Better EmailCAUTION
IMAP/SMTP email for AI agents -- read, send, organize folders, and manage attachments across multiple accounts, with auto-discovery.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
ARCHIVED 2026-09-13 — This repository is no longer maintained. Use IMAP/SMTP or your mail provider's API instead of this MCP server. Existing installations keep working but receive no updates or support.
mcp-name: io.github.n24q02m/better-email-mcp
IMAP/SMTP email for AI agents -- read, send, organize folders, and manage attachments across multiple accounts, with auto-discovery.
[](https://mcp.n24q02m.com/get-started/modes-overview/) [](https://github.com/n24q02m/better-email-mcp/actions/workflows/ci.yml) [](https://codecov.io/gh/n24q02m/better-email-mcp) [](https://www.npmjs.com/package/@n24q02m/better-email-mcp) [](https://hub.docker.com/r/n24q02m/better-email-mcp) [](LICENSE)
[](#) [](#) [](#) [](https://github.com/python-semantic-release/python-semantic-release) [](https://developer.mend.io/)
70586e7895a9OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add better-email-mcp --env EMAIL_CREDENTIALS=${EMAIL_CREDENTIALS} --env EMAIL_CREDENTIALS=${EMAIL_CREDENTIALS} -- npx -y @n24q02m/[email protected]claude mcp add better-email-mcp:latest --env EMAIL_CREDENTIALS=${EMAIL_CREDENTIALS} --env EMAIL_CREDENTIALS=${EMAIL_CREDENTIALS} -- docker run -i --rm docker.io/n24q02m/better-email-mcp:latest:NoneExposed tools (4)
3 read · 1 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
config__open_relay | read | Open the relay configuration form for better-email-mcp in the user browser. Returns the relay URL, whether the browser launched, and the current credential state. |
folders | read | List mailbox folders or read targeted mailbox status metadata.\n\nActions (required params -> optional):\n- list (-> account): folder names, paths, and flags for one or all accounts\n- status (account, folder): IMAP STATUS messages, unseen, and uid_next for exactly one mailbox |
help | read | Get full documentation for a tool. Use when compressed descriptions are insufficient. |
messages | write | Search, read, manage, compose, and send email messages.\n\nActions (required params -> optional):\n- search (-> account, query= |
Trust audit
CAUTIONgrade C · trust 76/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- declared (5 observation(s))
- Shell
- declared (3 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (25)
print("TOKEN OK len=", len(token), "sub=", _sub_of(token))print("AUTH-ONLY: replaying saved token for sub=", _sub_of(token), "(no re-save)")print("TOKEN OK len=", len(token), "sub=", _sub_of(token)).coderabbit.yaml
.gitguardian.yaml
.infisical.json
.mise.toml
.pre-commit-config.yaml
import { subjectContext } from '../../auth/subject-context.js'vi.mock('../../credential-state.js', () => ({import { getSetupUrl, getState, resetState, resolveCredentialState } from '../../credential-state.js'import { currentSub } from '../../auth/subject-context.js'import type { CredentialState } from '../../credential-state.js'mockGetSetupUrl.mockReturnValue('http://127.0.0.1:8080/authorize')setup_url: 'http://127.0.0.1:8080/authorize'
url: 'http://127.0.0.1:51234/authorize?session=abc',
expect(resolveSetupBaseUrl(undefined, '127.0.0.1', 3000)).toBe('http://127.0.0.1:3000')const HTTP_E2E_URL = `http://127.0.0.1:${HTTP_E2E_PORT}`@modelcontextprotocol/sdk, html-to-text, imapflow, mailparser, marked, nodemailer, sanitize-html, @biomejs/biome
- **4 composite tools** with 23 actions (plus `help` + `config__open_relay`) -- search, read, send, reply, forward, organize, and credential setup in single calls
This tool allows you to check the status of your email credentials, return the setup URL, reset your configuration, signal completion of external setup, and manage runtime caches. In HTTP mode the cre
export EMAIL_CREDENTIALS="[email protected]:your-app-password"
[](https://codecov.io/gh/n24q02m/better-email-mcp)
| `better-email-mcp` | Start the MCP server over **stdio** (default). Reads credentials from `EMAIL_CREDENTIALS`, or from `EMAIL_USER` + `EMAIL_APP_PASSWORD` |
EMAIL_CREDENTIALS="[email protected]:app-password" npx @n24q02m/better-email-mcp
Gates applied: no_behavioural_pass.
70586e7895a9full audit observations/trust-audit/mcp-server/n24q02m__better-email.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 70586e7895a9 | CAUTION | C | 76 | first audit |
Questions
What is the Better Email MCP server?
IMAP/SMTP email for AI agents -- read, send, organize folders, and manage attachments across multiple accounts, with auto-discovery.
What tools does Better Email expose?
4 in total: 3 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Better Email safe to connect to an agent?
With care. The audit graded it C (76/100) and found 25 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does Better Email need?
It reads CF_EMAIL_CREDENTIALS, CLOUDFLARE_API_TOKEN, CREDENTIAL_SECRET, EMAIL_APP_PASSWORD, EMAIL_CREDENTIALS, MCP_AUTH_DISABLE and MCP_RELAY_PASSWORD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Better Email run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @n24q02m/better-email-mcp at 1.41.5.
How current is this page?
The grade is for one exact copy of the source (70586e7895a9), read on 2026-10-08. The repository is watched and re-audited when it changes.