EmailDiscussions.com

EmailDiscussions.com (http://www.emaildiscussions.com/index.php)
-   FastMail Forum (http://www.emaildiscussions.com/forumdisplay.php?f=27)
-   -   FM adds an MCP server (http://www.emaildiscussions.com/showthread.php?t=81457)

TenFour 23 Apr 2026 08:08 PM

FM adds an MCP server
 
For connecting your favorite AI to your Fastmail account. https://www.fastmail.com/blog/an-mcp...-for-fastmail/

Grhm 24 Apr 2026 08:33 AM

Not quite as sinister as I thought, the way Rob explains it. But it's more than a little concerning that one of the permissions users can grant to our unaccountable AI robot overlords is not merely to draft e-mails for us but actuallly to send e-mails on our behalf.

JeremyNicoll 25 Apr 2026 04:41 AM

Quote:

Originally Posted by Grhm (Post 647466)
But it's more than a little concerning that one of the permissions users can grant to our unaccountable AI robot overlords is not merely to draft e-mails for us but actuallly to send e-mails on our behalf.


Yes I agree; not least because it seems to me that an AI-powered sender could send loads of (weird?) spam ... and what will that do to the reputation of FM's outgoing servers? Or is this no worse than's been possible for years with programs connecting to their SMTP servers?


My first impression when I read:

Quote:

"The OAuth consent screen will give you a choice of three levels of access: read-only (see emails, contacts, calendars), write (update emails, save drafts, edit contacts and events), and send (send emails)."
was that this is not nearly fine-grained enough (though maybe the blog was just being high-level/vague). Does the protocol allow someone to limit its access to just part of one's mail, and/or a subset of contacts, and/or to specific calendars, and/or a subset of info in those calendars?

Even if the protocol allows fine-grain control, have FM implemented it?

If it sees mails - does it see all of their headers too - or just the message?

TenFour 25 Apr 2026 08:26 AM

My guess is your AI client can "see" and edit anything you can see and edit using the web interface.

hadaso 25 Apr 2026 08:54 AM

I'm quite sure that to send spam using FM all one needs is to connect thorough SMTP and submit it' and that the same protections they use to detect sending spam through email clients or the webmail app would work with an MCP client trying to send spam.
I'm also quite sure that you can get an AI agent to handle your FM acount without using MCP by having it control an email client on your own computer or having it control your browser and using the webmail app.
I guess using MCP can make it more efficient by letting a cloud based AI agent interact directly with FM.
Incidentally, just a few hours before I saw this post I witnessed for the first time someone actually using AI to control their email. This person uses Outlook on his work account and has an AI agent that interacts with the mail client and also with his notes and perhaps work databases. He asked the AI agent to deal with replying to an email from a customer. The AI read the email, looked up past correspondence with the client, checked the notes and the databases for anything relevant, composed a reply and asked for confirmation before sending. All this required just a few seconds. The AI can also determine if there is information missing and suggest who to contact to get the required info, and can then send an email to various colleagues, wait for replies, nag if required, and when everything is ready send a reminder to finish the job, or can be preauthorized to finish the job without confirmation.
I don't think that I'm going to trust AI to control my data for the time being, but younger people do. I think read-only access can be very useful, and also read-only plus writing drafts (but without the ability to delete email or move it around for the time being).
Seeing examples of how MCP can be used with FM can be useful.
AI can be like an extremely smart person most of the time, but at other times can act like a complete moron (like some of the most powerful people on earth). So I would hesitate to give it to much control on my email account without understanding how I can control it.


All times are GMT +9. The time now is 12:50 PM.


Copyright EmailDiscussions.com 1998-2022. All Rights Reserved. Privacy Policy