Giving AI Email Access
IMAP, SMTP and email APIs
In one sentenceThe ways an AI agent can read or send email: an official connector, IMAP and SMTP, or an email-sending service. Each needs care.
What it means
There are three common routes. Connectors (OAuth) like the Gmail or Outlook connectors in ChatGPT and Claude let AI read and draft mail with permissions you approve, without sharing your password. IMAP (for reading) and SMTP (for sending) are the classic email protocols; agents like OpenClaw can use them with an app password. Email-sending services (Postmark, SendGrid, Resend, Amazon SES) give an agent an API for sending, after you verify your domain with TXT and CNAME records.
Email is high-risk: an inbox holds password resets, client data and invoices, and an AI that reads mail can be targeted by Prompt Injection hidden in an email.
How to use it
- Give agents a dedicated mailbox (for example, assistant@yourdomain.com) instead of your main inbox.
- Start read-only or drafts-only. Let the AI write drafts; you press send.
- Use app passwords or OAuth, never your main password, and revoke access when you stop using the agent.
- Follow anti-spam rules and only email people who expect to hear from you.
Related terms
MX Record TXT Record (SPF, DKIM, DMARC) MCP Prompt Injection Human in the Loop