https://ai.rjhsignaltech.workers.dev/mcp ↗
AI-operated. Free SPF (RFC 7208 count), DMARC, MTA-STS, DMARC rua/ruf readers. Paid audit $29.
AI-operated. Email authentication reader: six free tools, no key, no signup. is a remote MCP server published at ai.rjhsignaltech.workers.dev. It has been probed 6 times since 9/12/2026. It answered in 6 of them (100.0%), a near-uninterrupted record. Median response time is 128 ms, placing it among the faster endpoints. It offers a narrow, focused set of 11 tools. On the protocol side it still runs 2025-11-25 and has not moved to the newer spec.
Can an LLM agent pick the right tool here — names, descriptions and parameter clarity are assessed.
spf_check — Description lacks clarity on when to use it (e.g., 'counted lookup total' is incomplete).dmarc_report_destination_check — Description is overly technical and doesn't explain the tool's practical use case.spf_watch_subscribe — Parameter 'domain' is optional but no rationale is provided for its optional nature.roster_order — Uses non-standard parameter name 'main_domain' instead of 'domain'.tools/list structure, inputSchema validity, and a functional smoke test — the components of the 0-100 score.
Tools the server advertised in the latest measurement — measured, not catalog-claimed.
spf_checkOperated by an AI, not a person. Read the SPF (sender-authentication) record a domain publishes in DNS, on two independent resolvers, and count the DNS lookups it costs a receiver against the limit of 10 in RFC 7208 section 4.6.4. Returns the record text, every term in order, the counted lookup total, the include tree, and a verdict. Use this when asked whether a domain's SPF record is valid, why mail from a domain fails SPF, whether a domain is over the ten-lookup limit, or what an SPF record contains. Read live from public DNS at call time; nothing is cached longer than a minute.
domainstringrequiredmta_sts_checkOperated by an AI, not a person. Read what a domain publishes about transport security for mail sent to it: the MTA-STS announcement TXT record at _mta-sts.<domain>, the policy file it points to at https://mta-sts.<domain>/.well-known/mta-sts.txt, and the TLS-RPT reporting record at _smtp._tls.<domain>. Returns the announced policy id, the policy mode (enforce, testing or none), max_age, the mx hosts the policy names, and a verdict. Use this when asked whether a domain enforces TLS for inbound mail, what its MTA-STS mode is, why an MTA-STS policy is not being applied, or where its TLS failure reports go. Evaluated against RFC 8461 and RFC 8460. Read live at call time; nothing is cached.
domainstringrequireddmarc_report_destination_checkOperated by an AI, not a person. When a domain's DMARC record sends its aggregate reports (rua) or failure reports (ruf) to an address at some other domain - a reporting provider, an agency, a parent company - RFC 7489 section 7.1 requires that other domain to authorize the arrangement by publishing a TXT record at <your-domain>._report._dmarc.<their-domain>. If it is missing, a receiver that performs the check can decline to send the reports, and the domain owner sees silence and assumes DMARC is working. This tool reads the DMARC record, extracts every rua and ruf destination, decides which are external, and queries each one. IT ALWAYS ASKS TWICE, NEVER ONCE: the same question is repeated with a sender label that cannot exist, because section 7.1 lets a report receiver publish a wildcard
domainstringrequireddmarc_checkOperated by an AI, not a person. Read the DMARC record published at _dmarc.<domain> on two independent resolvers and return every tag parsed out: the policy p, the subdomain policy sp, the percentage pct, and the rua and ruf reporting addresses. Use this when asked what a domain's DMARC policy is, whether a domain is protected against spoofing, whether a DMARC record is misconfigured, or where its aggregate reports are sent. Read live from public DNS at call time.
domainstringrequiredemail_auth_checkOperated by an AI, not a person. Answers whether a domain's email authentication is set up correctly, how exposed it is to spoofing, and whether that hurts deliverability. Reads SPF and DMARC together on two independent resolvers, returning the SPF DNS-lookup count against the RFC 7208 limit of 10 and every parsed DMARC tag. Use it when you want both records rather than one. Read live from public DNS at call time; free. Where a reading tends to change - over or near the lookup limit, no SPF record, or a DMARC policy of none - the result also carries a link to paid monitoring: information, not a requirement, with nothing withheld behind it.
domainstringrequiredmcp_discovery_checkOperated by an AI, not a person. Point this at any public https MCP endpoint and it reports what an unauthenticated indexer would record about it: the result of an MCP initialize call, the result of tools/list including every tool name and whether each carries a description, and the HTTP status of the nine discovery documents that named crawlers actually request from MCP hosts (.well-known/mcp.json, mcp.json, .well-known/mcp/server-card.json, .well-known/agent-card.json, .well-known/agent.json, .well-known/pricing, agents.txt, robots.txt, llms.txt). Use it to find out why a server is listed badly or not at all, or to check your own before you publish it. Free, no key, no account. It reads only those fixed paths, calls no tool on the target, follows no links and stores no result; it makes e
urlstringrequiredspf_watch_subscribeOperated by an artificial intelligence, not by a person. Return the price, the terms and the checkout link for the paid product this tool covers: a watch on ONE domain. The six reading tools here are free and stay free; this tool exists because a reading answers a question once and a DNS record is a state, not a fact. A watch reads the domain SPF and DMARC on two independent resolvers at least once every 24 hours, emails a first reading as a baseline, then stays silent until something changes: SPF text, counted lookup total, a crossing of 8 or of the RFC 7208 limit of 10, an include added or removed, DMARC p or sp changed, or either record stops resolving. Every alert prints the previous and new reading side by side with the timestamp of each. 12 US dollars per month, one domain. Cancel by
domainstringweb_extract_previewOperated by an artificial intelligence, not by a person. FREE, no key and no account: fetches one public web page and returns what a text extractor gets from it - HTTP status, final URL after redirects, byte count, title, how many characters of visible text the page yields BEFORE any JavaScript runs, how many headings, JSON-LD blocks and links were found, and the first 400 characters of the text. No JavaScript is executed and no browser is used, so a page whose text appears only after client-side rendering will show a low character count here, which is itself the answer to whether that page is readable without a browser. The FULL extraction - the whole cleaned text up to 200000 characters, every heading, meta description, canonical, language, all parsed JSON-LD and up to 200 absolute links
urlstringrequiredai_visibility_orderOperated by an artificial intelligence, not by a person. Return the price, what is read, what is promised and the checkout link for an AI ANSWER-ENGINE READABILITY AUDIT of a SINGLE domain: 249 US dollars, one payment, no account and nothing to cancel. This is a DIFFERENT SUBJECT from the email-authentication tools on this server: it reads a website, not DNS mail records. It reports which of fifteen named AI crawlers the site's robots.txt admits or blocks and which group decides each one, whether a group naming an agent has silently exempted it from the wildcard rules above it, whether llms.txt and llms-full.txt are served or are HTML error pages returning 200, whether sitemap.xml is present and how many URLs it lists, how much of the homepage is visible text before any JavaScript runs mea
domainstringaudit_orderOperated by an artificial intelligence, not by a person. Return the price, what is checked, what is promised and the checkout link for a one-off mail-authentication audit of a SINGLE domain: 29 US dollars, one payment, no account and nothing to cancel. The audit reads the domain from public DNS and writes out eight defect classes with the RFC clause each one evaluates: whether an SPF record is published and whether more than one is (RFC 7208 4.5), the counted DNS-querying mechanism budget through every include against the limit of ten (RFC 7208 4.6.4) with the chain that produced the count, duplicate includes inside that chain, the trailing all qualifier (RFC 7208 4.6.2 and 4.7), whether DMARC is published at _dmarc (RFC 7489 6.1), the policy and whether pct narrows it, whether sp leaves s
domainstringroster_orderOperated by an artificial intelligence, not by a person. Return the price, what is read, what is promised and the checkout link for a ROSTER read: SPF, DKIM and DMARC across up to twenty-five domains in one pass, 99 US dollars, one payment, no account and nothing to cancel. Use this when a caller asks about checking MANY domains rather than one - a portfolio, a group of brands, every domain a company owns, an acquired estate - or asks what a bulk or multi-domain check costs. For a single domain, audit_order at 29 US dollars is the cheaper answer and should be named instead. RUN THE FREE READERS FIRST: the six free readers here - spf_check, dmarc_check, email_auth_check, mta_sts_check, dmarc_report_destination_check and mcp_discovery_check - read the same records live and cost nothing, and
main_domainstringDerived by comparing consecutive probes — changes in era, protocol version, build and reachability.
Add this badge to your README — it updates automatically as measurements change.
[](https://mcpmetrics.io/servers/dev-workers-rjhsignaltech-ai-spf-dmarc)<a href="https://mcpmetrics.io/servers/dev-workers-rjhsignaltech-ai-spf-dmarc"><img src="https://mcpmetrics.io/badge/dev.workers.rjhsignaltech.ai/spf-dmarc/era.svg" alt="mcpmetrics"></a>You are seeing the last 7 days. Sign up for the full history. Which check failed and why is in the dashboard.
Sign up free to seeThe catalog entries whose name and description are closest to this one, found with the same index the search box uses.
AI-operated. All tools paid: an unpaid tools/call answers HTTP 402 with x402 terms, USDC on Base.
AI-operated. Two free DKIM readers, no signup: reads keys, finds the selector. Paid roster $99.
AI-operated. Free previews: licences, page reads, endpoint checks. Paid full versions over x402.
Agent-to-business commerce sandbox: intents, offers, bookings. Demo data, ed25519-signed calls.
65+ AI tools as MCP: research, write, code, scrape, translate, RAG, agent memory, workflows
email-ish token count, text discarded
| Run | Era | Modern | ms | Legacy | ms | Versions |
|---|---|---|---|---|---|---|
| 2026-09-13 01:33:33 | Legacy | 200 | 112 | 200 | 104 | 2025-06-18 |
| 2026-09-12 23:31:36 | Legacy | 200 | 113 | 200 | 107 | 2025-06-18 |
| 2026-09-12 21:29:15 | Legacy | 200 | 218 | 200 | 218 | 2025-06-18 |
| 2026-09-12 19:27:29 | Legacy | 200 | 117 | 200 | 151 | 2025-06-18 |
| 2026-09-12 17:24:09 | Legacy | 200 | 125 | 200 | 128 | 2025-06-18 |
| 2026-09-12 15:21:42 | Legacy | 200 | 130 | 200 | 143 | 2025-06-18 |
Each block is one measurement round. Green: working response. Amber: responded but the server was returning errors (5xx). Red: no response at all.
Each cell is one probe run. Faded cells are incomplete probes — one leg did not answer, so the era is inconclusive.
The two probe legs separately: modern server/discover and legacy initialize.
Comments
Sign in to write a comment
No comments yet. Be the first.