Back to Browse

Palisade DMARC Agent MCP Server

by samuelchenardlovesboards
SecurityModerate6.5LocalRemoteNew
Free

AI-powered DMARC and email authentication for AI agents

About

Manage DMARC, SPF, DKIM, BIMI, MTA-STS, DNS records, and remediation tasks from MCP-compatible AI agents. Connect using your Palisade API key.

Security Report

6.5
Moderate6.5Moderate Risk

This MCP server is a thin stdio bridge to a remote Palisade email authentication API. While the architecture is sound and authentication is required, there is a critical credential handling vulnerability: the API key is passed as a command-line argument to the spawned `mcp-remote` process, making it visible to process inspection tools (ps, /proc) and potentially logged by the system. This is a confirmed dangerous pattern that should be remediated immediately. The server itself has minimal code and appropriate permissions for its purpose. Package verification found 1 issue.

3 files analyzed · 5 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

env_vars

Check that this permission is expected for this type of plugin.

HTTP Network Access

Connects to external APIs or services over the internet.

process_spawn

Check that this permission is expected for this type of plugin.

What You'll Need

Set these up before or after installing:

A Palisade API key used to authenticate requests to the Palisade MCP endpoint.Required

Environment variable: PALISADE_API_KEY

Sign up free

How to Install & Connect

Available as Local & Remote

This plugin can run on your machine or connect to a hosted endpoint. during install.

Getting Started

Once installed, try these example prompts and explore these capabilities:

  • 1Check the DMARC status for example.com
  • 2Show the DNS records needed to configure SPF and DKIM
  • 3List remediation tasks for my domains

Documentation

View on GitHub

From the project's GitHub README.

@palisadeemail/mcp

Connect an MCP client to the Palisade MCP server, which monitors and manages email authentication (SPF, DKIM, DMARC, MTA-STS, BIMI) for your domains.

Palisade's MCP server is remote (Streamable HTTP at https://api.palisade.email/mcp). This package is a thin local bridge for stdio-based clients, using mcp-remote under the hood. Clients that support remote HTTP MCP servers with a bearer token can point at the URL directly and skip this package.

Get an API key

Create one at app.palisade.email → Settings → API keys, or programmatically via headless signup. See the developer guide.

Use it

Set PALISADE_API_KEY and run:

PALISADE_API_KEY=secret_... npx -y @palisadeemail/mcp

Client config (stdio)

{
  "mcpServers": {
    "palisade": {
      "command": "npx",
      "args": ["-y", "@palisadeemail/mcp"],
      "env": { "PALISADE_API_KEY": "secret_..." }
    }
  }
}

Direct (clients that support remote HTTP MCP)

{
  "mcpServers": {
    "palisade": {
      "type": "http",
      "url": "https://api.palisade.email/mcp",
      "headers": { "Authorization": "Bearer secret_..." }
    }
  }
}

When headers.Authorization is set, the client authenticates with that API key and does not fall back to OAuth. The server replies 401 with a WWW-Authenticate challenge whenever credentials are missing or rejected, so a bad key surfaces as a connection error rather than silently starting an OAuth flow.

If the server connects but the Palisade tools are missing

A session that offers only authenticate / complete_authentication is using an OAuth-based entry, not your API-key entry. The Palisade server has no reduced tool set: any authenticated caller gets the full list under Tools. Those two tools come from the client's own pending-OAuth state.

This usually means a same-named server is configured somewhere else and is the one in effect. In Claude Code, --scope local applies only to the directory it was run in, and a palisade entry in user scope (from a previous OAuth connection) applies everywhere else. Check which entry actually wins:

claude mcp get palisade

The reported scope is the one in effect. If it is not the entry holding your API key, remove the other one, for example claude mcp remove palisade -s user, or give the API-key entry a distinct name.

Tools

Accounts (get_account), domains (list_domains, get_domain, add_domain, remove_domain, verify_domain), DNS setup (get_dns_records — the exact records to publish at your own DNS provider), MTA-STS (get_mta_sts, enable_mta_sts), remediation tasks (list_tasks, get_task), groups (list_groups), and billing (get_subscription, start_checkout, get_billing_portal_url).

Palisade tells you which DNS records to publish; you apply them at whatever DNS provider hosts the domain. Payment happens on Stripe-hosted pages.

Environment

  • PALISADE_API_KEY (required) — your Palisade API key.
  • PALISADE_MCP_URL (optional) — override the server URL (defaults to https://api.palisade.email/mcp).

Reviews

No reviews yet

Be the first to review this server!

Palisade DMARC Agent MCP Server - AI-powered DMARC and email authentication for AI agents | MCP Marketplace