agent-mail-gateway
Self-hosted email MCP server & REST gateway: give each AI agent its own IMAP/SMTP mailbox with sender/recipient allow lists, HTML-to-Markdown, attachments and calendar invites. One Docker container.
Install / Use
claude mcp add dominikamann -- npx -y github:dominikamann/agent-mail-gatewayIf the server publishes to npm under a different name, use that package instead β check the repo README.
MCP Server
Model Context Protocol server
Quality Score
Category
CommunicationSupported Platforms
Our assessment of agent-mail-gateway
agent-mail-gateway scores 83/100 on our quality scale, 343rd of 434 Communication skills we index.
Its MCP Server is 12 KB long, well organised into 15 sections with 5 code examples: a thorough specification that gives an agent plenty to work with.
It has 10 GitHub stars, so there is little community track record yet; judge it on its content.
Maintenance, license and trust
- The repository was last updated 3 days ago, so agent-mail-gateway is actively maintained.
- It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 97/100, with no cautions. These come from repository metadata, not a code audit β read the skill file before letting an agent act on it.
Safety scan
No issues foundOur scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands. An AI review of the same text found nothing harmful.
AI review by kimi-k2.7-code on 2026-10-08. Automated pattern scan on 2026-10-08. It catches known dangerous patterns, not every risk β read a skill before letting an agent act on it.
agent-mail-gateway compared with similar skills
All 4 of these similar skills score higher than agent-mail-gateway; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| agent-mail-gateway (this skill)by dominikamann | 83 | 10 | 3d ago | MCP Server |
| Agent-Reachby Panniantong | 100 | 93.2k | today | CLAUDE.md |
| headroomby headroomlabs-ai | 100 | 74.6k | today | CLAUDE.md |
| CowAgentby zhayujie | 100 | 47.3k | today | CLAUDE.md |
| Scraplingby D4Vinci | 100 | 86.2k | today | MCP Server |
Frequently asked questions
- How do I install agent-mail-gateway?
- Run
claude mcp add dominikamann -- npx -y github:dominikamann/agent-mail-gateway. The install tabs above show the steps for each supported agent. - Which AI agents does agent-mail-gateway work with?
- It is written for Claude Code and Claude Desktop, as a MCP Server file. Other agents that read the same format can often use it too.
- Is agent-mail-gateway safe to use?
- Our scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands. An AI review of the same text found nothing harmful. It is MIT-licensed and scores 97/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is agent-mail-gateway still maintained?
- The repository was last updated 3 days ago, so agent-mail-gateway is actively maintained.
Skill content
View source on GitHubAgent Mail Gateway
Give every AI agent its own email address β without giving it the keys to the mailbox.
Agent Mail Gateway is a small self-hosted service (one Docker container) that sits between your AI agents and ordinary mailboxes on your existing mail server. Each agent gets one API key for exactly one mailbox. Through the gateway it can read and answer mail, send attachments and manage calendar invitations β but only with the people you allow, and every outgoing message is checked before it leaves.
Agents talk to it over MCP (Model Context Protocol) or a plain REST API. Mail arrives as Markdown instead of HTML, which saves a lot of tokens.
Why
Giving an agent the IMAP/SMTP password of a mailbox means it can read everything, write to anyone, and a single prompt injection in an incoming email can make it leak data or spam people. The gateway keeps the password to itself and enforces your rules on every request:
| Without the gateway | With the gateway | |---|---| | Agent knows the mailbox password | Agent only has an API key for its mailbox | | Reads every mail, incl. spam and phishing | Sees only mail from senders you allow | | Can write to anyone | Can only write to recipients you allow | | Sloppy or wrong mails go out | Every mail is checked before sending (rules, optional LLM, your policies) | | HTML mails cost thousands of tokens | Mail arrives as compact Markdown |
Features
Mailbox access
- List, search, read, mark, delete; attachments in and out β as text, base64 or straight from a received message, so agents never have to juggle base64 for a CSV.
- Reply (incl. reply-all) and forward β the gateway fills in recipients,
Re:/Fwd:and threading. - HTML β Markdown for reading, Markdown β HTML for sending.
Calendar
- Send, update and cancel invitations; they update cleanly in Outlook, Gmail and Apple Calendar.
- See who accepted or declined your invitations.
- Read invitations you receive and accept, decline or tentatively accept them.
Control and safety
- Allow lists per mailbox for who the agent may receive mail from and write to
(
name@domainor*@domain). Everything else is invisible to the agent and moved to Trash (or kept). - Forged senders are rejected (SPF/DKIM/DMARC as checked by your mail server).
- Send limit per hour, audit log of every send, rejection and deletion.
- No fast retries on wrong passwords, so your server's fail2ban never blocks the gateway.
Review before sending (details below)
- Built-in rules catch empty mails, attachment-only mails, "see attached" without attachment, leftover placeholders and accidental duplicates β on by default.
- Optional LLM review (e.g. a local model in Ollama) for "is this mail complete and sensible?".
- Optional policies: your own rules in plain language, for everyone or for specific recipients β e.g. "never share financial information", "never mention gifts to Alex".
Integration
- MCP over Streamable HTTP, a stdio bridge for stdio-only clients, and a REST API with
OpenAPI docs at
/docs. - Signed webhooks when new mail arrives (compatible with Hermes Agent webhook routes).
- Hermes Agent plugin with a skill that teaches the agent how to use its mailbox.
- Works with any IMAP/SMTP server: Plesk, IONOS, Outlook, Postfix/Dovecot, β¦
How it works
Agent ββMCP / REST + API keyβββΆ ββββββββββββββββββββββββββββββββββββββββββ
β Auth key β exactly one mailbox β
Agent βββsigned webhookββββββββ β Policy who may write / be written β
β Review rules Β· LLM Β· your policies β
β Converter HTML β Markdown β
β Calendar invitations and replies β
β Mailbox IMAP + instant new-mail pushβββIMAPβββΆ your mail server
β Sender SMTP + copy to "Sent" βββSMTPβββΆ
ββββββββββββββββββββββββββββββββββββββββββ
config.yaml + .env (read-only)
Mail stays on your mail server; the gateway only keeps a small SQLite file with its own state.
Quick start
Use a dedicated mailbox for each agent (for example
assistant@yourmailserver.eu), not your personal one: by default, mail from senders that are not on the allow list is moved to Trash.
- Get the files:
mkdir agent-mail-gateway && cd agent-mail-gateway curl -LO https://raw.githubusercontent.com/dominikamann/agent-mail-gateway/main/docker-compose.yml curl -L -o config.yaml https://raw.githubusercontent.com/dominikamann/agent-mail-gateway/main/config.example.yaml curl -L -o .env https://raw.githubusercontent.com/dominikamann/agent-mail-gateway/main/.env.example - Edit
config.yaml: one entry per agent with its mail server, login and allow lists. - Put the secrets into
.env(openssl rand -hex 32makes a good API key). - Start it and check:
docker compose up -d curl http://localhost:8080/health # {"status":"ok"}; with a key also that mailbox's state curl -H "Authorization: Bearer <the AGENT_API_KEY from .env>" http://localhost:8080/v1/mailbox
A minimal mailbox entry:
mailboxes:
- name: assistant
address: youragent@yourmailserver.eu
api_key: ${AGENT_API_KEY}
imap: { host: mail.yourmailserver.eu, port: 993, security: tls }
smtp: { host: mail.yourmailserver.eu, port: 465, security: tls }
username: youragent@yourmailserver.eu
password: ${AGENT_MAIL_PASSWORD}
allow_receive_from: [you@yourmailserver.eu, "*@yourcompany.eu"]
allow_send_to: [you@yourmailserver.eu]
Every option is explained in docs/configuration.md.
Review before sending
Agents are sometimes sloppy β an email with only an attachment, "please find attached" without
a file, Hello {name}. The gateway checks every outgoing email and invitation before it is
sent. If something is wrong, nothing is sent and the agent gets a clear error with the reasons
(review_rejected), so it can fix the message and try again. Rejected attempts don't count
towards the send limit.
There are three layers; you choose per mailbox:
| Layer | Default | What it does |
|---|---|---|
| Rules | on (block) | Fixed checks without AI: empty text, only an attachment, missing subject, attachment mentioned but missing, leftover placeholders, the same mail twice within 10 minutes, invitations in the past. |
| LLM review | off | Asks a language model whether the message is complete and makes sense (e.g. does the reply actually answer the question?). |
| Policies | off | Your own rules in plain language, checked by the language model β for all recipients or only for specific ones. |
Rules and the LLM review can block the message, only warn (send anyway and report it), or be switched off; each policy rule either blocks or warns. The check covers new mails, replies, forwards, invitations and their changes, and comments in invitation answers.
review:
rules: block # block | warn | off
llm: # any OpenAI-compatible endpoint, e.g. a local Ollama
url: http://ollama:11434/v1
model: llama3.1:8b
mode: warn # quality check: warn | block | off
policies:
mode: block # what a violation does: block | warn
rules:
- rule: Never share financial information such as revenue, prices, invoices, bank details or salaries.
- rule: Never mention gifts, presents or surprise plans.
recipients: [alex@yourmailserver.eu]
- rule: Never send calendar invitations.
recipients: [sam@yourmailserver.eu]
A rule with recipients applies only when one of those people receives the message (To, Cc,
Bcc or invitation attendee). With Ollama the review runs entirely on your
own machine; no mail content leaves your server. Long messages are checked in parts β nothing
is cut off; part size and limits are configurable to fit your model's context window. The built-in review prompt can be replaced or
extended β see docs/configuration.md.
Using it
MCP tools
Point any MCP client at http://<host>:8080/mcp with the header
Authorization: Bearer <api key>, or use the stdio bridge.
| Tool | What it does |
|---|---|
| get_mailbox_info | Own address, current date and time, allow lists, limits and the review rules/policies |
| list_messages | Received mail, newest first; filter by unread, or search by text, sender, subject, date |
| read_message | One message as Markdown, incl. attachments list and received invitations |
| get_attachment | Download an attachment |
| mark_message / delete_message | Mark read/unread; move to Trash (if allowed) |
| send_message | Send a new email (Markdown, attachments) |
| reply_message / forward_message | Reply (or reply-all) in the thread; forward with attachments |
| create_event / update_event / cancel_event | Send, change and cancel invitations |
| list_events / get_event | Own events with attendee responses |
| respond_to_invitation | Accept, decline or tentatively accept a received invitation |
REST
# send a message
curl -X POST http://localhost:8080/v1/messages \
-H "Authorization: Bearer $AGENT_API_KEY" -H "Content-Type: application/json" \
-d '{"to":["you@yourmailserver.eu"],"subject":"Daily report","body_markdown":"All **green** today."}'
# unread mail
curl -H "Authorization: Bearer $AGENT_API_KEY" "http://localhost:8080/v1/messages?unread=true"
All endpoints, error codes and the webhook format: docs/api.md.
Hermes Agent
Connect the MCP server in ~/.hermes/config.yaml and install the plugin that teaches your
agents to use their mailbox safely:
hermes plugins install dominikamann/agent-mail-gateway/integrations/hermes/agent-mail-gateway --enable
Step by step, including waking the agent on new mail: docs/hermes.md.
Documentation
- Configuration β every option, allow lists, review, ports, sender authentication
- REST API, webhooks and MCP tools
- Hermes Agent integration and plugin
- stdio clients
- Security model
- Contributing Β· Changelog
Security
Run the gateway on a private network or behind a reverse proxy with TLS β API keys travel in
the Authorization header. Report vulnerabilities privately as described in
SECURITY.md.
License
<p align="center">Proudly provided by <a href="https://amannlabs.eu">amannlabs.eu</a></p>
Related Skills
Agent-Reach
93.2kGive your AI agent eyes to see the entire internet. Read & search Twitter, Reddit, YouTube, GitHub, Bilibili, XiaoHongShu β one CLI, zero API fees.
headroom
74.6kCompress tool outputs, logs, files, and RAG chunks before they reach the LLM. 20% fewer tokens for coding agents, 60-95% fewer tokens for JSON, same answers. Library, proxy, MCP server.
CowAgent
47.3kOpen-source personal AI assistant & Agent Harness. Plans tasks, runs tools and skills, self-evolves with memory and knowledge. Multi-agent, multi-model, multi-channel. Lightweight, extensible, one-line install.
Scrapling
86.2kπ·οΈ An adaptive Web Scraping framework that handles everything from a single request to a full-scale crawl! Don't be shy, join here: https://discord.gg/EMgGbDceNQ and follow here for daily tips and tricks: https://x.com/Scrapling_dev
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit β see the Safety scan above for what the skill file itself contains.
