# send_email

Send an email immediately.

Agent View of the PolicyLayer registry record for `send_email`. HTML page: https://policylayer.com/tools/0xka13b-microsoft-mcps/send-email

## Facts

- Tool: `send_email`
- Server: Microsoft MCP (`0xka13b/microsoft-mcps`) — https://policylayer.com/tools/0xka13b-microsoft-mcps.md
- Homepage: https://github.com/0xka13b/microsoft-mcps
- Risk category: Write (Medium risk)
- Registry record: grade F, identity unverified
- Server rate-limited: no
- Parameters: 7 (3 required)
- Recommended policy verdict: Rate-limited

## Parameters

| Parameter | Type | Required | Description |
| --- | --- | --- | --- |
| `cc` | array | no | CC recipients |
| `to` | array | yes | Recipient email addresses |
| `bcc` | array | no | BCC recipients |
| `body` | string | yes | Email body |
| `subject` | string | yes | Email subject |
| `body_type` | string | no | Body content type. Defaults to text. |
| `attachments` | array | no | File attachments |

Parameters from the server's own tool schema.

## Example call (MCP tools/call, JSON-RPC 2.0)

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "send_email",
    "arguments": {
      "to": [],
      "body": "<body>",
      "subject": "<subject>"
    }
  }
}
```

## Why send_email is rated Medium

This tool creates and commits a new email message to the system. While sending an email is technically irreversible (cannot be unsent in most email systems), it is classified as Write rather than Destructive because the action is creating/modifying data (composing and transmitting a message) rather than permanently deleting or overwriting existing data.

From the tool's own definition: "Tool performs 'Send an email immediately' — creates and transmits a message, which is a reversible but irreversible communication action that modifies the email system state."

Risk signals: Accepts raw HTML/template content (body) · High parameter count (10 properties)

## Use case

AI agents use send_email to create or update resources in Microsoft MCP, usually the action step of a workflow, after the agent has gathered context. Every call changes real data in your Microsoft MCP environment.

## Recommended policy (PolicyLayer)

Verdict: **Rate-limited**. Enforced by the PolicyLayer MCP gateway (https://policylayer.com/mcp-gateway) before a call reaches Microsoft MCP:

```json
{
  "version": "1",
  "default": "deny",
  "tools": {
    "send_email": {
      "limits": [
        {
          "counter": "send_email_rate",
          "window": "minute",
          "max": 30,
          "scope": "grant"
        }
      ]
    }
  }
}
```

## Other tools on Microsoft MCP (13)

- `delete_email` — Destructive — https://policylayer.com/tools/0xka13b-microsoft-mcps/delete-email.md
- `get_attachment` — Read — https://policylayer.com/tools/0xka13b-microsoft-mcps/get-attachment.md
- `get_email` — Read — https://policylayer.com/tools/0xka13b-microsoft-mcps/get-email.md
- `list_emails` — Read — https://policylayer.com/tools/0xka13b-microsoft-mcps/list-emails.md
- `me` — Read — https://policylayer.com/tools/0xka13b-microsoft-mcps/me.md
- `search_emails` — Read — https://policylayer.com/tools/0xka13b-microsoft-mcps/search-emails.md
- `unified_search` — Read — https://policylayer.com/tools/0xka13b-microsoft-mcps/unified-search.md
- `create_email_draft` — Write — https://policylayer.com/tools/0xka13b-microsoft-mcps/create-email-draft.md
- `create_reply_draft` — Write — https://policylayer.com/tools/0xka13b-microsoft-mcps/create-reply-draft.md
- `move_email` — Write — https://policylayer.com/tools/0xka13b-microsoft-mcps/move-email.md
- `reply_all_email` — Write — https://policylayer.com/tools/0xka13b-microsoft-mcps/reply-all-email.md
- `reply_to_email` — Write — https://policylayer.com/tools/0xka13b-microsoft-mcps/reply-to-email.md
- `update_email` — Write — https://policylayer.com/tools/0xka13b-microsoft-mcps/update-email.md

## For agents

This record is a snapshot. Live verdicts and the full registry:

- Check every server in your MCP config at once: `npx -y policylayer stack`
- Vet a server before you add it: install the mcp-precheck skill — `npx skills add https://policylayer.com` (skill text: https://policylayer.com/skill.md)
- Query the registry over MCP: endpoint `https://api.policylayer.com/mcp` — tools `check_mcp_server`, `check_mcp_stack`, `check_tool`, `search_registry`, `get_change_events`

---

Source: the PolicyLayer MCP registry — one continuously verified record per MCP server. Full record: https://policylayer.com/registry?q=0xka13b-microsoft-mcps · API: https://policylayer.com/registry/api · Policy library: https://policylayer.com/policies/0xka13b-microsoft-mcps
