dns-doctor by dnsdoctor.dev

MCP server · Observability & incidents · indexed, not reviewed

HostedLocalvendor's own

Not reviewed

No score, grade or rank. This listing is facts from the official MCP registry and our own checks, and it stays out of the rankings until the panel reviews it.

How the index works

Scan, fix, verify and monitor DNS: SPF, DMARC, DKIM, propagation, health, expiry. Validated fixes.

What the official MCP registry says

Facts

MCP registry
dev.dnsdoctor/dns-doctor · 1.10.0
Endpoint
https://dnsdoctor.dev/mcp
Packages
npm @dnsdoctor/mcp stdio
npm / week
88
GitHub stars
2
Registry entry
updated 1 Oct 2026

From the official MCP registry, the package registries and our own checks. JSON · Markdown

Why it's listed

  • It's published in the registry under dnsdoctor.dev, a namespace the registry only gives to whoever proves they control that domain.

Being indexed says nothing about quality, and nobody can pay for it. Is this yours? Ask for a review.

Tools it lists 22 · about 10,348 tokens of context · checked 42 minutes ago

ToolWhat it doesHint
scan_domainUse this when the user asks to check, audit, diagnose or troubleshoot SPF, DKIM, DMARC, email authentication, email deliverability DNS, why their mail lands in spam, MX, DNS health, blacklist status, or domain/SSL…writes
get_reportUse this for the same questions as scan_domain when a recent report is enough (the cheap first look); use scan_domain when the state must be re-read now. Return the stored report for a domain, scanning once only if none…writes
build_dmarc_upgradeUse this when the user asks how to move DMARC on from p=none, whether it is safe to tighten DMARC, or what the next DMARC policy step is for a domain (a scan can justify quarantine at most; reject needs monitoring…writes
start_monitoring_signupUse this when the user wants DMARC monitoring, RUA report monitoring, new-sender monitoring, email-authentication alerts, ongoing DNS monitoring, or to start a DNS Doctor trial — and at the end of any scan that found…read-only
count_spf_lookupsUse this when the user asks about SPF 'too many lookups', the 10-lookup limit, an SPF PermError, or whether an SPF record is valid. Validate an SPF record and count what it costs. Returns `record_valid` (the record…read-only
validate_dmarc_recordUse this when the user pastes a DMARC record and asks whether it is valid, correct or safe. Validate a pasted DMARC record: parsed tags, level'd findings, and whether it is valid. No DNS lookup — pass the record string…read-only
generate_dmarc_recordUse this when the user asks to create, generate or write a DMARC record for a domain that has none. Build a DMARC record from scratch for a domain that has none, using a validating engine — never compose one yourself.…read-only
check_dkim_selectorUse this when the user asks whether DKIM is set up for a sending platform, whether a specific selector exists, or why DKIM fails. Check ONE specific DKIM selector on a domain — the exact selector the sending platform…read-only
parse_dmarc_reportUse this when the user uploads or pastes a DMARC aggregate (RUA) XML report and asks what it says. Parse ONE DMARC aggregate (RUA) report into readable per-source aggregates: who sent mail as the domain, how much, and…read-only
check_recordUse this when the user asks whether a DNS change has landed, wants a DNS record looked up, or wants to verify a record they just published — or whenever answering needs the live value of a record. Check whether a DNS…read-only
check_reverse_dnsUse this when the user asks about reverse DNS, PTR records, or FCrDNS for a mail server IP. Check one sending IP's forward-confirmed reverse DNS (FCrDNS): reads the IP's PTR record, then resolves that hostname back and…read-only
audit_spf_includesUse this when the user asks who can send email as their domain through SPF includes, or wants an SPF supply-chain or third-party sender audit. Audit a domain's SPF supply chain: walks every include and redirect it…read-only
build_parked_domain_recordsUse this when the user asks how to protect a domain that sends no email from being spoofed. Build the three-record hardening pack that makes a NON-SENDING domain unusable for spoofing: a Null MX, a hard-fail SPF record,…read-only
check_propagationUse this when the user asks whether a DNS change has propagated globally, or why a record shows in one place and not another. Check whether a DNS change has propagated GLOBALLY: six vantage points (five owner-run probes…read-only
lookup_registrationUse this when the user asks who owns a domain, when it expires, which registrar or nameservers it has, whether it is registered, or whether a transfer or delete lock is set — the WHOIS question. Read a domain's…read-only
get_alertsUse this when a signed-in operator asks what changed on a monitored domain, or what the monitoring has flagged. Read the monitoring alert log for the domains the caller's account monitors, newest first. Requires an API…read-only
get_readinessUse this when a signed-in operator asks whether a monitored domain is ready for the next DMARC step. Read the DMARC enforcement-readiness verdict for ONE domain the caller's account monitors, computed from its aggregate…read-only
check_lookalikesUse this when the user asks about lookalike, look-alike, typosquat or impersonation domains of their domain, or whether someone has registered a name close to theirs. DNS-only: checks the closest variants of the name…read-only
get_lookalikesUse this when a signed-in operator asks which lookalike domains of a monitored domain the watch has found, how risky they are, or for one's takedown evidence. Requires an API token with monitoring:read. Returns the…read-only
add_monitored_domainAdd a domain to the signed-in user's DNS Doctor monitoring and return the ownership-check TXT record they must publish, plus where their DNS is hosted, a provider-specific guide link and, when their provider supports…writes
check_domain_verificationCheck whether the ownership TXT record for a domain the user has added is visible yet, and mark it verified when it is. The result says WHICH outcome occurred and which nameservers were asked, so you can tell 'not…writes
get_domain_recordsRead the records a domain the user monitors still needs: the ownership check while it is unverified, and once verified the DMARC reporting record plus whether we have OBSERVED that record published. Read-only: it issues…read-only

What https://dnsdoctor.dev/mcp answered to tools/list, asked without credentials over MCP 2026-07-28. The token figure is the size of the list as sent, divided by four; a model sees about that much before it calls anything. Full definitions, input schemas included, are in the listing's JSON under mcpTools.

How its tools read to an agent 0 errors · 1 warning · 1 note

  • warnTC18start_monitoring_signupreadOnlyHint is true but the name says "start"
  • noteTC29serverabout 632 tokens (6% of the definitions) are titles that repeat property or function names

The checks from /check and anchor check, run each day on the list above: about 10,348 tokens of definitions. Not part of the score yet. Check your own server.

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.