Safe-by-default MCP server for Microsoft Outlook mail (Microsoft Graph) — read, search, draft, send, reply, forward and organize email, with browser sign-in.
- ✓Open-source license (MIT)
- ✓Actively maintained (<30d)
- ✓Clear description
- ✓Topics declared
- ✓Documented (README)
claude mcp add mcp-outlook -- npx -y @dockndevai/mcp-outlook{
"mcpServers": {
"mcp-outlook": {
"command": "npx",
"args": ["-y", "@dockndevai/mcp-outlook"],
"env": {
"OUTLOOK_TOKEN": "<outlook_token>"
}
}
}
}OUTLOOK_TOKENMCP Servers overview
# mcp-outlook
[](https://www.npmjs.com/package/@dockndevai/mcp-outlook)
[](https://github.com/dockndevai/mcp-outlook/actions/workflows/ci.yml)
[](LICENSE)
A **safe-by-default** [Model Context Protocol](https://modelcontextprotocol.io) server for **Microsoft Outlook** mail, over [Microsoft Graph](https://learn.microsoft.com/graph/overview). It lets an agent read and operate a mailbox — list folders and messages, full-text **search**, read bodies and attachment metadata, list contacts, and (in higher modes) create drafts, **send / reply / forward**, mark read, move messages, and delete.
**Browser sign-in:** on first run it opens your browser to the Microsoft sign-in page, then caches the token and refreshes it silently — the server never sees your password.
Part of the [dockndevai MCP server suite](https://dockndevai.github.io/) — one governance model across all of them.
## What it gives an agent
The server starts **read-only** (see [Safe by default](#safe-by-default)); higher-capability tools are only registered when you raise the mode.
| Tool | For | Needs mode |
|---|---|---|
| `whoami` | confirm which mailbox is in use | read-only |
| `list_folders` | mail folders with unread/total counts | read-only |
| `list_messages` | recent messages (by folder, unread-only) | read-only |
| `search_messages` | full-text search across the mailbox | read-only |
| `get_message` | one message with full body + recipients | read-only |
| `list_attachments` | attachment metadata (bytes not returned) | read-only |
| `list_contacts` | personal contacts | read-only |
| `create_draft` | prepare a draft without sending | read-write |
| `send_mail` | compose & send a new email | read-write + `OUTLOOK_ALLOW_SEND` |
| `reply_mail` / `forward_mail` | reply (all) / forward a message | read-write + `OUTLOOK_ALLOW_SEND` |
| `mark_read` | mark read / unread (reversible) | read-write |
| `move_message` | move to another folder (reversible) | read-write |
| `delete_message` | delete (to Deleted Items) | admin + `OUTLOOK_ALLOW_DELETE` |
## Install
```bash
npx -y @dockndevai/mcp-outlook
```
You need an **Entra (Azure AD) app registration**. For the default browser sign-in, register a **public client** and add the redirect URI `http://localhost` (platform: *Mobile and desktop applications*), then use its **Application (client) ID** as `OUTLOOK_CLIENT_ID`. Grant delegated **Mail.Read** (and **Mail.Send** / **Mail.ReadWrite** if you want to send or organize). No client secret is needed for interactive use.
Prefer automation? Use **app-only** auth instead: set `OUTLOOK_CLIENT_SECRET` + `OUTLOOK_TENANT_ID` + `OUTLOOK_USER` (see [Authentication](#authentication)).
## Configure
```json
{
"mcpServers": {
"outlook": {
"command": "npx",
"args": ["-y", "@dockndevai/mcp-outlook"],
"env": {
"OUTLOOK_CLIENT_ID": "00000000-0000-0000-0000-000000000000",
"OUTLOOK_TENANT_ID": "common",
"OUTLOOK_MODE": "read-only"
}
}
}
}
```
On first use the server opens your browser to sign in and caches the token at `~/.mcp-outlook/token.json` (0600); later runs refresh silently.
See [docs/CLIENTS.md](docs/CLIENTS.md) for Claude Code / Cursor / Codex / VS Code / Windsurf snippets, and [.env.example](.env.example) for every supported variable.
## Authentication
Auth mode is chosen automatically (override with `OUTLOOK_AUTH`):
- **interactive** (default) — only `OUTLOOK_CLIENT_ID` set. Authorization-code + PKCE with a loopback redirect: the browser opens, you approve once, and the access + refresh token are cached on disk. Operates on the signed-in user's mailbox (`/me`). The server never handles your password.
- **client-credentials** (app-only) — `OUTLOOK_CLIENT_SECRET` present. The server fetches an app token itself; requires `OUTLOOK_TENANT_ID` and `OUTLOOK_USER` (the mailbox to act on, since an app token has no signed-in user). Grant the app **application** Mail permissions with admin consent.
- **token** — `OUTLOOK_TOKEN` set to a pre-obtained Graph bearer token. You manage its lifetime.
## Safe by default
The access model is enforced by [`src/security.ts`](src/security.ts) — defence in depth on top of the Graph token's own scopes/roles:
- **`OUTLOOK_MODE`** — `read-only` (default) → `read-write` → `admin`. A tool is registered only if the mode allows its capability. Read-only exposes the 7 read tools; drafts/moves need `read-write`; deletes need `admin`.
- **`OUTLOOK_ALLOW_SEND`** — sending mail (send / reply / forward) can't be undone, so on top of `read-write` it also requires this flag. Drafting is always allowed in read-write; nothing leaves the mailbox until sent.
- **`OUTLOOK_ALLOW_DELETE`** — deletes require this flag on top of `admin` mode.
- **`OUTLOOK_FOLDER_ALLOWLIST` / `OUTLOOK_PROTECTED_FOLDERS`** — confine which folders can be written to / moved into; mark folders (e.g. `sentitems`, `archive`) that may be read but never modified.
- **Interactive confirmation** — when the client supports MCP elicitation, sending mail and deleting a message pause and ask the **human** to approve before running; clients that can't elicit fall back to the `OUTLOOK_ALLOW_SEND` / `OUTLOOK_ALLOW_DELETE` gates.
- **`OUTLOOK_DRY_RUN`** — validate and log writes without executing them.
- **`OUTLOOK_AUDIT_LOG`** — a JSON audit line per guarded operation, on stderr (default on).
- **Attachment bytes are never returned** — `list_attachments` returns metadata only.
See [SECURITY.md](SECURITY.md).
## Developing
```bash
npm install
npm run build
# introspect the tool list without signing in (uses a fake token, no network):
echo '{"jsonrpc":"2.0","id":1,"method":"tools/list","params":{}}' | OUTLOOK_TOKEN=x node dist/index.js
npm test
```
## Licence
MIT
What people ask about mcp-outlook
What is dockndevai/mcp-outlook?
+
dockndevai/mcp-outlook is mcp servers for the Claude AI ecosystem. Safe-by-default MCP server for Microsoft Outlook mail (Microsoft Graph) — read, search, draft, send, reply, forward and organize email, with browser sign-in. It has 0 GitHub stars and its last recorded update is dated 2026-09-15.
How do I install mcp-outlook?
+
You can install mcp-outlook by cloning the repository (https://github.com/dockndevai/mcp-outlook) or following the README instructions on GitHub. ClaudeWave also provides quick install blocks on this page.
Is dockndevai/mcp-outlook safe to use?
+
Our security agent has analyzed dockndevai/mcp-outlook and assigned a Trust Score of 95/100 (tier: Verified). See the full breakdown of passed checks and flags on this page.
Who maintains dockndevai/mcp-outlook?
+
dockndevai/mcp-outlook is maintained by dockndevai. The last recorded GitHub activity is dated 2026-09-15, with 0 open issues.
Are there alternatives to mcp-outlook?
+
Yes. On ClaudeWave you can browse similar mcp servers at /categories/mcp, sorted by popularity or recent activity.
Deploy mcp-outlook to your cloud
Ship this repo to production in minutes. Each platform spins up its own environment with editable env vars.
Maintain this repo? Add a badge to your README
Drop the badge into your GitHub README to show it's tracked on ClaudeWave. Each badge links back to this page and reflects the live Trust Score.
[](https://claudewave.com/repo/dockndevai-mcp-outlook)<a href="https://claudewave.com/repo/dockndevai-mcp-outlook"><img src="https://claudewave.com/api/badge/dockndevai-mcp-outlook" alt="Featured on ClaudeWave: dockndevai/mcp-outlook" width="320" height="64" /></a>More MCP Servers
Fair-code workflow automation platform with native AI capabilities. Combine visual building with custom code, self-host or cloud, 400+ integrations.
User-friendly AI Interface (Supports Ollama, OpenAI API, ...)
An open-source AI agent that brings the power of Gemini directly into your terminal.
Real-time global intelligence dashboard. AI-powered news aggregation, geopolitical monitoring, and infrastructure tracking in a unified situational awareness interface
🕷️ An adaptive Web Scraping framework that handles everything from a single request to a full-scale crawl! Don't be shy, join here: https://discord.gg/EMgGbDceNQ
The fastest path to AI-powered full stack observability, even for lean teams.