io.inboxguard/email-deliverability
REMOTE · MCP.INBOXGUARD.IO · SCANNED AUG 3
Scan and fix a domain's email deliverability (SPF, DKIM, DMARC, MTA-STS, BIMI, DNS blocklists).
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score →
Endpoint Security83
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation is enforced on tool calls, but the challenge carries no valid RFC 9728 metadata, so a client cannot discover where to get a token. See how to fix → View diagnostics → Fail
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- HSTS check failed: the Strict-Transport-Security header is absent. See how to fix → View diagnostics → Fail
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability85
- 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
- AI-judged instruction clarity (excellent).Pass
- Tool/resource definitions use about 3016 tokens (~94/item across 32 items; 28 tools + 4 resources), lean.Pass
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management27
- Stability observed for 8 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
Capabilities73
- Spec-recency check failed: implements MCP spec 2025-06-18; the latest is 2026-07-28. See how to fix → Fail
- Supports UI / widget rendering.Pass
Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.
remote · mcp.inboxguard.io
claude mcp add --transport http io-inboxguard-email-deliverability https://mcp.inboxguard.io/mcp
[mcp_servers.io-inboxguard-email-deliverability] url = "https://mcp.inboxguard.io/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"io-inboxguard-email-deliverability": {
"type": "remote",
"url": "https://mcp.inboxguard.io/mcp",
"enabled": true
}
}
} openclaw mcp add io-inboxguard-email-deliverability --url https://mcp.inboxguard.io/mcp --transport streamable-http
mcp_servers:
io-inboxguard-email-deliverability:
url: "https://mcp.inboxguard.io/mcp" {
"mcpServers": {
"io-inboxguard-email-deliverability": {
"type": "http",
"url": "https://mcp.inboxguard.io/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 3 Aug 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 23 to 27. That category is still filling its 30-day observation window: 7 days of observed history at the previous scan, 8 at this one. The score rises as the window fills, whether or not the server changes.
- 1 Aug 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 17 to 20. That category is still filling its 30-day observation window: 5 days of observed history at the previous scan, 6 at this one. The score rises as the window fills, whether or not the server changes.
- 31 Jul 26 +3
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 30 Jul 26 −1
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 29 Jul 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 7 to 10. That category is still filling its 30-day observation window: 2 days of observed history at the previous scan, 3 at this one. The score rises as the window fills, whether or not the server changes.
- 27 Jul 26 +1
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 26 Jul 26 72
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 3 Aug 2026 · Probed https://mcp.inboxguard.io/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=mcp.inboxguard.io | CN=Amazon RSA 2048 M01,O=Amazon,C=US | 11 Jun 2026 | 25 Dec 2026 | RSA 2048 | SHA256-RSA | be26600e48bfd4e83b6ecbea280fb8d |
| SANs: mcp.inboxguard.io | ||||||
| CN=Amazon RSA 2048 M01,O=Amazon,C=US (CA) | CN=Amazon Root CA 1,O=Amazon,C=US | 23 Aug 2022 | 23 Aug 2030 | RSA 2048 | SHA256-RSA | 77312380b9d6688a33b1ed9bf9ccda68e0e0f |
| CN=Amazon Root CA 1,O=Amazon,C=US (CA) | CN=Starfield Services Root Certificate Authority - G2,O=Starfield Technologies\, Inc.,L=Scottsdale,ST=Arizona,C=US | 25 May 2015 | 31 Dec 2037 | RSA 2048 | SHA256-RSA | 67f944a2a27cdf3fac2ae2b01f908eeb9c4c6 |
DNSSEC insecure
Validation of mcp.inboxguard.io. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| io. | present | 57355 | 8 | Verified |
| inboxguard.io. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication Challenged, unverified
The endpoint asked for a token, but we could not retrieve and validate the RFC 9728 metadata that tells a client how to obtain one.
| Result | Challenged, unverified |
|---|---|
| Enforced | On tool calls |
| HTTP status | 200 |
WWW-Authenticate challenge Bearer resource_metadata="https://api.inboxguard.io/.well-known/oauth-protected-resource"
Bearer resource_metadata="https://api.inboxguard.io/.well-known/oauth-protected-resource" Protected resource metadata
| Document | https://api.inboxguard.io/.well-known/oauth-protected-resource |
|---|---|
| Retrieved | Yes |
| Problem | metadata_resource_mismatch |
| Resource | https://api.inboxguard.io |
| Authorisation server | https://api.inboxguard.io |
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://mcp.inboxguard.io/mcp | Verified | 200 | |
| http (plaintext) | http://mcp.inboxguard.io/mcp | HTTPS enforced |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.
analyze_headers Analyze raw email headers ~187
Re-verify SPF, DKIM, DMARC, and ARC from a raw RFC 5322 email (full message or just the headers block). Returns InboxGuard's independent verdict (`ours`), the sender's own Authentication-Results (`theirs`), whether they `agree`, and parsed envelope/headers — useful for spotting forged or mismatched auth results. No account needed.
| Name | Type | Req | Description |
|---|---|---|---|
| helo | string | — | Optional: the SMTP HELO/EHLO domain. |
| mailFrom | string | — | Optional: the envelope MAIL FROM (return-path) address. |
| message | string | yes | The raw email — full RFC 5322 message, or at least the headers block (Received, Authentication-Results, DKIM-Signature, From, …). |
| senderIp | string | — | Optional: connecting IP to evaluate SPF against (overrides the IP parsed from Received headers). |
No output schema declared.
No examples provided.
apply_dns_fix Apply the DNS fix plan ~187
Apply a DNS fix plan to a tracked domain by publishing records at the connected registrar. DESTRUCTIVE: it creates/updates/deletes DNS records. Two-step by design — first call get_dns_fix_plan, then pass its `connectionId` and `ops` here verbatim. The server re-derives the diff from the latest scan and rejects any op that no longer matches, so an agent can never apply arbitrary records. Requires an owner/admin API key with write or full scope. Re-scan afterward to confirm the fix.
| Name | Type | Req | Description |
|---|---|---|---|
| connectionId | string | yes | The connectionId from get_dns_fix_plan. |
| domain | string | yes | Domain name tracked in the account, e.g. example.com. |
| ops | array | yes | The `ops` array from get_dns_fix_plan, passed verbatim. The server validates each op against a freshly recomputed diff before executing. |
No output schema declared.
No examples provided.
check_blocklists Check DNS blocklists ~64
Check a domain (apex + MX-host IPs) against supported DNS blocklists and return listings, targets checked, and issues (authoritative-side queries; no public-resolver false positives).
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain to check, e.g. example.com. |
No output schema declared.
No examples provided.
connect_inbox_placement Connect an inbox-placement provider ~104
Store the org's seed-list inbox-placement provider + API key (provider: 'mailreach' or 'glockapps'; GlockApps also needs projectId). Enables start_inbox_placement_test. Requires an owner/admin API key with write or full scope.
| Name | Type | Req | Description |
|---|---|---|---|
| apiKey | string | yes | The vendor API key. |
| projectId | string | — | GlockApps project id (required for provider=glockapps). |
| provider | string | yes | Inbox-placement vendor. |
No output schema declared.
No examples provided.
connect_snds Connect Microsoft SNDS ~129
Store this org's Microsoft SNDS (Smart Network Data Services) automated-data-access key so InboxGuard syncs per-IP Outlook/Hotmail reputation daily. Get the key from the SNDS Automated Data Access page (https://sendersupport.olc.protection.outlook.com/snds/). Requires an owner/admin API key with write or full scope. Data appears within ~24h of the first sync.
| Name | Type | Req | Description |
|---|---|---|---|
| key | string | yes | The SNDS access key from the SNDS Automated Data Access page. |
| label | string | — | Optional label, e.g. "prod sending IPs". |
No output schema declared.
No examples provided.
create_notification_channel Create a notification channel ~152
Create a channel that InboxGuard alerts are delivered to: webhook (HMAC-signed), Slack, Microsoft Teams, PagerDuty, SMS, or email. Returns the channel id, and for kind=webhook the `signing_secret` used to verify deliveries. Requires an owner/admin API key with write or full scope.
| Name | Type | Req | Description |
|---|---|---|---|
| displayName | string | — | Optional label for the channel. |
| kind | string | yes | Channel type. |
| severityFilter | array | — | Which alert severities to deliver (default ["critical","warn"]). |
| target | string | yes | Destination matching `kind`: the webhook/Slack/Teams URL, PagerDuty integration key, phone number (E.164), or email address. |
No output schema declared.
No examples provided.
create_share_link Create a public share link ~97
Create a read-only public share link for a tracked domain's latest report (anyone with the URL can view it; no account). Returns a `token` and the public `url` (https://inboxguard.io/r/<token>). Requires an owner/admin API key with write or full scope, on a plan that includes public reports.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain name tracked in the account, e.g. example.com. |
No output schema declared.
No examples provided.
get_deliverability_report Get a deliverability report ~114
Return a structured deliverability report for a tracked domain: the latest score + letter grade, each check's status (pass/warn/fail), the top issues to fix, blocklist count, and DMARC policy. Includes `pdfUrl` — the same auth-gated endpoint that returns a branded one-page PDF (send your bearer token). Use this to summarize a domain's posture or hand a client a report.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain name tracked in the account, e.g. example.com. |
No output schema declared.
No examples provided.
get_deliverability_score Get deliverability score ~45
Return the overall deliverability score and letter grade for a domain (runs a fresh scan).
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain to score, e.g. example.com. |
No output schema declared.
No examples provided.
get_dmarc_summary Get DMARC summary ~109
Summarize ingested DMARC aggregate (RUA) reports for a domain tracked in your InboxGuard account: report volume, pass rate, top sending sources, and the rua inbox to publish. The domain must already be added to the account, and the plan must include DMARC ingest.
| Name | Type | Req | Description |
|---|---|---|---|
| days | integer | — | Lookback window in days (default 30, max 90). |
| domain | string | yes | Domain name tracked in the account, e.g. example.com. |
No output schema declared.
No examples provided.
get_dns_fix_plan Preview the DNS fix plan ~135
Compute the exact DNS-record changes needed to fix a tracked domain's deliverability, based on its latest scan and the org's connected registrar (Cloudflare/Route 53/GoDaddy/Namecheap). Read-only — nothing changes. Returns the `ops` to pass verbatim to apply_dns_fix, plus `manualReview` items that need a human decision (SPF sender list, DKIM keys, BIMI logo). Requires the domain to be tracked, a scan to exist, and a registrar connection covering the zone.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain name tracked in the account, e.g. example.com. |
No output schema declared.
No examples provided.
get_domain Get domain detail ~91
Full detail for one tracked domain: the domain record, the latest scan with all per-check findings (spf, dmarc, dkim, ptr, mta_sts, tls_rpt, mx_tls, blocklist), recent score history, open/recent alerts, and Google Postmaster stats when connected.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain name as tracked in the account, e.g. example.com. |
No output schema declared.
No examples provided.
get_inbox_placement_status Get inbox-placement status ~44
Report whether a seed-list inbox-placement provider is connected for the org, which provider, and how many tests have run. Lists the supported providers when not connected.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_inbox_placement_test Get an inbox-placement test ~89
Poll a seed-list inbox-placement test by testId. Returns status (running/completed/failed) and, once measured, the Inbox/Spam/Missing counts and inbox-placement score (0–100). Call after sending your campaign to the seed addresses from start_inbox_placement_test.
| Name | Type | Req | Description |
|---|---|---|---|
| testId | string | yes | The testId returned by start_inbox_placement_test. |
No output schema declared.
No examples provided.
get_portfolio Get the domain portfolio rollup ~85
Org-wide deliverability rollup across every monitored domain: average score + overall grade, the grade distribution (how many domains are A/B/C/D/F/unscored), total open alerts, the domains needing attention (lowest score / open alerts first), and a per-client-group breakdown. Use this for an at-a-glance portfolio health summary across an agency or multi-domain account.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_scan_job Get batch-scan job ~69
Poll an async batch scan started with scan_domains_batch: returns status (queued/running/succeeded/partial/failed), completed count, and per-domain results (domain, ok, score, grade) as they finish.
| Name | Type | Req | Description |
|---|---|---|---|
| jobId | string | yes | The jobId returned by scan_domains_batch. |
No output schema declared.
No examples provided.
get_snds_ip_stats Get Microsoft SNDS per-IP stats ~72
Return the latest per-IP reputation from Microsoft SNDS for the org's sending IPs: filter result (GREEN/YELLOW/RED), complaint-rate band, spam-trap hits, message volume, and current block status. Requires SNDS to be connected (see connect_snds / get_snds_status).
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_snds_status Get Microsoft SNDS status ~62
Report whether Microsoft SNDS is connected for the org, the last sync time + status, how many sending IPs are tracked, and how many are currently blocked by Outlook/Hotmail. Use before get_snds_ip_stats to confirm the integration is live.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
list_alerts List alerts ~91
List the account's deliverability alerts (score drops, check failures, blocklist listings). Defaults to open alerts only.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | — | Max alerts to return (default 50). |
| resolved | string | — | 'false' = open alerts only (default), 'true' = resolved only, 'all' = both. |
| severity | string | — | Filter by severity (default 'all'). |
No output schema declared.
No examples provided.
list_domains List tracked domains ~28
List the account's tracked domains with latest scan score, last scan time, and open alert count.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
list_inbox_placement_tests List inbox-placement tests ~38
List recent seed-list inbox-placement tests for the org (most recent first) with their status and Inbox/Spam/Missing scores.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
list_registrar_connections List registrar connections ~73
List the registrar accounts (Cloudflare, Route 53, GoDaddy, Namecheap) connected to the org — provider, verification, last-used time — plus the supported providers. Use this to check whether the detect-and-fix loop (get_dns_fix_plan / apply_dns_fix) is available before attempting it.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
list_scans List scan history ~80
List recent scans (id, domain, run time, score) across all tracked domains, or for one domain when a name is given.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | — | Optional: restrict to one tracked domain by name, e.g. example.com. Omit for all domains. |
| limit | integer | — | Max scans to return (default 20). |
No output schema declared.
No examples provided.
remove_domain Remove a monitored domain ~84
Stop monitoring a domain and delete it (and its scan history) from the account. DESTRUCTIVE and not reversible. Requires an owner/admin API key with write or full scope. (To ADD a domain, run scan_domain with this API key — authenticated scans auto-track the domain.)
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain name tracked in the account, e.g. example.com. |
No output schema declared.
No examples provided.
resolve_alert Resolve alert ~79
Mark an alert resolved (or reopen it with resolved=false). Requires an API key with write/full scope. Resolving an already-resolved alert is a no-op.
| Name | Type | Req | Description |
|---|---|---|---|
| alertId | string | yes | Alert UUID, from list_alerts or get_domain. |
| resolved | boolean | — | true (default) marks the alert resolved; false reopens it. |
No output schema declared.
No examples provided.
scan_domain Scan domain deliverability ~118
Run a full email-deliverability scan (SPF, DKIM, DMARC, MTA-STS, TLS-RPT, MX TLS, BIMI, DNS blocklists) for a domain and return a 0-100 score with per-check findings. Runs at your plan tier (full blocklist set on paid plans) and saves the scan to the domain history in your account.
| Name | Type | Req | Description |
|---|---|---|---|
| dkimSelectors | array | — | Optional DKIM selectors to probe. |
| domain | string | yes | Domain to scan, e.g. example.com. |
No output schema declared.
No examples provided.
scan_domains_batch Batch-scan domains (async) ~107
Queue an asynchronous batch scan of up to 50 domains and get a jobId immediately (avoids the 30s per-call limit). Poll get_scan_job with the jobId until status is succeeded/partial/failed to read per-domain scores. Requires an API key with write or full scope. These scans are NOT added to monitoring or saved to history.
| Name | Type | Req | Description |
|---|---|---|---|
| domains | array | yes | 1-50 domains to scan, e.g. ["example.com","acme.com"]. |
No output schema declared.
No examples provided.
start_inbox_placement_test Start an inbox-placement test ~102
Start a seed-list inbox-placement test. Returns a testId, the seed addresses to mail your campaign to, and (if the provider requires it) a header to insert. After sending to the seeds, poll get_inbox_placement_test for the Inbox/Spam/Missing verdict. Requires inbox-placement to be connected and an owner/admin API key with write or full scope.
| Name | Type | Req | Description |
|---|---|---|---|
| subject | string | — | Optional subject line to associate with the test. |
No output schema declared.
No examples provided.