DomainCanary Start free

Guides

Check your domain from ChatGPT or Claude

Last updated 1 Oct 2026

ChatGPT and Claude can't look up DNS records on their own, so when you ask why your mail fails DMARC, they guess. Add our connector and they read your live SPF, DKIM and DMARC records before they answer.

Do I need a DomainCanary account? No. The connector takes no sign-in, and it runs the same checks as the tools on this site.

Claude custom connector

  1. Open Customize, then Connectors, and click Add custom connector.
  2. Name it DomainCanary and enter https://domaincanary.com/mcp as the server URL. If the dialog asks how people sign in, choose No sign-in.
  3. Click Add.
  4. In a chat, click the + button at the lower left, open Connectors and turn DomainCanary on.

Every Claude plan can add custom connectors, and the Free plan allows one. On a Team or Enterprise plan, an Owner adds it under Organization settings, then Connectors, and each member connects from their own Connectors page.

ChatGPT developer mode

  1. Open Settings, then Security and login, and turn on Developer mode.
  2. Go to chatgpt.com/plugins and select the plus button.
  3. Name it DomainCanary and enter https://domaincanary.com/mcp as the server URL. It needs no authentication.
  4. Start a new conversation with DomainCanary turned on.

Developer mode depends on your account and on your workspace's policy. If you don't see it on a work account, ask your workspace admin.

Checks you can ask for

Ask in your own words, the way you'd ask a colleague.

  • Check a domain. "Check the email authentication on example.com" gets you what's wrong with its DMARC, SPF and DKIM records, and the records to publish.
  • Build an SPF record. "Build an SPF record for Google Workspace and Mailchimp" gets you one record for every sender you list, with its count of DNS lookups against the limit of 10. Give it your domain too, and it keeps the senders your record already has.
  • Explain a bounce. Paste the bounce, or just its code, such as 550 5.7.26. You get what the receiving server refused, what to change and when the bounces stop.
  • Read a DMARC report. Upload the .xml, .gz or .zip file in ChatGPT. In Claude, paste the XML. You get the message totals and the sending IP addresses that failed.

Answers link back to the site

Each answer ends with a link to the matching tool or guide on this site. A report answer lists up to 25 sending addresses per report, and the DMARC report analyzer shows up to 200.

Your input isn't logged

Nothing you send through the connector is written to our database, to disk or to a log. Each call writes one log line with the tool's name, whether it worked, how long it took and which assistant sent it. A domain check's answer stays in memory for ten minutes, so asking again doesn't repeat the DNS lookups. OpenAI and Anthropic hold your conversation under their own policies. Our privacy policy has the full list.

A DNS check shows what you've published. To see which of your real senders pass, you need the aggregate reports that receivers mail to your rua= address. Our weekly digest reads those reports and mails you the senders that failed.

Check all three records for your domain

SPF, DKIM and DMARC in one pass, read the way receivers read them.

Free · No signup · The result names what to change

Questions

Can the connector change my DNS records?

No. Every check reads public DNS or the text and files you give it. When an answer suggests a record, you publish it yourself at your DNS host.

What does "try again in a few minutes" mean?

Everyone who uses the connector shares one budget of DNS lookups, and each person gets a share of it every ten minutes. Wait as long as the message says, or run the same check on the page it links to.

DomainCanary is a DMARC enforcement service that protects your domain from email spoofing without blocking your own mail.