EmailMCP
REMOTE · MCP.SETIP.IO · SCANNED AUG 3
AI agent email — 23 tools free to read inbox, 28 paid to send. $9.99/mo. Token auto-provisioned.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score →
Endpoint Security89
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation is enforced on tool calls, but the challenge carries no valid RFC 9728 metadata, so a client cannot discover where to get a token. See how to fix → View diagnostics → Fail
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability71
- AI-judged instruction clarity (good).Pass
- Tool/resource definitions use about 3724 tokens (~66/item across 56 items; 56 tools + 0 resources), lean.Pass
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management27
- Stability observed for 8 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage99
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 97% of tool parameters carry a description.Partial
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.
remote · mcp.setip.io
claude mcp add --transport http io-setip-emailmcp https://mcp.setip.io/mcp
[mcp_servers.io-setip-emailmcp] url = "https://mcp.setip.io/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"io-setip-emailmcp": {
"type": "remote",
"url": "https://mcp.setip.io/mcp",
"enabled": true
}
}
} openclaw mcp add io-setip-emailmcp --url https://mcp.setip.io/mcp --transport streamable-http
mcp_servers:
io-setip-emailmcp:
url: "https://mcp.setip.io/mcp" {
"mcpServers": {
"io-setip-emailmcp": {
"type": "http",
"url": "https://mcp.setip.io/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 3 Aug 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 23 to 27. That category is still filling its 30-day observation window: 7 days of observed history at the previous scan, 8 at this one. The score rises as the window fills, whether or not the server changes.
- 1 Aug 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 17 to 20. That category is still filling its 30-day observation window: 5 days of observed history at the previous scan, 6 at this one. The score rises as the window fills, whether or not the server changes.
- 31 Jul 26 +5
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 30 Jul 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 29 Jul 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 7 to 10. That category is still filling its 30-day observation window: 2 days of observed history at the previous scan, 3 at this one. The score rises as the window fills, whether or not the server changes.
- 28 Jul 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 3 to 7. That category is still filling its 30-day observation window: 1 days of observed history at the previous scan, 2 at this one. The score rises as the window fills, whether or not the server changes.
- 27 Jul 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 26 Jul 26 70
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 3 Aug 2026 · Probed https://mcp.setip.io/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_256_GCM_SHA384 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=setip.io | CN=YR1,O=Let's Encrypt,C=US | 9 Jul 2026 | 7 Oct 2026 | RSA 2048 | SHA256-RSA | 5db34c4ac6c2e9adc995d07ffbfdfc4c304 |
| SANs: *.setip.io, setip.io | ||||||
| CN=YR1,O=Let's Encrypt,C=US (CA) | CN=Root YR,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | RSA 2048 | SHA256-RSA | a20253f15f2691c05dc1ce13b9bcca4e |
| CN=Root YR,O=ISRG,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | RSA 4096 | SHA256-RSA | f24b6d17f9d9ad7cb1c9fea78782699f |
DNSSEC insecure
Validation of mcp.setip.io. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| io. | present | 57355 | 8 | Verified |
| setip.io. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication Challenged, unverified
The endpoint asked for a token, but we could not retrieve and validate the RFC 9728 metadata that tells a client how to obtain one.
| Result | Challenged, unverified |
|---|---|
| Enforced | On tool calls |
| HTTP status | 200 |
WWW-Authenticate challenge Bearer realm="EmailMCP MCP", error="invalid_token", error_description="Set EMAILMCP_MCP_TOKEN and configure Codex with --bearer-token-env-var EMAILMCP_MCP_TOKEN"
Bearer realm="EmailMCP MCP", error="invalid_token", error_description="Set EMAILMCP_MCP_TOKEN and configure Codex with --bearer-token-env-var EMAILMCP_MCP_TOKEN" | Header | Value |
|---|---|
| strict-transport-security | max-age=31536000; includeSubDomains |
| content-security-policy | default-src 'self';script-src 'self' 'unsafe-inline';style-src 'self' 'unsafe-inline';img-src 'self' data: https:;base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';object-src 'none';script-src-attr 'none';upgrade-insecure-requests |
| x-content-type-options | nosniff |
| x-frame-options | SAMEORIGIN |
| referrer-policy | no-referrer |
Protected resource metadata
| Retrieved | No |
|---|---|
| Problem | no_resource_metadata |
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://mcp.setip.io/mcp | Verified | 200 | |
| http (plaintext) | http://mcp.setip.io/mcp | HTTPS enforced | 301 | https://mcp.setip.io/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.
add_sending_domain ~59
Add a customer sending domain. Generates DKIM keys and returns the 4 DNS records the customer needs to add. Works like SendGrid domain authentication — self-hosted.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Customer domain (e.g. company.com) |
No output schema declared.
No examples provided.
check_email_config ~21
Check if email providers are configured, guide setup if needed
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
check_ip_status ~41
Check the status of a pending WireGuard IP provisioning request
| Name | Type | Req | Description |
|---|---|---|---|
| request_id | string | — | Request ID from request_email_ip (omit to check saved request) |
No output schema declared.
No examples provided.
configure_mailgun ~78
Configure Mailgun email provider with step-by-step guidance
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | string | yes | Mailgun API Key (starts with "key-") |
| domain | string | yes | Mailgun domain (e.g., mg.yourdomain.com) |
| from_email | string | yes | From email address (e.g., [email protected]) |
No output schema declared.
No examples provided.
create_email_account ~82
Create an email account with SMTP credentials. Returns SMTP password once — save it. The account can then send/receive via this server.
| Name | Type | Req | Description |
|---|---|---|---|
| address | string | yes | Email address (e.g. [email protected]) |
| display_name | string | — | Display name for the account |
| domain | string | — | Sending domain (auto-derived from address if omitted) |
No output schema declared.
No examples provided.
create_email_rule ~147
Create a rule that triggers actions when incoming emails match conditions. Actions: forward, auto_reply, webhook, flag, move, mcp_tool, log, reject.
| Name | Type | Req | Description |
|---|---|---|---|
| actions | array | yes | Actions to execute when rule matches |
| description | string | — | What this rule does |
| match | object | yes | Match conditions (ALL must match). Use from, domain, subject, subject_regex, body_contains, has_attachments, to, header. |
| name | string | yes | Rule name (unique) |
| priority | number | — | Priority (lower = evaluated first, default 100) |
| stop | boolean | — | Stop processing further rules after this one matches (default: false) |
No output schema declared.
No examples provided.
create_mailbox ~66
Create a new local mailbox for receiving email (autonomous mode). Each address gets its own inbox accessible via MCP tools.
| Name | Type | Req | Description |
|---|---|---|---|
| address | string | yes | Email address for the mailbox (e.g. [email protected]) |
| display_name | string | — | Display name for the mailbox |
No output schema declared.
No examples provided.
delete_email_account ~33
Delete an email account and revoke its SMTP credentials
| Name | Type | Req | Description |
|---|---|---|---|
| address | string | yes | Email address of the account to delete |
No output schema declared.
No examples provided.
delete_email_rule ~28
Delete an email rule by ID
| Name | Type | Req | Description |
|---|---|---|---|
| rule_id | string | yes | Rule ID to delete |
No output schema declared.
No examples provided.
delete_mailbox ~37
Delete a local mailbox and all its stored emails (autonomous mode)
| Name | Type | Req | Description |
|---|---|---|---|
| address | string | yes | Email address of the mailbox to delete |
No output schema declared.
No examples provided.
get_conversation_context ~49
Get full conversation context for a specific thread
| Name | Type | Req | Description |
|---|---|---|---|
| maxEmails | number | — | Maximum number of emails to include in context |
| threadId | string | yes | Thread ID to get conversation for |
No output schema declared.
No examples provided.
get_conversation_threads ~71
Get conversation threads with forwarded emails
| Name | Type | Req | Description |
|---|---|---|---|
| limit | number | — | Maximum number of threads to return |
| participant | string | — | Filter threads by participant email address |
| since | string | — | Filter threads active since this date (ISO string) |
| subject | string | — | Filter threads by subject content |
No output schema declared.
No examples provided.
get_dns_records ~125
Generate all required DNS records (A, MX, SPF, DKIM, DMARC) for autonomous email. Outputs copyable records for your DNS provider.
| Name | Type | Req | Description |
|---|---|---|---|
| dkim_selector | string | — | DKIM selector (default: emailmcp) |
| dmarc_policy | string | — | DMARC policy (default: reject) |
| domain | string | yes | Your email domain (e.g. company.com) |
| ipv4 | string | yes | Your dedicated IPv4 address (from WireGuard provisioning) |
| mail_hostname | string | — | Mail server hostname (default: mail.domain) |
No output schema declared.
No examples provided.
get_domain_dns_records ~33
Get the DNS records a customer needs to add for a sending domain
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Customer domain |
No output schema declared.
No examples provided.
get_domain_verification_emails ~50
List mails received in the verification window for a given domain (e.g. to find Apple's verification code without checking the forward_to mailbox).
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain to filter on |
No output schema declared.
No examples provided.
get_domain_verification_status ~24
Show active verification windows, the receiver state, and TTLs.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_email_usage ~68
Get email usage statistics — delivery rate, bounce rate, per-domain breakdown, top bounce reasons. Reads from persistent stats.
| Name | Type | Req | Description |
|---|---|---|---|
| account | string | — | Filter stats by account address |
| domain | string | — | Filter stats by domain |
| period | string | — | Time period for usage statistics |
No output schema declared.
No examples provided.
get_forwarded_emails ~73
Retrieve forwarded emails with optional filtering
| Name | Type | Req | Description |
|---|---|---|---|
| limit | number | — | Maximum number of emails to return |
| originalSender | string | — | Filter by original sender email address |
| since | string | — | Filter emails since this date (ISO string) |
| threadId | string | — | Filter by conversation thread ID |
No output schema declared.
No examples provided.
get_health_status ~29
Get current health status of the email server — tunnel, SMTP, DNS, IP blocklist checks
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_idle_status ~31
Get status of IMAP IDLE watchers — which accounts are being watched, connection status, new email counts
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_mailbox_status ~84
Get status information for an email mailbox. If IMAP is configured in .env, no credentials needed. Use "account" to pick a named account.
| Name | Type | Req | Description |
|---|---|---|---|
| account | string | — | Named account (e.g. "work", "personal"). Omit for default. |
| imap_config | object | — | — |
| mailbox | string | — | Mailbox to check |
No output schema declared.
No examples provided.
get_smtp_receiver_status ~21
Get the current status of the SMTP forward receiver
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_suppression_list ~28
View all addresses on the bounce suppression list — these addresses will be rejected on send
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_threads_for_sender ~32
Get all conversation threads involving a specific sender
| Name | Type | Req | Description |
|---|---|---|---|
| senderAddress | string | yes | Email address of the sender |
No output schema declared.
No examples provided.
list_cloud_providers ~24
List supported cloud providers with pricing, regions, and PTR support info
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
list_email_accounts ~29
List all configured IMAP email accounts. Shows default and named accounts (work, personal, etc.).
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
list_email_accounts_managed ~35
List all email accounts with SMTP credentials (optionally filtered by domain)
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | — | Filter by domain |
No output schema declared.
No examples provided.
list_email_rules ~24
List all email rules with their match conditions, actions, and hit counts
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
list_local_mailboxes ~23
List all local mailboxes on this server (autonomous mode)
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
list_mailboxes ~74
List all available mailboxes for an email account. If IMAP is configured in .env, no credentials needed. Use "account" to pick a named account.
| Name | Type | Req | Description |
|---|---|---|---|
| account | string | — | Named account (e.g. "work", "personal"). Omit for default. |
| imap_config | object | — | — |
No output schema declared.
No examples provided.
list_sending_domains ~20
List all configured sending domains with their verification status
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
provision_resume ~50
Resume provisioning from where you left off. Automatically detects the current phase and advances: WireGuard connection → DNS setup → TLS → verification. Run this after each user action (connecting WireGuard, adding DNS records).
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
provision_start ~129
Phase 1: Create a cloud VPS with dedicated IP. Generates WireGuard config. Returns the IP and instructions to connect. Supports DigitalOcean, Vultr, Hetzner, OVH.
| Name | Type | Req | Description |
|---|---|---|---|
| cloud_api_key | string | yes | Cloud provider API key |
| cloud_provider | string | yes | Cloud provider |
| region | string | — | Cloud region (e.g. nyc1, ewr, nbg1, GRA11). Omit for default. |
| service_domain | string | yes | Domain you own for the email service (e.g. emailrelay.xyz). NS will point here. |
No output schema declared.
No examples provided.
provision_status ~23
Show current provisioning state — which phases are complete, what to do next
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
read_inbox ~121
Read emails from an inbox via IMAP with filtering options. If IMAP is configured in .env, no credentials needed. Use "account" to pick a named account (work, personal, etc.).
| Name | Type | Req | Description |
|---|---|---|---|
| account | string | — | Named account to read from (e.g. "work", "personal"). Omit for default account. |
| filter | object | — | — |
| imap_config | object | — | Optional if IMAP is configured in .env (IMAP_HOST, IMAP_EMAIL, IMAP_PASSWORD) |
| options | object | — | — |
No output schema declared.
No examples provided.
regenerate_zone_file ~33
Regenerate the complete DNS zone file for the service domain including all customer subdomains. Use after adding/removing domains.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
remove_from_suppression ~38
Remove an address from the bounce suppression list (manual override to allow sending again)
| Name | Type | Req | Description |
|---|---|---|---|
| address | string | yes | Email address to unblock |
No output schema declared.
No examples provided.
remove_sending_domain ~31
Remove a sending domain and its DKIM keys
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Customer domain to remove |
No output schema declared.
No examples provided.
request_email_ip ~54
Request a dedicated WireGuard IP for email sending. Submits to the provisioning queue.
| Name | Type | Req | Description |
|---|---|---|---|
| account_id | string | — | Optional account identifier |
| email_domain | string | yes | Your email domain (e.g. company.com) |
No output schema declared.
No examples provided.
reset_account_password ~35
Reset the SMTP password for an email account. Returns new password once.
| Name | Type | Req | Description |
|---|---|---|---|
| address | string | yes | Email address of the account |
No output schema declared.
No examples provided.
send_email ~294
Send an email with text or HTML content
| Name | Type | Req | Description |
|---|---|---|---|
| attachments | array | — | Array of file attachments |
| bcc | array | — | Array of BCC recipient email addresses |
| bulk_mode | string | — | Required when sending to multiple recipients. "individual": sends a separate email to each recipient (safest). "bcc": puts first recipient in TO:, rest in BCC. "to": puts all in TO: (exposes addresse… |
| cc | array | — | Array of CC recipient email addresses |
| from | string | — | Personal account address to send from. If set and matching account has personal SMTP/IMAP credentials (via set_personal_email_credentials), sends via that account and IMAP-APPENDs a copy to its Sent… |
| html | string | — | HTML content of the email |
| provider | string | — | Send via a specific provider instead of the default (e.g. smtp, mailgun, sendgrid, ses, gmail, resend). Requires that provider's credentials in env. |
| subject | string | yes | Email subject line |
| text | string | yes | Plain text content of the email |
| to | array | yes | Array of recipient email addresses |
No output schema declared.
No examples provided.
send_template_email ~159
Send an email using a predefined template
| Name | Type | Req | Description |
|---|---|---|---|
| bulk_mode | string | — | Required when sending to multiple recipients. "individual": sends a separate email to each recipient (safest). "bcc": puts first recipient in TO:, rest in BCC. "to": puts all in TO: (exposes addresse… |
| provider | string | — | Send via a specific provider instead of the default (e.g. smtp, mailgun, sendgrid, ses, gmail, resend) |
| subject | string | — | Email subject (can override template subject) |
| template | string | yes | Template name or path |
| to | array | yes | Array of recipient email addresses |
| variables | object | — | Template variables to replace |
No output schema declared.
No examples provided.
set_personal_email_credentials ~274
Attach a personal account's own SMTP + IMAP credentials (iCloud, Gmail app password, Fastmail, Office365, etc.) to an existing account. Once set, send_email with from=<address> sends via that SMTP and IMAP-APPENDs a copy to its Sent folder. Passwords are AES-256-GCM encrypted at rest with EMAILMCP_SECRET.
| Name | Type | Req | Description |
|---|---|---|---|
| address | string | yes | Address of the existing account (must already be created via create_email_account) |
| imap_host | string | yes | e.g. imap.mail.me.com, imap.gmail.com, imap.fastmail.com |
| imap_password | string | yes | IMAP password (often same as SMTP) |
| imap_port | number | — | Default 993 |
| imap_user | string | yes | IMAP username — usually the full email address |
| sent_folder | string | — | Override Sent folder name. Auto-discovered via SPECIAL-USE if omitted. |
| smtp_host | string | yes | e.g. smtp.mail.me.com (iCloud), smtp.gmail.com, smtp.fastmail.com |
| smtp_password | string | yes | SMTP password or app-specific password |
| smtp_port | number | — | Default 587 |
| smtp_user | string | yes | SMTP username — usually the full email address |
No output schema declared.
No examples provided.
setup_autonomous_security ~97
Auto-configure DKIM, SPF, and DMARC for autonomous email. Generates DKIM keys, creates DNS records, and outputs everything needed.
| Name | Type | Req | Description |
|---|---|---|---|
| dkim_selector | string | — | DKIM selector (default: emailmcp) |
| dmarc_policy | string | — | DMARC policy (default: reject) |
| domain | string | yes | Your email domain |
| ipv4 | string | yes | Your dedicated IPv4 address |
No output schema declared.
No examples provided.
start_domain_verification ~183
Begin a domain-verification window: temporarily set the target domain's MX to verify.setip.io, start (or reuse) the EmailMCP SMTP receiver on :25, and forward any inbound mail for *@domain to forward_to so a human can grab a verification code from the provider (Apple/Google/etc). Auto-tears down after ttl_minutes.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain whose MX is being temporarily redirected (must be a POC we own in setipio-api) |
| forward_to | string | yes | Address where verification mails are relayed in real time |
| real_mx_target | string | — | Optional. If provided, on teardown the MX is set to this target (e.g. apple.com) instead of restoring the pre-window snapshot. |
| ttl_minutes | number | — | Auto-teardown after this many minutes (default 60) |
No output schema declared.
No examples provided.
start_health_monitor ~38
Start monitoring the provisioned email server — checks tunnel, SMTP, DNS, and IP reputation every 60 seconds. Auto-restarts on failure.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
start_idle_watch ~69
Start real-time IMAP IDLE watching on email accounts. Get push notifications when new emails arrive. Works with Gmail, iCloud, Office365, etc.
| Name | Type | Req | Description |
|---|---|---|---|
| account | string | — | Account name to watch (e.g. "work", "personal"). Omit to watch all configured accounts. |
No output schema declared.
No examples provided.
start_smtp_receiver ~87
Start the SMTP server to receive forwarded corporate emails
| Name | Type | Req | Description |
|---|---|---|---|
| allowedForwarders | array | — | IP addresses allowed to forward emails (empty = allow all) |
| enableThreading | boolean | — | Enable conversation threading |
| port | number | — | Port to listen on (default: 2525) |
| receivingDomains | array | — | Domains to accept emails for (empty = accept all) |
No output schema declared.
No examples provided.
stop_domain_verification ~82
Tear down an active domain-verification window: restore MX (snapshot or supplied real_mx_target), remove the per-domain forwarder. Stops the receiver if no other windows remain.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain to tear down |
| real_mx_target | string | — | Optional final MX target (e.g. apple.com). Overrides the snapshot restore. |
No output schema declared.
No examples provided.
stop_idle_watch ~40
Stop IMAP IDLE watching on an account (or all accounts)
| Name | Type | Req | Description |
|---|---|---|---|
| account | string | — | Account to stop watching. Omit to stop all. |
No output schema declared.
No examples provided.