isitdns
Live DNS: dig public resolvers, audit or sweep a domain, walk a delegation, read the resolver board.
使うべきか
品質と安全性
検出事項(3)
- HIGH
- MEDIUMdig 内
- LOWdns_events 内
ツール定義とプロトコルへの準拠に関する自動分析に基づいています。
コンテキストコスト
これは、サーバーのツールがモデルのコンテキストに読み込まれるたびに消費されるおおよそのトークン数です。数が多いほど、ほかのタスクに使える注意が減ります。
インストール
ワンクリックインストール
これを `claude_desktop_config.json` ファイルに追加してください:
{
"mcpServers": {
"isitdns": {
"url": "https://isitdns.net/mcp"
}
}
}リモートエンドポイント
https://isitdns.net/mcpstreamable-httpできること
ツール一覧
ツール(12)
🟢dig(name, type, resolver, dnssec, cd, ...)
Ask ONE public DNS resolver on the board for one record, live, over DoH from the isitdns edge on Cloudflare. The resolver is a board id (cloudflare, google, quad9, opendns, adguard, cleanbrowsing, controld, quad9-unfiltered, adguard-family, cleanbrowsing-family, adguard-unfiltered, opendns-familyshield, nextdns, cloudflare-malware, cloudflare-family, mullvad-base, dns4eu-protective), an alias such as 8.8.8.8 or quad9 that maps to one, or "all" for the tier-1 operators side by side (cloudflare, google, quad9, adguard); every other board resolver is asked by its id; the default is cloudflare. A private (RFC 1918), link-local or LAN address, and any address not on the board, is refused, and the answer says why. To check whether the person's own path intercepts DNS, this tool is the reference only: ask canary.probe.isitdns.net here, and hand the person dig @192.0.2.1 <name>, which should get no answer (a documentation address with no server, RFC 5737; hand it over as written), and dig @1.1.1.1 <name>, both to run on their own machine. Returns the answer, the flags, the rcode, Extended DNS Errors and the latency in the shape dig prints, plus the JSON, and ends with an "ask again" link to the same query on the site (a dig with a flag off its default has no page and carries no link). With resolver "all", one TTL line per record set (RRSIG aside) seen on two or more rows with the same data: the lowest and highest TTL and the resolver that reported each. Over MCP the transport is DoH only: DoT, Do53 over TCP and the probe's Do53 over UDP are on the HTTP surface (https://isitdns.net/api/query, transport=). A resolver with no DoH endpoint on file cannot be asked here and answers so. Off-board address: refused; the answer carries the /api/query URL. With resolver "all": one line per group of rows with the same answer; NO ANSWER (asked, no reply) and NOT MEASURED (not asked) rows by name. The transcript is the primary result: keep the asked-at time, the resolver, transport, vantage, raw DNS sections, flags, rcode, EDE, latency, and the api and ask-again links. Give the person the api: and ask again: lines as printed (a dig with a flag off its default has no page and no ask again line).
入力スキーマ
{
"type": "object",
"properties": {
"name": {
"type": "string",
"description": "The name to ask for, e.g. example.com or _dmarc.example.com. Also accepted as \"domain\"; a URL is reduced to its host."
},
"type": {
"type": "string",
"default": "A",
"description": "Record type: A, AAAA, MX, TXT, NS, SOA, CNAME, DS, DNSKEY, CAA, SRV, HTTPS, SVCB, PTR, or TYPE<n>"
},
"resolver": {
"type": "string",
"default": "cloudflare",
"description": "A board resolver id (cloudflare, google, quad9, opendns, adguard, cleanbrowsing, controld, quad9-unfiltered, adguard-family, cleanbrowsing-family, adguard-unfiltered, opendns-familyshield, nextdns, cloudflare-malware, cloudflare-family, mullvad-base, dns4eu-protective), a registry alias such as 8.8.8.8 or dns.google, or \"all\" for the tier-1 operators side by side (cloudflare, google, quad9, adguard). An address that is not on the board is refused here with the HTTP URL that can dial it."
},
"dnssec": {
"type": "boolean",
"default": true,
"description": "Set the DO bit and read AD"
},
"cd": {
"type": "boolean",
"default": false,
"description": "Checking disabled: ask the resolver not to validate"
},
"ecs": {
"type": "string",
"description": "EDNS Client Subnet in CIDR form, e.g. 192.0.2.0/24"
},
"norec": {
"type": "boolean",
"default": false,
"description": "Clear RD, like dig +norec"
},
"nsid": {
"type": "boolean",
"default": false,
"description": "Request NSID (RFC 5001)"
},
"family": {
"type": "string",
"enum": [
"v4",
"v6",
"both"
],
"default": "v4",
"description": "Which address family to dial the resolver on"
}
},
"required": [
"name"
]
}🟢sweep_domain(domain, names, types)
Authoritative consistency, not cache propagation: find the zone's nameservers from the root down, then ask one address of each nameserver name per family (IPv4 and IPv6) every name x type you list, with recursion off, over TCP, and widen to every other address: the zone apex SOA and the certificate-readiness questions first, then any question the sampled servers disagree on, then any that failed, as far as the per-sweep budget, the rate limit and the deadline allow. Readiness says not measured, naming the addresses, whenever one was held back. The result names the addresses sampled, the questions widened, the addresses never asked and the addresses left out as slow or failing. Flags per name and type: disagree (servers differ, grouped by answer; vantages listed if more than one asked) · differs_by_vantage (split exactly by vantage; consistent with anycast or geo-steering, or one region lagging, which this sweep cannot tell apart) · not_authoritative (no aa bit) · lame (answered REFUSED) · no_answer (no response; the error per server) · not_asked (never sent: held back by the sample, paced out, the deadline, or 3 misses in a row) · serial_mismatch (SOA serials differ) · ttl_differs (same data, different TTLs) · same_error (every answering server gave the same error rcode) · private_address (RFC 1918, 6598, 4193, link-local, loopback; each range shown) · unreachable_from_edge (Cloudflare-hosted, the edge cannot dial it; asked from theoracle or thewizard instead, which via names) · relay_failed (asked from that probe, no answer) · not_relayed (not sent from it: cap, budget, misses, deadline). A nameserver with no address found is listed as not asked, never dropped; an owner no server answered usably is not measured, never empty. Asked for HTTPS or SVCB (with A and AAAA at the same names to compare hints), the answer also reads them (svcb): each AliasMode target (at most 4, the rest named as not followed) followed one hop after the sweep from a recursive resolver, Cloudflare's DoH with recursion on, not the zone's own servers, for its own HTTPS or SVCB and its A and AAAA, reporting what those reads found (a ServiceMode record, address records only, none of the three, AliasMode again or TargetName ".", NXDOMAIN: the alias dangles), not read when a read failed, or nothing concluded when the reads contradict each other; a target that reads as inside a network is not asked; ipv4hint and ipv6hint against the address records when the target is the owner, and mandatory keys the record does not carry (RFC 9460). It also reports certificate readiness per name: the CAA set that governs issuance and where it was found (RFC 8659 section 3), and what is published at _acme-challenge (RFC 8555 section 8.4). Use this instead of many dig calls when checking a zone after a change. Limits: 16 names, 8 types; the plan samples at most 8 addresses and sends at most 256 sweep queries per sweep, sample and widening together (a zone with more addresses is sampled, never refused for its size); 512 sweep queries a minute per caller (IPv6 per /64), 256 a minute to any one nameserver address, 2048 a minute site-wide (the delegation walk, the zone-cut check of up to 8 queries and the DS read are extra and counted by the per-call limit; the AliasMode follow, at most 12 DoH queries to one public resolver, is extra and counted by neither). One question at a time per server; a server that misses 3 in a row is not asked the rest; the zone-cut check, the grid and the DS read stop 60 s after the sweep starts, the delegation walk before them is not inside that limit, and the AliasMode follow after them has its own 4 s deadline. Give the person the api: and ask again: lines as printed.
入力スキーマ
{
"type": "object",
"properties": {
"domain": {
"type": "string",
"description": "The zone or name to sweep, e.g. example.com. Also accepted as \"name\"; a URL is reduced to its host."
},
"names": {
"type": "array",
"items": {
"type": "string"
},
"description": "Relative labels to ask, \"@\" for the apex. Default: @, www, _dmarc, _acme-challenge"
},
"types": {
"type": "array",
"items": {
"type": "string"
},
"description": "Record types. Default: SOA, NS, A, AAAA, MX, TXT, CAA"
}
},
"required": [
"domain"
]
}🟢check_domain(name)
The eleven-check DNS audit for a domain: parent and child nameservers agree, no open recursion, DNSSEC chain, TTL sanity, mail posture, glue at the parent, a DS that matches a live DNSKEY, and whether a truncated UDP answer can be had over TCP. Every check reports ok, warn, fail or skipped with the reason. No score, no grade. It does not test HTTP, SMTP delivery, registrar status or arbitrary record types: use trace for the delegation path step by step, sweep_domain to compare the authoritative servers, dig for one record from one resolver. Six of the eleven belong to a ZONE rather than to a name (the delegation, the DNSSEC chain, the nameserver's recursion policy, the glue, the DS match and the TCP fallback), so if you ask about a hostname those six are evaluated for the enclosing zone: the answer names it and marks the rows it applies to. Every transaction the audit made is a receipt under its check. Give the person the api: and ask again: lines as printed.
入力スキーマ
{
"type": "object",
"properties": {
"name": {
"type": "string",
"description": "The domain to audit. Also accepted as \"domain\"; a URL is reduced to its host."
}
},
"required": [
"name"
]
}🟢trace(name, type)
Walk the delegation from the root servers down to the authoritative server for a name, like dig +trace: recursion off at every hop, referrals and glue followed, lame, refused and unreachable servers reported, the final authoritative answer as given, plus a healthy-or-not verdict. It reads no DS, DNSKEY or RRSIG (the dnssec_check prompt does) and asks no recursive resolver (dig with resolver all does). Every hop, failed dial and side lookup is a receipt with its time, rcode, flags, EDE and latency. Give the person the api: and ask again: lines as printed.
入力スキーマ
{
"type": "object",
"properties": {
"name": {
"type": "string",
"description": "The name to walk. Also accepted as \"domain\"; a URL is reduced to its host."
},
"type": {
"type": "string",
"default": "A",
"description": "Record type for the final question"
}
},
"required": [
"name"
]
}🟢resolver_status(resolver)
Is public DNS having trouble right now? Every public resolver isitdns watches, tier-1 first: one label each, each probe's timestamped reading (the question, the resolver address, the probe, family and transport, the answer or failure, flags, rcode, EDE, latency), and a fresh read from the edge. When answering, give the readings behind the label; never 'DNS is fine' or 'resolver X is down' without them. Give a resolver for one card. Give the person the api: and ask again: lines as printed.
入力スキーマ
{
"type": "object",
"properties": {
"resolver": {
"type": "string",
"description": "One resolver by id (cloudflare, google, quad9, opendns, adguard, cleanbrowsing, controld, quad9-unfiltered, adguard-family, cleanbrowsing-family, adguard-unfiltered, opendns-familyshield, nextdns, cloudflare-malware, cloudflare-family, mullvad-base, dns4eu-protective), alias or address; omit for the whole board"
}
}
}🟢resolver_history(resolver, all)
The incident record for the public resolvers: start time, duration and severity of each. Notable incidents by default; all=true includes short degradations. Windows where several operators failed at once are excluded as our own probe's path, and the answer says how many. Give the person the api: and ask again: lines as printed.
入力スキーマ
{
"type": "object",
"properties": {
"resolver": {
"type": "string",
"description": "Limit to one resolver id; omit for all"
},
"all": {
"type": "boolean",
"default": false,
"description": "Include short degraded runs, not only notable incidents"
}
}
}🟢top_domains(domain)
The DNS health of the domains isitdns monitors, a list isitdns keeps, as of the last DAILY snapshot: rcode, addresses, DNSSEC and points, ordered by points, for each. Those come from one probe per day at 11:11:11 UTC and do not move intraday. The nameservers and the points are read separately, at Cloudflare's recursive, and are refreshed through the day. Ask for one domain to get its row, or omit to get the board and its summary. To check any domain right now rather than as of the snapshot, use check_domain. Give the person the api: and ask again: lines as printed.
入力スキーマ
{
"type": "object",
"properties": {
"domain": {
"type": "string",
"description": "One domain to read from the board, e.g. github.com; omit for the whole list"
}
}
}🟢dns_events
Days when several resolvers were unhealthy at once, as episodes: when each began, how long it ran, how many resolvers were affected at the peak, and which. Give the person the api: and ask again: lines as printed.
入力スキーマ
{
"type": "object",
"properties": {}
}🟢ksk_board
The RFC 8509 root key sentinel across the public resolvers: which resolvers trust which root KSK, and the root DNSKEY set as read now. Give the person the api: and ask again: lines as printed.
入力スキーマ
{
"type": "object",
"properties": {}
}🟢dnssec_chain(name, type)
Walk the DNSSEC chain for one name and type from the root key set to the answer, read through one public resolver with checking disabled (Cloudflare DoH, RFC 4035 section 3.2.2), and name the first link that breaks with its RFC 4035 condition. Per signed zone cut: the DS set at the parent and who signed it, the DNSKEY set with key tags and roles (KSK, ZSK, revoked), which DS matches which key (SHA-1, SHA-256, SHA-384 digests computed), whether a DS-matched key signs the DNSKEY set, and each signature's window against the read time; then the answer's signer and key tag, or the NSEC and NSEC3 records of a negative answer (counted, not checked). An insecure delegation (no DS at the parent) is reported as where the chain ends, not as a break. checked: key tags, signers, windows · signatures: not verified. Every read of the walk is a receipt with its time, rcode, flags, EDE and latency. Give the person the api: and ask again: lines as printed.
入力スキーマ
{
"type": "object",
"properties": {
"name": {
"type": "string",
"description": "The name, e.g. www.example.com. Also accepted as \"domain\"; a URL is reduced to its host."
},
"type": {
"type": "string",
"default": "A",
"description": "The record type to check at the end of the chain"
}
},
"required": [
"name"
]
}🟢alias_chain(name)
Follow a name's CNAME chain one hop at a time, asking one public resolver (Cloudflare DoH, recursion on) for type CNAME at each hop, so each hop's rcode is its own (a full query returns only the last name's rcode, RFC 6604 section 3). Returns each owner, target and TTL, and how the chain ends: the addresses at its end (A and AAAA, each family on its own, an address in inside space marked), no address (NOERROR, no A or AAAA), a resolver failure (SERVFAIL, REFUSED: nothing known about the records), NXDOMAIN (a dangling alias), a loop, an inside name (not asked), or a stop after 8 hops. Notes a target that reads like one written without its trailing dot. Not measured: dangling-target claim (takeover). Every question asked is a receipt with its time, rcode, flags and latency. Give the person the api: and ask again: lines as printed.
入力スキーマ
{
"type": "object",
"properties": {
"name": {
"type": "string",
"description": "The name to follow, e.g. www.example.com. Also accepted as \"domain\"; a URL is reduced to its host."
}
},
"required": [
"name"
]
}🟢registration(domain)
Is the domain itself on hold, expired or being deleted? Asks the registry's RDAP server (found through IANA's RDAP bootstrap registry, RFC 9224) and returns the EPP statuses with what each means for resolution (clientHold, serverHold and redemptionPeriod mean the registry says it is not publishing the delegation; resolvers keep a cached copy until its TTL runs out, and trace shows whether the TLD servers still refer), the registration, expiration and last-changed dates, the nameservers the registry holds, and whether the delegation is signed. A hostname is walked up to the registered domain. Every HTTP read is a line with its URL, status, round trip and time. Give the person the api: and ask again: lines as printed.
入力スキーマ
{
"type": "object",
"properties": {
"domain": {
"type": "string",
"description": "The registered domain or a hostname under it, e.g. example.com. Also accepted as \"name\"; a URL is reduced to its host."
}
},
"required": [
"domain"
]
}コミュニティ
エビデンス