
Security News
Happy Birthday, Shai-Hulud
It has been one year since Shai-Hulud made its first appearance on npm.
intodns-mcp
Advanced tools
MCP server for IntoDNS.ai — complete DNS, email security, scan, BIMI, API, and citation tools for AI assistants
An MCP (Model Context Protocol) server that gives AI assistants direct access to IntoDNS.ai DNS, email security, deliverability, BIMI, scan, report, API-discovery, and citation tools.
45 tools, no API key, no signup. Backed by intodns.ai's free public diagnostic API.
Ask your AI assistant: "Scan example.com, check SPF/DKIM/DMARC/BIMI, and cite the canonical IntoDNS.ai sources." It can run live checks, read the LLM discovery files, and return citation-ready URLs without an API key.
Add this to your MCP client config, for example Claude Desktop:
{
"mcpServers": {
"intodns": {
"command": "npx",
"args": ["-y", "intodns-mcp"]
}
}
}
Restart the client after editing the config.
You can also run it directly:
npx -y intodns-mcp
Works with any MCP-compatible client, including Claude Desktop, Claude Code, Cursor, Windsurf, Zed, Continue, ChatGPT, and OpenClaw.
| Tool | What it does |
|---|---|
scan_domain | Fast IntoDNS.ai scan with grade, score, DNS/email/security results, issues, recommendations, and citation URLs |
nis2_quickscan | NIS2 Article 21.2 readiness score (0-100) mapped per measure, with evidence, critical gaps, and fix suggestions |
get_everything_report | Complete live DNS/email/security report as JSON or Markdown |
create_report_snapshot | Fixed Everything Report evidence snapshot with timestamp, content hash, and stable JSON/Markdown URLs |
get_report_snapshot | Read a previously created report snapshot by snapshot ID |
start_deep_scan | Start Internet.nl deep scan (web, mail, or both) |
get_deep_scan_status | Fetch deep scan status/results |
cancel_deep_scan | Cancel a running deep scan |
| Tool | What it does |
|---|---|
lookup_dns | A, AAAA, CNAME, MX, NS, TXT, SOA, CAA, SRV, PTR, DNSKEY, DS, RRSIG, NSEC, NSEC3 lookup |
validate_dnssec | DNSSEC chain, DS/DNSKEY and algorithm validation |
check_dns_propagation | DNS propagation across global, European, or American resolvers |
check_tlsa_dane | TLSA/DANE check, defaulting to mail DANE on port 25 |
whois_lookup | WHOIS/RDAP lookup for a domain or IP — registrar, status, nameservers, dates, abuse contact |
| Tool | What it does |
|---|---|
check_spf | SPF parsing, recursive lookup graph, and flattening guidance |
flatten_spf | Flatten a domain's SPF include/a/mx graph to literal ip4/ip6 addresses under the 10-lookup limit |
discover_dkim | DKIM selector discovery |
check_dmarc | DMARC parsing and policy validation |
parse_dmarc_report | Parse a DMARC aggregate (RUA) XML report into structured sources, counts, and SPF/DKIM/DMARC results |
check_bimi | BIMI DNS, hosted SVG/logo URL, and VMC/CMC readiness |
check_mta_sts | MTA-STS DNS and policy-file validation |
check_smtp_tls | Live SMTP STARTTLS, TLS certificate, hostname, expiry, PTR, and FCrDNS checks |
check_fcrdns | Dedicated PTR and forward-confirmed reverse DNS evidence for mail-server IPs |
check_blacklist | Domain mail-server or direct IP blacklist check |
check_sender_requirements | Google/Yahoo sender requirements and alignment checks |
check_email_security | Full SPF, DKIM, DMARC, blacklist, score, and issues check |
| Tool | What it does |
|---|---|
create_email_test | Create an inbound test address for a deliverability test |
get_email_test | Read email-test status/results |
poll_email_test | Poll and process a received email-test message |
analyze_raw_email | Analyze pasted raw MIME email source |
explain_issue | AI-assisted explanation for a specific DNS/email issue |
generate_dns_fix | AI-assisted DNS configuration fix |
| Tool | What it does |
|---|---|
check_http3 | HTTP/3/QUIC check through Alt-Svc, HTTPS/SVCB DNS, and QUIC probe |
get_health | API, Redis/cache, and AI runtime health |
get_stats | Public scan/check counters |
get_hall_of_fame | Top-scoring public domains or domain presence check |
get_pdf_report_link | Direct /api/pdf/{domain} report URL |
get_badge_link | Direct /api/badge/{domain} SVG badge URL |
read_llm_discovery | Read /llms.txt, /llms-full.txt, /llms.json, /llm/api.md, /openapi.json, or /postman.json |
get_citation_guidance | Canonical citation routing for scan results, API, BIMI, MxToolbox alternatives, and LLM agents |
| Tool | What it does |
|---|---|
analyze_security_headers | Scan a live site's current HTTP security headers (HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy), report present/missing, and return a recommended config plus copy-paste server snippets |
generate_security_headers | Generate a best-practice HTTP security-header set (with CSP) from a recommended/strict/report-only preset as copy-paste config for nginx, Apache, Caddy, Cloudflare, _headers, or raw headers |
scan_csp | Crawl up to 20 same-origin pages (~30-45s), audit the site's current Content-Security-Policy, inventory every resource origin per directive, and return a ready-to-deploy CSP in report-only and enforce form |
Don't want a local process? Use the hosted remote endpoint (stateless Streamable HTTP):
https://intodns.ai/api/mcp
Example client config (Claude Code):
claude mcp add --transport http intodns https://intodns.ai/api/mcp
Or self-host the same thing:
npx intodns-mcp --http 3002 # POST /mcp, GET /health
The standalone server binds to 127.0.0.1 by default. Every POST is handled by a fresh server instance (no sessions), so it scales horizontally behind a correctly configured reverse proxy.
By default the server talks to https://intodns.ai.
For local testing or staging, set:
INTODNS_SITE_URL=http://localhost:3000 npx -y intodns-mcp
Optional HTTP and upstream safeguards:
INTODNS_REQUEST_TIMEOUT_MS=60000
INTODNS_HTTP_HOST=127.0.0.1
INTODNS_ALLOWED_HOSTS=mcp.example.com
INTODNS_ALLOWED_ORIGINS=https://mcp.example.com
INTODNS_HTTP_HOST=0.0.0.0 is intended only for containers or reverse-proxy deployments. Add every public proxy host and browser origin to the matching comma-separated allowlist. Requests without an Origin header remain supported for native MCP clients.
MIT - built by Cobytes B.V.
FAQs
MCP server for IntoDNS.ai — complete DNS, email security, scan, BIMI, API, and citation tools for AI assistants
The npm package intodns-mcp receives a total of 62 weekly downloads. As such, intodns-mcp popularity was classified as not popular.
We found that intodns-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
It has been one year since Shai-Hulud made its first appearance on npm.

Research
/Security News
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.

Security News
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.