Use the provider API without broadening the task
Porkbun's API covers registrations, renewals, DNSSEC, SSL, and more. Palisade keeps an email-authentication request scoped to the records and verification needed for that job.
Porkbun exposes a broad domain and DNS API, while Palisade specializes the workflow for SPF, DKIM, DMARC, BIMI, and MTA-STS. MCP prepares the exact fix; Smart DNS Deployment publishes it after approval in the app until the direct MCP provider-write path ships.
1 domain free up to 1,000 emails/month
Protect the unused Porkbun domain from sending mail.
TXT @ "v=spf1 -all"
TXT _dmarc "v=DMARC1; p=reject"
Illustrative parked-domain policy
Illustrative workflow. Provider writes currently happen in the Palisade app.
Porkbun's API covers registrations, renewals, DNSSEC, SSL, and more. Palisade keeps an email-authentication request scoped to the records and verification needed for that job.
A domain that never sends mail still needs an explicit posture. The workflow can distinguish a no-mail policy from an active sender migration instead of applying the same DMARC recipe to both.
The proposed DNS state stays visible before publication so a compact registrar dashboard does not become the only record of what changed and why.
The important boundary is explicit: MCP can inspect, explain, and prepare the record. The connected-provider write currently starts after approval in the Palisade app.
Available through Palisade MCP and the public DNS evidence it retrieves.
Recommendations depend on the domain's actual sending role.
Smart DNS Deployment performs the provider write after approval.
Staged for a later provider-write tool surface.
Confirm which provider is actually answering for the domain before choosing a publishing path.
Use your MCP client to inspect the domain, its senders, and the authentication task behind the warning.
See the exact owner, record type, value, and provider-specific handling before anything changes.
Approve in Palisade, then Smart DNS Deployment writes the record into the connected provider.
Recheck public DNS and the underlying SPF, DKIM, or DMARC evidence after propagation.
Add Palisade to Claude Code, then sign in when it opens your browser. The same governed workflow is available from any remote-MCP client.
claude mcp add --transport http palisade https://api.palisade.email/mcpPorkbun:Domains, renewals, DNS, DNSSEC, SSL, and hosting
Palisade:Email-authentication diagnosis and approved record deployment
Porkbun:Generic domain administration
Palisade:Active sender, parked domain, or defensive-registration posture
Porkbun:Porkbun console or API
Palisade:Palisade app after a visible approval
Porkbun:Provider operation result
Palisade:Public record and email-authentication state verified
Straight answers about provider authority, approval, and the current write boundary.
No. Porkbun documents its own API and first-party MCP capabilities. This page describes Palisade's specialized email-authentication workflow for Porkbun-hosted DNS.
That is not part of the current Palisade provider connection described here. Palisade's present automatic publishing scope is approved email-authentication records.
Palisade can diagnose the domain and prepare an explicit no-mail SPF and DMARC posture. The owner should confirm that the domain truly has no legitimate sending path before approving it.
No. MCP prepares and explains the change; the approved write currently happens through Smart DNS Deployment in the Palisade app.
Registrar and authoritative DNS
Registrar and managed DNS
Authoritative DNS and edge network
Authoritative DNS and AWS routing service
Logos provided by Logo.dev
1 domain free up to 1,000 emails/month