api.deadsimple.email
https://api.deadsimple.email/mcp
61
trust
0.55
confidence
medium
risk
trust-2026-08-12.2
observed 50m ago
Why this score
| tls_present_and_valid | +12 |
| mcp.unauthenticated_consequential_tools | -8 |
| reachable | +6 |
| mcp_capabilities_discoverable | +4 |
| headers.missing_hsts | -3 |
Findings (2)
| medium | Capabilities are listable without authentication, including 3 whose names suggest state change (create_inbox, delete_inbox, send_email) — inferred from tool names, not confirmed mcp.unauthenticated_consequential_tools @ 1.0.0 |
| low | No Strict-Transport-Security header headers.missing_hsts @ 1.0.0 |
Evidence (7)
| Type | Observed | SHA-256 |
|---|---|---|
| dns_resolution_observation | 50m ago | b413ad7c961a7a9c… |
| http_response_observation | 50m ago | f7e3dca007c88c27… |
| availability_observation | 50m ago | c3826f28dbce5f9f… |
| tls_certificate_observation | 50m ago | 00291580d8a8fe18… |
| oauth_metadata_observation | 50m ago | 8a1810db5866c5bc… |
| mcp_protocol_observation | 50m ago | 0d14ebc5dfac3633… |
| mcp_capability_observation | 50m ago | f68381aaf803ce3a… |
Every record is append-only and content-hashed. Corrections supersede; nothing is overwritten.
Operate this service?
Prove control of api.deadsimple.email to correct the record and request a rescan after fixing a finding. One DNS record — no account needed.