Skip to content
Back to skills

Dns Aid

ASecurity

Sub-skill: Implement DNS-AID records so agents discover endpoints through DNS. Use SVCB/HTTPS records under _agents namespace with alpn and connection parameters.

  • 99 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added September 5, 2026
ai-agentsgoapi

Works with

  • api

Security analysis

A100/100

Scanned September 5, 2026

npx -y skills add fabricioctelles/skills --skill dns-aid --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Dns Aid?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Dns Aid
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/fabricioctelles-dns-aid/badge)](https://www.skillsdirectory.com/skills/fabricioctelles-dns-aid)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: agent-ready-dns-aid
description: >
  Sub-skill: Implement DNS-AID records so agents discover endpoints through DNS.
  Use SVCB/HTTPS records under _agents namespace with alpn and connection parameters.
---
# Implement DNS for AI Discovery (DNS-AID)

Publish DNS for AI Discovery (DNS-AID) records so agents can discover your agent endpoints through DNS.

## Requirements

- Publish DNS for AI Discovery (DNS-AID) records under your domain's `_agents` namespace, such as `_index._agents.example.com` or `_a2a._agents.example.com`
- Use ServiceMode `SVCB` records, or `HTTPS` records for HTTPS endpoints, with `alpn` and endpoint connection parameters
- Use numeric `keyNNNNN` SvcParamKey names for experimental DNS for AI Discovery (DNS-AID) custom parameters until they are registered
- Sign public DNS for AI Discovery (DNS-AID) discovery zones with DNSSEC so validating resolvers return authenticated data

## Example

```dns
_a2a._agents.example.com. 3600 IN SVCB 1 agent.example.com. alpn="a2a" port=443 mandatory=alpn,port
```

## Validate

The scanner validates DNS for AI Discovery (DNS-AID) via DNS-over-HTTPS. By default, the scanner uses Cloudflare's `https://cloudflare-dns.com/dns-query` with automatic fallback to `https://dns.google/resolve` on resolver-level failures. Library callers can override the resolver with `ScanOptions.dohResolverUrl` (disables fallback).

```http
POST https://isitagentready.com/api/scan
Content-Type: application/json

{"url": "https://YOUR-SITE.com"}
```

Check that `checks.discoverability.dnsAid.status` is `"pass"`.

## References

- [draft-mozleywilliams-dnsop-dnsaid](https://datatracker.ietf.org/doc/draft-mozleywilliams-dnsop-dnsaid/)
- [RFC 9460 — SVCB and HTTPS Resource Records](https://www.rfc-editor.org/info/rfc9460)

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…