palisade-mcp
Local stdio bridge to the Palisade MCP server (SPF, DKIM, DMARC, MTA-STS, BIMI).
Documentation
@palisadeemail/mcp
Connect an MCP client to the Palisade Email Authentication MCP, which monitors and manages SPF, DKIM, DMARC, MTA-STS, and BIMI for your domains.
Palisade's MCP server is remote (Streamable HTTP at `https://api.palisade.email/mcp`). This package is a thin local bridge for stdio-based clients, using `mcp-remote` under the hood. Clients that support remote HTTP MCP servers with a bearer token can point at the URL directly and skip this package.
Get an API key
Create one at app.palisade.email → Settings → API keys, or programmatically via headless signup. See the Palisade MCP guide.
Use it
Set `PALISADE_API_KEY` and run:
PALISADE_API_KEY=secret_... npx -y @palisadeemail/mcpClient config (stdio)
{
"mcpServers": {
"palisade": {
"command": "npx",
"args": ["-y", "@palisadeemail/mcp"],
"env": { "PALISADE_API_KEY": "secret_..." }
}
}
}Direct (clients that support remote HTTP MCP)
{
"mcpServers": {
"palisade": {
"type": "http",
"url": "https://api.palisade.email/mcp",
"headers": { "Authorization": "Bearer secret_..." }
}
}
}When `headers.Authorization` is set, the client authenticates with that API key and does not fall back to OAuth. The server replies `401` with a `WWW-Authenticate` challenge whenever credentials are missing or rejected, so a bad key surfaces as a connection error rather than silently starting an OAuth flow. The one exception is API-key-only discovery below, where a client opts out of that challenge on purpose.
API-key-only discovery
Some MCP directories probe an endpoint before they forward a configured API key. For those
clients, use `https://api.palisade.email/mcp?auth=api-key`. It keeps API-key authentication
enabled but omits the OAuth discovery challenge from an unauthenticated probe. Send the same
`Authorization: Bearer secret_...` header after connecting.
If the server connects but the Palisade tools are missing
A session that offers only `authenticate` / `complete_authentication` is using an OAuth-based entry, not your API-key entry. The Palisade server has no reduced tool set: any authenticated caller gets the full list under Tools. Those two tools come from the client's own pending-OAuth state.
This usually means a same-named server is configured somewhere else and is the one in effect. In Claude Code, `--scope local` applies only to the directory it was run in, and a `palisade` entry in user scope (from a previous OAuth connection) applies everywhere else. Check which entry actually wins:
claude mcp get palisadeThe reported scope is the one in effect. If it is not the entry holding your API key, remove the other one, for example `claude mcp remove palisade -s user`, or give the API-key entry a distinct name.
Tools
Accounts (`get_account`), domains (`list_domains`, `get_domain`, `create_domain`, `update_domain`, `delete_domain`, `verify_domain`), DNS setup (`get_dns_records`, which returns the exact records to publish at your own DNS provider), SPF diagnostics (`get_spf`, which reads the live record, its DNS lookup count against the 10-lookup limit, and the problems found), hosted DMARC (`enable_hosted_dmarc`), MTA-STS (`get_mta_sts`, `enable_mta_sts`, `disable_mta_sts`), remediation tasks (`list_tasks`, `get_task`, `complete_task`, `dismiss_task`), DMARC reporting (`get_dmarc_summary`, `list_dmarc_senders`, which report aggregate figures and per-source breakdowns rather than raw report XML), groups (`list_groups`, `create_group`, `update_group`, `delete_group`), billing (`get_subscription`, `start_checkout`, `start_billing_portal`), and webhooks (`list_webhook_events`, `list_webhook_endpoints`, `create_webhook_endpoint`, `delete_webhook_endpoint`).
Palisade tells you which DNS records to publish; you apply them at whatever DNS provider hosts the domain. Payment happens on Stripe-hosted pages. Webhooks are the alternative to polling for long-running state changes: `create_webhook_endpoint` returns the signing secret once and never again, so store it when it is issued.
Environment
- `PALISADE_API_KEY` (required) — your Palisade API key.
- `PALISADE_MCP_URL` (optional) — override the server URL (defaults to `https://api.palisade.email/mcp`).
Frequently asked questions
What is palisade-mcp?
palisade-mcp is Local stdio bridge to the Palisade MCP server (SPF, DKIM, DMARC, MTA-STS, BIMI).
How do I install palisade-mcp?
Open the GitHub repository and follow its README. Most MCP servers are added to your client's MCP config, then called by your agent.
Is palisade-mcp open source?
Yes — it is hosted on GitHub at https://github.com/palisadeemail/palisade-mcp.
Related MCP tools
🔥 Official Firecrawl MCP Server - Adds powerful web scraping and search to Cursor, Claude and any other LLM clients. JavaScript-based implementation.
A model context protocol server to work with JetBrains IDEs: IntelliJ, PyCharm, WebStorm, etc. Also, works with Android Studio
A server that integrates Linear's project management system with the Model Context Protocol (MCP) to allow LLMs to interact with Linear.
CTTF: MCP integration between Cursor and Figma, allowing Cursor Agentic AI to communicate with Figma for reading designs and modifying them programmatically.
Shrimp Task Manager is a task tool built for AI Agents, emphasizing chain-of-thought, reflection, and style consistency.
A model context protocol server to work with JetBrains IDEs: IntelliJ, PyCharm, WebStorm, etc. Also, works with Android Studio
Run your own MCP server? See who uses it and what to fix.
Measure it with TrackMCP