MailtrapSAFE
Official mailtrap.io MCP server
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://github.com/mailtrap/mailtrap-mcp/actions/workflows/main.yml) [](https://www.npmjs.com/package/mcp-mailtrap)
The official MCP server for Mailtrap — the email delivery platform. It connects your Mailtrap account to Claude, Cursor, VS Code, and other MCP-compatible AI assistants.
Send transactional and bulk email, test messages safely in Email Sandbox, manage templates, contacts, sending domains, and webhooks, inspect email logs and delivery statistics, troubleshoot deliverability, and manage account resources — all using natural-language prompts.
Capabilities
- Email API and SMTP — Send transactional and bulk email, including batch and template-based messages.
- Email testing — Test messages in Email Sandbox and inspect content, headers, attachments, spam scores, and HTML client compatibility.
- Delivery monitoring — Search email logs, inspect event history, and analyze delivery, bounce, open, click, and spam rates.
- Email infrastructure — Manage sending domains, DNS verification, webhooks, and suppressions.
- Contacts — Manage contacts, lists, custom fields, and events, with imports and exports.
- Account management — Review billing usage and manage access, permissions, API tokens, and sub-accounts.
Supported MCP Clients
Works with Claude Desktop, Claude Code, Cursor, VS Code, and any other MCP-compatible client. Setup instructions for each are below.
Prerequisites
Before using this MCP server, you need to:
- Create a Mailtrap account
- Verify your domain
- Get your API token from Mailtrap API settings
- Get your Account ID fro
1c8f04b4a999OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add mcp-mailtrap --env MAILTRAP_API_TOKEN=${MAILTRAP_API_TOKEN} -- npx -y [email protected]Exposed tools (125)
58 read · 42 write · 25 destructive. Blast radius: 25 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
batch-send-bulk-email | write | Send a batch of bulk emails (Mailtrap bulk-stream API) in one call. Shared fields go on |
batch-send-sandbox-email | write | Send a batch of emails in sandbox mode to a test inbox in one Mailtrap API call. Shared fields go on |
batch-send-transactional-email | write | Send a batch of transactional emails in one Mailtrap API call. Shared fields go on |
bulk-update-permissions | destructive | Bulk create, update, or destroy permissions for an account access. Existing (resource_type, resource_id) pairs are updated; new ones are created. Set |
cancel-email-campaign | read | Cancel a |
clean-sandbox-inbox | destructive | Delete all messages from a sandbox inbox without deleting the inbox itself |
create-api-token | write | Create a new API token. The response includes the secret |
create-company-info | write | Set the company info of a sending domain, required for domain compliance verification. |
create-contact | write | Create a new contact. Requires |
create-contact-event | write | Record a contact event (by |
create-contact-export | write | Export contacts matching a set of AND-combined filters. Returns an export job; poll status with |
create-contact-field | write | Create a new contact field definition. |
create-contact-import | write | Bulk import contacts. Returns an import job record; poll status via |
create-contact-list | write | Create a new contact list. |
create-email-campaign | write | Create a new email campaign in the |
create-inbound-folder | write | Create a new inbound folder. |
create-inbound-inbox | write | Create a new inbound inbox in a folder. Omit |
create-sandbox-inbox | write | Create a new sandbox test inbox within a project. Returns SMTP credentials for the new inbox. |
create-sandbox-project | write | Create a new sandbox project to group test inboxes |
create-sending-domain | write | Create a new sending domain |
create-sub-account | write | Create a new sub-account under the organization. Requires |
create-suppression | write | Add an email address to the account |
create-template | write | Create a new email template |
create-tracking-opt-out | write | Exclude an email address from open and click tracking for a sending domain. |
create-webhook | write | Create a webhook. |
delete-api-token | destructive | Permanently delete an API token by ID. The token can no longer authenticate after deletion. |
delete-contact | destructive | Permanently delete a contact by ID or email. Returns the deleted contact record when available. |
delete-contact-field | destructive | Permanently delete a contact field definition by ID. |
delete-contact-list | destructive | Permanently delete a contact list by ID. |
delete-email-campaign | destructive | Delete an email campaign by ID; only a campaign in the |
delete-inbound-folder | destructive | Permanently delete an inbound folder along with all of its inboxes. |
delete-inbound-inbox | destructive | Permanently delete an inbound inbox. |
delete-inbound-message | destructive | Permanently delete an inbound message. |
delete-inbound-thread | destructive | Permanently delete an inbound thread. |
delete-sandbox-inbox | destructive | Delete a sandbox inbox and all its messages |
delete-sandbox-message | destructive | Delete a single sandbox message |
delete-sandbox-project | destructive | Delete a sandbox project and all its inboxes |
delete-sending-domain | destructive | Delete a sending domain |
delete-suppression | destructive | Delete a suppression by ID. Mailtrap will resume delivery to this email unless it gets suppressed again. |
delete-template | destructive | Delete an existing email template |
delete-tracking-opt-out | destructive | Remove an email address from the tracking opt-out list, so open and click tracking applies to it again. |
delete-webhook | destructive | Permanently delete a webhook by ID. Returns the deleted webhook record. |
enable-sandbox-email-address | write | Enable the receive-by-email address for a sandbox |
forward-inbound-message | read | Forward an inbound message to new recipients (at least one |
forward-sandbox-message | read | Forward a sandbox message to an email address (counts against your monthly forwarding quota) |
get-api-token | read | Get an API token by ID. The secret token value is NOT returned here — only the metadata (name, last 4 digits, resources). |
get-billing-usage | read | Get the current billing cycle usage for the account (sending and testing plans, limits, and current counts). |
get-company-info | read | Get the company info of a sending domain, used for domain compliance verification. |
get-contact | read | Get a contact by ID or email address. Returns the full contact record including list memberships, status, and custom fields. |
get-contact-export | read | Get the status of a contact export job. Once |
get-contact-field | read | Get a contact field definition by ID. |
get-contact-import | write | Get the status of a contact import job, including created/updated/over-limit counts. |
get-contact-list | read | Get a contact list by ID. |
get-email-campaign | read | Get an email campaign by ID. |
get-email-campaign-stats | read | Get aggregated performance statistics for an email campaign; optionally narrow the window with |
get-email-log-message | read | Get a single email log message by ID (UUID) to inspect delivery status and event history. |
get-inbound-folder | read | Get a single inbound folder by ID. |
get-inbound-inbox | read | Get a single inbound inbox by ID. |
get-inbound-message | read | Get a single inbound message with its full body and attachment download URLs. |
get-inbound-thread | read | Get a single inbound thread with its messages embedded (oldest first). |
get-permission-resources | read | Get all resources (inboxes, projects, domains, billing, account) to which the API token has admin access, nested by hierarchy. |
get-sandbox-attachment | read | Get the metadata and download URL for a single sandbox attachment. |
get-sandbox-inbox | read | Get sandbox inbox details including SMTP credentials, email counts, and status |
get-sandbox-message-eml | read | Get a sandbox message as an EML file payload. |
get-sandbox-message-headers | read | Get the parsed mail headers for a sandbox message. |
get-sandbox-message-html | read | Get the rendered HTML body of a sandbox message. |
get-sandbox-message-html-analysis | read | Get HTML analysis for a sandbox message (client compatibility, problematic elements). |
get-sandbox-message-html-source | read | Get the unrendered HTML source of a sandbox message. |
get-sandbox-message-raw | read | Get the raw message (MIME-formatted) for a sandbox message. |
get-sandbox-message-spam-score | read | Get the SpamAssassin spam report for a sandbox message (score, rules, report). |
get-sandbox-message-text | read | Get the plain-text body of a sandbox message. |
get-sandbox-messages | read | Get list of messages from the sandbox test inbox |
get-sandbox-project | read | Get a sandbox project by ID, including its inboxes and email counts |
get-sending-domain | read | Get a sending domain by ID and its verification status. Optionally include DNS setup instructions via include_setup_instructions. |
get-sending-stats | read | Get email sending statistics (delivery, bounce, open, click, spam rates) for a date range. Optionally break down by domain, category, email service provider, or date. |
get-template | read | Get a single email template by ID, including subject, category, and HTML/text body. |
get-webhook | read | Get a single webhook by ID. |
list-account-accesses | read | List account accesses (users, invites, API tokens) for the account. Optionally scope by domain UUIDs, inbox IDs, or project IDs. Requires account admin/owner permissions. |
list-accounts | read | List Mailtrap accounts accessible to the API token, with each account |
list-api-tokens | read | List all API tokens for the account. |
list-contact-fields | read | List all contact field definitions for the account. |
list-contact-lists | read | List all contact lists for the account. Optionally filter by name with |
list-email-campaigns | read | List the account |
list-email-logs | read | List sent email logs (delivery history) with optional pagination and filters; use to debug delivery issues. |
list-inbound-folders | read | List all inbound folders in the account. |
list-inbound-inboxes | read | List all inboxes in an inbound folder. |
list-inbound-messages | read | List received messages in an inbound inbox (paginated). Pass |
list-inbound-threads | read | List conversation threads in an inbound inbox (paginated). Pass |
list-sandbox-attachments | read | List all attachments on a sandbox message. |
list-sandbox-projects | read | List all sandbox projects and their inboxes in your Mailtrap account |
list-sandboxes | read | List all sandboxes accessible to the API token across projects |
list-sending-domains | read | List sending domains and their DNS verification status |
list-sub-accounts | read | List sub-accounts in the organization. Requires |
list-suppressions | read | List or search suppressions. Optionally filter by email. Returns up to 1000 suppressions per call. |
list-templates | read | List all email templates |
list-tracking-opt-outs | read | List email addresses excluded from open and click tracking. Returns up to 1000 records per call. |
list-webhooks | read | List all webhooks for the account. |
mark-sandbox-as-read | read | Mark all messages in a sandbox as read |
remove-account-access | destructive | Remove an account access by ID. For User specifiers this revokes permissions; for Invite or ApiToken specifiers it removes the specifier itself. Requires admin/owner. |
reply-all-to-inbound-message | read | Reply to an inbound message and copy the original |
reply-to-inbound-message | read | Reply to an inbound message (sends to the original sender). Sends a real email. |
reset-api-token | destructive | Reset (rotate) an API token by ID. The response includes the **new** secret |
reset-email-campaign | destructive | Reset a |
reset-sandbox-credentials | destructive | Reset the SMTP credentials for a sandbox |
reset-sandbox-email-address | destructive | Generate a new receive-by-email address for a sandbox |
schedule-email-campaign | write | Schedule a |
send-email | write | Send an email to your recipient email address using Mailtrap Email API. You can send emails to multiple recipients at once. |
send-sandbox-email | write | Send an email in sandbox mode to a test inbox without delivering to your recipients |
send-sending-domain-setup-instructions | write | Email DNS setup instructions for a sending domain to a given address. |
show-sandbox-email-message | read | Show sandbox email message details and content from the sandbox test inbox. Optionally include spam report (SpamAssassin score) and HTML analysis (client compatibility) for email testing workflows. |
start-email-campaign | write | Start sending a |
terminate-email-campaign | destructive | Terminate an email campaign that is currently sending ( |
update-company-info | write | Update the company info of a sending domain. |
update-contact | write | Update a contact (identified by ID or email). |
update-contact-field | write | Update a contact field definition. Any combination of |
update-contact-list | write | Rename an existing contact list. |
update-email-campaign | write | Update a |
update-inbound-folder | write | Rename an inbound folder. |
update-inbound-inbox | write | Rename an inbound inbox. |
update-sandbox-inbox | write | Update a sandbox inbox name or email username |
update-sandbox-message | write | Mark a sandbox message as read or unread |
update-sandbox-project | write | Rename an existing sandbox project |
update-sending-domain | write | Update a sending domain |
update-template | write | Update an existing email template |
update-webhook | write | Update a webhook |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- declared (2 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (11)
bulk-update-permissions, clean-sandbox-inbox, delete-api-token, delete-contact, delete-contact-field, delete-contact-list, delete-email-campaign, delete-inbound-folder, delete-inbound-inbox, delete-in
.eslintrc.js
import { requireClient } from "../../../client";jest.mock("../../../client", () => ({import { requireClient } from "../../../client";jest.mock("../../../client", () => ({import { requireClient } from "../../client";[](https://cursor.com/en-US/install-mcp?name=mailtrap&config=eyJlbnYiOnsiTUFJTFRSQVBfQVBJX1RPS0VOIjoieW91cl9tYWlsdHJhcF9hcGlfdG9rZ
@modelcontextprotocol/sdk, dotenv, mailsplit, mailtrap, zod, @anthropic-ai/mcpb, @modelcontextprotocol/inspector, @types/jest
[](https://insiders.vscode.dev/redirect/mcp/install?name=mailtr
- **mark-sandbox-as-read** / **reset-sandbox-credentials** / **enable-sandbox-email-address** / **reset-sandbox-email-address**: Single-action sandbox operations.
Gates applied: no_behavioural_pass.
1c8f04b4a999full audit observations/trust-audit/mcp-server/railsware__mailtrap.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 1c8f04b4a999 | SAFE | B | 89 | first audit |
Questions
What is the Mailtrap MCP server?
Official mailtrap.io MCP server
What tools does Mailtrap expose?
125 in total: 58 read-only, 42 that write, and 25 that can delete or overwrite (bulk-update-permissions, clean-sandbox-inbox, delete-api-token, delete-contact, delete-contact-field). Every one is listed on this page with its risk.
Is Mailtrap safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 25 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Mailtrap need?
It reads MAILTRAP_API_TOKEN and MAILTRAP_ORGANIZATION_API_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Mailtrap run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as mcp-mailtrap at 0.9.0.
How current is this page?
The grade is for one exact copy of the source (1c8f04b4a999), read on 2026-10-08. The repository is watched and re-audited when it changes.