Skip to Main Content
AI assistant integrations

Best DMARC MCP servers

Six DMARC platforms publish an MCP server today: Palisade, Authwright, PowerDMARC, DMARC Examiner, DmarcDkim.com and DMARKOFF, alongside the self-hostable DMARCguard. They split on one thing, and it is not tool counts: whether the assistant can only read your data, or can also change something. An MCP server is what lets an assistant work with your real DMARC data instead of reasoning from general knowledge. This roundup records what each vendor publishes on its own pages, covering what the assistant may do, transport, authentication, and what it costs to connect.

Samuel ChenardBy Samuel Chenard, CEO & Co-Founder, PalisadePublished 18 Aug 2026Updated 9 Sep 2026
Palisade
The Palisade dashboard an MCP client reads domain and task data from
Palisade
Top-ranked option
Palisade rubric score
96/100
Palisade rubric: rank #1 of 69 verified providers
Score calculation: 77 ÷ 80 × 100 = 96.25, rounded to 96/100
Palisade’s 8-dimension rubric
Compared
7 vendors
Best fit
Teams that want the assistant to fix, not just report
Why it leads
The pick when the assistant should carry a domain from problem to published fix, with a human approving each change.

Palisade is free for one domain, up to 1,000 emails a month. Paid IT-team plans are sized by email volume. Start a 15-day full-product trial with no credit card.

Feature comparison

The shortlist at a glance

DMARC MCP servers compared on what the assistant may do, transport, authentication, and cost to connect.

DMARC MCP servers compared on what the assistant may do, transport, authentication, and cost to connect.
PlatformAssistant mayTransportAuthCost to connect
PalisadeYes: Read + enableYes: Remote + stdioYes: OAuth (Palisade connector client)Yes: Free plan
AuthwrightYes: Read + write DNSYes: RemoteYes: OAuth 2.1 + bridge tokenYes: Free tier
PowerDMARCYes: Read + writeYes: RemoteYes: API tokenPartial: Not stated
DMARC ExaminerPartial: Read + dismissYes: Remote + stdioYes: OAuth, 5 scopesYes: Free tier
DmarcDkim.comPartial: Read onlyYes: RemoteYes: OAuth + keysPartial: Free lookups
DMARKOFFPartial: Read onlyYes: RemoteYes: OAuth 2.1Yes: In paid plans
DMARCguard (formerly parse-dmarc)Partial: ReadYes: Remote + stdioYes: OAuthYes: Free tier

Want to compare the workflow yourself? Try Palisade free with one domain and up to 1,000 emails a month.

Strong / published Partial / quote Documented noNot disclosed by vendor
Methodology

How we compared the field

One method, applied to every vendor

Each server was read on its own product or documentation pages on 18 August 2026, plus the official MCP registry where a vendor publishes there. Directory listings and review sites were not treated as vendor claims.

Palisade's tool inventory and OAuth setup were rechecked against its running server card and API guide on 9 September 2026.

Authwright was added on 20 August 2026 and read the same way. Its origin refuses non-browser requests, so its pages were read first-party through a text-rendering proxy rather than a plain fetch, which is also how PowerDMARC is read here.

The meysam81/parse-dmarc repository now redirects to dmarcguardhq/dmarcguard, so that entry is recorded under the DMARCguard name and read on both the repository and dmarcguard.io.

Where a vendor does not publish something, this page says so rather than inferring it.

Tool counts are quoted only where the vendor publishes a list. A count is not a capability measure, so nothing is ranked on it.

No server was benchmarked. Response quality depends on the assistant asking, not on the server alone, and cannot be measured from a product page.

Evaluation criteria

  • What the assistant may do. Whether the server is read-only, or can also create, change, or enable something.
  • Transport. Whether the server is remote, local over stdio, or both, which decides the clients that can reach it.
  • Authentication. What credential the connection uses, and what it scopes access to.
  • Cost to connect. Whether MCP access needs a paid plan, a trial, or works on a free tier.
Head to head

Palisade and Authwright, visually compared

The first two options in this roundup are shown in the same screenshot-led format used throughout our comparisons. Product images provide interface context; the linked facts establish plan access and product scope.

First two options

How Palisade and Authwright differ in this roundup.

DMARC MCP servers compared on what the assistant may do, transport, authentication, and cost to connect.

Palisade

Palisade domains dashboard with email activity chart and DMARC compliance report
Palisade product screenshot · Vendor source, checked 2026-07-17
  • Write scope: Reads your domains and tasks, returns the exact records for you to publish, and can switch on Palisade-hosted DMARC and MTA-STS
  • Transport: Streamable HTTP, plus a published npm bridge for stdio-only clients
  • Authentication: MCP requires OAuth through Palisade's public connector client (ryKtuiPypMeYMoL1Cmhxtz6BYrEYQbLV), using PKCE with no client secret. Sign in and select your organization. API keys and self-registered OAuth clients are not accepted on the MCP endpoint; API keys remain available for the REST API.

Authwright

A relevant product screenshot was not available in the reviewed evidence.

Authwright product screenshot
  • Write scope: Reads, proposes and writes: DNS records are written into the zone at the registrar through its API, with a changeset preview before the write and a rollback snapshot after. Also purchases domains, renews certificates and flips WHOIS privacySource
  • Transport: Streamable HTTP, documented for Claude Desktop, Claude Code, Cursor, Windsurf and ContinueSource
  • Authentication: Two credentials, and they are separate. The transport is documented as OAuth 2.1 with PKCE via Microsoft Entra ID, with the portal also issuing a workspace-scoped bridge token for editor clients. Underneath both, the workspace holds your registrar API keys, described as living in Azure Key Vault and zeroed from memory on tool exitSource
The field

The best DMARC MCP servers, ranked

01

Palisade

Our platformFree plan

The pick when the assistant should carry a domain from problem to published fix, with a human approving each change.

Palisade publishes a remote MCP server with 42 tools across 11 groups, including domains, DNS and policy, the authentication work queue, DMARC reports, public DNS checks, and account activity. The assistant retrieves the exact SPF, DKIM and DMARC records to publish, verifies them once they resolve, and works the task list Palisade generates. MCP access is available on any plan, including the free one.

Best for

Teams that want the assistant to fix, not just report

Key features

  • 42 tools across 11 groups
  • Remote Streamable HTTP, plus an npm bridge for stdio-only clients
  • Returns the exact records to publish, with per-record status
  • Reads the live SPF chain and its DNS lookup count against the 10-lookup limit
  • Can switch on Palisade-hosted DMARC and MTA-STS
  • Listed in the official MCP registry

Assistant may

Reads your domains and tasks, returns the exact records for you to publish, and can switch on Palisade-hosted DMARC and MTA-STS

Transport

Streamable HTTP, plus a published npm bridge for stdio-only clients

Auth

MCP requires OAuth through Palisade's public connector client (ryKtuiPypMeYMoL1Cmhxtz6BYrEYQbLV), using PKCE with no client secret. Sign in and select your organization. API keys and self-registered OAuth clients are not accepted on the MCP endpoint; API keys remain available for the REST API.

Cost to connect

Included on every plan, including the free one

Choose Palisade if You want the assistant to find the authentication problem, show you the evidence, hand you the exact record, and verify it after you publish, rather than only describing what is wrong.

02

Authwright

Free tier; paid rates not published

The only server here that writes DNS records itself, which is also why it is the only one that needs your registrar API credentials.

Authwright publishes 42 tools across six categories: email authentication, DNS records, domain portfolio, SSL/TLS, bulk operations, and health checks. Its flagship email_auth_wizard, marketed as Email EasyPass, diagnoses a domain, writes the corrected records at the registrar, hosts the MTA-STS policy, waits for propagation, and re-checks. Reaching the registrar means storing that registrar's API credentials, which is the trade this server asks you to make.

Best for

Agencies that want the assistant to write DNS at the registrar

Key features

  • 42 tools across 6 categories, 8 of them email authentication
  • Writes DNS through registrar adapters for GoDaddy, Namecheap, Cloudflare, Porkbun and Route 53
  • Changeset preview before each write, with a rollback snapshot after
  • SSL/TLS lifecycle and domain purchasing, which no other server here covers
  • Not listed in the official MCP registry, checked 20 August 2026

Assistant may

Reads, proposes and writes: DNS records are written into the zone at the registrar through its API, with a changeset preview before the write and a rollback snapshot after. Also purchases domains, renews certificates and flips WHOIS privacy

Verified 2026-08-20

Transport

Streamable HTTP, documented for Claude Desktop, Claude Code, Cursor, Windsurf and Continue

Verified 2026-08-20

Auth

Two credentials, and they are separate. The transport is documented as OAuth 2.1 with PKCE via Microsoft Entra ID, with the portal also issuing a workspace-scoped bridge token for editor clients. Underneath both, the workspace holds your registrar API keys, described as living in Azure Key Vault and zeroed from memory on tool exit

Verified 2026-08-20

Cost to connect

Free tier covers one account; paid tier rates are not published

Verified 2026-08-20

Choose Authwright if You manage a domain portfolio on one of the five supported registrars, you want certificate renewals and domain purchases in the same MCP session as the email work, and holding registrar API credentials at a vendor is a trade your security review accepts.

03

PowerDMARC

Trial; MCP plan not stated

The widest published surface over DMARC data itself, extending past reports into sub-account and member administration.

PowerDMARC hosts an MCP server whose published tool list covers aggregate and forensic report queries, domain health, DNS lookups, record generators, hosted records, audit logs and sub-account administration. Its own page shows the assistant creating a domain and adding a member, so the surface reaches account management rather than reporting alone.

Best for

Multi-account resellers wanting the widest report-side surface

Key features

  • Published tools across reports, domains, lookups and generators
  • Sub-account and member administration, listed as partner features
  • Vendor-hosted, connected with an API token
  • Documents Claude, Cursor and ChatGPT

Assistant may

Creates and deletes domains, generates records, and adds or removes sub-account members

Verified 2026-08-18

Transport

Remote Streamable HTTP at mcp-dmarc.com/mcp, per its official registry entry; the vendor's MCP page gives a config snippet per client without naming the transport

Verified 2026-08-18

Auth

API token generated in the PowerDMARC dashboard, scoped to that token's permissions

Verified 2026-08-18

Cost to connect

Not stated for MCP; the page links a 15-day trial

Verified 2026-08-18

Choose PowerDMARC if You administer many sub-accounts and want account and member management in the same MCP surface as the report data.

04

DMARC Examiner

Free tier; paid from $2.99/mo

Published in the official MCP registry with both a remote endpoint and an stdio bridge, and an enumerated tool list.

DMARC Examiner publishes an MCP server at mcp.dmarc-examiner.com/mcp with eight tools across five OAuth scopes, covering domains, reports, CSV export and alerts. Seven of the eight read; dismiss_alert is the one that changes state. It ships a remote Streamable HTTP endpoint and an npm stdio bridge.

Best for

A registry-published server with a free tier

Key features

  • Published in the official MCP registry, active since August 2026
  • Eight tools enumerated across five OAuth scopes
  • Remote Streamable HTTP plus an npm stdio bridge
  • Free tier of one domain and 1,000 emails per month

Assistant may

Seven of the eight published tools read domains, reports and alerts; dismiss_alert is the only one that changes state

Verified 2026-08-18

Transport

Streamable HTTP at mcp.dmarc-examiner.com/mcp, plus the @dmarc-examiner/mcp npm stdio bridge

Verified 2026-08-18

Auth

OAuth, with five scopes the connecting client is granted individually

Verified 2026-08-18

Cost to connect

Free tier available; paid plans from $2.99/month, each with a 14-day trial and no card required

Verified 2026-08-18

Choose DMARC Examiner if You want a registry-published server you can connect on a free tier, and reading reports, sources and alerts is the job.

05

DmarcDkim.com

Free lookup tools

A read-oriented server whose lookup tools run against any domain, not only your own.

DmarcDkim.com publishes an MCP server split into free lookup tools and account tools. The lookups cover DNS record types, DMARC validation, DKIM selector checks and SPF syntax against RFC 7208. The account tools read stored aggregate reports, failing senders, DNS history and TLS-RPT data, and need a paid subscription.

Best for

DNS and record diagnosis

Key features

  • Free lookup tools that run against any domain
  • SPF syntax validation and record merging
  • Stored report and DNS history on paid plans
  • OAuth for interactive clients, API keys for scripts

Assistant may

Retrieves and analyses existing records and reports; it does not modify DNS records

Verified 2026-08-18

Transport

Remote, set up from app.dmarcdkim.com/mcp-instructions

Verified 2026-08-18

Auth

OAuth for interactive clients, API keys for scripts and CI

Verified 2026-08-18

Cost to connect

Free lookup tools after sign-in; stored account data needs a paid subscription

Verified 2026-08-18

Choose DmarcDkim.com if You want an assistant that is strong at diagnosing records and reading reports, and you do not need it to change anything.

06

DMARKOFF

Paid plan; 14-day trial

Read-only by published design, which is the point if an assistant touching configuration is off the table.

DMARKOFF publishes an MCP server that exposes domain health, authentication results, policy status and alert data to an AI assistant. Its page states the server is read-only by default and cannot modify DNS records or account configuration, and that access is scoped to what the account authorizes.

Best for

Monitoring where the assistant must not change anything

Key features

  • Read-only by default, stated on the vendor's page
  • OAuth 2.1 with account permission scoping
  • Documents Claude, ChatGPT, Cursor, Windsurf and Continue.dev
  • Included on paid plans at no extra cost

Assistant may

Read-only by default; the page states it cannot modify DNS records or account configuration

Verified 2026-08-18

Transport

Remote Streamable HTTP at mcp.dmarkoff.com/mcp, per its official registry entry; the vendor's MCP page does not name the transport

Verified 2026-08-18

Auth

OAuth 2.1, scoped to what the account authorizes

Verified 2026-08-18

Cost to connect

Included on all paid plans; a 14-day trial needs no credit card

Verified 2026-08-18

Choose DMARKOFF if Your policy is that an assistant may read email authentication data and nothing else, and you want that boundary set by the server rather than by prompt discipline.

07

DMARCguard (formerly parse-dmarc)

Apache-2.0 to self-host

The open-source option, Apache-2.0 and self-hostable, with an MCP server that speaks both stdio and Streamable HTTP.

DMARCguard, which the meysam81/parse-dmarc repository now redirects to, fetches DMARC aggregate reports from a mailbox over IMAP, parses them and shows them in a dashboard. Its repository implements MCP under internal/mcp, registering tools alongside an OAuth package and both a stdio transport and a Streamable HTTP handler. The product site advertises 17 MCP tools for AI stacks. It is a different project from the Python parsedmarc by domainaware, despite the similar name.

Best for

Self-hosting on your own infrastructure

Key features

  • Apache-2.0 and self-hostable via Docker or a binary
  • MCP over both stdio and Streamable HTTP
  • OAuth included in the repository
  • 17 MCP tools advertised on the product site; nine registered in the repository

Assistant may

The published tool set covers reading and parsing report data

Verified 2026-08-18

Transport

Both: the repository ships a stdio transport and a Streamable HTTP handler

Verified 2026-08-18

Auth

OAuth, included in the repository under internal/mcp/oauth

Verified 2026-08-18

Cost to connect

Free to self-host under Apache-2.0; the hosted free plan includes 5 AI queries a day, unlimited from Pro

Verified 2026-08-18

Choose DMARCguard (formerly parse-dmarc) if You want DMARC report parsing on infrastructure you control at no licence cost, and you are comfortable running and updating it yourself.

Palisade

Still choosing from this shortlist? See what changes with Palisade.

1 domain free up to 1,000 emails/month

The agent does the heavy lifting

Sources identified, SPF and DKIM fixes drafted, each policy step proposed. You approve; nothing ships on its own.

Connect your AI with MCP

  • ChatGPT
  • Claude
  • Codex
  • Cursor
  • Windsurf

42 tools over MCP, so your assistant reads your domains and works the queue.

Connect your DNS manager directly

  • GoDaddy
  • Cloudflare
  • Namecheap
  • Amazon Route 53

Approved records go into your own zone at your own provider, across 64. No credentials reach us.

We evaluated many DMARC providers before choosing Palisade. The quality of their product, the responsiveness and friendliness of their team and their rapid progress on their product roadmap made it a no-brainer for us to move forward.
Read the case study

What Palisade customers say

Read customer stories

5.0 out of 5 on G2Trusted by over 10,000 domains

Pick a customer

Palisade made it so easy for us to get our blue verified checkmark and achieve our BIMI compliance

Max LeRoy

Max LeRoy

VP Product, Politico

Read case study
Questions

Frequently asked questions

What is a DMARC MCP server?

A Model Context Protocol server that gives an AI assistant a set of tools for working with email authentication data. Without one, an assistant can only describe DMARC in general terms. With one, it can read your actual domains, reports and records, and on some platforms act on them.

Which DMARC MCP servers can change records, and which only read?

DMARKOFF publishes that its server is read-only by default and cannot modify DNS or account configuration. DmarcDkim.com's tools read and validate rather than change, and DMARC Examiner's registry entry describes reading reports, sources and alerts. PowerDMARC publishes tools that create domains and manage sub-account members. Palisade returns the exact records for you to publish and can switch on its own hosted DMARC and MTA-STS. Authwright goes furthest: it writes records into your zone at the registrar itself, and also buys domains and renews certificates, which is why it needs your registrar API credentials. Check this before connecting anything, because it decides what a mistaken instruction can do.

Does connecting an AI assistant let it change my DNS on its own?

Not with Palisade. The server returns the records to publish and you publish them at your DNS provider; the agent proposes and a person approves. Other platforms draw the line differently, so read each vendor's published tool list rather than assuming a shared default.

Which of these need my registrar or DNS credentials?

Authwright does. Its onboarding asks you to paste a GoDaddy API key and secret, or a Cloudflare API token, into the portal, and its site says those credentials are encrypted at rest in Azure Key Vault and scoped per domain where the registrar API allows it. That is what lets it write records for you, and it means a vendor now holds keys to your registrar account. Palisade takes the other route: you authorise the connection in your own provider's window, no credentials reach Palisade, access is scoped to email-authentication records, and you can revoke it. That path covers 64 providers with automatic configuration, against the five registrars Authwright's adapters reach. Whichever you pick, the question to ask your security reviewer is who ends up holding the keys.

Do I need a paid plan to use a DMARC MCP server?

It varies. Palisade includes MCP access on every plan, including free. DMARC Examiner publishes a free tier of one domain and 1,000 emails per month. DMARKOFF includes it on paid plans with a 14-day trial. DmarcDkim.com offers free lookup tools with account data behind a subscription. DMARCguard is free to self-host under Apache-2.0. PowerDMARC's MCP page does not state a plan requirement; it links a 15-day trial. Authwright starts on a free workspace covering one account, and does not publish rates for its Agency Plus or Enterprise tiers.

What transport do these servers use, and does it matter?

It decides which clients can reach the server. A remote server over Streamable HTTP works with clients that support remote MCP. Clients that only speak local stdio need a bridge; Palisade, DMARC Examiner and DMARCguard all offer one. If your team is standardized on one client, check that it supports the transport before choosing.

Which of these are in the official MCP registry?

Five of the seven. Checked on 18 August 2026: Palisade as email.palisade/palisade, PowerDMARC as com.powerdmarc/mcp, DMARC Examiner as io.github.dmarc-examiner/mcp, DMARKOFF as com.dmarkoff/mcp, and DMARCguard still under its former name io.github.meysam81/parse-dmarc. DmarcDkim.com is not listed there, and neither is Authwright, re-checked on 20 August 2026. A registry listing is a distribution choice rather than a quality bar, so read it as one signal about how a server expects to be found. Note that the registry's own search matches server names rather than descriptions, so a keyword search for "dmarc" does not return all five.

Is a bigger tool count better?

No. A count says how many named calls exist, not whether they cover the work you do. Authwright publishes 42 tools, and 8 of them are email authentication; the rest handle domain purchasing, certificates, WHOIS privacy and bulk portfolio work. That is a real advantage if you manage a registrar portfolio, and beside the point if you came for DMARC. Read the published tool list against your own workflow rather than the headline number.

How is this list ranked?

This is Palisade's roundup, so Palisade appears first and we are transparent about that. Every factual claim about another vendor comes from that vendor's own site or repository on the date shown beside it, so you can check each one and judge the servers yourself.

Ready to test the shortlist instead of just reading it?

Try Palisade free on one domain and see how an agent-led workflow fits the criteria in this shortlist.

1 domain free up to 1,000 emails/month