MCP server for Apple Mail integration providing tools for searching, reading, organizing, and composing emails in Apple Mail
The Apple Mail MCP server defines 9 tools with generally clear purposes and complete input schemas. Naming is verb-forward and unambiguous (search_, get_, list_, mark_, move_, create_, send_). Tool descriptions are well-written (avg 180 - 220 chars, well above the 10-char minimum) and explain WHEN to use each tool. Input parameters are fully typed with descriptions. However, output schemas are not documented, callers must infer what each tool returns from context. Error handling is absent from the tool definitions; there's no guidance on what happens on failure (e.g. email not found, permission denied, network timeout). Security-wise, the server operates against a local macOS system via AppleScript/osascript, so credential injection is not a concern, but permission gates and audit trails are not mentioned. Composition is strong, tools chain logically (search → get_email → move, or create_draft → send_email). Schema validation is done via Zod, which is good practice.
Create a new draft email in Apple Mail. This tool creates a draft email with the specified recipients, subject, and content. The email is saved as a draft and can be edited or sent later from Apple Mail.
Get list of attachments for a specific email. This tool retrieves information about attachments in an email without downloading them. Useful for checking what files are attached before deciding to process them.
Get full details of a specific email by its message ID. This tool retrieves the complete information for a single email message, including full content, all recipients, attachments info, and metadata. Use this after searching to get the complete email.
List all email accounts configured in Apple Mail. This tool retrieves all email accounts available in Apple Mail, including account names and types. Useful for understanding which accounts are available for sending or searching.
Get a list of all mailboxes/folders across all accounts. This tool retrieves all available mailboxes in Apple Mail, including folder names, associated accounts, and message counts. Useful for understanding mail organization and choosing targets for search or move operations.
Output schemas not documented for any tool. LLMs must infer return types from descriptions alone, increasing hallucination risk and requiring extra reasoning cycles.
Error handling and recovery guidance absent. Tool definitions do not document what happens on failure (email not found, mailbox invalid, send timeout, permission denied). LLMs cannot self-correct without explicit error classification and next-step guidance.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | C | 69 | 2025-06-18+ | v2 |
| 2026-03-09 | F | 44 | - | v1 |
Mark email as read or unread. This tool updates the read status of an email. Useful for organizing and tracking which emails you've reviewed.
Move email to a different folder/mailbox. This tool moves an email from its current location to the specified mailbox. Useful for organizing emails into different folders.
Search for emails in Apple Mail by various criteria. This tool searches through your Apple Mail messages, supporting multiple filter criteria like sender, subject, content, and mailbox. Perfect for finding specific emails, filtering by sender, or locating receipts and important messages.
Send an email immediately from Apple Mail. This tool creates and sends an email in one action. The email is composed with the specified recipients, subject, and content, and sent immediately.
Irreversible operations (send_email) lack confirmation/dry-run pattern. No mention of confirmation step, dry-run capability, or undo. Best practice is to return a confirmation token or require explicit 'confirm=true' before actually sending.
Parameter constraints (e.g., subject max length 500, limit 1 - 100) are in Zod schema but NOT repeated in parameter descriptions.
No audit trail or permission gate documentation. Tools modify email state (move, mark, send, create) but no mention of logging, permission checks, or who called what. In production, this is critical for compliance and debugging.