Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already cover the safety profile (read-only, idempotent, non-destructive, open-world), so the bar is lower. The description adds genuine context beyond them by scoping the operation to 'DNS only: it does not connect to the mail servers', clarifying that no SMTP probing occurs, and by naming the returned data (IPs and reverse DNS) since there is no output schema.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.