# palisade [Health: Active]

**Category:** 💬 Communication  
**Repository:** https://github.com/palisadeemail/palisade-mcp  
**GitHub Stars:** 0  
**npm Downloads (last month):** 79840  
**Views:** 0  
**Installs:** 0  
**Upvotes:** 0  
**Directory Page:** https://allmcps.com/mcp/palisade-2

## Description
Monitor and manage email authentication (SPF, DKIM, DMARC, MTA-STS, BIMI) for your domains.

## Claude Desktop Quick Installation
Install path detected from listing signals. Uses `npx` (confidence: high):

```json
"mcpServers": {
  "palisade": {
    "command": "npx",
    "args": ["-y","@palisadeemail/mcp"]
  }
}
```

## Documentation

## What palisade MCP server does

The palisade MCP server exposes Palisade's email authentication service to MCP-compatible clients. It covers domain-level checks and management for SPF, DKIM, DMARC, MTA-STS, and BIMI, along with related account, task, reporting, billing, webhook, group, and DNS-connection operations.

Signed-in operations apply to the organization selected during OAuth authentication. Public DNS inspection is available without a Palisade account through a separate endpoint. That public route provides `audit_domain`, which evaluates a domain's authentication posture, and `validate_spf_include`, which checks an SPF include against the ten-lookup limit.

## How it works

The hosted service runs at `https://api.palisade.email/mcp` over Streamable HTTP. The npm package is a local stdio adapter built around `mcp-remote`, allowing stdio-oriented clients to connect without implementing the remote transport themselves.

Running the package opens a browser for OAuth sign-in. You choose an organization, and the bridge retains a token limited by that organization and the user's role. The authorization flow uses Palisade's public OAuth client; API keys are not accepted by the MCP endpoint. The local callback defaults to port 8765, which must be available and registered with the authorization service.

Clients that support Streamable HTTP can connect to the hosted endpoint directly. The public endpoint at `/mcp/public` does not open a browser or require a token, but its calls are throttled by client address. The package can be pointed at that endpoint for stdio-only clients.

## Setup and configuration

For a stdio client, run:

```bash
npx -y @palisadeemail/mcp
```

A typical client entry uses `npx` as the command and `-y @palisadeemail/mcp` as its arguments. Codex can register the same command with `codex mcp add`. Claude Code can skip the bridge and connect to the remote endpoint using HTTP, the supplied OAuth client ID, and callback port 8765.

The bridge supports three optional environment variables. `PALISADE_MCP_URL` changes the endpoint, `PALISADE_MCP_CLIENT_ID` changes the OAuth client ID, and `PALISADE_MCP_CALLBACK_PORT` changes the callback port. The replacement port must also be known to the authorization server. Set the URL to `https://api.palisade.email/mcp/public` to use only public DNS tools without authentication.

## Tools and capabilities

Available operations include:

- Inspecting accounts, domains, live DNS, SPF diagnostics, DNS records, and domain remediation plans.
- Creating, updating, verifying, and deleting domains, groups, hosted DMARC, and MTA-STS configuration.
- Listing, completing, and dismissing remediation tasks.
- Reviewing DMARC aggregate summaries and sender-level source breakdowns.
- Managing subscriptions, checkout, billing portals, webhook endpoints, webhook events, and activity logs.
- Creating prospecting reports for up to ten domains, returning a hosted PDF link, and managing those reports.
- Reviewing DNS provider connections and whether Palisade can publish records for a domain.

Palisade returns the DNS records to publish, but the actual changes are made at the DNS provider hosting the domain unless a supported DNS connection can publish them. Webhooks can be used instead of polling for long-running state changes. A webhook signing secret is returned only when the endpoint is created, so it must be stored at that time.

## Limitations and notes

The palisade MCP server scopes organization data and write operations to the authenticated organization. `audit_domain`, `validate_spf_include`, and prospecting reports use domain names and public DNS instead of an account domain ID. Each domain in a prospecting report consumes the same live-DNS budget as an individual audit.

A connection that exposes only `authenticate` and `complete_authentication` has not completed browser sign-in. Complete the OAuth flow before expecting Palisade's tools. If another configuration with the same server name is active, inspect the effective client entry; Claude Code scope can cause a different entry to win.

API-key authentication and dynamically registered OAuth clients are refused by the MCP endpoint. Payment actions open Stripe-hosted pages, and SPF validation is constrained by the DNS protocol's ten-lookup limit.

_Full upstream README: https://allmcps.com/mcp/palisade-2/readme_

