Best Email MCP Servers for AI Agents: 8 Official Options Compared

Estimated reading time: 12 minutes
An AI agent can draft an email without connecting to your email platform. Sending it, checking customer context, or testing where it lands requires access to the right tools.
Model Context Protocol (MCP) gives AI assistants a standard way to use those tools. An email MCP server might connect to an email service provider (ESP), a customer relationship management (CRM) platform, or a mailbox. Some also expose inbox placement tests. These capabilities overlap, but they answer different questions.
This guide compares eight official servers by their documented capabilities, setup requirements, and limits, so you can choose a starting point for your workflow.
Disclosure: GlockApps publishes this guide and includes its own MCP server. The products are grouped by use case, not ranked from best to worst.
How we selected and compared the servers
We selected vendor-maintained servers with public documentation covering four common jobs: sending email, working with marketing and CRM data, handling a mailbox, and testing inbox placement. This is a focused shortlist, not a directory of every email MCP server.
The comparison is based on official documentation and repositories. It is not a hands-on benchmark of reliability, speed, or deliverability. For each server, we checked what actions it exposes, where it runs, how it authenticates, and what account access or limitations affect those actions. Example prompts below illustrate possible workflows; they are not transcripts of tests we ran.
The right server is the one that covers your task, works with your MCP client, and fits the permissions you can safely grant. Tool count says little about that. Service plans, usage charges, and client requirements still apply.
Email MCP servers at a glance
| Server | Primary use | Hosting | Authentication | Sends email? |
|---|---|---|---|---|
| Resend | Sending and inbound | Hosted or local | OAuth or API key | Yes |
| Mailgun | Sending and analytics | Local | API key | Yes |
| Postmark | Transactional email | Local | Server token | Yes |
| Mailchimp Transactional | Sending and API diagnosis | Hosted | API key | Yes |
| Brevo | Campaigns and CRM | Hosted | MCP token | Yes; campaigns |
| HubSpot | CRM context | Hosted | OAuth with PKCE | No; logs activity |
| Gmail | Threads and drafts | Hosted | OAuth | No; drafts only |
| GlockApps | Placement testing | Hosted | Account link; API key | No; seed tests |
Sending and troubleshooting email
1. Resend MCP: application email and inbound workflows
Resend connects an agent to sending and receiving messages and attachments, templates, contacts, broadcasts, segments, domain configuration, and webhooks. It is a practical starting point when you are building an application that needs to send email and process replies.
Setup and access: Use Resend’s hosted endpoint with OAuth, or an API key for a headless connection. A local server is also available. You need a Resend account and a verified sending domain for your own sender addresses; normal service limits apply.
Example: “Send this welcome email to my test address, then retrieve its delivery status.” The agent can submit the message and read the provider’s result, which tells you the message was accepted, not where it landed.
Limit: Resend’s newer Inboxes feature is in beta, requires access, and is available only through the remote server, so the local package doesn’t cover everything the hosted endpoint does.
Official Resend MCP documentation
2. Mailgun MCP: sending, analytics, and deliverability data
Mailgun’s server covers sending, domains, templates, routing, suppressions, analytics, and validation. It also exposes Optimize tools for retrieving inbox placement test results and Inspect tools for retrieving email preview results.
Setup and access: Run the official @mailgun/mcp-server package locally with Node.js and a Mailgun API key. Mailgun does not currently host this server. Check that your account has access to the products and results your workflow needs.
Example: “Compare last week’s bounce rates by domain, then summarize inbox, spam, and missing placement for this Optimize seed-test result.” This combines sending analytics with a separate placement measurement.
Limit: Delivery events and Optimize results are different data sources. A delivered event means server acceptance, while a seed result shows placement in test mailboxes. The documented Optimize tools retrieve seed-test results; the repository doesn’t list a tool for creating tests. Product tags let you select which tool groups to load.
Official Mailgun MCP repository
3. Postmark MCP: transactional email operations
Postmark’s official server has expanded beyond its original four tools. Version 2.0 provides 24 tools for individual and batch sends, templates, message search, delivery diagnosis, bounces, suppressions, statistics, and webhooks.
Setup and access: Run @activecampaign/postmark-mcp locally with Node.js and a Postmark server token. Configure a verified sender and the appropriate message stream. Sending uses your Postmark account and its normal usage allowance.
Example: “Find the latest password-reset email sent to this test address and diagnose any delivery problem.” The diagnoseDelivery tool combines message history, suppression checks, and bounce information.
Limit: This diagnosis uses Postmark’s delivery data; it does not inspect the recipient’s inbox or spam folder. MCP coverage also differs from full API coverage: the server supports synchronous batch sending, but does not wrap Postmark’s asynchronous bulk endpoint.
Official Postmark MCP repository
4. Mailchimp Transactional MCP: sending and API troubleshooting
Mailchimp’s Transactional Messaging MCP server exposes account checks, template building, failed-send diagnosis, and tools to describe and call Transactional Messaging API endpoints. It suits teams already sending through Mailchimp Transactional.
Setup and access: Connect to the hosted endpoint with an API key. You need access to Transactional Messaging and an authenticated sending domain. If you restrict the key, Mailchimp requires the AI Agents permission group to be enabled alongside the permissions needed for your operations.
Example: “Send a test email to my test address, then retrieve engagement metrics for recent messages.” These are documented workflows supported through API calls.
Limit: The server is built for Transactional Messaging; the Mailchimp Marketing platform isn’t part of its documented scope. Because call_api can invoke API operations, inspect the key’s permissions and require approval for sends and other changes.
Official Mailchimp Transactional MCP guide
Marketing and CRM context
5. Brevo MCP: campaigns, contacts, and CRM workflows
Brevo’s hosted server connects an assistant to contacts, email campaigns, campaign analytics, templates, CRM records, and other marketing functions. Its main endpoint combines 27 modules, with separate endpoints available for narrower workflows.
Setup and access: Generate a dedicated MCP token in your Brevo account and use it as a Bearer token. Available actions and usage depend on your account. Some MCP clients connect directly; others use a local bridge.
Example: “Find the launch audience, create a campaign draft, and show me the content and recipient selection for approval.” The agent can work with audience data and campaign configuration in one platform.
Limit: Brevo documents the MCP token as granting full read/write account access. Connecting only a contacts or campaign module reduces the tools exposed to the agent; it does not turn that credential into a restricted account token. Apply approval controls separately, especially before sending or changing customer records.
Official Brevo MCP overview and token setup
6. HubSpot MCP: CRM context for follow-ups
HubSpot’s remote MCP server lets an agent retrieve CRM records and activities and write to supported objects. It can supply the context behind an email: the contact’s lifecycle stage, open deals, recent meetings, and previous interactions.
Setup and access: Create an MCP auth app and connect with OAuth using a client that supports PKCE. Access follows the user’s HubSpot permissions and the permissions granted during installation.
Example: “Review this contact’s latest meeting and open deal, then draft a follow-up for my approval.” The agent can use CRM context to compose the draft. A separate sending tool handles delivery; after a confirmed send, the agent can log the email activity.
Limit: Creating an email activity is not the same as sending an email. Also, HubSpot states that accounts with Sensitive Data enabled cannot access activity objects through this MCP server, which affects workflows involving emails, meetings, notes, and tasks.
Official HubSpot remote MCP guide
Working inside a mailbox
7. Gmail MCP: thread search and draft replies
Google’s official Gmail MCP server supports searching threads, retrieving thread content, creating and listing drafts, and applying or removing labels. It suits assistants that summarize conversations and prepare replies for review.
Setup and access: The server is in Developer Preview. It requires membership in the Google Workspace Developer Preview Program, a Google Cloud project with the Gmail API and Gmail MCP API enabled, and OAuth configuration. Your MCP client must support the required connection flow.
Example: “Find the latest thread about the renewal, summarize the customer’s questions, and create a draft reply.” You then review and send the draft from Gmail.
Limit: The documented tools don’t include sending, deleting mail, or downloading attachments. The Gmail API itself supports those actions; this server doesn’t expose them.
Official Gmail MCP setup and tool reference
Testing inbox placement
8. GlockApps MCP: the full pre-send testing loop
GlockApps connects an assistant to Inbox Insight manual tests and lets it run the whole testing loop from the conversation. The agent creates a test, hands you the seed addresses and test marker, waits for results, and reports placement by mailbox provider, along with authentication and blocklist findings.
Two tools do most of the diagnostic work. Diagnose returns a ranked list of the issues affecting placement, worst first, with an explanation for each. Compare shows how placement changed between two tests, overall and per provider, so you can confirm whether a fix worked. The agent can also analyze the message itself (size, image and link counts, broken or slow links) and generate a shareable report link.
Setup and access: Connect to the hosted endpoint and link your account using the GlockApps authentication flow. It asks for your API key on a GlockApps page. Each test consumes one test point; hourly and daily MCP test limits are available.
Example:
- “Create a test for this newsletter and give me the seed addresses.”
- Send to the seed addresses through the ESP, relay, or application you want to check.
- “Summarize placement by provider and tell me what to fix first.”
- After a change: “Run a new test and compare it with the previous one.”
How it differs from Mailgun’s placement tools: Mailgun’s MCP server retrieves Optimize seed-test results, and its repository doesn’t list a tool for creating tests. With GlockApps, the agent creates the test, collects the results, diagnoses issues, and compares runs, and the workflow is the same regardless of which ESP, relay, or server sends the message.
Limit: GlockApps does not send the campaign. The MCP currently supports manual Inbox Insight tests, not scheduled tests or free checkers. Results describe the test mailboxes; individual subscribers may see different placement.
GlockApps MCP capabilities and setup
What a placement test can tell you?
A delivery event and an inbox placement result answer different questions. Delivery confirms that a receiving server accepted the message. A seed test checks where copies of that message appeared in a controlled set of mailboxes.
Use your actual campaign and sending infrastructure when testing. If the results show a problem, investigate authentication, sending reputation, content, and provider-specific findings, then repeat the test after a change.
Treat the result as evidence about that test, not a guarantee for every subscriber. Seed addresses do not reproduce each recipient’s engagement history. Compare placement results with delivery logs, complaints, and mailbox-provider data when available.
For a working starting point, connect GlockApps and run one manual test before your next campaign.
Explore the GlockApps MCP setup guide
Before you give an agent send access
- Verify the package and publisher. Follow links from the vendor’s documentation. Postmark reported an unrelated malicious postmark-mcp package that copied outgoing email to a third party; it was not the official server.
- Restrict credentials where the provider supports it. Check the actual token permissions. Hiding a tool or choosing a smaller module is not equivalent to revoking the underlying account permission.
- Require approval for consequential actions. Review recipients, message content, attachments, and audience size before a send. Use small test audiences before enabling broader workflows.
- Treat incoming mail as untrusted content. Instructions inside an email must not authorize an agent to forward private data, change settings, or send messages.
- Set usage limits and handle retries carefully. Check the previous send result before retrying an uncertain request. Keep campaign sends and test consumption within limits you can review.
- Test placement and authentication before major campaigns. A seed test can reveal problems with the message or sending setup; it does not validate consent, remove bad addresses, or identify every spam trap in a mailing list.
Postmark’s report on the malicious package
Not on this list
Several marketing platforms also maintain official MCP servers, including Klaviyo, Kit, ActiveCampaign, Iterable, Customer.io, and Omnisend. We left them out to keep the comparison focused on the four jobs above.
Two well-known sending providers are missing for a different reason. At the time of review, SendGrid’s official MCP server only looked up documentation and could not send email, and Amazon SES offered sample code that isn’t intended for production use.
Choose a server for the next task
Start with the platform that already holds the data or sends the email. Resend, Mailgun, Postmark, and Mailchimp Transactional connect agents to sending workflows. Brevo brings campaigns and audience operations together. HubSpot supplies CRM context, while Gmail prepares replies inside an existing mailbox.
Add placement testing when the next question is where a campaign lands. GlockApps lets the agent run the whole test, diagnose, and compare loop across sending setups; Mailgun’s server retrieves Optimize placement results if you already use that product.
You do not need all eight. Choose one bounded task, verify the permissions and results, and add another server when it provides information or actions the first one cannot.
FAQ
Yes. Resend, Mailgun, Postmark, and Mailchimp Transactional expose sending operations. Brevo supports campaign workflows that include sending. Google’s official Gmail MCP server currently exposes drafts rather than a send tool.
GlockApps lets an agent create Inbox Insight tests, diagnose the results, and compare runs. Mailgun’s MCP server retrieves Optimize seed-test results. In either case, distinguish results from test mailboxes from delivery events or placement for individual subscribers.
No. Vendor maintenance helps establish provenance, but account permissions, approval controls, incoming content, and the agent’s behavior still matter. Review the tools and credentials before connecting production data.
You need the relevant service account and access to the features you plan to use. Sending quotas, product entitlements, and test credits still apply. Gmail additionally requires Developer Preview enrollment. Check the vendor’s current account requirements and your MCP client’s plan before setting up a workflow.