Domain Mail Check in Claude
Email DNS and domain check. The MCP server is https://mailcheck.openkrill.app/mcp. No key. The steps below are only for Claude. A call to check_email_auth was checked against that server on 2026-10-01.
What this server answers
Check how a domain is set up for email and who it is registered with, from public DNS and registry data.
Ask "is DMARC set up correctly for github.com?", "check SPF and DKIM for example.com", "which mail provider does acme.io use?" or "when does openai.com expire?".
The email check reads the domain's SPF record (following include and redirect, counting DNS lookups against the limit of 10), its DMARC policy, the MX records and, when you give a DKIM selector, whether the DKIM key is published. It returns a grade from A to F for protection against spoofing, the problems it found and a short list of fixes. The DNS records tool reads A, AAAA, MX, TXT, CAA and NS records with their TTLs, which also shows which mail provider a domain uses and which certificate authorities may issue for it. The registration tool reads the domain's registry record over RDAP: registrar, creation and expiry dates, status flags and name servers.
DNS answers come from Cloudflare's DNS over HTTPS service with Google Public DNS as a fallback, and registration data from the registry of the domain's ending, found through IANA's RDAP directory. Every answer names its source and the date it was read.
It does not send or test mail, read mailboxes, find subdomains, or return who owns a domain: registrant and contact details are never read or returned. It checks the exact domain you give, so a parent domain's SPF or DMARC record is not inherited. The domains you ask about are not stored; the only lasting record is a daily count of calls per tool.
What it can do
- Reads a domain's SPF record, counts its DNS lookups and flags weak or broken policies
- Reads the DMARC policy, percentage and report address
- Checks whether DKIM keys are published for up to 5 selectors you name
- Grades email spoofing protection from A to F with a short list of fixes
- Reads A, AAAA, MX, TXT, CAA and NS records with TTLs and names the mail provider from the MX records
- Shows registrar, creation and expiry dates, status flags and name servers from the registry over RDAP
- Never returns registrant or contact details; names its sources and dates
Tools
check_email_auth, Check email authentication. Use this when the user asks whether a domain's email is set up correctly, such as "is DMARC set up for github.com?" or "check SPF and DKIM for example.com". Pass the domain and, if known, up to 5 DKIM selector names. Returns SPF (policy, DNS lookup count, issues), DMARC (policy, percentage, report address, issues), DKIM per selector, the MX hosts and mail provider, a grade from A to F, a list of fixes, and the source and as_of date. It reads public DNS only: it does not send mail, test delivery or read mailboxes.check_dns_records, Look up DNS records. Use this when the user asks for a domain's DNS records, its mail provider or which certificate authorities may issue for it, such as "which mail provider does acme.io use?" or "show the MX and CAA records for github.com". Pass the domain and optionally up to 6 record types from A, AAAA, MX, TXT, CAA and NS (default: all). Returns each type's records with TTL, the mail provider named by the MX hosts, and the source and as_of date. It reads public DNS only; it cannot list subdomains or other record types.lookup_domain_registration, Look up domain registration. Use this when the user asks who a domain is registered with or when it expires, such as "when does openai.com expire and who is the registrar?". Pass the domain. Returns whether it is registered, the registrar, creation, update and expiry dates, days until expiry, registry status flags, name servers, and the source and as_of date. Registrant and contact details are never returned, so it cannot say who owns a domain.
Add Domain Mail Check in Claude
Claude connects to a remote MCP server as a custom connector. The connection is made from Anthropic's cloud, not from your laptop, so the server must be on the public internet. Domain Mail Check is. These steps were checked against Claude's custom-connector article (updated 2026-08-11) and the Claude Code MCP docs on 2026-10-01.
On a Pro or Max plan:
- Open Customize, then Connectors.
- Select the plus button, then Add custom connector.
- Paste
https://mailcheck.openkrill.app/mcp. Leave Advanced settings empty: this server does not need an OAuth client id or secret. - Select Add. The connector is yours. Anthropic has not reviewed it, and it is not a Directory listing.
- In a conversation, open the plus button, then Connectors, and enable Domain Mail Check. Ask: Is DMARC set up correctly for github.com?
On Team and Enterprise, an Owner adds the connector first at Organization settings, then Connectors, then Add, then Custom, then Web, and pastes the same URL. Members then connect it from Customize. A Free plan can add one custom connector.
In Claude Code, add it from the project directory:
claude mcp add --transport http mailcheck https://mailcheck.openkrill.app/mcp
That writes a local or user config. A JSON entry needs "type": "http" (or streamable-http) plus the url. An entry with a url and no type is skipped. Confirm with claude mcp get mailcheck. The tools you should see are check_email_auth, check_dns_records, lookup_domain_registration.
Enable the connector only in conversations that need it. Claude can call the tools while you work, including during research, so turn off any tool you do not want invoked. Domain Mail Check does not write to your accounts. It still receives the arguments of each call. Read the privacy page before you paste anything that is not public.
A call checked on 2026-10-01
github.com publishes SPF and DMARC. The grade is a reading of those records, not a security audit. The request below was posted to https://mailcheck.openkrill.app/mcp as tools/call. HTTP 200. Source: the Domain Mail Check server, read 2026-10-01.
{
"method": "tools/call",
"params": {
"name": "check_email_auth",
"arguments": {
"domain": "github.com"
}
}
}
- status. ok
- grade. A
- as of. 2026-10-01
- source. Cloudflare DNS over HTTPS (cloudflare-dns.com)
- notice. Checks the exact domain given: SPF and DMARC records of a parent domain are not inherited here. The grade rates protection against spoofing only; it does not read mail or test delivery, and DKIM needs a selector name fro
- dkim status. unknown
Repeat the call yourself if you need a newer reading. Cached answers expire. A rate limit is not a result: wait and try again. Nothing in the call is a ranking, a filing, or advice.