MCP protocol server exposing Apple Mail read/mutate/send tools with full-text search, message retrieval, attachment handling, and SMTP delivery
Apple Mail MCP demonstrates solid tool design with 18 well-named, verb-prefixed tools covering read, write, and send operations. All tools have descriptions (avg 85 chars, within 10-1024 range). Input schemas are present and typed for all tools. However, output schemas are not documented in the provided source, only input schemas are visible. Parameter descriptions are concise but sometimes lack format/constraint details (e.g., date_sent_from/to are Unix timestamps but lack explicit range guidance). Error handling is present but recovery guidance is minimal. Security is strong (no credentials in params, SMTP/keyring integration). Tool composition is clean, each tool has one responsibility, and naming conventions (search_, get_, list_, send_, create_, reply_, forward_) are consistent and LLM-friendly.
Count messages matching optional filters.
Create a draft message in the Drafts mailbox without sending.
Diagnostic tool reporting store access health, account/mailbox counts, and index coverage.
Extract text content from an attachment.
Compose and send a forward of an existing message.
Retrieve a base64-encoded attachment from a message.
Fetch one message by rowid.
Output schemas not documented. Only input schemas are visible in source. LLMs cannot plan downstream tool calls or extract required fields without knowing what each tool returns.
Date parameters (date_sent_from, date_sent_to) lack explicit format guidance. Descriptions state 'Unix timestamp' but do not specify range, precision (seconds vs milliseconds), or validation behavior for invalid values.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | A | 83 | 2026-07-28+ | v2 |
Get RFC 5322 message ID and threading links for a message.
Fetch all messages in a thread by thread ID.
List all configured mail accounts.
List attachment metadata for one message.
List mailboxes for an account with message counts.
Fetch recent messages with optional mailbox/account filters.
Compose and send a reply to an existing message.
Resolve an email address to display name and associated accounts.
Full-text search over mail with ranked hits and a coverage envelope.
Compose and send an email message via SMTP, optionally filing to Sent mailbox.
Quick health status of the Mail store access.
Irreversible operations (send_message, reply_message, forward_message) lack dry-run or confirmation step. Agents cannot preview consequences before executing. No recovery guidance in error responses.
Parameter descriptions are terse (avg 30-40 chars). Many lack actionable constraints: limit/offset ranges, mailbox name format, account identifier type (email vs display name), sender filter syntax.
No documented error classification or recovery guidance. Tools return errors but do not indicate whether failures are retryable, user-fixable, or fatal. LLMs cannot determine next steps.