MCP for email is an integration that exposes mailbox actions to an AI assistant. Arawa Mail’s implementation uses OAuth to one approved mailbox; authentication and scope vary across other email MCP servers. It is not SMTP, not IMAP, and not your transactional HTTP API. Use MCP when a person wants an assistant inside a specific inbox. Use the email API when application code must send receipts, OTPs, or queued product mail.
For example, an IMAP bridge may ask for a mailbox or app password and hold it in a third-party process. Its reach depends on the bridge’s implementation and the account’s permissions. Check the server’s capabilities and authorization model before granting access; MCP itself does not guarantee a particular mailbox scope or consent mechanism.
Arawa Mail’s remote email MCP server is different: the assistant never receives the mailbox password, and it can reach only the mailbox you approve.
What Model Context Protocol means for a mailbox
The Model Context Protocol (MCP) is a standard way for an AI client to discover and call tools. An email MCP server exposes mailbox actions as tools. The assistant asks to search or send; the human (or the client’s approval UI) decides whether that tool call runs.
On Arawa Mail the remote server URL is:
https://app.arawamail.com/mcp/email
That URL is bound to the current billing website and OAuth issuer. Always copy it from the live Connect an AI Assistant (MCP) docs page, not from an old screenshot.
Prerequisites are small: an active mailbox, an assistant that supports custom remote MCP plus OAuth, and permission to add connectors (team and enterprise products often need an admin). Documented clients with setup on that same page: ChatGPT, Claude, Grok, and Perplexity. Developers can probe discovery and tools with MCP Inspector:
npx @modelcontextprotocol/inspector --server-url https://app.arawamail.com/mcp/email --transport http
MCP vs the HTTP email API vs IMAP and SMTP
These three layers solve different operator problems. Mixing them is how agents leak passwords or how checkout receipts start depending on a chat session.
| Layer | Job | Auth model | Who triggers it | What you get back |
|---|---|---|---|---|
| Email MCP | Let an assistant work inside one approved mailbox | OAuth to that mailbox | A human in ChatGPT, Claude, Grok, or Perplexity | Search hits, conversation text, send/reply, file/archive/trash |
| HTTP email API | Application-triggered transactional mail | API key (optionally scoped to a domain) | Laravel, Next.js, workers, checkout | A stored message id, delivery events, Sent-folder copy |
| IMAP + SMTP | Wire protocols for mail clients and relays | Mailbox password or app password | Thunderbird, phones, some bridges | Folder sync and raw submission |
MCP does not replace SPF, DKIM, DMARC, or Enable Sending. It is not a mail transport. If the domain cannot send, the assistant cannot “MCP around” that fact. For the transport-versus-API decision in application code, see SMTP vs Email API.
What problem MCP solves that IMAP and REST do not
IMAP gives a client the whole mailbox if it has the password. REST sending APIs give application code a way to create outbound messages with an id you can log. Neither is a consented tool list for a chat assistant sitting next to a human.
MCP is the missing middle: the assistant can search unread mail in hello@, read a thread without marking it read by default, and propose a reply — without holding the mailbox password and without becoming your checkout mailer.
What the Arawa Mail email MCP server can and cannot do
After consent, documented capabilities are:
- Search by folder, text, sender, recipient, subject, unread status, and date range
- Read a conversation without marking it read by default
- Send a new email or reply from that mailbox
- Mark read or unread
- Archive or unarchive
- Move to Trash or restore from Trash
Documented non-capabilities:
- Another mailbox on the same domain
- Drafts
- Spam
- Attachment download
- Permanent delete
- Domain administration
Connecting Claude does not give it every mailbox on the domain. Connecting Grok to support@ does not let it empty Trash forever or pull invoice PDFs. Those ceilings are the product, not a missing feature.
Revoke from the mailbox at Settings → AI assistants, or remove the connector in the AI product.
MCP vs handing an agent an API key
An API key is for servers. It sends product mail: receipts, password resets, OTPs. It does not search a human inbox. It should not live in a chat product.
An MCP connection is for an assistant the human is already talking to. It attaches to a company mailbox the human already owns. That is the opposite of hosted “agent inbox” vendors that provision disposable identities for bots. Arawa Mail does not invent a second From address for the model. Humans still own the From address.
If the goal is “the agent should have somewhere to receive mail,” give it a real mailbox and a policy — not a sending key. That argument is in Give agents a mailbox, not just an API key and Don’t let an AI agent burn your domain.
When to connect an assistant — and when to stay in application code
Connect MCP when a person needs help inside one named inbox:
- A founder asks Grok to find unpaid-invoice threads in hello@ and draft a reminder — not auto-send it.
- A support lead connects Claude to support@ to summarize unread mail. Sending stays behind review.
Keep the HTTP API when software must send on a schedule or an event:
- Laravel queued mailables and
MAIL_MAILER=sdp - Next.js server actions calling
POST /emails - Checkout receipts, OTPs, password resets
MCP is not in the checkout path. It is not a bounce webhook. It is not a substitute for idempotent application sends.
Click-path setup for ChatGPT, Claude, Grok, and Perplexity lives in the published walkthrough: Connect ChatGPT, Claude, or Grok to an ArawaMail Mailbox (MCP). Do not treat this article as a second setup guide.
How we analyzed this
Claims in this piece follow the live Arawa Mail MCP guide (server URL, OAuth, can/cannot list, Inspector command, revoke path, and the warning that email can contain untrusted instructions). Client names match that page on draft day: ChatGPT, Claude, Grok, Perplexity. We separated three layers — MCP tools, HTTP sending API, IMAP/SMTP — because operators keep collapsing them into “just give the agent access.” Future posts cover triage workflows and a human-approval gate before send; this post owns the definition and the decision.
Review the tool call before it leaves the building
Email bodies can contain untrusted instructions aimed at the model. Before you approve a send, archive, or trash action, read the recipients, the body, and the mailbox change. That habit is the bridge to requiring a human approval step before send, and it is how you keep a useful assistant from becoming an unsupervised mailer.
FAQ
Should my Next.js app send receipts through MCP?
No. Receipts belong on the transactional HTTP API so you get a message id, retries, and a copy in Sent. MCP is for a human-supervised assistant in one mailbox.
Does connecting an assistant give it every mailbox on the domain?
No. OAuth consent is per mailbox. The assistant cannot access another mailbox or administer the domain.
Can the assistant download invoices or empty Trash permanently?
No. Attachment download and permanent delete are outside the documented tool list. Trash/restore is allowed; emptying history is not.
Is an IMAP-bridge MCP the same thing?
No. Many generic bridges store mailbox or app passwords. Arawa Mail documents OAuth to one mailbox with a published capability ceiling.
How do I disconnect it?
Mailbox Settings → AI assistants, or remove the connector in the AI product.
Editorial review
Product claims were checked against the linked Arawa Mail documentation on 3 October 2026. Scenarios are illustrative; they are not claims about an observed customer incident. For the protocol definition see the official MCP introduction.