Agent Tools / MCP install guides / Domain Mail Check in Cursor

Domain Mail Check in Cursor

Email DNS and domain check. The MCP server is https://mailcheck.openkrill.app/mcp. No key. The steps below are only for Cursor. A call to check_email_auth was checked against that server on 2026-10-01.

What this server answers

Check how a domain is set up for email and who it is registered with, from public DNS and registry data.

Ask "is DMARC set up correctly for github.com?", "check SPF and DKIM for example.com", "which mail provider does acme.io use?" or "when does openai.com expire?".

The email check reads the domain's SPF record (following include and redirect, counting DNS lookups against the limit of 10), its DMARC policy, the MX records and, when you give a DKIM selector, whether the DKIM key is published. It returns a grade from A to F for protection against spoofing, the problems it found and a short list of fixes. The DNS records tool reads A, AAAA, MX, TXT, CAA and NS records with their TTLs, which also shows which mail provider a domain uses and which certificate authorities may issue for it. The registration tool reads the domain's registry record over RDAP: registrar, creation and expiry dates, status flags and name servers.

DNS answers come from Cloudflare's DNS over HTTPS service with Google Public DNS as a fallback, and registration data from the registry of the domain's ending, found through IANA's RDAP directory. Every answer names its source and the date it was read.

It does not send or test mail, read mailboxes, find subdomains, or return who owns a domain: registrant and contact details are never read or returned. It checks the exact domain you give, so a parent domain's SPF or DMARC record is not inherited. The domains you ask about are not stored; the only lasting record is a daily count of calls per tool.

What it can do

Tools

Add Domain Mail Check in Cursor

Cursor reads MCP servers from mcp.json. A project file at .cursor/mcp.json applies to that project. A user file at ~/.cursor/mcp.json applies everywhere. These steps were checked against the Cursor MCP docs on 2026-10-01. Streamable HTTP is the transport: a url, not a shell command.

Create or edit the file so it contains this server. Merge it with servers you already have. Do not replace the whole file if other servers are listed.

{
  "mcpServers": {
    "mailcheck": {
      "url": "https://mailcheck.openkrill.app/mcp"
    }
  }
}

No headers and no auth block. Those are for servers that require a token or a pre-registered OAuth client. Domain Mail Check answers without either. Saving the file is the install. Open Cursor Settings, then MCP, and confirm Domain Mail Check is enabled. If it stays disconnected, reload the window. You should see check_email_auth, check_dns_records, lookup_domain_registration.

In Agent chat, ask: Is DMARC set up correctly for github.com? Cursor calls the tool over streamable HTTP and shows the arguments before it runs them, depending on your run mode. Approve the call the first time and read the result. The server is public and read-only. It does not see your repository unless the model puts repository text into the arguments, so do not paste secrets into the question.

A one-click Marketplace install does not exist for this server. The JSON above is the whole setup. Team admins can distribute the same url through a team marketplace, but that is an admin step, not something this page can do for you. OAuth redirect URLs in the Cursor docs matter only for servers that require sign-in. Skip them here.

A call checked on 2026-10-01

github.com publishes SPF and DMARC. The grade is a reading of those records, not a security audit. The request below was posted to https://mailcheck.openkrill.app/mcp as tools/call. HTTP 200. Source: the Domain Mail Check server, read 2026-10-01.

{
  "method": "tools/call",
  "params": {
    "name": "check_email_auth",
    "arguments": {
      "domain": "github.com"
    }
  }
}

Repeat the call yourself if you need a newer reading. Cached answers expire. A rate limit is not a result: wait and try again. Nothing in the call is a ranking, a filing, or advice.

Same server, other clients

Roles that use Domain Mail Check

Terms used on this page

Source: plugin listing for mailcheck in this repository, and a live tools/call on 2026-10-01. As of 2026-10-01.