Skip to main content
Glama
OrtaMarco

domain-security-mcp-server

by OrtaMarco

Email Authentication Audit

email_auth_audit
Read-onlyIdempotent

Check if a domain is protected against email spoofing by auditing SPF, DKIM, DMARC, and MX records, then get a 0-100 score with prioritized fixes.

Instructions

Headline tool. Audits a domain's email-authentication posture in one call — SPF, DKIM, DMARC and MX — then returns a 0–100 score, an A–F grade and a prioritised list of fixes. Use this first; reach for the per-record tools (spf_check, dmarc_check, dkim_check) only when you need the full detail of one mechanism.

Args:

  • domain (string): the domain to audit.

  • dkim_selectors (string[], optional): DKIM selectors to probe. If omitted, common provider selectors are tried (absence is then inconclusive).

  • response_format ('markdown' | 'json'): output format (default 'markdown').

Returns (JSON): { "domain": string, "grade": "A".."F", "score": number, // 0-100 "has_mx": boolean, "mx_hosts": string[], "spf": { found, record, all_qualifier, lookup_count, exceeds_lookup_limit, findings[] }, "dmarc":{ found, policy, tags, findings[] }, "dkim": { any_found, selectors[], findings[] }, "top_recommendations": string[] }

Examples:

  • "Is example.com protected against email spoofing?" -> email_auth_audit(domain="example.com")

  • "Audit acme.com, our DKIM selector is 'k1'" -> email_auth_audit(domain="acme.com", dkim_selectors=["k1"])

Errors: returns an error only if the domain is malformed; missing records are reported as findings, not errors.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
domainYesDomain to audit, e.g. 'example.com'.
dkim_selectorsNoOptional DKIM selectors to check (e.g. ['google','selector1']). If omitted, a list of common provider selectors is probed.
response_formatNoOutput format: 'markdown' for a human-readable summary (default) or 'json' for the full structured payload.markdown

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault
spfYes
dkimYes
dmarcYes
gradeYes
scoreYes
domainYes
has_mxYes
mx_hostsYes
top_recommendationsYes

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed17 schema fields changedv1.2.1
    • changedInput schema / $schema
      Previous value: -"http://json-schema.org/draft-07/schema#"New value: +"https://json-schema.org/draft/2020-12/schema"
    • removedInput schema / additionalProperties
      Removed value: -false
    • addedInput schema / properties / dkim_selectors / items / maxLength
      Added value: +63
    • addedInput schema / properties / dkim_selectors / maxItems
      Added value: +50
    • addedInput schema / properties / domain / maxLength
      Added value: +253
    • changedOutput schema / $schema
      Previous value: -"http://json-schema.org/draft-07/schema#"New value: +"https://json-schema.org/draft/2020-12/schema"
    • removedOutput schema / properties / dkim / properties / findings / items / $ref
      Removed value: -"#/properties/spf/properties/findings/items"
    • addedOutput schema / properties / dkim / properties / findings / items / additionalProperties
      Added value: +false
    • addedOutput schema / properties / dkim / properties / findings / items / properties
      Added value: +{
      +  "message": {
      +    "type": "string"
      +  },
      +  "severity": {
      +    "type": "string"
      +  }
      +}
    • addedOutput schema / properties / dkim / properties / findings / items / required
      Added value: +[
      +  "severity",
      +  "message"
      +]
    • addedOutput schema / properties / dkim / properties / findings / items / type
      Added value: +"object"
    • removedOutput schema / properties / dmarc / properties / findings / items / $ref
      Removed value: -"#/properties/spf/properties/findings/items"
    • addedOutput schema / properties / dmarc / properties / findings / items / additionalProperties
      Added value: +false
    • addedOutput schema / properties / dmarc / properties / findings / items / properties
      Added value: +{
      +  "message": {
      +    "type": "string"
      +  },
      +  "severity": {
      +    "type": "string"
      +  }
      +}
    • addedOutput schema / properties / dmarc / properties / findings / items / required
      Added value: +[
      +  "severity",
      +  "message"
      +]
    • addedOutput schema / properties / dmarc / properties / findings / items / type
      Added value: +"object"
    • addedOutput schema / properties / dmarc / properties / tags / propertyNames
      Added value: +{
      +  "type": "string"
      +}
  2. First observedv1.0.0

TDQS

A5/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare readOnlyHint, openWorldHint, idempotentHint, and destructiveHint=false. The description adds valuable behavioral context beyond that: it explains the return format (score, grade, fixes), the error behavior (only malformed domain errors; missing records are findings), and the nuance that omitting dkim_selectors makes absence inconclusive. This is rich disclosure that helps an agent interpret results correctly. No contradiction with annotations.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is long but every section earns its place: headline, args, returns, examples, errors. It is front-loaded with the primary purpose and use-first guidance. The structure is scannable and free of redundancy, making it efficient despite its length.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

The tool is complex (multiple mechanisms, optional selectors, format selection, return payload), and the description covers all aspects: parameter behaviors, return structure (full JSON shape), examples for common use cases, and error semantics. Given the schema and annotations, nothing an agent needs to invoke this tool correctly is missing.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters5/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, so the baseline is 3, but the description adds substantial meaning: it clarifies the optionality of dkim_selectors, the default behavior when omitted (common selectors probed, inconclusive absence), and the response_format semantics (markdown vs json). The examples further illustrate parameter usage. This goes well beyond what the schema alone conveys.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description states a specific verb ('Audits') and resource ('a domain's email-authentication posture'), enumerating the mechanisms (SPF, DKIM, DMARC, MX) and the deliverable (score, grade, fixes). It explicitly differentiates from the sibling per-record tools by naming them and indicating when to use them instead, so an agent can immediately tell this is the aggregate/headline tool.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description gives explicit guidance: 'Use this first' and 'reach for the per-record tools only when you need the full detail of one mechanism.' It also provides concrete examples mapping natural-language queries to tool invocations, leaving no ambiguity about when to select this tool over alternatives.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.