fix
Repair client domain issues safely by running deterministic checks and applying only safe fixes; replacements await human approval while missing records are created automatically.
Instructions
Check a client's domain, then repair what can be repaired safely.
check explains what is wrong. This acts on it. The same thirteen
deterministic checks run first and are still never decided by a model;
what a model decides is which repair to reach for, out of a set of tools
that cannot do anything else.
Anything that would replace a record somebody already published stops
and waits for a person. Approve it in the control room, or call
apply_mail_setup with approved=true. Creating a record that is
absent is not a judgement call and does not stop.
report_file is always written. watch and report are control room
URLs and appear only while it is running; munim approve answers
without it.
With agents off the checks still run and their findings still stand,
exactly as check degrades: only the repair needs a model.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| target | Yes | A client name, or a bare domain. The same resolution check uses. | |
| dkim_selector | No | The DKIM selector to look for. Change it only if the client sends through something other than Resend. | resend |