PluginBench
MCP Server
Active
Apache-2.0

Parse-DMARC MCP Server MCP Server

io.github.meysam81/parse-dmarc

Auto-fetch and visualize DMARC email authentication reports in a lightweight dashboard.

What is the Parse-DMARC MCP Server MCP server?

The Parse DMARC MCP Server is a lightweight DMARC parser that automatically fetches email authentication reports from your inbox and visualizes compliance data in a single dashboard. It helps you monitor who's sending email on behalf of your domain, catch spoofing attempts, and stop phishing by analyzing DMARC, SPF, and DKIM authentication results.

Parse DMARC simplifies DMARC report analysis by automatically retrieving compressed XML reports from your email inbox via IMAP and presenting them in an intuitive web dashboard. Instead of manually parsing technical XML files, you get real-time statistics on email authentication compliance, top sending sources, and policy actions—all in a 14MB Docker image with no database setup required.

How to install Parse-DMARC MCP Server

Copy-paste configuration for popular MCP clients.

transport: stdio
Config generated by PluginBench — verify against the source before use.
~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "parse-dmarc": {
      "command": "docker",
      "args": [
        "run",
        "-i",
        "--rm",
        "ghcr.io/meysam81/parse-dmarc:v1.4.7"
      ]
    }
  }
}

Tools & capabilities

Tools this server exposes to the agent.

  • Auto-fetch DMARC reports — Automatically retrieves DMARC aggregate reports from any IMAP inbox (Gmail, Outlook, etc.)
  • Dashboard statistics — Displays total messages analyzed, DMARC compliance rates, and authentication results via GET /api/statistics
  • Report listing and details — Paginated report list and detailed report views accessible via GET /api/reports and GET /api/reports/:id
  • Top sending sources — Shows top IP addresses and organizations sending email as your domain via GET /api/top-sources
  • DNS record generator — Built-in tool to help generate correct DMARC DNS records for domain setup
  • Prometheus metrics — Production-ready metrics endpoint at /metrics for monitoring and alerting integration

Use cases

  • Monitor email authentication compliance for your domain and detect unauthorized senders
  • Verify legitimate email services are properly configured with SPF and DKIM
  • Detect and investigate phishing attempts and domain spoofing attacks
  • Gradually enforce DMARC policies by reviewing reports before moving from p=none to p=quarantine or p=reject
  • Track DMARC compliance trends over time with historical report analysis
  • Integrate DMARC monitoring into your security infrastructure via Prometheus metrics

Parse-DMARC MCP Server MCP server FAQ

What is Parse DMARC and why do I need it?

Parse DMARC automatically fetches DMARC aggregate reports from your email inbox and displays them in a dashboard. DMARC reports show who's sending email claiming to be from your domain and whether they passed authentication (SPF/DKIM). Without this tool, reports arrive as compressed XML attachments that are nearly impossible to read manually.

Is Parse DMARC free?

Yes, Parse DMARC is open-source and free to use. It's available on GitHub and can be deployed to any cloud provider or self-hosted environment.

How do I install Parse DMARC in Cursor or Claude?

Parse DMARC is an MCP server that runs as a standalone service. You configure it with IMAP credentials for your email inbox, then access the dashboard via a web browser at http://localhost:8080. It integrates with Claude/Cursor through standard MCP protocol.

What authentication/credentials do I need?

You need IMAP credentials for the email inbox receiving your DMARC reports. For Gmail, use an App Password (not your regular password). For Outlook, use your regular password. You also need to set up a _dmarc TXT record in your domain's DNS to start receiving reports.

Do I need SPF and DKIM configured first?

No. DMARC reports will show you whether SPF and DKIM are passing or failing, which helps you configure them correctly. You can start with DMARC monitoring (p=none policy) and gradually enforce it as you fix authentication issues.

How long before I see DMARC reports?

After adding the _dmarc TXT record to your DNS, reports typically start arriving within 24-48 hours. The amount of email traffic doesn't matter—even small domains with a few emails per day will receive useful reports.

README (reference)

Source of truth, from the repository.

Parse DMARC

CI License GitHub release GitHub Stars GitHub Issues Go Report Card

Made with Go Made with Vue.js Docker Hub Docker Pulls Docker Image Size (tag)

Conventional Commits Renovate

Monitor who's sending email on behalf of your domain. Catch spoofing. Stop phishing.

Parse DMARC

Deploy Your Own Instance

Deploy Parse DMARC to your favorite cloud provider with one click:

Platform as a Service (PaaS)

ProviderDeployNotes
RailwayDeploy on RailwayRecommended for beginners
RenderDeploy to RenderFree tier available
KoyebDeploy to KoyebGlobal edge deployment. Manually mount /data as volume.
ZeaburDeploy on ZeaburAsia-Pacific optimized
NorthflankDeploy to NorthflankDeveloper-focused

Self-Hosted

ProviderDeployNotes
CapRoverDeploy to CapRoverSelf-hosted PaaS
CoolifyDeploy to CoolifyOpen-source Heroku alternative
DokployDeploy to DokploySelf-hosted deployment platform
DockerDockerRun anywhere

Infrastructure

ProviderDeployNotes
DigitalOcean DropletDeploy to DigitalOceanVM with Packer image

Note: All deployments require IMAP credentials. See Configuration for details on setting up Gmail, Outlook, or other email providers.

Why Do I Need This?

DMARC (Domain-based Message Authentication, Reporting & Conformance) helps protect your domain from email spoofing and phishing. When you enable DMARC on your domain, email providers like Gmail, Outlook, and Yahoo send you aggregate reports showing:

  • Who's sending email claiming to be from your domain
  • Which emails passed or failed authentication (SPF/DKIM)
  • How many emails were sent, and from which IP addresses
  • Whether malicious actors are trying to impersonate your domain

The Problem: These reports arrive as compressed XML attachments in your inbox - nearly impossible to read or analyze manually.

The Solution: Parse DMARC automatically fetches these reports from your inbox, parses them, and displays everything in a beautiful dashboard. All in a single 14MB Docker image.

Features

  • 📧 Auto-fetches reports from any IMAP inbox (Gmail, Outlook, etc.)
  • 📊 Beautiful dashboard with real-time statistics
  • 🔍 See exactly who's sending email as your domain
  • 🔧 Built-in DNS record generator for easy DMARC setup
  • 📦 Single binary - no databases to install, no complex setup
  • 🚀 Tiny 14MB Docker image
  • 🔒 Secure TLS support
  • 🌙 Dark mode support

Installation

Homebrew (macOS/Linux)

brew tap meysam81/tap
brew install parse-dmarc

Docker

docker pull meysam81/parse-dmarc

Binary Downloads

Download pre-built binaries from the Releases page.

Quick Start

Step 1: Set Up DNS to Receive DMARC Reports

This is the most important step! Without this, you won't receive any reports to analyze.

Add a DMARC TXT record to your domain's DNS:

Name: _dmarc.yourdomain.com
Type: TXT
Value: v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com

What this means:

  • p=none - Monitor only (don't block emails yet)
  • rua=mailto:dmarc@yourdomain.com - Send aggregate reports to this email address

Important: Replace dmarc@yourdomain.com with an actual email inbox you control. This is where Gmail, Outlook, Yahoo, etc. will send your DMARC reports.

DNS Examples:

  • Cloudflare: DNS > Add record > Type: TXT, Name: _dmarc, Content: v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com
  • Google Domains: DNS > Custom records > TXT, Name: _dmarc, Data: v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com
  • AWS Route53: Create record > Type: TXT, Name: _dmarc.yourdomain.com, Value: "v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com"

Reports typically start arriving within 24-48 hours.

Step 2: Run Parse DMARC with Docker

Run the container:

docker run -d \
  --name parse-dmarc \
  -p 8080:8080 \
  -e IMAP_HOST=imap.gmail.com \
  -e IMAP_PORT=993 \
  -e IMAP_USERNAME=your-email@gmail.com \
  -e IMAP_PASSWORD=your-app-password \
  -v parse-dmarc:/data \
  meysam81/parse-dmarc

For Gmail users: You'll need an App Password, not your regular Gmail password.

Access the dashboard: Open http://localhost:8080 in your browser.

What You'll See

Once DMARC reports start arriving and Parse DMARC processes them, your dashboard will show:

  • Total messages analyzed across all reports
  • DMARC compliance rate (SPF/DKIM pass rates)
  • Top sending sources (IP addresses and organizations sending as your domain)
  • Authentication results (which emails passed/failed SPF and DKIM)
  • Policy actions (how receiving servers handled your email)

This helps you:

  • Verify your legitimate email services are properly configured
  • Detect unauthorized use of your domain
  • Gradually move from monitoring (p=none) to enforcement (p=quarantine or p=reject)

Configuration Options

IMAP Settings for Common Providers

Gmail:

{
  "host": "imap.gmail.com",
  "port": 993,
  "username": "your-email@gmail.com",
  "password": "your-app-password",
  "use_tls": true
}

Requires App Password

Outlook/Office 365:

{
  "host": "outlook.office365.com",
  "port": 993,
  "username": "your-email@outlook.com",
  "password": "your-password",
  "use_tls": true
}

Generic IMAP: Most providers use port 993 with TLS. Check your provider's documentation.

Command Line Options

# Fetch once and exit (useful for cron jobs)
docker exec parse-dmarc ./parse-dmarc -fetch-once

# Serve dashboard only (no fetching)
docker exec parse-dmarc ./parse-dmarc -serve-only

# Custom fetch interval (in seconds, default 300)
docker exec parse-dmarc ./parse-dmarc -fetch-interval=600

Frequently Asked Questions

Q: I'm not receiving any reports. What's wrong?

A: Check these things in order:

  1. Did you add the _dmarc TXT record to your DNS? (Use a DNS checker like dig _dmarc.yourdomain.com TXT)
  2. Wait 24-48 hours - reports aren't instant
  3. Is your domain sending/receiving email? No email = no reports
  4. Check your IMAP credentials are correct in config.json

Q: Do I need SPF and DKIM set up first?

A: No! DMARC reports will show you whether SPF and DKIM are passing or failing, which helps you configure them correctly.

Q: What should my DMARC policy be?

A: Start with p=none (monitoring only). After reviewing reports and fixing any issues, gradually move to p=quarantine and then p=reject.

Q: How much email traffic do I need?

A: Any amount works. Even small domains with a few emails per day will receive useful reports.

Q: Can I use a Gmail account to receive reports?

A: Yes! Create a dedicated Gmail like dmarc@yourdomain.com, forward it to your personal Gmail if needed, and use Gmail's IMAP settings.

Advanced

Building from Source

git clone https://github.com/meysam81/parse-dmarc.git
cd parse-dmarc
just install-deps
just build
./bin/parse-dmarc -config=config.json

Docker Compose

See compose.yml for Docker Compose configuration.

API Endpoints

  • GET /api/statistics - Dashboard statistics
  • GET /api/reports - List of reports (paginated)
  • GET /api/reports/:id - Detailed report view
  • GET /api/top-sources - Top sending source IPs
  • GET /metrics - Prometheus metrics endpoint

Prometheus Metrics & Grafana Integration

Parse DMARC includes production-ready Prometheus metrics for monitoring and alerting. Metrics are enabled by default and exposed at /metrics.

Available Metrics

Build Information

MetricTypeDescription
parse_dmarc_build_infoGaugeBuild information (version, commit, build_date)

Report Processing

MetricTypeDescription
parse_dmarc_reports_fetched_totalCounterTotal DMARC report emails fetched from IMAP
parse_dmarc_reports_parsed_totalCounterTotal DMARC reports successfully parsed
parse_dmarc_reports_stored_totalCounterTotal DMARC reports stored in database
parse_dmarc_reports_parse_errors_totalCounterTotal parse errors
parse_dmarc_reports_store_errors_totalCounterTotal storage errors
parse_dmarc_reports_attachments_totalCounterTotal attachments processed
parse_dmarc_reports_fetch_duration_secondsHistogramDuration of fetch operations
parse_dmarc_reports_last_fetch_timestamp_secondsGaugeUnix timestamp of last successful fetch
parse_dmarc_reports_fetch_cycles_totalCounterTotal fetch cycles executed
parse_dmarc_reports_fetch_errors_totalCounterTotal fetch cycle errors

IMAP Connection

MetricTypeLabelsDescription
parse_dmarc_imap_connections_totalCounterstatusIMAP connection attempts (success/error)
parse_dmarc_imap_connection_duration_secondsHistogramIMAP connection establishment duration

DMARC Statistics

MetricTypeDescription
parse_dmarc_dmarc_reports_totalGaugeTotal reports in database
parse_dmarc_dmarc_messages_totalGaugeTotal messages across all reports
parse_dmarc_dmarc_compliant_messages_totalGaugeTotal DMARC-compliant messages
parse_dmarc_dmarc_compliance_rateGaugeOverall compliance rate (0-100)
parse_dmarc_dmarc_unique_source_ipsGaugeNumber of unique source IPs
parse_dmarc_dmarc_unique_domainsGaugeNumber of unique domains

Per-Domain/Org Metrics

MetricTypeLabelsDescription
parse_dmarc_dmarc_messages_by_domainGaugedomainMessages per domain
parse_dmarc_dmarc_compliance_rate_by_domainGaugedomainCompliance rate per domain
parse_dmarc_dmarc_reports_by_orgGaugeorg_nameReports per organization
parse_dmarc_dmarc_messages_by_dispositionGaugedispositionMessages by disposition type

Authentication Results

MetricTypeLabelsDescription
parse_dmarc_dmarc_spf_resultsGaugeresultSPF authentication result counts
parse_dmarc_dmarc_dkim_resultsGaugeresultDKIM authentication result counts

HTTP Server

MetricTypeLabelsDescription
parse_dmarc_http_requests_totalCountermethod, path, statusTotal HTTP requests
parse_dmarc_http_request_duration_secondsHistogrammethod, pathHTTP request duration
parse_dmarc_http_requests_in_flightGaugeCurrent in-flight requests

Go Runtime (Built-in)

Standard Go runtime metrics are also exposed:

  • go_goroutines - Number of goroutines
  • go_memstats_* - Memory statistics
  • go_gc_* - Garbage collection metrics
  • process_* - Process metrics (CPU, memory, file descriptors)

Disabling Metrics

To disable the metrics endpoint:

# Command line
./parse-dmarc --metrics=false

# Environment variable
export PARSE_DMARC_METRICS=false

# Docker
docker run -e PARSE_DMARC_METRICS=false meysam81/parse-dmarc

Prometheus Configuration

Add Parse DMARC to your prometheus.yml:

scrape_configs:
  - job_name: "parse-dmarc"
    static_configs:
      - targets: ["parse-dmarc:8080"]
    scrape_interval: 30s
    metrics_path: /metrics

For Kubernetes with ServiceMonitor (Prometheus Operator):

apiVersion: monitoring.coreos.com/v1
kind: ServiceMonitor
metadata:
  name: parse-dmarc
  labels:
    app: parse-dmarc
spec:
  selector:
    matchLabels:
      app: parse-dmarc
  endpoints:
    - port: http
      path: /metrics
      interval: 30s

Grafana Dashboard

A production-ready Grafana dashboard is included in grafana/dashboard.json.

Import Manually

  1. In Grafana, go to Dashboards > Import
  2. Upload grafana/dashboard.json or paste its contents
  3. Select your Prometheus datasource
  4. Click Import

Provision Automatically (Recommended for Production)

# Copy dashboard to Grafana dashboards directory
cp grafana/dashboard.json /var/lib/grafana/dashboards/parse-dmarc/

# Copy provisioning config
cp grafana/provisioning.yaml /etc/grafana/provisioning/dashboards/parse-dmarc.yaml

# Restart Grafana or wait for it to pick up changes
systemctl restart grafana-server

Dashboard Variables

VariablePurpose
datasourcePrometheus datasource to query
jobFilter by Prometheus job label
instanceFilter by instance(s)
domainFilter by monitored domain(s)

Dashboard Sections

SectionWhat It Shows
Overview - Golden SignalsCompliance rate, total messages, reports count, time since last fetch
DMARC Authentication ResultsSPF/DKIM pass rates, disposition breakdown, per-domain compliance
Report Sources & OrganizationsTop reporting organizations (Google, Microsoft, etc.), messages by domain
IMAP & Fetch OperationsConnection health, fetch cycle monitoring, latency heatmaps
Error TrackingParse errors, storage errors, fetch failures
HTTP ServerRequest rates, latency percentiles, error rates
Go RuntimeGoroutines, memory usage, GC stats, CPU usage

Example Grafana Panels

Compliance Rate Gauge:

parse_dmarc_dmarc_compliance_rate

Messages Over Time:

rate(parse_dmarc_dmarc_messages_total[5m])

Compliance Rate by Domain:

parse_dmarc_dmarc_compliance_rate_by_domain

SPF/DKIM Pass Rate:

# SPF Pass Rate
parse_dmarc_dmarc_spf_results{result="pass"} / ignoring(result) sum(parse_dmarc_dmarc_spf_results) * 100

# DKIM Pass Rate
parse_dmarc_dmarc_dkim_results{result="pass"} / ignoring(result) sum(parse_dmarc_dmarc_dkim_results) * 100

Fetch Success Rate:

1 - (rate(parse_dmarc_reports_fetch_errors_total[1h]) / rate(parse_dmarc_reports_fetch_cycles_total[1h]))

IMAP Connection Health:

rate(parse_dmarc_imap_connections_total{status="success"}[5m]) /
(rate(parse_dmarc_imap_connections_total{status="success"}[5m]) + rate(parse_dmarc_imap_connections_total{status="error"}[5m]))

HTTP Request Latency (p95):

histogram_quantile(0.95, rate(parse_dmarc_http_request_duration_seconds_bucket[5m]))

Reports by Organization:

topk(10, parse_dmarc_dmarc_reports_by_org)

Alerting Rules

Example Prometheus alerting rules:

groups:
  - name: parse-dmarc
    rules:
      - alert: DMARCComplianceLow
        expr: parse_dmarc_dmarc_compliance_rate < 90
        for: 1h
        labels:
          severity: warning
        annotations:
          summary: "DMARC compliance rate is below 90%"
          description: "Current compliance rate: {{ $value }}%"

      - alert: DMARCFetchFailures
        expr: rate(parse_dmarc_reports_fetch_errors_total[15m]) > 0
        for: 30m
        labels:
          severity: critical
        annotations:
          summary: "Parse DMARC fetch failures detected"
          description: "IMAP fetch operations are failing"

      - alert: IMAPConnectionErrors
        expr: rate(parse_dmarc_imap_connections_total{status="error"}[5m]) > 0
        for: 10m
        labels:
          severity: warning
        annotations:
          summary: "IMAP connection errors detected"
          description: "Check IMAP credentials and server connectivity"

      - alert: NoRecentFetch
        expr: time() - parse_dmarc_reports_last_fetch_timestamp_seconds > 600
        for: 5m
        labels:
          severity: warning
        annotations:
          summary: "No recent DMARC report fetch"
          description: "Last fetch was {{ humanizeDuration $value }} ago"

Docker Compose with Prometheus & Grafana

Complete monitoring stack:

version: "3.8"

services:
  parse-dmarc:
    image: meysam81/parse-dmarc
    ports:
      - "8080:8080"
    volumes:
      - ./config.json:/app/config.json
      - ./data:/data

  prometheus:
    image: prom/prometheus
    ports:
      - "9090:9090"
    volumes:
      - ./prometheus.yml:/etc/prometheus/prometheus.yml
    command:
      - "--config.file=/etc/prometheus/prometheus.yml"

  grafana:
    image: grafana/grafana
    ports:
      - "3000:3000"
    environment:
      - GF_SECURITY_ADMIN_PASSWORD=admin
    volumes:
      - grafana-data:/var/lib/grafana

volumes:
  grafana-data:

With prometheus.yml:

global:
  scrape_interval: 15s

scrape_configs:
  - job_name: "parse-dmarc"
    static_configs:
      - targets: ["parse-dmarc:8080"]

Access:

Why Parse DMARC vs ParseDMARC?

This project is inspired by ParseDMARC but built for simplicity:

  • Single 14MB binary vs Python + Elasticsearch + Kibana stack
  • Built-in dashboard vs external visualization tools
  • SQLite vs Elasticsearch (no JVM required)
  • Zero dependencies vs complex setup

Contributing

Issues and pull requests are welcome! Please check the issues page.

License

Apache-2.0 - see LICENSE for details.


Found this useful? Star the repo! ⭐

Related MCP servers

Free App Store competitive intelligence for Claude — rival downloads, revenue, and ASO keywords.

3
JavaScript
MIT
View repository →

Colter audits product pages for AI shopping agents and returns fixes, tests, and Evidence Packs.

View repository →
OKokf-mcp logo

okf-mcp

Active

Validate, search, graph, and safely author local Open Knowledge Format bundles.

4
JavaScript
MIT
View repository →

Virtual travel avatar on Google Maps with AI image generation and SNS integration for MCP clients.

23
TypeScript
MIT
View repository →

Navigate and query OpenAPI specs with fuzzy search, pagination, and API testing

View repository →

Search, read and act on Apple Calendar — ranges, free-time lookup, writes off by default

4
TypeScript
MIT
View repository →