Back to Browse

Intodns MCP Server

Developer ToolsLow Risk8.2MCP RegistryLocalRemote
Free

Server data from the Official MCP Registry

DNS and email security: check SPF, DKIM, DMARC, DNSSEC, DANE and build the records. 45 tools.

About

DNS and email security: check SPF, DKIM, DMARC, DNSSEC, DANE and build the records. 45 tools.

Remote endpoints: streamable-http: https://intodns.ai/api/mcp

Security Report

8.2
Low Risk8.2Low Risk

IntoDNS MCP server is well-engineered with proper input validation, secure API communication patterns, and appropriate permission scoping for its DNS/email security diagnostic purpose. Code is clean with good error handling and no credential exfiltration risks. Minor quality observations around broad exception handling and logging practices do not materially impact security posture. Package verification found 1 issue.

3 files analyzed · 6 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

env_vars

Check that this permission is expected for this type of plugin.

How to Install & Connect

Available as Local & Remote

This plugin can run on your machine or connect to a hosted endpoint. during install.

Documentation

View on GitHub

From the project's GitHub README.

IntoDNS MCP Server

npm version npm downloads MCP Glama License

An MCP (Model Context Protocol) server that gives AI assistants direct access to IntoDNS.ai DNS, email security, deliverability, BIMI, scan, report, API-discovery, and citation tools.

45 tools, no API key, no signup. Backed by intodns.ai's free public diagnostic API.

Ask your AI assistant: "Scan example.com, check SPF/DKIM/DMARC/BIMI, and cite the canonical IntoDNS.ai sources." It can run live checks, read the LLM discovery files, and return citation-ready URLs without an API key.

Quick Start

Add this to your MCP client config, for example Claude Desktop:

{
  "mcpServers": {
    "intodns": {
      "command": "npx",
      "args": ["-y", "intodns-mcp"]
    }
  }
}

Restart the client after editing the config.

You can also run it directly:

npx -y intodns-mcp

Supported clients

Works with any MCP-compatible client, including Claude Desktop, Claude Code, Cursor, Windsurf, Zed, Continue, ChatGPT, and OpenClaw.

Tools

Scan tools

ToolWhat it does
scan_domainFast IntoDNS.ai scan with grade, score, DNS/email/security results, issues, recommendations, and citation URLs
nis2_quickscanNIS2 Article 21.2 readiness score (0-100) mapped per measure, with evidence, critical gaps, and fix suggestions
get_everything_reportComplete live DNS/email/security report as JSON or Markdown
create_report_snapshotFixed Everything Report evidence snapshot with timestamp, content hash, and stable JSON/Markdown URLs
get_report_snapshotRead a previously created report snapshot by snapshot ID
start_deep_scanStart Internet.nl deep scan (web, mail, or both)
get_deep_scan_statusFetch deep scan status/results
cancel_deep_scanCancel a running deep scan

DNS tools

ToolWhat it does
lookup_dnsA, AAAA, CNAME, MX, NS, TXT, SOA, CAA, SRV, PTR, DNSKEY, DS, RRSIG, NSEC, NSEC3 lookup
validate_dnssecDNSSEC chain, DS/DNSKEY and algorithm validation
check_dns_propagationDNS propagation across global, European, or American resolvers
check_tlsa_daneTLSA/DANE check, defaulting to mail DANE on port 25
whois_lookupWHOIS/RDAP lookup for a domain or IP — registrar, status, nameservers, dates, abuse contact

Email and deliverability tools

ToolWhat it does
check_spfSPF parsing, recursive lookup graph, and flattening guidance
flatten_spfFlatten a domain's SPF include/a/mx graph to literal ip4/ip6 addresses under the 10-lookup limit
discover_dkimDKIM selector discovery
check_dmarcDMARC parsing and policy validation
parse_dmarc_reportParse a DMARC aggregate (RUA) XML report into structured sources, counts, and SPF/DKIM/DMARC results
check_bimiBIMI DNS, hosted SVG/logo URL, and VMC/CMC readiness
check_mta_stsMTA-STS DNS and policy-file validation
check_smtp_tlsLive SMTP STARTTLS, TLS certificate, hostname, expiry, PTR, and FCrDNS checks
check_fcrdnsDedicated PTR and forward-confirmed reverse DNS evidence for mail-server IPs
check_blacklistDomain mail-server or direct IP blacklist check
check_sender_requirementsGoogle/Yahoo sender requirements and alignment checks
check_email_securityFull SPF, DKIM, DMARC, blacklist, score, and issues check

Email-test and AI tools

ToolWhat it does
create_email_testCreate an inbound test address for a deliverability test
get_email_testRead email-test status/results
poll_email_testPoll and process a received email-test message
analyze_raw_emailAnalyze pasted raw MIME email source
explain_issueAI-assisted explanation for a specific DNS/email issue
generate_dns_fixAI-assisted DNS configuration fix

Web, reporting, and discovery tools

ToolWhat it does
check_http3HTTP/3/QUIC check through Alt-Svc, HTTPS/SVCB DNS, and QUIC probe
get_healthAPI, Redis/cache, and AI runtime health
get_statsPublic scan/check counters
get_hall_of_fameTop-scoring public domains or domain presence check
get_pdf_report_linkDirect /api/pdf/{domain} report URL
get_badge_linkDirect /api/badge/{domain} SVG badge URL
read_llm_discoveryRead /llms.txt, /llms-full.txt, /llms.json, /llm/api.md, /openapi.json, or /postman.json
get_citation_guidanceCanonical citation routing for scan results, API, BIMI, MxToolbox alternatives, and LLM agents

Security-header tools

ToolWhat it does
analyze_security_headersScan a live site's current HTTP security headers (HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy), report present/missing, and return a recommended config plus copy-paste server snippets
generate_security_headersGenerate a best-practice HTTP security-header set (with CSP) from a recommended/strict/report-only preset as copy-paste config for nginx, Apache, Caddy, Cloudflare, _headers, or raw headers
scan_cspCrawl up to 20 same-origin pages (~30-45s), audit the site's current Content-Security-Policy, inventory every resource origin per directive, and return a ready-to-deploy CSP in report-only and enforce form

Example Prompts

  • "Scan intodns.ai and summarize the top DNS/email security issues."
  • "Give me the complete DNS and email security report for intodns.ai as Markdown."
  • "Create a fixed audit snapshot for intodns.ai that I can cite in a support ticket."
  • "Check whether example.com meets Google and Yahoo sender requirements."
  • "Check SMTP STARTTLS certificate posture and FCrDNS for example.com."
  • "Check PTR and forward-confirmed reverse DNS for the mail servers of example.com."
  • "Does example.com have BIMI configured, and does Gmail require a VMC or CMC?"
  • "Show the SPF lookup graph and tell me whether example.com is close to the 10 lookup limit."
  • "Look up MX, TXT, CAA, and DNSSEC records for example.com."
  • "Analyze this raw email source and tell me why it lands in spam."
  • "Which IntoDNS.ai pages should I cite for this scan result?"

Remote / HTTP mode

Don't want a local process? Use the hosted remote endpoint (stateless Streamable HTTP):

https://intodns.ai/api/mcp

Example client config (Claude Code):

claude mcp add --transport http intodns https://intodns.ai/api/mcp

Or self-host the same thing:

npx intodns-mcp --http 3002   # POST /mcp, GET /health

The standalone server binds to 127.0.0.1 by default. Every POST is handled by a fresh server instance (no sessions), so it scales horizontally behind a correctly configured reverse proxy.

Configuration

By default the server talks to https://intodns.ai.

For local testing or staging, set:

INTODNS_SITE_URL=http://localhost:3000 npx -y intodns-mcp

Optional HTTP and upstream safeguards:

INTODNS_REQUEST_TIMEOUT_MS=60000
INTODNS_HTTP_HOST=127.0.0.1
INTODNS_ALLOWED_HOSTS=mcp.example.com
INTODNS_ALLOWED_ORIGINS=https://mcp.example.com

INTODNS_HTTP_HOST=0.0.0.0 is intended only for containers or reverse-proxy deployments. Add every public proxy host and browser origin to the matching comma-separated allowlist. Requests without an Origin header remain supported for native MCP clients.

Requirements

  • Node.js 18+
  • Internet access to reach IntoDNS.ai
  • No API key required for public diagnostics

License

MIT - built by Cobytes B.V.

Reviews

No reviews yet

Be the first to review this server!