DNSSEC health report: key inventory, signature expiry, algorithm assessment, DS at parent, rollover readiness, full chain of trust (Root → TLD → Domain) with chain_intact flag and broken-link identification, warnings, and recommendations.
resolve_check
DNS resolution diagnostics. Returns status: ok / nxdomain / nodata / servfail / refused / timeout / degraded.
diagnose
Full diagnosis combining resolution + DNSSEC. Use first when something is broken.
propagation_check
Check DNS propagation across 16 global resolvers: Google, Cloudflare, Quad9, China, Korea, Russia.
mx_check
MX health + provider detection: Google Workspace, M365, Proofpoint, Zoho, 35+ providers.
domain_status
Registrar lock and EPP status. Checks transfer lock, delete lock, serverHold, pendingDelete.
geo_lookup
Geolocation and hosting: country, city, ISP, ASN, CDN detection, is_hosting flag.
What this means. This server responded to the MCP handshake and listed its tools without authentication. The schema fingerprint lets us flag if tool signatures silently change (schema drift) between checks.