MCP Server

isitdns

net.isitdns/isitdns
Cloud & Infrastructure Security Public & reachable MCP 2026-07-28

What this MCP does

Provides live DNS lookups, delegation tracing, resolver monitoring, outage history, DNSSEC checks, and domain configuration audits.

alias_chain
Follow a CNAME chain
Use when a name is a CNAME and the person asks where it leads. Returns each hop with its target and TTL, and how it ends: addresses, none, a resolver failure, NXDOMAIN (dangling), a loop, or an inside name.
Read only Open world Idempotent
Input schema
{'type': 'object', 'required': ['name'], 'properties': {'name': {'type': 'string', 'description': 'The name to follow, e.g. www.example.com. Also as "domain"; a URL is read as its host.'}}}
check_domain
Check a domain
Use when a domain or website is not working or not resolving (is it DNS?): one call. The first line says whether the name resolves; then the eleven-check audit of its zone, each row ok, warn, fail or skipped and why.
Read only Open world Idempotent
Input schema
{'type': 'object', 'required': ['name'], 'properties': {'from': {'enum': ['north-america', 'europe'], 'type': 'string', 'description': 'Ask from the probe in this region'}, 'name': {'type': 'string', 'description': 'The domain to audit. Also as "domain"; a URL is read as its host.'}}}
dig
dig
Use for one exact question to one public resolver, not as the first call for a site that is not working. Returns records, flags, rcode, EDE and latency; DoH from the edge, or Do53 from a region's probe (from).
Read only Open world Idempotent
Input schema
{'type': 'object', 'required': ['name'], 'properties': {'cd': {'type': 'boolean', 'default': False, 'description': 'Ask the resolver not to validate'}, 'ecs': {'type': 'string', 'description': 'EDNS Client Subnet, e.g. 192.0.2.0/24'}, 'from': {'enum': ['north-america', 'europe'], 'type': 'string', 'description': 'Ask from the probe in this region'}, 'name': {'type': 'string', 'description': 'The name, e.g. _dmarc.example.com. Also as "domain"; a URL is read as its host.'}, 'nsid': {'type': 'boolean', 'default': False, 'description': 'Request NSID (RFC 5001)'}, 'type': {'type': 'string', 'default': 'A', 'description': 'Record type, e.g. A, MX, TXT, DS, HTTPS, or TYPE<n>'}, 'norec': {'type': 'boolean', 'default': False, 'description': 'Clear RD, like dig +norec'}, 'dnssec': {'type': 'boolean', 'default': True, 'description': 'Set the DO bit and read AD'}, 'family': {'enum': ['v4', 'v6', 'both'], 'type': 'string', 'default': 'v4', 'description': 'Address family to dial'}, 'resolver': {'type': 'string', 'default': 'cloudflare', 'description': 'A board resolver id (cloudflare, google, quad9, opendns, adguard, cleanbrowsing, controld, quad9-unfiltered, adguard-family, cleanbrowsing-family, adguard-unfiltered, opendns-familyshield, nextdns, cloudflare-malware, cloudflare-family, mullvad-base, dns4eu-protective), an alias such as 8.8.8.8, or all for the tier-1 operators side by side.'}}}
dnssec_chain
Walk the DNSSEC chain
Use when a name fails validation or the person asks whether its DNSSEC chain holds. Returns each signed zone cut from the root to the answer and the first link that breaks, or where it goes insecure.
Read only Open world Idempotent
Input schema
{'type': 'object', 'required': ['name'], 'properties': {'name': {'type': 'string', 'description': 'The name, e.g. www.example.com. Also as "domain"; a URL is read as its host.'}, 'type': {'type': 'string', 'default': 'A', 'description': 'The record type to check at the end of the chain'}}}
path_receipt
Path receipt
Use when the person wants proof of what their resolver sends. First call: one dig to run. Second, with the nonce: what we saw (resolver address, UDP/TCP, DO, CD, EDNS size, cookie, ECS, case, arrivals) and the signed TXT.
Read only Open world
Input schema
{'type': 'object', 'properties': {'nonce': {'type': 'string', 'description': 'From the first call'}}}
registration
Registration status (RDAP)
Use when a domain has vanished from DNS and the person asks whether it expired or is on hold. Returns the registry's RDAP statuses and what each means for resolution, the dates and its nameservers; no contacts.
Read only Open world Idempotent
Input schema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'description': 'The domain or a hostname under it. Also as "name"; a URL is read as its host.'}}}
sweep_domain
Sweep a domain across its authoritative servers
Use after a zone change, when the person asks whether the authoritative servers agree. Returns each nameserver's answer to each name and type you list, the disagreements, lame or silent servers, and CAA and ACME readiness.
Read only Open world Idempotent
Input schema
{'type': 'object', 'required': ['domain'], 'properties': {'names': {'type': 'array', 'items': {'type': 'string'}, 'description': 'Relative labels to ask, "@" for the apex. Default: @, www, _dmarc, _acme-challenge'}, 'types': {'type': 'array', 'items': {'type': 'string'}, 'description': 'Record types. Default: SOA, NS, A, AAAA, MX, TXT, CAA'}, 'domain': {'type': 'string', 'description': 'The zone or name to sweep, e.g. example.com. Also as "name"; a URL is read as its host.'}}}
trace
Delegation walk
Use when the person wants to walk the delegation for a name, root to authoritative, like dig +trace. Returns each referral and glue, lame or unreachable servers, the final answer and a verdict.
Read only Open world Idempotent
Input schema
{'type': 'object', 'required': ['name'], 'properties': {'name': {'type': 'string', 'description': 'The name to walk. Also as "domain"; a URL is read as its host.'}, 'type': {'type': 'string', 'default': 'A', 'description': 'Record type for the final question'}}}
Removed
top_domains
Oct. 1, 2026, 2:50 a.m.
Removed
resolver_status
Oct. 1, 2026, 2:50 a.m.
Removed
resolver_history
Oct. 1, 2026, 2:50 a.m.
Removed
ksk_board
Oct. 1, 2026, 2:50 a.m.
Removed
dns_events
Oct. 1, 2026, 2:50 a.m.
Added
path_receipt
Oct. 1, 2026, 2:50 a.m.
Changed
registration
Oct. 1, 2026, 2:50 a.m.
Changed
alias_chain
Oct. 1, 2026, 2:50 a.m.
Changed
sweep_domain
Oct. 1, 2026, 2:50 a.m.
Changed
dnssec_chain
Oct. 1, 2026, 2:50 a.m.
Changed
trace
Oct. 1, 2026, 2:50 a.m.
Changed
dig
Oct. 1, 2026, 2:50 a.m.
Changed
check_domain
Oct. 1, 2026, 2:50 a.m.
Added
registration
Sept. 29, 2026, 2:59 a.m.
Added
alias_chain
Sept. 29, 2026, 2:59 a.m.
Added
dnssec_chain
Sept. 29, 2026, 2:59 a.m.
Changed
ksk_board
Sept. 29, 2026, 2:59 a.m.
Changed
dns_events
Sept. 29, 2026, 2:59 a.m.
Changed
top_domains
Sept. 29, 2026, 2:59 a.m.
Changed
resolver_history
Sept. 29, 2026, 2:59 a.m.
Changed
resolver_status
Sept. 29, 2026, 2:59 a.m.
Changed
trace
Sept. 29, 2026, 2:59 a.m.
Changed
check_domain
Sept. 29, 2026, 2:59 a.m.
Changed
sweep_domain
Sept. 29, 2026, 2:59 a.m.
Changed
dig
Sept. 29, 2026, 2:59 a.m.
Added
sweep_domain
Sept. 27, 2026, 2:50 a.m.
Changed
top_domains
Sept. 25, 2026, 2:59 a.m.
Added
ksk_board
Sept. 17, 2026, 12:54 p.m.
Added
dns_events
Sept. 17, 2026, 12:54 p.m.
Added
top_domains
Sept. 17, 2026, 12:54 p.m.