Blog / Agents
Don't make your AI agent read your whole inbox
The problem with "just ask the agent to check my email"
An agent that triages your inbox has to read each email to decide whether it matters. That sounds cheap until you count:
- Most email is not for the agent. Newsletters, receipts, shipping updates, sign-in alerts, promotions. In a typical inbox they are the majority, and the right action for almost all of them is "nothing".
- Every email costs tokens. A short personal email is a few hundred tokens. A newsletter or an HTML receipt, turned into text, is often well over a thousand.
- Context is the scarcer resource. Whatever the agent reads to triage sits in its context window next to the task you actually care about: drafting the reply, planning the week, following up with a client. Forty promotions in that window make the important work worse, not just more expensive.
A rough example
These numbers are an illustration, not a measurement. Change them to match your inbox:
| Per day | |
|---|---|
| Emails arriving | 120 |
| Share that needs no action (newsletters, receipts, notifications, promos) | about 70% |
| Average size as text | about 600 tokens |
| Tokens read just to triage | about 72,000 |
| …of which on email you'd never act on | about 50,000 |
Across a month that is well over a million tokens of reading done only to decide what to ignore, and it happens again every time the agent starts fresh.
Split the job in two
Sorting and thinking are different jobs:
- Sorting is one narrow decision, repeated all day: which of my categories is this? A small classifier that can only answer with one of your categories does it quickly, in the same way every time.
- Thinking (writing the reply, deciding what to do, summarizing a thread) is where a large model earns its cost.
So sort first, then hand the agent a short list. Instead of "read my inbox", the instruction becomes "read what's in Needs reply and draft answers". The agent sees five emails, not a hundred and twenty.
There's a privacy benefit too. When an agent triages everything, every email body goes to its model provider. When it only reads Needs reply, the rest of your mail never leaves your inbox and the sorter.
How to set this up with MailTag today
MailTag sorts every new email into one of your categories every 5 minutes, right inside the inbox you already use:
- In Gmail each category is a label, such as
>Needs replyor>Urgent(you can change what goes in front, or remove it, in Settings → Mailboxes). Any agent that can already read your Gmail can be told to look only at those labels. - In iCloud, Yahoo, Fastmail and other IMAP inboxes the categories are folders (
>Newsletter,>Receipt…) or marks, and an agent with mail access can open just those. - Your categories are yours. Each one is a name and a one-line description, like "Investors: emails from investors or about fundraising". MailTag always picks one of them and never invents a new one, and you can pin senders or whole domains to a category.
- For builders: signed webhooks per category on paid plans (for example Urgent → Slack), and a triage API on Business.
The sorting runs on our own servers in the EU. Email content is never stored and never sent to any other company, and MailTag can't send or delete email.
Connect your agent to MailTag's MCP server
On every plan, agents such as Claude or ChatGPT can connect to MailTag directly through its MCP server and ask for "everything in Needs reply since yesterday" without reading the rest of the inbox. You decide, per agent, what it can see and do:
- Which mailboxes, and which emails: all of them, some categories or some of your saved views.
- How far back: 30 days, 7 days, today or only from now on.
- What it reads: the sender's name and address, only the domain or nothing, and whether it sees the subject.
- What it can change: nothing, or also relabel emails and edit categories.
If you turn on MailTag's safety check, emails that look like phishing or carry hidden instructions for AI agents come marked, and you can have them hidden from the agent.
FAQ
Does MailTag replace my AI agent?
No. MailTag sorts; your agent thinks. Used together, the agent reads a handful of emails that need it instead of your whole inbox.
Is a small classifier accurate enough to trust?
It always picks one of your categories and gives each decision a confidence score. When a sender is always the same kind of email, a rule per sender or domain makes it exact.
Can my agent use MailTag right now?
Yes. On any plan it can connect to the MCP server with the permissions you choose. It can also use the labels (Gmail) or folders (other providers) MailTag creates.
Does MailTag send my email to OpenAI or another AI company?
No. Sorting happens on our own servers in the EU, content is never stored, and no outside company receives your email.
Keep reading
Give Claude, ChatGPT or Cursor safe access to email
Connect an AI agent to your email through MailTag's MCP server and choose what it sees: which mailboxes, categories and dates, and nothing more.
Read →Agents · 30 Sept 2026Email prompt injection: how one email hijacks an AI agent
An email can hide instructions your AI assistant follows. How it works, real cases in Copilot and Gemini, and how to protect an agent that reads mail.
Read →