Blog / Agents
Give Claude, ChatGPT or Cursor safe access to email
https://mailtag.app/mcp, on every plan, including Free), and on the consent screen choose what it may see: which mailboxes, which categories or saved views, how far back, whether it sees the sender and subject, and whether it can change anything. The agent gets a short, sorted list instead of your inbox, and never the text of your emails.Why "full access" is the wrong default
Most ways of connecting an agent to email give it everything: every message, every attachment, years of history, and often the power to send. That's convenient, and it's also the setup security researchers warn about. An agent that can read your private data, reads text written by strangers (every email is), and can send things out is exactly what a malicious email tries to exploit. We explain how in Prompt injection through email.
The fix is the same as for any other access: give the agent only what the task needs.
What your agent gets through MailTag
MailTag already sorts every new email into your own categories. The MCP server lets an agent work with that sorting, within limits you set per agent:
| You choose | Options |
|---|---|
| Mailboxes | all of them, or some |
| Emails | all, some categories (for example only Urgent and Needs reply), or the emails in some of your saved views |
| How far back | 30 days, 7 days, today, or only from the moment you connect it |
| Sender | hidden, only the domain, or name and address |
| Subject | shown or not |
| Read state | shown or not |
| Changes | none, or also relabel emails and edit categories or views (editing only for an agent that sees all emails) |
| Dangerous emails | shown marked, or hidden: dangerous ones, or dangerous and doubtful (when you turn on the safety check) |
What it always gets, within that scope: each email's category, date, mailbox and Message-ID, and a link to open it. What it never gets from MailTag: the email's text, snippets or attachments. It also can never send, delete or move email out of your mailbox.
If the agent needs to read an email in full, it opens that one email through its own mail access, using the Message-ID. The point is that it only opens the few emails that matter, instead of reading everything to find them.
Connect it
You need a MailTag account (any plan, including Free) with your mailbox connected. Then:
Claude (web and desktop)
- Go to Customize → Connectors, click + and Add custom connector.
- Paste
https://mailtag.app/mcpand click Add. - Claude opens MailTag's sign-in. Choose the permissions, step by step, and allow.
On Team and Enterprise, an owner first adds it under Organization settings → Connectors. Custom connectors also work on Claude's free plan, limited to one.
Claude Code
claude mcp add --transport http mailtag https://mailtag.app/mcp
Then run /mcp in a session (or claude mcp login mailtag) to sign in and choose the permissions.
ChatGPT
- In Settings → Security and login, turn on Developer mode (Plus, Pro, Business, Enterprise and Education, on the web).
- Add an app with the URL
https://mailtag.app/mcpand OAuth sign-in. - In a chat, pick it from the + menu under Developer mode.
ChatGPT renames these menus now and then; if a step doesn't match, look for "Developer mode" in its settings.
Cursor, VS Code and scripts
Create a key in MailTag under Settings → Agents → For developers, with the same permission steps, and add it to your client's MCP config:
{
"mcpServers": {
"mailtag": {
"url": "https://mailtag.app/mcp",
"headers": { "Authorization": "Bearer mta_…" }
}
}
}
In Cursor that file is .cursor/mcp.json (project) or ~/.cursor/mcp.json (all projects). The full reference is in the MCP docs.
A setup that works for most people
- Mailboxes: only your work one.
- Emails: the categories Urgent and Needs reply.
- How far back: 7 days.
- Sender and subject: shown, so the agent can tell you what's waiting.
- Changes: none at first. Allow relabeling later if you want the agent to tidy up.
- Dangerous emails: turn on the safety check in Settings → Mailboxes and hide dangerous ones from the agent.
Ask it "what needs a reply today?" and it answers from a handful of emails, not thousands.
What you can see and undo
Every agent is listed under Settings → Agents, with when it was last used and which tools it called (never the emails or your questions). You can change its permissions or disconnect it there at any time, and it loses access on the spot.
FAQ
Does MailTag send my email to Anthropic or OpenAI?
No. MailTag sorts your email on its own servers in the EU and never stores the content. Through the MCP server, the agent only receives what you allowed: categories, dates, and the sender and subject if you chose so. If the agent then opens an email through its own access, that part is between you and the agent's provider.
Can the agent send or delete email through MailTag?
No. MailTag's MCP server has no tools to send, delete or move email out of your mailbox.
Which plan do I need?
Any plan. The MCP server is included on every plan, including Free. On Free, MailTag sorts 100 emails a month, so those are the emails your agent can see.
Can I give two agents different access?
Yes. Each agent has its own permissions: one can see only Receipt from the last 30 days, another only Urgent from today.
Keep reading
Email prompt injection: how one email hijacks an AI agent
An email can hide instructions your AI assistant follows. How it works, real cases in Copilot and Gemini, and how to protect an agent that reads mail.
Read →Guides · 30 Sept 2026Organize iCloud, Yahoo or Fastmail email automatically
What iCloud, Yahoo and Fastmail can sort on their own, where their rules stop, and how to sort each new email into your own categories over IMAP.
Read →