MCP documentation menu

datapulse_live_domain_health

Live LookupScope: datapulse:dnsOutput: JSONRead-only

Live domain health probe — DNS, DNSSEC, delegation, nameservers, TLS, HTTP, mail, CAA, TLSA in one report (synchronous)

Description

Live domain health probe — one call checks a domain’s DNS, DNSSEC, delegation, nameservers, web, TLS, HTTP, mail posture, CAA and TLSA, and returns the full report.

What is checked: DNSSEC-validated A, AAAA, MX, TXT and NS at the apex and A/AAAA at www (each with its trust level); DNSSEC state (secure/insecure/island/bogus/servfail/unknown); a delegation trace from the root servers comparing the parent’s NS set with the child’s; a nameserver audit (every NS resolved and asked for the SOA over UDP, TCP and EDNS; serial drift, prefix diversity, glue); TCP 80 and 443 on every address; the TLS chain served on 443 (valid/expired/not_yet_valid/hostname_mismatch/self_signed/incomplete_chain/untrusted_root/invalid/handshake_failed, where valid means the chain as served verified while incomplete_chain means it verified only after the probe fetched the missing intermediate, a repair browsers make for themselves and curl and Java do not) with certificate details and TLS 1.0/1.1 acceptance; one HTTP GET on 80 and 443 with status, Location, Server and HSTS; redirect chains per name; QUIC/HTTP3 on every address; mail posture (DMARC, evaluated SPF with lookup count, MX target sanity, DKIM selectors, MTA-STS, TLS-RPT) for zone apexes; CAA per host against the issuer actually served; DANE/TLSA; wildcard detection; reserved addresses; HSTS preload-list status. Port 25 is never probed and no zone transfer is requested.

Always synchronous and always live: every call queues a new probe and returns that probe’s report, nothing is cached; created_at is the time of this probe. Typical latency 1.5-3 seconds. The probe’s own worst case is 16 seconds when every server in every phase hangs; this tool waits up to 30.

Reading the result: the response is the lookup record with the probe report in raw_output. status is “completed” even for a broken domain — the verdict is inside the report: raw_output.ok is false when raw_output.errors is non-empty (NXDOMAIN, no NS, DNSSEC bogus, delegation mismatch, lame or unreachable nameservers, fewer than two NS, missing glue, reserved addresses, any certificate chain problem, 5xx on every address, redirect loops, SPF permerror or +all, bad MX targets, CAA-forbidden issuer, TLSA mismatch, lookups that failed or timed out); raw_output.warnings are advisory (no AAAA, no MX or null MX, no SPF, missing DMARC or p=none, certificate expiring within 30 days, TLS 1.0/1.1 accepted or no TLS 1.3, clear-text HTTP without redirect, short HSTS, HTTPS unreachable while HTTP answers, nameserver serial drift or low prefix diversity, www served by a wildcard, uneven QUIC). status “failed” with an error means the probe tool itself could not run, not that the domain is unhealthy.

domain_hash is the same hash datapulse_domain_overview uses, so the two results join.

If the call reports the lookup is still running, the job finishes server-side; simply call again (a new probe, results are kept 24 hours).

For usage guidance, call datapulse_help(topic="domain_health")

Parameters

ParameterTypeDescription
domain
required
string
The domain to probe (e.g., ’example.com’). Its spelling is canonicalized and no labels are removed (www. kept): the probe itself checks both the apex and www. Unicode (IDN) names, the UTS-46 label separators (ideographic and fullwidth full stops) and trailing root dots (’example.com.’) are accepted. IP literals, single labels (’localhost’) and an underscore in the registrable domain (’exa_mple.com’; ‘_dmarc.example.com’ is fine) are rejected. When normalising a non-ASCII name changes which domain is asked about, as a fullwidth homograph folding to a real ASCII domain does, the result carries submitted_domain.
Min length: 1Max length: 253
Input schema (JSON)
{
  "additionalProperties": false,
  "properties": {
    "domain": {
      "description": "The domain to probe (e.g., 'example.com'). Its spelling is canonicalized and no labels are removed (www. kept): the probe itself checks both the apex and www. Unicode (IDN) names, the UTS-46 label separators (ideographic and fullwidth full stops) and trailing root dots ('example.com.') are accepted. IP literals, single labels ('localhost') and an underscore in the registrable domain ('exa_mple.com'; '_dmarc.example.com' is fine) are rejected. When normalising a non-ASCII name changes which domain is asked about, as a fullwidth homograph folding to a real ASCII domain does, the result carries submitted_domain.",
      "maxLength": 253,
      "minLength": 1,
      "type": "string"
    }
  },
  "required": [
    "domain"
  ],
  "type": "object"
}

Generated from the live server (DataPulse MCP 1.0.0) on October 1, 2026.