# DnsGuard > Free email-domain health checker for SPF, DKIM, DMARC, BIMI, MX, MTA-STS and TLS-RPT. Returns a 0–100 score, an A–F grade, per-record findings and plain-English fixes. Public JSON API plus a remote MCP server for AI agents. DnsGuard only reads public data: DNS records (over DNS-over-HTTPS) and, when a domain publishes MTA-STS, its public policy file at https://mta-sts./.well-known/mta-sts.txt. It does not send email or store the domains you check. Scoring: MX 10, SPF 25, DMARC 30, DKIM 25, BIMI 10 = 100 core points. MTA-STS (up to 3) and TLS-RPT (up to 2) add up to 5 bonus points, applied only when SPF passes and DMARC is p=quarantine or p=reject; the total is capped at 100. Grades: A ≥ 90, B ≥ 80, C ≥ 70, D ≥ 60, otherwise F. DKIM selectors can't be listed via DNS, so common and provider-specific selectors are tried; pass your own selector for an exact result. ## For AI agents - [MCP server](https://dnsguard.mike-tusa.workers.dev/mcp): remote MCP over Streamable HTTP at `https://dnsguard.mike-tusa.workers.dev/mcp` (POST only, stateless, JSON responses, no sessions). Protocol versions: 2026-07-28, 2025-11-25, 2025-06-18, 2025-03-26, 2024-11-05 (2026-07-28 per-request `_meta`; older versions use `initialize`). One tool: `check_domain` with `domain` (required), `dkim_selector` and `include_raw` (optional). Read-only. Client config (most MCP clients accept this; some use a different format, for example VS Code uses a `servers` key): `{"mcpServers":{"dnsguard":{"type":"http","url":"https://dnsguard.mike-tusa.workers.dev/mcp"}}}` - [OpenAPI 3.1 spec](https://dnsguard.mike-tusa.workers.dev/openapi.json): machine-readable description of the JSON API - [JSON API docs](https://dnsguard.mike-tusa.workers.dev/#api): human-readable API reference with examples ## JSON API - `GET https://dnsguard.mike-tusa.workers.dev/api/check?domain=example.com` (optional `&selector=`): full check as JSON (`score`, `grade`, `scoreBreakdown`, `checks.{mx,spf,dmarc,dkim,bimi,mtaSts,tlsRpt}` each with `status`, `score`, `findings`, `recommendations`, `record`). CORS enabled. - `GET https://dnsguard.mike-tusa.workers.dev/api/health`: `{ "ok": true, "version": "0.7.2" }` - `GET https://dnsguard.mike-tusa.workers.dev/api/auth/status`: current limits and whether free-key sign-in is available - Errors: `{ "error": { "code", "message" } }` with HTTP 400 `invalid_domain`/`invalid_selector`, 401 `invalid_api_key`, 422 `domain_not_found`, 429 `rate_limited`/`daily_quota_exceeded`/`daily_capacity_reached` (see `Retry-After`), 502 `dns_unavailable`, 503, 504 `timeout`. ## Limits, keys and pricing - Anonymous (no key): about 20 checks per minute per IP; all anonymous users share about 5,000 checks per UTC day. - Free API key (sign in with Google on the homepage): about 120 checks per minute and 1,000 per UTC day. Send `Authorization: Bearer dg_live_…` (or `X-Api-Key`). - DnsGuard Pro, $9/mo via Polar: about 600 checks per minute and 10,000 per UTC day per license. Send `Authorization: Bearer DNSG-…`. [Subscribe](https://buy.polar.sh/polar_cl_gikZjiwyAE6uZPCem4zDUlQLJTrEMo7VHvCph3xozYN) - The MCP endpoint uses the same keys and the same counters: each `tools/call` is one check. `initialize`, `tools/list` and other non-check messages don't count as checks, but have a light cap of about 120 per minute per IP (over it: HTTP 429 with `Retry-After`). Over a limit, the tool result has `isError: true` with the reason and `retryAfterSeconds`. An invalid key returns HTTP 401. Results are cached for 2 minutes and cache hits don't count. - MCP request caps: 65,536-byte body, JSON-RPC batches (legacy versions only) of at most 10 messages with at most one `tools/call`. ## Guides - [SPF guide](https://dnsguard.mike-tusa.workers.dev/guides/spf): syntax, the 10-lookup limit, common mistakes - [DKIM guide](https://dnsguard.mike-tusa.workers.dev/guides/dkim): selectors, key sizes, rotation - [DMARC guide](https://dnsguard.mike-tusa.workers.dev/guides/dmarc): policies, reporting, rollout plan - [BIMI guide](https://dnsguard.mike-tusa.workers.dev/guides/bimi): logo requirements and VMC certificates - [MTA-STS and TLS-RPT guide](https://dnsguard.mike-tusa.workers.dev/guides/mta-sts): policy file, modes, reporting ## Optional - [Homepage and checker](https://dnsguard.mike-tusa.workers.dev/) - [Privacy](https://dnsguard.mike-tusa.workers.dev/#privacy) - Contact: digitalpromohub.support+dnsguard@gmail.com