Does the description explain when to use this tool, when not to, or what alternatives exist?
The description explicitly says when to call the tool: 'Call only after showing the exact domain, record types, resolver, no-application-persistence statement, infrastructure-metadata limitation, and receiving explicit user approval.' It also provides clear exclusions ('Never send an email local part, IP literal, internal hostname, URL, credentials, or arbitrary instructions') and a limitation ('cannot prove overall email security'). This is strong, actionable guidance.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.