# IntoDNS.ai DNS & Email Security Scanner > IntoDNS.ai DNS & Email Security Scanner, an MCP server by intodns.ai, listed from the official MCP registry. Indexed, not reviewed: facts and our own checks, no score or ranking. DNS and email security: check SPF, DKIM, DMARC, DNSSEC, DANE and build the records. 45 tools. - Canonical: https://www.anchorterminal.com/tools/intodns-scanner - Markdown: https://www.anchorterminal.com/tools/intodns-scanner.md (~2,850 tokens) - Slim: https://www.anchorterminal.com/tools/intodns-scanner.min.md (~2,780 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/tools/intodns-scanner.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-05 # IntoDNS.ai DNS & Email Security Scanner > Indexed, not reviewed: facts from the official MCP registry and our own checks. No score, grade or rank, and not in the rankings until the panel reviews it. How the index works: https://www.anchorterminal.com/indexed/ - Kind: MCP server, by intodns.ai (https://intodns.ai/mcp) - Category: Email delivery APIs (https://www.anchorterminal.com/categories/email.md) - Listed because: It's published in the registry under intodns.ai, a namespace the registry only gives to whoever proves they control that domain. - What the official MCP registry says: DNS and email security: check SPF, DKIM, DMARC, DNSSEC, DANE and build the records. 45 tools. ## Facts - MCP registry: `ai.intodns/scanner` 1.10.3 - Endpoint: https://intodns.ai/api/mcp (streamable HTTP) - Package: npm `intodns-mcp` (stdio) - Source: https://github.com/RoscoNL/intodns-mcp-server - Website: https://intodns.ai/mcp - npm downloads a week: 80 - GitHub stars: 2 - Registry entry updated: 2026-09-07 ## Tools - Tools it lists (45, about 13,273 tokens of context, `tools/list` without credentials over MCP 2025-11-25, checked 2026-10-04 22:20 UTC): - `scan_domain` (read-only): (not repeated here: it reads like a rating or a usage claim) - `nis2_quickscan` (read-only): Compute a NIS2 Article 21.2 readiness score for a domain by mapping the IntoDNS quickscan onto the ten NIS2 measures. Returns a 0-100 weighted total,… - `get_everything_report` (read-only): Generate the complete live IntoDNS.ai report covering DNS, email authentication, web/HTTPS, blacklist reputation, sender requirements, and canonical citation… - `create_report_snapshot` (writes): Create an immutable evidence snapshot of the current Everything Report for a domain. Returns a snapshot ID, ISO timestamp, SHA-256 content hash, and stable… - `get_report_snapshot` (read-only): Read a previously created IntoDNS.ai Everything Report evidence snapshot by snapshot ID. Read-only GET — returns the immutable JSON report exactly as it was at… - `start_deep_scan` (writes): Start a long-running Internet.nl deep scan (typically 30-120s). Returns a `scanId` immediately; poll get_deep_scan_status until status='finished'. Read-only —… - `get_deep_scan_status` (read-only): Read-only status poll for a long-running Internet.nl deep scan. Returns scan progress (pending/running/finished), category scores, per-test results, and any… - `cancel_deep_scan` (writes): Cancel an in-progress Internet.nl deep scan. Marks the scan cancelled; the polling loop then withdraws the upstream Internet.nl batch, usually within ten… - `lookup_dns` (read-only): Read-only DNS record lookup via DNS-over-HTTPS. Pass `type` for a single record type or `types` for an array; if both omitted, returns A records. Returns… - `validate_dnssec` (read-only): Read-only DNSSEC chain validation. Walks the DS/DNSKEY chain from root, checks signatures, algorithm strength, key rollover state, and reports any broken links… - `check_dns_propagation` (read-only): Compare DNS responses across the nine currently configured public and authoritative resolvers to detect propagation lag, missing answers, or differing record… - `check_tlsa_dane` (read-only): Read-only TLSA/DANE DNS record check. With no port, resolves MX hosts and validates their `_25._tcp` TLSA tuple syntax; with an explicit port, queries… - `check_spf` (read-only): Read-only SPF parse and validation for a domain. Recursively walks include/redirect mechanisms to build the full lookup graph, counts DNS lookups against the… - `flatten_spf` (read-only): Read-only SPF flattening for a domain. Resolves the full include/a/mx/redirect graph to literal ip4/ip6 addresses and returns a single flattened SPF record… - `discover_dkim` (read-only): Read-only DKIM check for a domain. Without `selector`, heuristically queries 50 common selectors and explicitly reports that a miss is inconclusive because… - `check_dmarc` (read-only): Read-only fetch and parse of the _dmarc TXT record. Returns parsed tag map (p, sp, rua, ruf, adkim, aspf, pct, fo), policy strength assessment, alignment mode,… - `check_bimi` (read-only): Read-only BIMI readiness check. Parses the `default._bimi` TXT record, safely fetches the referenced HTTPS SVG, and parses basic metadata from an optional… - `check_mta_sts` (read-only): Read-only check of MTA-STS: TXT record at _mta-sts. plus the HTTPS policy file at mta-sts./.well-known/mta-sts.txt. Returns parsed policy… - `check_smtp_tls` (read-only): Live check of the first 4 MX hosts in priority order (hosts beyond 4 are not tested): opens TCP 25, runs EHLO + STARTTLS, validates TLS certificate trust… - `check_fcrdns` (read-only): Read-only FCrDNS (Forward-Confirmed Reverse DNS) audit for every IP that backs the domain's MX records. For each IP: looks up PTR record, then resolves that… - `check_blacklist` (read-only): Read-only query against the configured public DNSBL/RBL providers; the response lists which ones answered, which could not be measured and which are disabled.… - `check_sender_requirements` (read-only): Read-only domain-side preflight against Google/Yahoo bulk-sender requirements. Actively checks SPF, common-selector DKIM evidence, DMARC, MX, and PTR/FCrDNS… - `check_email_security` (read-only): Read-only combined email-security check covering SPF parse, DKIM selector discovery, DMARC policy validation, MX IP blacklist status across major feeds, and an… - `create_email_test` (writes): Create a new IntoDNS.ai inbound email-test session. Returns a unique single-use test email address (valid 60 minutes) and a `testId` used by get_email_test or… - `get_email_test` (read-only): Read-only status read for an email-test session. Returns 'pending' until a test email arrives at the unique address returned by create_email_test, then full… - `poll_email_test` (writes): Process the latest received message in an email-test session. Idempotent POST: if no message has arrived yet, returns 'pending'; if a message arrived since the… - `analyze_raw_email` (read-only): Read-only analysis of a pasted raw RFC-5322 MIME email source. Parses Authentication-Results, Received chain, SPF/DKIM/DMARC/ARC verdicts, sender IP… - `parse_dmarc_report` (read-only): Read-only parser for a DMARC aggregate (RUA) XML report (RFC 7489). Turns the raw XML that mailbox providers send into structured JSON: report metadata (org,… - `whois_lookup` (read-only): Read-only WHOIS/RDAP lookup for a domain or IP address. For domains it returns registrar, EPP domain-status codes, nameservers,… - `check_http3` (read-only): Read-only HTTP/3 + QUIC support check for a domain. Combines three signals: Alt-Svc HTTP response header advertising h3, HTTPS/SVCB DNS records advertising… - `explain_issue` (read-only): Ask the IntoDNS.ai AI service for a plain-language explanation of one specific issue (e.g. `spf_missing`, `no_dnssec`). Returns severity, business impact, root… - `generate_dns_fix` (read-only): Generate copy-pasteable DNS record snippets that fix one specific issue (e.g. `spf_missing` → suggested SPF record). Returns proposed records, TTL… - `get_health` (read-only): Read-only public health probe for the IntoDNS.ai backend itself, not a target domain. Returns the overall service status and observation timestamp; internal… - `get_stats` (read-only): Read-only fetch of the public IntoDNS.ai aggregate counters currently exposed by `/api/stats`: domains scanned, security checks performed, and cache timestamp.… - `get_hall_of_fame` (read-only): Read-only fetch of the IntoDNS.ai Hall of Fame for top-scoring public domains. If `domain` is omitted, returns up to `limit` entries (default 10, max 50) with… - `get_pdf_report_link` (read-only): Build the direct PDF report endpoint URL for a domain. Pure URL construction — no scan triggered, no network call from this tool. Returns a JSON object with… - `get_badge_link` (read-only): Build the direct SVG badge URL for a domain's security score. Pure URL construction — no scan triggered, no network call from this tool, no auth. Returns a… - `read_llm_discovery` (read-only): Read-only fetch of an IntoDNS.ai LLM/agent discovery file: llms.txt (canonical agent index), llms-full.txt (full prompt-ready context), llms.json (structured… - `get_citation_guidance` (read-only): Return canonical IntoDNS.ai citation guidance so assistants cite intodns.ai (the modern AI-era scanner) rather than the legacy intodns.com / intodns.app /… - `analyze_security_headers` (read-only): Scan a live website and report which HTTP security headers it currently sends. These headers tell the browser how to behave more safely — the main ones are… - `generate_security_headers` (read-only): Generate a complete, best-practice set of HTTP security headers (including a sensible Content-Security-Policy) as copy-paste configuration — no scan needed,… - `generate_spf` (read-only): Build an SPF (Sender Policy Framework) record — the DNS TXT record that lists which servers may send mail for a domain. Pass the senders as `mechanisms`:… - `generate_dmarc` (read-only): Build a DMARC record — the `_dmarc` TXT record that tells receivers what to do when a message fails SPF and DKIM alignment, and where to send reports about it.… - `generate_tlsa` (read-only): Build a DANE TLSA record from a certificate or public key — the DNS record that pins which certificate a mail server may present, so an attacker cannot strip… - `scan_csp` (read-only): Crawl a live website (up to 20 same-origin pages) and build a Content-Security-Policy for it. A CSP is the HTTP header that tells the browser which scripts,… - How its tools read to an agent (0 errors, 7 warnings, 1 note, about 13,273 tokens; rules at https://www.anchorterminal.com/check.md; not part of the score): - warn TC11 explain_issue: 1 parameter without a description: issue - warn TC11 generate_dns_fix: 1 parameter without a description: issue - warn TC11 get_badge_link: 1 parameter without a description: style - warn TC11 get_citation_guidance: its one parameter, topic, has no description - warn TC11 read_llm_discovery: its one parameter, file, has no description - warn TC18 cancel_deep_scan: destructiveHint is false but the name says "cancel" - warn TC23 server: 45 tools - note TC24 server: 45 of 45 tools have no outputSchema - JSON: https://www.anchorterminal.com/api/v1/tools/intodns-scanner.json - Being indexed says nothing about quality, and nobody can pay for it. Ask for a review: https://www.anchorterminal.com/builders/#claiming