palisade-mcp
Local stdio bridge to the Palisade MCP server (SPF, DKIM, DMARC, MTA-STS, BIMI).
Documentation
@palisadeemail/mcp
Connect an MCP client to the Palisade Email Authentication MCP, which monitors and manages SPF, DKIM, DMARC, MTA-STS, and BIMI for your domains.
Palisade's MCP server is remote (Streamable HTTP at `https://api.palisade.email/mcp`). This package is a thin local bridge for stdio-based clients, using `mcp-remote` under the hood. Clients that support remote HTTP MCP servers with a bearer token can point at the URL directly and skip this package.
Get an API key
Create one at app.palisade.email → Settings → API keys, or programmatically via headless signup. See the Palisade MCP guide.
Use it
Set `PALISADE_API_KEY` and run:
PALISADE_API_KEY=secret_... npx -y @palisadeemail/mcpClient config (stdio)
{
"mcpServers": {
"palisade": {
"command": "npx",
"args": ["-y", "@palisadeemail/mcp"],
"env": { "PALISADE_API_KEY": "secret_..." }
}
}
}Direct (clients that support remote HTTP MCP)
{
"mcpServers": {
"palisade": {
"type": "http",
"url": "https://api.palisade.email/mcp",
"headers": { "Authorization": "Bearer secret_..." }
}
}
}When `headers.Authorization` is set, the client authenticates with that API key and does not fall back to OAuth. The server replies `401` with a `WWW-Authenticate` challenge whenever credentials are missing or rejected, so a bad key surfaces as a connection error rather than silently starting an OAuth flow. The one exception is API-key-only discovery below, where a client opts out of that challenge on purpose.
API-key-only discovery
Some MCP directories probe an endpoint before they forward a configured API key. For those
clients, use `https://api.palisade.email/mcp?auth=api-key`. It keeps API-key authentication
enabled but omits the OAuth discovery challenge from an unauthenticated probe. Send the same
`Authorization: Bearer secret_...` header after connecting.
If the server connects but the Palisade tools are missing
A session that offers only `authenticate` / `complete_authentication` is using an OAuth-based entry, not your API-key entry. The Palisade server has no reduced tool set: any authenticated caller gets the full list under Tools. Those two tools come from the client's own pending-OAuth state.
This usually means a same-named server is configured somewhere else and is the one in effect. In Claude Code, `--scope local` applies only to the directory it was run in, and a `palisade` entry in user scope (from a previous OAuth connection) applies everywhere else. Check which entry actually wins:
claude mcp get palisadeThe reported scope is the one in effect. If it is not the entry holding your API key, remove the other one, for example `claude mcp remove palisade -s user`, or give the API-key entry a distinct name.
Tools
Accounts (`get_account`), domains (`list_domains`, `get_domain`, `create_domain`, `update_domain`, `delete_domain`, `verify_domain`), DNS setup (`get_dns_records`, which returns the exact records to publish at your own DNS provider), SPF diagnostics (`get_spf`, which reads the live record, its DNS lookup count against the 10-lookup limit, and the problems found), hosted DMARC (`enable_hosted_dmarc`), MTA-STS (`get_mta_sts`, `enable_mta_sts`, `disable_mta_sts`), remediation tasks (`list_tasks`, `get_task`, `complete_task`, `dismiss_task`), DMARC reporting (`get_dmarc_summary`, `list_dmarc_senders`, which report aggregate figures and per-source breakdowns rather than raw report XML), groups (`list_groups`, `create_group`, `update_group`, `delete_group`), billing (`get_subscription`, `start_checkout`, `start_billing_portal`), and webhooks (`list_webhook_events`, `list_webhook_endpoints`, `create_webhook_endpoint`, `delete_webhook_endpoint`).
Palisade tells you which DNS records to publish; you apply them at whatever DNS provider hosts the domain. Payment happens on Stripe-hosted pages. Webhooks are the alternative to polling for long-running state changes: `create_webhook_endpoint` returns the signing secret once and never again, so store it when it is issued.
Environment
- `PALISADE_API_KEY` (required) — your Palisade API key.
- `PALISADE_MCP_URL` (optional) — override the server URL (defaults to `https://api.palisade.email/mcp`).
Frequently asked questions
What is palisade-mcp?
palisade-mcp is Local stdio bridge to the Palisade MCP server (SPF, DKIM, DMARC, MTA-STS, BIMI).
How do I install palisade-mcp?
Open the GitHub repository and follow its README. Most MCP servers are added to your client's MCP config, then called by your agent.
Is palisade-mcp open source?
Yes — it is hosted on GitHub at https://github.com/palisadeemail/palisade-mcp.
Related MCP tools
🔥 Official Firecrawl MCP Server - Adds powerful web scraping and search to Cursor, Claude and any other LLM clients. JavaScript-based implementation.
A server that integrates Linear's project management system with the Model Context Protocol (MCP) to allow LLMs to interact with Linear.
CTTF: MCP integration between Cursor and Figma, allowing Cursor Agentic AI to communicate with Figma for reading designs and modifying them programmatically.
Shrimp Task Manager is a task tool built for AI Agents, emphasizing chain-of-thought, reflection, and style consistency.
A model context protocol server to work with JetBrains IDEs: IntelliJ, PyCharm, WebStorm, etc. Also, works with Android Studio
An MCP client for Neovim that seamlessly integrates MCP servers into your editing workflow with an intuitive interface for managing, testing, and using MCP s...
Run your own MCP server? See who uses it and what to fix.
Measure it with TrackMCP