Skip to Main Content
Cloudflare logoPalisade MCP × CloudflareLaunch preview

Cloudflare email authentication

Palisade MCP diagnoses SPF, DKIM, DMARC, BIMI, and MTA-STS while Cloudflare remains the authoritative DNS provider. Your assistant prepares the change and the Palisade app publishes it after approval; direct Cloudflare writes from MCP are staged, not live.

1 domain free up to 1,000 emails/month

Analysis is liveHuman approval before publish
Palisade MCP

Check Cloudflare before enabling this Microsoft 365 DKIM selector.

Cloudflare authoritative zone detected
CNAME target validated against sender instructions
Email-auth record classified as DNS-only
Exact change waiting for human approval
Proposed recordApproval required

CNAME selector1._domainkey

selector1-example-com._domainkey.tenant.onmicrosoft.com

Cloudflare setting: DNS only

Illustrative workflow. Provider writes currently happen in the Palisade app.

Built for Cloudflare

Provider-aware where mistakes get expensive

Keep email records separate from web proxying

Cloudflare exposes proxy status for A, AAAA, and CNAME records. The provider review makes the DNS-only requirement explicit when an email sender supplies a DKIM CNAME.

Recognize partner-managed zones

Cloudflare notes that zones added by a hosting partner may need to be managed through that partner. Palisade treats authoritative detection and connection eligibility as different checks.

Verify beyond Cloudflare's save response

Palisade rechecks public DNS and the email-authentication task after the provider accepts a change, rather than treating API success as the final state.

Current capability

What works now, and what is still a preview

The important boundary is explicit: MCP can inspect, explain, and prepare the record. The connected-provider write currently starts after approval in the Palisade app.

Audit Cloudflare-hosted email-authentication DNS

MCP reads Palisade evidence and exact remediation records.

Live

Prepare DNS-only email-auth changes

The proposal carries record type, owner, content, TTL, and provider-specific cautions.

Live

Publish an approved record into Cloudflare

Smart DNS Deployment performs the write from the Palisade app.

App handoff

Write Cloudflare DNS directly from MCP

Reserved for the governed provider-write release and not claimed as live today.

Preview
The governed loop

From a question in your AI client to verified DNS

  1. 01

    Detect authority

    Confirm which provider is actually answering for the domain before choosing a publishing path.

  2. 02

    Ask Palisade

    Use your MCP client to inspect the domain, its senders, and the authentication task behind the warning.

  3. 03

    Review the diff

    See the exact owner, record type, value, and provider-specific handling before anything changes.

  4. 04

    Approve and publish

    Approve in Palisade, then Smart DNS Deployment writes the record into the connected provider.

  5. 05

    Verify the outcome

    Recheck public DNS and the underlying SPF, DKIM, or DMARC evidence after propagation.

Provider notes

Cloudflare details worth preserving in every change review

API permission
Cloudflare documents DNS Write as the required token permission for creating records.
Proxy-aware types
Cloudflare exposes proxy status for A, AAAA, and CNAME records.
Record attributes
Cloudflare supports TTL plus optional comments and tags on DNS records.
Partner caveat
A hosting-partner-managed zone may need to be changed through the partner.

Connect from an MCP client

Add Palisade to Claude Code, then sign in when it opens your browser. The same governed workflow is available from any remote-MCP client.

Claude Code
bash
claude mcp add --transport http palisade https://api.palisade.email/mcp
See all client configurations
Division of work

Where Palisade fits beside Cloudflare

Primary scope

Cloudflare:Cloudflare zones, edge services, and infrastructure

Palisade:SPF, DKIM, DMARC, BIMI, and MTA-STS remediation

Estate view

Cloudflare:Cloudflare account

Palisade:Cloudflare alongside GoDaddy, Namecheap, Route 53, and other providers

Current write path

Cloudflare:Cloudflare dashboard, API, or native tooling

Palisade:Approved write through Smart DNS Deployment in the app

Success criterion

Cloudflare:DNS mutation accepted

Palisade:DNS visible and the authentication task re-evaluated

Questions

Cloudflare MCP FAQ

Straight answers about provider authority, approval, and the current write boundary.

Is Palisade the official Cloudflare MCP server?

No. Cloudflare has its own MCP and developer tooling. Palisade provides a cross-provider email-authentication workflow that can prepare and verify Cloudflare DNS changes alongside domains hosted elsewhere.

Does Palisade proxy DKIM records through Cloudflare?

The record should preserve the sending provider's required DNS behavior. For DKIM CNAME records, the review calls out DNS-only handling rather than silently applying a web-proxy setting.

Can Palisade MCP write to Cloudflare directly today?

Not through the current MCP tool surface. The external DNS write is approved and performed from the Palisade app through Smart DNS Deployment.

Why does Cloudflare show the zone but not allow the connection?

Cloudflare documents that hosting-partner-managed zones may need to be administered through the partner. Authority, account visibility, and write eligibility are separate checks.

Bring Cloudflare into your email-authentication workflow

1 domain free up to 1,000 emails/month