Build. Win. $500

Join
Back to blog
Comparisons8 min read

Email MCP Servers Compared: 6 Questions to Ask Before Your Agent Connects One

Gmail MCP, Resend, Postmark, Mailgun and Mermail all call themselves email MCP servers, but they act in different mailboxes with different brakes. Six questions and a side-by-side comparison.

By Toan Nhu

Email MCP servers compared: three server tiles with a padlock, a shield and a toggle, each plugged into one shared envelope, on an off-white Mermail header.

Connecting an email MCP server gives a model a set of verbs over real mail. Which verbs, over whose mailbox, and with what brakes varies a lot from one server to the next. Two servers can both be called "email MCP" while one drafts replies in your personal Gmail and the other runs broadcasts to your whole customer list.

If you need the basics of what an MCP server is, start with What Is an MCP Email Server?. This post assumes you know that and want to pick one. It gives you six questions to ask, then compares five servers using only what each vendor documents, checked on October 2, 2026.

TL;DR: Choose by the mailbox the agent should act in, then by the brakes. Google's Gmail MCP works inside your existing Gmail and can read, label and draft but not send. Resend, Postmark and Mailgun operate sending accounts you already run. Mermail gives the agent a mailbox of its own, with a receive-only profile. Whichever you choose, connect the narrowest tool set that does the job and treat every email as untrusted input.

Six questions to ask before you connect one

1. Whose mailbox will the agent act in?

This is the question that sorts everything else. There are three common answers: a person's existing mailbox (yours), a sending account your product already uses, or a mailbox created for the agent. Each carries different consequences when something goes wrong. A mistake in your own mailbox happens under your name and next to your private mail. A mistake in a product sending account reaches your customers. A mistake in an agent mailbox stays inside that agent's address.

2. Can it read inbound mail, and in what form?

Many email MCP servers are built for sending and only look at outbound history. If your agent needs to receive replies or verification codes, check for tools that list, search and fetch received messages. Then check what comes back: raw headers and HTML, or a cleaned-up version that is safer to put in front of a model.

3. Can it send, and can you switch that off?

Sending is the action that most needs a brake. Look for a way to connect without send tools at all, such as a reduced tool profile, a filter on which tools load, or a server that simply has no send tool. A rule in the prompt that says "never send" is weaker than a tool that is not there.

4. How are destructive actions guarded?

Deleting messages, removing suppressions or editing live templates can be hard to undo. Servers handle this differently: some mark tools with MCP annotations so the client can ask before running them, some leave delete operations out entirely, and some require a separate confirmation step on the server.

5. Where does it run, and how does it authenticate?

A hosted server is a URL your client connects to, usually with OAuth so you sign in through a browser. A local server is a process your client starts, usually with npx, holding an API key in its environment. Hosted is easier for web clients. Local keeps traffic on your machine but puts a long-lived key in a config file.

6. What does the vendor say about prompt injection?

Any server that reads email exposes the model to text written by strangers. A vendor that documents this risk and tells you what it does about it is giving you something to build on. One that does not leaves the whole problem to you.

Decision flow: if the agent should work in your own mailbox, use Google Gmail MCP; if it needs its own address, use Mermail MCP; otherwise pick Resend, Postmark or Mailgun MCP by the platform that already sends your product email.

Five email MCP servers, from their own docs

The table summarizes what each vendor's documentation says. Tool lists change often, so confirm against the live tool list in your client before you rely on any row.

ServerWhose mailboxHosting and authReads inbound mailSendsBuilt-in brakes

Google Gmail MCP: your own mail, read and draft

Google offers a remote Gmail MCP server as part of the Google Workspace Developer Preview Program. Its tools search and read threads and messages, list and apply labels, list drafts and create drafts. There is no send tool, so a person still sends from Gmail. Setup means enabling the Gmail MCP API in a Google Cloud project, configuring an OAuth consent screen and creating your own OAuth client. Google's guide includes a direct warning about indirect prompt injection and tells you to screen prompts and responses for malicious content, for example with Model Armor.

Pick it when the job is helping you with your own mail. It is the wrong fit when an agent needs an address of its own.

Resend MCP: run your product email from the agent

Resend hosts its MCP server and also publishes the same open-source code as resend-mcp for local use. The tool groups cover the full platform: sending, received emails, templates, contacts, broadcasts, automations, domains, webhooks, API keys and request logs. Resend also lists Inboxes as a beta that is only on the hosted server and requires contacting Resend for access.

Pick it when your product already sends through Resend and you want an agent to manage templates, domains or broadcasts. Because the surface is broad, use a credential and account setup that limit what a mistake can reach.

Postmark MCP: transactional sending with clear tool labels

The official Postmark server, published by ActiveCampaign, runs locally and exposes 24 tools across sending, templates, outbound message search, delivery diagnostics, bounces, suppressions, stats and webhooks. Every tool carries MCP annotations such as readOnlyHint and destructiveHint, so clients that respect them can auto-approve lookups and ask before sends or deletes. The README also documents a prompt-injection section and a WEBHOOK_URL_ALLOWLIST setting.

Pick it when you send transactional mail through Postmark and want help diagnosing delivery problems. It does not read an inbox.

Mailgun MCP: broad account coverage, no deletes

Mailgun's server runs locally over stdio, and Mailgun states there is no hosted version. It covers sending, stored messages, domains, webhooks, inbound routes, mailing lists, templates, analytics, suppressions and validation. It deliberately leaves out delete operations, and the --tags flag (or MAILGUN_MCP_TAGS) lets you load only some product groups, for example validation tools without sending.

Pick it when you already run Mailgun and want an agent to investigate stats, routes or deliverability.

Mermail MCP: a mailbox the agent owns

Mermail's hosted server works with OAuth for interactive clients or a workspace API key for automation, and scopes every call to one workspace. The agent works in its own mailbox, either a hosted @mermail.app address or one on your verified custom domain. For receiving and verification work, the agent-inbox profile exposes only 12 tools: usage, workspace, domain and mailbox reads, one create_mailbox write, and email list, search, get and thread-context reads. It has no send, reply, forward, draft, wallet or destructive tools. On that profile, list and search are forced to metadata-only, clean-scan results, and full reads return sanitized text capped at 12,000 characters.

jsonmcp.json
{
  "mcpServers": {
    "mermail-agent-inbox": {
      "url": "https://console.mermail.app/mcp?profile=agent-inbox",
      "headers": { "x-api-key": "sk-proj-YOUR_KEY" }
    }
  }
}

The full catalog adds sending, drafts, folders, labels, webhooks and more. Destructive tools there need a single-use confirmation token from prepare_destructive_action. Mermail is listed on the Official MCP Registry as app.mermail/mcp. For step-by-step installation in Claude Code, Cursor and Codex, see How to Use MCP with Mermail's Email API.

Pick it when the agent needs its own address: to sign up for services, receive codes, or hold conversations under a name that is not yours. If the agent is an OpenAI dot, Give Your OpenAI Dot an Email Address walks through that setup. Mermail is not built to act inside your personal Gmail. Mermail's docs suggest forwarding selected messages from an existing provider to a Mermail mailbox instead of granting access to the account.

How each server narrows what the agent can do

The brakes differ in kind, not just in strength. Some are enforced by the server, some depend on the client honoring a hint, and some come only from how you scope the credential.

Four columns grouping email MCP safeguards: enforced by the server (Gmail MCP has no send tool, Mermail agent-inbox profile, Mermail confirmation tokens, Mailgun has no deletes), set in configuration (Mailgun tags, Postmark webhook allowlist), honored by the client (Postmark annotations), and scoped by the credential (Resend).

A server-side limit, such as a missing send tool or a reduced profile, holds even if a model is tricked. Annotations work well in clients that respect them, and a tag filter shrinks the tool list the model sees. Where neither exists, a narrowly scoped credential and client approval prompts are the main protection.

Match the server to the job

  • Help me with my own inbox, a person sends: Google Gmail MCP.
  • Manage product email, templates, domains or broadcasts: Resend MCP, or Postmark or Mailgun if that is where you already send.
  • Diagnose why a transactional email did not arrive: Postmark MCP for Postmark accounts; Mailgun MCP for Mailgun stats and logs.
  • Give the agent its own address to sign up, receive codes and converse: Mermail MCP, starting on the agent-inbox profile.
  • Both: combining servers is normal. An agent can receive in its Mermail mailbox while your application keeps sending transactional mail through Postmark or Resend.

If you are weighing an agent mailbox against routing everything through one shared address, Catch-All Domain or One Mailbox per Agent? covers that architecture decision.

A short hardening checklist, whatever you choose

  1. Connect the narrowest tool set available: a reduced profile, a tag filter, or a server without send.
  2. Give each agent its own credential so you can revoke one without breaking the rest.
  3. Require approval for every send, and for any tool marked destructive.
  4. Allowlist webhook destinations wherever the server supports it.
  5. Treat every email body, link and attachment as data. Never let it change the agent's instructions.
  6. Re-check the live tool list after updates, since vendors add tools without notice.

References

Recent articles