idig-dns
Professional DNS diagnostics: 14 tools for DNS, DNSSEC, email security, SSL, and propagation.
Should I use this
Quality & Safety
Findings (3)
- LOWin mx_check
- LOWin ttl_check
- LOWin http_check
Based on automated analysis of tool definitions and protocol compliance.
Context Cost
This is the approximate number of tokens consumed each time the server's tools are loaded into a model's context. Higher counts reduce the attention available for other tasks.
Install
One-Click Install
Add this to your `claude_desktop_config.json` file:
{
"mcpServers": {
"idig-dns": {
"url": "https://mcp.softricks.net/sse"
}
}
}Remote endpoints
https://mcp.softricks.net/ssesseWhat it can do
Tool inventory
Tools (19)
⚪dns_lookup(domain, token, rr)
Look up DNS records for a domain. Record types: a, aaaa, ns, mx, txt, soa, caa, srv, cname, ds, tlsa, https, svcb, any, all.
Input Schema
{
"type": "object",
"properties": {
"domain": {
"title": "Domain",
"type": "string"
},
"token": {
"title": "Token",
"type": "string"
},
"rr": {
"default": "a",
"title": "Rr",
"type": "string"
}
},
"required": [
"domain",
"token"
],
"title": "dns_lookupArguments"
}⚪email_security_audit(domain, token)
Full SPF, DKIM, DMARC, and BIMI audit with A-F grade and prioritized fix recommendations.
Input Schema
{
"type": "object",
"properties": {
"domain": {
"title": "Domain",
"type": "string"
},
"token": {
"title": "Token",
"type": "string"
}
},
"required": [
"domain",
"token"
],
"title": "email_security_auditArguments"
}⚪dnssec_validate(domain, token)
Validate DNSSEC chain of trust. Returns: secure / insecure / bogus / indeterminate.
Input Schema
{
"type": "object",
"properties": {
"domain": {
"title": "Domain",
"type": "string"
},
"token": {
"title": "Token",
"type": "string"
}
},
"required": [
"domain",
"token"
],
"title": "dnssec_validateArguments"
}⚪dnssec_health(domain, token)
DNSSEC health report: key inventory, signature expiry, algorithm assessment, DS at parent, rollover readiness, full chain of trust (Root → TLD → Domain) with chain_intact flag and broken-link identification, warnings, and recommendations.
Input Schema
{
"type": "object",
"properties": {
"domain": {
"title": "Domain",
"type": "string"
},
"token": {
"title": "Token",
"type": "string"
}
},
"required": [
"domain",
"token"
],
"title": "dnssec_healthArguments"
}🟢resolve_check(domain, token)
DNS resolution diagnostics. Returns status: ok / nxdomain / nodata / servfail / refused / timeout / degraded.
Input Schema
{
"type": "object",
"properties": {
"domain": {
"title": "Domain",
"type": "string"
},
"token": {
"title": "Token",
"type": "string"
}
},
"required": [
"domain",
"token"
],
"title": "resolve_checkArguments"
}⚪diagnose(domain, token)
Full diagnosis combining resolution + DNSSEC. Use first when something is broken.
Input Schema
{
"type": "object",
"properties": {
"domain": {
"title": "Domain",
"type": "string"
},
"token": {
"title": "Token",
"type": "string"
}
},
"required": [
"domain",
"token"
],
"title": "diagnoseArguments"
}🟢propagation_check(domain, token, record_type)
Check DNS propagation across 16 global resolvers: Google, Cloudflare, Quad9, China, Korea, Russia.
Input Schema
{
"type": "object",
"properties": {
"domain": {
"title": "Domain",
"type": "string"
},
"token": {
"title": "Token",
"type": "string"
},
"record_type": {
"default": "A",
"title": "Record Type",
"type": "string"
}
},
"required": [
"domain",
"token"
],
"title": "propagation_checkArguments"
}🟢mx_check(domain, token)
MX health + provider detection: Google Workspace, M365, Proofpoint, Zoho, 35+ providers.
Input Schema
{
"type": "object",
"properties": {
"domain": {
"title": "Domain",
"type": "string"
},
"token": {
"title": "Token",
"type": "string"
}
},
"required": [
"domain",
"token"
],
"title": "mx_checkArguments"
}🔴domain_status(domain, token)
Registrar lock and EPP status. Checks transfer lock, delete lock, serverHold, pendingDelete.
Input Schema
{
"type": "object",
"properties": {
"domain": {
"title": "Domain",
"type": "string"
},
"token": {
"title": "Token",
"type": "string"
}
},
"required": [
"domain",
"token"
],
"title": "domain_statusArguments"
}⚪geo_lookup(domain, token)
Geolocation and hosting: country, city, ISP, ASN, CDN detection, is_hosting flag.
Input Schema
{
"type": "object",
"properties": {
"domain": {
"title": "Domain",
"type": "string"
},
"token": {
"title": "Token",
"type": "string"
}
},
"required": [
"domain",
"token"
],
"title": "geo_lookupArguments"
}🟢ttl_check(domain, token)
TTL advisory: flags dangerous TTLs and gives step-by-step migration lowering plan.
Input Schema
{
"type": "object",
"properties": {
"domain": {
"title": "Domain",
"type": "string"
},
"token": {
"title": "Token",
"type": "string"
}
},
"required": [
"domain",
"token"
],
"title": "ttl_checkArguments"
}🟢zone_consistency(domain, token)
Check all authoritative nameservers return identical answers. Catches lame delegation and SOA mismatches.
Input Schema
{
"type": "object",
"properties": {
"domain": {
"title": "Domain",
"type": "string"
},
"token": {
"title": "Token",
"type": "string"
}
},
"required": [
"domain",
"token"
],
"title": "zone_consistencyArguments"
}🟢ssl_check(domain, token)
SSL certificate: validity, expiry countdown, domain match, issuer, chain completeness.
Input Schema
{
"type": "object",
"properties": {
"domain": {
"title": "Domain",
"type": "string"
},
"token": {
"title": "Token",
"type": "string"
}
},
"required": [
"domain",
"token"
],
"title": "ssl_checkArguments"
}⚪subdomain_discover(domain, token)
Discover subdomains by probing 75 common names plus crt.sh Certificate Transparency logs. Surfaces exposed dev/staging environments.
Input Schema
{
"type": "object",
"properties": {
"domain": {
"title": "Domain",
"type": "string"
},
"token": {
"title": "Token",
"type": "string"
}
},
"required": [
"domain",
"token"
],
"title": "subdomain_discoverArguments"
}🟢blacklist_check(domain, token)
IP blacklist / DNSBL check. Tests A-record and MX IPs against Spamhaus, Barracuda, SpamCop, SORBS, and more.
Input Schema
{
"type": "object",
"properties": {
"domain": {
"title": "Domain",
"type": "string"
},
"token": {
"title": "Token",
"type": "string"
}
},
"required": [
"domain",
"token"
],
"title": "blacklist_checkArguments"
}⚪whois_lookup(domain, token)
Parsed WHOIS: registrar, creation/expiry dates, domain age, nameservers, EPP status, DNSSEC status.
Input Schema
{
"type": "object",
"properties": {
"domain": {
"title": "Domain",
"type": "string"
},
"token": {
"title": "Token",
"type": "string"
}
},
"required": [
"domain",
"token"
],
"title": "whois_lookupArguments"
}🟢http_check(domain, token)
HTTP/HTTPS reachability: status codes, redirect chain, HSTS header, HTTP→HTTPS redirect detection.
Input Schema
{
"type": "object",
"properties": {
"domain": {
"title": "Domain",
"type": "string"
},
"token": {
"title": "Token",
"type": "string"
}
},
"required": [
"domain",
"token"
],
"title": "http_checkArguments"
}⚪zone_axfr(domain, token)
AXFR zone transfer vulnerability check. Tests whether any authoritative NS allows public zone transfers (critical misconfiguration).
Input Schema
{
"type": "object",
"properties": {
"domain": {
"title": "Domain",
"type": "string"
},
"token": {
"title": "Token",
"type": "string"
}
},
"required": [
"domain",
"token"
],
"title": "zone_axfrArguments"
}⚪dane_validate(domain, token, port)
DANE/TLSA validation: cross-validates TLSA DNS records against the live TLS certificate. Supports all four TLSA usage types.
Input Schema
{
"type": "object",
"properties": {
"domain": {
"title": "Domain",
"type": "string"
},
"token": {
"title": "Token",
"type": "string"
},
"port": {
"default": 443,
"title": "Port",
"type": "integer"
}
},
"required": [
"domain",
"token"
],
"title": "dane_validateArguments"
}Recommended Prompts
blacklist_checkblacklist_checkCommunity
Evidence