@pipeworx/email-infra

Connect: https://pipeworx.io/mcp — every tool in the catalog, including @pipeworx/email-infra’s. Install: one-click buttons

Connect to just the @pipeworx/email-infra pack

https://gateway.pipeworx.io/email-infra/mcp — only @pipeworx/email-infra’s own tools, nothing else in the catalog.

No MCP client? Skip the connection: POST https://gateway.pipeworx.io/v1/tools/search_packs {"query":"..."} to find a tool below, GET /v1/tools/<name> for its schema, POST the same URL with arguments for the data — see For AI agents.

Tools: 6

Deliverability brain for a recipient domain: which secure email gateway fronts its inbound mail, its SPF/DKIM/DMARC/BIMI/MTA-STS posture, its RDAP registration age, and a one-call sending-domain risk audit that combines all three with DNS/HTTP-only heuristics.

Tools

  • mx_gateway(domain) — classifies which secure email gateway fronts a domain’s inbound mail (M365, Google Workspace, Mimecast, Proofpoint, Cisco Secure Email, Symantec/Broadcom, Cloudflare Email Security, self-hosted, or null_mx/no_mx/no_such_domain) from live MX records, with the SPF include as a secondary hint. Every match carries a source of documented (traceable to the vendor’s own support docs) or inferred (seen only in this pack’s build-time validation sample) — never a single blended confidence number.
  • mx_gateway_batch(domains[]) — mx_gateway over up to 25 domains, plus a cohort tally by provider, for splitting a send list and throttling by gateway before a cold-email launch.
  • auth_grade(domain) — SPF (a real RFC 7208 DNS-lookup count via recursive include/redirect resolution, with a loop guard and the RFC’s own depth cap — not an approximation), DMARC (policy/pct/rua/ruf), DKIM (probed over six common selectors: google, selector1, selector2, k1, s1, default — absence across these is explicitly NOT proof DKIM is unset), BIMI, and MTA-STS (DNS record plus a live fetch of the .well-known policy). Each control returns its own grade and issues.
  • domain_age(domain) — registration age via RDAP. Reuses @pipeworx/rdap’s IANA-bootstrap RDAP client (workspace dependency, rdap.callTool('domain', ...)) rather than re-implementing bootstrap/fallback-base resolution.
  • sending_domain_audit(domain) — one call combining mx_gateway, auth_grade and domain_age, plus risk heuristics: new-domain age (<90 days, a practitioner convention, not a vendor spec), parked-page/redirect detection (nameserver check against known parking providers + a homepage fetch), and a keyword-stuffed-name heuristic. Every heuristic is labelled as such. The registrar name is returned for the CALLER to compare across their own domain list — same-registrar-bulk-registration is only visible across a list, never for one domain in isolation.
  • dnsbl_check(target, _spamhausKey?, _surblKey?) — Spamhaus DQS and/or SURBL lookups. BYOK only.

Auth

Keyless for mx_gateway, mx_gateway_batch, auth_grade, domain_age, and sending_domain_audit — everything is a live DNS (DoH) or RDAP read.

dnsbl_check is BYOK only and this is a deliberate design decision, not a missing platform key: Spamhaus’s Data Query Service (DQS) terms and SURBL’s free-tier usage policy both forbid embedding their public DNSBL lookups in a paid product. With no _spamhausKey/_surblKey, the tool returns status: "not_checked" — never "clean" — and says so in reason. Pass your own Spamhaus DQS key as _spamhausKey and/or a SURBL commercial data-feed key as _surblKey to run a real check.

Data sources

  • dns.google/resolve — Google Public DNS-over-HTTPS (JSON API). Every MX/TXT/NS lookup in this pack goes through it. Reachable from a Cloudflare Worker (edge-probed against the exact URLs this pack uses before ship).
  • @pipeworx/rdap (workspace package) — IANA-bootstrap RDAP client, used by domain_age for registration date/registrar.
  • The queried domain’s own mta-sts. subdomain, e.g. https://mta-sts.example.com/.well-known/mta-sts.txt — fetched (through safeFetch with resolvePublic: true, since the host is caller-controlled) only when the domain’s _mta-sts TXT record already confirms an MTA-STS record exists.
  • The queried domain’s own homepage, e.g. https://example.com/ — fetched by sending_domain_audit’s parked-page check (through safeFetch with SSRF guards), to detect a redirect to a different host or a common domain-for-sale marketplace phrase in the homepage body.

Things the next person would otherwise rediscover

  • The mail-gateway suffix table is NOT a vendor API — it is DNS-pattern matching, and most of it IS traceable to vendor documentation (Google Workspace’s aspmx.l.google.com/smtp.google.com, Microsoft 365’s *.mail.protection.outlook.com, Proofpoint’s *.pphosted.com, Mimecast’s *.mimecast.com, Cisco Secure Email’s *.iphmx.com, Broadcom/Symantec’s *.messagelabs.com). A handful of suffixes are inferred — observed live during this pack’s validation sweep but with no vendor doc page found at build time: Microsoft’s newer single-label *.mx.microsoft MX format, Proofpoint’s government-cloud *.gpphosted.com, and Cloudflare’s own *.cf-emailsecurity.net. Every inferred match says so in evidence.
  • RFC 7505 “null MX” (0 .) is a different, stronger signal than “no MX records at all” — it is an explicit, signed statement that the domain never accepts mail (example.com itself is null-MX). mx_gateway reports it as provider: "null_mx", distinct from no_mx (no MX published, status unknown) and no_such_domain (NXDOMAIN).
  • SPF lookup counting is genuinely recursive, not a flat count of top-level include: tokens — it follows include/redirect chains (with a visited-set loop guard and RFC 7208’s own 10-lookup depth cap) because a domain with 2 top-level includes can easily carry 7+ real DNS lookups once each include’s own SPF record is walked (observed live: stripe.com is 7, fedex.com’s is near the limit via %{ir} macro expansion).
  • A multi-homed domain is resolved by majority vote across ALL its MX hosts, not just the lowest-priority one. fedex.com publishes one self-hosted smart-host (mapper.gslb.fedex.com, priority 100) ahead of two Proofpoint hosts (priority 200) — mx_gateway correctly reports provider: "proofpoint" with confidence: "high" because 2 of 3 MX hosts match a documented suffix, with the unmatched host visible in evidence.mx_matches.
  • A transport/resolution failure (SERVFAIL, REFUSED, a non-200 from dns.google) always throws — it never degrades into an empty array or found: false. NXDOMAIN and “NOERROR with no records” are the only two DNS outcomes treated as real negatives, because both are legitimate answers for a DKIM/BIMI/MTA-STS selector probe (the selector subdomain usually doesn’t exist in DNS at all when the selector is wrong, which is NXDOMAIN, not a resolver failure).
  • DKIM absence across the six checked selectors is explicitly NOT proof DKIM is unset — many providers (ESPs especially) use random or customer-specific selectors this probe does not enumerate. auth_grade returns grade: "inconclusive" rather than "F" in that case, and says so in issues.

Tools

  • mx_gateway — Identify which secure email gateway fronts a domain’s inbound mail — M365, Google Workspace, Mimecast,
  • mx_gateway_batch — Run mx_gateway over up to 25 domains at once and return a per-domain breakdown plus a cohort tally by
  • auth_grade — Grade a domain’s email-authentication posture: SPF (real RFC 7208 DNS-lookup count via include/redirect
  • domain_age — Registration age of a domain via RDAP (reuses the @pipeworx/rdap pack’s IANA-bootstrap RDAP client — the
  • sending_domain_audit — One-call sending-domain risk audit: combines mx_gateway, auth_grade and domain_age, plus DNS/HTTP-only risk
  • dnsbl_check — Check a domain or IP against Spamhaus DQS and/or SURBL DNSBLs. BYOK ONLY — requires an API key: Spamhaus DQS

Tools

  • auth_grade — Grade a domain's email-authentication posture: SPF (real RFC 7208 DNS-lookup count via include/redirect
  • dnsbl_check — Check a domain or IP against Spamhaus DQS and/or SURBL DNSBLs. BYOK ONLY — requires an API key: Spamhaus DQS
  • domain_age — Registration age of a domain via RDAP (reuses the @pipeworx/rdap pack's IANA-bootstrap RDAP client — the
  • mx_gateway — Identify which secure email gateway fronts a domain's inbound mail — M365, Google Workspace, Mimecast,
  • mx_gateway_batch — Run mx_gateway over up to 25 domains at once and return a per-domain breakdown plus a cohort tally by
  • sending_domain_audit — One-call sending-domain risk audit: combines mx_gateway, auth_grade and domain_age, plus DNS/HTTP-only risk

Regenerated from source · build October 9, 2026