← Back to blog

Connect on-premises Exchange to an AI agent

guidesexchange

Most ways to connect an AI agent to Outlook go through Microsoft Graph. That includes Claude's Microsoft 365 connector, Microsoft's Work IQ MCP server, and most community Outlook servers. Graph reaches mailboxes in Exchange Online. If your mailbox lives on an Exchange server that your company runs itself, none of those options apply.

Exchange Server still speaks the standard mail protocols: IMAP for reading and authenticated SMTP for sending. That is enough to connect it to any MCP client. This guide uses Fluxmail, a self-hosted MCP server, to connect a mailbox on Exchange Server 2016, 2019, or Subscription Edition to Claude Code, Codex, Cursor, or another agent.

If your mailbox is in Exchange Online, use Connect Outlook / Exchange instead. Graph gives you categories and a richer API.

What your Exchange administrator needs to turn on

IMAP is off by default in Exchange Server. Before anything else, your administrator needs to:

  1. Start the Microsoft Exchange IMAP4 and Microsoft Exchange IMAP4 Backend services and set them to start automatically.
  2. Configure the IMAP settings for clients. The usual choice is port 993 with TLS.
  3. Configure authenticated SMTP for IMAP clients. Exchange normally accepts authenticated client submissions on port 587.

Your IT team may also need to allow the connection through a firewall or VPN, and approve the use of an AI tool with company mail at all. Ask first. Many organizations have a policy on it.

To see what your server uses, open Outlook on the web and go to Settings > Options > Mail > Accounts > POP and IMAP. Once IMAP is on, that page lists the server names and ports.

Connect the mailbox

Install Fluxmail on your computer, or on a server inside the network that can reach Exchange, and create the local administrator:

npm install -g fluxmail
fluxmail setup --name "Your name" --email you@example.com

Then connect the mailbox:

fluxmail accounts add imap \
  --email ann@contoso.com \
  --imap-host mail.contoso.com \
  --smtp-host mail.contoso.com \
  --imap-user 'CONTOSO\ann' \
  --smtp-user 'CONTOSO\ann'

Use your own address and server name. The username is whatever you use to sign in to Exchange. That is often DOMAIN\username, sometimes your email address. Keep the single quotes around a name with a backslash so the shell passes it through unchanged. If your sign-in name is your email address, leave out both user options. Fluxmail uses the email address by default.

Fluxmail defaults to IMAP over TLS on port 993 and SMTP with STARTTLS on port 587, which match a typical Exchange setup. If your server differs, pass --imap-port, --imap-security, --smtp-port, or --smtp-security. Fluxmail prompts for your password without showing it, tests both connections, and encrypts the password in its local database.

Check the folders

Exchange names its special folders Sent Items, Deleted Items, and Junk Email. Fluxmail looks for special folders by their IMAP flags first and common names second. If it warns that one is missing when you connect, set it by name:

fluxmail accounts list
fluxmail accounts configure <account-id> --trash-folder 'Deleted Items'
fluxmail accounts configure <account-id> --spam-folder 'Junk Email'

Fluxmail never guesses when a folder is missing. An archive or delete that needs an unresolved folder fails with an error instead of moving mail somewhere unexpected.

Send yourself a test message with fluxmail emails send --to ann@contoso.com --subject Test --body Test and check Sent Items. If the message appears twice, the server already saves a copy of SMTP submissions. Run the same fluxmail accounts add imap command again with --no-save-sent added so Fluxmail stops adding its own. Reconnecting keeps your folder settings.

Connect your agent

Start with read-only access. For Claude Code:

claude mcp add fluxmail -- fluxmail stdio --profile read-only

For Codex CLI:

codex mcp add fluxmail -- fluxmail stdio --profile read-only

Connect an MCP client covers Cursor, Claude Desktop, and clients that connect over HTTP.

Then ask a question only your mailbox can answer:

What are the ten most recent messages in my inbox, and which of them ask me for something?

The agent searches with Fluxmail's search_emails tool and reads messages over IMAP. Fluxmail's search syntax is the same for Exchange as for Gmail and Outlook.com, so prompts and skills you write for one work with the others.

What works and what does not

Over IMAP and SMTP, an agent can:

  • Search, read, and download attachments.
  • Create and update drafts, which appear in Outlook.
  • Move messages between folders, archive, and mark them read or unread.
  • Send, reply, forward, and schedule mail, if you allow sending.

IMAP does not carry Outlook categories, calendars, or contacts, so those are out of reach. Searches run on the Exchange server, so results depend on what the server indexes.

Keep company mail safe

Company mailboxes hold other people's information, and anyone outside can email you. Start with read-only. Move to read-write when you want drafts, and give an agent send access only for a workflow that needs it. Limit each agent to the mailboxes it needs. How to give an AI agent access to your email safely walks through each control.

Next steps