Docs/Skills/DMARC Validation Skill

DMARC Validation Skill

Validate DMARC records for a domain

OperationalCredits 10 per callp50 542msDomain Data

Overview

A DMARC record lookup API. This tool queries DNS records to inspect and validate the DMARC record associated with a domain. It analyzes policy strength, formatting and alignment modes, derives whether the domain actively enforces DMARC and a composite email-spoofing risk score, and provides guidance for better email deliverability and protection against spoofing.

Live Test DMARC Validation Skill Skill →

The tool

Once your client is connected to the VerveKit server, this appears in its tool list as DMARCValidationSkill. It is read-only and open-world — it fetches and never mutates anything on your side — so most clients call it without asking you to confirm.

Tool call
{
  "name": "DMARCValidationSkill",
  "arguments": {
    "domain": "paypal.com"
  }
}

You do not name the tool yourself; the model picks it. Asking about paypal.com in the terms this skill covers is enough for it to reach for DMARCValidationSkill on its own — naming it explicitly also works, and is the way to force the call.

Connecting

One server URL covers every skill in the catalog, including this one. Authorization is OAuth: the client opens a browser once, and there is no key to paste into a config file.

{
  "mcpServers": {
    "vervekit": {
      "url": "https://api.vervekit.com/v1/mcp"
    }
  }
}

Per-client setup — Claude, Cursor, VS Code, ChatGPT — is on the MCP setup page.

Arguments

These are the properties on the tool's inputSchema, so a well-behaved client validates them before the call is made. Premium arguments are accepted on every plan but only take effect on plans that include them.

ArgumentTypeDescription
domainRequiredstringThe domain to validate the DMARC record for
domain

What the model gets back

The result carries a structuredContent object matching the tool's declared outputSchema, so a client reads fields without parsing prose. status is "ok" and error is null on success; a null field means the value was not available for that input, not that the call failed.

Result
{
  "status": "ok",
  "error": null,
  "data": {
    "host": "paypal.com",
    "dmarcHost": "_dmarc.paypal.com",
    "hasDmarc": true,
    "dmarc_record": "v=DMARC1; p=reject; rua=mailto:[email protected],mailto:[email protected]; ruf=mailto:[email protected],mailto:[email protected]",
    "rua": {
      "email": "[email protected],[email protected]",
      "domain": "rua.agari.com",
      "valid": true
    },
    "ruf": {
      "email": "[email protected],[email protected]",
      "domain": "ruf.agari.com",
      "valid": true
    },
    "v": "DMARC1",
    "p": "reject",
    "sp": null,
    "pct": null,
    "adkim": null,
    "aspf": null,
    "fo": null,
    "rf": null,
    "ri": null,
    "valid": true,
    "issues": [],
    "isEnforced": true,
    "riskScore": 5,
    "riskLevel": "low"
  }
}

Response fields

Paths are relative to data. Premium fields are absent rather than zeroed on plans that do not include them, so check for presence instead of comparing to 0.

FieldTypeExampleDescription
hoststringpaypal.comThe domain name that was validated
dmarcHoststring_dmarc.paypal.comThe DMARC DNS record hostname for the domain
hasDmarcbooleantrueIndicates whether a DMARC record exists for domain
dmarc_recordstringv=DMARC1; p=reject; rua=mailto:[email protected],mailto:[email protected]; ruf=mailto:[email protected],mailto:[email protected]The complete DMARC record string from DNS
ruaobject{…}Aggregate report destination from the rua tag, with the address and whether it is valid
rua.emailPremiumstring[email protected],[email protected]Email address for aggregate report delivery
rua.domainstringrua.agari.comDomain name extracted from aggregate report email
rua.validPremiumbooleantrueIndicates if aggregate report email is valid
rufobject{…}Forensic report destination from the ruf tag, with the address and whether it is valid
ruf.emailPremiumstring[email protected],[email protected]Email address for forensic report delivery
ruf.domainstringruf.agari.comDomain name extracted from forensic report email
ruf.validPremiumbooleantrueIndicates if forensic report email is valid
vstringDMARC1DMARC protocol version from record
pstringrejectDMARC policy for domain (reject, quarantine, none)
spobjectnullPolicy applied to subdomains from the sp tag; null when the record does not set one
pctobjectnullPercentage of mail the policy applies to from the pct tag; null means the default of 100
adkimobjectnullDKIM alignment mode from the adkim tag, relaxed or strict; null means the default of relaxed
aspfobjectnullSPF alignment mode from the aspf tag, relaxed or strict; null means the default of relaxed
foobjectnullForensic reporting options from the fo tag, controlling when a report is generated
rfobjectnullForensic report format from the rf tag
riobjectnullRequested interval between aggregate reports in seconds, from the ri tag
validbooleantrueOverall validation status of DMARC record
issuesarray[]Problems found in the record, such as a missing policy or an unreachable report address
isEnforcedPremiumbooleantrueWhether the domain actively enforces DMARC — policy is quarantine or reject and applied to 100% of mail. False for monitoring-only (p=none), partial rollout (pct<100), or no DMARC record
riskScorePremiumnumber5Composite 0-100 email-spoofing risk based on the DMARC policy and rollout percentage — higher means the domain is more easily spoofed (no DMARC or p=none scores high; enforced reject scores low)
riskLevelPremiumstringlowRisk band derived from the score: low, medium or high

Failure modes

Errors come back as tool errors carrying a sentence the model can act on, not a bare status code. Error handling covers the full list.

StatusWhat it means
400 / 422The arguments did not validate. The message names the offending one.
401The OAuth session is invalid or expired — reconnect the server.
403Blocked by a key restriction or an IP allow-list. Never a bad identity.
404This skill is not part of VerveKit. Check the catalog.
429Out of credits, or a brief rate limit. The message tells them apart.

A call costs 10 credits each time the tool actually runs; a model that reasons about the tool without calling it costs nothing.

Use cases

Vendor Security Audits
Audit partner domains during vendor reviews by inspecting their published DMARC policy and flagging entries set to none instead of reject.
Outbound Campaign Verification
Before sending mass marketing broadcasts, deliverability platforms verify sender domains to confirm that DMARC records exist and specify strict alignment modes.
Inbound Mail Protection
To stop spoofed sender addresses, secure email gateways evaluate incoming message domains against live DMARC policies and quarantine suspicious traffic.
Domain Portfolio Health
DNS administrators track customer domains across registrars to detect misconfigured report addresses, missing subdomain policies, and unaddressed syntax issues.

Other ways to use DMARC Validation Skill

Set up DMARC Validation Skill on VerveKit, or reach the same source a different way. Your VerveKit account and credits work on all of them — one key, one balance.

Call it as a REST APIOne HTTPS endpoint and an x-api-key header, with SDKs for Node, Python and .NET.APIVerve →Reference →
Google Sheets or ExcelA =VERVE() formula fills a column — no script, no export, recalculates in place.VerveSheets →Reference →
Ground an agent on itA cited, machine-checkable fact your model can't produce on its own.VerveContext →Reference →

More in Domain Data:

Was this page helpful?