FastmailSAFE
Unofficial MCP server for the Fastmail JMAP API — email, contacts, and calendar tools for AI assistants. Not affiliated with Fastmail. Includes a DXT for Claude Desktop.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
An unofficial Model Context Protocol (MCP) server that provides access to the Fastmail API, enabling AI assistants to interact with email, contacts, and calendar data.
Disclaimer: This is a community project. It is not affiliated with, endorsed by, or supported by Fastmail. "Fastmail" is a trademark of Fastmail Pty Ltd; it is used here only to describe compatibility with their public JMAP/CalDAV/WebDAV APIs. Use at your own risk under the terms of the project license.
Features
Core Email Operations
- List mailboxes and get mailbox statistics
- List, search, and filter emails with advanced criteria
- Get specific emails by ID with full content
- Send emails (text and HTML) with proper draft/sent handling
- Reply to emails with proper threading (In-Reply-To, References headers)
- Create, edit, and send email drafts (with or without threading)
- Email management: mark read/unread, delete, move between folders
Advanced Email Features
- Attachment Handling: List, download, and send attachments; save attachments straight to WebDAV cloud storage
- Privacy-lean metadata tools: Metadata-only variants of list/search/thread tools (no body content)
- Threading Support: Get complete conversation threads
- Advanced Search: Multi-criteria filtering (sender, date range, attachments, read status)
- Bulk Operations: Process multiple emails simultaneously
- Statistics & Analytics: Account summaries and mailbox statistics
Contacts Operations
- List all contacts with full contact information
- Get specific contacts by ID
- Search contacts by name or email
- Create, update, and delete contacts (JMAP ContactCard/set; requires an API token with read-write contacts scope)
Calendar Operations
- List, get, create, update, and delete calendar events (via CalDAV)
- All-day and timed events, participants, recurrence-aware updates
Label vs Move Operations
- move_email/bulk_move: Replaces AL
16872ad4c120OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add fastmail-mcp -- npx -y [email protected]
{
"mcpServers": {
"fastmail-mcp": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (42)
24 read · 12 write · 6 destructive. Blast radius: 6 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
add_labels | write | Add labels (mailboxes) to an email without removing existing ones |
bulk_add_labels | write | Add labels to multiple emails simultaneously |
bulk_delete | destructive | Delete multiple emails (move to trash) |
bulk_mark_read | read | Mark multiple emails as read/unread |
bulk_move | write | Move multiple emails to a mailbox |
bulk_pin | read | Pin or unpin multiple emails |
bulk_remove_labels | destructive | Remove labels from multiple emails simultaneously |
check_function_availability | read | Check which MCP functions are available based on account permissions. Calendar tools run over CalDAV, so calendar is reported available when CalDAV credentials are configured, regardless of the JMAP calendar capability. |
create_calendar_event | write | Create a new calendar event. Supports date-only (e.g. 2026-04-01) for all-day events. DTEND is exclusive per RFC 5545 — a one-day event on April 1 needs end: 2026-04-02. |
create_contact | write | Create a new contact in the address book. Requires a name or at least one email address. Requires an API token with read-write contacts scope. |
create_draft | write | Create an email draft without sending it. Supports threading headers for replies. IMPORTANT: each call creates a new draft — do not call twice for the same message. |
create_mailbox | write | Create a new mailbox (folder). Returns the new mailbox ID. The caller is responsible for validating the name is appropriate (length, character set, parent-folder allow-list) before calling — JMAP itself only enforces uniqueness within a parent. |
delete_calendar_event | destructive | Delete a calendar event by ID |
delete_contact | destructive | Permanently delete a contact from the address book. This cannot be undone. Requires read-write contacts scope. |
delete_email | destructive | Delete an email (move to trash) |
download_attachment | read | Download an email attachment. If savePath is provided, saves the file to disk and returns the file path and size. Otherwise returns a download URL. |
edit_draft | write | Edit an existing draft email. Since JMAP emails are immutable, this atomically destroys the old draft and creates a new one with the updated fields. Only fields you provide will be changed; others are preserved from the original draft. |
get_account_summary | read | Get overall account summary with statistics |
get_calendar_event | read | Get a specific calendar event by ID. Returns organizer and participants when available. |
get_contact | read | Get a specific contact by ID |
get_email | read | Get a specific email by ID |
get_email_attachments | read | Get list of attachments for an email |
get_mailbox_by_name | read | Look up a single mailbox by its full path from root (e.g. |
get_mailbox_stats | read | Get statistics for a mailbox (unread count, total emails, etc.) |
get_recent_emails | read | Get the most recent emails across all mailboxes except Trash and Spam (pass mailboxName to scope to one folder, e.g. |
get_thread | read | Get all emails in a conversation thread. Draft messages are excluded by default; set includeDrafts=true to include in-progress drafts in the thread. |
list_calendar_events | read | List events from a calendar |
list_calendars | read | List all calendars |
list_contacts | read | List contacts from the address book. When the server reports a total match count, results are wrapped in a { |
list_emails | read | List emails from a mailbox. When the server reports a total match count, results are wrapped in a { |
list_identities | read | List sending identities (email addresses that can be used for sending) |
list_mailboxes | read | List mailboxes in the Fastmail account. By default returns all mailboxes with full metadata; on accounts with hundreds of mailboxes the full result can exceed the MCP tool result window. Use |
mark_email_read | read | Mark an email as read or unread |
move_email | write | Move an email to a different mailbox |
pin_email | read | Pin or unpin an email |
remove_labels | destructive | Remove specific labels (mailboxes) from an email |
reply_email | read | Reply to an existing email with proper threading headers (In-Reply-To, References). Automatically fetches the original email to build the reply chain. By default sends immediately; set send=false to save as a draft instead. |
search_contacts | read | Search contacts by name or email. When the server reports a total match count, results are wrapped in a { |
send_draft | write | Send an existing draft email. The draft must have recipients (to/cc/bcc) and a from address. After sending, the email is moved to the Sent folder and the draft keyword is removed. |
send_email | write | Send an email |
test_bulk_operations | read | Test bulk operations by finding recent emails and performing safe operations (mark read/unread) |
update_contact | write | Update an existing contact. Each provided field WHOLLY REPLACES the stored value (e.g. emails: [] removes all emails) — unspecified fields are left untouched. Requires read-write contacts scope. |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (4 observation(s))
- Shell
- declared (2 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (11)
bulk_delete, bulk_remove_labels, delete_calendar_event, delete_contact, delete_email, remove_labels
.dxtignore
.secret-scan-local.txt.example
() => JmapClient.validateSavePath(`${homedir()}/.ssh/authorized_keys`),() => JmapClient.validateSavePath(`${allowedDir}/../../../.bashrc`),() => JmapClient.validateSavePath(`${customDir}/../../etc/shadow`, customDir),['embedded traversal', 'a/../../b', /must not contain/],
() => validateFastmailUrl('https://аpi.fastmail.com/jmap/api/', 'baseUrl'),@modelcontextprotocol/sdk, rrule, tsdav, @types/node, tsx, typescript
- The server avoids logging raw errors and sensitive data (tokens, email addresses, identities, attachment names/blobIds) in error messages.
The server uses bearer token authentication with Fastmail's API. API tokens provide secure access without exposing your main account password.
Gates applied: no_behavioural_pass.
16872ad4c120full audit observations/trust-audit/mcp-server/madllama25__fastmail.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 16872ad4c120 | SAFE | B | 89 | first audit |
Questions
What is the Fastmail MCP server?
Unofficial MCP server for the Fastmail JMAP API — email, contacts, and calendar tools for AI assistants. Not affiliated with Fastmail. Includes a DXT for Claude Desktop.
What tools does Fastmail expose?
42 in total: 24 read-only, 12 that write, and 6 that can delete or overwrite (bulk_delete, bulk_remove_labels, delete_calendar_event, delete_contact, delete_email). Every one is listed on this page with its risk.
Is Fastmail safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 6 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Fastmail need?
No credential environment variables were found in its source, so it appears to need none.
How does Fastmail run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as fastmail-mcp at 1.13.4.
How current is this page?
The grade is for one exact copy of the source (16872ad4c120), read on 2026-10-07. The repository is watched and re-audited when it changes.