Skip to main content
Glama

Email Security Posture

email_security_posture
Read-onlyIdempotent

Analyze domain email authentication posture: SPF, DMARC, DKIM with numeric score and findings. Dual-use: red-team (spoofing feasibility) + blue-team (posture audit). Score 0-100, grades A+-F. DKIM probing tests common selectors + recent dates; custom selectors must be supplied. Passive DNS-only; no SMTP probe. Free: 30/hr, Pro: 500/hr.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
domainYesDomain to audit email authentication posture for (e.g. 'example.com')
selectorsNoOptional comma-separated custom DKIM selectors to probe

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault
resultYes

Schema Changelog

Changes observed during successful MCP inspections. Dates show when Glama detected each change.

  1. Changed2 schema fields changed
    • changedOutput schema / properties / result / properties / next_calls / type
      Previous value: -"array"New value: +[
      +  "array",
      +  "null"
      +]
    • changedOutput schema / properties / result / properties / verdict / type
      Previous value: -"object"New value: +[
      +  "object",
      +  "null"
      +]
  2. Changed1 schema field changed
    • changedOutput schema / properties / result / properties / next_calls / type
      Previous value: -"object"New value: +"array"
  3. Changed1 schema field changed
    • changedOutput schema / (root)
      Previous value: -nullNew value: +{
      +  "properties": {
      +    "result": {
      +      "properties": {
      +        "all_findings": {
      +          "type": "array"
      +        },
      +        "dkim": {
      +          "type": "object"
      +        },
      +        "dmarc": {
      +          "type": "object"
      +        },
      +        "domain": {
      +          "type": "string"
      +        },
      +        "next_calls": {
      +          "type": "object"
      +        },
      +        "posture_grade": {
      +          "type": "string"
      +        },
      +        "posture_score": {
      +          "type": "integer"
      +        },
      +        "spf": {
      +          "type": "object"
      +        },
      +        "summary": {
      +          "type": "string"
      +        },
      +        "verdict": {
      +          "type": "object"
      +        }
      +      },
      +      "required": [
      +        "domain",
      +        "spf",
      +        "dmarc",
      +        "dkim",
      +        "posture_score",
      +        "posture_grade",
      +        "all_findings",
      +        "summary"
      +      ],
      +      "type": "object"
      +    }
      +  },
      +  "required": [
      +    "result"
      +  ],
      +  "type": "object"
      +}
  4. Changed1 schema field changed
    • changedOutput schema / (root)
      Previous value: -{
      -  "$defs": {
      -    "DkimPosture": {
      -      "properties": {
      -        "findings": {
      -          "items": {
      -            "$ref": "#/$defs/Finding"
      -          },
      -          "type": "array"
      -        },
      -        "status": {
      -          "enum": [
      -            "verified",
      -            "unverifiable"
      -          ],
      -          "type": "string"
      -        },
      -        "tested_selectors": {
      -          "items": {
      -            "type": "string"
      -          },
      -          "type": "array"
      -        },
      -        "verified_selectors": {
      -          "items": {
      -            "type": "string"
      -          },
      -          "type": "array"
      -        }
      -      },
      -      "required": [
      -        "status"
      -      ],
      -      "type": "object"
      -    },
      -    "DmarcPosture": {
      -      "properties": {
      -        "adkim": {
      -          "anyOf": [
      -            {
      -              "enum": [
      -                "s",
      -                "r"
      -              ],
      -              "type": "string"
      -            },
      -            {
      -              "type": "null"
      -            }
      -          ]
      -        },
      -        "aspf": {
      -          "anyOf": [
      -            {
      -              "enum": [
      -                "s",
      -                "r"
      -              ],
      -              "type": "string"
      -            },
      -            {
      -              "type": "null"
      -            }
      -          ]
      -        },
      -        "findings": {
      -          "items": {
      -            "$ref": "#/$defs/Finding"
      -          },
      -          "type": "array"
      -        },
      -        "fo": {
      -          "anyOf": [
      -            {
      -              "type": "string"
      -            },
      -            {
      -              "type": "null"
      -            }
      -          ]
      -        },
      -        "pct": {
      -          "anyOf": [
      -            {
      -              "type": "integer"
      -            },
      -            {
      -              "type": "null"
      -            }
      -          ]
      -        },
      -        "policy": {
      -          "anyOf": [
      -            {
      -              "enum": [
      -                "none",
      -                "quarantine",
      -                "reject"
      -              ],
      -              "type": "string"
      -            },
      -            {
      -              "type": "null"
      -            }
      -          ]
      -        },
      -        "present": {
      -          "type": "boolean"
      -        },
      -        "record": {
      -          "anyOf": [
      -            {
      -              "type": "string"
      -            },
      -            {
      -              "type": "null"
      -            }
      -          ]
      -        },
      -        "rua_uris": {
      -          "items": {
      -            "type": "string"
      -          },
      -          "type": "array"
      -        },
      -        "ruf_uris": {
      -          "items": {
      -            "type": "string"
      -          },
      -          "type": "array"
      -        },
      -        "subdomain_policy": {
      -          "anyOf": [
      -            {
      -              "enum": [
      -                "none",
      -                "quarantine",
      -                "reject"
      -              ],
      -              "type": "string"
      -            },
      -            {
      -              "type": "null"
      -            }
      -          ]
      -        }
      -      },
      -      "required": [
      -        "present"
      -      ],
      -      "type": "object"
      -    },
      -    "EmailSecurityPostureResponse": {
      -      "properties": {
      -        "all_findings": {
      -          "items": {
      -            "$ref": "#/$defs/Finding"
      -          },
      -          "type": "array"
      -        },
      -        "dkim": {
      -          "$ref": "#/$defs/DkimPosture"
      -        },
      -        "dmarc": {
      -          "$ref": "#/$defs/DmarcPosture"
      -        },
      -        "domain": {
      -          "type": "string"
      -        },
      -        "next_calls": {
      -          "anyOf": [
      -            {
      -              "items": {
      -                "$ref": "#/$defs/PivotHint"
      -              },
      -              "type": "array"
      -            },
      -            {
      -              "type": "null"
      -            }
      -          ]
      -        },
      -        "posture_grade": {
      -          "enum": [
      -            "A+",
      -            "A",
      -            "B",
      -            "C",
      -            "D",
      -            "F"
      -          ],
      -          "type": "string"
      -        },
      -        "posture_score": {
      -          "type": "integer"
      -        },
      -        "spf": {
      -          "$ref": "#/$defs/SpfPosture"
      -        },
      -        "summary": {
      -          "type": "string"
      -        },
      -        "verdict": {
      -          "anyOf": [
      -            {
      -              "$ref": "#/$defs/Verdict"
      -            },
      -            {
      -              "type": "null"
      -            }
      -          ]
      -        }
      -      },
      -      "required": [
      -        "domain",
      -        "spf",
      -        "dmarc",
      -        "dkim",
      -        "posture_score",
      -        "posture_grade",
      -        "all_findings",
      -        "summary"
      -      ],
      -      "type": "object"
      -    },
      -    "ErrorDetail": {
      -      "properties": {
      -        "code": {
      -          "enum": [
      -            "invalid_argument",
      -            "not_found",
      -            "rate_limit_exceeded",
      -            "auth_required",
      -            "tier_limit",
      -            "upstream_timeout",
      -            "upstream_error",
      -            "internal_error"
      -          ],
      -          "type": "string"
      -        },
      -        "docs_url": {
      -          "anyOf": [
      -            {
      -              "type": "string"
      -            },
      -            {
      -              "type": "null"
      -            }
      -          ]
      -        },
      -        "message": {
      -          "maxLength": 500,
      -          "type": "string"
      -        },
      -        "retry_after_seconds": {
      -          "anyOf": [
      -            {
      -              "type": "integer"
      -            },
      -            {
      -              "type": "null"
      -            }
      -          ]
      -        },
      -        "upgrade_url": {
      -          "anyOf": [
      -            {
      -              "type": "string"
      -            },
      -            {
      -              "type": "null"
      -            }
      -          ]
      -        }
      -      },
      -      "required": [
      -        "code",
      -        "message"
      -      ],
      -      "type": "object"
      -    },
      -    "ErrorResponse": {
      -      "properties": {
      -        "error": {
      -          "$ref": "#/$defs/ErrorDetail"
      -        }
      -      },
      -      "required": [
      -        "error"
      -      ],
      -      "type": "object"
      -    },
      -    "Finding": {
      -      "properties": {
      -        "check": {
      -          "type": "string"
      -        },
      -        "description": {
      -          "type": "string"
      -        },
      -        "fix_hint": {
      -          "type": "string"
      -        },
      -        "severity": {
      -          "enum": [
      -            "critical",
      -            "high",
      -            "medium",
      -            "low"
      -          ],
      -          "type": "string"
      -        },
      -        "status": {
      -          "enum": [
      -            "pass",
      -            "warn",
      -            "fail"
      -          ],
      -          "type": "string"
      -        }
      -      },
      -      "required": [
      -        "check",
      -        "status",
      -        "severity",
      -        "description",
      -        "fix_hint"
      -      ],
      -      "type": "object"
      -    },
      -    "PivotHint": {
      -      "additionalProperties": true,
      -      "properties": {
      -        "input": {
      -          "type": "string"
      -        },
      -        "params": {
      -          "anyOf": [
      -            {
      -              "additionalProperties": {
      -                "type": "string"
      -              },
      -              "type": "object"
      -            },
      -            {
      -              "type": "null"
      -            }
      -          ]
      -        },
      -        "reason": {
      -          "type": "string"
      -        },
      -        "tool": {
      -          "enum": [
      -            "cve_lookup",
      -            "cve_search",
      -            "cve_leading",
      -            "bulk_cve_lookup",
      -            "calculate_risk_score",
      -            "get_cvss_details",
      -            "exploit_lookup",
      -            "kev_detail",
      -            "cwe_lookup",
      -            "subdomain_enum",
      -            "ssl_check",
      -            "tech_fingerprint",
      -            "asn_lookup",
      -            "ip_lookup",
      -            "ioc_lookup",
      -            "bulk_ioc_lookup",
      -            "hash_lookup",
      -            "threat_intel",
      -            "threat_report",
      -            "audit_domain",
      -            "domain_report",
      -            "dns_lookup",
      -            "whois_lookup",
      -            "wayback_lookup",
      -            "scan_headers",
      -            "check_headers",
      -            "check_secrets",
      -            "check_injection",
      -            "check_dependencies",
      -            "email_mx",
      -            "email_security_posture",
      -            "email_disposable",
      -            "email_verify",
      -            "robots_txt",
      -            "redirect_chain",
      -            "brand_assets",
      -            "seo_audit",
      -            "phone_lookup",
      -            "username_lookup",
      -            "password_check",
      -            "phishing_check",
      -            "atlas_technique_lookup",
      -            "atlas_technique_search",
      -            "bulk_atlas_technique_lookup",
      -            "atlas_case_study_lookup",
      -            "atlas_case_study_search",
      -            "d3fend_defense_lookup",
      -            "d3fend_defense_search",
      -            "d3fend_defense_for_attack",
      -            "d3fend_attack_coverage",
      -            "sigma_rule_lookup",
      -            "bulk_sigma_rule_lookup",
      -            "tech_stack_cve_audit"
      -          ],
      -          "type": "string"
      -        }
      -      },
      -      "required": [
      -        "tool",
      -        "input",
      -        "reason"
      -      ],
      -      "type": "object"
      -    },
      -    "SpfMechanism": {
      -      "properties": {
      -        "qualifier": {
      -          "enum": [
      -            "+",
      -            "-",
      -            "~",
      -            "?"
      -          ],
      -          "type": "string"
      -        },
      -        "type": {
      -          "type": "string"
      -        },
      -        "value": {
      -          "type": "string"
      -        }
      -      },
      -      "required": [
      -        "type",
      -        "value",
      -        "qualifier"
      -      ],
      -      "type": "object"
      -    },
      -    "SpfPosture": {
      -      "properties": {
      -        "all_policy": {
      -          "anyOf": [
      -            {
      -              "enum": [
      -                "permissive",
      -                "soft_fail",
      -                "strict",
      -                "neutral"
      -              ],
      -              "type": "string"
      -            },
      -            {
      -              "type": "null"
      -            }
      -          ]
      -        },
      -        "findings": {
      -          "items": {
      -            "$ref": "#/$defs/Finding"
      -          },
      -          "type": "array"
      -        },
      -        "has_spf_all": {
      -          "type": "boolean"
      -        },
      -        "lookup_count": {
      -          "type": "integer"
      -        },
      -        "mechanisms": {
      -          "items": {
      -            "$ref": "#/$defs/SpfMechanism"
      -          },
      -          "type": "array"
      -        },
      -        "present": {
      -          "type": "boolean"
      -        },
      -        "record": {
      -          "anyOf": [
      -            {
      -              "type": "string"
      -            },
      -            {
      -              "type": "null"
      -            }
      -          ]
      -        },
      -        "redirect_target": {
      -          "anyOf": [
      -            {
      -              "type": "string"
      -            },
      -            {
      -              "type": "null"
      -            }
      -          ]
      -        }
      -      },
      -      "required": [
      -        "present",
      -        "lookup_count",
      -        "has_spf_all"
      -      ],
      -      "type": "object"
      -    },
      -    "Verdict": {
      -      "properties": {
      -        "completeness": {
      -          "enum": [
      -            "complete",
      -            "partial",
      -            "minimal"
      -          ],
      -          "type": "string"
      -        },
      -        "data_age_seconds": {
      -          "anyOf": [
      -            {
      -              "type": "integer"
      -            },
      -            {
      -              "type": "null"
      -            }
      -          ]
      -        },
      -        "deterministic": {
      -          "type": "boolean"
      -        },
      -        "falsifiable_fields": {
      -          "items": {
      -            "type": "string"
      -          },
      -          "type": "array"
      -        },
      -        "sources_queried": {
      -          "items": {
      -            "type": "string"
      -          },
      -          "type": "array"
      -        },
      -        "sources_unavailable": {
      -          "items": {
      -            "type": "string"
      -          },
      -          "type": "array"
      -        }
      -      },
      -      "required": [
      -        "deterministic"
      -      ],
      -      "type": "object"
      -    }
      -  },
      -  "properties": {
      -    "result": {
      -      "anyOf": [
      -        {
      -          "$ref": "#/$defs/EmailSecurityPostureResponse"
      -        },
      -        {
      -          "$ref": "#/$defs/ErrorResponse"
      -        }
      -      ]
      -    }
      -  },
      -  "required": [
      -    "result"
      -  ],
      -  "type": "object"
      -}New value: +null
  5. Changed136 schema fields changed
    • removedOutput schema / $defs / DkimPosture / description
      Removed value: -"DKIM posture — selector discovery and verification."
    • removedOutput schema / $defs / DkimPosture / properties / findings / title
      Removed value: -"Findings"
    • removedOutput schema / $defs / DkimPosture / properties / status / description
      Removed value: -"Verification status"
    • removedOutput schema / $defs / DkimPosture / properties / status / title
      Removed value: -"Status"
    • removedOutput schema / $defs / DkimPosture / properties / tested_selectors / description
      Removed value: -"All selectors probed"
    • removedOutput schema / $defs / DkimPosture / properties / tested_selectors / title
      Removed value: -"Tested Selectors"
    • removedOutput schema / $defs / DkimPosture / properties / verified_selectors / title
      Removed value: -"Verified Selectors"
    • removedOutput schema / $defs / DkimPosture / title
      Removed value: -"DkimPosture"
    • removedOutput schema / $defs / DmarcPosture / description
      Removed value: -"DMARC posture analysis."
    • removedOutput schema / $defs / DmarcPosture / properties / adkim / default
      Removed value: -null
    • removedOutput schema / $defs / DmarcPosture / properties / adkim / description
      Removed value: -"DKIM alignment mode"
    • removedOutput schema / $defs / DmarcPosture / properties / adkim / title
      Removed value: -"Adkim"
    • removedOutput schema / $defs / DmarcPosture / properties / aspf / default
      Removed value: -null
    • removedOutput schema / $defs / DmarcPosture / properties / aspf / description
      Removed value: -"SPF alignment mode"
    • removedOutput schema / $defs / DmarcPosture / properties / aspf / title
      Removed value: -"Aspf"
    • removedOutput schema / $defs / DmarcPosture / properties / findings / title
      Removed value: -"Findings"
    • removedOutput schema / $defs / DmarcPosture / properties / fo / default
      Removed value: -null
    • removedOutput schema / $defs / DmarcPosture / properties / fo / description
      Removed value: -"Failure reporting options"
    • removedOutput schema / $defs / DmarcPosture / properties / fo / title
      Removed value: -"Fo"
    • removedOutput schema / $defs / DmarcPosture / properties / pct / default
      Removed value: -null
    • removedOutput schema / $defs / DmarcPosture / properties / pct / description
      Removed value: -"Rollout percentage"
    • removedOutput schema / $defs / DmarcPosture / properties / pct / title
      Removed value: -"Pct"
    • removedOutput schema / $defs / DmarcPosture / properties / policy / default
      Removed value: -null
    • removedOutput schema / $defs / DmarcPosture / properties / policy / title
      Removed value: -"Policy"
    • removedOutput schema / $defs / DmarcPosture / properties / present / description
      Removed value: -"DMARC record exists"
    • removedOutput schema / $defs / DmarcPosture / properties / present / title
      Removed value: -"Present"
    • removedOutput schema / $defs / DmarcPosture / properties / record / default
      Removed value: -null
    • removedOutput schema / $defs / DmarcPosture / properties / record / title
      Removed value: -"Record"
    • removedOutput schema / $defs / DmarcPosture / properties / rua_uris / description
      Removed value: -"Aggregate report URIs"
    • removedOutput schema / $defs / DmarcPosture / properties / rua_uris / title
      Removed value: -"Rua Uris"
    • removedOutput schema / $defs / DmarcPosture / properties / ruf_uris / description
      Removed value: -"Forensic report URIs"
    • removedOutput schema / $defs / DmarcPosture / properties / ruf_uris / title
      Removed value: -"Ruf Uris"
    • removedOutput schema / $defs / DmarcPosture / properties / subdomain_policy / default
      Removed value: -null
    • removedOutput schema / $defs / DmarcPosture / properties / subdomain_policy / title
      Removed value: -"Subdomain Policy"
    • removedOutput schema / $defs / DmarcPosture / title
      Removed value: -"DmarcPosture"
    • removedOutput schema / $defs / EmailSecurityPostureResponse / description
      Removed value: -"Email authentication posture: SPF + DMARC + DKIM with score and findings."
    • removedOutput schema / $defs / EmailSecurityPostureResponse / properties / all_findings / description
      Removed value: -"Flattened findings"
    • removedOutput schema / $defs / EmailSecurityPostureResponse / properties / all_findings / title
      Removed value: -"All Findings"
    • removedOutput schema / $defs / EmailSecurityPostureResponse / properties / dkim / description
      Removed value: -"DKIM posture"
    • removedOutput schema / $defs / EmailSecurityPostureResponse / properties / dmarc / description
      Removed value: -"DMARC posture"
    • removedOutput schema / $defs / EmailSecurityPostureResponse / properties / domain / description
      Removed value: -"Domain analyzed"
    • removedOutput schema / $defs / EmailSecurityPostureResponse / properties / domain / title
      Removed value: -"Domain"
    • removedOutput schema / $defs / EmailSecurityPostureResponse / properties / next_calls / default
      Removed value: -null
    • removedOutput schema / $defs / EmailSecurityPostureResponse / properties / next_calls / description
      Removed value: -"Suggested follow-up MCP tool calls. Ordered by relevance; agents should chain these without re-prompting the user."
    • removedOutput schema / $defs / EmailSecurityPostureResponse / properties / next_calls / title
      Removed value: -"Next Calls"
    • removedOutput schema / $defs / EmailSecurityPostureResponse / properties / posture_grade / description
      Removed value: -"Grade A+-F"
    • removedOutput schema / $defs / EmailSecurityPostureResponse / properties / posture_grade / title
      Removed value: -"Posture Grade"
    • removedOutput schema / $defs / EmailSecurityPostureResponse / properties / posture_score / description
      Removed value: -"Score 0-100"
    • removedOutput schema / $defs / EmailSecurityPostureResponse / properties / posture_score / title
      Removed value: -"Posture Score"
    • removedOutput schema / $defs / EmailSecurityPostureResponse / properties / spf / description
      Removed value: -"SPF posture"
    • removedOutput schema / $defs / EmailSecurityPostureResponse / properties / summary / description
      Removed value: -"Summary"
    • removedOutput schema / $defs / EmailSecurityPostureResponse / properties / summary / title
      Removed value: -"Summary"
    • removedOutput schema / $defs / EmailSecurityPostureResponse / properties / verdict / default
      Removed value: -null
    • removedOutput schema / $defs / EmailSecurityPostureResponse / properties / verdict / description
      Removed value: -"Falsifiability metadata: sources_queried, sources_unavailable, completeness, deterministic flag. Lets agents distinguish 'no data' from 'source failed' without re-running the call."
    • removedOutput schema / $defs / EmailSecurityPostureResponse / title
      Removed value: -"EmailSecurityPostureResponse"
    • removedOutput schema / $defs / ErrorDetail / description
      Removed value: -"Structured failure body. Codes mirror app/exceptions.AppException\nsubclasses; agent retry / upgrade decisions key off `code`, not `message`."
    • removedOutput schema / $defs / ErrorDetail / properties / code / description
      Removed value: -"Stable machine-readable failure category. Agents key retry/upgrade decisions off this."
    • removedOutput schema / $defs / ErrorDetail / properties / code / title
      Removed value: -"Code"
    • removedOutput schema / $defs / ErrorDetail / properties / docs_url / default
      Removed value: -null
    • removedOutput schema / $defs / ErrorDetail / properties / docs_url / description
      Removed value: -"Documentation pointer (e.g. tool input contract) when code='invalid_argument'."
    • removedOutput schema / $defs / ErrorDetail / properties / docs_url / title
      Removed value: -"Docs Url"
    • removedOutput schema / $defs / ErrorDetail / properties / message / description
      Removed value: -"Human-readable detail. Free text — never parse. Capped at 500 chars to prevent oversized upstream errors from bloating responses."
    • removedOutput schema / $defs / ErrorDetail / properties / message / title
      Removed value: -"Message"
    • removedOutput schema / $defs / ErrorDetail / properties / retry_after_seconds / default
      Removed value: -null
    • removedOutput schema / $defs / ErrorDetail / properties / retry_after_seconds / description
      Removed value: -"When code='rate_limit_exceeded', the minimum seconds to wait before retrying."
    • removedOutput schema / $defs / ErrorDetail / properties / retry_after_seconds / title
      Removed value: -"Retry After Seconds"
    • removedOutput schema / $defs / ErrorDetail / properties / upgrade_url / default
      Removed value: -null
    • removedOutput schema / $defs / ErrorDetail / properties / upgrade_url / description
      Removed value: -"Pricing/upgrade URL when code='tier_limit' or 'rate_limit_exceeded' on the Free tier."
    • removedOutput schema / $defs / ErrorDetail / properties / upgrade_url / title
      Removed value: -"Upgrade Url"
    • removedOutput schema / $defs / ErrorDetail / title
      Removed value: -"ErrorDetail"
    • removedOutput schema / $defs / ErrorResponse / description
      Removed value: -"MCP error envelope. Tool return type is always\n`SpecificResponse | ErrorResponse` — Union flag tells the agent which arm\narrived without parsing the inner body."
    • removedOutput schema / $defs / ErrorResponse / title
      Removed value: -"ErrorResponse"
    • removedOutput schema / $defs / Finding / description
      Removed value: -"Discrete audit finding."
    • removedOutput schema / $defs / Finding / properties / check / description
      Removed value: -"What was checked"
    • removedOutput schema / $defs / Finding / properties / check / title
      Removed value: -"Check"
    • removedOutput schema / $defs / Finding / properties / description / description
      Removed value: -"Finding description"
    • removedOutput schema / $defs / Finding / properties / description / title
      Removed value: -"Description"
    • removedOutput schema / $defs / Finding / properties / fix_hint / description
      Removed value: -"Remediation hint"
    • removedOutput schema / $defs / Finding / properties / fix_hint / title
      Removed value: -"Fix Hint"
    • removedOutput schema / $defs / Finding / properties / severity / description
      Removed value: -"Severity"
    • removedOutput schema / $defs / Finding / properties / severity / title
      Removed value: -"Severity"
    • removedOutput schema / $defs / Finding / properties / status / description
      Removed value: -"Outcome"
    • removedOutput schema / $defs / Finding / properties / status / title
      Removed value: -"Status"
    • removedOutput schema / $defs / Finding / title
      Removed value: -"Finding"
    • removedOutput schema / $defs / PivotHint / description
      Removed value: -"A suggested follow-up MCP tool call. Surfaced inside response.next_calls so\nLLM agents can chain related lookups without manual prompting. Each hint names\nthe tool, the input value to pass, and a short reason explaining why this\npivot adds value in the current context."
    • removedOutput schema / $defs / PivotHint / properties / input / description
      Removed value: -"Suggested input value to pass to the tool — typically a CVE ID, CWE ID, domain, or IP. Pre-populated from the current response so the agent can call the next tool without re-deriving the argument."
    • removedOutput schema / $defs / PivotHint / properties / input / title
      Removed value: -"Input"
    • removedOutput schema / $defs / PivotHint / properties / params / default
      Removed value: -null
    • removedOutput schema / $defs / PivotHint / properties / params / description
      Removed value: -"Optional extra kwargs to pass alongside `input`. Used by pivot generators when the next call benefits from a secondary parameter, e.g. {'exclude_id': 'AML.T0051'} to skip the originating technique from a sibling-tactic search. Omitted when no extra args are needed."
    • removedOutput schema / $defs / PivotHint / properties / params / title
      Removed value: -"Params"
    • removedOutput schema / $defs / PivotHint / properties / reason / description
      Removed value: -"Short rationale (one sentence) for why this follow-up call adds value, e.g. 'Federal patch deadline + ransomware association', 'Public exploits / PoC availability'."
    • removedOutput schema / $defs / PivotHint / properties / reason / title
      Removed value: -"Reason"
    • removedOutput schema / $defs / PivotHint / properties / tool / description
      Removed value: -"Canonical MCP tool name to call next. Constrained to known operation_ids in tools/list — adding a new tool here requires expanding the Literal."
    • removedOutput schema / $defs / PivotHint / properties / tool / title
      Removed value: -"Tool"
    • removedOutput schema / $defs / PivotHint / title
      Removed value: -"PivotHint"
    • removedOutput schema / $defs / SpfMechanism / description
      Removed value: -"Single SPF mechanism (a, mx, include, ip4, ip6, ptr, exists, redirect)."
    • removedOutput schema / $defs / SpfMechanism / properties / qualifier / description
      Removed value: -"Qualifier: + (pass), - (fail), ~ (softfail), ? (neutral)"
    • removedOutput schema / $defs / SpfMechanism / properties / qualifier / title
      Removed value: -"Qualifier"
    • removedOutput schema / $defs / SpfMechanism / properties / type / description
      Removed value: -"Mechanism type"
    • removedOutput schema / $defs / SpfMechanism / properties / type / title
      Removed value: -"Type"
    • removedOutput schema / $defs / SpfMechanism / properties / value / description
      Removed value: -"Mechanism value"
    • removedOutput schema / $defs / SpfMechanism / properties / value / title
      Removed value: -"Value"
    • removedOutput schema / $defs / SpfMechanism / title
      Removed value: -"SpfMechanism"
    • removedOutput schema / $defs / SpfPosture / description
      Removed value: -"SPF posture analysis."
    • removedOutput schema / $defs / SpfPosture / properties / all_policy / default
      Removed value: -null
    • removedOutput schema / $defs / SpfPosture / properties / all_policy / title
      Removed value: -"All Policy"
    • removedOutput schema / $defs / SpfPosture / properties / findings / title
      Removed value: -"Findings"
    • removedOutput schema / $defs / SpfPosture / properties / has_spf_all / description
      Removed value: -"Has 'all' mechanism"
    • removedOutput schema / $defs / SpfPosture / properties / has_spf_all / title
      Removed value: -"Has Spf All"
    • removedOutput schema / $defs / SpfPosture / properties / lookup_count / description
      Removed value: -"DNS lookups needed"
    • removedOutput schema / $defs / SpfPosture / properties / lookup_count / title
      Removed value: -"Lookup Count"
    • removedOutput schema / $defs / SpfPosture / properties / mechanisms / title
      Removed value: -"Mechanisms"
    • removedOutput schema / $defs / SpfPosture / properties / present / description
      Removed value: -"SPF record exists"
    • removedOutput schema / $defs / SpfPosture / properties / present / title
      Removed value: -"Present"
    • removedOutput schema / $defs / SpfPosture / properties / record / default
      Removed value: -null
    • removedOutput schema / $defs / SpfPosture / properties / record / title
      Removed value: -"Record"
    • removedOutput schema / $defs / SpfPosture / properties / redirect_target / default
      Removed value: -null
    • removedOutput schema / $defs / SpfPosture / properties / redirect_target / title
      Removed value: -"Redirect Target"
    • removedOutput schema / $defs / SpfPosture / title
      Removed value: -"SpfPosture"
    • removedOutput schema / $defs / Verdict / properties / completeness / default
      Removed value: -"complete"
    • removedOutput schema / $defs / Verdict / properties / completeness / description
      Removed value: -"'complete' = every planned source returned data; 'partial' = at least one source in sources_unavailable failed or was skipped; 'minimal' = only the primary/required source returned, optional enrichment missing."
    • removedOutput schema / $defs / Verdict / properties / completeness / title
      Removed value: -"Completeness"
    • removedOutput schema / $defs / Verdict / properties / data_age_seconds / default
      Removed value: -null
    • removedOutput schema / $defs / Verdict / properties / data_age_seconds / description
      Removed value: -"Seconds elapsed since the oldest cached source was fetched, or null when every source was queried live for this request. Use to judge freshness."
    • removedOutput schema / $defs / Verdict / properties / data_age_seconds / title
      Removed value: -"Data Age Seconds"
    • removedOutput schema / $defs / Verdict / properties / deterministic / description
      Removed value: -"True when the response is fully reproducible from the listed sources for the same input at the same moment (no randomness, no model inference). False for endpoints that include probabilistic scoring or LLM output."
    • removedOutput schema / $defs / Verdict / properties / deterministic / title
      Removed value: -"Deterministic"
    • removedOutput schema / $defs / Verdict / properties / falsifiable_fields / description
      Removed value: -"Top-level response fields whose values a caller can independently re-derive from the named upstream sources (e.g. 'dns', 'ssl', 'whois'). Fields not in this list are derived/computed and cannot be directly re-verified."
    • removedOutput schema / $defs / Verdict / properties / falsifiable_fields / title
      Removed value: -"Falsifiable Fields"
    • removedOutput schema / $defs / Verdict / properties / sources_queried / description
      Removed value: -"Canonical source identifiers successfully consulted for this response (e.g. 'ripe_stat', 'shodan_internetdb', 'firehol'). Agent-readable list, order not significant."
    • removedOutput schema / $defs / Verdict / properties / sources_queried / title
      Removed value: -"Sources Queried"
    • removedOutput schema / $defs / Verdict / properties / sources_unavailable / description
      Removed value: -"Sources that were expected but not returned — either intentionally skipped (lite mode, tier gating) or failed (quota, timeout, upstream down). Empty list means every planned source produced data."
    • removedOutput schema / $defs / Verdict / properties / sources_unavailable / title
      Removed value: -"Sources Unavailable"
    • removedOutput schema / $defs / Verdict / title
      Removed value: -"Verdict"
    • removedOutput schema / properties / result / title
      Removed value: -"Result"
    • removedOutput schema / title
      Removed value: -"email_security_postureOutput"
  6. Changed1 schema field changed
    • changedOutput schema / $defs / PivotHint / properties / tool / enum
      Previous value: -[
      -  "cve_lookup",
      -  "cve_search",
      -  "cve_leading",
      -  "bulk_cve_lookup",
      -  "calculate_risk_score",
      -  "get_cvss_details",
      -  "exploit_lookup",
      -  "kev_detail",
      -  "cwe_lookup",
      -  "subdomain_enum",
      -  "ssl_check",
      -  "tech_fingerprint",
      -  "asn_lookup",
      -  "ip_lookup",
      -  "ioc_lookup",
      -  "bulk_ioc_lookup",
      -  "hash_lookup",
      -  "threat_intel",
      -  "threat_report",
      -  "audit_domain",
      -  "domain_report",
      -  "dns_lookup",
      -  "whois_lookup",
      -  "wayback_lookup",
      -  "scan_headers",
      -  "check_headers",
      -  "check_secrets",
      -  "check_injection",
      -  "check_dependencies",
      -  "email_mx",
      -  "email_security_posture",
      -  "email_disposable",
      -  "email_verify",
      -  "robots_txt",
      -  "redirect_chain",
      -  "brand_assets",
      -  "seo_audit",
      -  "phone_lookup",
      -  "username_lookup",
      -  "password_check",
      -  "phishing_check",
      -  "atlas_technique_lookup",
      -  "atlas_technique_search",
      -  "bulk_atlas_technique_lookup",
      -  "atlas_case_study_lookup",
      -  "atlas_case_study_search",
      -  "d3fend_defense_lookup",
      -  "d3fend_defense_search",
      -  "d3fend_defense_for_attack",
      -  "d3fend_attack_coverage",
      -  "sigma_rule_lookup",
      -  "bulk_sigma_rule_lookup"
      -]New value: +[
      +  "cve_lookup",
      +  "cve_search",
      +  "cve_leading",
      +  "bulk_cve_lookup",
      +  "calculate_risk_score",
      +  "get_cvss_details",
      +  "exploit_lookup",
      +  "kev_detail",
      +  "cwe_lookup",
      +  "subdomain_enum",
      +  "ssl_check",
      +  "tech_fingerprint",
      +  "asn_lookup",
      +  "ip_lookup",
      +  "ioc_lookup",
      +  "bulk_ioc_lookup",
      +  "hash_lookup",
      +  "threat_intel",
      +  "threat_report",
      +  "audit_domain",
      +  "domain_report",
      +  "dns_lookup",
      +  "whois_lookup",
      +  "wayback_lookup",
      +  "scan_headers",
      +  "check_headers",
      +  "check_secrets",
      +  "check_injection",
      +  "check_dependencies",
      +  "email_mx",
      +  "email_security_posture",
      +  "email_disposable",
      +  "email_verify",
      +  "robots_txt",
      +  "redirect_chain",
      +  "brand_assets",
      +  "seo_audit",
      +  "phone_lookup",
      +  "username_lookup",
      +  "password_check",
      +  "phishing_check",
      +  "atlas_technique_lookup",
      +  "atlas_technique_search",
      +  "bulk_atlas_technique_lookup",
      +  "atlas_case_study_lookup",
      +  "atlas_case_study_search",
      +  "d3fend_defense_lookup",
      +  "d3fend_defense_search",
      +  "d3fend_defense_for_attack",
      +  "d3fend_attack_coverage",
      +  "sigma_rule_lookup",
      +  "bulk_sigma_rule_lookup",
      +  "tech_stack_cve_audit"
      +]
  7. Changed1 schema field changed
    • changedOutput schema / $defs / PivotHint / properties / tool / enum
      Previous value: -[
      -  "cve_lookup",
      -  "cve_search",
      -  "cve_leading",
      -  "bulk_cve_lookup",
      -  "calculate_risk_score",
      -  "get_cvss_details",
      -  "exploit_lookup",
      -  "kev_detail",
      -  "cwe_lookup",
      -  "subdomain_enum",
      -  "ssl_check",
      -  "tech_fingerprint",
      -  "asn_lookup",
      -  "ip_lookup",
      -  "ioc_lookup",
      -  "bulk_ioc_lookup",
      -  "hash_lookup",
      -  "threat_intel",
      -  "threat_report",
      -  "audit_domain",
      -  "domain_report",
      -  "dns_lookup",
      -  "whois_lookup",
      -  "wayback_lookup",
      -  "scan_headers",
      -  "check_headers",
      -  "check_secrets",
      -  "check_injection",
      -  "check_dependencies",
      -  "email_mx",
      -  "email_security_posture",
      -  "email_disposable",
      -  "email_verify",
      -  "robots_txt",
      -  "redirect_chain",
      -  "brand_assets",
      -  "seo_audit",
      -  "phone_lookup",
      -  "username_lookup",
      -  "password_check",
      -  "phishing_check",
      -  "atlas_technique_lookup",
      -  "atlas_technique_search",
      -  "bulk_atlas_technique_lookup",
      -  "atlas_case_study_lookup",
      -  "atlas_case_study_search",
      -  "d3fend_defense_lookup",
      -  "d3fend_defense_search",
      -  "d3fend_defense_for_attack",
      -  "d3fend_attack_coverage"
      -]New value: +[
      +  "cve_lookup",
      +  "cve_search",
      +  "cve_leading",
      +  "bulk_cve_lookup",
      +  "calculate_risk_score",
      +  "get_cvss_details",
      +  "exploit_lookup",
      +  "kev_detail",
      +  "cwe_lookup",
      +  "subdomain_enum",
      +  "ssl_check",
      +  "tech_fingerprint",
      +  "asn_lookup",
      +  "ip_lookup",
      +  "ioc_lookup",
      +  "bulk_ioc_lookup",
      +  "hash_lookup",
      +  "threat_intel",
      +  "threat_report",
      +  "audit_domain",
      +  "domain_report",
      +  "dns_lookup",
      +  "whois_lookup",
      +  "wayback_lookup",
      +  "scan_headers",
      +  "check_headers",
      +  "check_secrets",
      +  "check_injection",
      +  "check_dependencies",
      +  "email_mx",
      +  "email_security_posture",
      +  "email_disposable",
      +  "email_verify",
      +  "robots_txt",
      +  "redirect_chain",
      +  "brand_assets",
      +  "seo_audit",
      +  "phone_lookup",
      +  "username_lookup",
      +  "password_check",
      +  "phishing_check",
      +  "atlas_technique_lookup",
      +  "atlas_technique_search",
      +  "bulk_atlas_technique_lookup",
      +  "atlas_case_study_lookup",
      +  "atlas_case_study_search",
      +  "d3fend_defense_lookup",
      +  "d3fend_defense_search",
      +  "d3fend_defense_for_attack",
      +  "d3fend_attack_coverage",
      +  "sigma_rule_lookup",
      +  "bulk_sigma_rule_lookup"
      +]
  8. Added

TDQS

A4.6/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already indicate read-only, idempotent, non-destructive behavior, and the description adds significant extra context: it is passive DNS-only (no SMTP probe), DKIM probing tests common selectors and recent dates, custom selectors must be supplied, and there are rate limits (30/hr free, 500/hr Pro). These details help the agent understand side effects, constraints, and operational limitations beyond the annotations.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is information-dense and front-loaded with the primary purpose, then usage, scoring details, probing behavior, and rate limits. It is slightly longer than necessary but every sentence contributes meaningful information. No fluff, though the run-on structure could be improved for readability.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given the presence of an output schema, the description does not need to explain return values. It covers the main purpose, protocols, scoring scale, probing behavior, passive nature, and rate limits. It is complete for an agent to understand what the tool does, how it behaves, and what parameters to supply. The description also helps differentiate it from numerous sibling security tools.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The schema already covers both parameters well (100% coverage). The description enhances the 'selectors' parameter by explaining that it supplies custom DKIM selectors and that probing defaults to common selectors with recent dates. This gives the agent insight into how the parameter is used and what happens if omitted, adding value beyond the schema descriptions.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the tool analyzes email authentication posture (SPF, DMARC, DKIM) and produces a numeric score and findings. It specifies the resource (domain) and the specific protocols, and distinguishes itself from sibling tools like email_mx or email_verify by focusing on authentication posture. The dual-use framing (red-team/blue-team) further clarifies its purpose.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description provides clear context for when to use the tool: for red-team spoofing feasibility and blue-team posture audits. It does not explicitly name alternative tools or state when not to use it, but the context is enough for an agent to decide in most scenarios. The sibling tool list shows related tools, but the description itself doesn't draw explicit comparisons.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

TDQS

A4.5/5.0
Disambiguation4/5

Most tools have clearly distinct purposes, with differences between lookup/search/scan/audit for each domain. However, some overlap exists (e.g., email_mx vs email_security_posture, scan_headers vs contrast_scan) which could cause occasional confusion. Overall, boundaries are well-defined.

Naming Consistency5/5

Tool names follow a consistent verb_noun pattern (e.g., cve_lookup, check_headers, bulk_cve_lookup) with all lowercase underscores. Variations like kev_detail or ssl_check are minor and still predictable. No chaotic mixing of conventions.

Tool Count4/5

54 tools is high but justified by the broad cybersecurity scope (CVE, ATLAS, D3FEND, Sigma, domain, email, IOC, scanning). Some redundancy exists (e.g., three email-related tools), but the count is not excessive given the API's comprehensive feature set.

Completeness5/5

The tool set thoroughly covers the threat intelligence and domain investigation lifecycle: CVE/KEV/exploit/CWE, ATLAS/D3FEND/Sigma, DNS/WHOIS/SSL/subdomains, email security, IOC enrichment, and active scanning. No significant gaps are apparent for the stated cybersecurity purpose.