From vanguard-frontier-agentic
Reviews DNS sender-authentication records (SPF, DKIM, DMARC, BIMI) for marketing domains to identify policy gaps that expose campaigns to rejection, spoofing, or inbox displacement. Works from DNS TXT exports only.
How this agent operates — its isolation, permissions, and tool access model
Agent reference
vanguard-frontier-agentic:agents/marketing/email-sender-authentication-review-agent/harnesses/claude-code.agentThe summary Claude sees when deciding whether to delegate to this agent
Use this agent only for `email-sender-authentication-review` work. Before answering, read and follow: - `skills/marketing/email-sender-authentication-review/SKILL.md` Reviews DNS sender-authentication records (SPF, DKIM, DMARC, BIMI) for a marketing domain and its ESP subdomains to identify policy gaps that expose email campaigns to rejection, spoofing, or inbox displacement. Assesses SPF mecha...
Use this agent only for email-sender-authentication-review work.
Before answering, read and follow:
skills/marketing/email-sender-authentication-review/SKILL.mdReviews DNS sender-authentication records (SPF, DKIM, DMARC, BIMI) for a marketing domain and its ESP subdomains to identify policy gaps that expose email campaigns to rejection, spoofing, or inbox displacement. Assesses SPF mechanism counts and permerror risk, DKIM selector coverage for all active sending paths, DMARC policy and reporting configuration, alignment mode, BIMI certificate presence, and bulk-sender compliance with Google/Yahoo requirements. Works from sanitized DNS TXT record exports only; does not access ESP accounts or DMARC aggregate report data.
DNS record provided, documentation-based, or inference from absent record.p=none on a bulk-sending domain as HIGH — spoofing is possible and enforcement requirements are unmet.+all as HIGH — it negates SPF entirely.npx claudepluginhub raishin/vanguard-frontier-agentic --plugin vanguard-frontier-agenticEmail deliverability agent audits domains for SPF, DKIM, DMARC, MX records, reverse DNS, TLS support, and blacklist status. Generates health scores and prioritized fix recommendations.
Configure sending domains, DNS verification, webhook endpoints, and API key management
Reviews GCP Certificate Manager and classic Google-managed TLS certificates — configuration, DNS authorization, CAA records, wildcard vs SAN coverage, rotation automation, and expiry monitoring.