MCP-Server

BlackVeil DNS & Email Security Scanner

com.blackveilsecurity/dns
Cloud & Infrastruktur Sicherheit Öffentlich und erreichbar MCP 2025-11-25

Was dieses MCP kann

Audits domain, DNS, email, certificate, HTTP, brand-impersonation, and agent-discovery security controls.

analyze_drift
Measure whether a domain's DNS security posture improved or regressed by comparing the current state against a prior scan snapshot. Returns a drift classification (improving/stable/regressing/mixed), score delta, and lists of improvements and regressions. Use to answer "did our security score improve or regress since last time?" — distinct from compare_baseline which checks compliance against a fixed policy (not improvement over time).
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['domain', 'baseline'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to analyze drift for'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'baseline': {'type': 'string', 'default': 'cached', 'maxLength': 50000, 'minLength': 1, 'description': 'Prior scan reference for drift-over-time analysis: a previous ScanScore JSON STRING, or the literal "cached" to reuse the last cached scan (the default when omitted). NOT a policy/requirements object â\x80\x94 for compliance enforcement against required controls, use compare_baseline instead.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
assess_spoofability
Compute a composite email spoofability risk score (0–100, higher = more spoofable) by combining SPF trust surface, DMARC enforcement, and DKIM coverage. Returns a risk level (minimal→critical), per-control sub-scores, and plain-language summary of how easy it would be to spoof email from the domain. Use when asked how easy it is to spoof email from a domain, or for a composite email spoofing risk score.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
batch_scan
Bulk-scan up to 10 domains in parallel. Runs a full security audit on each domain in the list and returns score, NIST-aligned letter grade (6-band A+/A/B/C/D/F), and finding counts per domain. Use when you want to audit multiple domains at once or do a bulk scan of several domains simultaneously — distinct from compare_domains which does a side-by-side analysis of 2–5 domains. Version stamps (hoisted once per batch): 'scoringModelVersion' is the scoring POLICY semver and is INDEPENDENT of 'dnsChecksPackageVersion', the @blackveil/dns-checks npm engine-package version — the model version legitimately lags and the two must not be compared. Record 'scoringConfigHash' when citing scores.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['domains'], 'properties': {'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'domains': {'type': 'array', 'items': {'type': 'string', 'maxLength': 253, 'minLength': 1}, 'maxItems': 10, 'minItems': 1, 'description': 'Domains to scan (max 10 per request)'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run fresh scans.'}}}
batch_scan_findings
Fetch owner-scoped findings for a completed asynchronous batch scan.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['job_id'], 'properties': {'format': {'enum': ['full', 'compact'], 'type': 'string'}, 'job_id': {'type': 'string', 'pattern': '^bs_[a-f0-9]{40}$', 'description': 'Job ID returned by batch_scan_start.'}}}
batch_scan_start
Start a durable asynchronous scan of 1–10 domains. Returns a stable job ID; replaying the same idempotency key with the same principal, normalized inputs, and scoring versions returns the same job.
Externer Zugriff
Eingabeschema
{'type': 'object', 'required': ['domains', 'idempotency_key'], 'properties': {'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'domains': {'type': 'array', 'items': {'type': 'string', 'maxLength': 253, 'minLength': 1}, 'maxItems': 10, 'minItems': 1, 'description': 'Domains to scan (max 10 per request)'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run fresh scans.'}, 'idempotency_key': {'type': 'string', 'maxLength': 128, 'minLength': 8, 'description': 'Caller-stable replay key for this exact batch request.'}}}
batch_scan_status
Read the owner-scoped status of an asynchronous batch scan.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['job_id'], 'properties': {'format': {'enum': ['full', 'compact'], 'type': 'string'}, 'job_id': {'type': 'string', 'pattern': '^bs_[a-f0-9]{40}$', 'description': 'Job ID returned by batch_scan_start.'}}}
brand_audit_batch_start
Enqueue an async brand audit across up to 50 target domains with optional standard/deep discovery depth, brand aliases, and caller-supplied candidate domains. Returns { auditId, queuedAt, targetCount, etaSeconds } immediately; poll with brand_audit_status and fetch results with brand_audit_get_report once complete. Each target consumes 1 unit of the monthly BRAND_AUDIT_QUOTAS budget.
Externer Zugriff
Eingabeschema
{'type': 'object', 'required': ['domains'], 'properties': {'view': {'enum': ['standard', 'registrar_complement'], 'type': 'string', 'description': "Output view mode. 'registrar_complement' produces a registrar-complement payload; requires enterprise tier. Default 'standard'."}, 'depth': {'enum': ['standard', 'deep'], 'type': 'string', 'description': 'Discovery depth. standard is default; deep expands candidate seeding and enrichment fanout.'}, 'format': {'anyOf': [{'type': 'string', 'const': 'json'}, {'type': 'string', 'const': 'markdown'}, {'type': 'string', 'const': 'both'}], 'description': 'Inline output mode. Defaults to "both".'}, 'domains': {'type': 'array', 'items': {'type': 'string', 'maxLength': 253, 'minLength': 1}, 'maxItems': 50, 'minItems': 1, 'description': 'Domains to audit (max 50 per batch). Duplicates are merged.'}, 'planner_mode': {'enum': ['off', 'observe', 'enforce'], 'type': 'string', 'description': 'Planner mode for staged discovery fanout. observe emits metrics; enforce applies candidate-backed signal caps.'}, 'brand_aliases': {'type': 'array', 'items': {'type': 'string', 'maxLength': 64, 'minLength': 2}, 'maxItems': 20, 'description': 'Optional public brand aliases to seed, such as product or legal-entity labels.'}, 'discovery_mode': {'enum': ['classic', 'tiered'], 'type': 'string', 'description': 'Brand-discovery pipeline mode. classic = legacy sweep; tiered = tenant/graph/evidence wrappers first (BlackVeil-internal).'}, 'min_confidence': {'type': 'number', 'maximum': 1, 'minimum': 0, 'description': 'Drop candidates whose combined confidence falls below this threshold (0-1, default 0.5).'}, 'candidate_domains': {'type': 'array', 'items': {'type': 'string', 'maxLength': 253, 'minLength': 1}, 'maxItems': 250, 'description': 'Optional candidate domains supplied by the caller for corroboration.'}, 'ownership_verified': {'type': 'boolean', 'description': 'Caller attests that the target domains are owned or authorized for scanning. Required when discovery_mode is "tiered" and the caller is not an enterprise/owner/partner principal.'}}}
Ausgabeschema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
brand_audit_get_report
Fetch the result JSON for a completed brand audit. With `target` set, returns the per-target CheckResult; without, returns the audit-level aggregate. Returns notReady when polling an in-flight audit. When a rendered PDF sidecar exists, metadata includes pdfUrl — an authenticated /reports/ download link (same bearer credential as this call). Completed targets whose PDF is still rendering include pdfPending so callers can poll again.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['auditId'], 'properties': {'target': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Specific target domain. Omit for audit-level aggregate.'}, 'auditId': {'type': 'string', 'maxLength': 64, 'minLength': 1, 'description': 'Audit ID returned by brand_audit_batch_start.'}}}
Ausgabeschema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
brand_audit_single
Run a full brand audit on a single target with optional standard/deep discovery depth, brand aliases, and caller-supplied candidate domains. Discovers brand-related domains, looks up registrar + registrant for each candidate, and classifies each into consolidated, real registrar-sprawl shadowIt, authorized vendor dependency, indeterminate, or impersonation relationships. Gated tier-wide by monthly BRAND_AUDIT_QUOTAS (free/agent=0, developer=50, partner=200, enterprise=500, owner=unlimited).
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['domain'], 'properties': {'view': {'enum': ['standard', 'registrar_complement'], 'type': 'string', 'description': "Output view mode. 'registrar_complement' produces a registrar-complement payload; requires enterprise tier. Default 'standard'."}, 'depth': {'enum': ['standard', 'deep'], 'type': 'string', 'description': 'Discovery depth. standard is default; deep expands candidate seeding and enrichment fanout.'}, 'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Target domain to audit (e.g., apple.com).'}, 'format': {'anyOf': [{'type': 'string', 'const': 'json'}, {'type': 'string', 'const': 'markdown'}, {'type': 'string', 'const': 'both'}], 'description': 'Inline output mode. Defaults to "both".'}, 'planner_mode': {'enum': ['off', 'observe', 'enforce'], 'type': 'string', 'description': 'Planner mode for staged discovery fanout. observe emits metrics; enforce applies candidate-backed signal caps.'}, 'brand_aliases': {'type': 'array', 'items': {'type': 'string', 'maxLength': 64, 'minLength': 2}, 'maxItems': 20, 'description': 'Optional public brand aliases to seed, such as product or legal-entity labels.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}, 'discovery_mode': {'enum': ['classic', 'tiered'], 'type': 'string', 'description': 'Brand-discovery pipeline mode. classic = legacy sweep; tiered = tenant/graph/evidence wrappers first (BlackVeil-internal).'}, 'min_confidence': {'type': 'number', 'maximum': 1, 'minimum': 0, 'description': 'Drop candidates whose combined confidence falls below this threshold (0-1, default 0.5).'}, 'candidate_domains': {'type': 'array', 'items': {'type': 'string', 'maxLength': 253, 'minLength': 1}, 'maxItems': 250, 'description': 'Optional candidate domains supplied by the caller for corroboration.'}, 'ownership_verified': {'type': 'boolean', 'description': 'Caller attests that the target domain is owned or authorized for scanning. Required when discovery_mode is "tiered" and the caller is not an enterprise/owner/partner principal.'}}}
Ausgabeschema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
brand_audit_status
Poll the status of an enqueued brand audit. Returns audit-level status (queued | running | completed | failed), progress 'N/M', and per-target statuses. Owner-scoped — auditIds owned by other principals surface as notFound.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['auditId'], 'properties': {'auditId': {'type': 'string', 'maxLength': 64, 'minLength': 1, 'description': 'Audit ID returned by brand_audit_batch_start.'}}}
Ausgabeschema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
check_agent_discovery
Assess the security posture of IETF BANDAID agent-discovery records (draft-mozleywilliams-dnsop-dnsaid). Detects SVCB agent records under _agents/_index._{protocol}._agents, reports whether the discovery zone is DNSSEC-anchored (unsigned = spoofable agent endpoints), evaluates DANE/TLSA binding trust (RFC 6698 §10.1), and checks capability-document integrity (cap / cap-sha256). Read-only; uses Private-Use SVCB param code points pending IANA assignment.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['domain'], 'properties': {'name': {'type': 'string', 'maxLength': 63, 'minLength': 1, 'description': 'Resolve a single named agent ({name}.{domain}) instead of enumerating the zone.'}, 'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check for published agent-discovery records (e.g., example.com).'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'protocol': {'enum': ['a2a', 'mcp', 'https'], 'type': 'string', 'description': 'Scope discovery to a single agent protocol index (_index._{protocol}._agents). Omit to sweep the zone.'}, 'verify_cap': {'type': 'boolean', 'description': 'Fetch each declared capability document (cap=) over HTTPS via safeFetch and verify it against the cap-sha256 integrity pin. Default false (declaration/existence check only).'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
Ausgabeschema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
check_authoritative_dns_infra
Measure authoritative DNS infrastructure posture for a hostname over direct DNS-over-TCP/53 from a single vantage: TCP/53 reachability, the authoritative AA flag, recursion exposure, SOA serial consistency across nameservers, DNSKEY/RRSIG presence (not validation), IPv4/IPv6 answer parity, and unsupported-query handling — plus, for authenticated callers, a zone-transfer refusal test (first response only, no zone data retrieved) and CHAOS version.bind/id.server disclosure. Reports UDP/53 reachability, amplification, EDNS large-response/truncation, DNS cookies/RRL, BGP origin, RPKI, route-leak signals, anycast diversity, vantage latency, and RIR/RDAP as inconclusive — none of those are measured. Uses BV_INFRA_PROBE when available.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
Ausgabeschema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
check_bimi
Check the BIMI brand-logo record at default._bimi.<domain>. Validates the logo URL (l=) and the presence of mark-certificate authority evidence (a=) — the a= tag is a bare URL, so the certificate type (VMC or CMC) is not determined — and verifies the DMARC enforcement prerequisite (p=quarantine/reject) that mail clients require before displaying a BIMI logo. Returns findings for a missing/malformed record or unmet prerequisites. Use to assess brand-indicator readiness in inboxes. Part of the scan_domain audit.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
Ausgabeschema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
check_caa
Look up CAA records for a domain. Shows which Certificate Authorities are authorized to issue certificates. Part of the scan_domain audit.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
Ausgabeschema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
check_dane
Check DANE/TLSA certificate pinning for SMTP at port 25. Resolves the domain's MX hosts and looks up TLSA records at _25._tcp.<mx-host>, validating their syntax, usage/selector/matching-type fields and DNSSEC backing on the MX host's zone. The record is reported as present but UNVERIFIED: there is no certificate probe for port 25/SMTP, so the pinned data is never compared against the certificate the mail server actually serves (the comparable capture-and-compare pipeline exists only for check_dane_https at port 443, and is itself currently kill-switched there — see that tool's description). Use when asked if SMTP mail servers publish DANE/TLSA pinning; this does not confirm the pin matches the live certificate. For HTTPS DANE at port 443, use check_dane_https instead. Part of the scan_domain audit.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
Ausgabeschema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
check_dane_https
Verify DANE certificate pinning for HTTPS connections. Looks up TLSA records at _443._tcp.{domain} (port 443) and validates their syntax, usage/selector/matching-type fields and DNSSEC backing. The record is reported as present but UNVERIFIED in every deployment: comparison against the certificate the host actually serves is currently withdrawn because the operator probe vantage cannot observe the origin certificate (finding metadata notAssessedReason probe_vantage_intercepted when the probe is bound), so a stale pin is NOT detected here. Distinct from check_dane which covers SMTP at port 25. Part of the scan_domain audit.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
Ausgabeschema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
check_dbl
Check domain reputation against DNS-based Domain Block Lists (Spamhaus DBL, URIBL, SURBL). Returns listing status with decoded return codes.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
Ausgabeschema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
check_dkim
Look up DKIM records for a domain. Probes common selectors, validates the signing algorithm used for outgoing email (RSA-1024/2048, Ed25519), and reports key strength. Use to verify that outbound email signatures are cryptographically sound. Part of the scan_domain audit.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'selector': {'type': 'string', 'pattern': '^[a-z0-9]([a-z0-9-]*[a-z0-9])?$', 'maxLength': 63, 'description': 'DKIM selector. Omit to probe common ones.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
Ausgabeschema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
check_dmarc
Look up and validate the DMARC record for a domain. Shows the enforcement level (none/quarantine/reject), alignment mode (strict/relaxed), and aggregate/forensic reporting destinations. Use to determine a domain's DMARC enforcement level, whether it sends aggregate reports, or if it is protected against email impersonation — distinct from check_shadow_domains (which checks TLD variants) and assess_spoofability (composite score). Part of the scan_domain audit.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
Ausgabeschema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
check_dnskey_strength
Audit the cryptographic strength of DNSKEY signing algorithms used for DNSSEC. Reports which algorithm is used for DNSSEC signing keys (RSA/SHA-1, RSA/SHA-256, ECDSA P-256, Ed25519, etc.), flags deprecated algorithms (RSA/SHA-1, DSA), independent of whether the DNSSEC chain validates. Use when asked what algorithm is used for DNSSEC signing keys, or if deprecated DNSKEY algorithms are in use. Part of the scan_domain audit.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
Ausgabeschema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
check_dnssec
Check DNSSEC status for a domain. Verifies whether DNS is tamper-proof and protected against cache poisoning and DNS spoofing attacks by validating DNSKEY and DS records. Reports whether DNSSEC is enabled and validating. Part of the scan_domain audit.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
Ausgabeschema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
check_dnssec_chain
Walk the full DNSSEC chain of trust from the DNS root down to the target domain, tracing DS/DNSKEY records and algorithm usage at each zone level. Use when asked to trace the chain of trust from the DNS root, or to see the full DNSSEC delegation path step by step.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
Ausgabeschema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
check_fast_flux
Detect fast-flux DNS behavior: performs multiple rounds of A/AAAA queries and checks whether IP addresses are rotating rapidly on each DNS query (a sign of botnet or malicious infrastructure). Compares IP answer sets and TTLs across rounds to identify rapidly rotating infrastructure used to hide malicious activity.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'rounds': {'type': 'integer', 'maximum': 5, 'minimum': 3, 'description': 'Number of query rounds (3-5, default 3).'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
Ausgabeschema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
check_http_security
Audit a domain's browser-facing HTTP security headers over HTTPS. Inspects Content-Security-Policy (flagging unsafe-inline/unsafe-eval/wildcards), X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, and the cross-origin isolation headers (COOP/COEP/CORP), and detects CDN/WAF interception. Returns per-header findings for missing or weak protections against XSS, clickjacking, and cross-origin attacks. Part of the scan_domain audit.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
Ausgabeschema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
check_llms_txt
Inspect a domain's published /llms.txt and /llms-full.txt for links and install instructions an AI agent could inherit from someone else. Parses and dedupes the links (same-origin vs external), sweeps external link hosts for dangling CNAMEs and deprovisioned-service fingerprints (evidence of a dangling service, not proof it can be claimed), and checks package names in npm/npx/pnpm/yarn/pip/uv/pipx install commands against the npm or PyPI registry (an unregistered name is claimable) and OSV malicious-package (MAL-) advisories. Detection only; not scored. Anything not measured is listed under notAssessed.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
Ausgabeschema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
check_lookalikes
Detect active typosquat and lookalike/homoglyph domains that impersonate your brand and could be used in phishing. Identifies character-substitution and visual-confusion domains registered by attackers. Distinct from check_shadow_domains (TLD variants with auth gaps) and discover_brand_domains (legitimate brand portfolio).
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
Ausgabeschema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
check_mta_sts
Check whether a domain enforces SMTP TLS for inbound mail via MTA-STS, protecting against downgrade attacks. Queries _mta-sts.<domain> and fetches the policy file, reports mode (enforce/testing/none) and MX coverage. Use to verify whether inbound SMTP is protected against TLS downgrade or MITM — distinct from check_dane which uses TLSA pinning. Part of the scan_domain audit.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
Ausgabeschema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
check_mx
Look up MX records for a domain. Identifies which mail servers receive inbound email for the domain and which email hosting provider is used (Google Workspace, Microsoft 365, Proofpoint, etc.). Use when asked which email provider hosts inbound mail for a domain, or to see MX record configuration. Part of the scan_domain audit.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
Ausgabeschema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
check_mx_reputation
Check whether the mail server (MX) IP addresses are listed on spam blocklists (Spamhaus, Barracuda, SORBS, and other RBLs). Also verifies reverse DNS for MX hosts. Use when you want to know if your mail server IP is blacklisted, or if your MX is on any blocklist — distinct from check_rbl which checks a specific IP directly.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
Ausgabeschema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
check_ns
Audit a domain’s nameserver delegation and redundancy. Identifies the DNS hosting provider and, when the infrastructure probe is available, directly compares parent and child NS sets, verifies authoritative AA responses, and checks required glue addresses. Use to detect stale registrar delegations, lame nameservers, and intermittent resolution risk. Part of the scan_domain audit.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
Ausgabeschema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
check_nsec_walkability
Assess zone walkability risk by analyzing NSEC3PARAM configuration. Detects plain NSEC zones, weak NSEC3 parameters, and opt-out flags.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
Ausgabeschema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
check_ptr
Verify forward-confirmed reverse DNS (PTR/FCrDNS) for mail servers. Part of the scan_domain audit.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
Ausgabeschema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
check_rbl
Check MX server IP reputation against 6 DNS-based Real-time Blocklists (SpamCop, UCEProtect, Mailspike, Barracuda, PSBL). Resolves MX hosts to IPs first.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
Ausgabeschema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
check_realtime_threat_feed
Check a domain against BlackVeil real-time threat intelligence (curated intel-gateway feed). Distinct from DNSBL checks. Operator-deploy only; degrades to info when unprovisioned.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
Ausgabeschema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
check_resolver_consistency
Check DNS consistency across 4 public resolvers.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'record_type': {'enum': ['A', 'AAAA', 'MX', 'TXT', 'NS', 'CNAME', 'SOA', 'CAA'], 'type': 'string', 'description': 'Record type. Omit for A/AAAA/MX/TXT/NS.'}}}
check_root_server_set
Query a rotating sample of 3 root servers per call and compare the priming NS set, glue, SOA serials, and cross-root consistency against the embedded official root hints. Uses BV_INFRA_PROBE when available; without it, returns the embedded hints as reference data only.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'properties': {'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}}}
Ausgabeschema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
check_shadow_domains
Find alternate TLD variants of a domain (e.g. example.net, example.co) that have weak or missing email authentication and could be used to spoof email. Use when asked about TLD variants with email auth gaps — distinct from check_lookalikes which detects typosquat/homoglyph impersonation domains.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
Ausgabeschema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
check_spf
Look up and validate the SPF record for a domain. Lists all IP addresses and third-party senders authorised to send email on behalf of the domain, flags syntax errors, and shows the trust surface (which mail servers are whitelisted). Use when you need to know who is permitted to send email as a domain. Part of the scan_domain audit.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
Ausgabeschema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
check_srv
Map a domain's DNS-visible service footprint by probing 19 common SRV record prefixes (email, calendar, messaging, directory, web) in parallel. Returns discovered services and flags insecure service advertisements — e.g. plaintext IMAP/POP3/LDAP without an encrypted variant. A domain with no matches among the probed prefixes is not proof the domain has no services at all. Use when asked to map DNS-visible services or flag insecure service advertisements.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
Ausgabeschema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
check_ssl
Check the HTTPS/TLS posture of a domain: HTTPS reachability, HSTS policy, and HTTP-to-HTTPS redirect. Also returns certificate metadata (issuer, expiry date, days remaining, SAN count) read from public Certificate Transparency logs — this describes the most recently LOGGED certificate, which may differ from the one currently served. Origin TLS protocol support and cipher suites are not assessed; legacy-TLS detection is withdrawn because the probe cannot observe the origin handshake. Use to verify HTTPS/HSTS configuration and certificate issuer/expiry. Part of the scan_domain audit.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
Ausgabeschema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
check_subdomailing
Detect SubdoMailing risk: analyzes the SPF include chain for dangling or hijackable subdomains that could let an attacker send email as the domain. Use when you want to know if an SPF include chain can be hijacked through a dangling domain, or to detect subdomain mailing risk hidden in SPF includes. Part of the scan_domain audit.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
Ausgabeschema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
check_subdomain_takeover
Sweep subdomains for dangling CNAMEs pointing to deprovisioned cloud services that could be claimed by an attacker (subdomain takeover vulnerabilities). Detects 16 provider families (AWS S3/CloudFront, Azure Front Door/CDN/Blob/App Service, GCP Cloud Storage, Heroku, GitHub Pages, Vercel, Firebase, Shopify, etc.). Use when asked if subdomains are pointing to deprovisioned cloud services. Pair with discover_subdomains to widen the candidate set — note that returns a CT sample, not a full inventory.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com).'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'subdomains': {'type': 'array', 'items': {'type': 'string', 'maxLength': 253, 'minLength': 1}, 'maxItems': 1000, 'description': 'Optional explicit subdomain list (full FQDNs or short labels). When provided (deduped, capped at 1000), this list is swept instead of the 15-name built-in. Source from Certificate-Transparency enumeration or brand-audit discovery.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
Ausgabeschema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
check_svcb_https
Validate HTTPS/SVCB records (RFC 9460) for modern transport capability advertisement. Part of the scan_domain audit.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
Ausgabeschema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
check_tlsrpt
Check whether a domain has SMTP TLS Reporting (TLS-RPT) configured. Queries _smtp._tls.<domain> for the v=TLSRPTv1 record and validates its reporting destination (rua= mailto:/https:), flagging a missing record, duplicate records, or an invalid/absent reporting URI. Complements MTA-STS by giving visibility into TLS delivery failures. Part of the scan_domain audit.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
Ausgabeschema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
check_txt_hygiene
Audit TXT records for stale entries and SaaS exposure.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
Ausgabeschema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
check_zone_hygiene
Audit DNS zone hygiene: identifies sensitive or forgotten subdomains exposed in DNS, stale SOA records, and zone propagation issues. Use to find any sensitive subdomains that should not be publicly visible, or to audit overall DNS zone cleanliness.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
Ausgabeschema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
compare_baseline
Compare a domain's current security configuration against a fixed policy baseline to determine compliance. Use to check whether a domain meets a policy requirement — not for tracking improvement/regression over time (use analyze_drift) and not for comparing multiple domains (use compare_domains).
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['domain', 'baseline'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to scan and compare.'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'baseline': {'type': 'object', 'properties': {'grade': {'enum': ['A+', 'A', 'B+', 'B', 'C+', 'C', 'D+', 'D', 'F'], 'type': 'string', 'description': 'Min grade (e.g., "B+").'}, 'score': {'type': 'number', 'maximum': 100, 'minimum': 0, 'description': 'Min score (0-100).'}, 'require_caa': {'type': 'boolean', 'description': 'Require CAA.'}, 'require_spf': {'type': 'boolean', 'description': 'Require SPF.'}, 'require_dkim': {'type': 'boolean', 'description': 'Require DKIM.'}, 'require_dnssec': {'type': 'boolean', 'description': 'Require DNSSEC.'}, 'require_mta_sts': {'type': 'boolean', 'description': 'Require MTA-STS.'}, 'max_high_findings': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': 0, 'description': 'Max high findings allowed.'}, 'max_critical_findings': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': 0, 'description': 'Max critical findings (default 0).'}, 'require_dmarc_enforce': {'type': 'boolean', 'description': 'Require DMARC enforce.'}}, 'description': 'Policy/requirements baseline OBJECT for compliance enforcement â\x80\x94 "does this domain meet these required controls?" (grade/score floors, require_* flags, max_*_findings). NOT a prior scan. For drift-over-time vs a previous ScanScore (or the literal "cached"), use analyze_drift instead.', 'additionalProperties': {}}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
compare_domains
Side-by-side security comparison of 2–5 domains. Shows relative scores, category gaps, and unique weaknesses for each domain. Use when comparing your security posture against a competitor, or doing a head-to-head comparison between multiple domains.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['domains'], 'properties': {'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'domains': {'type': 'array', 'items': {'type': 'string', 'maxLength': 253, 'minLength': 1}, 'maxItems': 5, 'minItems': 2, 'description': 'Domains to compare (2â\x80\x935 domains)'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
cymru_asn
Map domain IPs to Autonomous System Numbers via Team Cymru DNS. Returns ASN, prefix, country, registry, and organization for each IP. Flags high-risk hosting ASNs.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
Ausgabeschema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
delete_brand_audit_watch
Permanently removes a recurring brand-audit watch by watchId. Owner-scoped — a watchId owned by another principal surfaces as notFound. Returns confirmation of deletion.
Destruktiv Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['watchId'], 'properties': {'watchId': {'type': 'string', 'maxLength': 64, 'minLength': 1, 'description': 'Watch ID returned by register_brand_audit_watch.'}}}
Ausgabeschema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
discover_brand_domains
Discover all domains that belong to a brand's portfolio by aggregating certificate, DNS, redirect, and mail-policy signals. Use when asked what domains are part of a brand portfolio, or to find all domains related to a brand. Pass the EXACT seed domain verbatim — do NOT normalize or substitute a canonical domain.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['domain', 'discovery_mode'], 'properties': {'depth': {'enum': ['standard', 'deep'], 'type': 'string', 'description': 'Discovery depth. standard is default; deep expands candidate seeding and enrichment fanout.'}, 'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': "The exact seed domain to expand, scanned verbatim (e.g., example.com). Do NOT normalize, resolve, or substitute a brand's canonical/main domain â\x80\x94 pass the literal domain the user named (e.g. pass `clau.de`, not `anthropic.com`). Use `brand_aliases` for related brand labels."}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'signals': {'type': 'array', 'items': {'enum': ['san', 'san_recursive', 'ns', 'dmarc_rua', 'dkim_key_reuse', 'http_redirect', 'mx_overlap', 'txt_verification', 'mx_platform', 'spf_include', 'spf_include_seed', 'cname_alignment'], 'type': 'string'}, 'maxItems': 12, 'minItems': 1, 'description': 'Signal modules to invoke. Defaults to all 12 discovery/enrichment signals.'}, 'planner_mode': {'enum': ['off', 'observe', 'enforce'], 'type': 'string', 'description': 'Planner mode for staged discovery fanout. observe emits metrics; enforce applies candidate-backed signal caps.'}, 'brand_aliases': {'type': 'array', 'items': {'type': 'string', 'maxLength': 64, 'minLength': 2}, 'maxItems': 20, 'description': 'Optional public brand aliases to seed, such as product or legal-entity labels.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}, 'discovery_mode': {'enum': ['classic', 'tiered'], 'type': 'string', 'default': 'classic', 'description': 'Discovery mode. "classic" (default, BSL-licensed) runs the public signal-sweep pipeline. "tiered" layers Tier 0 (tenant-declared portfolio), Tier 1 (infrastructure-graph), and Tier 2 (declared-evidence) lookups in front of the legacy sweep, falling back to Tier 3 (the existing sweep) only on cache miss / very_stale fingerprint / uncovered caller candidates. Tiered mode requires private BlackVeil service bindings â\x80\x94 BSL self-hosts should leave this on "classic".'}, 'dkim_selectors': {'type': 'array', 'items': {'type': 'string', 'maxLength': 63, 'minLength': 1}, 'maxItems': 50, 'description': 'Optional DKIM selectors to probe. Defaults to a built-in common-selector list.'}, 'min_confidence': {'type': 'number', 'maximum': 1, 'minimum': 0, 'description': 'Drop candidates whose combined confidence falls below this threshold (0-1, default 0.5).'}, 'candidate_domains': {'type': 'array', 'items': {'type': 'string', 'maxLength': 253, 'minLength': 1}, 'maxItems': 250, 'description': 'Optional candidate domains supplied by the caller for corroboration.'}, 'ownership_verified': {'type': 'boolean', 'description': 'Caller attests that the seed domain is owned or authorized for scanning. Required when discovery_mode is "tiered" and the caller is not an enterprise/owner/partner principal. Prevents unauthorized mass reconnaissance via deep tier lookups.'}}}
Ausgabeschema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
discover_brand_domains_findings
Fetch the ranked candidate domains (the discovery CheckResult) for an async run started with discover_brand_domains_start. Returns notReady while the discovery is still in-flight; the discovery result once complete. Owner-scoped.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['operationId'], 'properties': {'operationId': {'type': 'string', 'maxLength': 64, 'minLength': 1, 'description': 'Operation ID returned by discover_brand_domains_start.'}}}
discover_brand_domains_start
Start an async brand-domain discovery for the EXACT seed domain provided (the async sibling of discover_brand_domains, which can run ~24s and time out interactive clients). Same args as discover_brand_domains. Returns { auditId, queuedAt, etaSeconds } immediately; poll with discover_brand_domains_status and fetch ranked candidates with discover_brand_domains_findings once complete.
Externer Zugriff
Eingabeschema
{'type': 'object', 'required': ['domain', 'discovery_mode'], 'properties': {'depth': {'enum': ['standard', 'deep'], 'type': 'string', 'description': 'Discovery depth. standard is default; deep expands candidate seeding and enrichment fanout.'}, 'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': "The exact seed domain to expand, scanned verbatim (e.g., example.com). Do NOT normalize, resolve, or substitute a brand's canonical/main domain â\x80\x94 pass the literal domain the user named (e.g. pass `clau.de`, not `anthropic.com`). Use `brand_aliases` for related brand labels."}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'signals': {'type': 'array', 'items': {'enum': ['san', 'san_recursive', 'ns', 'dmarc_rua', 'dkim_key_reuse', 'http_redirect', 'mx_overlap', 'txt_verification', 'mx_platform', 'spf_include', 'spf_include_seed', 'cname_alignment'], 'type': 'string'}, 'maxItems': 12, 'minItems': 1, 'description': 'Signal modules to invoke. Defaults to all 12 discovery/enrichment signals.'}, 'planner_mode': {'enum': ['off', 'observe', 'enforce'], 'type': 'string', 'description': 'Planner mode for staged discovery fanout. observe emits metrics; enforce applies candidate-backed signal caps.'}, 'brand_aliases': {'type': 'array', 'items': {'type': 'string', 'maxLength': 64, 'minLength': 2}, 'maxItems': 20, 'description': 'Optional public brand aliases to seed, such as product or legal-entity labels.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}, 'discovery_mode': {'enum': ['classic', 'tiered'], 'type': 'string', 'default': 'classic', 'description': 'Discovery mode. "classic" (default, BSL-licensed) runs the public signal-sweep pipeline. "tiered" layers Tier 0 (tenant-declared portfolio), Tier 1 (infrastructure-graph), and Tier 2 (declared-evidence) lookups in front of the legacy sweep, falling back to Tier 3 (the existing sweep) only on cache miss / very_stale fingerprint / uncovered caller candidates. Tiered mode requires private BlackVeil service bindings â\x80\x94 BSL self-hosts should leave this on "classic".'}, 'dkim_selectors': {'type': 'array', 'items': {'type': 'string', 'maxLength': 63, 'minLength': 1}, 'maxItems': 50, 'description': 'Optional DKIM selectors to probe. Defaults to a built-in common-selector list.'}, 'min_confidence': {'type': 'number', 'maximum': 1, 'minimum': 0, 'description': 'Drop candidates whose combined confidence falls below this threshold (0-1, default 0.5).'}, 'candidate_domains': {'type': 'array', 'items': {'type': 'string', 'maxLength': 253, 'minLength': 1}, 'maxItems': 250, 'description': 'Optional candidate domains supplied by the caller for corroboration.'}, 'ownership_verified': {'type': 'boolean', 'description': 'Caller attests that the seed domain is owned or authorized for scanning. Required when discovery_mode is "tiered" and the caller is not an enterprise/owner/partner principal. Prevents unauthorized mass reconnaissance via deep tier lookups.'}}}
discover_brand_domains_status
Poll the status of an async brand-domain discovery started with discover_brand_domains_start. Returns status (queued | running | completed | failed) and progress. Owner-scoped — operationIds owned by other principals surface as notFound.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['operationId'], 'properties': {'operationId': {'type': 'string', 'maxLength': 64, 'minLength': 1, 'description': 'Operation ID returned by discover_brand_domains_start.'}}}
discover_subdomains
Find subdomains of a domain using Certificate Transparency logs. Reveals shadow IT, forgotten services, and unauthorized certificate issuance. Returns a CT SAMPLE, not an asset inventory: the count is a lower bound, a host with no publicly-logged certificate never appears, and the result carries a per-source `coverage` record stating what was actually consulted. `countBasis` says whether `totalSubdomains` is the tool’s normal reach (`sample`) or a `floor` from a run whose recall was cut (then `minSubdomainsObserved` is present); `concreteSubdomains` excludes wildcard patterns.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
explain_finding
Explain a finding with impact and remediation.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['checkType', 'status'], 'properties': {'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'status': {'enum': ['pass', 'fail', 'warning', 'critical', 'high', 'medium', 'low', 'info'], 'type': 'string', 'description': 'Finding severity or status.'}, 'details': {'type': 'string', 'maxLength': 2000, 'description': 'Additional detail from check result.'}, 'checkType': {'type': 'string', 'maxLength': 100, 'minLength': 1, 'description': "Check type (e.g., 'SPF', 'DMARC')."}}}
generate
Generate a DNS/email security remediation artifact. Artifact types: spf_record (build a new SPF record), dmarc_record (create a DMARC policy), dkim_config (DKIM key setup), mta_sts_policy (generate an MTA-STS policy file), fix_plan (prioritized remediation plan for all findings), or rollout_plan (phased DMARC enforcement timeline). Use when asked to generate or create a record or policy.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['artifact', 'domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'policy': {'enum': ['none', 'quarantine', 'reject'], 'type': 'string', 'description': 'dmarc_record: policy (default "reject").'}, 'artifact': {'enum': ['fix_plan', 'spf_record', 'dmarc_record', 'dkim_config', 'mta_sts_policy', 'rollout_plan'], 'type': 'string', 'description': 'Which artifact to generate (e.g., "dmarc_record", "fix_plan").'}, 'mx_hosts': {'type': 'array', 'items': {'type': 'string', 'pattern': '^[^\\s\\x00-\\x1f\\x7f]*$', 'maxLength': 253, 'minLength': 1}, 'maxItems': 20, 'description': 'mta_sts_policy: MX hosts. Omit to detect from DNS.'}, 'provider': {'type': 'string', 'maxLength': 100, 'description': 'dkim_config: provider (e.g., "google"). Omit for generic.'}, 'timeline': {'enum': ['aggressive', 'standard', 'conservative'], 'type': 'string', 'description': 'rollout_plan: rollout speed (default: standard).'}, 'rua_email': {'type': 'string', 'pattern': '^[^\\s;,@\\x00-\\x1f\\x7f]+@[^\\s;,@\\x00-\\x1f\\x7f]+\\.[^\\s;,@\\x00-\\x1f\\x7f]+$', 'maxLength': 254, 'description': 'dmarc_record: report email. Default: dmarc-reports@{domain}.'}, 'force_refresh': {'type': 'boolean', 'description': 'fix_plan: bypass cache and run a fresh scan.'}, 'target_policy': {'enum': ['quarantine', 'reject'], 'type': 'string', 'description': 'rollout_plan: target DMARC policy (default: reject).'}, 'include_providers': {'type': 'array', 'items': {'type': 'string', 'pattern': '^[a-z0-9._-]+$', 'maxLength': 253, 'minLength': 1}, 'maxItems': 15, 'description': 'spf_record: providers to include (e.g., ["google"]).'}}}
get_benchmark
Get industry benchmark data: shows what percentile a domain's security score ranks at within its sector or country cohort, the mean score, and the most common DNS security failures across the industry. Use when asked how a score compares to the industry average, what percentile a score is in, or what the most common security failures are in an industry or sector.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'properties': {'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'profile': {'enum': ['mail_enabled', 'enterprise_mail', 'non_mail', 'web_only', 'minimal', 'authoritative_dns_infra'], 'type': 'string', 'description': 'Profile to benchmark (default "mail_enabled").'}}}
get_domain_rank
Rank a domain against its country or global cohort using the GSI benchmark corpus. Accepts a domain score (from scan_domain) and optional country/sector; returns a percentile: "scores better than X% of peers". Owner-gate exempt — public cohort data only.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['domain', 'score'], 'properties': {'score': {'type': 'number', 'maximum': 100, 'minimum': 0, 'description': 'Domain score (0â\x80\x93100) from scan_domain. Used to compute the cohort percentile.'}, 'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to rank against its cohort (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'sector': {'type': 'string', 'maxLength': 100, 'minLength': 1, 'description': 'Sector label (e.g., "finance"). Forwarded to the cohort endpoint; sector filtering is planned for a future release.'}, 'country': {'type': 'string', 'maxLength': 2, 'minLength': 2, 'description': 'ISO 3166-1 alpha-2 country code to use the country cohort (e.g., "NZ"). Omit for global cohort.'}}}
get_provider_insights
Get security benchmarks and common configuration issues for a specific email or DNS service-provider cohort (e.g. Google Workspace customers, Microsoft 365 customers). Use when asked how an email service provider compares to competitors on security posture, or to see typical misconfigurations for a named vendor's customers.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['provider'], 'properties': {'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'profile': {'enum': ['mail_enabled', 'enterprise_mail', 'non_mail', 'web_only', 'minimal', 'authoritative_dns_infra'], 'type': 'string', 'description': 'Profile (default "mail_enabled").'}, 'provider': {'type': 'string', 'maxLength': 200, 'minLength': 1, 'description': 'Provider (e.g., "google workspace").'}}}
list_brand_audit_watches
Returns the caller's recurring brand-audit watches: watchId, domain, interval, webhook presence, last-run time, and active state. Owner-scoped. Read-only.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'properties': {}}
Ausgabeschema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
map_compliance
Map scan findings to compliance frameworks: NIST 800-177, PCI DSS 4.0, SOC 2, CIS Controls. Shows pass/fail/partial status per control.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
map_supply_chain
Map DNS-visible third-party service dependencies for a domain. Correlates SPF, NS, TXT verifications, SRV services, and CAA records to reveal which third-party vendors can send email as the domain, control DNS, or access integrated services. Use when asked to map third-party or supply-chain dependencies — not for listing who can send email (use check_spf for that).
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
osint_investigate_domain_start
Start an async OSINT investigation for a domain. Operator-deploy only; degrades to info when unprovisioned. Returns an investigationId immediately — poll with osint_investigation_status and retrieve results with osint_investigation_report.
Externer Zugriff
Eingabeschema
{'type': 'object', 'required': ['query'], 'properties': {'query': {'type': 'string', 'maxLength': 253, 'minLength': 1}}, 'additionalProperties': False}
osint_investigate_email_start
Start an async OSINT investigation for an email address (breach exposure, account correlation). Owner/enterprise tier only — people-centric OSINT is restricted to prevent misuse. Returns an investigationId immediately — poll with osint_investigation_status and retrieve results with osint_investigation_report.
Externer Zugriff
Eingabeschema
{'type': 'object', 'required': ['query'], 'properties': {'query': {'type': 'string', 'maxLength': 253, 'minLength': 1}}, 'additionalProperties': False}
osint_investigate_infrastructure_start
Start an async deep-infrastructure OSINT investigation for a query (domain, IP, or org). Operator-deploy only; degrades to info when unprovisioned. Returns an investigationId immediately — poll with osint_investigation_status.
Externer Zugriff
Eingabeschema
{'type': 'object', 'required': ['query'], 'properties': {'query': {'type': 'string', 'maxLength': 253, 'minLength': 1}}, 'additionalProperties': False}
osint_investigate_supply_chain_start
Start an async supply-chain OSINT investigation for a query. Operator-deploy only; degrades to info when unprovisioned. Returns an investigationId immediately — poll with osint_investigation_status.
Externer Zugriff
Eingabeschema
{'type': 'object', 'required': ['query'], 'properties': {'query': {'type': 'string', 'maxLength': 253, 'minLength': 1}}, 'additionalProperties': False}
osint_investigate_username_start
Start an async OSINT investigation for a username (cross-platform presence, breach correlation). Owner/enterprise tier only — people-centric OSINT is restricted to prevent misuse. Returns an investigationId immediately — poll with osint_investigation_status and retrieve results with osint_investigation_report.
Externer Zugriff
Eingabeschema
{'type': 'object', 'required': ['query'], 'properties': {'query': {'type': 'string', 'maxLength': 253, 'minLength': 1}}, 'additionalProperties': False}
osint_investigation_report
Retrieve the final report of a completed OSINT investigation by investigationId. Operator-deploy only; degrades to info when unprovisioned or not yet complete.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['investigationId'], 'properties': {'investigationId': {'type': 'string', 'maxLength': 128, 'minLength': 1}}, 'additionalProperties': False}
osint_investigation_status
Poll the status of an OSINT investigation by investigationId. Operator-deploy only; degrades to info when unprovisioned. Returns current status (running | completed | failed) and progress metadata.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['investigationId'], 'properties': {'investigationId': {'type': 'string', 'maxLength': 128, 'minLength': 1}}, 'additionalProperties': False}
prioritize_portfolio_leads
Rank a brand’s portfolio (or an explicit domain set) into prioritized registrar-partner sales leads by product-gap value × severity. Multi-domain, paid. Reuses map_registrar_products per domain, then ranks. Distinct from map_registrar_products (per-domain product mapping) and batch_scan (raw scores).
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'properties': {'brand': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Brand seed apex; discovers the portfolio, derives ownership buckets, then ranks the top candidates.'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'domains': {'type': 'array', 'items': {'type': 'string', 'maxLength': 253, 'minLength': 1}, 'maxItems': 10, 'minItems': 1, 'description': 'Explicit domain set to rank (max 10). Ownership bucket = "unknown".'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run fresh scans.'}}}
rdap_lookup
Fetch domain registration data via RDAP (modern WHOIS replacement). Returns the domain registrar (the company the domain was registered with), registrant contact, creation/expiration dates, EPP status codes, and domain age. Use when asked who registered the domain, who the registrar is, or when the registration expires — distinct from check_ns which identifies the DNS nameserver provider.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
Ausgabeschema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
register_brand_audit_watch
Creates a recurring brand-audit watch for a domain on a daily/weekly/monthly cadence. Each run enqueues a fresh brand_audit_batch_start and (when a webhook is configured) POSTs a diff webhook on classification drift. Returns the new watchId. Owner-scoped; per-principal cap of 20 active watches.
Externer Zugriff
Eingabeschema
{'type': 'object', 'required': ['domain', 'interval'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to watch.'}, 'interval': {'enum': ['daily', 'weekly', 'monthly'], 'type': 'string', 'description': 'Recurrence interval.'}, 'webhook_url': {'type': 'string', 'format': 'uri', 'maxLength': 2048, 'description': 'Optional webhook URL â\x80\x94 POSTed on classification drift. Re-validated for SSRF at both register and delivery time.'}}}
Ausgabeschema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
resolve_spf_chain
Trace the full SPF include chain for a domain. Recursively resolves all includes, shows lookup count, tree depth, and flags circular includes or exceeding the 10-lookup limit.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
scan_buckets_findings
Retrieve findings from a completed cloud-bucket discovery scan by scanId. Operator-deploy only; degrades to info when unprovisioned. The scanId is required so reads can be owner-scoped; target and provider filters are optional.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['scanId'], 'properties': {'scanId': {'type': 'string', 'maxLength': 128, 'minLength': 1}, 'target': {'type': 'string', 'maxLength': 253, 'minLength': 1}, 'providers': {'type': 'array', 'items': {'type': 'string', 'maxLength': 32}, 'maxItems': 8}}, 'additionalProperties': False}
scan_buckets_start
Start an async cloud-bucket discovery scan for a target domain. Operator-deploy only; degrades to info when unprovisioned. Returns a scanId immediately — poll progress with scan_buckets_status and retrieve results with scan_buckets_findings.
Externer Zugriff
Eingabeschema
{'type': 'object', 'required': ['target'], 'properties': {'target': {'type': 'string', 'maxLength': 253, 'minLength': 1}, 'providers': {'type': 'array', 'items': {'type': 'string', 'maxLength': 32}, 'maxItems': 8}}, 'additionalProperties': False}
scan_buckets_status
Poll the status of a cloud-bucket discovery scan by scanId. Operator-deploy only; degrades to info when unprovisioned. Returns scan status (running | completed | failed) and progress metadata.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['scanId'], 'properties': {'scanId': {'type': 'string', 'maxLength': 128, 'minLength': 1}}, 'additionalProperties': False}
scan_domain
Run a full DNS and email security audit for a single domain. Aggregates every scan-included check in parallel (SPF, DKIM, DMARC, DNSSEC, TLS/SSL, MTA-STS, CAA, BIMI, subdomain takeover, and more) and returns an overall security score, NIST-aligned letter grade (6-band A+/A/B/C/D/F), maturity stage, and prioritized findings. Use for a comprehensive single-domain audit, to get a domain's overall security grade, or to assess email security maturity. Version stamps: 'scoringModelVersion' is the scoring POLICY semver (changes only when weights/thresholds/severities change, so it advances slowly) and is INDEPENDENT of — never comparable to — 'dnsChecksPackageVersion', the @blackveil/dns-checks npm engine-package version, which moves every release; a lower model version is expected, not a version gap. When citing a score, record 'scoringConfigHash' — it identifies the exact scoring configuration that produced the result.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'profile': {'enum': ['auto', 'mail_enabled', 'enterprise_mail', 'non_mail', 'web_only', 'minimal', 'authoritative_dns_infra'], 'type': 'string', 'description': 'Scoring profile. Default "auto" detects.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh scan. Useful after DNS changes.'}}}
sge_quickscan
Answer, for ONE domain, whether it meets the New Zealand Secure Government Email (SGE) requirements agencies must satisfy by October 2026. Reports all seven SGE controls — DMARC p=reject, SPF -all, DKIM, SMTP transport TLS, MTA-STS enforce, TLS-RPT, full sub-domain coverage — each as satisfied, not satisfied, or NOT MEASURED, with the structured evidence behind every verdict. Neither SMTP transport TLS nor sub-domain coverage can be observed from a single domain scan, so a DNS-only result tops out at INDETERMINATE, which is not a pass. Distinct from map_compliance, which maps findings to NIST/PCI/SOC 2/CIS.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
simulate_attack_paths
Analyze current DNS posture and enumerate specific attack paths an adversary could exploit, with severity, feasibility, steps, and mitigations.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
validate_fix
Re-check a specific security control after applying a fix, to confirm the finding is now resolved. Use only when a fix has already been applied and you want to verify or confirm the remediation was successful — not for initial inspection of a record.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['domain', 'check'], 'properties': {'check': {'enum': ['spf', 'dmarc', 'dkim', 'dnssec', 'ssl', 'mta_sts', 'ns', 'caa', 'bimi', 'tlsrpt', 'http_security', 'dane'], 'type': 'string', 'description': 'Check name to re-run (e.g., "dmarc", "spf")'}, 'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to validate the fix for'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'expected': {'type': 'string', 'maxLength': 1000, 'description': 'Expected DNS record value to verify against'}}}
Hinzugefügt
check_llms_txt
1. October 2026 02:53
Geändert
check_root_server_set
25. September 2026 03:01
Geändert
check_authoritative_dns_infra
25. September 2026 03:01
Geändert
check_dane
21. September 2026 02:59
Geändert
sge_quickscan
19. September 2026 02:50
Hinzugefügt
osint_investigation_report
17. September 2026 12:34
Hinzugefügt
osint_investigation_status
17. September 2026 12:34
Hinzugefügt
osint_investigate_email_start
17. September 2026 12:34
Hinzugefügt
osint_investigate_username_start
17. September 2026 12:34
Hinzugefügt
osint_investigate_supply_chain_start
17. September 2026 12:34
Hinzugefügt
osint_investigate_infrastructure_start
17. September 2026 12:34
Hinzugefügt
osint_investigate_domain_start
17. September 2026 12:34
Hinzugefügt
scan_buckets_findings
17. September 2026 12:34
Hinzugefügt
scan_buckets_status
17. September 2026 12:34
Hinzugefügt
scan_buckets_start
17. September 2026 12:34
Hinzugefügt
delete_brand_audit_watch
17. September 2026 12:34
Hinzugefügt
register_brand_audit_watch
17. September 2026 12:34
Hinzugefügt
list_brand_audit_watches
17. September 2026 12:34
Hinzugefügt
brand_audit_get_report
17. September 2026 12:34
Hinzugefügt
brand_audit_status
17. September 2026 12:34
Hinzugefügt
brand_audit_batch_start
17. September 2026 12:34
Hinzugefügt
brand_audit_single
17. September 2026 12:34
Hinzugefügt
discover_brand_domains_findings
17. September 2026 12:34
Hinzugefügt
discover_brand_domains_status
17. September 2026 12:34
Hinzugefügt
discover_brand_domains_start
17. September 2026 12:34
Hinzugefügt
discover_brand_domains
17. September 2026 12:34
Hinzugefügt
check_root_server_set
17. September 2026 12:34
Hinzugefügt
check_authoritative_dns_infra
17. September 2026 12:34
Hinzugefügt
check_subdomain_takeover
17. September 2026 12:34
Hinzugefügt
check_fast_flux
17. September 2026 12:34