Skip to main content
Glama

RelayShield Scam Checks

Score an email for phishing signals

check_email
Read-only

Scores a suspicious email for phishing signals from its parsed fields. Provide any of: from_address, from_name, reply_to, return_path, subject, body_text, and links (up to 25). Returns a risk level and score with the specific flags behind them; links in the email are also checked against RelayShield's threat-intelligence corpus. A verdict of unknown means nothing conclusive was found; this tool never reports an email as safe.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
linksNoLinks found in the body, up to 25.
subjectNoMessage subject.
reply_toNoReply-To address, if present and different from from_address.
body_textNoPlain-text body, used for urgency/deadline/threat phrasing.
from_nameNoThe claimed sender's display name.
return_pathNoEnvelope sender, if available. Informational only.
from_addressNoThe claimed sender's address, e.g. alerts@phrase.com.

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observed

TDQS

A4/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already cover the safety profile (readOnly, non-destructive), so the bar is lower; the description still adds useful behavior: the return shape (risk level, score, specific flags), the 'unknown means nothing conclusive' semantic, and the explicit guarantee that it never reports an email as safe. This 'never says safe' caveat is exactly the kind of nuance an agent needs and cannot get from annotations.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Three sentences, front-loaded with the purpose, then inputs, then return semantics. Tight overall, though the mid-sentence param enumeration partially duplicates the schema and could be trimmed.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With no output schema, the description carries the return-value burden itself and does so: it explains the risk level, score, flags, the 'unknown' verdict, and the no-safe-verdict guarantee. All seven optional parameters are schema-documented, so nothing needed to call the tool is missing.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so every parameter is already documented, and the baseline is 3. The description only re-enumerates the field names plus the 'up to 25' link cap that the schema already states via maxItems, adding no new syntax or format meaning.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb ('scores') and resource ('a suspicious email for phishing signals') and names the input surface. It is clearly distinguishable from siblings check_breach, check_link, and check_wallet, which operate on different artifacts.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The phrase 'Provide any of' communicates that inputs are flexible and nothing is required, which is implied usage guidance. However, it never says when to reach for check_email versus check_link, even though link analysis is a documented sub-behavior here, so routing between siblings is left to inference.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

Resources