Skip to main content
Glama

Get the DNSSEC status of a zone

eurodns_dns_get_dnssec_status
Read-onlyIdempotent

Check DNSSEC signing status of a hosted zone, including keys and DS data. Use before and after configuring DNSSEC or changing nameservers to verify zone and registry agree.

Instructions

Returns whether the zone of domainName is DNSSEC-signed, with its keys and the DS data a registry needs to publish. Read it before and after eurodns_domain_set_dnssec, and again after moving nameservers, to confirm the zone and the registry agree. It reports the zone hosted here only: what the registry actually publishes is not read, so a domain registered elsewhere needs its registrar checked separately rather than trusted from this answer.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
domainNameYesName of the zone, e.g. example.com: a domain whose DNS is hosted here.

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault
dataYesResponse body as returned by the API.
statusYesUpstream HTTP status code.

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed1 schema field changedv0.10.0
    • changedInput schema / properties / domainName / description
      Previous value: -"a domain name (e.g. example.com)"New value: +"Name of the zone, e.g. example.com: a domain whose DNS is hosted here."
  2. First observedv0.9.1

TDQS

A4.4/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare readOnlyHint=true, openWorldHint=true, idempotentHint=true, and destructiveHint=false, establishing a safe, non-mutating operation. The description adds value by clarifying the tool reports only the hosted zone's DNSSEC state, not the registry's publication, and frames its use for verification. It does not contradict annotations and adds contextual nuance beyond the structured fields.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is well-structured, leading with the core function, then usage guidance, then a caveat about scope. Each sentence contributes value without redundancy. It is slightly longer than the bare minimum but every clause earns its place, so it is appropriately sized and front-loaded.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given the tool has one parameter, a clear output schema, and annotations that establish its read-only and idempotent nature, the description is fully adequate. It covers purpose, usage timing, and a key limitation (registry scope). An agent has everything needed to invoke it correctly and interpret results without ambiguity.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The sole parameter, domainName, is fully described in the schema ('Name of the zone, e.g. example.com: a domain whose DNS is hosted here.'). With 100% schema description coverage, the baseline is 3. The description only restates that it operates on the zone of domainName, adding no substantive new semantics beyond the schema. It meets the baseline but does not exceed it.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the tool returns whether a zone is DNSSEC-signed, along with keys and DS data, using a specific verb ('returns') and resource (DNSSEC status of a zone). It explicitly distinguishes itself from siblings like eurodns_domain_set_dnssec (which sets DNSSEC) and eurodns_dns_get_zone (general zone retrieval) by focusing on DNSSEC status and verification. The scope limitation (only reports hosted zone, not registry) further differentiates it from a generic registry check.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description provides explicit guidance on when to use it: 'Read it before and after eurodns_domain_set_dnssec, and again after moving nameservers, to confirm the zone and the registry agree.' It also specifies a when-not scenario: for domains registered elsewhere, it advises checking the registrar separately rather than trusting this tool. This clearly routes the agent to the correct usage and alternative.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.