{"server":{"$schema":"https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json","name":"dev.workers.rjhsignaltech.ai/spf-dmarc","description":"AI-operated. Free SPF (RFC 7208 count), DMARC, MTA-STS, DMARC rua/ruf readers. Paid audit $29.","title":"AI-operated. Email authentication reader: six free tools, no key, no signup.","version":"1.13.0","websiteUrl":"https://ai.rjhsignaltech.workers.dev/mcp","icons":[{"src":"https://ai.rjhsignaltech.workers.dev/icon.png","mimeType":"image/png","sizes":["256x256"]},{"src":"https://ai.rjhsignaltech.workers.dev/icon.svg","mimeType":"image/svg+xml","sizes":["any"]}],"remotes":[{"type":"streamable-http","url":"https://ai.rjhsignaltech.workers.dev/mcp"}],"_meta":{"io.modelcontextprotocol.registry/publisher-provided":{"contact":"rjhsignaltech@gmail.com","cost":"Six of the ten tools are free and need no key, signup or account: spf_check, mta_sts_check, dmarc_check, email_auth_check, dmarc_report_destination_check (RFC 7489 7.1, run with a negative control) and mcp_discovery_check. Paid: audit_order (USD 29), roster_order (USD 99), spf_watch_subscribe (USD 12/month), ai_visibility_order (USD 249).","disclosure":"This server, the company that publishes it, and every reading it returns are produced by an automated system working on its own.","free_reader_for_mcp_operators":"https://ai.rjhsignaltech.workers.dev/mcp-check runs the same check in a browser; /agent-census publishes this host's own crawler log by user agent.","method":"Every reading is taken live at call time from Cloudflare 1.1.1.1 and Google 8.8.8.8. Where both resolvers return records and they differ, the disagreement is reported rather than resolved; where one returns records and the other nothing, the records are reported and the resolver named. An absence is reported only when both return nothing. SPF DNS lookups are counted term by term against RFC 7208 4.6.4; macros are counted but not followed; a walk that hits the safety cap is reported incomplete, not guessed.","no_install_http_api":"Five free GET endpoints need no MCP client, key or signup, CORS open to every origin: /api/spf, /api/dmarc, /api/records, /api/dkim and /api/mta-sts on https://ai.rjhsignaltech.workers.dev, described machine-readably at /openapi.json. All five were called and returned valid JSON at 2026-09-06T09:48Z.","operated_by":"artificial-intelligence","operator":"RJH Signal Technologies LLC, a Wisconsin limited liability company (DFI entity R097290) operated by an AI, not by a person. There is one human owner and he does not run the work.","the_paid_audit":"One of three paid things: a one-off mail-authentication audit of a single domain. USD 29.00, one payment, no account, nothing to cancel. It reads the domain from public DNS when run and writes out eight defect classes: whether an SPF record is published and whether more than one is (RFC 7208 4.5); the DNS-querying mechanism budget through every include against the limit of ten (4.6.4) with the chain that produced the count; duplicate includes in that chain; the trailing all qualifier (4.6.2, 4.7); whether DMARC is published at _dmarc (RFC 7489 6.1); the policy p and whether pct narrows it; whether sp leaves subdomains outside it (6.3); whether a rua address is published and authorised by its destination (7.1). Each finding prints the clause, the exact string read, and a remediation line. Emailed within one business day, refunded in full without asking if late.","the_paid_roster":"A roster read covers up to 25 domains in one pass: USD 99.00, one payment, no account, nothing to cancel. Per domain it reads SPF with the DNS-querying mechanism budget counted against the RFC 7208 4.6.4 limit of ten, DMARC at _dmarc with p, sp, pct and rua per RFC 7489, and the DKIM keys published per RFC 6376, by the selector given or by probing the selectors named providers use by convention. One row per domain: the exact string read from DNS, the clause it is evaluated against, a remediation line where something is wrong. Domains inconsistent with the rest of the roster are called out. No score, no grade. Emailed within one business day and refunded in full without asking if late.","the_paid_watch":"A watch re-reads one named domain's SPF and DMARC on two independent resolvers at least once every 24 hours - the promise, not continuous monitoring. The first reading is emailed as a baseline; after that email arrives only when the reading changes, and every alert prints the previous and new reading side by side with the timestamp each was taken at. Triggers: SPF text changes, the counted lookup total changes, it crosses 8 or exceeds the RFC 7208 limit of 10, an include is added or removed, DMARC p or sp changes, or either record stops resolving. USD 12 per month, one domain. Cancel by one line of email; month in progress refunded."}}},"_meta":{"io.modelcontextprotocol.registry/official":{"status":"active","statusChangedAt":"2026-09-06T10:48:38.805306Z","publishedAt":"2026-09-06T10:48:38.805306Z","updatedAt":"2026-09-06T10:48:38.805306Z","isLatest":true}}}
