DMARKOFF MCP

MCP serverDatabases & data

Understand the health of your domain's email setup and catch unusual activity early. Once added, your AI can analyze your DMARC data, check SPF and DKIM, and report on compliance. It can also help you get a new domain set up.

Available today. Use it from your connected AI after setup.

After adding it, ask your AI to check the health of one of your domains or to walk you through setting up a new one.

Then ask your AI: use DMARKOFF MCP

What your AI can do with it

  • Check the health of a domain's email setup
  • Review SPF and DKIM settings
  • Report on DMARC compliance
  • Flag unusual activity in your domain's email data
  • Walk you through setting up a new domain

From the project's README

As published by dmarcoff/mcp in README.md.

DMARC analytics inside your AI assistant.

DMARKOFF MCP connects your DMARC monitoring data to AI assistants — Claude, ChatGPT, Cursor, Windsurf — through the Model Context Protocol. Instead of opening a dashboard and building filters, you ask a question and get an answer with real numbers behind it.

Endpoint: https://mcp.dmarkoff.com/mcp
Requires: an active DMARKOFF account and an API key from app.dmarkoff.com/account/mcp


What it looks like in practice

"Which domains dropped in compliance over the last 14 days?"

The AI checks health across all your projects and surfaces the ones that changed — ranked by how much.

"Why is SPF failing on acme-transact.com? Who's the problem sender?"

The AI checks return paths, finds the sending source (say, SendGrid using its own bounce domain instead of yours), and tells you what to fix.

"Anything unusual in email traffic compared to last week?"

The AI compares yesterday's stats against a 14-day baseline — compliance rate, unknown sender volume, message counts. The kind of check most teams skip because setting it up manually takes too long.


Quick connect

Claude.ai

  1. Settings → Connectors → Add custom connector
  2. URL: https://mcp.dmarkoff.com/mcp
  3. Advanced settings:
    • OAuth Client ID: claude (any value)
    • OAuth Client Secret: your DMARKOFF API key
  4. Click Add, then Connect

Works on Free (1 custom connector limit), Pro, Max, Team, and Enterprise.

Claude Desktop

Click + in the chat window → Connectors → Manage Connectors → Add custom connector, paste the URL, complete the OAuth flow.

Or edit the config file (~/Library/Application Support/Claude/claude_desktop_config.json on macOS):

{
  "mcpServers": {
    "dmarkoff": {
      "command": "npx",
      "args": [
        "mcp-remote",
        "https://mcp.dmarkoff.com/mcp",
        "--header",
        "Authorization: Bearer YOUR_API_KEY"
      ]
    }
  }
}

Claude Code

claude mcp add --transport http dmarkoff https://mcp.dmarkoff.com/mcp \
  --header "Authorization: Bearer YOUR_API_KEY"

Cursor

Settings → Tools & MCP → Add new MCP server, select Streamable HTTP, enter the URL.

Or edit ~/.cursor/mcp.json:

{
  "mcpServers": {
    "dmarkoff": {
      "url": "https://mcp.dmarkoff.com/mcp",
      "headers": {
        "Authorization": "Bearer YOUR_API_KEY"
      }
    }
  }
}

ChatGPT (Business / Enterprise / Edu)

Enable Developer Mode, then go to Settings → Apps → Create App:

  • MCP Server URL: https://mcp.dmarkoff.com/mcp
  • Auth type: OAuth
  • Client ID: chatgpt
  • Client Secret: your DMARKOFF API key
  • Authorization URL: https://mcp.dmarkoff.com/oauth/authorize
  • Token URL: https://mcp.dmarkoff.com/oauth/token
  • Scope: leave empty — the server issues unscoped tokens

Windsurf

Edit ~/.codeium/windsurf/mcp_config.json:

{
  "mcpServers": {
    "dmarkoff": {
      "serverUrl": "https://mcp.dmarkoff.com/mcp",
      "headers": {
        "Authorization": "Bearer YOUR_API_KEY"
      }
    }
  }
}

Note: Windsurf uses serverUrl, not url.

Full connection guide for all clients


Things to ask

Show me an overview of all my DMARC projects
Which domains have Critical severity right now?
Why is SPF failing on domain.com? Which senders are the problem?
Are there anomalies in email traffic over the last 24 hours?
Show me source details for domain.com grouped by ISP — only rows where SPF is failing
We publish p=reject on domain.com — why did some mail still get delivered?
Gmail is throttling us on domain.com. What are they actually complaining about?
Our SPF record is at 10 lookups — which includes still carry mail and which can go?
Compliance on domain.com dropped last week. Did the DMARC or SPF record change?

Live DNS checks — these work for any domain, monitored or not:

Check the SPF record for example.com — are there too many DNS lookups?
What DMARC policy does example.com have right now?
Look up the DKIM key for selector "google" on example.com

Onboarding a new domain — the assistant registers it and hands you the exact TXT record to publish:

Add example.com to my project and tell me what to put in DNS
We already have DMARC on example.com — add our reporting address without touching the rest of the record

Tools

Analytics (require API key)

ToolWhat it does
projects_overviewSummary across all projects: domain counts, three compliance rates, severity breakdown
list_domainsFilter domains by severity, search query, payment status; pagination
get_domain_full_dataFull diagnostic: DMARC/SPF/DKIM records, stats, timeline, trends, and the same numbers over the previous period — start here
get_domain_statsCompliance percentages for a custom date range
get_domain_timelineDay-by-day message counts and auth results
get_domain_activity_healthPer-day SPF/DKIM/DMARC severity vs 14-day baseline — detect when and why things changed
get_domain_sendersTop sending sources broken down by known ESPs, unknown, forwarded — per provider or per sending domain
get_domain_source_detailsPer-record detail grouped by IP, ISP, hostname, or reporter with filters
get_domain_anomaly_reportYesterday vs 14-day baseline — flags compliance drops and volume changes
get_geo_sourcesTop 100 sending locations with compliance stats
get_domain_detailDMARC record text, policy, health status per dimension, errors, name servers
get_spf_recordsSPF return paths, lookup count, errors, pass/fail volume per source
get_dkim_recordsDKIM selectors, signing domains, pass/fail volume per source
get_record_historyPast versions of a DMARC, SPF or DKIM record with what changed between checks — when did this break
get_policy_overridesWhy receivers did not enforce your policy: ARC, forwarding, sampling, local rules
get_smtp_rejectionsMail throttled or rejected at SMTP time, by reason — Gmail's 421/550 codes explained
get_spf_usageWhich SPF mechanisms actually carry mail, and which senders your record misses — for lookup-limit clean-ups

Live DNS (API key, but no monitored project)

ToolWhat it does
dns_check_spfCurrent SPF record with parsed include tree and lookup count
dns_check_dmarcCurrent DMARC policy from DNS
dns_check_dkimDKIM public key for a given selector
dns_check_txtAll TXT records with type classification (spf, dmarc, mta-sts, bimi, other)
generate_dmarc_recordThe DMARC record a domain should publish, merged on top of whatever is already in DNS. With a project, adds your reporting address to rua

Onboarding (requires API key and owner access to the project)

ToolWhat it does
add_domainAdds up to 20 domains to a project and returns the DMARC record to publish for them

Every tool is read-only (readOnlyHint: true per MCP spec) except add_domain. That one creates domains — it never updates or deletes anything — and each non-parked domain it adds consumes a paid domain slot on your plan.

Full tool reference with parameters


Security

  • API key auth — access is scoped to your DMARKOFF account
  • OAuth 2.1 (RFC 8414, RFC 9728) — compatible with standard MCP flows used by Claude.ai and ChatGPT
  • Project-level isolation — the AI only sees what your API key has access to
  • Per-API-key rate limiting — protection against accidental overuse
  • Nothing is modified or deleted — every tool is read-only except add_domain, which only creates domains in a project you own, and only when you ask for it

How this differs from other DMARC MCP tools

DNS checks tell you SPF is failing. DMARKOFF MCP tells you which specific sender is causing the failure, how many messages it affected over the last two weeks, and what the fix is. That data comes from your aggregate reports — the actual traffic — not just what's published in DNS.

It also answers the questions that come after: whether the problem is new (every domain report carries the previous period beside the current one), what a record looked like before someone edited it, why a receiver ignored the policy you published, and which parts of an oversized SPF record are still earning their DNS lookups.


Troubleshooting

Tools don't appear in the client
→ Confirm your client supports Streamable HTTP (not just SSE).
→ Some clients need a full restart after config changes.

401 Unauthorized
→ Check your API key at app.dmarkoff.com/account/mcp.

"No projects found"
→ The API key needs access to at least one project. Log into app.dmarkoff.com to verify.

OAuth errors
→ The Client Secret field takes your DMARKOFF API key, not your account password.

Need help? Email support@mail.dmarkoff.com or open an issue.

Signals

GitHub stars
8
Last commit
Sep 2026
Advanced
Delivery
mcp MCP server → your ahel gateway (mcp.ahel.ai) → every connected AI client.
Catalog kind
mcp-server
Gateway key
com-dmarkoff-mcp
Source
github.com/dmarcoff/mcp
Hosted endpoint
https://mcp.dmarkoff.com/mcp