Atlas / MCP servers / mailtrap / Mailtrap

MailtrapSAFE

mcp/mailtrap/mailtrap-1

Official mailtrap.io MCP server

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
125 58r · 42w · 25d
Transport
stdio
License
MIT
Stars
65
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://github.com/mailtrap/mailtrap-mcp/actions/workflows/main.yml) [](https://www.npmjs.com/package/mcp-mailtrap)

The official MCP server for Mailtrap — the email delivery platform. It connects your Mailtrap account to Claude, Cursor, VS Code, and other MCP-compatible AI assistants.

Send transactional and bulk email, test messages safely in Email Sandbox, manage templates, contacts, sending domains, and webhooks, inspect email logs and delivery statistics, troubleshoot deliverability, and manage account resources — all using natural-language prompts.

Capabilities

  • Email API and SMTP — Send transactional and bulk email, including batch and template-based messages.
  • Email testing — Test messages in Email Sandbox and inspect content, headers, attachments, spam scores, and HTML client compatibility.
  • Delivery monitoring — Search email logs, inspect event history, and analyze delivery, bounce, open, click, and spam rates.
  • Email infrastructure — Manage sending domains, DNS verification, webhooks, and suppressions.
  • Contacts — Manage contacts, lists, custom fields, and events, with imports and exports.
  • Account management — Review billing usage and manage access, permissions, API tokens, and sub-accounts.

Supported MCP Clients

Works with Claude Desktop, Claude Code, Cursor, VS Code, and any other MCP-compatible client. Setup instructions for each are below.

Prerequisites

Before using this MCP server, you need to:

  1. Create a Mailtrap account
  2. Verify your domain
  3. Get your API token from Mailtrap API settings
  4. Get your Account ID fro
Read from source at commit 1c8f04b4a999OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add mcp-mailtrap --env MAILTRAP_API_TOKEN=${MAILTRAP_API_TOKEN} -- npx -y [email protected]
03

Exposed tools (125)

58 read · 42 write · 25 destructive. Blast radius: 25 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
batch-send-bulk-emailwriteSend a batch of bulk emails (Mailtrap bulk-stream API) in one call. Shared fields go on
batch-send-sandbox-emailwriteSend a batch of emails in sandbox mode to a test inbox in one Mailtrap API call. Shared fields go on
batch-send-transactional-emailwriteSend a batch of transactional emails in one Mailtrap API call. Shared fields go on
bulk-update-permissionsdestructiveBulk create, update, or destroy permissions for an account access. Existing (resource_type, resource_id) pairs are updated; new ones are created. Set
cancel-email-campaignreadCancel a
clean-sandbox-inboxdestructiveDelete all messages from a sandbox inbox without deleting the inbox itself
create-api-tokenwriteCreate a new API token. The response includes the secret
create-company-infowriteSet the company info of a sending domain, required for domain compliance verification.
create-contactwriteCreate a new contact. Requires
create-contact-eventwriteRecord a contact event (by
create-contact-exportwriteExport contacts matching a set of AND-combined filters. Returns an export job; poll status with
create-contact-fieldwriteCreate a new contact field definition.
create-contact-importwriteBulk import contacts. Returns an import job record; poll status via
create-contact-listwriteCreate a new contact list.
create-email-campaignwriteCreate a new email campaign in the
create-inbound-folderwriteCreate a new inbound folder.
create-inbound-inboxwriteCreate a new inbound inbox in a folder. Omit
create-sandbox-inboxwriteCreate a new sandbox test inbox within a project. Returns SMTP credentials for the new inbox.
create-sandbox-projectwriteCreate a new sandbox project to group test inboxes
create-sending-domainwriteCreate a new sending domain
create-sub-accountwriteCreate a new sub-account under the organization. Requires
create-suppressionwriteAdd an email address to the account
create-templatewriteCreate a new email template
create-tracking-opt-outwriteExclude an email address from open and click tracking for a sending domain.
create-webhookwriteCreate a webhook.
delete-api-tokendestructivePermanently delete an API token by ID. The token can no longer authenticate after deletion.
delete-contactdestructivePermanently delete a contact by ID or email. Returns the deleted contact record when available.
delete-contact-fielddestructivePermanently delete a contact field definition by ID.
delete-contact-listdestructivePermanently delete a contact list by ID.
delete-email-campaigndestructiveDelete an email campaign by ID; only a campaign in the
delete-inbound-folderdestructivePermanently delete an inbound folder along with all of its inboxes.
delete-inbound-inboxdestructivePermanently delete an inbound inbox.
delete-inbound-messagedestructivePermanently delete an inbound message.
delete-inbound-threaddestructivePermanently delete an inbound thread.
delete-sandbox-inboxdestructiveDelete a sandbox inbox and all its messages
delete-sandbox-messagedestructiveDelete a single sandbox message
delete-sandbox-projectdestructiveDelete a sandbox project and all its inboxes
delete-sending-domaindestructiveDelete a sending domain
delete-suppressiondestructiveDelete a suppression by ID. Mailtrap will resume delivery to this email unless it gets suppressed again.
delete-templatedestructiveDelete an existing email template
delete-tracking-opt-outdestructiveRemove an email address from the tracking opt-out list, so open and click tracking applies to it again.
delete-webhookdestructivePermanently delete a webhook by ID. Returns the deleted webhook record.
enable-sandbox-email-addresswriteEnable the receive-by-email address for a sandbox
forward-inbound-messagereadForward an inbound message to new recipients (at least one
forward-sandbox-messagereadForward a sandbox message to an email address (counts against your monthly forwarding quota)
get-api-tokenreadGet an API token by ID. The secret token value is NOT returned here — only the metadata (name, last 4 digits, resources).
get-billing-usagereadGet the current billing cycle usage for the account (sending and testing plans, limits, and current counts).
get-company-inforeadGet the company info of a sending domain, used for domain compliance verification.
get-contactreadGet a contact by ID or email address. Returns the full contact record including list memberships, status, and custom fields.
get-contact-exportreadGet the status of a contact export job. Once
get-contact-fieldreadGet a contact field definition by ID.
get-contact-importwriteGet the status of a contact import job, including created/updated/over-limit counts.
get-contact-listreadGet a contact list by ID.
get-email-campaignreadGet an email campaign by ID.
get-email-campaign-statsreadGet aggregated performance statistics for an email campaign; optionally narrow the window with
get-email-log-messagereadGet a single email log message by ID (UUID) to inspect delivery status and event history.
get-inbound-folderreadGet a single inbound folder by ID.
get-inbound-inboxreadGet a single inbound inbox by ID.
get-inbound-messagereadGet a single inbound message with its full body and attachment download URLs.
get-inbound-threadreadGet a single inbound thread with its messages embedded (oldest first).
get-permission-resourcesreadGet all resources (inboxes, projects, domains, billing, account) to which the API token has admin access, nested by hierarchy.
get-sandbox-attachmentreadGet the metadata and download URL for a single sandbox attachment.
get-sandbox-inboxreadGet sandbox inbox details including SMTP credentials, email counts, and status
get-sandbox-message-emlreadGet a sandbox message as an EML file payload.
get-sandbox-message-headersreadGet the parsed mail headers for a sandbox message.
get-sandbox-message-htmlreadGet the rendered HTML body of a sandbox message.
get-sandbox-message-html-analysisreadGet HTML analysis for a sandbox message (client compatibility, problematic elements).
get-sandbox-message-html-sourcereadGet the unrendered HTML source of a sandbox message.
get-sandbox-message-rawreadGet the raw message (MIME-formatted) for a sandbox message.
get-sandbox-message-spam-scorereadGet the SpamAssassin spam report for a sandbox message (score, rules, report).
get-sandbox-message-textreadGet the plain-text body of a sandbox message.
get-sandbox-messagesreadGet list of messages from the sandbox test inbox
get-sandbox-projectreadGet a sandbox project by ID, including its inboxes and email counts
get-sending-domainreadGet a sending domain by ID and its verification status. Optionally include DNS setup instructions via include_setup_instructions.
get-sending-statsreadGet email sending statistics (delivery, bounce, open, click, spam rates) for a date range. Optionally break down by domain, category, email service provider, or date.
get-templatereadGet a single email template by ID, including subject, category, and HTML/text body.
get-webhookreadGet a single webhook by ID.
list-account-accessesreadList account accesses (users, invites, API tokens) for the account. Optionally scope by domain UUIDs, inbox IDs, or project IDs. Requires account admin/owner permissions.
list-accountsreadList Mailtrap accounts accessible to the API token, with each account
list-api-tokensreadList all API tokens for the account.
list-contact-fieldsreadList all contact field definitions for the account.
list-contact-listsreadList all contact lists for the account. Optionally filter by name with
list-email-campaignsreadList the account
list-email-logsreadList sent email logs (delivery history) with optional pagination and filters; use to debug delivery issues.
list-inbound-foldersreadList all inbound folders in the account.
list-inbound-inboxesreadList all inboxes in an inbound folder.
list-inbound-messagesreadList received messages in an inbound inbox (paginated). Pass
list-inbound-threadsreadList conversation threads in an inbound inbox (paginated). Pass
list-sandbox-attachmentsreadList all attachments on a sandbox message.
list-sandbox-projectsreadList all sandbox projects and their inboxes in your Mailtrap account
list-sandboxesreadList all sandboxes accessible to the API token across projects
list-sending-domainsreadList sending domains and their DNS verification status
list-sub-accountsreadList sub-accounts in the organization. Requires
list-suppressionsreadList or search suppressions. Optionally filter by email. Returns up to 1000 suppressions per call.
list-templatesreadList all email templates
list-tracking-opt-outsreadList email addresses excluded from open and click tracking. Returns up to 1000 records per call.
list-webhooksreadList all webhooks for the account.
mark-sandbox-as-readreadMark all messages in a sandbox as read
remove-account-accessdestructiveRemove an account access by ID. For User specifiers this revokes permissions; for Invite or ApiToken specifiers it removes the specifier itself. Requires admin/owner.
reply-all-to-inbound-messagereadReply to an inbound message and copy the original
reply-to-inbound-messagereadReply to an inbound message (sends to the original sender). Sends a real email.
reset-api-tokendestructiveReset (rotate) an API token by ID. The response includes the **new** secret
reset-email-campaigndestructiveReset a
reset-sandbox-credentialsdestructiveReset the SMTP credentials for a sandbox
reset-sandbox-email-addressdestructiveGenerate a new receive-by-email address for a sandbox
schedule-email-campaignwriteSchedule a
send-emailwriteSend an email to your recipient email address using Mailtrap Email API. You can send emails to multiple recipients at once.
send-sandbox-emailwriteSend an email in sandbox mode to a test inbox without delivering to your recipients
send-sending-domain-setup-instructionswriteEmail DNS setup instructions for a sending domain to a given address.
show-sandbox-email-messagereadShow sandbox email message details and content from the sandbox test inbox. Optionally include spam report (SpamAssassin score) and HTML analysis (client compatibility) for email testing workflows.
start-email-campaignwriteStart sending a
terminate-email-campaigndestructiveTerminate an email campaign that is currently sending (
update-company-infowriteUpdate the company info of a sending domain.
update-contactwriteUpdate a contact (identified by ID or email).
update-contact-fieldwriteUpdate a contact field definition. Any combination of
update-contact-listwriteRename an existing contact list.
update-email-campaignwriteUpdate a
update-inbound-folderwriteRename an inbound folder.
update-inbound-inboxwriteRename an inbound inbox.
update-sandbox-inboxwriteUpdate a sandbox inbox name or email username
update-sandbox-messagewriteMark a sandbox message as read or unread
update-sandbox-projectwriteRename an existing sandbox project
update-sending-domainwriteUpdate a sending domain
update-templatewriteUpdate an existing email template
update-webhookwriteUpdate a webhook
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
declared (2 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (11)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
bulk-update-permissions, clean-sandbox-inbox, delete-api-token, delete-contact, delete-contact-field, delete-contact-list, delete-email-campaign, delete-inbound-folder, delete-inbound-inbox, delete-in
Why it matters. 25 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.eslintrc.js
.eslintrc.js
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/accountAccesses/__tests__/listAccountAccesses.test.ts:2
import { requireClient } from "../../../client";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/accountAccesses/__tests__/listAccountAccesses.test.ts:12
jest.mock("../../../client", () => ({
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/accountAccesses/__tests__/removeAccountAccess.test.ts:2
import { requireClient } from "../../../client";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/accountAccesses/__tests__/removeAccountAccess.test.ts:12
jest.mock("../../../client", () => ({
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/accountAccesses/listAccountAccesses.ts:1
import { requireClient } from "../../client";
LOWObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
README.md:48
[![Install in Cursor](https://cursor.com/deeplink/mcp-install-dark.svg)](https://cursor.com/en-US/install-mcp?name=mailtrap&config=eyJlbnYiOnsiTUFJTFRSQVBfQVBJX1RPS0VOIjoieW91cl9tYWlsdHJhcF9hcGlfdG9rZ
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, dotenv, mailsplit, mailtrap, zod, @anthropic-ai/mcpb, @modelcontextprotocol/inspector, @types/jest
Why it matters. 23 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
CLAUDE.md:105
- **mark-sandbox-as-read** / **reset-sandbox-credentials** / **enable-sandbox-email-address** / **reset-sandbox-email-address**: Single-action sandbox operations.
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
README.md:50
[![Install with Node in VS Code](https://img.shields.io/badge/VS_Code-Node-0098FF?style=flat-square&logo=visualstudiocode&logoColor=white)](https://insiders.vscode.dev/redirect/mcp/install?name=mailtr
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 1c8f04b4a999full audit observations/trust-audit/mcp-server/mailtrap__mailtrap-1.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-071c8f04b4a999SAFEB89first audit
06

Questions

What is the Mailtrap MCP server?

Official mailtrap.io MCP server

What tools does Mailtrap expose?

125 in total: 58 read-only, 42 that write, and 25 that can delete or overwrite (bulk-update-permissions, clean-sandbox-inbox, delete-api-token, delete-contact, delete-contact-field). Every one is listed on this page with its risk.

Is Mailtrap safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 25 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Mailtrap need?

It reads MAILTRAP_API_TOKEN and MAILTRAP_ORGANIZATION_API_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Mailtrap run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as mcp-mailtrap at 0.9.0.

How current is this page?

The grade is for one exact copy of the source (1c8f04b4a999), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement