Skip to main content
Glama

threat_passive_dns

Query passive DNS data for a domain to retrieve historical IPs and first/last seen timestamps. Falls back from SecurityTrails API to crt.sh when no API key is set.

Instructions

Query passive DNS data for a domain. Uses SecurityTrails API if SECURITYTRAILS_API_KEY is set, otherwise falls back to Certificate Transparency logs (crt.sh) for historical cert data plus current multi-resolver comparison. Returns historical IPs, first/last seen timestamps.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
domainYesThe domain to query passive DNS history for (e.g. 'example.com')
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations, the description carries full burden. It discloses the dual data sources, the conditional fallback logic, and the returned data types (historical IPs, first/last seen timestamps). It omits potential rate limits or error behavior, but for a read-only query tool this is a solid disclosure.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Three concise sentences, each earning its place: first defines the operation, second explains the backend selection, third states output. No redundancy or filler.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a single-parameter tool with no output schema, the description covers the core behavior, data source selection, and return values. It could add note on result format or time bounds, but it is sufficiently complete for a simple query tool.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100% with a single 'domain' parameter already fully described in the schema. The description adds no further parameter-specific semantics, so baseline 3 is appropriate.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description opens with 'Query passive DNS data for a domain,' a specific verb-resource pair that clearly states the tool's function. It also distinguishes this tool from CT-focused siblings by explaining the fallback from SecurityTrails to crt.sh and the multi-resolver comparison.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description implies usage by stating the query type and return values, and it discloses the API-key-based fallback behavior. However, it does not explicitly tell when to use this versus sibling tools like ct_search or threat_ip_to_domains, leaving alternatives unmentioned.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Install Server

Other Tools

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/badchars/dns-security-mcp'

If you have feedback or need assistance with the MCP directory API, please join our Discord server