yandex-mail-mcp
Provides 28 tools to read, search, send, and manage Yandex Mail emails via the Model Context Protocol.
README
Yandex Mail MCP Server
MCP (Model Context Protocol) server for Yandex Mail. Enables Claude Desktop and other MCP clients to read, search, and manage emails via Yandex Mail — 28 tools covering every common mail workflow.
Features
- Folders — list, create, rename, delete (with Cyrillic names via IMAP UTF-7)
- Search — full IMAP syntax:
FROM/TO/SUBJECT/BODY,LARGER/SMALLER,SENTSINCE/SENTBEFORE,HEADER <field> <value>,KEYWORD/UNKEYWORD,OR/NOT. Cyrillic queries supported. - Read — full content, text + HTML body, attachment list
- Inspect — fetch MIME structure + size WITHOUT downloading bodies (
inspect_email/fetch_part) — critical for large messages - Flags —
mark_read/mark_unread/mark_flagged/mark_answered+ genericset_flags - Send — plain/HTML, attachments (RFC 2231 for non-ASCII names), save-to-Sent
- Reply — proper
In-Reply-To/Referencesthreading, dedupedRe:prefix,reply_allwith RFC 5322 address parsing - Forward — as
message/rfc822attachment or inline quoted body - Move/Delete — atomic
UID MOVE(RFC 6851) when supported, smart Trash discovery via\TrashSPECIAL-USE - Bulk —
bulk_move/bulk_delete/bulk_set_flagsetc. — chunked UID operations for batch workflows - Convenience —
empty_trash,get_unread_summary(counts across all folders in one session)
All operations use stable IMAP UIDs (not sequence numbers), and connection helpers retry transiently on DNS/network flakes.
Quick Start with uvx (recommended)
No install, no venv — uvx fetches the package and runs it sandboxed. Add this to ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or %APPDATA%/Claude/claude_desktop_config.json (Windows):
Option 1: From PyPI
{
"mcpServers": {
"yandex-mail": {
"command": "uvx",
"args": ["yandex-mail-mcp"],
"env": {
"YANDEX_EMAIL": "your-address@yandex.ru",
"YANDEX_APP_PASSWORD": "your-app-password-here"
}
}
}
}
Option 2: From GitHub (latest development build)
{
"mcpServers": {
"yandex-mail": {
"command": "uvx",
"args": [
"--from",
"git+https://github.com/imdeniil/yandex-mail-mcp",
"yandex-mail-mcp"
],
"env": {
"YANDEX_EMAIL": "your-address@yandex.ru",
"YANDEX_APP_PASSWORD": "your-app-password-here"
}
}
}
}
Restart Claude Desktop. The server will appear as yandex-mail with 28 tools available.
To pin to a specific release:
"--from", "git+https://github.com/imdeniil/yandex-mail-mcp@v0.1.1"
Getting a Yandex app password
- Go to Yandex ID
- Enable Two-Factor Authentication (required for app passwords)
- Go to Security → App Passwords
- Create new app password for "Mail"
- Paste the generated password into
YANDEX_APP_PASSWORDabove
Alternative: Install from source
If you want to hack on the code or don't want uvx:
git clone https://github.com/imdeniil/yandex-mail-mcp.git
cd yandex-mail-mcp
python3 -m venv .venv
source .venv/bin/activate
pip install -e . # installs as editable package with deps
# or for dev tools too:
pip install -e ".[dev]"
cp .env.example .env
# Edit .env with your Yandex email and app password
Then point Claude Desktop at the venv's Python:
{
"mcpServers": {
"yandex-mail": {
"command": "/absolute/path/to/yandex-mail-mcp/.venv/bin/yandex-mail-mcp"
}
}
}
Configuration
Credentials
The server looks for credentials in this order (first wins):
- Environment variables
YANDEX_EMAIL/YANDEX_APP_PASSWORD(best for uvx + Claude Desktop) $YANDEX_MAIL_MCP_ENVoverride path to a.envfile$PWD/.env(project-local, for direct invocation)$XDG_CONFIG_HOME/yandex-mail-mcp/.env(typically~/.config/yandex-mail-mcp/.env).envnext toyandex_mail_mcp.py(source checkout)
For Claude Desktop + uvx, just put them in the env block of the config as shown above.
Log file location
The server writes to a log file (stdout is reserved for MCP protocol). Resolution order:
$YANDEX_MAIL_MCP_LOG_FILEoverride$XDG_STATE_HOME/yandex-mail-mcp/yandex_mail_mcp.log(typically~/.local/state/yandex-mail-mcp/yandex_mail_mcp.log)- Next to
yandex_mail_mcp.pyin source checkouts $TMPDIR/yandex_mail_mcp.loglast-resort fallback
Available Tools
28 tools across 6 categories. See CHANGELOG.md for the full list. Key ones:
| Tool | Purpose |
|---|---|
list_folders() |
Enumerate mailbox folders with attrs |
get_unread_summary() |
Unread counts across all folders |
search_emails(folder, query, limit, offset) |
IMAP query with pagination |
inspect_email(folder, email_id) |
Headers + MIME structure, no body download |
fetch_part(folder, email_id, part_number) |
Download a specific MIME part |
read_email(folder, email_id) |
Full text + HTML + attachments |
send_email(to, subject, body, cc, bcc, html, attachments) |
Send |
reply_email(folder, email_id, body, reply_all, ...) |
Reply with threading |
forward_email(folder, email_id, to, body, as_attachment, ...) |
Forward |
move_email / delete_email |
Atomic where possible |
mark_read / mark_unread / mark_flagged / mark_answered |
Flag shortcuts |
bulk_move / bulk_delete / bulk_set_flags |
Batch operations |
create_folder / rename_folder / delete_folder |
Mailbox management |
empty_trash() |
One-call trash cleanup |
Search Query Examples
ALL # All emails
UNSEEN # Unread
FROM sender@example.com # From specific sender
SUBJECT hello # Subject contains "hello"
SINCE 01-Dec-2024 # Received since date
SENTSINCE 01-Jan-2024 # Sent since date
LARGER 1048576 # Larger than 1 MB
HEADER List-Id announce # Custom header search
HEADER X-Custom "multi word value" # Multi-word via shlex
KEYWORD Important # User keyword flag
UNSEEN FROM boss@company.com # Combined (implicit AND)
OR FROM alice@x.com FROM bob@x.com # Logical OR
NOT DELETED # Negation
UNSEEN LARGER 500000 SINCE 01-Jan-2024 # Multi-criteria
Running Tests
# Install dev deps
pip install -e ".[dev]"
# Safe tests (always run — unit + read-only integration)
pytest
# Full suite including destructive + send (modifies mailbox, sends mail)
pytest --run-destructive
# Specific category
pytest -m destructive --run-destructive
pytest -m send --run-destructive
Integration tests require .env with valid credentials. Destructive and send tests are gated behind --run-destructive for safety.
Security Notes
-
send_emailattachments can read any file accessible to the server process. Theattachmentsparameter accepts absolute file paths, so in principle an LLM could be prompt-injected (e.g. via the body of an incoming email read throughread_email) into attaching sensitive files such as~/.ssh/id_rsato an outgoing message. This is inherent to exposing a filesystem-reading primitive over MCP.Mitigations:
- Every
send_emailcall must be approved by you in the MCP client (Claude Desktop shows tool calls before executing them — always read which files are being attached before approving). - Every attachment path is written to the log file for audit.
- Run the server as a user that only has access to files you are willing to send by email.
- Every
-
download_attachmentsanitises filenames from received email (strips path components, asserts the resolved path stays withinsave_dir) so a malicious sender cannot write outside the target directory. -
delete_folderis destructive. Behavior on non-empty folders is server-dependent per RFC 3501 §6.3.4. Approve carefully. -
Credentials come from environment variables (MCP client config) or a
.envfile. Keep.envout of version control.
Not supported (intentionally)
Verified empirically against imap.yandex.com:
- ManageSieve / server-side filters — Yandex does not expose the ManageSieve protocol (port 4190 closed, no
SIEVEcapability). User filter rules ("Правила обработки писем") can only be managed through the Yandex web UI. This MCP server provides client-side equivalents viabulk_*+ conditional logic. - SORT / THREAD extensions (RFC 5256) — Yandex returns
BAD Command syntax error. Sort client-side if needed. - IDLE push notifications — supported by Yandex but not exposed as an MCP tool because long-polling doesn't fit the stateless request/response model. Use
get_folder_statusorget_unread_summaryfor polling instead.
License
MIT
推荐服务器
Baidu Map
百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。
Playwright MCP Server
一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。
Magic Component Platform (MCP)
一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。
Audiense Insights MCP Server
通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。
VeyraX
一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。
graphlit-mcp-server
模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。
Kagi MCP Server
一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。
e2b-mcp-server
使用 MCP 通过 e2b 运行代码。
Neon MCP Server
用于与 Neon 管理 API 和数据库交互的 MCP 服务器
Exa MCP Server
模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。