proofpoint-mcp
The Proofpoint MCP Server connects AI assistants to Proofpoint TAP and Essentials APIs for comprehensive email security management, threat investigation, and intelligence operations.
Targeted Attack Protection (TAP): Retrieve all threats, delivered/blocked messages, and permitted/blocked clicks with time window and status filters; look up specific threats or campaigns by ID.
Quarantine Management: List, search, release, or permanently delete quarantined messages by folder, sender, recipient, subject, and date.
Threat Intelligence: Get campaign details, threat details by ID, list known threat families, and retrieve indicators of compromise (IOCs) such as URLs, IPs, domains, and file hashes.
DLP (Data Loss Prevention): List and filter DLP incidents by status/severity, view incident details, and track encrypted messages.
People & User Risk: Retrieve Very Attacked People (VAP) reports, top URL clickers, and individual user risk scores.
Forensics & Threat Response: Get forensic evidence for threats/campaigns (behavioral analysis, network activity, file modifications), search messages across mailboxes, and perform auto-pull (search & destroy) operations.
Smart Search / Message Tracing: Trace messages through mail flow by sender, recipient, subject, or message ID; retrieve full message headers and processing logs.
Policy Management: List and view email security policies (inbound/outbound/internal) and email routing rules.
URL Defense: Decode Proofpoint-rewritten URLs back to their originals and analyze URLs for threat classification and risk scores.
Security Event Monitoring: List spam, phishing, and malware detection events, get event details, and view detection statistics over time.
Reports & Analytics: Generate organization security summaries, threat summaries, mail flow reports, and executive summaries with configurable time windows.
Discovery & Status: Use
proofpoint_navigateto explore available tools by domain andproofpoint_statusto check credentials and available domains.
Proofpoint MCP Server
A Model Context Protocol (MCP) server for Proofpoint TAP and Essentials APIs. Enables AI assistants to investigate threats, trace emails, manage quarantine, access threat intelligence, and perform URL defense operations.
This is a Model Context Protocol (MCP) server that connects Claude (or any MCP-compatible AI) to your Proofpoint environment.
Part of the MSP Claude Plugins ecosystem — a growing suite of AI integrations for the MSP stack. Built by MSPs, for MSPs.
Installation
npm install @wyre-technology/proofpoint-mcpRelated MCP server: avanan-mcp
Configuration
Set the following environment variables:
Variable | Required | Description |
| Yes | Your Proofpoint TAP service principal |
| Yes | Your Proofpoint TAP service secret |
| No | Custom base URL (default: tap-api-v2.proofpoint.com) |
| No | Transport mode: stdio (default) or http |
Usage
Running with Claude Desktop
Add to your Claude Desktop claude_desktop_config.json:
{
"mcpServers": {
"proofpoint-mcp": {
"command": "npx",
"args": ["@wyre-technology/proofpoint-mcp"],
"env": {
"PROOFPOINT_SERVICE_PRINCIPAL": "your-proofpoint-service-principal"
"PROOFPOINT_SERVICE_SECRET": "your-proofpoint-service-secret"
}
}
}
}Running with Claude Code (CLI)
claude mcp add proofpoint-mcp \
-e PROOFPOINT_SERVICE_PRINCIPAL=your-value \
-e PROOFPOINT_SERVICE_SECRET=your-value \
-- npx -y @wyre-technology/proofpoint-mcpDocker
docker build -t proofpoint-mcp .
docker run \
-e PROOFPOINT_SERVICE_PRINCIPAL=your-value \
-e PROOFPOINT_SERVICE_SECRET=your-value \
-p 8080:8080 proofpoint-mcpFeatures
Interactive Threat Card (MCP Apps)
proofpoint_threat_get_by_id renders as an interactive, read-only card in
MCP Apps hosts (Claude Desktop/web) showing the threat name, status,
category, severity, and resolved actor / malware-family / campaign names;
plain-JSON behavior is unchanged in other hosts. The card is neutral by
default and brandable via window.__BRAND__ injection or MCP_BRAND_* env
vars (MCP_BRAND_NAME, MCP_BRAND_LOGO_URL, MCP_BRAND_PRIMARY_COLOR,
MCP_BRAND_ACCENT_COLOR, MCP_BRAND_BG, MCP_BRAND_TEXT) — no rebuild
needed.
Available Domains
Dlp
Data loss prevention policies
Events
Security event stream and SIEM export
Forensics
Forensic analysis of threats
People
Very Attacked People (VAP) reporting
Policy
Email policy management
Quarantine
Email quarantine management
Reports
Security reports and summaries
Smart Search
Advanced email search
Tap
Targeted Attack Protection events and campaigns
Threat Intel
Threat intelligence and indicators of compromise
Url Defense
URL rewriting and click defense
Development
# Clone the repository
git clone https://github.com/wyre-technology/proofpoint-mcp.git
cd proofpoint-mcp
# Install dependencies
npm install
# Build
npm run build
# Run tests
npm testContributing
Contributions are welcome! Please see CONTRIBUTING.md if present, or open an issue to discuss changes.
License
Licensed under the Apache License, Version 2.0. See LICENSE for details.
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- Alicense-qualityDmaintenanceAn advanced email security analysis MCP server for real-time phishing detection, comprehensive header analysis, and threat intelligence integration. It enables users to extract indicators of compromise and validate email authentication protocols like DKIM, SPF, and DMARC.MIT
- AlicenseAqualityAmaintenanceMCP server for Checkpoint Harmony Email & Collaboration (Avanan). Enables AI assistants to manage email security, anti-phishing, anti-malware, and threat detection via the Avanan API.131Apache 2.0
- AlicenseBqualityAmaintenanceMCP server for KnowBe4 — security awareness training, phishing simulation, and user risk management API integration30Apache 2.0
- AlicenseAqualityAmaintenanceMCP server for Ironscales — phishing incident management, email classification, and remediation2Apache 2.0
Related MCP Connectors
MCP Server for agents to onboard, pay, and provision services autonomously with InFlow
MCP server for Pentest-Tools.com: run scans, manage findings and reports via your preffered LLM.
Pulsedive MCP — threat-intelligence IOC enrichment (pulsedive.com)
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/wyre-technology/proofpoint-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server