# BlackVeil DNS & Email Security Scanner (slim) > BlackVeil DNS & Email Security Scanner, an MCP server by blackveilsecurity.com, listed from the official MCP registry. Indexed, not reviewed: facts and our own checks, no score or ranking. DNS and email security scanner with 81 MCP tools for SPF, DMARC, DNSSEC, SSL, and brand… - Full: https://www.anchorterminal.com/tools/blackveilsecurity-dns.md (~4,700 tokens) · this version ~4,630 tokens · JSON https://www.anchorterminal.com/tools/blackveilsecurity-dns.json · canonical https://www.anchorterminal.com/tools/blackveilsecurity-dns - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-05 # BlackVeil DNS & Email Security Scanner > Indexed, not reviewed: facts from the official MCP registry and our own checks. No score, grade or rank, and not in the rankings until the panel reviews it. How the index works: https://www.anchorterminal.com/indexed/ - Kind: MCP server, by blackveilsecurity.com (https://www.blackveilsecurity.com/dns) - Category: Email delivery APIs (https://www.anchorterminal.com/categories/email.md) - Listed because: It's published in the registry under blackveilsecurity.com, a namespace the registry only gives to whoever proves they control that domain. - What the official MCP registry says: DNS and email security scanner with 81 MCP tools for SPF, DMARC, DNSSEC, SSL, and brand audits. ## Facts - MCP registry: `com.blackveilsecurity/dns` 3.97.0 - Endpoint: https://dns-mcp.blackveilsecurity.com/mcp (streamable HTTP) - Source: https://github.com/MadaBurns/bv-mcp - Website: https://www.blackveilsecurity.com/dns - GitHub stars: 9 - Registry entry updated: 2026-10-04 ## Tools - Tools it lists (81, about 26,225 tokens of context, `tools/list` without credentials over MCP 2025-06-18, checked 2026-10-04 22:22 UTC): - `check_mx` (read-only): Look up MX records for a domain. Identifies which mail servers receive inbound email for the domain and which email hosting provider is used (Google Workspace,… - `check_spf` (read-only): Look up and validate the SPF record for a domain. Lists all IP addresses and third-party senders authorised to send email on behalf of the domain, flags syntax… - `check_dmarc` (read-only): Look up and validate the DMARC record for a domain. Shows the enforcement level (none/quarantine/reject), alignment mode (strict/relaxed), and… - `check_dkim` (read-only): Look up DKIM records for a domain. Probes common selectors, validates the signing algorithm used for outgoing email (RSA-1024/2048, Ed25519), and reports key… - `check_dnssec` (read-only): Check DNSSEC status for a domain. Verifies whether DNS is tamper-proof and protected against cache poisoning and DNS spoofing attacks by validating DNSKEY and… - `check_ssl` (read-only): Check the HTTPS/TLS posture of a domain: HTTPS reachability, HSTS policy, and HTTP-to-HTTPS redirect. Also returns certificate metadata (issuer, expiry date,… - `check_mta_sts` (read-only): Check whether a domain enforces SMTP TLS for inbound mail via MTA-STS, protecting against downgrade attacks. Queries _mta-sts. and fetches the policy… - `check_ns` (read-only): Audit a domain’s nameserver delegation and redundancy. Identifies the DNS hosting provider and, when the infrastructure probe is available, directly compares… - `check_caa` (read-only): Look up CAA records for a domain. Shows which Certificate Authorities are authorized to issue certificates. Part of the scan_domain audit. - `check_bimi` (read-only): Check the BIMI brand-logo record at default._bimi.. Validates the logo URL (l=) and the presence of mark-certificate authority evidence (a=) — the a=… - `check_tlsrpt` (read-only): Check whether a domain has SMTP TLS Reporting (TLS-RPT) configured. Queries _smtp._tls. for the v=TLSRPTv1 record and validates its reporting… - `check_http_security` (read-only): Audit a domain's browser-facing HTTP security headers over HTTPS. Inspects Content-Security-Policy (flagging unsafe-inline/unsafe-eval/wildcards),… - `check_dane` (read-only): Check DANE/TLSA certificate pinning for SMTP at port 25. Resolves the domain's MX hosts and looks up TLSA records at _25._tcp., validating their… - `check_ptr` (read-only): Verify forward-confirmed reverse DNS (PTR/FCrDNS) for mail servers. Part of the scan_domain audit. - `check_dane_https` (read-only): Verify DANE certificate pinning for HTTPS connections. Looks up TLSA records at _443._tcp.{domain} (port 443) and validates their syntax,… - `check_svcb_https` (read-only): Validate HTTPS/SVCB records (RFC 9460) for modern transport capability advertisement. Part of the scan_domain audit. - `check_lookalikes` (read-only): Detect active typosquat and lookalike/homoglyph domains that impersonate your brand and could be used in phishing. Identifies character-substitution and… - `check_subdomailing` (read-only): Detect SubdoMailing risk: analyzes the SPF include chain for dangling or hijackable subdomains that could let an attacker send email as the domain. Use when… - `scan_domain` (read-only): Run a full DNS and email security audit for a single domain. Aggregates every scan-included check in parallel (SPF, DKIM, DMARC, DNSSEC, TLS/SSL, MTA-STS, CAA,… - `batch_scan` (read-only): Bulk-scan up to 10 domains in parallel. Runs a full security audit on each domain in the list and returns score, NIST-aligned letter grade (6-band… - `batch_scan_start` (writes): Start a durable asynchronous scan of 1–10 domains. Returns a stable job ID; replaying the same idempotency key with the same principal, normalized inputs, and… - `batch_scan_status` (read-only): Read the owner-scoped status of an asynchronous batch scan. - `batch_scan_findings` (read-only): Fetch owner-scoped findings for a completed asynchronous batch scan. - `compare_domains` (read-only): Side-by-side security comparison of 2–5 domains. Shows relative scores, category gaps, and unique weaknesses for each domain. Use when comparing your security… - `compare_baseline` (read-only): Compare a domain's current security configuration against a fixed policy baseline to determine compliance. Use to check whether a domain meets a policy… - `check_shadow_domains` (read-only): Find alternate TLD variants of a domain (e.g. example.net, example.co) that have weak or missing email authentication and could be used to spoof email. Use… - `check_txt_hygiene` (read-only): Audit TXT records for stale entries and SaaS exposure. - `check_mx_reputation` (read-only): Check whether the mail server (MX) IP addresses are listed on spam blocklists (Spamhaus, Barracuda, SORBS, and other RBLs). Also verifies reverse DNS for MX… - `check_srv` (read-only): Map a domain's DNS-visible service footprint by probing 19 common SRV record prefixes (email, calendar, messaging, directory, web) in parallel. Returns… - `check_zone_hygiene` (read-only): Audit DNS zone hygiene: identifies sensitive or forgotten subdomains exposed in DNS, stale SOA records, and zone propagation issues. Use to find any sensitive… - `generate` (read-only): Generate a DNS/email security remediation artifact. Artifact types: spf_record (build a new SPF record), dmarc_record (create a DMARC policy), dkim_config… - `get_domain_rank` (read-only): Rank a domain against its country or global cohort using the GSI benchmark corpus. Accepts a domain score (from scan_domain) and optional country/sector;… - `get_benchmark` (read-only): Get industry benchmark data: shows what percentile a domain's security score ranks at within its sector or country cohort, the mean score, and the most common… - `get_provider_insights` (read-only): Get security benchmarks and common configuration issues for a specific email or DNS service-provider cohort (e.g. Google Workspace customers, Microsoft 365… - `assess_spoofability` (read-only): Compute a composite email spoofability risk score (0–100, higher = more spoofable) by combining SPF trust surface, DMARC enforcement, and DKIM coverage.… - `check_resolver_consistency` (read-only): Check DNS consistency across 4 public resolvers. - `explain_finding` (read-only): Explain a finding with impact and remediation. - `map_supply_chain` (read-only): Map DNS-visible third-party service dependencies for a domain. Correlates SPF, NS, TXT verifications, SRV services, and CAA records to reveal which third-party… - `analyze_drift` (read-only): Measure whether a domain's DNS security posture improved or regressed by comparing the current state against a prior scan snapshot. Returns a drift… - `validate_fix` (read-only): Re-check a specific security control after applying a fix, to confirm the finding is now resolved. Use only when a fix has already been applied and you want to… - `resolve_spf_chain` (read-only): Trace the full SPF include chain for a domain. Recursively resolves all includes, shows lookup count, tree depth, and flags circular includes or exceeding the… - `discover_subdomains` (read-only): Find subdomains of a domain using Certificate Transparency logs. Reveals shadow IT, forgotten services, and unauthorized certificate issuance. Returns a CT… - `map_compliance` (read-only): Map scan findings to compliance frameworks: NIST 800-177, PCI DSS 4.0, SOC 2, CIS Controls. Shows pass/fail/partial status per control. - `sge_quickscan` (read-only): Answer, for ONE domain, whether it meets the New Zealand Secure Government Email (SGE) requirements agencies must satisfy by October 2026. Reports all seven… - `prioritize_portfolio_leads` (read-only): Rank a brand’s portfolio (or an explicit domain set) into prioritized registrar-partner sales leads by product-gap value × severity. Multi-domain, paid. Reuses… - `simulate_attack_paths` (read-only): Analyze current DNS posture and enumerate specific attack paths an adversary could exploit, with severity, feasibility, steps, and mitigations. - `check_dbl` (read-only): Check domain reputation against DNS-based Domain Block Lists (Spamhaus DBL, URIBL, SURBL). Returns listing status with decoded return codes. - `check_rbl` (read-only): Check MX server IP reputation against 6 DNS-based Real-time Blocklists (SpamCop, UCEProtect, Mailspike, Barracuda, PSBL). Resolves MX hosts to IPs first. - `cymru_asn` (read-only): Map domain IPs to Autonomous System Numbers via Team Cymru DNS. Returns ASN, prefix, country, registry, and organization for each IP. Flags high-risk hosting… - `rdap_lookup` (read-only): Fetch domain registration data via RDAP (modern WHOIS replacement). Returns the domain registrar (the company the domain was registered with), registrant… - `check_realtime_threat_feed` (read-only): Check a domain against BlackVeil real-time threat intelligence (curated intel-gateway feed). Distinct from DNSBL checks. Operator-deploy only; degrades to info… - `check_nsec_walkability` (read-only): Assess zone walkability risk by analyzing NSEC3PARAM configuration. Detects plain NSEC zones, weak NSEC3 parameters, and opt-out flags. - `check_dnssec_chain` (read-only): Walk the full DNSSEC chain of trust from the DNS root down to the target domain, tracing DS/DNSKEY records and algorithm usage at each zone level. Use when… - `check_agent_discovery` (read-only): Assess the security posture of IETF BANDAID agent-discovery records (draft-mozleywilliams-dnsop-dnsaid). Detects SVCB agent records under… - `check_llms_txt` (read-only): Inspect a domain's published /llms.txt and /llms-full.txt for links and install instructions an AI agent could inherit from someone else. Parses and dedupes… - `check_dnskey_strength` (read-only): Audit the cryptographic strength of DNSKEY signing algorithms used for DNSSEC. Reports which algorithm is used for DNSSEC signing keys (RSA/SHA-1, RSA/SHA-256,… - `check_fast_flux` (read-only): Detect fast-flux DNS behavior: performs multiple rounds of A/AAAA queries and checks whether IP addresses are rotating rapidly on each DNS query (a sign of… - `check_subdomain_takeover` (read-only): Sweep subdomains for dangling CNAMEs pointing to deprovisioned cloud services that could be claimed by an attacker (subdomain takeover vulnerabilities).… - `check_authoritative_dns_infra` (read-only): Measure authoritative DNS infrastructure posture for a hostname over direct DNS-over-TCP/53 from a single vantage: TCP/53 reachability, the authoritative AA… - `check_root_server_set` (read-only): Query a rotating sample of 3 root servers per call and compare the priming NS set, glue, SOA serials, and cross-root consistency against the embedded official… - `discover_brand_domains` (read-only): Discover all domains that belong to a brand's portfolio by aggregating certificate, DNS, redirect, and mail-policy signals. Use when asked what domains are… - `discover_brand_domains_start` (writes): Start an async brand-domain discovery for the EXACT seed domain provided (the async sibling of discover_brand_domains, which can run ~24s and time out… - `discover_brand_domains_status` (read-only): Poll the status of an async brand-domain discovery started with discover_brand_domains_start. Returns status (queued | running | completed | failed) and… - `discover_brand_domains_findings` (read-only): Fetch the ranked candidate domains (the discovery CheckResult) for an async run started with discover_brand_domains_start. Returns notReady while the discovery… - `brand_audit_single` (read-only): Run a full brand audit on a single target with optional standard/deep discovery depth, brand aliases, and caller-supplied candidate domains. Discovers… - `brand_audit_batch_start` (writes): Enqueue an async brand audit across up to 50 target domains with optional standard/deep discovery depth, brand aliases, and caller-supplied candidate domains.… - `brand_audit_status` (read-only): Poll the status of an enqueued brand audit. Returns audit-level status (queued | running | completed | failed), progress 'N/M', and per-target statuses.… - `brand_audit_get_report` (read-only): Fetch the result JSON for a completed brand audit. With `target` set, returns the per-target CheckResult; without, returns the audit-level aggregate. Returns… - `list_brand_audit_watches` (read-only): Returns the caller's recurring brand-audit watches: watchId, domain, interval, webhook presence, last-run time, and active state. Owner-scoped. Read-only. - `register_brand_audit_watch` (writes): Creates a recurring brand-audit watch for a domain on a daily/weekly/monthly cadence. Each run enqueues a fresh brand_audit_batch_start and (when a webhook is… - `delete_brand_audit_watch` (writes): Permanently removes a recurring brand-audit watch by watchId. Owner-scoped — a watchId owned by another principal surfaces as notFound. Returns confirmation of… - `scan_buckets_start` (writes): Start an async cloud-bucket discovery scan for a target domain. Operator-deploy only; targets must be operator-authorized on the recon watchlist; degrades to… - `scan_buckets_status` (read-only): Poll the status of a cloud-bucket discovery scan by scanId. Operator-deploy only; targets must be operator-authorized on the recon watchlist; degrades to info… - `scan_buckets_findings` (read-only): Retrieve findings from a completed cloud-bucket discovery scan by scanId. Operator-deploy only; targets must be operator-authorized on the recon watchlist;… - `osint_investigate_domain_start` (writes): Start an async OSINT investigation for a domain. Operator-deploy only; targets must be operator-authorized on the recon watchlist; degrades to info when… - `osint_investigate_infrastructure_start` (writes): Start an async deep-infrastructure OSINT investigation for a query (domain, IP, or org). Operator-deploy only; targets must be operator-authorized on the recon… - `osint_investigate_supply_chain_start` (writes): Start an async supply-chain OSINT investigation for a query. Operator-deploy only; targets must be operator-authorized on the recon watchlist; degrades to info… - `osint_investigate_username_start` (writes): Start an async OSINT investigation for a username (cross-platform presence, breach correlation). Owner/enterprise tier only — people-centric OSINT is… - `osint_investigate_email_start` (writes): Start an async OSINT investigation for an email address (breach exposure, account correlation). Owner/enterprise tier only — people-centric OSINT is restricted… - `osint_investigation_status` (read-only): Poll the status of an OSINT investigation by investigationId. Operator-deploy only; targets must be operator-authorized on the recon watchlist; degrades to… - `osint_investigation_report` (read-only): Retrieve the final report of a completed OSINT investigation by investigationId. Operator-deploy only; targets must be operator-authorized on the recon… - How its tools read to an agent (0 errors, 16 warnings, 1 note, about 26,225 tokens; rules at https://www.anchorterminal.com/check.md; not part of the score): - warn TC10 analyze_drift: "baseline" is required and has a default - warn TC10 discover_brand_domains: "discovery_mode" is required and has a default - warn TC10 discover_brand_domains_start: "discovery_mode" is required and has a default - warn TC11 batch_scan_findings: 1 parameter without a description: format - warn TC11 batch_scan_status: 1 parameter without a description: format - warn TC11 osint_investigate_domain_start: its one parameter, query, has no description - warn TC11 osint_investigate_email_start: its one parameter, query, has no description - warn TC11 osint_investigate_infrastructure_start: its one parameter, query, has no description - warn TC11 osint_investigate_supply_chain_start: its one parameter, query, has no description - warn TC11 osint_investigate_username_start: its one parameter, query, has no description - warn TC11 osint_investigation_report: its one parameter, investigationId, has no description - warn TC11 osint_investigation_status: its one parameter, investigationId, has no description - warn TC11 scan_buckets_findings: none of its 3 parameters has a description - warn TC11 scan_buckets_start: none of its 2 parameters has a description - warn TC11 scan_buckets_status: its one parameter, scanId, has no description - warn TC23 server: 81 tools, about 25,058 tokens of definitions - note TC24 server: 36 of 81 tools have no outputSchema - JSON: https://www.anchorterminal.com/api/v1/tools/blackveilsecurity-dns.json - Being indexed says nothing about quality, and nobody can pay for it. Ask for a review: https://www.anchorterminal.com/builders/#claiming