@guardbee/mcp-dns-intelligence
π¬π§ English | πΉπ· TΓΌrkΓ§e

An MCP server that enumerates DNS records, detects SPF / DMARC / DKIM misconfigurations, and finds dangling subdomains. Uses Node.js's built-in dns/promises β no external dependencies.
This package sends usage telemetry by default (tool name + short parameters β see @guardbee/mcp-telemetry). Disable with GUARDBEE_TELEMETRY=0.
Features
- Full DNS Enumeration β A, AAAA, MX, NS, TXT, CNAME, SOA records
- SPF Analysis β
+all, ?all, excessive DNS lookups, duplicate record detection
- DMARC Analysis β policy (
none/quarantine/reject), pct, missing rua address
- DKIM Check β probes 9 common selectors (
default, google, selector1, mail, etc.)
- Subdomain Enumeration β 60+ common subdomains; dangling CNAME detection (14 cloud providers)
- Email Security Summary β combined SPF + DMARC + DKIM analysis with copy-pasteable fix recommendations
- 23 Unit Tests β pure logic tests, no network connection required
Quick Start
npm install -g @guardbee/mcp-dns-intelligence
Add to claude_desktop_config.json:
{
"mcpServers": {
"guardbee-dns-intelligence": {
"command": "npx",
"args": ["-y", "@guardbee/mcp-dns-intelligence"]
}
}
}
| Tool | Description |
|---|
enumerate_dns | Enumerates all DNS records for a domain and runs SPF/DMARC/DKIM analysis |
enumerate_subdomains | Probes common subdomains; flags dangling CNAMEs |
check_email_security | Combined SPF + DMARC + DKIM audit with fix recommendations |
lookup_dns | Targeted DNS lookup for a specific record type (A/MX/TXT/etc.) |
Example Usage
You can ask Claude:
"Is there a problem with example.com's DNS configuration?"
"Audit example.com's email security β SPF, DMARC, and DKIM"
"List example.com's subdomains, flag any dangling ones"
"What are example.com's MX records?"
Example Output
Email Security Check: example.com
ββββββββββββββββββββββββββββββββββββββββββββββββββ
ββ SPF βββββββββββββββββββββββββββββββββββββββββ
β v=spf1 include:_spf.google.com -all
ββ DMARC βββββββββββββββββββββββββββββββββββββββ
β No DMARC record found at _dmarc.example.com
Add: v=DMARC1; p=quarantine; rua=mailto:dmarc@example.com
ββ DKIM ββββββββββββββββββββββββββββββββββββββββ
β Found DKIM selectors: google
SPF Findings
| Code | Severity | Description |
|---|
SPF_MISSING | π‘ Medium | No SPF record found |
SPF_PERMISSIVE_ALL | π΄ Critical | +all β allows any server |
SPF_NEUTRAL_ALL | π High | ?all β doesn't reject unauthorized senders |
SPF_NO_ALL | π‘ Medium | No all mechanism |
SPF_TOO_MANY_LOOKUPS | π High | > 10 DNS lookups β causes SPF to fail |
SPF_DUPLICATE | π High | Multiple SPF records |
DMARC Findings
| Code | Severity | Description |
|---|
DMARC_MISSING | π High | No DMARC record |
DMARC_NO_POLICY | π High | Missing p= policy |
DMARC_POLICY_NONE | π‘ Medium | p=none β monitoring mode, no enforcement |
DMARC_PCT_LOW | π΅ Low | pct < 100 β partial enforcement |
DMARC_NO_RUA | π΅ Low | No aggregate report address (rua) |
Dangling Subdomain Detection
Subdomains whose CNAME points to one of the following providers but doesn't resolve are flagged as dangling and carry a subdomain-takeover risk:
AWS S3, Azure App Service, GitHub Pages, Heroku, Netlify, Vercel, Cloudflare Pages, Surge, Pantheon, WP Engine, Ghost, Shopify, Fastly, AWS CloudFront
CLI β CI/CD Integration
In addition to MCP server mode, this can also be used directly as a CLI:
npx @guardbee/mcp-dns-intelligence check example.com
npx @guardbee/mcp-dns-intelligence check example.com --fail-on=high
npx @guardbee/mcp-dns-intelligence subdomains example.com
npx @guardbee/mcp-dns-intelligence subdomains example.com --concurrency=50
npx @guardbee/mcp-dns-intelligence check example.com --format=json
Exit codes: 0 = no issues Β· 1 = findings above threshold / dangling subdomain Β· 2 = error
Configuration via guardbee.yml
Create a guardbee.yml at your project root to persist CLI flags. CLI flags always override file settings.
dns-intelligence:
fail-on: high
concurrency: 20
domains:
- example.com
- staging.example.com
See guardbee.example.yml for a sample file.
GitHub Actions β DNS Security Audit
name: DNS Security Check
on:
schedule:
- cron: "0 6 * * *"
workflow_dispatch:
jobs:
dns-check:
runs-on: ubuntu-latest
steps:
- name: Check DNS configuration
run: npx @guardbee/mcp-dns-intelligence check ${{ vars.DOMAIN }} --fail-on=high
- name: Scan for dangling subdomains
run: npx @guardbee/mcp-dns-intelligence subdomains ${{ vars.DOMAIN }}
GitLab CI
dns-security:
image: node:20
script:
- npx @guardbee/mcp-dns-intelligence check $DOMAIN --fail-on=high
- npx @guardbee/mcp-dns-intelligence subdomains $DOMAIN
only:
- schedules
Pre-Deployment Email Security Check
- name: Verify email security records
run: |
npx @guardbee/mcp-dns-intelligence check ${{ vars.DOMAIN }} \
--fail-on=high \
--format=json | tee dns-report.json
- name: Upload DNS report
uses: actions/upload-artifact@v4
with:
name: dns-security-report
path: dns-report.json
Development
npm install
npm test
npm run build
License
MIT β GuardBee