BlackVeil DNS & Email Security Scanner
REMOTE · DNS-MCP.BLACKVEILSECURITY.COM · SCANNED SEP 22
DNS and email security scanner with 80 MCP tools for SPF, DMARC, DNSSEC, SSL, and brand audits.
Available components
Recent critical change
Authorization (6 Aug 2026). See the changelog before you install this server.
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security66
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation check failed: no authorisation is required to call this server, and it exposes a tool marked destructive (delete_brand_audit_watch). See how to fix → View diagnostics → Fail
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC is configured correctly; the domain's records validate against the full chain to the root. View diagnostics → Pass
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability82
- 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 11475 tokens (~133/item across 86 items; 80 tools + 6 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management99
- Stability check failed: schema churn in the 30 days we've observed: 1 tool removals, 0 breaking changes, 0 auth/transport breaks, 5 additions. See how to fix → Fail
Tool Coverage98
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 94% of tool parameters carry a description.Partial
- Structured output schemas are declared (55% of tools); any adoption earns full credit.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- All 1 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
- An AI judge read all 82 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities60
- Spec-recency check failed: implements MCP spec 2025-06-18; the latest is 2026-07-28. See how to fix → Fail
How do I install the BlackVeil DNS & Email Security Scanner MCP server?
BlackVeil DNS & Email Security Scanner is a hosted endpoint at https://dns-mcp.blackveilsecurity.com/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · dns-mcp.blackveilsecurity.com
claude mcp add --transport http com-blackveilsecurity-dns 'https://dns-mcp.blackveilsecurity.com/mcp'
{
"mcpServers": {
"com-blackveilsecurity-dns": {
"url": "https://dns-mcp.blackveilsecurity.com/mcp"
}
}
} {
"servers": {
"com-blackveilsecurity-dns": {
"type": "http",
"url": "https://dns-mcp.blackveilsecurity.com/mcp"
}
}
} [mcp_servers.com-blackveilsecurity-dns] url = "https://dns-mcp.blackveilsecurity.com/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"com-blackveilsecurity-dns": {
"type": "remote",
"url": "https://dns-mcp.blackveilsecurity.com/mcp",
"enabled": true
}
}
} openclaw mcp add com-blackveilsecurity-dns --url 'https://dns-mcp.blackveilsecurity.com/mcp' --transport streamable-http
mcp_servers:
com-blackveilsecurity-dns:
url: "https://dns-mcp.blackveilsecurity.com/mcp" {
"McpServers": {
"com-blackveilsecurity-dns": {
"Transport": "http",
"Url": "https://dns-mcp.blackveilsecurity.com/mcp"
}
}
} assistant mcp add com-blackveilsecurity-dns -t streamable-http -u 'https://dns-mcp.blackveilsecurity.com/mcp'
{
"mcpServers": {
"com-blackveilsecurity-dns": {
"type": "http",
"url": "https://dns-mcp.blackveilsecurity.com/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 21 Sept 26 0
- Server version: 3.85.0 → 3.86.1 functional
- Server version: 3.84.0 → 3.85.0 functional
- 20 Sept 26 0
- Tool “check_dane” rewrote its description, which is the text the model reads security
- Server version: 3.83.0 → 3.84.0 functional
- 19 Sept 26 0
- Server version: 3.82.0 → 3.83.0 functional
- 18 Sept 26 0
- Tool “sge_quickscan” rewrote its description, which is the text the model reads security
- Server version: 3.81.2 → 3.82.0 functional
- 17 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 88 to 94.
- 15 Sept 26 0
- Server version: 3.81.1 → 3.81.2 functional
- Server version: 3.81.0 → 3.81.1 functional
- Server version: 3.80.0 → 3.81.0 functional
- 14 Sept 26 0
- Server version: 3.79.0 → 3.80.0 functional
- Server version: 3.78.0 → 3.79.0 functional
- New tool “sge_quickscan” functional
- 9 Sept 26 0
- Tool “prioritize_csc_leads” was removed ▼ security
- Server version: 3.77.0 → 3.78.0 functional
- New tool “prioritize_portfolio_leads” functional
- “brand_audit_batch_start” reworded the description of “view” cosmetic
- “brand_audit_single” reworded the description of “view” cosmetic
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 22 Sept 2026 · Probed https://dns-mcp.blackveilsecurity.com/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=blackveilsecurity.com | CN=WE1,O=Google Trust Services,C=US | 22 Aug 2026 | 20 Nov 2026 | ECDSA 256 | ECDSA-SHA256 | f7b1b2d7918c822f0ec60d1ffbf06454 |
| SANs: blackveilsecurity.com, dns-mcp.blackveilsecurity.com | ||||||
| CN=WE1,O=Google Trust Services,C=US (CA) | CN=GTS Root R4,O=Google Trust Services LLC,C=US | 13 Dec 2023 | 20 Feb 2029 | ECDSA 256 | ECDSA-SHA384 | 7ff31977972c224a76155d13b6d685e3 |
| CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) | CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE | 15 Nov 2023 | 28 Jan 2028 | ECDSA 384 | SHA256-RSA | 7fe530bf331343bedd821610493d8a1b |
Background: What to check on a remote MCP endpoint →
DNSSEC secure
Validation of dns-mcp.blackveilsecurity.com. — Secure
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| com. | present | 19718 | 13 | Verified |
| blackveilsecurity.com. | present | 2371 | 13 | Verified |
| dns-mcp.blackveilsecurity.com. | Verified address RRset verified with the apex keys |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
| Header | Value |
|---|---|
| strict-transport-security | max-age=63072000; includeSubDomains; preload |
| content-security-policy | default-src 'self'; script-src 'none'; style-src 'self' 'unsafe-inline'; object-src 'none'; frame-ancestors 'none'; form-action 'self' |
| x-content-type-options | nosniff |
| x-frame-options | DENY |
| referrer-policy | no-referrer |
| permissions-policy | geolocation=(), microphone=(), camera=() |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://dns-mcp.blackveilsecurity.com/mcp | Verified | 200 | |
| http (plaintext) | http://dns-mcp.blackveilsecurity.com/mcp | HTTPS enforced | 301 | https://dns-mcp.blackveilsecurity.com/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
analyze_drift ~200
Measure whether a domain's DNS security posture improved or regressed by comparing the current state against a prior scan snapshot. Returns a drift classification (improving/stable/regressing/mixed), score delta, and lists of improvements and regressions. Use to answer "did our security score improve or regress since last time?" — distinct from compare_baseline which checks compliance against a fixed policy (not improvement over time).
| Name | Type | Req | Description |
|---|---|---|---|
| baseline | string | yes | Prior scan reference for drift-over-time analysis: a previous ScanScore JSON STRING, or the literal "cached" to reuse the last cached scan (the default when omitted). NOT a policy/requirements object… |
| domain | string | yes | Domain to analyze drift for |
| force_refresh | boolean | – | Bypass cache and run a fresh check. Useful after DNS changes. |
| format | string | – | Output verbosity. Auto-detected if omitted. |
No output schema declared.
No examples provided.
assess_spoofability ~153
Compute a composite email spoofability risk score (0–100, higher = more spoofable) by combining SPF trust surface, DMARC enforcement, and DKIM coverage. Returns a risk level (minimal→critical), per-control sub-scores, and plain-language summary of how easy it would be to spoof email from the domain. Use when asked how easy it is to spoof email from a domain, or for a composite email spoofing risk score.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain to check (e.g., example.com) |
| force_refresh | boolean | – | Bypass cache and run a fresh check. Useful after DNS changes. |
| format | string | – | Output verbosity. Auto-detected if omitted. |
No output schema declared.
No examples provided.
batch_scan ~212
Bulk-scan up to 10 domains in parallel. Runs a full security audit on each domain in the list and returns score, NIST-aligned letter grade (6-band A+/A/B/C/D/F), and finding counts per domain. Use when you want to audit multiple domains at once or do a bulk scan of several domains simultaneously — distinct from compare_domains which does a side-by-side analysis of 2–5 domains. Version stamps (hoisted once per batch): 'scoringModelVersion' is the scoring POLICY semver and is INDEPENDENT of 'dnsChecksPackageVersion', the @blackveil/dns-checks npm engine-package version — the model version legitimately lags and the two must not be compared. Record 'scoringConfigHash' when citing scores.
| Name | Type | Req | Description |
|---|---|---|---|
| domains | array | yes | Domains to scan (max 10 per request) |
| force_refresh | boolean | – | Bypass cache and run fresh scans. |
| format | string | – | Output verbosity. Auto-detected if omitted. |
No output schema declared.
No examples provided.
batch_scan_findings ~44
Fetch owner-scoped findings for a completed asynchronous batch scan.
| Name | Type | Req | Description |
|---|---|---|---|
| format | string | – | – |
| job_id | string | yes | Job ID returned by batch_scan_start. |
No output schema declared.
No examples provided.
batch_scan_start ~117
Start a durable asynchronous scan of 1–10 domains. Returns a stable job ID; replaying the same idempotency key with the same principal, normalized inputs, and scoring versions returns the same job.
| Name | Type | Req | Description |
|---|---|---|---|
| domains | array | yes | Domains to scan (max 10 per request) |
| force_refresh | boolean | – | Bypass cache and run fresh scans. |
| format | string | – | Output verbosity. Auto-detected if omitted. |
| idempotency_key | string | yes | Caller-stable replay key for this exact batch request. |
No output schema declared.
No examples provided.
batch_scan_status ~43
Read the owner-scoped status of an asynchronous batch scan.
| Name | Type | Req | Description |
|---|---|---|---|
| format | string | – | – |
| job_id | string | yes | Job ID returned by batch_scan_start. |
No output schema declared.
No examples provided.
brand_audit_batch_start ~358
Enqueue an async brand audit across up to 50 target domains with optional standard/deep discovery depth, brand aliases, and caller-supplied candidate domains. Returns { auditId, queuedAt, targetCount, etaSeconds } immediately; poll with brand_audit_status and fetch results with brand_audit_get_report once complete. Each target consumes 1 unit of the monthly BRAND_AUDIT_QUOTAS budget.
| Name | Type | Req | Description |
|---|---|---|---|
| brand_aliases | array | – | Optional public brand aliases to seed, such as product or legal-entity labels. |
| candidate_domains | array | – | Optional candidate domains supplied by the caller for corroboration. |
| depth | string | – | Discovery depth. standard is default; deep expands candidate seeding and enrichment fanout. |
| discovery_mode | string | – | Brand-discovery pipeline mode. classic = legacy sweep; tiered = tenant/graph/evidence wrappers first (BlackVeil-internal). |
| domains | array | yes | Domains to audit (max 50 per batch). Duplicates are merged. |
| format | – | – | Inline output mode. Defaults to "both". |
| min_confidence | number | – | Drop candidates whose combined confidence falls below this threshold (0-1, default 0.5). |
| ownership_verified | boolean | – | Caller attests that the target domains are owned or authorized for scanning. Required when discovery_mode is "tiered" and the caller is not an enterprise/owner/partner principal. |
| planner_mode | string | – | Planner mode for staged discovery fanout. observe emits metrics; enforce applies candidate-backed signal caps. |
| view | string | – | Output view mode. 'registrar_complement' produces a registrar-complement payload; requires enterprise tier. Default 'standard'. |
| Name | Type | Req | Description |
|---|---|---|---|
| category | string | yes | – |
| checkStatus | string | – | – |
| findings | array | yes | – |
| partial | boolean | – | – |
| passed | boolean | yes | – |
| score | number | yes | – |
No examples provided.
brand_audit_get_report ~130
Fetch the result JSON for a completed brand audit. With `target` set, returns the per-target CheckResult; without, returns the audit-level aggregate. Returns notReady when polling an in-flight audit. When a rendered PDF sidecar exists, metadata includes pdfUrl — an authenticated /reports/ download link (same bearer credential as this call). Completed targets whose PDF is still rendering include pdfPending so callers can poll again.
| Name | Type | Req | Description |
|---|---|---|---|
| auditId | string | yes | Audit ID returned by brand_audit_batch_start. |
| target | string | – | Specific target domain. Omit for audit-level aggregate. |
| Name | Type | Req | Description |
|---|---|---|---|
| category | string | yes | – |
| checkStatus | string | – | – |
| findings | array | yes | – |
| partial | boolean | – | – |
| passed | boolean | yes | – |
| score | number | yes | – |
No examples provided.
brand_audit_single ~396
Run a full brand audit on a single target with optional standard/deep discovery depth, brand aliases, and caller-supplied candidate domains. Discovers brand-related domains, looks up registrar + registrant for each candidate, and classifies each into consolidated, real registrar-sprawl shadowIt, authorized vendor dependency, indeterminate, or impersonation relationships. Gated tier-wide by monthly BRAND_AUDIT_QUOTAS (free/agent=0, developer=50, partner=200, enterprise=500, owner=unlimited).
| Name | Type | Req | Description |
|---|---|---|---|
| brand_aliases | array | – | Optional public brand aliases to seed, such as product or legal-entity labels. |
| candidate_domains | array | – | Optional candidate domains supplied by the caller for corroboration. |
| depth | string | – | Discovery depth. standard is default; deep expands candidate seeding and enrichment fanout. |
| discovery_mode | string | – | Brand-discovery pipeline mode. classic = legacy sweep; tiered = tenant/graph/evidence wrappers first (BlackVeil-internal). |
| domain | string | yes | Target domain to audit (e.g., apple.com). |
| force_refresh | boolean | – | Bypass cache and run a fresh check. Useful after DNS changes. |
| format | – | – | Inline output mode. Defaults to "both". |
| min_confidence | number | – | Drop candidates whose combined confidence falls below this threshold (0-1, default 0.5). |
| ownership_verified | boolean | – | Caller attests that the target domain is owned or authorized for scanning. Required when discovery_mode is "tiered" and the caller is not an enterprise/owner/partner principal. |
| planner_mode | string | – | Planner mode for staged discovery fanout. observe emits metrics; enforce applies candidate-backed signal caps. |
| view | string | – | Output view mode. 'registrar_complement' produces a registrar-complement payload; requires enterprise tier. Default 'standard'. |
| Name | Type | Req | Description |
|---|---|---|---|
| category | string | yes | – |
| checkStatus | string | – | – |
| findings | array | yes | – |
| partial | boolean | – | – |
| passed | boolean | yes | – |
| score | number | yes | – |
No examples provided.
brand_audit_status ~75
Poll the status of an enqueued brand audit. Returns audit-level status (queued | running | completed | failed), progress 'N/M', and per-target statuses. Owner-scoped — auditIds owned by other principals surface as notFound.
| Name | Type | Req | Description |
|---|---|---|---|
| auditId | string | yes | Audit ID returned by brand_audit_batch_start. |
| Name | Type | Req | Description |
|---|---|---|---|
| category | string | yes | – |
| checkStatus | string | – | – |
| findings | array | yes | – |
| partial | boolean | – | – |
| passed | boolean | yes | – |
| score | number | yes | – |
No examples provided.
check_agent_discovery ~279
Assess the security posture of IETF BANDAID agent-discovery records (draft-mozleywilliams-dnsop-dnsaid). Detects SVCB agent records under _agents/_index._{protocol}._agents, reports whether the discovery zone is DNSSEC-anchored (unsigned = spoofable agent endpoints), evaluates DANE/TLSA binding trust (RFC 6698 §10.1), and checks capability-document integrity (cap / cap-sha256). Read-only; uses Private-Use SVCB param code points pending IANA assignment.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain to check for published agent-discovery records (e.g., example.com). |
| force_refresh | boolean | – | Bypass cache and run a fresh check. Useful after DNS changes. |
| format | string | – | Output verbosity. Auto-detected if omitted. |
| name | string | – | Resolve a single named agent ({name}.{domain}) instead of enumerating the zone. |
| protocol | string | – | Scope discovery to a single agent protocol index (_index._{protocol}._agents). Omit to sweep the zone. |
| verify_cap | boolean | – | Fetch each declared capability document (cap=) over HTTPS via safeFetch and verify it against the cap-sha256 integrity pin. Default false (declaration/existence check only). |
| Name | Type | Req | Description |
|---|---|---|---|
| category | string | yes | – |
| checkStatus | string | – | – |
| findings | array | yes | – |
| partial | boolean | – | – |
| passed | boolean | yes | – |
| score | number | yes | – |
No examples provided.
check_authoritative_dns_infra ~96
Check authoritative DNS infrastructure posture for a hostname. Uses BV_INFRA_PROBE when available for raw DNS, routing, RPKI, and vantage-point evidence.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain to check (e.g., example.com) |
| force_refresh | boolean | – | Bypass cache and run a fresh check. Useful after DNS changes. |
| format | string | – | Output verbosity. Auto-detected if omitted. |
| Name | Type | Req | Description |
|---|---|---|---|
| category | string | yes | – |
| checkStatus | string | – | – |
| findings | array | yes | – |
| partial | boolean | – | – |
| passed | boolean | yes | – |
| score | number | yes | – |
No examples provided.
check_bimi ~179
Check the BIMI brand-logo record at default._bimi.<domain>. Validates the logo URL (l=) and the presence of mark-certificate authority evidence (a=) — the a= tag is a bare URL, so the certificate type (VMC or CMC) is not determined — and verifies the DMARC enforcement prerequisite (p=quarantine/reject) that mail clients require before displaying a BIMI logo. Returns findings for a missing/malformed record or unmet prerequisites. Use to assess brand-indicator readiness in inboxes. Part of the scan_domain audit.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain to check (e.g., example.com) |
| force_refresh | boolean | – | Bypass cache and run a fresh check. Useful after DNS changes. |
| format | string | – | Output verbosity. Auto-detected if omitted. |
| Name | Type | Req | Description |
|---|---|---|---|
| category | string | yes | – |
| checkStatus | string | – | – |
| findings | array | yes | – |
| partial | boolean | – | – |
| passed | boolean | yes | – |
| score | number | yes | – |
No examples provided.
check_caa ~87
Look up CAA records for a domain. Shows which Certificate Authorities are authorized to issue certificates. Part of the scan_domain audit.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain to check (e.g., example.com) |
| force_refresh | boolean | – | Bypass cache and run a fresh check. Useful after DNS changes. |
| format | string | – | Output verbosity. Auto-detected if omitted. |
| Name | Type | Req | Description |
|---|---|---|---|
| category | string | yes | – |
| checkStatus | string | – | – |
| findings | array | yes | – |
| partial | boolean | – | – |
| passed | boolean | yes | – |
| score | number | yes | – |
No examples provided.
check_dane ~244
Check DANE/TLSA certificate pinning for SMTP at port 25. Resolves the domain's MX hosts and looks up TLSA records at _25._tcp.<mx-host>, validating their syntax, usage/selector/matching-type fields and DNSSEC backing on the MX host's zone. The record is reported as present but UNVERIFIED: there is no certificate probe for port 25/SMTP, so the pinned data is never compared against the certificate the mail server actually serves (the comparable capture-and-compare pipeline exists only for check_dane_https at port 443, and is itself currently kill-switched there — see that tool's description). Use when asked if SMTP mail servers publish DANE/TLSA pinning; this does not confirm the pin matches the live certificate. For HTTPS DANE at port 443, use check_dane_https instead. Part of the scan_domain audit.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain to check (e.g., example.com) |
| force_refresh | boolean | – | Bypass cache and run a fresh check. Useful after DNS changes. |
| format | string | – | Output verbosity. Auto-detected if omitted. |
| Name | Type | Req | Description |
|---|---|---|---|
| category | string | yes | – |
| checkStatus | string | – | – |
| findings | array | yes | – |
| partial | boolean | – | – |
| passed | boolean | yes | – |
| score | number | yes | – |
No examples provided.
check_dane_https ~191
Verify DANE certificate pinning for HTTPS connections. Looks up TLSA records at _443._tcp.{domain} (port 443) and validates their syntax, usage/selector/matching-type fields and DNSSEC backing. The record is reported as present but UNVERIFIED in every deployment: comparison against the certificate the host actually serves is currently withdrawn because the operator probe vantage cannot observe the origin certificate (finding metadata notAssessedReason probe_vantage_intercepted when the probe is bound), so a stale pin is NOT detected here. Distinct from check_dane which covers SMTP at port 25. Part of the scan_domain audit.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain to check (e.g., example.com) |
| force_refresh | boolean | – | Bypass cache and run a fresh check. Useful after DNS changes. |
| format | string | – | Output verbosity. Auto-detected if omitted. |
| Name | Type | Req | Description |
|---|---|---|---|
| category | string | yes | – |
| checkStatus | string | – | – |
| findings | array | yes | – |
| partial | boolean | – | – |
| passed | boolean | yes | – |
| score | number | yes | – |
No examples provided.
check_dbl ~91
Check domain reputation against DNS-based Domain Block Lists (Spamhaus DBL, URIBL, SURBL). Returns listing status with decoded return codes.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain to check (e.g., example.com) |
| force_refresh | boolean | – | Bypass cache and run a fresh check. Useful after DNS changes. |
| format | string | – | Output verbosity. Auto-detected if omitted. |
| Name | Type | Req | Description |
|---|---|---|---|
| category | string | yes | – |
| checkStatus | string | – | – |
| findings | array | yes | – |
| partial | boolean | – | – |
| passed | boolean | yes | – |
| score | number | yes | – |
No examples provided.
check_dkim ~137
Look up DKIM records for a domain. Probes common selectors, validates the signing algorithm used for outgoing email (RSA-1024/2048, Ed25519), and reports key strength. Use to verify that outbound email signatures are cryptographically sound. Part of the scan_domain audit.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain to check (e.g., example.com) |
| force_refresh | boolean | – | Bypass cache and run a fresh check. Useful after DNS changes. |
| format | string | – | Output verbosity. Auto-detected if omitted. |
| selector | string | – | DKIM selector. Omit to probe common ones. |
| Name | Type | Req | Description |
|---|---|---|---|
| category | string | yes | – |
| checkStatus | string | – | – |
| findings | array | yes | – |
| partial | boolean | – | – |
| passed | boolean | yes | – |
| score | number | yes | – |
No examples provided.
check_dmarc ~158
Look up and validate the DMARC record for a domain. Shows the enforcement level (none/quarantine/reject), alignment mode (strict/relaxed), and aggregate/forensic reporting destinations. Use to determine a domain's DMARC enforcement level, whether it sends aggregate reports, or if it is protected against email impersonation — distinct from check_shadow_domains (which checks TLD variants) and assess_spoofability (composite score). Part of the scan_domain audit.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain to check (e.g., example.com) |
| force_refresh | boolean | – | Bypass cache and run a fresh check. Useful after DNS changes. |
| format | string | – | Output verbosity. Auto-detected if omitted. |
| Name | Type | Req | Description |
|---|---|---|---|
| category | string | yes | – |
| checkStatus | string | – | – |
| findings | array | yes | – |
| partial | boolean | – | – |
| passed | boolean | yes | – |
| score | number | yes | – |
No examples provided.
check_dnskey_strength ~165
Audit the cryptographic strength of DNSKEY signing algorithms used for DNSSEC. Reports which algorithm is used for DNSSEC signing keys (RSA/SHA-1, RSA/SHA-256, ECDSA P-256, Ed25519, etc.), flags deprecated algorithms (RSA/SHA-1, DSA), independent of whether the DNSSEC chain validates. Use when asked what algorithm is used for DNSSEC signing keys, or if deprecated DNSKEY algorithms are in use. Part of the scan_domain audit.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain to check (e.g., example.com) |
| force_refresh | boolean | – | Bypass cache and run a fresh check. Useful after DNS changes. |
| format | string | – | Output verbosity. Auto-detected if omitted. |
| Name | Type | Req | Description |
|---|---|---|---|
| category | string | yes | – |
| checkStatus | string | – | – |
| findings | array | yes | – |
| partial | boolean | – | – |
| passed | boolean | yes | – |
| score | number | yes | – |
No examples provided.
check_dnssec ~111
Check DNSSEC status for a domain. Verifies whether DNS is tamper-proof and protected against cache poisoning and DNS spoofing attacks by validating DNSKEY and DS records. Reports whether DNSSEC is enabled and validating. Part of the scan_domain audit.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain to check (e.g., example.com) |
| force_refresh | boolean | – | Bypass cache and run a fresh check. Useful after DNS changes. |
| format | string | – | Output verbosity. Auto-detected if omitted. |
| Name | Type | Req | Description |
|---|---|---|---|
| category | string | yes | – |
| checkStatus | string | – | – |
| findings | array | yes | – |
| partial | boolean | – | – |
| passed | boolean | yes | – |
| score | number | yes | – |
No examples provided.
check_dnssec_chain ~121
Walk the full DNSSEC chain of trust from the DNS root down to the target domain, tracing DS/DNSKEY records and algorithm usage at each zone level. Use when asked to trace the chain of trust from the DNS root, or to see the full DNSSEC delegation path step by step.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain to check (e.g., example.com) |
| force_refresh | boolean | – | Bypass cache and run a fresh check. Useful after DNS changes. |
| format | string | – | Output verbosity. Auto-detected if omitted. |
| Name | Type | Req | Description |
|---|---|---|---|
| category | string | yes | – |
| checkStatus | string | – | – |
| findings | array | yes | – |
| partial | boolean | – | – |
| passed | boolean | yes | – |
| score | number | yes | – |
No examples provided.
check_fast_flux ~138
Detect fast-flux DNS behavior: performs multiple rounds of A/AAAA queries and checks whether IP addresses are rotating rapidly on each DNS query (a sign of botnet or malicious infrastructure). Compares IP answer sets and TTLs across rounds to identify rapidly rotating infrastructure used to hide malicious activity.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain to check (e.g., example.com) |
| force_refresh | boolean | – | Bypass cache and run a fresh check. Useful after DNS changes. |
| format | string | – | Output verbosity. Auto-detected if omitted. |
| rounds | integer | – | Number of query rounds (3-5, default 3). |
| Name | Type | Req | Description |
|---|---|---|---|
| category | string | yes | – |
| checkStatus | string | – | – |
| findings | array | yes | – |
| partial | boolean | – | – |
| passed | boolean | yes | – |
| score | number | yes | – |
No examples provided.
check_http_security ~167
Audit a domain's browser-facing HTTP security headers over HTTPS. Inspects Content-Security-Policy (flagging unsafe-inline/unsafe-eval/wildcards), X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, and the cross-origin isolation headers (COOP/COEP/CORP), and detects CDN/WAF interception. Returns per-header findings for missing or weak protections against XSS, clickjacking, and cross-origin attacks. Part of the scan_domain audit.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain to check (e.g., example.com) |
| force_refresh | boolean | – | Bypass cache and run a fresh check. Useful after DNS changes. |
| format | string | – | Output verbosity. Auto-detected if omitted. |
| Name | Type | Req | Description |
|---|---|---|---|
| category | string | yes | – |
| checkStatus | string | – | – |
| findings | array | yes | – |
| partial | boolean | – | – |
| passed | boolean | yes | – |
| score | number | yes | – |
No examples provided.
check_lookalikes ~127
Detect active typosquat and lookalike/homoglyph domains that impersonate your brand and could be used in phishing. Identifies character-substitution and visual-confusion domains registered by attackers. Distinct from check_shadow_domains (TLD variants with auth gaps) and discover_brand_domains (legitimate brand portfolio).
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain to check (e.g., example.com) |
| force_refresh | boolean | – | Bypass cache and run a fresh check. Useful after DNS changes. |
| format | string | – | Output verbosity. Auto-detected if omitted. |
| Name | Type | Req | Description |
|---|---|---|---|
| category | string | yes | – |
| checkStatus | string | – | – |
| findings | array | yes | – |
| partial | boolean | – | – |
| passed | boolean | yes | – |
| score | number | yes | – |
No examples provided.
check_mta_sts ~148
Check whether a domain enforces SMTP TLS for inbound mail via MTA-STS, protecting against downgrade attacks. Queries _mta-sts.<domain> and fetches the policy file, reports mode (enforce/testing/none) and MX coverage. Use to verify whether inbound SMTP is protected against TLS downgrade or MITM — distinct from check_dane which uses TLSA pinning. Part of the scan_domain audit.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain to check (e.g., example.com) |
| force_refresh | boolean | – | Bypass cache and run a fresh check. Useful after DNS changes. |
| format | string | – | Output verbosity. Auto-detected if omitted. |
| Name | Type | Req | Description |
|---|---|---|---|
| category | string | yes | – |
| checkStatus | string | – | – |
| findings | array | yes | – |
| partial | boolean | – | – |
| passed | boolean | yes | – |
| score | number | yes | – |
No examples provided.
check_mx ~127
Look up MX records for a domain. Identifies which mail servers receive inbound email for the domain and which email hosting provider is used (Google Workspace, Microsoft 365, Proofpoint, etc.). Use when asked which email provider hosts inbound mail for a domain, or to see MX record configuration. Part of the scan_domain audit.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain to check (e.g., example.com) |
| force_refresh | boolean | – | Bypass cache and run a fresh check. Useful after DNS changes. |
| format | string | – | Output verbosity. Auto-detected if omitted. |
| Name | Type | Req | Description |
|---|---|---|---|
| category | string | yes | – |
| checkStatus | string | – | – |
| findings | array | yes | – |
| partial | boolean | – | – |
| passed | boolean | yes | – |
| score | number | yes | – |
No examples provided.
check_mx_reputation ~142
Check whether the mail server (MX) IP addresses are listed on spam blocklists (Spamhaus, Barracuda, SORBS, and other RBLs). Also verifies reverse DNS for MX hosts. Use when you want to know if your mail server IP is blacklisted, or if your MX is on any blocklist — distinct from check_rbl which checks a specific IP directly.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain to check (e.g., example.com) |
| force_refresh | boolean | – | Bypass cache and run a fresh check. Useful after DNS changes. |
| format | string | – | Output verbosity. Auto-detected if omitted. |
| Name | Type | Req | Description |
|---|---|---|---|
| category | string | yes | – |
| checkStatus | string | – | – |
| findings | array | yes | – |
| partial | boolean | – | – |
| passed | boolean | yes | – |
| score | number | yes | – |
No examples provided.
check_ns ~128
Audit a domain’s nameserver delegation and redundancy. Identifies the DNS hosting provider and, when the infrastructure probe is available, directly compares parent and child NS sets, verifies authoritative AA responses, and checks required glue addresses. Use to detect stale registrar delegations, lame nameservers, and intermittent resolution risk. Part of the scan_domain audit.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain to check (e.g., example.com) |
| force_refresh | boolean | – | Bypass cache and run a fresh check. Useful after DNS changes. |
| format | string | – | Output verbosity. Auto-detected if omitted. |
| Name | Type | Req | Description |
|---|---|---|---|
| category | string | yes | – |
| checkStatus | string | – | – |
| findings | array | yes | – |
| partial | boolean | – | – |
| passed | boolean | yes | – |
| score | number | yes | – |
No examples provided.
check_nsec_walkability ~93
Assess zone walkability risk by analyzing NSEC3PARAM configuration. Detects plain NSEC zones, weak NSEC3 parameters, and opt-out flags.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain to check (e.g., example.com) |
| force_refresh | boolean | – | Bypass cache and run a fresh check. Useful after DNS changes. |
| format | string | – | Output verbosity. Auto-detected if omitted. |
| Name | Type | Req | Description |
|---|---|---|---|
| category | string | yes | – |
| checkStatus | string | – | – |
| findings | array | yes | – |
| partial | boolean | – | – |
| passed | boolean | yes | – |
| score | number | yes | – |
No examples provided.
check_ptr ~84
Verify forward-confirmed reverse DNS (PTR/FCrDNS) for mail servers. Part of the scan_domain audit.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain to check (e.g., example.com) |
| force_refresh | boolean | – | Bypass cache and run a fresh check. Useful after DNS changes. |
| format | string | – | Output verbosity. Auto-detected if omitted. |
| Name | Type | Req | Description |
|---|---|---|---|
| category | string | yes | – |
| checkStatus | string | – | – |
| findings | array | yes | – |
| partial | boolean | – | – |
| passed | boolean | yes | – |
| score | number | yes | – |
No examples provided.
check_rbl ~103
Check MX server IP reputation against 6 DNS-based Real-time Blocklists (SpamCop, UCEProtect, Mailspike, Barracuda, PSBL). Resolves MX hosts to IPs first.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain to check (e.g., example.com) |
| force_refresh | boolean | – | Bypass cache and run a fresh check. Useful after DNS changes. |
| format | string | – | Output verbosity. Auto-detected if omitted. |
| Name | Type | Req | Description |
|---|---|---|---|
| category | string | yes | – |
| checkStatus | string | – | – |
| findings | array | yes | – |
| partial | boolean | – | – |
| passed | boolean | yes | – |
| score | number | yes | – |
No examples provided.
check_realtime_threat_feed ~105
Check a domain against BlackVeil real-time threat intelligence (curated intel-gateway feed). Distinct from DNSBL checks. Operator-deploy only; degrades to info when unprovisioned.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain to check (e.g., example.com) |
| force_refresh | boolean | – | Bypass cache and run a fresh check. Useful after DNS changes. |
| format | string | – | Output verbosity. Auto-detected if omitted. |
| Name | Type | Req | Description |
|---|---|---|---|
| category | string | yes | – |
| checkStatus | string | – | – |
| findings | array | yes | – |
| partial | boolean | – | – |
| passed | boolean | yes | – |
| score | number | yes | – |
No examples provided.
check_resolver_consistency ~75
Check DNS consistency across 4 public resolvers.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain to check (e.g., example.com) |
| format | string | – | Output verbosity. Auto-detected if omitted. |
| record_type | string | – | Record type. Omit for A/AAAA/MX/TXT/NS. |
No output schema declared.
No examples provided.
check_root_server_set ~50
Check the DNS root server set against official root hints, root glue, delegation, serial, and DNSKEY cross-root evidence.
| Name | Type | Req | Description |
|---|---|---|---|
| format | string | – | Output verbosity. Auto-detected if omitted. |
| Name | Type | Req | Description |
|---|---|---|---|
| category | string | yes | – |
| checkStatus | string | – | – |
| findings | array | yes | – |
| partial | boolean | – | – |
| passed | boolean | yes | – |
| score | number | yes | – |
No examples provided.
check_shadow_domains ~126
Find alternate TLD variants of a domain (e.g. example.net, example.co) that have weak or missing email authentication and could be used to spoof email. Use when asked about TLD variants with email auth gaps — distinct from check_lookalikes which detects typosquat/homoglyph impersonation domains.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain to check (e.g., example.com) |
| force_refresh | boolean | – | Bypass cache and run a fresh check. Useful after DNS changes. |
| format | string | – | Output verbosity. Auto-detected if omitted. |
| Name | Type | Req | Description |
|---|---|---|---|
| category | string | yes | – |
| checkStatus | string | – | – |
| findings | array | yes | – |
| partial | boolean | – | – |
| passed | boolean | yes | – |
| score | number | yes | – |
No examples provided.
check_spf ~131
Look up and validate the SPF record for a domain. Lists all IP addresses and third-party senders authorised to send email on behalf of the domain, flags syntax errors, and shows the trust surface (which mail servers are whitelisted). Use when you need to know who is permitted to send email as a domain. Part of the scan_domain audit.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain to check (e.g., example.com) |
| force_refresh | boolean | – | Bypass cache and run a fresh check. Useful after DNS changes. |
| format | string | – | Output verbosity. Auto-detected if omitted. |
| Name | Type | Req | Description |
|---|---|---|---|
| category | string | yes | – |
| checkStatus | string | – | – |
| findings | array | yes | – |
| partial | boolean | – | – |
| passed | boolean | yes | – |
| score | number | yes | – |
No examples provided.
check_srv ~151
Map a domain's DNS-visible service footprint by probing 19 common SRV record prefixes (email, calendar, messaging, directory, web) in parallel. Returns discovered services and flags insecure service advertisements — e.g. plaintext IMAP/POP3/LDAP without an encrypted variant. A domain with no matches among the probed prefixes is not proof the domain has no services at all. Use when asked to map DNS-visible services or flag insecure service advertisements.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain to check (e.g., example.com) |
| force_refresh | boolean | – | Bypass cache and run a fresh check. Useful after DNS changes. |
| format | string | – | Output verbosity. Auto-detected if omitted. |
| Name | Type | Req | Description |
|---|---|---|---|
| category | string | yes | – |
| checkStatus | string | – | – |
| findings | array | yes | – |
| partial | boolean | – | – |
| passed | boolean | yes | – |
| score | number | yes | – |
No examples provided.
check_ssl ~172
Check the HTTPS/TLS posture of a domain: HTTPS reachability, HSTS policy, and HTTP-to-HTTPS redirect. Also returns certificate metadata (issuer, expiry date, days remaining, SAN count) read from public Certificate Transparency logs — this describes the most recently LOGGED certificate, which may differ from the one currently served. Origin TLS protocol support and cipher suites are not assessed; legacy-TLS detection is withdrawn because the probe cannot observe the origin handshake. Use to verify HTTPS/HSTS configuration and certificate issuer/expiry. Part of the scan_domain audit.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain to check (e.g., example.com) |
| force_refresh | boolean | – | Bypass cache and run a fresh check. Useful after DNS changes. |
| format | string | – | Output verbosity. Auto-detected if omitted. |
| Name | Type | Req | Description |
|---|---|---|---|
| category | string | yes | – |
| checkStatus | string | – | – |
| findings | array | yes | – |
| partial | boolean | – | – |
| passed | boolean | yes | – |
| score | number | yes | – |
No examples provided.
check_subdomailing ~132
Detect SubdoMailing risk: analyzes the SPF include chain for dangling or hijackable subdomains that could let an attacker send email as the domain. Use when you want to know if an SPF include chain can be hijacked through a dangling domain, or to detect subdomain mailing risk hidden in SPF includes. Part of the scan_domain audit.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain to check (e.g., example.com) |
| force_refresh | boolean | – | Bypass cache and run a fresh check. Useful after DNS changes. |
| format | string | – | Output verbosity. Auto-detected if omitted. |
| Name | Type | Req | Description |
|---|---|---|---|
| category | string | yes | – |
| checkStatus | string | – | – |
| findings | array | yes | – |
| partial | boolean | – | – |
| passed | boolean | yes | – |
| score | number | yes | – |
No examples provided.
check_subdomain_takeover ~237
Sweep subdomains for dangling CNAMEs pointing to deprovisioned cloud services that could be claimed by an attacker (subdomain takeover vulnerabilities). Detects 16 provider families (AWS S3/CloudFront, Azure Front Door/CDN/Blob/App Service, GCP Cloud Storage, Heroku, GitHub Pages, Vercel, Firebase, Shopify, etc.). Use when asked if subdomains are pointing to deprovisioned cloud services. Pair with discover_subdomains to widen the candidate set — note that returns a CT sample, not a full inventory.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain to check (e.g., example.com). |
| force_refresh | boolean | – | Bypass cache and run a fresh check. Useful after DNS changes. |
| format | string | – | Output verbosity. Auto-detected if omitted. |
| subdomains | array | – | Optional explicit subdomain list (full FQDNs or short labels). When provided (deduped, capped at 1000), this list is swept instead of the 15-name built-in. Source from Certificate-Transparency enumer… |
| Name | Type | Req | Description |
|---|---|---|---|
| category | string | yes | – |
| checkStatus | string | – | – |
| findings | array | yes | – |
| partial | boolean | – | – |
| passed | boolean | yes | – |
| score | number | yes | – |
No examples provided.
check_svcb_https ~88
Validate HTTPS/SVCB records (RFC 9460) for modern transport capability advertisement. Part of the scan_domain audit.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain to check (e.g., example.com) |
| force_refresh | boolean | – | Bypass cache and run a fresh check. Useful after DNS changes. |
| format | string | – | Output verbosity. Auto-detected if omitted. |
| Name | Type | Req | Description |
|---|---|---|---|
| category | string | yes | – |
| checkStatus | string | – | – |
| findings | array | yes | – |
| partial | boolean | – | – |
| passed | boolean | yes | – |
| score | number | yes | – |
No examples provided.
check_tlsrpt ~149
Check whether a domain has SMTP TLS Reporting (TLS-RPT) configured. Queries _smtp._tls.<domain> for the v=TLSRPTv1 record and validates its reporting destination (rua= mailto:/https:), flagging a missing record, duplicate records, or an invalid/absent reporting URI. Complements MTA-STS by giving visibility into TLS delivery failures. Part of the scan_domain audit.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain to check (e.g., example.com) |
| force_refresh | boolean | – | Bypass cache and run a fresh check. Useful after DNS changes. |
| format | string | – | Output verbosity. Auto-detected if omitted. |
| Name | Type | Req | Description |
|---|---|---|---|
| category | string | yes | – |
| checkStatus | string | – | – |
| findings | array | yes | – |
| partial | boolean | – | – |
| passed | boolean | yes | – |
| score | number | yes | – |
No examples provided.
check_txt_hygiene ~74
Audit TXT records for stale entries and SaaS exposure.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain to check (e.g., example.com) |
| force_refresh | boolean | – | Bypass cache and run a fresh check. Useful after DNS changes. |
| format | string | – | Output verbosity. Auto-detected if omitted. |
| Name | Type | Req | Description |
|---|---|---|---|
| category | string | yes | – |
| checkStatus | string | – | – |
| findings | array | yes | – |
| partial | boolean | – | – |
| passed | boolean | yes | – |
| score | number | yes | – |
No examples provided.
check_zone_hygiene ~110
Audit DNS zone hygiene: identifies sensitive or forgotten subdomains exposed in DNS, stale SOA records, and zone propagation issues. Use to find any sensitive subdomains that should not be publicly visible, or to audit overall DNS zone cleanliness.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain to check (e.g., example.com) |
| force_refresh | boolean | – | Bypass cache and run a fresh check. Useful after DNS changes. |
| format | string | – | Output verbosity. Auto-detected if omitted. |
| Name | Type | Req | Description |
|---|---|---|---|
| category | string | yes | – |
| checkStatus | string | – | – |
| findings | array | yes | – |
| partial | boolean | – | – |
| passed | boolean | yes | – |
| score | number | yes | – |
No examples provided.
What is the BlackVeil DNS & Email Security Scanner MCP server?
BlackVeil DNS & Email Security Scanner is an MCP server listed in the public MCP registry as com.blackveilsecurity/dns. DNS and email security scanner with 80 MCP tools for SPF, DMARC, DNSSEC, SSL, and brand audits. This page covers its hosted endpoint (https://dns-mcp.blackveilsecurity.com/mcp).
Is the BlackVeil DNS & Email Security Scanner MCP server safe to use?
BlackVeil DNS & Email Security Scanner scores 81 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the BlackVeil DNS & Email Security Scanner MCP server expose?
BlackVeil DNS & Email Security Scanner exposes 80 tools: check_mx, check_spf, check_dmarc, check_dkim, check_dnssec, and 75 more. Their descriptions and schemas cost roughly 11,255 tokens of context every time the server is loaded.
Does the BlackVeil DNS & Email Security Scanner MCP server require authentication?
No. We connected to BlackVeil DNS & Email Security Scanner without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the BlackVeil DNS & Email Security Scanner MCP server still maintained?
BlackVeil DNS & Email Security Scanner is still listed as active in the MCP registry. We last reached this channel on 22 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.