# email-deliverability MCP server

Scan and fix a domain's email deliverability (SPF, DKIM, DMARC, MTA-STS, BIMI, DNS blocklists).

## Links
- Registry page: https://www.getdrio.com/mcp/io-inboxguard-email-deliverability

## Install
- Endpoint: https://mcp.inboxguard.io/mcp
- Auth: Not captured

## Setup notes
- Remote endpoint: https://mcp.inboxguard.io/mcp

## Tools
- scan_domain (Scan domain deliverability) - Run a full email-deliverability scan (SPF, DKIM, DMARC, MTA-STS, TLS-RPT, MX TLS, BIMI, DNS blocklists) for a domain and return a 0-100 score with per-check findings. Runs at your plan tier (full blocklist set on paid plans) and saves the scan to the domain history in your account. Endpoint: https://mcp.inboxguard.io/mcp
- get_deliverability_score (Get deliverability score) - Return the overall deliverability score and letter grade for a domain (runs a fresh scan). Endpoint: https://mcp.inboxguard.io/mcp
- check_blocklists (Check DNS blocklists) - Check a domain (apex + MX-host IPs) against supported DNS blocklists and return listings, targets checked, and issues (authoritative-side queries; no public-resolver false positives). Endpoint: https://mcp.inboxguard.io/mcp
- get_dmarc_summary (Get DMARC summary) - Summarize ingested DMARC aggregate (RUA) reports for a domain tracked in your InboxGuard account: report volume, pass rate, top sending sources, and the rua inbox to publish. The domain must already be added to the account, and the plan must include DMARC ingest. Endpoint: https://mcp.inboxguard.io/mcp
- list_domains (List tracked domains) - List the account's tracked domains with latest scan score, last scan time, and open alert count. Endpoint: https://mcp.inboxguard.io/mcp
- get_domain (Get domain detail) - Full detail for one tracked domain: the domain record, the latest scan with all per-check findings (spf, dmarc, dkim, ptr, mta_sts, tls_rpt, mx_tls, blocklist), recent score history, open/recent alerts, and Google Postmaster stats when connected. Endpoint: https://mcp.inboxguard.io/mcp
- list_alerts (List alerts) - List the account's deliverability alerts (score drops, check failures, blocklist listings). Defaults to open alerts only. Endpoint: https://mcp.inboxguard.io/mcp
- list_scans (List scan history) - List recent scans (id, domain, run time, score) across all tracked domains, or for one domain when a name is given. Endpoint: https://mcp.inboxguard.io/mcp
- resolve_alert (Resolve alert) - Mark an alert resolved (or reopen it with resolved=false). Requires an API key with write/full scope. Resolving an already-resolved alert is a no-op. Endpoint: https://mcp.inboxguard.io/mcp
- get_dns_fix_plan (Preview the DNS fix plan) - Compute the exact DNS-record changes needed to fix a tracked domain's deliverability, based on its latest scan and the org's connected registrar (Cloudflare/Route 53/GoDaddy/Namecheap). Read-only — nothing changes. Returns the `ops` to pass verbatim to apply_dns_fix, plus `manualReview` items that need a human decision (SPF sender list, DKIM keys, BIMI logo). Requires the domain to be tracked, a scan to exist, and a registrar connection covering the zone. Endpoint: https://mcp.inboxguard.io/mcp
- apply_dns_fix (Apply the DNS fix plan) - Apply a DNS fix plan to a tracked domain by publishing records at the connected registrar. DESTRUCTIVE: it creates/updates/deletes DNS records. Two-step by design — first call get_dns_fix_plan, then pass its `connectionId` and `ops` here verbatim. The server re-derives the diff from the latest scan and rejects any op that no longer matches, so an agent can never apply arbitrary records. Requires an owner/admin API key with write or full scope. Re-scan afterward to confirm the fix. Endpoint: https://mcp.inboxguard.io/mcp
- analyze_headers (Analyze raw email headers) - Re-verify SPF, DKIM, DMARC, and ARC from a raw RFC 5322 email (full message or just the headers block). Returns InboxGuard's independent verdict (`ours`), the sender's own Authentication-Results (`theirs`), whether they `agree`, and parsed envelope/headers — useful for spotting forged or mismatched auth results. No account needed. Endpoint: https://mcp.inboxguard.io/mcp
- scan_domains_batch (Batch-scan domains (async)) - Queue an asynchronous batch scan of up to 50 domains and get a jobId immediately (avoids the 30s per-call limit). Poll get_scan_job with the jobId until status is succeeded/partial/failed to read per-domain scores. Requires an API key with write or full scope. These scans are NOT added to monitoring or saved to history. Endpoint: https://mcp.inboxguard.io/mcp
- get_scan_job (Get batch-scan job) - Poll an async batch scan started with scan_domains_batch: returns status (queued/running/succeeded/partial/failed), completed count, and per-domain results (domain, ok, score, grade) as they finish. Endpoint: https://mcp.inboxguard.io/mcp
- remove_domain (Remove a monitored domain) - Stop monitoring a domain and delete it (and its scan history) from the account. DESTRUCTIVE and not reversible. Requires an owner/admin API key with write or full scope. (To ADD a domain, run scan_domain with this API key — authenticated scans auto-track the domain.) Endpoint: https://mcp.inboxguard.io/mcp
- list_registrar_connections (List registrar connections) - List the registrar accounts (Cloudflare, Route 53, GoDaddy, Namecheap) connected to the org — provider, verification, last-used time — plus the supported providers. Use this to check whether the detect-and-fix loop (get_dns_fix_plan / apply_dns_fix) is available before attempting it. Endpoint: https://mcp.inboxguard.io/mcp
- create_notification_channel (Create a notification channel) - Create a channel that InboxGuard alerts are delivered to: webhook (HMAC-signed), Slack, Microsoft Teams, PagerDuty, SMS, or email. Returns the channel id, and for kind=webhook the `signing_secret` used to verify deliveries. Requires an owner/admin API key with write or full scope. Endpoint: https://mcp.inboxguard.io/mcp
- create_share_link (Create a public share link) - Create a read-only public share link for a tracked domain's latest report (anyone with the URL can view it; no account). Returns a `token` and the public `url` (https://inboxguard.io/r/<token>). Requires an owner/admin API key with write or full scope, on a plan that includes public reports. Endpoint: https://mcp.inboxguard.io/mcp
- connect_snds (Connect Microsoft SNDS) - Store this org's Microsoft SNDS (Smart Network Data Services) automated-data-access key so InboxGuard syncs per-IP Outlook/Hotmail reputation daily. Get the key from the SNDS Automated Data Access page (https://sendersupport.olc.protection.outlook.com/snds/). Requires an owner/admin API key with write or full scope. Data appears within ~24h of the first sync. Endpoint: https://mcp.inboxguard.io/mcp
- get_snds_status (Get Microsoft SNDS status) - Report whether Microsoft SNDS is connected for the org, the last sync time + status, how many sending IPs are tracked, and how many are currently blocked by Outlook/Hotmail. Use before get_snds_ip_stats to confirm the integration is live. Endpoint: https://mcp.inboxguard.io/mcp
- get_snds_ip_stats (Get Microsoft SNDS per-IP stats) - Return the latest per-IP reputation from Microsoft SNDS for the org's sending IPs: filter result (GREEN/YELLOW/RED), complaint-rate band, spam-trap hits, message volume, and current block status. Requires SNDS to be connected (see connect_snds / get_snds_status). Endpoint: https://mcp.inboxguard.io/mcp
- connect_inbox_placement (Connect an inbox-placement provider) - Store the org's seed-list inbox-placement provider + API key (provider: 'mailreach' or 'glockapps'; GlockApps also needs projectId). Enables start_inbox_placement_test. Requires an owner/admin API key with write or full scope. Endpoint: https://mcp.inboxguard.io/mcp
- get_inbox_placement_status (Get inbox-placement status) - Report whether a seed-list inbox-placement provider is connected for the org, which provider, and how many tests have run. Lists the supported providers when not connected. Endpoint: https://mcp.inboxguard.io/mcp
- start_inbox_placement_test (Start an inbox-placement test) - Start a seed-list inbox-placement test. Returns a testId, the seed addresses to mail your campaign to, and (if the provider requires it) a header to insert. After sending to the seeds, poll get_inbox_placement_test for the Inbox/Spam/Missing verdict. Requires inbox-placement to be connected and an owner/admin API key with write or full scope. Endpoint: https://mcp.inboxguard.io/mcp
- get_inbox_placement_test (Get an inbox-placement test) - Poll a seed-list inbox-placement test by testId. Returns status (running/completed/failed) and, once measured, the Inbox/Spam/Missing counts and inbox-placement score (0–100). Call after sending your campaign to the seed addresses from start_inbox_placement_test. Endpoint: https://mcp.inboxguard.io/mcp
- list_inbox_placement_tests (List inbox-placement tests) - List recent seed-list inbox-placement tests for the org (most recent first) with their status and Inbox/Spam/Missing scores. Endpoint: https://mcp.inboxguard.io/mcp
- get_deliverability_report (Get a deliverability report) - Return a structured deliverability report for a tracked domain: the latest score + letter grade, each check's status (pass/warn/fail), the top issues to fix, blocklist count, and DMARC policy. Includes `pdfUrl` — the same auth-gated endpoint that returns a branded one-page PDF (send your bearer token). Use this to summarize a domain's posture or hand a client a report. Endpoint: https://mcp.inboxguard.io/mcp
- get_portfolio (Get the domain portfolio rollup) - Org-wide deliverability rollup across every monitored domain: average score + overall grade, the grade distribution (how many domains are A/B/C/D/F/unscored), total open alerts, the domains needing attention (lowest score / open alerts first), and a per-client-group breakdown. Use this for an at-a-glance portfolio health summary across an agency or multi-domain account. Endpoint: https://mcp.inboxguard.io/mcp

## Resources
- ui://inboxguard/scan-result - Interactive deliverability scorecard for scan_domain output. MIME type: text/html;profile=mcp-app
- https://inboxguard.io/llms-full.txt - Complete product + API reference. MIME type: text/markdown
- https://inboxguard.io/openapi.json - OpenAPI 3.1 contract. MIME type: application/json
- https://inboxguard.io/auth.md - How agents authenticate. MIME type: text/markdown

## Prompts
Not captured

## Metadata
- Owner: io.inboxguard
- Version: 1.2.0
- Runtime: Streamable Http
- Transports: HTTP
- License: Not captured
- Language: Not captured
- Stars: Not captured
- Updated: Jun 12, 2026
- Source: https://registry.modelcontextprotocol.io
