Skip to main content
Glama

Domain Mail Check

Check email authentication

check_email_auth
Read-onlyIdempotent

Use this when the user asks whether a domain's email is set up correctly, such as "is DMARC set up for github.com?" or "check SPF and DKIM for example.com". Pass the domain and, if known, up to 5 DKIM selector names. Returns SPF (policy, DNS lookup count, issues), DMARC (policy, percentage, report address, issues), DKIM per selector, the MX hosts and mail provider, a grade from A to F, a list of fixes, and the source and as_of date. It reads public DNS only: it does not send mail, test delivery or read mailboxes.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
domainYesThe domain, such as "example.com". A web address or an email address is reduced to its domain.
dkim_selectorsNoDKIM selector names to look for, such as ["google"] or ["selector1", "selector2"]. Optional; DKIM cannot be found without one. At most 5.

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault
mxYes
spfNo
dkimYes
as_ofYes
dmarcNo
fixesYes
gradeYes
domainYes
noticeNo
sourceYes
statusYes
messageNo
grade_basisNo
unavailableYes
mail_providerNo

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observed

TDQS

A4.2/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare readOnly, idempotent, openWorld and non-destructive, so safety is covered. The description adds genuinely new behavioral context: it touches public DNS only and explicitly does not send mail, test delivery, or read mailboxes, which rules out a common misinterpretation of 'email auth'.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

A single well-ordered paragraph: trigger conditions first, then inputs, then returns, then scope limits. Dense but every clause carries information; only the long return enumeration is somewhat redundant given an output schema exists.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a two-parameter read-only lookup, the description covers when to use it, what to pass, what comes back, and what it deliberately does not do. With an output schema present, nothing an agent needs to invoke it correctly is missing.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100% and both parameters are documented in the schema, including the note that DKIM cannot be found without a selector. The description only restates 'pass the domain and, if known, up to 5 DKIM selector names', adding no syntax or semantics beyond the schema.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb+resource (check email authentication for a domain) and enumerates exactly what is examined: SPF, DMARC, DKIM, MX. This cleanly separates it from check_dns_records and lookup_domain_registration without needing to open either schema.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Gives concrete trigger phrasing ('is DMARC set up for github.com?') plus a scope exclusion ('does not send mail, test delivery or read mailboxes') that prevents misuse. It does not, however, route the agent to a named alternative such as check_dns_records for generic DNS questions.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

Resources