Agent Tools / MCP install guides / Domain Mail Check in ChatGPT

Domain Mail Check in ChatGPT

Email DNS and domain check. The MCP server is https://mailcheck.openkrill.app/mcp. No key. The steps below are only for ChatGPT. A call to check_email_auth was checked against that server on 2026-10-01.

What this server answers

Check how a domain is set up for email and who it is registered with, from public DNS and registry data.

Ask "is DMARC set up correctly for github.com?", "check SPF and DKIM for example.com", "which mail provider does acme.io use?" or "when does openai.com expire?".

The email check reads the domain's SPF record (following include and redirect, counting DNS lookups against the limit of 10), its DMARC policy, the MX records and, when you give a DKIM selector, whether the DKIM key is published. It returns a grade from A to F for protection against spoofing, the problems it found and a short list of fixes. The DNS records tool reads A, AAAA, MX, TXT, CAA and NS records with their TTLs, which also shows which mail provider a domain uses and which certificate authorities may issue for it. The registration tool reads the domain's registry record over RDAP: registrar, creation and expiry dates, status flags and name servers.

DNS answers come from Cloudflare's DNS over HTTPS service with Google Public DNS as a fallback, and registration data from the registry of the domain's ending, found through IANA's RDAP directory. Every answer names its source and the date it was read.

It does not send or test mail, read mailboxes, find subdomains, or return who owns a domain: registrant and contact details are never read or returned. It checks the exact domain you give, so a parent domain's SPF or DMARC record is not inherited. The domains you ask about are not stored; the only lasting record is a daily count of calls per tool.

What it can do

Tools

Add Domain Mail Check in ChatGPT

ChatGPT does not read a local config file. A custom MCP server is added in the product, and only after developer mode is on. These steps were checked against OpenAI's plugin connect guide and the ChatGPT MCP guide on 2026-10-01. Developer mode can be hidden by a workspace policy, so a Team or Enterprise admin may have to allow it first.

  1. Open ChatGPT settings, then Security and login, and turn on Developer mode.
  2. Open ChatGPT plugins and select the plus button.
  3. Enter a name such as "Domain Mail Check" and a one-line description of what you want it to answer.
  4. Under Connection, choose the public endpoint and paste https://mailcheck.openkrill.app/mcp. Include the /mcp path. Do not add a tunnel id: this server is already public.
  5. Create the connection and review the tools ChatGPT lists. You should see check_email_auth, check_dns_records, lookup_domain_registration. The feedback tools on the same server are optional and not required for the lookup.
  6. Start a new conversation, add the connection from the tools menu, and ask: Is DMARC set up correctly for github.com?

No API key and no OAuth client id are required. The server answers without a login. Calls are limited per network and per day, and a limit comes back as a tool error rather than a partial answer. If the tool list is stale after a server change, open the connection and select Refresh, then start a new conversation.

The ChatGPT desktop app, Codex CLI and IDE extension share a different config. In the desktop app, open Settings, then MCP servers, choose Add server, select Streamable HTTP, and paste the same URL. In ~/.codex/config.toml the equivalent is a table named mcp_servers.mailcheck with url = "https://mailcheck.openkrill.app/mcp". ChatGPT on the web does not read that file. A published directory listing is also a different path: this page is the developer-mode connection, not a claim that Domain Mail Check is already in the ChatGPT directory.

Treat the server as untrusted until you have read a few answers. A remote MCP server sees the arguments the model sends. Domain Mail Check is read-only and documents what it sends onward on the privacy page.

A call checked on 2026-10-01

github.com publishes SPF and DMARC. The grade is a reading of those records, not a security audit. The request below was posted to https://mailcheck.openkrill.app/mcp as tools/call. HTTP 200. Source: the Domain Mail Check server, read 2026-10-01.

{
  "method": "tools/call",
  "params": {
    "name": "check_email_auth",
    "arguments": {
      "domain": "github.com"
    }
  }
}

Repeat the call yourself if you need a newer reading. Cached answers expire. A rate limit is not a result: wait and try again. Nothing in the call is a ranking, a filing, or advice.

Same server, other clients

Roles that use Domain Mail Check

Terms used on this page

Source: plugin listing for mailcheck in this repository, and a live tools/call on 2026-10-01. As of 2026-10-01.