PostmarkSAFE
Official Postmark MCP server by ActiveCampaign — 24 tools to send, template, search, and diagnose transactional email from Claude, Cursor & other AI assistants.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Official Postmark MCP Server [](https://www.npmjs.com/package/@activecampaign/postmark-mcp)
Send emails with Postmark using Claude and other MCP-compatible AI assistants.
Features
- Exposes a Model Context Protocol (MCP) server backed by your Postmark account
- 24 tools spanning email sending (single + batch), templates (CRUD + validation), message search, delivery diagnostics, bounces, suppressions, stats, server info, and webhooks
- MCP tool annotations (
readOnlyHint,destructiveHint) let supporting clients auto-approve safe reads and require confirmation before mutating or destructive operations - Simple configuration via environment variables
- Comprehensive error handling and graceful shutdown
- Structured JSON logging to stderr with optional log-file persistence; email addresses are partially masked by default
- HTTPS enforcement and optional domain allowlist for webhook registration
- Automatic open/click tracking on every send
Useful Docs
- 📒 API Documentation
- 🔎 API Explorer
- 📖 Engineering Articles
- 📝 Changelog — what's new in each release
Feedback
We'd love to hear from you! Please share your feedback and suggestions using our feedback form.
Follow us on X - @postmarkapp
Requirements
- Node.js v20 or higher
- A [Postmark acco
abe74c405316OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add postmark-mcp --env POSTMARK_SERVER_TOKEN=${POSTMARK_SERVER_TOKEN} -- npx -y @activecampaign/[email protected]{
"mcpServers": {
"postmark-mcp": {
"command": "npx",
"args": [
"-y",
"@activecampaign/[email protected]"
],
"env": {
"POSTMARK_SERVER_TOKEN": "${POSTMARK_SERVER_TOKEN}"
}
}
}
}Exposed tools (24)
14 read · 7 write · 3 destructive. Blast radius: 3 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
activateBounce | read | Reactivate a deactivated email address so it can receive mail again on Postmark. Only works on bounces where CanActivate is true (typically HardBounce). SpamComplaint bounces cannot be reactivated. Use searchBounces or diagnoseDelivery to find the bounceId. |
createSuppressions | write | Add up to 50 email addresses to the suppression list for a Postmark message stream. Suppressed addresses will not receive mail on that stream. Each address in the response indicates whether suppression was created or failed. |
createTemplate | write | Create a new email template on this Postmark server. Requires a name and at least one of htmlBody or textBody. Subject is required for Standard templates and must be omitted for Layout templates. Optionally bind a Standard template to an existing Layout via layoutTemplate. |
createWebhook | read | |
deleteSuppressions | destructive | Remove up to 50 addresses from the suppression list on a Postmark message stream, allowing them to receive mail again. SpamComplaint suppressions cannot be deleted via API. Deleting a HardBounce suppression is equivalent to reactivating that bounce. |
deleteTemplate | destructive | Permanently delete a Postmark template by numeric ID or string alias. This cannot be undone. Layout templates cannot be deleted while Standard templates are still bound to them. |
deleteWebhook | destructive | Permanently delete a Postmark webhook by its numeric ID. Postmark will stop sending event notifications to that URL immediately. Use listWebhooks to find the ID. |
diagnoseDelivery | read | Diagnose why an email may not have reached a recipient. Runs message search, suppression lookup, and bounce history checks in parallel and returns a plain-English recommendation. Use this as a first step when a recipient reports a missing, undelivered, or bounced email. |
editTemplate | write | Update an existing Postmark template |
getBounceDump | read | Retrieve the raw SMTP conversation transcript for a specific bounce record. Useful for diagnosing exactly how a remote mail server rejected a message. Dumps are only retained for 30 days after the bounce. |
getDeliveryStats | read | Retrieve outbound email statistics for this Postmark server. The default |
getMessageDetails | read | Retrieve the full delivery details and event timeline (Delivered, Opened, Clicked, Bounced, etc.) for a single outbound message by its Postmark MessageID. Use searchOutboundMessages to find a MessageID first. |
getServerInfo | read | Retrieve this Postmark server |
getTemplate | read | Retrieve the full content of a single Postmark template — HTML body, text body, subject, type (Standard/Layout), and layout association — by numeric ID or string alias. |
listSuppressions | read | List suppressed email addresses on a Postmark message stream. Optionally filter by suppression reason (HardBounce, SpamComplaint, ManualSuppression), origin (Recipient, Customer, Admin), email address, or date range. Suppressed addresses will not receive mail on that stream. |
listTemplates | read | List saved email templates on this Postmark server. Returns up to 100 templates with name, ID, alias, subject, type (Standard or Layout), and layout binding. Use getTemplate to retrieve a template |
listWebhooks | read | List all webhooks configured on this Postmark server via the Webhooks API. Optionally filter by message stream. Shows each webhook |
searchBounces | read | Search the Postmark bounce log. Filter by bounce type, email address, tag, message ID, message stream, and date range. Returns bounce records with type, description, timestamp, and whether each address can be reactivated. Bounce records are retained for 45 days. |
searchOutboundMessages | read | Search outbound message history on this Postmark server. Filter by recipient, sender, subject, tag, delivery status, message stream, or date range. Returns up to 500 messages per call with basic metadata. Use getMessageDetails to retrieve the full event timeline for a specific message. |
sendBatch | write | Send up to 500 independent emails in a single synchronous Postmark API call (POST /email/batch). Each message has its own recipient, subject, and body. Returns per-message results — the overall HTTP call succeeds even when individual messages fail. Use sendEmail for a single message. |
sendBatchWithTemplate | write | Send the same Postmark template to up to 500 recipients in a single call, with per-recipient template models (POST /email/batchWithTemplates). Supply either templateId or templateAlias. Returns per-message results. Use sendEmailWithTemplate for a single recipient. |
sendEmail | write | Send a single transactional email via Postmark. Accepts one recipient or an array of up to 50. The From address must be a verified sender signature. Open and link tracking are enabled automatically. Use sendBatch to send multiple distinct messages in one call. |
sendEmailWithTemplate | write | Send a single email rendered from a saved Postmark template. Supply either templateId (numeric) or templateAlias (string) plus a templateModel object that provides the template variables. The From address must be a verified sender signature. |
validateTemplate | read | Validate Postmark Mustachio template syntax and variable references without saving anything. Checks subject, HTML body, and/or text body for errors and optionally renders them against a test data model. Use this before createTemplate or editTemplate to catch mistakes early. |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (1 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (5)
deleteSuppressions, deleteTemplate, deleteWebhook
- **Email address masking in logs.** PII-reduced by default — the mailbox is partially masked (first and last characters retained, middle replaced with length-proportional asterisks — e.g. `alice@exam
Because this MCP server can send email and register webhooks, it is a potential target for [prompt injection](https://owasp.org/www-project-top-10-for-large-language-model-applications/) — where malic
This MCP server acts with the full permissions of the configured `POSTMARK_SERVER_TOKEN`. It exposes 24 tools — including bulk email sends, template management, webhook registration, and suppression l
Postmark has [two token types](https://postmarkapp.com/developer/api/overview#authentication): a **Server Token** (used here) and an **Account Token**. Neither supports sub-scoped permissions — a Serv
Gates applied: no_behavioural_pass.
abe74c405316full audit observations/trust-audit/mcp-server/activecampaign__postmark.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | abe74c405316 | SAFE | B | 89 | first audit |
Questions
What is the Postmark MCP server?
Official Postmark MCP server by ActiveCampaign — 24 tools to send, template, search, and diagnose transactional email from Claude, Cursor & other AI assistants.
What tools does Postmark expose?
24 in total: 14 read-only, 7 that write, and 3 that can delete or overwrite (deleteSuppressions, deleteTemplate, deleteWebhook). Every one is listed on this page with its risk.
Is Postmark safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 3 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Postmark need?
It reads POSTMARK_SERVER_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Postmark run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @activecampaign/postmark-mcp at 2.1.1.
How current is this page?
The grade is for one exact copy of the source (abe74c405316), read on 2026-10-08. The repository is watched and re-audited when it changes.