DNS security MCP server for SOC investigations — Streamable HTTP / OAuth via Pocket ID
dns-mcp demonstrates solid definition quality across 25 tools. All tools have explicit descriptions (194-char baseline met). Input schemas are present and well-structured with proper JSON Schema typing for all 25 tools. Domain naming is verb-first and clear (dns_query, check_spf, enumerate_dkim_selectors). Parameters consistently use enums where appropriate (dns_query.qtype, check_dane.proto) and include regex patterns for domain/IP validation. However, output schemas are not documented in the provided source, responses are inferred from implementation but not formally declared in tool definitions. Error handling guidance is minimal; descriptions do not explain recovery paths or next steps for LLM agents. Tool composition is strong, each tool does one thing and parameters chain correctly (e.g., domain parameter reused across 20+ tools with identical pattern matching). No parameters expose secrets; all inputs are read-only DNS queries except reset_stats (WRITE risk noted). Minor issues: descriptions could be more LLM-optimized (some are technical DNS jargon without 'when to use' guidance), and no tool annotations (readOnlyHint/destructiveHint) are visible in schema.
Check BIMI (Brand Indicators for Message Identification) records.
Check CAA (Certification Authority Authorization) records.
Check Certificate Transparency (CT) logs for issued certificates.
Check DANE (DNSSEC Authentication of Named Entities) records for TLS certificate validation.
Check DBL (Domain Blacklist) status for a domain.
Check DKIM (DomainKeys Identified Mail) records.
Output schemas not documented. Tool definitions show input schemas but do not declare what fields responses contain. LLMs cannot plan downstream calls or extract return values without documented output structure.
Missing error handling guidance. Descriptions do not explain recovery paths or next steps when tools fail. E.g., dns_query does not state 'If domain not found, try check_zone_transfer' or 'Retry with different record type if NXDOMAIN.'
Inferred effective spec: <=2025-11-25.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | A | 81 | <=2025-11-25 | v2 |
| 2026-03-09 | F | 33 | - | v1 |
Check DMARC (Domain-based Message Authentication, Reporting and Conformance) policy.
Check for fast-flux detection patterns.
Check MTA-STS (Mail Transfer Agent Strict Transport Security) policy.
Check RBL (Realtime Blackhole List) status for an IP address.
Check SMTP TLS Reporting (TLSRPT) policy.
Check SPF (Sender Policy Framework) records for email authentication.
Check TLSA (DANE/TLSA) records for email and HTTPS security.
Check for unauthorized zone transfer (AXFR) access.
Query Cymru IP-to-ASN mapping service.
Detect DNS hijacking indicators.
Query DNS records via DoH (DNS-over-HTTPS). Supports A, AAAA, MX, TXT, NS, SOA, CNAME, PTR, SRV, CAA, DNSKEY, DS, RRSIG, NSEC, NSEC3, TLSA, SSHFP, HTTPS, SVCB, NAPTR.
Validate DNSSEC signatures for a domain.
Enumerate common DKIM selectors for a domain.
Extract NSEC/NSEC3 DNSSEC denial-of-existence information.
Return current timestamp, server uptime, and dns_tool version.
Query RDAP (Registration Data Access Protocol) for domain/IP registration details.
Reset session statistics counters.
Return call statistics for tools in the current session.
Return the authenticated user's identity from JWT claims.
Descriptions lack LLM-optimized context. Many tools use technical DNS terminology (DNSSEC, NSEC, TLSA, CAA, DANE) without explaining WHEN an agent should invoke them or WHY. E.g., check_bimi description is 52 chars; baselines show 194 chars average for optimal LLM reasoning.
No tool annotations (readOnlyHint, destructiveHint, idempotentHint) visible in schema. reset_stats is marked WRITE in Risk field but no destructiveHint in JSON Schema annotation. Tool definitions should declare safety/idempotency for agent planning.
Parameter rdap_lookup.query lacks domain/IP specificity. Accepts '1 - 253 chars' but does not guide LLMs on valid formats (FQDN vs IPv4 vs IPv6). Regex patterns in other tools (domain, ip) are not replicated here.