Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

io.inboxguard/email-deliverability

REMOTE · MCP.INBOXGUARD.IO · SCANNED SEP 20

Scan and fix a domain's email deliverability (SPF, DKIM, DMARC, MTA-STS, BIMI, DNS blocklists).

0 this week 90 Trust /100
Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →

Endpoint Security83
Transport & Reachability100
Schema Quality & AI Usability89
  • 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
  • AI-judged instruction clarity (excellent).Pass
  • Tool/resource definitions use about 3215 tokens (~100/item across 32 items; 28 tools + 4 resources), lean.Pass
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management100
  • No destabilizing schema changes in the last 30 days.Pass
Tool Coverage100
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 100% of tool parameters carry a description.Pass
Tool Safety100
  • No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
  • All 1 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
  • An AI judge read all 30 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities73
  • Spec-recency check failed: implements MCP spec 2025-06-18; the latest is 2026-07-28. See how to fix → Fail
  • Supports UI / widget rendering.Pass
Install

How do I install the io.inboxguard/email-deliverability MCP server?

io.inboxguard/email-deliverability is a hosted endpoint at https://mcp.inboxguard.io/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

remote · mcp.inboxguard.io

# add to Claude Code
claude mcp add --transport http io-inboxguard-email-deliverability 'https://mcp.inboxguard.io/mcp'
// .cursor/mcp.json
{
  "mcpServers": {
    "io-inboxguard-email-deliverability": {
      "url": "https://mcp.inboxguard.io/mcp"
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "io-inboxguard-email-deliverability": {
      "type": "http",
      "url": "https://mcp.inboxguard.io/mcp"
    }
  }
}
# ~/.codex/config.toml
[mcp_servers.io-inboxguard-email-deliverability]
url = "https://mcp.inboxguard.io/mcp"
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "io-inboxguard-email-deliverability": {
      "type": "remote",
      "url": "https://mcp.inboxguard.io/mcp",
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add io-inboxguard-email-deliverability --url 'https://mcp.inboxguard.io/mcp' --transport streamable-http
# ~/.hermes/config.yaml
mcp_servers:
  io-inboxguard-email-deliverability:
    url: "https://mcp.inboxguard.io/mcp"
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "io-inboxguard-email-deliverability": {
      "Transport": "http",
      "Url": "https://mcp.inboxguard.io/mcp"
    }
  }
}
# add to Vellum
assistant mcp add io-inboxguard-email-deliverability -t streamable-http -u 'https://mcp.inboxguard.io/mcp'
// mcp.json
{
  "mcpServers": {
    "io-inboxguard-email-deliverability": {
      "type": "http",
      "url": "https://mcp.inboxguard.io/mcp"
    }
  }
}

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 26 Aug 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 25 Aug 26 +1
    • Stability: 0.97 → pass security
  • 23 Aug 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 90 to 93. That category is still filling its 30-day observation window: 27 days of observed history at the previous scan, 28 at this one. The score rises as the window fills, whether or not the server changes.

  • 11 Aug 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 6 Aug 26 0
    • Tool “get_deliverability_report” rewrote its description, which is the text the model reads security
    • Tool “scan_domain” rewrote its description, which is the text the model reads security
  • 31 Jul 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 30 Jul 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 27 Jul 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 20 Sept 2026 · Probed https://mcp.inboxguard.io/mcp

TLS valid

Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .

Subject Issuer Valid from Valid until Key Signature Serial
CN=mcp.inboxguard.io CN=Amazon RSA 2048 M01,O=Amazon,C=US 11 Jun 2026 25 Dec 2026 RSA 2048 SHA256-RSA be26600e48bfd4e83b6ecbea280fb8d
SANs: mcp.inboxguard.io
CN=Amazon RSA 2048 M01,O=Amazon,C=US (CA) CN=Amazon Root CA 1,O=Amazon,C=US 23 Aug 2022 23 Aug 2030 RSA 2048 SHA256-RSA 77312380b9d6688a33b1ed9bf9ccda68e0e0f
CN=Amazon Root CA 1,O=Amazon,C=US (CA) CN=Starfield Services Root Certificate Authority - G2,O=Starfield Technologies\, Inc.,L=Scottsdale,ST=Arizona,C=US 25 May 2015 31 Dec 2037 RSA 2048 SHA256-RSA 67f944a2a27cdf3fac2ae2b01f908eeb9c4c6

Background: What to check on a remote MCP endpoint →

DNSSEC insecure

Validation of mcp.inboxguard.io. Not signed

Zone DS Keys Algorithms Outcome
. trust_anchor 20326, 38696 8, 8 Verified
io. present 57355 8 Verified
inboxguard.io. absent Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation
Authentication Challenged, unverified

The endpoint asked for a token, but we could not retrieve and validate the RFC 9728 metadata that tells a client how to obtain one.

Result Challenged, unverified
Enforced On tool calls
HTTP status 200

WWW-Authenticate challenge Bearer resource_metadata="https://api.inboxguard.io/.well-known/oauth-protected-resource"

Bearer resource_metadata="https://api.inboxguard.io/.well-known/oauth-protected-resource"

Protected resource metadata

Document https://api.inboxguard.io/.well-known/oauth-protected-resource
Retrieved Yes
Problem metadata_resource_mismatch
Resource https://api.inboxguard.io
Authorisation server https://api.inboxguard.io

Background: How OAuth 2.1 works in the 2026 MCP spec →

Transports 2 probes
Transport URL Outcome Status Location
streamable-http https://mcp.inboxguard.io/mcp Verified 200
http (plaintext) http://mcp.inboxguard.io/mcp HTTPS enforced
MCP tools · 28 exposed · ~2,804 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
analyze_headers ~187

Re-verify SPF, DKIM, DMARC, and ARC from a raw RFC 5322 email (full message or just the headers block). Returns InboxGuard's independent verdict (`ours`), the sender's own Authentication-Results (`theirs`), whether they `agree`, and parsed envelope/headers — useful for spotting forged or mismatched auth results. No account needed.

NameTypeReqDescription
helostringOptional: the SMTP HELO/EHLO domain.
mailFromstringOptional: the envelope MAIL FROM (return-path) address.
messagestringyesThe raw email — full RFC 5322 message, or at least the headers block (Received, Authentication-Results, DKIM-Signature, From, …).
senderIpstringOptional: connecting IP to evaluate SPF against (overrides the IP parsed from Received headers).

No output schema declared.

No examples provided.

apply_dns_fix ~187

Apply a DNS fix plan to a tracked domain by publishing records at the connected registrar. DESTRUCTIVE: it creates/updates/deletes DNS records. Two-step by design — first call get_dns_fix_plan, then pass its `connectionId` and `ops` here verbatim. The server re-derives the diff from the latest scan and rejects any op that no longer matches, so an agent can never apply arbitrary records. Requires an owner/admin API key with write or full scope. Re-scan afterward to confirm the fix.

NameTypeReqDescription
connectionIdstringyesThe connectionId from get_dns_fix_plan.
domainstringyesDomain name tracked in the account, e.g. example.com.
opsarrayyesThe `ops` array from get_dns_fix_plan, passed verbatim. The server validates each op against a freshly recomputed diff before executing.

No output schema declared.

No examples provided.

check_blocklists ~64

Check a domain (apex + MX-host IPs) against supported DNS blocklists and return listings, targets checked, and issues (authoritative-side queries; no public-resolver false positives).

NameTypeReqDescription
domainstringyesDomain to check, e.g. example.com.

No output schema declared.

No examples provided.

connect_inbox_placement ~104

Store the org's seed-list inbox-placement provider + API key (provider: 'mailreach' or 'glockapps'; GlockApps also needs projectId). Enables start_inbox_placement_test. Requires an owner/admin API key with write or full scope.

NameTypeReqDescription
apiKeystringyesThe vendor API key.
projectIdstringGlockApps project id (required for provider=glockapps).
providerstringyesInbox-placement vendor.

No output schema declared.

No examples provided.

connect_snds ~129

Store this org's Microsoft SNDS (Smart Network Data Services) automated-data-access key so InboxGuard syncs per-IP Outlook/Hotmail reputation daily. Get the key from the SNDS Automated Data Access page (https://sendersupport.olc.protection.outlook.com/snds/). Requires an owner/admin API key with write or full scope. Data appears within ~24h of the first sync.

NameTypeReqDescription
keystringyesThe SNDS access key from the SNDS Automated Data Access page.
labelstringOptional label, e.g. "prod sending IPs".

No output schema declared.

No examples provided.

create_notification_channel ~152

Create a channel that InboxGuard alerts are delivered to: webhook (HMAC-signed), Slack, Microsoft Teams, PagerDuty, SMS, or email. Returns the channel id, and for kind=webhook the `signing_secret` used to verify deliveries. Requires an owner/admin API key with write or full scope.

NameTypeReqDescription
displayNamestringOptional label for the channel.
kindstringyesChannel type.
severityFilterarrayWhich alert severities to deliver (default ["critical","warn"]).
targetstringyesDestination matching `kind`: the webhook/Slack/Teams URL, PagerDuty integration key, phone number (E.164), or email address.

No output schema declared.

No examples provided.

create_share_link ~97

Create a read-only public share link for a tracked domain's latest report (anyone with the URL can view it; no account). Returns a `token` and the public `url` (https://inboxguard.io/r/<token>). Requires an owner/admin API key with write or full scope, on a plan that includes public reports.

NameTypeReqDescription
domainstringyesDomain name tracked in the account, e.g. example.com.

No output schema declared.

No examples provided.

get_deliverability_report ~189

Return a structured deliverability report for a tracked domain: the latest score + letter grade + `scoreSubtitle` (explains the denominator when a check was excluded, e.g. "80/100 · scored on 65 of 83 applicable points · 1 check unverified"), each check's status (pass/warn/fail/unverified/not_applicable — `not_applicable` means the check doesn't apply to this domain and `unverified` means it couldn't be checked this scan; neither is a failure), the top issues to fix, blocklist count, and DMARC policy. Includes `pdfUrl` — the same auth-gated endpoint that returns a branded one-page PDF (send your bearer token). Use this to summarize a domain's posture or hand a client a report.

NameTypeReqDescription
domainstringyesDomain name tracked in the account, e.g. example.com.

No output schema declared.

No examples provided.

get_deliverability_score ~45

Return the overall deliverability score and letter grade for a domain (runs a fresh scan).

NameTypeReqDescription
domainstringyesDomain to score, e.g. example.com.

No output schema declared.

No examples provided.

get_dmarc_summary ~109

Summarize ingested DMARC aggregate (RUA) reports for a domain tracked in your InboxGuard account: report volume, pass rate, top sending sources, and the rua inbox to publish. The domain must already be added to the account, and the plan must include DMARC ingest.

NameTypeReqDescription
daysintegerLookback window in days (default 30, max 90).
domainstringyesDomain name tracked in the account, e.g. example.com.

No output schema declared.

No examples provided.

get_dns_fix_plan ~135

Compute the exact DNS-record changes needed to fix a tracked domain's deliverability, based on its latest scan and the org's connected registrar (Cloudflare/Route 53/GoDaddy/Namecheap). Read-only — nothing changes. Returns the `ops` to pass verbatim to apply_dns_fix, plus `manualReview` items that need a human decision (SPF sender list, DKIM keys, BIMI logo). Requires the domain to be tracked, a scan to exist, and a registrar connection covering the zone.

NameTypeReqDescription
domainstringyesDomain name tracked in the account, e.g. example.com.

No output schema declared.

No examples provided.

get_domain ~91

Full detail for one tracked domain: the domain record, the latest scan with all per-check findings (spf, dmarc, dkim, ptr, mta_sts, tls_rpt, mx_tls, blocklist), recent score history, open/recent alerts, and Google Postmaster stats when connected.

NameTypeReqDescription
domainstringyesDomain name as tracked in the account, e.g. example.com.

No output schema declared.

No examples provided.

get_inbox_placement_status ~44

Report whether a seed-list inbox-placement provider is connected for the org, which provider, and how many tests have run. Lists the supported providers when not connected.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

get_inbox_placement_test ~89

Poll a seed-list inbox-placement test by testId. Returns status (running/completed/failed) and, once measured, the Inbox/Spam/Missing counts and inbox-placement score (0–100). Call after sending your campaign to the seed addresses from start_inbox_placement_test.

NameTypeReqDescription
testIdstringyesThe testId returned by start_inbox_placement_test.

No output schema declared.

No examples provided.

get_portfolio ~85

Org-wide deliverability rollup across every monitored domain: average score + overall grade, the grade distribution (how many domains are A/B/C/D/F/unscored), total open alerts, the domains needing attention (lowest score / open alerts first), and a per-client-group breakdown. Use this for an at-a-glance portfolio health summary across an agency or multi-domain account.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

get_scan_job ~69

Poll an async batch scan started with scan_domains_batch: returns status (queued/running/succeeded/partial/failed), completed count, and per-domain results (domain, ok, score, grade) as they finish.

NameTypeReqDescription
jobIdstringyesThe jobId returned by scan_domains_batch.

No output schema declared.

No examples provided.

get_snds_ip_stats ~72

Return the latest per-IP reputation from Microsoft SNDS for the org's sending IPs: filter result (GREEN/YELLOW/RED), complaint-rate band, spam-trap hits, message volume, and current block status. Requires SNDS to be connected (see connect_snds / get_snds_status).

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

get_snds_status ~62

Report whether Microsoft SNDS is connected for the org, the last sync time + status, how many sending IPs are tracked, and how many are currently blocked by Outlook/Hotmail. Use before get_snds_ip_stats to confirm the integration is live.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

list_alerts ~91

List the account's deliverability alerts (score drops, check failures, blocklist listings). Defaults to open alerts only.

NameTypeReqDescription
limitintegerMax alerts to return (default 50).
resolvedstring'false' = open alerts only (default), 'true' = resolved only, 'all' = both.
severitystringFilter by severity (default 'all').

No output schema declared.

No examples provided.

list_domains ~28

List the account's tracked domains with latest scan score, last scan time, and open alert count.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

list_inbox_placement_tests ~38

List recent seed-list inbox-placement tests for the org (most recent first) with their status and Inbox/Spam/Missing scores.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

list_registrar_connections ~73

List the registrar accounts (Cloudflare, Route 53, GoDaddy, Namecheap) connected to the org — provider, verification, last-used time — plus the supported providers. Use this to check whether the detect-and-fix loop (get_dns_fix_plan / apply_dns_fix) is available before attempting it.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

list_scans ~80

List recent scans (id, domain, run time, score) across all tracked domains, or for one domain when a name is given.

NameTypeReqDescription
domainstringOptional: restrict to one tracked domain by name, e.g. example.com. Omit for all domains.
limitintegerMax scans to return (default 20).

No output schema declared.

No examples provided.

remove_domain ~84

Stop monitoring a domain and delete it (and its scan history) from the account. DESTRUCTIVE and not reversible. Requires an owner/admin API key with write or full scope. (To ADD a domain, run scan_domain with this API key — authenticated scans auto-track the domain.)

NameTypeReqDescription
domainstringyesDomain name tracked in the account, e.g. example.com.

No output schema declared.

No examples provided.

resolve_alert ~79

Mark an alert resolved (or reopen it with resolved=false). Requires an API key with write/full scope. Resolving an already-resolved alert is a no-op.

NameTypeReqDescription
alertIdstringyesAlert UUID, from list_alerts or get_domain.
resolvedbooleantrue (default) marks the alert resolved; false reopens it.

No output schema declared.

No examples provided.

scan_domain ~212

Run a full email-deliverability scan (SPF, DKIM, DMARC, MTA-STS, TLS-RPT, MX TLS, BIMI, DNS blocklists) for a domain and return a 0-100 score with per-check findings. A check can come back `not_applicable` (does not apply to this domain, e.g. MTA-STS on a domain with no MX — excluded from the score, not a failure) or `unverified` (could not be determined this scan, e.g. DKIM behind an ESP with a random per-tenant selector like Amazon SES Easy DKIM — never treat as a failure). `scoreSubtitle` explains the denominator when anything was excluded. Runs at your plan tier (full blocklist set on paid plans) and saves the scan to the domain history in your account.

NameTypeReqDescription
dkimSelectorsarrayOptional DKIM selectors to probe.
domainstringyesDomain to scan, e.g. example.com.

No output schema declared.

No examples provided.

scan_domains_batch ~107

Queue an asynchronous batch scan of up to 50 domains and get a jobId immediately (avoids the 30s per-call limit). Poll get_scan_job with the jobId until status is succeeded/partial/failed to read per-domain scores. Requires an API key with write or full scope. These scans are NOT added to monitoring or saved to history.

NameTypeReqDescription
domainsarrayyes1-50 domains to scan, e.g. ["example.com","acme.com"].

No output schema declared.

No examples provided.

start_inbox_placement_test ~102

Start a seed-list inbox-placement test. Returns a testId, the seed addresses to mail your campaign to, and (if the provider requires it) a header to insert. After sending to the seeds, poll get_inbox_placement_test for the Inbox/Spam/Missing verdict. Requires inbox-placement to be connected and an owner/admin API key with write or full scope.

NameTypeReqDescription
subjectstringOptional subject line to associate with the test.

No output schema declared.

No examples provided.

Common questions

What is the io.inboxguard/email-deliverability MCP server?

io.inboxguard/email-deliverability is an MCP server listed in the public MCP registry as io.inboxguard/email-deliverability. Scan and fix a domain's email deliverability (SPF, DKIM, DMARC, MTA-STS, BIMI, DNS blocklists). This page covers its hosted endpoint (https://mcp.inboxguard.io/mcp).

Is the io.inboxguard/email-deliverability MCP server safe to use?

io.inboxguard/email-deliverability scores 90 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

What tools does the io.inboxguard/email-deliverability MCP server expose?

io.inboxguard/email-deliverability exposes 28 tools: scan_domain, get_deliverability_score, check_blocklists, get_dmarc_summary, list_domains, and 23 more. Their descriptions and schemas cost roughly 2,804 tokens of context every time the server is loaded.

Does the io.inboxguard/email-deliverability MCP server require authentication?

Yes. io.inboxguard/email-deliverability asked us for credentials when we connected, so you will need to authorise it in your MCP client before it can do anything.

Is the io.inboxguard/email-deliverability MCP server still maintained?

io.inboxguard/email-deliverability is still listed as active in the MCP registry. We last reached this channel on 20 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.