Verifly
REMOTE · VERIFLY.EMAIL · SCANNED AUG 3
Email verification for AI agents — verify, clean & validate emails; self-onboard + crypto pay
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score →
Endpoint Security57
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation not fully verified: no authorisation is required to call this server, and 17 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe. See how to fix → View diagnostics → Unverified
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- HSTS check failed: the Strict-Transport-Security header is absent. See how to fix → View diagnostics → Fail
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability81
- AI-judged instruction clarity (excellent).Pass
- Tool/resource definitions use about 1575 tokens (~92/item across 17 items; 17 tools + 0 resources), lean.Pass
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management27
- Stability observed for 8 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.
remote · verifly.email
claude mcp add --transport http email-verifly-verifly https://verifly.email/mcp
[mcp_servers.email-verifly-verifly] url = "https://verifly.email/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"email-verifly-verifly": {
"type": "remote",
"url": "https://verifly.email/mcp",
"enabled": true
}
}
} openclaw mcp add email-verifly-verifly --url https://verifly.email/mcp --transport streamable-http
mcp_servers:
email-verifly-verifly:
url: "https://verifly.email/mcp" {
"mcpServers": {
"email-verifly-verifly": {
"type": "http",
"url": "https://verifly.email/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 3 Aug 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 23 to 27. That category is still filling its 30-day observation window: 7 days of observed history at the previous scan, 8 at this one. The score rises as the window fills, whether or not the server changes.
- 31 Jul 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 30 Jul 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 29 Jul 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 7 to 10. That category is still filling its 30-day observation window: 2 days of observed history at the previous scan, 3 at this one. The score rises as the window fills, whether or not the server changes.
- 28 Jul 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 3 to 7. That category is still filling its 30-day observation window: 1 days of observed history at the previous scan, 2 at this one. The score rises as the window fills, whether or not the server changes.
- 27 Jul 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 26 Jul 26 65
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 3 Aug 2026 · Probed https://verifly.email/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_256_GCM_SHA384 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=verifly.email | CN=YE2,O=Let's Encrypt,C=US | 26 Jun 2026 | 24 Sept 2026 | ECDSA 256 | ECDSA-SHA384 | 57cd7fecead359ec5982a410c6eb9dc822e |
| SANs: verifly.email, veriflyemail.com, www.verifly.email, www.veriflyemail.com | ||||||
| CN=YE2,O=Let's Encrypt,C=US (CA) | CN=Root YE,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | ECDSA 384 | ECDSA-SHA384 | 4df3b15dd6c0784c507cd37b58e6f115 |
| CN=Root YE,O=ISRG,C=US (CA) | CN=ISRG Root X2,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | ECDSA-SHA384 | 872165fc34b6e5fba8add5b3705fb53a |
| CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | SHA256-RSA | 6c8f1dc727c7117f7baf853ac980f9cd |
DNSSEC insecure
Validation of verifly.email. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| email. | present | 62422 | 8 | Verified |
| verifly.email. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://verifly.email/mcp | Verified | 200 | |
| http (plaintext) | http://verifly.email/mcp | HTTPS enforced | 301 | https://verifly.email/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.
buy_credits Buy credits (returns a payment link or crypto invoice) ~246
Start a purchase of a credit package and return a way to pay. This does NOT complete a payment by itself — it returns a payment link / address: • method 'stripe' → returns a checkout_url. Paying by card requires a HUMAN to open that link and enter card details; an agent cannot finish a card payment on its own. • method 'crypto' → returns a Plisio invoice with a checkout_url AND, when you pass a `currency` (BTC, ETH, LTC, USDT, USDC), a RAW wallet `address` + `amount`. An autonomous agent CAN pay this from a crypto wallet with no browser/human, then credits are added automatically once the payment confirms. Prefer crypto for fully autonomous top-ups. Get a package id from get_packages first.
| Name | Type | Req | Description |
|---|---|---|---|
| currency | string | — | For method 'crypto': the coin to pay in; returns a raw wallet address an agent can pay autonomously. |
| method | string | — | Payment method. 'stripe' = card link (needs a human), 'crypto' = wallet-payable invoice. Default 'stripe'. |
| package_id | string | yes | The package id to buy (from get_packages). |
No output schema declared.
No examples provided.
check_domain_health Check email-domain health (MX / SPF / DMARC) ~66
Check the DNS and deliverability health of an email domain: MX records, SPF, DMARC, and an overall health score. Useful for diagnosing why a domain bounces or for validating a sending domain.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain to check, e.g. example.com |
No output schema declared.
No examples provided.
clean_email_list Clean an email list ~104
Clean a list of email addresses before an import or campaign: dedupes, removes invalid syntax, and (optionally) strips disposable and role accounts. Returns the cleaned list plus a summary of what was removed.
| Name | Type | Req | Description |
|---|---|---|---|
| emails | array | yes | Email addresses to clean. |
| exclude_role_accounts | boolean | — | Remove role accounts (info@, support@, ...). Default false. |
| remove_disposable | boolean | — | Remove disposable/throwaway addresses. Default true. |
No output schema declared.
No examples provided.
extract_emails Extract email addresses from text ~84
Extract all email addresses found in a block of free-form text (notes, pasted documents, signatures). Optionally deduplicates and lowercases the results.
| Name | Type | Req | Description |
|---|---|---|---|
| deduplicate | boolean | — | Remove duplicate addresses. Default true. |
| lowercase | boolean | — | Lowercase all extracted addresses. Default true. |
| text | string | yes | Free-form text to scan for email addresses. |
No output schema declared.
No examples provided.
get_account Get account information ~45
Return the account profile for the current API key: email, name, company, timezone, remaining credits, total credits used, number of API keys, and plan. Costs no credits.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_credits Get remaining Verifly credits ~33
Return the API key's remaining verification credits and recent usage (today / this month) and plan. Costs no credits.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_job_results Get the results of a completed bulk job ~76
Fetch the full per-address results of a completed bulk verification job by job_id (each email's verdict, recommendation, and reason) plus the valid/invalid/risky summary and credits used. The job must be 'completed' — check get_job_status first.
| Name | Type | Req | Description |
|---|---|---|---|
| job_id | string | yes | The job_id returned by submit_bulk. |
No output schema declared.
No examples provided.
get_job_status Get the status of a bulk verification job ~74
Fetch the current status and progress of a bulk verification job by its job_id (status, percent progress, processed count, and a valid/invalid/risky summary). Poll this after submit_bulk until status is 'completed', then call get_job_results.
| Name | Type | Req | Description |
|---|---|---|---|
| job_id | string | yes | The job_id returned by submit_bulk. |
No output schema declared.
No examples provided.
get_packages List buyable credit packages ~45
List the credit packages available for purchase (id, name, credit amount, price in USD, and price per 1k credits). Use the returned package id with buy_credits.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_started How to start using Verifly (no key needed) ~65
Call this FIRST if you have no Verifly API key. Returns how Verifly works and how to get access with no human: pay-as-you-go email verification API, 100 free credits on self-registration, no monthly fee. No API key required to call this tool.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_usage Get detailed usage statistics ~85
Return detailed usage statistics for the account over a period (day, week, or month): total credits used, emails processed, request counts broken down by endpoint and source, a daily breakdown, and recent activity.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | — | Max recent log entries to include (default 100, max 1000). |
| period | string | — | Reporting period. Default 'month'. |
No output schema declared.
No examples provided.
list_jobs List bulk verification jobs ~93
List the account's bulk verification jobs, most recent first, with their status, progress, and summary. Optionally filter by status and paginate. Use this to find past jobs and their job_ids.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | — | Max jobs to return (1-100, default 50). |
| offset | integer | — | Pagination offset (default 0). |
| status | string | — | Only return jobs in this status. |
No output schema declared.
No examples provided.
register_account Self-register a new Verifly account + API key ~144
Programmatically create a brand-new Verifly account — this is how an agent self-onboards with no human in the loop. Requires only an email and a password (min 8 chars; disposable email domains are rejected). The new account starts with free credits. The response includes the new account id/email and a freshly generated `api_key.key` that is shown ONCE — capture and store it immediately, it cannot be retrieved again. Subsequent tool calls can then use that key as the bearer token.
| Name | Type | Req | Description |
|---|---|---|---|
| string | yes | Email for the new account (not a disposable domain). | |
| password | string | yes | Password for the new account (minimum 8 characters). |
No output schema declared.
No examples provided.
submit_bulk Submit an async bulk verification job ~139
Submit a list of email addresses as an asynchronous bulk verification job — the right tool for large lists. Returns immediately with a job_id, status, and the check_status_url / results_url to poll. Small lists may complete inline (status 'completed'); larger ones return status 'pending' — poll get_job_status until it is 'completed', then call get_job_results. Optionally register a webhook_url (public HTTPS) to be notified when the job finishes.
| Name | Type | Req | Description |
|---|---|---|---|
| emails | array | yes | Email addresses to verify in this job (deduped server-side). |
| webhook_url | string | — | Optional public HTTPS URL to POST a job.completed notification to. |
No output schema declared.
No examples provided.
verify_batch Verify a batch of email addresses ~105
Synchronously verify a list of email addresses (best for up to a few hundred). Returns a per-address verdict for each email. For very large lists use the bulk async endpoint instead.
| Name | Type | Req | Description |
|---|---|---|---|
| emails | array | yes | Array of email addresses to verify. |
| exclude_public_domains | boolean | — | Flag/exclude public domains (gmail.com, ...). Default false. |
| exclude_role_accounts | boolean | — | Flag/exclude role accounts (info@, sales@, ...). Default false. |
No output schema declared.
No examples provided.
verify_email Verify a single email address ~78
Verify one email address in real time. Returns a deliverability verdict (valid / invalid / risky / unknown), the reason, detailed flags (disposable, role account, catch-all, MX, SMTP), a send/reject recommendation, and credit usage.
| Name | Type | Req | Description |
|---|---|---|---|
| string | yes | The email address to verify, e.g. [email protected] |
No output schema declared.
No examples provided.
verify_email_demo Verify an email — free demo (no key required) ~93
Verify one email address with NO account or API key, so you can evaluate Verifly before registering. Rate-limited per IP (a few checks). Returns the same deliverability verdict and flags as the full API. For real volume, call register_account for a key + 100 free credits, then use verify_email.
| Name | Type | Req | Description |
|---|---|---|---|
| string | yes | The email address to verify, e.g. [email protected] |
No output schema declared.
No examples provided.