PowerDMARC MCP Server: Connect Your AI to Your DMARC Data

Your DMARC data, just a question away.

Called dmarc_aggregate_per_sending_source Live data

0sources

sending mail as powerdmarc.com

Same prompt. Different intelligence.

WITHOUT POWERDMARC MCP
WITH POWERDMARC MCP
Email security audit, powerdmarc.com
audit powerdmarc.com's email security, which domains are spoofable and what should our DMARC policy actually be?

General guidance on DMARC posture

Honest take, without access to your actual DMARC reports I can only walk you through the standard playbook. The typical recommendation is to start at p=none, monitor for a few weeks, then move toward p=quarantine and eventually p=reject.

For SPF, you'll want to stay under the 10 DNS lookup limit, and your DKIM keys should be at least 1024-bit (ideally 2048). BIMI requires a VMC and prior DMARC enforcement.

I don't have visibility into powerdmarc.com's actual sending sources, current policy, alignment failures, or any spoofing attempts targeting your subdomains, so I can't tell you which domains are spoofable.

Reply...
Opus 4.7 Extended
Email security audit, powerdmarc.com
audit powerdmarc.com's email security, which domains are spoofable and what should our DMARC policy actually be?
Called powerdmarc:get_domains() Live data

Domain portfolio

12 domains, 30-day window

Domain Score Spoofing (30d) Policy Status
powerdmarc.com621,284p=noneMonitor
mail.powerdmarc.com388,917no recordSpoofable
powerdmarc-billing.com2914,602no recordSpoofable
support.powerdmarc.com71312p=quarantinePartial
marketing.powerdmarc.com442,108p=noneSpoofable
powerdmarc.io940p=rejectEnforced

Three domains are actively spoofable right now, mail.powerdmarc.com, powerdmarc-billing.com, and marketing.powerdmarc.com. Combined, they absorbed ~25,600 spoofing attempts in the last 30 days...

Ask about a domain, recommend a policy, or generate a fix...
Opus 4.7 Extended

What Is the PowerDMARC MCP Server?

The PowerDMARC MCP server is a Model Context Protocol server that connects an AI assistant like Claude, Cursor, or any MCP-compatible client directly to your PowerDMARC account. Once connected, you can query DMARC aggregate reports, manage domains, and run DNS lookups in plain English, with read and write access to your own data.

The Model Context Protocol (MCP) acts as a standardized bridge between AI models and your external tools or datasets. While many of the best DMARC MCP servers offer only read-only access to view basic metrics, the PowerDMARC MCP server goes a step further by providing full read and write capabilities. This means your AI assistant isn’t just analyzing your email authentication posture; it can actively help you manage your domains, generate records, and update configurations directly from your chat interface.

"Audit yourdomain.com's email security. Which domains are spoofable, and what should our DMARC policy actually be?"
13 DNS lookups in the SPF record
marketing.yourdomain.comp=none
mail.yourdomain.comp=reject
staging.yourdomain.comp=quarantine

What can you ask your AI?

Three categories of questions, every one answered with live data from your PowerDMARC account. No dashboards, no XML.

01 · See

Get visibility

"List all my domains and their current DMARC policies."

Instant portfolio view, every domain with its policy, score, and enforcement status.

"Who is sending email as my domain right now?"

Full map of authorized senders, unknown sources, volumes, and authentication rates over 30 days.

"Where in the world is my email being reported from?"

DMARC reports grouped by country, including any geographic anomalies worth investigating.

02 · Diagnose

Find problems

"Show me who tried to spoof my domain this week."

Forensic failure data, every attacker source, attempt count, and authentication outcome.

"Audit my SPF record, am I under the 10 lookup limit?"

Validates SPF syntax, counts DNS lookups, flags PermError risk before it breaks your delivery.

"What's the health score across all my domains?"

Weighted score across SPF, DKIM, and DMARC alignment, with the weak spots called out.

03 · Fix

Take action

"Generate a DMARC record with quarantine policy."

DNS-ready record built to your specification, copy-paste into your registrar and you're live.

"Look up the DMARC record for any domain."

DNS lookups across 14 record types plus WHOIS, all from a single natural-language question.

"Add a new domain to my account and set it to monitor."

Create the domain, generate the policy record, and start collecting reports without leaving your AI.

All tools at your AI's fingertips

Every tool listed below is live in the PowerDMARC MCP server. Ask questions the way you'd ask a colleague, and get live data back from your account.

DMARC Reports
Query aggregate and forensic DMARC report data across any date range, grouped by country, host, org, result, or sending source.
Available tools
  • dmarc_aggregate_detailed_stats Full stats for a date range
  • dmarc_aggregate_per_country Grouped by country
  • dmarc_aggregate_per_host Per sending host
  • dmarc_aggregate_per_org Per reporting org
  • dmarc_aggregate_per_result Pass/fail breakdown
  • dmarc_aggregate_per_sending_source Per source IP
  • dmarc_forensic_data Forensic failure reports
Domain Health and Management
Get health scores, authentication status, mail volume history, and manage domains in your account.
Available tools
  • domain_health Health score and auth status
  • mail_volume_history Historical mail volume
  • dkim_analytics DKIM analytics
  • list_domains List all domains
  • get_domain Details for a domain
  • create_domain Register a new domain
  • delete_domain Remove a domain
DNS Lookups
Look up any DNS record type including A, AAAA, MX, TXT, SPF, DMARC, PTR, NS, CNAME, and WHOIS.
Available tools
  • dns_lookup A, AAAA, MX, TXT, SPF, DMARC, PTR, NS, CNAME
  • whois_lookup WHOIS registration info
Supported record types
AAAAAMXTXTNSCNAMESPFDMARCPTRWHOIS
Record Generators
Generate valid DMARC, SPF, and DKIM records on demand, plus analyze raw email headers to diagnose delivery issues.
Available tools
  • generate_dmarc_record Generate a DMARC TXT record
  • generate_spf_record Generate an SPF record
  • generate_dkim_record Generate a DKIM public key
  • analyze_email_header Diagnose raw email headers
Hosted Records
Query and manage your hosted DMARC, SPF, DKIM, BIMI, and MTA-STS records directly from your AI.
Available tools
  • get_hosted_dmarc Hosted DMARC record
  • get_hosted_spf Hosted SPF record
  • get_dkim_selectors DKIM selectors
  • get_hosted_bimi Hosted BIMI record
  • get_mta_sts_policy MTA-STS policy
MSSP Partner Tools Partners only
Manage all your client accounts, members, and domain groups directly from your AI assistant.
Available tools
  • mssp_list_accounts List all sub-accounts
  • mssp_list_members List members of a sub-account
  • mssp_create_member Add a user to a sub-account
  • mssp_delete_member Remove a user
  • mssp_domain_groups Manage domain groups
Audit Logs and Forensics
Pull account activity records and dig into forensic failure reports for any failed message.
Available tools
  • get_audit_logs Account activity, logins, config changes
  • dmarc_forensic_data Failure reports for individual messages

Here is exactly what your AI can execute on your behalf:

Function Name What it does Access Level
get_domain_health Retrieves health scores, authentication status, and mail volume history. Read
manage_domains Add, update, or remove domains in your PowerDMARC account. Write
dns_lookup Look up any DNS record type, including A, AAAA, MX, TXT, SPF, DMARC, PTR, NS, CNAME, and WHOIS. Read
generate_dmarc_record Generate a valid DMARC TXT record on demand. Read
generate_spf_record Generate a valid SPF record on demand. Read
generate_dkim_record Generate a DKIM public key. Read
analyze_email_header Analyze raw email headers to diagnose delivery issues. Read
manage_hosted_records Query and update your hosted DMARC, SPF, DKIM, BIMI, and MTA-STS records. Read/Write
manage_client_accounts Manage all client accounts, members, and domain groups. Read/Write
get_forensic_reports Pull account activity records and dig into forensic failure reports for failed messages. Read

For developers looking to integrate these endpoints outside of an MCP client, refer to our complete DMARC API documentation.

How to connect your AI in 3 steps

PowerDMARC hosts the MCP server for you. Just grab your token, pick your AI client, and you’re done.

Using PowerDMARC through a partner or reseller? Your config snippet is pre-filled and ready to copy from your portal. Head to the MCP Tab in your dashboard to get it.

1
Get your API token

Go to API Settings in your PowerDMARC dashboard and generate or copy your token.

2
Connect your AI client

Pick your AI client below. Some support one-click UI setup, others need a quick config snippet.

3
Test the connection

Ask your AI: “Check my DMARC setup.” If you see live data, you’re connected.

Requirements and Supported AI Clients

To utilize the PowerDMARC MCP server, you must have an active PowerDMARC account. Access to the MCP server requires a valid API key, which is available on our paid enterprise plans and our MCP server for MSPs (multi-tenant) tier. 

Generate a dedicated API key from your PowerDMARC dashboard to authenticate the client. Rate limits vary by plan and API quota.

Select Your AI Client

Config file location
Configuration snippet
json
 

How the PowerDMARC MCP Server Handles Access and Permissions

Connecting AI to your infrastructure requires strong security controls. As explained in our guide on malicious MCP servers, the PowerDMARC MCP server uses secure API keys and strict permissions to limit access. Each API key is tied to the permissions of the user who generated it, so the AI can only access authorized domains, client accounts, and features. For MSPs and enterprises, this helps keep cross-tenant data isolated.

You can revoke access at any time by deleting or regenerating the API key from your PowerDMARC dashboard.

Frequently Asked Questions

Do I need to know how to code?
No. Most popular AI clients like Claude and Cursor let you add MCP servers directly through their settings UI. For others, it is a simple copy-paste of a config snippet. No terminal skills required.
What data does my AI get access to?
Only the data tied to your API token permissions. Your AI cannot access anything outside your account scope. You control the token, you control the access.
Does it work with ChatGPT?
Yes, it works with ChatGPT and any other AI assistant that supports the Model Context Protocol. If your client has an MCP config file, it works with PowerDMARC.
Is there a usage limit?
Standard plans include up to 60 tool calls per minute, which is more than enough for interactive use. Enterprise customers can request higher rate limits.
What is a DMARC MCP server?
A DMARC MCP (Model Context Protocol) server is a bridge that connects an AI assistant to your email authentication data. It translates your plain-English prompts into secure API calls, allowing the AI to read your DMARC reports, diagnose DNS issues, and manage your domain security posture natively.
Which AI assistants work with PowerDMARC's MCP server?
Our MCP server officially supports Claude Desktop and Cursor. However, because it is built on the open Model Context Protocol standard, it is compatible with any modern AI assistant or IDE that supports integrating third-party MCP servers.
Is the PowerDMARC MCP server read-only?
No, it provides both read and write capabilities. While many alternatives only allow you to view data, the PowerDMARC MCP server empowers your AI to actively manage domains, update hosted records (like SPF, DKIM, and DMARC), and manage client accounts.
Is it safe to connect an AI assistant to my DMARC data?
Yes. The connection is secured via a scoped API key generated from your account. The AI can only access the data and domains that your specific user role is permitted to see, and you can instantly revoke access at any time by deleting the API key.
Do I need a paid PowerDMARC plan to use the MCP server?
Yes, connecting an AI assistant requires API access. This feature requires an API key, which is available to users on our paid enterprise tiers and our multi-tenant MSP plans. Rate limits correspond to your plan's API quota.

Ready to Connect Your AI?

Stop context-switching. Start asking.

Connect your AI to PowerDMARC in under two minutes and query your email security data the way you already work.