MCP connector for Claude

Domain Health: will the email land?

Domain Health looks at any domain the way a mail server, a browser and a registry do, and says in plain words what it found: whether its email will reach the inbox or can be forged, whether its certificate and headers keep visitors safe, and whether the domain itself is locked, renewed and resolving. Every finding has a severity, a one-sentence fix, and the RFC or provider rule behind it. No model judges anything.

Connector URL

https://mcp.modernmustardseed.com/domain-health

Streamable HTTP. No sign-in. Every tool is read-only.

Connect it

  1. In Claude, open Settings, then Connectors.
  2. Choose Add custom connector, paste https://mcp.modernmustardseed.com/domain-health, and save. No account or key is needed.
  3. Ask about any domain. Claude calls the tools when the question needs them.

In Claude Code: claude mcp add --transport http domain-health https://mcp.modernmustardseed.com/domain-health

Try these

The tools

check_email_auth

Check email authentication

Answers whether mail from the domain will reach the inbox and whether others can forge it. Reads MX, expands SPF through every include and counts lookups against the limit of 10 (and void lookups against 2), reads the DMARC policy, subdomain policy, alignment and report permissions, finds DKIM keys at about 40 common selectors plus any you name and measures each key, and checks BIMI, MTA-STS and TLS-RPT. Also says whether the domain meets the DNS part of the Google, Yahoo and Microsoft bulk sender rules.

Inputs: domain (required; a URL or email address also works); dkim_selectors (optional, up to 10); detail: "summary" or "full".

check_ssl

Check SSL certificate

Connects to port 443 and reports the certificate issuer, names covered, expiry and days left, key type and size, whether the chain is complete and trusted, whether it matches the name, which TLS versions from 1.0 to 1.3 the server accepts, and the CAA record that limits who may issue the next certificate. Checks www too when given a bare domain.

Inputs: domain (required); include_www (default true); detail.

check_security_headers

Check security headers

Loads the homepage the way a browser does and grades Strict-Transport-Security, Content-Security-Policy, clickjacking protection (X-Frame-Options or frame-ancestors), X-Content-Type-Options, Referrer-Policy and Permissions-Policy, plus the http to https redirect, cookie flags and software version disclosure.

Inputs: domain (required); detail.

check_domain_registration

Check domain registration

Reads the registry record over RDAP: registrar and its IANA id, abuse contact, created, expires and last changed dates, status locks such as clientTransferProhibited, danger states such as redemption period or hold, and nameservers. Compares the registry nameservers with the live zone and checks DNSSEC, including a broken DNSSEC chain.

Inputs: domain (required; subdomains are checked as their registered domain); detail.

full_domain_report

Full domain report

Runs all four checks at once and answers three questions in plain words: will its email land, is its website safe, and is the domain owned well. Returns a score and grade per area, the top fixes across every area, and each finding.

Inputs: domain (required); dkim_selectors (optional); detail.

How to read a result

The rules we check against

Email

SSL and TLS

Security headers

Registration and DNS

Data sources and licenses

SourceWhat we readTerms
Cloudflare 1.1.1.1 DNS over HTTPSEvery DNS question (MX, TXT, CAA, NS, DS, A and AAAA), asked over HTTPS.Free public resolver; Cloudflare public DNS resolver privacy commitments.
Google Public DNS JSON APIThe fallback resolver when Cloudflare does not answer.Google Public DNS terms of service.
IANA RDAP bootstrap registryFinds which registry RDAP server answers for each top-level domain.Public IANA registry data, published for exactly this use (RFC 9224).
Registry and registrar RDAP serversThe public registration record of the domain you name, one request per check.Public registration data that ICANN requires registries and registrars to publish over RDAP; each server returns its own terms of use in the response.
The domain you nameIts HTTPS certificate and TLS handshake, its homepage headers, its MTA-STS policy file and its BIMI logo, read as a browser or mail server would.Public web content, read once per check.

We never scrape WHOIS. Where a country-code registry publishes no RDAP service (for example .de), registration comes back not_measured with that reason, and every other check still runs.

Limits

What it will not touch

DNS questions go only to Cloudflare and Google public resolvers, so a name can never steer a lookup into a private network. Every connection to a web or mail policy server goes through our SSRF guard: public addresses only, ports 80 and 443 only, every redirect checked again, every response capped in size and time. IP addresses, private names such as localhost or .internal, and reserved names are refused before anything is sent. Nothing is ever written, changed or signed in to.

Troubleshooting

“No DKIM key was found at any of the common selectors”
Open any message the domain sent, view the original, find the DKIM-Signature header and its s= value, and pass it as dkim_selectors.
A finding says not_measured
A DNS server, registry or website did not answer in time. Nothing was guessed. Try again in a minute.
I fixed a record and the result has not changed
Results are cached for 5 minutes and DNS changes can take as long as the record's TTL to spread. Check checked_at and ask again after a few minutes.
Registration is not available
Some country-code registries do not publish RDAP. We do not fall back to WHOIS scraping.

For reviewers

No account, key or setup is needed. Add the connector URL above, then call:

  1. check_email_auth with domain github.com: SPF with its include tree at 10 of 10 lookups, DMARC at quarantine with sp=reject, and DKIM keys at several provider selectors. Add detail: "full" to see every passing check.
  2. check_ssl with domain expired.badssl.com: a critical expired certificate. Try wrong.host.badssl.com for a name mismatch.
  3. check_security_headers with domain example.com: missing HSTS, CSP and framing protection, and no redirect to HTTPS.
  4. check_domain_registration with domain dnssec-failed.org: a broken DNSSEC chain reported as critical. With spiegel.de, registration is not_measured because .de publishes no RDAP.
  5. full_domain_report with domain paypal.com: all three answers, four area scores and the top fixes.
  6. Refusals: 169.254.169.254, localhost and printer.local each return a specific error and nothing is fetched.

Support and security

Questions, problems and security reports go to sarah@modernmustardseed.com. A machine-readable contact is at /.well-known/security.txt. How we handle data is in the privacy policy.