Type "can ChatGPT read my email" into Google and you get a page of confident yeses. Type the same question about Claude, Copilot or Gemini and you get the same yeses, from the same handful of sites, each one ending in a pitch for a different product. The answer is true. It is also the least useful true thing anyone could tell you, because in September 2026 all four of them can read your email. Which AI can actually manage your email, for the mailbox you probably have, is a different question, and none of those pages ask it.
I spent the better part of two weeks reading what the four vendors actually publish about their own email integrations, first on 30 August and again today, 12 September, because two of the pages changed in between. What I found is that "can it read my email" is the wrong question, and that the four questions underneath it get four different answers per vendor, some of which contradict other pages on the same vendor's site.
This is a comparison of ChatGPT, Claude, Copilot and Gemini for email, taken from their documentation rather than their marketing, with every claim linked so you can check it. I will tell you now where it lands, because you would work it out from the table anyway: for most of the mailboxes people actually have, the best answer is not any of the four vendors' own integrations but a connector that gives the assistant you already pay for the whole mailbox, and the one I recommend is ours. The disclosure below says so plainly, and the table is there so you can check the working rather than take my word. Where a vendor does not say, the table says "not stated" rather than guessing, and there is one question none of them answers at all. (The generic question, what an AI can do with your email at all, has its own page on the product site; this one is about the four vendors by name.)
Disclosure, before you read further
The last third of this article names Mailbox MCP as the route to the mailboxes the four vendors do not reach. We build and sell it. 365i publishes this site and I build that product. Everything about the vendors is sourced to their pages, and our own column in the table carries its crosses like everyone else's. I think it is the best option in the comparison, and I have put it next to the alternatives rather than instead of them so you can disagree with the evidence in front of you. Read the rest knowing who is writing it.
Can AI read my email? Yes, and that is the least useful true answer
The reason the yes is useless is that reading was never the hard part. "Which AI can manage your email" and "can AI manage my inbox" are the questions people actually type, and what decides the answer is a set of narrower questions underneath them. I would put them in this order.
Which mailbox can it reach? Gmail is not the same as Google Workspace, a work Microsoft 365 account is not the same as a personal @outlook.com address, and neither of them is the mailbox your web host gave you with your domain. Each vendor draws that line somewhere different, and for most people the line falls short of the address they actually use for business.
Once it is in, what can it change? Summarising is not filing. Drafting is not sending. Applying a label is not moving a message to a folder. Every vendor documents the reading verbs in detail and the writing verbs sparingly, and the gaps between them are where your workflow lives.
Does it wait to be asked, or does it watch? Until three weeks ago the answer for all four was "waits". That changed on 25 August, for one of them, on one mailbox type, on paid plans only.
Will it press Send? Three postures exist: it sends after you approve, it never sends by design, or it sends on shared mailboxes but not your own. Which posture you get depends on the vendor, the product within the vendor, and in one case on a setting your administrator has to find.
Behind those four sits a fifth that I have not seen anybody ask, and I will get to it: does the act of an assistant reading a message mark it as read?
ChatGPT vs Claude vs Copilot vs Gemini for email: the capability table
Seven vendor products, because "Claude" is three separate email integrations with three different answers and conflating them is the commonest mistake in the articles that currently rank for "ChatGPT vs Claude for email", most of which compare writing style and never ask which mailbox either one can open. The eighth column is ours, so you can see where the ticks fall against the same rows, and it carries its crosses like everyone else. (The same seven, set against a connector row by row, are on the native connectors versus MCP page in the Mailbox MCP documentation, which is where this table started.) Every cell was checked against the vendor's page on 12 September 2026. A tick means the vendor documents it, a cross means the vendor documents that it does not, a half circle means it is documented with a condition the cell names, and a dash means not stated anywhere we could find, which is the most common cell and the most honest one.
- Documented by the vendor
- Documented, on a condition the cell names
- Documented as not available
- Not stated anywhere on the vendor's pages
| Capability | Claude Gmail | Claude M365 | Claude Outlook add-in | ChatGPT Gmail | ChatGPT Outlook | Copilot Outlook | Gemini Gmail | Mailbox MCP (ours) |
|---|---|---|---|---|---|---|---|---|
| Search and read | Yes, documented. | Yes, documented. | Yes, documented. | Yes, documented. | Yes, documented. | Yes, documented. | Yes, documented. | Yes, documented. |
| Send mail | Yes, documented.asks approval | Yes, documented.admin must enable | No, documented as not available.by design | Yes, documented.paid plans | Partly, on a condition.shared mailboxes only | Not stated by the vendor. | No, documented as not available. | Yes, documented.client can require approval |
| Reply and forward | Yes, documented. | Yes, documented. | Partly, on a condition.drafts only | Not stated by the vendor. | Not stated by the vendor. | Not stated by the vendor. | Partly, on a condition.drafts only | Yes, documented.dedicated tools, threaded |
| Move to a folder | Not stated by the vendor. | No, documented as not available.no tool | Yes, documented. | Not stated by the vendor. | Partly, on a condition.shared mailboxes only | Yes, documented. | Not stated by the vendor. | Yes, documented.500 per call |
| Trash or delete | Not stated by the vendor. | Yes, documented.to Deleted Items | Not stated by the vendor. | Not stated by the vendor. | Not stated by the vendor. | Yes, documented. | Partly, on a condition.beta only | Yes, documented.to Trash, never erased |
| Archive | Not stated by the vendor. | Not stated by the vendor. | Yes, documented. | Not stated by the vendor. | Not stated by the vendor. | Yes, documented. | Partly, on a condition.beta only | Yes, documented. |
| Label or category | Yes, documented.labels | Yes, documented.categories | Not stated by the vendor. | Not stated by the vendor. | Not stated by the vendor. | Yes, documented. | Partly, on a condition.beta only | Partly, on a condition.as folders |
| Flag for follow-up | Not stated by the vendor. | No, documented as not available.no tool | Yes, documented. | Not stated by the vendor. | Not stated by the vendor. | Yes, documented. | Partly, on a condition.beta only | Yes, documented.500 per call |
| Mark read or unread | Not stated by the vendor. | No, documented as not available.no tool | Not stated by the vendor. | Not stated by the vendor. | Partly, on a condition.shared mailboxes only | Yes, documented. | Partly, on a condition.beta only | Yes, documented.only when asked |
| Reacts to new mail | No, documented as not available. | No, documented as not available. | No, documented as not available. | Yes, documented.since 25 Aug 2026 | No, documented as not available. | Partly, on a condition.preview, not in the EU | No, documented as not available. | No, documented as not available.by design |
| Read attachments | No, documented as not available.metadata only | Yes, documented. | Yes, documented.not PDF | Not stated by the vendor. | Yes, documented.own mailbox only | Not stated by the vendor. | Not stated by the vendor. | Yes, documented.PDF, Office, pictures, scans |
| Send with attachments | Not stated by the vendor. | No, documented as not available.rejected | Not applicable. | Not stated by the vendor. | Not stated by the vendor. | Not stated by the vendor. | Not stated by the vendor. | Yes, documented.four routes, 10 MB |
| Leaves mail unread after reading it | Not stated by the vendor. | Not stated by the vendor. | Not stated by the vendor. | Not stated by the vendor. | Not stated by the vendor. | Not stated by the vendor. | Not stated by the vendor. | Yes, documented.measured |
| Personal @outlook.com | No, documented as not available. | No, documented as not available.stated | Not stated by the vendor. | No, documented as not available. | Not stated by the vendor. | Partly, on a condition.read only | No, documented as not available. | Yes, documented.one Microsoft sign-in |
| Any IMAP mailbox | No, documented as not available. | No, documented as not available. | No, documented as not available. | No, documented as not available. | No, documented as not available. | No, documented as not available. | No, documented as not available. | Yes, documented. |
| Works in more than one AI client | No, documented as not available.Claude only | No, documented as not available.Claude only | No, documented as not available.Outlook only | No, documented as not available.ChatGPT only | No, documented as not available.ChatGPT only | No, documented as not available.Copilot only | No, documented as not available.Gmail only | Yes, documented.Claude, ChatGPT, Cursor and more |
| Free tier | Partly, on a condition.pages disagree | Yes, documented. | No, documented as not available. | Not stated by the vendor. | Not stated by the vendor. | Partly, on a condition.chat only | Partly, on a condition.US only | Yes, documented.5 calls a day, no card |
Four things to notice before the detail. The "any IMAP mailbox" row is a solid line of crosses until the last column. The "leaves mail unread after reading it" row is a solid line of dashes until the last column, where the answer is measured rather than stated. The "works in more than one AI client" row is the quiet one: every vendor integration works inside that vendor's assistant and nowhere else, and a connector works in all of them. And the only tick in the "reacts to new mail" row is three weeks old, and it is not ours: a connector does nothing until a client asks, which is a limit we chose and one the last section explains.
Which mailbox each AI email assistant can actually reach
Start here, because if the answer is "not yours" nothing else in the table matters.
Claude reaches Google accounts through its Gmail connector and Microsoft business tenants through its Microsoft 365 connector. (Both routes, and the custom-connector route with its app-password dead end, are walked through in can Claude read my email, which is the single-vendor version of this section.) The second has a condition Anthropic states plainly: it "requires a Microsoft Entra tenant tied to a Microsoft Business plan. Personal Microsoft accounts (such as @outlook.com or @hotmail.com addresses) can't be used to connect." That refuses Microsoft's own consumer mail. The Claude for Outlook add-in needs Exchange Online and does not run on Outlook for iOS or Android.
ChatGPT reaches Gmail and Outlook through its apps: you connect ChatGPT to Gmail with a Google sign-in and connect ChatGPT to Outlook with a Microsoft one, with Outlook oriented at Entra accounts and the shared and delegated mailboxes of an organisation. Since 28 August you can connect more than one Google account, so a personal and a work Gmail can sit in the same conversation. The plan gates, and where ChatGPT stops, are in can ChatGPT read my email.
Copilot is two products wearing one name. At work, Microsoft says it "supports primary mailboxes that are hosted on Exchange Online", and as of a page update on 8 September 2026 it "is also available on users' archive mailboxes and shared and delegate mailboxes that they have access to", though still not group mailboxes. That sentence read the opposite way a fortnight ago, which is the clearest example I have of why the date on a comparison matters. For personal accounts, Copilot at copilot.com connects to Outlook.com and, unusually, to Gmail, and its documented verbs are all reading: find emails, get a contact's address, check the calendar. (Copilot Studio, Microsoft's agent builder, is the one Microsoft surface that takes a custom connector; its setup page is one of the thirteen.)
Gemini reaches Gmail and nothing else, and Google is narrowing that. From January 2027 Gmail "will fully remove 'Send as' for third-party accounts, Gmailify, and POP", so the trick of pulling a non-Google mailbox into Gmail to get Gemini over it has an end date. Availability is also gated by geography: for personal Gmail without a paid plan, Google says access "is currently limited to the US".
Put those four together and a pattern falls out. No vendor connects to an IMAP mailbox. The address your web host gave you with your domain, the Fastmail or iCloud account, the mailbox on a Plesk or cPanel server that half of UK small business still runs on, is reachable by none of the four through their own integrations. (It is reachable by any IMAP connection, which is the whole point of the last third of this article.) That is not an oversight in the table. It is the shape of the market, and it is why Mailbox MCP exists: one connector that reaches Gmail, a work Microsoft 365 tenant, a personal outlook.com address and any IMAP host, and hands the same tool set to the assistant on all of them.
What each AI can do once it is in your inbox: read, file, flag, delete
This is where the marketing and the documentation part company. Every vendor says its assistant can "manage" your email. Ranked by how much of the mailbox the vendor actually documents it changing, the order is not the one you would guess.
Copilot in Outlook, with a licence, changes the most. Microsoft's triage page lists pin, flag, mark read or unread, archive, delete, move, copy, mark as junk, set categories, create folders and create inbox rules, and says Copilot "performs the requested action and updates your mailbox in Outlook automatically". It is the fullest set of filing verbs any vendor publishes. Two limits: the feature "is currently available only in English", and the newer agentic inbox, which can move, archive, flag and write rules from a chat, is a Frontier preview that Microsoft says "is not currently available to users in the EU".
Claude's Microsoft 365 connector sends but cannot file. Anthropic publishes the connector's tool list, which is the most checkable evidence in this whole comparison, and reading it is more useful than reading any feature page. There are tools to search, send, forward, trash, untrash and batch-delete, five draft tools including one that updates a draft in place, and a set of "label" tools that the document says operate on Outlook categories rather than folders. What is missing is the interesting half: no move-to-folder tool, no mark-read tool, no flag tool. The connector can put a message in Deleted Items and cannot put it in a folder called Invoices. (What a move actually does to a message, and which mail an assistant should be kept away from, is the subject of can an AI sort my emails into folders.) It also carries three safeguards worth knowing before you rely on it: "Emails Claude sends include an attribution header identifying them as agent-initiated", per-user limits apply to sends with no number published, and "Attachments aren't supported in any write tool".
Claude for Outlook, the add-in, moves and flags but never sends. It is a different product from the connector, in beta on Pro, Max, Team and Enterprise, and it uses Microsoft Graph for "thread retrieval, search, free/busy lookups, and move or flag operations". So on the same Microsoft mailbox, one Anthropic product can send and cannot move, and the other can move and cannot send. If you want both you run both.
Claude's Gmail connector sends, replies, forwards and labels. The help centre lists search and read, drafting, "Send, reply to, and forward emails from Gmail", and "Manage email organization with labels and threads". Move, trash, archive, flag and mark-read do not appear on the page at all, and "attachment content is not directly accessible through Gmail (metadata only)". Engadget's how-to of 8 September confirms the sending works on every plan, which matters because Anthropic's own developer documentation still says otherwise, and I will come back to that.
ChatGPT is a split answer. On Gmail, OpenAI's release note of 8 June 2026 says "you can now ask ChatGPT to draft and send emails directly from the same conversation", on Plus, Pro, Business and Enterprise. On Outlook the capability list for the signed-in user's own mailbox contains search, retrieval, full message text, people lookup and contact management, and no write action on a message at all. (Search is the verb every product in the table has, and the one nobody tests; can an AI find old emails is about why searching by meaning beats searching by string, and why IMAP search behaves unlike Gmail.) Then the same page says that for "supported shared or delegated mailboxes, ChatGPT can read messages, browse folders, mark messages as read or unread, move messages, and send plain-text email from or on behalf of the mailbox". A shared support inbox can be filed and answered from ChatGPT. Your own inbox, per the document, can be read.
Gemini in Gmail drafts and summarises, and files only in a beta. "Help me write", conversation summaries, search and "Help me schedule" are the documented core. Google's Gmail help does list "Archive your emails, Delete your emails, Label your emails, Mark or unmark your emails as read, Star your emails", with an explicit confirmation card, a 60-second undo and a refusal above 10,000 matching threads. A Gmail star is the follow-up flag under another name, which is why it sits in that row of the table. But the section opens with a gate that comparison articles keep omitting: "This feature is available through Gemini Beta (for work accounts only and enabled by organization), and Workspace Experiments (a trusted tester program for personal accounts)." If your administrator has not opted in, or you are on a personal account outside the tester programme, the filing verbs are not there.
Set the seven side by side and every one has a hole: Claude's connector cannot file, ChatGPT cannot file your own Outlook mailbox, Gemini files only in a beta, Copilot files only with a licence and only in English. Mailbox MCP's tool list has every verb in this section on every mailbox it connects: move, archive, flag, mark read and unread, delete to Trash, each in batches of up to 500, plus reply and forward as dedicated tools that keep the conversation threaded. It is the only column in the table with no hole in the filing rows.
Does the AI watch your inbox or wait to be asked?
Every dedicated email assistant product on the market sells against this line. Their pitch, and it is a fair one, is that the big four only act inside a chat you opened, so they cannot tell you the moment something important lands. For three of the four that is still true. For one it stopped being true on 25 August 2026.
OpenAI's release note for that day says scheduled tasks in ChatGPT Work "can use webhooks to respond when something changes in a supported app", that "supported webhooks include new Gmail messages", and that Plus and Pro users "can ask Work on web, iOS, and Android to respond when a new Gmail message arrives". The note adds that "actions that require approval pause until you review them", which is the right design and the detail I would want to know. It is Gmail only, it needs a paid plan, and it is three weeks old, but it is a real trigger and it makes ChatGPT the only one of the four whose documentation describes reacting to mail rather than being asked about it.
Microsoft's agentic Copilot in Outlook is the nearest thing to a second yes, and it comes with two asterisks: it is a preview available "only to users who are part of the Frontier program", and it is not available in the EU. Gemini's Agent Mode, which is where Google's autonomous inbox actions live, was US-only and Ultra-gated at our August reading. Claude has nothing autonomous over mail on any of its three products. Nothing runs unless you, or a client acting for you, asks.
I want to be fair to the dedicated products here, because this section could read as "the big four have caught up". They have not. A product built to watch a mailbox all day, sort it, chase replies and book meetings is doing a different job from a chat assistant with a webhook, and for some people it is the right job; buy an AI email assistant, or use the subscription you have sets the two approaches against each other without a feature grid. What a session-bound assistant can do well is triage on demand, and can an AI manage my inbox is the method: survey first, decide in batches, act last. The distinction this article cares about is narrower: whether the assistant you already pay for can be made to react at all, and for one of them the documented answer is now yes.
Will ChatGPT, Claude, Copilot or Gemini actually send an email?
Three postures, and every product in the table takes one of them.
Sends after you approve. Claude on Gmail: "By default, Claude asks for your approval before each of these actions", where the actions are send, reply and forward. Claude on Microsoft 365, once an administrator enables write tools. And ChatGPT: can ChatGPT send emails? Yes, on Gmail and Outlook on paid plans, with sending classed as an important action that asks first. Whatever the posture, the working method is the same, and can an AI answer my emails is the long version: draft first, send second, and brief it on tone before either.
Never sends, by design. Claude for Outlook, and Anthropic's wording is the clearest statement of the posture any vendor has published:
"Claude never sends mail or invites on its own. The add-in does not request the
Anthropic, in Use Claude for Outlook, product documentation read 12 September 2026 (verify quote at source)Mail.Sendpermission. Every draft lands unsent in Outlook's compose or appointment form, and you click Send."
What I like about that sentence is that it is a fact about permissions rather than a promise about behaviour. A product that asks nicely before sending can be talked out of asking. A product that never obtained the permission to send cannot send, whatever an email in the inbox tells it to do. Copilot in Outlook and Gemini in Gmail take the same posture without saying it as sharply: their documented drafting flows all end with a person pressing Send, and neither page contains a sending verb the assistant performs itself.
Sends on shared mailboxes but not your own. ChatGPT's Outlook app, per its own capability list, which is the odd one out and worth reading twice before you assume it covers your inbox.
OpenAI's description of its workspace agents, from April, is the most useful general statement of how the approval posture is meant to work, and it names email specifically:
"When you delegate work to an agent, you stay in control. You decide what tools and data it can use, what actions it can take, and when it needs approval. For sensitive steps, like editing a spreadsheet, sending an email, or adding a calendar event, you can require the agent to ask for permission before moving forward."
OpenAI, in Introducing workspace agents in ChatGPT, 22 April 2026 (verify quote at source)
Read that next to the Anthropic sentence and you can see the two philosophies side by side. OpenAI's is a permission you configure; Anthropic's add-in is a permission that was never requested. Both are defensible. The thing to notice is the phrase "you can require", because the default is what most people will run, and a default is a decision someone else made for you. On every product in this table, find out what happens when you do not touch the settings, and then decide whether that is the mailbox you want to hand over.
Mailbox MCP takes the first posture and makes it the client's decision rather than ours. Every tool that sends, replies or forwards is annotated destructive, which is the signal a client uses to stop and ask, so in Claude you can leave reading on "always allow" and keep sending on "ask every time", and in ChatGPT the same actions fall under the confirmations OpenAI describes above. The tool list shows the annotation against each of the 32, so you know before you connect which ones your client will ask about.
Where OpenAI, Anthropic, Microsoft and Google contradict their own documentation
When we first read all of this on 30 August we found six places where one vendor page said one thing and another page from the same vendor said the opposite. I re-checked them today. One has since been fixed, which I will note because it is only fair, and four still stand. Quote one half of any of these and you are wrong, and can be shown to be wrong from the vendor's own site.
Anthropic, on who gets Gmail. The help centre says the Google Workspace connectors "are available for all users on Claude and Claude Desktop". The developer documentation for the same integration says "Available on Pro, Max, Team, and Enterprise plans". Both pages were live today.
Anthropic, on whether Claude can write to Gmail. The help centre's FAQ: "Can Claude send emails on my behalf? Yes." The developer documentation's Limitations warning, same day: "Claude cannot create, send, or modify emails." The help centre is the newer page and matches what the product does; the developer page is the one Google returns second for "can claude read my email".
OpenAI, on Outlook writes. The Outlook app's capability list for your own mailbox has no message writes, yet the requested permissions include Mail.ReadWrite and Mail.Send, and the June release note says ChatGPT sends from a connected Outlook account. The page documents shared-mailbox sending in detail and says nothing about sending from your own.
Microsoft, on what Copilot does without a licence. The licence comparison page describes work-data reasoning without a Copilot add-on as "Limited (uploaded files)". The Outlook chat page says that without the add-on you can "ask questions about your inbox, calendar, meetings and other limited data and take action directly in Outlook", and offers "Flag all unread emails from my manager" as an example prompt. If you run a Microsoft 365 business tenant and have been told you need the add-on to do anything useful with mail, try it before you buy it.
The one that was fixed. On 30 August, Anthropic's Microsoft 365 setup page opened its permissions section with "Permissions are read-only" and then listed Mail.Send under write permissions on the same page. Today it reads "Permissions are read-only by default. Claude can only send, create, or update content if you enable write tools." That is the correct sentence, and somebody at Anthropic wrote it in the last fortnight. Documentation that gets corrected is documentation somebody is reading, which is a point in its favour, not against.
I find the contradictions oddly reassuring rather than damning. They are what you get when a product changes faster than the people writing about it, and every vendor in this table shipped something new to email in the last five weeks. The lesson is not that the vendors are careless. It is that any comparison without a date on it is already wrong, including this one, eventually. It is also the standard we hold our own column to: every number about Mailbox MCP is derived from the two source files that register its tools and checked by a script that fails when the site and the server disagree, which is how the parent post caught its own tool count moving from 28 to 31 while it was being written.
Does an AI reading your email mark it as read? Nobody says
Here is the fifth question, does AI mark emails as read when it reads them, and it is the one I most wanted an answer to, because the unread flag is how a lot of people, me included, keep track of what still needs a human. If an assistant triages eighty unread messages by opening each one, and opening marks it read, the triage has destroyed the only signal you had, and there is no undo at that scale.
Across seven products and every page I read, twice, no vendor states either way what an ordinary read does to the unread flag. The only read-state statement anywhere is ChatGPT being able to mark shared-mailbox messages read or unread when you ask it to, which is a different thing. The cell is a dash seven times across.
I can tell you what ours does, because we measured it: reading never sets the seen flag, and marking read is a separate tool that runs only when asked. It is the first entry on the features page because it is the one that decided how everything else was built. I cannot tell you what theirs do, and neither can they, in writing. So if the unread flag matters to you, run the test yourself before you let anything triage in volume. Send yourself a message, ask the assistant to summarise it, and look at your inbox. It takes a minute and it is the single most useful minute in this article. Run it on a Mailbox MCP connection and the message is still unread afterwards, which is the measurement that put the one tick in that row.
Prompt injection: email is attacker-controlled text
There is one risk that applies to every product in the table equally, and it is not about which vendor you pick. Anyone can send you an email. That means anyone can put text in front of the assistant reading your inbox, and text is how you instruct an assistant. Anthropic says this plainly in the Claude for Outlook documentation: "Email bodies and attachments are untrusted input and may contain instructions intended to manipulate Claude rather than you."
Simon Willison, who has been writing about this class of attack since before most of these products existed, gave it the name that stuck:
"The LLM vendors are not going to save us! We need to avoid the lethal trifecta combination of tools ourselves to stay safe."
Simon Willison, independent developer and creator of Datasette, in The lethal trifecta for AI agents, 16 June 2025 (verify quote at source)
The trifecta is access to private data, exposure to untrusted content, and the ability to communicate externally. An email assistant with a send tool has all three by definition, and Willison's own example in that post is exactly this: a tool that can access your email is "a perfect source of untrusted content: an attacker can literally email your LLM and tell it what to do". I read that sentence in June last year and thought it was a problem for other people. Then I connected a real business mailbox to an assistant and watched it read a newsletter, and the thought that followed was not about the newsletter. It was that every message in that inbox had been written by someone who was not me, and I had just handed all of them a seat at the table.
What tool design can do is bound the damage, and this is where the table earns its keep. Nothing on Claude's Microsoft 365 connector erases mail; delete goes to Deleted Items. Claude for Outlook cannot send at all. Gemini's filing actions need a confirmation and undo for 60 seconds. ChatGPT pauses approval-gated actions in a triggered task until you review them. None of those makes injection go away. All of them turn "the assistant was tricked" from a disaster into an inconvenience, and that is the property to shop for. Is it safe to give an AI access to your email turns that into eight questions to put to any vendor, ours included, and the security page is our answer to all eight, including what we hold and what we will not do.
The mailboxes none of the four reach, and the route that does
Go back to the reach section and count. Gmail: Claude, ChatGPT, Gemini, and Copilot for personal accounts. Microsoft 365 work tenant: Claude, ChatGPT, Copilot. Personal Outlook.com: Copilot, reading only. Everything else: nobody.
"Everything else" is a larger group than the vendor pages make it look. It is the mailbox that came with your domain on your web host. It is Fastmail, iCloud Mail, Proton via its bridge, Zoho, and every mail server a business runs for itself. It is the personal @outlook.com address in Claude, refused by name. It is a Microsoft 365 mailbox whose administrator will not enable the Claude write tools, or a Google Workspace domain where Gemini Beta is off. For all of those, the four vendors' own integrations answer the question in this article's title with "none of them".
The documented route to those mailboxes is a custom connector: a remote server that speaks the Model Context Protocol and presents the mailbox to the assistant as a set of named tools. (Remote matters: a local server is a program on your machine, which a browser-based client cannot start, while a remote one is a URL.) Anthropic allows these on every plan, including Free, which is capped at one connector (the Claude.ai setup page is Settings, Connectors, Add custom connector, and a URL, and Claude Desktop takes the same URL). OpenAI documents them for "ChatGPT Business and Enterprise/Edu customers on ChatGPT web"; on 1 September 2026 we watched a ChatGPT Plus account connect one and send a real email through it (the ChatGPT setup page records the developer-mode steps), which is past that documentation and might not stay that way. Both facts, the promise and the measurement, belong in the same sentence.
The case for going that way rather than buying another assistant was put well by someone with no stake in ours, on the day the protocol was published:
"Open technologies like the Model Context Protocol are the bridges that connect AI to real-world applications, ensuring innovation is accessible, transparent, and rooted in collaboration."
Dhanji R. Prasanna, Chief Technology Officer at Block, in Introducing the Model Context Protocol, Anthropic, 25 November 2024 (verify quote at source)
"Bridges" is the word I keep coming back to, and I did not expect a launch-day quote from a payments company to age this well. The four vendors have each built a private road from their assistant to the two mailbox providers big enough to be worth a road. A bridge is a different thing: it is built once, to a published shape, and any assistant that speaks the protocol can cross it to any mailbox on the other side. That is what lets one connector serve Claude, ChatGPT, Cursor and a dozen editors without a separate integration for each, and it is what puts the mailbox on your web host on the same footing as Gmail.
That is what Mailbox MCP is, and here is where the disclosure at the top applies. It is our product. It connects any IMAP mailbox, Gmail or Microsoft 365, and hands the assistant 32 email tools, every one of them named on the tool list, with a call cost published against every scenario. There is a written setup page for each of thirteen clients and a guide per task, because a generic README helps nobody at the moment they are stuck on the wrong menu. Read its column against the seven beside it and the case makes itself. It reaches every mailbox in the table, including the two the vendors refuse: any IMAP host and a personal outlook.com address. It has a tool for every filing verb in the table at once, where each vendor has some and not others, and it moves, flags and marks up to 500 messages in one call. Its reply and forward are dedicated tools that keep the thread intact in Outlook, which is the thing that separates "supports replies" from "replies correctly". Since 12 September it also reads what is inside an attachment, not only the message around it: a PDF invoice or a Word contract as text, a spreadsheet with its formulas already worked out, a photographed receipt as a picture, with a zip or an old .doc named rather than opened and the file's contents treated as exactly as untrusted as the email that carried it. Reading never marks a message read, delete goes to Trash and nothing on the surface erases mail, so a pass that went wrong is recoverable. And it is the only column that works in more than one assistant: the same connector serves Claude, ChatGPT, Cursor, VS Code and a dozen more, so switching assistant does not mean starting again. With a calendar connected it adds up to 21 more tools, all 21 on Microsoft 365, and the calendar can be Google, Microsoft 365 or any CalDAV server, which is the same "everything else" the mail side covers. Since 16 September an address book adds 5 contact tools on the same pattern: a CardDAV book on any mailbox that connects with a password (Fastmail, iCloud, Nextcloud, Zoho and most mail hosts), or your Outlook contacts arriving with a Microsoft 365 sign-in, so a card is found, read in full, added, corrected or deleted in your own book where your phone sees it, and a webmail export is imported as a vCard file. Google's own contacts are the one book it does not reach, because Google's CardDAV endpoint takes only a Google sign-in. Its real limits are in the column too: it cannot watch a mailbox and act on its own, it cannot send on a schedule, labels are reached as folders, and the free tier is five calls a day per mailbox. When we asked Gemini to assess it against the vendors' own documentation it called it "the gold standard"; an assistant's opinion of a product is not evidence and I would not lead with it, but the table above is the reasoning it used, and you can run the same comparison yourself. The companion article is the long version, with the email MCP servers compared and the five-step connection guide, and I would rather you read that than have me repeat it here.
One first-party note on what this looks like in practice, because a comparison built from documentation should say what happens when you use the thing. We ran a complete website build for a Hampshire accountancy practice through a connected project mailbox in the last fortnight of August: 31 client-facing messages in 14 days, every one drafted by the assistant from the whole thread and every one opened, read and sent by a person. The Drafts folder was empty at the end. On the morning of 31 August two of those messages went out with a block of raw code visible at the bottom, entirely our fault, apologised for at 08:24 and fixed the same morning. I include that because it is what a new tool in a client-facing workflow looks like in its first fortnight, and because "draft first, a person sends" is the posture that turned it into an embarrassment rather than a problem. The full write-up of that build is on the agency site.
AI calendar assistant: what each one does with your diary
Connecting a mailbox does not connect a diary, on any of the four, because mail and calendar are separate services with separate permissions. Briefly, since the calendar is a second article's worth on its own.
Claude's Google Workspace connector covers Google Calendar alongside Gmail, and the Microsoft 365 connector's write tools cover calendar events on a work tenant. Claude for Outlook "checks free/busy for everyone whose calendar you can see" and drafts the invite into Outlook's appointment form for you to send. ChatGPT has separate Google Calendar and Outlook Calendar apps; the Outlook Calendar one reads events and availability and, on shared calendars with the right permissions, can "create, update, RSVP to, cancel, or delete events". Copilot in Outlook schedules meetings conversationally with a licence. Gemini in Gmail can "schedule events, reschedule or delete existing events, find open time slots, or check calendars for availability", with the caveat that "you can only create events on your primary calendar".
The pattern is the same as mail: Google and Microsoft calendars are covered, CalDAV calendars, which is what Fastmail, iCloud and most self-hosted mail platforms use, are covered by nobody. Our own calendar guide takes all three routes, letting an AI book meetings on a calendar you actually keep covers the one answer you must not trust (an attendee it cannot see comes back as unknown, not free), and on a Microsoft 365 mailbox the connector offers all 21 calendar tools on top of the 32 for mail, including propose_new_time and set_out_of_office, which no vendor integration in this comparison expresses as a tool, and the calendar section of the companion article explains why a CalDAV server is offered only the tools it can actually answer.
The address book follows the diary. Where a vendor documents contacts at all it is a read: ChatGPT's Outlook app lists "people lookup and contact management" for your own mailbox, and Copilot's personal documentation has "get a contact's address". A CardDAV address book, which is the one a phone syncs to on Fastmail, iCloud, Nextcloud, Zoho or a self-hosted mail platform, is reached by none of them. Mailbox MCP connects one to any password mailbox and takes Outlook contacts with a Microsoft 365 sign-in, with 5 tools that read, add, correct, delete and import in your own book; the contacts section of the companion article has the detail, including what we found when we connected our own: 25 people from mail history and 0 from the book, because a webmail contacts page is not the CardDAV book.
Which AI should you use for email? By mailbox, then by job
Start from the mailbox you have, not the assistant you like. The assistant is the easy part to change, and if the row you land on says Mailbox MCP, that is the point: one connector, every mailbox, whichever assistant you keep.
| Your mailbox | Best documented fit | Why |
|---|---|---|
| Personal Gmail | Claude, or ChatGPT if you want triggers; Mailbox MCP if you want filing, flags and threaded replies too | Claude documents send, reply, forward and labels with approval on every plan. ChatGPT is the only one that can react to a new message, on Plus and above. Neither documents move, flag or mark-read; the connector has all three. |
| Google Workspace | Gemini inside Gmail for drafting; Claude, ChatGPT or Mailbox MCP to act from chat | Gemini's filing verbs need Gemini Beta enabled by your administrator. The connectors do not, and Mailbox MCP needs only an app password from your own Google account. |
| Microsoft 365 work tenant, Copilot licence | Copilot in Outlook, or Mailbox MCP to use Claude or ChatGPT on the same mailbox | The fullest filing set any vendor publishes: move, archive, flag, junk, categories, folders, rules. English only, and Copilot only; the connector brings the same verbs to whichever assistant you prefer. |
| Microsoft 365 work tenant, no Copilot licence | Mailbox MCP, one Microsoft sign-in; or Claude's connector if an admin enables write tools | Claude's connector sends and trashes but cannot move, flag or mark read. Copilot Chat without a licence answers questions and, per one Microsoft page, flags. The connector needs no Copilot licence and, in a normal tenant, no administrator approval, and on this mailbox it offers every mail, calendar and contact tool it has, the contacts being the Outlook ones that arrive with the sign-in. |
| Personal Outlook.com or Hotmail | Copilot at copilot.com to read; Mailbox MCP to read, file and send | Claude refuses personal Microsoft accounts by name. Only consumer Copilot documents reaching them, and only for reading. Mailbox MCP connects one with a single Microsoft sign-in and hands your assistant the full tool set. |
| Your web host, Fastmail, iCloud, any IMAP | Mailbox MCP, or another custom remote MCP connector | No vendor integration reaches an IMAP mailbox. Anthropic allows custom connectors on every plan; OpenAI documents them for Business and Enterprise. Which clients and which mail providers a connector works with is a list, not a guess. |
Then the job. If what you typed into Google was "AI email assistant for Outlook", the row you need depends on whether the account is a work tenant or a personal address, because the best AI for email on one is not available on the other. If the job is "tell me what needs me", every one of the seven does it, and the differences are taste. If the job is "find the email I can only half remember", every one of the seven searches, and how well is a different matter. If the job is "file four hundred newsletters", you need a move tool, which rules out both ChatGPT on your own Outlook mailbox and Claude's Microsoft 365 connector. If the job is "answer this, in the thread, from my address", you want an AI that can read and reply to emails rather than only draft them, which means send plus reply, and on the vendor side that is Claude on Gmail or a work tenant, or ChatGPT on Gmail. If the job is "do that every morning without me", you need a trigger, which is ChatGPT on Gmail and nobody else. And if the job involves an attachment leaving your account, read the Claude Microsoft 365 line about write tools rejecting attachments before you plan around it.
If you have not chosen an assistant at all yet, our comparison of what each AI subscription costs covers the buying decision and which AI tool to use for which job covers the one after it. The question in this article sits between those two: once you have the subscription, what it can do to the mailbox you already own.
The limits of this ChatGPT, Claude, Copilot and Gemini comparison
What this table cannot tell you
It is documentation, not measurement. Every cell says what the vendor publishes, which is checkable and dated, rather than what the product does on a given afternoon. Where we have measured something ourselves, the text says so. Where a vendor's page is silent, the cell says NS, and NS is not N.
It has a shelf life of weeks. Two of the pages behind it changed between 30 August and 12 September, one of them reversing a sentence outright. Treat any cell as true on the date in the caption and worth re-checking after that.
It reads the vendors' own products only. Superhuman, Shortwave, Fyxer, Kai and the rest are a different category, a finished assistant rather than a connection to one you already pay for, and comparing them against this table would be comparing a car with a bridge. Nor does it compare connectors with each other; that table, MailMCP.io, Google's own server and Nylas against ours, is the email MCP servers compared page and the parent post. The same inputs-versus-outputs argument this site makes about AI visibility applies: the question here is what the connection can do, not what a product promises to do with it.
It is written by an interested party. The product it ends on is ours. Everything it says about the vendors is linked to their pages so you do not have to take our word for any of it, and the product site holds itself to the same verification rules. If you test these things for a living, there is a developer and reviewer offer that gives you a mailbox to break.
The wider point, and the reason a site about AI visibility is writing about email at all, is the one this site makes about websites: an AI system works well against explicit, machine-readable declarations and badly against inference. Anthropic's published tool list for its Microsoft 365 connector told me more in a minute than three feature pages did in an hour, because it declared exactly what the assistant had been handed and let me count what was missing. It is why how Mailbox MCP works is written as a list of what the assistant is handed rather than a list of benefits. That is the same thing AI Visibility Checking asks of a website, and the same thing the AI Discovery Files exist to publish: an ai.json file is, in effect, a business publishing its own tool list, down to which actions an agent may take and on what terms. Whether the machine is reading a mailbox or a business, declared capability beats a guess.
Two practical notes. If you run the website as well as the mailbox, 365i hosts both, and the hosting tiers include the fully-featured mailboxes with webmail, calendars and contacts that this article calls "any IMAP". And if your site already publishes its discovery files, you can submit it to the directory for free verification and a public score.
Frequently asked questions
Can ChatGPT read my email without a paid plan?
The Gmail, Google Calendar and Google Contacts connectors reached Plus users globally on 4 February 2026, and OpenAI's June 2026 release note says sending from a connected Gmail or Outlook account is available "on the web for users on Plus, Pro, Business, and Enterprise plans". None of the availability statements we could find names the Free tier. So the practical answer is that reading and sending need a paid plan.
Can Claude send emails, or only read them?
Both, on Gmail and on a work Microsoft 365 tenant. Anthropic's help centre says Claude can "send, reply to, and forward emails from Gmail" and asks for your approval before each of those actions by default. On Microsoft 365 the write tools exist but an administrator has to switch them on. The separate Claude for Outlook add-in never sends at all: it does not request the Mail.Send permission and every draft lands unsent in Outlook.
Can Copilot read my emails without a Copilot licence?
Partly, and Microsoft's own pages disagree on how much. The Outlook chat page says that without an add-on licence you can ask Copilot Chat "questions about your inbox, calendar, meetings and other limited data and take action directly in Outlook", with "Flag all unread emails from my manager" as an example. The licence comparison page describes work-data reasoning without the licence as "Limited (uploaded files)". Test it in your own tenant before you budget for the add-on.
Can Gemini send emails for me from Gmail?
No. Every description of Gemini in Gmail stops at a draft: it summarises, searches, extracts and writes, and you press Send. Archiving, deleting, labelling and marking read are documented, but only inside Gemini Beta for work accounts whose organisation has enabled it, or the Workspace Experiments tester programme for personal accounts, and each action needs an explicit confirmation with a 60-second undo.
Which AI can read email that is not on Gmail or Outlook?
None of the four vendors' own integrations. Claude reaches Google accounts and Microsoft Entra business tenants, ChatGPT reaches Gmail and Outlook, Copilot reaches Exchange Online and, for personal accounts, Outlook.com and Gmail, and Gemini reaches Gmail. A mailbox on your web host, on Fastmail, on iCloud, or a personal @outlook.com address in Claude, needs a custom connector such as an email MCP server. Anthropic allows those on every plan including Free; OpenAI documents them for Business and Enterprise.
Does an AI reading my email mark it as read?
No vendor says. Across every page we read for Claude, ChatGPT, Copilot and Gemini, the only read-state statement anywhere is that ChatGPT can mark shared-mailbox messages read or unread when asked. Nobody documents what an ordinary read does to the unread flag, so if that flag is how you track what still needs you, test it on a message you can afford to lose track of before you let an assistant triage a hundred.
Is it safe to give an AI access to my email?
It depends on what the connection can do, not on which AI it is. Email is text anyone can send you, so a message can carry instructions aimed at the assistant reading it; Anthropic's own Outlook documentation calls email bodies and attachments "untrusted input". Prefer connections that ask before sending, that cannot erase mail permanently, and that open one mailbox at a time, and review anything that leaves your account. Eight questions to put to any vendor turns that into a checklist.
Which AI is best for email in 2026?
It depends on the mailbox first and the job second. On Gmail, Claude has the widest documented write set with approval; ChatGPT is the only one that can react to a new message arriving. On a work Microsoft 365 tenant, Copilot with a licence does the most filing and Claude's connector sends but cannot move or flag. On a personal Outlook.com address, Copilot at copilot.com reads it and the other three do not. On anything else, a custom connector is the only documented route, and across all of those mailboxes Mailbox MCP is the one option in the comparison with every filing verb, threaded replies, and the same 32 tools whichever assistant you use.
Sources
- Use Google Workspace connectors (Gmail) - Anthropic Help Centre
- Gmail integration - Anthropic developer documentation
- Set up the Microsoft 365 connector - Anthropic Help Centre
- Microsoft 365 connector security guide, with the published tool list - Anthropic Help Centre
- Use Claude for Outlook - Anthropic documentation
- Get started with custom connectors using remote MCP - Anthropic Help Centre
- Outlook Email and Calendar apps in ChatGPT - OpenAI Help Centre
- ChatGPT release notes (8 June, 25 August and 28 August 2026 entries) - OpenAI Help Centre
- Developer mode and MCP apps in ChatGPT - OpenAI Help Centre
- Introducing workspace agents in ChatGPT - OpenAI
- Triage email with Microsoft 365 Copilot in Outlook - Microsoft Support
- App and network requirements for Microsoft Copilot admins (updated 8 September 2026) - Microsoft Learn
- How Copilot Chat works with and without a Microsoft Copilot license - Microsoft Support
- Chat with Copilot in Outlook - Microsoft Support
- Use Microsoft Copilot in Outlook to manage your inbox (Frontier) - Microsoft Support
- Connecting Microsoft Copilot to other services - Microsoft Support
- Collaborate with Gemini in Gmail - Google Gmail Help
- Learn about Gemini features in Gmail (availability) - Google Gmail Help
- Learn about changes to third-party email account support in Gmail - Google Gmail Help
- MCP Reference: gmailmcp.googleapis.com - Google for Developers
- The lethal trifecta for AI agents - Simon Willison
- Introducing the Model Context Protocol - Anthropic
- How to let Claude send emails for you - Engadget, 8 September 2026
- The full tool list - Mailbox MCP
- Claude, ChatGPT and Copilot email connectors vs MCP - Mailbox MCP
- Connect a CalDAV calendar or a CardDAV address book - Mailbox MCP
- Manage contacts with the CardDAV protocol - Google for Developers