MCP-Server

DomainCanary

com.domaincanary/mcp
Sicherheit Öffentlich und erreichbar MCP 2025-11-25

Was dieses MCP kann

Checks and constructs email authentication records and analyzes DMARC reports and email bounces.

analyze_report
Read a DMARC aggregate report
Use this when someone has a DMARC aggregate report and wants to know which senders passed and which failed. The report is the XML, .gz or .zip file that receivers such as Google and Yahoo email to the address in a domain's rua tag. In ChatGPT, pass the uploaded file. Elsewhere, pass the report XML as text. Returns totals per report and each sending IP address with its SPF, DKIM and DMARC results. The result gives a next step for the report's domain and a link to a live check of that domain's DNS records. Nothing from the report is stored.
Nur Lesen Idempotent
Eingabeschema
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'file': {'type': 'object', 'required': ['download_url', 'file_id'], 'properties': {'file_id': {'type': 'string', 'maxLength': 512}, 'file_name': {'type': 'string', 'maxLength': 1024}, 'mime_type': {'type': 'string', 'maxLength': 255}, 'download_url': {'type': 'string', 'maxLength': 4096}}, 'description': 'The report file the user uploaded in ChatGPT: the .xml, .xml.gz or .zip a mailbox provider emailed them.'}, 'report_xml': {'type': 'string', 'maxLength': 1000000, 'description': 'The report XML as text, from <feedback> to </feedback>. Use this when there is no uploaded file, or when the user pasted the XML.'}}}
Ausgabeschema
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['reports', 'reports_omitted', 'skipped_payloads', 'record_limit_reached', 'external_data', 'next_steps', 'analyzer_url'], 'properties': {'reports': {'type': 'array', 'items': {'type': 'object', 'required': ['org', 'domain', 'date_begin', 'date_end', 'policy', 'messages', 'passed', 'failed', 'sources', 'failing_sources', 'verdict', 'worst_source', 'records_with_extra_dkim', 'truncated_fields', 'rows', 'rows_omitted'], 'properties': {'org': {'type': ['string', 'null']}, 'rows': {'type': 'array', 'items': {'type': 'object', 'required': ['ip', 'messages', 'passed', 'disposition', 'spf_result', 'spf_domain', 'dkim_result', 'dkim_domain', 'dkim_signatures', 'override_reasons'], 'properties': {'ip': {'type': 'string'}, 'passed': {'type': 'boolean'}, 'messages': {'type': 'number'}, 'spf_domain': {'type': ['string', 'null']}, 'spf_result': {'anyOf': [{'enum': ['none', 'neutral', 'pass', 'fail', 'softfail', 'temperror', 'permerror', 'unrecognised'], 'type': 'string'}, {'type': 'null'}]}, 'disposition': {'anyOf': [{'enum': ['none', 'quarantine', 'reject'], 'type': 'string'}, {'type': 'null'}]}, 'dkim_domain': {'type': ['string', 'null']}, 'dkim_result': {'anyOf': [{'enum': ['none', 'pass', 'fail', 'policy', 'neutral', 'temperror', 'permerror', 'unrecognised'], 'type': 'string'}, {'type': 'null'}]}, 'dkim_signatures': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'override_reasons': {'type': 'array', 'items': {'type': 'object', 'required': ['type', 'comment_in_external_data'], 'properties': {'type': {'anyOf': [{'enum': ['forwarded', 'sampled_out', 'trusted_forwarder', 'mailing_list', 'local_policy', 'other', 'unrecognised'], 'type': 'string'}, {'type': 'null'}]}, 'comment_in_external_data': {'type': 'boolean'}}, 'additionalProperties': False}}}, 'additionalProperties': False}}, 'domain': {'type': ['string', 'null']}, 'failed': {'type': 'number'}, 'passed': {'type': 'number'}, 'policy': {'enum': ['none', 'quarantine', 'reject', 'unrecognised'], 'type': 'string'}, 'sources': {'type': 'number'}, 'verdict': {'enum': ['clean', 'warn', 'flagged'], 'type': 'string'}, 'date_end': {'type': 'string'}, 'messages': {'type': 'number'}, 'date_begin': {'type': 'string'}, 'rows_omitted': {'type': 'number'}, 'worst_source': {'anyOf': [{'type': 'object', 'required': ['ip', 'messages', 'disposition'], 'properties': {'ip': {'type': 'string'}, 'messages': {'type': 'number'}, 'disposition': {'anyOf': [{'enum': ['none', 'quarantine', 'reject'], 'type': 'string'}, {'type': 'null'}]}}, 'additionalProperties': False}, {'type': 'null'}]}, 'failing_sources': {'type': 'number'}, 'truncated_fields': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'records_with_extra_dkim': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}}, 'additionalProperties': False}}, 'next_steps': {'type': 'array', 'items': {'type': 'object', 'required': ['domain', 'kind', 'text', 'link_text', 'url'], 'properties': {'url': {'type': 'string'}, 'kind': {'enum': ['quarantine', 'reject', 'raise_pct', 'keep', 'fix_senders', 'check'], 'type': 'string'}, 'text': {'type': 'string'}, 'domain': {'type': ['string', 'null']}, 'link_text': {'type': 'string'}}, 'additionalProperties': False}}, 'analyzer_url': {'type': ['string', 'null']}, 'external_data': {'type': 'object', 'required': ['notice', 'fields', 'omitted'], 'properties': {'fields': {'type': 'array', 'items': {'type': 'object', 'required': ['source', 'label', 'name', 'value', 'shortened'], 'properties': {'name': {'type': ['string', 'null']}, 'label': {'type': 'string'}, 'value': {'type': 'string'}, 'source': {'enum': ['dns', 'report', 'request'], 'type': 'string'}, 'shortened': {'type': 'boolean'}}, 'additionalProperties': False}}, 'notice': {'type': 'string'}, 'omitted': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}}, 'additionalProperties': False}, 'reports_omitted': {'type': 'number'}, 'skipped_payloads': {'type': 'number'}, 'record_limit_reached': {'type': 'boolean'}}, 'additionalProperties': False}
build_spf
Build an SPF record
Use this when someone lists the services that send their email and wants the SPF record to publish, or wants a sender added to the SPF record they already have. Takes provider names such as Google Workspace or Mailchimp, include terms such as include:spf.example.com, or IP addresses, and returns one merged record with its count of DNS lookups against the limit of ten. Pass the domain when you know it, so the result includes the senders already in its published record.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['senders'], 'properties': {'all': {'enum': ['~all', '-all'], 'type': 'string', 'description': 'How the record ends. A new record ends in ~all unless you pass -all. A record the domain already publishes keeps its own ending unless you pass one.'}, 'ip4': {'type': 'array', 'items': {'type': 'string', 'maxLength': 64, 'minLength': 1}, 'maxItems': 10, 'description': "IPv4 addresses or ranges that send this domain's mail directly, such as 192.0.2.10 or 192.0.2.0/24."}, 'ip6': {'type': 'array', 'items': {'type': 'string', 'maxLength': 64, 'minLength': 1}, 'maxItems': 10, 'description': "IPv6 addresses or ranges that send this domain's mail directly, such as 2001:db8::1 or 2001:db8::/32."}, 'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'The domain the record is for. When given, the SPF record it publishes today is read and the senders are added to it, so nothing already in it is lost.'}, 'senders': {'type': 'array', 'items': {'type': 'string', 'maxLength': 300, 'minLength': 1}, 'maxItems': 20, 'minItems': 1, 'description': "The platforms that send this domain's mail: provider names such as Google Workspace or Mailchimp, or include terms such as include:spf.example.com."}}}
Ausgabeschema
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['domain', 'outcome', 'published', 'after', 'added', 'skipped', 'unrecognised', 'no_include', 'lookups', 'over_limit', 'findings', 'findings_omitted', 'external_data', 'url'], 'properties': {'url': {'type': 'string'}, 'added': {'type': 'array', 'items': {'type': 'string'}}, 'after': {'type': ['string', 'null']}, 'domain': {'type': ['string', 'null']}, 'lookups': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'outcome': {'enum': ['built', 'created', 'merged', 'already-present', 'not-spf', 'invalid', 'nothing-to-add'], 'type': 'string'}, 'skipped': {'type': 'array', 'items': {'type': 'string'}}, 'findings': {'type': 'array', 'items': {'type': 'object', 'required': ['level', 'message'], 'properties': {'level': {'enum': ['ok', 'warn', 'error'], 'type': 'string'}, 'message': {'type': 'string'}}, 'additionalProperties': False}}, 'published': {'type': 'boolean'}, 'no_include': {'type': 'array', 'items': {'type': 'object', 'required': ['name', 'url'], 'properties': {'url': {'type': 'string'}, 'name': {'type': 'string'}}, 'additionalProperties': False}}, 'over_limit': {'type': 'boolean'}, 'unrecognised': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'external_data': {'type': 'object', 'required': ['notice', 'fields', 'omitted'], 'properties': {'fields': {'type': 'array', 'items': {'type': 'object', 'required': ['source', 'label', 'name', 'value', 'shortened'], 'properties': {'name': {'type': ['string', 'null']}, 'label': {'type': 'string'}, 'value': {'type': 'string'}, 'source': {'enum': ['dns', 'report', 'request'], 'type': 'string'}, 'shortened': {'type': 'boolean'}}, 'additionalProperties': False}}, 'notice': {'type': 'string'}, 'omitted': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}}, 'additionalProperties': False}, 'findings_omitted': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}}, 'additionalProperties': False}
check_domain
Check a domain's email authentication
Use this when someone asks whether a domain's email authentication is set up correctly, why mail from a domain fails DMARC, SPF or DKIM, or which DNS records to publish for it. Reads the domain's live DMARC, SPF and DKIM records and returns what is wrong with each, plus the records to add or change. Pass a DKIM selector when you know it. Without one, common selectors are tried. Takes a domain name only, not a mailbox address or an IP address.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'The domain to check, such as example.com. A URL is cut down to its host.'}, 'selector': {'type': 'string', 'maxLength': 63, 'description': 'The DKIM selector, the s= value in a DKIM-Signature header. Leave it out to try common ones.'}}}
Ausgabeschema
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['domain', 'verdict', 'dmarc', 'spf', 'dkim', 'records_to_publish', 'external_data', 'url'], 'properties': {'spf': {'type': 'object', 'required': ['found', 'lookups', 'findings', 'findings_omitted'], 'properties': {'found': {'type': 'boolean'}, 'lookups': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'findings': {'type': 'array', 'items': {'type': 'object', 'required': ['level', 'message'], 'properties': {'level': {'enum': ['ok', 'warn', 'error'], 'type': 'string'}, 'message': {'type': 'string'}}, 'additionalProperties': False}}, 'findings_omitted': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}}, 'additionalProperties': False}, 'url': {'type': 'string'}, 'dkim': {'type': 'object', 'required': ['selector', 'found', 'findings', 'findings_omitted'], 'properties': {'found': {'type': 'boolean'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'required': ['level', 'message'], 'properties': {'level': {'enum': ['ok', 'warn', 'error'], 'type': 'string'}, 'message': {'type': 'string'}}, 'additionalProperties': False}}, 'selector': {'type': ['string', 'null']}, 'findings_omitted': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}}, 'additionalProperties': False}, 'dmarc': {'type': 'object', 'required': ['found', 'policy', 'findings', 'findings_omitted'], 'properties': {'found': {'type': 'boolean'}, 'policy': {'anyOf': [{'enum': ['none', 'quarantine', 'reject'], 'type': 'string'}, {'type': 'null'}]}, 'findings': {'type': 'array', 'items': {'type': 'object', 'required': ['level', 'message'], 'properties': {'level': {'enum': ['ok', 'warn', 'error'], 'type': 'string'}, 'message': {'type': 'string'}}, 'additionalProperties': False}}, 'findings_omitted': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}}, 'additionalProperties': False}, 'domain': {'type': 'string'}, 'verdict': {'enum': ['clean', 'warn', 'flagged', 'idle'], 'type': 'string'}, 'external_data': {'type': 'object', 'required': ['notice', 'fields', 'omitted'], 'properties': {'fields': {'type': 'array', 'items': {'type': 'object', 'required': ['source', 'label', 'name', 'value', 'shortened'], 'properties': {'name': {'type': ['string', 'null']}, 'label': {'type': 'string'}, 'value': {'type': 'string'}, 'source': {'enum': ['dns', 'report', 'request'], 'type': 'string'}, 'shortened': {'type': 'boolean'}}, 'additionalProperties': False}}, 'notice': {'type': 'string'}, 'omitted': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}}, 'additionalProperties': False}, 'records_to_publish': {'type': 'array', 'items': {'type': 'object', 'required': ['name', 'type', 'value', 'why'], 'properties': {'why': {'type': 'string'}, 'name': {'type': 'string'}, 'type': {'type': 'string', 'const': 'TXT'}, 'value': {'type': 'string'}}, 'additionalProperties': False}}}, 'additionalProperties': False}
explain_bounce
Explain a bounce or SMTP error
Use this when someone pastes a bounce message, an SMTP reply such as 550 5.7.26, or an Authentication-Results header and asks what it means or how to fix it. Returns what the receiving server refused, what to change, when it clears, and the page that explains it. Works from the pasted text alone and reads no DNS records.
Nur Lesen Idempotent
Eingabeschema
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['text'], 'properties': {'text': {'type': 'string', 'maxLength': 4000, 'minLength': 1, 'description': 'The bounce message, the SMTP reply or the Authentication-Results line, as pasted. When the bounce runs past 4,000 characters, pass the lines with the error code and the reason.'}}}
Ausgabeschema
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['matched', 'code', 'page', 'meaning', 'change', 'clears', 'faq', 'related'], 'properties': {'faq': {'type': 'array', 'items': {'type': 'object', 'required': ['q', 'a'], 'properties': {'a': {'type': 'string'}, 'q': {'type': 'string'}}, 'additionalProperties': False}}, 'code': {'type': ['string', 'null']}, 'page': {'type': 'object', 'required': ['title', 'url'], 'properties': {'url': {'type': 'string'}, 'title': {'type': 'string'}}, 'additionalProperties': False}, 'change': {'type': ['string', 'null']}, 'clears': {'type': ['string', 'null']}, 'matched': {'type': 'boolean'}, 'meaning': {'type': 'string'}, 'related': {'type': 'array', 'items': {'type': 'object', 'required': ['title', 'url'], 'properties': {'url': {'type': 'string'}, 'title': {'type': 'string'}}, 'additionalProperties': False}}}, 'additionalProperties': False}
Hinzugefügt
analyze_report
4. October 2026 02:40
Hinzugefügt
explain_bounce
4. October 2026 02:40
Hinzugefügt
build_spf
4. October 2026 02:40
Hinzugefügt
check_domain
4. October 2026 02:40