secureIT API & MCP server
My security checks aren’t just available as a form, but openly as an interface: as a REST API and as an MCP server (Model Context Protocol). This lets an AI assistant such as Claude or ChatGPT call the checks directly and explain the result. No registration, no API key, free of charge.
https://secureit.icu/mcphttps://secureit.icu/api/v1https://secureit.icu/openapi.jsonhttps://secureit.icu/llms.txtWhat you can check with it
| Check | What it does | Automatable |
|---|---|---|
| Phishing self-test /api/v1/phishing-selbsttest |
Will a person fall for a genuine-looking attack email? | only with approval |
| Spoofing check /api/v1/spoofing-check |
Can someone forge an email in your name? (CEO fraud) | only with approval |
| Deliverability check /api/v1/mailcheck |
Do your emails reach recipients properly authenticated? | open |
| Domain check /api/v1/dns-check |
Are SPF, DKIM and DMARC actually set up correctly? | open |
Connecting the MCP server
The server speaks JSON-RPC 2.0 over HTTP POST (Streamable HTTP, no SSE). There’s nothing to install — you simply enter the address:
{
"mcpServers": {
"secureit": {
"type": "http",
"url": "https://secureit.icu/mcp"
}
}
}
Available tools:
dns_check— rate a domain’s SPF, DKIM and DMARC from the DNSmailcheck_start/mailcheck_ergebnis— how a mailbox actually authenticatesspoofing_check_anfordern/spoofing_check_status— check sender spoofing (CEO fraud)phishing_selbsttest_anfordern/phishing_selbsttest_status— test susceptibility to phishingtests_liste— list all checks including usage rules
REST API: an example
The domain check needs nothing but a domain and responds immediately:
curl "https://secureit.icu/api/v1/dns-check?domain=example.com"
The response rates SPF, DKIM, DMARC and MX individually (gut, schwach, fehlt, unbekannt — good, weak, missing, unknown), gives an overall verdict and concrete recommendations in plain language (in German). All endpoints are fully described in the OpenAPI file.
Security rules
Two of the checks send real emails. To keep them from becoming a tool for abuse, fixed rules apply — the same on every route, whether form, API or AI assistant:
- Own domain only: for the spoofing check, the recipient and spoofed sender address must have the same domain. Other people’s domains can’t be tested.
- A human approves: an assistant may request these tests but not trigger them. Nothing is sent until the person concerned clicks the confirmation link in their email. This link is never handed out via the interface — otherwise the assistant could confirm itself.
- One test per domain, test type and hour, so nobody can flood a mailbox with test emails.
- Fixed content: the text of a test email is predefined — for the spoofing check it’s the explanation of the test, for the self-test randomly chosen scenarios. No freely written phishing text can be sent via secureIT.
- No third-party evaluation: only the person tested receives the personal results of the phishing self-test by email — never the requesting service.
- Logged: every test requested and every test carried out is logged and reported to me.
Terms of use
Use is free and free of charge. I only ask that you credit secureIT as the source and link to the relevant page when passing on results. A limit of 60 requests per minute per IP applies.
These checks are a starting point, not a substitute for advice: SPF, DKIM and DMARC belong in your domain’s DNS settings and are set by your IT. I’m happy to help with assessing the results and training your team.
Questions about integration?
If you want to build the interface into a product or an AI assistant and something is missing — let me know, I’ll gladly extend it.
Get in touch → See the checks in the browser