Overview
Includes validation of certificate data format, length verification, and security level assessment with recommendations for optimal DANE configuration.
Live Test DANE Validator Skill Skill →
The tool
Once your client is connected to the VerveKit server, this appears in its tool list as DANEValidatorSkill. It is read-only and open-world — it fetches and never mutates anything on your side — so most clients call it without asking you to confirm.
{
"name": "DANEValidatorSkill",
"arguments": {
"record": "_443._tcp.example.com. 3600 IN TLSA 3 1 1 2bb183af273adee2e02d60ba7a0dc0efcf5e0a2af42dab7b3f8ba9c0def1f6c8"
}
}You do not name the tool yourself; the model picks it. Asking about _443._tcp.example.com. 3600 IN TLSA 3 1 1 2bb183af273adee2e02d60ba7a0dc0efcf5e0a2af42dab7b3f8ba9c0def1f6c8 in the terms this skill covers is enough for it to reach for DANEValidatorSkill on its own — naming it explicitly also works, and is the way to force the call.
Connecting
One server URL covers every skill in the catalog, including this one. Authorization is OAuth: the client opens a browser once, and there is no key to paste into a config file.
{
"mcpServers": {
"vervekit": {
"url": "https://api.vervekit.com/v1/mcp"
}
}
}https://api.vervekit.com/v1/mcpPer-client setup — Claude, Cursor, VS Code, ChatGPT — is on the MCP setup page.
Arguments
These are the properties on the tool's inputSchema, so a well-behaved client validates them before the call is made. Premium arguments are accepted on every plan but only take effect on plans that include them.
| Argument | Type | Description |
|---|---|---|
recordRequired | string | The DANE/TLSA record string to validate |
What the model gets back
The result carries a structuredContent object matching the tool's declared outputSchema, so a client reads fields without parsing prose. status is "ok" and error is null on success; a null field means the value was not available for that input, not that the call failed.
{
"status": "ok",
"error": null,
"data": {
"raw_record": "_443._tcp.example.com. 86400 IN TLSA 3 1 1 0123456789ABCDEF0123456789ABCDEF0123456789ABCDEF0123456789ABCDEF",
"parsed": {
"name": "_443._tcp.example.com.",
"port": 443,
"protocol": "tcp",
"hostname": "example.com",
"ttl": 86400,
"class": "IN",
"usage": 3,
"selector": 1,
"matching": 1,
"certificate_data": "0123456789ABCDEF0123456789ABCDEF0123456789ABCDEF0123456789ABCDEF",
"certificate_data_length": 64
},
"interpretation": {
"usage": {
"name": "DANE-EE",
"description": "Domain-issued certificate",
"full_description": "Certificate must exactly match the provided association data (most common)"
},
"selector": {
"name": "SPKI",
"description": "SubjectPublicKeyInfo",
"full_description": "Match against the Subject Public Key Info (recommended)"
},
"matching": {
"name": "SHA-256",
"description": "SHA-256 hash",
"full_description": "SHA-256 hash of the selected content (recommended)"
},
"security_level": "Recommended",
"recommendation": "This is the recommended DANE configuration (DANE-EE + SPKI + SHA-256)"
},
"validation": {
"is_valid": true,
"certificate_data_format": "Valid hexadecimal",
"certificate_data_length_valid": true
}
}
}
Response fields
Paths are relative to data. Premium fields are absent rather than zeroed on plans that do not include them, so check for presence instead of comparing to 0.
| Field | Type | Example | Description |
|---|---|---|---|
raw_record | string | _443._tcp.example.com. 86400 IN TLSA 3 1 1 0123456789ABCDEF0123456789ABCDEF0123456789ABCDEF0123456789ABCDEF | Original DANE/TLSA record string input |
parsed | object | {…} | |
parsed.name | string | _443._tcp.example.com. | Fully qualified domain name from TLSA record |
parsed.port | number | 443 | Port number specified in TLSA record |
parsed.protocol | string | tcp | Protocol type (tcp or udp) from record |
parsed.hostname | string | example.com | Extracted hostname without service prefix |
parsed.ttl | number | 86400 | Time to live value in seconds |
parsed.class | string | IN | DNS class designation (typically IN) |
parsed.usage | number | 3 | TLSA usage field value (0-3) |
parsed.selector | number | 1 | TLSA selector field value (0-1) |
parsed.matching | number | 1 | TLSA matching type field value (0-3) |
parsed.certificate_data | string | 0123456789ABCDEF0123456789ABCDEF0123456789ABCDEF0123456789ABCDEF | Hexadecimal certificate association data |
parsed.certificate_data_length | number | 64 | Length of certificate data in characters |
interpretationPremium | object | {…} | Detailed interpretation and security analysis of DANE record |
interpretation.usagePremium | object | {…} | |
interpretation.usage.namePremium | string | DANE-EE | Human-readable TLSA usage type name |
interpretation.usage.descriptionPremium | string | Domain-issued certificate | Short description of usage type meaning |
interpretation.usage.full_descriptionPremium | string | Certificate must exactly match the provided association data (most common) | Comprehensive explanation of usage field |
interpretation.selectorPremium | object | {…} | |
interpretation.selector.namePremium | string | SPKI | Human-readable selector type designation |
interpretation.selector.descriptionPremium | string | SubjectPublicKeyInfo | Short description of selector meaning |
interpretation.selector.full_descriptionPremium | string | Match against the Subject Public Key Info (recommended) | Detailed explanation of selector type |
interpretation.matchingPremium | object | {…} | |
interpretation.matching.namePremium | string | SHA-256 | Human-readable matching algorithm name |
interpretation.matching.descriptionPremium | string | SHA-256 hash | Short description of matching algorithm |
interpretation.matching.full_descriptionPremium | string | SHA-256 hash of the selected content (recommended) | Detailed explanation of matching algorithm |
interpretation.security_levelPremium | string | Recommended | Security assessment of configuration level |
interpretation.recommendationPremium | string | This is the recommended DANE configuration (DANE-EE + SPKI + SHA-256) | Expert security recommendation for configuration |
validation | object | {…} | |
validation.is_valid | boolean | true | Overall validation result for DANE record |
validation.certificate_data_format | string | Valid hexadecimal | Certificate data hexadecimal format validation result |
validation.certificate_data_length_valid | boolean | true | Validation status of certificate data length |
Failure modes
Errors come back as tool errors carrying a sentence the model can act on, not a bare status code. Error handling covers the full list.
| Status | What it means |
|---|---|
400 / 422 | The arguments did not validate. The message names the offending one. |
401 | The OAuth session is invalid or expired — reconnect the server. |
403 | Blocked by a key restriction or an IP allow-list. Never a bad identity. |
404 | This skill is not part of VerveKit. Check the catalog. |
429 | Out of credits, or a brief rate limit. The message tells them apart. |
A call costs 2 credits each time the tool actually runs; a model that reasons about the tool without calling it costs nothing.
Use cases
- DANE Configuration
- Validate DANE/TLSA record configuration to ensure proper certificate association and DNS security implementation
- Authentication Audit
- Audit DNS-based authentication of named entities (DANE) for email servers and web services security compliance
- Security Scanning
- Build DNS security scanning tools that validate TLSA records for certificate pinning and trust anchor verification
- Certificate Pinning
- Verify certificate pinning implementation using TLSA records to protect against man-in-the-middle attacks and CA compromise
Other ways to use DANE Validator Skill
Set up DANE Validator Skill on VerveKit, or reach the same source a different way. Your VerveKit account and credits work on all of them — one key, one balance.
Related
More in Security: