# DMARC Examiner Muse connector

From musedirectory.ai, the independent directory of Meta Muse connectors. Not affiliated with Meta.

## DMARC Examiner

Monitor DMARC reports, check email authentication alignment, and export security alerts for your domains.

- Record: https://musedirectory.ai/connector/dmarc-examiner
- Category: Finance & Bills
- Developer: DMARC Examiner (https://dmarc-examiner.com/docs/settings/mcp-integration?utm_source=mcp-registry&utm_medium=content&utm_campaign=mcp-repo)
- Muse status: Extra setup. Not in Muse's Connectors list yet. Muse can still use it: its page gives you a request to paste into Muse.
- Health: Working, 1180ms, checked 2026-09-28T07:30:53Z
- Endpoint: https://mcp.dmarc-examiner.com/mcp
- Auth: No account needed; Pricing: unknown
- Screening: Screened, no issues found (2026-09-25T06:51:34Z)
- Source: Found in the official MCP Registry (io.github.dmarc-examiner/mcp) https://registry.modelcontextprotocol.io/v0/servers?search=io.github.dmarc-examiner%2Fmcp

Connects to DMARC Examiner to read aggregate and forensic reports on email authentication. Muse can list monitored domains, inspect DMARC records, retrieve reports and statistics, manage alerts, and export data as CSV for email security analysis.

Example request: "Show me a summary of DMARC authentication failures for my domain this week."

How to connect: Not in Muse's Connectors list yet, but Muse can still use it. Paste this into Muse: "Use DMARC Examiner to help me. It is a free service with an MCP server at https://mcp.dmarc-examiner.com/mcp. It does not need an API key. Ask me before you share anything with it." Muse asks before it shares anything with the app's site. Meta does not review apps used this way, so only use ones you trust. We tested this in the Muse app on September 24, 2026: Muse used an app's link directly this way and returned a live answer.

Tools:
- list_domains: List all monitored domains in your organization
- get_domain: Get details of a specific domain
- check_dmarc: Inspect the public DMARC record at _dmarc.<domain>. The domain does not need to belong to your organization. Returns parsed policy and rua/ruf addresses.
- create_domain: Add a new domain to the organization. Response includes the reporting_email and dmarc_record values to publish in DNS. May return 402 if the plan domain limit has been reached.
- verify_domain: Re-check a domain's DNS to confirm the DMARC record contains the organization's reporting email. Updates status to verified on success.
- delete_domain: Remove a domain from monitoring. Soft-deletes; historical reports remain accessible.
- list_reports: List DMARC reports for your organization
- get_report: Get details of a specific DMARC report
- get_report_statistics: Get statistics for a specific DMARC report
- export_report_csv: Export a DMARC report as CSV
- list_alerts: List alerts for your organization
- dismiss_alert: Dismiss a specific alert
- list_forensic_reports: List DMARC RUF (forensic) reports with optional filtering and pagination. Returns 403 if the plan does not include forensic reports (Pro plan and above).
- get_forensic_report: Get the full detail of a forensic (RUF) report by UUID, including the raw failed message envelope.
- get_forensic_reports_statistics: Aggregated forensic-report counters grouped by auth failure type, delivery result, source IP (with geolocation) and reported domain.
- get_forensic_reports_summary: Summary of forensic activity in the last 7 days — useful for daily digest views.
- list_webhooks: List webhook endpoints configured for the organization. Returns 403 if the plan does not include advanced alerting (Pro and above).
- create_webhook: Create a new webhook endpoint. URL must start with https://. Returns 422 if the organization has reached its webhook limit.
- update_webhook: Update a webhook. Any combination of url, name and is_active may be provided; URL must remain HTTPS.
- delete_webhook: Delete a webhook endpoint permanently.
- test_webhook: Send a synchronous webhook.test event to verify connectivity. Returns the delivery status. Test events do NOT update last_triggered_at, last_status or failure_count.

Screening checks:
- MCP handshake: pass (Answered in 238ms)
- Domain against threat feeds (Cloudflare security DNS): pass (mcp.dmarc-examiner.com, dmarc-examiner.com not flagged)
- Published packages against the OSV malicious-package database: pass (No malicious-package advisories)
- Hidden instructions or invisible characters in tool text: pass (21 tools read, nothing found)
- Inputs asking for passwords, card numbers or seed phrases: pass (None found)
- Domain and redirects: pass (Domain registered 953 days ago)
- AI review of purpose and tool behavior: pass (No concerns)
