Skip to the documentation
MCP server

Domain checks

The public mail records of any domain.

Domain checks tools

ToolWhat it does
checkDmarcWhat the DMARC record of any domain says: how strict it is, every tag, the parent domain it inherits from and what is wrong with it.
checkBimiWhether inboxes can draw the logo a domain publishes, with the logo, its mark certificate, the DMARC policy beside it and what stops it showing.
checkDeliverabilityMX, SPF, DKIM, DMARC and BIMI for any domain, each pass, warn, fail or absent with a verdict, weighed into a score out of 100 and a grade from A to F.

These are the free checkers on the OpenEmail website. They read public DNS and nothing in the workspace, so they need no permission and work on any domain, not only yours.

Every answer is what DNS said at that moment. A result that starts Refused (unreachable): means DNS did not answer, and is worth trying again.

Reference

checkDmarc

No scopeThe app's assistant runs it without askingToolkitworkspace

Read any domain's DMARC record from public DNS, as the DMARC checker on the OpenEmail website does: how strict it is (missing, invalid, monitor for p=none, quarantine or reject), every tag, the parent domain it inherits from, and what is wrong with it.

Inputs

domainstringRequired

The domain, such as acme.com. An email address or a URL is read as its domain.

1 to 320 characters

Also available in

API
GET /tools/dmarc
SDK
tools.checkDmarc()

checkBimi

No scopeThe app's assistant runs it without askingToolkitworkspace

Read any domain's BIMI record, fetch the logo it names and check the DMARC policy beside it, as the BIMI checker on the OpenEmail website does. Inboxes draw a logo only at p=quarantine or p=reject, and the issues say what stops it showing.

Inputs

domainstringRequired

The domain, such as acme.com. An email address or a URL is read as its domain.

1 to 320 characters

Also available in

API
GET /tools/bimi
SDK
tools.checkBimi()

checkDeliverability

No scopeThe app's assistant runs it without askingToolkitworkspace

Check whether mail from any domain is set up to be trusted, as the deliverability checker on the OpenEmail website does: MX, SPF, DKIM, DMARC and BIMI, each pass, warn, fail or absent with a verdict, weighed into a score out of 100 and a grade from A to F.

Inputs

domainstringRequired

The domain, such as acme.com. An email address or a URL is read as its domain.

1 to 320 characters

Also available in

API
GET /tools/deliverability
SDK
tools.checkDeliverability()