Audit DNS and email security: SPF, DMARC, DKIM, DNSSEC, SSL, and brand protection for your domain.
Scans a domain's DNS and email authentication records to detect security gaps, spoofing risk, and misconfigurations. Checks SPF, DMARC, DKIM, DNSSEC, SSL/TLS, MTA-STS, CAA, BIMI, and more. Generates remediation plans and compliance reports.
Try asking Muse: "Check if my company domain is vulnerable to email spoofing and get a security score."
Source: Found in the official MCP Registry (com.blackveilsecurity/dns) · First listed September 24, 2026
Each bar is one check, every 15 minutes. Green means it answered. Last checked 54 min ago.
What Muse can see: It does not ask you to sign in, so it cannot see your accounts. It only sees what Muse sends it from your request.
Before it acts: Read what Muse plans to do before you approve it, and remove the app from Muse when you stop using it.
musedirectory.ai is not part of Meta. More about how Muse handles your information
Not in Muse's Connectors list yet, but Muse can still use it. Copy the request below and paste it into Muse. Muse asks before it shares anything with the app's site. Meta does not review apps used this way, so only use ones you trust. We tested this in the Muse app on September 24, 2026: Muse used an app's link directly this way and returned a live answer.
https://dns-mcp.blackveilsecurity.com/mcpNot in Muse's Connectors list yet. Muse can still use it: its page gives you a request to paste into Muse.
Response time at the last check: 732ms. Worked in 100% of checks over 30 days.
Screened, no issues found
Screening looks for known threats and hidden instructions at the time of the check, and runs again weekly and whenever the tool list changes. It cannot see the server's code, so only connect what you need and review what Muse asks to do. How screening works.
check_mxLook up MX records for a domain. Identifies which mail servers receive inbound email for the domain and which email hosting provider is used (Google Workspace, Microsoft 365, Proofpoint, etc.). Use when asked which email provider hosts inbound mail for a domain, or to see MX recocheck_spfLook up and validate the SPF record for a domain. Lists all IP addresses and third-party senders authorised to send email on behalf of the domain, flags syntax errors, and shows the trust surface (which mail servers are whitelisted). Use when you need to know who is permitted to check_dmarcLook up and validate the DMARC record for a domain. Shows the enforcement level (none/quarantine/reject), alignment mode (strict/relaxed), and aggregate/forensic reporting destinations. Use to determine a domain's DMARC enforcement level, whether it sends aggregate reports, or ifcheck_dkimLook up DKIM records for a domain. Probes common selectors, validates the signing algorithm used for outgoing email (RSA-1024/2048, Ed25519), and reports key strength. Use to verify that outbound email signatures are cryptographically sound. Part of the scan_domain audit.check_dnssecCheck DNSSEC status for a domain. Verifies whether DNS is tamper-proof and protected against cache poisoning and DNS spoofing attacks by validating DNSKEY and DS records. Reports whether DNSSEC is enabled and validating. Part of the scan_domain audit.check_sslCheck the HTTPS/TLS posture of a domain: HTTPS reachability, HSTS policy, and HTTP-to-HTTPS redirect. Also returns certificate metadata (issuer, expiry date, days remaining, SAN count) read from public Certificate Transparency logs — this describes the most recently LOGGED certifcheck_mta_stsCheck whether a domain enforces SMTP TLS for inbound mail via MTA-STS, protecting against downgrade attacks. Queries _mta-sts.<domain> and fetches the policy file, reports mode (enforce/testing/none) and MX coverage. Use to verify whether inbound SMTP is protected against TLS dowcheck_nsAudit a domain’s nameserver delegation and redundancy. Identifies the DNS hosting provider and, when the infrastructure probe is available, directly compares parent and child NS sets, verifies authoritative AA responses, and checks required glue addresses. Use to detect stale regcheck_caaLook up CAA records for a domain. Shows which Certificate Authorities are authorized to issue certificates. Part of the scan_domain audit.check_bimiCheck the BIMI brand-logo record at default._bimi.<domain>. Validates the logo URL (l=) and the presence of mark-certificate authority evidence (a=) — the a= tag is a bare URL, so the certificate type (VMC or CMC) is not determined — and verifies the DMARC enforcement prerequisitcheck_tlsrptCheck whether a domain has SMTP TLS Reporting (TLS-RPT) configured. Queries _smtp._tls.<domain> for the v=TLSRPTv1 record and validates its reporting destination (rua= mailto:/https:), flagging a missing record, duplicate records, or an invalid/absent reporting URI. Complements Mcheck_http_securityAudit a domain's browser-facing HTTP security headers over HTTPS. Inspects Content-Security-Policy (flagging unsafe-inline/unsafe-eval/wildcards), X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, and the cross-origin isolation headers (COOP/COEP/CORP)check_daneCheck DANE/TLSA certificate pinning for SMTP at port 25. Resolves the domain's MX hosts and looks up TLSA records at _25._tcp.<mx-host>, validating their syntax, usage/selector/matching-type fields and DNSSEC backing on the MX host's zone. The record is reported as present but UNcheck_ptrVerify forward-confirmed reverse DNS (PTR/FCrDNS) for mail servers. Part of the scan_domain audit.check_dane_httpsVerify DANE certificate pinning for HTTPS connections. Looks up TLSA records at _443._tcp.{domain} (port 443) and validates their syntax, usage/selector/matching-type fields and DNSSEC backing. The record is reported as present but UNVERIFIED in every deployment: comparison againcheck_svcb_httpsValidate HTTPS/SVCB records (RFC 9460) for modern transport capability advertisement. Part of the scan_domain audit.check_lookalikesDetect active typosquat and lookalike/homoglyph domains that impersonate your brand and could be used in phishing. Identifies character-substitution and visual-confusion domains registered by attackers. Distinct from check_shadow_domains (TLD variants with auth gaps) and discovercheck_subdomailingDetect SubdoMailing risk: analyzes the SPF include chain for dangling or hijackable subdomains that could let an attacker send email as the domain. Use when you want to know if an SPF include chain can be hijacked through a dangling domain, or to detect subdomain mailing risk hidscan_domainRun a full DNS and email security audit for a single domain. Aggregates every scan-included check in parallel (SPF, DKIM, DMARC, DNSSEC, TLS/SSL, MTA-STS, CAA, BIMI, subdomain takeover, and more) and returns an overall security score, NIST-aligned letter grade (6-band A+/A/B/C/D/batch_scanBulk-scan up to 10 domains in parallel. Runs a full security audit on each domain in the list and returns score, NIST-aligned letter grade (6-band A+/A/B/C/D/F), and finding counts per domain. Use when you want to audit multiple domains at once or do a bulk scan of several domainbatch_scan_startStart a durable asynchronous scan of 1–10 domains. Returns a stable job ID; replaying the same idempotency key with the same principal, normalized inputs, and scoring versions returns the same job.batch_scan_statusRead the owner-scoped status of an asynchronous batch scan.batch_scan_findingsFetch owner-scoped findings for a completed asynchronous batch scan.compare_domainsSide-by-side security comparison of 2–5 domains. Shows relative scores, category gaps, and unique weaknesses for each domain. Use when comparing your security posture against a competitor, or doing a head-to-head comparison between multiple domains.compare_baselineCompare a domain's current security configuration against a fixed policy baseline to determine compliance. Use to check whether a domain meets a policy requirement — not for tracking improvement/regression over time (use analyze_drift) and not for comparing multiple domains (use check_shadow_domainsFind alternate TLD variants of a domain (e.g. example.net, example.co) that have weak or missing email authentication and could be used to spoof email. Use when asked about TLD variants with email auth gaps — distinct from check_lookalikes which detects typosquat/homoglyph imperscheck_txt_hygieneAudit TXT records for stale entries and SaaS exposure.check_mx_reputationCheck whether the mail server (MX) IP addresses are listed on spam blocklists (Spamhaus, Barracuda, SORBS, and other RBLs). Also verifies reverse DNS for MX hosts. Use when you want to know if your mail server IP is blacklisted, or if your MX is on any blocklist — distinct from ccheck_srvMap a domain's DNS-visible service footprint by probing 19 common SRV record prefixes (email, calendar, messaging, directory, web) in parallel. Returns discovered services and flags insecure service advertisements — e.g. plaintext IMAP/POP3/LDAP without an encrypted variant. A docheck_zone_hygieneAudit DNS zone hygiene: identifies sensitive or forgotten subdomains exposed in DNS, stale SOA records, and zone propagation issues. Use to find any sensitive subdomains that should not be publicly visible, or to audit overall DNS zone cleanliness.generateGenerate a DNS/email security remediation artifact. Artifact types: spf_record (build a new SPF record), dmarc_record (create a DMARC policy), dkim_config (DKIM key setup), mta_sts_policy (generate an MTA-STS policy file), fix_plan (prioritized remediation plan for all findings),get_domain_rankRank a domain against its country or global cohort using the GSI benchmark corpus. Accepts a domain score (from scan_domain) and optional country/sector; returns a percentile: "scores better than X% of peers". Owner-gate exempt — public cohort data only.get_benchmarkGet industry benchmark data: shows what percentile a domain's security score ranks at within its sector or country cohort, the mean score, and the most common DNS security failures across the industry. Use when asked how a score compares to the industry average, what percentile aget_provider_insightsGet security benchmarks and common configuration issues for a specific email or DNS service-provider cohort (e.g. Google Workspace customers, Microsoft 365 customers). Use when asked how an email service provider compares to competitors on security posture, or to see typical miscassess_spoofabilityCompute a composite email spoofability risk score (0–100, higher = more spoofable) by combining SPF trust surface, DMARC enforcement, and DKIM coverage. Returns a risk level (minimal→critical), per-control sub-scores, and plain-language summary of how easy it would be to spoof emcheck_resolver_consistencyCheck DNS consistency across 4 public resolvers.explain_findingExplain a finding with impact and remediation.map_supply_chainMap DNS-visible third-party service dependencies for a domain. Correlates SPF, NS, TXT verifications, SRV services, and CAA records to reveal which third-party vendors can send email as the domain, control DNS, or access integrated services. Use when asked to map third-party or sanalyze_driftMeasure whether a domain's DNS security posture improved or regressed by comparing the current state against a prior scan snapshot. Returns a drift classification (improving/stable/regressing/mixed), score delta, and lists of improvements and regressions. Use to answer "did our svalidate_fixRe-check a specific security control after applying a fix, to confirm the finding is now resolved. Use only when a fix has already been applied and you want to verify or confirm the remediation was successful — not for initial inspection of a record.https://dns-mcp.blackveilsecurity.com/mcpNot in Muse's Connectors list yet, but Muse can still use it. Paste this into Muse: "Use BlackVeil DNS & Email Security Scanner to help me. It is a free service with an MCP server at https://dns-mcp.blackveilsecurity.com/mcp. It does not need an API key. Ask me before you share anything with it." Muse asks before it shares anything with the app's site. Meta does not review apps used this way, so only use ones you trust. We tested this in the Muse app on September 24, 2026: Muse used an app's link directly this way and returned a live answer.
At the last check (September 28, 2026, 08:15 UTC) the endpoint was working, answering in 732ms. Over the last 7 days it answered 100% of health checks. It is checked every 15 minutes.
It was screened on September 24, 2026 with the result "screened, no issues found". Screening checks the domain against threat feeds and reads the tools for hidden instructions and requests for passwords or card numbers. It cannot see the server's code, so grant only the access you need.
It exposes 40 tools, including check_mx, check_spf, check_dmarc, check_dkim. For example, you could ask Muse: "Check if my company domain is vulnerable to email spoofing and get a security score."
This listing was added from public sources (Found in the official MCP Registry (com.blackveilsecurity/dns)). If you build BlackVeil DNS & Email Security Scanner, claim it to correct the details and get your badge.
Paste this on your site or README. It always shows the latest check.
<a href="https://musedirectory.ai/connector/blackveil-dns-email-security-scanner"><img src="https://musedirectory.ai/badge/blackveil-dns-email-security-scanner.svg" alt="BlackVeil DNS & Email Security Scanner on musedirectory.ai" width="236" height="40"></a>