Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, email [email protected] and we’ll put it right.

io.inboxguard/email-deliverability

REMOTE · MCP.INBOXGUARD.IO · SCANNED AUG 3

Scan and fix a domain's email deliverability (SPF, DKIM, DMARC, MTA-STS, BIMI, DNS blocklists).

+5 this week 78 Trust /100
Trust breakdown (6 categories)

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score →

Endpoint Security83
Transport & Reachability100
Schema Quality & AI Usability85
  • 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
  • AI-judged instruction clarity (excellent).Pass
  • Tool/resource definitions use about 3016 tokens (~94/item across 32 items; 28 tools + 4 resources), lean.Pass
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management27
  • Stability observed for 8 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 100% of tool parameters carry a description.Pass
Capabilities73
  • Spec-recency check failed: implements MCP spec 2025-06-18; the latest is 2026-07-28. See how to fix → Fail
  • Supports UI / widget rendering.Pass
Install

Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.

remote · mcp.inboxguard.io

# add to Claude Code
claude mcp add --transport http io-inboxguard-email-deliverability https://mcp.inboxguard.io/mcp
# ~/.codex/config.toml
[mcp_servers.io-inboxguard-email-deliverability]
url = "https://mcp.inboxguard.io/mcp"
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "io-inboxguard-email-deliverability": {
      "type": "remote",
      "url": "https://mcp.inboxguard.io/mcp",
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add io-inboxguard-email-deliverability --url https://mcp.inboxguard.io/mcp --transport streamable-http
# ~/.hermes/config.yaml
mcp_servers:
  io-inboxguard-email-deliverability:
    url: "https://mcp.inboxguard.io/mcp"
// mcp.json
{
  "mcpServers": {
    "io-inboxguard-email-deliverability": {
      "type": "http",
      "url": "https://mcp.inboxguard.io/mcp"
    }
  }
}

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 3 Aug 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 23 to 27. That category is still filling its 30-day observation window: 7 days of observed history at the previous scan, 8 at this one. The score rises as the window fills, whether or not the server changes.

  • 1 Aug 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 17 to 20. That category is still filling its 30-day observation window: 5 days of observed history at the previous scan, 6 at this one. The score rises as the window fills, whether or not the server changes.

  • 31 Jul 26 +3
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 30 Jul 26 −1
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 29 Jul 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 7 to 10. That category is still filling its 30-day observation window: 2 days of observed history at the previous scan, 3 at this one. The score rises as the window fills, whether or not the server changes.

  • 27 Jul 26 +1
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 26 Jul 26 72

    First indexed and scored.

Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 3 Aug 2026 · Probed https://mcp.inboxguard.io/mcp

TLS valid

Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .

Subject Issuer Valid from Valid until Key Signature Serial
CN=mcp.inboxguard.io CN=Amazon RSA 2048 M01,O=Amazon,C=US 11 Jun 2026 25 Dec 2026 RSA 2048 SHA256-RSA be26600e48bfd4e83b6ecbea280fb8d
SANs: mcp.inboxguard.io
CN=Amazon RSA 2048 M01,O=Amazon,C=US (CA) CN=Amazon Root CA 1,O=Amazon,C=US 23 Aug 2022 23 Aug 2030 RSA 2048 SHA256-RSA 77312380b9d6688a33b1ed9bf9ccda68e0e0f
CN=Amazon Root CA 1,O=Amazon,C=US (CA) CN=Starfield Services Root Certificate Authority - G2,O=Starfield Technologies\, Inc.,L=Scottsdale,ST=Arizona,C=US 25 May 2015 31 Dec 2037 RSA 2048 SHA256-RSA 67f944a2a27cdf3fac2ae2b01f908eeb9c4c6
DNSSEC insecure

Validation of mcp.inboxguard.io. Not signed

Zone DS Keys Algorithms Outcome
. trust_anchor 20326, 38696 8, 8 Verified
io. present 57355 8 Verified
inboxguard.io. absent Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation
Authentication Challenged, unverified

The endpoint asked for a token, but we could not retrieve and validate the RFC 9728 metadata that tells a client how to obtain one.

Result Challenged, unverified
Enforced On tool calls
HTTP status 200

WWW-Authenticate challenge Bearer resource_metadata="https://api.inboxguard.io/.well-known/oauth-protected-resource"

Bearer resource_metadata="https://api.inboxguard.io/.well-known/oauth-protected-resource"

Protected resource metadata

Document https://api.inboxguard.io/.well-known/oauth-protected-resource
Retrieved Yes
Problem metadata_resource_mismatch
Resource https://api.inboxguard.io
Authorisation server https://api.inboxguard.io
Transports 2 probes
Transport URL Outcome Status Location
streamable-http https://mcp.inboxguard.io/mcp Verified 200
http (plaintext) http://mcp.inboxguard.io/mcp HTTPS enforced
MCP tools — 28 exposed · ~2,635 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.

Tool Tokens
analyze_headers ~187

Re-verify SPF, DKIM, DMARC, and ARC from a raw RFC 5322 email (full message or just the headers block). Returns InboxGuard's independent verdict (`ours`), the sender's own Authentication-Results (`theirs`), whether they `agree`, and parsed envelope/headers — useful for spotting forged or mismatched auth results. No account needed.

NameTypeReqDescription
helostringOptional: the SMTP HELO/EHLO domain.
mailFromstringOptional: the envelope MAIL FROM (return-path) address.
messagestringyesThe raw email — full RFC 5322 message, or at least the headers block (Received, Authentication-Results, DKIM-Signature, From, …).
senderIpstringOptional: connecting IP to evaluate SPF against (overrides the IP parsed from Received headers).

No output schema declared.

No examples provided.

apply_dns_fix ~187

Apply a DNS fix plan to a tracked domain by publishing records at the connected registrar. DESTRUCTIVE: it creates/updates/deletes DNS records. Two-step by design — first call get_dns_fix_plan, then pass its `connectionId` and `ops` here verbatim. The server re-derives the diff from the latest scan and rejects any op that no longer matches, so an agent can never apply arbitrary records. Requires an owner/admin API key with write or full scope. Re-scan afterward to confirm the fix.

NameTypeReqDescription
connectionIdstringyesThe connectionId from get_dns_fix_plan.
domainstringyesDomain name tracked in the account, e.g. example.com.
opsarrayyesThe `ops` array from get_dns_fix_plan, passed verbatim. The server validates each op against a freshly recomputed diff before executing.

No output schema declared.

No examples provided.

check_blocklists ~64

Check a domain (apex + MX-host IPs) against supported DNS blocklists and return listings, targets checked, and issues (authoritative-side queries; no public-resolver false positives).

NameTypeReqDescription
domainstringyesDomain to check, e.g. example.com.

No output schema declared.

No examples provided.

connect_inbox_placement ~104

Store the org's seed-list inbox-placement provider + API key (provider: 'mailreach' or 'glockapps'; GlockApps also needs projectId). Enables start_inbox_placement_test. Requires an owner/admin API key with write or full scope.

NameTypeReqDescription
apiKeystringyesThe vendor API key.
projectIdstringGlockApps project id (required for provider=glockapps).
providerstringyesInbox-placement vendor.

No output schema declared.

No examples provided.

connect_snds ~129

Store this org's Microsoft SNDS (Smart Network Data Services) automated-data-access key so InboxGuard syncs per-IP Outlook/Hotmail reputation daily. Get the key from the SNDS Automated Data Access page (https://sendersupport.olc.protection.outlook.com/snds/). Requires an owner/admin API key with write or full scope. Data appears within ~24h of the first sync.

NameTypeReqDescription
keystringyesThe SNDS access key from the SNDS Automated Data Access page.
labelstringOptional label, e.g. "prod sending IPs".

No output schema declared.

No examples provided.

create_notification_channel ~152

Create a channel that InboxGuard alerts are delivered to: webhook (HMAC-signed), Slack, Microsoft Teams, PagerDuty, SMS, or email. Returns the channel id, and for kind=webhook the `signing_secret` used to verify deliveries. Requires an owner/admin API key with write or full scope.

NameTypeReqDescription
displayNamestringOptional label for the channel.
kindstringyesChannel type.
severityFilterarrayWhich alert severities to deliver (default ["critical","warn"]).
targetstringyesDestination matching `kind`: the webhook/Slack/Teams URL, PagerDuty integration key, phone number (E.164), or email address.

No output schema declared.

No examples provided.

create_share_link ~97

Create a read-only public share link for a tracked domain's latest report (anyone with the URL can view it; no account). Returns a `token` and the public `url` (https://inboxguard.io/r/<token>). Requires an owner/admin API key with write or full scope, on a plan that includes public reports.

NameTypeReqDescription
domainstringyesDomain name tracked in the account, e.g. example.com.

No output schema declared.

No examples provided.

get_deliverability_report ~114

Return a structured deliverability report for a tracked domain: the latest score + letter grade, each check's status (pass/warn/fail), the top issues to fix, blocklist count, and DMARC policy. Includes `pdfUrl` — the same auth-gated endpoint that returns a branded one-page PDF (send your bearer token). Use this to summarize a domain's posture or hand a client a report.

NameTypeReqDescription
domainstringyesDomain name tracked in the account, e.g. example.com.

No output schema declared.

No examples provided.

get_deliverability_score ~45

Return the overall deliverability score and letter grade for a domain (runs a fresh scan).

NameTypeReqDescription
domainstringyesDomain to score, e.g. example.com.

No output schema declared.

No examples provided.

get_dmarc_summary ~109

Summarize ingested DMARC aggregate (RUA) reports for a domain tracked in your InboxGuard account: report volume, pass rate, top sending sources, and the rua inbox to publish. The domain must already be added to the account, and the plan must include DMARC ingest.

NameTypeReqDescription
daysintegerLookback window in days (default 30, max 90).
domainstringyesDomain name tracked in the account, e.g. example.com.

No output schema declared.

No examples provided.

get_dns_fix_plan ~135

Compute the exact DNS-record changes needed to fix a tracked domain's deliverability, based on its latest scan and the org's connected registrar (Cloudflare/Route 53/GoDaddy/Namecheap). Read-only — nothing changes. Returns the `ops` to pass verbatim to apply_dns_fix, plus `manualReview` items that need a human decision (SPF sender list, DKIM keys, BIMI logo). Requires the domain to be tracked, a scan to exist, and a registrar connection covering the zone.

NameTypeReqDescription
domainstringyesDomain name tracked in the account, e.g. example.com.

No output schema declared.

No examples provided.

get_domain ~91

Full detail for one tracked domain: the domain record, the latest scan with all per-check findings (spf, dmarc, dkim, ptr, mta_sts, tls_rpt, mx_tls, blocklist), recent score history, open/recent alerts, and Google Postmaster stats when connected.

NameTypeReqDescription
domainstringyesDomain name as tracked in the account, e.g. example.com.

No output schema declared.

No examples provided.

get_inbox_placement_status ~44

Report whether a seed-list inbox-placement provider is connected for the org, which provider, and how many tests have run. Lists the supported providers when not connected.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

get_inbox_placement_test ~89

Poll a seed-list inbox-placement test by testId. Returns status (running/completed/failed) and, once measured, the Inbox/Spam/Missing counts and inbox-placement score (0–100). Call after sending your campaign to the seed addresses from start_inbox_placement_test.

NameTypeReqDescription
testIdstringyesThe testId returned by start_inbox_placement_test.

No output schema declared.

No examples provided.

get_portfolio ~85

Org-wide deliverability rollup across every monitored domain: average score + overall grade, the grade distribution (how many domains are A/B/C/D/F/unscored), total open alerts, the domains needing attention (lowest score / open alerts first), and a per-client-group breakdown. Use this for an at-a-glance portfolio health summary across an agency or multi-domain account.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

get_scan_job ~69

Poll an async batch scan started with scan_domains_batch: returns status (queued/running/succeeded/partial/failed), completed count, and per-domain results (domain, ok, score, grade) as they finish.

NameTypeReqDescription
jobIdstringyesThe jobId returned by scan_domains_batch.

No output schema declared.

No examples provided.

get_snds_ip_stats ~72

Return the latest per-IP reputation from Microsoft SNDS for the org's sending IPs: filter result (GREEN/YELLOW/RED), complaint-rate band, spam-trap hits, message volume, and current block status. Requires SNDS to be connected (see connect_snds / get_snds_status).

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

get_snds_status ~62

Report whether Microsoft SNDS is connected for the org, the last sync time + status, how many sending IPs are tracked, and how many are currently blocked by Outlook/Hotmail. Use before get_snds_ip_stats to confirm the integration is live.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

list_alerts ~91

List the account's deliverability alerts (score drops, check failures, blocklist listings). Defaults to open alerts only.

NameTypeReqDescription
limitintegerMax alerts to return (default 50).
resolvedstring'false' = open alerts only (default), 'true' = resolved only, 'all' = both.
severitystringFilter by severity (default 'all').

No output schema declared.

No examples provided.

list_domains ~28

List the account's tracked domains with latest scan score, last scan time, and open alert count.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

list_inbox_placement_tests ~38

List recent seed-list inbox-placement tests for the org (most recent first) with their status and Inbox/Spam/Missing scores.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

list_registrar_connections ~73

List the registrar accounts (Cloudflare, Route 53, GoDaddy, Namecheap) connected to the org — provider, verification, last-used time — plus the supported providers. Use this to check whether the detect-and-fix loop (get_dns_fix_plan / apply_dns_fix) is available before attempting it.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

list_scans ~80

List recent scans (id, domain, run time, score) across all tracked domains, or for one domain when a name is given.

NameTypeReqDescription
domainstringOptional: restrict to one tracked domain by name, e.g. example.com. Omit for all domains.
limitintegerMax scans to return (default 20).

No output schema declared.

No examples provided.

remove_domain ~84

Stop monitoring a domain and delete it (and its scan history) from the account. DESTRUCTIVE and not reversible. Requires an owner/admin API key with write or full scope. (To ADD a domain, run scan_domain with this API key — authenticated scans auto-track the domain.)

NameTypeReqDescription
domainstringyesDomain name tracked in the account, e.g. example.com.

No output schema declared.

No examples provided.

resolve_alert ~79

Mark an alert resolved (or reopen it with resolved=false). Requires an API key with write/full scope. Resolving an already-resolved alert is a no-op.

NameTypeReqDescription
alertIdstringyesAlert UUID, from list_alerts or get_domain.
resolvedbooleantrue (default) marks the alert resolved; false reopens it.

No output schema declared.

No examples provided.

scan_domain ~118

Run a full email-deliverability scan (SPF, DKIM, DMARC, MTA-STS, TLS-RPT, MX TLS, BIMI, DNS blocklists) for a domain and return a 0-100 score with per-check findings. Runs at your plan tier (full blocklist set on paid plans) and saves the scan to the domain history in your account.

NameTypeReqDescription
dkimSelectorsarrayOptional DKIM selectors to probe.
domainstringyesDomain to scan, e.g. example.com.

No output schema declared.

No examples provided.

scan_domains_batch ~107

Queue an asynchronous batch scan of up to 50 domains and get a jobId immediately (avoids the 30s per-call limit). Poll get_scan_job with the jobId until status is succeeded/partial/failed to read per-domain scores. Requires an API key with write or full scope. These scans are NOT added to monitoring or saved to history.

NameTypeReqDescription
domainsarrayyes1-50 domains to scan, e.g. ["example.com","acme.com"].

No output schema declared.

No examples provided.

start_inbox_placement_test ~102

Start a seed-list inbox-placement test. Returns a testId, the seed addresses to mail your campaign to, and (if the provider requires it) a header to insert. After sending to the seeds, poll get_inbox_placement_test for the Inbox/Spam/Missing verdict. Requires inbox-placement to be connected and an owner/admin API key with write or full scope.

NameTypeReqDescription
subjectstringOptional subject line to associate with the test.

No output schema declared.

No examples provided.