Connect Mimecast
Mimecast is an email security and archiving platform. It sits in front of a company's mail, holds and inspects what arrives, keeps a searchable archive of what was sent and received, and scores the…
Written By Christopher Scaminaci
Last updated 6 days ago
Mimecast is an email security and archiving platform. It sits in front of a company's mail, holds and inspects what arrives, keeps a searchable archive of what was sent and received, and scores the people who handle it. StackJack talks to Mimecast through its API 2.0, which is the same interface behind the Mimecast Administration console you already use.
Connecting Mimecast to StackJack gives your AI assistant a family of mc_ MCP tools — MCP (Model
Context Protocol) tools are the standardized commands an AI assistant can call through StackJack.
With them, your AI can:
- Answer "where is my email?" — find held and processing messages, trace a message end to end, read the mail queues, see why something was rejected, and decode a rewritten link
- Release or reject held mail (on Pro plans) — close the most common Mimecast ticket there is, one message or a batch
- Investigate threats — threat events and statistics, attachment, link-click, impersonation and data-loss logs, reported emails and their analysis, and the security event feeds
- Search the archive — eDiscovery-shaped searches, message lists and detail, smart tags, retention adjustments and message visibility
- Look up people and groups — internal users, aliases, attributes, delegates, group membership, and the status of a directory synchronization
- Report on human risk — safe scores, watchlists, phishing campaign results, per-user training detail, and individual and organizational risk trends
- Run DMARC — if your Mimecast subscription includes DMARC Analyzer, your AI can look after the domains you send mail from: add and group them, read and set their DKIM selectors, SPF records and DMARC policies (including for domains you manage on someone else's behalf), check what DNS is publishing right now, work through the sending sources it discovers, and pull the compliance and enforcement picture. It can also download a forensic failure report, which arrives as a temporary download link rather than a file in the conversation — and stays encrypted to whatever key you gave Mimecast, so you open it with your own key after you download it.
- Read and change policy (reads Free, changes on Pro) — greylisting, delivery routes, sender authentication, anti-spoofing, blocked senders, address alteration and managed links
- Manage domains and connections (reads Free, changes on Pro) — internal, external and pending domains, verification and DNS records, journaling services, and the Active Directory, Google and Microsoft 365 directory connections
How StackJack authenticates to Mimecast
You create an API 2.0 application in the Mimecast Administration console. It gives you a Client ID and a Client Secret, and you paste both into StackJack. There is nothing to renew on a schedule: StackJack exchanges the pair for a short-lived token on its own and gets a fresh one whenever the old one runs out. You never see it.
What the application may do is decided in Mimecast, not in StackJack
This is the one thing worth reading twice, because it causes almost every Mimecast support ticket.
When you create the application, Mimecast asks you for two things that decide everything afterwards:
- Products — which groups of the API the application may reach. Threat Management, Directories, Gateway, Awareness Training, DMARC Analyzer and so on are separate products. DMARC Analyzer is the one people forget: leave it unticked and every DMARC tool comes back saying the application is not allowed to use that part of the API, which reads exactly like a bad key and is not one.
- Role — what level of access the application has inside those products, typically read-only or read and write.
Those choices are fixed at creation. StackJack can never ask for more than the application carries, so a read-only role produces read-only behavior no matter what an AI assistant is asked to do. That is a useful safety control, and it is the one we recommend you start with.
The consequence is that a tool can come back saying the application is not allowed to use that part of the API even though your credentials are perfectly good. That is not a bad key and regenerating the secret will not help. Go back to the application in Mimecast and add the missing product.
It is also worth knowing that Mimecast sells more than one email security product and they do not share the same tools. An Email Security Cloud Gateway account will say "not found" to a Cloud Integrated tool and the other way round, and DMARC Analyzer is separate again. Each tool says which product it belongs to.
Pick your data region
Mimecast runs three gateways and your account lives on exactly one of them:
- Global — the default, and the right answer for most accounts. It moves to the nearest healthy instance by itself if one has a problem.
- United Kingdom and United States — single-instance services chosen for data residency. Neither has any failover, so requests fail outright while that instance is down. Pick one of these only if your Mimecast account was created on it.
The region decides where your API traffic is processed. If you are not sure which one your account uses, start with Global.
Steps
- Decide what the application may reach. Pick the products and the role first, because you cannot change them from StackJack later. Start read-only if you only want reporting. Tick DMARC Analyzer too if you want the DMARC tools.
- Create the application. In the Mimecast Administration console, open Services, then API and Platform Integrations, and create a new API 2.0 application. Fill in a name, a description and a contact, then choose your products and role.
- Copy the Client ID and generate the Client Secret. Mimecast shows the secret exactly once and it cannot be retrieved afterwards. Copy it before you close the page and treat it as a password.
- Confirm your region. Most accounts are Global. Choose United Kingdom or United States only if your account was created on that instance.
- Enter the details in StackJack. Open Connectors, choose Mimecast, pick the region, and paste the Client ID and Client Secret.
- Run a Test Connection. A failure here is almost always the secret being truncated on copy, or the wrong region.
If you ever need to change the secret, generate a new one on the same application rather than creating a second application — a new application would need its products and role set up again. When you come back to edit a saved connection, the Client Secret box starts blank on purpose; leaving it blank keeps the secret you already stored.
Managing several companies with one set of keys
If you manage other companies' Mimecast accounts, create the application in your partner (NFR) account instead, under Multi Account Controls, then API Gateway. One set of keys then reaches every customer you administer, and there is no second connector to set up per customer.
Every Mimecast tool takes an optional account code that says which customer it acts on. Leave it
empty and the tool acts on your own account. mc_list_partner_customers lists the customers you
administer along with their account codes, and it is the read to run first.
Two limits are worth knowing before you build anything on this:
- A partner key reaches a customer only if you actually administer that customer in Mimecast.
- Mimecast does not let a partner key send email on behalf of a managed customer.
Two Mimecast products, two sets of tools
Mimecast sells Email Security Cloud Gateway — the classic model where your mail is routed through Mimecast — and Email Security Cloud Integrated, which attaches to Microsoft 365 instead. They do not share an API surface.
A Cloud Gateway account answers "not found" to a Cloud Integrated tool, and the reverse, and neither
answer means anything is broken. Every tool's description says which product it is for. If you are
not sure which you have, mc_get_whoami tells you.
Tiers
- Free — every read. Held-message searches, message tracing, threat and click logs, archive search, user and group lookups, awareness and risk scores, audit events, policy and domain reads, and the managed-customer list.
- Pro — every change. Creating and updating policies, domains, groups, users, journaling services, directory connections and smart tags, and running connection tests; and equally the changes that are hard or impossible to undo — releasing and rejecting held mail, blocking senders, deleting policies, domains, groups, delegates and integrations, purging mailboxes, remediating delivered messages, and restoring a configuration snapshot over the live one.
- Business — the same tool set as Pro with a higher monthly call quota.
Five more changes are marked destructive because of what their body can do, not what their name says. Importing users can empty the group it imports into, if the import options say so. Replacing a DMARC task, a DMARC domain group or a DMARC notification replaces the lists inside it, so a domain or a group you leave out drops out. And a retention adjustment set to zero days purges the messages it names from the archive at once.
Importing users takes the file itself. Hand your assistant the CSV content, or point it at an XLS or XLSX workbook by URL or as an attachment — the import options travel separately. StackJack downloads a URL for you and refuses anything over 25 MB.
That second group of changes is marked destructive. Whether your AI application asks you to confirm before running one depends on that application's own settings — see Destructive tools and confirmation. Review that setting before you let an assistant near held mail.
See the generated Mimecast tool reference for the current inventory, plan assignment, input schemas, and destructive-action labels.
Paging and limits
Mimecast returns large results a page at a time, with a maximum of 100 records per page. A page comes back with a token for the next one, and the token is simply absent when there is no more data — so a result with no token is a finished list, not an error.
Mimecast does not publish a request quota for most of its API, so StackJack paces requests conservatively and backs off on its own if Mimecast throttles it. That usually makes a large report slower rather than failed. Pacing smooths a burst; it does not guarantee every call arrives. Narrow the read — a shorter date range, one customer at a time rather than your whole book — and check whether a write landed before repeating it. See Retrying a failed or timed-out write.
Troubleshooting
"Not allowed to use that part of the API." The application's products or role do not cover the tool you ran. Fix it on the application in Mimecast; the keys are fine.
"Client ID and Client Secret not recognized." Check the pair, and copy the secret in full — a truncated paste is the most common cause and looks exactly like a wrong secret. If you no longer have the secret, generate a new one on the same application.
A tool returns "not found" for something you can see in the console. Check which Mimecast product the tool is for. The two email security products answer only their own routes.
Everything is slow or comes back throttled. Narrow the date range, reduce the page size, and work one managed customer at a time.
Mimecast tools
mc_ · 374 tools · Free 194 · Pro 180
Account
Configuration snapshots
Partner (MSP)
Archive search
Data retention
Archive access logs
Audit events
Delivery monitoring
Awareness scores
Human risk
Phishing campaigns
Training queue and users
Administrator roles
Directory connections
Groups
Users
DMARC DNS checks
DMARC delegated domains
DMARC detected domains
DMARC domain groups
DMARC domains
DMARC policy presets
DMARC compliance
DMARC customer settings
DMARC events and issues
DMARC notifications
DMARC reports
DMARC sources
DMARC tasks
DMARC users
Domain onboarding
External domains
Internal domains
Protection mode
Gateway configuration
Held messages
Journaling
Managed senders
Message tracking
Outbound email
Cloud Integrated policies
Connectors
Marketplace integrations
Address alteration
Anti-spoofing
Anti-spoofing bypass
Blocked senders
DNS authentication
Delivery routes
Greylisting
Managed URLs
Web security
Protection logs
Remediation
Reported emails
SIEM feeds
Threat events
Threat intelligence
Threat statistics
More in Connector guides
Connect Acronis Cyber Protect CloudConnect Action1Connect AddigyConnect AlertOpsStill need help? Ask the team