Server definition
- Hash
- sha256:e9410b4a97946e946341908848f4217dbf57fc88ecf38623e8af795a7973e774
- What it is
- What a remote MCP server returned when asked what it offers: 8 tools
The blob, as servednamed by its sha256
{
"instructions": "WHICH TOOL: isn't working / not resolving / is it DNS? -> check_domain, one call. NS path -> trace. CNAME -> alias_chain. auths agree? -> sweep_domain. one resolver -> dig. what my resolver sends -> path_receipt. DNSSEC -> dnssec_chain. hold? -> registration. READ-ONLY, REMOTE (isitdns edge and probes); refused, with reason: private or off-board resolver · inside name · private NS address. Every verdict with its readings (asked what, of which server, from where, when; rcode, flags, EDE, latency); not measured is said, never inferred. Do not write \"it is not DNS\"; write what was checked, from where, and what it showed. INTERCEPTION is measured on the person's own machine, never by these tools: give them dig @192.0.2.1 <name>, which should get NO answer (a documentation address with no server, RFC 5737: an answer proves their path answers DNS it was not sent; hand it over as written), then dig @1.1.1.1 <name>; canary.probe.isitdns.net (only answer 192.0.2.111) is the reference. API: an answer that is not an error carries \"api: <url>\" above it and \"ask again: <url>\" last; give the person the api: and ask again: lines as printed. A dig with a flag off its default has no ask again line. RCODE: NOERROR+data answer · NOERROR empty = NODATA (norec: not cached) · NXDOMAIN (filtering rows: blocked, compare unfiltered) · SERVFAIL resolver failed (cd=true answers: validation) · REFUSED/timeout: nothing about the record · AD: validated. Prompts (prompts/list): 12 workflows over these tools. Docs: https://isitdns.net/agents",
"tools": [
{
"description": "Use when a name is a CNAME and the person asks where it leads. Returns each hop with its target and TTL, and how it ends: addresses, none, a resolver failure, NXDOMAIN (dangling), a loop, or an inside name.",
"inputSchema": {
"properties": {
"name": {
"description": "The name to follow, e.g. www.example.com. Also as \"domain\"; a URL is read as its host.",
"type": "string"
}
},
"required": [
"name"
],
"type": "object"
},
"name": "alias_chain",
"outputSchema": null
},
{
"description": "Use when a domain or website is not working or not resolving (is it DNS?): one call. The first line says whether the name resolves; then the eleven-check audit of its zone, each row ok, warn, fail or skipped and why.",
"inputSchema": {
"properties": {
"from": {
"description": "Ask from the probe in this region",
"enum": [
"north-america",
"europe"
],
"type": "string"
},
"name": {
"description": "The domain to audit. Also as \"domain\"; a URL is read as its host.",
"type": "string"
}
},
"required": [
"name"
],
"type": "object"
},
"name": "check_domain",
"outputSchema": null
},
{
"description": "Use for one exact question to one public resolver, not as the first call for a site that is not working. Returns records, flags, rcode, EDE and latency; DoH from the edge, or Do53 from a region's probe (from).",
"inputSchema": {
"properties": {
"cd": {
"default": false,
"description": "Ask the resolver not to validate",
"type": "boolean"
},
"dnssec": {
"default": true,
"description": "Set the DO bit and read AD",
"type": "boolean"
},
"ecs": {
"description": "EDNS Client Subnet, e.g. 192.0.2.0/24",
"type": "string"
},
"family": {
"default": "v4",
"description": "Address family to dial",
"enum": [
"v4",
"v6",
"both"
],
"type": "string"
},
"from": {
"description": "Ask from the probe in this region",
"enum": [
"north-america",
"europe"
],
"type": "string"
},
"name": {
"description": "The name, e.g. _dmarc.example.com. Also as \"domain\"; a URL is read as its host.",
"type": "string"
},
"norec": {
"default": false,
"description": "Clear RD, like dig +norec",
"type": "boolean"
},
"nsid": {
"default": false,
"description": "Request NSID (RFC 5001)",
"type": "boolean"
},
"resolver": {
"default": "cloudflare",
"description": "A board resolver id (cloudflare, google, quad9, opendns, adguard, cleanbrowsing, controld, quad9-unfiltered, adguard-family, cleanbrowsing-family, adguard-unfiltered, opendns-familyshield, nextdns, cloudflare-malware, cloudflare-family, mullvad-base, dns4eu-protective), an alias such as 8.8.8.8, or all for the tier-1 operators side by side.",
"type": "string"
},
"type": {
"default": "A",
"description": "Record type, e.g. A, MX, TXT, DS, HTTPS, or TYPE<n>",
"type": "string"
}
},
"required": [
"name"
],
"type": "object"
},
"name": "dig",
"outputSchema": null
},
{
"description": "Use when a name fails validation or the person asks whether its DNSSEC chain holds. Returns each signed zone cut from the root to the answer and the first link that breaks, or where it goes insecure.",
"inputSchema": {
"properties": {
"name": {
"description": "The name, e.g. www.example.com. Also as \"domain\"; a URL is read as its host.",
"type": "string"
},
"type": {
"default": "A",
"description": "The record type to check at the end of the chain",
"type": "string"
}
},
"required": [
"name"
],
"type": "object"
},
"name": "dnssec_chain",
"outputSchema": null
},
{
"description": "Use when the person wants proof of what their resolver sends. First call: one dig to run. Second, with the nonce: what we saw (resolver address, UDP/TCP, DO, CD, EDNS size, cookie, ECS, case, arrivals) and the signed TXT.",
"inputSchema": {
"properties": {
"nonce": {
"description": "From the first call",
"type": "string"
}
},
"type": "object"
},
"name": "path_receipt",
"outputSchema": null
},
{
"description": "Use when a domain has vanished from DNS and the person asks whether it expired or is on hold. Returns the registry's RDAP statuses and what each means for resolution, the dates and its nameservers; no contacts.",
"inputSchema": {
"properties": {
"domain": {
"description": "The domain or a hostname under it. Also as \"name\"; a URL is read as its host.",
"type": "string"
}
},
"required": [
"domain"
],
"type": "object"
},
"name": "registration",
"outputSchema": null
},
{
"description": "Use after a zone change, when the person asks whether the authoritative servers agree. Returns each nameserver's answer to each name and type you list, the disagreements, lame or silent servers, and CAA and ACME readiness.",
"inputSchema": {
"properties": {
"domain": {
"description": "The zone or name to sweep, e.g. example.com. Also as \"name\"; a URL is read as its host.",
"type": "string"
},
"names": {
"description": "Relative labels to ask, \"@\" for the apex. Default: @, www, _dmarc, _acme-challenge",
"items": {
"type": "string"
},
"type": "array"
},
"types": {
"description": "Record types. Default: SOA, NS, A, AAAA, MX, TXT, CAA",
"items": {
"type": "string"
},
"type": "array"
}
},
"required": [
"domain"
],
"type": "object"
},
"name": "sweep_domain",
"outputSchema": null
},
{
"description": "Use when the person wants to walk the delegation for a name, root to authoritative, like dig +trace. Returns each referral and glue, lame or unreachable servers, the final answer and a verdict.",
"inputSchema": {
"properties": {
"name": {
"description": "The name to walk. Also as \"domain\"; a URL is read as its host.",
"type": "string"
},
"type": {
"default": "A",
"description": "Record type for the final question",
"type": "string"
}
},
"required": [
"name"
],
"type": "object"
},
"name": "trace",
"outputSchema": null
}
]
}Verify it yourself
curl -s https://api.teppi.xyz/v1/evidence/sha256:e9410b4a97946e946341908848f4217dbf57fc88ecf38623e8af795a7973e774 | sha256sum