Skip to main content
Glama

Check a domain's email authentication (SPF, DKIM, DMARC, BIMI, MX, MTA-STS, TLS-RPT)

check_domain
Read-onlyIdempotent

Audit the email-authentication DNS records of a domain. Returns a 0–100 score and A–F grade (MX 10, SPF 25, DMARC 30, DKIM 25, BIMI 10, plus up to 5 bonus points for MTA-STS and TLS-RPT, capped at 100), each check's status, published record, findings and recommended fixes, and a link to the full report. Read-only: it only queries public DNS and the domain's public MTA-STS policy file. Same engine and scoring as the DnsGuard JSON API (GET /api/check).

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
domainYesDomain to check, e.g. example.com. A URL or email address is accepted and reduced to its domain.
include_rawNoAlso return the full /api/check JSON (all records, SPF include tree, DKIM keys) in structuredContent.raw. Larger output.
dkim_selectorNoOptional DKIM selector (the s= value from a DKIM-Signature header), e.g. s1 or google. Common selectors are always tried.

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault
rawNoFull /api/check response (only when include_raw is true)
tierNo
gradeYes
notesNo
scoreYes
apiUrlNo
cachedNo
checksYes
domainYes
versionNo
maxScoreYes
checkedAtNo
reportUrlYes
scoreBreakdownNo
organizationalDomainNo

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observed

TDQS

Score is being calculated.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

Resources