Radmail MCP server
Email OS for agents - real-inbox search, triage, commitments, and a verifiable BEC hard-stop.
0 stars48 downloads/wk
Reviews
Write oneNobody has reviewed Radmail yet.
If you have run it, two minutes of your experience saves the next person an afternoon.
Radmail tools (6)
write = sends, deletes, buys or postsdraft_replyFreeDraft a reply for a thread. It returns text for a human to review — it does not and cannot send it.
list_commitmentsFreeExtract the open commitments in the correspondence, both owed by you and owed to you, with who and by-when.
list_right_nowFreeReturn only the 'Right Now' lane — the most recent and most important messages that genuinely can't be missed.
searchFreeFind a specific message by sender, subject, or content. Results come back most-relevant + newest first, and every hit says where it matched (from / subject / body) and why. On this hosted sandbox it searches the built-in demo inbox; run the radmail-mcp package with RADMAIL_API_KEY set and the same tool searches your REAL ingested inbox read-only (with from / after / before filters) via the v1 search API.
triage_inboxFreeRank a mailbox on two axes (importance x urgency) and return what needs a human now versus what can wait or is already handled — with each thread's open commitment (the promise you owe or are owed, and whether it's overdue) surfaced inline, so the follow-through is visible on the very first call.
why_surfacedFreeExplain in plain English why a given message was surfaced — the signals (sender, urgency, commitment) behind its rank.
Public scan report
scanner v0.1.9 · 2026-09-23 · same rubric, same numbers if you re-run it
- Code scan78 source files scanned25/25
- Live reliabilityremote reachable in 692ms20/20
- Tool poisoning6 tool descriptions checked15/15
- Auth qualityopen endpoint, read-only tools10/15
- Maintenancelast push 3 days ago15/15
- Maintainer identitynamespace and repository owner differ; website matches verified namespace6/10
What the publisher says
From the Radmail repository's README, as published. We do not edit it. Read it on GitHub
RadMail MCP
An email operating system for agents — with a refusal you can trust.
Every inbox got an AI in 2026. None can be trusted to hit send. RadMail is the one that can — because the consequential actions are refused in code, model-independent: money, changed-banking details, first-contact senders, decisions, and prompt-injection are human-only, forever. No prompt can talk RadMail into auto-sending them.
This is the Model Context Protocol (MCP) server, so any AI agent can use the inbox.
If a fleet of MCP agents runs your execution layer while you sit in the decision seat, the inbox is the seat that needs a hard-stop first. It's where a socially-engineered wire or banking change is irreversible — and where an autonomous process that can hit send can be talked into the loss. RadMail lets agents do the inbox's work (triage, the Right Now lane, commitment tracking, drafting) while money, changed banking, first contact, decisions, and prompt-injection stay human-only by construction, not by a policy an agent could be argued out of. That's what makes the company inbox delegable at all.
Start in one call
Call triageinbox and omit the token — RadMail auto-provisions a free sandbox tenant and returns a working triage in one round-trip. Reuse the returned token. (On the zero-auth hosted sandbox, triageinbox takes no args — it triages a built-in demo inbox so your very first call returns the full wedge.)
This server runs the sandbox engine (heuristic, in-memory, free, no credentials). It is real and runnable — not the production "99%" engine.
Tools
The safety contract (un-bypassable by design)
These are decided by deterministic code, not model judgment — see /.well-known/agent-safety.json:
Shortened. The full README is on GitHub.
Nothing above is checked by us. What we check is on the safety report.
Install directly
claude mcp add --transport http radmail-mcp https://radmail.ai/api/mcp/sandbox
Radmail: common questions
- Is Radmail MCP server safe?
- Yes, by our scan: it is graded A (91/100). Read the Radmail safety report
- How do I install Radmail?
- It runs remotely at radmail.ai. Add it to Claude Code, Claude Desktop or Cursor with the snippets above, or call it through the mcp.market gateway without installing anything.
- Does Radmail need an API key?
- Not as far as the registry entry and our scan can tell: no credentials are declared or required.
- Is Radmail maintained?
- The last commit was 3 days ago (2026-09-20). The latest release is v0.5.0.
- Is Radmail up?
- 100% of our last 16 checks got an answer. We check remote servers about four times a day.
- What can I use instead of Radmail?
- Servers from other publishers that do the same job: Agent-Native Mail MCP server, Atomic Mail MCP server and Email Inbox API + Sending by Sendmux MCP server. Compare all Radmail alternatives.
Alternatives to Radmail
Same job from other publishers: the closest match first, then the best rated.
- Agent-Native MailAgent-Native Superhuman - email client with keyboard shortcuts and AI triagenot reviewedEstablishedA
- Atomic MailProgrammable email inbox for AI agents — JMAP, PoW auth, stdio MCP server.not reviewedEstablishedA
- Email Inbox API + Sending by SendmuxAI email inbox and sending tools with attachments, search, live events, and webhooks.not reviewedEstablishedA
- MCP EmailsNever-stored live email: read, send, organize, schedule and auto-triage Gmail or any IMAP mailbox.not reviewedGrowingA
smbCloud Mail & AuthEmail infrastructure and authentication for developers: domains, inbox routes, auth apps, deploys.not reviewedGrowingA