carries a limit, set by its owner in the control panel on the mailbox's Connector tab: one of the same permission levels and the calendar switch. What any connection can actually do is the lower of its own level and the limit, and it has the calendar only when both are on. A connection may be set below the limit, never above it. Lowering the limit caps every connection above it on its next call; raising it again gives each of them back what was chosen, because nothing is rewritten. The limit is enforced by the server, not by the client: a consent screen cannot be approved above it, a pasted access token takes it as its level, and a tool above it is refused before it costs a call. So the most any AI can do with the mailbox is a fact you set once, in a place only you can sign in to.

What does it cost?

Nothing to start. Any mailbox connects free, with no card, at 5 calls a day, which is enough to try every feature on this page against your own mail. Pro is £2.92 a month, paid annually at £34.99 + VAT, per mailbox, and lifts the ceiling to 1,000 calls a day for that mailbox. Both figures are published limits, stated the same way on every page of this site, and there is no per-client price: one mailbox on Pro serves however many AI clients you connect to it.

Does it work with Outlook, Gmail and an ordinary IMAP mailbox?

Yes to all 3. A Microsoft 365 mailbox connects with one Microsoft sign-in, a Gmail mailbox with an app password, and any other mailbox with the IMAP settings your existing mail client is already using: Fastmail, iCloud, a domain host, a company mail server. Outlook, Apple Mail, Thunderbird and webmail go on working exactly as before, because the AI reaches the same mailbox through the same protocols and leaves it looking untouched. The one kind of mailbox that cannot be connected is a Microsoft 365 shared or delegated mailbox, the sort with no sign-in of its own.

Attribution

Sources

The measured claims are ours: the attachment hashes, the threading headers, the sent-copy count and the delivery times were taken while the engine was being built, against a live mailbox of 26,930 messages, and the 3 attachments were read on through the live service. How it works gives each figure with the method beside it, and the changelog dates every release named on this page.

Keep going

Read next

For teams

Everything only a team gets on a shared mailbox: single sign-on, a connection and a level per person, approvals, and a record that says who did what.

Tool reference

Every tool by its registered name, what it touches, which are read-only, and the level that reaches each one.

Pricing for one person

Free on any mailbox, Pro per mailbox, what counts as a call, and how cancelling and refunds work.

Is it safe to give an AI your email?

The questions worth asking any tool that wants your mailbox, written so they work on a competitor as well as on us.

Connect a mailbox and try it.

5 calls a day free, on any mailbox, with no card. Set the level on the consent screen and the limit on the Connector tab before the AI has done anything at all.