# io.github.parasxos/apple-mail-mcp (pypi · apple-mailbox-mcp)

Fast local Apple Mail MCP: indexed search, full-text bodies, verified sends, triage. macOS.

- Trust score: 80/100 (high trust)
- Change this week: +3
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-09-20

## Components

- pypi · `apple-mailbox-mcp`: 80/100 (this document), [markdown](https://verifymcp.io/servers/parasxos-apple-mail-mcp/apple-mailbox-mcp.md), [page](https://verifymcp.io/servers/parasxos-apple-mail-mcp/apple-mailbox-mcp)

## Channel facts

- Registry: `pypi`
- Package: `apple-mailbox-mcp`
- Version: `1.7.0`
- Transport: `stdio`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-09-20.

- **Supply Chain Security**: 100/100
  - No malware found by supply-chain analysis.
  - No known CVEs affecting this package version or its production dependencies.
  - Runs setuptools.build_meta at install time, a recognised native-build step with no shell scripting around it.
  - 1 of 30 dependencies flagged as unhealthy.
- **Provenance & Transparency**: 32/100
  - Source repository is publicly reachable at the declared URL.
  - Provenance check failed: no build-provenance attestation is published.
  - License check failed: no license is declared.
  - Actively maintained (last published 5 days ago).
  - Disclosure check failed: no security disclosure policy was found in the source repository.
- **Schema Quality & AI Usability**: 79/100
  - AI-judged instruction clarity (excellent).
  - Tool/resource definitions use about 1862 tokens (~88/item across 21 items; 21 tools + 0 resources), lean.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 83/100
  - Stability observed for 25 of 30 days with no destabilising changes; credit accrues until the full window elapses.
- **Tool Coverage**: 100/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 100% of tool parameters carry a description.
  - Structured output schemas are declared (100% of tools); any adoption earns full credit.
- **Tool Safety**: 100/100
  - No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.
  - All 4 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.
  - An AI judge read all 21 captured unit(s) of tool text and found none that tries to manipulate the model reading it.
- **Capabilities**: 100/100
  - Implements a current MCP spec version (2026-07-28).

## Install

### How do I install the io.github.parasxos/apple-mail-mcp server?

io.github.parasxos/apple-mail-mcp runs locally as a PyPI package, launched with uvx apple-mailbox-mcp. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

### Claude

```bash
claude mcp add parasxos-apple-mail-mcp -- uvx apple-mailbox-mcp
```

### Cursor

```json
{
  "mcpServers": {
    "parasxos-apple-mail-mcp": {
      "command": "uvx",
      "args": [
        "apple-mailbox-mcp"
      ]
    }
  }
}
```

### VS Code

```json
{
  "servers": {
    "parasxos-apple-mail-mcp": {
      "command": "uvx",
      "args": [
        "apple-mailbox-mcp"
      ]
    }
  }
}
```

### Codex

```bash
codex mcp add parasxos-apple-mail-mcp -- uvx apple-mailbox-mcp
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "parasxos-apple-mail-mcp": {
      "type": "local",
      "command": [
        "uvx",
        "apple-mailbox-mcp"
      ],
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add parasxos-apple-mail-mcp --command uvx --arg apple-mailbox-mcp
```

### Hermes

```yaml
mcp_servers:
  parasxos-apple-mail-mcp:
    command: "uvx"
    args: ["apple-mailbox-mcp"]
```

### Netclaw

```json
{
  "McpServers": {
    "parasxos-apple-mail-mcp": {
      "Transport": "stdio",
      "Command": "uvx",
      "Arguments": [
        "apple-mailbox-mcp"
      ]
    }
  }
}
```

### Vellum

```bash
assistant mcp add parasxos-apple-mail-mcp -t stdio -c uvx -a apple-mailbox-mcp
```

### Other

```json
{
  "mcpServers": {
    "parasxos-apple-mail-mcp": {
      "command": "uvx",
      "args": [
        "apple-mailbox-mcp"
      ]
    }
  }
}
```

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-09-19 (score 80, +1)

No change was recorded against any check on this day. Stability & Change Management went from 77 to 80. That category is still filling its 30-day observation window: 23 days of observed history at the previous scan, 24 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-17 (score 79, +1)

No change was recorded against any check on this day. Stability & Change Management went from 70 to 73. That category is still filling its 30-day observation window: 21 days of observed history at the previous scan, 22 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-15 (score 78, +16)

- [security improvement] Malware scan: unverified → pass

### 2026-09-14 (score 62, −15)

- [security regression] Malware scan: pass → unverified
- [functional] Package version: 1.6.0 → 1.7.0

### 2026-09-12 (score 77, +1)

- [security regression] Stability: 0.53 → unverified
- [security regression] Tool safety: pass → unverified
- [functional regression] Capabilities: pass → unverified
- [functional regression] Tool coverage: 100 → unverified
- [functional] First check of Schema quality: unverified
- [functional] Package version: 1.5.2 → 1.6.0

### 2026-09-10 (score 76, +1)

No change was recorded against any check on this day. Stability & Change Management went from 47 to 50. That category is still filling its 30-day observation window: 14 days of observed history at the previous scan, 15 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-08 (score 75, +1)

No change was recorded against any check on this day. Stability & Change Management went from 40 to 43. That category is still filling its 30-day observation window: 12 days of observed history at the previous scan, 13 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-06 (score 74, +1)

No change was recorded against any check on this day. Stability & Change Management went from 33 to 37. That category is still filling its 30-day observation window: 10 days of observed history at the previous scan, 11 at this one. The score rises as the window fills, whether or not the server changes.

## MCP tools (21)

### `search_emails` (~205 tokens)

Search emails

Search local envelope data and full bodies; sender filters are case-insensitive substring matches.

Input parameters:

- `account`: Account UUID; omit it to include every configured account.
- `after`: Only include mail after this ISO-8601 date or timestamp.
- `before`: Only include mail before this ISO-8601 date or timestamp.
- `from_addr`: Sender name, address, or address fragment to match.
- `has_attachment`: True for mail with attachments, false for mail without them.
- `limit` (integer): Maximum number of results to return.
- `mailbox`: Mailbox name to search, such as INBOX or Archive.
- `offset` (integer): Number of matching results to skip for pagination.
- `query` (string): Words to find in the subject, sender, snippet, or indexed body.
- `to_addr`: Recipient name, address, or address fragment to match.
- `unread_only` (boolean): When true, include only unread messages.

### `get_email` (~59 tokens)

Read an email

Read one email by envelope ID at full, metadata, or minimal detail.

Input parameters:

- `id` (string, required): Envelope ID returned by search, recent, or thread tools.
- `view` (string): Payload size: full, metadata without bodies, or minimal.

### `get_emails_batch` (~62 tokens)

Read multiple emails

Read up to 50 emails in one bounded request, with per-ID errors.

Input parameters:

- `ids` (array, required): Envelope IDs returned by search, recent, or thread tools.
- `view` (string): Payload size: full, metadata without bodies, or minimal.

### `get_thread` (~33 tokens)

Read an email thread

Return the messages in one conversation in chronological order.

Input parameters:

- `thread_id` (string, required): Conversation ID returned on an email reference.

### `list_mailboxes` (~20 tokens)

List mailboxes

List configured mailboxes with server and locally readable counts.

### `list_recent` (~65 tokens)

List recent emails

List recent messages, optionally scoped to an account and mailbox.

Input parameters:

- `account`: Account UUID; omit it to include every configured account.
- `limit` (integer): Maximum number of results to return.
- `mailbox`: Mailbox name to search, such as INBOX or Archive.

### `get_attachment` (~49 tokens)

Save an attachment for reading

Save one attachment to the configured temporary directory for reading.

Input parameters:

- `attachment_id` (string, required): Attachment part ID returned by get_email.
- `id` (string, required): Envelope ID of the email containing the attachment.

### `refresh_mail` (~56 tokens)

Refresh mail

Ask Mail.app to fetch new mail and report the before/after snapshot.

Input parameters:

- `timeout_seconds` (number): Maximum seconds allowed for the Mail.app refresh request.
- `wait_seconds` (number): Seconds to wait after Mail.app starts refreshing.

### `list_scheduled` (~50 tokens)

List scheduled emails

List healthy and damaged scheduled-mail records by lifecycle state.

Input parameters:

- `limit` (integer): Maximum number of results to return.
- `state`: Scheduled-mail state to return; omit it to include all states.

### `doctor` (~21 tokens)

Check email setup

Diagnose permissions, identities, transports, scheduling, storage, and indexing.

### `audit` (~126 tokens)

Read the activity history

Read the local mutation ledger with time, tool, event, plan, and operation filters.

Input parameters:

- `event`: Only return activity with this event name.
- `limit` (integer): Maximum number of results to return.
- `operation_id`: Operation ID that joins related activity across processes.
- `plan_id`: Triage plan ID returned by a planning tool.
- `since`: Inclusive ISO-8601 start bound; calendar prefixes are accepted.
- `tool`: Only return activity emitted by this tool name.
- `until`: Inclusive ISO-8601 end bound; calendar prefixes are accepted.

### `send_email` (~120 tokens)

Send an email

Compose standards-correct MIME and send it through the selected identity.

Input parameters:

- `attachments`: Optional list of local file paths, one path per item.
- `bcc`: Optional comma-separated Bcc recipients.
- `body` (string, required): Plain-text email content; paragraph breaks are preserved.
- `cc`: Optional comma-separated Cc recipients.
- `from_identity`: Configured sending identity; omit it to use the default.
- `subject` (string, required): Email subject line.
- `to` (string, required): Comma-separated primary recipients, including optional display names.

### `create_draft` (~117 tokens)

Create an email draft

Create a never-sent draft in the selected identity's server-side Drafts folder.

Input parameters:

- `body` (string, required): Plain-text email content; paragraph breaks are preserved.
- `cc`: Optional comma-separated Cc recipients.
- `from_identity`: Configured sending identity; omit it to use the default.
- `in_reply_to` (string): Optional Message-ID used to thread the draft as a reply.
- `subject` (string, required): Email subject line.
- `to` (string, required): Comma-separated primary recipients, including optional display names.

### `reply_email` (~144 tokens)

Reply to an email

Reply with correct threading, optional history, attachments, and reply-all.

Input parameters:

- `attachments`: Optional list of local file paths, one path per item.
- `bcc`: Optional comma-separated Bcc recipients.
- `body` (string, required): Plain-text email content; paragraph breaks are preserved.
- `cc`: Optional comma-separated Cc recipients.
- `from_identity`: Configured sending identity; omit it to use the default.
- `id` (string, required): Envelope ID of the email being answered.
- `include_history` (boolean): Quote the original message below the new reply.
- `reply_all` (boolean): Also copy the original To and Cc recipients, excluding yourself.

### `cancel_scheduled` (~39 tokens)

Cancel a scheduled email

Revoke a pending scheduled email locally and, when needed, in Exchange.

Input parameters:

- `id` (string, required): Scheduled-email ID returned when it was created.

### `triage_plan` (~211 tokens)

Prepare mailbox changes

Prepare a reviewable bulk-change plan; sender filters use case-insensitive substring matching.

Input parameters:

- `account`: Account UUID; omit it to include every configured account.
- `actions`: Mailbox actions to stage for every selected message.
- `after`: Only include mail after this ISO-8601 date or timestamp.
- `before`: Only include mail before this ISO-8601 date or timestamp.
- `from_addr`: Sender name, address, or address fragment to match.
- `has_attachment`: True for mail with attachments, false for mail without them.
- `limit` (integer): Maximum messages to stage; 0 uses the configured safe plan cap.
- `mailbox`: Mailbox name to search, such as INBOX or Archive.
- `query` (string): Words to find in the subject, sender, snippet, or indexed body.
- `to_addr`: Recipient name, address, or address fragment to match.
- `unread_only` (boolean): When true, include only unread messages.

### `triage_plan_delete` (~198 tokens)

Prepare email deletion

Prepare a capped Trash plan whose sender filter is exact, never a broad substring match.

Input parameters:

- `account`: Account UUID; omit it to include every configured account.
- `after`: Only include mail after this ISO-8601 date or timestamp.
- `before`: Only include mail before this ISO-8601 date or timestamp.
- `from_addr`: Exact sender email address to match; fragments never select mail.
- `has_attachment`: True for mail with attachments, false for mail without them.
- `limit` (integer): Maximum messages to stage; 0 uses the configured deletion cap.
- `mailbox`: Mailbox name to search, such as INBOX or Archive.
- `query` (string): Words to find in the subject, sender, snippet, or indexed body.
- `to_addr`: Recipient name, address, or address fragment to match.
- `unread_only` (boolean): When true, include only unread messages.

### `triage_apply` (~37 tokens)

Apply reviewed mailbox changes

Apply one reviewed plan and verify each resulting mailbox state.

Input parameters:

- `plan_id` (string, required): Triage plan ID returned by a planning tool.

### `mailbox_create` (~54 tokens)

Create a mailbox

Create a mailbox idempotently and report live and index verification.

Input parameters:

- `account` (string, required): Account UUID that will own the mailbox.
- `path` (string, required): Mailbox path within the account; slashes create nested folders.

### `mailbox_delete` (~53 tokens)

Delete a mailbox

Delete an empty mailbox only, with live verification and safe fallback.

Input parameters:

- `account` (string, required): Account UUID that owns the mailbox.
- `path` (string, required): Mailbox path within the account; slashes create nested folders.

### `schedule_email` (~143 tokens)

Schedule an email

Freeze an email now and schedule local or Exchange-side delivery.

Input parameters:

- `attachments`: Optional list of local file paths, one path per item.
- `bcc`: Optional comma-separated Bcc recipients.
- `body` (string, required): Plain-text email content; paragraph breaks are preserved.
- `cc`: Optional comma-separated Cc recipients.
- `from_identity`: Configured sending identity; omit it to use the default.
- `send_at` (string, required): Delivery time in ISO-8601; a timestamp without an offset is local time.
- `subject` (string, required): Email subject line.
- `to` (string, required): Comma-separated primary recipients, including optional display names.

## Diagnostics

Captured diagnostic sections: Provenance, Install scripts, Dependencies. The full working is on the page: https://verifymcp.io/servers/parasxos-apple-mail-mcp/apple-mailbox-mcp#diagnostics

## Score history

- 2026-09-20: 80
- 2026-09-19: 80
- 2026-09-18: 79
- 2026-09-17: 79
- 2026-09-16: 78
- 2026-09-15: 78
- 2026-09-14: 62
- 2026-09-13: 77
- 2026-09-12: 77
- 2026-09-11: 76
- 2026-09-10: 76
- 2026-09-09: 75
- 2026-09-08: 75
- 2026-09-07: 74
- 2026-09-06: 74
- 2026-09-05: 73
- 2026-09-04: 73
- 2026-09-03: 72
- 2026-09-02: 72
- 2026-09-01: 69
- 2026-08-31: 69
- 2026-08-30: 69
- 2026-08-29: 69
- 2026-08-28: 69
- 2026-08-27: 69
- 2026-08-26: 69

## Common questions

### What is the io.github.parasxos/apple-mail-mcp server?

io.github.parasxos/apple-mail-mcp is listed in the public MCP registry as io.github.parasxos/apple-mail-mcp. Fast local Apple Mail MCP: indexed search, full-text bodies, verified sends, triage. macOS. This page covers its PyPI package (apple-mailbox-mcp).

### Is the io.github.parasxos/apple-mail-mcp server safe to use?

io.github.parasxos/apple-mail-mcp scores 80 out of 100 on VerifyMCP. We found no known CVEs affecting it as of 20 September 2026. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

### What tools does the io.github.parasxos/apple-mail-mcp server expose?

io.github.parasxos/apple-mail-mcp exposes 21 tools: search_emails, get_email, get_emails_batch, get_thread, list_mailboxes, and 16 more. Their descriptions and schemas cost roughly 1,862 tokens of context every time the server is loaded.

### Is the io.github.parasxos/apple-mail-mcp server still maintained?

io.github.parasxos/apple-mail-mcp is still listed as active in the MCP registry. We last reached this channel on 20 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

## Links

- PyPI project: https://pypi.org/project/apple-mailbox-mcp/
- Socket report: https://socket.dev/pypi/package/apple-mailbox-mcp
- Repository: https://github.com/parasxos/apple-mail-mcp
- Changelog RSS feed: https://verifymcp.io/servers/parasxos-apple-mail-mcp/apple-mailbox-mcp.xml
- Changelog JSON feed: https://verifymcp.io/servers/parasxos-apple-mail-mcp/apple-mailbox-mcp.json
- HTML version of this page: https://verifymcp.io/servers/parasxos-apple-mail-mcp/apple-mailbox-mcp
