ID
IntoDNS.ai DNS & Email Security Scanner
20 endpointsliveDNS and email security: check SPF, DKIM, DMARC, DNSSEC, DANE and build the records. 45 tools. (MCP server ai.intodns/scanner, aggregated from the official registry)
$Set up https://cracked-ai-pearl.vercel.app/SKILL.md, and then use Cracked to show me what I can do for IntoDNS.ai DNS & Email Security Scanner.
| Endpoint | What it does | Price | Health |
|---|---|---|---|
| scan domain /scan_domain | Run the fast IntoDNS.ai DNS and email security scan (~3-8s). Returns a letter grade A+ to F, numeric score 0-100, structured issue list, prioritised recommendat | $0.0020 per call | unknown |
| nis2 quickscan /nis2_quickscan | Compute a NIS2 Article 21.2 readiness score for a domain by mapping the IntoDNS quickscan onto the ten NIS2 measures. Returns a 0-100 weighted total, per-measur | $0.0020 per call | unknown |
| get everything report /get_everything_report | Generate the complete live IntoDNS.ai report covering DNS, email authentication, web/HTTPS, blacklist reputation, sender requirements, and canonical citation UR | $0.0020 per call | unknown |
| create report snapshot /create_report_snapshot | Create an immutable evidence snapshot of the current Everything Report for a domain. Returns a snapshot ID, ISO timestamp, SHA-256 content hash, and stable book | $0.0020 per call | unknown |
| get report snapshot /get_report_snapshot | Read a previously created IntoDNS.ai Everything Report evidence snapshot by snapshot ID. Read-only GET — returns the immutable JSON report exactly as it was at | $0.0020 per call | unknown |
| start deep scan /start_deep_scan | Start a long-running Internet.nl deep scan (typically 30-120s). Returns a `scanId` immediately; poll get_deep_scan_status until status='finished'. Read-only — n | $0.0020 per call | unknown |
| get deep scan status /get_deep_scan_status | Read-only status poll for a long-running Internet.nl deep scan. Returns scan progress (pending/running/finished), category scores, per-test results, and any fai | $0.0020 per call | unknown |
| cancel deep scan /cancel_deep_scan | Cancel an in-progress Internet.nl deep scan. Idempotent DELETE — safe to call even if scan already finished or never started (returns acknowledgement either way | $0.0020 per call | unknown |
| lookup dns /lookup_dns | Read-only DNS record lookup via DNS-over-HTTPS. Pass `type` for a single record type or `types` for an array; if both omitted, returns A records. Returns parsed | $0.0020 per call | unknown |
| validate dnssec /validate_dnssec | Read-only DNSSEC chain validation. Walks the DS/DNSKEY chain from root, checks signatures, algorithm strength, key rollover state, and reports any broken links | $0.0020 per call | unknown |
| check dns propagation /check_dns_propagation | Compare DNS responses across the nine currently configured public and authoritative resolvers to detect propagation lag, missing answers, or inconsistent TTL/da | $0.0020 per call | unknown |
| check tlsa dane /check_tlsa_dane | Read-only TLSA/DANE DNS record check. With no port, resolves MX hosts and validates their `_25._tcp` TLSA tuple syntax; with an explicit port, queries `_<port>. | $0.0020 per call | unknown |
| check spf /check_spf | Read-only SPF parse and validation for a domain. Recursively walks include/redirect mechanisms to build the full lookup graph, counts DNS lookups against the RF | $0.0020 per call | unknown |
| flatten spf /flatten_spf | Read-only SPF flattening for a domain. Resolves the full include/a/mx/redirect graph to literal ip4/ip6 addresses and returns a single flattened SPF record that | $0.0020 per call | unknown |
| discover dkim /discover_dkim | Read-only DKIM check for a domain. Without `selector`, heuristically queries 50 common selectors and explicitly reports that a miss is inconclusive because DKIM | $0.0020 per call | unknown |
| check dmarc /check_dmarc | Read-only fetch and parse of the _dmarc TXT record. Returns parsed tag map (p, sp, rua, ruf, adkim, aspf, pct, fo), policy strength assessment, alignment mode, | $0.0020 per call | unknown |
| check bimi /check_bimi | Read-only BIMI readiness check. Parses the `default._bimi` TXT record, safely fetches the referenced HTTPS SVG, and parses basic metadata from an optional VMC/C | $0.0020 per call | unknown |
| check mta sts /check_mta_sts | Read-only check of MTA-STS: TXT record at _mta-sts.<domain> plus the HTTPS policy file at mta-sts.<domain>/.well-known/mta-sts.txt. Returns parsed policy (mode: | $0.0020 per call | unknown |
| check smtp tls /check_smtp_tls | Live check of every MX host: opens TCP 25, runs EHLO + STARTTLS, validates TLS certificate trust chain, hostname match, expiry window, advertised EHLO capabilit | $0.0020 per call | unknown |
| check fcrdns /check_fcrdns | Read-only FCrDNS (Forward-Confirmed Reverse DNS) audit for every IP that backs the domain's MX records. For each IP: looks up PTR record, then resolves that PTR | $0.0020 per call | unknown |