Atlas / MCP servers / activecampaign / Postmark

PostmarkSAFE

mcp/activecampaign/postmark

Official Postmark MCP server by ActiveCampaign — 24 tools to send, template, search, and diagnose transactional email from Claude, Cursor & other AI assistants.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
24 14r · 7w · 3d
Transport
stdio
License
MIT
Stars
57
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Official Postmark MCP Server [](https://www.npmjs.com/package/@activecampaign/postmark-mcp)

Send emails with Postmark using Claude and other MCP-compatible AI assistants.

Features

  • Exposes a Model Context Protocol (MCP) server backed by your Postmark account
  • 24 tools spanning email sending (single + batch), templates (CRUD + validation), message search, delivery diagnostics, bounces, suppressions, stats, server info, and webhooks
  • MCP tool annotations (readOnlyHint, destructiveHint) let supporting clients auto-approve safe reads and require confirmation before mutating or destructive operations
  • Simple configuration via environment variables
  • Comprehensive error handling and graceful shutdown
  • Structured JSON logging to stderr with optional log-file persistence; email addresses are partially masked by default
  • HTTPS enforcement and optional domain allowlist for webhook registration
  • Automatic open/click tracking on every send

Useful Docs

Feedback

We'd love to hear from you! Please share your feedback and suggestions using our feedback form.

Follow us on X - @postmarkapp

Requirements

  • Node.js v20 or higher
  • A [Postmark acco
Read from source at commit abe74c405316OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add postmark-mcp --env POSTMARK_SERVER_TOKEN=${POSTMARK_SERVER_TOKEN} -- npx -y @activecampaign/[email protected]
claude-desktop
{
  "mcpServers": {
    "postmark-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "@activecampaign/[email protected]"
      ],
      "env": {
        "POSTMARK_SERVER_TOKEN": "${POSTMARK_SERVER_TOKEN}"
      }
    }
  }
}
03

Exposed tools (24)

14 read · 7 write · 3 destructive. Blast radius: 3 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
activateBouncereadReactivate a deactivated email address so it can receive mail again on Postmark. Only works on bounces where CanActivate is true (typically HardBounce). SpamComplaint bounces cannot be reactivated. Use searchBounces or diagnoseDelivery to find the bounceId.
createSuppressionswriteAdd up to 50 email addresses to the suppression list for a Postmark message stream. Suppressed addresses will not receive mail on that stream. Each address in the response indicates whether suppression was created or failed.
createTemplatewriteCreate a new email template on this Postmark server. Requires a name and at least one of htmlBody or textBody. Subject is required for Standard templates and must be omitted for Layout templates. Optionally bind a Standard template to an existing Layout via layoutTemplate.
createWebhookread
deleteSuppressionsdestructiveRemove up to 50 addresses from the suppression list on a Postmark message stream, allowing them to receive mail again. SpamComplaint suppressions cannot be deleted via API. Deleting a HardBounce suppression is equivalent to reactivating that bounce.
deleteTemplatedestructivePermanently delete a Postmark template by numeric ID or string alias. This cannot be undone. Layout templates cannot be deleted while Standard templates are still bound to them.
deleteWebhookdestructivePermanently delete a Postmark webhook by its numeric ID. Postmark will stop sending event notifications to that URL immediately. Use listWebhooks to find the ID.
diagnoseDeliveryreadDiagnose why an email may not have reached a recipient. Runs message search, suppression lookup, and bounce history checks in parallel and returns a plain-English recommendation. Use this as a first step when a recipient reports a missing, undelivered, or bounced email.
editTemplatewriteUpdate an existing Postmark template
getBounceDumpreadRetrieve the raw SMTP conversation transcript for a specific bounce record. Useful for diagnosing exactly how a remote mail server rejected a message. Dumps are only retained for 30 days after the bounce.
getDeliveryStatsreadRetrieve outbound email statistics for this Postmark server. The default
getMessageDetailsreadRetrieve the full delivery details and event timeline (Delivered, Opened, Clicked, Bounced, etc.) for a single outbound message by its Postmark MessageID. Use searchOutboundMessages to find a MessageID first.
getServerInforeadRetrieve this Postmark server
getTemplatereadRetrieve the full content of a single Postmark template — HTML body, text body, subject, type (Standard/Layout), and layout association — by numeric ID or string alias.
listSuppressionsreadList suppressed email addresses on a Postmark message stream. Optionally filter by suppression reason (HardBounce, SpamComplaint, ManualSuppression), origin (Recipient, Customer, Admin), email address, or date range. Suppressed addresses will not receive mail on that stream.
listTemplatesreadList saved email templates on this Postmark server. Returns up to 100 templates with name, ID, alias, subject, type (Standard or Layout), and layout binding. Use getTemplate to retrieve a template
listWebhooksreadList all webhooks configured on this Postmark server via the Webhooks API. Optionally filter by message stream. Shows each webhook
searchBouncesreadSearch the Postmark bounce log. Filter by bounce type, email address, tag, message ID, message stream, and date range. Returns bounce records with type, description, timestamp, and whether each address can be reactivated. Bounce records are retained for 45 days.
searchOutboundMessagesreadSearch outbound message history on this Postmark server. Filter by recipient, sender, subject, tag, delivery status, message stream, or date range. Returns up to 500 messages per call with basic metadata. Use getMessageDetails to retrieve the full event timeline for a specific message.
sendBatchwriteSend up to 500 independent emails in a single synchronous Postmark API call (POST /email/batch). Each message has its own recipient, subject, and body. Returns per-message results — the overall HTTP call succeeds even when individual messages fail. Use sendEmail for a single message.
sendBatchWithTemplatewriteSend the same Postmark template to up to 500 recipients in a single call, with per-recipient template models (POST /email/batchWithTemplates). Supply either templateId or templateAlias. Returns per-message results. Use sendEmailWithTemplate for a single recipient.
sendEmailwriteSend a single transactional email via Postmark. Accepts one recipient or an array of up to 50. The From address must be a verified sender signature. Open and link tracking are enabled automatically. Use sendBatch to send multiple distinct messages in one call.
sendEmailWithTemplatewriteSend a single email rendered from a saved Postmark template. Supply either templateId (numeric) or templateAlias (string) plus a templateModel object that provides the template variables. The From address must be a verified sender signature.
validateTemplatereadValidate Postmark Mustachio template syntax and variable references without saving anything. Checks subject, HTML body, and/or text body for errors and optionally renders them against a test data model. Use this before createTemplate or editTemplate to catch mistakes early.
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (1 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (5)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
deleteSuppressions, deleteTemplate, deleteWebhook
Why it matters. 3 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
CHANGELOG.md:39
- **Email address masking in logs.** PII-reduced by default — the mailbox is partially masked (first and last characters retained, middle replaced with length-proportional asterisks — e.g. `alice@exam
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
README.md:751
Because this MCP server can send email and register webhooks, it is a potential target for [prompt injection](https://owasp.org/www-project-top-10-for-large-language-model-applications/) — where malic
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
README.md:725
This MCP server acts with the full permissions of the configured `POSTMARK_SERVER_TOKEN`. It exposes 24 tools — including bulk email sends, template management, webhook registration, and suppression l
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
README.md:727
Postmark has [two token types](https://postmarkapp.com/developer/api/overview#authentication): a **Server Token** (used here) and an **Account Token**. Neither supports sub-scoped permissions — a Serv

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha abe74c405316full audit observations/trust-audit/mcp-server/activecampaign__postmark.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08abe74c405316SAFEB89first audit
06

Questions

What is the Postmark MCP server?

Official Postmark MCP server by ActiveCampaign — 24 tools to send, template, search, and diagnose transactional email from Claude, Cursor & other AI assistants.

What tools does Postmark expose?

24 in total: 14 read-only, 7 that write, and 3 that can delete or overwrite (deleteSuppressions, deleteTemplate, deleteWebhook). Every one is listed on this page with its risk.

Is Postmark safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 3 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Postmark need?

It reads POSTMARK_SERVER_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Postmark run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @activecampaign/postmark-mcp at 2.1.1.

How current is this page?

The grade is for one exact copy of the source (abe74c405316), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement