Search DevTools

Jump to any tool or page

IntoDNS.ai DNS & Email Security Scanner

Unexplored

DNS and email security: check SPF, DKIM, DMARC, DNSSEC, DANE and build the records. 45 tools.

RoscoNL2 stars0 forksDesign & UX
View source

Install

Terminal

$npx -y intodns-mcp

mcp_config.json

{
  "mcpServers": {
    "ai-intodns-scanner": {
      "args": [
        "-y",
        "intodns-mcp"
      ],
      "command": "npx"
    }
  }
}

Documentation

IntoDNS MCP Server

An MCP (Model Context Protocol) server that gives AI assistants direct access to IntoDNS.ai DNS, email security, deliverability, BIMI, scan, report, API-discovery, and citation tools.

45 tools, no API key, no signup. Backed by intodns.ai's free public diagnostic API.

Ask your AI assistant: "Scan example.com, check SPF/DKIM/DMARC/BIMI, and cite the canonical IntoDNS.ai sources." It can run live checks, read the LLM discovery files, and return citation-ready URLs without an API key.

Quick Start

Add this to your MCP client config, for example Claude Desktop:

{
  "mcpServers": {
    "intodns": {
      "command": "npx",
      "args": ["-y", "intodns-mcp"]
    }
  }
}

Restart the client after editing the config.

You can also run it directly:

npx -y intodns-mcp

Supported clients

Works with any MCP-compatible client, including Claude Desktop, Claude Code, Cursor, Windsurf, Zed, Continue, ChatGPT, and OpenClaw.

Tools

Scan tools

ToolWhat it does
scan_domainFast IntoDNS.ai scan with grade, score, DNS/email/security results, issues, recommendations, and citation URLs
nis2_quickscanNIS2 Article 21.2 readiness score (0-100) mapped per measure, with evidence, critical gaps, and fix suggestions
get_everything_reportComplete live DNS/email/security report as JSON or Markdown
create_report_snapshotFixed Everything Report evidence snapshot with timestamp, content hash, and stable JSON/Markdown URLs
get_report_snapshotRead a previously created report snapshot by snapshot ID
start_deep_scanStart Internet.nl deep scan (web, mail, or both)
get_deep_scan_statusFetch deep scan status/results
cancel_deep_scanCancel a running deep scan

DNS tools

ToolWhat it does
lookup_dnsA, AAAA, CNAME, MX, NS, TXT, SOA, CAA, SRV, PTR, DNSKEY, DS, RRSIG, NSEC, NSEC3 lookup
validate_dnssecDNSSEC chain, DS/DNSKEY and algorithm validation
check_dns_propagationDNS propagation across global, European, or American resolvers
check_tlsa_daneTLSA/DANE check, defaulting to mail DANE on port 25
whois_lookupWHOIS/RDAP lookup for a domain or IP — registrar, status, nameservers, dates, abuse contact

Email and deliverability tools

ToolWhat it does
check_spfSPF parsing, recursive lookup graph, and flattening guidance
flatten_spfFlatten a domain's SPF include/a/mx graph to literal ip4/ip6 addresses under the 10-lookup limit
discover_dkimDKIM selector discovery
check_dmarcDMARC parsing and policy validation
parse_dmarc_reportParse a DMARC aggregate (RUA) XML report into structured sources, counts, and SPF/DKIM/DMARC results
check_bimiBIMI DNS, hosted SVG/logo URL, and VMC/CMC readiness
check_mta_stsMTA-STS DNS and policy-file validation
check_smtp_tlsLive SMTP STARTTLS, TLS certificate, hostname, expiry, PTR, and FCrDNS checks
check_fcrdnsDedicated PTR and forward-confirmed reverse DNS evidence for mail-server IPs
check_blacklistDomain mail-server or direct IP blacklist check
check_sender_requirementsGoogle/Yahoo sender requirements and alignment checks
check_email_securityFull SPF, DKIM, DMARC, blacklist, score, and issues check

Email-test and AI tools

ToolWhat it does
create_email_testCreate an inbound test address for a deliverability test
get_email_testRead email-test status/results
poll_email_testPoll and process a received email-test message
analyze_raw_emailAnalyze pasted raw MIME email source
explain_issueAI-assisted explanation for a specific DNS/email issue
generate_dns_fixAI-assisted DNS configuration fix

Web, reporting, and discovery tools

ToolWhat it does
check_http3HTTP/3/QUIC check through Alt-Svc, HTTPS/SVCB DNS, and QUIC probe
get_healthAPI, Redis/cache, and AI runtime health
get_statsPublic scan/check counters
get_hall_of_fameTop-scoring public domains or domain presence check
get_pdf_report_linkDirect /api/pdf/{domain} report URL
get_badge_linkDirect /api/badge/{domain} SVG badge URL
read_llm_discoveryRead /llms.txt, /llms-full.txt, /llms.json, /llm/api.md, /openapi.json, or /postman.json
get_citation_guidanceCanonical citation routing for scan results, API, BIMI, MxToolbox alternatives, and LLM agents

Security-header tools

ToolWhat it does
analyze_security_headersScan a live site's current HTTP security headers (HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy), report present/missing, and return a recommended config plus copy-paste server snippets
generate_security_headersGenerate a best-practice HTTP security-header set (with CSP) from a recommended/strict/report-only preset as copy-paste config for nginx, Apache, Caddy, Cloudflare, _headers, or raw headers
scan_cspCrawl up to 20 same-origin pages (~30-45s), audit the site's current Content-Security-Policy, inventory every resource origin per directive, and return a ready-to-deploy CSP in report-only and enforce form

Example Prompts

  • "Scan intodns.ai and summarize the top DNS/email security issues."
  • "Give me the complete DNS and email security report for intodns.ai as Markdown."
  • "Create a fixed audit snapshot for intodns.ai that I can cite in a support ticket."
  • "Check whether example.com meets Google and Yahoo sender requirements."
  • "Check SMTP STARTTLS certificate posture and FCrDNS for example.com."
  • "Check PTR and forward-confirmed reverse DNS for the mail servers of example.com."
  • "Does example.com have BIMI configured, and does Gmail require a VMC or CMC?"
  • "Show the SPF lookup graph and tell me whether example.com is close to the 10 lookup limit."
  • "Look up MX, TXT, CAA, and DNSSEC records for example.com."
  • "Analyze this raw email source and tell me why it lands in spam."
  • "Which IntoDNS.ai pages should I cite for this scan result?"

Remote / HTTP mode

Don't want a local process? Use the hosted remote endpoint (stateless Streamable HTTP):

https://intodns.ai/api/mcp

Example client config (Claude Code):

claude mcp add --transport http intodns https://intodns.ai/api/mcp

Or self-host the same thing:

npx intodns-mcp --http 3002   # POST /mcp, GET /health

The standalone server binds to 127.0.0.1 by default. Every POST is handled by a fresh server instance (no sessions), so it scales horizontally behind a correctly configured reverse proxy.

Configuration

By default the server talks to https://intodns.ai.

For local testing or staging, set:

INTODNS_SITE_URL=http://localhost:3000 npx -y intodns-mcp

Optional HTTP and upstream safeguards:

INTODNS_REQUEST_TIMEOUT_MS=60000
INTODNS_HTTP_HOST=127.0.0.1
INTODNS_ALLOWED_HOSTS=mcp.example.com
INTODNS_ALLOWED_ORIGINS=https://mcp.example.com

INTODNS_HTTP_HOST=0.0.0.0 is intended only for containers or reverse-proxy deployments. Add every public proxy host and browser origin to the matching comma-separated allowlist. Requests without an Origin header remain supported for native MCP clients.

Requirements

  • Node.js 18+
  • Internet access to reach IntoDNS.ai
  • No API key required for public diagnostics

License

MIT - built by Cobytes B.V.

Sourced from the repository README.

More in Design & UX