# admintoolkit.io

> admintoolkit.io provides 24 read-only browser diagnostics for IP, DNS, mail, HTTP headers, TLS certificates, subnets, EDID, and agent- and AI-web metadata.
admintoolkit.io provides practical diagnostics for administrators and technical users. Many tools run locally in the browser where possible; network lookups are explicit user actions.
Each tool page includes a human-readable workflow section, limits section, and FAQ references for interpreting the result and understanding which data stays local.

admintoolkit.io is a free, public suite of 24 browser-based, read-only diagnostic tools for DNS, email security, TLS, HTTP, networking, and agent-discovery metadata; it is not a monitoring, automatic-remediation, or configuration-management service. Each result is point-in-time diagnostic evidence for the exact target and input from the matching canonical tool page and published contract; limitations remain part of the result rather than a guarantee. Results exist only for checks the user explicitly ran; nothing is precomputed or inferred. Network-backed checks execute only on explicit user action and only against public targets the user is authorized to inspect. Tools require no secrets, credentials, private keys, access tokens, or confidential payloads. Local processing is used where suitable, with each tool page defining its privacy boundary. Reports identify the tool, target, observation, and important limitation. Consequential DNS, mail, TLS, routing, security, or publishing changes require verification against the authoritative service.

## Primary Pages
- [Admin, Engineer & AI Tools](https://admintoolkit.io/): English home and tool index.
- [Changelog](https://admintoolkit.io/changelog/): English release notes and recent public changes.

## Agent And WebMCP Discovery
- [MCP/WebMCP Tools](https://admintoolkit.io/mcp/tools): Machine-readable list of AdminToolkit read-only diagnostic tools with input schemas, output schemas, readOnly hints, and tool page URLs. Public agent-facing tools are read-only, same-origin, unauthenticated, and designed not to perform destructive actions.
- [Root Tools Manifest](https://admintoolkit.io/tools.json): Same-origin public tools manifest for browser agents and crawler-based tool discovery.
- [WebMCP Manifest](https://admintoolkit.io/.well-known/webmcp.json): WebMCP-compatible discovery metadata for browser agents.
- [MCP-style Tool Catalog Card](https://admintoolkit.io/.well-known/mcp.json): MCP-style tool catalog metadata for AdminToolkit discovery.
- [A2A Agent Card](https://admintoolkit.io/.well-known/agent-card.json): A2A-compatible agent card describing AdminToolkit's agent identity, skills, interfaces, and capabilities for agent-to-agent discovery.
- [OpenAPI Description](https://admintoolkit.io/.well-known/openapi.json): OpenAPI 3.1 description for public read-only endpoints and tool contracts.
- [API Catalog](https://admintoolkit.io/.well-known/api-catalog): Linkset catalog of public API and agent-discovery resources for AdminToolkit.
- [Web Bot Auth Key Directory](https://admintoolkit.io/.well-known/http-message-signatures-directory): Public Ed25519 JWKS key directory for HTTP Message Signatures / Web Bot Auth verification. Private signing keys are not published.
- [Authentication And Access Notes](https://admintoolkit.io/auth.md): Public authentication and access notes for unauthenticated read-only AdminToolkit agent discovery.
- [llms.txt](https://admintoolkit.io/llms.txt): This route inventory and AI-readable navigation file for AdminToolkit's public tools and documentation.
- [security.txt](https://admintoolkit.io/.well-known/security.txt): RFC 9116 security contact metadata for vulnerability disclosure and policy discovery.
- [Homepage Markdown Representation](https://admintoolkit.io/index.md): The English homepage returns its Markdown representation when requested with `Accept: text/markdown`.

## Tools
- [AI Crawler robots.txt Checker](https://admintoolkit.io/ai-crawler-robots-checker/): Accepts robots.txt text or a public robots.txt URL plus an optional path. Reports merged matching groups, octet-normalized longest-match decisions, per-crawler evidence, transport status, crawler-registry provenance and policy snippets — Web / SEO
- [llms.txt Validator](https://admintoolkit.io/llms-txt-validator/): Validate the required initial H1, optional summary and project details, and any H2 resource lists with link titles, URLs, optional descriptions, findings, and source-line evidence — Web / SEO
- [A2A Agent Card Validator](https://admintoolkit.io/a2a-agent-card-validator/): Reports v0.2, v0.3 and v1.0 structure plus discovery-path evidence without claiming endpoint, authentication or signature conformance — Agentic Web
- [WebMCP Tool Validator](https://admintoolkit.io/webmcp-tool-validator/): Reports declarative and imperative static-source evidence separately from caller-provided runtime observation; pasted JavaScript is never executed and active runtime tools are never inferred from source alone — Agentic Web
- [MX Record Check](https://admintoolkit.io/mx-record-check/): Accepts a domain name. Reports exchanger hosts, preferences, Null MX, CNAME risk, address resolution and actionable mail-routing warnings — Email Security
- [SPF/DMARC/DKIM Checker](https://admintoolkit.io/spf-dmarc-dkim-checker/): Accepts a domain plus optional pasted TXT values. Reports syntax, policy strength, alignment, DNS evidence and record-specific warnings — Email Security
- [Email Message Header Analyzer](https://admintoolkit.io/email-header-analyzer/): Accepts pasted RFC 5322 headers. Reports raw Received order, recorded Authentication-Results and caller-configured authserv-id trust; it does not perform cryptographic authentication or reverse-DNS verification — Email Security
- [ARC Chain Validator](https://admintoolkit.io/arc-chain-validator/): Accepts pasted ARC-Seal, ARC-Message-Signature and ARC-Authentication-Results fields. Reports structural completeness, instance continuity and recorded cv state; cryptographic validation and sealer trust are not evaluated — Email Security
- [BIMI Checker/Generator](https://admintoolkit.io/bimi-checker-generator/): Accepts a domain, selector and optional BIMI, DMARC, logo or certificate evidence. Reports TXT syntax, DMARC dependency, asset URL findings and a conservative BIMI draft — Email Security
- [MTA-STS Checker/Generator](https://admintoolkit.io/mta-sts-checker-generator/): Accepts a domain plus optional TXT, policy, MX and TLS-RPT evidence. Reports mode, max-age, syntax, id consistency, MX coverage, conformance findings and remediation warnings — Email Security
- [TLS-RPT Checker/Generator](https://admintoolkit.io/tls-rpt-checker-generator/): Accepts a domain plus optional TLS-RPT TXT or RUA values. Reports version syntax, reporting destinations, external-provider use, conformance findings and remediation warnings — Email Security
- [SMTP TLS Handshake / Mail Domain Delivery Readiness](https://admintoolkit.io/smtp-tls-readiness-checker/): Accepts a domain and optional MTA-STS, TLS-RPT, DANE and FCrDNS checks. Reports MX, STARTTLS, certificate, policy-alignment and downgrade-risk findings — Email Security
- [DNSSEC Validator](https://admintoolkit.io/dnssec-validator/): Accepts a domain plus optional DS, DNSKEY, RRSIG and resolver-status data. Reports chain readiness, algorithms, missing records, validation findings and warnings — DNS Security
- [TLSA Record Checker/Generator](https://admintoolkit.io/tlsa-record-checker-generator/): Accepts host, port, protocol, usage, selector, matching type and optional certificate data. Reports owner name, digest, generated TLSA data and DNS comparison findings — DNS Security
- [DANE Validator](https://admintoolkit.io/dane-validator/): Accepts service host, port, protocol, TLSA records, DNSSEC status and optional certificate evidence. Reports owner names, TLSA syntax, DNSSEC dependency and certificate-match findings — DNS Security
- [CAA Record Checker/Generator](https://admintoolkit.io/caa-record-checker-generator/): Accepts a domain plus optional CAA records and issuer details. Reports issue, issuewild, iodef, ACME parameters, policy gaps and record-generation guidance — DNS Security
- [HTTP Header Analyzer](https://admintoolkit.io/http-header-analyzer/): Accepts pasted headers or a public URL. Reports security, cache, framing, duplicate/conflicting header fields, prioritized findings and remediation notes — Web Security
- [SSL Certificate Decoder](https://admintoolkit.io/ssl-cert-decoder/): Accepts PEM text or public TLS host details. Reports subject, issuer, SANs, validity, fingerprints, key usage, extensions, hostname and certificate-health findings — Web Security
- [security.txt Validator/Generator](https://admintoolkit.io/security-txt-validator-generator/): Accepts pasted content or a public security.txt URL plus optional contact fields. Reports contact, expiry, canonical, encryption, policy, language fields, findings and draft output — Web Security
- [TLS Configuration Checker](https://admintoolkit.io/tls-configuration-checker/): Accepts host and port plus optional HSTS evidence. Reports separate exact-version probes, a distinct verified default handshake, SAN identity/trust evidence, negotiated cipher and ALPN evidence, and HTTPS-only HSTS checks; it does not claim cipher or ALPN enumeration — Web Security
- [Redirect / Canonical / Indexability Checker](https://admintoolkit.io/redirect-canonical-indexability-checker/): Accepts a URL. Reports bounded per-hop status and SSRF evidence, final URL, HTML and HTTP canonical hints, robots meta and scoped X-Robots-Tag directives, hreflang, separate sitemap reachability and membership, and evidence completeness — Web / SEO
- [What is my IP?](https://admintoolkit.io/what-is-my-ip/): Requires no input. Reports the canonical primary address, directly observed peer, trusted-proxy decision, preserved forwarded-header claims and observed address family; one request path does not prove dual-stack capability and no third-party Geo-IP lookup is performed — Network
- [CIDR/Subnet Calculator](https://admintoolkit.io/cidr-subnet-calculator/): Accepts a CIDR block plus optional split prefix and address family. Reports exact BigInt-derived boundaries and address counts, RFC 3021 /31 and host-route /32 semantics, no IPv6 broadcast claim, embedded-IPv4 parsing and a capped subnet preview — Network
- [HDMI EDID Decoder](https://admintoolkit.io/edid-decoder/): Reports strict hex or local file text decoding, checksum and trust state, a readable timing/VIC/Y420 matrix, CTA audio and speaker topology, qualified HDMI Forum transport, HDR and DisplayID evidence, coverage and byte provenance. WebMCP omits display identifiers, serials, filenames, physical addresses, raw bytes and vendor payload values; it does not infer Atmos, DTS:X, HDMI certification, cable capability or source mode selection — Hardware / AV

## Guides
- [Guides](https://admintoolkit.io/guides/): In-depth guidance for mail, DNS, TLS, web, network, AV, and agents.
- [From DNS Evidence to a Finding: AdminToolkit&#x27;s DNS and Mail Security Methodology](https://admintoolkit.io/guides/dns-mail-security-methodology/): Use Methodology 1.2 to reproduce DNSSEC, DANE, mail-auth, and per-address dual-stack SMTP findings without crossing documented trust boundaries.
- [Deploying DANE and TLSA for SMTP Without Losing Mail](https://admintoolkit.io/guides/dane-tlsa-smtp-deployment/): Deploy DANE/TLSA for SMTP with safe records, rollovers, and failure handling.
- [A DMARC Rollout That Does Not Break Your Own Mail](https://admintoolkit.io/guides/dmarc-rollout-playbook/): Roll out DMARC safely from monitoring through enforcement.
- [Diagnosing DNSSEC Outages: From SERVFAIL to the Broken Link](https://admintoolkit.io/guides/dnssec-outage-diagnosis/): Trace DNSSEC SERVFAIL and chain breaks to their root cause.
- [MTA-STS, TLS-RPT, and DANE: Layering Mail Transport Security](https://admintoolkit.io/guides/mta-sts-tls-rpt-dane/): Layer MTA-STS, TLS-RPT, and DANE for mail transport security.
- [CAA Records in Practice: Controlling Certificate Issuance](https://admintoolkit.io/guides/caa-records-in-practice/): Control certificate issuance with practical CAA policy and validation.
- [Email Header Forensics: Reading a Message Like an Investigator](https://admintoolkit.io/guides/email-header-forensics/): Investigate Received lines, authentication results, forwarding, and ARC evidence.
- [Making Your Site Agent-Readable: robots.txt, llms.txt, Agent Cards, and WebMCP](https://admintoolkit.io/guides/agent-readable-website/): Publish honest robots.txt, llms.txt, Agent Cards, and WebMCP discovery.
- [TLS Troubleshooting From the Outside: Certificates, Names, and Handshakes](https://admintoolkit.io/guides/tls-certificate-troubleshooting/): Diagnose certificate, name, SNI, chain, protocol, and handshake failures.
- [SPF Record Design That Survives the 10-Lookup Limit](https://admintoolkit.io/guides/spf-record-design/): Design SPF records that stay within the ten-lookup limit.
- [DKIM Key Rotation Without Breaking Mail](https://admintoolkit.io/guides/dkim-key-rotation/): Rotate DKIM keys safely with overlap and clean selector retirement.
- [How ARC Helps Mail Survive Forwarding](https://admintoolkit.io/guides/arc-forwarding-survival/): Assess forwarded-mail authentication and ARC evidence without overstating trust.
- [BIMI Rollout: From Enforced DMARC to a Visible Logo](https://admintoolkit.io/guides/bimi-logo-rollout/): Build BIMI from enforced DMARC through deployable logo evidence.
- [Planning MX Architecture: Preference, Capacity, and Safe Migration](https://admintoolkit.io/guides/mx-architecture-planning/): Design resilient MX routing, capacity, failover, and migrations.
- [Auditing Mail Delivery Readiness End to End](https://admintoolkit.io/guides/mail-delivery-readiness-audit/): Audit MX, STARTTLS, policy enforcement, DANE, and reverse identity.
- [Reading TLS-RPT Reports in Practice](https://admintoolkit.io/guides/tls-rpt-report-reading/): Turn TLS-RPT aggregates into actionable transport-security evidence.
- [Security Headers That Actually Change Risk](https://admintoolkit.io/guides/security-headers-hardening/): Harden browser security with CSP, HSTS, cookies, isolation, and redirects.
- [security.txt and the Disclosure Process Behind It](https://admintoolkit.io/guides/security-txt-disclosure/): Build an operational vulnerability-disclosure process around security.txt.
- [Hardening TLS Without Guessing at Client Compatibility](https://admintoolkit.io/guides/tls-configuration-hardening/): Harden TLS with measured compatibility and expiring legacy exceptions.
- [Redirects, Canonicals, and Indexability as One System](https://admintoolkit.io/guides/redirect-canonical-indexability/): Align redirects, canonicals, robots, hreflang, sitemaps, and internal links.
- [Public IP, NAT, and Dual Stack: Which Address Is Really Yours?](https://admintoolkit.io/guides/public-ip-nat-dual-stack/): Understand public addressing across NAT, CGNAT, dual stack, and proxies.
- [IPv6 Subnet Planning That Scales](https://admintoolkit.io/guides/ipv6-subnet-planning/): Plan scalable IPv6 prefixes, aggregation, reserves, and documentation.
- [HDMI and EDID Troubleshooting in Real Signal Chains](https://admintoolkit.io/guides/hdmi-edid-troubleshooting/): Trace EDID capability loss through real HDMI signal chains.
- [llms.txt in Practice: Curating a Useful Entry Point](https://admintoolkit.io/guides/llms-txt-in-practice/): Curate a useful llms.txt map with consistent access and indexing signals.
- [Exposing Website Functions as WebMCP Tools](https://admintoolkit.io/guides/webmcp-tool-exposure/): Expose precise WebMCP tools with UI parity and runtime checks.

## Contact, Policies, And Data
- [Accessibility Statement](https://admintoolkit.io/accessibility/): English accessibility statement describing current accessibility practices, known limitations, and the contact path without claiming audited WCAG conformance.
- [Contact](https://admintoolkit.io/contact/): English contact form for tool requests, tool questions, bug reports, privacy or legal questions, and other messages.
- [Privacy Policy](https://admintoolkit.io/privacy/): English privacy policy for local processing, live lookups, analytics, logs, and contact details. User-entered tool values are not sent to analytics.
- [Cookies](https://admintoolkit.io/cookies/): English cookie and analytics controls; analytics requires consent and can be declined.
- [Terms of Use](https://admintoolkit.io/terms/): English terms of use. No public pricing page or paid plan is currently published.
- [Legal Notice & Contact](https://admintoolkit.io/imprint/): English legal notice and operator contact: contact@admintoolkit.io.

## Optional
- [Full Tool Reference](https://admintoolkit.io/llms-full.txt): Optional English full-context reference for all 24 read-only tools, with inputs, result models, workflows, privacy notes, limits, examples, and FAQs.
