Zero mail retention
Messages, subjects, attachments and contacts are fetched from your provider when you ask and never written to disk. There is no access log and no body log. Sessions live in memory and disappear on restart.
Free hosted service or self-hosted. Open source, MIT licensed.
MailMCP connects the IMAP, POP3 and SMTP accounts you already have to Claude, Cursor and any other MCP client. Mail is read on demand and never saved. Use the free hosted service, or run it on your own machine or domain.
Free for everyone. No card, no trial. Already have an account? Sign in
Ask your assistant to open MailMCP using
web_open.
We connect your existing accounts. We do not provide email addresses.
Anything urgent from my accountant this week?
messages_search
from accountant, last 7 days, unread
messages_read
message 4821, 9 KB
One message needs you: the Q3 filing is due Friday. Want me to draft a reply for your review?
CONNECT YOUR ASSISTANT
Copy this prompt into Codex or your MCP-compatible assistant. It includes the setup steps and the browser sign-in you need to complete.
Already have a MailMCP account? Use the same login to keep your connected mailboxes. Enter mail passwords in the web panel, never in the chat.
Server URLhttps://mailmcp.org/mcp
Adding the server and signing in are separate steps. If it is already added, run this in a terminal on the same computer as your Codex client:
codex mcp login mailmcp --scopes openid,mailmcp
Keep the command running. Open the authorization link it displays, sign in and accept access. Opening mailmcp.org on its own does not authorize Codex. In the app or IDE, use MCP settings → Authenticate instead.
Using SSH, a container or a cloud agent? A localhost callback points to the machine running the command. Run login on your own computer when Codex runs there; for a remote client, follow the callback instructions in the guide. Never paste callback codes or tokens into chat.
Full setup and troubleshooting guide (EN / ES) · Official Codex documentation
Messages, subjects, attachments and contacts are fetched from your provider when you ask and never written to disk. There is no access log and no body log. Sessions live in memory and disappear on restart.
Whether you use the free hosted service or your own server, the only thing kept is your connection settings, encrypted with AES-256-GCM. No analytics, no tracking pixels, no third-party scripts, and email renders as plain text so remote images never load.
Every line is public under the MIT license. Read the threat model, run the test suite, fork it, or host it for your team. There is no closed component and no upsell.
Create a free account on the hosted service, or clone the repository and run it as a local MCP server or as a Docker deployment on your own domain.
Ask your assistant to open MailMCP with the tool
web_open
and add your IMAP, POP3 or SMTP settings in the browser. Credentials never enter
the chat transcript.
Triage the inbox, find an attachment, flag what matters, or draft a reply. Sending and moving mail always wait for your confirmation.
Every tool runs as the authenticated user. None of them accepts another owner's ID, and the ones that send or move mail wait for your confirmation.
accounts_listaccounts_addaccounts_updateaccounts_removeaccounts_verifyfolders_listfolders_createmessages_listmessages_searchmessages_readmessages_flagmessages_movemessages_sendmessages_replyattachments_listattachments_downloadweb_openweb_revoke_sessionsHosted by us
No card, no trial, no plan to choose. Sign in, connect the accounts you already have and start asking your assistant. It runs the exact code published in the repository, at mailmcp.org, on a server we operate.
Hosted by you
Run it as a local MCP server on your laptop, or deploy the Docker image on your own domain behind your own identity provider. Nothing is held back for a paid tier, because there is none.
Your assistant talks to MailMCP. MailMCP talks to your mail provider over verified TLS. Nothing sits in between, and nothing stays behind.
| Stored | Never stored |
|---|---|
| Connection settings for each account, encrypted with AES-256-GCM under a key you hold | Message bodies, subjects or headers |
| Hashed session tokens in memory, valid for one hour and revocable at any time | Attachments, contacts or search history |
| Your language preference, in your own browser | Access logs, analytics or tracking identifiers |
Not end-to-end encrypted, and we say so plainly: whoever runs the server and holds the master key can decrypt the vault. When you self-host, that person is you. Read the full threat model
Claude Desktop, Claude Code, Cursor, VS Code, Windsurf and any client that speaks the Model Context Protocol, over local stdio or authenticated HTTPS.
Gmail, Outlook, iCloud, Fastmail, Proton through Bridge, your company's mail server, or any provider offering IMAP, POP3 or SMTP with an app password.
No. Messages are fetched from your provider when you or your assistant ask for them and are held in memory only for that request. Nothing about your mail is written to disk or logged.
Only the settings needed to connect: server, port, username, app password, label and sender name. They live in a vault encrypted with AES-256-GCM under a 256-bit master key held by the operator. Sessions are kept in memory and expire after an hour.
Yes. The full source is on GitHub under the MIT license, including the web client, the MCP server, the deployment templates and the test suite.
Yes. The hosted service is free for everyone, with no card, trial or paid tier. You sign in, connect the accounts you already have and start using it with your assistant. Self-hosting remains available with the same code and features.
It runs the same open-source code with the same rules: mail is fetched live and never written to disk, there is no access or body logging, and only your encrypted connection settings are kept. Removing a connection deletes its credentials immediately. The difference is who holds the master key: the operator on the hosted service, you when you self-host.
Any client that supports the Model Context Protocol, including Claude Desktop, Claude Code, Cursor and VS Code. Locally it runs over stdio; on a domain it exposes an OAuth-protected MCP endpoint.
No. You bring the accounts you already have. MailMCP never sells, provisions or hosts mailboxes.
Not without you. Sending and moving mail require an explicit confirmation, and the server instructs assistants to treat email content as untrusted data, never as instructions.
No. The server process decrypts credentials to log in to your provider, so whoever operates it and holds the master key could read them. Self-hosting keeps that person you.
Create a free account on the hosted service and connect your accounts in the browser, or clone the repository and add it to your MCP client, or deploy the Docker image behind the included Caddy configuration with your own OIDC provider. The hosting guide covers self-hosting.
Free on the hosted service, or on your own server in a few minutes.
Select a message to open it.