Outlook

Read, manage, and send Outlook mail through Arcade’s verified Smithery remote MCP server.

Description

Outlook on Smithery is a verified remote MCP server with a durable listing identity, and the reviewed product page connects its deployment to Arcade. Smithery presents the service as Outlook with an active deployment and the remote endpoint outlook.run.tools. Arcade’s corresponding documentation describes Microsoft Outlook Mail as a distinct integration over Microsoft Graph and names tools for reading, searching, composing, and sending email. This entry therefore catalogs an identifiable provider service rather than a temporary Smithery demo. No public source repository for this exact deployment is identified, so this catalog does not claim local installation and does not substitute an unrelated community repository link.

Product boundary and operation

The server connects an MCP-capable client to Outlook mail capabilities. According to the provider, these include identifying the connected account, listing and filtering messages, accessing messages and attachments, and working with folders and drafts. Tools can create drafts, update existing drafts, send drafts, compose replies, and immediately send new messages. This combination supports mailbox research, triage, prepared communication, and carefully bounded routine work. The actual tool set can change on a remote service, so the Smithery page and Arcade documentation should be reviewed again before productive account changes.

Email and calendar data

The verified Smithery and Arcade material concerns Outlook Mail, not a separate calendar MCP server. Microsoft Graph can expose both mail and calendar data in Microsoft 365 mailboxes, but the documented Outlook Mail tools do not establish general calendar access. Users should therefore not treat calendar operations as a guaranteed function of this listing. Email bodies, subject lines, recipients, attachments, folders, and drafts can be highly sensitive. Write and send access is possible: CreateAndSendEmail sends immediately, while draft, reply, and SendDraft tools can change prepared or existing communication. Recipients, content, attachments, and timing must be reviewed before execution.

OAuth and tenant permissions

Smithery tool metadata identifies OAuth 2.0 with Microsoft as the identity provider. The named permissions include Mail.Read for reading, Mail.ReadWrite for creating and changing mail, and Mail.Send for sending; some tools may also require MailboxSettings.Read. The user authorizes the connected Microsoft account and must review the requested scopes. In an organization, Microsoft Entra policies, administrator consent, Conditional Access, restricted mailbox delegation, and tenant rules can narrow access further. Shared or delegated mailboxes are a distinct permission case: a connection should access only mailboxes for which the account has actual authorization.

Privacy and data sharing

With a remote MCP server, requests pass through Smithery and the Arcade-operated gateway before Microsoft Graph reaches the authorized mailbox. Email text and metadata may enter the MCP client context and then be sent to that client’s model provider. This is not a guarantee of local processing. Before use, review data flows, retention, logging, processing agreements, and organizational rules. This catalog stores no passwords, OAuth tokens, secrets, credentials, or API keys. Grant only the smallest practical permission scope and separate test and production accounts where policy requires it.

Security boundaries

Email content may expose confidential information or contain manipulative instructions. An agent must not treat such content as trusted control input. Deleting, changing, replying, and immediately sending are especially sensitive because they alter external state or trigger communication. Use confirmation steps, explicit recipient rules, and human approval for sending and sensitive changes. Review attachments, forwarding behavior, and shared mailboxes as well. Tool annotations and Microsoft permissions describe technical capability, not a replacement for a privacy assessment or tenant governance.

Appropriate use

Outlook on Smithery suits controlled mailbox search, summaries, drafting assistance, and limited automation in MCP clients. It is not a promise of unsupervised communication automation and is not evidence of calendar functionality. The official Smithery product page is the direct deployment source; Arcade documents the underlying Outlook Mail integration, and Microsoft documents Graph permissions. Recheck all three sources if the endpoint, tool set, OAuth flow, or organizational requirements change.

Requirements

An MCP-capable client, a Microsoft account with an Outlook mailbox, and explicit OAuth authorization for the required Microsoft Graph permissions.

Installation instructions

Not recorded yet.

Authentication

OAuth 2.0 through Microsoft; review requested scopes before user authorization.

Required access permissions

Depending on the tool, Mail.Read, Mail.ReadWrite, Mail.Send, and possibly MailboxSettings.Read; tenant and delegation rules also apply.

Transmitted or stored data

Remote processing through Smithery and Arcade to Microsoft Graph. Email data may reach the MCP client and its model provider; review data flows and privacy rules.

Security risks

Reading, changing, and sending can expose confidential data or trigger communication. Use least-privilege scopes, confirmation, and human approval.

License and costs

License
Not recorded yet.
Cost
free

Alternatives

Not recorded yet.

At a glance

Provider
Arcade
Status
Official server
Deployment
Remote
Current version
Not recorded yet.
Last reviewed
09.09.2026

Repository and documentation

Categories

Supported clients

Not recorded yet.