Skip to main content
AllMCPs
BrowseBestCategoriesStackCompareToolsGuidesBlog
Log in Submit MCP

Stay in the loop

Get new MCP servers and top picks in your inbox.

AllMCPs

The open directory for discovering and installing Model Context Protocol servers.

AllMCPs on GitHub (opens in a new tab)
Launched onTiny Startupstinystartups.com
Explore
  • Browse servers
  • Best MCP servers
  • Categories
  • MCP clients
  • Agent prompts
  • Stack Builder
  • Compare servers
  • Random discovery New
  • Submit a server
  • Pricing & Boost Boost
Learn
  • Guides hub
  • What is MCP?
  • Install guide
  • Build an MCP server
  • Deploy an MCP server
  • Security guide
  • Troubleshooting
  • MCP for SEO & AEO
  • Protocol versioning
  • Transports: stdio vs HTTP
  • State of MCP (stats)
  • Blog & updates
Tools
  • All developer tools
  • Config generator
  • Config validator
  • Config auditor
  • MCP playground
  • Token calculator
  • OpenAPI β†’ MCP
  • Badge generator
For agents
  • REST API docs
  • Trust & traffic Live
  • Remote MCP server SSE β†— (opens in a new tab)
  • llms.txt β†— (opens in a new tab)
  • Catalog JSON β†— (opens in a new tab)
Company
  • About
  • Advertise Sponsor
  • Contact
  • GitHub β†— (opens in a new tab)
  • Terms
  • Privacy
AllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZoneAllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZone
Β© 2026 Jackalope Digital LLC. All rights reserved.
  1. Home
  2. πŸ’¬ Communication
  3. Domain Security
D
Health: Not checked yetWe have not completed a health check for this listing yet.No health check has run yet.

Domain Security

User RatingsBe the first to rate and review this MCP server! Enrichment pendingWe haven’t run our AI enrichment pass on this listing yet, so the overview, use cases, and FAQ below may be sparse or missing. We work through the catalog over time β€” check back soon.
View Repository

Audit a domain's email and web security: SPF, DKIM, DMARC, MTA-STS, DNSSEC, TLS, WHOIS. No API keys.

Quick Install

Automated & IDE Setup

Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β€” or use 1-click editor setup below.

One-click editor setup isn’t available for this listing yet β€” we don’t have a confirmed install command, and we’d rather show nothing than point your editor at the wrong package or host. Follow the project’s own setup instructions, linked above.

Manual Client & Custom JSON ConfigExpand JSON β–Ύ
No confirmed setup config for this listing yet. We only publish a config block when the install details come from the project itself β€” its README, its docs, or a verified owner. We haven’t found those for Domain Security, and we’d rather show nothing than a guess you’d paste into your client. Follow the project’s own setup instructions for the current steps.
Install Directory Badge Claim listing AlternativesπŸ’¬ More in Communication

Documentation Overview

domain-security-mcp-server

An MCP server that lets an AI agent audit the email and domain security of any domain β€” SPF, DKIM, DMARC, MTA-STS, TLS-RPT, BIMI, DNSSEC, DNS, TLS/SSL and WHOIS β€” in plain language. No API keys required.

ci npm MCP TypeScript License: MIT

Built on the v2 MCP SDK: the server speaks the 2026-07-28 protocol revision and keeps accepting 2025-era clients (Claude Desktop, Claude Code, Cursor) from the same factory β€” the era is negotiated per connection, so there is nothing to configure on either side.

Ask Claude "Is acme.com protected against email spoofing?" and it runs a full authentication audit and hands you a graded report with prioritised fixes β€” instead of you pasting a domain into five different web tools.

Code
> Is ortamarco.me protected against email spoofing?

  email_auth_audit(domain="ortamarco.me")

  Grade: A (95/100) Β· MX: present
  βœ… SPF ends in '-all' (hard fail). 3/10 DNS lookups.
  βœ… DMARC policy is enforced ('p=reject').
  βœ… DKIM key found for selector: google.
  Top recommendation: add a TLS-RPT record for delivery-failure reports.

Why this exists

The email-security ecosystem is full of single-purpose web checkers (SPF here, DMARC there, WHOIS somewhere else) and the few MCP equivalents are locked behind paid API tokens. This server brings the whole deliverability & domain-security toolkit to any MCP client, key-free, with one headline workflow tool that does the synthesis for you.

It is the agent-facing companion to the network tools at ortamarco.me and shares the same battle-tested core (public-resolver DNS, host validation, timeouts).

Tools

ToolWhat it does
email_auth_audit ⭐One-call SPF + DKIM + DMARC + MX audit β†’ 0–100 score, A–F grade, prioritised fixes
spf_checkParse SPF; recursively count DNS lookups vs the RFC 7208 limit of 10; flag +all/?all
dmarc_checkParse DMARC policy (p, sp, rua, pct, aspf/adkim) with warnings
dkim_checkProbe <selector>._domainkey keys (supply selectors or use common ones)
mta_sts_checkValidate the _mta-sts TXT and the .well-known/mta-sts.txt policy + mode
tls_rpt_checkCheck the _smtp._tls TLS-RPT record
bimi_checkCheck the default._bimi BIMI record
dnssec_checkDS/DNSKEY presence + DNSSEC AD validation flag (via DoH)
dns_lookupAll record types (A/AAAA/CNAME/MX/NS/TXT/SOA) via public resolvers
ssl_certificateTLS cert issuer, validity window, days-to-expiry, SANs, fingerprint
whois_lookupRegistrar, dates, name servers, status (raw port-43 WHOIS, IANA-resolved)
reverse_dnsPTR records for an IP
ip_geolocationOffline IP geolocation (DB-IP Lite) + reverse DNS
mx_lookupMail servers (MX) with priority and resolved IPs
caa_checkWhich CAs may issue TLS certificates (CAA records)
blacklist_checkIP/domain against open-access email DNSBLs
dns_propagationCompare a record across 5 public resolvers worldwide
http_security_headersGrade a site's HSTS, CSP, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy and COOP
analyze_email_headersParse raw headers β†’ SPF/DKIM/DMARC verdicts + Received hop chain with delays

Every tool is read-only, declares an outputSchema and returns structuredContent (validated by the SDK) alongside human-readable Markdown (default) or JSON (response_format="json"), plus actionable error messages.

Install

Requires Node.js 20.18+. Nothing to clone β€” every MCP client can run it with npx.

Use it with Claude Code

Terminal
claude mcp add domain-security -- npx -y domain-security-mcp-server

Use it with Claude Desktop or Cursor

Add to claude_desktop_config.json (or ~/.cursor/mcp.json) β€” see examples/:

config.json
{
  "mcpServers": {
    "domain-security": {
      "command": "npx",
      "args": ["-y", "domain-security-mcp-server"]
    }
  }
}

On Windows use "command": "cmd" with "args": ["/c", "npx", "-y", "domain-security-mcp-server"]. Restart the client, then ask: "Audit the email security of stripe.com."

Self-host (HTTP transport)

The same server speaks stateless Streamable HTTP for remote or multi-client use. One endpoint serves both protocol eras and there is no session state, so no Mcp-Session-Id header is issued or expected.

bash
TRANSPORT=http npx -y domain-security-mcp-server
# POST JSON-RPC to http://127.0.0.1:3000/mcp   Β·   health at /healthz

It is safe by default: it binds to 127.0.0.1 and only accepts localhost Host and Origin headers, which blocks DNS-rebinding attacks from a web page. To expose it β€” for example behind Coolify or Traefik β€” opt in explicitly:

VariableDefaultPurpose
TRANSPORTstdiohttp to serve Streamable HTTP
PORT3000Listening port
HOST127.0.0.1Bind address; 0.0.0.0 to accept remote connections
ALLOWED_HOSTSβ€”Comma-separated hostnames the Host header may carry (e.g. mcp.example.com)
ALLOWED_ORIGINSβ€”Comma-separated origins allowed to call from a browser
MCP_AUTH_TOKENβ€”If set, every request needs Authorization: Bearer <token>

Binding to a non-loopback address without ALLOWED_HOSTS or MCP_AUTH_TOKEN works, but the server says so on stderr. With Docker (the image sets HOST=0.0.0.0):

Terminal
docker build -t domain-security-mcp .
docker run -p 3000:3000 -e ALLOWED_HOSTS=mcp.example.com -e MCP_AUTH_TOKEN=change-me domain-security-mcp

Security

The tools reach out to hosts that the caller names, so every outbound connection is screened against server-side request forgery:

  • Private, loopback, link-local (cloud metadata), shared, multicast and reserved addresses are refused in every spelling, including IPv4 embedded in IPv6 ([::ffff:169.254.169.254]).
  • The check happens at connect time, on the address the socket is actually about to use, so DNS rebinding and names only an internal resolver knows are refused too. Redirects are followed by hand and every hop is re-checked.
  • Response bodies, redirects, WHOIS referrals and every network call are capped and time-limited.

Found a problem? Please open a private security advisory.

Develop

Terminal
npm run dev      # tsx watch (stdio)
npm run inspect  # open the MCP Inspector against the built server
npm run build     # type-check + emit dist/
npm run typecheck # type-check only
npm test          # offline unit tests: SSRF guard, SPF/DMARC/DKIM scoring,
                  # header parsing, HTTP transport defaults
npm run smoke     # call all 19 tools on BOTH protocol eras and validate
                  # structuredContent against each tool's outputSchema

evals/ holds a 10-question LLM evaluation set (stable, verifiable) and instructions for running it β€” see evals/README.md.

How it works

Code
src/
β”œβ”€β”€ index.ts        # transport selection (stdio | http), v2 SDK entry points
β”œβ”€β”€ server.ts       # factory: registers every tool on one McpServer
β”œβ”€β”€ core/           # pure logic, no MCP coupling β€” reusable & testable
β”‚   β”œβ”€β”€ validate.ts # input validation and the address classifier
β”‚   β”œβ”€β”€ netguard.ts # connect-time SSRF guard, redirect-safe fetch, capped bodies
β”‚   β”œβ”€β”€ dns.ts      # public-resolver DNS + DoH client
β”‚   β”œβ”€β”€ net.ts      # MX, CAA, DNSBL and propagation checks
β”‚   β”œβ”€β”€ tls.ts      # certificate inspection and trust
β”‚   β”œβ”€β”€ whois.ts    # port-43 WHOIS with IANA/registrar referral
β”‚   β”œβ”€β”€ http.ts     # security-header grading
β”‚   β”œβ”€β”€ geoip.ts    # offline IP geolocation on DB-IP Lite (each file read on first use)
β”‚   β”œβ”€β”€ email-headers.ts  # raw header parsing and hop timing
β”‚   └── email-auth.ts  # SPF/DKIM/DMARC/MTA-STS/TLS-RPT/BIMI/DNSSEC + scoring
└── tools/          # thin MCP wrappers (Zod schemas, descriptions, formatting)

The core/ layer is deliberately free of any MCP types, so the exact same logic powers both this server and the web tools on ortamarco.me.

Credits

IP Geolocation by DB-IP. ip_geolocation uses the free DB-IP "IP to City Lite" database, licensed under CC BY 4.0 and installed as the @ip-location-db/dbip-city-mmdb package; the credit also appears in the tool's description and Markdown output. The database has no time zone, so time_zone is estimated from the coordinates with @photostructure/tz-lookup (CC0).

License

MIT Β© Marco Orta

Read the full README β†’View source on GitHub β†’

Related MCP Servers

View all in Communication View all alternatives
  • E
    E2a β€” email for AI agents

    Authenticated email gateway for AI agents β€” per-agent inboxes, HITL approval, SPF/DKIM verified.

    πŸ’¬ Communication1 views
    Compare vs E2a β€” email for AI agents β†’
  • M
    MAILTYPE β€” Email Domain Capability Intelligence

    Email-domain intelligence: MX capability, provider, disposable status, SPF, DMARC, and MTA-STS.

    πŸ’¬ Communication1 views
    Compare vs MAILTYPE β€” Email Domain Capability Intelligence β†’
  • M
    Mail7 Email Validation

    Verify email addresses, clean lists, and audit a domain SPF, DKIM, DMARC and MX setup.

    πŸ’¬ Communication1 views
    Compare vs Mail7 Email Validation β†’
  • T
    Telnyx

    Official TypeScript library for the Telnyx API

    πŸ’¬ Communication1 views
    Compare vs Telnyx β†’

Reviews

No reviews yet β€” be the first to share how this listing worked for you.

Frequently Asked Questions about Domain Security

We don't have a confirmed install command for Domain Security yet, so we don't publish a generated one β€” a guessed package name would point at the wrong package or none at all. Follow the project's own README or setup instructions (https://github.com/OrtaMarco/domain-security-mcp-server) for the current steps.

AllMCPs Directory Badge

Full Badge Customizer

Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.

Badge Style:
Live Dynamic SVG PreviewDomain Security AllMCPs Directory Badge
Markdown (GitHub README)
[![AllMCPs](https://allmcps.com/api/badge/domain-security?style=directory)](https://allmcps.com/mcp/domain-security)
HTML Embed
<a href="https://allmcps.com/mcp/domain-security"><img src="https://allmcps.com/api/badge/domain-security?style=directory" alt="Domain Security on AllMCPs" /></a>

Technical Specs & Signals

CategoryπŸ’¬Communication
More technical detailsExpand β–Ύ
Last updatedSep 28, 2026
Views0
Unique ViewsTotal visits recorded for this listing page on AllMCPs.
Installs0
Installs & Copy ActionsTotal times users copied install commands or configuration snippets for this server.
28Quality signal: Emerging Β· 28/100How this signal is calculated β–Ύ
Server availabilityNot measured

Not scored for repo-hosted servers β€” we can't reach the running server, only its GitHub page. Hosted MCP endpoints are health-checked live.

Verified ownership8/20
Documentation & tools12/30
Adoption & activity1/15
Community engagement0/10

A guidance signal from public completeness & health data β€” not a user rating. New listings start lower and rise as they add docs, get verified, and grow adoption. Signals we can't observe for a listing are skipped, not counted against it.

β˜… Featured
M

Moxie Docs MCP

MCP & Agent Skills for Automated Documentation, and codebase conventions + context

Explore Server β†’

Own this project?

This directory is pre-filled from public sources. Claim via GitHub README, site badge, or DNS TXT to unlock edit access and the Official badge and attach your website β€” proof is checked automatically, then reviewed by our team.

Free dofollow backlink: add your website and place the AllMCPs badge on it β€” no claim needed. We detect it automatically and keep it verified as long as the badge stays live.

Claim & get free dofollow

Share & Embed

Add our SVG badge (dark/light directory styles) or embeddable widget to your site.

Explore more

More in πŸ’¬ Communication β†’Best MCP servers for Slack & Communication β†’Alternatives to Domain Security β†’Install in Claude DesktopInstall in CursorInstall in VS CodeSetup guides for all 13 MCP clients