DMARKOFF MCP
MCP serverDatabases & dataUnderstand the health of your domain's email setup and catch unusual activity early. Once added, your AI can analyze your DMARC data, check SPF and DKIM, and report on compliance. It can also help you get a new domain set up.
Available today. Use it from your connected AI after setup.
Needs your own account with this service. Credentials stay encrypted.
After adding it, ask your AI to check the health of one of your domains or to walk you through setting up a new one.
Then ask your AI: use DMARKOFF MCP
What your AI can do with it
- Check the health of a domain's email setup
- Review SPF and DKIM settings
- Report on DMARC compliance
- Flag unusual activity in your domain's email data
- Walk you through setting up a new domain
From the project's README
As published by dmarcoff/mcp in README.md.
DMARC analytics inside your AI assistant.
DMARKOFF MCP connects your DMARC monitoring data to AI assistants — Claude, ChatGPT, Cursor, Windsurf — through the Model Context Protocol. Instead of opening a dashboard and building filters, you ask a question and get an answer with real numbers behind it.
Endpoint: https://mcp.dmarkoff.com/mcp
Requires: an active DMARKOFF account and an API key from app.dmarkoff.com/account/mcp
What it looks like in practice
"Which domains dropped in compliance over the last 14 days?"
The AI checks health across all your projects and surfaces the ones that changed — ranked by how much.
"Why is SPF failing on acme-transact.com? Who's the problem sender?"
The AI checks return paths, finds the sending source (say, SendGrid using its own bounce domain instead of yours), and tells you what to fix.
"Anything unusual in email traffic compared to last week?"
The AI compares yesterday's stats against a 14-day baseline — compliance rate, unknown sender volume, message counts. The kind of check most teams skip because setting it up manually takes too long.
Quick connect
Claude.ai
- Settings → Connectors → Add custom connector
- URL:
https://mcp.dmarkoff.com/mcp - Advanced settings:
- OAuth Client ID:
claude(any value) - OAuth Client Secret: your DMARKOFF API key
- OAuth Client ID:
- Click Add, then Connect
Works on Free (1 custom connector limit), Pro, Max, Team, and Enterprise.
Claude Desktop
Click + in the chat window → Connectors → Manage Connectors → Add custom connector, paste the URL, complete the OAuth flow.
Or edit the config file (~/Library/Application Support/Claude/claude_desktop_config.json on macOS):
{
"mcpServers": {
"dmarkoff": {
"command": "npx",
"args": [
"mcp-remote",
"https://mcp.dmarkoff.com/mcp",
"--header",
"Authorization: Bearer YOUR_API_KEY"
]
}
}
}
Claude Code
claude mcp add --transport http dmarkoff https://mcp.dmarkoff.com/mcp \
--header "Authorization: Bearer YOUR_API_KEY"
Cursor
Settings → Tools & MCP → Add new MCP server, select Streamable HTTP, enter the URL.
Or edit ~/.cursor/mcp.json:
{
"mcpServers": {
"dmarkoff": {
"url": "https://mcp.dmarkoff.com/mcp",
"headers": {
"Authorization": "Bearer YOUR_API_KEY"
}
}
}
}
ChatGPT (Business / Enterprise / Edu)
Enable Developer Mode, then go to Settings → Apps → Create App:
- MCP Server URL:
https://mcp.dmarkoff.com/mcp - Auth type: OAuth
- Client ID:
chatgpt - Client Secret: your DMARKOFF API key
- Authorization URL:
https://mcp.dmarkoff.com/oauth/authorize - Token URL:
https://mcp.dmarkoff.com/oauth/token - Scope: leave empty — the server issues unscoped tokens
Windsurf
Edit ~/.codeium/windsurf/mcp_config.json:
{
"mcpServers": {
"dmarkoff": {
"serverUrl": "https://mcp.dmarkoff.com/mcp",
"headers": {
"Authorization": "Bearer YOUR_API_KEY"
}
}
}
}
Note: Windsurf uses
serverUrl, noturl.
→ Full connection guide for all clients
Things to ask
Show me an overview of all my DMARC projects
Which domains have Critical severity right now?
Why is SPF failing on domain.com? Which senders are the problem?
Are there anomalies in email traffic over the last 24 hours?
Show me source details for domain.com grouped by ISP — only rows where SPF is failing
We publish p=reject on domain.com — why did some mail still get delivered?
Gmail is throttling us on domain.com. What are they actually complaining about?
Our SPF record is at 10 lookups — which includes still carry mail and which can go?
Compliance on domain.com dropped last week. Did the DMARC or SPF record change?
Live DNS checks — these work for any domain, monitored or not:
Check the SPF record for example.com — are there too many DNS lookups?
What DMARC policy does example.com have right now?
Look up the DKIM key for selector "google" on example.com
Onboarding a new domain — the assistant registers it and hands you the exact TXT record to publish:
Add example.com to my project and tell me what to put in DNS
We already have DMARC on example.com — add our reporting address without touching the rest of the record
Tools
Analytics (require API key)
| Tool | What it does |
|---|---|
projects_overview | Summary across all projects: domain counts, three compliance rates, severity breakdown |
list_domains | Filter domains by severity, search query, payment status; pagination |
get_domain_full_data | Full diagnostic: DMARC/SPF/DKIM records, stats, timeline, trends, and the same numbers over the previous period — start here |
get_domain_stats | Compliance percentages for a custom date range |
get_domain_timeline | Day-by-day message counts and auth results |
get_domain_activity_health | Per-day SPF/DKIM/DMARC severity vs 14-day baseline — detect when and why things changed |
get_domain_senders | Top sending sources broken down by known ESPs, unknown, forwarded — per provider or per sending domain |
get_domain_source_details | Per-record detail grouped by IP, ISP, hostname, or reporter with filters |
get_domain_anomaly_report | Yesterday vs 14-day baseline — flags compliance drops and volume changes |
get_geo_sources | Top 100 sending locations with compliance stats |
get_domain_detail | DMARC record text, policy, health status per dimension, errors, name servers |
get_spf_records | SPF return paths, lookup count, errors, pass/fail volume per source |
get_dkim_records | DKIM selectors, signing domains, pass/fail volume per source |
get_record_history | Past versions of a DMARC, SPF or DKIM record with what changed between checks — when did this break |
get_policy_overrides | Why receivers did not enforce your policy: ARC, forwarding, sampling, local rules |
get_smtp_rejections | Mail throttled or rejected at SMTP time, by reason — Gmail's 421/550 codes explained |
get_spf_usage | Which SPF mechanisms actually carry mail, and which senders your record misses — for lookup-limit clean-ups |
Live DNS (API key, but no monitored project)
| Tool | What it does |
|---|---|
dns_check_spf | Current SPF record with parsed include tree and lookup count |
dns_check_dmarc | Current DMARC policy from DNS |
dns_check_dkim | DKIM public key for a given selector |
dns_check_txt | All TXT records with type classification (spf, dmarc, mta-sts, bimi, other) |
generate_dmarc_record | The DMARC record a domain should publish, merged on top of whatever is already in DNS. With a project, adds your reporting address to rua |
Onboarding (requires API key and owner access to the project)
| Tool | What it does |
|---|---|
add_domain | Adds up to 20 domains to a project and returns the DMARC record to publish for them |
Every tool is read-only (readOnlyHint: true per MCP spec) except add_domain. That one creates domains — it never updates or deletes anything — and each non-parked domain it adds consumes a paid domain slot on your plan.
→ Full tool reference with parameters
Security
- API key auth — access is scoped to your DMARKOFF account
- OAuth 2.1 (RFC 8414, RFC 9728) — compatible with standard MCP flows used by Claude.ai and ChatGPT
- Project-level isolation — the AI only sees what your API key has access to
- Per-API-key rate limiting — protection against accidental overuse
- Nothing is modified or deleted — every tool is read-only except
add_domain, which only creates domains in a project you own, and only when you ask for it
How this differs from other DMARC MCP tools
DNS checks tell you SPF is failing. DMARKOFF MCP tells you which specific sender is causing the failure, how many messages it affected over the last two weeks, and what the fix is. That data comes from your aggregate reports — the actual traffic — not just what's published in DNS.
It also answers the questions that come after: whether the problem is new (every domain report carries the previous period beside the current one), what a record looked like before someone edited it, why a receiver ignored the policy you published, and which parts of an oversized SPF record are still earning their DNS lookups.
Troubleshooting
Tools don't appear in the client
→ Confirm your client supports Streamable HTTP (not just SSE).
→ Some clients need a full restart after config changes.
401 Unauthorized
→ Check your API key at app.dmarkoff.com/account/mcp.
"No projects found"
→ The API key needs access to at least one project. Log into app.dmarkoff.com to verify.
OAuth errors
→ The Client Secret field takes your DMARKOFF API key, not your account password.
Need help? Email support@mail.dmarkoff.com or open an issue.
Signals
- GitHub stars
- 8
- Last commit
- Sep 2026
Advanced
- Delivery
- mcp MCP server → your ahel gateway (mcp.ahel.ai) → every connected AI client.
- Catalog kind
- mcp-server
- Gateway key
com-dmarkoff-mcp- Source
- github.com/dmarcoff/mcp
- Hosted endpoint
https://mcp.dmarkoff.com/mcp