# com.themailx/email-deliverability

Check SPF/DKIM/DMARC/BIMI, blacklists, SMTP/IMAP; DNS lookups; generate email DNS records.

- **Type:** MCP server
- **Trust:** 60/100 (B), scored on the content rubric
- **Verification:** community-indexed — nobody has claimed this listing
- **Version:** 1.0.0
- **Author:** com.themailx
- **License:** Unknown
- **Endpoints:** streamable-http https://themailx.com/mcp
- **Source:** https://themailx.com
- **Endpoint health:** reachable (last checked 2026-10-02T08:27:13.630Z, 6 samples) — uptime is not a security property and is not part of the trust score
- **Compatible clients:** claude-code, cursor, copilot, chatgpt, gemini (basis: transport)

## Trust

60/100 (B), scored on the content rubric
- Publisher verified: no
- Install scripts: nothing suspicious found
- Prompt-injection scan: clean
- Obfuscation scan: clean
- Evidence age: 38 days

## Security scan

- **Status:** clean
- **Scanned:** 2026-08-28T22:40:20.743Z
- **Version scanned:** live
- **CVEs:** no coverage — this entry has no package coordinates to query OSV against, so "no known CVEs" is NOT asserted for it.

## Tools

16 declared. Observed from a live `tools/list` probe.
- `spf_check` — Check if a domain has a valid SPF (Sender Policy Framework) DNS record. SPF specifies which mail servers are authorized to send email on behalf of a domain.
- `dkim_check` — Check if a domain has a valid DKIM (DomainKeys Identified Mail) DNS record for a given selector. DKIM allows the receiver to verify that an email was sent by th
- `dmarc_check` — Check if a domain has a valid DMARC (Domain-based Message Authentication, Reporting & Conformance) DNS record. DMARC tells receiving servers what to do with ema
- `bimi_check` — Check if a domain has a valid BIMI (Brand Indicators for Message Identification) DNS record. BIMI allows brands to display their logo next to authenticated emai
- `dmarc_generate` — Generate a DMARC DNS record for a domain. Returns the record name, value, and type ready to be added to DNS.
- `spf_generate` — Generate an SPF DNS record for a domain based on the email provider being used. Returns the record name, value, and type ready to be added to DNS.
- `smtp_check` — Test an SMTP server connection by attempting to connect and authenticate. If from_email and to_email are provided, the tool may attempt to send a test email. On
- `imap_check` — Test an IMAP server connection by attempting to connect and authenticate. Use this to verify email receiving configuration.
- `smtp_finder` — Look up SMTP server settings (host, port, encryption) for a given email provider. Use this to find the correct SMTP configuration for services like Gmail, Outlo
- `imap_finder` — Look up IMAP server settings (host, port, encryption) for a given email provider. Use this to find the correct IMAP configuration for services like Gmail, Outlo
- `blacklist_check` — Check if a domain or IP address is listed in popular email blacklists (DNSBLs). Being blacklisted can severely impact email deliverability.
- `mx_lookup` — Look up MX (Mail Exchanger) records for a domain. Returns the mail servers and their priorities.
- `txt_lookup` — Look up all TXT records for a domain. TXT records contain SPF policies, domain verification tokens, DKIM keys, and other metadata.
- `cname_lookup` — Look up CNAME (Canonical Name) records for a domain. Shows where a hostname aliases to.
- `ptr_lookup` — Reverse DNS lookup. Find the hostname associated with an IP address. A valid PTR record is important for email sending reputation.
- `dns_lookup` — Look up all DNS records for a domain in one query. Returns A, AAAA, CNAME, MX, NS, TXT, and SOA records.

## Install

**Verdict: review** — Installable, but 2 things to check first: No CVE coverage: this entry has no npm/PyPI coordinates to query OSV against, so "no known vulnerabilities" is not a claim that can be made about it.
**Cautions** (coverage gaps and advisories — never blocking)
- No CVE coverage: this entry has no npm/PyPI coordinates to query OSV against, so "no known vulnerabilities" is not a claim that can be made about it.
- No publisher has proved control of this listing; it is indexed, not vouched for.
**Config** (claude-code):
```json
"{\n  \"mcpServers\": {\n    \"email-deliverability\": {\n      \"type\": \"http\",\n      \"url\": \"https://themailx.com/mcp\"\n    }\n  }\n}"
```

## Blast radius

Contained to moderate — no credential declaration found, from the publisher, the upstream registry, or the README. Known so far: runs on someone else's infrastructure; read-only tool surface.
- Floor 9, ceiling 27 (tier: unknown)
- `unknown` means the floor and ceiling land in different bands — not measured enough to name one. It does not mean low.
- This is impact, not likelihood. A high radius is not a defect: a filesystem server is supposed to write files. It is never part of the trust score.

## Machine-readable views of this entry

- Signed JSON: https://forgeregistry.com/api/v1/packages/com.themailx%2Femail-deliverability
- Install plan: https://forgeregistry.com/api/v1/packages/com.themailx%2Femail-deliverability/install-plan
- Alternatives: https://forgeregistry.com/api/v1/alternatives/com.themailx%2Femail-deliverability
- HTML page: https://forgeregistry.com/registry/com.themailx%2Femail-deliverability
- MCP: POST https://forgeregistry.com/api/mcp → `forge_get_package` / `forge_install_plan`

## About this document

Generated by Forge (https://forgeregistry.com) — a compact rendering of the same record served, signed, at the JSON URL above. Trust and scan facts are the registry's own measurements; anything Forge did not measure is named as unmeasured rather than omitted.
