Check RFC 9309 robots.txt matching for documented or custom crawler product tokens with merged groups, transport evidence, and registry provenance.
Web / SEOEssential Tools for Admins, Engineers and AI Agents
What does admintoolkit.io provide?
admintoolkit.io brings together essential browser tools for admins, engineers and AI agents: DNS, mail security, TLS, HTTP headers, public IP checks, CIDR, EDID, and agent-readable web metadata such as robots.txt, llms.txt, A2A Agent Cards, and WebMCP tool definitions. The tools are built for traceable diagnostics with local parsing where possible, explicit live lookups, and WebMCP support for AI agents.
Validate the required initial H1, optional summary and project details, and any H2 resource lists with link titles, URLs, optional descriptions, findings, and source-line evidence.
Web / SEOValidate A2A Agent Card discovery JSON, skills, interfaces, capabilities, and deployment metadata.
Agentic WebInspect WebMCP declarative and imperative static source without executing JavaScript; runtime tools require actual browser observation.
Agentic WebQuery MX records through DNS-over-HTTPS, sort priorities, resolve first hosts, and spot Null MX or CNAME problems.
Email SecurityParse SPF, DMARC, and DKIM TXT records, highlight policy issues, and run DNS lookup only when needed.
Email SecurityParse full message headers locally, preserve raw Received order, and classify recorded Authentication-Results without claiming cryptographic or reverse-DNS verification.
Email SecurityCheck ARC instance structure, continuity, and recorded cv state without claiming cryptographic validation or sealer trust.
Email SecurityCheck BIMI records, DMARC readiness, logo and certificate URLs, and generate a conservative BIMI TXT draft.
Email SecurityAssess MTA-STS TXT and HTTPS policy files, compare MX coverage, and return conformance findings with remediation warnings.
Email SecurityAssess TLS-RPT TXT records, validate RUA destinations, flag external providers, and return conformance findings with remediation warnings.
Email SecurityReview MX, STARTTLS, certificate match, MTA-STS, TLS-RPT, and optional DANE and FCrDNS readiness evidence.
Email SecurityReview DS, DNSKEY, RRSIG structural inventory and the validating resolver's DNSSEC verdict for a domain.
DNS SecurityBuild valid TLSA records from certificate data and compare DANE fields directly with live DNS TLSA answers.
DNS SecurityValidate DANE service owner names, TLSA RRsets, DNSSEC context, and implemented DANE-EE live comparisons.
DNS SecurityCheck and generate CAA issue, issuewild, iodef, ACME account bindings, validation methods, and issuemail tags.
DNS SecurityAnalyze pasted HTTP response headers locally, or fetch headers for a public URL through the restricted endpoint.
Web SecurityDecode X.509 certificates in the browser, or fetch one public host certificate through the guarded TLS endpoint.
Web SecurityValidate RFC 9116 vulnerability-disclosure contacts, expiry, canonical URL, policy, encryption, and hiring fields.
Web SecurityRun separate exact-version TLS probes and summarize verified certificate identity, negotiated cipher/ALPN evidence, and HTTPS-only HSTS evidence.
Web SecurityCheck bounded redirect chains, final status, HTML and HTTP canonical hints, robots metadata, scoped X-Robots-Tag, hreflang, and separate sitemap reachability and membership.
Web / SEOShows the canonical public address, observed peer, trusted-proxy evidence, browser metadata, and forwarded headers; Geo-IP/ASN and map requests require separate clicks.
NetworkCalculate exact IPv4 and IPv6 networks and BigInt address counts locally, including RFC 3021 /31, host /32, embedded IPv4, and capped split previews.
NetworkDecode EDID hex or local files into trust-qualified timing, YCbCr 4:2:0, audio, speaker, HDMI transport, HDR, DisplayID, checksum, and byte-provenance evidence.
Hardware / AVLocal parsers stay in the browser where possible. DNS, HTTP, TLS, Geo-IP and map calls are shown as live actions; the public-IP reflection is same-origin, while Geo-IP/ASN and map requests require separate clicks.
Root WebMCP tool contracts
The root page registers 24 directly executable, read-only WebMCP diagnostics. Each tool has a direct runtime handler and returns structured findings. Discovery endpoints include /tools.json, /.well-known/webmcp.json, /.well-known/mcp.json, /.well-known/tools.json, /mcp/tools, /.well-known/openapi.json, and /.well-known/api-catalog.
Smart checks for real troubleshooting
admintoolkit.io is for the checks that come up while operating DNS, mail, TLS, web, network, and AV systems. It keeps each result close to the input: public IP context, MX routing, SPF/DMARC/DKIM/BIMI records, message headers, DNSSEC and DANE evidence, CAA policy, certificates, HTTP response headers, CIDR math, EDID data, and agentic web metadata such as llms.txt, robots.txt, A2A Agent Cards, and WebMCP tool definitions. Agent-ready diagnostics: admintoolkit.io exposes its 24 tools as read-only WebMCP runtime tools where supported by compatible agents. The pages are intentionally narrow. They give you one readable fact at a time, with the raw value still visible enough to compare against logs, tickets, DNS changes, firewall rules, or the device that produced the data.
- Review DNS, mail-authentication, and transport-security evidence.
- Inspect HTTP headers, certificates, public-IP context, CIDR ranges, and EDID data.
- Validate robots.txt, llms.txt, A2A Agent Cards, WebMCP, and related agent metadata.
Local first, live when needed
Some tools are fully local, including header parsing, certificate decoding from pasted data, CIDR calculation, EDID decoding, and static validation of robots.txt, llms.txt, A2A, WebMCP, security.txt, ARC, and pasted DNS records. Live checks are separated by action and by tool: DNS uses browser DNS-over-HTTPS first with same-origin fallback when needed, public IP and selected host checks use same-origin helper endpoints, Geo-IP uses api.ip.sb, and the map loads only after its own opt-in. If a tool needs a current network answer, the lookup path is visible and limited to the data needed for that check.
Built for first-pass evidence
The point is not to replace vendor consoles, packet captures, DNSViz, mail logs, or full audits. The point is to get a clear first-pass fact without losing time: which address is visible, which DNS record exists, whether DNSSEC, DANE, MTA-STS, TLS-RPT, or SMTP TLS evidence lines up, which certificate is served, which header is missing, which subnet contains an address, what an EDID block says, or whether emerging agentic web metadata is structurally ready before publication. That is usually enough to decide the next step without turning a quick report into a noisy investigation.