Domain.Posture

Stripe MCP server — security posture

Stripe's MCP tooling for payments data and docs.

B79Last scanned August 27, 2026

Vendor domain: stripe.com

Email authentication

  • DMARCEnforced (p=reject).
  • SPFPublished — authorizes which servers may send mail for this domain.
  • DKIMDetected — outgoing mail can be cryptographically verified.
  • MTA-STSNot published — inbound mail delivery can be downgraded to plaintext.
  • TLS-RPTNot published — no reports if mail delivery or TLS fails.

Disclosures

  • security.txtPublishes a security contact (RFC 9116).
  • llms.txtPublishes llms.txt for AI crawlers.

AI crawler stance

  • GPTBotGPTBot's access is unspecified in robots.txt.
  • ClaudeBotClaudeBot's access is unspecified in robots.txt.
  • Google-ExtendedGoogle-Extended's access is unspecified in robots.txt.
  • PerplexityBotPerplexityBot's access is unspecified in robots.txt.
  • CCBotCCBot's access is unspecified in robots.txt.
  • meta-externalagentmeta-externalagent's access is unspecified in robots.txt.

What this is — and isn't

These are outside-in observations of public infrastructure — DNS, TLS, and well-known paths. They say nothing about the vendor's code, data handling, or internal controls.

Related entities

Doing due diligence on Stripe MCP server? Get the signed report — the same findings as a dated, independently verifiable PDF your review can file.

Full domain dossier for stripe.com