Skip to main content
Glama

IntoDNS.ai DNS & Email Security Scanner

generate_dmarc

Read-onlyIdempotent

Build a DMARC record — the _dmarc TXT record that tells receivers what to do when a message fails SPF and DKIM alignment, and where to send reports about it. The risk here is not syntax but policy. p=none monitors without affecting delivery and is where every deployment starts; p=quarantine sends failures to spam; p=reject refuses them outright, which silently destroys legitimate mail from any sender that was missed and gives that sender no explanation. Always publish a rua address: without aggregate reports there is no way to see which senders fail before enforcing against them. Use percentage to apply an enforcing policy to only part of the mail while rolling out. Returns the record, the host to publish it on (_dmarc), and warnings covering the mistakes that actually break mail — enforcing without reporting, reject at full coverage, pct at p=none, and strict alignment breaking subdomain senders and ESPs. Nothing is looked up or stored. A rua/ruf entry that is not a mailbox (name@example.com, optionally mailto: and a !size) or a pct outside 1-100 is refused with an error instead of a record.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
pctNoAlias for `percentage`, matching the DNS tag name.
ruaNoAggregate report address(es). mailto: is added automatically.
rufNoForensic report address(es). Contains message content and is honoured by very few receivers.
policyNop= — start at 'none' and only enforce once reports show all legitimate senders aligning. Defaults to none.
percentageNopct= — share of mail the policy applies to, for a gradual rollout. Has no effect at p=none. Also accepted as `pct`.
spfAlignmentNoaspf= — strict requires an exact domain match and breaks subdomain senders.
dkimAlignmentNoadkim= — strict requires an exact domain match and breaks many ESPs.
reportIntervalNori= — seconds between aggregate reports. Defaults to 86400 (daily).
subdomainPolicyNosp= — a different policy for subdomains. Omitted when it matches the main policy.

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observed

TDQS

A4.6/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Goes well beyond the annotations: explains the real-world risk of policy choices (reject silently destroys legitimate mail), states that it returns warnings covering deployment mistakes, refuses invalid rua/ruf/pct entries with an error, and explicitly notes that nothing is looked up or stored. This is fully consistent with readOnlyHint, idempotentHint, and destructiveHint=false.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is longer than average, but almost every clause earns its place given the policy risk and nine optional parameters. It is front-loaded with the core purpose and the key caution ('The risk here is not syntax but policy'), then covers returns and validation. It could be tightened slightly, but it is not bloated.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a tool with no output schema and nine optional parameters, this description fully covers what the tool returns (record, host, warnings), how it behaves on invalid input, side effects (none), and the deployment context needed to use it safely. An agent has enough to select and invoke it correctly.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, so the baseline is 3. The description adds meaningful policy-level semantics for the most consequential parameters: p=none/quarantine/reject tradeoffs, the requirement for rua, pct having no effect at p=none, and strict alignment breaking subdomain senders/ESPs. This enriches the schema without duplicating it.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description names a specific verb and resource ('Build a DMARC record — the `_dmarc` TXT record') and explains exactly what the record does: tell receivers how to handle SPF/DKIM failures and where to send reports. This sharply distinguishes it from sibling tools like check_dmarc (inspection) and generate_spf (different record type).

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description gives strong context on when to use different policy settings: start with p=none, only enforce after reports show alignment, use percentage for gradual rollout, and always publish rua. However, it never explicitly names sibling tools or states when not to use this tool versus alternatives, so it stops short of full exclusion guidance.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.