Skip to the documentation
API

Tools

Every operation in this group: what it accepts, what it returns and the errors it can answer with.

Operations

Checks of the public mail records of any domain, the free tools on the OpenEmail website: its DMARC policy, its BIMI logo, and a deliverability report across MX, SPF, DKIM, DMARC and BIMI. They read public DNS and nothing in the workspace, so they need no scope, and every answer is what DNS said at that moment.

GET/tools/dmarc

Check a domain's DMARC policy

No scopeReads

Reads the domain's DMARC record from public DNS, or the record of the organisational domain it inherits from, and says how strict it is and what is wrong with it. stage is missing, invalid, monitor for p=none, quarantine or reject.

Needs no scope: any key or access token for the workspace may run it.

Query parameters

domainstringRequired

The domain to check, such as acme.com. An email address, a URL or a domain with a trailing dot is read as its domain. Any public domain works, not only the ones in this workspace.

Up to 320 characters

Returns

What the DMARC record says.

Errors

422

invalid_parameter on domain: it does not read as a domain.

503

unreachable: public DNS did not answer for the domain just now. Nothing about the domain was decided, so try again in a moment.

The errors every operation can return400401403404500Error catalog

Also available in

SDK
tools.checkDmarc()
CLI
openemail tools check-dmarc
MCP
checkDmarc

GET/tools/bimi

Check a domain's BIMI logo

No scopeReads

Reads the domain's BIMI record, fetches the logo it names and checks the DMARC policy beside it, since inboxes draw a logo only at p=quarantine or p=reject. status is present, partial when the record is there but something stops inboxes showing it, absent or invalid, and issues says why.

Needs no scope: any key or access token for the workspace may run it.

Query parameters

domainstringRequired

The domain to check, such as acme.com. An email address, a URL or a domain with a trailing dot is read as its domain. Any public domain works, not only the ones in this workspace.

Up to 320 characters

Returns

What the BIMI record says and whether inboxes can draw the logo.

Errors

422

invalid_parameter on domain: it does not read as a domain.

503

unreachable: public DNS did not answer for the domain just now. Nothing about the domain was decided, so try again in a moment.

The errors every operation can return400401403404500Error catalog

Also available in

SDK
tools.checkBimi()
CLI
openemail tools check-bimi
MCP
checkBimi

GET/tools/deliverability

Check a domain's deliverability

No scopeReads

Checks the records a receiving mailbox reads before it trusts mail from the domain: MX, SPF, DKIM at the selectors its mail provider uses, DMARC and BIMI. Each check says pass, warn, fail or absent with a verdict and notes written to be shown to a person, and score weighs them into 0 to 100, graded A to F.

Needs no scope: any key or access token for the workspace may run it.

Query parameters

domainstringRequired

The domain to check, such as acme.com. An email address, a URL or a domain with a trailing dot is read as its domain. Any public domain works, not only the ones in this workspace.

Up to 320 characters

Returns

Each check, the score and the grade.

Errors

422

invalid_parameter on domain: it does not read as a domain.

503

unreachable: public DNS did not answer for the domain just now. Nothing about the domain was decided, so try again in a moment.

The errors every operation can return400401403404500Error catalog

Also available in

SDK
tools.checkDeliverability()
CLI
openemail tools check-deliverability
MCP
checkDeliverability

Objects

BimiReportobject

objectstringRequired
One of"bimi_report"
domainstringRequired
recordstringRequired

The BIMI record at default._bimi, or null.

Can be null
versionstring
Can be null
logoUrlstring

The l= of the record: where the SVG logo is served.

Can be null
authorityUrlstring

The a= of the record: where the mark certificate is served, or null without one.

Can be null
logoSvgstring

The logo as it was fetched, when it could be, to show it.

Can be null
logoReachableboolean
dmarcPolicystring

The p= of the DMARC record beside it.

Can be null
dmarcEnforcedboolean

Whether that policy is quarantine or reject, the only ones under which a logo is drawn.

statusstringRequired
One of"present""partial""absent""invalid"
issuesstring[]Required

DeliverabilityCheckobject

idstringRequired
One of"mx""spf""dkim""dmarc""bimi"
labelstringRequired
statusstringRequired
One of"pass""warn""fail""absent"
verdictstringRequired

One line saying what was found.

recordstringRequired

The record that was read, when there is one.

Can be null
notesstring[]Required

DeliverabilityReportobject

objectstringRequired
One of"deliverability_report"
domainstringRequired
scoreintegerRequired
At least 0At most 100
gradestringRequired
One of"A""B""C""D""F"
providerstringRequired

The mail provider its MX records point at, such as Google Workspace, when it is known.

Can be null
checksDeliverabilityCheck[]Required

DmarcReportobject

objectstringRequired
One of"dmarc_report"
domainstringRequired

The domain that was checked, lower-cased.

recordstringRequired

The DMARC record as published, or null when there is none.

Can be null
inheritedFromstringRequired

The parent domain whose record applies, when the domain has none of its own. Null when the record is its own or there is none.

Can be null
tagsRecord<string, string>Required

Every tag of the record, such as p, sp, pct and rua, as written.

stagestringRequired
One of"missing""invalid""monitor""quarantine""reject"
issuesstring[]Required

Problems found, each written to be shown to a person. Empty when there are none.