BlackVeil DNS & Email Security Scanner by blackveilsecurity.com

MCP server · Email delivery APIs · indexed, not reviewed

Hostedvendor's own

Not reviewed

No score, grade or rank. This listing is facts from the official MCP registry and our own checks, and it stays out of the rankings until the panel reviews it.

How the index works

DNS and email security scanner with 81 MCP tools for SPF, DMARC, DNSSEC, SSL, and brand audits.

What the official MCP registry says

Facts

MCP registry
com.blackveilsecurity/dns · 3.97.0
Endpoint
https://dns-mcp.blackveilsecurity.com/mcp
GitHub stars
9
Registry entry
updated 4 Oct 2026

From the official MCP registry, the package registries and our own checks. JSON · Markdown

Why it's listed

  • It's published in the registry under blackveilsecurity.com, a namespace the registry only gives to whoever proves they control that domain.

Being indexed says nothing about quality, and nobody can pay for it. Is this yours? Ask for a review.

Tools it lists 81 · about 26,225 tokens of context · checked 1 hour ago

ToolWhat it doesHint
check_mxLook up MX records for a domain. Identifies which mail servers receive inbound email for the domain and which email hosting provider is used (Google Workspace, Microsoft 365, Proofpoint, etc.). Use when asked which…read-only
check_spfLook up and validate the SPF record for a domain. Lists all IP addresses and third-party senders authorised to send email on behalf of the domain, flags syntax errors, and shows the trust surface (which mail servers are…read-only
check_dmarcLook up and validate the DMARC record for a domain. Shows the enforcement level (none/quarantine/reject), alignment mode (strict/relaxed), and aggregate/forensic reporting destinations. Use to determine a domain's DMARC…read-only
check_dkimLook up DKIM records for a domain. Probes common selectors, validates the signing algorithm used for outgoing email (RSA-1024/2048, Ed25519), and reports key strength. Use to verify that outbound email signatures are…read-only
check_dnssecCheck DNSSEC status for a domain. Verifies whether DNS is tamper-proof and protected against cache poisoning and DNS spoofing attacks by validating DNSKEY and DS records. Reports whether DNSSEC is enabled and…read-only
check_sslCheck the HTTPS/TLS posture of a domain: HTTPS reachability, HSTS policy, and HTTP-to-HTTPS redirect. Also returns certificate metadata (issuer, expiry date, days remaining, SAN count) read from public Certificate…read-only
check_mta_stsCheck whether a domain enforces SMTP TLS for inbound mail via MTA-STS, protecting against downgrade attacks. Queries _mta-sts.<domain> and fetches the policy file, reports mode (enforce/testing/none) and MX coverage.…read-only
check_nsAudit a domain’s nameserver delegation and redundancy. Identifies the DNS hosting provider and, when the infrastructure probe is available, directly compares parent and child NS sets, verifies authoritative AA…read-only
check_caaLook up CAA records for a domain. Shows which Certificate Authorities are authorized to issue certificates. Part of the scan_domain audit.read-only
check_bimiCheck the BIMI brand-logo record at default._bimi.<domain>. Validates the logo URL (l=) and the presence of mark-certificate authority evidence (a=) — the a= tag is a bare URL, so the certificate type (VMC or CMC) is…read-only
check_tlsrptCheck whether a domain has SMTP TLS Reporting (TLS-RPT) configured. Queries _smtp._tls.<domain> for the v=TLSRPTv1 record and validates its reporting destination (rua= mailto:/https:), flagging a missing record,…read-only
check_http_securityAudit a domain's browser-facing HTTP security headers over HTTPS. Inspects Content-Security-Policy (flagging unsafe-inline/unsafe-eval/wildcards), X-Frame-Options, X-Content-Type-Options, Referrer-Policy,…read-only
check_daneCheck DANE/TLSA certificate pinning for SMTP at port 25. Resolves the domain's MX hosts and looks up TLSA records at _25._tcp.<mx-host>, validating their syntax, usage/selector/matching-type fields and DNSSEC backing on…read-only
check_ptrVerify forward-confirmed reverse DNS (PTR/FCrDNS) for mail servers. Part of the scan_domain audit.read-only
check_dane_httpsVerify DANE certificate pinning for HTTPS connections. Looks up TLSA records at _443._tcp.{domain} (port 443) and validates their syntax, usage/selector/matching-type fields and DNSSEC backing. The record is reported as…read-only
check_svcb_httpsValidate HTTPS/SVCB records (RFC 9460) for modern transport capability advertisement. Part of the scan_domain audit.read-only
check_lookalikesDetect active typosquat and lookalike/homoglyph domains that impersonate your brand and could be used in phishing. Identifies character-substitution and visual-confusion domains registered by attackers. Distinct from…read-only
check_subdomailingDetect SubdoMailing risk: analyzes the SPF include chain for dangling or hijackable subdomains that could let an attacker send email as the domain. Use when you want to know if an SPF include chain can be hijacked…read-only
scan_domainRun a full DNS and email security audit for a single domain. Aggregates every scan-included check in parallel (SPF, DKIM, DMARC, DNSSEC, TLS/SSL, MTA-STS, CAA, BIMI, subdomain takeover, and more) and returns an overall…read-only
batch_scanBulk-scan up to 10 domains in parallel. Runs a full security audit on each domain in the list and returns score, NIST-aligned letter grade (6-band A+/A/B/C/D/F), and finding counts per domain. Use when you want to audit…read-only
batch_scan_startStart a durable asynchronous scan of 1–10 domains. Returns a stable job ID; replaying the same idempotency key with the same principal, normalized inputs, and scoring versions returns the same job.writes
batch_scan_statusRead the owner-scoped status of an asynchronous batch scan.read-only
batch_scan_findingsFetch owner-scoped findings for a completed asynchronous batch scan.read-only
compare_domainsSide-by-side security comparison of 2–5 domains. Shows relative scores, category gaps, and unique weaknesses for each domain. Use when comparing your security posture against a competitor, or doing a head-to-head…read-only
compare_baselineCompare a domain's current security configuration against a fixed policy baseline to determine compliance. Use to check whether a domain meets a policy requirement — not for tracking improvement/regression over time…read-only
check_shadow_domainsFind alternate TLD variants of a domain (e.g. example.net, example.co) that have weak or missing email authentication and could be used to spoof email. Use when asked about TLD variants with email auth gaps — distinct…read-only
check_txt_hygieneAudit TXT records for stale entries and SaaS exposure.read-only
check_mx_reputationCheck whether the mail server (MX) IP addresses are listed on spam blocklists (Spamhaus, Barracuda, SORBS, and other RBLs). Also verifies reverse DNS for MX hosts. Use when you want to know if your mail server IP is…read-only
check_srvMap a domain's DNS-visible service footprint by probing 19 common SRV record prefixes (email, calendar, messaging, directory, web) in parallel. Returns discovered services and flags insecure service advertisements —…read-only
check_zone_hygieneAudit DNS zone hygiene: identifies sensitive or forgotten subdomains exposed in DNS, stale SOA records, and zone propagation issues. Use to find any sensitive subdomains that should not be publicly visible, or to audit…read-only
generateGenerate a DNS/email security remediation artifact. Artifact types: spf_record (build a new SPF record), dmarc_record (create a DMARC policy), dkim_config (DKIM key setup), mta_sts_policy (generate an MTA-STS policy…read-only
get_domain_rankRank a domain against its country or global cohort using the GSI benchmark corpus. Accepts a domain score (from scan_domain) and optional country/sector; returns a percentile: "scores better than X% of peers".…read-only
get_benchmarkGet industry benchmark data: shows what percentile a domain's security score ranks at within its sector or country cohort, the mean score, and the most common DNS security failures across the industry. Use when asked…read-only
get_provider_insightsGet security benchmarks and common configuration issues for a specific email or DNS service-provider cohort (e.g. Google Workspace customers, Microsoft 365 customers). Use when asked how an email service provider…read-only
assess_spoofabilityCompute a composite email spoofability risk score (0–100, higher = more spoofable) by combining SPF trust surface, DMARC enforcement, and DKIM coverage. Returns a risk level (minimal→critical), per-control sub-scores,…read-only
check_resolver_consistencyCheck DNS consistency across 4 public resolvers.read-only
explain_findingExplain a finding with impact and remediation.read-only
map_supply_chainMap DNS-visible third-party service dependencies for a domain. Correlates SPF, NS, TXT verifications, SRV services, and CAA records to reveal which third-party vendors can send email as the domain, control DNS, or…read-only
analyze_driftMeasure whether a domain's DNS security posture improved or regressed by comparing the current state against a prior scan snapshot. Returns a drift classification (improving/stable/regressing/mixed), score delta, and…read-only
validate_fixRe-check a specific security control after applying a fix, to confirm the finding is now resolved. Use only when a fix has already been applied and you want to verify or confirm the remediation was successful — not for…read-only
resolve_spf_chainTrace the full SPF include chain for a domain. Recursively resolves all includes, shows lookup count, tree depth, and flags circular includes or exceeding the 10-lookup limit.read-only
discover_subdomainsFind subdomains of a domain using Certificate Transparency logs. Reveals shadow IT, forgotten services, and unauthorized certificate issuance. Returns a CT SAMPLE, not an asset inventory: the count is a lower bound, a…read-only
map_complianceMap scan findings to compliance frameworks: NIST 800-177, PCI DSS 4.0, SOC 2, CIS Controls. Shows pass/fail/partial status per control.read-only
sge_quickscanAnswer, for ONE domain, whether it meets the New Zealand Secure Government Email (SGE) requirements agencies must satisfy by October 2026. Reports all seven SGE controls — DMARC p=reject, SPF -all, DKIM, SMTP transport…read-only
prioritize_portfolio_leadsRank a brand’s portfolio (or an explicit domain set) into prioritized registrar-partner sales leads by product-gap value × severity. Multi-domain, paid. Reuses map_registrar_products per domain, then ranks. Distinct…read-only
simulate_attack_pathsAnalyze current DNS posture and enumerate specific attack paths an adversary could exploit, with severity, feasibility, steps, and mitigations.read-only
check_dblCheck domain reputation against DNS-based Domain Block Lists (Spamhaus DBL, URIBL, SURBL). Returns listing status with decoded return codes.read-only
check_rblCheck MX server IP reputation against 6 DNS-based Real-time Blocklists (SpamCop, UCEProtect, Mailspike, Barracuda, PSBL). Resolves MX hosts to IPs first.read-only
cymru_asnMap domain IPs to Autonomous System Numbers via Team Cymru DNS. Returns ASN, prefix, country, registry, and organization for each IP. Flags high-risk hosting ASNs.read-only
rdap_lookupFetch domain registration data via RDAP (modern WHOIS replacement). Returns the domain registrar (the company the domain was registered with), registrant contact, creation/expiration dates, EPP status codes, and domain…read-only
check_realtime_threat_feedCheck a domain against BlackVeil real-time threat intelligence (curated intel-gateway feed). Distinct from DNSBL checks. Operator-deploy only; degrades to info when unprovisioned.read-only
check_nsec_walkabilityAssess zone walkability risk by analyzing NSEC3PARAM configuration. Detects plain NSEC zones, weak NSEC3 parameters, and opt-out flags.read-only
check_dnssec_chainWalk the full DNSSEC chain of trust from the DNS root down to the target domain, tracing DS/DNSKEY records and algorithm usage at each zone level. Use when asked to trace the chain of trust from the DNS root, or to see…read-only
check_agent_discoveryAssess the security posture of IETF BANDAID agent-discovery records (draft-mozleywilliams-dnsop-dnsaid). Detects SVCB agent records under _agents/_index._{protocol}._agents, reports whether the discovery zone is…read-only
check_llms_txtInspect a domain's published /llms.txt and /llms-full.txt for links and install instructions an AI agent could inherit from someone else. Parses and dedupes the links (same-origin vs external), sweeps external link…read-only
check_dnskey_strengthAudit the cryptographic strength of DNSKEY signing algorithms used for DNSSEC. Reports which algorithm is used for DNSSEC signing keys (RSA/SHA-1, RSA/SHA-256, ECDSA P-256, Ed25519, etc.), flags deprecated algorithms…read-only
check_fast_fluxDetect fast-flux DNS behavior: performs multiple rounds of A/AAAA queries and checks whether IP addresses are rotating rapidly on each DNS query (a sign of botnet or malicious infrastructure). Compares IP answer sets…read-only
check_subdomain_takeoverSweep subdomains for dangling CNAMEs pointing to deprovisioned cloud services that could be claimed by an attacker (subdomain takeover vulnerabilities). Detects 16 provider families (AWS S3/CloudFront, Azure Front…read-only
check_authoritative_dns_infraMeasure authoritative DNS infrastructure posture for a hostname over direct DNS-over-TCP/53 from a single vantage: TCP/53 reachability, the authoritative AA flag, recursion exposure, SOA serial consistency across…read-only
check_root_server_setQuery a rotating sample of 3 root servers per call and compare the priming NS set, glue, SOA serials, and cross-root consistency against the embedded official root hints. Uses BV_INFRA_PROBE when available; without it,…read-only
discover_brand_domainsDiscover all domains that belong to a brand's portfolio by aggregating certificate, DNS, redirect, and mail-policy signals. Use when asked what domains are part of a brand portfolio, or to find all domains related to a…read-only
discover_brand_domains_startStart an async brand-domain discovery for the EXACT seed domain provided (the async sibling of discover_brand_domains, which can run ~24s and time out interactive clients). Same args as discover_brand_domains. Returns {…writes
discover_brand_domains_statusPoll the status of an async brand-domain discovery started with discover_brand_domains_start. Returns status (queued | running | completed | failed) and progress. Owner-scoped — operationIds owned by other principals…read-only
discover_brand_domains_findingsFetch the ranked candidate domains (the discovery CheckResult) for an async run started with discover_brand_domains_start. Returns notReady while the discovery is still in-flight; the discovery result once complete.…read-only
brand_audit_singleRun a full brand audit on a single target with optional standard/deep discovery depth, brand aliases, and caller-supplied candidate domains. Discovers brand-related domains, looks up registrar + registrant for each…read-only
brand_audit_batch_startEnqueue an async brand audit across up to 50 target domains with optional standard/deep discovery depth, brand aliases, and caller-supplied candidate domains. Returns { auditId, queuedAt, targetCount, etaSeconds }…writes
brand_audit_statusPoll the status of an enqueued brand audit. Returns audit-level status (queued | running | completed | failed), progress 'N/M', and per-target statuses. Owner-scoped — auditIds owned by other principals surface as…read-only
brand_audit_get_reportFetch the result JSON for a completed brand audit. With `target` set, returns the per-target CheckResult; without, returns the audit-level aggregate. Returns notReady when polling an in-flight audit. When a rendered PDF…read-only
list_brand_audit_watchesReturns the caller's recurring brand-audit watches: watchId, domain, interval, webhook presence, last-run time, and active state. Owner-scoped. Read-only.read-only
register_brand_audit_watchCreates a recurring brand-audit watch for a domain on a daily/weekly/monthly cadence. Each run enqueues a fresh brand_audit_batch_start and (when a webhook is configured) POSTs a diff webhook on classification drift.…writes
delete_brand_audit_watchPermanently removes a recurring brand-audit watch by watchId. Owner-scoped — a watchId owned by another principal surfaces as notFound. Returns confirmation of deletion.writes
scan_buckets_startStart an async cloud-bucket discovery scan for a target domain. Operator-deploy only; targets must be operator-authorized on the recon watchlist; degrades to info when unprovisioned. Returns a scanId immediately — poll…writes
scan_buckets_statusPoll the status of a cloud-bucket discovery scan by scanId. Operator-deploy only; targets must be operator-authorized on the recon watchlist; degrades to info when unprovisioned. Returns scan status (running | completed…read-only
scan_buckets_findingsRetrieve findings from a completed cloud-bucket discovery scan by scanId. Operator-deploy only; targets must be operator-authorized on the recon watchlist; degrades to info when unprovisioned. The scanId is required so…read-only
osint_investigate_domain_startStart an async OSINT investigation for a domain. Operator-deploy only; targets must be operator-authorized on the recon watchlist; degrades to info when unprovisioned. Returns an investigationId immediately — poll with…writes
osint_investigate_infrastructure_startStart an async deep-infrastructure OSINT investigation for a query (domain, IP, or org). Operator-deploy only; targets must be operator-authorized on the recon watchlist; degrades to info when unprovisioned. Returns an…writes
osint_investigate_supply_chain_startStart an async supply-chain OSINT investigation for a query. Operator-deploy only; targets must be operator-authorized on the recon watchlist; degrades to info when unprovisioned. Returns an investigationId immediately…writes
osint_investigate_username_startStart an async OSINT investigation for a username (cross-platform presence, breach correlation). Owner/enterprise tier only — people-centric OSINT is restricted to prevent misuse. Returns an investigationId immediately…writes
osint_investigate_email_startStart an async OSINT investigation for an email address (breach exposure, account correlation). Owner/enterprise tier only — people-centric OSINT is restricted to prevent misuse. Returns an investigationId immediately —…writes
osint_investigation_statusPoll the status of an OSINT investigation by investigationId. Operator-deploy only; targets must be operator-authorized on the recon watchlist; degrades to info when unprovisioned. Returns current status (running |…read-only
osint_investigation_reportRetrieve the final report of a completed OSINT investigation by investigationId. Operator-deploy only; targets must be operator-authorized on the recon watchlist; degrades to info when unprovisioned or not yet complete.read-only

What https://dns-mcp.blackveilsecurity.com/mcp answered to tools/list, asked without credentials over MCP 2025-06-18. The token figure is the size of the list as sent, divided by four; a model sees about that much before it calls anything. Full definitions, input schemas included, are in the listing's JSON under mcpTools.

How its tools read to an agent 0 errors · 16 warnings · 1 note

  • warnTC10analyze_drift"baseline" is required and has a default
  • warnTC10discover_brand_domains"discovery_mode" is required and has a default
  • warnTC10discover_brand_domains_start"discovery_mode" is required and has a default
  • warnTC11batch_scan_findings1 parameter without a description: format
  • warnTC11batch_scan_status1 parameter without a description: format
  • warnTC11osint_investigate_domain_startits one parameter, query, has no description
  • warnTC11osint_investigate_email_startits one parameter, query, has no description
  • warnTC11osint_investigate_infrastructure_startits one parameter, query, has no description
  • warnTC11osint_investigate_supply_chain_startits one parameter, query, has no description
  • warnTC11osint_investigate_username_startits one parameter, query, has no description
  • warnTC11osint_investigation_reportits one parameter, investigationId, has no description
  • warnTC11osint_investigation_statusits one parameter, investigationId, has no description
  • warnTC11scan_buckets_findingsnone of its 3 parameters has a description
  • warnTC11scan_buckets_startnone of its 2 parameters has a description
  • warnTC11scan_buckets_statusits one parameter, scanId, has no description
  • warnTC23server81 tools, about 25,058 tokens of definitions
  • noteTC24server36 of 81 tools have no outputSchema

The checks from /check and anchor check, run each day on the list above: about 26,225 tokens of definitions. Not part of the score yet. Check your own server.

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.