IMAPCAUTION
A powerful Model Context Protocol (MCP) server for IMAP email integration with Claude
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A powerful Model Context Protocol (MCP) server that provides seamless IMAP email integration with secure account management and connection pooling.
Features
- 🔐 Secure Account Management: Encrypted credential storage with AES-256 encryption
- 🚀 Connection Pooling: Efficient IMAP connection management
- 📧 Comprehensive Email Operations: Search, read, move, mark, delete, and bulk delete emails
- ✉️ Email Sending: Send, reply, and forward emails via SMTP
- 📁 Folder Management: List folders, check status, get unread counts
- 🔄 Multiple Account Support: Manage multiple IMAP accounts simultaneously
- 🛡️ Type-Safe: Built with TypeScript for reliability
- 🌐 Web-Based Setup Wizard: Easy account configuration with provider presets
- 📱 15+ Email Providers: Pre-configured settings for Gmail, Outlook, Yahoo, and more
- 🔗 Auto SMTP Configuration: Automatic SMTP settings based on IMAP provider
Installation
Requires Node.js 22.12 or newer. Node 18 and 20 have both reached end-of-life, and several of this package's dependencies no longer support them. Check yours with node --version.Run via npx (No Installation Required)
Once published to npm, you can run the server directly without cloning or building anything — npx downloads the prebuilt package and runs it:
npx -y imap-mcp-server
This is the easiest way to use the server in an MCP client (see Configuration for ready-to-paste npx configs).
Quick Install (Recommended)
macOS/Linux:
curl -fsSL https://raw.githubusercontent.com/nikolausm/imap-mcp-server/main/install.sh | bash
Windows (PowerShell as Administrator):
iwr -useb https://raw.githubusercontent.com/nikolausm/imap-mcp-server/main/install.ps1 | iex
Manual Installation
- Clone the repository:
git clone https://github.com/nikolausm/imap-mcp-server.git cd imap-mcp-server
- Install dependencie
6ebae8af186dOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add imap-mcp-server -- npx -y [email protected]
Exposed tools (40)
22 read · 10 write · 8 destructive. Blast radius: 8 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
imap_add_account | write | |
imap_add_keyword | write | |
imap_add_spam_domain | write | |
imap_add_whitelist_domain | write | |
imap_bulk_delete | destructive | |
imap_bulk_delete_by_search | destructive | |
imap_check_spam | read | |
imap_connect | read | |
imap_create_folder | write | |
imap_delete_by_domain | destructive | |
imap_delete_email | destructive | |
imap_delete_spam | destructive | |
imap_disconnect | read | |
imap_domain_stats | read | |
imap_download_attachment | read | |
imap_find_email_by_message_id | read | |
imap_find_thread_messages | read | |
imap_flag_email | read | |
imap_folder_status | read | |
imap_forward_email | read | |
imap_get_email | read | |
imap_get_latest_emails | read | |
imap_get_unread_count | read | |
imap_list_accounts | read | |
imap_list_folders | read | |
imap_list_spam_domains | read | |
imap_mark_as_read | read | |
imap_mark_as_unread | read | |
imap_move_email | write | |
imap_remove_account | destructive | |
imap_remove_keyword | destructive | |
imap_remove_spam_domain | destructive | |
imap_reply_to_email | read | |
imap_save_draft | write | |
imap_search_emails | read | |
imap_send_email | write | |
imap_test_account | read | |
imap_unflag_email | read | |
imap_update_account | write | |
imap_upload_file | write |
Trust audit
CAUTIONgrade B · trust 87/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- declared (6 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (14)
const SECRET = 'imap-plaintext-secret';
imap_bulk_delete, imap_bulk_delete_by_search, imap_delete_by_domain, imap_delete_email, imap_delete_spam, imap_remove_account, imap_remove_keyword, imap_remove_spam_domain
const wizardEnvVarName = new Function('accountName', 'suffix', match![1]) aspath.join(__dirname, '../../public'),
filename: '../../../../../../tmp/imap-mcp-escape.txt',
filename: '../../../../../../tmp/imap-mcp-escape.txt',
baseUrl = `http://127.0.0.1:${port}`;const out = normalizeWhitespace('a\n\n\n\nb c \n');@modelcontextprotocol/sdk, body-parser, chalk, commander, cors, dotenv, express, imapflow
Credentials can be overridden at read time via environment variables keyed
- Selective tool access via environment variables (Issue #87). `IMAP_MCP_READ_ONLY` (truthy: `1`/`true`/`yes`/`on`) registers only the safe, read-only subset — searching, reading, listing folders, unr
(`0700`/`0600`) so other local users cannot read the key or the credentials
anyone who can read both files can read your credentials.
curl -fsSL https://raw.githubusercontent.com/nikolausm/imap-mcp-server/main/install.sh | bash
Gates applied: no_behavioural_pass.
6ebae8af186dfull audit observations/trust-audit/mcp-server/nikolausm__imap-4.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 6ebae8af186d | CAUTION | B | 87 | first audit |
Questions
What is the IMAP MCP server?
A powerful Model Context Protocol (MCP) server for IMAP email integration with Claude
What tools does IMAP expose?
40 in total: 22 read-only, 10 that write, and 8 that can delete or overwrite (imap_bulk_delete, imap_bulk_delete_by_search, imap_delete_by_domain, imap_delete_email, imap_delete_spam). Every one is listed on this page with its risk.
Is IMAP safe to connect to an agent?
With care. The audit graded it B (87/100) and found 14 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 8 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does IMAP need?
It reads IMAP_MCP_ACCOUNT_ENV_MANAGED_IMAP_PASSWORD, IMAP_MCP_ACCOUNT_WORK_GMAIL_IMAP_PASSWORD, IMAP_MCP_ACCOUNT_WORK_GMAIL_SMTP_PASSWORD and IPQUALITYSCORE_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does IMAP run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as imap-mcp-server at 2.1.0.
How current is this page?
The grade is for one exact copy of the source (6ebae8af186d), read on 2026-10-07. The repository is watched and re-audited when it changes.