Overview
A DMARC record lookup API. This tool queries DNS records to inspect and validate the DMARC record associated with a domain. It analyzes policy strength, formatting and alignment modes, derives whether the domain actively enforces DMARC and a composite email-spoofing risk score, and provides guidance for better email deliverability and protection against spoofing.
Live Test DMARC Grounding Data for AI Agents Source →
The tool
Once your client is connected to the VerveContext server, this appears in its tool list as DMARCGroundingDataforAIAgents. It is read-only and open-world — it fetches and never mutates anything on your side — so most clients call it without asking you to confirm.
{
"name": "DMARCGroundingDataforAIAgents",
"arguments": {
"domain": "paypal.com"
}
}You do not name the tool yourself; the model picks it. Asking about paypal.com in the terms this source covers is enough for it to reach for DMARCGroundingDataforAIAgents on its own — naming it explicitly also works, and is the way to force the call.
Connecting
One server URL covers every source in the catalog, including this one. Authorization is OAuth: the client opens a browser once, and there is no key to paste into a config file.
{
"mcpServers": {
"vervecontext": {
"url": "https://api.vervecontext.com/v1/mcp"
}
}
}https://api.vervecontext.com/v1/mcpPer-client setup — Claude, Cursor, VS Code, ChatGPT — is on the MCP setup page.
Arguments
These are the properties on the tool's inputSchema, so a well-behaved client validates them before the call is made. Premium arguments are accepted on every plan but only take effect on plans that include them.
| Argument | Type | Description |
|---|---|---|
domainRequired | string | The domain to validate the DMARC record for domain |
What the model gets back
The result carries a structuredContent object matching the tool's declared outputSchema, so a client reads fields without parsing prose. status is "ok" and error is null on success; a null field means the value was not available for that input, not that the call failed.
{
"status": "ok",
"error": null,
"data": {
"host": "paypal.com",
"dmarcHost": "_dmarc.paypal.com",
"hasDmarc": true,
"dmarc_record": "v=DMARC1; p=reject; rua=mailto:[email protected],mailto:[email protected]; ruf=mailto:[email protected],mailto:[email protected]",
"rua": {
"email": "[email protected],[email protected]",
"domain": "rua.agari.com",
"valid": true
},
"ruf": {
"email": "[email protected],[email protected]",
"domain": "ruf.agari.com",
"valid": true
},
"v": "DMARC1",
"p": "reject",
"sp": null,
"pct": null,
"adkim": null,
"aspf": null,
"fo": null,
"rf": null,
"ri": null,
"valid": true,
"issues": [],
"isEnforced": true,
"riskScore": 5,
"riskLevel": "low"
}
}
Response fields
Paths are relative to data. Premium fields are absent rather than zeroed on plans that do not include them, so check for presence instead of comparing to 0.
| Field | Type | Example | Description |
|---|---|---|---|
host | string | paypal.com | The domain name that was validated |
dmarcHost | string | _dmarc.paypal.com | The DMARC DNS record hostname for the domain |
hasDmarc | boolean | true | Indicates whether a DMARC record exists for domain |
dmarc_record | string | v=DMARC1; p=reject; rua=mailto:[email protected],mailto:[email protected]; ruf=mailto:[email protected],mailto:[email protected] | The complete DMARC record string from DNS |
rua | object | {…} | Aggregate report destination from the rua tag, with the address and whether it is valid |
rua.emailPremium | string | [email protected],[email protected] | Email address for aggregate report delivery |
rua.domain | string | rua.agari.com | Domain name extracted from aggregate report email |
rua.validPremium | boolean | true | Indicates if aggregate report email is valid |
ruf | object | {…} | Forensic report destination from the ruf tag, with the address and whether it is valid |
ruf.emailPremium | string | [email protected],[email protected] | Email address for forensic report delivery |
ruf.domain | string | ruf.agari.com | Domain name extracted from forensic report email |
ruf.validPremium | boolean | true | Indicates if forensic report email is valid |
v | string | DMARC1 | DMARC protocol version from record |
p | string | reject | DMARC policy for domain (reject, quarantine, none) |
sp | object | null | Policy applied to subdomains from the sp tag; null when the record does not set one |
pct | object | null | Percentage of mail the policy applies to from the pct tag; null means the default of 100 |
adkim | object | null | DKIM alignment mode from the adkim tag, relaxed or strict; null means the default of relaxed |
aspf | object | null | SPF alignment mode from the aspf tag, relaxed or strict; null means the default of relaxed |
fo | object | null | Forensic reporting options from the fo tag, controlling when a report is generated |
rf | object | null | Forensic report format from the rf tag |
ri | object | null | Requested interval between aggregate reports in seconds, from the ri tag |
valid | boolean | true | Overall validation status of DMARC record |
issues | array | [] | Problems found in the record, such as a missing policy or an unreachable report address |
isEnforcedPremium | boolean | true | Whether the domain actively enforces DMARC — policy is quarantine or reject and applied to 100% of mail. False for monitoring-only (p=none), partial rollout (pct<100), or no DMARC record |
riskScorePremium | number | 5 | Composite 0-100 email-spoofing risk based on the DMARC policy and rollout percentage — higher means the domain is more easily spoofed (no DMARC or p=none scores high; enforced reject scores low) |
riskLevelPremium | string | low | Risk band derived from the score: low, medium or high |
Why ground on it
A model can produce something that looks like this answer from its training data, and be confidently out of date or simply wrong. This source returns the current value in a shape you can check, which is the difference between an answer you can cite and one you have to hedge.
Point an evaluation at host: it is the field most worth pinning a claim to, and it is either present and current or absent — never plausibly invented.
Failure modes
Errors come back as tool errors carrying a sentence the model can act on, not a bare status code. Error handling covers the full list.
| Status | What it means |
|---|---|
400 / 422 | The arguments did not validate. The message names the offending one. |
401 | The OAuth session is invalid or expired — reconnect the server. |
403 | Blocked by a key restriction or an IP allow-list. Never a bad identity. |
404 | This source is not part of VerveContext. Check the catalog. |
429 | Out of credits, or a brief rate limit. The message tells them apart. |
A call costs 10 credits each time the tool actually runs; a model that reasons about the tool without calling it costs nothing.
Use cases
- Vendor Security Audits
- Audit partner domains during vendor reviews by inspecting their published DMARC policy and flagging entries set to none instead of reject.
- Outbound Campaign Verification
- Before sending mass marketing broadcasts, deliverability platforms verify sender domains to confirm that DMARC records exist and specify strict alignment modes.
- Inbound Mail Protection
- To stop spoofed sender addresses, secure email gateways evaluate incoming message domains against live DMARC policies and quarantine suspicious traffic.
- Domain Portfolio Health
- DNS administrators track customer domains across registrars to detect misconfigured report addresses, missing subdomain policies, and unaddressed syntax issues.
Other ways to use DMARC Grounding Data for AI Agents
Set up DMARC Grounding Data for AI Agents on VerveContext, or reach the same source a different way. Your VerveContext account and credits work on all of them — one key, one balance.
Related
More in Domain Data: