DnsGuard

dev.workers.mike-tusa.dnsguardv0.7.2Updated Oct 8, 2026

Check a domain's email authentication: SPF, DKIM, DMARC, BIMI, MX, MTA-STS, TLS-RPT. Score + fixes.

VerifiedStreamable HTTPWeb executableDeveloper ToolsSecurity & Monitoring

Overview

AI-generated overview

Lets an assistant check a domain's email authentication records — SPF, DKIM, DMARC, BIMI, MX, MTA-STS and TLS-RPT — and get a score with fixes.

What it does
DnsGuard inspects a domain's email authentication setup, covering SPF, DKIM, DMARC, BIMI, MX, MTA-STS and TLS-RPT records. It returns a score plus suggested fixes for what it finds. It runs as a remote endpoint, so the assistant calls it over HTTP rather than running anything locally.
When to use it
Useful when you need to audit or troubleshoot why a domain's mail is failing authentication, landing in spam, or missing DMARC enforcement. Also handy for checking a domain before or after a DNS or email configuration change.
Requirements
A remote MCP endpoint over streamable HTTP; no local package or runtime is needed. An Authorization header is optional: a free key obtained via Google sign-in on the provider's site, or a Pro key for higher limits. It works without a key.
Before you install
The optional Authorization header carries a credential; treat it as a secret and avoid exposing it. The service is remote, so the domains you query are sent to a third party. No write, send, or delete actions are described.

Installation

In SourceWeft

  1. Open DnsGuard in the dashboard and add it to a workspace.
  2. Enable the server for the chats that should use its tools.

Web executable via Streamable HTTP. Remote servers run from the web runtime once configured in a workspace.

Other MCP clients

Add this to your client's mcpServers config.

{
  "mcpServers": {
    "dnsguard": {
      "type": "http",
      "url": "https://dnsguard.mike-tusa.workers.dev/mcp"
    }
  }
}

Tools

0
Tool metadata has not been indexed yet.

Version history

1
  1. v0.7.2LatestOct 8, 2026