maillog-mcp
OfficialClick on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@maillog-mcpSend an email to jane@example.com saying the report is ready."
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
@maillog/node-sdk
Node SDK and MCP server for the Maillog email API. Other languages: Python · Go · Ruby · PHP · Rust
Install
npm install @maillog/node-sdkRelated MCP server: Inbound Email MCP Server
Get a key without an account
curl -X POST https://api.maillog.nl/v1/keys/sandbox \
-H "Content-Type: application/json" \
-d '{"email":"you@example.com"}'The key it returns may only send to that address and expires after 24 hours. For your own domains, sign up at https://maillog.nl/signup.
Send
import { Maillog } from "@maillog/node-sdk";
const maillog = new Maillog(process.env.MAILLOG_API_KEY);
const { id } = await maillog.emails.send({
from: "Acme <noreply@acme.nl>",
to: ["you@example.com"],
subject: "hello",
html: "<p>it works</p>",
});emails.sendBatch(emails) takes 1 to 100 at a time. emails.list({ limit, offset, status })
returns what was sent, with delivery status and open/click counts.
Errors
Failures throw MaillogError with .status and .body, so a 422 from validation
and a 403 from an expired key can be handled apart.
import { MaillogError } from "@maillog/node-sdk";
try {
await maillog.emails.send(params);
} catch (err) {
if (err instanceof MaillogError && err.status === 422) {
// body carries errors[] with the offending field
}
}There is no retry logic, on purpose: a client that silently resends produces duplicate mail, and only you know whether that is acceptable.
MCP server
The package ships an MCP server so an assistant can send mail directly.
claude mcp add maillog --env MAILLOG_API_KEY=ma_xxx -- npx -y maillog-mcpTools: send_email, list_emails.
Options
new Maillog(apiKey, {
baseUrl: "http://localhost:3086", // default https://api.maillog.nl
timeoutMs: 30_000,
});Develop
npm run build # tsc to dist/
node --test src/*.test.tsMIT.
Available Tools
2 toolslist_emailsList sent emailsA
List emails previously sent through Maillog, newest first, with delivery status and open/click counts. Use this to check whether a message actually went out.
| Name | Required | Description | Default |
|---|---|---|---|
| limit | No | ||
| offset | No | ||
| status | No | Filter, e.g. "sent", "queued", "failed" |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries the burden. It adds behavioral details by specifying ordering ('newest first') and return fields ('delivery status and open/click counts'). However, it doesn't address pagination defaults, rate limits, or the meaning of status values.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is two short sentences with the action front-loaded. Every clause adds information—resource, ordering, output, and use case—leaving no filler.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
The description covers the essential return contents and use case, but with no output schema and no annotations, it leaves some gaps around default limit, response format, and failure behavior. Adequate for a simple list but not fully complete.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Only status has a schema description; limit and offset have none, and the description doesn't explain them. The schema coverage is 33%, below the 50% threshold, so the description needed to compensate and didn't.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description states a clear action ('List') and target resource ('emails previously sent through Maillog'), and it notes output contents ('delivery status and open/click counts'). This makes it easily distinguishable from its only sibling, send_email, which is a write operation.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The phrase 'Use this to check whether a message actually went out' provides an explicit use case. It doesn't spell out exclusions or name send_email, but the context of listing vs sending makes the choice clear.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
send_emailSend an emailA
Send a transactional email through Maillog. The 'from' address must be on a domain verified in the Maillog dashboard, except for sandbox keys, which may only send to the address the sandbox key was issued for.
| Name | Required | Description | Default |
|---|---|---|---|
| cc | No | ||
| to | Yes | Recipient addresses | |
| bcc | No | ||
| from | Yes | Sender, e.g. "Acme <noreply@acme.nl>" | |
| html | No | HTML body. Provide html or text. | |
| text | No | Plain text body. Provide html or text. | |
| subject | Yes | ||
| reply_to | No |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries the disclosure burden. It adds a meaningful behavioral constraint: 'from' must be on a domain verified in Maillog, and sandbox keys may only send to the address the key was issued for. However, it does not disclose failure behavior, delivery semantics, or other side effects beyond the act of sending.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is two sentences long: the first states the purpose, the second states the key constraint. There is no filler, and the most important information is front-loaded before the caveat.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For an 8-parameter write operation with no annotations and no output schema, the description is minimally adequate: it gives the core purpose and one critical precondition. It omits response/error behavior, the need to supply html or text, and any guidance about selecting this tool over list_emails, leaving clear gaps.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is only 50%; from, to, html, and text have schema descriptions, while cc, bcc, subject, and reply_to do not. The description adds important meaning to 'from' by requiring a verified domain and to 'to' through the sandbox restriction, but it does not compensate for the wholly undocumented remaining parameters.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description uses a specific verb and resource: 'Send a transactional email through Maillog.' The action 'Send' immediately distinguishes this tool from the read-oriented sibling list_emails, so an agent can tell them apart without inspecting the schema.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
There is no explicit when-to-use or when-not-to-use guidance. The phrase 'transactional email' implies the intended context, and the sibling list_emails is clearly a different operation, but no alternative or exclusion condition is named. Usage is only implied, not stated.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections. Dates show when Glama detected each change.
2 tool updates
v0.1.0- First observed
list_emails - First observed
send_email
TDQS
send_email and list_emails are clearly distinct: one creates a new email, the other reads previously sent emails. There is no overlap or ambiguity between the two operations.
Both tool names follow a consistent verb_noun snake_case pattern, matching the broader MCP convention. The style is predictable and uniform across the small set.
Two tools is on the thin side for a server, but the pair covers the core send-and-verify workflow implied by the Maillog domain. It is functional yet minimal, so the count is borderline appropriate.
The server covers the essential email send and delivery-check lifecycle with no obvious dead ends. Minor gaps exist, such as no single-email detail lookup or domain management, but the core workflow is workable.
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Connectors
Email infrastructure for AI agents — send, receive, search, and reply to email over MCP.
Send, track, and manage transactional and bulk email delivery
Send email and read templates, marketing contacts, lists, stats, bounces and unsubscribes.
Email for AI agents — send, receive as a webhook, manage domains, templates, routing.
Related MCP Servers
- FlicenseNot gradedqualityDmaintenanceEnables creating temporary email inboxes and sending emails through the AgentMail API, allowing AI agents to manage email communications programmatically.1-
- FlicenseBqualityDmaintenanceEnables AI assistants to interact with the Inbound Email API to manage domains, endpoints, and email communications. Users can send or schedule emails, manage webhooks, and retrieve email threads through natural language commands.142-
- AlicenseNot gradedqualityDmaintenanceEnables email integration via IMAP and SMTP, allowing model assistants to read, send, search emails, and list folders.7714ISC
- AlicenseNot gradedqualityCmaintenanceEnables AI agents to interact with Microsoft 365 Outlook Mail, allowing email operations via natural language.29MIT
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/maillog-dev/sdk-node'
If you have feedback or need assistance with the MCP directory API, please join our Discord server