MCP connector for Claude
Domain Health: will the email land?
Domain Health looks at any domain the way a mail server, a browser and a registry do, and says in plain words what it found: whether its email will reach the inbox or can be forged, whether its certificate and headers keep visitors safe, and whether the domain itself is locked, renewed and resolving. Every finding has a severity, a one-sentence fix, and the RFC or provider rule behind it. No model judges anything.
Connector URL
https://mcp.modernmustardseed.com/domain-health
Streamable HTTP. No sign-in. Every tool is read-only.
Connect it
- In Claude, open Settings, then Connectors.
- Choose Add custom connector, paste
https://mcp.modernmustardseed.com/domain-health, and save. No account or key is needed. - Ask about any domain. Claude calls the tools when the question needs them.
In Claude Code: claude mcp add --transport http domain-health https://mcp.modernmustardseed.com/domain-health
Try these
- “Will email from stripe.com land in the inbox? Check SPF, DKIM and DMARC and tell me what to fix first.”
- “Run a full domain report on github.com: is the website safe, is the domain locked, and when does it expire?”
- “Check the SSL certificate on wrong.host.badssl.com and explain in plain words why browsers warn about it.”
The tools
check_email_auth
Check email authentication
Answers whether mail from the domain will reach the inbox and whether others can forge it. Reads MX, expands SPF through every include and counts lookups against the limit of 10 (and void lookups against 2), reads the DMARC policy, subdomain policy, alignment and report permissions, finds DKIM keys at about 40 common selectors plus any you name and measures each key, and checks BIMI, MTA-STS and TLS-RPT. Also says whether the domain meets the DNS part of the Google, Yahoo and Microsoft bulk sender rules.
Inputs: domain (required; a URL or email address also works); dkim_selectors (optional, up to 10); detail: "summary" or "full".
check_ssl
Check SSL certificate
Connects to port 443 and reports the certificate issuer, names covered, expiry and days left, key type and size, whether the chain is complete and trusted, whether it matches the name, which TLS versions from 1.0 to 1.3 the server accepts, and the CAA record that limits who may issue the next certificate. Checks www too when given a bare domain.
Inputs: domain (required); include_www (default true); detail.
check_security_headers
Check security headers
Loads the homepage the way a browser does and grades Strict-Transport-Security, Content-Security-Policy, clickjacking protection (X-Frame-Options or frame-ancestors), X-Content-Type-Options, Referrer-Policy and Permissions-Policy, plus the http to https redirect, cookie flags and software version disclosure.
Inputs: domain (required); detail.
check_domain_registration
Check domain registration
Reads the registry record over RDAP: registrar and its IANA id, abuse contact, created, expires and last changed dates, status locks such as clientTransferProhibited, danger states such as redemption period or hold, and nameservers. Compares the registry nameservers with the live zone and checks DNSSEC, including a broken DNSSEC chain.
Inputs: domain (required; subdomains are checked as their registered domain); detail.
full_domain_report
Full domain report
Runs all four checks at once and answers three questions in plain words: will its email land, is its website safe, and is the domain owned well. Returns a score and grade per area, the top fixes across every area, and each finding.
Inputs: domain (required); dkim_selectors (optional); detail.
How to read a result
- Status is pass, warn, fail, info or not_measured. A lookup that timed out or a registry without RDAP is not_measured, never a fail: we do not report a record as missing when we could not see it.
- Severity is critical, high, medium, low or info. Critical means mail is rejected, a browser shows a warning, or the domain can be lost now.
- Fix is one sentence on every warn and fail. Cite names the RFC, W3C, ICANN or mailbox provider document the rule comes from, with a link.
- Verdicts. Email is strong (SPF, DKIM and DMARC at quarantine or reject), ok (authenticated, DMARC not enforced), at_risk (one of the three missing or broken), failing (no working authentication) or no_mail (the domain neither sends nor receives mail). Website safety and ownership are strong, ok, at_risk or failing by their worst finding.
- Scores. Each area starts at 100 and loses 35 for a critical, 20 for a high, 10 for a medium and 4 for a low warn or fail; info costs nothing. Any critical failure caps the area at 59. A is 90 and up, B 80, C 70, D 60, F below.
- DKIM keys live under a selector name that DNS cannot list. We try 38 common selectors from the major providers; if none answers, the result says so and asks for the s= value from a DKIM-Signature header, rather than claiming DKIM is absent.
- Authentication that passes is necessary, not sufficient. Inbox placement also depends on sending reputation: volume, complaints and bounces. Many senders put marketing mail on a subdomain so it cannot drag the main domain down.
The rules we check against
SSL and TLS
Security headers
Registration and DNS
Data sources and licenses
| Source | What we read | Terms |
|---|---|---|
| Cloudflare 1.1.1.1 DNS over HTTPS | Every DNS question (MX, TXT, CAA, NS, DS, A and AAAA), asked over HTTPS. | Free public resolver; Cloudflare public DNS resolver privacy commitments. |
| Google Public DNS JSON API | The fallback resolver when Cloudflare does not answer. | Google Public DNS terms of service. |
| IANA RDAP bootstrap registry | Finds which registry RDAP server answers for each top-level domain. | Public IANA registry data, published for exactly this use (RFC 9224). |
| Registry and registrar RDAP servers | The public registration record of the domain you name, one request per check. | Public registration data that ICANN requires registries and registrars to publish over RDAP; each server returns its own terms of use in the response. |
| The domain you name | Its HTTPS certificate and TLS handshake, its homepage headers, its MTA-STS policy file and its BIMI logo, read as a browser or mail server would. | Public web content, read once per check. |
We never scrape WHOIS. Where a country-code registry publishes no RDAP service (for example .de), registration comes back not_measured with that reason, and every other check still runs.
Limits
- Results are saved for 5 minutes, so a repeat question is instant and a fix you just made shows up soon after. Cached results say cached: true with the time they were measured.
- Each domain can be checked fresh 6 times every 10 minutes. Across all users: 300 fresh checks an hour, 3,000 a day, and 120 calls a minute per tool on each server instance. Over a limit, the tool says so and names the time to try again.
- A full report usually takes 3 to 10 seconds and never more than 50. One report asks at most 160 DNS questions.
What it will not touch
DNS questions go only to Cloudflare and Google public resolvers, so a name can never steer a lookup into a private network. Every connection to a web or mail policy server goes through our SSRF guard: public addresses only, ports 80 and 443 only, every redirect checked again, every response capped in size and time. IP addresses, private names such as localhost or .internal, and reserved names are refused before anything is sent. Nothing is ever written, changed or signed in to.
Troubleshooting
- “No DKIM key was found at any of the common selectors”
- Open any message the domain sent, view the original, find the DKIM-Signature header and its s= value, and pass it as dkim_selectors.
- A finding says not_measured
- A DNS server, registry or website did not answer in time. Nothing was guessed. Try again in a minute.
- I fixed a record and the result has not changed
- Results are cached for 5 minutes and DNS changes can take as long as the record's TTL to spread. Check checked_at and ask again after a few minutes.
- Registration is not available
- Some country-code registries do not publish RDAP. We do not fall back to WHOIS scraping.
For reviewers
No account, key or setup is needed. Add the connector URL above, then call:
check_email_authwith domaingithub.com: SPF with its include tree at 10 of 10 lookups, DMARC at quarantine with sp=reject, and DKIM keys at several provider selectors. Adddetail: "full"to see every passing check.check_sslwith domainexpired.badssl.com: a critical expired certificate. Trywrong.host.badssl.comfor a name mismatch.check_security_headerswith domainexample.com: missing HSTS, CSP and framing protection, and no redirect to HTTPS.check_domain_registrationwith domaindnssec-failed.org: a broken DNSSEC chain reported as critical. Withspiegel.de, registration is not_measured because .de publishes no RDAP.full_domain_reportwith domainpaypal.com: all three answers, four area scores and the top fixes.- Refusals:
169.254.169.254,localhostandprinter.localeach return a specific error and nothing is fetched.
Support and security
Questions, problems and security reports go to sarah@modernmustardseed.com. A machine-readable contact is at /.well-known/security.txt. How we handle data is in the privacy policy.