Keep email records separate from web proxying
Cloudflare exposes proxy status for A, AAAA, and CNAME records. The provider review makes the DNS-only requirement explicit when an email sender supplies a DKIM CNAME.
Palisade MCP diagnoses SPF, DKIM, DMARC, BIMI, and MTA-STS while Cloudflare remains the authoritative DNS provider. Your assistant prepares the change and the Palisade app publishes it after approval; direct Cloudflare writes from MCP are staged, not live.
1 domain free up to 1,000 emails/month
Check Cloudflare before enabling this Microsoft 365 DKIM selector.
CNAME selector1._domainkey
selector1-example-com._domainkey.tenant.onmicrosoft.com
Cloudflare setting: DNS only
Illustrative workflow. Provider writes currently happen in the Palisade app.
Cloudflare exposes proxy status for A, AAAA, and CNAME records. The provider review makes the DNS-only requirement explicit when an email sender supplies a DKIM CNAME.
Cloudflare notes that zones added by a hosting partner may need to be managed through that partner. Palisade treats authoritative detection and connection eligibility as different checks.
Palisade rechecks public DNS and the email-authentication task after the provider accepts a change, rather than treating API success as the final state.
The important boundary is explicit: MCP can inspect, explain, and prepare the record. The connected-provider write currently starts after approval in the Palisade app.
MCP reads Palisade evidence and exact remediation records.
The proposal carries record type, owner, content, TTL, and provider-specific cautions.
Smart DNS Deployment performs the write from the Palisade app.
Reserved for the governed provider-write release and not claimed as live today.
Confirm which provider is actually answering for the domain before choosing a publishing path.
Use your MCP client to inspect the domain, its senders, and the authentication task behind the warning.
See the exact owner, record type, value, and provider-specific handling before anything changes.
Approve in Palisade, then Smart DNS Deployment writes the record into the connected provider.
Recheck public DNS and the underlying SPF, DKIM, or DMARC evidence after propagation.
Add Palisade to Claude Code, then sign in when it opens your browser. The same governed workflow is available from any remote-MCP client.
claude mcp add --transport http palisade https://api.palisade.email/mcpCloudflare:Cloudflare zones, edge services, and infrastructure
Palisade:SPF, DKIM, DMARC, BIMI, and MTA-STS remediation
Cloudflare:Cloudflare account
Palisade:Cloudflare alongside GoDaddy, Namecheap, Route 53, and other providers
Cloudflare:Cloudflare dashboard, API, or native tooling
Palisade:Approved write through Smart DNS Deployment in the app
Cloudflare:DNS mutation accepted
Palisade:DNS visible and the authentication task re-evaluated
Straight answers about provider authority, approval, and the current write boundary.
No. Cloudflare has its own MCP and developer tooling. Palisade provides a cross-provider email-authentication workflow that can prepare and verify Cloudflare DNS changes alongside domains hosted elsewhere.
The record should preserve the sending provider's required DNS behavior. For DKIM CNAME records, the review calls out DNS-only handling rather than silently applying a web-proxy setting.
Not through the current MCP tool surface. The external DNS write is approved and performed from the Palisade app through Smart DNS Deployment.
Cloudflare documents that hosting-partner-managed zones may need to be administered through the partner. Authority, account visibility, and write eligibility are separate checks.
Verified 2026-08-21.
Registrar and authoritative DNS
Registrar and managed DNS
Registrar, authoritative DNS, and domain API
Authoritative DNS and AWS routing service
Logos provided by Logo.dev
1 domain free up to 1,000 emails/month