Agent Tools / MCP install guides / Email SPF, DKIM, DMARC and Domain Expiry Check
Answer Guide

Email SPF, DKIM, DMARC and Domain Expiry Check

Domain Mail Check answers five short questions about how a domain handles email and when its registration ends, from public DNS and registry data. Last checked 2026-10-01.

check DMARC policy for a domain

check_email_auth reads the domain's DMARC policy, its percentage and its report address, and grades protection against spoofing from A to F.

The answer lists the problems found and a short list of fixes. It checks the exact domain you give, so a parent domain's record is not inherited. Tool: check_email_auth on https://mailcheck.openkrill.app/mcp.

SPF record DNS lookup limit

check_email_auth follows the include and redirect terms of an SPF record and counts the DNS lookups against the limit of 10.

It flags a weak or broken SPF policy in the same answer as the DMARC and MX results. Tool: check_email_auth on https://mailcheck.openkrill.app/mcp.

DKIM selector check

check_email_auth tells you whether a DKIM key is published for each selector you name, up to 5 selectors in one call.

A selector must be named, because DKIM keys cannot be listed from DNS. Tool: check_email_auth on https://mailcheck.openkrill.app/mcp.

which email provider does a domain use

check_dns_records names the mail provider from the domain's MX hosts.

It also reads A, AAAA, TXT, CAA and NS records with their TTLs, and the CAA records show which certificate authorities may issue for the domain. Tool: check_dns_records on https://mailcheck.openkrill.app/mcp.

when does a domain expire and who is the registrar

lookup_domain_registration returns the registrar, the creation, update and expiry dates and the days left until expiry.

The data comes from the registry over RDAP. Registrant and contact details are never returned, so the answer cannot say who owns the domain. Tool: lookup_domain_registration on https://mailcheck.openkrill.app/mcp.

Run it yourself

This page does not return live data. Call the tool on the server to get it. The server is Domain Mail Check at https://mailcheck.openkrill.app/mcp, with no key. Install steps: ChatGPT, Claude, Cursor, Pi. A call to check_email_auth was posted to the live server on 2026-10-01, and the install pages show it. The full tool list is in the MCP install guides directory.

Source: the Domain Mail Check plugin listing in this repository and a live tools/call on 2026-10-01. Last checked 2026-10-01. These answers are reviewed again every 1 to 3 months.