dns-doctor
Was dieses MCP kann
Audits and verifies DNS, SPF, DKIM, DMARC, MX, propagation, reverse DNS, domain registration, email security, and monitoring configuration.
Tools
Eingabeschema
{'type': 'object', 'title': 'add_monitored_domainArguments', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'title': 'Domain', 'description': "The domain, e.g. example.com. For add_monitored_domain: any registrable domain the linked account owns (re-adding one it already monitors returns that row). For check_domain_verification and get_domain_records: a domain this account already monitors, verified or still pending. Any other name — another account's, or one nobody monitors — is refused as not found; ownership is never disclosed."}}}
Ausgabeschema
{'type': 'object', 'title': 'add_monitored_domainDictOutput', 'additionalProperties': True}
Eingabeschema
{'type': 'object', 'title': 'audit_spf_includesArguments', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'title': 'Domain', 'description': 'The domain to check, e.g. example.com. Bare registrable names and subdomains both work; scheme, path or port do not belong here. Unicode names are accepted and normalized to punycode.'}}}
Ausgabeschema
{'type': 'object', 'title': 'audit_spf_includesDictOutput', 'additionalProperties': True}
Eingabeschema
{'type': 'object', 'title': 'build_dmarc_upgradeArguments', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'title': 'Domain', 'description': 'The domain to check, e.g. example.com. Bare registrable names and subdomains both work; scheme, path or port do not belong here. Unicode names are accepted and normalized to punycode.'}}}
Ausgabeschema
{'type': 'object', 'title': 'build_dmarc_upgradeDictOutput', 'additionalProperties': True}
Eingabeschema
{'type': 'object', 'title': 'build_parked_domain_recordsArguments', 'required': ['domain', 'confirm_no_mail'], 'properties': {'domain': {'type': 'string', 'title': 'Domain', 'description': 'The domain to check, e.g. example.com. Bare registrable names and subdomains both work; scheme, path or port do not belong here. Unicode names are accepted and normalized to punycode.'}, 'rua_email': {'anyOf': [{'type': 'string'}, {'type': 'null'}], 'title': 'Rua Email', 'default': None, 'description': 'Mailbox to receive DMARC aggregate (RUA) reports, as a plain address like dmarc@example.com. Strongly recommended: without it nobody can see who sends as the domain.'}, 'confirm_no_mail': {'type': 'boolean', 'title': 'Confirm No Mail', 'description': 'Must be true, and only the HUMAN who owns the domain may decide it: it records their confirmation that this domain sends no email at all. Never set it on your own judgment or because a scan looked quiet — ask them. It unlocks the question only; the server independently re-checks DNS for evidence of mail and refuses when it finds any.'}}}
Ausgabeschema
{'type': 'object', 'title': 'build_parked_domain_recordsDictOutput', 'additionalProperties': True}
Eingabeschema
{'type': 'object', 'title': 'check_dkim_selectorArguments', 'required': ['domain', 'selector'], 'properties': {'domain': {'type': 'string', 'title': 'Domain', 'description': 'The domain to check, e.g. example.com. Bare registrable names and subdomains both work; scheme, path or port do not belong here. Unicode names are accepted and normalized to punycode.'}, 'selector': {'type': 'string', 'title': 'Selector', 'description': "The DKIM selector to probe — the name before ._domainkey, e.g. 'google', 'selector1', or a dotted form like 's1.prod'. The sending platform's settings page names it; it is not guessable from the domain."}}}
Ausgabeschema
{'type': 'object', 'title': 'check_dkim_selectorDictOutput', 'additionalProperties': True}
Eingabeschema
{'type': 'object', 'title': 'check_domain_verificationArguments', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'title': 'Domain', 'description': "The domain, e.g. example.com. For add_monitored_domain: any registrable domain the linked account owns (re-adding one it already monitors returns that row). For check_domain_verification and get_domain_records: a domain this account already monitors, verified or still pending. Any other name — another account's, or one nobody monitors — is refused as not found; ownership is never disclosed."}}}
Ausgabeschema
{'type': 'object', 'title': 'check_domain_verificationDictOutput', 'additionalProperties': True}
Eingabeschema
{'type': 'object', 'title': 'check_propagationArguments', 'required': ['name'], 'properties': {'name': {'type': 'string', 'title': 'Name', 'description': 'The exact DNS name to look up, e.g. example.com, www.example.com or _dmarc.example.com. It is used as given — a leading www. is NOT stripped and underscore labels are kept — so pass the name the record is actually published at, not the registrable domain.'}, 'record_type': {'enum': ['A', 'AAAA', 'CNAME', 'MX', 'TXT', 'NS'], 'type': 'string', 'title': 'Record Type', 'default': 'A', 'description': 'The record type to read at that exact name (default A). SPF and DMARC records are TXT — pass TXT with the right name rather than expecting a derived query name.'}, 'expected_value': {'anyOf': [{'type': 'string'}, {'type': 'null'}], 'title': 'Expected Value', 'default': None, 'description': "Optional value the record should now hold, e.g. '1.2.3.4' or the new DMARC record text. Supply it and each cell is reported as match or mismatch against it; omit it and the check only reports whether the vantage points agree with each other."}}}
Ausgabeschema
{'type': 'object', 'title': 'check_propagationDictOutput', 'additionalProperties': True}
Eingabeschema
{'type': 'object', 'title': 'check_recordArguments', 'required': ['domain', 'kind'], 'properties': {'host': {'anyOf': [{'type': 'string'}, {'type': 'null'}], 'title': 'Host', 'default': None, 'description': "Optional label to prepend to the domain (e.g. 'mail' to check mail.<domain>) — honored for txt, cname, a and aaaa only; spf, dmarc and mx derive their own query name."}, 'kind': {'enum': ['spf', 'dmarc', 'txt', 'mx', 'cname', 'a', 'aaaa'], 'type': 'string', 'title': 'Kind', 'description': "Which record to read; the right query is derived from it — 'dmarc' reads TXT at _dmarc.<domain> filtered to v=DMARC1, 'spf' reads the apex TXT filtered to v=spf1, so don't prefix the domain yourself."}, 'domain': {'type': 'string', 'title': 'Domain', 'description': 'The domain to check, e.g. example.com. Bare registrable names and subdomains both work; scheme, path or port do not belong here. Unicode names are accepted and normalized to punycode.'}}}
Ausgabeschema
{'type': 'object', 'title': 'check_recordDictOutput', 'additionalProperties': True}
Eingabeschema
{'type': 'object', 'title': 'check_reverse_dnsArguments', 'required': ['ip'], 'properties': {'ip': {'type': 'string', 'title': 'Ip', 'description': 'The sending IP to check, IPv4 or IPv6. Must be a public address — private, loopback and CGNAT ranges have no meaningful reverse DNS and are refused.'}}}
Ausgabeschema
{'type': 'object', 'title': 'check_reverse_dnsDictOutput', 'additionalProperties': True}
Eingabeschema
{'type': 'object', 'title': 'count_spf_lookupsArguments', 'properties': {'domain': {'anyOf': [{'type': 'string'}, {'type': 'null'}], 'title': 'Domain', 'default': None, 'description': 'Domain whose PUBLISHED SPF record should be resolved and counted recursively (nested includes cost lookups too). Pass exactly one of domain or record, never both.'}, 'record': {'anyOf': [{'type': 'string'}, {'type': 'null'}], 'title': 'Record', 'default': None, 'description': "A pasted SPF record to parse instead of resolving one, e.g. 'v=spf1 include:_spf.google.com ~all'. Counts this record's own terms only. Pass exactly one of domain or record, never both."}}}
Ausgabeschema
{'type': 'object', 'title': 'count_spf_lookupsDictOutput', 'additionalProperties': True}
Eingabeschema
{'type': 'object', 'title': 'generate_dmarc_recordArguments', 'required': ['policy'], 'properties': {'policy': {'enum': ['none', 'quarantine', 'reject'], 'type': 'string', 'title': 'Policy', 'description': "The requested p= policy: 'none' monitors only, 'quarantine' sends failing mail to spam, 'reject' refuses it outright. Start at 'none' unless the domain's aggregate reports already justify enforcement."}, 'rua_email': {'anyOf': [{'type': 'string'}, {'type': 'null'}], 'title': 'Rua Email', 'default': None, 'description': 'Mailbox to receive DMARC aggregate (RUA) reports, as a plain address like dmarc@example.com. Strongly recommended: without it nobody can see who sends as the domain.'}, 'strict_alignment': {'type': 'boolean', 'title': 'Strict Alignment', 'default': False, 'description': 'Set true to emit strict alignment (aspf=s adkim=s), requiring an exact domain match instead of the organizational-domain match. Leave false unless you know every sender aligns strictly.'}, 'subdomain_policy': {'anyOf': [{'enum': ['none', 'quarantine', 'reject'], 'type': 'string'}, {'type': 'null'}], 'title': 'Subdomain Policy', 'default': None, 'description': 'Optional sp= policy for subdomains when it should differ from the main p= policy. Omit to let subdomains inherit p=.'}}}
Ausgabeschema
{'type': 'object', 'title': 'generate_dmarc_recordDictOutput', 'additionalProperties': True}
Eingabeschema
{'type': 'object', 'title': 'get_alertsArguments', 'properties': {'type': {'anyOf': [{'type': 'string'}, {'type': 'null'}], 'title': 'Type', 'default': None, 'description': "Optional alert-type filter, e.g. 'record_changed'. An unknown value is rejected rather than silently returning an empty page — omit it unless you know the exact type."}, 'limit': {'type': 'integer', 'title': 'Limit', 'default': 50, 'description': 'Page size, 1..100 (default 50). Page down with `before` before you advance `since`, or you will skip every row you did not receive.'}, 'since': {'anyOf': [{'type': 'string'}, {'type': 'null'}], 'title': 'Since', 'default': None, 'description': 'Optional ISO-8601 timestamp: return alerts created at or after it (INCLUSIVE). Poll by storing the newest created_at you have seen and passing it back — rows repeat rather than go missing, so de-duplicate on id.'}, 'before': {'anyOf': [{'type': 'string'}, {'type': 'null'}], 'title': 'Before', 'default': None, 'description': "The opaque cursor from a previous page's next_before, relayed verbatim to fetch the next older page. Never construct or edit one."}, 'domain': {'anyOf': [{'type': 'string'}, {'type': 'null'}], 'title': 'Domain', 'default': None, 'description': "Optional filter to ONE of the account's verified monitored domains. Omit it for every domain the account monitors; an unowned or unknown name is refused as not found."}}}
Ausgabeschema
{'type': 'object', 'title': 'get_alertsDictOutput', 'additionalProperties': True}
Eingabeschema
{'type': 'object', 'title': 'get_domain_recordsArguments', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'title': 'Domain', 'description': "The domain, e.g. example.com. For add_monitored_domain: any registrable domain the linked account owns (re-adding one it already monitors returns that row). For check_domain_verification and get_domain_records: a domain this account already monitors, verified or still pending. Any other name — another account's, or one nobody monitors — is refused as not found; ownership is never disclosed."}}}
Ausgabeschema
{'type': 'object', 'title': 'get_domain_recordsDictOutput', 'additionalProperties': True}
Eingabeschema
{'type': 'object', 'title': 'get_readinessArguments', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'title': 'Domain', 'description': "One of the token account's VERIFIED monitored domains, e.g. example.com. Any other name — another account's, or one nobody monitors — is refused as not found; ownership is never disclosed."}}}
Ausgabeschema
{'type': 'object', 'title': 'get_readinessDictOutput', 'additionalProperties': True}
Eingabeschema
{'type': 'object', 'title': 'get_reportArguments', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'title': 'Domain', 'description': 'The domain to check, e.g. example.com. Bare registrable names and subdomains both work; scheme, path or port do not belong here. Unicode names are accepted and normalized to punycode.'}}}
Ausgabeschema
{'type': 'object', 'title': 'get_reportDictOutput', 'additionalProperties': True}
Eingabeschema
{'type': 'object', 'title': 'lookup_registrationArguments', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'title': 'Domain', 'description': 'The domain to check, e.g. example.com. Bare registrable names and subdomains both work; scheme, path or port do not belong here. Unicode names are accepted and normalized to punycode.'}}}
Ausgabeschema
{'type': 'object', 'title': 'lookup_registrationDictOutput', 'additionalProperties': True}
Eingabeschema
{'type': 'object', 'title': 'parse_dmarc_reportArguments', 'required': ['content_base64'], 'properties': {'filename': {'anyOf': [{'type': 'string'}, {'type': 'null'}], 'title': 'Filename', 'default': None, 'description': 'Optional original attachment filename, recorded in logs only — format detection is content-based, so this changes nothing about parsing.'}, 'content_base64': {'type': 'string', 'title': 'Content Base64', 'description': 'One DMARC aggregate (RUA) report file, base64-encoded: the .xml, .xml.gz or .zip attachment exactly as received, up to 2 MiB decoded. Encode the file bytes — do not paste raw XML here.'}}}
Ausgabeschema
{'type': 'object', 'title': 'parse_dmarc_reportDictOutput', 'additionalProperties': True}
Eingabeschema
{'type': 'object', 'title': 'scan_domainArguments', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'title': 'Domain', 'description': 'The domain to check, e.g. example.com. Bare registrable names and subdomains both work; scheme, path or port do not belong here. Unicode names are accepted and normalized to punycode.'}}}
Ausgabeschema
{'type': 'object', 'title': 'scan_domainDictOutput', 'additionalProperties': True}
Eingabeschema
{'type': 'object', 'title': 'start_monitoring_signupArguments', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'title': 'Domain', 'description': 'The domain to check, e.g. example.com. Bare registrable names and subdomains both work; scheme, path or port do not belong here. Unicode names are accepted and normalized to punycode.'}}}
Ausgabeschema
{'type': 'object', 'title': 'start_monitoring_signupDictOutput', 'additionalProperties': True}
Eingabeschema
{'type': 'object', 'title': 'validate_dmarc_recordArguments', 'required': ['record'], 'properties': {'record': {'type': 'string', 'title': 'Record', 'description': "The DMARC record text to validate, e.g. 'v=DMARC1; p=none; rua=mailto:reports@example.com'. The record value only — not the _dmarc hostname it is published at."}}}
Ausgabeschema
{'type': 'object', 'title': 'validate_dmarc_recordDictOutput', 'additionalProperties': True}
Letzte Tool-Änderungen
Ähnliche MCP-Server
BorealHost
Provides web hosting and infrastructure management, including site deployment, DNS, domains, containers, compute, backups, cachin…
BlackVeil DNS & Email Security Scanner
Audits domain, DNS, email, certificate, HTTP, brand-impersonation, and agent-discovery security controls.
Hackertarget
Performs passive DNS, ASN, IP geolocation, HTTP header, ping, link, and network-path reconnaissance and diagnostics.
Busymate DevTools
Captures, inspects, exports, and debugs HTTPS traffic from devices and applications, with request and response inspection, proxy …
Ripe Stat
Provides RIPE registry and routing data for IP addresses, prefixes, ASNs, BGP state and neighbors, network ownership, geolocation…
Cloudflare Radar
Provides Cloudflare Radar internet observatory data on DDoS attacks, BGP leaks, domain popularity, internet quality, and traffic …
Domains
Checks domain registration status and availability and searches certificate-transparency records for certificates and subdomains.
Rdap
Looks up authoritative RDAP registration records for domains, IP addresses, autonomous systems, entities, and nameservers.