Skip to main content
Glama

SPF checker

dossier_spf
Read-only

Find and parse a domain's SPF record into its mechanisms. Use to check which servers may send mail for a domain, or to debug delivery failures; pair with dossier_dmarc and dossier_dkim for the whole email-authentication picture. Reads TXT records over Cloudflare DNS-over-HTTPS. Reports records that contain v=spf1 but do not start with it (for example behind a hidden byte-order mark) as lookalikes that receivers discard, and treats more than one SPF record as an error, as RFC 7208 requires. Returns JSON with a status field: {status:"ok", data, fetchedAt} on success, {status:"not_applicable", reason} when the thing is genuinely absent, {status:"timeout", ms}, or {status:"error", message} when it could not be determined. Treat not_applicable as a finding and error as unknown.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
domainYesPublic domain name, e.g. example.com. IP addresses, ports, paths and protocol prefixes are rejected.

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed2 schema fields changed
    • removedInput schema / additionalProperties
      Removed value: -false
    • changedInput schema / properties / domain / description
      Previous value: -"Public FQDN, e.g. example.com. Must be resolvable on the public internet; IPs, ports, paths, and protocol prefixes are rejected."New value: +"Public domain name, e.g. example.com. IP addresses, ports, paths and protocol prefixes are rejected."
  2. Changed1 schema field changed
    • changedInput schema / properties / domain / description
      Previous value: -"Public FQDN."New value: +"Public FQDN, e.g. example.com. Must be resolvable on the public internet; IPs, ports, paths, and protocol prefixes are rejected."
  3. Added

TDQS

A4.5/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

The description goes well beyond the readOnlyHint annotation by disclosing the transport (Cloudflare DNS-over-HTTPS), edge-case handling (lookalike records behind byte-order marks), and RFC 7208 behavior for multiple SPF records. It also explains the response statuses and their semantics, which is valuable behavioral context the annotations do not provide.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is dense but every sentence earns its place: purpose, use cases, sibling pairing, transport, edge-case behavior, and complete status contract. It is front-loaded with the core action and usage, with finer behavioral details following in a logical order.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Even without an output schema, the description fully explains the return contract: ok, not_applicable, timeout, and error, including how an agent should interpret not_applicable versus error. Combined with the single fully-documented parameter, nothing essential is missing for selecting and invoking the tool correctly.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

There is only one parameter, and the schema already describes it fully with examples and exclusions ('IP addresses, ports, paths and protocol prefixes are rejected'). The description adds little beyond the schema's domain coverage, so the high schema-description coverage baseline of 3 is appropriate.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description opens with a specific verb and resource: 'Find and parse a domain's SPF record into its mechanisms.' It then states the practical use cases (check authorized senders, debug delivery failures) and distinguishes itself by naming dossier_dmarc and dossier_dkim as complementary tools rather than substitutes.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

It gives explicit guidance on when to use the tool: 'Use to check which servers may send mail for a domain, or to debug delivery failures.' It also recommends pairing with dossier_dmarc and dossier_dkim for the full email-authentication picture, giving clear context for choosing this tool. It does not explicitly state when not to use it, but the guidance is still actionable.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

Resources