mcpserver.lol
registry/dns
Connection check verified live · 20h ago

dns

DNS and email security scanner with 79 MCP tools for SPF, DMARC, DNSSEC, SSL, and brand audits.

Tools 79
GitHub stars 8
Installs / wk
Licence
Transport streamable-http
Last checked 20h ago

Tools & capabilities

79 tools

Read from the running server on 20h ago.

analyze_drift read-only domain*formatbaseline*force_refresh
Measure whether a domain's DNS security posture improved or regressed by comparing the current state against a prior scan snapshot. Returns a drift classification (improving/stable…
assess_spoofability read-only domain*formatforce_refresh
Compute a composite email spoofability risk score (0–100, higher = more spoofable) by combining SPF trust surface, DMARC enforcement, and DKIM coverage. Returns a risk level (minim…
batch_scan read-only formatdomains*force_refresh
Bulk-scan up to 10 domains in parallel. Runs a full security audit on each domain in the list and returns score, NIST-aligned letter grade (6-band A+/A/B/C/D/F), and finding counts…
batch_scan_findings read-only formatjob_id*
Fetch owner-scoped findings for a completed asynchronous batch scan.
batch_scan_start formatdomains*force_refreshidempotency_key*
Start a durable asynchronous scan of 1–10 domains. Returns a stable job ID; replaying the same idempotency key with the same principal, normalized inputs, and scoring versions retu…
batch_scan_status read-only formatjob_id*
Read the owner-scoped status of an asynchronous batch scan.
brand_audit_batch_start viewdepthformatdomains*planner_modebrand_aliases +4
Enqueue an async brand audit across up to 50 target domains with optional standard/deep discovery depth, brand aliases, and caller-supplied candidate domains. Returns { auditId, qu…
brand_audit_get_report read-only targetauditId*
Fetch the result JSON for a completed brand audit. With `target` set, returns the per-target CheckResult; without, returns the audit-level aggregate. Returns notReady when polling…
brand_audit_single read-only viewdepthdomain*formatplanner_modebrand_aliases +5
Run a full brand audit on a single target with optional standard/deep discovery depth, brand aliases, and caller-supplied candidate domains. Discovers brand-related domains, looks…
brand_audit_status read-only auditId*
Poll the status of an enqueued brand audit. Returns audit-level status (queued | running | completed | failed), progress 'N/M', and per-target statuses. Owner-scoped — auditIds own…
check_agent_discovery read-only namedomain*formatprotocolverify_capforce_refresh
Assess the security posture of IETF BANDAID agent-discovery records (draft-mozleywilliams-dnsop-dnsaid). Detects SVCB agent records under _agents/_index._{protocol}._agents, report…
check_authoritative_dns_infra read-only domain*formatforce_refresh
Check authoritative DNS infrastructure posture for a hostname. Uses BV_INFRA_PROBE when available for raw DNS, routing, RPKI, and vantage-point evidence.
check_bimi read-only domain*formatforce_refresh
Check the BIMI brand-logo record at default._bimi.<domain>. Validates the logo URL (l=) and the presence of mark-certificate authority evidence (a=) — the a= tag is a bare URL, so…
check_caa read-only domain*formatforce_refresh
Look up CAA records for a domain. Shows which Certificate Authorities are authorized to issue certificates. Part of the scan_domain audit.
check_dane read-only domain*formatforce_refresh
Check DANE/TLSA certificate pinning for SMTP at port 25. Resolves the domain's MX hosts and looks up TLSA records at _25._tcp.<mx-host>, verifying whether SMTP mail-server certific…
check_dane_https read-only domain*formatforce_refresh
Verify DANE certificate pinning for HTTPS connections. Looks up TLSA records at _443._tcp.{domain} (port 443) and validates their syntax, usage/selector/matching-type fields and DN…
check_dbl read-only domain*formatforce_refresh
Check domain reputation against DNS-based Domain Block Lists (Spamhaus DBL, URIBL, SURBL). Returns listing status with decoded return codes.
check_dkim read-only domain*formatselectorforce_refresh
Look up DKIM records for a domain. Probes common selectors, validates the signing algorithm used for outgoing email (RSA-1024/2048, Ed25519), and reports key strength. Use to verif…
check_dmarc read-only domain*formatforce_refresh
Look up and validate the DMARC record for a domain. Shows the enforcement level (none/quarantine/reject), alignment mode (strict/relaxed), and aggregate/forensic reporting destinat…
check_dnskey_strength read-only domain*formatforce_refresh
Audit the cryptographic strength of DNSKEY signing algorithms used for DNSSEC. Reports which algorithm is used for DNSSEC signing keys (RSA/SHA-1, RSA/SHA-256, ECDSA P-256, Ed25519…
check_dnssec read-only domain*formatforce_refresh
Check DNSSEC status for a domain. Verifies whether DNS is tamper-proof and protected against cache poisoning and DNS spoofing attacks by validating DNSKEY and DS records. Reports w…
check_dnssec_chain read-only domain*formatforce_refresh
Walk the full DNSSEC chain of trust from the DNS root down to the target domain, tracing DS/DNSKEY records and algorithm usage at each zone level. Use when asked to trace the chain…
check_fast_flux read-only domain*formatroundsforce_refresh
Detect fast-flux DNS behavior: performs multiple rounds of A/AAAA queries and checks whether IP addresses are rotating rapidly on each DNS query (a sign of botnet or malicious infr…
check_http_security read-only domain*formatforce_refresh
Audit a domain's browser-facing HTTP security headers over HTTPS. Inspects Content-Security-Policy (flagging unsafe-inline/unsafe-eval/wildcards), X-Frame-Options, X-Content-Type-O…
check_lookalikes read-only domain*formatforce_refresh
Detect active typosquat and lookalike/homoglyph domains that impersonate your brand and could be used in phishing. Identifies character-substitution and visual-confusion domains re…
check_mta_sts read-only domain*formatforce_refresh
Check whether a domain enforces SMTP TLS for inbound mail via MTA-STS, protecting against downgrade attacks. Queries _mta-sts.<domain> and fetches the policy file, reports mode (en…
check_mx read-only domain*formatforce_refresh
Look up MX records for a domain. Identifies which mail servers receive inbound email for the domain and which email hosting provider is used (Google Workspace, Microsoft 365, Proof…
check_mx_reputation read-only domain*formatforce_refresh
Check whether the mail server (MX) IP addresses are listed on spam blocklists (Spamhaus, Barracuda, SORBS, and other RBLs). Also verifies reverse DNS for MX hosts. Use when you wan…
check_ns read-only domain*formatforce_refresh
Audit a domain’s nameserver delegation and redundancy. Identifies the DNS hosting provider and, when the infrastructure probe is available, directly compares parent and child NS se…
check_nsec_walkability read-only domain*formatforce_refresh
Assess zone walkability risk by analyzing NSEC3PARAM configuration. Detects plain NSEC zones, weak NSEC3 parameters, and opt-out flags.
check_ptr read-only domain*formatforce_refresh
Verify forward-confirmed reverse DNS (PTR/FCrDNS) for mail servers. Part of the scan_domain audit.
check_rbl read-only domain*formatforce_refresh
Check MX server IP reputation against 6 DNS-based Real-time Blocklists (SpamCop, UCEProtect, Mailspike, Barracuda, PSBL). Resolves MX hosts to IPs first.
check_realtime_threat_feed read-only domain*formatforce_refresh
Check a domain against BlackVeil real-time threat intelligence (curated intel-gateway feed). Distinct from DNSBL checks. Operator-deploy only; degrades to info when unprovisioned.
check_resolver_consistency read-only domain*formatrecord_type
Check DNS consistency across 4 public resolvers.
check_root_server_set read-only format
Check the DNS root server set against official root hints, root glue, delegation, serial, and DNSKEY cross-root evidence.
check_shadow_domains read-only domain*formatforce_refresh
Find alternate TLD variants of a domain (e.g. example.net, example.co) that have weak or missing email authentication and could be used to spoof email. Use when asked about TLD var…
check_spf read-only domain*formatforce_refresh
Look up and validate the SPF record for a domain. Lists all IP addresses and third-party senders authorised to send email on behalf of the domain, flags syntax errors, and shows th…
check_srv read-only domain*formatforce_refresh
Map a domain's DNS-visible service footprint by probing 19 common SRV record prefixes (email, calendar, messaging, directory, web) in parallel. Returns discovered services and flag…
check_ssl read-only domain*formatforce_refresh
Check the HTTPS/TLS posture of a domain: HTTPS reachability, HSTS policy, and HTTP-to-HTTPS redirect. Also returns certificate metadata (issuer, expiry date, days remaining, SAN co…
check_subdomailing read-only domain*formatforce_refresh
Detect SubdoMailing risk: analyzes the SPF include chain for dangling or hijackable subdomains that could let an attacker send email as the domain. Use when you want to know if an…
check_subdomain_takeover read-only domain*formatsubdomainsforce_refresh
Sweep subdomains for dangling CNAMEs pointing to deprovisioned cloud services that could be claimed by an attacker (subdomain takeover vulnerabilities). Detects 16 provider familie…
check_svcb_https read-only domain*formatforce_refresh
Validate HTTPS/SVCB records (RFC 9460) for modern transport capability advertisement. Part of the scan_domain audit.
check_tlsrpt read-only domain*formatforce_refresh
Check whether a domain has SMTP TLS Reporting (TLS-RPT) configured. Queries _smtp._tls.<domain> for the v=TLSRPTv1 record and validates its reporting destination (rua= mailto:/http…
check_txt_hygiene read-only domain*formatforce_refresh
Audit TXT records for stale entries and SaaS exposure.
check_zone_hygiene read-only domain*formatforce_refresh
Audit DNS zone hygiene: identifies sensitive or forgotten subdomains exposed in DNS, stale SOA records, and zone propagation issues. Use to find any sensitive subdomains that shoul…
compare_baseline read-only domain*formatbaseline*force_refresh
Compare a domain's current security configuration against a fixed policy baseline to determine compliance. Use to check whether a domain meets a policy requirement — not for tracki…
compare_domains read-only formatdomains*force_refresh
Side-by-side security comparison of 2–5 domains. Shows relative scores, category gaps, and unique weaknesses for each domain. Use when comparing your security posture against a com…
cymru_asn read-only domain*formatforce_refresh
Map domain IPs to Autonomous System Numbers via Team Cymru DNS. Returns ASN, prefix, country, registry, and organization for each IP. Flags high-risk hosting ASNs.
delete_brand_audit_watch can modify data watchId*
Permanently removes a recurring brand-audit watch by watchId. Owner-scoped — a watchId owned by another principal surfaces as notFound. Returns confirmation of deletion.
discover_brand_domains read-only depthdomain*formatsignalsplanner_modebrand_aliases +6
Discover all domains that belong to a brand's portfolio by aggregating certificate, DNS, redirect, and mail-policy signals. Use when asked what domains are part of a brand portfoli…
discover_brand_domains_findings read-only operationId*
Fetch the ranked candidate domains (the discovery CheckResult) for an async run started with discover_brand_domains_start. Returns notReady while the discovery is still in-flight;…
discover_brand_domains_start depthdomain*formatsignalsplanner_modebrand_aliases +6
Start an async brand-domain discovery for the EXACT seed domain provided (the async sibling of discover_brand_domains, which can run ~24s and time out interactive clients). Same ar…
discover_brand_domains_status read-only operationId*
Poll the status of an async brand-domain discovery started with discover_brand_domains_start. Returns status (queued | running | completed | failed) and progress. Owner-scoped — op…
discover_subdomains read-only domain*formatforce_refresh
Find subdomains of a domain using Certificate Transparency logs. Reveals shadow IT, forgotten services, and unauthorized certificate issuance. Returns a CT SAMPLE, not an asset inv…
explain_finding read-only formatstatus*detailscheckType*
Explain a finding with impact and remediation.
generate read-only domain*formatpolicyartifact*mx_hostsprovider +5
Generate a DNS/email security remediation artifact. Artifact types: spf_record (build a new SPF record), dmarc_record (create a DMARC policy), dkim_config (DKIM key setup), mta_sts…
get_benchmark read-only formatprofile
Get industry benchmark data: shows what percentile a domain's security score ranks at within its sector or country cohort, the mean score, and the most common DNS security failures…
get_domain_rank read-only score*domain*formatsectorcountry
Rank a domain against its country or global cohort using the GSI benchmark corpus. Accepts a domain score (from scan_domain) and optional country/sector; returns a percentile: "sco…
get_provider_insights read-only formatprofileprovider*
Get security benchmarks and common configuration issues for a specific email or DNS service-provider cohort (e.g. Google Workspace customers, Microsoft 365 customers). Use when ask…
list_brand_audit_watches read-only
Returns the caller's recurring brand-audit watches: watchId, domain, interval, webhook presence, last-run time, and active state. Owner-scoped. Read-only.
map_compliance read-only domain*formatforce_refresh
Map scan findings to compliance frameworks: NIST 800-177, PCI DSS 4.0, SOC 2, CIS Controls. Shows pass/fail/partial status per control.
map_supply_chain read-only domain*formatforce_refresh
Map DNS-visible third-party service dependencies for a domain. Correlates SPF, NS, TXT verifications, SRV services, and CAA records to reveal which third-party vendors can send ema…
osint_investigate_domain_start query*
Start an async OSINT investigation for a domain. Operator-deploy only; degrades to info when unprovisioned. Returns an investigationId immediately — poll with osint_investigation_s…
osint_investigate_email_start query*
Start an async OSINT investigation for an email address (breach exposure, account correlation). Owner/enterprise tier only — people-centric OSINT is restricted to prevent misuse. R…
osint_investigate_infrastructure_start query*
Start an async deep-infrastructure OSINT investigation for a query (domain, IP, or org). Operator-deploy only; degrades to info when unprovisioned. Returns an investigationId immed…
osint_investigate_supply_chain_start query*
Start an async supply-chain OSINT investigation for a query. Operator-deploy only; degrades to info when unprovisioned. Returns an investigationId immediately — poll with osint_inv…
osint_investigate_username_start query*
Start an async OSINT investigation for a username (cross-platform presence, breach correlation). Owner/enterprise tier only — people-centric OSINT is restricted to prevent misuse.…
osint_investigation_report read-only investigationId*
Retrieve the final report of a completed OSINT investigation by investigationId. Operator-deploy only; degrades to info when unprovisioned or not yet complete.
osint_investigation_status read-only investigationId*
Poll the status of an OSINT investigation by investigationId. Operator-deploy only; degrades to info when unprovisioned. Returns current status (running | completed | failed) and p…
prioritize_csc_leads read-only brandformatdomainsforce_refresh
Rank a brand’s portfolio (or an explicit domain set) into prioritized CSC sales leads by product-gap value × severity. Multi-domain, paid. Reuses map_csc_products per domain, then…
rdap_lookup read-only domain*formatforce_refresh
Fetch domain registration data via RDAP (modern WHOIS replacement). Returns the domain registrar (the company the domain was registered with), registrant contact, creation/expirati…
register_brand_audit_watch domain*interval*webhook_url
Creates a recurring brand-audit watch for a domain on a daily/weekly/monthly cadence. Each run enqueues a fresh brand_audit_batch_start and (when a webhook is configured) POSTs a d…
resolve_spf_chain read-only domain*formatforce_refresh
Trace the full SPF include chain for a domain. Recursively resolves all includes, shows lookup count, tree depth, and flags circular includes or exceeding the 10-lookup limit.
scan_buckets_findings read-only scanId*targetproviders
Retrieve findings from a completed cloud-bucket discovery scan by scanId. Operator-deploy only; degrades to info when unprovisioned. The scanId is required so reads can be owner-sc…
scan_buckets_start target*providers
Start an async cloud-bucket discovery scan for a target domain. Operator-deploy only; degrades to info when unprovisioned. Returns a scanId immediately — poll progress with scan_bu…
scan_buckets_status read-only scanId*
Poll the status of a cloud-bucket discovery scan by scanId. Operator-deploy only; degrades to info when unprovisioned. Returns scan status (running | completed | failed) and progre…
scan_domain read-only domain*formatprofileforce_refresh
Run a full DNS and email security audit for a single domain. Aggregates every scan-included check in parallel (SPF, DKIM, DMARC, DNSSEC, TLS/SSL, MTA-STS, CAA, BIMI, subdomain take…
simulate_attack_paths read-only domain*formatforce_refresh
Analyze current DNS posture and enumerate specific attack paths an adversary could exploit, with severity, feasibility, steps, and mitigations.
validate_fix read-only check*domain*formatexpected
Re-check a specific security control after applying a fix, to confirm the finding is now resolved. Use only when a fix has already been applied and you want to verify or confirm th…