MCP Server

MailVakt

com.mailvakt/mailvakt
Security Public & reachable MCP 2025-11-25

What this MCP does

Audits email authentication and delivery configuration, analyzes headers, proposes DNS records, summarizes DMARC reports, and runs inbox tests.

add_domain
Add domain
Add a domain to the signed-in user's MailVakt account for DMARC report collection. Takes a domain; returns its DMARC reporting (rua) address and account entry. Repeated calls for the same account and domain return the existing entry. Requires domains:write permission. Does not verify domain ownership, modify DNS, or start receiving reports until the user publishes the reporting address in DNS.
Idempotent
Input schema
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'The domain to add, e.g. example.com'}}}
analyze_email_headers
Analyze email headers
Analyze raw email headers supplied by the user to investigate authentication or delivery issues. Returns the SPF, DKIM and DMARC results reported in those headers, alignment, sending IP and detected issues. Parses the supplied text without external DNS or HTTP lookups; it does not independently verify DKIM signatures or establish the receiving provider's exact spam-filter decision. Provide headers only, not the message body.
Read only
Input schema
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['headers'], 'properties': {'headers': {'type': 'string', 'maxLength': 262144, 'minLength': 1, 'description': 'The raw message headers, as copied from "Show original"'}}}
diagnose_domain
Diagnose email domain
Audit a domain's SPF, DKIM, DMARC, MX, alignment, BIMI, MTA-STS and TLS-RPT configuration when troubleshooting email authentication or spam delivery. Takes a domain, optional checks and DKIM selectors, and fresh=true to bypass cached results. Returns a graded scorecard, findings, proposed DNS fixes and a public report permalink. Uses DNS and policy-file lookups; never changes DNS or guarantees inbox placement.
Read only Open world
Input schema
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['domain'], 'properties': {'fresh': {'type': 'boolean', 'description': 'Bypass caches and re-query DNS'}, 'checks': {'type': 'array', 'items': {'enum': ['mx', 'spf', 'dkim', 'dmarc', 'alignment', 'bimi', 'mta-sts', 'tls-rpt'], 'type': 'string'}, 'description': 'Run only these checks (default: all)'}, 'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'The domain to check, e.g. example.com'}, 'dkim_selectors': {'type': 'array', 'items': {'type': 'string', 'maxLength': 63, 'minLength': 1}, 'maxItems': 20, 'description': 'Extra DKIM selectors to probe, e.g. google, s1'}}}
generate_dns_records
Generate email DNS records
Propose email-authentication DNS records and policy files for a domain using its DNS configuration and optional provider names or IDs. Supports baseline (monitoring) or enforce goals; baseline is the default. Returns typed SPF, DKIM, DMARC, MTA-STS and TLS-RPT proposals or provider setup instructions where applicable. Provider-specific values and reporting addresses may need user input. Uses public DNS/policy lookups, possibly cached. Does not publish records or change DNS.
Read only Open world
Input schema
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['domain'], 'properties': {'goal': {'enum': ['baseline', 'enforce'], 'type': 'string', 'description': 'baseline: monitor (p=none); enforce: quarantine/reject'}, 'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'The domain the records are for, e.g. example.com'}, 'providers': {'type': 'array', 'items': {'type': 'string', 'maxLength': 64, 'minLength': 1}, 'maxItems': 20, 'description': 'Provider ids or names, e.g. google-workspace, sendgrid (default: detected)'}}}
get_dmarc_summary
DMARC report summary
Summarize received DMARC aggregate reports for a domain already in the signed-in user's MailVakt account. Takes the domain and a 1-to-90-day window (default 7); returns report and message totals, DMARC pass/fail counts, and per-source SPF/DKIM alignment and receiver actions. Requires domains:read and reports:read permissions. Returns zero totals if no reports were received, or an error if the domain is not in the account. Does not add domains or generate report traffic.
Read only
Input schema
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['domain'], 'properties': {'days': {'type': 'integer', 'default': 7, 'maximum': 90, 'minimum': 1, 'description': 'Window in days (default 7)'}, 'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': "One of the user's domains, e.g. example.com"}}}
get_inbox_test
Get inbox test result
Read a MailVakt email-receipt test using the ID returned by start_inbox_test. Returns pending, received or expired status and, when processed, the received message's authentication, unsubscribe, content and deliverability findings. Reports processing failures as errors. Anyone with the test ID can retrieve it; use only an ID supplied by the user or created in this conversation. Does not measure placement at other mailbox providers.
Read only
Input schema
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['id'], 'properties': {'id': {'type': 'string', 'pattern': '^[a-z2-7]{1,32}$', 'description': 'The id returned by start_inbox_test'}}}
list_domains
List domains
List domains in the signed-in user's MailVakt account, including each domain's DMARC reporting address. Takes no input and requires domains:read permission. Returns an empty list if the account has no domains. Use to find the account's available domains before requesting DMARC summaries; does not enumerate domains belonging to other users.
Read only
Input schema
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {}}
start_inbox_test
Start inbox test
Create an email-receipt test in MailVakt. Takes an optional expected sender domain; returns a test ID, unique recipient address and expiry time. The user must send a test message to that address before expiry, then use get_inbox_test to read the result. Creates a new test on each call. Does not send email or measure inbox-versus-spam placement at Gmail, Outlook or other mailbox providers.
Input schema
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'expected_from_domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'The domain the test email will be sent from, e.g. example.com'}}}
Added
get_dmarc_summary
Oct. 3, 2026, 2:40 a.m.
Added
list_domains
Oct. 3, 2026, 2:40 a.m.
Added
add_domain
Oct. 3, 2026, 2:40 a.m.
Added
get_inbox_test
Oct. 3, 2026, 2:40 a.m.
Added
start_inbox_test
Oct. 3, 2026, 2:40 a.m.
Added
generate_dns_records
Oct. 3, 2026, 2:40 a.m.
Added
analyze_email_headers
Oct. 3, 2026, 2:40 a.m.
Added
diagnose_domain
Oct. 3, 2026, 2:40 a.m.