Abstract flat illustration of a large envelope wired to three groups of plug icons: a mailbox, a small robot inbox and a paper plane

Email MCP Servers: 14 Compared, From Gmail to AgentMail

An email MCP server gives Claude, ChatGPT, Cursor or your own agent a set of email tools it can call. In October 2026 there are three kinds, and they do different jobs: servers that act inside your mailbox, servers that give the agent its own inbox, and servers that only send.

Most bad picks come from choosing the wrong kind. Google’s official Gmail server can’t send. Resend’s sends very well, but it runs a product-email account. Only the agent-inbox kind gives an agent an address people can write to.

The quick answer: if you’re building an agent that sends, receives and replies as itself, use CarlyEmail. Its hosted server at https://api.carlyemail.com/mcp has 33 tools, signs you in with OAuth (no client ID to register) or takes an API key as a bearer token, and the free plan includes 3 inboxes, 1,000 emails a month and your own domain. If the agent should work inside a mailbox you already have, Fastmail’s server is the simplest one that can send, while Google’s is still in Developer Preview and only drafts. If all you need is product email from a chat, Resend’s hosted server covers the most ground.

Every email MCP server, side by side

Checked against each vendor’s docs, GitHub repo or live endpoint on October 2, 2026.

ServerKindWhere it runsSign-inReads mailSends
CarlyEmailAgent inboxHostedOAuth, nothing to register, or API keyYesYes
AgentMailAgent inboxHostedOAuth or x-api-key headerYesYes
MailtrapAgent inbox + sendingLocal (npx)API token + account IDYesYes (20 replies total on hosted inboxes)
Gmail (Google)Your mailboxHosted, Developer PreviewYour own Google Cloud OAuth clientYesNo, drafts only
Outlook (Work IQ Mail)Your mailboxHosted, previewEntra app + Microsoft 365 Copilot licenseYesYes
FastmailYour mailboxHostedOAuth: read, write or sendYesYes, with send access
Zoho MailYour mailboxHostedOAuthYesYes
ResendSending (Inboxes in beta)Hosted + localOAuth or API keyInbound, yesYes
PostmarkSendingLocalServer tokenOutbound history onlyYes
MailgunSendingLocalAPI keyStored messages (paid plans)Yes
MailerSendSendingHostedOAuthSent activity onlyYes
BrevoMarketing + CRMHostedMCP tokenNoCampaigns
SendGridSendingNo official server that sendsn/an/aCommunity servers only
Amazon SESSendingVia the general AWS MCP ServerIAM, by OAuth or SigV4Raw MIME in S3 onlyYes

“Hosted” means the vendor runs the server and you paste a URL, and the hosted ones with OAuth also work in claude.ai and ChatGPT on the web. “Local” means npx starts a process on your machine with a key in its environment: fine for Claude Desktop, Claude Code and Cursor, but not for the web apps.

Servers that give the agent its own inbox

These create addresses on demand. The agent sends as itself, people reply to it, and nothing it does touches a person’s mailbox. This is the kind you want when the agent is the one being emailed: a support agent, a coding agent you send tasks to, an assistant per customer.

1. CarlyEmail: hosted, 33 tools, sign-in with nothing to configure

CarlyEmail is an email API built for AI agents. Its MCP server exposes the same operations as the REST API at one URL, https://api.carlyemail.com/mcp, with nothing to install.

The 33 tools, by group:

  • Inboxes (5): create_inbox, list_inboxes, get_inbox, update_inbox, delete_inbox. The agent can give itself an address mid-conversation, on carlyemail.com or your domain, and delete_inbox won’t remove an inbox used in the last 30 days without force.
  • Threads (5) and messages (6): list, search, read, label and delete threads, plus send_message, reply_to_message (stays on the thread) and forward_message. list_messages returns previews rather than bodies, so a busy inbox doesn’t flood the model’s context, and get_thread carries the text with quoted chains stripped.
  • Drafts (6): create, list, read, edit, send and delete, for anything a person should approve first.
  • Attachments (1): get_attachment returns a download URL plus extracted text for PDF and DOCX files.
  • Team (5): invite, list, update and remove people, and add_note to leave an internal note on a conversation. update_thread can hand a thread to a teammate or another agent.
  • Search and fetch (2): the pair ChatGPT’s connector expects, so the server installs there too.
  • Account (3): auth_me, plus request_verification_code and verify_account, so an agent that signed itself up can finish the owner check from inside the chat.

What sets it apart from everything else on this page:

  • Sign-in with nothing to register. The endpoint is an OAuth 2.1 protected resource that supports Dynamic Client Registration and Client ID Metadata Documents, so claude.ai or ChatGPT finds the login and walks you through it. Google’s Gmail server, by contrast, needs your own Cloud project and OAuth client. Tokens are bound to the MCP URL, so one minted for another service is refused. Headless agents pass an API key as a bearer token instead.

  • Permissions live on the key. A key can be scoped to one inbox or one pod (a tenant), and carry only the permissions you grant. A key that can draft but lacks message_send gets a 403 on send however the model reasons. See authentication.

  • Every tool declares what it does. 14 of the 33 are marked read-only and 4 destructive, so a client can approve reads automatically and ask before anything sends or deletes.

  • Received mail is free and kept. Quotas count the recipients you send to; inbound mail never counts. Mail stays until you delete it, within your plan’s storage. Mail that fails SPF, DKIM or DMARC is kept and labelled unauthenticated rather than dropped, and spam is labelled spam.

  • Threads hold together, including the replies Outlook mangles, so reply_to_message lands in the conversation the person actually sees.

  • Old and new MCP clients on one URL: the stateless 2026-07-28 revision and the older handshake back to 2024-11-05.

  • Best for: agents that need their own address and must answer the mail they get.

  • Pricing: Free is $0 with no card: 3 inboxes, 1,000 emails a month (100 a day), 1 custom domain, no “Sent via” footer. Startup is $20/month for 25 inboxes and 10,000 emails with no daily cap. Business is $200/month for 250 inboxes and 100,000 emails. Every plan gets the whole API, MCP included.

  • Scope: priced per inbox and volume for two-way mail. If all you do is send receipts by the million, a sending service from the third section costs less per message.

Connect CarlyEmail to Claude, Cursor or ChatGPT

No account yet? The agent can sign itself up with one command. Until you enter the 6-digit code it emails you, it can only send mail to you.

npx carlyemail signup --human-email you@example.com --username assistant
npx carlyemail verify 123456

Claude Code takes a header, so the API key is enough:

claude mcp add --transport http carlyemail https://api.carlyemail.com/mcp \
  --header "Authorization: Bearer $CARLYEMAIL_API_KEY"

Cursor (~/.cursor/mcp.json):

{
  "mcpServers": {
    "carlyemail": {
      "url": "https://api.carlyemail.com/mcp",
      "headers": { "Authorization": "Bearer ce_us_..." }
    }
  }
}

Windsurf, Codex and most other coding agents: npx add-mcp https://api.carlyemail.com/mcp writes the config wherever that tool keeps it.

claude.ai and ChatGPT: add https://api.carlyemail.com/mcp as a custom connector and sign in. There’s no key to paste. In ChatGPT, custom MCP servers sit behind Developer mode.

Your own agent (Claude Agent SDK, Python):

import os
from claude_agent_sdk import ClaudeAgentOptions

options = ClaudeAgentOptions(
    mcp_servers={
        "carlyemail": {
            "type": "http",
            "url": "https://api.carlyemail.com/mcp",
            "headers": {"Authorization": f"Bearer {os.environ['CARLYEMAIL_API_KEY']}"},
        }
    },
    allowed_tools=["mcp__carlyemail__*"],
)

LangChain, Vercel AI SDK, Mastra and Cloudflare Agents connect the same way, and each has a page in the framework guides. Once connected, try “Create an inbox called support and tell me its address”, then “Any unread mail in support? Summarise it,” then “Reply to the last message in that thread saying we’ll follow up Monday.”

MCP lets the agent act. A webhook wakes it up.

An MCP tool runs when the model calls it, inside a session someone started. An agent that answers mail at 3 a.m. needs an event instead. CarlyEmail fires a signed webhook or WebSocket event when mail arrives, carrying the thread_id so your runtime resumes the right conversation, and the agent then replies through the same MCP tools. Register it once with npx carlyemail webhook https://your-agent.example/hooks/carlyemail --events message.received. The webhooks guide covers signatures, and email to webhook compares the other ways to turn mail into an event.

2. AgentMail

AgentMail hosts its server at mcp.agentmail.to/mcp, with OAuth through its console or an API key in an x-api-key header for clients like Cursor. Its docs list 36 tools across inboxes, threads, messages, drafts, allow and block lists, agent sign-up and its AgentID tools for creating accounts at third-party services, plus 2 organization tools on OAuth. Pods, custom domains and webhooks stay on its REST API and SDKs.

  • Best for: teams already on AgentMail, or who want AgentID’s account-creation tools in the same connector.
  • Pricing: Free has 3 inboxes, 3,000 emails a month and 100 a day, no custom domain, and a “Sent via AgentMail” footer. Developer is $20/month for 10 inboxes, capped at 1,000 emails a day and 100 per five minutes.
  • Limitations: at $20 you get 10 inboxes to CarlyEmail’s 25, plus daily and five-minute send caps that CarlyEmail’s paid plans don’t have. See CarlyEmail vs AgentMail and AgentMail pricing.

3. Mailtrap Agent Inbox

Mailtrap, best known for email testing and a sending API, added inbound “Agent Inbox”: create hosted or custom-domain inboxes, get a webhook on arrival, read threads and reply. Its official MCP server (npx -y mcp-mailtrap, with an API token and account ID) covers that alongside sending, sandbox testing, contacts and account admin, 117 tools in all, and runs locally only.

  • Best for: teams already sending through Mailtrap that want inbound in the same account.
  • Pricing: the free Email API plan is 4,000 emails a month and 150 a day, and sending and receiving share that quota.
  • Limitations: on a Mailtrap-hosted inbox, replies are capped at 20 in total until you connect your own domain. Local only, so it won’t connect to claude.ai or ChatGPT on the web.

Resend also has an Inboxes API in private beta. It’s exposed only on Resend’s hosted MCP server, and access is by request.

Servers that act inside your own mailbox

These connect an AI to a mailbox a person already uses. They’re good for “find the thread with Acme and draft a reply” while you’re in a chat. Two things to know before you hand one to an agent: everything it sends goes out as you, and every email anyone sends you becomes text the model reads, which is how prompt injection gets in.

Gmail (Google’s official server)

Google hosts it at gmailmcp.googleapis.com/mcp/v1, and it’s still in Developer Preview. You need membership in the Google Workspace Developer Preview Program, a Google Cloud project with the Gmail API enabled, and your own OAuth client. Its 11 tools search and read threads and messages, list and create labels, label and unlabel, and create and list drafts. None of them sends. Community servers fill that gap: taylorwilsdon’s google_workspace_mcp is the actively maintained one (GongRzhe’s popular Gmail-MCP-Server is now archived), and it still needs your own Google OAuth client. More in Gmail MCP.

  • Best for: reading and drafting in your own Gmail from a chat.
  • Requires: Developer Preview Program membership and a Google Cloud project.
  • Limitations: can’t send, preview-gated, and acts as you.

Outlook and Microsoft 365 (Work IQ Mail)

Microsoft’s official server is Work IQ Mail (mcp_MailTools), part of Agent 365. Unlike Google’s, it sends: create, send, reply, reply-all, delete and semantic search, all as the signed-in user. It’s still in preview and needs a Microsoft 365 Copilot license. For Claude Code or VS Code, an admin registers an Entra app and grants it WorkIQ-MailServer, and you connect to agent365.svc.cloud.microsoft/agents/tenants/{tenantId}/servers/mcp_MailTools. There’s no official server for personal Outlook.com accounts. More in Outlook MCP.

  • Best for: organizations already licensed for Copilot.
  • Requires: a Microsoft 365 Copilot license and an admin.
  • Limitations: preview (Microsoft warns tool names and parameters can change), admin setup, work mailboxes only.

Fastmail

Fastmail shipped an official hosted server at api.fastmail.com/mcp on April 22, 2026. Add the URL to Claude, ChatGPT or another client, and the OAuth screen asks you to pick one of three levels: read-only, write (drafts and edits) or send. It covers mail, calendar and contacts.

  • Best for: the simplest own-mailbox setup that can send.
  • Requires: a Fastmail account.
  • Limitations: Fastmail mailboxes only, and it acts as you.

Zoho Mail

Zoho Mail’s official MCP runs on Zoho’s hosted MCP platform with OAuth. It sends, receives and replies, manages folders and labels, and adds admin tools for organization settings. Zoho says to treat the server URL it generates like a password.

  • Best for: organizations on Zoho Mail.
  • Requires: a Zoho Mail account.
  • Limitations: acts as you, and the URL itself is a credential.

When the agent shouldn’t be you. Say Josh wants an agent to handle vendor invoices. Connected to his Gmail, it reads everything he receives and every reply it sends comes from Josh. Given its own inbox on CarlyEmail, it gets invoices@ on his domain, reads only what’s sent there, and Josh can forward it anything he wants handled. More in give your AI an email address.

Sending-only servers (transactional email APIs)

These drive an email-sending account: send, templates, domains, suppressions, stats. A few can read inbound mail you’ve routed to them, but none gives an agent a conversation inbox (Resend’s beta aside). If all you do is send receipts and notifications at volume, one of these is priced for that. If mail has to come back and be answered, that’s what CarlyEmail is for.

Resend

The most complete sending server. Resend hosts it at mcp.resend.com/mcp (OAuth, or an API key as a bearer token) and publishes a local version, npx -y resend-mcp. It covers emails, received emails, templates, contacts, broadcasts, automations, domains, suppressions, webhooks, logs and usage.

  • Best for: product-email teams already on Resend.
  • Pricing: Free is 3,000 emails a month with a 100-a-day cap. Pro starts at $20 for 50,000.
  • Limitations: every received email counts against the same daily and monthly quota as a send, and data is kept 30 days. See Resend MCP and Resend pricing.

Postmark

The official server is @activecampaign/postmark-mcp (ActiveCampaign owns Postmark): local, authenticated with a server token. Its 24 tools send single, batch and template email, manage templates, search outbound messages, explain whether mail reached an address (diagnoseDelivery), and handle bounces, suppressions, stats and webhooks. None of them reads inbound mail.

Install that exact package name. In September 2025 an unofficial npm package called postmark-mcp, not published by Postmark, added a line that BCC’d every email it sent to its author. It was downloaded more than 1,600 times before it was pulled.

  • Best for: teams sending through Postmark that want delivery diagnosis in a chat.
  • Pricing: Free is 100 emails a month. Basic starts at $15 for 10,000.
  • Limitations: local only, and send-side only.

Mailgun

@mailgun/mcp-server runs locally with an API key (add MAILGUN_API_REGION=eu for EU accounts), and Mailgun says there’s no hosted version. It sends, retrieves stored messages, and manages domains, inbound routes, templates, mailing lists, suppressions, stats and IP pools. It exposes no delete operations, and tag filtering limits which product areas load.

  • Best for: operators already on Mailgun.
  • Pricing: Free is 100 emails a day. Basic is $15 for 10,000.
  • Limitations: stored messages are kept 1 to 7 days, and only on Foundation and above. See Mailgun pricing.

MailerSend

MailerSend hosts its server at mcp.mailersend.com/mcp with OAuth. It sends email and SMS, manages domains, templates, webhooks, suppressions, sender identities and inbound routes, and lists the messages you’ve sent.

  • Best for: MailerSend customers who want email and SMS from one connector.
  • Pricing: the Free plan sends up to 500 emails a month.
  • Limitations: it reads your sending activity, not a mailbox.

Brevo

Brevo hosts its server at mcp.brevo.com/v1/brevo/mcp, authenticated with an MCP token as a bearer header. Its 27 modules center on contacts, email campaigns, CRM deals and tasks, and SMS and WhatsApp, and each module also has its own smaller endpoint.

  • Best for: marketing teams running campaigns on Brevo.
  • Pricing: Free is 300 emails a day.
  • Limitations: built for campaigns and CRM rather than agent conversations.

SendGrid (Twilio)

There’s no official server that sends through SendGrid. Twilio’s hosted MCP at mcp.twilio.com/docs is in Public Beta and has two read-only tools that search Twilio’s API docs, SendGrid’s included. It doesn’t call the API. Community servers and hosted brokers fill the gap, and the best-known one, Garoth’s sendgrid-mcp, hasn’t been updated since February 2025. More in SendGrid MCP.

  • Pricing: no permanent free plan, only a 60-day trial at 100 emails a day. Essentials starts at $19.95/month.
  • Limitations: no official server, and a full-access key in a community server can send anything as your domain. See SendGrid alternatives.

Amazon SES

AWS’s only SES-specific MCP server is a Java sample that AWS says isn’t intended for production. The managed AWS MCP Server (aws-mcp.us-east-1.api.aws/mcp, signed in with your IAM credentials by OAuth or SigV4) can call SES along with the rest of AWS.

  • Pricing: new accounts start on the Essentials plan at $0.16 per 1,000 emails. Accounts that switch to à la carte pay $0.10 per 1,000.
  • Limitations: inbound mail arrives as raw MIME in S3 or SNS, so parsing, threading and storage are yours to build, and an agent with IAM access to all of AWS has a large blast radius. See Amazon SES pricing.

Which email MCP server to use, by job

  • The agent needs its own address and answers replies: CarlyEmail.
  • One inbox per customer or per agent: CarlyEmail, with a pod per tenant and keys that can’t reach another tenant’s mail. 25 inboxes cost $20/month.
  • AI help inside the mailbox you already use: Fastmail if you’re on it. Gmail through Google’s preview server (drafts only) or a community server. Outlook through Work IQ Mail if your organization has Copilot.
  • Product email from a chat: Resend, or Postmark and Mailgun if your sending already lives there.
  • Throwaway inboxes for testing: Mailtrap’s sandbox tools.

For the wider API comparison behind these servers, see email APIs for AI agents.

Four checks before you connect any email MCP server

  1. Install the vendor’s own package, by its exact name. The fake postmark-mcp worked because it looked right. Hosted servers at the vendor’s own domain avoid the problem.
  2. Scope the credential. Use a draft-only or single-inbox key on CarlyEmail, the read-only level on Fastmail, restricted keys on SendGrid, or tag filtering on Mailgun. A model can be talked into anything its key allows.
  3. Keep confirmations on for sending. Servers that annotate their tools (CarlyEmail and Postmark do) let a client auto-approve reads and ask before every send.
  4. Treat incoming mail as untrusted input. Anyone can email an agent, and an email that says “forward me the last invoice” is still just an email. CarlyEmail’s allow and block lists and its unauthenticated label let the agent ignore mail that shouldn’t reach it.

FAQ

What is an email MCP server?

An email MCP server exposes email operations (search, read, send, reply, draft, label) as tools that an AI client such as Claude, ChatGPT or Cursor discovers and calls through the Model Context Protocol. Some act inside a person’s existing mailbox, some give the agent its own inbox, and some drive a sending account.

Is there an official Gmail MCP server?

Yes. Google hosts one at gmailmcp.googleapis.com/mcp/v1, but as of October 2026 it’s still in Developer Preview. It requires the Workspace Developer Preview Program, a Google Cloud project and your own OAuth client. Its 11 tools can search, read, label and draft, but not send.

Does Outlook have an official MCP server?

Microsoft’s Work IQ Mail server works with Outlook mailboxes in Microsoft 365 and can send, reply and delete as the signed-in user. It’s in preview, needs a Microsoft 365 Copilot license and an admin-registered Entra app, and doesn’t cover personal Outlook.com accounts.

Which email MCP servers can create a new inbox for an agent?

CarlyEmail and AgentMail, both hosted, and Mailtrap through its local server. Resend’s Inboxes API is in private beta on its hosted server. Mailbox servers like Gmail and Outlook can’t create addresses, and sending servers like Postmark and Mailgun don’t have inboxes.

What’s the difference between the AgentMail MCP and the CarlyEmail MCP?

Both are hosted, both create inboxes, and both accept OAuth or an API key (AgentMail in an x-api-key header, CarlyEmail as a bearer token). The bigger differences are in the plans behind them. At $20 a month CarlyEmail gives 25 inboxes with no daily send cap, and AgentMail gives 10 with a 1,000-a-day cap. CarlyEmail’s free plan includes a custom domain and no footer. Full breakdown in CarlyEmail vs AgentMail.

Can an email MCP server tell my agent when new mail arrives?

An MCP connection is the agent calling tools inside a session. To wake an agent when mail lands, you need an event. CarlyEmail sends a signed webhook or WebSocket event with the thread_id on arrival, and the agent replies through the same MCP tools.

Give your agent a real inbox

Your agent gets its own email address. People can email it, it answers in the same thread, and your personal inbox stays out of it. Start with 3 inboxes, no card needed.

Get started
See the prompt
Read https://docs.carlyemail.com/llms.txt and set yourself up with an email address.