New Your team’s decisions, in one playbook every coding agent works from. Never answer your agent twice

domain_fetch_dns_records

Fetch current DNS records for a domain via Cloudflare DNS over HTTPS. Read-only. No side effects. Idempotent. domain: Domain name without protocol e.g. cloudflare.com. Required. record_types: List of DNS record types to fetch. Required. Valid values: A, AAAA, MX, TXT, NS, CNAME, SOA. Example: ["A...

SERVERDataNexus MCP SOURCEdev-7bd0/mcp-server
Low RISK CLASS
Category Read
Parameters 20 required
Recommended Allowedsee the rule below
Registry record Grade F, identity unverified Pull the record →

This record as markdown: /tools/dev-7bd0-mcp-server/domain-fetch-dns-records.md

What domain_fetch_dns_records does on DataNexus MCP

AI agents call domain_fetch_dns_records to retrieve information from DataNexus MCP without modifying anything. It is typically the context-gathering step in research, monitoring, and reporting workflows, before the agent takes action elsewhere.

ParameterTypeRequiredDescription
domain string Domain without protocol e.g. anthropic.com. Required.
record_types array DNS record types e.g. ['A','MX','TXT']. Optional.

Parameters from the server's own tool schema.

Why domain_fetch_dns_records is rated Low

This tool retrieves public DNS information for a domain. It performs a query-only operation with no ability to modify data, execute code, or trigger side effects. DNS records are publicly available information. The read-only nature and explicit statement of idempotence confirm this is a safe information retrieval tool with minimal risk.

From the tool's definition Tool description explicitly states "Read-only. No side effects. Idempotent." Fetches DNS records via Cloudflare DNS over HTTPS. Returns current DNS records without modification or execution of code.

Questions about domain_fetch_dns_records

What does the domain_fetch_dns_records tool do? +

Fetch current DNS records for a domain via Cloudflare DNS over HTTPS. Read-only. No side effects. Idempotent. domain: Domain name without protocol e.g. cloudflare.com. Required. record_types: List of DNS record types to fetch. Required. Valid values: A, AAAA, MX, TXT, NS, CNAME, SOA. Example: ["A", "MX", "TXT"]. Returns all matching records currently in effect. Use this when you need live DNS resolution. Use domain_fetch_domain_rdap instead when you need registration metadata not DNS records. Verified source: Cloudflare DoH. 4-hour cache. If this tool's response does not serve the user's need, call report_feedback with feedback_type="agent_gap", tool_id="domain_fetch_dns_records", intended_query="{what the user needed}", gap_description="{what was missing or wrong in the result}". It is categorised as a Read tool in the DataNexus MCP MCP Server, which means it retrieves data without modifying state.

What parameters does domain_fetch_dns_records accept? +

domain_fetch_dns_records accepts 2 parameters: domain, record_types. The full parameter table on this page comes from the server's own tool schema.

How do I enforce a policy on domain_fetch_dns_records? +

Register the DataNexus MCP server in PolicyLayer and add a rule for domain_fetch_dns_records: allow, deny, rate-limit, or require approval. Point your MCP client at the PolicyLayer proxy URL and the rule is enforced on every call, before it reaches DataNexus MCP. Nothing to install.

What risk level is domain_fetch_dns_records? +

domain_fetch_dns_records is a Read tool with low risk. Read-only tools are generally safe to allow by default.

Can I rate-limit domain_fetch_dns_records? +

Yes. Add a rate_limit block to the domain_fetch_dns_records rule in your PolicyLayer policy. For example, setting max: 10 and window: 60 limits the tool to 10 calls per minute. Rate limits are tracked per agent session and reset automatically.

How do I block domain_fetch_dns_records completely? +

Set action: deny in the PolicyLayer policy for domain_fetch_dns_records. The AI agent will receive a policy violation error and cannot call the tool. You can also include a reason field to explain why the tool is blocked.

What MCP server provides domain_fetch_dns_records? +

domain_fetch_dns_records is provided by the DataNexus MCP server (dev-7bd0/mcp-server). PolicyLayer sits as a proxy in front of this server to enforce policies before tool calls reach the server.

More on DataNexus, and thousands of servers like it.

// THE MCP REGISTRY

PolicyLayer tracks 44,603 MCP servers and 515,000+ tools.

Every server has a live record: who publishes it, whether it answers without auth, its risk grade, every tool classified, the recommended policy. This page is one line of DataNexus's. Pull the full record:

Teams ship this data inside their own products. See what a licence covers →

// GET IN TOUCH

Have a question or want to learn more? Send us a message.

Message sent.

We'll get back to you soon.