Skip to main content
Glama

mail_send

Send an email through Mail.app, verifying delivery in Sent or Outbox. Multi-recipient sends require confirm=true; dry_run previews are not deliveries.

Instructions

Send an email through Mail.app. Success means the message was verified in Sent or is still in Outbox (still sending) — AppleScript send returning is not enough. Sending to more than one recipient in total (to + cc + bcc) requires confirm=true. dry_run and unconfirmed multi-recipient calls are not deliveries (MCP isError). A send hang is a timeout, not TCC, unless Mail reports -1743/-10004; hang recover matches To+subject (Message-ID when available), never subject alone. Clients must Sent-check before retrying a timed-out send.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
ccNoCC email addresses
toYesRecipient email addresses (required, at least one)
bccNoBCC email addresses
bodyYesMessage body (required)
confirmNoRequired for deletes and multi-recipient sends; without it the call only previews
dry_runNoPreview only: report what would happen and change nothing (default false)
subjectYesSubject line (required)
body_formatNoPlain text (default) or HTML. HTML is tag-stripped; the body is pasted into Mail's compose window (System Events focus on the message body, then Cmd-A and clipboard paste). AppleScript content/html content is not set because it quote-wraps the Sent body

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observedv3.0.8

TDQS

A4.1/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations, the description carries the full behavioral burden and does so thoroughly. It discloses success verification criteria (Sent or Outbox, not merely AppleScript return), multi-recipient confirm requirements, dry_run and unconfirmed non-delivery semantics, timeout vs. TCC error codes (-1743/-10004), hang recovery matching rules, and the need for a Sent-check before retry.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is front-loaded with the core purpose and contains no filler. It packs many distinct operational rules into a dense paragraph, which slightly reduces scannability, but every sentence adds necessary information for correct invocation.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given the complexity of sending mail, the absence of annotations, and the lack of an output schema, the description is complete for an agent to call the tool correctly. It covers success, failure, required flags, timeout recovery, and retry prerequisites, so little critical context is missing.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so the baseline is 3. The description adds meaning beyond the schema by specifying that multi-recipient means more than one recipient in total (to + cc + bcc) and that dry_run and unconfirmed multi-recipient calls are non-deliveries returned as MCP isError. These are useful semantic extensions for confirm and dry_run.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb and resource: 'Send an email through Mail.app.' The operational constraints are immediate and unambiguous. It does not explicitly differentiate itself from sibling send tools such as messages_send, mail_draft, or mail_reply, so it falls short of a 5.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Provides clear rules for confirm=true on multi-recipient sends and describes dry_run and unconfirmed calls as non-deliveries. It also warns about retrying timed-out sends. However, it never says when to choose mail_send over sibling tools like mail_draft, messages_send, or mail_reply, so usage guidance for tool selection is only implied.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.