smtp-mcp-wrapper
Sends real HTML email through Gmail's SMTP relay, allowing MCP clients to send emails using a Gmail account.
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@smtp-mcp-wrappersend an email to user@example.com with subject 'Update' and body 'All good'"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
smtp-mcp-wrapper
A minimal, self-hosted MCP server that exposes a
single send_email tool. It sends real HTML email through an SMTP relay (e.g. Gmail).
The tool is served over the streamable-HTTP MCP transport at /mcp, with an
unauthenticated /healthz liveness route. The implementation is intentionally tiny
(stdlib smtplib) to keep the audit/attack surface small.
⚠️ Security requirement: this server MUST be gated by an authorization service
This server implements no authentication of its own, by design. Anyone who can reach
/mcp can send email. Do not expose it directly to the internet or bind it to a public
port.
It must sit behind an identity-aware authorization proxy — such as
Pomerium in MCP mode, or an
equivalent like Cloudflare Access
or oauth2-proxy — that authenticates and
authorizes every request before it reaches /mcp.
Reference topology:
edge tunnel → reverse proxy (TLS) → Pomerium (SSO + allowlist to a single identity) → smtp-mcp-wrapper
(internal network only)The provided docker-compose.yml deliberately publishes no host ports and attaches
the container only to the proxy's internal Docker network, so the server is unreachable
except through the authorization proxy.
Defense in depth already built in (these complement, they do not replace, the proxy):
ALLOWED_TOhard-limits recipients, so even a misused tool cannot mail outside the allowlist.Setting
REQUIRE_POMERIUM_IDENTITY=truemakes the app cryptographically verify Pomerium's identity assertion on every/mcprequest — signature (against Pomerium's JWKS), expiry, and audience. This blocks anything on the shared Docker network from reaching the app directly and bypassing Pomerium. See Enabling app-layer verification.
Related MCP server: Mail MCP Server
Configuration
All configuration is via environment variables. Copy .env.example to .env and fill in
real values. .env is git-ignored and must stay that way — it holds the SMTP password.
Nothing secret is baked into the image (credentials are injected at runtime), which is why
the published container image can safely be public.
Variable | Default | Description |
|
| SMTP relay host. |
|
| SMTP relay port (STARTTLS). |
| — | SMTP username. |
| — | SMTP password. For Gmail, use an App Password. |
|
| From address. |
| — | Optional display name for the From header. |
| — | Recipient used when the tool's |
| — | Comma-separated recipient allowlist. Empty = any recipient allowed. |
|
| Send a test email to |
|
| Verify Pomerium's identity assertion on every |
| — | Pomerium's JWKS endpoint, e.g. |
| — | Expected |
| — | Expected |
|
| Comma-separated header(s) carrying the assertion JWT. |
| — | Comma-separated |
|
| Comma-separated |
|
| Server bind address/port. |
The send_email tool
send_email(subject: str, html: str, to?: str, text?: str) -> strSends an HTML email. to falls back to DEFAULT_TO and must be within ALLOWED_TO when
that allowlist is set. text is an optional plain-text alternative for non-HTML clients.
DNS-rebinding guard (Host allowlist)
MCP SDK 2.x checks the Host header on every /mcp request and answers 421 Misdirected
Request when it is not allowlisted (CVE-2025-66416 made this on by default). This
server leaves it off unless MCP_ALLOWED_HOSTS is set, so an SDK upgrade alone can
never take a working deployment offline — you opt in.
⚠️ The allowlist is not your public hostname. Pomerium — like most reverse proxies by default — rewrites
Hostto the upstream address before forwarding. The route may behttps://email-mcp.example.com, but what the container receives isHost: email-mcp:8080. Allowlisting the public name still 421s.
Find what actually arrives rather than guessing: in Pomerium's access log, the authority
field on the http-request line is the Host the upstream sees (the host field on the
authorize check line is the public route). This varies per route in the same Pomerium
instance, so check this one.
MCP_ALLOWED_HOSTS=email-mcp:8080Then redeploy and confirm the startup line names it:
DNS-rebinding guard enabled — allowed hosts: email-mcp:8080; ...
INFO: Uvicorn running on http://0.0.0.0:8080Matching is literal — a bare example.com will not match a Host carrying a port; use
example.com:* for any port. Alternatively set preserve_host_header: true on the
Pomerium route and allowlist the public name instead.
Verify with a real tool call, not the healthcheck. /healthz is not behind the guard,
so a container answering healthy proves nothing — a misconfigured allowlist shows up only
as a 421 on POST /mcp. scripts/smoke_test.sh automates exactly this check and runs in
CI before any image is pushed.
Enabling app-layer verification
This step is optional — Pomerium already gates all access. Enable it only if you also
want the app to reject any request that reaches it without a valid Pomerium identity
(e.g. a compromised neighbor on the shared Docker network hitting email-mcp:8080
directly). When on, the app verifies the assertion JWT's signature, expiry, and audience.
1. Pomerium — set these on the email-mcp route. The critical addition is
pass_identity_headers: true; without it Pomerium forwards no identity header and the app
rejects every request. Pomerium must also have a signing key configured (it serves the
matching public keys at /.well-known/pomerium/jwks.json).
routes:
- from: https://email-mcp.example.com
to: http://email-mcp:8080 # pathless — the /mcp path passes through
name: email-mcp
mcp:
server: {}
pass_identity_headers: true # <-- REQUIRED: sends X-Pomerium-Assertion to the app
policy:
- allow:
and:
- email:
is: you@example.com2. App — set these in .env:
REQUIRE_POMERIUM_IDENTITY=true
POMERIUM_JWKS_URL=https://email-mcp.example.com/.well-known/pomerium/jwks.json
POMERIUM_AUDIENCE=email-mcp.example.comThen docker compose up -d. If REQUIRE_POMERIUM_IDENTITY=true but POMERIUM_JWKS_URL is
unset, the server refuses to start (a security gate must not run unable to verify). To turn
the feature off again, set REQUIRE_POMERIUM_IDENTITY=false.
Run
cp .env.example .env # then edit .env with real values
docker compose up -dHealth check:
docker compose exec email-mcp \
python -c "import urllib.request; print(urllib.request.urlopen('http://localhost:8080/healthz').read())"
# -> b'ok'Then add the email-mcp route to your authorization proxy (pathless upstream, e.g.
to: http://email-mcp:8080, so the /mcp path passes through) and connect your MCP
client to https://<your-host>/mcp.
Maintenance
Patches flow with near-zero manual effort:
Dependabot (
.github/dependabot.yml) watchesrequirements.txt, the Dockerfile base image, and the workflow's actions, opening upgrade PRs weekly. Also enable Dependabot security updates in the repo's Settings → Code security.CI (
.github/workflows/build.yml) builds and pushes the image to GHCR on push tomain, on Dependabot PRs, via manual dispatch, and weekly (Mon 06:00 UTC) withno-cacheso the OS and Python patches are genuinely refreshed even without code changes.Smoke test (
scripts/smoke_test.sh) runs against the built image before the push step, driving a real MCPinitialize+tools/listover a non-localhostHost. This is what makes an unattended SDK bump safe to merge: the failures an MCP SDK upgrade actually causes — binding the wrong interface, or aHostallowlist that rejects the proxy — produce an image that builds and reports healthy while every tool call fails, so a build-only gate would wave them straight through. Run it locally with./scripts/smoke_test.sh <image>.On the host, pull the rebuilt image with Watchtower (the compose file already sets the opt-in label) or a cron running
docker compose pull && docker compose up -d.
Links
Pomerium — MCP support
Pomerium — Protect an MCP server
This server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
AlicenseDqualityDmaintenanceAn MCP server implementation that allows sending emails over MailPace's fast transactional email API.Last updated11MIT- Alicense-qualityDmaintenanceAn MCP server that provides email sending capabilities via SMTP, featuring tools for sending standard and template-based emails. It utilizes the FastMCP Streamable HTTP transport for flexible client connectivity over HTTP without requiring stdio subprocesses.Last updated5MIT
- Flicense-qualityBmaintenanceA minimal MCP server for reading and sending emails via IMAP/SMTP, supporting multiple accounts in a single instance with zero external dependencies.Last updated1
- Alicense-qualityDmaintenanceA production-ready MCP server that empowers AI agents to securely send emails via SMTP, supporting plain text, HTML, and attachments.Last updatedMIT
Related MCP Connectors
A basic MCP server to operate on the Postman API.
MCP server exposing the Backtest360 engine API as tools for AI agents.
Hosted email MCP for AI agents with inboxes, send/receive, memory, recovery, and credits.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/JB09/smtp-mcp-wrapper'
If you have feedback or need assistance with the MCP directory API, please join our Discord server