Back to Browse

Apple Mail MCP Server

Developer ToolsModerate7.2MCP RegistryLocal
Free

Server data from the Official MCP Registry

Privacy-first local MCP for Apple Mail on macOS: inbox context, drafts, approvals, and follow-ups.

About

Privacy-first local MCP for Apple Mail on macOS: inbox context, drafts, approvals, and follow-ups.

Security Report

7.2
Moderate7.2Low Risk

This is a well-designed Apple Mail MCP server with strong security fundamentals. The server implements proper approval workflows for sensitive operations, uses subprocess safely by passing arguments rather than interpolating scripts, and maintains detailed audit logging. A few minor code quality issues and a small permission scope concern prevent a higher score, but the architecture is sound and appropriate for its intended use case. Supply chain analysis found 1 known vulnerability in dependencies (0 critical, 1 high severity). Package verification found 1 issue.

3 files analyzed · 7 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

File System Read

Reads files on your machine. Normal for tools that analyze or process local data.

File System Write

Writes or modifies files on your machine. Check that this is expected for the tool.

Shell Command Execution

Runs commands on your machine. Be cautious — only use if you trust this plugin.

env_vars

Check that this permission is expected for this type of plugin.

process_spawn

Check that this permission is expected for this type of plugin.

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-jakobfigur-apple-mail-mcp": {
      "args": [
        "-y",
        "@jakobf1/apple-mail-mcp"
      ],
      "command": "npx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

Apple Mail MCP

A local, stdio-based Model Context Protocol server for Apple Mail on macOS.

It talks only to the Apple Mail app already configured on the user's Mac. It does not need IMAP/SMTP passwords or open a network port.

Safety model

  • Mailbox and message tools are read-only by default.
  • create_draft opens an unsent, visible draft in Apple Mail.
  • send_email requires user_approved: true. MCP clients should call it only after the user has approved the exact message.
  • Message changes such as marking, flagging, and moving also require user_approved: true.
  • Dynamic content is passed to osascript as arguments, not interpolated into AppleScript source.
  • Every write action has a local, metadata-only JSONL audit entry. Bodies and credentials are never written to that log.
  • The approval inbox and relationship context are stored only in the local JSON data store described below.

The MCP server itself is local. However, an MCP client may send tool results to an AI model or another service. Only connect clients and models you trust with mail content.

Requirements

  • macOS with Apple Mail configured
  • Node.js 20+
  • Permission for the host application (for example Codex or Terminal) to control Mail under System Settings → Privacy & Security → Automation

Install

npm (recommended)

npm install -g @jakobf1/apple-mail-mcp

Then configure your MCP client with the installed command:

{
  "mcpServers": {
    "apple-mail": {
      "command": "apple-mail-mcp"
    }
  }
}

From source

git clone https://github.com/YOUR_ACCOUNT/apple-mail-mcp.git
cd apple-mail-mcp
npm install
npm run build

Add to an MCP client

If you installed from source rather than npm, use the compiled server over stdio:

{
  "mcpServers": {
    "apple-mail": {
      "command": "node",
      "args": ["/absolute/path/to/apple-mail-mcp/dist/index.js"]
    }
  }
}

Restart the MCP client after saving its configuration. The first call will trigger the normal macOS automation permission prompt.

Optional sender policy

To allow sending only from specific configured Apple Mail addresses, configure a comma-separated allowlist when launching the server:

{
  "env": {
    "APPLE_MAIL_MCP_ALLOWED_SENDERS": "hello@example.com"
  }
}

Write-action audit metadata is stored locally at ~/.apple-mail-mcp/audit.jsonl by default. Set APPLE_MAIL_MCP_AUDIT_LOG to use another local path.

AI-first local workspace

The approval inbox and relationship context share a local JSON store at ~/.apple-mail-mcp/data.json by default. It contains queued draft bodies and the contact notes you intentionally save, so treat it as private mail data. Set APPLE_MAIL_MCP_DATA_STORE to use another local path.

APPLE_MAIL_MCP_DRY_RUN=true validates sends but prevents delivery. You can also enforce recipient restrictions with APPLE_MAIL_MCP_ALLOWED_RECIPIENTS, APPLE_MAIL_MCP_ALLOWED_RECIPIENT_DOMAINS, and a local time window such as APPLE_MAIL_MCP_SENDING_WINDOW=09:00-18:00.

Tools

ToolWhat it does
list_accountsLists configured Apple Mail accounts and sender addresses.
list_mailboxesLists the top-level mailboxes in an account.
list_messagesReturns inbox or mailbox summaries without message bodies.
search_messagesSearches recent messages by sender or subject.
get_messageReads one message body by id, with a configurable length limit.
create_draftOpens a visible, unsent outgoing message.
send_emailHands an approved message to Apple Mail for delivery.
create_reply_draftOpens a visible reply draft and preserves Apple Mail's reply recipient/subject handling.
set_message_read_statusMarks one approved message read or unread.
set_message_flag_statusFlags or unflags one approved message.
move_messageMoves one approved message to another mailbox.
get_audit_logReads the local metadata-only audit trail.
get_send_policy / preview_sendInspects or validates the active send safeguards without delivery.
queue_email_for_approval / list_approval_queueStores proposed emails locally for human review.
approve_queued_email / discard_queued_emailApplies an explicitly approved queue decision.
save_contact_context / get_contact_contextMaintains private relationship notes, tone, commitments, and follow-up dates.
get_contact_briefCombines a saved contact profile with recent inbox summaries.
list_follow_up_radarSurfaces saved contacts that are due for a human-approved follow-up.
get_work_mode / set_work_modeSwitches between focused policies such as inbox zero, sales follow-up, support, and deep work.
save_thread_summarySaves a user-approved local thread summary with its source message ids.
get_daily_briefingCombines unread messages, pending approvals, and due follow-ups into a safe daily action brief.

Scope and non-goals

This project is local-only. It is not an SMTP server, does not manage credentials, and does not bypass macOS privacy prompts. It deliberately excludes deletion, attachment export, background scheduling, and automatic sending.

Publishing and registry metadata

The package is published as @jakobf1/apple-mail-mcp. Its MCP Registry identity is io.github.jakobfigur/apple-mail-mcp; see server.json for portable install metadata.

License

MIT

Reviews

No reviews yet

Be the first to review this server!