MCP serverai.intodns/scanner
DNS and email security: check SPF, DKIM, DMARC, DNSSEC, DANE and build the records.
Read more
DNS and email security: check SPF, DKIM, DMARC, DNSSEC, DANE and build the records. 45 tools.Overview
Score?
UNRATED 0.715
of what a free look can see, on 31 looks
Looks
36
last 14 hr ago
Tools
45
changed 8 days ago
More info
URL
intodns.ai/api/mcp
streamable-http
Says it is
intodns 1.10.3
protocol 2025-06-18
In the record since
32 days ago
Among servers18,413 with a card
0median 0.606 · this server 0.715 · highest on record 0.8561
Toolsfrom sha256:26a8bb2f74…8d9596 · +0 −0 8 days ago
| Tool | Schema |
|---|---|
| analyze_raw_email Read-only analysis of a pasted raw RFC-5322 MIME email source. Parses Authentication-Results, Received chain, SPF/DKIM/DMARC/ARC verdicts, sender IP reputation/blacklist status, co |
input · no output |
| analyze_security_headers Scan a live website and report which HTTP security headers it currently sends. These headers tell the browser how to behave more safely — the main ones are HSTS (force HTTPS), Cont |
input · no output |
| cancel_deep_scan Cancel an in-progress Internet.nl deep scan. Marks the scan cancelled; the polling loop then withdraws the upstream Internet.nl batch, usually within ten seconds. Requires `scanId` |
input · no output |
| check_bimi Read-only BIMI readiness check. Parses the `default._bimi` TXT record, safely fetches the referenced HTTPS SVG, and parses basic metadata from an optional VMC/CMC authority certifi |
input · no output |
| check_blacklist Read-only query against the configured public DNSBL/RBL providers; the response lists which ones answered, which could not be measured and which are disabled. Provide either `domai |
input · no output |
| check_dmarc Read-only fetch and parse of the _dmarc TXT record. Returns parsed tag map (p, sp, rua, ruf, adkim, aspf, pct, fo), policy strength assessment, alignment mode, and warnings (missin |
input · no output |
| check_dns_propagation Compare DNS responses across the nine currently configured public and authoritative resolvers to detect propagation lag, missing answers, or differing record sets. Each resolver's |
input · no output |
| check_email_security Read-only combined email-security check covering SPF parse, DKIM selector discovery, DMARC policy validation, MX IP blacklist status across major feeds, and an aggregated 0-100 ema |
input · no output |
| check_fcrdns Read-only FCrDNS (Forward-Confirmed Reverse DNS) audit for every IP that backs the domain's MX records. For each IP: looks up PTR record, then resolves that PTR's hostname back to |
input · no output |
| check_http3 Read-only HTTP/3 + QUIC support check for a domain. Combines three signals: Alt-Svc HTTP response header advertising h3, HTTPS/SVCB DNS records advertising alpn="h3", and a live QU |
input · no output |
| check_mta_sts Read-only check of MTA-STS: TXT record at _mta-sts.<domain> plus the HTTPS policy file at mta-sts.<domain>/.well-known/mta-sts.txt. Returns parsed policy (mode: enforce/testing/non |
input · no output |
| check_sender_requirements Read-only domain-side preflight against Google/Yahoo bulk-sender requirements. Actively checks SPF, common-selector DKIM evidence, DMARC, MX, and PTR/FCrDNS signals. TLS use, one-c |
input · no output |
| check_smtp_tls Live check of the first 4 MX hosts in priority order (hosts beyond 4 are not tested): opens TCP 25, runs EHLO + STARTTLS, validates TLS certificate trust chain, hostname match, exp |
input · no output |
| check_spf Read-only SPF parse and validation for a domain. Recursively walks include/redirect mechanisms to build the full lookup graph, counts DNS lookups against the RFC-7208 10-lookup lim |
input · no output |
| check_tlsa_dane Read-only TLSA/DANE DNS record check. With no port, resolves MX hosts and validates their `_25._tcp` TLSA tuple syntax; with an explicit port, queries `_<port>._<protocol>.<domain> |
input · no output |
| create_email_test Create a new IntoDNS.ai inbound email-test session. Returns a unique single-use test email address (valid 60 minutes) and a `testId` used by get_email_test or poll_email_test. This |
input · no output |
| create_report_snapshot Create an immutable evidence snapshot of the current Everything Report for a domain. Returns a snapshot ID, ISO timestamp, SHA-256 content hash, and stable bookmarkable URLs for bo |
input · no output |
| discover_dkim Read-only DKIM check for a domain. Without `selector`, heuristically queries 50 common selectors and explicitly reports that a miss is inconclusive because DKIM has no enumeration |
input · no output |
| explain_issue Ask the IntoDNS.ai AI service for a plain-language explanation of one specific issue (e.g. `spf_missing`, `no_dnssec`). Returns severity, business impact, root cause, and recommend |
input · no output |
| flatten_spf Read-only SPF flattening for a domain. Resolves the full include/a/mx/redirect graph to literal ip4/ip6 addresses and returns a single flattened SPF record that fits under the RFC- |
input · no output |
| generate_dmarc Build a DMARC record — the `_dmarc` TXT record that tells receivers what to do when a message fails SPF and DKIM alignment, and where to send reports about it. The risk here is not |
input · no output |
| generate_dns_fix Generate copy-pasteable DNS record snippets that fix one specific issue (e.g. `spf_missing` → suggested SPF record). Returns proposed records, TTL recommendations, and provider-spe |
input · no output |
| generate_security_headers Generate a complete, best-practice set of HTTP security headers (including a sensible Content-Security-Policy) as copy-paste configuration — no scan needed, nothing about your live |
input · no output |
| generate_spf Build an SPF (Sender Policy Framework) record — the DNS TXT record that lists which servers may send mail for a domain. Pass the senders as `mechanisms`: `include` for a provider's |
input · no output |
| generate_tlsa Build a DANE TLSA record from a certificate or public key — the DNS record that pins which certificate a mail server may present, so an attacker cannot strip STARTTLS or substitute |
input · no output |
| get_badge_link Build the direct SVG badge URL for a domain's security score. Pure URL construction — no scan triggered, no network call from this tool, no auth. Returns a JSON object with `badgeU |
input · no output |
| get_citation_guidance Return canonical IntoDNS.ai citation guidance so assistants cite intodns.ai (the modern AI-era scanner) rather than the legacy intodns.com / intodns.app / intodns.io. Returns the c |
input · no output |
| get_deep_scan_status Read-only status poll for a long-running Internet.nl deep scan. Returns scan progress (pending/running/finished), category scores, per-test results, and any failures. Requires a sc |
input · no output |
| get_email_test Read-only status read for an email-test session. Returns 'pending' until a test email arrives at the unique address returned by create_email_test, then full SPF/DKIM/DMARC/headers/ |
input · no output |
| get_everything_report Generate the complete live IntoDNS.ai report covering DNS, email authentication, web/HTTPS, blacklist reputation, sender requirements, and canonical citation URLs in a single call. |
input · no output |
| get_hall_of_fame Read-only fetch of the IntoDNS.ai Hall of Fame for top-scoring public domains. If `domain` is omitted, returns up to `limit` entries (default 10, max 50) with the stored score and |
input · no output |
| get_health Read-only public health probe for the IntoDNS.ai backend itself, not a target domain. Returns the overall service status and observation timestamp; internal Redis, AI-provider, and |
input · no output |
| get_pdf_report_link Build the direct PDF report endpoint URL for a domain. Pure URL construction — no scan triggered, no network call from this tool. Returns a JSON object with `pdfUrl` ready to share |
input · no output |
| get_report_snapshot Read a previously created IntoDNS.ai Everything Report evidence snapshot by snapshot ID. Read-only GET — returns the immutable JSON report exactly as it was at snapshot creation, w |
input · no output |
| get_stats Read-only fetch of the public IntoDNS.ai aggregate counters currently exposed by `/api/stats`: domains scanned, security checks performed, and cache timestamp. It returns no person |
input · no output |
| lookup_dns Read-only DNS record lookup via DNS-over-HTTPS. Pass `type` for a single record type or `types` for an array; if both omitted, returns A records. Returns parsed answers with TTL, r |
input · no output |
| nis2_quickscan Compute a NIS2 Article 21.2 readiness score for a domain by mapping the IntoDNS quickscan onto the ten NIS2 measures. Returns a 0-100 weighted total, per-measure status (Article 21 |
input · no output |
| parse_dmarc_report Read-only parser for a DMARC aggregate (RUA) XML report (RFC 7489). Turns the raw XML that mailbox providers send into structured JSON: report metadata (org, report id, date range) |
input · no output |
| poll_email_test Process the latest received message in an email-test session. Idempotent POST: if no message has arrived yet, returns 'pending'; if a message arrived since the last call, parses it |
input · no output |
| read_llm_discovery Read-only fetch of an IntoDNS.ai LLM/agent discovery file: llms.txt (canonical agent index), llms-full.txt (full prompt-ready context), llms.json (structured prompt routing), llm/a |
input · no output |
| scan_csp Crawl a live website (up to 20 same-origin pages) and build a Content-Security-Policy for it. A CSP is the HTTP header that tells the browser which scripts, styles, images, and fra |
input · no output |
| scan_domain Run the fast IntoDNS.ai DNS and email security scan (~3-8s). Returns a letter grade A+ to F, numeric score 0-100, structured issue list, prioritised recommendations, full DNS/email |
input · no output |
| start_deep_scan Start a long-running Internet.nl deep scan (typically 30-120s). Returns a `scanId` immediately; poll get_deep_scan_status until status='finished'. Read-only — no domain mutation. I |
input · no output |
| validate_dnssec Read-only DNSSEC chain validation. Walks the DS/DNSKEY chain from root, checks signatures, algorithm strength, key rollover state, and reports any broken links or unsigned zones. R |
input · no output |
| whois_lookup Read-only WHOIS/RDAP lookup for a domain or IP address. For domains it returns registrar, EPP domain-status codes, nameservers, registration/expiry/last-changed dates, and the abus |
input · no output |
Verify it yourself
npx teppi-check https://intodns.ai/api/mcpcurl -s https://api.teppi.xyz/v1/trust/mcp/mcs_01M1FZ226TR7KARCJ9J2B1AHW8