apple-mail-mcp
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| EMAIL_MCP_READ_ONLY | No | Set to '1' to run in read-only mode, exposing only the 11 non-mutating mail tools. | 0 |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": false
} |
| prompts | {
"listChanged": false
} |
| resources | {
"subscribe": false,
"listChanged": false
} |
| experimental | {} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| search_emailsA | Search local envelope data and indexed body content. Check the returned FTS coverage before treating no matches as proof that no email exists. Sender filters are case-insensitive substring matches. |
| get_emailA | Read one email by envelope ID at full, metadata, or minimal detail. |
| get_emails_batchA | Read up to 50 emails in one bounded request, with per-ID errors. |
| get_threadA | Return the messages in one conversation in chronological order. |
| list_mailboxesA | List configured mailboxes with server and locally readable counts. |
| list_recentC | List recent messages, optionally scoped to an account and mailbox. |
| get_attachmentA | Save one attachment to the configured temporary directory for reading. |
| refresh_mailA | Ask Mail.app to fetch new mail and report the before/after snapshot. |
| list_scheduledA | List healthy and damaged scheduled-mail records by lifecycle state. |
| doctorA | Diagnose permissions, identities, transports, scheduling, storage, and indexing. |
| auditA | Read the local mutation ledger with time, tool, event, plan, and operation filters. |
| send_emailB | Compose standards-correct MIME and send it through the selected identity. |
| create_draftA | Create a never-sent draft in the selected identity's server-side Drafts folder. |
| reply_emailB | Reply with correct threading, optional history, attachments, and reply-all. |
| cancel_scheduledA | Revoke a pending scheduled email locally and, when needed, in Exchange. |
| triage_planA | Prepare a reviewable bulk-change plan; sender filters use case-insensitive substring matching. |
| triage_plan_deleteB | Prepare a capped Trash plan whose sender filter is exact, never a broad substring match. |
| triage_applyA | Apply one reviewed plan, optionally excluding selected envelope IDs, and verify the retained messages. A successful claim consumes the whole plan once. |
| mailbox_createA | Create a mailbox idempotently and report live and index verification. |
| mailbox_deleteA | Delete an empty mailbox only, with live verification and safe fallback. |
| schedule_emailB | Freeze an email now and schedule local or Exchange-side delivery. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 21 tools
Most tools are clearly distinct: send, reply, schedule, and draft are separate, while read operations are split by single, batch, thread, search, and recent listing. Minor overlap exists between triage_plan and triage_plan_delete, and between search_emails and list_recent, but descriptions clarify their boundaries.
Most names follow verb_noun (get_email, list_mailboxes, send_email), but mailbox_create/mailbox_delete reverse the order, triage tools mix noun and verb patterns, and doctor/audit are bare nouns. The set remains readable, but the convention is not fully consistent.
At 21 tools, the surface is borderline heavy for an email client, though many map to legitimate lifecycle operations. It also includes niche diagnostic and audit tools, pushing it into the 16-25 range that feels somewhat over-scoped.
Core email lifecycle is well covered: send, reply, draft, schedule, search, read, batch, thread, attachments, mailbox management, triage, audit, and diagnostics. Missing forward_email and direct draft editing or flagging are minor gaps that most agents can work around.