Free passive security scanning for AI agents. MCP server for checking any domain's email spoofing (DMARC/SPF/DKIM), TLS, security headers, exposed files and subdomain-takeover risk.
- ✓Open-source license (MIT)
- ✓Actively maintained (<30d)
- ✓Clear description
- ✓Documented (README)
claude mcp add nel-veil-mcp -- npx -y nel-veil-mcp{
"mcpServers": {
"nel-veil-mcp": {
"command": "npx",
"args": ["-y", "nel-veil-mcp"]
}
}
}Resumen de MCP Servers
# NEL VEIL MCP — free domain security checks for AI agents
Ask your agent *"can someone spoof email from example.com?"* and get a real answer in about ten seconds.
NEL VEIL MCP gives any MCP-compatible agent **seven tools** for checking a domain's public security posture: email spoofing (DMARC/SPF/DKIM), TLS weaknesses, HTTP security headers, publicly exposed files, subdomain-takeover risk, a combined scan, and retrieval of an earlier scan.
**Free. No API key. No signup.**
---
## Install
**Claude Code** — one command:
```bash
claude mcp add nel-veil -- npx -y nel-veil-mcp
```
**Any MCP client** — add this to your config file:
```json
{
"mcpServers": {
"nel-veil": {
"command": "npx",
"args": ["-y", "nel-veil-mcp"]
}
}
}
```
**Run it directly**, to check it works:
```bash
npx -y nel-veil-mcp
```
It prints a ready line **to stderr** — something like `nel-veil-mcp 0.1.5 ready — 7 tools, free passive tier.` — and then waits for JSON-RPC on stdin. That is correct: it is a stdio server, not a CLI, and stdout carries the protocol, so nothing else is ever written there.
Requires Node 18 or newer.
---
## 30 seconds: is your domain spoofable?
After installing, ask your agent:
> Check if example.com can be email-spoofed.
It calls `check_email_spoofing`. Real output for `example.com` at the time of writing:
```
Check if a domain can be email-spoofed — example.com
Score: 100/100 (done)
2 findings:
[LOW] DMARC has no reporting address (rua/ruf), you have no visibility into spoofing
[LOW] DKIM key may be 1024-bit (weak), 2048-bit recommended
Free check, built from public information. No port scanning and no exploit testing —
though some checks (TLS via Qualys SSL Labs, admin-panel reachability) do more than
passive reading; see nelprofessional.com/mcp. Active scanning requires verified domain
ownership and runs only at nelprofessional.com.
More: https://www.nelprofessional.com/mcp
```
That domain is in good shape. The finding people are most often surprised by is a DMARC policy of `p=none` — it looks configured, monitors everything, and blocks nothing.
---
## Tools
| Tool | Answers |
|---|---|
| `check_email_spoofing` | Can someone send email that appears to come from this domain? (DMARC/SPF/DKIM) |
| `check_tls` | Does this domain's TLS have known weaknesses? (Qualys SSL Labs grade — see the note below) |
| `check_security_headers` | Does this site send the headers that protect visitors in the browser? |
| `check_exposed_files` | Is this domain publicly serving files it should not be? |
| `check_subdomain_takeover` | Are there DNS records pointing at services someone else could claim? |
| `scan_domain` | All of the above at once, with a per-module score. |
| `get_scan_report` | Retrieve a scan already run at nelprofessional.com, by its `scn_…` id. |
Each returns a 0–100 score plus specific findings you can act on.
---
## What this sends — stated plainly
Being precise here matters more than sounding safe, because this is the paragraph you rely on when deciding whether you may point a tool at someone else's domain.
**No tool here does port scanning or exploit testing.** Those are genuinely intrusive, they need the domain owner's permission, and they are deliberately not exposed over MCP at all.
**But "passive" is not the same as "invisible", and two tools do more than read public records:**
- **`check_tls` is not passive.** It queries **Qualys SSL Labs**, which performs its own *active* TLS assessment of the target from Qualys's infrastructure (reusing a recent cached result when Qualys has one). NEL sends no probe itself, but running this does cause the target to be actively tested by a third party. It returns the SSL Labs grade and known problems — Heartbleed, POODLE, RC4, deprecated protocols, weak forward secrecy, certificate chain issues. It does **not** report certificate expiry, issuer, or hostname validity.
- **`check_subdomain_takeover` is not DNS-only.** It resolves a small fixed list of common subdomain names and makes one HTTPS request to any that point at a known cloud host. It never claims or modifies anything.
- **`check_exposed_files`** requests a small fixed list of well-known paths (`.env`, `.git/config` and similar). It never brute-forces or fuzzes — the list does not grow or adapt — but these are paths a crawler would not request, so they are recognisable in a target's logs as a security check.
- **`scan_domain`** runs all of the above, and additionally checks whether common admin panels (`/phpmyadmin/`, `/manager/html`) are publicly reachable.
Everything above is information the domain publishes. None of it attacks anything. But it is more than ordinary crawling, so prefer running it against a domain you own or are authorised to assess.
Active scanning — port exposure, API probing, proof-of-concept checks — lives at [nelprofessional.com](https://www.nelprofessional.com), behind DNS-TXT proof that you control the domain. That is the right place for it, because a human proves ownership once and NEL can stand behind the result.
**Rate limits.** Ten single checks and three full scans per minute, per IP address. If you hit it, wait a minute.
**Privacy.** This package sends no API key, no email address, and no account identifier. Each request carries the domain you asked about and a `nel-veil-mcp` user-agent. Note that, like any HTTP service, NEL sees the IP the request came from — it is what the rate limit is keyed on.
---
## Configuration
| Variable | Default | Purpose |
|---|---|---|
| `NEL_API_URL` | `https://api.nelprofessional.com` | Point at a self-hosted NEL backend. Only needed for local development. |
---
## Development
These steps need the [git repository](https://github.com/NELPROINC/nel-veil-mcp), not the published npm package — the tarball ships only `dist/`, so `src/` and `scripts/` are not in it.
```bash
git clone https://github.com/NELPROINC/nel-veil-mcp.git
cd nel-veil-mcp
npm install
npm run build
node scripts/mcp-smoke.mjs example.com
```
`scripts/mcp-smoke.mjs` launches the built server exactly as `npx` would, performs the MCP handshake, lists the tools and calls one for real — so it catches transport and schema problems a unit test would not.
---
## About NEL VEIL
NEL VEIL is the security scanner behind [NEL Professional](https://www.nelprofessional.com), a marketplace connecting organisations with verified cybersecurity professionals. The same modules that power this MCP server power the scans on the site.
Full documentation: [nelprofessional.com/mcp](https://www.nelprofessional.com/mcp)
---
## License
MIT — see [LICENSE](LICENSE).
Lo que la gente pregunta sobre nel-veil-mcp
¿Qué es NELPROINC/nel-veil-mcp?
+
NELPROINC/nel-veil-mcp es mcp servers para el ecosistema de Claude AI. Free passive security scanning for AI agents. MCP server for checking any domain's email spoofing (DMARC/SPF/DKIM), TLS, security headers, exposed files and subdomain-takeover risk. Tiene 0 estrellas en GitHub y su última actualización registrada es del 2026-08-25.
¿Cómo se instala nel-veil-mcp?
+
Puedes instalar nel-veil-mcp clonando el repositorio (https://github.com/NELPROINC/nel-veil-mcp) o siguiendo las instrucciones del README en GitHub. ClaudeWave también te ofrece bloques de instalación rápida en esta misma página.
¿Es seguro usar NELPROINC/nel-veil-mcp?
+
Nuestro agente de seguridad ha analizado NELPROINC/nel-veil-mcp y le ha asignado un Trust Score de 87/100 (tier: Trusted). Revisa el desglose completo de comprobaciones superadas y flags en esta página.
¿Quién mantiene NELPROINC/nel-veil-mcp?
+
NELPROINC/nel-veil-mcp es mantenido por NELPROINC. La última actividad registrada en GitHub es del 2026-08-25, con 0 issues abiertos.
¿Hay alternativas a nel-veil-mcp?
+
Sí. En ClaudeWave puedes explorar mcp servers similares en /categories/mcp, ordenados por popularidad o actividad reciente.
Despliega nel-veil-mcp en tu cloud
Lleva este repo a producción en minutos. Cada plataforma genera su propio entorno con variables de entorno editables.
¿Mantienes este repo? Añade un badge a tu README
Pega el badge en tu README de GitHub para mostrar que está auditado por ClaudeWave. Cada badge enlaza de vuelta a esta página y muestra el Trust Score actual.
[](https://claudewave.com/repo/nelproinc-nel-veil-mcp)<a href="https://claudewave.com/repo/nelproinc-nel-veil-mcp"><img src="https://claudewave.com/api/badge/nelproinc-nel-veil-mcp" alt="Featured on ClaudeWave: NELPROINC/nel-veil-mcp" width="320" height="64" /></a>Más MCP Servers
Fair-code workflow automation platform with native AI capabilities. Combine visual building with custom code, self-host or cloud, 400+ integrations.
User-friendly AI Interface (Supports Ollama, OpenAI API, ...)
An open-source AI agent that brings the power of Gemini directly into your terminal.
Real-time global intelligence dashboard. AI-powered news aggregation, geopolitical monitoring, and infrastructure tracking in a unified situational awareness interface
The fastest path to AI-powered full stack observability, even for lean teams.
🕷️ An adaptive Web Scraping framework that handles everything from a single request to a full-scale crawl!