Every change Wellknown observed on this MCP server, newest first, with what it was before and what it became. Tool-surface changes carry the definition diff. Nothing here is edited after the fact.
Added "base64_decode", "base64_encode", "dossier_summary" and 5 more; removed "dossier_full"; changed the definition of "dns_lookup", "dossier_ai_crawlers", "dossier_cors" and 18 more (22 tools before, 29 now)
before
—after
DNS lookupContext lookup:Resolvea singleone DNS record type (A, AAAA, MX, TXT, NS, CNAME, SOA, CAA,or SRV) for a name and return the raw answers. Use for a quick, targetedlookupslookup,ofincludingoneonrecordsubdomainstype;and names such as _dmarc.example.com; prefer dossier_dns for afull multi-typedomain'sDNSmainauditrecords inparallel, or dossier_full for a complete domain healthonecheck.call. Queries CloudflareDoH (1.1.1.1/dns-query) over HTTPS, follows CNAME chains, 5 s timeout.DNS-over-HTTPS. Returns a JSON array ofanswer objects with{name, type,andTTL, data};fields.anOnemptyerror,arrayreturnsmeansathestringnamedescribingexiststhebutDNShasfailure.no record of that type.
{"$schema":"http://json-schema.org/draft-07/schema#","additionalProperties":false,"properties":{"name":{"description":"Domain name or hostnameName to resolve, e.g. example.com or mail.example.com.FQDN preferred; relative labels are accepted.","type":"string"},"type":{"description":"DNS recordRecord type to query.Common choices: A (IPv4), AAAA (IPv6), MX (mail), TXT (SPF/DKIM/verification), NS (nameservers), CNAME (alias).","enum":["A","AAAA","MX","TXT","NS","CNAME","SOA","CAA","SRV"],"type":"string"}},"required" ⟨4 unchanged words⟩
before
—after
{"openWorldHint":true,"readOnlyHint":true}before
—after
AI-crawler policyCore dossier check:Report what a domain'sAI-crawler policy — whetherrobots.txtallows, blocks, or is silentsaysonto thesixmajor AIagentscrawlers (GPTBot, ClaudeBot, Google-Extended, PerplexityBot, CCBot, meta-externalagent).: allowed, blocked or unspecified for each. Use to answer"doeswhetherthisa
before
—after
CORS checkerCore dossier check:Send a CORS preflight (OPTIONSrequest) to https://<domain>/ and return the access-control-*response headers. Use to verify CORS policy for aheadersspecificinorigin-methodthepair,answer.orUse to check whether adomainsiteallowsaccepts cross-origin
before
—after
Certificate log lookupCoreListdossiersubdomainscheck:ofDiscoverasubdomainsdomainvisiblethat appear in Certificate Transparency logs. Usefortoattack-surfacemapmapping;what
before
—after
DKIM lookupCore dossier check:Probe adomain'sdomain for DKIM public keysbyatquerying<selector>._domainkey.<domain>.<selector>._domainkey.<domain>Passforselectorseachwhenselector.youUseknowto
before
—after
DMARC checkerCore dossier check: RetrieveFind and parsea domain'sthe DMARC policyfrom itsat _dmarc.<domain>TXT record, returning all tags. Use to audit email authentication policy,intoverifyitsthetags (p,(policy)sp,andpct, rua,
before
—after
DNS recordsCore dossier check:Fetch a domain'sfull DNS profile —A, AAAA, NS, SOA, CAA,and TXT records— allinparallel.one call. Use as the first step of adomain audit or when you need a comprehensiveDNSsnapshot in one call;review; prefer dns_lookup for a single record type,ordossier_fullforall 10 dossierMX,checksCNAMEat
before
—after
DNSSEC checkerCoreCheckdossierwhethercheck:aVerifydomain'sDNSSECzonechain-of-trustisforsignedawithdomainDNSSEC(and validates:
before
—after
Security headersCore dossier check:Fetch https://<domain>/ and returnall HTTPevery responseheadersheader,with an audit highlighting missing or misconfigured security headers.soUseyoutocan reviewCSPStrict-Transport-Security,HSTSContent-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy,andPermissions-Policy;
before
—after
llms.txt checkerCore dossier check: DetectCheck whether a domain publishes an llms.txtat its,rootthe—markdowntheindexemergingsomeconventionsitesthatprovidegivesfor AIagents
before
—after
MTA-STS checkerCore dossier check:Fetch and validate a domain's MTA-STS policy (mode, mx, max_age, policy id). Use to confirm inboundSMTPmailistolockedthetodomainTLSmustforbethisdelivereddomain.over TLS.
before
—after
MX lookupCore dossier check: Look upList a domain's MX (mail exchanger) recordsand return themsortedascendingby priority. Usewhen verifying inbound-mail routing or as a precursortoSPF or DMARC checks; prefer dns_lookup with type=MXseeifwhereyouaonlydomain'sneedinboundthemailraw
before
—after
Redirect chainCore dossier check:Trace thefull HTTPredirect chainstartingfrom https://<domain>/,recordingoneeachentryhop'sper hop with its status code anddestinationtarget,URL.up to 10 hops. Use to debug redirect loops,verify HTTP→HTTPS upgrades,oraudit link shorteners; stops at
before
—after
security.txt checkerCore dossier check:CheckVerifywhether a domain publishesa security.txt/.well-known/security.txt (RFC 9116)at /.well-known/security.txt —, the standardmachine-readablewaychanneltofortellreportingresearchersvulnerabilities.whereUse
before
—after
SPF checkerCore dossier check: RetrieveFind and parse a domain's SPF record,decomposing itintomechanisms anditsqualifiers.mechanisms. Use toverifychecksenderserverspolicy,maydebugsenddelivery
before
—after
TLS certificateCore dossier check: Fetch and inspectRead the TLS certificatepresented bya domain presents on port 443: subject,returningissuer,chainvaliditydetailsdates,anddaysvalidityremaining,period.subjectUsealternative
before
—after
TLS-RPT checkerCore dossier check:Look up a domain'sTLS-RPT (SMTP TLS Reporting)policy.policy at _smtp._tls.<domain>. Use to confirm the domain receives reportsofaboutSMTP-TLSfailedfailures.TLSResolvesdelivery_smtp._tls.<domain>ofTXTits
before
—after
Web surfaceCore dossier check: SnapshotSummarise a domain's public web surface: robots.txt, sitemap.xml,and thehome-page <head>homemetadatapage's(title, description, OpenGraph,and Twittercards).card tags. Use forSEO audits,acontentquickdiscovery,
before
—after
WHOIS lookupCore dossier check:Look upthea domain's registrar, creation date, expiry date,and registrystatusesstatuses.forUseafordomain.anUseownershipfororownership/expiryexpiry
before
—after
IP lookupContext lookup:LookResolveup an IPv4 or IPv6 address:tocity,itsregion,geolocationcountry,ASNcoordinates,orgtimezonename,and the network (ASN andcity/country.organisation)
before
—after
User agent parserContext lookup:Parse a User-Agent headerstringintostructuredbrowser,OSoperating system, devicetype,andrendering-enginerenderingcomponents.engine. Useto identify client capabilities from a raw UA string, e.g.whenanalysingreading server logs or requestheaders; does not perform any network lookups — entirely local parsing.headers. Runssynchronously using the ua-parser-js library
Base64 decode — Decode base64 to UTF-8 text. Accepts the standard and the URL-safe alphabet, with or without padding or line breaks. Fails when the input is not valid base64 or does not decode to text (binary data is not returned). Runs locally.
Base64 encode — Encode UTF-8 text as base64. Set url_safe for the URL-safe alphabet (- and _ in place of + and /, no padding), as used in JSON Web Tokens. Runs locally. Returns the encoded string.
Domain summary (9 checks) — Run the nine DNS, email-authentication and TLS checks on a domain in parallel and return one graded line per check: DNS records, MX, SPF, DMARC, DKIM, DNSSEC, TLS-RPT, MTA-STS and the TLS certificate. Use it first when asked how a domain is set up or whether its email can be spoofed; then call the single dossier_* tool for any check you need the raw data for. Each line has the check id, its status, a severity (info, low, medium, high, critical) and a one-line reason, graded by the same rules as Domain Posture. It does not return raw records or fix instructions, and it leaves out the nine web …
JSON formatter — Validate JSON and re-print it with an indent of 2 or 4 spaces, or minified with indent 0. Use to check whether a string is valid JSON or to make it readable. Runs locally. Returns the formatted JSON, or the parser's error message.
JWT decoder — Decode a JSON Web Token's header and payload. It does NOT verify the signature, so never treat the claims as trusted on the strength of this tool. Use to inspect claims such as exp, iss and aud while debugging. Runs locally; the token is not stored or sent anywhere. Returns JSON {header, payload, signature}.
URL decode — Decode percent-encoded text. Fails on a malformed sequence such as a lone % sign. A plus sign is left as a plus; replace it with a space first if the text came from an HTML form. Runs locally.
URL encode — Percent-encode text for use in a URL query value or path segment (encodeURIComponent rules: everything except letters, digits and - _ . ! ~ * ' ( ) is encoded). Runs locally. Returns the encoded string.
UUID generator — Generate UUIDs. Version 4 is fully random. Version 7 starts with a millisecond timestamp, so values sort by creation time, which suits database keys. Runs locally with a cryptographic random source. Returns a JSON array of strings.
Aggregate dossier check: Run all 10 Domain Dossier checks — dns, mx, spf, dmarc, dkim, tls, redirects, headers, cors, web-surface — in parallel and return all results in a single response. Use when you need a comprehensive domain health snapshot in one call; counts as ONE paywall call regardless of how many checks run. For a single focused check, prefer the individual dossier_* tools to minimise latency. Fires all 10 checks concurrently via Cloudflare DoH or direct HTTPS, 5 s per-check timeout. Returns a JSON object keyed by check id (dns, mx, etc.), each value a CheckResult discriminated uni…
Certificate recorded, valid to 2026-11-11
Authorization not required
Recently observed → Live
First tool surface recorded: 22 tools (server version 0.1.0)
Live → Recently observed
Showing the latest 6 events. The API returns up to 500 and filters by kind: ?kind=tool_surface_changed
{"$schema":"http://json-schema.org/draft-07/schema#","additionalProperties":false,"properties":{"domain":{"description":"PublicFQDNdomain name, e.g. example.com.Must be resolvable on the public internet;IPIPsaddresses, ports, paths,and protocol prefixes are rejected.","type": ⟨5 unchanged words⟩
before
—after
{"openWorldHint":true,"readOnlyHint":true}{"$schema":"http://json-schema.org/draft-07/schema#","additionalProperties":false,"properties":{"domain":{"description":"PublicFQDNdomain name, e.g. example.com.Must be resolvable on the public internet;IPIPsaddresses, ports, paths,and protocol prefixes are rejected.","type":"string"},"method":{"description":"Access-Control-Request-Methodheadertovaluesend, e.g.POST or PUT.POST. Defaults toGET if omitted.GET.","type":"string"},"origin":{"description":"Origin headervaluetoinclude in the preflightsend, e.g. https://app.example.com. Defaults to https://domainposture.com if omitted.//domainposture.com.","type":"string"}},"required": ⟨3 unchanged words⟩
before
—after
{"openWorldHint":true,"readOnlyHint":true}{"$schema":"http://json-schema.org/draft-07/schema#","additionalProperties":false,"properties":{"domain":{"description":"PublicFQDNdomain name, e.g. example.com.Must be resolvable on the public internet;IPIPsaddresses, ports, paths,and protocol prefixes are rejected.","type": ⟨5 unchanged words⟩
before
—after
{"openWorldHint":true,"readOnlyHint":true}{"$schema":"http://json-schema.org/draft-07/schema#","additionalProperties":false,"properties":{"domain":{"description":"PublicFQDNdomain name, e.g. example.com.Must be resolvable on the public internet;IPIPsaddresses, ports, paths,and protocol prefixes are rejected.","type": ⟨10 unchanged words⟩ "google\", \"s1\"]. Omit toprobeuse the built-incommon-selectors set: default, google, k1, selector1, selector2, mxvault.list.","items":{"type":"string"}, ⟨6 unchanged words⟩
before
—after
{"openWorldHint":true,"readOnlyHint":true}{"$schema":"http://json-schema.org/draft-07/schema#","additionalProperties":false,"properties":{"domain":{"description":"PublicFQDNdomain name, e.g. example.com.Must be resolvable on the public internet;IPIPsaddresses, ports, paths,and protocol prefixes are rejected.","type": ⟨5 unchanged words⟩
before
—after
{"openWorldHint":true,"readOnlyHint":true}{"$schema":"http://json-schema.org/draft-07/schema#","additionalProperties":false,"properties":{"domain":{"description":"PublicFQDNdomain name, e.g. example.com.Must be resolvable on the public internet;IPIPsaddresses, ports, paths,and protocol prefixes are rejected.","type": ⟨5 unchanged words⟩
before
—after
{"openWorldHint":true,"readOnlyHint":true}{"$schema":"http://json-schema.org/draft-07/schema#","additionalProperties":false,"properties":{"domain":{"description":"PublicFQDNdomain name, e.g. example.com.Must be resolvable on the public internet;IPIPsaddresses, ports, paths,and protocol prefixes are rejected.","type": ⟨5 unchanged words⟩
before
—after
{"openWorldHint":true,"readOnlyHint":true}{"$schema":"http://json-schema.org/draft-07/schema#","additionalProperties":false,"properties":{"domain":{"description":"PublicFQDNdomain name, e.g. example.com.Must be resolvable on the public internet;IPIPsaddresses, ports, paths,and protocol prefixes are rejected.","type": ⟨5 unchanged words⟩
before
—after
{"openWorldHint":true,"readOnlyHint":true}{"$schema":"http://json-schema.org/draft-07/schema#","additionalProperties":false,"properties":{"domain":{"description":"PublicFQDNdomain name, e.g. example.com.Must be resolvable on the public internet;IPIPsaddresses, ports, paths,and protocol prefixes are rejected.","type": ⟨5 unchanged words⟩
before
—after
{"openWorldHint":true,"readOnlyHint":true}{"$schema":"http://json-schema.org/draft-07/schema#","additionalProperties":false,"properties":{"domain":{"description":"PublicFQDNdomain name, e.g. example.com.Must be resolvable on the public internet;IPIPsaddresses, ports, paths,and protocol prefixes are rejected.","type": ⟨5 unchanged words⟩
before
—after
{"openWorldHint":true,"readOnlyHint":true}{"$schema":"http://json-schema.org/draft-07/schema#","additionalProperties":false,"properties":{"domain":{"description":"PublicFQDNdomain name, e.g. example.com.Must be resolvable on the public internet;IPIPsaddresses, ports, paths,and protocol prefixes are rejected.","type": ⟨5 unchanged words⟩
before
—after
{"openWorldHint":true,"readOnlyHint":true}{"$schema":"http://json-schema.org/draft-07/schema#","additionalProperties":false,"properties":{"domain":{"description":"PublicFQDNdomain name, e.g. example.com.Must be resolvable on the public internet;IPIPsaddresses, ports, paths,and protocol prefixes are rejected.","type": ⟨5 unchanged words⟩
before
—after
{"openWorldHint":true,"readOnlyHint":true}{"$schema":"http://json-schema.org/draft-07/schema#","additionalProperties":false,"properties":{"domain":{"description":"PublicFQDNdomain name, e.g. example.com.Must be resolvable on the public internet;IPIPsaddresses, ports, paths,and protocol prefixes are rejected.","type": ⟨5 unchanged words⟩
before
—after
{"openWorldHint":true,"readOnlyHint":true}{"$schema":"http://json-schema.org/draft-07/schema#","additionalProperties":false,"properties":{"domain":{"description":"PublicFQDNdomain name, e.g. example.com.Must be resolvable on the public internet;IPIPsaddresses, ports, paths,and protocol prefixes are rejected.","type": ⟨5 unchanged words⟩
before
—after
{"openWorldHint":true,"readOnlyHint":true}{"$schema":"http://json-schema.org/draft-07/schema#","additionalProperties":false,"properties":{"domain":{"description":"PublicFQDNdomain name, e.g. example.com.Must be resolvable on the public internet;IPIPsaddresses, ports, paths,and protocol prefixes are rejected.","type": ⟨5 unchanged words⟩
before
—after
{"openWorldHint":true,"readOnlyHint":true}{"$schema":"http://json-schema.org/draft-07/schema#","additionalProperties":false,"properties":{"domain":{"description":"PublicFQDNdomain name, e.g. example.com.Must be resolvable on the public internet;IPIPsaddresses, ports, paths,and protocol prefixes are rejected.","type": ⟨5 unchanged words⟩
before
—after
{"openWorldHint":true,"readOnlyHint":true}{"$schema":"http://json-schema.org/draft-07/schema#","additionalProperties":false,"properties":{"domain":{"description":"PublicFQDNdomain name, e.g. example.com.Must be resolvable on the public internet;IPIPsaddresses, ports, paths,and protocol prefixes are rejected.","type": ⟨5 unchanged words⟩
before
—after
{"openWorldHint":true,"readOnlyHint":true}{"$schema":"http://json-schema.org/draft-07/schema#","additionalProperties":false,"properties":{"domain":{"description":"PublicFQDNdomain name, e.g. example.com.Must be resolvable on the public internet;IPIPsaddresses, ports, paths,and protocol prefixes are rejected.","type": ⟨5 unchanged words⟩
before
—after
{"openWorldHint":true,"readOnlyHint":true}{"$schema":"http://json-schema.org/draft-07/schema#","additionalProperties":false,"properties":{"ip":{"description":"IPv4 or IPv6 addressto look up, e.g.1.2.3.41.1.1.1 or20012606:db84700::1. Hostnames are not accepted.1111.","type":"string"}},"required": ⟨3 unchanged words⟩
before
—after
{"openWorldHint":true,"readOnlyHint":true}{"$schema":"http://json-schema.org/draft-07/schema#","additionalProperties":false,"properties":{"ua":{"description":"FullThe full User-Agent headervalue as sent by the browser or HTTP client, e.g. \"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36\".value.","type":"string"}},"required": ⟨3 unchanged words⟩
before
—after
{"openWorldHint":false,"readOnlyHint":true}