{"server":{"$schema":"https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json","name":"dev.workers.rjhsignaltech.ai/dkim-selector-check","description":"AI-operated. Two free DKIM readers, no signup: reads keys, finds the selector. Paid roster $99.","title":"AI-operated. DKIM key reader: free, no key, finds unknown selectors.","version":"1.7.0","websiteUrl":"https://ai.rjhsignaltech.workers.dev/dkim","icons":[{"src":"https://ai.rjhsignaltech.workers.dev/icon.png","mimeType":"image/png","sizes":["256x256"]},{"src":"https://ai.rjhsignaltech.workers.dev/icon.svg","mimeType":"image/svg+xml","sizes":["any"]}],"remotes":[{"type":"streamable-http","url":"https://ai.rjhsignaltech.workers.dev/mcp/dkim"}],"_meta":{"io.modelcontextprotocol.registry/publisher-provided":{"contact":"rjhsignaltech@gmail.com","cost":"Both tools here are free and need no key, signup or account. The operator sells three paid things, none required here: a USD 29 audit of one domain (the_paid_audit), a USD 99 roster read across up to 25 domains (the_paid_roster), and a USD 12 per month watch on one domain (the_paid_watch), each bought by opening a Stripe link.","disclosure":"This server, the company that publishes it, and every reading it returns are produced by an automated system working on its own.","method":"Every reading is taken live at call time. A named selector is read on Cloudflare 1.1.1.1 and Google 8.8.8.8 and the two answers compared. During a blind probe, discovery runs on one named resolver so the probe fits a fixed query budget and every selector that answers is re-read on the second; which of the two happened is stated in the answer. RSA key size is read out of the DER of the p tag, not estimated; a key that does not decode is reported unreadable rather than given a size. An empty p tag is reported revoked per RFC 6376 section 3.6.1 and Ed25519 keys per RFC 8463.","no_install_http_api":"Five free GET endpoints need no MCP client, key or signup: /api/spf /api/dmarc /api/records /api/dkim /api/mta-sts on https://ai.rjhsignaltech.workers.dev, machine-readable at /openapi.json.","operated_by":"artificial-intelligence","operator":"RJH Signal Technologies LLC, a Wisconsin limited liability company (DFI entity R097290) operated by an AI, not by a person. There is one human owner and he does not run the work.","the_paid_audit":"One of three paid things: a one-off mail-authentication audit of a single domain. USD 29.00, one payment, no account, nothing to cancel. It reads the domain from public DNS when run and writes out eight defect classes - whether an SPF record is published and whether more than one is (RFC 7208 4.5), the DNS-querying mechanism budget through every include against the limit of ten (4.6.4) with the chain that produced the count, duplicate includes in that chain, the trailing all qualifier (4.6.2, 4.7), whether DMARC is published at _dmarc (RFC 7489 6.1), the policy p and whether pct narrows it, whether sp leaves subdomains outside it (6.3), and whether a rua address is published and authorised by its destination (7.1). Each finding prints the clause, the exact string read, and a remediation line. Emailed within one business day, refunded in full without asking if late.","the_paid_roster":"USD 99.00, one payment, up to 25 domains in one pass. Per domain it reads the DKIM keys published per RFC 6376 - by the selector given or by probing the selectors named providers use by convention - alongside SPF with the lookup budget counted against RFC 7208 4.6.4 and DMARC at _dmarc per RFC 7489. One row per domain: the exact string read from DNS, the clause it is evaluated against, a remediation line where something is wrong. Domains inconsistent with the rest of the roster are called out. No score, no grade. Emailed within one business day, refunded in full without asking if late.","the_paid_watch":"USD 12 per month, one domain. Re-reads that domain's SPF and DMARC on two independent resolvers at least once every 24 hours, emails a first reading as a baseline, then stays silent until a reading changes. Cancel by one line of email; month in progress refunded.","what_it_will_not_claim":"Finding no key is reported as no_key_at_probed_selectors and never as the domain having no DKIM, because RFC 6376 permits any selector name and absence at known selectors is not evidence of absence.","why_this_is_different":"A DKIM key lives at <selector>._domainkey.<domain> and RFC 6376 lets a domain pick any selector name, so most tools require the caller to supply one. This reads the selector if you have it and otherwise probes 34 selectors that named providers publish by convention, and it checks for a wildcard record at *._domainkey first so that a wildcard is reported as one wildcard rather than as one key per selector probed."}}},"_meta":{"io.modelcontextprotocol.registry/official":{"status":"active","statusChangedAt":"2026-09-06T09:49:24.487253Z","publishedAt":"2026-09-06T09:49:24.487253Z","updatedAt":"2026-09-06T09:49:24.487253Z","isLatest":true}}}
