BlackVeil DNS & Email Security Scanner
What this MCP does
Audits domain, DNS, email, certificate, HTTP, brand-impersonation, and agent-discovery security controls.
Tools
Input schema
{'type': 'object', 'required': ['domain', 'baseline'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to analyze drift for'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'baseline': {'type': 'string', 'default': 'cached', 'maxLength': 50000, 'minLength': 1, 'description': 'Prior scan reference for drift-over-time analysis: a previous ScanScore JSON STRING, or the literal "cached" to reuse the last cached scan (the default when omitted). NOT a policy/requirements object â\x80\x94 for compliance enforcement against required controls, use compare_baseline instead.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
Input schema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
Input schema
{'type': 'object', 'required': ['domains'], 'properties': {'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'domains': {'type': 'array', 'items': {'type': 'string', 'maxLength': 253, 'minLength': 1}, 'maxItems': 10, 'minItems': 1, 'description': 'Domains to scan (max 10 per request)'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run fresh scans.'}}}
Input schema
{'type': 'object', 'required': ['job_id'], 'properties': {'format': {'enum': ['full', 'compact'], 'type': 'string'}, 'job_id': {'type': 'string', 'pattern': '^bs_[a-f0-9]{40}$', 'description': 'Job ID returned by batch_scan_start.'}}}
Input schema
{'type': 'object', 'required': ['domains', 'idempotency_key'], 'properties': {'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'domains': {'type': 'array', 'items': {'type': 'string', 'maxLength': 253, 'minLength': 1}, 'maxItems': 10, 'minItems': 1, 'description': 'Domains to scan (max 10 per request)'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run fresh scans.'}, 'idempotency_key': {'type': 'string', 'maxLength': 128, 'minLength': 8, 'description': 'Caller-stable replay key for this exact batch request.'}}}
Input schema
{'type': 'object', 'required': ['job_id'], 'properties': {'format': {'enum': ['full', 'compact'], 'type': 'string'}, 'job_id': {'type': 'string', 'pattern': '^bs_[a-f0-9]{40}$', 'description': 'Job ID returned by batch_scan_start.'}}}
Input schema
{'type': 'object', 'required': ['domains'], 'properties': {'view': {'enum': ['standard', 'registrar_complement'], 'type': 'string', 'description': "Output view mode. 'registrar_complement' produces a registrar-complement payload; requires enterprise tier. Default 'standard'."}, 'depth': {'enum': ['standard', 'deep'], 'type': 'string', 'description': 'Discovery depth. standard is default; deep expands candidate seeding and enrichment fanout.'}, 'format': {'anyOf': [{'type': 'string', 'const': 'json'}, {'type': 'string', 'const': 'markdown'}, {'type': 'string', 'const': 'both'}], 'description': 'Inline output mode. Defaults to "both".'}, 'domains': {'type': 'array', 'items': {'type': 'string', 'maxLength': 253, 'minLength': 1}, 'maxItems': 50, 'minItems': 1, 'description': 'Domains to audit (max 50 per batch). Duplicates are merged.'}, 'planner_mode': {'enum': ['off', 'observe', 'enforce'], 'type': 'string', 'description': 'Planner mode for staged discovery fanout. observe emits metrics; enforce applies candidate-backed signal caps.'}, 'brand_aliases': {'type': 'array', 'items': {'type': 'string', 'maxLength': 64, 'minLength': 2}, 'maxItems': 20, 'description': 'Optional public brand aliases to seed, such as product or legal-entity labels.'}, 'discovery_mode': {'enum': ['classic', 'tiered'], 'type': 'string', 'description': 'Brand-discovery pipeline mode. classic = legacy sweep; tiered = tenant/graph/evidence wrappers first (BlackVeil-internal).'}, 'min_confidence': {'type': 'number', 'maximum': 1, 'minimum': 0, 'description': 'Drop candidates whose combined confidence falls below this threshold (0-1, default 0.5).'}, 'candidate_domains': {'type': 'array', 'items': {'type': 'string', 'maxLength': 253, 'minLength': 1}, 'maxItems': 250, 'description': 'Optional candidate domains supplied by the caller for corroboration.'}, 'ownership_verified': {'type': 'boolean', 'description': 'Caller attests that the target domains are owned or authorized for scanning. Required when discovery_mode is "tiered" and the caller is not an enterprise/owner/partner principal.'}}}
Output schema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
Input schema
{'type': 'object', 'required': ['auditId'], 'properties': {'target': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Specific target domain. Omit for audit-level aggregate.'}, 'auditId': {'type': 'string', 'maxLength': 64, 'minLength': 1, 'description': 'Audit ID returned by brand_audit_batch_start.'}}}
Output schema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
Input schema
{'type': 'object', 'required': ['domain'], 'properties': {'view': {'enum': ['standard', 'registrar_complement'], 'type': 'string', 'description': "Output view mode. 'registrar_complement' produces a registrar-complement payload; requires enterprise tier. Default 'standard'."}, 'depth': {'enum': ['standard', 'deep'], 'type': 'string', 'description': 'Discovery depth. standard is default; deep expands candidate seeding and enrichment fanout.'}, 'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Target domain to audit (e.g., apple.com).'}, 'format': {'anyOf': [{'type': 'string', 'const': 'json'}, {'type': 'string', 'const': 'markdown'}, {'type': 'string', 'const': 'both'}], 'description': 'Inline output mode. Defaults to "both".'}, 'planner_mode': {'enum': ['off', 'observe', 'enforce'], 'type': 'string', 'description': 'Planner mode for staged discovery fanout. observe emits metrics; enforce applies candidate-backed signal caps.'}, 'brand_aliases': {'type': 'array', 'items': {'type': 'string', 'maxLength': 64, 'minLength': 2}, 'maxItems': 20, 'description': 'Optional public brand aliases to seed, such as product or legal-entity labels.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}, 'discovery_mode': {'enum': ['classic', 'tiered'], 'type': 'string', 'description': 'Brand-discovery pipeline mode. classic = legacy sweep; tiered = tenant/graph/evidence wrappers first (BlackVeil-internal).'}, 'min_confidence': {'type': 'number', 'maximum': 1, 'minimum': 0, 'description': 'Drop candidates whose combined confidence falls below this threshold (0-1, default 0.5).'}, 'candidate_domains': {'type': 'array', 'items': {'type': 'string', 'maxLength': 253, 'minLength': 1}, 'maxItems': 250, 'description': 'Optional candidate domains supplied by the caller for corroboration.'}, 'ownership_verified': {'type': 'boolean', 'description': 'Caller attests that the target domain is owned or authorized for scanning. Required when discovery_mode is "tiered" and the caller is not an enterprise/owner/partner principal.'}}}
Output schema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
Input schema
{'type': 'object', 'required': ['auditId'], 'properties': {'auditId': {'type': 'string', 'maxLength': 64, 'minLength': 1, 'description': 'Audit ID returned by brand_audit_batch_start.'}}}
Output schema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
Input schema
{'type': 'object', 'required': ['domain'], 'properties': {'name': {'type': 'string', 'maxLength': 63, 'minLength': 1, 'description': 'Resolve a single named agent ({name}.{domain}) instead of enumerating the zone.'}, 'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check for published agent-discovery records (e.g., example.com).'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'protocol': {'enum': ['a2a', 'mcp', 'https'], 'type': 'string', 'description': 'Scope discovery to a single agent protocol index (_index._{protocol}._agents). Omit to sweep the zone.'}, 'verify_cap': {'type': 'boolean', 'description': 'Fetch each declared capability document (cap=) over HTTPS via safeFetch and verify it against the cap-sha256 integrity pin. Default false (declaration/existence check only).'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
Output schema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
Input schema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
Output schema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
Input schema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
Output schema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
Input schema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
Output schema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
Input schema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
Output schema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
Input schema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
Output schema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
Input schema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
Output schema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
Input schema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'selector': {'type': 'string', 'pattern': '^[a-z0-9]([a-z0-9-]*[a-z0-9])?$', 'maxLength': 63, 'description': 'DKIM selector. Omit to probe common ones.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
Output schema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
Input schema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
Output schema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
Input schema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
Output schema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
Input schema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
Output schema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
Input schema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
Output schema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
Input schema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'rounds': {'type': 'integer', 'maximum': 5, 'minimum': 3, 'description': 'Number of query rounds (3-5, default 3).'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
Output schema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
Input schema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
Output schema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
Input schema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
Output schema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
Input schema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
Output schema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
Input schema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
Output schema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
Input schema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
Output schema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
Input schema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
Output schema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
Input schema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
Output schema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
Input schema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
Output schema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
Input schema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
Output schema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
Input schema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
Output schema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
Input schema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
Output schema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
Input schema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'record_type': {'enum': ['A', 'AAAA', 'MX', 'TXT', 'NS', 'CNAME', 'SOA', 'CAA'], 'type': 'string', 'description': 'Record type. Omit for A/AAAA/MX/TXT/NS.'}}}
Input schema
{'type': 'object', 'properties': {'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}}}
Output schema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
Input schema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
Output schema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
Input schema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
Output schema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
Input schema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
Output schema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
Input schema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
Output schema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
Input schema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
Output schema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
Input schema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com).'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'subdomains': {'type': 'array', 'items': {'type': 'string', 'maxLength': 253, 'minLength': 1}, 'maxItems': 1000, 'description': 'Optional explicit subdomain list (full FQDNs or short labels). When provided (deduped, capped at 1000), this list is swept instead of the 15-name built-in. Source from Certificate-Transparency enumeration or brand-audit discovery.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
Output schema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
Input schema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
Output schema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
Input schema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
Output schema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
Input schema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
Output schema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
Input schema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
Output schema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
Input schema
{'type': 'object', 'required': ['domain', 'baseline'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to scan and compare.'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'baseline': {'type': 'object', 'properties': {'grade': {'enum': ['A+', 'A', 'B+', 'B', 'C+', 'C', 'D+', 'D', 'F'], 'type': 'string', 'description': 'Min grade (e.g., "B+").'}, 'score': {'type': 'number', 'maximum': 100, 'minimum': 0, 'description': 'Min score (0-100).'}, 'require_caa': {'type': 'boolean', 'description': 'Require CAA.'}, 'require_spf': {'type': 'boolean', 'description': 'Require SPF.'}, 'require_dkim': {'type': 'boolean', 'description': 'Require DKIM.'}, 'require_dnssec': {'type': 'boolean', 'description': 'Require DNSSEC.'}, 'require_mta_sts': {'type': 'boolean', 'description': 'Require MTA-STS.'}, 'max_high_findings': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': 0, 'description': 'Max high findings allowed.'}, 'max_critical_findings': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': 0, 'description': 'Max critical findings (default 0).'}, 'require_dmarc_enforce': {'type': 'boolean', 'description': 'Require DMARC enforce.'}}, 'description': 'Policy/requirements baseline OBJECT for compliance enforcement â\x80\x94 "does this domain meet these required controls?" (grade/score floors, require_* flags, max_*_findings). NOT a prior scan. For drift-over-time vs a previous ScanScore (or the literal "cached"), use analyze_drift instead.', 'additionalProperties': {}}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
Input schema
{'type': 'object', 'required': ['domains'], 'properties': {'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'domains': {'type': 'array', 'items': {'type': 'string', 'maxLength': 253, 'minLength': 1}, 'maxItems': 5, 'minItems': 2, 'description': 'Domains to compare (2â\x80\x935 domains)'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
Input schema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
Output schema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
Input schema
{'type': 'object', 'required': ['watchId'], 'properties': {'watchId': {'type': 'string', 'maxLength': 64, 'minLength': 1, 'description': 'Watch ID returned by register_brand_audit_watch.'}}}
Output schema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
Input schema
{'type': 'object', 'required': ['domain', 'discovery_mode'], 'properties': {'depth': {'enum': ['standard', 'deep'], 'type': 'string', 'description': 'Discovery depth. standard is default; deep expands candidate seeding and enrichment fanout.'}, 'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': "The exact seed domain to expand, scanned verbatim (e.g., example.com). Do NOT normalize, resolve, or substitute a brand's canonical/main domain â\x80\x94 pass the literal domain the user named (e.g. pass `clau.de`, not `anthropic.com`). Use `brand_aliases` for related brand labels."}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'signals': {'type': 'array', 'items': {'enum': ['san', 'san_recursive', 'ns', 'dmarc_rua', 'dkim_key_reuse', 'http_redirect', 'mx_overlap', 'txt_verification', 'mx_platform', 'spf_include', 'spf_include_seed', 'cname_alignment'], 'type': 'string'}, 'maxItems': 12, 'minItems': 1, 'description': 'Signal modules to invoke. Defaults to all 12 discovery/enrichment signals.'}, 'planner_mode': {'enum': ['off', 'observe', 'enforce'], 'type': 'string', 'description': 'Planner mode for staged discovery fanout. observe emits metrics; enforce applies candidate-backed signal caps.'}, 'brand_aliases': {'type': 'array', 'items': {'type': 'string', 'maxLength': 64, 'minLength': 2}, 'maxItems': 20, 'description': 'Optional public brand aliases to seed, such as product or legal-entity labels.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}, 'discovery_mode': {'enum': ['classic', 'tiered'], 'type': 'string', 'default': 'classic', 'description': 'Discovery mode. "classic" (default, BSL-licensed) runs the public signal-sweep pipeline. "tiered" layers Tier 0 (tenant-declared portfolio), Tier 1 (infrastructure-graph), and Tier 2 (declared-evidence) lookups in front of the legacy sweep, falling back to Tier 3 (the existing sweep) only on cache miss / very_stale fingerprint / uncovered caller candidates. Tiered mode requires private BlackVeil service bindings â\x80\x94 BSL self-hosts should leave this on "classic".'}, 'dkim_selectors': {'type': 'array', 'items': {'type': 'string', 'maxLength': 63, 'minLength': 1}, 'maxItems': 50, 'description': 'Optional DKIM selectors to probe. Defaults to a built-in common-selector list.'}, 'min_confidence': {'type': 'number', 'maximum': 1, 'minimum': 0, 'description': 'Drop candidates whose combined confidence falls below this threshold (0-1, default 0.5).'}, 'candidate_domains': {'type': 'array', 'items': {'type': 'string', 'maxLength': 253, 'minLength': 1}, 'maxItems': 250, 'description': 'Optional candidate domains supplied by the caller for corroboration.'}, 'ownership_verified': {'type': 'boolean', 'description': 'Caller attests that the seed domain is owned or authorized for scanning. Required when discovery_mode is "tiered" and the caller is not an enterprise/owner/partner principal. Prevents unauthorized mass reconnaissance via deep tier lookups.'}}}
Output schema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
Input schema
{'type': 'object', 'required': ['operationId'], 'properties': {'operationId': {'type': 'string', 'maxLength': 64, 'minLength': 1, 'description': 'Operation ID returned by discover_brand_domains_start.'}}}
Input schema
{'type': 'object', 'required': ['domain', 'discovery_mode'], 'properties': {'depth': {'enum': ['standard', 'deep'], 'type': 'string', 'description': 'Discovery depth. standard is default; deep expands candidate seeding and enrichment fanout.'}, 'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': "The exact seed domain to expand, scanned verbatim (e.g., example.com). Do NOT normalize, resolve, or substitute a brand's canonical/main domain â\x80\x94 pass the literal domain the user named (e.g. pass `clau.de`, not `anthropic.com`). Use `brand_aliases` for related brand labels."}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'signals': {'type': 'array', 'items': {'enum': ['san', 'san_recursive', 'ns', 'dmarc_rua', 'dkim_key_reuse', 'http_redirect', 'mx_overlap', 'txt_verification', 'mx_platform', 'spf_include', 'spf_include_seed', 'cname_alignment'], 'type': 'string'}, 'maxItems': 12, 'minItems': 1, 'description': 'Signal modules to invoke. Defaults to all 12 discovery/enrichment signals.'}, 'planner_mode': {'enum': ['off', 'observe', 'enforce'], 'type': 'string', 'description': 'Planner mode for staged discovery fanout. observe emits metrics; enforce applies candidate-backed signal caps.'}, 'brand_aliases': {'type': 'array', 'items': {'type': 'string', 'maxLength': 64, 'minLength': 2}, 'maxItems': 20, 'description': 'Optional public brand aliases to seed, such as product or legal-entity labels.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}, 'discovery_mode': {'enum': ['classic', 'tiered'], 'type': 'string', 'default': 'classic', 'description': 'Discovery mode. "classic" (default, BSL-licensed) runs the public signal-sweep pipeline. "tiered" layers Tier 0 (tenant-declared portfolio), Tier 1 (infrastructure-graph), and Tier 2 (declared-evidence) lookups in front of the legacy sweep, falling back to Tier 3 (the existing sweep) only on cache miss / very_stale fingerprint / uncovered caller candidates. Tiered mode requires private BlackVeil service bindings â\x80\x94 BSL self-hosts should leave this on "classic".'}, 'dkim_selectors': {'type': 'array', 'items': {'type': 'string', 'maxLength': 63, 'minLength': 1}, 'maxItems': 50, 'description': 'Optional DKIM selectors to probe. Defaults to a built-in common-selector list.'}, 'min_confidence': {'type': 'number', 'maximum': 1, 'minimum': 0, 'description': 'Drop candidates whose combined confidence falls below this threshold (0-1, default 0.5).'}, 'candidate_domains': {'type': 'array', 'items': {'type': 'string', 'maxLength': 253, 'minLength': 1}, 'maxItems': 250, 'description': 'Optional candidate domains supplied by the caller for corroboration.'}, 'ownership_verified': {'type': 'boolean', 'description': 'Caller attests that the seed domain is owned or authorized for scanning. Required when discovery_mode is "tiered" and the caller is not an enterprise/owner/partner principal. Prevents unauthorized mass reconnaissance via deep tier lookups.'}}}
Input schema
{'type': 'object', 'required': ['operationId'], 'properties': {'operationId': {'type': 'string', 'maxLength': 64, 'minLength': 1, 'description': 'Operation ID returned by discover_brand_domains_start.'}}}
Input schema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
Input schema
{'type': 'object', 'required': ['checkType', 'status'], 'properties': {'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'status': {'enum': ['pass', 'fail', 'warning', 'critical', 'high', 'medium', 'low', 'info'], 'type': 'string', 'description': 'Finding severity or status.'}, 'details': {'type': 'string', 'maxLength': 2000, 'description': 'Additional detail from check result.'}, 'checkType': {'type': 'string', 'maxLength': 100, 'minLength': 1, 'description': "Check type (e.g., 'SPF', 'DMARC')."}}}
Input schema
{'type': 'object', 'required': ['artifact', 'domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'policy': {'enum': ['none', 'quarantine', 'reject'], 'type': 'string', 'description': 'dmarc_record: policy (default "reject").'}, 'artifact': {'enum': ['fix_plan', 'spf_record', 'dmarc_record', 'dkim_config', 'mta_sts_policy', 'rollout_plan'], 'type': 'string', 'description': 'Which artifact to generate (e.g., "dmarc_record", "fix_plan").'}, 'mx_hosts': {'type': 'array', 'items': {'type': 'string', 'pattern': '^[^\\s\\x00-\\x1f\\x7f]*$', 'maxLength': 253, 'minLength': 1}, 'maxItems': 20, 'description': 'mta_sts_policy: MX hosts. Omit to detect from DNS.'}, 'provider': {'type': 'string', 'maxLength': 100, 'description': 'dkim_config: provider (e.g., "google"). Omit for generic.'}, 'timeline': {'enum': ['aggressive', 'standard', 'conservative'], 'type': 'string', 'description': 'rollout_plan: rollout speed (default: standard).'}, 'rua_email': {'type': 'string', 'pattern': '^[^\\s;,@\\x00-\\x1f\\x7f]+@[^\\s;,@\\x00-\\x1f\\x7f]+\\.[^\\s;,@\\x00-\\x1f\\x7f]+$', 'maxLength': 254, 'description': 'dmarc_record: report email. Default: dmarc-reports@{domain}.'}, 'force_refresh': {'type': 'boolean', 'description': 'fix_plan: bypass cache and run a fresh scan.'}, 'target_policy': {'enum': ['quarantine', 'reject'], 'type': 'string', 'description': 'rollout_plan: target DMARC policy (default: reject).'}, 'include_providers': {'type': 'array', 'items': {'type': 'string', 'pattern': '^[a-z0-9._-]+$', 'maxLength': 253, 'minLength': 1}, 'maxItems': 15, 'description': 'spf_record: providers to include (e.g., ["google"]).'}}}
Input schema
{'type': 'object', 'properties': {'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'profile': {'enum': ['mail_enabled', 'enterprise_mail', 'non_mail', 'web_only', 'minimal', 'authoritative_dns_infra'], 'type': 'string', 'description': 'Profile to benchmark (default "mail_enabled").'}}}
Input schema
{'type': 'object', 'required': ['domain', 'score'], 'properties': {'score': {'type': 'number', 'maximum': 100, 'minimum': 0, 'description': 'Domain score (0â\x80\x93100) from scan_domain. Used to compute the cohort percentile.'}, 'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to rank against its cohort (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'sector': {'type': 'string', 'maxLength': 100, 'minLength': 1, 'description': 'Sector label (e.g., "finance"). Forwarded to the cohort endpoint; sector filtering is planned for a future release.'}, 'country': {'type': 'string', 'maxLength': 2, 'minLength': 2, 'description': 'ISO 3166-1 alpha-2 country code to use the country cohort (e.g., "NZ"). Omit for global cohort.'}}}
Input schema
{'type': 'object', 'required': ['provider'], 'properties': {'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'profile': {'enum': ['mail_enabled', 'enterprise_mail', 'non_mail', 'web_only', 'minimal', 'authoritative_dns_infra'], 'type': 'string', 'description': 'Profile (default "mail_enabled").'}, 'provider': {'type': 'string', 'maxLength': 200, 'minLength': 1, 'description': 'Provider (e.g., "google workspace").'}}}
Input schema
{'type': 'object', 'properties': {}}
Output schema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
Input schema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
Input schema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
Input schema
{'type': 'object', 'required': ['query'], 'properties': {'query': {'type': 'string', 'maxLength': 253, 'minLength': 1}}, 'additionalProperties': False}
Input schema
{'type': 'object', 'required': ['query'], 'properties': {'query': {'type': 'string', 'maxLength': 253, 'minLength': 1}}, 'additionalProperties': False}
Input schema
{'type': 'object', 'required': ['query'], 'properties': {'query': {'type': 'string', 'maxLength': 253, 'minLength': 1}}, 'additionalProperties': False}
Input schema
{'type': 'object', 'required': ['query'], 'properties': {'query': {'type': 'string', 'maxLength': 253, 'minLength': 1}}, 'additionalProperties': False}
Input schema
{'type': 'object', 'required': ['query'], 'properties': {'query': {'type': 'string', 'maxLength': 253, 'minLength': 1}}, 'additionalProperties': False}
Input schema
{'type': 'object', 'required': ['investigationId'], 'properties': {'investigationId': {'type': 'string', 'maxLength': 128, 'minLength': 1}}, 'additionalProperties': False}
Input schema
{'type': 'object', 'required': ['investigationId'], 'properties': {'investigationId': {'type': 'string', 'maxLength': 128, 'minLength': 1}}, 'additionalProperties': False}
Input schema
{'type': 'object', 'properties': {'brand': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Brand seed apex; discovers the portfolio, derives ownership buckets, then ranks the top candidates.'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'domains': {'type': 'array', 'items': {'type': 'string', 'maxLength': 253, 'minLength': 1}, 'maxItems': 10, 'minItems': 1, 'description': 'Explicit domain set to rank (max 10). Ownership bucket = "unknown".'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run fresh scans.'}}}
Input schema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
Output schema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
Input schema
{'type': 'object', 'required': ['domain', 'interval'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to watch.'}, 'interval': {'enum': ['daily', 'weekly', 'monthly'], 'type': 'string', 'description': 'Recurrence interval.'}, 'webhook_url': {'type': 'string', 'format': 'uri', 'maxLength': 2048, 'description': 'Optional webhook URL â\x80\x94 POSTed on classification drift. Re-validated for SSRF at both register and delivery time.'}}}
Output schema
{'type': 'object', 'required': ['category', 'score', 'passed', 'findings'], 'properties': {'score': {'type': 'number'}, 'passed': {'type': 'boolean'}, 'partial': {'type': 'boolean'}, 'category': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'properties': {}, 'additionalProperties': {}}}, 'checkStatus': {'type': 'string'}}, 'additionalProperties': {}}
Input schema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
Input schema
{'type': 'object', 'required': ['scanId'], 'properties': {'scanId': {'type': 'string', 'maxLength': 128, 'minLength': 1}, 'target': {'type': 'string', 'maxLength': 253, 'minLength': 1}, 'providers': {'type': 'array', 'items': {'type': 'string', 'maxLength': 32}, 'maxItems': 8}}, 'additionalProperties': False}
Input schema
{'type': 'object', 'required': ['target'], 'properties': {'target': {'type': 'string', 'maxLength': 253, 'minLength': 1}, 'providers': {'type': 'array', 'items': {'type': 'string', 'maxLength': 32}, 'maxItems': 8}}, 'additionalProperties': False}
Input schema
{'type': 'object', 'required': ['scanId'], 'properties': {'scanId': {'type': 'string', 'maxLength': 128, 'minLength': 1}}, 'additionalProperties': False}
Input schema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'profile': {'enum': ['auto', 'mail_enabled', 'enterprise_mail', 'non_mail', 'web_only', 'minimal', 'authoritative_dns_infra'], 'type': 'string', 'description': 'Scoring profile. Default "auto" detects.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh scan. Useful after DNS changes.'}}}
Input schema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
Input schema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to check (e.g., example.com)'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'force_refresh': {'type': 'boolean', 'description': 'Bypass cache and run a fresh check. Useful after DNS changes.'}}}
Input schema
{'type': 'object', 'required': ['domain', 'check'], 'properties': {'check': {'enum': ['spf', 'dmarc', 'dkim', 'dnssec', 'ssl', 'mta_sts', 'ns', 'caa', 'bimi', 'tlsrpt', 'http_security', 'dane'], 'type': 'string', 'description': 'Check name to re-run (e.g., "dmarc", "spf")'}, 'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain to validate the fix for'}, 'format': {'enum': ['full', 'compact'], 'type': 'string', 'description': 'Output verbosity. Auto-detected if omitted.'}, 'expected': {'type': 'string', 'maxLength': 1000, 'description': 'Expected DNS record value to verify against'}}}
Recent tool changes
Similar MCP servers
BorealHost
Provides web hosting and infrastructure management, including site deployment, DNS, domains, containers, compute, backups, cachin…
Hackertarget
Performs passive DNS, ASN, IP geolocation, HTTP header, ping, link, and network-path reconnaissance and diagnostics.
Busymate DevTools
Captures, inspects, exports, and debugs HTTPS traffic from devices and applications, with request and response inspection, proxy …
Ripe Stat
Provides RIPE registry and routing data for IP addresses, prefixes, ASNs, BGP state and neighbors, network ownership, geolocation…
Cloudflare Radar
Provides Cloudflare Radar internet observatory data on DDoS attacks, BGP leaks, domain popularity, internet quality, and traffic …
Domains
Checks domain registration status and availability and searches certificate-transparency records for certificates and subdomains.
Rdap
Looks up authoritative RDAP registration records for domains, IP addresses, autonomous systems, entities, and nameservers.
seekrit — secrets for agents
Manages encrypted application secrets, shared secret groups, environments, access grants, service tokens, leases, KMS metadata, a…