
mcp4mail
online.mcp4mailv1.0.0更新於 Sep 28, 2026
Your IMAP mailbox as an MCP server: read, search and (if you allow it) organize mail. Open source.
概覽
把 IMAP 信箱接上成為 MCP 伺服器,讓助理讀取、搜尋信件,並在你允許時整理信箱。
- 功能
- 用一組工具連接 IMAP 信箱:列出已連結的帳號與資料夾,依主旨、寄件人、收件人與日期搜尋郵件,讀取單封郵件,下載附件,以及查找往來聯絡人。寫入類工具可以加上標記、搬移、移到垃圾桶、儲存草稿與寄信。變更只對已開啟該權限的信箱生效,send_message 也要等使用者透過連結確認後才會真正寄出。
- 適用情境
- 適合讓助理搜尋、分類或摘要現有信箱,或起草回信。也適合先只開放讀取與搜尋、再自行決定是否允許變更的情況。想讓 IMAP 憑證留在自己伺服器上的人則可自行架設。
- 執行需求
- 需要以 OAuth 2.1 授權的遠端端點,以及一組提供使用者名稱與密碼的 IMAP 帳號(建議使用應用程式專用密碼)。自行架設需要 Docker Compose、PostgreSQL,以及存放信箱密碼加密金鑰的環境變數。
安裝
在 SourceWeft 中
- 開啟 儀表板中的 mcp4mail,將其新增到工作區。
- 為需要使用其工具的對話啟用該服務。
Web executable,透過 Streamable HTTP。 遠端服務在工作區中設定後即可從網頁執行環境執行。
其他 MCP 客戶端
把它新增到你客戶端的 mcpServers 設定中。
{
"mcpServers": {
"mcp4mail": {
"type": "http",
"url": "https://mcp4mail.online/mcp"
}
}
}README
mcp4mail
Your mailbox as an MCP server. Connect an IMAP account and let your AI assistant read and search your mail, authorized over OAuth 2.1. Hosted at mcp4mail.online, open source and self-hostable.
Run it yourself and your credentials never leave your machine. A hosted mail connector necessarily keeps
your IMAP password on someone else's server; with mcp4mail you can keep it in your own database instead. One
docker compose up gets you there: see the self-hosting guide.
Early days: the MCP endpoint lists your connected accounts; reading and searching mail is next.
This project is primarily developed by AI developers orchestrated through mcptask.online. Watch the development happen live: https://mcptask.online/live
How this project is built
This is a real open-source product and, at the same time, a public demonstration. Tasks are written by
people in mcptask.online, picked up by runners (Claude Code driven by the
mcptask runner, on our own machines), and every change follows the same path: task → branch → pull request
→ tests & CI → merge → deploy to mcp4mail.online. Nobody, person or runner,
pushes to main directly: the branch is protected by a repository ruleset that requires an open pull
request, a linear history, and green status checks (security scans, lint, unit tests, system tests) before
a squash merge is allowed.
Watch it live: https://mcptask.online/live
Where to look if you want to verify any of this yourself: the Pull requests tab, where each
PR links its task and shows its CI runs, including the failed ones; CLAUDE.md and
.claude/, the instructions the runners work from; and the
CI configuration.
People still write the task briefs, review the pull requests, and decide what ships and what doesn't; a runner executes a task end to end, but it is not deciding what to build. A runner is a user with a seat here, not something free or unlimited.
MCP tools
Write tools work only on a mailbox whose owner switched on "Allow the AI to make changes to this mailbox";
everywhere else they are refused, see below. send_message never sends
on its own: you get an email with a link and the message leaves only when you press Send.
Self-hosting
Read docs/self-hosting.md first: which environment variables matter, why
HITCH_RESOURCE_URI must match your public URL exactly, TLS, and how mailbox passwords are stored.
Stack
Ruby 3.4, Rails 8.1, PostgreSQL, Hotwire (Turbo + Stimulus), Tailwind CSS, Solid Queue / Cache / Cable.
Development
PostgreSQL must be running locally; the default config connects over the local socket as your OS user.
Secrets
This repository is public. Nothing secret is ever committed: config/master.key, .env* and
credentials.yml are git-ignored, production secrets come from the environment.
Mailbox passwords are encrypted at rest with Active Record Encryption. In production, generate keys with
bin/rails db:encryption:init and provide them through the encrypted credentials
(active_record_encryption.*) or the ACTIVE_RECORD_ENCRYPTION_PRIMARY_KEY,
ACTIVE_RECORD_ENCRYPTION_DETERMINISTIC_KEY and ACTIVE_RECORD_ENCRYPTION_KEY_DERIVATION_SALT environment
variables. Development and test derive throwaway keys from the per-machine tmp/local_secret.txt.
Mail accounts
mcp4mail connects to your mailbox over plain IMAP with a username and password. Use an app-specific password wherever your provider offers one (Gmail, iCloud, Fastmail, Outlook.com, Yahoo and others do), so that what is stored in the database can be revoked on its own and is not the key to your whole account. How the password is stored and who can decrypt it is described in the security notes of the self-hosting guide.
MCP endpoint: read-only by design
Every mailbox is read-only until you say otherwise. Each mailbox on the Mail accounts page has one switch, "Allow the AI to make changes to this mailbox", and it is off by default. No scopes, no per-tool permissions: that switch is the whole opt-in.
- Off (the default): the AI can only read and search. Any tool that would change the mailbox is refused
with a message telling the model the mailbox is read-only, and the refusal is written to the audit log as
denied. - On: tools that change mail (flag, move, draft and, with your approval, send) may act on that mailbox.
The tool registry refuses to boot with a tool that is neither read-only and non-destructive nor explicitly
declared as a write tool (write_tool destructive: ... on McpTools::ApplicationTool), so nothing can
slip in as a write tool by accident. Write tools announce readOnlyHint: false and declare their own
destructiveHint.
What read-only does and does not mean, plainly:
-
Nothing can change a mailbox without its switch. Folders are opened with IMAP
EXAMINE, so even reading does not mark messages as seen. -
It does read your mail, whenever an AI client you connected asks. Connect only clients you trust with that.
-
It keeps a copy of message headers (sender, recipients, subject, date, flags, size) in its own database, refreshed every 15 minutes, so searches do not hit your mail server each time.
-
Scoping. Every tool resolves data through the signed-in user's own mail accounts; an account id that is not theirs is refused before any tool code runs.
-
Rate limits. Hitch limits each user + client pair (120 requests a minute); on top of that each user has one quota for tool calls across all their clients (240 a minute).
-
Audit log. Every call is written to
mcp_audit_events: user, client, tool, account, outcome, rows returned, duration. Arguments are not stored. -
Search guard. Pages are capped at 50 results, and each account has a budget of searches (60 per 10 minutes) and returned rows (1,000 an hour), so a runaway loop cannot walk a whole mailbox.
Contributing
See CONTRIBUTING.md. bin/ci must pass.
License
來源:README.md,提交 9bdbe93
工具
0版本歷史
1- v1.0.0最新Sep 28, 2026
