EmailBLOCK
一个让AI轻松接管邮箱的MCP服务,基于 Model Context Protocol (MCP) 构建,支持在 MCP-X,Claude Desktop 等 MCP 客户端中使用。
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://badge.fury.io/js/mcp-email) [](https://www.npmjs.com/package/mcp-email) [](https://opensource.org/licenses/MIT)
一个让AI轻松接管邮箱的通用MCP服务器,基于 Model Context Protocol (MCP) 构建,支持在 MCP-X、Claude Desktop 等 MCP 客户端中使用。
支持多种邮箱服务商自动配置:QQ邮箱、163邮箱、Gmail、Outlook、腾讯企业邮箱、网易企业邮箱、阿里云邮箱、新浪邮箱、搜狐邮箱等。
📦 快速安装
# npm 安装 npm install -g mcp-email # 使用 npx 运行(推荐) npx mcp-email
✨ 功能特性
- 📤 邮件发送: 支持发送HTML和纯文本邮件
- 👥 多收件人: 支持多个收件人、抄送、密送
- 📎 附件支持: 支持文件附件和Base64编码内容
- 🔧 动态配置: 支持运行时配置邮箱服务器
- 🔍 连接测试: 内置SMTP服务器连接测试
- 🛡️ 安全认证: 支持微信企业邮箱授权码认证
- ⚡ 高性能: 优化的连接超时和重试机制
📚 详细配置指南
项目提供了详细的配置指南,包含各大邮箱服务商的配置说明:
📖 CONFIG_GUIDE.md - 完整配置指南,包含:
- 📧 163邮箱详细配置教程
- 🏢 微信企业邮箱配置指南
- 🌐 QQ邮箱、Gmail等主流邮箱配置
- 🛠️ 故障排除和常见问题解决
📋 系统要求
- Node.js 16.x 或更高版本
- 邮箱账号
- MCP 客户端 (如 Claude Desktop)
🚀 快速开始
方式一:直接使用npm包(推荐)
1. 安装npm包
# 全局安装 npm install -g mcp-email # 或本地安装 npm install mcp-email
2. 在MCP客户端中配置
MCP-X 配置示例:
{
"mcpServers": {
"universal-email": {
"command": "npx",
"args": ["mcp-email"],
"env": {
"EMAIL_USER": "[email protected]",
"EMAIL_PASSWORD": "your-password-or-auth-code",
"EMAIL_TYPE": "auto"
}
}
}
}方式二:从源码安装
1. 克隆项目
git clone https://github.com/TimeCyber/email-mcp.git cd email-mcp
2. 安装依赖
npm install
3. 配置 MCP 客户端(源码安装)
MCP-X 配置:
{
"mcpServers": {
"universal-email": {
"command": "node",
"args": ["F:\\path\\to\\email-mcp\\index.js"],
"env": {
"EMAIL_USER": "[email protected]",
"EMAIL_PASSWORD": "your-password-or-auth-code",
"EMAIL_TYPE": "auto"
}
}
}
}企业邮箱配置:
{
"mcpSec82fc291d137OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add mcp-email --env EMAIL_PASSWORD=${EMAIL_PASSWORD} --env WECHAT_EMAIL_PASSWORD=${WECHAT_EMAIL_PASSWORD} -- npx -y [email protected]{
"mcpServers": {
"mcp-email": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"EMAIL_PASSWORD": "${EMAIL_PASSWORD}",
"WECHAT_EMAIL_PASSWORD": "${WECHAT_EMAIL_PASSWORD}"
}
}
}
}Exposed tools (7)
6 read · 1 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
configure_email_server | read | 手动配置邮箱服务器设置(高级用户使用) |
get_email_content | read | 获取指定邮件的详细内容 |
get_recent_emails | read | 获取最近三天的邮件列表 |
list_supported_providers | read | 列出支持的邮箱提供商 |
send_email | write | 发送邮件 |
setup_email_account | read | 设置邮箱账号(自动识别邮箱类型并配置服务器) |
test_email_connection | read | 测试邮箱服务器连接 |
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (2 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (4)
tlsOptions: { rejectUnauthorized: false }tlsOptions: { rejectUnauthorized: false }password: 'your-enterprise-auth-code', // 需要实际的企业邮箱授权码
@modelcontextprotocol/sdk, dotenv, imap, mailparser, nodemailer, poplib, @types/node, @types/nodemailer
Gates applied: no_behavioural_pass.
c82fc291d137full audit observations/trust-audit/mcp-server/timecyber__email-4.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | c82fc291d137 | BLOCK | D | 69 | first audit |
Questions
What is the Email MCP server?
一个让AI轻松接管邮箱的MCP服务,基于 Model Context Protocol (MCP) 构建,支持在 MCP-X,Claude Desktop 等 MCP 客户端中使用。
What tools does Email expose?
7 in total: 6 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Email safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Email need?
It reads EMAIL_PASSWORD and WECHAT_EMAIL_PASSWORD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Email run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as mcp-email at 1.0.0.
How current is this page?
The grade is for one exact copy of the source (c82fc291d137), read on 2026-10-08. The repository is watched and re-audited when it changes.