Back to Browse

Deliverability Doctor MCP Server

Developer ToolsLow Risk10.0MCP RegistryRemote
Free

Server data from the Official MCP Registry

Check if a domain can be email-spoofed: SPF, DMARC, DKIM, MX graded from public DNS. Authless.

About

Check if a domain can be email-spoofed: SPF, DMARC, DKIM, MX graded from public DNS. Authless.

Remote endpoints: streamable-http: https://deliverability-doctor.deliverability-doctor.workers.dev/mcp

Security Report

10.0
Low Risk10.0Low Risk

Valid MCP server (2 strong, 2 medium validity signals). No known CVEs in dependencies. Imported from the Official MCP Registry.

2 tools verified · Open access · No issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

env_vars

Check that this permission is expected for this type of plugin.

How to Connect

Remote Plugin

No local installation needed. Your AI client connects to the remote endpoint directly.

Add this to your MCP configuration to connect:

{
  "mcpServers": {
    "io-github-integrity-os-deliverability-doctor": {
      "url": "https://deliverability-doctor.deliverability-doctor.workers.dev/mcp"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

Deliverability Doctor

Remote MCP server: "Can my domain be email-spoofed?" answered from public DNS, graded, with concrete fixes. Connectable to Claude (custom connector) and ChatGPT (Apps SDK / MCP connector) — both speak MCP, one server serves both.

Tools

  • check_email_security(domain) — SPF (incl. RFC 7208 multiple-record permerror and redirect= handling), DMARC (policy, rua, pct), MX, DKIM at 7 common selectors. Graded A–F report, fixes per finding, upsell line only when problems exist. Accepts bare domain, URL, or email address.
  • compare_email_security(domains[2..5]) — comparison table with grades.

Design decisions

  • Authless: reads public DNS only, stores nothing, takes nothing but a domain. Lowest possible connect friction; nothing sensitive to protect.
  • DNS-over-HTTPS (Cloudflare → Google fallback): identical code runs on local Node and on Cloudflare Workers — no dns module dependency.
  • Stateless streamable HTTP: fresh transport per request, no sessions; safe to scale, trivial for clients.
  • NXDOMAIN is refused, not graded — "domain doesn't exist" ≠ "spoofable".
  • Verified against known postures before first run: gmail.com (redirect= must not be flagged), n8n.io (must grade A on p=reject), missing-everything domain (must grade F), NXDOMAIN (must refuse).

Run

npm install
node server.js          # :8787/mcp

Quick public demo: cloudflared tunnel --url http://localhost:8787 → use https://<random>.trycloudflare.com/mcp as the connector URL.

Status 2026-08-23

  • Local: end-to-end MCP verified (initialize / tools/list / tools/call).
  • Public: live via quick tunnel, initialize verified from the public URL.
  • Durable hosting: pending — Cloudflare Workers deploy needs Kacper's account (~5 min). Tunnel URL dies with the process/PC.
  • Directory submissions (Anthropic connector directory, ChatGPT apps): need the durable URL first, then Kacper's developer accounts.

Monetization path

Free tool = distribution. Report links the $99 written audit (niekonieczny.gumroad.com/l/vscjt) only when problems are found. NOTE: Gumroad payouts currently frozen on Stripe KYC — unfreeze before promoting.

Reviews

No reviews yet

Be the first to review this server!