Tavily MCP server — security posture
Search API built for LLM workflows.
B79Last scanned August 27, 2026
Vendor domain: tavily.com
Email authentication
- DMARCEnforced (p=quarantine).
- SPFPublished — authorizes which servers may send mail for this domain.
- DKIMDetected — outgoing mail can be cryptographically verified.
- MTA-STSPublished — enforces TLS for inbound mail delivery.
- TLS-RPTPublished — the domain receives delivery and TLS failure reports.
Disclosures
- security.txtNo security.txt — researchers have no published route to report issues.
- llms.txtPublishes llms.txt for AI crawlers.
AI crawler stance
- GPTBotGPTBot is allowed to crawl.
- ClaudeBotClaudeBot is allowed to crawl.
- Google-ExtendedGoogle-Extended is allowed to crawl.
- PerplexityBotPerplexityBot is allowed to crawl.
- CCBotCCBot is allowed to crawl.
- meta-externalagentmeta-externalagent's access is unspecified in robots.txt.
What this is — and isn't
These are outside-in observations of public infrastructure — DNS, TLS, and well-known paths. They say nothing about the vendor's code, data handling, or internal controls.