Domain Health
Server Details
Domain checks: SPF, DKIM, DMARC, BIMI, MTA-STS, SSL/TLS and HTTP security headers.
- Status
- Healthy
- Last Tested
- Transport
- Streamable HTTP · MCP 2025-11-25
- URL
TDQS
Score is being calculated.
Available Tools
5 toolscheck_domain_registrationCheck domain registrationRead-onlyIdempotentInspect
Read a domain's public registration record from its registry over RDAP (no WHOIS scraping): registrar, creation, expiry and last-change dates, status locks such as clientTransferProhibited, danger states such as redemption period or hold, and nameservers. Also compares the registry's nameservers with the live zone and checks DNSSEC. Subdomains are checked as their registered domain. Some country-code registries do not publish RDAP; the tool says so.
| Name | Required | Description | Default |
|---|---|---|---|
| detail | No | "summary" (default) lists only findings that need action; "full" also lists every passing check. | summary |
| domain | Yes | The domain to check, such as example.com. A website address (https://www.example.com/page) or an email address (jo@example.com) also works; the domain is taken from it. |
check_email_authCheck email authenticationRead-onlyIdempotentInspect
Explain in plain words whether email from a domain will reach the inbox and whether others can forge it. Checks MX, SPF with every include expanded and counted against the 10-lookup limit, DMARC policy, alignment and report permissions, DKIM keys at about 40 common selectors plus any you name (with key size), BIMI, MTA-STS and TLS-RPT, and the DNS rules Google, Yahoo and Microsoft set for bulk senders. Every finding has a severity, a one-sentence fix and the RFC or provider document behind it. Reads public DNS only.
| Name | Required | Description | Default |
|---|---|---|---|
| detail | No | "summary" (default) lists only findings that need action; "full" also lists every passing check. | summary |
| domain | Yes | The domain to check, such as example.com. A website address (https://www.example.com/page) or an email address (jo@example.com) also works; the domain is taken from it. | |
| dkim_selectors | No | Extra DKIM selectors to check, such as the s= value from a DKIM-Signature header (for example "s1" or "selector1"). About 40 common selectors are always checked. |
check_security_headersCheck security headersRead-onlyIdempotentInspect
Read the HTTP security headers a domain's homepage sends, as a browser receives them, and grade each: Strict-Transport-Security, Content-Security-Policy, clickjacking protection (X-Frame-Options or CSP frame-ancestors), X-Content-Type-Options, Referrer-Policy and Permissions-Policy, plus whether http:// redirects to https://, cookie flags, and software version disclosure. Only public web servers on ports 80 and 443 are contacted.
| Name | Required | Description | Default |
|---|---|---|---|
| detail | No | "summary" (default) lists only findings that need action; "full" also lists every passing check. | summary |
| domain | Yes | The domain to check, such as example.com. A website address (https://www.example.com/page) or an email address (jo@example.com) also works; the domain is taken from it. |
check_sslCheck SSL certificateRead-onlyIdempotentInspect
Check the HTTPS certificate and TLS setup of a domain on port 443: issuer, expiry date and days left, whether the chain is complete and trusted, whether the certificate matches the name, key type and size, which TLS versions (1.0 to 1.3) the server accepts, and the CAA record that limits who may issue certificates. Checks www as well when given a bare domain. Every finding has a severity, a fix and a citation.
| Name | Required | Description | Default |
|---|---|---|---|
| detail | No | "summary" (default) lists only findings that need action; "full" also lists every passing check. | summary |
| domain | Yes | The domain to check, such as example.com. A website address (https://www.example.com/page) or an email address (jo@example.com) also works; the domain is taken from it. | |
| include_www | No | Also check www.<domain> when a bare domain is given and www exists. Default true. |
full_domain_reportFull domain reportRead-onlyIdempotentInspect
Run every Domain Health check on one domain at once (email authentication, SSL and TLS, security headers, registration and DNSSEC) and answer three questions in plain words: will its email land, is its website safe, and is the domain owned well. Returns a score and grade per area, the top fixes across all areas, and every finding with its severity, fix and citation. Takes 5 to 20 seconds.
| Name | Required | Description | Default |
|---|---|---|---|
| detail | No | "summary" (default) lists only findings that need action; "full" also lists every passing check. | summary |
| domain | Yes | The domain to check, such as example.com. A website address (https://www.example.com/page) or an email address (jo@example.com) also works; the domain is taken from it. | |
| dkim_selectors | No | Extra DKIM selectors to check, such as the s= value from a DKIM-Signature header (for example "s1" or "selector1"). About 40 common selectors are always checked. |
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections.
5 tool updates
- First observed
check_domain_registration - First observed
check_email_auth - First observed
check_security_headers - First observed
check_ssl - First observed
full_domain_report
Related MCP Connectors
Check a domain's email authentication: SPF, DKIM, DMARC, BIMI, MX, MTA-STS, TLS-RPT. Score + fixes.
11Email deliverability checks: SPF, DKIM, DMARC, BIMI, MTA-STS, blacklists, headers, spam words
DNS resolution, HTTP security headers, and SPF/DMARC email hygiene audits.
Monitor and manage email authentication (SPF, DKIM, DMARC, MTA-STS, BIMI) for your domains.
Related MCP Servers
- AlicenseAqualityCmaintenancePerforms domain security posture checks including SPF, DKIM, DMARC, TLS, and HTTP security headers.31 npmMIT
- AlicenseAqualityBmaintenanceProvides comprehensive email deliverability and domain registration analysis, evaluating SPF, DKIM, DMARC, DNS records, and expiry to identify issues and suggest fixes.5MIT
- AlicenseNot gradedqualityDmaintenanceEnables DNS and email security analysis through passive and active scanning capabilities. Provides comprehensive domain security checks including SPF, DMARC, DNSSEC validation, MX record analysis, and SMTP connectivity testing.MIT
- AlicenseAqualityFmaintenanceProvides comprehensive tools for real-time DNS queries across 53 record types, global propagation checks, and SSL certificate analysis. It also enables domain security scans for SPF/DKIM/DMARC configurations and HTTP uptime monitoring.872 npm22Apache 2.0
Glama MCP Gateway
Add one secure layer between your agents and this server.