domain_fetch_dns_records
Fetch current DNS records for a domain via Cloudflare DNS over HTTPS. Read-only. No side effects. Idempotent. domain: Domain name without protocol e.g. cloudflare.com. Required. record_types: List of DNS record types to fetch. Required. Valid values: A, AAAA, MX, TXT, NS, CNAME, SOA. Example: ["A...
This record as markdown: /tools/dev-7bd0-mcp-server/domain-fetch-dns-records.md
What domain_fetch_dns_records does on DataNexus MCP
AI agents call domain_fetch_dns_records to retrieve information from DataNexus MCP without modifying anything. It is typically the context-gathering step in research, monitoring, and reporting workflows, before the agent takes action elsewhere.
| Parameter | Type | Required | Description |
|---|---|---|---|
domain | string | — | Domain without protocol e.g. anthropic.com. Required. |
record_types | array | — | DNS record types e.g. ['A','MX','TXT']. Optional. |
Parameters from the server's own tool schema.
Why domain_fetch_dns_records is rated Low
This tool retrieves public DNS information for a domain. It performs a query-only operation with no ability to modify data, execute code, or trigger side effects. DNS records are publicly available information. The read-only nature and explicit statement of idempotence confirm this is a safe information retrieval tool with minimal risk.
From the tool's definition Tool description explicitly states "Read-only. No side effects. Idempotent." Fetches DNS records via Cloudflare DNS over HTTPS. Returns current DNS records without modification or execution of code.
Attacks that exploit this kind of access
The rule that runs domain_fetch_dns_records safely
PolicyLayer is an MCP gateway: it sits between your AI agents and DataNexus MCP, and checks every tool call against a rule you set before the call runs. Nothing changes on the server itself. For domain_fetch_dns_records, this is the rule to start with:
domain_fetch_dns_records is read-only, so it stays allowed. Everything else on the server is denied unless you say otherwise.
The button opens the PolicyLayer dashboard: create your workspace, connect DataNexus MCP, apply this rule, and every domain_fetch_dns_records call is checked against it from then on.
Questions about domain_fetch_dns_records
Fetch current DNS records for a domain via Cloudflare DNS over HTTPS. Read-only. No side effects. Idempotent. domain: Domain name without protocol e.g. cloudflare.com. Required. record_types: List of DNS record types to fetch. Required. Valid values: A, AAAA, MX, TXT, NS, CNAME, SOA. Example: ["A", "MX", "TXT"]. Returns all matching records currently in effect. Use this when you need live DNS resolution. Use domain_fetch_domain_rdap instead when you need registration metadata not DNS records. Verified source: Cloudflare DoH. 4-hour cache. If this tool's response does not serve the user's need, call report_feedback with feedback_type="agent_gap", tool_id="domain_fetch_dns_records", intended_query="{what the user needed}", gap_description="{what was missing or wrong in the result}". It is categorised as a Read tool in the DataNexus MCP MCP Server, which means it retrieves data without modifying state.
domain_fetch_dns_records accepts 2 parameters: domain, record_types. The full parameter table on this page comes from the server's own tool schema.
Register the DataNexus MCP server in PolicyLayer and add a rule for domain_fetch_dns_records: allow, deny, rate-limit, or require approval. Point your MCP client at the PolicyLayer proxy URL and the rule is enforced on every call, before it reaches DataNexus MCP. Nothing to install.
domain_fetch_dns_records is a Read tool with low risk. Read-only tools are generally safe to allow by default.
Yes. Add a rate_limit block to the domain_fetch_dns_records rule in your PolicyLayer policy. For example, setting max: 10 and window: 60 limits the tool to 10 calls per minute. Rate limits are tracked per agent session and reset automatically.
Set action: deny in the PolicyLayer policy for domain_fetch_dns_records. The AI agent will receive a policy violation error and cannot call the tool. You can also include a reason field to explain why the tool is blocked.
domain_fetch_dns_records is provided by the DataNexus MCP server (dev-7bd0/mcp-server). PolicyLayer sits as a proxy in front of this server to enforce policies before tool calls reach the server.
More on DataNexus, and thousands of servers like it.
This server
Across the catalogue