# @bitfloo/mailoo

Mailoo — email MCP server for IMAP, SMTP, and ManageSieve. Multi-account, per-folder profiles.

- **Type:** MCP server
- **Trust:** 85/100 (A), scored on the package rubric
- **Verification:** verified (build provenance)
- **Version:** 0.1.6
- **Author:** Bitfloo
- **License:** LGPL-3.0-or-later
- **npm:** @bitfloo/mailoo
- **Source:** https://github.com/Bitfloo/mailoo
- **Compatible clients:** claude-code, cursor, copilot, gemini (basis: transport)

## Trust

85/100 (A), scored on the package rubric
- Publisher verified: no
- Build provenance: verified attestation
- npm trusted publishing (OIDC): yes
- Install scripts: nothing suspicious found
- Prompt-injection scan: not run
- Obfuscation scan: not run
- Evidence age: 0 days

## Security scan

- **Status:** clean
- **Scanned:** 2026-09-29T01:53:56.045Z
- **Version scanned:** 0.1.6
- **CVEs:** none found by OSV at scan time

## Tools

40 declared. Statically extracted from the shipped source — a floor on the surface, not a census.
- `list_accounts` — List all configured email accounts. Call this first to discover available account names for use with other tools.
- `get_email_stats` — Get email statistics and analytics for a mailbox. Shows volume, top senders, daily trends, and read/flagged counts.
- `download_attachment` — Download an email attachment by filename. First use get_email to see available attachments and their filenames.
- `bulk_action` — Batch operation on multiple emails by UID list. Supports mark_read, mark_unread, flag, unflag, move, and delete. delete moves the messages to Trash. Max 100 IDs
- `extract_calendar` — Extract calendar events (ICS/iCalendar) from an email. Returns structured event data including time, location, attendees, and status.
- `add_to_calendar`
- `check_calendar_permissions`
- `list_calendars`
- `list_events`
- `list_reminders`
- `create_reminder`
- `analyze_email_for_scheduling`
- `extract_contacts` — Extract unique contacts from recent email headers. Returns contacts sorted by frequency (most frequent first). Useful for finding frequent correspondents or bui
- `save_draft` — Save an email draft to the Drafts folder. Compose over time, then use send_draft to send it. Use list_emails with the Drafts mailbox to see saved drafts.
- `send_draft` — Send an existing draft email and remove it from Drafts. The draft is fetched, sent via SMTP, then deleted. Use list_emails with the Drafts mailbox to find draft
- `list_emails` — List emails in a mailbox with optional filters. Returns paginated results with metadata
- `get_email` — Get the full content of a specific email by ID.
- `get_emails` — Fetch the full content of multiple emails in a single call (max 20).
- `get_email_status` — Get the current read/flag/label state of an email without fetching its body.
- `search_emails` — Search emails by keyword across subject, sender, and body.
- `create_mailbox` — Create a new mailbox (folder). Use '/' as separator for nested folders (e.g., 'Work/Projects'). Use list_mailboxes to see existing folders.
- `rename_mailbox` — Rename an existing mailbox (folder). Use list_mailboxes to see current folder paths.
- `delete_mailbox` — ⚠️ DESTRUCTIVE: Permanently delete a mailbox and ALL its contents. This cannot be undone. Use list_mailboxes to verify the folder path.
- `check_health` — Check connection health, quota, and capabilities for email accounts. Useful for diagnosing issues.
- `list_labels` — List available labels for an email account.
- `add_label` — Add a label to an email.
- `remove_label` — Remove a label from an email. For ProtonMail, this removes the email from the label folder.
- `create_label` — Create a new label. For ProtonMail, creates a folder under Labels/.
- `delete_label` — Delete a label. For ProtonMail, deletes the label folder.
- `find_email_folder` — Find which real mailbox folder(s) an email belongs to.
- `list_mailboxes` — List all mailbox folders for an account with unread counts and special-use flags. Use list_accounts first to get the account name.
- `move_email` — Move an email to a different mailbox folder.
- `delete_email` — Delete an email. By default moves to Trash. Set permanent=true for permanent deletion (⚠️ irreversible).
- `mark_email` — Change email flags — mark as read/unread, flag/unflag. Idempotent: marking an already-read email as read is a no-op.
- `schedule_email` — Schedule an email to be sent at a specific time in the future. The email is queued locally and sent automatically when the time arrives.
- `list_scheduled` — List scheduled emails. Shows pending, sent, or all scheduled emails.
- `cancel_scheduled` — Cancel a scheduled email. Removes it from the queue and moves the associated draft to Trash.
- `get_email_security` — Read-only SPF/DKIM/DMARC and From/Reply-To/Return-Path domain signals for an email.
- `send_email` — Send a new email. Supports plain text or HTML body, CC, BCC, and attachments.
- `reply_email` — Reply to an email with proper threading (In-Reply-To & References headers). Use get_email first to read the original.

## Install

**Verdict: install** — No blocking findings and no open coverage gaps — safe to install as configured.
**Config** (claude-code):
```json
"{\n  \"mcpServers\": {\n    \"mailoo\": {\n      \"command\": \"npx\",\n      \"args\": [\n        \"-y\",\n        \"@bitfloo/mailoo\"\n      ],\n      \"env\": {\n        \"MCP_EMAIL_PASSWORD\": \"<YOUR_MCP_EMAIL_PASSWORD>\",\n        \"MCP_EMAIL_OAUTH2_CLIENT_SECRET\": \"<YOUR_MCP_EMAIL_OAUTH2_CLIENT_SECRET>\",\n        \"MCP_EMAIL_OAUTH2_REFRESH_TOKEN\": \"<YOUR_MCP_EMAIL_OAUTH2_REFRESH_TOKEN>\",\n        \"MCP_EMAIL_ALERT_WEBHOOK_URL\": \"<YOUR_MCP_EMAIL_ALERT_WEBHOOK_URL>\",\n        \"MCP_EMAIL_HTTP_TOKEN\": \"<YOUR_MCP_EMAIL_HTTP_TOKEN>\"\n      }\n    }\n  }\n}"
```
**Credentials it will ask for** (names only — Forge never holds a value):
- `MCP_EMAIL_PASSWORD` — Mcp Email Password (optional)
- `MCP_EMAIL_OAUTH2_CLIENT_SECRET` — Mcp Email Oauth2 Client Secret (optional)
- `MCP_EMAIL_OAUTH2_REFRESH_TOKEN` — Mcp Email Oauth2 Refresh Token (optional)
- `MCP_EMAIL_ALERT_WEBHOOK_URL` — Mcp Email Alert Webhook URL (optional)
- `MCP_EMAIL_HTTP_TOKEN` — Mcp Email Http Token (optional)
Placeholders only. Forge never holds, brokers, or transmits a credential value — replace each <YOUR_NAME> in your own config file. Do not send a value back to Forge; no Forge endpoint accepts one.
- This entry needs 5 credentials (0 required). The generated config carries placeholders, so it will fail in the editor rather than at runtime if they are left unset.

## Blast radius

Critical blast radius — deletes data; holds an oauth grant.
- Floor 65, ceiling 65 (tier: critical)
- This is impact, not likelihood. A high radius is not a defect: a filesystem server is supposed to write files. It is never part of the trust score.

## Machine-readable views of this entry

- Signed JSON: https://forgeregistry.com/api/v1/packages/%40bitfloo%2Fmailoo
- Install plan: https://forgeregistry.com/api/v1/packages/%40bitfloo%2Fmailoo/install-plan
- Alternatives: https://forgeregistry.com/api/v1/alternatives/%40bitfloo%2Fmailoo
- HTML page: https://forgeregistry.com/registry/%40bitfloo%2Fmailoo
- MCP: POST https://forgeregistry.com/api/mcp → `forge_get_package` / `forge_install_plan`

## About this document

Generated by Forge (https://forgeregistry.com) — a compact rendering of the same record served, signed, at the JSON URL above. Trust and scan facts are the registry's own measurements; anything Forge did not measure is named as unmeasured rather than omitted.
