How it works

Connect a mailbox, then just ask.

Mailbox MCP is a remote MCP server. There is nothing to install and nothing running on your machine. You connect a mailbox you already own, add one URL to your AI client, and the mail tools appear.

  • Set-up time About 2 minutes
  • To install Nothing
  • Works with Any MCP client

Set-up

The 3 steps

  1. Connect the mailbox you already own

    Sign in to the control panel and add a mailbox. Microsoft 365 takes one Microsoft sign-in; Gmail takes an app password; anything else takes the IMAP settings your existing mail client is already using. Each has its own guide, and each guide is honest about the parts that are awkward.

    Microsoft 365, Gmail, or any IMAP host.

  2. Add the server to your AI client

    The panel gives you a URL. You add it as a connector and the mail tools appear in the list of things your assistant can use. That is the entire integration: no download, no local process, no key file on your laptop that stops working when you get a new laptop.

    Claude is where most people start, and it is what the rest of this site names because naming something concrete is more use than naming a category. The same URL works anywhere else that speaks MCP.

  3. Ask for what you would have done yourself

    Not commands, and not a syntax to learn. You describe the outcome and your assistant uses the tools to reach it.

    Find the thread with Hollis about the March invoice,
    reply attaching the revised quote from my Drafts,
    and file the original under Clients.

    It searches the mailbox, opens the thread, composes a reply carrying the right headers so it lands inside the conversation rather than beside it, attaches the file, sends, and moves the original. The mailbox afterwards looks like you did it.

Tool surface

Every tool your AI client gets, and what each one does

32 email tools, grouped by what they are for, and every mailbox gets all of them. This is the whole surface, so you can judge it before connecting anything rather than discover it afterwards. Every one is a deliberate action, taken because you asked for an outcome that needs it. There is a longer explanation of what an email MCP server actually is if the idea is new.

The complete tool reference takes the same email tools and groups them by what your AI client will stop and ask you about, with what each one refuses as well as what it does.

The 32 Mailbox MCP tools explained: a robot pointing at a board listing them, with a mailbox wired to the board beside him.
32 tools, and nothing that is not on this list

Read 7 tools

Search, threads, attachments, who really sent it

  • list_mailboxes
  • list_emails
  • read_email
  • read_attachment
  • read_thread
  • search_emails
  • find_contact

Send 6 tools

As any of your addresses, or as a real draft

  • draft_email
  • draft_reply
  • draft_forward
  • update_draft
  • list_identities
  • send_email

Reply 1 tool

In thread, carrying the right headers

  • reply_email

Forward 1 tool

With everything the original carried

  • forward_email

File 9 tools

Move, archive or junk 500 at once

  • create_upload_link
  • create_folder
  • move_email
  • delete_email
  • archive_email
  • mark_junk
  • not_junk
  • rename_folder
  • delete_folder

Flag 4 tools

Mark read, unread or flagged, on request

  • mark_read
  • mark_unread
  • flag_email
  • unflag_email

Check 4 tools

Bounces, receipts, trust records, uploads

  • check_bounces
  • check_deliverability
  • check_upload
  • check_receipts

Marking read is an action, not a side effect

Reading a message through Mailbox MCP does not mark it read. That is a separate tool, mark_read, used only when you ask for it. It matters more than it sounds: an unread count that changes on its own stops meaning anything, and once it stops meaning anything you have lost a tool you were relying on without noticing.

Connected separately

Calendar tools, and the mailboxes that get them

Connecting a mailbox does not connect a diary, because they are separate services. Approve calendar access on a Microsoft 365 mailbox and your AI client is handed all 21 calendar tools as well as the email ones. Every other mailbox has 2 routes and can take either, whoever hosts the mail: sign in to Google for a Google calendar, or give the address of a CalDAV calendar server. Until you do one of those 3 things, you get the email tools and nothing else, which is worth knowing before you choose a plan rather than after.

IMAP is a mail protocol and there is no calendar inside it, at any host, so connecting the mail cannot connect the diary. What most hosts run is a separate calendar server speaking CalDAV, and if you give us its address the calendar tools appear. Fastmail, iCloud and Nextcloud all run one; on Fastmail and iCloud the same app password opens both, so it is usually one field.

What a CalDAV calendar can do depends on the server, so we ask it rather than assume. No 2 are quite alike: one will send invitations to other people and answer who is free, another only stores events. The account is opened before anything is saved, the answer decides which tools are registered, and the panel names them, so what your client is offered is what will work on your calendar.

Google Calendar is the third route, and it is a sign-in rather than an address. An app password of the kind a Gmail mailbox connects with is a mail credential: it opens IMAP and SMTP and nothing else. Google runs a CalDAV endpoint too, and it refuses that same app password, so the route above never rescued this one and no amount of pasting was going to. What reaches a Google diary is a Google permission, which is why there is a button rather than a field.

You press it, choose an account, and Google shows you what is being asked for before you approve it. It covers the diary only and never the mail, it is on any mailbox rather than only a Gmail one, and the Google account does not have to match the address the mailbox is on, which matters more often than it sounds: plenty of people keep the work diary and the work mail in different places. You can withdraw it from your Google account at any time, and disconnecting it here hands the permission back rather than leaving it sitting on your account page.

Where a mailbox has no calendar, it is handed no calendar tools at all. Not tools that answer "this mailbox has no calendar" - no tools. One certain to refuse still spends a call against your daily allowance to say so, still invites the model to try again a different way, and still advertises a capability you did not buy. The server reads what your connection actually covers and registers to match, so the list your client shows you is the list that will work.

Read the diary 4 tools

A window of days, a search, one event in full

  • list_calendars
  • list_events
  • read_event
  • search_events

Find a time 2 tools

Free/busy for several people, and the suggestions

  • check_availability
  • find_meeting_times

Book your own time 3 tools

Create, change and delete, with no email sent

  • create_event
  • update_event
  • delete_event

Meet other people 4 tools

Invite, reschedule, cancel, forward

  • schedule_meeting
  • update_meeting
  • cancel_meeting
  • forward_event

Answer invitations 2 tools

Accept, decline, or propose another time

  • respond_to_invitation
  • propose_new_time

Out of office 3 tools

Read it, set it for a period, turn it off

  • read_out_of_office
  • set_out_of_office
  • clear_out_of_office

Reminders and categories 3 tools

Snooze, dismiss, and the colours Outlook shows

  • list_categories
  • snooze_reminder
  • dismiss_reminder

Unknown is not the same answer as free

Asking when several people are free returns their busy and free blocks, never the subjects of their meetings. When somebody's calendar cannot be read at all - a different organisation, or permission never granted - that person comes back as unknown, and unknown is never rendered as free. Microsoft reports those one attendee at a time inside an otherwise successful response, which is exactly how an integration ends up booking a meeting over an afternoon it could not see.

Measured

What it leaves untouched

The promise the whole product is built around: your mailbox goes on looking and behaving exactly as you left it. Each of these was checked against a live mailbox rather than assumed from an API response.

  • Unread flags when reading unchanged
  • Reply threading In-Reply-To + References
  • Sent Items after a send 1 copy, ID matched
  • Attachment bytes SHA-256 identical
  • Folders it invents none

Architecture

Why it is a remote server

Plenty of MCP servers run on your own machine. That is a perfectly good design and it has one property that rules it out here: it only works while your machine is on, unlocked, and running the process.

A remote server means the connection belongs to your account rather than to a computer. You can move between devices, use Claude from a phone, and replace a laptop without reconnecting anything. It also means there is no local install to keep updated, which on a mail integration matters more than usual: the awkward parts of mail are provider changes like the 2 described in the set-up guides, and those get handled server-side without you doing anything.

The trade is that your mailbox credentials are held by us rather than by you, and that is a real trade rather than a detail. The security page sets out what is held, how, and what we will not do with it.

Why Mailbox MCP is a remote server rather than a local one: the robot weighing up a laptop against a server, with a question in a thought bubble.
Belongs to your account, not to a machine

Compatibility

Which AI clients it works with

MCP is an open protocol rather than one company's feature, and Mailbox MCP is an ordinary MCP server: it is reached over HTTPS, it authenticates with a bearer token, and it offers a set of mail tools. Nothing in it knows which assistant is on the other end.

In practice that means it works with Claude on the web, in the desktop app and in Claude Code, and equally with Cursor, VS Code in agent mode, Zed, Cline, Goose, LibreChat, Microsoft Copilot Studio, and any agent you have written yourself against an MCP SDK.

The one requirement

Your client has to support remote MCP servers, not only local ones. Some clients were built to launch an MCP server as a process on your own machine and talk to it over standard input and output, and a hosted server is not reachable that way. If yours is one of those, a small local proxy such as mcp-remote bridges the 2 and the connection behaves normally afterwards.

An assistant with no MCP support at all cannot connect, and that is not something we can work around from this side. If the distinction between a server your client launches and a server your client calls is new, that guide covers it properly. Which products support MCP changes month to month, so check your own client's connector settings rather than trusting any list, including one on a supplier's website.

Why the rest of the site says Claude

Because it is what most people asking for this are using, and because a concrete example is more useful than a category. It is not a restriction, and there is no separate licence, plan or price for using Mailbox MCP with something else.

The AI clients Mailbox MCP works with: the robot feeding one cable out to 4 different screens running different assistants.
One server, any client that speaks the protocol

Limits

What it does not do

  • A calendar has to be connected separately

    Connecting a mailbox does not connect a diary, because they are separate services. A Microsoft 365 mailbox is asked for calendar access on the same sign-in as the mail. Every other mailbox has 2 routes and can use either: sign in to Google for a Google calendar, or give the address of a CalDAV calendar server, which most mail hosts run alongside the mail one. A mailbox with none of them is handed no calendar tools at all rather than tools that would refuse.

  • 10 MB a message

    Attachments are capped at 10 MB for the whole message rather than per file, so 3 4 MB files are refused. That ceiling is ours rather than a provider's, and forwarding a message counts the files it was already carrying.

  • A file the assistant writes itself

    Only this one is small. A file already in the mailbox, a file at a web address and a file you upload through a one-off link are all streamed at send time and never pass through the model, so the 10 MB message ceiling is the only limit on them. A file the assistant composes has to be written out as output, which caps it at a few tens of kilobytes.

  • Nothing is scheduled

    Nothing is scheduled and nothing runs while you are away. There is no tool that sends a message later, and every one of them acts inside a conversation, when you ask.

Connect a mailbox and try it.

5 calls a day, free, on any mailbox. Pro is £2.92 a month per mailbox, paid annually at £34.99 + VAT, when you want more.