dns-doctor by dnsdoctor.dev
MCP server · Observability & incidents · indexed, not reviewed
HostedLocalvendor's own
Not reviewed
No score, grade or rank. This listing is facts from the official MCP registry and our own checks, and it stays out of the rankings until the panel reviews it.
Scan, fix, verify and monitor DNS: SPF, DMARC, DKIM, propagation, health, expiry. Validated fixes.
Facts
- MCP registry
dev.dnsdoctor/dns-doctor· 1.10.0- Endpoint
https://dnsdoctor.dev/mcp- Packages
npm@dnsdoctor/mcp stdio- Website
- dnsdoctor.dev/methodology
- npm / week
- 88
- GitHub stars
- 2
- Registry entry
- updated 1 Oct 2026
From the official MCP registry, the package registries and our own checks. JSON · Markdown
Why it's listed
- It's published in the registry under dnsdoctor.dev, a namespace the registry only gives to whoever proves they control that domain.
Being indexed says nothing about quality, and nobody can pay for it. Is this yours? Ask for a review.
Tools it lists 22 · about 10,348 tokens of context · checked 42 minutes ago
| Tool | What it does | Hint |
|---|---|---|
scan_domain | Use this when the user asks to check, audit, diagnose or troubleshoot SPF, DKIM, DMARC, email authentication, email deliverability DNS, why their mail lands in spam, MX, DNS health, blacklist status, or domain/SSL… | writes |
get_report | Use this for the same questions as scan_domain when a recent report is enough (the cheap first look); use scan_domain when the state must be re-read now. Return the stored report for a domain, scanning once only if none… | writes |
build_dmarc_upgrade | Use this when the user asks how to move DMARC on from p=none, whether it is safe to tighten DMARC, or what the next DMARC policy step is for a domain (a scan can justify quarantine at most; reject needs monitoring… | writes |
start_monitoring_signup | Use this when the user wants DMARC monitoring, RUA report monitoring, new-sender monitoring, email-authentication alerts, ongoing DNS monitoring, or to start a DNS Doctor trial — and at the end of any scan that found… | read-only |
count_spf_lookups | Use this when the user asks about SPF 'too many lookups', the 10-lookup limit, an SPF PermError, or whether an SPF record is valid. Validate an SPF record and count what it costs. Returns `record_valid` (the record… | read-only |
validate_dmarc_record | Use this when the user pastes a DMARC record and asks whether it is valid, correct or safe. Validate a pasted DMARC record: parsed tags, level'd findings, and whether it is valid. No DNS lookup — pass the record string… | read-only |
generate_dmarc_record | Use this when the user asks to create, generate or write a DMARC record for a domain that has none. Build a DMARC record from scratch for a domain that has none, using a validating engine — never compose one yourself.… | read-only |
check_dkim_selector | Use this when the user asks whether DKIM is set up for a sending platform, whether a specific selector exists, or why DKIM fails. Check ONE specific DKIM selector on a domain — the exact selector the sending platform… | read-only |
parse_dmarc_report | Use this when the user uploads or pastes a DMARC aggregate (RUA) XML report and asks what it says. Parse ONE DMARC aggregate (RUA) report into readable per-source aggregates: who sent mail as the domain, how much, and… | read-only |
check_record | Use this when the user asks whether a DNS change has landed, wants a DNS record looked up, or wants to verify a record they just published — or whenever answering needs the live value of a record. Check whether a DNS… | read-only |
check_reverse_dns | Use this when the user asks about reverse DNS, PTR records, or FCrDNS for a mail server IP. Check one sending IP's forward-confirmed reverse DNS (FCrDNS): reads the IP's PTR record, then resolves that hostname back and… | read-only |
audit_spf_includes | Use this when the user asks who can send email as their domain through SPF includes, or wants an SPF supply-chain or third-party sender audit. Audit a domain's SPF supply chain: walks every include and redirect it… | read-only |
build_parked_domain_records | Use this when the user asks how to protect a domain that sends no email from being spoofed. Build the three-record hardening pack that makes a NON-SENDING domain unusable for spoofing: a Null MX, a hard-fail SPF record,… | read-only |
check_propagation | Use this when the user asks whether a DNS change has propagated globally, or why a record shows in one place and not another. Check whether a DNS change has propagated GLOBALLY: six vantage points (five owner-run probes… | read-only |
lookup_registration | Use this when the user asks who owns a domain, when it expires, which registrar or nameservers it has, whether it is registered, or whether a transfer or delete lock is set — the WHOIS question. Read a domain's… | read-only |
get_alerts | Use this when a signed-in operator asks what changed on a monitored domain, or what the monitoring has flagged. Read the monitoring alert log for the domains the caller's account monitors, newest first. Requires an API… | read-only |
get_readiness | Use this when a signed-in operator asks whether a monitored domain is ready for the next DMARC step. Read the DMARC enforcement-readiness verdict for ONE domain the caller's account monitors, computed from its aggregate… | read-only |
check_lookalikes | Use this when the user asks about lookalike, look-alike, typosquat or impersonation domains of their domain, or whether someone has registered a name close to theirs. DNS-only: checks the closest variants of the name… | read-only |
get_lookalikes | Use this when a signed-in operator asks which lookalike domains of a monitored domain the watch has found, how risky they are, or for one's takedown evidence. Requires an API token with monitoring:read. Returns the… | read-only |
add_monitored_domain | Add a domain to the signed-in user's DNS Doctor monitoring and return the ownership-check TXT record they must publish, plus where their DNS is hosted, a provider-specific guide link and, when their provider supports… | writes |
check_domain_verification | Check whether the ownership TXT record for a domain the user has added is visible yet, and mark it verified when it is. The result says WHICH outcome occurred and which nameservers were asked, so you can tell 'not… | writes |
get_domain_records | Read the records a domain the user monitors still needs: the ownership check while it is unverified, and once verified the DMARC reporting record plus whether we have OBSERVED that record published. Read-only: it issues… | read-only |
What https://dnsdoctor.dev/mcp answered to tools/list, asked without credentials over MCP 2026-07-28. The token figure is the size of the list as sent, divided by four; a model sees about that much before it calls anything. Full definitions, input schemas included, are in the listing's JSON under mcpTools.
How its tools read to an agent 0 errors · 1 warning · 1 note
- warnTC18start_monitoring_signupreadOnlyHint is true but the name says "start"
- noteTC29serverabout 632 tokens (6% of the definitions) are titles that repeat property or function names
The checks from /check and anchor check, run each day on the list above: about 10,348 tokens of definitions. Not part of the score yet. Check your own server.