mcp-outbound-infrastructure-fingerprint
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@mcp-outbound-infrastructure-fingerprintfingerprint outbound infrastructure for acme.com"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Outbound Infrastructure Fingerprint MCP Server
MCP server for the Mamba Labs Outbound Infrastructure Fingerprint actor on Apify.
Give it a company domain. It tells your agent whether that company runs cold email outbound, and on what stack.
Tool
fingerprint_outbound_infrastructure
Input | Type | Notes |
| string | One company domain. |
| string[] | Batch. Takes precedence over |
| boolean | Default true. The strongest signal and the slowest step. |
|
| Default |
| boolean | Default false. Adds a separately billed blacklist check and health score. |
| boolean | Ignore the 7 day result cache. |
Returns a flat row per domain: runs_outbound (program, light, none, unknown), confidence, sending_domains[], registration_clusters[], sending_platforms[], inbox_provider, warmup_detected, infrastructure_vendors[], spf_status, dkim_status, dmarc_policy, and an evidence[] array of quotable strings.
Related MCP server: HeaderHawk
What it actually detects
A real outbound program does not send from the domain the business runs on. It buys lookalikes (getcompany.com, company-mail.com, trycompany.co), gives them their own mail tenant, and redirects their web root at the real site. That redirect is the attribution handle, and finding those domains is the part nobody else does.
Measured on nine live domains: 6 of 6 detected on companies that demonstrably run outbound, 0 false positives of 3 on controls.
Two honest limits. When the brand token is an ordinary English word (Gong, Clay, Ramp), lookalike patterns collide with unrelated businesses that legitimately own them; the actor sets brand_is_common_word and caps confidence rather than reporting a confident none. And sending-platform recall is partial by design: Instantly, Smartlead, Lemlist, Apollo and Salesloft connect over OAuth to a customer's own mailbox and publish no SPF include host at all, so an empty sending_platforms tells you little while a populated one is solid.
Setup
{
"mcpServers": {
"mamba-outbound-infrastructure-fingerprint": {
"command": "npx",
"args": ["-y", "@mambalabsdev/mcp-outbound-infrastructure-fingerprint"],
"env": { "APIFY_TOKEN": "your-apify-token" }
}
}
}Get a token at console.apify.com/account/integrations. Read-only; consumes Apify credits per domain analyzed.
Also available
This tool is also exposed by the GTM Suite umbrella server, alongside the rest of the Mamba Labs GTM actors, if you would rather run one server than many.
Built by Mamba Labs.
Available Tools
1 toolfingerprint_outbound_infrastructureFingerprint Outbound InfrastructureARead-onlyIdempotent
Given a company domain, determine whether that company runs cold email outbound and on what stack. Returns a runs_outbound verdict of program (a deliberate cold outbound setup), light (one weak signal), none, or unknown, plus the evidence behind it. The strongest signal is the lookalike sending domains a real outbound program leaves behind: domains like getcompany.com or company-mail.com that carry their own mail and redirect back to the primary site. Also returns the inbox provider (Google Workspace, Microsoft 365 and others) for the primary domain and each sending domain, any detected sending platform (Outreach, Salesloft, Lemlist, Instantly, Smartlead, Apollo and more), registration clusters showing sending domains bought on the same day, cold email infrastructure vendors, and deliverability posture (SPF, DKIM, DMARC). Note that sending platform recall is partial by design: sequencers that connect over OAuth to a customer's own mailbox leave no DNS trace, so an empty sending_platforms means little while a populated one is solid. Public DNS and HTTP redirects only, no login, no mailbox access. Returns flat Clay-ready JSON. Read-only; requires an APIFY_TOKEN and consumes Apify credits per domain analyzed.
| Name | Required | Description | Default |
|---|---|---|---|
| domain | No | A single company domain, e.g. smartlead.ai. Provide either domain or domains. | |
| domains | No | Batch mode: several company domains analyzed in one call. Takes precedence over domain. | |
| skipCache | No | Force a fresh analysis and ignore the 7 day result cache. | |
| check_deliverability | No | Add a blacklist check and a 0-100 health score by running the separate Domain Deliverability Checker actor, which bills its own per-domain rate on top of this one. Default false. SPF, DKIM and DMARC are read from DNS either way. | |
| scan_sending_domains | No | Scan for lookalike sending domains. Default true. This is the strongest signal and the slowest step; turning it off makes runs fast but caps the verdict at what platform and deliverability signals alone can prove. | |
| sending_domain_depth | No | deep (default) checks .com, .co, .io, .net and .org. standard drops .net and .org for slightly fewer DNS lookups, at the cost of missing sending domains on those TLDs. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Beyond the annotations (readOnly, idempotent, non-destructive), the description discloses important behavioral traits: 'sending platform recall is partial by design', 'requires an APIFY_TOKEN and consumes Apify credits per domain analyzed', and 'Public DNS and HTTP redirects only, no login, no mailbox access.' These details significantly aid the agent in predicting side effects and costs, going far beyond the structured hints.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is well-structured: it opens with purpose, then details signals, outputs, and limitations. It is longer than average, but every sentence contributes substantive information (cost, recall limitations, deliverability checks). The only minor issue is a slight redundancy in mentioning 'no login' twice, but overall it is appropriately dense for a complex tool.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
With no output schema, the description carries the full burden of explaining return values. It enumerates the key outputs: runs_outbound verdict, evidence, inbox provider, sending platform, registration clusters, and deliverability posture. It also mentions the flat Clay-ready JSON format and the availability of a 7-day cache via skipCache. This is complete enough for an agent to select and invoke the tool correctly.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The input schema already covers 100% of parameters with descriptions, providing the baseline of 3. The tool description adds rationale for key parameters, such as explaining that lookalike sending domains are the 'strongest signal' behind scan_sending_domains, and that disabling it 'caps the verdict.' This extra context helps the agent decide parameter values, slightly exceeding schema-only semantics.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description opens with a specific verb and resource: 'Given a company domain, determine whether that company runs cold email outbound and on what stack.' It clearly names the output (runs_outbound verdict) and distinguishes the tool from generic DNS lookup tools by focusing on outbound infrastructure fingerprinting. Although no siblings are listed, the description fully defines the tool's unique function.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description specifies that it uses only public DNS and HTTP redirects, with no login or mailbox access, setting clear expectations about what the tool can and cannot do. It also notes that sending platform recall is partial, which helps users interpret results. Since no sibling tools exist, explicit alternative recommendations are not applicable, but the context is sufficient.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections. Dates show when Glama detected each change.
1 tool update
v1.0.0- First observed
fingerprint_outbound_infrastructure
TDQS
With only one tool, there is no possibility of confusion or overlap. The tool's purpose is clearly defined and distinct.
The single tool name follows a clear verb_noun pattern ('fingerprint_outbound_infrastructure'), and with only one tool there is no inconsistency to evaluate.
The server contains only one tool, which is slightly below the typical 3-15 range, but the tool is comprehensive and serves a very narrow, specific purpose, making the single-tool count reasonable.
The tool covers the full scope of outbound infrastructure fingerprinting: detecting sending domains, inbox providers, sending platforms, registration clusters, infrastructure vendors, and deliverability posture. No obvious gaps are apparent for the stated purpose.
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Connectors
Email posture for any domain: can it receive mail, can it be spoofed? MX, SPF and DMARC.
Email-domain intelligence: MX capability, provider, disposable status, SPF, DMARC, and MTA-STS.
Monitor and manage email authentication (SPF, DKIM, DMARC, MTA-STS, BIMI) for your domains.
AI-operated. Email authentication and deliverability: reads DKIM keys, finds unknown selectors.
Related MCP Servers
- AlicenseNot gradedqualityDmaintenanceEnables DNS and email security analysis through passive and active scanning capabilities. Provides comprehensive domain security checks including SPF, DMARC, DNSSEC validation, MX record analysis, and SMTP connectivity testing.MIT
- AlicenseNot gradedqualityDmaintenanceAn advanced email security analysis MCP server for real-time phishing detection, comprehensive header analysis, and threat intelligence integration. It enables users to extract indicators of compromise and validate email authentication protocols like DKIM, SPF, and DMARC.MIT
- FlicenseNot gradedqualityCmaintenanceEnables B2B research by finding verified work emails, extracting contacts, detecting tech stacks, and profiling DNS and SaaS, all through a suite of MCP tools.-
- AlicenseAqualityAmaintenanceEnables auditing any domain's email deliverability and DNS health, including SPF, DKIM, DMARC, MX, mail provider, DNS blacklist status, catch-all, domain age, and a deliverability score.1941MIT
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/mambalabsdev/mcp-outbound-infrastructure-fingerprint'
If you have feedback or need assistance with the MCP directory API, please join our Discord server