@pipeworx/email-infra
Connect: https://pipeworx.io/mcp — every tool in the catalog, including @pipeworx/email-infra’s. Install: one-click buttons
Connect to just the @pipeworx/email-infra pack
https://gateway.pipeworx.io/email-infra/mcp — only @pipeworx/email-infra’s own tools, nothing else in the catalog.
No MCP client? Skip the connection: POST https://gateway.pipeworx.io/v1/tools/search_packs {"query":"..."} to find a tool below, GET /v1/tools/<name> for its schema, POST the same URL with arguments for the data — see For AI agents.
Tools: 6
Deliverability brain for a recipient domain: which secure email gateway fronts its inbound mail, its SPF/DKIM/DMARC/BIMI/MTA-STS posture, its RDAP registration age, and a one-call sending-domain risk audit that combines all three with DNS/HTTP-only heuristics.
Tools
mx_gateway(domain)— classifies which secure email gateway fronts a domain’s inbound mail (M365, Google Workspace, Mimecast, Proofpoint, Cisco Secure Email, Symantec/Broadcom, Cloudflare Email Security, self-hosted, ornull_mx/no_mx/no_such_domain) from live MX records, with the SPF include as a secondary hint. Every match carries asourceofdocumented(traceable to the vendor’s own support docs) orinferred(seen only in this pack’s build-time validation sample) — never a single blended confidence number.mx_gateway_batch(domains[])—mx_gatewayover up to 25 domains, plus a cohort tally by provider, for splitting a send list and throttling by gateway before a cold-email launch.auth_grade(domain)— SPF (a real RFC 7208 DNS-lookup count via recursiveinclude/redirectresolution, with a loop guard and the RFC’s own depth cap — not an approximation), DMARC (policy/pct/rua/ruf), DKIM (probed over six common selectors:google,selector1,selector2,k1,s1,default— absence across these is explicitly NOT proof DKIM is unset), BIMI, and MTA-STS (DNS record plus a live fetch of the.well-knownpolicy). Each control returns its own grade and issues.domain_age(domain)— registration age via RDAP. Reuses@pipeworx/rdap’s IANA-bootstrap RDAP client (workspace dependency,rdap.callTool('domain', ...)) rather than re-implementing bootstrap/fallback-base resolution.sending_domain_audit(domain)— one call combiningmx_gateway,auth_gradeanddomain_age, plus risk heuristics: new-domain age (<90 days, a practitioner convention, not a vendor spec), parked-page/redirect detection (nameserver check against known parking providers + a homepage fetch), and a keyword-stuffed-name heuristic. Every heuristic is labelled as such. The registrar name is returned for the CALLER to compare across their own domain list — same-registrar-bulk-registration is only visible across a list, never for one domain in isolation.dnsbl_check(target, _spamhausKey?, _surblKey?)— Spamhaus DQS and/or SURBL lookups. BYOK only.
Auth
Keyless for mx_gateway, mx_gateway_batch, auth_grade, domain_age, and
sending_domain_audit — everything is a live DNS (DoH) or RDAP read.
dnsbl_check is BYOK only and this is a deliberate design decision, not a
missing platform key: Spamhaus’s Data Query Service (DQS) terms and SURBL’s
free-tier usage policy both forbid embedding their public DNSBL lookups in a
paid product. With no _spamhausKey/_surblKey, the tool returns
status: "not_checked" — never "clean" — and says so in reason. Pass
your own Spamhaus DQS key as _spamhausKey and/or a SURBL commercial
data-feed key as _surblKey to run a real check.
Data sources
- dns.google/resolve — Google Public DNS-over-HTTPS (JSON API). Every MX/TXT/NS lookup in this pack goes through it. Reachable from a Cloudflare Worker (edge-probed against the exact URLs this pack uses before ship).
@pipeworx/rdap(workspace package) — IANA-bootstrap RDAP client, used bydomain_agefor registration date/registrar.- The queried domain’s own
mta-sts.subdomain, e.g.https://mta-sts.example.com/.well-known/mta-sts.txt— fetched (throughsafeFetchwithresolvePublic: true, since the host is caller-controlled) only when the domain’s_mta-stsTXT record already confirms an MTA-STS record exists. - The queried domain’s own homepage, e.g.
https://example.com/— fetched bysending_domain_audit’s parked-page check (throughsafeFetchwith SSRF guards), to detect a redirect to a different host or a common domain-for-sale marketplace phrase in the homepage body.
Things the next person would otherwise rediscover
- The mail-gateway suffix table is NOT a vendor API — it is DNS-pattern
matching, and most of it IS traceable to vendor documentation (Google
Workspace’s
aspmx.l.google.com/smtp.google.com, Microsoft 365’s*.mail.protection.outlook.com, Proofpoint’s*.pphosted.com, Mimecast’s*.mimecast.com, Cisco Secure Email’s*.iphmx.com, Broadcom/Symantec’s*.messagelabs.com). A handful of suffixes areinferred— observed live during this pack’s validation sweep but with no vendor doc page found at build time: Microsoft’s newer single-label*.mx.microsoftMX format, Proofpoint’s government-cloud*.gpphosted.com, and Cloudflare’s own*.cf-emailsecurity.net. Everyinferredmatch says so inevidence. - RFC 7505 “null MX” (
0 .) is a different, stronger signal than “no MX records at all” — it is an explicit, signed statement that the domain never accepts mail (example.comitself is null-MX).mx_gatewayreports it asprovider: "null_mx", distinct fromno_mx(no MX published, status unknown) andno_such_domain(NXDOMAIN). - SPF lookup counting is genuinely recursive, not a flat count of
top-level
include:tokens — it followsinclude/redirectchains (with a visited-set loop guard and RFC 7208’s own 10-lookup depth cap) because a domain with 2 top-level includes can easily carry 7+ real DNS lookups once each include’s own SPF record is walked (observed live:stripe.comis 7,fedex.com’s is near the limit via%{ir}macro expansion). - A multi-homed domain is resolved by majority vote across ALL its MX
hosts, not just the lowest-priority one.
fedex.compublishes one self-hosted smart-host (mapper.gslb.fedex.com, priority 100) ahead of two Proofpoint hosts (priority 200) —mx_gatewaycorrectly reportsprovider: "proofpoint"withconfidence: "high"because 2 of 3 MX hosts match a documented suffix, with the unmatched host visible inevidence.mx_matches. - A transport/resolution failure (SERVFAIL, REFUSED, a non-200 from
dns.google) always throws — it never degrades into an empty array or
found: false. NXDOMAIN and “NOERROR with no records” are the only two DNS outcomes treated as real negatives, because both are legitimate answers for a DKIM/BIMI/MTA-STS selector probe (the selector subdomain usually doesn’t exist in DNS at all when the selector is wrong, which is NXDOMAIN, not a resolver failure). - DKIM absence across the six checked selectors is explicitly NOT proof
DKIM is unset — many providers (ESPs especially) use random or
customer-specific selectors this probe does not enumerate.
auth_gradereturnsgrade: "inconclusive"rather than"F"in that case, and says so inissues.
Tools
- mx_gateway — Identify which secure email gateway fronts a domain’s inbound mail — M365, Google Workspace, Mimecast,
- mx_gateway_batch — Run mx_gateway over up to 25 domains at once and return a per-domain breakdown plus a cohort tally by
- auth_grade — Grade a domain’s email-authentication posture: SPF (real RFC 7208 DNS-lookup count via include/redirect
- domain_age — Registration age of a domain via RDAP (reuses the @pipeworx/rdap pack’s IANA-bootstrap RDAP client — the
- sending_domain_audit — One-call sending-domain risk audit: combines mx_gateway, auth_grade and domain_age, plus DNS/HTTP-only risk
- dnsbl_check — Check a domain or IP against Spamhaus DQS and/or SURBL DNSBLs. BYOK ONLY — requires an API key: Spamhaus DQS
Tools
auth_grade— Grade a domain's email-authentication posture: SPF (real RFC 7208 DNS-lookup count via include/redirectdnsbl_check— Check a domain or IP against Spamhaus DQS and/or SURBL DNSBLs. BYOK ONLY — requires an API key: Spamhaus DQSdomain_age— Registration age of a domain via RDAP (reuses the @pipeworx/rdap pack's IANA-bootstrap RDAP client — themx_gateway— Identify which secure email gateway fronts a domain's inbound mail — M365, Google Workspace, Mimecast,mx_gateway_batch— Run mx_gateway over up to 25 domains at once and return a per-domain breakdown plus a cohort tally bysending_domain_audit— One-call sending-domain risk audit: combines mx_gateway, auth_grade and domain_age, plus DNS/HTTP-only risk