BlackVeil DNS & Email Security Scanner MCP Tools
BlackVeil DNS & Email Security Scanner exposes 80 tools. Each one has its own page with the configuration for every client that can run this server.
-
check_mxRead-onlycheck mx
-
check_spfRead-onlycheck spf
-
check_dmarcRead-onlycheck dmarc
-
check_dkimRead-onlycheck dkim
-
check_dnssecRead-onlycheck dnssec
-
check_sslRead-onlycheck ssl
-
check_mta_stsRead-onlycheck mta sts
-
check_nsRead-onlycheck ns
-
check_caaRead-onlycheck caa
-
check_bimiRead-onlycheck bimi
-
check_tlsrptRead-onlycheck tlsrpt
-
check_http_securityRead-onlycheck http security
-
check_daneRead-onlycheck dane
-
check_ptrRead-onlycheck ptr
-
check_dane_httpsRead-onlycheck dane https
-
check_svcb_httpsRead-onlycheck svcb https
-
check_lookalikesRead-onlycheck lookalikes
-
check_subdomailingRead-onlycheck subdomailing
-
scan_domainscan domain
-
batch_scanbatch scan
-
batch_scan_startbatch scan start
-
batch_scan_statusbatch scan status
-
batch_scan_findingsbatch scan findings
-
compare_domainscompare domains
-
compare_baselinecompare baseline
-
check_shadow_domainsRead-onlycheck shadow domains
-
check_txt_hygieneRead-onlycheck txt hygiene
-
check_mx_reputationRead-onlycheck mx reputation
-
check_srvRead-onlycheck srv
-
check_zone_hygieneRead-onlycheck zone hygiene
-
generategenerate
-
get_domain_rankRead-onlyget domain rank
-
get_benchmarkRead-onlyget benchmark
-
get_provider_insightsRead-onlyget provider insights
-
assess_spoofabilityassess spoofability
-
check_resolver_consistencyRead-onlycheck resolver consistency
-
explain_findingexplain finding
-
map_supply_chainmap supply chain
-
analyze_driftanalyze drift
-
validate_fixvalidate fix
-
resolve_spf_chainRead-onlyresolve spf chain
-
discover_subdomainsdiscover subdomains
-
map_compliancemap compliance
-
sge_quickscansge quickscan
-
prioritize_portfolio_leadsprioritize portfolio leads
-
simulate_attack_pathssimulate attack paths
-
check_dblRead-onlycheck dbl
-
check_rblRead-onlycheck rbl
-
cymru_asncymru asn
-
rdap_lookuprdap lookup
-
check_realtime_threat_feedRead-onlycheck realtime threat feed
-
check_nsec_walkabilityRead-onlycheck nsec walkability
-
check_dnssec_chainRead-onlycheck dnssec chain
-
check_agent_discoveryRead-onlycheck agent discovery
-
check_dnskey_strengthRead-onlycheck dnskey strength
-
check_fast_fluxRead-onlycheck fast flux
-
check_subdomain_takeoverRead-onlycheck subdomain takeover
-
check_authoritative_dns_infraRead-onlycheck authoritative dns infra
-
check_root_server_setRead-onlycheck root server set
-
discover_brand_domainsdiscover brand domains
-
discover_brand_domains_startdiscover brand domains start
-
discover_brand_domains_statusdiscover brand domains status
-
discover_brand_domains_findingsdiscover brand domains findings
-
brand_audit_singlebrand audit single
-
brand_audit_batch_startbrand audit batch start
-
brand_audit_statusbrand audit status
-
brand_audit_get_reportbrand audit get report
-
list_brand_audit_watchesRead-onlylist brand audit watches
-
register_brand_audit_watchregister brand audit watch
-
delete_brand_audit_watchMutatingdelete brand audit watch
-
scan_buckets_startscan buckets start
-
scan_buckets_statusscan buckets status
-
scan_buckets_findingsscan buckets findings
-
osint_investigate_domain_startosint investigate domain start
-
osint_investigate_infrastructure_startosint investigate infrastructure start
-
osint_investigate_supply_chain_startosint investigate supply chain start
-
osint_investigate_username_startosint investigate username start
-
osint_investigate_email_startosint investigate email start
-
osint_investigation_statusosint investigation status
-
osint_investigation_reportosint investigation report
This list was read from the server itself, by connecting to it and calling tools/list on 24 September 2026. It is what
the server actually exposes, not what its listing claims.
Mutating and Read-only are read off each tool's name, not its schema — a hint, not a guarantee. The registry stores tool names only; connect the server for its live schemas.