Server definition
- Hash
- sha256:33b295b9437714d12454adf04e6bd7dcc9fd5d0be4fa3646942e38fd97d3a7b2
- What it is
- What a remote MCP server returned when asked what it offers: 28 tools
The blob, as servednamed by its sha256
{
"instructions": "InboxGuard tools cover deliverability scanning AND the authenticated product end to end. Deliverability scanning: scan_domain (renders an interactive scorecard ui://inboxguard/scan-result), get_deliverability_score, check_blocklists, analyze_headers (re-verify SPF/DKIM/DMARC/ARC on a raw email), scan_domains_batch + get_scan_job (async batch of up to 50). Every tools/call requires an API-key bearer token — for a keyless one-off scan, POST to the REST endpoint /scan-domain (5/hour per IP). With an API key, scans run at the org's plan tier and auto-track the domain; account tools: list_domains, get_domain, remove_domain, list_scans, list_alerts, resolve_alert, get_dmarc_summary, list_registrar_connections, create_notification_channel, create_share_link. Detect-and-fix loop: scan_domain → get_dns_fix_plan → apply_dns_fix → re-scan. Reputation feeds: connect_snds → get_snds_status → get_snds_ip_stats (Microsoft SNDS per-IP Outlook/Hotmail reputation). Inbox-placement: connect_inbox_placement → start_inbox_placement_test (returns seed addresses to mail) → get_inbox_placement_test (Inbox/Spam/Missing verdict). Reporting: get_deliverability_report → a domain's score, per-check status, top issues, and a PDF download URL. Portfolio: get_portfolio → org-wide rollup (avg score, grade distribution, domains needing attention, per-client-group breakdown). Discovery is open; tools/call needs an API-key bearer token (https://inboxguard.io/auth.md). Docs: https://inboxguard.io/llms-full.txt",
"tools": [
{
"description": "Re-verify SPF, DKIM, DMARC, and ARC from a raw RFC 5322 email (full message or just the headers block). Returns InboxGuard's independent verdict (`ours`), the sender's own Authentication-Results (`theirs`), whether they `agree`, and parsed envelope/headers — useful for spotting forged or mismatched auth results. No account needed.",
"inputSchema": {
"properties": {
"helo": {
"description": "Optional: the SMTP HELO/EHLO domain.",
"type": "string"
},
"mailFrom": {
"description": "Optional: the envelope MAIL FROM (return-path) address.",
"type": "string"
},
"message": {
"description": "The raw email — full RFC 5322 message, or at least the headers block (Received, Authentication-Results, DKIM-Signature, From, …).",
"minLength": 50,
"type": "string"
},
"senderIp": {
"description": "Optional: connecting IP to evaluate SPF against (overrides the IP parsed from Received headers).",
"type": "string"
}
},
"required": [
"message"
],
"type": "object"
},
"name": "analyze_headers",
"outputSchema": null
},
{
"description": "Apply a DNS fix plan to a tracked domain by publishing records at the connected registrar. DESTRUCTIVE: it creates/updates/deletes DNS records. Two-step by design — first call get_dns_fix_plan, then pass its `connectionId` and `ops` here verbatim. The server re-derives the diff from the latest scan and rejects any op that no longer matches, so an agent can never apply arbitrary records. Requires an owner/admin API key with write or full scope. Re-scan afterward to confirm the fix.",
"inputSchema": {
"properties": {
"connectionId": {
"description": "The connectionId from get_dns_fix_plan.",
"format": "uuid",
"type": "string"
},
"domain": {
"description": "Domain name tracked in the account, e.g. example.com.",
"type": "string"
},
"ops": {
"description": "The `ops` array from get_dns_fix_plan, passed verbatim. The server validates each op against a freshly recomputed diff before executing.",
"items": {
"type": "object"
},
"type": "array"
}
},
"required": [
"domain",
"connectionId",
"ops"
],
"type": "object"
},
"name": "apply_dns_fix",
"outputSchema": null
},
{
"description": "Check a domain (apex + MX-host IPs) against supported DNS blocklists and return listings, targets checked, and issues (authoritative-side queries; no public-resolver false positives).",
"inputSchema": {
"properties": {
"domain": {
"description": "Domain to check, e.g. example.com.",
"type": "string"
}
},
"required": [
"domain"
],
"type": "object"
},
"name": "check_blocklists",
"outputSchema": null
},
{
"description": "Store the org's seed-list inbox-placement provider + API key (provider: 'mailreach' or 'glockapps'; GlockApps also needs projectId). Enables start_inbox_placement_test. Requires an owner/admin API key with write or full scope.",
"inputSchema": {
"properties": {
"apiKey": {
"description": "The vendor API key.",
"type": "string"
},
"projectId": {
"description": "GlockApps project id (required for provider=glockapps).",
"type": "string"
},
"provider": {
"description": "Inbox-placement vendor.",
"enum": [
"mailreach",
"glockapps"
],
"type": "string"
}
},
"required": [
"provider",
"apiKey"
],
"type": "object"
},
"name": "connect_inbox_placement",
"outputSchema": null
},
{
"description": "Store this org's Microsoft SNDS (Smart Network Data Services) automated-data-access key so InboxGuard syncs per-IP Outlook/Hotmail reputation daily. Get the key from the SNDS Automated Data Access page (https://sendersupport.olc.protection.outlook.com/snds/). Requires an owner/admin API key with write or full scope. Data appears within ~24h of the first sync.",
"inputSchema": {
"properties": {
"key": {
"description": "The SNDS access key from the SNDS Automated Data Access page.",
"type": "string"
},
"label": {
"description": "Optional label, e.g. \"prod sending IPs\".",
"type": "string"
}
},
"required": [
"key"
],
"type": "object"
},
"name": "connect_snds",
"outputSchema": null
},
{
"description": "Create a channel that InboxGuard alerts are delivered to: webhook (HMAC-signed), Slack, Microsoft Teams, PagerDuty, SMS, or email. Returns the channel id, and for kind=webhook the `signing_secret` used to verify deliveries. Requires an owner/admin API key with write or full scope.",
"inputSchema": {
"properties": {
"displayName": {
"description": "Optional label for the channel.",
"type": "string"
},
"kind": {
"description": "Channel type.",
"enum": [
"webhook",
"slack",
"teams",
"pagerduty",
"sms",
"email"
],
"type": "string"
},
"severityFilter": {
"description": "Which alert severities to deliver (default [\"critical\",\"warn\"]).",
"items": {
"enum": [
"info",
"warn",
"critical"
],
"type": "string"
},
"type": "array"
},
"target": {
"description": "Destination matching `kind`: the webhook/Slack/Teams URL, PagerDuty integration key, phone number (E.164), or email address.",
"type": "string"
}
},
"required": [
"kind",
"target"
],
"type": "object"
},
"name": "create_notification_channel",
"outputSchema": null
},
{
"description": "Create a read-only public share link for a tracked domain's latest report (anyone with the URL can view it; no account). Returns a `token` and the public `url` (https://inboxguard.io/r/<token>). Requires an owner/admin API key with write or full scope, on a plan that includes public reports.",
"inputSchema": {
"properties": {
"domain": {
"description": "Domain name tracked in the account, e.g. example.com.",
"type": "string"
}
},
"required": [
"domain"
],
"type": "object"
},
"name": "create_share_link",
"outputSchema": null
},
{
"description": "Return a structured deliverability report for a tracked domain: the latest score + letter grade + `scoreSubtitle` (explains the denominator when a check was excluded, e.g. \"80/100 · scored on 65 of 83 applicable points · 1 check unverified\"), each check's status (pass/warn/fail/unverified/not_applicable — `not_applicable` means the check doesn't apply to this domain and `unverified` means it couldn't be checked this scan; neither is a failure), the top issues to fix, blocklist count, and DMARC policy. Includes `pdfUrl` — the same auth-gated endpoint that returns a branded one-page PDF (send your bearer token). Use this to summarize a domain's posture or hand a client a report.",
"inputSchema": {
"properties": {
"domain": {
"description": "Domain name tracked in the account, e.g. example.com.",
"type": "string"
}
},
"required": [
"domain"
],
"type": "object"
},
"name": "get_deliverability_report",
"outputSchema": null
},
{
"description": "Return the overall deliverability score and letter grade for a domain (runs a fresh scan).",
"inputSchema": {
"properties": {
"domain": {
"description": "Domain to score, e.g. example.com.",
"type": "string"
}
},
"required": [
"domain"
],
"type": "object"
},
"name": "get_deliverability_score",
"outputSchema": null
},
{
"description": "Summarize ingested DMARC aggregate (RUA) reports for a domain tracked in your InboxGuard account: report volume, pass rate, top sending sources, and the rua inbox to publish. The domain must already be added to the account, and the plan must include DMARC ingest.",
"inputSchema": {
"properties": {
"days": {
"description": "Lookback window in days (default 30, max 90).",
"maximum": 90,
"minimum": 1,
"type": "integer"
},
"domain": {
"description": "Domain name tracked in the account, e.g. example.com.",
"type": "string"
}
},
"required": [
"domain"
],
"type": "object"
},
"name": "get_dmarc_summary",
"outputSchema": null
},
{
"description": "Compute the exact DNS-record changes needed to fix a tracked domain's deliverability, based on its latest scan and the org's connected registrar (Cloudflare/Route 53/GoDaddy/Namecheap). Read-only — nothing changes. Returns the `ops` to pass verbatim to apply_dns_fix, plus `manualReview` items that need a human decision (SPF sender list, DKIM keys, BIMI logo). Requires the domain to be tracked, a scan to exist, and a registrar connection covering the zone.",
"inputSchema": {
"properties": {
"domain": {
"description": "Domain name tracked in the account, e.g. example.com.",
"type": "string"
}
},
"required": [
"domain"
],
"type": "object"
},
"name": "get_dns_fix_plan",
"outputSchema": null
},
{
"description": "Full detail for one tracked domain: the domain record, the latest scan with all per-check findings (spf, dmarc, dkim, ptr, mta_sts, tls_rpt, mx_tls, blocklist), recent score history, open/recent alerts, and Google Postmaster stats when connected.",
"inputSchema": {
"properties": {
"domain": {
"description": "Domain name as tracked in the account, e.g. example.com.",
"type": "string"
}
},
"required": [
"domain"
],
"type": "object"
},
"name": "get_domain",
"outputSchema": null
},
{
"description": "Report whether a seed-list inbox-placement provider is connected for the org, which provider, and how many tests have run. Lists the supported providers when not connected.",
"inputSchema": {
"properties": {},
"type": "object"
},
"name": "get_inbox_placement_status",
"outputSchema": null
},
{
"description": "Poll a seed-list inbox-placement test by testId. Returns status (running/completed/failed) and, once measured, the Inbox/Spam/Missing counts and inbox-placement score (0–100). Call after sending your campaign to the seed addresses from start_inbox_placement_test.",
"inputSchema": {
"properties": {
"testId": {
"description": "The testId returned by start_inbox_placement_test.",
"format": "uuid",
"type": "string"
}
},
"required": [
"testId"
],
"type": "object"
},
"name": "get_inbox_placement_test",
"outputSchema": null
},
{
"description": "Org-wide deliverability rollup across every monitored domain: average score + overall grade, the grade distribution (how many domains are A/B/C/D/F/unscored), total open alerts, the domains needing attention (lowest score / open alerts first), and a per-client-group breakdown. Use this for an at-a-glance portfolio health summary across an agency or multi-domain account.",
"inputSchema": {
"properties": {},
"type": "object"
},
"name": "get_portfolio",
"outputSchema": null
},
{
"description": "Poll an async batch scan started with scan_domains_batch: returns status (queued/running/succeeded/partial/failed), completed count, and per-domain results (domain, ok, score, grade) as they finish.",
"inputSchema": {
"properties": {
"jobId": {
"description": "The jobId returned by scan_domains_batch.",
"format": "uuid",
"type": "string"
}
},
"required": [
"jobId"
],
"type": "object"
},
"name": "get_scan_job",
"outputSchema": null
},
{
"description": "Return the latest per-IP reputation from Microsoft SNDS for the org's sending IPs: filter result (GREEN/YELLOW/RED), complaint-rate band, spam-trap hits, message volume, and current block status. Requires SNDS to be connected (see connect_snds / get_snds_status).",
"inputSchema": {
"properties": {},
"type": "object"
},
"name": "get_snds_ip_stats",
"outputSchema": null
},
{
"description": "Report whether Microsoft SNDS is connected for the org, the last sync time + status, how many sending IPs are tracked, and how many are currently blocked by Outlook/Hotmail. Use before get_snds_ip_stats to confirm the integration is live.",
"inputSchema": {
"properties": {},
"type": "object"
},
"name": "get_snds_status",
"outputSchema": null
},
{
"description": "List the account's deliverability alerts (score drops, check failures, blocklist listings). Defaults to open alerts only.",
"inputSchema": {
"properties": {
"limit": {
"description": "Max alerts to return (default 50).",
"maximum": 200,
"minimum": 1,
"type": "integer"
},
"resolved": {
"description": "'false' = open alerts only (default), 'true' = resolved only, 'all' = both.",
"enum": [
"false",
"true",
"all"
],
"type": "string"
},
"severity": {
"description": "Filter by severity (default 'all').",
"enum": [
"critical",
"warn",
"info",
"all"
],
"type": "string"
}
},
"type": "object"
},
"name": "list_alerts",
"outputSchema": null
},
{
"description": "List the account's tracked domains with latest scan score, last scan time, and open alert count.",
"inputSchema": {
"properties": {},
"type": "object"
},
"name": "list_domains",
"outputSchema": null
},
{
"description": "List recent seed-list inbox-placement tests for the org (most recent first) with their status and Inbox/Spam/Missing scores.",
"inputSchema": {
"properties": {},
"type": "object"
},
"name": "list_inbox_placement_tests",
"outputSchema": null
},
{
"description": "List the registrar accounts (Cloudflare, Route 53, GoDaddy, Namecheap) connected to the org — provider, verification, last-used time — plus the supported providers. Use this to check whether the detect-and-fix loop (get_dns_fix_plan / apply_dns_fix) is available before attempting it.",
"inputSchema": {
"properties": {},
"type": "object"
},
"name": "list_registrar_connections",
"outputSchema": null
},
{
"description": "List recent scans (id, domain, run time, score) across all tracked domains, or for one domain when a name is given.",
"inputSchema": {
"properties": {
"domain": {
"description": "Optional: restrict to one tracked domain by name, e.g. example.com. Omit for all domains.",
"type": "string"
},
"limit": {
"description": "Max scans to return (default 20).",
"maximum": 100,
"minimum": 1,
"type": "integer"
}
},
"type": "object"
},
"name": "list_scans",
"outputSchema": null
},
{
"description": "Stop monitoring a domain and delete it (and its scan history) from the account. DESTRUCTIVE and not reversible. Requires an owner/admin API key with write or full scope. (To ADD a domain, run scan_domain with this API key — authenticated scans auto-track the domain.)",
"inputSchema": {
"properties": {
"domain": {
"description": "Domain name tracked in the account, e.g. example.com.",
"type": "string"
}
},
"required": [
"domain"
],
"type": "object"
},
"name": "remove_domain",
"outputSchema": null
},
{
"description": "Mark an alert resolved (or reopen it with resolved=false). Requires an API key with write/full scope. Resolving an already-resolved alert is a no-op.",
"inputSchema": {
"properties": {
"alertId": {
"description": "Alert UUID, from list_alerts or get_domain.",
"format": "uuid",
"type": "string"
},
"resolved": {
"description": "true (default) marks the alert resolved; false reopens it.",
"type": "boolean"
}
},
"required": [
"alertId"
],
"type": "object"
},
"name": "resolve_alert",
"outputSchema": null
},
{
"description": "Run a full email-deliverability scan (SPF, DKIM, DMARC, MTA-STS, TLS-RPT, MX TLS, BIMI, DNS blocklists) for a domain and return a 0-100 score with per-check findings. A check can come back `not_applicable` (does not apply to this domain, e.g. MTA-STS on a domain with no MX — excluded from the score, not a failure) or `unverified` (could not be determined this scan, e.g. DKIM behind an ESP with a random per-tenant selector like Amazon SES Easy DKIM — never treat as a failure). `scoreSubtitle` explains the denominator when anything was excluded. Runs at your plan tier (full blocklist set on paid plans) and saves the scan to the domain history in your account.",
"inputSchema": {
"properties": {
"dkimSelectors": {
"description": "Optional DKIM selectors to probe.",
"items": {
"type": "string"
},
"type": "array"
},
"domain": {
"description": "Domain to scan, e.g. example.com.",
"type": "string"
}
},
"required": [
"domain"
],
"type": "object"
},
"name": "scan_domain",
"outputSchema": null
},
{
"description": "Queue an asynchronous batch scan of up to 50 domains and get a jobId immediately (avoids the 30s per-call limit). Poll get_scan_job with the jobId until status is succeeded/partial/failed to read per-domain scores. Requires an API key with write or full scope. These scans are NOT added to monitoring or saved to history.",
"inputSchema": {
"properties": {
"domains": {
"description": "1-50 domains to scan, e.g. [\"example.com\",\"acme.com\"].",
"items": {
"type": "string"
},
"maxItems": 50,
"minItems": 1,
"type": "array"
}
},
"required": [
"domains"
],
"type": "object"
},
"name": "scan_domains_batch",
"outputSchema": null
},
{
"description": "Start a seed-list inbox-placement test. Returns a testId, the seed addresses to mail your campaign to, and (if the provider requires it) a header to insert. After sending to the seeds, poll get_inbox_placement_test for the Inbox/Spam/Missing verdict. Requires inbox-placement to be connected and an owner/admin API key with write or full scope.",
"inputSchema": {
"properties": {
"subject": {
"description": "Optional subject line to associate with the test.",
"type": "string"
}
},
"type": "object"
},
"name": "start_inbox_placement_test",
"outputSchema": null
}
]
}Verify it yourself
curl -s https://api.teppi.xyz/v1/evidence/sha256:33b295b9437714d12454adf04e6bd7dcc9fd5d0be4fa3646942e38fd97d3a7b2 | sha256sum