email_check_dmarc
Check DMARC record with policy analysis and reporting configuration
How to use it
email_check_dmarc is exposed by the Dns Security MCP MCP server. Add the server to your MCP client (Claude Desktop, Cursor, Windsurf and others), and the email_check_dmarc tool becomes available to the model automatically. See the full listing for setup details and every tool this server provides.
Install Dns Security MCP
npx -y dns-security-mcpOther tools in Dns Security MCP (39)
Perform DNS cache snooping by sending non-recursive query (RD=0) to a nameserver
Resolve all DNS record types for a domain in parallel
Attempt DNSSEC NSEC zone walking to enumerate domain names in a signed zone
Check DNS propagation by querying 20+ globally distributed public resolvers
Test whether a nameserver is an open recursive resolver (RD=1 for external domain)
Perform PTR (reverse DNS) lookup with Forward Confirmed rDNS (FCrDNS) validation
Fingerprint a DNS server by querying CHAOS class TXT records (version.bind)
Detect split-horizon (split-brain) DNS by comparing internal vs external resolver responses
Enumerate subdomains using passive CT (Certificate Transparency) log lookups via crt.sh
Analyze DNS TTL values across all record types for a domain
Detect wildcard DNS configurations by resolving random non-existent subdomains
Attempt AXFR (full zone transfer) against a domain's nameserver via TCP
Inventory all DNSSEC algorithms used in DS, DNSKEY, and RRSIG records
List all DNSKEY records for a domain
Check DS (Delegation Signer) records for a domain
Check NSEC/NSEC3 records for a domain
Check RRSIG (Resource Record Signature) records and expiry
Comprehensive DNSSEC audit: all 7 checks combined with unified report
Check for DNSSEC key rollover indicators
Full DNSSEC chain of trust validation from root to TLD to domain
Check BIMI (Brand Indicators for Message Identification) record
Check DANE/TLSA records for a domain's MX hosts
Check DKIM records by probing common selectors (google, selector1, dkim, etc.)
Check MTA-STS (Mail Transfer Agent Strict Transport Security) configuration
Check PTR and FCrDNS (Forward-Confirmed reverse DNS) for MX hosts
Check SPF (Sender Policy Framework) record with mechanism analysis
Comprehensive email security audit across all protocols
Calculate email spoofability score (0-100) based on SPF, DKIM, DMARC
Assess BGP-level impact of domain hijacking via Team Cymru ASN lookup
Monitor DNS record changes by comparing against a stored baseline
Detect dangling CNAME records that could allow subdomain takeover
Detect dangling MX records that could allow email hijacking
Detect dangling NS records that could allow full domain takeover
Detect DNS rebinding candidates via IP changes combined with low TTL
Walk the DNS delegation chain and verify consistency
Check domain registrar security posture via RDAP
Full subdomain takeover scan using CT logs and CNAME resolution
Calculate Shannon entropy per subdomain label to detect tunneling
Measure subdomain label and total query lengths for anomaly detection