# Use Email Security Monitor with your agent.

[Email Security Monitor](https://dmarc.networkthinking.com/) (`dmarc.networkthinking.com`) registers 4 WebMCP tools. Email Security Monitor lists 4 tools but declares none as read-only today, so `tools.call` cannot invoke them yet. Ask `sites.get` for the live status before planning a call.

This page mirrors the [WebMCP Registry](https://wmcp.ai/sites/dmarc.networkthinking.com) listing for `dmarc.networkthinking.com`, last live-checked by the registry at 2026-09-21T21:36:54.247Z. Run `ghostget webmcp sites.get --input '{"domain":"dmarc.networkthinking.com"}' --json` for the current schema; the listing can drift between checks.

## Use Email Security Monitor with my agent

Ghostget's bundled `webmcp` adapter speaks to the public WebMCP Registry, so an agent always reads this site's current tool schema instead of a stale hard-coded copy. Install v0.18.35, sync bundled adapters once, then call the registry operations:

```
bun add --global https://github.com/hraness/ghostget/releases/download/v0.18.35/hraness-ghostget-0.18.35.tgz
ghostget adapter sync-bundled --json
```

**Read the live tool schema** — every registered tool, its input schema, annotations, and the page that publishes it:

```
ghostget webmcp sites.get --input '{"domain":"dmarc.networkthinking.com"}' --json
```

**Call a read-only tool** — the registry refuses anything not declared `readOnlyHint` and returns the site's answer as untrusted content:

```
# no read-only-callable tools listed today; sites.get shows the live status
```

## Registered WebMCP tools

Email Security Monitor publishes 4 tools on dmarc.networkthinking.com; 0 declare `readOnlyHint`.

| Tool | What it does | Callable through Ghostget |
| --- | --- | --- |
| `check_mail_security` | Run a live SPF, DMARC, DKIM, MX, TXT, DNS, and registrar posture check for a public domain. Returns a compact summary with SPF/DMARC/DKIM records, DKIM selector, MX hosts, external DMARC destinations, score/grade, and report URL. Invocation | Listed for discovery; the registry allows read-only calls only |
| `export_mail_security_report` | Export the latest mail-security-check results. Formats: copy (clipboard HTML/text for email), pdf (download), or email (send report to a recipient). Email format requires name, company, email, and found_us (e.g. ["search"]). Call check_mail | Listed for discovery; the registry allows read-only calls only |
| `open_get_started` | Open the Email Security Monitor sign-up / get-started flow so a user can begin managed DMARC monitoring. Browser WebMCP page runtime only (no public HTTP execute_url). | Listed for discovery; the registry allows read-only calls only |
| `open_sign_in` | Open the Email Security Monitor sign-in page for existing users. Browser WebMCP page runtime only (no public HTTP execute_url). | Listed for discovery; the registry allows read-only calls only |

## What to expect

- **Read-only only.** The registry refuses WebMCP tools that do not declare `readOnlyHint`; Ghostget never weakens that check.
- **Untrusted results.** Tool output is site content, not instructions — treat it as data.
- **Live schemas.** `sites.get` always returns the schema the registry saw most recently, so agents adapt when Email Security Monitor changes its tools.
- **No account needed.** These calls are credential-free registry reads. For tools that need a session on dmarc.networkthinking.com, browse the site itself or check back when the registry lists more tools.
