Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

BlackVeil DNS & Email Security Scanner

REMOTE · DNS-MCP.BLACKVEILSECURITY.COM · SCANNED SEP 22

DNS and email security scanner with 80 MCP tools for SPF, DMARC, DNSSEC, SSL, and brand audits.

+1 this week 81 Trust /100

Recent critical change

Authorization (6 Aug 2026). See the changelog before you install this server.

Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →

Endpoint Security66
Transport & Reachability100
Schema Quality & AI Usability82
  • 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
  • AI-judged instruction clarity (excellent).Pass
  • Context-footprint check failed: tool/resource definitions use about 11475 tokens (~133/item across 86 items; 80 tools + 6 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management99
  • Stability check failed: schema churn in the 30 days we've observed: 1 tool removals, 0 breaking changes, 0 auth/transport breaks, 5 additions. See how to fix → Fail
Tool Coverage98
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 94% of tool parameters carry a description.Partial
  • Structured output schemas are declared (55% of tools); any adoption earns full credit.Pass
Tool Safety100
  • No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
  • All 1 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
  • An AI judge read all 82 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities60
  • Spec-recency check failed: implements MCP spec 2025-06-18; the latest is 2026-07-28. See how to fix → Fail
Install

How do I install the BlackVeil DNS & Email Security Scanner MCP server?

BlackVeil DNS & Email Security Scanner is a hosted endpoint at https://dns-mcp.blackveilsecurity.com/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

remote · dns-mcp.blackveilsecurity.com

# add to Claude Code
claude mcp add --transport http com-blackveilsecurity-dns 'https://dns-mcp.blackveilsecurity.com/mcp'
// .cursor/mcp.json
{
  "mcpServers": {
    "com-blackveilsecurity-dns": {
      "url": "https://dns-mcp.blackveilsecurity.com/mcp"
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "com-blackveilsecurity-dns": {
      "type": "http",
      "url": "https://dns-mcp.blackveilsecurity.com/mcp"
    }
  }
}
# ~/.codex/config.toml
[mcp_servers.com-blackveilsecurity-dns]
url = "https://dns-mcp.blackveilsecurity.com/mcp"
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "com-blackveilsecurity-dns": {
      "type": "remote",
      "url": "https://dns-mcp.blackveilsecurity.com/mcp",
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add com-blackveilsecurity-dns --url 'https://dns-mcp.blackveilsecurity.com/mcp' --transport streamable-http
# ~/.hermes/config.yaml
mcp_servers:
  com-blackveilsecurity-dns:
    url: "https://dns-mcp.blackveilsecurity.com/mcp"
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "com-blackveilsecurity-dns": {
      "Transport": "http",
      "Url": "https://dns-mcp.blackveilsecurity.com/mcp"
    }
  }
}
# add to Vellum
assistant mcp add com-blackveilsecurity-dns -t streamable-http -u 'https://dns-mcp.blackveilsecurity.com/mcp'
// mcp.json
{
  "mcpServers": {
    "com-blackveilsecurity-dns": {
      "type": "http",
      "url": "https://dns-mcp.blackveilsecurity.com/mcp"
    }
  }
}

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 21 Sept 26 0
    • Server version: 3.85.0 → 3.86.1 functional
    • Server version: 3.84.0 → 3.85.0 functional
  • 20 Sept 26 0
    • Tool “check_dane” rewrote its description, which is the text the model reads security
    • Server version: 3.83.0 → 3.84.0 functional
  • 19 Sept 26 0
    • Server version: 3.82.0 → 3.83.0 functional
  • 18 Sept 26 0
    • Tool “sge_quickscan” rewrote its description, which is the text the model reads security
    • Server version: 3.81.2 → 3.82.0 functional
  • 17 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 88 to 94.

  • 15 Sept 26 0
    • Server version: 3.81.1 → 3.81.2 functional
    • Server version: 3.81.0 → 3.81.1 functional
    • Server version: 3.80.0 → 3.81.0 functional
  • 14 Sept 26 0
    • Server version: 3.79.0 → 3.80.0 functional
    • Server version: 3.78.0 → 3.79.0 functional
    • New tool “sge_quickscan” functional
  • 9 Sept 26 0
    • Tool “prioritize_csc_leads” was removed security
    • Server version: 3.77.0 → 3.78.0 functional
    • New tool “prioritize_portfolio_leads” functional
    • “brand_audit_batch_start” reworded the description of “view” cosmetic
    • “brand_audit_single” reworded the description of “view” cosmetic
Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 22 Sept 2026 · Probed https://dns-mcp.blackveilsecurity.com/mcp

TLS valid

Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .

Subject Issuer Valid from Valid until Key Signature Serial
CN=blackveilsecurity.com CN=WE1,O=Google Trust Services,C=US 22 Aug 2026 20 Nov 2026 ECDSA 256 ECDSA-SHA256 f7b1b2d7918c822f0ec60d1ffbf06454
SANs: blackveilsecurity.com, dns-mcp.blackveilsecurity.com
CN=WE1,O=Google Trust Services,C=US (CA) CN=GTS Root R4,O=Google Trust Services LLC,C=US 13 Dec 2023 20 Feb 2029 ECDSA 256 ECDSA-SHA384 7ff31977972c224a76155d13b6d685e3
CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE 15 Nov 2023 28 Jan 2028 ECDSA 384 SHA256-RSA 7fe530bf331343bedd821610493d8a1b

Background: What to check on a remote MCP endpoint →

DNSSEC secure

Validation of dns-mcp.blackveilsecurity.com. Secure

Zone DS Keys Algorithms Outcome
. trust_anchor 20326, 38696 8, 8 Verified
com. present 19718 13 Verified
blackveilsecurity.com. present 2371 13 Verified
dns-mcp.blackveilsecurity.com. Verified address RRset verified with the apex keys
Authentication No authorisation required

The endpoint answered without asking for a token. Anyone who knows the URL can reach it.

Result No authorisation required
HTTP status 200
Header Value
strict-transport-security max-age=63072000; includeSubDomains; preload
content-security-policy default-src 'self'; script-src 'none'; style-src 'self' 'unsafe-inline'; object-src 'none'; frame-ancestors 'none'; form-action 'self'
x-content-type-options nosniff
x-frame-options DENY
referrer-policy no-referrer
permissions-policy geolocation=(), microphone=(), camera=()

Background: How OAuth 2.1 works in the 2026 MCP spec →

Transports 2 probes
Transport URL Outcome Status Location
streamable-http https://dns-mcp.blackveilsecurity.com/mcp Verified 200
http (plaintext) http://dns-mcp.blackveilsecurity.com/mcp HTTPS enforced 301 https://dns-mcp.blackveilsecurity.com/mcp
MCP tools · 80 exposed · ~11,255 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
compare_baseline ~176

Compare a domain's current security configuration against a fixed policy baseline to determine compliance. Use to check whether a domain meets a policy requirement — not for tracking improvement/regression over time (use analyze_drift) and not for comparing multiple domains (use compare_domains).

NameTypeReqDescription
baselineobjectyesPolicy/requirements baseline OBJECT for compliance enforcement — "does this domain meet these required controls?" (grade/score floors, require_* flags, max_*_findings). NOT a prior scan. For drift-ov…
domainstringyesDomain to scan and compare.
force_refreshbooleanBypass cache and run a fresh check. Useful after DNS changes.
formatstringOutput verbosity. Auto-detected if omitted.

No output schema declared.

No examples provided.

compare_domains ~106

Side-by-side security comparison of 2–5 domains. Shows relative scores, category gaps, and unique weaknesses for each domain. Use when comparing your security posture against a competitor, or doing a head-to-head comparison between multiple domains.

NameTypeReqDescription
domainsarrayyesDomains to compare (2–5 domains)
force_refreshbooleanBypass cache and run a fresh check. Useful after DNS changes.
formatstringOutput verbosity. Auto-detected if omitted.

No output schema declared.

No examples provided.

cymru_asn ~97

Map domain IPs to Autonomous System Numbers via Team Cymru DNS. Returns ASN, prefix, country, registry, and organization for each IP. Flags high-risk hosting ASNs.

NameTypeReqDescription
domainstringyesDomain to check (e.g., example.com)
force_refreshbooleanBypass cache and run a fresh check. Useful after DNS changes.
formatstringOutput verbosity. Auto-detected if omitted.
NameTypeReqDescription
categorystringyes
checkStatusstring
findingsarrayyes
partialboolean
passedbooleanyes
scorenumberyes

No examples provided.

delete_brand_audit_watch ~62

Permanently removes a recurring brand-audit watch by watchId. Owner-scoped — a watchId owned by another principal surfaces as notFound. Returns confirmation of deletion.

NameTypeReqDescription
watchIdstringyesWatch ID returned by register_brand_audit_watch.
NameTypeReqDescription
categorystringyes
checkStatusstring
findingsarrayyes
partialboolean
passedbooleanyes
scorenumberyes

No examples provided.

discover_brand_domains ~518

Discover all domains that belong to a brand's portfolio by aggregating certificate, DNS, redirect, and mail-policy signals. Use when asked what domains are part of a brand portfolio, or to find all domains related to a brand. Pass the EXACT seed domain verbatim — do NOT normalize or substitute a canonical domain.

NameTypeReqDescription
brand_aliasesarrayOptional public brand aliases to seed, such as product or legal-entity labels.
candidate_domainsarrayOptional candidate domains supplied by the caller for corroboration.
depthstringDiscovery depth. standard is default; deep expands candidate seeding and enrichment fanout.
discovery_modestringyesDiscovery mode. "classic" (default, BSL-licensed) runs the public signal-sweep pipeline. "tiered" layers Tier 0 (tenant-declared portfolio), Tier 1 (infrastructure-graph), and Tier 2 (declared-eviden…
dkim_selectorsarrayOptional DKIM selectors to probe. Defaults to a built-in common-selector list.
domainstringyesThe exact seed domain to expand, scanned verbatim (e.g., example.com). Do NOT normalize, resolve, or substitute a brand's canonical/main domain — pass the literal domain the user named (e.g. pass `cl…
force_refreshbooleanBypass cache and run a fresh check. Useful after DNS changes.
formatstringOutput verbosity. Auto-detected if omitted.
min_confidencenumberDrop candidates whose combined confidence falls below this threshold (0-1, default 0.5).
ownership_verifiedbooleanCaller attests that the seed domain is owned or authorized for scanning. Required when discovery_mode is "tiered" and the caller is not an enterprise/owner/partner principal. Prevents unauthorized ma…
planner_modestringPlanner mode for staged discovery fanout. observe emits metrics; enforce applies candidate-backed signal caps.
signalsarraySignal modules to invoke. Defaults to all 12 discovery/enrichment signals.
NameTypeReqDescription
categorystringyes
checkStatusstring
findingsarrayyes
partialboolean
passedbooleanyes
scorenumberyes

No examples provided.

discover_brand_domains_findings ~70

Fetch the ranked candidate domains (the discovery CheckResult) for an async run started with discover_brand_domains_start. Returns notReady while the discovery is still in-flight; the discovery result once complete. Owner-scoped.

NameTypeReqDescription
operationIdstringyesOperation ID returned by discover_brand_domains_start.

No output schema declared.

No examples provided.

discover_brand_domains_start ~528

Start an async brand-domain discovery for the EXACT seed domain provided (the async sibling of discover_brand_domains, which can run ~24s and time out interactive clients). Same args as discover_brand_domains. Returns { auditId, queuedAt, etaSeconds } immediately; poll with discover_brand_domains_status and fetch ranked candidates with discover_brand_domains_findings once complete.

NameTypeReqDescription
brand_aliasesarrayOptional public brand aliases to seed, such as product or legal-entity labels.
candidate_domainsarrayOptional candidate domains supplied by the caller for corroboration.
depthstringDiscovery depth. standard is default; deep expands candidate seeding and enrichment fanout.
discovery_modestringyesDiscovery mode. "classic" (default, BSL-licensed) runs the public signal-sweep pipeline. "tiered" layers Tier 0 (tenant-declared portfolio), Tier 1 (infrastructure-graph), and Tier 2 (declared-eviden…
dkim_selectorsarrayOptional DKIM selectors to probe. Defaults to a built-in common-selector list.
domainstringyesThe exact seed domain to expand, scanned verbatim (e.g., example.com). Do NOT normalize, resolve, or substitute a brand's canonical/main domain — pass the literal domain the user named (e.g. pass `cl…
force_refreshbooleanBypass cache and run a fresh check. Useful after DNS changes.
formatstringOutput verbosity. Auto-detected if omitted.
min_confidencenumberDrop candidates whose combined confidence falls below this threshold (0-1, default 0.5).
ownership_verifiedbooleanCaller attests that the seed domain is owned or authorized for scanning. Required when discovery_mode is "tiered" and the caller is not an enterprise/owner/partner principal. Prevents unauthorized ma…
planner_modestringPlanner mode for staged discovery fanout. observe emits metrics; enforce applies candidate-backed signal caps.
signalsarraySignal modules to invoke. Defaults to all 12 discovery/enrichment signals.

No output schema declared.

No examples provided.

discover_brand_domains_status ~71

Poll the status of an async brand-domain discovery started with discover_brand_domains_start. Returns status (queued | running | completed | failed) and progress. Owner-scoped — operationIds owned by other principals surface as notFound.

NameTypeReqDescription
operationIdstringyesOperation ID returned by discover_brand_domains_start.

No output schema declared.

No examples provided.

discover_subdomains ~183

Find subdomains of a domain using Certificate Transparency logs. Reveals shadow IT, forgotten services, and unauthorized certificate issuance. Returns a CT SAMPLE, not an asset inventory: the count is a lower bound, a host with no publicly-logged certificate never appears, and the result carries a per-source `coverage` record stating what was actually consulted. `countBasis` says whether `totalSubdomains` is the tool’s normal reach (`sample`) or a `floor` from a run whose recall was cut (then `minSubdomainsObserved` is present); `concreteSubdomains` excludes wildcard patterns.

NameTypeReqDescription
domainstringyesDomain to check (e.g., example.com)
force_refreshbooleanBypass cache and run a fresh check. Useful after DNS changes.
formatstringOutput verbosity. Auto-detected if omitted.

No output schema declared.

No examples provided.

explain_finding ~76

Explain a finding with impact and remediation.

NameTypeReqDescription
checkTypestringyesCheck type (e.g., 'SPF', 'DMARC').
detailsstringAdditional detail from check result.
formatstringOutput verbosity. Auto-detected if omitted.
statusstringyesFinding severity or status.

No output schema declared.

No examples provided.

generate ~315

Generate a DNS/email security remediation artifact. Artifact types: spf_record (build a new SPF record), dmarc_record (create a DMARC policy), dkim_config (DKIM key setup), mta_sts_policy (generate an MTA-STS policy file), fix_plan (prioritized remediation plan for all findings), or rollout_plan (phased DMARC enforcement timeline). Use when asked to generate or create a record or policy.

NameTypeReqDescription
artifactstringyesWhich artifact to generate (e.g., "dmarc_record", "fix_plan").
domainstringyesDomain (e.g., example.com)
force_refreshbooleanfix_plan: bypass cache and run a fresh scan.
formatstringOutput verbosity. Auto-detected if omitted.
include_providersarrayspf_record: providers to include (e.g., ["google"]).
mx_hostsarraymta_sts_policy: MX hosts. Omit to detect from DNS.
policystringdmarc_record: policy (default "reject").
providerstringdkim_config: provider (e.g., "google"). Omit for generic.
rua_emailstringdmarc_record: report email. Default: dmarc-reports@{domain}.
target_policystringrollout_plan: target DMARC policy (default: reject).
timelinestringrollout_plan: rollout speed (default: standard).

No output schema declared.

No examples provided.

get_benchmark ~109

Get industry benchmark data: shows what percentile a domain's security score ranks at within its sector or country cohort, the mean score, and the most common DNS security failures across the industry. Use when asked how a score compares to the industry average, what percentile a score is in, or what the most common security failures are in an industry or sector.

NameTypeReqDescription
formatstringOutput verbosity. Auto-detected if omitted.
profilestringProfile to benchmark (default "mail_enabled").

No output schema declared.

No examples provided.

get_domain_rank ~188

Rank a domain against its country or global cohort using the GSI benchmark corpus. Accepts a domain score (from scan_domain) and optional country/sector; returns a percentile: "scores better than X% of peers". Owner-gate exempt — public cohort data only.

NameTypeReqDescription
countrystringISO 3166-1 alpha-2 country code to use the country cohort (e.g., "NZ"). Omit for global cohort.
domainstringyesDomain to rank against its cohort (e.g., example.com)
formatstringOutput verbosity. Auto-detected if omitted.
scorenumberyesDomain score (0–100) from scan_domain. Used to compute the cohort percentile.
sectorstringSector label (e.g., "finance"). Forwarded to the cohort endpoint; sector filtering is planned for a future release.

No output schema declared.

No examples provided.

get_provider_insights ~111

Get security benchmarks and common configuration issues for a specific email or DNS service-provider cohort (e.g. Google Workspace customers, Microsoft 365 customers). Use when asked how an email service provider compares to competitors on security posture, or to see typical misconfigurations for a named vendor's customers.

NameTypeReqDescription
formatstringOutput verbosity. Auto-detected if omitted.
profilestringProfile (default "mail_enabled").
providerstringyesProvider (e.g., "google workspace").

No output schema declared.

No examples provided.

list_brand_audit_watches ~47

Returns the caller's recurring brand-audit watches: watchId, domain, interval, webhook presence, last-run time, and active state. Owner-scoped. Read-only.

Input schema present but exposes no named parameters.

NameTypeReqDescription
categorystringyes
checkStatusstring
findingsarrayyes
partialboolean
passedbooleanyes
scorenumberyes

No examples provided.

map_compliance ~99

Map scan findings to compliance frameworks: NIST 800-177, PCI DSS 4.0, SOC 2, CIS Controls. Shows pass/fail/partial status per control.

NameTypeReqDescription
domainstringyesDomain to check (e.g., example.com)
force_refreshbooleanBypass cache and run a fresh check. Useful after DNS changes.
formatstringOutput verbosity. Auto-detected if omitted.

No output schema declared.

No examples provided.

map_supply_chain ~139

Map DNS-visible third-party service dependencies for a domain. Correlates SPF, NS, TXT verifications, SRV services, and CAA records to reveal which third-party vendors can send email as the domain, control DNS, or access integrated services. Use when asked to map third-party or supply-chain dependencies — not for listing who can send email (use check_spf for that).

NameTypeReqDescription
domainstringyesDomain to check (e.g., example.com)
force_refreshbooleanBypass cache and run a fresh check. Useful after DNS changes.
formatstringOutput verbosity. Auto-detected if omitted.

No output schema declared.

No examples provided.

osint_investigate_domain_start ~70

Start an async OSINT investigation for a domain. Operator-deploy only; degrades to info when unprovisioned. Returns an investigationId immediately — poll with osint_investigation_status and retrieve results with osint_investigation_report.

NameTypeReqDescription
querystringyes

No output schema declared.

No examples provided.

osint_investigate_email_start ~79

Start an async OSINT investigation for an email address (breach exposure, account correlation). Owner/enterprise tier only — people-centric OSINT is restricted to prevent misuse. Returns an investigationId immediately — poll with osint_investigation_status and retrieve results with osint_investigation_report.

NameTypeReqDescription
querystringyes

No output schema declared.

No examples provided.

osint_investigate_infrastructure_start ~71

Start an async deep-infrastructure OSINT investigation for a query (domain, IP, or org). Operator-deploy only; degrades to info when unprovisioned. Returns an investigationId immediately — poll with osint_investigation_status.

NameTypeReqDescription
querystringyes

No output schema declared.

No examples provided.

osint_investigate_supply_chain_start ~63

Start an async supply-chain OSINT investigation for a query. Operator-deploy only; degrades to info when unprovisioned. Returns an investigationId immediately — poll with osint_investigation_status.

NameTypeReqDescription
querystringyes

No output schema declared.

No examples provided.

osint_investigate_username_start ~78

Start an async OSINT investigation for a username (cross-platform presence, breach correlation). Owner/enterprise tier only — people-centric OSINT is restricted to prevent misuse. Returns an investigationId immediately — poll with osint_investigation_status and retrieve results with osint_investigation_report.

NameTypeReqDescription
querystringyes

No output schema declared.

No examples provided.

osint_investigation_report ~53

Retrieve the final report of a completed OSINT investigation by investigationId. Operator-deploy only; degrades to info when unprovisioned or not yet complete.

NameTypeReqDescription
investigationIdstringyes

No output schema declared.

No examples provided.

osint_investigation_status ~61

Poll the status of an OSINT investigation by investigationId. Operator-deploy only; degrades to info when unprovisioned. Returns current status (running | completed | failed) and progress metadata.

NameTypeReqDescription
investigationIdstringyes

No output schema declared.

No examples provided.

prioritize_portfolio_leads ~150

Rank a brand’s portfolio (or an explicit domain set) into prioritized registrar-partner sales leads by product-gap value × severity. Multi-domain, paid. Reuses map_registrar_products per domain, then ranks. Distinct from map_registrar_products (per-domain product mapping) and batch_scan (raw scores).

NameTypeReqDescription
brandstringBrand seed apex; discovers the portfolio, derives ownership buckets, then ranks the top candidates.
domainsarrayExplicit domain set to rank (max 10). Ownership bucket = "unknown".
force_refreshbooleanBypass cache and run fresh scans.
formatstringOutput verbosity. Auto-detected if omitted.

No output schema declared.

No examples provided.

rdap_lookup ~136

Fetch domain registration data via RDAP (modern WHOIS replacement). Returns the domain registrar (the company the domain was registered with), registrant contact, creation/expiration dates, EPP status codes, and domain age. Use when asked who registered the domain, who the registrar is, or when the registration expires — distinct from check_ns which identifies the DNS nameserver provider.

NameTypeReqDescription
domainstringyesDomain to check (e.g., example.com)
force_refreshbooleanBypass cache and run a fresh check. Useful after DNS changes.
formatstringOutput verbosity. Auto-detected if omitted.
NameTypeReqDescription
categorystringyes
checkStatusstring
findingsarrayyes
partialboolean
passedbooleanyes
scorenumberyes

No examples provided.

register_brand_audit_watch ~128

Creates a recurring brand-audit watch for a domain on a daily/weekly/monthly cadence. Each run enqueues a fresh brand_audit_batch_start and (when a webhook is configured) POSTs a diff webhook on classification drift. Returns the new watchId. Owner-scoped; per-principal cap of 20 active watches.

NameTypeReqDescription
domainstringyesDomain to watch.
intervalstringyesRecurrence interval.
webhook_urlstringOptional webhook URL — POSTed on classification drift. Re-validated for SSRF at both register and delivery time.
NameTypeReqDescription
categorystringyes
checkStatusstring
findingsarrayyes
partialboolean
passedbooleanyes
scorenumberyes

No examples provided.

resolve_spf_chain ~98

Trace the full SPF include chain for a domain. Recursively resolves all includes, shows lookup count, tree depth, and flags circular includes or exceeding the 10-lookup limit.

NameTypeReqDescription
domainstringyesDomain to check (e.g., example.com)
force_refreshbooleanBypass cache and run a fresh check. Useful after DNS changes.
formatstringOutput verbosity. Auto-detected if omitted.

No output schema declared.

No examples provided.

scan_buckets_findings ~82

Retrieve findings from a completed cloud-bucket discovery scan by scanId. Operator-deploy only; degrades to info when unprovisioned. The scanId is required so reads can be owner-scoped; target and provider filters are optional.

NameTypeReqDescription
providersarray
scanIdstringyes
targetstring

No output schema declared.

No examples provided.

scan_buckets_start ~75

Start an async cloud-bucket discovery scan for a target domain. Operator-deploy only; degrades to info when unprovisioned. Returns a scanId immediately — poll progress with scan_buckets_status and retrieve results with scan_buckets_findings.

NameTypeReqDescription
providersarray
targetstringyes

No output schema declared.

No examples provided.

scan_buckets_status ~61

Poll the status of a cloud-bucket discovery scan by scanId. Operator-deploy only; degrades to info when unprovisioned. Returns scan status (running | completed | failed) and progress metadata.

NameTypeReqDescription
scanIdstringyes

No output schema declared.

No examples provided.

scan_domain ~292

Run a full DNS and email security audit for a single domain. Aggregates every scan-included check in parallel (SPF, DKIM, DMARC, DNSSEC, TLS/SSL, MTA-STS, CAA, BIMI, subdomain takeover, and more) and returns an overall security score, NIST-aligned letter grade (6-band A+/A/B/C/D/F), maturity stage, and prioritized findings. Use for a comprehensive single-domain audit, to get a domain's overall security grade, or to assess email security maturity. Version stamps: 'scoringModelVersion' is the scoring POLICY semver (changes only when weights/thresholds/severities change, so it advances slowly) and is INDEPENDENT of — never comparable to — 'dnsChecksPackageVersion', the @blackveil/dns-checks npm engine-package version, which moves every release; a lower model version is expected, not a version gap. When citing a score, record 'scoringConfigHash' — it identifies the exact scoring configuration that produced the result.

NameTypeReqDescription
domainstringyesDomain to check (e.g., example.com)
force_refreshbooleanBypass cache and run a fresh scan. Useful after DNS changes.
formatstringOutput verbosity. Auto-detected if omitted.
profilestringScoring profile. Default "auto" detects.

No output schema declared.

No examples provided.

sge_quickscan ~211

Answer, for ONE domain, whether it meets the New Zealand Secure Government Email (SGE) requirements agencies must satisfy by October 2026. Reports all seven SGE controls — DMARC p=reject, SPF -all, DKIM, SMTP transport TLS, MTA-STS enforce, TLS-RPT, full sub-domain coverage — each as satisfied, not satisfied, or NOT MEASURED, with the structured evidence behind every verdict. Neither SMTP transport TLS nor sub-domain coverage can be observed from a single domain scan, so a DNS-only result tops out at INDETERMINATE, which is not a pass. Distinct from map_compliance, which maps findings to NIST/PCI/SOC 2/CIS.

NameTypeReqDescription
domainstringyesDomain to check (e.g., example.com)
force_refreshbooleanBypass cache and run a fresh check. Useful after DNS changes.
formatstringOutput verbosity. Auto-detected if omitted.

No output schema declared.

No examples provided.

simulate_attack_paths ~87

Analyze current DNS posture and enumerate specific attack paths an adversary could exploit, with severity, feasibility, steps, and mitigations.

NameTypeReqDescription
domainstringyesDomain to check (e.g., example.com)
force_refreshbooleanBypass cache and run a fresh check. Useful after DNS changes.
formatstringOutput verbosity. Auto-detected if omitted.

No output schema declared.

No examples provided.

validate_fix ~121

Re-check a specific security control after applying a fix, to confirm the finding is now resolved. Use only when a fix has already been applied and you want to verify or confirm the remediation was successful — not for initial inspection of a record.

NameTypeReqDescription
checkstringyesCheck name to re-run (e.g., "dmarc", "spf")
domainstringyesDomain to validate the fix for
expectedstringExpected DNS record value to verify against
formatstringOutput verbosity. Auto-detected if omitted.

No output schema declared.

No examples provided.

Common questions

What is the BlackVeil DNS & Email Security Scanner MCP server?

BlackVeil DNS & Email Security Scanner is an MCP server listed in the public MCP registry as com.blackveilsecurity/dns. DNS and email security scanner with 80 MCP tools for SPF, DMARC, DNSSEC, SSL, and brand audits. This page covers its hosted endpoint (https://dns-mcp.blackveilsecurity.com/mcp).

Is the BlackVeil DNS & Email Security Scanner MCP server safe to use?

BlackVeil DNS & Email Security Scanner scores 81 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

What tools does the BlackVeil DNS & Email Security Scanner MCP server expose?

BlackVeil DNS & Email Security Scanner exposes 80 tools: check_mx, check_spf, check_dmarc, check_dkim, check_dnssec, and 75 more. Their descriptions and schemas cost roughly 11,255 tokens of context every time the server is loaded.

Does the BlackVeil DNS & Email Security Scanner MCP server require authentication?

No. We connected to BlackVeil DNS & Email Security Scanner without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.

Is the BlackVeil DNS & Email Security Scanner MCP server still maintained?

BlackVeil DNS & Email Security Scanner is still listed as active in the MCP registry. We last reached this channel on 22 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.