io.github.Integrity-Os/deliverability-doctor
Check if a domain can be email-spoofed: SPF, DMARC, DKIM, MX graded from public DNS. Authless.
Open source Repository Open in the app JSON README (API)
About
Check if a domain can be email-spoofed: SPF, DMARC, DKIM, MX graded from public DNS. Authless.
Details
- Kind
- MCP servers
- Topic
- Communication
- Publisher
- integrity-os
- Origin
- official
- Category
- ferramentas
- Transport
- http
- Version
- 1.0.2
- Last push
- 2026-08-26T04:39:11Z
- Repository state
- ativo
- Language
- JavaScript
- License
- MIT
- Added
- 2026-08-29 03:01:58
- Updated
- 2026-08-29 03:01:58
- Origin id
io.github.Integrity-Os/deliverability-doctor
README
# Deliverability Doctor Remote MCP server: **"Can my domain be email-spoofed?"** answered from public DNS, graded, with concrete fixes. Connectable to Claude (custom connector) and ChatGPT (Apps SDK / MCP connector) — both speak MCP, one server serves both. ## Tools - `check_email_security(domain)` — SPF (incl. RFC 7208 multiple-record permerror and `redirect=` handling), DMARC (policy, rua, pct), MX, DKIM at 7 common selectors. Graded A–F report, fixes per finding, upsell line only when problems exist. Accepts bare domain, URL, or email address. - `compare_email_security(domains[2..5])` — comparison table with grades. ## Design decisions - **Authless**: reads public DNS only, stores nothing, takes nothing but a domain. Lowest possible connect friction; nothing sensitive to protect. - **DNS-over-HTTPS** (Cloudflare → Google fallback): identical code runs on local Node and on Cloudflare Workers — no `dns` module dependency. - **Stateless streamable HTTP**: fresh transport per request, no sessions; safe to scale, trivial for clients. - **NXDOMAIN is refused, not graded** — "domain doesn't exist" ≠ "spoofable". - Verified against known postures before first run: gmail.com (`redirect=` must not be flagged), n8n.io (must grade A on `p=reject`), missing-everything domain (must grade F), NXDOMAIN (must refuse). ## Run ```bash npm install node server.js # :8787/mcp ``` Quick public demo: `cloudflared tunnel --url http://localhost:8787` → use `https://<random>.trycloudflare.com/mcp` as the connector URL. ## Status 2026-08-23 - Local: end-to-end MCP verified (initialize / tools/list / tools/call). - Public: live via quick tunnel, initialize verified from the public URL. - Durable hosting: **pending** — Cloudflare Workers deploy needs Kacper's account (~5 min). Tunnel URL dies with the process/PC. - Directory submissions (Anthropic connector directory, ChatGPT apps): need the durable URL first, then Kacper's developer accounts. ## Monetization path Free tool = distribution. Report links the $99 written audit (niekonieczny.gumroad.com/l/vscjt) only when problems are found. NOTE: Gumroad payouts currently frozen on Stripe KYC — unfreeze before promoting.