BlackVeil DNS & Email Security Scanner
REMOTE · DNS-MCP.BLACKVEILSECURITY.COM · SCANNED SEP 22
DNS and email security scanner with 80 MCP tools for SPF, DMARC, DNSSEC, SSL, and brand audits.
Available components
Recent critical change
Authorization (6 Aug 2026). See the changelog before you install this server.
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security66
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation check failed: no authorisation is required to call this server, and it exposes a tool marked destructive (delete_brand_audit_watch). See how to fix → View diagnostics → Fail
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC is configured correctly; the domain's records validate against the full chain to the root. View diagnostics → Pass
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability82
- 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 11475 tokens (~133/item across 86 items; 80 tools + 6 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management99
- Stability check failed: schema churn in the 30 days we've observed: 1 tool removals, 0 breaking changes, 0 auth/transport breaks, 5 additions. See how to fix → Fail
Tool Coverage98
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 94% of tool parameters carry a description.Partial
- Structured output schemas are declared (55% of tools); any adoption earns full credit.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- All 1 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
- An AI judge read all 82 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities60
- Spec-recency check failed: implements MCP spec 2025-06-18; the latest is 2026-07-28. See how to fix → Fail
How do I install the BlackVeil DNS & Email Security Scanner MCP server?
BlackVeil DNS & Email Security Scanner is a hosted endpoint at https://dns-mcp.blackveilsecurity.com/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · dns-mcp.blackveilsecurity.com
claude mcp add --transport http com-blackveilsecurity-dns 'https://dns-mcp.blackveilsecurity.com/mcp'
{
"mcpServers": {
"com-blackveilsecurity-dns": {
"url": "https://dns-mcp.blackveilsecurity.com/mcp"
}
}
} {
"servers": {
"com-blackveilsecurity-dns": {
"type": "http",
"url": "https://dns-mcp.blackveilsecurity.com/mcp"
}
}
} [mcp_servers.com-blackveilsecurity-dns] url = "https://dns-mcp.blackveilsecurity.com/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"com-blackveilsecurity-dns": {
"type": "remote",
"url": "https://dns-mcp.blackveilsecurity.com/mcp",
"enabled": true
}
}
} openclaw mcp add com-blackveilsecurity-dns --url 'https://dns-mcp.blackveilsecurity.com/mcp' --transport streamable-http
mcp_servers:
com-blackveilsecurity-dns:
url: "https://dns-mcp.blackveilsecurity.com/mcp" {
"McpServers": {
"com-blackveilsecurity-dns": {
"Transport": "http",
"Url": "https://dns-mcp.blackveilsecurity.com/mcp"
}
}
} assistant mcp add com-blackveilsecurity-dns -t streamable-http -u 'https://dns-mcp.blackveilsecurity.com/mcp'
{
"mcpServers": {
"com-blackveilsecurity-dns": {
"type": "http",
"url": "https://dns-mcp.blackveilsecurity.com/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 21 Sept 26 0
- Server version: 3.85.0 → 3.86.1 functional
- Server version: 3.84.0 → 3.85.0 functional
- 20 Sept 26 0
- Tool “check_dane” rewrote its description, which is the text the model reads security
- Server version: 3.83.0 → 3.84.0 functional
- 19 Sept 26 0
- Server version: 3.82.0 → 3.83.0 functional
- 18 Sept 26 0
- Tool “sge_quickscan” rewrote its description, which is the text the model reads security
- Server version: 3.81.2 → 3.82.0 functional
- 17 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 88 to 94.
- 15 Sept 26 0
- Server version: 3.81.1 → 3.81.2 functional
- Server version: 3.81.0 → 3.81.1 functional
- Server version: 3.80.0 → 3.81.0 functional
- 14 Sept 26 0
- Server version: 3.79.0 → 3.80.0 functional
- Server version: 3.78.0 → 3.79.0 functional
- New tool “sge_quickscan” functional
- 9 Sept 26 0
- Tool “prioritize_csc_leads” was removed ▼ security
- Server version: 3.77.0 → 3.78.0 functional
- New tool “prioritize_portfolio_leads” functional
- “brand_audit_batch_start” reworded the description of “view” cosmetic
- “brand_audit_single” reworded the description of “view” cosmetic
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 22 Sept 2026 · Probed https://dns-mcp.blackveilsecurity.com/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=blackveilsecurity.com | CN=WE1,O=Google Trust Services,C=US | 22 Aug 2026 | 20 Nov 2026 | ECDSA 256 | ECDSA-SHA256 | f7b1b2d7918c822f0ec60d1ffbf06454 |
| SANs: blackveilsecurity.com, dns-mcp.blackveilsecurity.com | ||||||
| CN=WE1,O=Google Trust Services,C=US (CA) | CN=GTS Root R4,O=Google Trust Services LLC,C=US | 13 Dec 2023 | 20 Feb 2029 | ECDSA 256 | ECDSA-SHA384 | 7ff31977972c224a76155d13b6d685e3 |
| CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) | CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE | 15 Nov 2023 | 28 Jan 2028 | ECDSA 384 | SHA256-RSA | 7fe530bf331343bedd821610493d8a1b |
Background: What to check on a remote MCP endpoint →
DNSSEC secure
Validation of dns-mcp.blackveilsecurity.com. — Secure
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| com. | present | 19718 | 13 | Verified |
| blackveilsecurity.com. | present | 2371 | 13 | Verified |
| dns-mcp.blackveilsecurity.com. | Verified address RRset verified with the apex keys |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
| Header | Value |
|---|---|
| strict-transport-security | max-age=63072000; includeSubDomains; preload |
| content-security-policy | default-src 'self'; script-src 'none'; style-src 'self' 'unsafe-inline'; object-src 'none'; frame-ancestors 'none'; form-action 'self' |
| x-content-type-options | nosniff |
| x-frame-options | DENY |
| referrer-policy | no-referrer |
| permissions-policy | geolocation=(), microphone=(), camera=() |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://dns-mcp.blackveilsecurity.com/mcp | Verified | 200 | |
| http (plaintext) | http://dns-mcp.blackveilsecurity.com/mcp | HTTPS enforced | 301 | https://dns-mcp.blackveilsecurity.com/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
compare_baseline ~176
Compare a domain's current security configuration against a fixed policy baseline to determine compliance. Use to check whether a domain meets a policy requirement — not for tracking improvement/regression over time (use analyze_drift) and not for comparing multiple domains (use compare_domains).
| Name | Type | Req | Description |
|---|---|---|---|
| baseline | object | yes | Policy/requirements baseline OBJECT for compliance enforcement — "does this domain meet these required controls?" (grade/score floors, require_* flags, max_*_findings). NOT a prior scan. For drift-ov… |
| domain | string | yes | Domain to scan and compare. |
| force_refresh | boolean | – | Bypass cache and run a fresh check. Useful after DNS changes. |
| format | string | – | Output verbosity. Auto-detected if omitted. |
No output schema declared.
No examples provided.
compare_domains ~106
Side-by-side security comparison of 2–5 domains. Shows relative scores, category gaps, and unique weaknesses for each domain. Use when comparing your security posture against a competitor, or doing a head-to-head comparison between multiple domains.
| Name | Type | Req | Description |
|---|---|---|---|
| domains | array | yes | Domains to compare (2–5 domains) |
| force_refresh | boolean | – | Bypass cache and run a fresh check. Useful after DNS changes. |
| format | string | – | Output verbosity. Auto-detected if omitted. |
No output schema declared.
No examples provided.
cymru_asn ~97
Map domain IPs to Autonomous System Numbers via Team Cymru DNS. Returns ASN, prefix, country, registry, and organization for each IP. Flags high-risk hosting ASNs.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain to check (e.g., example.com) |
| force_refresh | boolean | – | Bypass cache and run a fresh check. Useful after DNS changes. |
| format | string | – | Output verbosity. Auto-detected if omitted. |
| Name | Type | Req | Description |
|---|---|---|---|
| category | string | yes | – |
| checkStatus | string | – | – |
| findings | array | yes | – |
| partial | boolean | – | – |
| passed | boolean | yes | – |
| score | number | yes | – |
No examples provided.
delete_brand_audit_watch ~62
Permanently removes a recurring brand-audit watch by watchId. Owner-scoped — a watchId owned by another principal surfaces as notFound. Returns confirmation of deletion.
| Name | Type | Req | Description |
|---|---|---|---|
| watchId | string | yes | Watch ID returned by register_brand_audit_watch. |
| Name | Type | Req | Description |
|---|---|---|---|
| category | string | yes | – |
| checkStatus | string | – | – |
| findings | array | yes | – |
| partial | boolean | – | – |
| passed | boolean | yes | – |
| score | number | yes | – |
No examples provided.
discover_brand_domains ~518
Discover all domains that belong to a brand's portfolio by aggregating certificate, DNS, redirect, and mail-policy signals. Use when asked what domains are part of a brand portfolio, or to find all domains related to a brand. Pass the EXACT seed domain verbatim — do NOT normalize or substitute a canonical domain.
| Name | Type | Req | Description |
|---|---|---|---|
| brand_aliases | array | – | Optional public brand aliases to seed, such as product or legal-entity labels. |
| candidate_domains | array | – | Optional candidate domains supplied by the caller for corroboration. |
| depth | string | – | Discovery depth. standard is default; deep expands candidate seeding and enrichment fanout. |
| discovery_mode | string | yes | Discovery mode. "classic" (default, BSL-licensed) runs the public signal-sweep pipeline. "tiered" layers Tier 0 (tenant-declared portfolio), Tier 1 (infrastructure-graph), and Tier 2 (declared-eviden… |
| dkim_selectors | array | – | Optional DKIM selectors to probe. Defaults to a built-in common-selector list. |
| domain | string | yes | The exact seed domain to expand, scanned verbatim (e.g., example.com). Do NOT normalize, resolve, or substitute a brand's canonical/main domain — pass the literal domain the user named (e.g. pass `cl… |
| force_refresh | boolean | – | Bypass cache and run a fresh check. Useful after DNS changes. |
| format | string | – | Output verbosity. Auto-detected if omitted. |
| min_confidence | number | – | Drop candidates whose combined confidence falls below this threshold (0-1, default 0.5). |
| ownership_verified | boolean | – | Caller attests that the seed domain is owned or authorized for scanning. Required when discovery_mode is "tiered" and the caller is not an enterprise/owner/partner principal. Prevents unauthorized ma… |
| planner_mode | string | – | Planner mode for staged discovery fanout. observe emits metrics; enforce applies candidate-backed signal caps. |
| signals | array | – | Signal modules to invoke. Defaults to all 12 discovery/enrichment signals. |
| Name | Type | Req | Description |
|---|---|---|---|
| category | string | yes | – |
| checkStatus | string | – | – |
| findings | array | yes | – |
| partial | boolean | – | – |
| passed | boolean | yes | – |
| score | number | yes | – |
No examples provided.
discover_brand_domains_findings ~70
Fetch the ranked candidate domains (the discovery CheckResult) for an async run started with discover_brand_domains_start. Returns notReady while the discovery is still in-flight; the discovery result once complete. Owner-scoped.
| Name | Type | Req | Description |
|---|---|---|---|
| operationId | string | yes | Operation ID returned by discover_brand_domains_start. |
No output schema declared.
No examples provided.
discover_brand_domains_start ~528
Start an async brand-domain discovery for the EXACT seed domain provided (the async sibling of discover_brand_domains, which can run ~24s and time out interactive clients). Same args as discover_brand_domains. Returns { auditId, queuedAt, etaSeconds } immediately; poll with discover_brand_domains_status and fetch ranked candidates with discover_brand_domains_findings once complete.
| Name | Type | Req | Description |
|---|---|---|---|
| brand_aliases | array | – | Optional public brand aliases to seed, such as product or legal-entity labels. |
| candidate_domains | array | – | Optional candidate domains supplied by the caller for corroboration. |
| depth | string | – | Discovery depth. standard is default; deep expands candidate seeding and enrichment fanout. |
| discovery_mode | string | yes | Discovery mode. "classic" (default, BSL-licensed) runs the public signal-sweep pipeline. "tiered" layers Tier 0 (tenant-declared portfolio), Tier 1 (infrastructure-graph), and Tier 2 (declared-eviden… |
| dkim_selectors | array | – | Optional DKIM selectors to probe. Defaults to a built-in common-selector list. |
| domain | string | yes | The exact seed domain to expand, scanned verbatim (e.g., example.com). Do NOT normalize, resolve, or substitute a brand's canonical/main domain — pass the literal domain the user named (e.g. pass `cl… |
| force_refresh | boolean | – | Bypass cache and run a fresh check. Useful after DNS changes. |
| format | string | – | Output verbosity. Auto-detected if omitted. |
| min_confidence | number | – | Drop candidates whose combined confidence falls below this threshold (0-1, default 0.5). |
| ownership_verified | boolean | – | Caller attests that the seed domain is owned or authorized for scanning. Required when discovery_mode is "tiered" and the caller is not an enterprise/owner/partner principal. Prevents unauthorized ma… |
| planner_mode | string | – | Planner mode for staged discovery fanout. observe emits metrics; enforce applies candidate-backed signal caps. |
| signals | array | – | Signal modules to invoke. Defaults to all 12 discovery/enrichment signals. |
No output schema declared.
No examples provided.
discover_brand_domains_status ~71
Poll the status of an async brand-domain discovery started with discover_brand_domains_start. Returns status (queued | running | completed | failed) and progress. Owner-scoped — operationIds owned by other principals surface as notFound.
| Name | Type | Req | Description |
|---|---|---|---|
| operationId | string | yes | Operation ID returned by discover_brand_domains_start. |
No output schema declared.
No examples provided.
discover_subdomains ~183
Find subdomains of a domain using Certificate Transparency logs. Reveals shadow IT, forgotten services, and unauthorized certificate issuance. Returns a CT SAMPLE, not an asset inventory: the count is a lower bound, a host with no publicly-logged certificate never appears, and the result carries a per-source `coverage` record stating what was actually consulted. `countBasis` says whether `totalSubdomains` is the tool’s normal reach (`sample`) or a `floor` from a run whose recall was cut (then `minSubdomainsObserved` is present); `concreteSubdomains` excludes wildcard patterns.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain to check (e.g., example.com) |
| force_refresh | boolean | – | Bypass cache and run a fresh check. Useful after DNS changes. |
| format | string | – | Output verbosity. Auto-detected if omitted. |
No output schema declared.
No examples provided.
explain_finding ~76
Explain a finding with impact and remediation.
| Name | Type | Req | Description |
|---|---|---|---|
| checkType | string | yes | Check type (e.g., 'SPF', 'DMARC'). |
| details | string | – | Additional detail from check result. |
| format | string | – | Output verbosity. Auto-detected if omitted. |
| status | string | yes | Finding severity or status. |
No output schema declared.
No examples provided.
generate ~315
Generate a DNS/email security remediation artifact. Artifact types: spf_record (build a new SPF record), dmarc_record (create a DMARC policy), dkim_config (DKIM key setup), mta_sts_policy (generate an MTA-STS policy file), fix_plan (prioritized remediation plan for all findings), or rollout_plan (phased DMARC enforcement timeline). Use when asked to generate or create a record or policy.
| Name | Type | Req | Description |
|---|---|---|---|
| artifact | string | yes | Which artifact to generate (e.g., "dmarc_record", "fix_plan"). |
| domain | string | yes | Domain (e.g., example.com) |
| force_refresh | boolean | – | fix_plan: bypass cache and run a fresh scan. |
| format | string | – | Output verbosity. Auto-detected if omitted. |
| include_providers | array | – | spf_record: providers to include (e.g., ["google"]). |
| mx_hosts | array | – | mta_sts_policy: MX hosts. Omit to detect from DNS. |
| policy | string | – | dmarc_record: policy (default "reject"). |
| provider | string | – | dkim_config: provider (e.g., "google"). Omit for generic. |
| rua_email | string | – | dmarc_record: report email. Default: dmarc-reports@{domain}. |
| target_policy | string | – | rollout_plan: target DMARC policy (default: reject). |
| timeline | string | – | rollout_plan: rollout speed (default: standard). |
No output schema declared.
No examples provided.
get_benchmark ~109
Get industry benchmark data: shows what percentile a domain's security score ranks at within its sector or country cohort, the mean score, and the most common DNS security failures across the industry. Use when asked how a score compares to the industry average, what percentile a score is in, or what the most common security failures are in an industry or sector.
| Name | Type | Req | Description |
|---|---|---|---|
| format | string | – | Output verbosity. Auto-detected if omitted. |
| profile | string | – | Profile to benchmark (default "mail_enabled"). |
No output schema declared.
No examples provided.
get_domain_rank ~188
Rank a domain against its country or global cohort using the GSI benchmark corpus. Accepts a domain score (from scan_domain) and optional country/sector; returns a percentile: "scores better than X% of peers". Owner-gate exempt — public cohort data only.
| Name | Type | Req | Description |
|---|---|---|---|
| country | string | – | ISO 3166-1 alpha-2 country code to use the country cohort (e.g., "NZ"). Omit for global cohort. |
| domain | string | yes | Domain to rank against its cohort (e.g., example.com) |
| format | string | – | Output verbosity. Auto-detected if omitted. |
| score | number | yes | Domain score (0–100) from scan_domain. Used to compute the cohort percentile. |
| sector | string | – | Sector label (e.g., "finance"). Forwarded to the cohort endpoint; sector filtering is planned for a future release. |
No output schema declared.
No examples provided.
get_provider_insights ~111
Get security benchmarks and common configuration issues for a specific email or DNS service-provider cohort (e.g. Google Workspace customers, Microsoft 365 customers). Use when asked how an email service provider compares to competitors on security posture, or to see typical misconfigurations for a named vendor's customers.
| Name | Type | Req | Description |
|---|---|---|---|
| format | string | – | Output verbosity. Auto-detected if omitted. |
| profile | string | – | Profile (default "mail_enabled"). |
| provider | string | yes | Provider (e.g., "google workspace"). |
No output schema declared.
No examples provided.
list_brand_audit_watches ~47
Returns the caller's recurring brand-audit watches: watchId, domain, interval, webhook presence, last-run time, and active state. Owner-scoped. Read-only.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| category | string | yes | – |
| checkStatus | string | – | – |
| findings | array | yes | – |
| partial | boolean | – | – |
| passed | boolean | yes | – |
| score | number | yes | – |
No examples provided.
map_compliance ~99
Map scan findings to compliance frameworks: NIST 800-177, PCI DSS 4.0, SOC 2, CIS Controls. Shows pass/fail/partial status per control.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain to check (e.g., example.com) |
| force_refresh | boolean | – | Bypass cache and run a fresh check. Useful after DNS changes. |
| format | string | – | Output verbosity. Auto-detected if omitted. |
No output schema declared.
No examples provided.
map_supply_chain ~139
Map DNS-visible third-party service dependencies for a domain. Correlates SPF, NS, TXT verifications, SRV services, and CAA records to reveal which third-party vendors can send email as the domain, control DNS, or access integrated services. Use when asked to map third-party or supply-chain dependencies — not for listing who can send email (use check_spf for that).
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain to check (e.g., example.com) |
| force_refresh | boolean | – | Bypass cache and run a fresh check. Useful after DNS changes. |
| format | string | – | Output verbosity. Auto-detected if omitted. |
No output schema declared.
No examples provided.
osint_investigate_domain_start ~70
Start an async OSINT investigation for a domain. Operator-deploy only; degrades to info when unprovisioned. Returns an investigationId immediately — poll with osint_investigation_status and retrieve results with osint_investigation_report.
| Name | Type | Req | Description |
|---|---|---|---|
| query | string | yes | – |
No output schema declared.
No examples provided.
osint_investigate_email_start ~79
Start an async OSINT investigation for an email address (breach exposure, account correlation). Owner/enterprise tier only — people-centric OSINT is restricted to prevent misuse. Returns an investigationId immediately — poll with osint_investigation_status and retrieve results with osint_investigation_report.
| Name | Type | Req | Description |
|---|---|---|---|
| query | string | yes | – |
No output schema declared.
No examples provided.
osint_investigate_infrastructure_start ~71
Start an async deep-infrastructure OSINT investigation for a query (domain, IP, or org). Operator-deploy only; degrades to info when unprovisioned. Returns an investigationId immediately — poll with osint_investigation_status.
| Name | Type | Req | Description |
|---|---|---|---|
| query | string | yes | – |
No output schema declared.
No examples provided.
osint_investigate_supply_chain_start ~63
Start an async supply-chain OSINT investigation for a query. Operator-deploy only; degrades to info when unprovisioned. Returns an investigationId immediately — poll with osint_investigation_status.
| Name | Type | Req | Description |
|---|---|---|---|
| query | string | yes | – |
No output schema declared.
No examples provided.
osint_investigate_username_start ~78
Start an async OSINT investigation for a username (cross-platform presence, breach correlation). Owner/enterprise tier only — people-centric OSINT is restricted to prevent misuse. Returns an investigationId immediately — poll with osint_investigation_status and retrieve results with osint_investigation_report.
| Name | Type | Req | Description |
|---|---|---|---|
| query | string | yes | – |
No output schema declared.
No examples provided.
osint_investigation_report ~53
Retrieve the final report of a completed OSINT investigation by investigationId. Operator-deploy only; degrades to info when unprovisioned or not yet complete.
| Name | Type | Req | Description |
|---|---|---|---|
| investigationId | string | yes | – |
No output schema declared.
No examples provided.
osint_investigation_status ~61
Poll the status of an OSINT investigation by investigationId. Operator-deploy only; degrades to info when unprovisioned. Returns current status (running | completed | failed) and progress metadata.
| Name | Type | Req | Description |
|---|---|---|---|
| investigationId | string | yes | – |
No output schema declared.
No examples provided.
prioritize_portfolio_leads ~150
Rank a brand’s portfolio (or an explicit domain set) into prioritized registrar-partner sales leads by product-gap value × severity. Multi-domain, paid. Reuses map_registrar_products per domain, then ranks. Distinct from map_registrar_products (per-domain product mapping) and batch_scan (raw scores).
| Name | Type | Req | Description |
|---|---|---|---|
| brand | string | – | Brand seed apex; discovers the portfolio, derives ownership buckets, then ranks the top candidates. |
| domains | array | – | Explicit domain set to rank (max 10). Ownership bucket = "unknown". |
| force_refresh | boolean | – | Bypass cache and run fresh scans. |
| format | string | – | Output verbosity. Auto-detected if omitted. |
No output schema declared.
No examples provided.
rdap_lookup ~136
Fetch domain registration data via RDAP (modern WHOIS replacement). Returns the domain registrar (the company the domain was registered with), registrant contact, creation/expiration dates, EPP status codes, and domain age. Use when asked who registered the domain, who the registrar is, or when the registration expires — distinct from check_ns which identifies the DNS nameserver provider.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain to check (e.g., example.com) |
| force_refresh | boolean | – | Bypass cache and run a fresh check. Useful after DNS changes. |
| format | string | – | Output verbosity. Auto-detected if omitted. |
| Name | Type | Req | Description |
|---|---|---|---|
| category | string | yes | – |
| checkStatus | string | – | – |
| findings | array | yes | – |
| partial | boolean | – | – |
| passed | boolean | yes | – |
| score | number | yes | – |
No examples provided.
register_brand_audit_watch ~128
Creates a recurring brand-audit watch for a domain on a daily/weekly/monthly cadence. Each run enqueues a fresh brand_audit_batch_start and (when a webhook is configured) POSTs a diff webhook on classification drift. Returns the new watchId. Owner-scoped; per-principal cap of 20 active watches.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain to watch. |
| interval | string | yes | Recurrence interval. |
| webhook_url | string | – | Optional webhook URL — POSTed on classification drift. Re-validated for SSRF at both register and delivery time. |
| Name | Type | Req | Description |
|---|---|---|---|
| category | string | yes | – |
| checkStatus | string | – | – |
| findings | array | yes | – |
| partial | boolean | – | – |
| passed | boolean | yes | – |
| score | number | yes | – |
No examples provided.
resolve_spf_chain ~98
Trace the full SPF include chain for a domain. Recursively resolves all includes, shows lookup count, tree depth, and flags circular includes or exceeding the 10-lookup limit.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain to check (e.g., example.com) |
| force_refresh | boolean | – | Bypass cache and run a fresh check. Useful after DNS changes. |
| format | string | – | Output verbosity. Auto-detected if omitted. |
No output schema declared.
No examples provided.
scan_buckets_findings ~82
Retrieve findings from a completed cloud-bucket discovery scan by scanId. Operator-deploy only; degrades to info when unprovisioned. The scanId is required so reads can be owner-scoped; target and provider filters are optional.
| Name | Type | Req | Description |
|---|---|---|---|
| providers | array | – | – |
| scanId | string | yes | – |
| target | string | – | – |
No output schema declared.
No examples provided.
scan_buckets_start ~75
Start an async cloud-bucket discovery scan for a target domain. Operator-deploy only; degrades to info when unprovisioned. Returns a scanId immediately — poll progress with scan_buckets_status and retrieve results with scan_buckets_findings.
| Name | Type | Req | Description |
|---|---|---|---|
| providers | array | – | – |
| target | string | yes | – |
No output schema declared.
No examples provided.
scan_buckets_status ~61
Poll the status of a cloud-bucket discovery scan by scanId. Operator-deploy only; degrades to info when unprovisioned. Returns scan status (running | completed | failed) and progress metadata.
| Name | Type | Req | Description |
|---|---|---|---|
| scanId | string | yes | – |
No output schema declared.
No examples provided.
scan_domain ~292
Run a full DNS and email security audit for a single domain. Aggregates every scan-included check in parallel (SPF, DKIM, DMARC, DNSSEC, TLS/SSL, MTA-STS, CAA, BIMI, subdomain takeover, and more) and returns an overall security score, NIST-aligned letter grade (6-band A+/A/B/C/D/F), maturity stage, and prioritized findings. Use for a comprehensive single-domain audit, to get a domain's overall security grade, or to assess email security maturity. Version stamps: 'scoringModelVersion' is the scoring POLICY semver (changes only when weights/thresholds/severities change, so it advances slowly) and is INDEPENDENT of — never comparable to — 'dnsChecksPackageVersion', the @blackveil/dns-checks npm engine-package version, which moves every release; a lower model version is expected, not a version gap. When citing a score, record 'scoringConfigHash' — it identifies the exact scoring configuration that produced the result.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain to check (e.g., example.com) |
| force_refresh | boolean | – | Bypass cache and run a fresh scan. Useful after DNS changes. |
| format | string | – | Output verbosity. Auto-detected if omitted. |
| profile | string | – | Scoring profile. Default "auto" detects. |
No output schema declared.
No examples provided.
sge_quickscan ~211
Answer, for ONE domain, whether it meets the New Zealand Secure Government Email (SGE) requirements agencies must satisfy by October 2026. Reports all seven SGE controls — DMARC p=reject, SPF -all, DKIM, SMTP transport TLS, MTA-STS enforce, TLS-RPT, full sub-domain coverage — each as satisfied, not satisfied, or NOT MEASURED, with the structured evidence behind every verdict. Neither SMTP transport TLS nor sub-domain coverage can be observed from a single domain scan, so a DNS-only result tops out at INDETERMINATE, which is not a pass. Distinct from map_compliance, which maps findings to NIST/PCI/SOC 2/CIS.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain to check (e.g., example.com) |
| force_refresh | boolean | – | Bypass cache and run a fresh check. Useful after DNS changes. |
| format | string | – | Output verbosity. Auto-detected if omitted. |
No output schema declared.
No examples provided.
simulate_attack_paths ~87
Analyze current DNS posture and enumerate specific attack paths an adversary could exploit, with severity, feasibility, steps, and mitigations.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain to check (e.g., example.com) |
| force_refresh | boolean | – | Bypass cache and run a fresh check. Useful after DNS changes. |
| format | string | – | Output verbosity. Auto-detected if omitted. |
No output schema declared.
No examples provided.
validate_fix ~121
Re-check a specific security control after applying a fix, to confirm the finding is now resolved. Use only when a fix has already been applied and you want to verify or confirm the remediation was successful — not for initial inspection of a record.
| Name | Type | Req | Description |
|---|---|---|---|
| check | string | yes | Check name to re-run (e.g., "dmarc", "spf") |
| domain | string | yes | Domain to validate the fix for |
| expected | string | – | Expected DNS record value to verify against |
| format | string | – | Output verbosity. Auto-detected if omitted. |
No output schema declared.
No examples provided.
What is the BlackVeil DNS & Email Security Scanner MCP server?
BlackVeil DNS & Email Security Scanner is an MCP server listed in the public MCP registry as com.blackveilsecurity/dns. DNS and email security scanner with 80 MCP tools for SPF, DMARC, DNSSEC, SSL, and brand audits. This page covers its hosted endpoint (https://dns-mcp.blackveilsecurity.com/mcp).
Is the BlackVeil DNS & Email Security Scanner MCP server safe to use?
BlackVeil DNS & Email Security Scanner scores 81 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the BlackVeil DNS & Email Security Scanner MCP server expose?
BlackVeil DNS & Email Security Scanner exposes 80 tools: check_mx, check_spf, check_dmarc, check_dkim, check_dnssec, and 75 more. Their descriptions and schemas cost roughly 11,255 tokens of context every time the server is loaded.
Does the BlackVeil DNS & Email Security Scanner MCP server require authentication?
No. We connected to BlackVeil DNS & Email Security Scanner without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the BlackVeil DNS & Email Security Scanner MCP server still maintained?
BlackVeil DNS & Email Security Scanner is still listed as active in the MCP registry. We last reached this channel on 22 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.