Atlas / MCP servers / madllama25 / Fastmail

FastmailSAFE

mcp/madllama25/fastmail

Unofficial MCP server for the Fastmail JMAP API — email, contacts, and calendar tools for AI assistants. Not affiliated with Fastmail. Includes a DXT for Claude Desktop.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
42 24r · 12w · 6d
Transport
stdio
License
MIT
Stars
132
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

An unofficial Model Context Protocol (MCP) server that provides access to the Fastmail API, enabling AI assistants to interact with email, contacts, and calendar data.

Disclaimer: This is a community project. It is not affiliated with, endorsed by, or supported by Fastmail. "Fastmail" is a trademark of Fastmail Pty Ltd; it is used here only to describe compatibility with their public JMAP/CalDAV/WebDAV APIs. Use at your own risk under the terms of the project license.

Features

Core Email Operations

  • List mailboxes and get mailbox statistics
  • List, search, and filter emails with advanced criteria
  • Get specific emails by ID with full content
  • Send emails (text and HTML) with proper draft/sent handling
  • Reply to emails with proper threading (In-Reply-To, References headers)
  • Create, edit, and send email drafts (with or without threading)
  • Email management: mark read/unread, delete, move between folders

Advanced Email Features

  • Attachment Handling: List, download, and send attachments; save attachments straight to WebDAV cloud storage
  • Privacy-lean metadata tools: Metadata-only variants of list/search/thread tools (no body content)
  • Threading Support: Get complete conversation threads
  • Advanced Search: Multi-criteria filtering (sender, date range, attachments, read status)
  • Bulk Operations: Process multiple emails simultaneously
  • Statistics & Analytics: Account summaries and mailbox statistics

Contacts Operations

  • List all contacts with full contact information
  • Get specific contacts by ID
  • Search contacts by name or email
  • Create, update, and delete contacts (JMAP ContactCard/set; requires an API token with read-write contacts scope)

Calendar Operations

  • List, get, create, update, and delete calendar events (via CalDAV)
  • All-day and timed events, participants, recurrence-aware updates

Label vs Move Operations

  • move_email/bulk_move: Replaces AL
Read from source at commit 16872ad4c120OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add fastmail-mcp -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "fastmail-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (42)

24 read · 12 write · 6 destructive. Blast radius: 6 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
add_labelswriteAdd labels (mailboxes) to an email without removing existing ones
bulk_add_labelswriteAdd labels to multiple emails simultaneously
bulk_deletedestructiveDelete multiple emails (move to trash)
bulk_mark_readreadMark multiple emails as read/unread
bulk_movewriteMove multiple emails to a mailbox
bulk_pinreadPin or unpin multiple emails
bulk_remove_labelsdestructiveRemove labels from multiple emails simultaneously
check_function_availabilityreadCheck which MCP functions are available based on account permissions. Calendar tools run over CalDAV, so calendar is reported available when CalDAV credentials are configured, regardless of the JMAP calendar capability.
create_calendar_eventwriteCreate a new calendar event. Supports date-only (e.g. 2026-04-01) for all-day events. DTEND is exclusive per RFC 5545 — a one-day event on April 1 needs end: 2026-04-02.
create_contactwriteCreate a new contact in the address book. Requires a name or at least one email address. Requires an API token with read-write contacts scope.
create_draftwriteCreate an email draft without sending it. Supports threading headers for replies. IMPORTANT: each call creates a new draft — do not call twice for the same message.
create_mailboxwriteCreate a new mailbox (folder). Returns the new mailbox ID. The caller is responsible for validating the name is appropriate (length, character set, parent-folder allow-list) before calling — JMAP itself only enforces uniqueness within a parent.
delete_calendar_eventdestructiveDelete a calendar event by ID
delete_contactdestructivePermanently delete a contact from the address book. This cannot be undone. Requires read-write contacts scope.
delete_emaildestructiveDelete an email (move to trash)
download_attachmentreadDownload an email attachment. If savePath is provided, saves the file to disk and returns the file path and size. Otherwise returns a download URL.
edit_draftwriteEdit an existing draft email. Since JMAP emails are immutable, this atomically destroys the old draft and creates a new one with the updated fields. Only fields you provide will be changed; others are preserved from the original draft.
get_account_summaryreadGet overall account summary with statistics
get_calendar_eventreadGet a specific calendar event by ID. Returns organizer and participants when available.
get_contactreadGet a specific contact by ID
get_emailreadGet a specific email by ID
get_email_attachmentsreadGet list of attachments for an email
get_mailbox_by_namereadLook up a single mailbox by its full path from root (e.g.
get_mailbox_statsreadGet statistics for a mailbox (unread count, total emails, etc.)
get_recent_emailsreadGet the most recent emails across all mailboxes except Trash and Spam (pass mailboxName to scope to one folder, e.g.
get_threadreadGet all emails in a conversation thread. Draft messages are excluded by default; set includeDrafts=true to include in-progress drafts in the thread.
list_calendar_eventsreadList events from a calendar
list_calendarsreadList all calendars
list_contactsreadList contacts from the address book. When the server reports a total match count, results are wrapped in a {
list_emailsreadList emails from a mailbox. When the server reports a total match count, results are wrapped in a {
list_identitiesreadList sending identities (email addresses that can be used for sending)
list_mailboxesreadList mailboxes in the Fastmail account. By default returns all mailboxes with full metadata; on accounts with hundreds of mailboxes the full result can exceed the MCP tool result window. Use
mark_email_readreadMark an email as read or unread
move_emailwriteMove an email to a different mailbox
pin_emailreadPin or unpin an email
remove_labelsdestructiveRemove specific labels (mailboxes) from an email
reply_emailreadReply to an existing email with proper threading headers (In-Reply-To, References). Automatically fetches the original email to build the reply chain. By default sends immediately; set send=false to save as a draft instead.
search_contactsreadSearch contacts by name or email. When the server reports a total match count, results are wrapped in a {
send_draftwriteSend an existing draft email. The draft must have recipients (to/cc/bcc) and a from address. After sending, the email is moved to the Sent folder and the draft keyword is removed.
send_emailwriteSend an email
test_bulk_operationsreadTest bulk operations by finding recent emails and performing safe operations (mark read/unread)
update_contactwriteUpdate an existing contact. Each provided field WHOLLY REPLACES the stored value (e.g. emails: [] removes all emails) — unspecified fields are left untouched. Requires read-write contacts scope.
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (4 observation(s))
Shell
declared (2 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (11)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
bulk_delete, bulk_remove_labels, delete_calendar_event, delete_contact, delete_email, remove_labels
Why it matters. 6 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.dxtignore
.dxtignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.secret-scan-local.txt.example
.secret-scan-local.txt.example
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
src/jmap-client.test.ts:746
() => JmapClient.validateSavePath(`${homedir()}/.ssh/authorized_keys`),
Why it matters. touches a credential store
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/jmap-client.test.ts:736
() => JmapClient.validateSavePath(`${allowedDir}/../../../.bashrc`),
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/jmap-client.test.ts:785
() => JmapClient.validateSavePath(`${customDir}/../../etc/shadow`, customDir),
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/webdav-files-client.test.ts:19
['embedded traversal', 'a/../../b', /must not contain/],
LOWObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
src/url-validation.test.ts:80
() => validateFastmailUrl('https://аpi.fastmail.com/jmap/api/', 'baseUrl'),
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, rrule, tsdav, @types/node, tsx, typescript
Why it matters. 6 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
README.md:424
- The server avoids logging raw errors and sensitive data (tokens, email addresses, identities, attachment names/blobIds) in error messages.
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
README.md:290
The server uses bearer token authentication with Fastmail's API. API tokens provide secure access without exposing your main account password.
Why it matters. asks the agent to read credentials

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 16872ad4c120full audit observations/trust-audit/mcp-server/madllama25__fastmail.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0716872ad4c120SAFEB89first audit
06

Questions

What is the Fastmail MCP server?

Unofficial MCP server for the Fastmail JMAP API — email, contacts, and calendar tools for AI assistants. Not affiliated with Fastmail. Includes a DXT for Claude Desktop.

What tools does Fastmail expose?

42 in total: 24 read-only, 12 that write, and 6 that can delete or overwrite (bulk_delete, bulk_remove_labels, delete_calendar_event, delete_contact, delete_email). Every one is listed on this page with its risk.

Is Fastmail safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 6 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Fastmail need?

No credential environment variables were found in its source, so it appears to need none.

How does Fastmail run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as fastmail-mcp at 1.13.4.

How current is this page?

The grade is for one exact copy of the source (16872ad4c120), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement