Skip to main content
Connector guides

Connect EasyDMARC

EasyDMARC is an email-authentication platform. It receives the DMARC reports that mailbox providers send about your clients' domains, checks and generates SPF, DKIM, DMARC, BIMI, MTA-STS and TLS-RPT…

Written By Christopher Scaminaci

Last updated About 3 hours ago

EasyDMARC is an email-authentication platform. It receives the DMARC reports that mailbox providers send about your clients' domains, checks and generates SPF, DKIM, DMARC, BIMI, MTA-STS and TLS-RPT records, watches DNS for changes, and gives an MSP one console for every client domain. StackJack talks to it through the EasyDMARC public API, the same interface EasyDMARC documents for integrations.

Connecting EasyDMARC to StackJack gives your AI assistant a family of easydmarc_ MCP tools. MCP (Model Context Protocol) tools are the standardized commands an AI assistant can call through StackJack. With them, your AI can:

  • Answer the daily DMARC questions - is a client's SPF over the ten-lookup limit, is DMARC at p=reject, does a DKIM selector resolve, is BIMI valid. Single and batch lookups for every record type, plus the parsed record structure and the record to publish
  • Draft the fix - generate an MTA-STS or TLS-RPT record, build a DMARC record from a structure, and read the exact record EasyDMARC wants published for a domain
  • See who is sending as a domain - the parsed aggregate (RUA) reports, with SPF and DKIM pass and fail counts, volume over time, distinct senders and countries, and pass rates, so "can we move this client to quarantine" has an answer
  • Investigate a spoofing or phishing report - the forensic (RUF) reports, their statistics, and short-lived links to the original message and its attachments
  • See what changed - the audit log of an organization, as a list or as a CSV file
  • List the estate - an organization's domains, with their type, policy and verification state, and its domain groups

It can also make changes, on the Pro tier:

  • Onboard and tidy domains - add one domain or many, move a domain between groups or to parked, add several existing domains to a group or take one out, create and rename groups, delete a retired domain
  • Manage webhooks - create, update, delete and re-key the webhooks that deliver EasyDMARC events to your own systems
  • Administer partner accounts - create, rename and delete client organizations, invite or create users, remove their access, assign, renew, cancel and change subscription plans, and add or remove payment methods

Reading is free. Every change needs the Pro tier, and the ones that cannot be undone, or that change what you are billed, are labelled so your AI assistant asks before running them.

What you need first

  • An EasyDMARC plan with API access. API access is part of the Enterprise (Email Trust) plan and the MSP plan. The DMARC Plus, DMARC Premium and Deliverability plans cannot create API credentials.
  • A partner agreement, for the partner tools only. Organizations, users, billing, plans and the partner profile belong to EasyDMARC's Partner API, which EasyDMARC provisions through its partner team. An MSP on the MSP plan can create credentials itself, and the domain, report, DNS and audit log tools work with them. Without a partner agreement the partner tools answer "You don't have a partner account".

How StackJack authenticates to EasyDMARC

EasyDMARC gives you a Client ID and a Client Secret, created in the EasyDMARC Account Console under API Credentials. You paste both into StackJack.

There is no web address to enter. EasyDMARC runs one shared API for every customer, and StackJack already knows where it is.

Behind the scenes StackJack exchanges your Client ID and Secret for a short-lived access token whenever it needs one, and keeps it fresh on its own. EasyDMARC issues no refresh token, so there is nothing to renew on a schedule and nothing for you to rotate. If EasyDMARC ever rejects a token, StackJack gets a new one and tries once more before reporting a problem.

The Default Organization ID (optional)

Most EasyDMARC tools act on one organization: its domains, its reports, its audit log. One connection can reach every organization your API client can see, so each tool takes an organization ID. The Default Organization ID on the connection fills that in when a request does not name one, so you only have to type it once. Any request can still name a different organization.

A partner account can list every organization it owns with the organizations tool, so the box can stay empty. EasyDMARC does not say where an account without a partner agreement reads its organization ID. If you cannot find it, leave the box empty and give the ID in the request, or ask EasyDMARC support.

Steps

  1. Check your plan includes API access, as described above.
  2. Create an API client. Sign in to EasyDMARC, open the Account Console and go to API Credentials, then create a client for StackJack. EasyDMARC shows a Client ID and a Client Secret.
  3. Copy both values straight away. Treat the secret as a password and keep it somewhere safe.
  4. Find your organization ID, if you want a default (optional).
  5. Enter the details in StackJack. Open Connectors, choose EasyDMARC, paste the Client ID and the Client Secret, and add the Default Organization ID if you have one. The form asks for the Client ID and Client Secret every time you save it.
  6. Run a Test Connection. It proves the Client ID and Client Secret and that EasyDMARC accepts the token it issues. It does not prove access to any particular organization, so ask your AI to list the domains of one to confirm that.

What to know before your AI uses this connector

Partner tools need partner access

If the organizations, users, billing or partner profile tools answer "You don't have a partner account", or the request names an organization that does not belong to your partner account, the fix is the partner agreement or the organization ID, not a new key. The domain, report, DNS and audit log tools do not depend on it.

Some tools change what you are billed, or who has access

EasyDMARC's MSP plan is priced per managed domain, so adding domains can raise your bill. The partner subscription tools assign, renew, cancel and change plans, adding a payment method stores a payment token against a client organization, and the user tools invite people, create users directly with a role and remove access. Renaming an organization can also link it to a different partner account, which moves who manages and bills it. Replacing a whole domain record and taking a domain out of a group are labelled the same way. All of those are labelled as destructive so your AI assistant asks first. Cancelling a subscription, deleting an organization and removing a user's access cannot be undone from the API.

A few tools hand back a credential

Treat what these return as a password, and do not paste it into a ticket or a chat:

  • the sign-in link tool returns a single-use link that signs whoever opens it in as that user
  • creating a webhook and re-keying one return the signing secret used to verify deliveries, and reading or updating a webhook can return it too
  • the payment method and billing information reads return a client's stored payment details
  • the failure report and invoice download tools return an address that opens the file without further sign-in. A failure report link lives five minutes and carries the content of the original message

Some routes are documented but not switched on yet

EasyDMARC documents webhooks, DNS Intelligence, domain search and three single DNS lookups (TLS-RPT, MTA-STS and the MTA-STS policy CNAME), but its public gateway did not serve those routes when this connector was built. Four domain routes are in the same position because EasyDMARC's own specification marks them internal, under construction or not yet available: updating a whole domain record, verifying a domain's setup, adding several domains to a group and taking a domain out of a group. The tools are included. Until EasyDMARC turns those routes on, EasyDMARC answers that it cannot find the route. That is on EasyDMARC's side and says nothing about your credentials, and the neighbouring tools keep working, for example changing one field of a domain moves it to another group.

Failure reports carry message content

A failure (forensic) report describes an individual message that failed authentication, so it includes addresses and message metadata, and the detail tool can include the raw headers and body. EasyDMARC masks personal data by default. Grant these reads deliberately.

Plans and limits

Every read is available on the Free tier, including the ones EasyDMARC sends as a POST. Every change needs Pro. Business reaches the same tools as Pro and differs by monthly call quota.

See the generated EasyDMARC tool reference for the current inventory, plan assignment, input schemas, and destructive-action labels.

EasyDMARC allows 60 requests a minute per customer, plus daily limits it does not publish. StackJack paces itself below the minute limit and waits for the delay EasyDMARC asks for, so a wide sweep takes longer rather than failing. When you have several domains, use the batch DNS lookups: a batch counts once against the limit. Lists come back one page at a time, and StackJack always asks for a sensible number of rows on your behalf.

EasyDMARC sits behind Cloudflare. If Cloudflare ever challenges a request, StackJack reports it without counting it against your connection, so a passing challenge cannot switch off a working credential.

Several organizations and several accounts

One connection spans every organization the API client can reach, so an MSP with many client organizations needs one connection. If you hold more than one EasyDMARC account, add one connection per account from the connector's card, name each after the account, and your AI names it on each call. Omit the name and the call runs against your default connection. See Several connections of one connector.

Troubleshooting

"EasyDMARC did not accept the Client ID and Client Secret" - the API client was deleted, regenerated or disabled. Regenerating a client replaces both values. Open the Account Console, go to API Credentials, copy the pair again, paste both into the connection and run a Test Connection. Also check the plan still includes API access.

"EasyDMARC rejected the access token it had just issued (invalid_grant)" - StackJack already fetched a fresh token and tried once more, so the stored API client is the likely cause. Check it is still active in the Account Console, regenerate it if you are unsure, and paste the new pair in.

"organizationId is required" - the tool needs an organization and the request did not name one. Add a Default Organization ID to the connection, or give the ID in the request. A partner account can list its organizations first.

The partner tools say you do not have a partner account - that needs EasyDMARC's partner agreement, as described above. The other tools are unaffected.

"EasyDMARC's gateway does not serve this route yet" - the route is one of those EasyDMARC documents but has not switched on. Use the neighbouring tool, for example the domain list instead of domain search, or try again later.

Cloudflare challenged this request - nothing is wrong with the credentials and the connection was not counted as failing. It is usually a passing decision at the edge, so try again in a few minutes. If it keeps happening, open a support ticket.

Requests come back throttled - 60 requests a minute is shared across everything on your EasyDMARC customer account, including other integrations. Use the batch DNS lookups, ask for fewer rows per page, or space the work out. StackJack already waits for the delay EasyDMARC asks for.

A report tool returns nothing for a domain that has mail - the report tools are scoped by domain name and date range, and the domain must be added to the organization before its reports appear. Check the dates are ISO 8601, for example 2026-09-01T00:00:00.000Z.

EasyDMARC tools

easydmarc_ · 111 tools · Free 81 · Pro 30

DNS intelligence

ToolWhat it does
easydmarc_list_dns_intelligence_checks
Free · Read-only
List the DNS Intelligence checks that are available.
easydmarc_list_dns_intelligence_lookups
Free · Read-only
List the DNS lookup types DNS Intelligence can resolve.
easydmarc_list_dns_intelligence_profiles
Free · Read-only
List the DNS Intelligence profile operations that are available.
easydmarc_run_dns_intelligence_checks
Free · Read-only
Run a batch of DNS Intelligence checks against a domain.
easydmarc_run_dns_intelligence_lookup
Free · Read-only
Resolve one record type for a domain through DNS Intelligence.
easydmarc_run_dns_intelligence_profiles
Free · Read-only
Run a batch of DNS Intelligence profiles against a domain.

DNS lookup

ToolWhat it does
easydmarc_build_dmarc_record
Free · Read-only
Build a DMARC record string from a record structure.
easydmarc_generate_mta_sts_record
Free · Read-only
Generate an MTA-STS record and policy file for a domain.
easydmarc_generate_tls_rpt_record
Free · Read-only
Generate a TLS-RPT record for a domain.
easydmarc_get_dmarc_record_structure
Free · Read-only
Get the parsed structure of a domain's DMARC record.
easydmarc_get_dmarc_records_raw
Free · Read-only
Get the raw DMARC records of a domain.
easydmarc_get_dmarc_verification_status_batch
Free · Read-only
Check whether many domains publish EasyDMARC's report address.
easydmarc_get_spf_lookup_result
Free · Read-only
Get the structured SPF lookup result of a domain.
easydmarc_lookup_a
Free · Read-only
Look up the A record of a domain.
easydmarc_lookup_a_batch
Free · Read-only
Look up the A record of many domains in one call.
easydmarc_lookup_aaaa
Free · Read-only
Look up the AAAA record of a domain.
easydmarc_lookup_aaaa_batch
Free · Read-only
Look up the AAAA record of many domains in one call.
easydmarc_lookup_bimi
Free · Read-only
Look up the BIMI record of a domain.
easydmarc_lookup_bimi_batch
Free · Read-only
Look up the BIMI record of many domains in one call.
easydmarc_lookup_cname
Free · Read-only
Look up the CNAME record of a domain.
easydmarc_lookup_cname_batch
Free · Read-only
Look up the CNAME record of many domains in one call.
easydmarc_lookup_dkim
Free · Read-only
Look up DKIM records for a domain and a list of selectors.
easydmarc_lookup_dkim_batch
Free · Read-only
Look up DKIM records for many domain and selector sets in one call.
easydmarc_lookup_dkim_by_selectors
Free · Read-only
Look up DKIM records for selectors that each name their own domain.
easydmarc_lookup_dmarc
Free · Read-only
Look up and validate the DMARC record of a domain.
easydmarc_lookup_dmarc_batch
Free · Read-only
Look up and validate the DMARC record of many domains in one call.
easydmarc_lookup_mta_sts
Free · Read-only
Look up the MTA-STS record and policy file of a domain.
easydmarc_lookup_mta_sts_cname
Free · Read-only
Look up the MTA-STS CNAME of a domain.
easydmarc_lookup_mta_sts_mx_records
Free · Read-only
Look up the MX records MTA-STS policy generation would use.
easydmarc_lookup_mta_sts_policy_cname
Free · Read-only
Look up the MTA-STS policy-host CNAME of a domain.
easydmarc_lookup_mx
Free · Read-only
Look up the MX records of a domain.
easydmarc_lookup_mx_batch
Free · Read-only
Look up the MX record of many domains in one call.
easydmarc_lookup_ns
Free · Read-only
Look up the NS record of a domain.
easydmarc_lookup_ns_batch
Free · Read-only
Look up the NS record of many domains in one call.
easydmarc_lookup_ptr
Free · Read-only
Look up the PTR (reverse DNS) record of an IP address.
easydmarc_lookup_ptr_batch
Free · Read-only
Look up the PTR records of many IP addresses in one call.
easydmarc_lookup_spf
Free · Read-only
Look up and expand the SPF record of a domain.
easydmarc_lookup_spf_batch
Free · Read-only
Look up and expand the SPF record of many domains in one call.
easydmarc_lookup_tls_rpt
Free · Read-only
Look up and validate the TLS-RPT record of a domain.
easydmarc_lookup_tls_rpt_cname
Free · Read-only
Look up the TLS-RPT CNAME of a domain.
easydmarc_lookup_txt
Free · Read-only
Look up the TXT record of a domain.
easydmarc_lookup_txt_batch
Free · Read-only
Look up the TXT record of many domains in one call.
easydmarc_validate_bimi_record
Free · Read-only
Validate a BIMI record for a domain.

Domain groups

ToolWhat it does
easydmarc_add_domains_to_group
Pro · Write
Add existing domains to a domain group.
easydmarc_create_domain_group
Pro · Write
Create a domain group in an organization.
easydmarc_delete_domain_group
Pro · Destructive
DESTRUCTIVE: delete a domain group.
easydmarc_get_domain_group
Free · Read-only
Get one domain group and its domains.
easydmarc_list_domain_groups
Free · Read-only
List the domain groups of an organization.
easydmarc_remove_domain_from_group
Pro · Destructive
DESTRUCTIVE: remove a domain from a domain group.
easydmarc_rename_domain_group
Pro · Write
Rename a domain group.

Domains

ToolWhat it does
easydmarc_create_domain
Pro · Write
Add a domain to an organization.
easydmarc_create_domains_batch
Pro · Destructive
DESTRUCTIVE: add many domains to an organization in one call.
easydmarc_delete_domain
Pro · Destructive
DESTRUCTIVE: delete a domain from an organization.
easydmarc_get_domain
Free · Read-only
Get one domain of an organization.
easydmarc_get_domain_setup_record
Free · Read-only
Get the DMARC record to publish for a domain.
easydmarc_get_domains_overview
Free · Read-only
List domains with their details and date-ranged statistics.
easydmarc_list_domains
Free · Read-only
List the domains of an organization.
easydmarc_replace_domain
Pro · Destructive
DESTRUCTIVE: replace a domain's record (all fields required).
easydmarc_search_domains
Free · Read-only
Search and filter an organization's domains.
easydmarc_update_domain
Pro · Write
Change a domain's type, group or name.
easydmarc_verify_domain
Pro · Destructive
DESTRUCTIVE: verify a domain's setup, optionally setting its managed flag and tags.

Webhooks

ToolWhat it does
easydmarc_create_webhook
Pro · Destructive
DESTRUCTIVE: create a webhook that receives EasyDMARC events.
easydmarc_delete_webhook
Pro · Destructive
DESTRUCTIVE: delete a webhook.
easydmarc_get_webhook
Free · Read-only
Get one webhook.
easydmarc_list_webhook_deliveries
Free · Read-only
List the delivery attempts of a webhook.
easydmarc_list_webhooks
Free · Read-only
List the webhooks of an owner.
easydmarc_regenerate_webhook_secret
Pro · Destructive
DESTRUCTIVE: replace a webhook's signing secret.
easydmarc_update_webhook
Pro · Destructive
DESTRUCTIVE: update a webhook's name, URL, events or active flag.
ToolWhat it does
easydmarc_create_magic_link
Pro · Destructive
DESTRUCTIVE: create a single-use sign-in link for a user.

Billing information

ToolWhat it does
easydmarc_get_billing_info
Free · Read-only
Get the billing information of an organization.

Invoices

ToolWhat it does
easydmarc_get_invoice
Free · Read-only
Get one invoice of an organization.
easydmarc_get_invoice_pdf_url
Free · Read-only
Get a download URL for an invoice PDF.
easydmarc_list_invoices
Free · Read-only
List the invoices of an organization.

Organization users

ToolWhat it does
easydmarc_list_organization_users
Free · Read-only
List the users of an organization.

Organizations

ToolWhat it does
easydmarc_create_organization
Pro · Write
Create a customer organization.
easydmarc_delete_organization
Pro · Destructive
DESTRUCTIVE: delete an organization.
easydmarc_get_organization
Free · Read-only
Get one organization of a partner account.
easydmarc_list_organizations
Free · Read-only
List the organizations of a partner account.
easydmarc_update_organization
Pro · Destructive
DESTRUCTIVE: rename an organization or link it to a partner.

Partner profile

ToolWhat it does
easydmarc_get_partner_profile
Free · Read-only
Get the partner profile of the connection.

Payment methods

ToolWhat it does
easydmarc_add_payment_method
Pro · Destructive
DESTRUCTIVE: add a payment method (card or PayPal) to an organization.
easydmarc_list_payment_methods
Free · Read-only
List the payment methods of an organization.
easydmarc_remove_payment_method
Pro · Destructive
DESTRUCTIVE: remove a payment method from an organization.

Subscriptions and plans

ToolWhat it does
easydmarc_assign_subscription
Pro · Destructive
DESTRUCTIVE: assign a priced plan to an organization.
easydmarc_cancel_subscription
Pro · Destructive
DESTRUCTIVE: cancel a subscription.
easydmarc_change_subscription_plan
Pro · Destructive
DESTRUCTIVE: upgrade or downgrade a subscription to another price.
easydmarc_list_plans
Free · Read-only
List the plans and prices a partner can assign.
easydmarc_list_subscriptions
Free · Read-only
List the subscriptions of an organization.
easydmarc_list_subscriptions_bulk
Free · Read-only
List the subscriptions of many organizations in one call.
easydmarc_renew_subscription
Pro · Destructive
DESTRUCTIVE: renew a subscription.
easydmarc_set_subscription_auto_renew
Pro · Destructive
DESTRUCTIVE: turn a subscription's automatic renewal on or off.

Users

ToolWhat it does
easydmarc_create_users
Pro · Destructive
DESTRUCTIVE: create users directly in an organization.
easydmarc_get_user
Free · Read-only
Get one user of an organization.
easydmarc_invite_users
Pro · Destructive
DESTRUCTIVE: invite users to an organization by email.
easydmarc_revoke_user_access
Pro · Destructive
DESTRUCTIVE: remove users' access to an organization.
easydmarc_update_user_name
Pro · Write
Change a user's first or last name.

Aggregate reports

ToolWhat it does
easydmarc_get_rua_aggregations
Free · Read-only
Aggregate DMARC reports by field.
easydmarc_get_rua_auth_pass_rates
Free · Read-only
Get SPF and DKIM pass rates for domains.
easydmarc_get_rua_distinct_values
Free · Read-only
List the distinct values of one report field.
easydmarc_get_rua_report
Free · Read-only
Get one DMARC aggregate (RUA) report by id.
easydmarc_get_rua_volume
Free · Read-only
Get DMARC report volume grouped by field.
easydmarc_get_rua_volume_history
Free · Read-only
Get DMARC report volume over time (day, week or month).
easydmarc_list_rua_reports
Free · Read-only
List parsed DMARC aggregate (RUA) report rows.

Audit log

ToolWhat it does
easydmarc_export_audit_log
Free · Read-only
Export the audit log of an organization as a CSV file.
easydmarc_list_audit_log
Free · Read-only
List the audit log of an organization.

Failure reports

ToolWhat it does
easydmarc_get_failure_report
Free · Read-only
Get one failure report with optional headers and body.
easydmarc_get_failure_report_aggregates
Free · Read-only
Get failure report statistics grouped by dimension.
easydmarc_get_failure_report_attachment_url
Free · Read-only
Get a presigned URL for one attachment of a failure report.
easydmarc_get_failure_report_attachments_urls
Free · Read-only
Get presigned URLs for every attachment of a failure report.
easydmarc_get_failure_report_eml_url
Free · Read-only
Get a presigned URL for a failure report's original EML message.
easydmarc_list_failure_reports
Free · Read-only
List DMARC failure (forensic) reports.