PluginBench
MCP Server
Active

Email (IMAP/SMTP) MCP Server

io.github.mindstone/mcp-server-email-imap

Read, search, send, and manage emails across iCloud, Gmail, Yahoo, Outlook, and custom IMAP providers.

What is the Email (IMAP/SMTP) MCP server?

The Email (IMAP/SMTP) MCP server enables AI agents to read, search, send, and manage emails through IMAP and SMTP protocols. It supports major email providers including iCloud, Gmail, Yahoo, and Outlook, as well as custom IMAP servers.

This server gives Claude and other MCP hosts full email capabilities—reading and searching your inbox, composing and sending messages, and managing folders. It works with any IMAP/SMTP provider, making it useful for email automation, research, customer support workflows, and personal productivity tasks.

How to install Email (IMAP/SMTP)

Copy-paste configuration for popular MCP clients.

transport: stdio
Config generated by PluginBench — verify against the source before use.
Environment / auth
  • EMAIL_IMAP_EMAIL
    required

    Email address

  • EMAIL_IMAP_PASSWORD
    required
    secret

    App-specific password

  • EMAIL_IMAP_PROVIDER

    Provider — icloud, gmail, yahoo, outlook, or custom (auto-detected from email domain if unset)

  • EMAIL_IMAP_IMAP_HOST

    Custom IMAP host (for provider=custom)

  • EMAIL_IMAP_SMTP_HOST

    Custom SMTP host (for provider=custom)

  • EMAIL_IMAP_IMAP_PORT

    Custom IMAP port

  • EMAIL_IMAP_SMTP_PORT

    Custom SMTP port

  • EMAIL_IMAP_MAX_RECIPIENTS

    Safety cap: maximum combined To+CC+BCC recipients per email_send call. Defaults to 25; raising bypasses spam-prevention guardrails against prompt-injection-driven mass sends.

  • EMAIL_IMAP_RATE_LIMIT_PER_HOUR

    Safety cap: maximum email_send calls per rolling window. Defaults to 50; protects against runaway sends when injection content escapes the LLM's intent.

  • EMAIL_IMAP_RATE_LIMIT_WINDOW_MS

    Sliding-window length for the rate limit (ms)

  • MCP_WORKSPACE_PATH

    Workspace directory that email_get_attachment downloads into (fresh email-imap-attachment-* staging directories). Defaults to the system temp directory.

~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "mcp-server-email-imap": {
      "command": "npx",
      "args": [
        "-y",
        "@mindstone/mcp-server-email-imap"
      ],
      "env": {
        "EMAIL_IMAP_EMAIL": "<YOUR_EMAIL_IMAP_EMAIL>",
        "EMAIL_IMAP_PASSWORD": "<YOUR_EMAIL_IMAP_PASSWORD>",
        "EMAIL_IMAP_PROVIDER": "<YOUR_EMAIL_IMAP_PROVIDER>",
        "EMAIL_IMAP_IMAP_HOST": "<YOUR_EMAIL_IMAP_IMAP_HOST>",
        "EMAIL_IMAP_SMTP_HOST": "<YOUR_EMAIL_IMAP_SMTP_HOST>",
        "EMAIL_IMAP_IMAP_PORT": "<YOUR_EMAIL_IMAP_IMAP_PORT>",
        "EMAIL_IMAP_SMTP_PORT": "<YOUR_EMAIL_IMAP_SMTP_PORT>",
        "EMAIL_IMAP_MAX_RECIPIENTS": "<YOUR_EMAIL_IMAP_MAX_RECIPIENTS>",
        "EMAIL_IMAP_RATE_LIMIT_PER_HOUR": "<YOUR_EMAIL_IMAP_RATE_LIMIT_PER_HOUR>",
        "EMAIL_IMAP_RATE_LIMIT_WINDOW_MS": "<YOUR_EMAIL_IMAP_RATE_LIMIT_WINDOW_MS>",
        "MCP_WORKSPACE_PATH": "<YOUR_MCP_WORKSPACE_PATH>"
      }
    }
  }
}

Tools & capabilities

Tools this server exposes to the agent.

  • Read emails — Retrieve and read email messages from your mailbox
  • Search emails — Search and filter emails by subject, sender, content, and other criteria
  • Send emails — Compose and send new email messages via SMTP
  • Manage emails — Move, delete, and organize emails across folders

Use cases

  • Automatically search and summarize emails from specific senders or with certain keywords
  • Draft and send emails on behalf of the user based on natural language instructions
  • Organize and archive emails by moving them between folders
  • Extract information from email threads for research or documentation
  • Monitor inbox for important messages and alert the user to urgent emails

Email (IMAP/SMTP) MCP server FAQ

What email providers does this server support?

It supports iCloud, Gmail, Yahoo, Outlook, and any custom IMAP/SMTP server. You provide your email credentials and server details during setup.

Is this server free to use?

Yes, the server itself is open-source and free. You only need valid credentials for your email provider.

How do I install this in Claude Desktop or Cursor?

Install via npm: `npm install @mindstone/mcp-server-email-imap`, then configure it in your MCP host's settings with your email provider credentials.

What authentication is required?

You need to provide your email address, password (or app-specific password for Gmail/Outlook), and IMAP/SMTP server details. Some providers may require app-specific passwords for security.

Can this server send emails?

Yes, it can compose and send emails via SMTP using your email account credentials.

Is my email content secure?

The server runs locally on your machine and credentials are stored per your MCP host's configuration. External email content is wrapped in untrusted-content envelopes to prevent injection attacks.

README (reference)

Source of truth, from the repository.

<p align="center"> <img src="docs/assets/rogue.svg" alt="Rogue, the Rebel character for safe action and control" width="112" /> </p>

mcp-servers

OpenSSF Scorecard

Source-available MCP servers by Mindstone. Works with any MCP host — Claude Desktop, Cursor, Rebel, and others.

Browse all 35 connectors with their version, auth model, and tool count at the catalogue site (regenerated from each connector's STATUS.json on every push).

Connectors

ConnectorDescription
apple-shortcutsRun and list Apple Shortcuts on macOS via the shortcuts CLI
browser-automationHeadless browser control via accessibility snapshots — navigate, fill forms, click, and screenshot pages via the agent-browser CLI
elevenlabsGenerate speech, music, and sound effects, browse voices, and transcribe audio via the ElevenLabs API
email-imapRead, search, send, and manage emails through IMAP and SMTP
fathomList and search meetings, view details, read transcripts, and manage teams via Fathom AI
freshdeskManage helpdesk tickets, search support requests, reply to customers, and add internal notes
gammaCreate AI-powered presentations, documents, webpages, and social posts via Gamma
google-analyticsDiscover GA4 accounts and properties, explore the live schema, and run reports via the Google Analytics API
google-workspaceRead, search, and send across Gmail, Calendar, Drive, Docs, Sheets, Slides, Contacts, and Comments with host-orchestrated OAuth and per-account on-disk credentials
hubspotManage HubSpot CRM — contacts, companies, deals, tickets, leads, tasks, notes, properties, lists, workflows, knowledge base, and files — with multi-account, host-orchestrated OAuth
humaansQuery employee profiles, job roles, time-away requests, and company info via Humaans HR
klingGenerate AI videos from text descriptions or images via Kling AI
microsoft-calendarList, create, update, and respond to Outlook calendar events, check free/busy, and list calendars; reuses the cohort's host-orchestrated Microsoft 365 OAuth surface
microsoft-filesList, search, upload, download, share, and read OneDrive files via Microsoft Graph; reuses the cohort's host-orchestrated Microsoft 365 OAuth surface
microsoft-mailList, search, read, send, reply, forward, draft, move, and delete Outlook email; owns the cohort's host-orchestrated Microsoft 365 OAuth surface
microsoft-sharepointDiscover sites, browse libraries, read pages and lists, search content, and mutate SharePoint files/lists with incremental Sites.Read.All consent
microsoft-teamsList and read Teams chats, send chat messages, list teams and channels, and read presence; reuses the cohort's host-orchestrated Microsoft 365 OAuth surface
mixmaxManage sequences, send tracked emails, use templates, and monitor engagement via Mixmax
nano-bananaGenerate and edit images using Google Gemini's AI capabilities
napkinGenerate professional visuals — diagrams, infographics, and illustrations — from text via Napkin AI
officeRead and edit Word documents, Excel workbooks, and PowerPoint presentations from desktop Microsoft 365 via an Office Add-in sidecar
openai-imageGenerate and edit images via OpenAI's gpt-image-2 — sharp text rendering, multilingual support, and four quality levels
outreachManage prospects, sequences, accounts, tasks, and mailings via the Outreach sales engagement API
pandadocCreate, send, and manage documents, templates, and e-signatures via PandaDoc
quickbooksManage invoices, bills, customers, vendors, employees, and accounts in QuickBooks Online
replit-sshRead, write, list, and check files on Replit projects over SSH/SFTP, with one-shot SSH key + config setup on the operator's machine
retell-aiPlace voice-agent phone calls, manage agents and LLM prompts, and discover voices via the Retell AI API
runwayGenerate AI video, images, audio, speech, and sound effects via Runway ML
salesforceManage accounts, contacts, opportunities, leads, tasks, users, and custom objects via the Salesforce API
servicenowManage incidents, change requests, users, and knowledge base articles in ServiceNow
slackMulti-workspace Slack — channels, messages, threads, reactions, users, files, bookmarks, and scheduled messages via the Slack Web API, with host-orchestrated OAuth
talentlmsManage users, courses, groups, branches, enrolments, and assessments in TalentLMS
vantaRead and manage compliance posture in Vanta — vulnerabilities, tests, controls, evidence, resources, people, vendors, documents, and compliance summary
workdayQuery workers, profiles, and organizations in Workday HCM
zendeskManage tickets, macros, users, and views in Zendesk Support

Quick Start

Each server builds independently:

cd connectors/<name>
npm install
npm run build

Or run directly via npx (once published):

npx -y @mindstone/mcp-server-zendesk

Moving from @mindstone-engineering/? Every server has been republished under the shorter @mindstone/ npm scope. The legacy @mindstone-engineering/mcp-server-* packages still install but are marked deprecated. See MIGRATION.md for the consumer one-liner and the deprecation timeline.

See each server's README for configuration and host setup instructions. Some connectors require additional environment variables to opt into specific behaviour (e.g. QB_ALLOW_PROD_WRITES for QuickBooks production writes, MCP_WORKSPACE_PATH for sandboxed file reads) — see the per-connector READMEs for the full list.

Security & Hardening

This monorepo follows a defence-in-depth posture for tool-call hosts. Highlights include:

  • Workflow safety. GitHub Actions workflows are env-fy'd against script injection (CWE-94), every action is pinned to a commit SHA (kept current by Dependabot), and each job is granted a least-privilege permissions: block. Publish is split into a build job (does the install/test/pack with no publish credentials) and a publish job (downloads the packed tarball, runs only npm publish --ignore-scripts --provenance under OIDC trusted publishing, gated by the npm-publish environment). The publish job invokes NO third-party JS — tsc, vitest, lifecycle scripts, etc. all run upstream, away from id-token: write. See docs/security/AUDIT_FOX-3319_tanstack_supply_chain.md for the supply-chain threat model and docs/security/BRANCH_PROTECTION.md for required GitHub settings.
  • Release-age cool-down. The repo-level .npmrc sets min-release-age=7 (days), so CI refuses to install dependency versions published in the last week. This blocks the "same-day malicious re-publish" path that ships post-npm audit-clean PRs into a release tag.
  • Provenance-attested releases. Releases are published by CI (.github/workflows/release.yml) under the @mindstone/ npm scope via Trusted Publishing OIDC — no long-lived npm token exists anywhere — with --provenance Sigstore attestations consumers can verify via npm audit signatures. Every publishable release commit must carry a Release-Gate trailer pointing at its pre-release security review, and every publish posts an alert; the full gate chain is in docs/PUBLISH_APPROVAL_PROCESS.md. (Only a brand-new connector's first publish is manual and WebAuthn-gated; those tarballs carry no provenance attestation but remain shasum-verifiable — check out the release commit and run npm pack; see MIGRATION.md.)
  • OpenSSF Scorecard. The repo runs the OpenSSF Scorecard weekly via .github/workflows/scorecard.yml. The report is generated by a third party from the source tree, so every claim above (action pinning, branch protection, token usage, dependency hygiene) is independently checked rather than just asserted here. The current score is shown by the badge at the top of this README.

Recommendations for consumers

These connectors are published as plain npm packages. The strongest single thing you can do to protect yourself from a future supply-chain compromise of any npm package (these or otherwise) is to use a client that does not run lifecycle scripts by default:

  • pnpm (pnpm install / pnpm dlx) — does not execute postinstall/prepare hooks unless explicitly allowlisted via onlyBuiltDependencies. pnpm v11+ also defaults to a 24-hour minimumReleaseAge cool-down.
  • bun (bunx) — same default, no lifecycle scripts unless allowlisted.
  • npm — if you must use npm, set min-release-age=7 and ignore-scripts=true in your global ~/.npmrc. Requires npm v11.10+ for min-release-age.

None of our published packages need postinstall to function, so disabling lifecycle scripts in your installer of choice is safe.

  • Untrusted-content envelopes. External content from email, helpdesk, and ticketing systems (email-imap, freshdesk, zendesk) is wrapped in <untrusted-content source="..."> envelopes with close-tag breakout escaping, so an LLM host can recognise and refuse instruction-injection attempts.
  • Workspace sandboxing. File-uploading connectors (nano-banana, pandadoc, elevenlabs) constrain reads to MCP_WORKSPACE_PATH (or os.tmpdir()) with canonical-prefix containment that handles symlinked roots like /tmp → /private/tmp.
  • Secure-by-default writes. Production-impacting writes (QuickBooks invoices/bills/customers/vendors) require an explicit QB_ALLOW_PROD_WRITES=1 opt-in env var; outreach prospect-enrolment and mixmax sequence-recipient tools carry destructiveHint: true so hosts surface confirmation prompts.
  • SSRF & path traversal. Download connectors (napkin, runway) enforce host allow-lists, manual-redirect handling, and symlink-safe write paths under a configurable root.
  • Loopback OAuth bind. Connectors with local OAuth callback servers (salesforce, outreach) hard-code 127.0.0.1, ignoring any MCP_OAUTH_BIND_HOST override.
  • E.164 validation. Outbound phone-call tools (retell-ai) reject non-E.164 numbers before any upstream API call.

For per-connector security notes, see each connector's README.

To report a vulnerability, please see SECURITY.md.

The Mindstone open-source family

This repo is one of several open-source projects from Mindstone:

  • Rebel — the AI workspace desktop app that ships these connectors out of the box (source release in progress).
  • Super-MCP — a proxy MCP router that loads only the tools you actually need, saving your context window.
  • rebel-system — the public Rebel system: skills, prompts, operators, help docs, and templates.
  • meeting-note-recorder — meeting detection, recording, and live transcripts (the Rebel note-taker).

Licence

Each connector is licensed under FSL-1.1-MIT — see the LICENSE file in each connector directory for details.

Related MCP servers

FAFathom logo

Fathom

Active

Access Fathom AI meeting transcriptions, search meetings, and manage teams via MCP

10
TypeScript
View repository →
FRFreshdesk logo

Freshdesk

Active

Manage Freshdesk helpdesk tickets, search support requests, reply to customers, and add internal notes.

10
TypeScript
View repository →
GAGamma logo

Gamma

Active

Create AI-powered presentations, documents, webpages, and social posts via Gamma

10
TypeScript
View repository →

Discover GA4 accounts, explore schemas, and run analytics reports via Google Analytics API

10
TypeScript
View repository →

Access Gmail, Calendar, Drive, Docs, Sheets, Slides, Contacts, and more via Google Workspace with host-orchestrated OAuth.

10
TypeScript
View repository →
HUHubSpot logo

HubSpot

Active

Manage HubSpot CRM contacts, deals, tickets, and workflows with multi-account OAuth integration.

10
TypeScript
View repository →