Docs
Ask an AI about your email security.
Authex runs an MCP server. Add one URL to Claude or ChatGPT and you can scan any domain in plain language, or connect your account and ask about your whole fleet.
Connector URL
https://app.authexlabs.com/api/mcpThat is the whole configuration. There is no API key to generate.
Two ways to use it. Only one needs an account.
No account
Scan any domain
Reads public DNS for any domain on the internet, yours or not, and returns the same six protocol checks the free scanner runs. Useful for prospects, suppliers and competitors. Works the moment you add the URL.
Connected account
Read your own fleet
Your domains, who signs your mail, your DMARC activity, open agent actions, alerts, compliance readiness and your Microsoft 365 or Google Workspace reviews. Ask about your account and your AI client will offer to connect.
Setting it up.
Claude
- 01Open Settings, then Connectors.
- 02Choose Add custom connector.
- 03Paste https://app.authexlabs.com/api/mcp as the URL and save.
- 04Ask Claude to scan a domain. Nothing else is needed.
- 05To read your own account, ask about your domains. Claude will offer to connect, and you approve it on an Authex consent screen.
ChatGPT
- 01Open Settings, then Connectors, and enable developer mode if you do not see custom connectors.
- 02Choose to add a connector and paste the same URL.
- 03Ask it to scan a domain to confirm it works.
- 04Ask about your own domains when you want the account tools, and approve the Authex consent screen.
ChatGPT's connector settings move around more than most. If you cannot find custom connectors, the feature may not be enabled for your plan yet.
Any other MCP client
- 01Add the URL as a remote MCP server over streamable HTTP.
- 02The server advertises its own OAuth discovery, so a compliant client can complete the connection with no extra configuration.
- 03No API key is issued and none is needed. Authentication is OAuth or nothing.
What to ask it.
Without an account
- “Scan google.com and tell me how their email security looks.”
- “Compare the DMARC setup of stripe.com and shopify.com.”
- “Is this supplier domain safe to receive invoices from?”
- “Explain what is wrong with acme.com's SPF record.”
With your account connected
- “Which of my domains are not yet at DMARC enforcement?”
- “What is the single next action for each of my clients?”
- “Who is sending mail as my domain, and is any of it unexpected?”
- “Show me the alerts raised across my account this week.”
- “How do my domains stand against the Google and Yahoo bulk sender rules?”
- “Which Microsoft 365 tenants have outstanding security findings?”
What it will not do.
Every tool is read only. Nothing an AI client calls can change your DNS, add or remove a domain, alter a tenant, or touch your settings. The DNS agent applies real changes to real customer domains, and handing that to a chat window is not something we are willing to do.
Two limits worth knowing
A public scan probes common DKIM selectors only, so a DKIM result of not found means no common selector matched, never that a domain has no DKIM. And a published DMARC policy is not the same as a protected domain, which is why the scan reports whether the policy is actually enforced rather than only quoting it.
Your own domains read better
For a domain in your account, the account tools see your real DKIM selectors and your actual mail activity, so they are both more accurate and more complete than a public probe of the same domain.
Where your data goes
When you connect your account, the answers you ask for are sent to whichever AI provider you are using, and their handling is governed by their terms. You can revoke a connection at any time from Settings inside Authex.
If something is not working.
- It says I need to connect, but I already did.
- Check Settings inside Authex for the app under connected apps. If it is not listed, the connection did not finish. Remove the connector in your AI client and add it again.
- Scanning is refusing a domain.
- Give a plain registrable domain such as acme.com. Anything with an address, a path or extra characters is refused rather than guessed at, because guessing would mean reporting on a different domain than the one you asked about.
- It says I am asking too often.
- Scans are rate limited, more tightly when you are not signed in. Wait a minute and try again. Connecting your account raises the limit.
- A scan timed out.
- Usually the domain’s own nameservers are slow to answer. Trying again later generally works.
Try it on a domain you do not own.
No account needed. Add the URL, then ask about a supplier, a prospect, or your own company.