Atlas / MCP servers / resend / Send Email

Send EmailCAUTION

mcp/resend/send-email

The official MCP server to send emails and interact with Resend

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
107 60r · 33w · 14d
Transport
streamable-http
License
MIT
Stars
575
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://www.npmjs.com/package/resend-mcp)

Connect your AI agent to the Resend platform. Send and receive emails, manage contacts, broadcasts, domains, and more, directly from any MCP client like Claude, Cursor, or Claude Code.

We offer both a remote MCP server hosted by Resend and a local MCP server (this package).

Remote MCP Server

Resend hosts the MCP server at:

https://mcp.resend.com/mcp

Connect any MCP client that supports remote servers (Streamable HTTP). There's nothing to install and no local process to run, which makes it the best option for web-based clients like Claude and hosted agent platforms.

When you connect, your client opens a browser window to log in to Resend and approve access using OAuth.

Claude Code

claude mcp add --transport http resend https://mcp.resend.com/mcp

Then run /mcp in Claude Code and select resend to complete the OAuth login.

Claude

In Claude (web or desktop), open Settings > Connectors > Add custom connector and enter:

https://mcp.resend.com/mcp

Cursor

Open the command palette and choose "Cursor Settings" > "MCP" > "Add new global MCP server".

{
"mcpServers": {
"resend": {
"url": "https://mcp.resend.com/mcp"
}
}
}

Codex

codex mcp add resend --url https://mcp.resend.com/mcp

Copilot

To use GitHub Copilot in VS Code, add the following to your settings.json:

{
"mcp": {
"servers": {
"resend": {
"type": "http",
"url": "https://mcp.resend.com/mcp"
}
}
}
}

Windsurf

{
"mcpServers": {
"resend": {
"serverUrl": "https://mcp.resend.com/mcp"
}
}
}

Warp

In Warp's Settings, navigate to Agents > MCP servers, and click +Add to add a new server.

{
"resend": {
Read from source at commit 08a3fd1f254fOBSERVED · 2026-09-30
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add resend-mcp -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "resend-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (107)

60 read · 33 write · 14 destructive. Blast radius: 14 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
add-contact-to-segmentwrite
add-suppressionwrite
batch-add-suppressionswrite
batch-remove-suppressionsdestructive
cancel-broadcastread
cancel-emailread
compose-broadcastread
compose-templateread
connect-to-editorread
create-api-keywrite
create-automationwrite
create-broadcastwrite
create-contactwrite
create-contact-importwrite
create-contact-propertywrite
create-domainwrite
create-domain-claimwrite
create-segmentwrite
create-templatewrite
create-topicwrite
create-webhookwrite
disconnect-from-editorread
duplicate-automationread
duplicate-broadcastread
duplicate-templateread
get-automationread
get-automation-runsread
get-broadcastread
get-contactread
get-contact-importwrite
get-contact-propertyread
get-domainread
get-domain-claimread
get-emailread
get-email-metricsread
get-logread
get-received-emailread
get-received-email-attachmentread
get-segmentread
get-sent-email-attachmentread
get-suppressionread
get-templateread
get-tiptap-json-contentread
get-topicread
get-usageread
get-webhookread
get-webhook-eventread
list-api-keysread
list-broadcast-clicked-linksread
list-broadcast-recipientsread
list-broadcastsread
list-contact-importsread
list-contact-propertiesread
list-contact-segmentsread
list-contact-topicsread
list-contactsread
list-domainsread
list-emailsread
list-logsread
list-oauth-grantsread
list-received-email-attachmentsread
list-received-emailsread
list-segmentsread
list-sent-email-attachmentsread
list-suppressionsread
list-templatesread
list-topicsread
list-webhook-event-attemptsread
list-webhook-eventsread
list-webhooksread
manage-eventsread
pingread
publish-templatewrite
remove-api-keydestructive
remove-automationdestructive
remove-broadcastdestructive
remove-contactdestructive
remove-contact-from-segmentdestructive
remove-contact-propertydestructive
remove-domaindestructive
remove-segmentdestructive
remove-suppressiondestructive
remove-templatedestructive
remove-topicdestructive
remove-webhookdestructive
replay-webhook-eventread
revoke-oauth-grantdestructive
rotate-webhook-signing-secretread
send-batch-emailswrite
send-broadcastwrite
send-emailwrite
send-eventwrite
share-emailread
update-api-keywrite
update-automationwrite
update-broadcastwrite
update-contactwrite
update-contact-propertywrite
update-contact-topicswrite
update-domainwrite
update-emailwrite
update-segmentwrite
update-templatewrite
update-topicwrite
update-webhookwrite
verify-domainread
verify-domain-claimread
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
declared (3 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (12)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
batch-remove-suppressions, remove-api-key, remove-automation, remove-broadcast, remove-contact, remove-contact-from-segment, remove-contact-property, remove-domain, remove-segment, remove-suppression,
Why it matters. 14 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
MEDIUMAuth / authz · mcp.remote_no_auth · CWE-287, CWE-862
streamable-http
Why it matters. a network transport with no auth environment variable found
Fix. require a token
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/cli/index.ts:2
import packageJson from '../../package.json' with { type: 'json' };
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/cli/help.test.ts:2
import { HELP_TEXT, printHelp } from '../../src/cli/help.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/cli/parse.test.ts:3
import { parseArgs, parseReplierAddresses } from '../../src/cli/parse.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/cli/resolve.test.ts:2
import { parseArgs } from '../../src/cli/parse.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/cli/resolve.test.ts:3
import { resolveConfig } from '../../src/cli/resolve.js';
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:295
The server will listen on `http://127.0.0.1:3000` and expose the MCP endpoint at `/mcp` using Streamable HTTP.
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:300
claude mcp add resend --transport http http://127.0.0.1:3000/mcp --header "Authorization: Bearer re_xxxxxxxxx"
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:311
"url": "http://127.0.0.1:3000/mcp",
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:421
claude mcp add resend --transport http http://127.0.0.1:3000/mcp --header "Authorization: Bearer re_xxxxxxxxx"
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:446
"url": "http://127.0.0.1:3000/mcp",

Gates applied: no_behavioural_pass.

Audited 2026-09-30 · audit v0.4.1 · source sha 08a3fd1f254ffull audit observations/trust-audit/mcp-server/resend__send-email.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-3008a3fd1f254fCAUTIONB89first audit
06

Questions

What is the Send Email MCP server?

The official MCP server to send emails and interact with Resend

What tools does Send Email expose?

107 in total: 60 read-only, 33 that write, and 14 that can delete or overwrite (batch-remove-suppressions, remove-api-key, remove-automation, remove-broadcast, remove-contact). Every one is listed on this page with its risk.

Is Send Email safe to connect to an agent?

With care. The audit graded it B (89/100) and found 12 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 14 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Send Email need?

No credential environment variables were found in its source, so it appears to need none.

How does Send Email run?

It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as resend-mcp at 2.24.0.

How current is this page?

The grade is for one exact copy of the source (08a3fd1f254f), read on 2026-09-30. The repository is watched and re-audited when it changes.

Advertisement