Claude Code skills · updated 2026-10-03

DMARCbis + SPF record skill for Claude Code — RFC 9989 tags, SPF permerror

Flags SPF, DMARC and DKIM records in zone files that break RFC 7208 or RFC 9989

dmarcbis-spf-record-check - findings on the bundled example

On one 6-line BIND zone file it printed 11 findings (8 errors, 3 warnings) from 19 rules, each with file:line, what breaks and the RFC section.

Get it on Whop - $12 onceGet it on Gumroad

Who it's for

For DevOps and platform engineers who keep their domain's DNS in zone files or Terraform and own the mail records.

What breaks, and when

RFC 9989 (May 2026) removed pct=, so a pct=10 staged rollout now gets the full policy on 100% of your mail; an SPF record over 10 lookups is a PermError, treated as no SPF at all.

What it printed on the bundled example

== SPF & DMARC Record Lint — 11 findings (8 errors, 3 warnings) in 1 file · 19 rules
  ERROR dmarc-sample.zone:3  [spf_lookup_limit]
        SPF record needs 11 DNS lookups — the limit is 10. Receivers return PermError and treat the domain as having no SPF at all. Flatten or remove includes. [RFC 7208 4.6.4, IETF, April 2014]
  ERROR dmarc-sample.zone:3  [spf_ptr]
        The 'ptr' mechanism is deprecated and must not be published — receivers may ignore it, and it costs a DNS lookup per candidate host. Replace it with ip4:/ip6: or include:. [RFC 7208 5.5, IETF, April 2014: 'its use is discouraged']
  ERROR dmarc-sample.zone:4  [spf_duplicate]
        Second 'v=spf1' record published on the same name. More than one SPF record for a domain is a PermError — merge them into one record. [RFC 7208 4.5, IETF, April 2014]
  ERROR dmarc-sample.zone:4  [spf_pass_all]
        '+all' (or a bare 'all') passes SPF for every sender on the internet, which is the same as publishing no SPF. End the record with '-all', or '~all' while you migrate. [RFC 7208 5.1, IETF, April 2014]

What you get

Install

Unzip into ~/.claude/skills/ (all projects) or your-repo/.claude/skills/ (one repo), then ask Claude Code: "Can you check the SPF and DMARC records in our zone files? Don't edit anything yet.". Needs Node 16+.

unzip dmarcbis-spf-record-check.zip -d ~/.claude/skills/

Ask Claude

“Can you check the SPF and DMARC records in our zone files? Don't edit anything yet.”

What it does not do

No live DNS lookups and no include: resolution; it checks the records written in your repo, not what is published.

FAQ

What is a Claude Code skill?

A folder with a SKILL.md and scripts that Claude Code loads when your request matches it. You ask in plain words and Claude runs the scanner the skill carries.

How is this different from asking Claude without the skill?

The skill carries a dated rule table and a scanner that reads every file, so Claude quotes the exact date and line instead of answering from memory.

Does it send my code anywhere?

No live DNS lookups and no include: resolution; it checks the records written in your repo, not what is published.

How do I install it?

Unzip into ~/.claude/skills/ (all projects) or your-repo/.claude/skills/ (one repo), then ask Claude Code: "Can you check the SPF and DMARC records in our zone files? Don't edit anything yet.". Needs Node 16+.

What do I get when I buy?

The zip. On Whop it is in your library as a download lesson with the zip attached; on Gumroad it is the product file.