EmailBLOCK
Email MCP server with full IMAP + SMTP support — read, search, send, manage, and organize email from any AI assistant via the Model Context Protocol
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://github.com/RichardLitt/standard-readme) [](LICENSE) [](https://www.npmjs.com/package/@codefuturist/email-mcp) [](https://www.npmjs.com/package/@codefuturist/email-mcp) [](https://github.com/codefuturist/email-mcp/actions/workflows/ci.yml)
An MCP (Model Context Protocol) server providing comprehensive email capabilities via IMAP and SMTP.
Enables AI assistants to read, search, send, manage, schedule, and analyze emails across multiple accounts. Exposes 47 tools, 7 prompts, and 6 resources over the MCP protocol with OAuth2 support (experimental), email scheduling, calendar extraction, analytics, provider-aware label management, real-time IMAP IDLE watcher with AI-powered triage, customizable presets and static rules, and a guided setup wizard.
Highlights
Table of Contents
- Highlights
- Security
- Background
- Install
- Usage
-
d188fe5ee334OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add email-mcp -- npx -y @codefuturist/[email protected]
Exposed tools (50)
32 read · 13 write · 5 destructive. Blast radius: 5 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
Custom | read | Full control. Provide your own system_prompt in config. The preset contributes nothing — you define everything. |
add_label | write | Add a label to an email. |
add_to_calendar | write | |
analyze_email_for_scheduling | read | |
apply_template | write | Apply an email template with variable substitution. Use action |
bulk_action | read | Batch operation on multiple emails by UID list. Supports mark_read, mark_unread, flag, unflag, move, and delete. Max 100 IDs per call. Returns success/failure counts. |
cancel_scheduled | read | Cancel a scheduled email. Removes it from the queue and deletes the associated draft. |
check_calendar_permissions | read | |
check_health | read | Check connection health, quota, and capabilities for email accounts. Useful for diagnosing issues. |
check_notification_setup | read | Diagnose desktop notification support on this platform. |
configure_alerts | write | Update alert/notification settings at runtime. Changes take effect immediately. |
create_label | write | Create a new label. For ProtonMail, creates a folder under Labels/. |
create_mailbox | write | Create a new mailbox (folder). Use |
create_reminder | write | |
delete_email | destructive | Delete an email. By default moves to Trash. Set permanent=true for permanent deletion (⚠️ irreversible). |
delete_label | destructive | Delete a label. For ProtonMail, deletes the label folder. |
delete_mailbox | destructive | ⚠️ DESTRUCTIVE: Permanently delete a mailbox and ALL its contents. This cannot be undone. Use list_mailboxes to verify the folder path. |
download_attachment | read | Download an email attachment by filename. First use get_email to see available attachments and their filenames. Returns base64-encoded content for files ≤5MB. |
extract_calendar | read | Extract calendar events (ICS/iCalendar) from an email. Returns structured event data including time, location, attendees, and status. |
extract_contacts | read | Extract unique contacts from recent email headers. Returns contacts sorted by frequency (most frequent first). Useful for finding frequent correspondents or building an address book. |
find_email_folder | read | Find which real mailbox folder(s) an email belongs to. |
forward_email | read | Forward an email to new recipients with optional additional message. Original email is quoted below. |
get_email | read | Get the full content of a specific email by ID. |
get_email_stats | read | Get email statistics and analytics for a mailbox. Shows volume, top senders, daily trends, and read/flagged counts. |
get_email_status | read | Get the current read/flag/label state of an email without fetching its body. |
get_emails | read | Fetch the full content of multiple emails in a single call (max 20). |
get_hooks_config | read | Get the current AI hooks configuration including preset, rules, and custom instructions. |
get_thread | read | Reconstruct a full email conversation thread by following References and In-Reply-To headers. |
get_watcher_status | read | Get the status of IMAP IDLE watcher connections and recent activity. |
list_accounts | read | List all configured email accounts. Call this first to discover available account names for use with other tools. |
list_calendars | read | |
list_emails | read | List emails in a mailbox with optional filters. Returns paginated results with metadata |
list_events | read | |
list_labels | read | List available labels for an email account. |
list_mailboxes | read | List all mailbox folders for an account with unread counts and special-use flags. Use list_accounts first to get the account name. |
list_presets | read | List all available AI triage presets with their descriptions and suggested labels. |
list_reminders | read | |
list_scheduled | read | List scheduled emails. Shows pending, sent, or all scheduled emails. |
list_templates | read | List all available email templates. Templates are TOML files in ~/.config/email-mcp/templates/ with {{variable}} placeholders for subject and body. |
mark_email | read | Change email flags — mark as read/unread, flag/unflag. Idempotent: marking an already-read email as read is a no-op. |
move_email | write | Move an email to a different mailbox folder. |
remove_label | destructive | Remove a label from an email. For ProtonMail, this removes the email from the label folder. |
rename_mailbox | write | Rename an existing mailbox (folder). Use list_mailboxes to see current folder paths. |
reply_email | read | Reply to an email with proper threading (In-Reply-To & References headers). Use get_email first to read the original. |
save_draft | write | Save an email draft to the Drafts folder. Compose over time, then use send_draft to send it. Use list_emails with the Drafts mailbox to see saved drafts. |
schedule_email | write | Schedule an email to be sent at a specific time in the future. The email is queued locally and sent automatically when the time arrives. |
search_emails | read | Search emails by keyword across subject, sender, and body. |
send_draft | destructive | Send an existing draft email and remove it from Drafts. The draft is fetched, sent via SMTP, then deleted. Use list_emails with the Drafts mailbox to find draft IDs. |
send_email | write | Send a new email. Supports plain text or HTML body, CC, and BCC. |
test_notification | write | Send a test desktop notification to verify that OS permissions are correctly configured. |
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (6 observation(s))
- Network
- declared (7 observation(s))
- Shell
- declared (5 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (17)
tls: { rejectUnauthorized: false },console.log(` password = ${'•'.repeat(8)}\n`);process.stderr.write(` Endpoint : http://0.0.0.0:${port}/mcp\n`);process.stderr.write(` Health : http://0.0.0.0:${port}/health\n`);delete_email, delete_label, delete_mailbox, remove_label, send_draft
.goreleaser.yaml
.goreleaser.yaml.legacy
import type { AccountConfig } from '../../types/index.js';import ConnectionManager from '../../connections/manager.js';
import RateLimiter from '../../safety/rate-limiter.js';
import ImapService from '../../services/imap.service.js';
import SmtpService from '../../services/smtp.service.js';
expect(() => validateWebhookUrl('https://127.0.0.1/hook')).toThrow('loopback or private');expect(() => validateWebhookUrl('https://10.0.0.1/hook')).toThrow('loopback or private');expect(() => validateWebhookUrl('https://172.16.0.1/hook')).toThrow('loopback or private');@clack/prompts, @modelcontextprotocol/sdk, imapflow, node-ical, nodemailer, smol-toml, zod, @biomejs/biome
- **No credential storage** — passwords and tokens are read from your local config file or environment variables at runtime
Gates applied: no_behavioural_pass.
d188fe5ee334full audit observations/trust-audit/mcp-server/codefuturist__email-16.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | d188fe5ee334 | BLOCK | D | 69 | first audit |
Questions
What is the Email MCP server?
Email MCP server with full IMAP + SMTP support — read, search, send, manage, and organize email from any AI assistant via the Model Context Protocol
What tools does Email expose?
50 in total: 32 read-only, 13 that write, and 5 that can delete or overwrite (delete_email, delete_label, delete_mailbox, remove_label, send_draft). Every one is listed on this page with its risk.
Is Email safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 5 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Email need?
It reads MCP_EMAIL_OAUTH2_CLIENT_ID, MCP_EMAIL_OAUTH2_CLIENT_SECRET, MCP_EMAIL_OAUTH2_PROVIDER, MCP_EMAIL_OAUTH2_REFRESH_TOKEN and MCP_EMAIL_PASSWORD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Email run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @codefuturist/email-mcp at 0.2.3.
How current is this page?
The grade is for one exact copy of the source (d188fe5ee334), read on 2026-10-07. The repository is watched and re-audited when it changes.