Workplace#Email

Email MCP: manage any mailbox over IMAP and SMTP

An email server not tied to Gmail or Outlook. Standard IMAP and SMTP give agents multi-account reading, search, scheduled sending, drafts and templates.

Project and installation docs

View project

https://github.com/codefuturist/email-mcp

Most email MCP servers sit on the Gmail API or Microsoft Graph, which leaves out anyone on Fastmail, iCloud, ProtonMail Bridge or a company mail server. Email MCP uses plain IMAP and SMTP, so any mailbox that speaks those protocols works, and it can hold several accounts at once so the agent handles personal and work mail together.

What it does

  • Read and search: list_emails filters by date, sender and flags, search_emails covers subject and body, get_thread rebuilds a conversation from References headers, and download_attachment fetches files up to 5 MB.
  • Write and send: send_email, reply_email and forward_email, plus save_draft, apply_template and schedule_email for later delivery.
  • Organize: move, flag and bulk-act on up to 100 messages; labels adapt to the provider (Gmail labels, ProtonMail folders or IMAP keywords).
  • Live watcher: an IMAP IDLE watcher can trigger AI triage, desktop alerts or webhooks when mail arrives.

Who it’s for

  • People on a custom domain or a non-Google, non-Microsoft provider who want help clearing the inbox and drafting replies.
  • Freelancers and small teams juggling several mailboxes.

Setup

Needs Node.js 22 or newer. Run the wizard to add an account; it detects server settings and tests the connection:

npx @codefuturist/email-mcp setup

Then start the stdio server from your client config:

{
  "mcpServers": {
    "email": {
      "command": "npx",
      "args": ["-y", "@codefuturist/email-mcp", "stdio"]
    }
  }
}

Our take

A small project worth watching: about 120 stars as of 2026-10-06, yet a thorough README, 47 tools, 7 prompts and 6 resources, per-account token-bucket rate limits and an audit log that never records passwords. Compared with Google Workspace MCP or Microsoft 365 MCP, it gives up calendars and documents in exchange for working with any mailbox. The risks come first, though. It can send and delete mail and even remove whole folders with delete_mailbox, and a prompt injection hidden in an email could push the agent to send messages. There’s a global read-only setting; turn it on while you get comfortable. Account passwords sit in plain text in ~/.config/email-mcp/config.toml by default, so use an app password for Gmail; OAuth2 support is still experimental. Licensed LGPL-3.0.