Google Cloud DNS MCP server for managing DNS zones and records via API
Server provides 6 tools with clear verb-noun naming (list_, get_, create_, update_, delete_). All tools have descriptions and input schemas are visible. However, parameter descriptions are sparse and generic. Output schemas are not documented. Error handling is present but minimal. Tool descriptions are adequate (50-100 chars) but lack context on when to use each tool vs. others. No tool annotations (readOnlyHint, destructiveHint) despite clear read/write/destructive categorization. Missing guidance on prerequisites, dependencies, and recovery paths for errors.
Create a new DNS record in a managed zone
Delete a DNS record
Get details for a specific DNS managed zone
List DNS records in a managed zone
List all DNS managed zones in the Google Cloud project
Update an existing DNS record
Output schemas not documented. Tools return ToolResult with text content, but LLMs cannot plan downstream calls or extract structured data without knowing what fields are returned. No documentation of pagination, result limits, or field types in responses.
Missing tool annotations despite clear semantics. gcloud_dns_list_zones and gcloud_dns_get_zone are READ_ONLY but lack readOnlyHint. gcloud_dns_create_record, update_record are WRITE but lack destructiveHint. gcloud_dns_delete_record is DESTRUCTIVE but lacks explicit annotation. Agents cannot infer idempotency or retry safety.
Parameter descriptions lack actionable constraints. 'ttl' has no minimum/maximum (baselines: 60-86400 typical). 'rrdatas' array accepts any strings, no validation hints for IP format (A/AAAA), CNAME format, etc. 'type' enum values hinted but not formally constrained. LLMs will pass invalid record data.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | D | 59 | 2026-07-28+ | v2 |
Error messages generic and not actionable. 'Error listing managed zones: {error.message}' tells LLM nothing about recovery ('Did you check credentials?', 'Is the project ID correct?'). No distinction between retryable, user-fixable, and fatal errors. No suggestions for next steps.
No confirmation or dry-run for destructive operations. gcloud_dns_delete_record can permanently remove DNS records without any agent-facing confirmation step. Pattern: confirmation-request missing.
Tool descriptions lack context on usage patterns and interdependencies. No guidance on calling list_zones before get_zone, or list_records before create_record. No mention of required zone name format or DNS name format requirements. Agents cannot plan multi-step operations.
List tools lack pagination parameters. gcloud_dns_list_zones and gcloud_dns_list_records have no limit, offset/page, or cursor. If a project has hundreds of zones or records, results will be truncated or cause context window explosion. Baselines expect limit=20-50 with pagination.
Response format uses plain text rendering rather than structured JSON. Agents must parse formatted text strings to extract zone names, record data, nameservers, etc. Fragile and error-prone. Should return objects with typed fields (id, name, dnsName, creationTime).