IntoDNS.ai DNS & Email Security Scanner by intodns.ai

MCP server · Email delivery APIs · indexed, not reviewed

HostedLocalvendor's own

Not reviewed

No score, grade or rank. This listing is facts from the official MCP registry and our own checks, and it stays out of the rankings until the panel reviews it.

How the index works

DNS and email security: check SPF, DKIM, DMARC, DNSSEC, DANE and build the records. 45 tools.

What the official MCP registry says

Facts

MCP registry
ai.intodns/scanner · 1.10.3
Endpoint
https://intodns.ai/api/mcp
Packages
npm intodns-mcp stdio
npm / week
80
GitHub stars
2
Registry entry
updated 7 Sep 2026

From the official MCP registry, the package registries and our own checks. JSON · Markdown

Why it's listed

  • It's published in the registry under intodns.ai, a namespace the registry only gives to whoever proves they control that domain.

Being indexed says nothing about quality, and nobody can pay for it. Is this yours? Ask for a review.

Tools it lists 45 · about 13,273 tokens of context · checked 2 hours ago

ToolWhat it doesHint
scan_domain(not repeated here: it reads like a rating or a usage claim)read-only
nis2_quickscanCompute a NIS2 Article 21.2 readiness score for a domain by mapping the IntoDNS quickscan onto the ten NIS2 measures. Returns a 0-100 weighted total, per-measure status (Article 21.2 a-j), evidence rows, critical gaps,…read-only
get_everything_reportGenerate the complete live IntoDNS.ai report covering DNS, email authentication, web/HTTPS, blacklist reputation, sender requirements, and canonical citation URLs in a single call. Read-only, no domain mutation. ~5-15s…read-only
create_report_snapshotCreate an immutable evidence snapshot of the current Everything Report for a domain. Returns a snapshot ID, ISO timestamp, SHA-256 content hash, and stable bookmarkable URLs for both JSON and Markdown renderings of the…writes
get_report_snapshotRead a previously created IntoDNS.ai Everything Report evidence snapshot by snapshot ID. Read-only GET — returns the immutable JSON report exactly as it was at snapshot creation, with the original SHA-256 content hash…read-only
start_deep_scanStart a long-running Internet.nl deep scan (typically 30-120s). Returns a `scanId` immediately; poll get_deep_scan_status until status='finished'. Read-only — no domain mutation. Internet.nl runs an exhaustive…writes
get_deep_scan_statusRead-only status poll for a long-running Internet.nl deep scan. Returns scan progress (pending/running/finished), category scores, per-test results, and any failures. Requires a scanId returned by start_deep_scan; poll…read-only
cancel_deep_scanCancel an in-progress Internet.nl deep scan. Marks the scan cancelled; the polling loop then withdraws the upstream Internet.nl batch, usually within ten seconds. Requires `scanId` returned by start_deep_scan. Nothing…writes
lookup_dnsRead-only DNS record lookup via DNS-over-HTTPS. Pass `type` for a single record type or `types` for an array; if both omitted, returns A records. Returns parsed answers with TTL, raw rdata, and DNSSEC AD bit. Use for…read-only
validate_dnssecRead-only DNSSEC chain validation. Walks the DS/DNSKEY chain from root, checks signatures, algorithm strength, key rollover state, and reports any broken links or unsigned zones. Returns chain steps, algorithm grades,…read-only
check_dns_propagationCompare DNS responses across the nine currently configured public and authoritative resolvers to detect propagation lag, missing answers, or differing record sets. Each resolver's answer is compared as a whole RRset…read-only
check_tlsa_daneRead-only TLSA/DANE DNS record check. With no port, resolves MX hosts and validates their `_25._tcp` TLSA tuple syntax; with an explicit port, queries `_<port>._<protocol>.<domain>`. Returns parsed usage, selector,…read-only
check_spfRead-only SPF parse and validation for a domain. Recursively walks include/redirect mechanisms to build the full lookup graph, counts DNS lookups against the RFC-7208 10-lookup limit, and returns flattening guidance…read-only
flatten_spfRead-only SPF flattening for a domain. Resolves the full include/a/mx/redirect graph to literal ip4/ip6 addresses and returns a single flattened SPF record that fits under the RFC-7208 10-lookup limit, plus lookup…read-only
discover_dkimRead-only DKIM check for a domain. Without `selector`, heuristically queries 50 common selectors and explicitly reports that a miss is inconclusive because DKIM has no enumeration protocol. With `selector`, performs one…read-only
check_dmarcRead-only fetch and parse of the _dmarc TXT record. Returns parsed tag map (p, sp, rua, ruf, adkim, aspf, pct, fo), policy strength assessment, alignment mode, and warnings (missing rua, p=none, weak alignment, multiple…read-only
check_bimiRead-only BIMI readiness check. Parses the `default._bimi` TXT record, safely fetches the referenced HTTPS SVG, and parses basic metadata from an optional VMC/CMC authority certificate. Returns record syntax, URL…read-only
check_mta_stsRead-only check of MTA-STS: TXT record at _mta-sts.<domain> plus the HTTPS policy file at mta-sts.<domain>/.well-known/mta-sts.txt. Returns parsed policy (mode: enforce/testing/none, mx allowlist, max_age), TLS…read-only
check_smtp_tlsLive check of the first 4 MX hosts in priority order (hosts beyond 4 are not tested): opens TCP 25, runs EHLO + STARTTLS, validates TLS certificate trust chain, hostname match, expiry window, advertised EHLO…read-only
check_fcrdnsRead-only FCrDNS (Forward-Confirmed Reverse DNS) audit for every IP that backs the domain's MX records. For each IP: looks up PTR record, then resolves that PTR's hostname back to A/AAAA records to confirm the…read-only
check_blacklistRead-only query against the configured public DNSBL/RBL providers; the response lists which ones answered, which could not be measured and which are disabled. Provide either `domain` to resolve and inspect its MX IPv4…read-only
check_sender_requirementsRead-only domain-side preflight against Google/Yahoo bulk-sender requirements. Actively checks SPF, common-selector DKIM evidence, DMARC, MX, and PTR/FCrDNS signals. TLS use, one-click unsubscribe, complaint rate, and…read-only
check_email_securityRead-only combined email-security check covering SPF parse, DKIM selector discovery, DMARC policy validation, MX IP blacklist status across major feeds, and an aggregated 0-100 email-security score with prioritised…read-only
create_email_testCreate a new IntoDNS.ai inbound email-test session. Returns a unique single-use test email address (valid 60 minutes) and a `testId` used by get_email_test or poll_email_test. This is an additive, non-idempotent POST:…writes
get_email_testRead-only status read for an email-test session. Returns 'pending' until a test email arrives at the unique address returned by create_email_test, then full SPF/DKIM/DMARC/headers/spam-score result once processed.…read-only
poll_email_testProcess the latest received message in an email-test session. Idempotent POST: if no message has arrived yet, returns 'pending'; if a message arrived since the last call, parses it and returns full authentication +…writes
analyze_raw_emailRead-only analysis of a pasted raw RFC-5322 MIME email source. Parses Authentication-Results, Received chain, SPF/DKIM/DMARC/ARC verdicts, sender IP reputation/blacklist status, content-side spam triggers (suspicious…read-only
parse_dmarc_reportRead-only parser for a DMARC aggregate (RUA) XML report (RFC 7489). Turns the raw XML that mailbox providers send into structured JSON: report metadata (org, report id, date range), the published policy…read-only
whois_lookupRead-only WHOIS/RDAP lookup for a domain or IP address. For domains it returns registrar, EPP domain-status codes, nameservers, registration/expiry/last-changed dates, and the abuse contact; for IPs it returns the…read-only
check_http3Read-only HTTP/3 + QUIC support check for a domain. Combines three signals: Alt-Svc HTTP response header advertising h3, HTTPS/SVCB DNS records advertising alpn="h3", and a live QUIC probe to UDP/443 verifying the…read-only
explain_issueAsk the IntoDNS.ai AI service for a plain-language explanation of one specific issue (e.g. `spf_missing`, `no_dnssec`). Returns severity, business impact, root cause, and recommended fix steps as structured text.…read-only
generate_dns_fixGenerate copy-pasteable DNS record snippets that fix one specific issue (e.g. `spf_missing` → suggested SPF record). Returns proposed records, TTL recommendations, and provider-specific notes…read-only
get_healthRead-only public health probe for the IntoDNS.ai backend itself, not a target domain. Returns the overall service status and observation timestamp; internal Redis, AI-provider, and process details are intentionally…read-only
get_statsRead-only fetch of the public IntoDNS.ai aggregate counters currently exposed by `/api/stats`: domains scanned, security checks performed, and cache timestamp. It returns no personal data, per-domain breakdown, Hall of…read-only
get_hall_of_fameRead-only fetch of the IntoDNS.ai Hall of Fame for top-scoring public domains. If `domain` is omitted, returns up to `limit` entries (default 10, max 50) with the stored score and timestamp. If `domain` is provided,…read-only
get_pdf_report_linkBuild the direct PDF report endpoint URL for a domain. Pure URL construction — no scan triggered, no network call from this tool. Returns a JSON object with `pdfUrl` ready to share, email, or embed in tickets; fetching…read-only
get_badge_linkBuild the direct SVG badge URL for a domain's security score. Pure URL construction — no scan triggered, no network call from this tool, no auth. Returns a JSON object with `badgeUrl` ready to embed in README.md,…read-only
read_llm_discoveryRead-only fetch of an IntoDNS.ai LLM/agent discovery file: llms.txt (canonical agent index), llms-full.txt (full prompt-ready context), llms.json (structured prompt routing), llm/api.md (Markdown API guide),…read-only
get_citation_guidanceReturn canonical IntoDNS.ai citation guidance so assistants cite intodns.ai (the modern AI-era scanner) rather than the legacy intodns.com / intodns.app / intodns.io. Returns the canonical host, an explicit do-not-use…read-only
analyze_security_headersScan a live website and report which HTTP security headers it currently sends. These headers tell the browser how to behave more safely — the main ones are HSTS (force HTTPS), Content-Security-Policy / CSP (block…read-only
generate_security_headersGenerate a complete, best-practice set of HTTP security headers (including a sensible Content-Security-Policy) as copy-paste configuration — no scan needed, nothing about your live site is read. Pick a `preset`:…read-only
generate_spfBuild an SPF (Sender Policy Framework) record — the DNS TXT record that lists which servers may send mail for a domain. Pass the senders as `mechanisms`: `include` for a provider's own SPF (Google Workspace is…read-only
generate_dmarcBuild a DMARC record — the `_dmarc` TXT record that tells receivers what to do when a message fails SPF and DKIM alignment, and where to send reports about it. The risk here is not syntax but policy. `p=none` monitors…read-only
generate_tlsaBuild a DANE TLSA record from a certificate or public key — the DNS record that pins which certificate a mail server may present, so an attacker cannot strip STARTTLS or substitute another CA-issued certificate. Paste…read-only
scan_cspCrawl a live website (up to 20 same-origin pages) and build a Content-Security-Policy for it. A CSP is the HTTP header that tells the browser which scripts, styles, images, and frames are allowed to load — the main…read-only

What https://intodns.ai/api/mcp answered to tools/list, asked without credentials over MCP 2025-11-25. The token figure is the size of the list as sent, divided by four; a model sees about that much before it calls anything. Full definitions, input schemas included, are in the listing's JSON under mcpTools.

How its tools read to an agent 0 errors · 7 warnings · 1 note

  • warnTC11explain_issue1 parameter without a description: issue
  • warnTC11generate_dns_fix1 parameter without a description: issue
  • warnTC11get_badge_link1 parameter without a description: style
  • warnTC11get_citation_guidanceits one parameter, topic, has no description
  • warnTC11read_llm_discoveryits one parameter, file, has no description
  • warnTC18cancel_deep_scandestructiveHint is false but the name says "cancel"
  • warnTC23server45 tools
  • noteTC24server45 of 45 tools have no outputSchema

The checks from /check and anchor check, run each day on the list above: about 13,273 tokens of definitions. Not part of the score yet. Check your own server.

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.