plaindmarc-mcp
v0.1.0
Published
Read-only MCP server for DMARC, SPF, DKIM, BIMI and MTA-STS checks, DMARC record generation, and aggregate-report analysis — powered by plaindmarc.com's public tools. No API key, no account.
Maintainers
Readme
plaindmarc-mcp
A read-only MCP server that gives an AI agent seven email-authentication tools — DMARC, SPF, DKIM, BIMI and MTA-STS checks, DMARC record generation, and aggregate-report analysis — powered by plaindmarc.com's public tools.
No API key. No account. Read-only. It never writes DNS, never signs in, and never touches billing. Every check is a live DNS lookup or a plain-string transform; nothing about you is collected or stored.
Tools
| Tool | What it does |
|------|--------------|
| check_dmarc | DMARC verdict + letter grade (A–F), the policy, and whether reports are actually being received (rua) — a domain can be protected yet unmonitored. |
| check_spf | SPF record, the 10-DNS-lookup count, and ~all/-all vs a permissive ending. |
| check_dkim | A DKIM selector's key (follows CNAME chains): found / missing / revoked / weak. Needs the selector. |
| check_bimi | BIMI eligibility (logo + VMC + DMARC at enforcement) — eligibility, not a guarantee. |
| check_mta_sts | MTA-STS + TLS-RPT DNS setup (states that the HTTPS policy file isn't fetched remotely). |
| generate_dmarc_record | Builds a valid DMARC record; warns against jumping straight to p=reject/quarantine. |
| analyze_dmarc_report | Explains a raw DMARC aggregate (rua) XML report in plain English. |
Install
Runs with npx — no global install needed:
npx -y plaindmarc-mcpClaude Code
claude mcp add plaindmarc -- npx -y plaindmarc-mcpClaude Desktop / any MCP client
Add to your MCP config (Claude Desktop: claude_desktop_config.json):
{
"mcpServers": {
"plaindmarc": {
"command": "npx",
"args": ["-y", "plaindmarc-mcp"]
}
}
}Then ask, e.g. "Is example.com protected against email spoofing, and is anyone watching its DMARC reports?" or "Generate a DMARC record for example.com."
Notes
- Honest by design. A DNS failure or missing record returns an explicit unknown/error state with the reason — never a guessed verdict, and a FAIL is never softened.
- Rate-friendly. Requests are concurrency-capped with exponential backoff on 429, so auditing a portfolio of domains completes cleanly.
- Point at a different backend with
PLAINDMARC_BASE_URL(defaults tohttps://plaindmarc.com).
MIT licensed. Built by PlainDMARC.
