Parse-DMARC MCP Server provides tools to query and analyze DMARC aggregate reports. It exposes DMARC report data and analysis tools to MCP clients like Claude.
The parse-dmarc server presents 9 well-named, read-only tools with clear verb-noun naming (get_*, parse_*). All tools have descriptions (average ~120 chars, within baseline 194-char median). Input schemas are visible and typed in internal/mcp/tools.go. However, several critical gaps reduce quality: (1) No tool annotations (readOnlyHint, etc.) despite all tools being read-only, this is a missed opportunity for the MCP protocol. (2) Output schemas are defined as Go structs but not formally documented in the tool definitions; LLMs must infer expected fields. (3) Error handling is minimal, handlers return fmt.Errorf() with no recovery guidance. (4) Parameter descriptions are terse (6-15 chars avg for limit/offset/id); they lack constraint details (e.g., 'limit must be 1-100'). (5) No per-tool output schema documentation visible in the registration code. The tools are functionally sound and follow good naming conventions, but lack production-grade hardening.
Get DKIM (DomainKeys Identified Mail) authentication result statistics. Shows counts for each result type (pass, fail, none, etc.).
Get DMARC compliance statistics grouped by domain. Shows total messages, compliant messages, and compliance rate for each domain.
Get report counts grouped by reporting organization (e.g., Google, Microsoft, Yahoo). Helps understand which email providers are sending DMARC reports.
Get full details of a specific DMARC report by its database ID. Returns the complete parsed report including all records and authentication results.
List DMARC reports with pagination. Returns report summaries including ID, organization, domain, date range, message counts, and compliance rate.
Get SPF (Sender Policy Framework) authentication result statistics. Shows counts for each result type (pass, fail, softfail, neutral, etc.).
No tool annotations (readOnlyHint, destructiveHint, idempotentHint) declared. All 9 tools are read-only and would benefit from explicit readOnlyHint annotation to signal to agents that these tools are safe to call speculatively.
Output schemas not formally documented in tool registration. Go struct definitions exist (StatisticsOutput, ReportsOutput, etc.) in internal/mcp/tools.go but are not included in the tool schema passed to MCP. LLMs cannot predict output fields without seeing the schema.
Inferred effective spec: <=2025-11-25.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | C | 65 | <=2025-11-25 | v2 |
Get overall DMARC compliance statistics including total reports, messages, compliance rate, unique source IPs, and unique domains.
Get the top sending IP addresses ranked by message count. Shows pass/fail breakdown for each IP to help identify potential spoofing sources.
Parse a raw DMARC aggregate report from XML data. Accepts gzip, zip, or plain XML. The report_data should be base64 encoded. Returns the parsed report structure.
Parameter descriptions lack constraint details. 'limit' is described as 'maximum number of results to return (default: 50)' but does not state the range (is it 1-100? 1-10000?). 'id' states 'the database ID of the report to retrieve' but does not clarify if it is required or optional.
Minimal error handling. Tool handlers return fmt.Errorf() with generic messages ('failed to get statistics') that do not guide the LLM on recovery (e.g., 'Database connection failed. Retry after 10 seconds.' or 'No reports found matching the query.').
parse_dmarc_report accepts raw report_data as base64. No validation is visible in the handler on whether the decoded data is valid XML/gzip/zip or whether it actually contains a DMARC report. Malformed input triggers an unguided error.