인증된 AgentReady.md 증명서
발급일 sig: 5f9128674b8f29f0 검증 →

분석된 URL

https://admintoolkit.io

측정: 지난주

다른 URL 분석

AI-Ready 점수

우수

/ 100

토큰 절감량

HTML 토큰 31.384
Markdown 토큰 1324
절감 96%

점수 상세

접근성 88/100
AI 발견 가능성 93/100
구조화 데이터 100/100
시맨틱 HTML 100/100
콘텐츠 효율성 74/100

신흥 프로토콜

6개 중 3개 감지

AI 에이전트가 찾는 well-known 엔드포인트. 감지되면 에이전트가 서비스를 자동으로 발견하고 연결할 수 있습니다.

  • OAuth Protected Resource RFC 9728
    /.well-known/oauth-protected-resource
  • OAuth Discovery RFC 8414
    /.well-known/oauth-authorization-server
  • MCP Server Card SEP-1649 draft
    /.well-known/mcp/server-card.json
  • A2A Agent Card A2A v1.0
    /.well-known/agent-card.json
    • name: admintoolkit.io
    • v2026-07-01
    • 4 capabilities
    • 2 skill(s)
  • API Catalog RFC 9727
    /.well-known/api-catalog
    • 1 API(s)
  • Agent Skills index Discovery RFC v0.2.0 draft
    /.well-known/agent-skills/index.json
    • 4 skill(s)
    • check-mail-and-tls-readiness, markdown-negotiation, use-admintoolkit-tools, validate-agent-discovery

이 점수는 그대로 있지 않습니다. 모니터링은 아직 없습니다. 명단에 등록하면 출시할 때 알려드립니다.

명단에 등록되었습니다! 서비스 출시 시 알려드리겠습니다.

측정 결과 Content ratio: 5.7% (6259 content chars / 109861 HTML bytes)

페이지의 실제 콘텐츠와 전체 HTML의 비율이 낮습니다. 페이지 무게의 상당 부분이 콘텐츠가 아닌 마크업, 스크립트, 스타일입니다.

구현 방법

CSS를 외부 스타일시트로 이동하고, 인라인 스타일을 제거하고, JavaScript를 최소화하고, HTML이 콘텐츠 구조에 집중하도록 하세요.

코딩 에이전트에 붙여넣어 수정하게 하세요
Markdown 토큰: 1324
## Essential Tools for Admins, Engineers and AI Agents

Network ToolsEmail SecurityBrowser-based

admintoolkit.io brings together essential browser tools for admins, engineers and AI agents: DNS, mail security, TLS, HTTP headers, public IP checks, CIDR, EDID, and agent-readable web metadata such as robots.txt, llms.txt, A2A Agent Cards, and WebMCP tool definitions. The tools are built for traceable diagnostics with local parsing where possible, explicit live lookups, and WebMCP support for AI agents.

Check RFC 9309 robots.txt matching for documented or custom crawler product tokens with merged groups, transport evidence, and registry provenance.

Web / SEO

Validate the required initial H1, optional summary and project details, and any H2 resource lists with link titles, URLs, optional descriptions, findings, and source-line evidence.

Web / SEO

Validate A2A Agent Card discovery JSON, skills, interfaces, capabilities, and deployment metadata.

Agentic Web

Inspect WebMCP declarative and imperative static source without executing JavaScript; runtime tools require actual browser observation.

Agentic Web

Query MX records through DNS-over-HTTPS, sort priorities, resolve first hosts, and spot Null MX or CNAME problems.

Email Security

Parse SPF, DMARC, and DKIM TXT records, highlight policy issues, and run DNS lookup only when needed.

Email Security

Parse full message headers locally, preserve raw Received order, and classify recorded Authentication-Results without claiming cryptographic or reverse-DNS verification.

Email Security

Check ARC instance structure, continuity, and recorded cv state without claiming cryptographic validation or sealer trust.

Email Security

Check BIMI records, DMARC readiness, logo and certificate URLs, and generate a conservative BIMI TXT draft.

Email Security

Assess MTA-STS TXT and HTTPS policy files, compare MX coverage, and return conformance findings with remediation warnings.

Email Security

Assess TLS-RPT TXT records, validate RUA destinations, flag external providers, and return conformance findings with remediation warnings.

Email Security

Review MX, STARTTLS, certificate match, MTA-STS, TLS-RPT, and optional DANE and FCrDNS readiness evidence.

Email Security

Review DS, DNSKEY, RRSIG structural inventory and the validating resolver's DNSSEC verdict for a domain.

DNS Security

Build valid TLSA records from certificate data and compare DANE fields directly with live DNS TLSA answers.

DNS Security

Validate DANE service owner names, TLSA RRsets, DNSSEC context, and implemented DANE-EE live comparisons.

DNS Security

Check and generate CAA issue, issuewild, iodef, ACME account bindings, validation methods, and issuemail tags.

DNS Security

Analyze pasted HTTP response headers locally, or fetch headers for a public URL through the restricted endpoint.

Web Security

Decode X.509 certificates in the browser, or fetch one public host certificate through the guarded TLS endpoint.

Web Security

Validate RFC 9116 vulnerability-disclosure contacts, expiry, canonical URL, policy, encryption, and hiring fields.

Web Security

Run separate exact-version TLS probes and summarize verified certificate identity, negotiated cipher/ALPN evidence, and HTTPS-only HSTS evidence.

Web Security

Check bounded redirect chains, final status, HTML and HTTP canonical hints, robots metadata, scoped X-Robots-Tag, hreflang, and separate sitemap reachability and membership.

Web / SEO

Shows the canonical public address, observed peer, trusted-proxy evidence, browser metadata, and forwarded headers; Geo-IP/ASN and map requests require separate clicks.

Network

Calculate exact IPv4 and IPv6 networks and BigInt address counts locally, including RFC 3021 /31, host /32, embedded IPv4, and capped split previews.

Network

Decode EDID hex or local files into display identity, timings, CTA blocks, audio data, HDR metadata, and checksum status.

Hardware / AV

Local parsers stay in the browser where possible. DNS, HTTP, TLS, Geo-IP and map calls are shown as live actions; the public-IP reflection is same-origin, while Geo-IP/ASN and map requests require separate clicks.

## Smart checks for real troubleshooting

admintoolkit.io is for the checks that come up while operating DNS, mail, TLS, web, network, and AV systems. It keeps each result close to the input: public IP context, MX routing, SPF/DMARC/DKIM/BIMI records, message headers, DNSSEC and DANE evidence, CAA policy, certificates, HTTP response headers, CIDR math, EDID data, and agentic web metadata such as llms.txt, robots.txt, A2A Agent Cards, and WebMCP tool definitions. Agent-ready diagnostics: admintoolkit.io exposes its 24 tools as read-only WebMCP runtime tools where supported by compatible agents. The pages are intentionally narrow. They give you one readable fact at a time, with the raw value still visible enough to compare against logs, tickets, DNS changes, firewall rules, or the device that produced the data.

## Local first, live when needed

Some tools are fully local, including header parsing, certificate decoding from pasted data, CIDR calculation, EDID decoding, and static validation of robots.txt, llms.txt, A2A, WebMCP, security.txt, ARC, and pasted DNS records. Live checks are separated by action and by tool: DNS uses browser DNS-over-HTTPS first with same-origin fallback when needed, public IP and selected host checks use same-origin helper endpoints, Geo-IP uses api.ip.sb, and the map loads only after its own opt-in. If a tool needs a current network answer, the lookup path is visible and limited to the data needed for that check.

## Built for first-pass evidence

The point is not to replace vendor consoles, packet captures, DNSViz, mail logs, or full audits. The point is to get a clear first-pass fact without losing time: which address is visible, which DNS record exists, whether DNSSEC, DANE, MTA-STS, TLS-RPT, or SMTP TLS evidence lines up, which certificate is served, which header is missing, which subnet contains an address, what an EDID block says, or whether emerging agentic web metadata is structurally ready before publication. That is usually enough to decide the next step without turning a quick report into a noisy investigation.
admintoolkit - Admin, Engineer & AI Tools                           [Skip to content](https://admintoolkit.io/#app "Skip to main content")

# Essential Tools for Admins, Engineers and AI Agents

Network ToolsEmail SecurityBrowser-based

admintoolkit.io brings together essential browser tools for admins, engineers and AI agents: DNS, mail security, TLS, HTTP headers, public IP checks, CIDR, EDID, and agent-readable web metadata such as robots.txt, llms.txt, A2A Agent Cards, and WebMCP tool definitions. The tools are built for traceable diagnostics with local parsing where possible, explicit live lookups, and WebMCP support for AI agents.

[AI Crawler robots.txt Checker](https://admintoolkit.io/ai-crawler-robots-checker/ "AI Crawler robots.txt Checker")

Check RFC 9309 robots.txt matching for documented or custom crawler product tokens with merged groups, transport evidence, and registry provenance.

Web / SEO

[llms.txt Validator](https://admintoolkit.io/llms-txt-validator/ "llms.txt Validator")

Validate the required initial H1, optional summary and project details, and any H2 resource lists with link titles, URLs, optional descriptions, findings, and source-line evidence.

Web / SEO

[A2A Agent Card Validator](https://admintoolkit.io/a2a-agent-card-validator/ "A2A Agent Card Validator")

Validate A2A Agent Card discovery JSON, skills, interfaces, capabilities, and deployment metadata.

Agentic Web

[WebMCP Tool Validator](https://admintoolkit.io/webmcp-tool-validator/ "WebMCP Tool Validator")

Inspect WebMCP declarative and imperative static source without executing JavaScript; runtime tools require actual browser observation.

Agentic Web

[MX Record Check](https://admintoolkit.io/mx-record-check/ "MX Record Check")

Query MX records through DNS-over-HTTPS, sort priorities, resolve first hosts, and spot Null MX or CNAME problems.

Email Security

[SPF/DMARC/DKIM Checker](https://admintoolkit.io/spf-dmarc-dkim-checker/ "SPF/DMARC/DKIM Checker")

Parse SPF, DMARC, and DKIM TXT records, highlight policy issues, and run DNS lookup only when needed.

Email Security

[Email Message Header Analyzer](https://admintoolkit.io/email-header-analyzer/ "Email Message Header Analyzer")

Parse full message headers locally, preserve raw Received order, and classify recorded Authentication-Results without claiming cryptographic or reverse-DNS verification.

Email Security

[ARC Chain Validator](https://admintoolkit.io/arc-chain-validator/ "ARC Chain Validator")

Check ARC instance structure, continuity, and recorded cv state without claiming cryptographic validation or sealer trust.

Email Security

[BIMI Checker/Generator](https://admintoolkit.io/bimi-checker-generator/ "BIMI Checker/Generator")

Check BIMI records, DMARC readiness, logo and certificate URLs, and generate a conservative BIMI TXT draft.

Email Security

[MTA-STS Checker/Generator](https://admintoolkit.io/mta-sts-checker-generator/ "MTA-STS Checker/Generator")

Assess MTA-STS TXT and HTTPS policy files, compare MX coverage, and return conformance findings with remediation warnings.

Email Security

[TLS-RPT Checker/Generator](https://admintoolkit.io/tls-rpt-checker-generator/ "TLS-RPT Checker/Generator")

Assess TLS-RPT TXT records, validate RUA destinations, flag external providers, and return conformance findings with remediation warnings.

Email Security

[SMTP TLS Handshake / Mail Domain Delivery Readiness](https://admintoolkit.io/smtp-tls-readiness-checker/ "SMTP TLS Handshake / Mail Domain Delivery Readiness")

Review MX, STARTTLS, certificate match, MTA-STS, TLS-RPT, and optional DANE and FCrDNS readiness evidence.

Email Security

[DNSSEC Validator](https://admintoolkit.io/dnssec-validator/ "DNSSEC Validator")

Review DS, DNSKEY, RRSIG structural inventory and the validating resolver's DNSSEC verdict for a domain.

DNS Security

[TLSA Record Checker/Generator](https://admintoolkit.io/tlsa-record-checker-generator/ "TLSA Record Checker/Generator")

Build valid TLSA records from certificate data and compare DANE fields directly with live DNS TLSA answers.

DNS Security

[DANE Validator](https://admintoolkit.io/dane-validator/ "DANE Validator")

Validate DANE service owner names, TLSA RRsets, DNSSEC context, and implemented DANE-EE live comparisons.

DNS Security

[CAA Record Checker/Generator](https://admintoolkit.io/caa-record-checker-generator/ "CAA Record Checker/Generator")

Check and generate CAA issue, issuewild, iodef, ACME account bindings, validation methods, and issuemail tags.

DNS Security

[HTTP Header Analyzer](https://admintoolkit.io/http-header-analyzer/ "HTTP Header Analyzer")

Analyze pasted HTTP response headers locally, or fetch headers for a public URL through the restricted endpoint.

Web Security

[SSL Certificate Decoder](https://admintoolkit.io/ssl-cert-decoder/ "SSL Certificate Decoder")

Decode X.509 certificates in the browser, or fetch one public host certificate through the guarded TLS endpoint.

Web Security

[security.txt Validator/Generator](https://admintoolkit.io/security-txt-validator-generator/ "security.txt Validator/Generator")

Validate RFC 9116 vulnerability-disclosure contacts, expiry, canonical URL, policy, encryption, and hiring fields.

Web Security

[TLS Configuration Checker](https://admintoolkit.io/tls-configuration-checker/ "TLS Configuration Checker")

Run separate exact-version TLS probes and summarize verified certificate identity, negotiated cipher/ALPN evidence, and HTTPS-only HSTS evidence.

Web Security

[Redirect / Canonical / Indexability Checker](https://admintoolkit.io/redirect-canonical-indexability-checker/ "Redirect / Canonical / Indexability Checker")

Check bounded redirect chains, final status, HTML and HTTP canonical hints, robots metadata, scoped X-Robots-Tag, hreflang, and separate sitemap reachability and membership.

Web / SEO

[What is my IP?](https://admintoolkit.io/what-is-my-ip/ "What is my IP?")

Shows the canonical public address, observed peer, trusted-proxy evidence, browser metadata, and forwarded headers; Geo-IP/ASN and map requests require separate clicks.

Network

[CIDR/Subnet Calculator](https://admintoolkit.io/cidr-subnet-calculator/ "CIDR/Subnet Calculator")

Calculate exact IPv4 and IPv6 networks and BigInt address counts locally, including RFC 3021 /31, host /32, embedded IPv4, and capped split previews.

Network

[HDMI EDID Decoder](https://admintoolkit.io/edid-decoder/ "HDMI EDID Decoder")

Decode EDID hex or local files into display identity, timings, CTA blocks, audio data, HDR metadata, and checksum status.

Hardware / AV

Local parsers stay in the browser where possible. DNS, HTTP, TLS, Geo-IP and map calls are shown as live actions; the public-IP reflection is same-origin, while Geo-IP/ASN and map requests require separate clicks.

## Root WebMCP tool contracts

The root page registers 24 directly executable, read-only WebMCP diagnostics. Each tool has a direct runtime handler and returns structured findings. Discovery endpoints include /tools.json, /.well-known/webmcp.json, /.well-known/mcp.json, /.well-known/tools.json, /mcp/tools, /.well-known/openapi.json, and /.well-known/api-catalog.

AI Crawler robots.txt Checker: Return a read-only RFC 9309 robots.txt access report for AI and search crawlers. Accepts robots.txt text or a public robots.txt URL plus an optional path. Includes merged matching groups, octet-normalized longest-match decisions, per-crawler evidence, transport status, crawler-registry provenance and policy snippets.

Url  Path  Content  Crawlers  Run AI Crawler robots.txt Checker

llms.txt Validator: Validate the required initial H1, optional summary and project details, and any H2 resource lists with link titles, URLs, optional descriptions, findings, and source-line evidence.

Url  Content  Run llms.txt Validator

A2A Agent Card Validator: Return a read-only version-aware A2A Agent Card validation report. Includes v0.2, v0.3 and v1.0 structure plus discovery-path evidence without claiming endpoint, authentication or signature conformance.

Url  Json  Run A2A Agent Card Validator

WebMCP Tool Validator: Return a read-only WebMCP report for pasted or fetched source. Includes declarative and imperative static-source evidence separately from caller-provided runtime observation; pasted JavaScript is never executed and active runtime tools are never inferred from source alone.

Url  Source  Run WebMCP Tool Validator

MX Record Check: Return a read-only MX routing report for a mail domain. Accepts a domain name. Includes exchanger hosts, preferences, Null MX, CNAME risk, address resolution and actionable mail-routing warnings.

Domain  Run MX Record Check

SPF/DMARC/DKIM Checker: Return a read-only SPF, DMARC and DKIM report for a mail domain. Accepts a domain plus optional pasted TXT values. Includes syntax, policy strength, alignment, DNS evidence and record-specific warnings.

Domain  Selector mode  Selector  Policy  Spf record  Dmarc record  Dkim record  Run SPF/DMARC/DKIM Checker

Email Message Header Analyzer: Return a read-only email message header report. Accepts pasted RFC 5322 headers. Includes raw Received order, recorded Authentication-Results and caller-configured authserv-id trust; it does not perform cryptographic authentication or reverse-DNS verification.

Headers  Trusted authserv ids  Run Email Message Header Analyzer

ARC Chain Validator: Return a read-only ARC structural validation report. Accepts pasted ARC-Seal, ARC-Message-Signature and ARC-Authentication-Results fields. Includes structural completeness, instance continuity and recorded cv state; cryptographic validation and sealer trust are not evaluated.

Headers  Run ARC Chain Validator

BIMI Checker/Generator: Return a read-only BIMI readiness report for a mail domain. Accepts a domain, selector and optional BIMI, DMARC, logo or certificate evidence. Includes TXT syntax, DMARC dependency, asset URL findings and a conservative BIMI draft.

Domain  Selector  Record  Dmarc  Logo url  Evidence url  Run BIMI Checker/Generator

MTA-STS Checker/Generator: Return a read-only MTA-STS deployment report for a mail domain. Accepts a domain plus optional TXT, policy, MX and TLS-RPT evidence. Includes mode, max-age, syntax, id consistency, MX coverage, conformance findings and remediation warnings.

Domain  Dns txt  Policy  Mode  Mx hosts  Tls rpt  Run MTA-STS Checker/Generator

TLS-RPT Checker/Generator: Return a read-only SMTP TLS Reporting report for a mail domain. Accepts a domain plus optional TLS-RPT TXT or RUA values. Includes version syntax, reporting destinations, external-provider use, conformance findings and remediation warnings.

Domain  Dns txt  Rua  Run TLS-RPT Checker/Generator

SMTP TLS Handshake / Mail Domain Delivery Readiness: Return a read-only SMTP TLS delivery readiness report for a mail domain. Accepts a domain and optional MTA-STS, TLS-RPT, DANE and FCrDNS checks. Includes MX, STARTTLS, certificate, policy-alignment and downgrade-risk findings.

Domain  Check mta sts  Check tls rpt  Check dane  Check fcrdns  Run SMTP TLS Handshake / Mail Domain Delivery Readiness

DNSSEC Validator: Return a read-only DNSSEC evidence report for a domain. Accepts a domain plus optional DS, DNSKEY, RRSIG and resolver-status data. Includes chain readiness, algorithms, missing records, validation findings and warnings.

Domain  Ds records  Dnskey records  Rrsig records  Status  Run DNSSEC Validator

TLSA Record Checker/Generator: Return a read-only DANE TLSA record report. Accepts host, port, protocol, usage, selector, matching type and optional certificate data. Includes owner name, digest, generated TLSA data and DNS comparison findings.

Host  Port  Protocol  Usage  Selector  Matching  Pem  File  Run TLSA Record Checker/Generator

DANE Validator: Return a read-only DANE service validation report. Accepts service host, port, protocol, TLSA records, DNSSEC status and optional certificate evidence. Includes owner names, TLSA syntax, DNSSEC dependency and certificate-match findings.

Host  Port  Protocol  Mode  Tlsa records  Dnssec  Run DANE Validator

CAA Record Checker/Generator: Return a read-only CAA certificate-authority policy report for a domain. Accepts a domain plus optional CAA records and issuer details. Includes issue, issuewild, iodef, ACME parameters, policy gaps and record-generation guidance.

Domain  Records  Ca  Iodef  Methods  Issuemail  Run CAA Record Checker/Generator

HTTP Header Analyzer: Return a read-only HTTP response-header report for a public endpoint. Accepts pasted headers or a public URL. Includes security, cache, framing, duplicate/conflicting header fields, prioritized findings and remediation notes.

Url  Headers  Run HTTP Header Analyzer

SSL Certificate Decoder: Return a read-only X.509 TLS certificate report. Accepts PEM text or public TLS host details. Includes subject, issuer, SANs, validity, fingerprints, key usage, extensions, hostname and certificate-health findings.

Host  Port  Protocol  Pem  Run SSL Certificate Decoder

security.txt Validator/Generator: Return a read-only RFC 9116 security.txt report. Accepts pasted content or a public security.txt URL plus optional contact fields. Includes contact, expiry, canonical, encryption, policy, language fields, findings and draft output.

Url  Content  Contact  Encryption  Policy  Pgp key  Run security.txt Validator/Generator

TLS Configuration Checker: Return a read-only public TLS configuration report for a host. Accepts host and port plus optional HSTS evidence. Includes separate exact-version probes, a distinct verified default handshake, SAN identity/trust evidence, negotiated cipher and ALPN evidence, and HTTPS-only HSTS checks; it does not claim cipher or ALPN enumeration.

Host  Port  Hsts  Run TLS Configuration Checker

Redirect / Canonical / Indexability Checker: Return a read-only redirect, canonical and indexability report for a public URL. Accepts a URL. Includes bounded per-hop status and SSRF evidence, final URL, HTML and HTTP canonical hints, robots meta and scoped X-Robots-Tag directives, hreflang, separate sitemap reachability and membership, and evidence completeness.

Url  Run Redirect / Canonical / Indexability Checker

What is my IP?: Return a read-only same-origin IP context report for the current request. Requires no input. Includes the canonical primary address, directly observed peer, trusted-proxy decision, preserved forwarded-header claims and observed address family; one request path does not prove dual-stack capability and no third-party Geo-IP lookup is performed.

 Run What is my IP?

CIDR/Subnet Calculator: Return a read-only local IPv4 or IPv6 CIDR report. Accepts a CIDR block plus optional split prefix and address family. Includes exact BigInt-derived boundaries and address counts, RFC 3021 /31 and host-route /32 semantics, no IPv6 broadcast claim, embedded-IPv4 parsing and a capped subnet preview.

Cidr  Target  Family  Run CIDR/Subnet Calculator

HDMI EDID Decoder: Return a read-only local EDID 1.3/1.4 and bounded CTA report. Includes identity, checksums, feature-qualified preferred timing, detailed timings, SVD/SAD and speaker data, selected CTA extended blocks, and lossless raw unknown blocks from hex or file content. It does not infer Atmos, DTS:X, dynamic HDR, Dolby Vision, HDR10+, FRL, DSC, VRR, ALLM, or QMS from unimplemented evidence.

File  Edid hex  Run HDMI EDID Decoder

## Smart checks for real troubleshooting

admintoolkit.io is for the checks that come up while operating DNS, mail, TLS, web, network, and AV systems. It keeps each result close to the input: public IP context, MX routing, SPF/DMARC/DKIM/BIMI records, message headers, DNSSEC and DANE evidence, CAA policy, certificates, HTTP response headers, CIDR math, EDID data, and agentic web metadata such as llms.txt, robots.txt, A2A Agent Cards, and WebMCP tool definitions. Agent-ready diagnostics: admintoolkit.io exposes its 24 tools as read-only WebMCP runtime tools where supported by compatible agents. The pages are intentionally narrow. They give you one readable fact at a time, with the raw value still visible enough to compare against logs, tickets, DNS changes, firewall rules, or the device that produced the data.

## Local first, live when needed

Some tools are fully local, including header parsing, certificate decoding from pasted data, CIDR calculation, EDID decoding, and static validation of robots.txt, llms.txt, A2A, WebMCP, security.txt, ARC, and pasted DNS records. Live checks are separated by action and by tool: DNS uses browser DNS-over-HTTPS first with same-origin fallback when needed, public IP and selected host checks use same-origin helper endpoints, Geo-IP uses api.ip.sb, and the map loads only after its own opt-in. If a tool needs a current network answer, the lookup path is visible and limited to the data needed for that check.

## Built for first-pass evidence

The point is not to replace vendor consoles, packet captures, DNSViz, mail logs, or full audits. The point is to get a clear first-pass fact without losing time: which address is visible, which DNS record exists, whether DNSSEC, DANE, MTA-STS, TLS-RPT, or SMTP TLS evidence lines up, which certificate is served, which header is missing, which subnet contains an address, what an EDID block says, or whether emerging agentic web metadata is structurally ready before publication. That is usually enough to decide the next step without turning a quick report into a noisy investigation.

이 파일을 서버의 /index.md에 업로드하여 AI 에이전트가 페이지의 깔끔한 버전에 접근할 수 있게 하세요. Accept: text/markdown 콘텐츠 협상을 설정하여 자동으로 제공할 수도 있습니다.

권장 내용

llms.txt 다운로드
# admintoolkit.io

> AdminToolkit exposes read-only DNS, mail, TLS, HTTP, IP, CIDR, EDID, and agentic web diagnostics as same-origin WebMCP-compatible tool contracts with direct runtime handlers, JSON-LD UseAction metadata, OpenAPI 3.1 schemas, /tools.json and /mcp/tools discovery, and document.modelContext.registerToo…

## Main
- [admintoolkit - Admin, Engineer & AI Tools](https://admintoolkit.io): admintoolkit.io gives admins browser-based DNS, mail authentication, TLS, HTTP, public IP, CIDR, and EDID checks with l…
- [Deutsch](https://admintoolkit.io/de/)
- [changelog](https://admintoolkit.io/changelog/)
- [guides](https://admintoolkit.io/guides/)
- [admintoolkit.io](https://admintoolkit.io/)

## Legal
- [privacy](https://admintoolkit.io/privacy/)
- [cookies](https://admintoolkit.io/cookies/)
- [terms](https://admintoolkit.io/terms/)
- [legal notice](https://admintoolkit.io/imprint/)

## Support
- [contact](https://admintoolkit.io/contact/)

전체 llms.txt는 도메인 전체 분석이 필요합니다 (곧 출시)

이 파일을 도메인 루트의 https://admintoolkit.io/llms.txt에 업로드하세요. ChatGPT, Claude, Perplexity 등의 AI 에이전트가 이 파일을 확인하여 사이트 구조를 파악합니다.

이 사이트에는 이미 llms.txt 파일이 있습니다.

유효한 형식
# admintoolkit.io

> admintoolkit.io provides 24 read-only browser diagnostics for IP, DNS, mail, HTTP headers, TLS certificates, subnets, EDID, and agent- and AI-web metadata.
admintoolkit.io provides practical diagnostics for administrators and technical users. Many tools run locally in the browser where possible; network lookups are explicit user actions.
Each tool page includes a human-readable workflow section, limits section, and FAQ references for interpreting the result and understanding which data stays local.

admintoolkit.io is a free, public suite of 24 browser-based, read-only diagnostic tools for DNS, email security, TLS, HTTP, networking, and agent-discovery metadata; it is not a monitoring, automatic-remediation, or configuration-management service. Each result is point-in-time diagnostic evidence for the exact target and input from the matching canonical tool page and published contract; limitations remain part of the result rather than a guarantee. Results exist only for checks the user explicitly ran; nothing is precomputed or inferred. Network-backed checks execute only on explicit user action and only against public targets the user is authorized to inspect. Tools require no secrets, credentials, private keys, access tokens, or confidential payloads. Local processing is used where suitable, with each tool page defining its privacy boundary. Reports identify the tool, target, observation, and important limitation. Consequential DNS, mail, TLS, routing, security, or publishing changes require verification against the authoritative service.

## Primary Pages
- [Admin, Engineer & AI Tools](https://admintoolkit.io/): English home and tool index.
- [Changelog](https://admintoolkit.io/changelog/): English release notes and recent public changes.

## Agent And WebMCP Discovery
- [MCP/WebMCP Tools](https://admintoolkit.io/mcp/tools): Machine-readable list of AdminToolkit read-only diagnostic tools with input schemas, output schemas, readOnly hints, and tool page URLs. Public agent-facing tools are read-only, same-origin, unauthenticated, and designed not to perform destructive actions.
- [Root Tools Manifest](https://admintoolkit.io/tools.json): Same-origin public tools manifest for browser agents and crawler-based tool discovery.
- [WebMCP Manifest](https://admintoolkit.io/.well-known/webmcp.json): WebMCP-compatible discovery metadata for browser agents.
- [MCP-style Tool Catalog Card](https://admintoolkit.io/.well-known/mcp.json): MCP-style tool catalog metadata for AdminToolkit discovery.
- [A2A Agent Card](https://admintoolkit.io/.well-known/agent-card.json): A2A-compatible agent card describing AdminToolkit's agent identity, skills, interfaces, and capabilities for agent-to-agent discovery.
- [OpenAPI Description](https://admintoolkit.io/.well-known/openapi.json): OpenAPI 3.1 description for public read-only endpoints and tool contracts.
- [API Catalog](https://admintoolkit.io/.well-known/api-catalog): Linkset catalog of public API and agent-discovery resources for AdminToolkit.
- [Web Bot Auth Key Directory](https://admintoolkit.io/.well-known/http-message-signatures-directory): Public Ed25519 JWKS key directory for HTTP Message Signatures / Web Bot Auth verification. Private signing keys are not published.
- [Authentication And Access Notes](https://admintoolkit.io/auth.md): Public authentication and access notes for unauthenticated read-only AdminToolkit agent discovery.
- [llms.txt](https://admintoolkit.io/llms.txt): This route inventory and AI-readable navigation file for AdminToolkit's public tools and documentation.
- [security.txt](https://admintoolkit.io/.well-known/security.txt): RFC 9116 security contact metadata for vulnerability disclosure and policy discovery.
- [Homepage Markdown Representation](https://admintoolkit.io/index.md): The English homepage returns its Markdown representation when requested with `Accept: text/markdown`.

## Tools
- [AI Crawler robots.txt Checker](https://admintoolkit.io/ai-crawler-robots-checker/): Accepts robots.txt text or a public robots.txt URL plus an optional path. Reports merged matching groups, octet-normalized longest-match decisions, per-crawler evidence, transport status, crawler-registry provenance and policy snippets — Web / SEO
- [llms.txt Validator](https://admintoolkit.io/llms-txt-validator/): Validate the required initial H1, optional summary and project details, and any H2 resource lists with link titles, URLs, optional descriptions, findings, and source-line evidence — Web / SEO
- [A2A Agent Card Validator](https://admintoolkit.io/a2a-agent-card-validator/): Reports v0.2, v0.3 and v1.0 structure plus discovery-path evidence without claiming endpoint, authentication or signature conformance — Agentic Web
- [WebMCP Tool Validator](https://admintoolkit.io/webmcp-tool-validator/): Reports declarative and imperative static-source evidence separately from caller-provided runtime observation; pasted JavaScript is never executed and active runtime tools are never inferred from source alone — Agentic Web
- [MX Record Check](https://admintoolkit.io/mx-record-check/): Accepts a domain name. Reports exchanger hosts, preferences, Null MX, CNAME risk, address resolution and actionable mail-routing warnings — Email Security
- [SPF/DMARC/DKIM Checker](https://admintoolkit.io/spf-dmarc-dkim-checker/): Accepts a domain plus optional pasted TXT values. Reports syntax, policy strength, alignment, DNS evidence and record-specific warnings — Email Security
- [Email Message Header Analyzer](https://admintoolkit.io/email-header-analyzer/): Accepts pasted RFC 5322 headers. Reports raw Received order, recorded Authentication-Results and caller-configured authserv-id trust; it does not perform cryptographic authentication or reverse-DNS verification — Email Security
- [ARC Chain Validator](https://admintoolkit.io/arc-chain-validator/): Accepts pasted ARC-Seal, ARC-Message-Signature and ARC-Authentication-Results fields. Reports structural completeness, instance continuity and recorded cv state; cryptographic validation and sealer trust are not evaluated — Email Security
- [BIMI Checker/Generator](https://admintoolkit.io/bimi-checker-generator/): Accepts a domain, selector and optional BIMI, DMARC, logo or certificate evidence. Reports TXT syntax, DMARC dependency, asset URL findings and a conservative BIMI draft — Email Security
- [MTA-STS Checker/Generator](https://admintoolkit.io/mta-sts-checker-generator/): Accepts a domain plus optional TXT, policy, MX and TLS-RPT evidence. Reports mode, max-age, syntax, id consistency, MX coverage, conformance findings and remediation warnings — Email Security
- [TLS-RPT Checker/Generator](https://admintoolkit.io/tls-rpt-checker-generator/): Accepts a domain plus optional TLS-RPT TXT or RUA values. Reports version syntax, reporting destinations, external-provider use, conformance findings and remediation warnings — Email Security
- [SMTP TLS Handshake / Mail Domain Delivery Readiness](https://admintoolkit.io/smtp-tls-readiness-checker/): Accepts a domain and optional MTA-STS, TLS-RPT, DANE and FCrDNS checks. Reports MX, STARTTLS, certificate, policy-alignment and downgrade-risk findings — Email Security
- [DNSSEC Validator](https://admintoolkit.io/dnssec-validator/): Accepts a domain plus optional DS, DNSKEY, RRSIG and resolver-status data. Reports chain readiness, algorithms, missing records, validation findings and warnings — DNS Security
- [TLSA Record Checker/Generator](https://admintoolkit.io/tlsa-record-checker-generator/): Accepts host, port, protocol, usage, selector, matching type and optional certificate data. Reports owner name, digest, generated TLSA data and DNS comparison findings — DNS Security
- [DANE Validator](https://admintoolkit.io/dane-validator/): Accepts service host, port, protocol, TLSA records, DNSSEC status and optional certificate evidence. Reports owner names, TLSA syntax, DNSSEC dependency and certificate-match findings — DNS Security
- [CAA Record Checker/Generator](https://admintoolkit.io/caa-record-checker-generator/): Accepts a domain plus optional CAA records and issuer details. Reports issue, issuewild, iodef, ACME parameters, policy gaps and record-generation guidance — DNS Security
- [HTTP Header Analyzer](https://admintoolkit.io/http-header-analyzer/): Accepts pasted headers or a public URL. Reports security, cache, framing, duplicate/conflicting header fields, prioritized findings and remediation notes — Web Security
- [SSL Certificate Decoder](https://admintoolkit.io/ssl-cert-decoder/): Accepts PEM text or public TLS host details. Reports subject, issuer, SANs, validity, fingerprints, key usage, extensions, hostname and certificate-health findings — Web Security
- [security.txt Validator/Generator](https://admintoolkit.io/security-txt-validator-generator/): Accepts pasted content or a public security.txt URL plus optional contact fields. Reports contact, expiry, canonical, encryption, policy, language fields, findings and draft output — Web Security
- [TLS Configuration Checker](https://admintoolkit.io/tls-configuration-checker/): Accepts host and port plus optional HSTS evidence. Reports separate exact-version probes, a distinct verified default handshake, SAN identity/trust evidence, negotiated cipher and ALPN evidence, and HTTPS-only HSTS checks; it does not claim cipher or ALPN enumeration — Web Security
- [Redirect / Canonical / Indexability Checker](https://admintoolkit.io/redirect-canonical-indexability-checker/): Accepts a URL. Reports bounded per-hop status and SSRF evidence, final URL, HTML and HTTP canonical hints, robots meta and scoped X-Robots-Tag directives, hreflang, separate sitemap reachability and membership, and evidence completeness — Web / SEO
- [What is my IP?](https://admintoolkit.io/what-is-my-ip/): Requires no input. Reports the canonical primary address, directly observed peer, trusted-proxy decision, preserved forwarded-header claims and observed address family; one request path does not prove dual-stack capability and no third-party Geo-IP lookup is performed — Network
- [CIDR/Subnet Calculator](https://admintoolkit.io/cidr-subnet-calculator/): Accepts a CIDR block plus optional split prefix and address family. Reports exact BigInt-derived boundaries and address counts, RFC 3021 /31 and host-route /32 semantics, no IPv6 broadcast claim, embedded-IPv4 parsing and a capped subnet preview — Network
- [HDMI EDID Decoder](https://admintoolkit.io/edid-decoder/): Reports identity, checksums, feature-qualified preferred timing, detailed timings, SVD/SAD and speaker data, selected CTA extended blocks, and lossless raw unknown blocks from hex or file content. It does not infer Atmos, DTS:X, dynamic HDR, Dolby Vision, HDR10+, FRL, DSC, VRR, ALLM, or QMS from unimplemented evidence — Hardware / AV

## Guides
- [Guides](https://admintoolkit.io/guides/): In-depth guidance for mail, DNS, TLS, web, network, AV, and agents.
- [From DNS Evidence to a Finding: AdminToolkit's DNS and Mail Security Methodology](https://admintoolkit.io/guides/dns-mail-security-methodology/): Use Methodology 1.2 to reproduce DNSSEC, DANE, mail-auth, and per-address dual-stack SMTP findings without crossing documented trust boundaries.
- [Deploying DANE and TLSA for SMTP Without Losing Mail](https://admintoolkit.io/guides/dane-tlsa-smtp-deployment/): Deploy DANE/TLSA for SMTP with safe records, rollovers, and failure handling.
- [A DMARC Rollout That Does Not Break Your Own Mail](https://admintoolkit.io/guides/dmarc-rollout-playbook/): Roll out DMARC safely from monitoring through enforcement.
- [Diagnosing DNSSEC Outages: From SERVFAIL to the Broken Link](https://admintoolkit.io/guides/dnssec-outage-diagnosis/): Trace DNSSEC SERVFAIL and chain breaks to their root cause.
- [MTA-STS, TLS-RPT, and DANE: Layering Mail Transport Security](https://admintoolkit.io/guides/mta-sts-tls-rpt-dane/): Layer MTA-STS, TLS-RPT, and DANE for mail transport security.
- [CAA Records in Practice: Controlling Certificate Issuance](https://admintoolkit.io/guides/caa-records-in-practice/): Control certificate issuance with practical CAA policy and validation.
- [Email Header Forensics: Reading a Message Like an Investigator](https://admintoolkit.io/guides/email-header-forensics/): Investigate Received lines, authentication results, forwarding, and ARC evidence.
- [Making Your Site Agent-Readable: robots.txt, llms.txt, Agent Cards, and WebMCP](https://admintoolkit.io/guides/agent-readable-website/): Publish honest robots.txt, llms.txt, Agent Cards, and WebMCP discovery.
- [TLS Troubleshooting From the Outside: Certificates, Names, and Handshakes](https://admintoolkit.io/guides/tls-certificate-troubleshooting/): Diagnose certificate, name, SNI, chain, protocol, and handshake failures.
- [SPF Record Design That Survives the 10-Lookup Limit](https://admintoolkit.io/guides/spf-record-design/): Design SPF records that stay within the ten-lookup limit.
- [DKIM Key Rotation Without Breaking Mail](https://admintoolkit.io/guides/dkim-key-rotation/): Rotate DKIM keys safely with overlap and clean selector retirement.
- [How ARC Helps Mail Survive Forwarding](https://admintoolkit.io/guides/arc-forwarding-survival/): Assess forwarded-mail authentication and ARC evidence without overstating trust.
- [BIMI Rollout: From Enforced DMARC to a Visible Logo](https://admintoolkit.io/guides/bimi-logo-rollout/): Build BIMI from enforced DMARC through deployable logo evidence.
- [Planning MX Architecture: Preference, Capacity, and Safe Migration](https://admintoolkit.io/guides/mx-architecture-planning/): Design resilient MX routing, capacity, failover, and migrations.
- [Auditing Mail Delivery Readiness End to End](https://admintoolkit.io/guides/mail-delivery-readiness-audit/): Audit MX, STARTTLS, policy enforcement, DANE, and reverse identity.
- [Reading TLS-RPT Reports in Practice](https://admintoolkit.io/guides/tls-rpt-report-reading/): Turn TLS-RPT aggregates into actionable transport-security evidence.
- [Security Headers That Actually Change Risk](https://admintoolkit.io/guides/security-headers-hardening/): Harden browser security with CSP, HSTS, cookies, isolation, and redirects.
- [security.txt and the Disclosure Process Behind It](https://admintoolkit.io/guides/security-txt-disclosure/): Build an operational vulnerability-disclosure process around security.txt.
- [Hardening TLS Without Guessing at Client Compatibility](https://admintoolkit.io/guides/tls-configuration-hardening/): Harden TLS with measured compatibility and expiring legacy exceptions.
- [Redirects, Canonicals, and Indexability as One System](https://admintoolkit.io/guides/redirect-canonical-indexability/): Align redirects, canonicals, robots, hreflang, sitemaps, and internal links.
- [Public IP, NAT, and Dual Stack: Which Address Is Really Yours?](https://admintoolkit.io/guides/public-ip-nat-dual-stack/): Understand public addressing across NAT, CGNAT, dual stack, and proxies.
- [IPv6 Subnet Planning That Scales](https://admintoolkit.io/guides/ipv6-subnet-planning/): Plan scalable IPv6 prefixes, aggregation, reserves, and documentation.
- [HDMI and EDID Troubleshooting in Real Signal Chains](https://admintoolkit.io/guides/hdmi-edid-troubleshooting/): Trace EDID capability loss through real HDMI signal chains.
- [llms.txt in Practice: Curating a Useful Entry Point](https://admintoolkit.io/guides/llms-txt-in-practice/): Curate a useful llms.txt map with consistent access and indexing signals.
- [Exposing Website Functions as WebMCP Tools](https://admintoolkit.io/guides/webmcp-tool-exposure/): Expose precise WebMCP tools with UI parity and runtime checks.

## Contact, Policies, And Data
- [Contact](https://admintoolkit.io/contact/): English contact form for tool requests, tool questions, bug reports, privacy or legal questions, and other messages.
- [Privacy Policy](https://admintoolkit.io/privacy/): English privacy policy for local processing, live lookups, analytics, logs, and contact details. User-entered tool values are not sent to analytics.
- [Cookies](https://admintoolkit.io/cookies/): English cookie and analytics controls; analytics requires consent and can be declined.
- [Terms of Use](https://admintoolkit.io/terms/): English terms of use. No public pricing page or paid plan is currently published.
- [Legal Notice & Contact](https://admintoolkit.io/imprint/): English legal notice and operator contact: [email protected].

## Optional
- [Full Tool Reference](https://admintoolkit.io/llms-full.txt): Optional English full-context reference for all 24 read-only tools, with inputs, result models, workflows, privacy notes, limits, examples, and FAQs.

접근성

JavaScript 없이 콘텐츠 이용 가능 (100/100)

Content available without JavaScript

HTML에서 콘텐츠가 빠른 위치에 배치 (50/100)

Main content starts at 44% of HTML

적절한 페이지 크기 (100/100)

Page size: 107KB

AI 발견 가능성

robots.txt가 AI 봇 허용 (100/100)

All major AI search bots allowed

Markdown for Agents 지원 (85/100) Application
&#10003; Accept: text/markdown &#10003; .md URL &#10003; <link> tag &#10007; Link header
sitemap.xml 있음 (100/100)

Sitemap found

robots.txt 파일 있음 (100/100)

robots.txt exists

llms.txt 파일 있음 (100/100)

llms.txt exists and is valid

Content-Signal 있음 (robots.txt 또는 HTTP 헤더) (60/100)
&#10003; robots.txt &#10007; HTTP header &#10007; Policy

구조화 데이터

Schema.org / JSON-LD 있음 (100/100)

JSON-LD found: Organization, WebSite, BreadcrumbList, WebPage, WebApplication, ItemList

Open Graph 태그 있음 (100/100)

All OG tags present

메타 설명 있음 (100/100)

Meta description: 158 chars

정규 URL 있음 (100/100)

Canonical URL present

lang 속성 있음 (100/100)

lang="en"

시맨틱 HTML

올바른 제목 계층 구조 (100/100)

Clean heading hierarchy

article 또는 main 요소 사용 (100/100)

Has both <article> and <main>

시맨틱 HTML 요소 사용 (100/100)

36 semantic elements, 27 divs (ratio: 57%)

의미 있는 이미지 alt 속성 (100/100)

No informative images (2 decorative)

낮은 div 중첩 깊이 (100/100)

Avg div depth: 0.0, max: 0

콘텐츠 효율성

양호한 토큰 감소율 (100/100)

96% token reduction (HTML→Markdown)

양호한 콘텐츠 대 잡음 비율 (25/100)

Content ratio: 5.7% (6259 content chars / 109861 HTML bytes)

적절한 페이지 무게 (80/100)

HTML size: 107KB

최소한의 인라인 스타일 (100/100)

0/477 elements with inline styles (0.0%)

{
  "url": "https://admintoolkit.io",
  "timestamp": 1785269726353,
  "fetch": {
    "mode": "simple",
    "timeMs": 152,
    "htmlSizeBytes": 109861,
    "supportsMarkdown": true,
    "markdownAgents": {
      "contentNegotiation": true,
      "mdUrl": {
        "found": true,
        "url": "https://admintoolkit.io/index.md"
      },
      "linkTag": {
        "found": true,
        "url": "https://admintoolkit.io/index.md"
      },
      "linkHeader": {
        "found": false,
        "url": null
      },
      "responseHeaders": {
        "contentSignal": null,
        "xMarkdownTokens": null,
        "vary": "Accept,Accept-Encoding"
      },
      "frontmatter": {
        "present": false,
        "fields": [],
        "level": "none"
      },
      "level": "application",
      "contentNegotiationMediaType": "text/markdown",
      "properMediaType": true
    },
    "statusCode": 200
  },
  "extraction": {
    "title": "admintoolkit - Admin, Engineer & AI Tools",
    "excerpt": "admintoolkit.io gives admins browser-based DNS, mail authentication, TLS, HTTP, public IP, CIDR, and EDID checks with local parsing and explicit live lookups.",
    "byline": null,
    "siteName": "admintoolkit.io",
    "lang": "en",
    "contentLength": 6259,
    "metadata": {
      "description": "admintoolkit.io gives admins browser-based DNS, mail authentication, TLS, HTTP, public IP, CIDR, and EDID checks with local parsing and explicit live lookups.",
      "ogTitle": "admintoolkit - Admin, Engineer & AI Tools",
      "ogDescription": "admintoolkit.io gives admins browser-based DNS, mail authentication, TLS, HTTP, public IP, CIDR, and EDID checks with local parsing and explicit live lookups.",
      "ogImage": "https://admintoolkit.io/brand/admintoolkit/social/home.png",
      "ogType": "website",
      "canonical": "https://admintoolkit.io/",
      "lang": "en",
      "schemas": [
        {
          "@type": "Organization",
          "@id": "https://admintoolkit.io/#organization",
          "name": "admintoolkit.io",
          "url": "https://admintoolkit.io/"
        },
        {
          "@type": "WebSite",
          "@id": "https://admintoolkit.io/#website",
          "name": "admintoolkit.io",
          "url": "https://admintoolkit.io/",
          "publisher": {
            "@id": "https://admintoolkit.io/#organization"
          },
          "inLanguage": [
            "en",
            "de"
          ]
        },
        {
          "@type": "BreadcrumbList",
          "itemListElement": [
            {
              "@type": "ListItem",
              "position": 1,
              "name": "admintoolkit.io",
              "item": "https://admintoolkit.io/"
            }
          ]
        },
        {
          "@type": "WebPage",
          "@id": "https://admintoolkit.io/#webpage",
          "url": "https://admintoolkit.io/",
          "name": "Essential Tools for Admins, Engineers and AI Agents",
          "isPartOf": {
            "@id": "https://admintoolkit.io/#website"
          },
          "inLanguage": "en"
        },
        {
          "@type": "WebApplication",
          "@id": "https://admintoolkit.io/#application",
          "name": "admintoolkit.io",
          "url": "https://admintoolkit.io/",
          "applicationCategory": "UtilitiesApplication",
          "operatingSystem": "Any",
          "isAccessibleForFree": true,
          "description": "AdminToolkit exposes read-only DNS, mail, TLS, HTTP, IP, CIDR, EDID, and agentic web diagnostics as same-origin WebMCP-compatible tool contracts with direct runtime handlers, JSON-LD UseAction metadata, OpenAPI 3.1 schemas, /tools.json and /mcp/tools discovery, and document.modelContext.registerTool as the primary registration path; a distinct legacy navigator.modelContext is used only as a compatibility fallback where present.",
          "publisher": {
            "@id": "https://admintoolkit.io/#organization"
          },
          "potentialAction": [
            {
              "@type": "ViewAction",
              "name": "List AdminToolkit WebMCP tools",
              "description": "Read the same-origin AdminToolkit MCP/WebMCP tool manifest at /tools.json or /mcp/tools with tool names, inputSchema, outputSchema, readOnly flags, OpenAPI links, and tool page URLs.",
              "target": {
                "@type": "EntryPoint",
                "urlTemplate": "https://admintoolkit.io/mcp/tools",
                "httpMethod": "GET",
                "contentType": "application/json"
              }
            },
            {
              "@type": "UseAction",
              "name": "Open AdminToolkit report tool",
              "description": "Resolve a same-origin read-only AdminToolkit report route by slug. The route is described by JSON-LD UseAction metadata, OpenAPI schema links, and document.modelContext.registerTool as the primary registration path; a distinct legacy navigator.modelContext is only a compatibility fallback.",
              "target": {
                "@type": "EntryPoint",
                "urlTemplate": "https://admintoolkit.io/{tool}/",
                "httpMethod": "GET",
                "encodingType": "application/x-www-form-urlencoded",
                "contentType": "text/html"
              },
              "query-input": [
                {
                  "@type": "PropertyValueSpecification",
                  "name": "tool",
                  "valueName": "tool",
                  "description": "AdminToolkit tool route slug.",
                  "valueRequired": true
                }
              ]
            }
          ]
        },
        {
          "@type": "ItemList",
          "@id": "https://admintoolkit.io/#tool-list",
          "name": "AdminToolkit read-only report tools",
          "itemListElement": [
            {
              "@type": "ListItem",
              "position": 1,
              "name": "AI Crawler robots.txt Checker",
              "url": "https://admintoolkit.io/ai-crawler-robots-checker/"
            },
            {
              "@type": "ListItem",
              "position": 2,
              "name": "llms.txt Validator",
              "url": "https://admintoolkit.io/llms-txt-validator/"
            },
            {
              "@type": "ListItem",
              "position": 3,
              "name": "A2A Agent Card Validator",
              "url": "https://admintoolkit.io/a2a-agent-card-validator/"
            },
            {
              "@type": "ListItem",
              "position": 4,
              "name": "WebMCP Tool Validator",
              "url": "https://admintoolkit.io/webmcp-tool-validator/"
            },
            {
              "@type": "ListItem",
              "position": 5,
              "name": "MX Record Check",
              "url": "https://admintoolkit.io/mx-record-check/"
            },
            {
              "@type": "ListItem",
              "position": 6,
              "name": "SPF/DMARC/DKIM Checker",
              "url": "https://admintoolkit.io/spf-dmarc-dkim-checker/"
            },
            {
              "@type": "ListItem",
              "position": 7,
              "name": "Email Message Header Analyzer",
              "url": "https://admintoolkit.io/email-header-analyzer/"
            },
            {
              "@type": "ListItem",
              "position": 8,
              "name": "ARC Chain Validator",
              "url": "https://admintoolkit.io/arc-chain-validator/"
            },
            {
              "@type": "ListItem",
              "position": 9,
              "name": "BIMI Checker/Generator",
              "url": "https://admintoolkit.io/bimi-checker-generator/"
            },
            {
              "@type": "ListItem",
              "position": 10,
              "name": "MTA-STS Checker/Generator",
              "url": "https://admintoolkit.io/mta-sts-checker-generator/"
            },
            {
              "@type": "ListItem",
              "position": 11,
              "name": "TLS-RPT Checker/Generator",
              "url": "https://admintoolkit.io/tls-rpt-checker-generator/"
            },
            {
              "@type": "ListItem",
              "position": 12,
              "name": "SMTP TLS Handshake / Mail Domain Delivery Readiness",
              "url": "https://admintoolkit.io/smtp-tls-readiness-checker/"
            },
            {
              "@type": "ListItem",
              "position": 13,
              "name": "DNSSEC Validator",
              "url": "https://admintoolkit.io/dnssec-validator/"
            },
            {
              "@type": "ListItem",
              "position": 14,
              "name": "TLSA Record Checker/Generator",
              "url": "https://admintoolkit.io/tlsa-record-checker-generator/"
            },
            {
              "@type": "ListItem",
              "position": 15,
              "name": "DANE Validator",
              "url": "https://admintoolkit.io/dane-validator/"
            },
            {
              "@type": "ListItem",
              "position": 16,
              "name": "CAA Record Checker/Generator",
              "url": "https://admintoolkit.io/caa-record-checker-generator/"
            },
            {
              "@type": "ListItem",
              "position": 17,
              "name": "HTTP Header Analyzer",
              "url": "https://admintoolkit.io/http-header-analyzer/"
            },
            {
              "@type": "ListItem",
              "position": 18,
              "name": "SSL Certificate Decoder",
              "url": "https://admintoolkit.io/ssl-cert-decoder/"
            },
            {
              "@type": "ListItem",
              "position": 19,
              "name": "security.txt Validator/Generator",
              "url": "https://admintoolkit.io/security-txt-validator-generator/"
            },
            {
              "@type": "ListItem",
              "position": 20,
              "name": "TLS Configuration Checker",
              "url": "https://admintoolkit.io/tls-configuration-checker/"
            },
            {
              "@type": "ListItem",
              "position": 21,
              "name": "Redirect / Canonical / Indexability Checker",
              "url": "https://admintoolkit.io/redirect-canonical-indexability-checker/"
            },
            {
              "@type": "ListItem",
              "position": 22,
              "name": "What is my IP?",
              "url": "https://admintoolkit.io/what-is-my-ip/"
            },
            {
              "@type": "ListItem",
              "position": 23,
              "name": "CIDR/Subnet Calculator",
              "url": "https://admintoolkit.io/cidr-subnet-calculator/"
            },
            {
              "@type": "ListItem",
              "position": 24,
              "name": "HDMI EDID Decoder",
              "url": "https://admintoolkit.io/edid-decoder/"
            }
          ]
        }
      ],
      "robotsMeta": "index, follow",
      "author": null,
      "generator": null,
      "markdownAlternateHref": "https://admintoolkit.io/index.md"
    }
  },
  "markdown": "## Essential Tools for Admins, Engineers and AI Agents\n\nNetwork ToolsEmail SecurityBrowser-based\n\nadmintoolkit.io brings together essential browser tools for admins, engineers and AI agents: DNS, mail security, TLS, HTTP headers, public IP checks, CIDR, EDID, and agent-readable web metadata such as robots.txt, llms.txt, A2A Agent Cards, and WebMCP tool definitions. The tools are built for traceable diagnostics with local parsing where possible, explicit live lookups, and WebMCP support for AI agents.\n\nCheck RFC 9309 robots.txt matching for documented or custom crawler product tokens with merged groups, transport evidence, and registry provenance.\n\nWeb / SEO\n\nValidate the required initial H1, optional summary and project details, and any H2 resource lists with link titles, URLs, optional descriptions, findings, and source-line evidence.\n\nWeb / SEO\n\nValidate A2A Agent Card discovery JSON, skills, interfaces, capabilities, and deployment metadata.\n\nAgentic Web\n\nInspect WebMCP declarative and imperative static source without executing JavaScript; runtime tools require actual browser observation.\n\nAgentic Web\n\nQuery MX records through DNS-over-HTTPS, sort priorities, resolve first hosts, and spot Null MX or CNAME problems.\n\nEmail Security\n\nParse SPF, DMARC, and DKIM TXT records, highlight policy issues, and run DNS lookup only when needed.\n\nEmail Security\n\nParse full message headers locally, preserve raw Received order, and classify recorded Authentication-Results without claiming cryptographic or reverse-DNS verification.\n\nEmail Security\n\nCheck ARC instance structure, continuity, and recorded cv state without claiming cryptographic validation or sealer trust.\n\nEmail Security\n\nCheck BIMI records, DMARC readiness, logo and certificate URLs, and generate a conservative BIMI TXT draft.\n\nEmail Security\n\nAssess MTA-STS TXT and HTTPS policy files, compare MX coverage, and return conformance findings with remediation warnings.\n\nEmail Security\n\nAssess TLS-RPT TXT records, validate RUA destinations, flag external providers, and return conformance findings with remediation warnings.\n\nEmail Security\n\nReview MX, STARTTLS, certificate match, MTA-STS, TLS-RPT, and optional DANE and FCrDNS readiness evidence.\n\nEmail Security\n\nReview DS, DNSKEY, RRSIG structural inventory and the validating resolver's DNSSEC verdict for a domain.\n\nDNS Security\n\nBuild valid TLSA records from certificate data and compare DANE fields directly with live DNS TLSA answers.\n\nDNS Security\n\nValidate DANE service owner names, TLSA RRsets, DNSSEC context, and implemented DANE-EE live comparisons.\n\nDNS Security\n\nCheck and generate CAA issue, issuewild, iodef, ACME account bindings, validation methods, and issuemail tags.\n\nDNS Security\n\nAnalyze pasted HTTP response headers locally, or fetch headers for a public URL through the restricted endpoint.\n\nWeb Security\n\nDecode X.509 certificates in the browser, or fetch one public host certificate through the guarded TLS endpoint.\n\nWeb Security\n\nValidate RFC 9116 vulnerability-disclosure contacts, expiry, canonical URL, policy, encryption, and hiring fields.\n\nWeb Security\n\nRun separate exact-version TLS probes and summarize verified certificate identity, negotiated cipher/ALPN evidence, and HTTPS-only HSTS evidence.\n\nWeb Security\n\nCheck bounded redirect chains, final status, HTML and HTTP canonical hints, robots metadata, scoped X-Robots-Tag, hreflang, and separate sitemap reachability and membership.\n\nWeb / SEO\n\nShows the canonical public address, observed peer, trusted-proxy evidence, browser metadata, and forwarded headers; Geo-IP/ASN and map requests require separate clicks.\n\nNetwork\n\nCalculate exact IPv4 and IPv6 networks and BigInt address counts locally, including RFC 3021 /31, host /32, embedded IPv4, and capped split previews.\n\nNetwork\n\nDecode EDID hex or local files into display identity, timings, CTA blocks, audio data, HDR metadata, and checksum status.\n\nHardware / AV\n\nLocal parsers stay in the browser where possible. DNS, HTTP, TLS, Geo-IP and map calls are shown as live actions; the public-IP reflection is same-origin, while Geo-IP/ASN and map requests require separate clicks.\n\n## Smart checks for real troubleshooting\n\nadmintoolkit.io is for the checks that come up while operating DNS, mail, TLS, web, network, and AV systems. It keeps each result close to the input: public IP context, MX routing, SPF/DMARC/DKIM/BIMI records, message headers, DNSSEC and DANE evidence, CAA policy, certificates, HTTP response headers, CIDR math, EDID data, and agentic web metadata such as llms.txt, robots.txt, A2A Agent Cards, and WebMCP tool definitions. Agent-ready diagnostics: admintoolkit.io exposes its 24 tools as read-only WebMCP runtime tools where supported by compatible agents. The pages are intentionally narrow. They give you one readable fact at a time, with the raw value still visible enough to compare against logs, tickets, DNS changes, firewall rules, or the device that produced the data.\n\n## Local first, live when needed\n\nSome tools are fully local, including header parsing, certificate decoding from pasted data, CIDR calculation, EDID decoding, and static validation of robots.txt, llms.txt, A2A, WebMCP, security.txt, ARC, and pasted DNS records. Live checks are separated by action and by tool: DNS uses browser DNS-over-HTTPS first with same-origin fallback when needed, public IP and selected host checks use same-origin helper endpoints, Geo-IP uses api.ip.sb, and the map loads only after its own opt-in. If a tool needs a current network answer, the lookup path is visible and limited to the data needed for that check.\n\n## Built for first-pass evidence\n\nThe point is not to replace vendor consoles, packet captures, DNSViz, mail logs, or full audits. The point is to get a clear first-pass fact without losing time: which address is visible, which DNS record exists, whether DNSSEC, DANE, MTA-STS, TLS-RPT, or SMTP TLS evidence lines up, which certificate is served, which header is missing, which subnet contains an address, what an EDID block says, or whether emerging agentic web metadata is structurally ready before publication. That is usually enough to decide the next step without turning a quick report into a noisy investigation.\n",
  "fullPageMarkdown": "admintoolkit - Admin, Engineer & AI Tools                           [Skip to content](https://admintoolkit.io/#app \"Skip to main content\")\n\n# Essential Tools for Admins, Engineers and AI Agents\n\nNetwork ToolsEmail SecurityBrowser-based\n\nadmintoolkit.io brings together essential browser tools for admins, engineers and AI agents: DNS, mail security, TLS, HTTP headers, public IP checks, CIDR, EDID, and agent-readable web metadata such as robots.txt, llms.txt, A2A Agent Cards, and WebMCP tool definitions. The tools are built for traceable diagnostics with local parsing where possible, explicit live lookups, and WebMCP support for AI agents.\n\n[AI Crawler robots.txt Checker](https://admintoolkit.io/ai-crawler-robots-checker/ \"AI Crawler robots.txt Checker\")\n\nCheck RFC 9309 robots.txt matching for documented or custom crawler product tokens with merged groups, transport evidence, and registry provenance.\n\nWeb / SEO\n\n[llms.txt Validator](https://admintoolkit.io/llms-txt-validator/ \"llms.txt Validator\")\n\nValidate the required initial H1, optional summary and project details, and any H2 resource lists with link titles, URLs, optional descriptions, findings, and source-line evidence.\n\nWeb / SEO\n\n[A2A Agent Card Validator](https://admintoolkit.io/a2a-agent-card-validator/ \"A2A Agent Card Validator\")\n\nValidate A2A Agent Card discovery JSON, skills, interfaces, capabilities, and deployment metadata.\n\nAgentic Web\n\n[WebMCP Tool Validator](https://admintoolkit.io/webmcp-tool-validator/ \"WebMCP Tool Validator\")\n\nInspect WebMCP declarative and imperative static source without executing JavaScript; runtime tools require actual browser observation.\n\nAgentic Web\n\n[MX Record Check](https://admintoolkit.io/mx-record-check/ \"MX Record Check\")\n\nQuery MX records through DNS-over-HTTPS, sort priorities, resolve first hosts, and spot Null MX or CNAME problems.\n\nEmail Security\n\n[SPF/DMARC/DKIM Checker](https://admintoolkit.io/spf-dmarc-dkim-checker/ \"SPF/DMARC/DKIM Checker\")\n\nParse SPF, DMARC, and DKIM TXT records, highlight policy issues, and run DNS lookup only when needed.\n\nEmail Security\n\n[Email Message Header Analyzer](https://admintoolkit.io/email-header-analyzer/ \"Email Message Header Analyzer\")\n\nParse full message headers locally, preserve raw Received order, and classify recorded Authentication-Results without claiming cryptographic or reverse-DNS verification.\n\nEmail Security\n\n[ARC Chain Validator](https://admintoolkit.io/arc-chain-validator/ \"ARC Chain Validator\")\n\nCheck ARC instance structure, continuity, and recorded cv state without claiming cryptographic validation or sealer trust.\n\nEmail Security\n\n[BIMI Checker/Generator](https://admintoolkit.io/bimi-checker-generator/ \"BIMI Checker/Generator\")\n\nCheck BIMI records, DMARC readiness, logo and certificate URLs, and generate a conservative BIMI TXT draft.\n\nEmail Security\n\n[MTA-STS Checker/Generator](https://admintoolkit.io/mta-sts-checker-generator/ \"MTA-STS Checker/Generator\")\n\nAssess MTA-STS TXT and HTTPS policy files, compare MX coverage, and return conformance findings with remediation warnings.\n\nEmail Security\n\n[TLS-RPT Checker/Generator](https://admintoolkit.io/tls-rpt-checker-generator/ \"TLS-RPT Checker/Generator\")\n\nAssess TLS-RPT TXT records, validate RUA destinations, flag external providers, and return conformance findings with remediation warnings.\n\nEmail Security\n\n[SMTP TLS Handshake / Mail Domain Delivery Readiness](https://admintoolkit.io/smtp-tls-readiness-checker/ \"SMTP TLS Handshake / Mail Domain Delivery Readiness\")\n\nReview MX, STARTTLS, certificate match, MTA-STS, TLS-RPT, and optional DANE and FCrDNS readiness evidence.\n\nEmail Security\n\n[DNSSEC Validator](https://admintoolkit.io/dnssec-validator/ \"DNSSEC Validator\")\n\nReview DS, DNSKEY, RRSIG structural inventory and the validating resolver's DNSSEC verdict for a domain.\n\nDNS Security\n\n[TLSA Record Checker/Generator](https://admintoolkit.io/tlsa-record-checker-generator/ \"TLSA Record Checker/Generator\")\n\nBuild valid TLSA records from certificate data and compare DANE fields directly with live DNS TLSA answers.\n\nDNS Security\n\n[DANE Validator](https://admintoolkit.io/dane-validator/ \"DANE Validator\")\n\nValidate DANE service owner names, TLSA RRsets, DNSSEC context, and implemented DANE-EE live comparisons.\n\nDNS Security\n\n[CAA Record Checker/Generator](https://admintoolkit.io/caa-record-checker-generator/ \"CAA Record Checker/Generator\")\n\nCheck and generate CAA issue, issuewild, iodef, ACME account bindings, validation methods, and issuemail tags.\n\nDNS Security\n\n[HTTP Header Analyzer](https://admintoolkit.io/http-header-analyzer/ \"HTTP Header Analyzer\")\n\nAnalyze pasted HTTP response headers locally, or fetch headers for a public URL through the restricted endpoint.\n\nWeb Security\n\n[SSL Certificate Decoder](https://admintoolkit.io/ssl-cert-decoder/ \"SSL Certificate Decoder\")\n\nDecode X.509 certificates in the browser, or fetch one public host certificate through the guarded TLS endpoint.\n\nWeb Security\n\n[security.txt Validator/Generator](https://admintoolkit.io/security-txt-validator-generator/ \"security.txt Validator/Generator\")\n\nValidate RFC 9116 vulnerability-disclosure contacts, expiry, canonical URL, policy, encryption, and hiring fields.\n\nWeb Security\n\n[TLS Configuration Checker](https://admintoolkit.io/tls-configuration-checker/ \"TLS Configuration Checker\")\n\nRun separate exact-version TLS probes and summarize verified certificate identity, negotiated cipher/ALPN evidence, and HTTPS-only HSTS evidence.\n\nWeb Security\n\n[Redirect / Canonical / Indexability Checker](https://admintoolkit.io/redirect-canonical-indexability-checker/ \"Redirect / Canonical / Indexability Checker\")\n\nCheck bounded redirect chains, final status, HTML and HTTP canonical hints, robots metadata, scoped X-Robots-Tag, hreflang, and separate sitemap reachability and membership.\n\nWeb / SEO\n\n[What is my IP?](https://admintoolkit.io/what-is-my-ip/ \"What is my IP?\")\n\nShows the canonical public address, observed peer, trusted-proxy evidence, browser metadata, and forwarded headers; Geo-IP/ASN and map requests require separate clicks.\n\nNetwork\n\n[CIDR/Subnet Calculator](https://admintoolkit.io/cidr-subnet-calculator/ \"CIDR/Subnet Calculator\")\n\nCalculate exact IPv4 and IPv6 networks and BigInt address counts locally, including RFC 3021 /31, host /32, embedded IPv4, and capped split previews.\n\nNetwork\n\n[HDMI EDID Decoder](https://admintoolkit.io/edid-decoder/ \"HDMI EDID Decoder\")\n\nDecode EDID hex or local files into display identity, timings, CTA blocks, audio data, HDR metadata, and checksum status.\n\nHardware / AV\n\nLocal parsers stay in the browser where possible. DNS, HTTP, TLS, Geo-IP and map calls are shown as live actions; the public-IP reflection is same-origin, while Geo-IP/ASN and map requests require separate clicks.\n\n## Root WebMCP tool contracts\n\nThe root page registers 24 directly executable, read-only WebMCP diagnostics. Each tool has a direct runtime handler and returns structured findings. Discovery endpoints include /tools.json, /.well-known/webmcp.json, /.well-known/mcp.json, /.well-known/tools.json, /mcp/tools, /.well-known/openapi.json, and /.well-known/api-catalog.\n\nAI Crawler robots.txt Checker: Return a read-only RFC 9309 robots.txt access report for AI and search crawlers. Accepts robots.txt text or a public robots.txt URL plus an optional path. Includes merged matching groups, octet-normalized longest-match decisions, per-crawler evidence, transport status, crawler-registry provenance and policy snippets.\n\nUrl  Path  Content  Crawlers  Run AI Crawler robots.txt Checker\n\nllms.txt Validator: Validate the required initial H1, optional summary and project details, and any H2 resource lists with link titles, URLs, optional descriptions, findings, and source-line evidence.\n\nUrl  Content  Run llms.txt Validator\n\nA2A Agent Card Validator: Return a read-only version-aware A2A Agent Card validation report. Includes v0.2, v0.3 and v1.0 structure plus discovery-path evidence without claiming endpoint, authentication or signature conformance.\n\nUrl  Json  Run A2A Agent Card Validator\n\nWebMCP Tool Validator: Return a read-only WebMCP report for pasted or fetched source. Includes declarative and imperative static-source evidence separately from caller-provided runtime observation; pasted JavaScript is never executed and active runtime tools are never inferred from source alone.\n\nUrl  Source  Run WebMCP Tool Validator\n\nMX Record Check: Return a read-only MX routing report for a mail domain. Accepts a domain name. Includes exchanger hosts, preferences, Null MX, CNAME risk, address resolution and actionable mail-routing warnings.\n\nDomain  Run MX Record Check\n\nSPF/DMARC/DKIM Checker: Return a read-only SPF, DMARC and DKIM report for a mail domain. Accepts a domain plus optional pasted TXT values. Includes syntax, policy strength, alignment, DNS evidence and record-specific warnings.\n\nDomain  Selector mode  Selector  Policy  Spf record  Dmarc record  Dkim record  Run SPF/DMARC/DKIM Checker\n\nEmail Message Header Analyzer: Return a read-only email message header report. Accepts pasted RFC 5322 headers. Includes raw Received order, recorded Authentication-Results and caller-configured authserv-id trust; it does not perform cryptographic authentication or reverse-DNS verification.\n\nHeaders  Trusted authserv ids  Run Email Message Header Analyzer\n\nARC Chain Validator: Return a read-only ARC structural validation report. Accepts pasted ARC-Seal, ARC-Message-Signature and ARC-Authentication-Results fields. Includes structural completeness, instance continuity and recorded cv state; cryptographic validation and sealer trust are not evaluated.\n\nHeaders  Run ARC Chain Validator\n\nBIMI Checker/Generator: Return a read-only BIMI readiness report for a mail domain. Accepts a domain, selector and optional BIMI, DMARC, logo or certificate evidence. Includes TXT syntax, DMARC dependency, asset URL findings and a conservative BIMI draft.\n\nDomain  Selector  Record  Dmarc  Logo url  Evidence url  Run BIMI Checker/Generator\n\nMTA-STS Checker/Generator: Return a read-only MTA-STS deployment report for a mail domain. Accepts a domain plus optional TXT, policy, MX and TLS-RPT evidence. Includes mode, max-age, syntax, id consistency, MX coverage, conformance findings and remediation warnings.\n\nDomain  Dns txt  Policy  Mode  Mx hosts  Tls rpt  Run MTA-STS Checker/Generator\n\nTLS-RPT Checker/Generator: Return a read-only SMTP TLS Reporting report for a mail domain. Accepts a domain plus optional TLS-RPT TXT or RUA values. Includes version syntax, reporting destinations, external-provider use, conformance findings and remediation warnings.\n\nDomain  Dns txt  Rua  Run TLS-RPT Checker/Generator\n\nSMTP TLS Handshake / Mail Domain Delivery Readiness: Return a read-only SMTP TLS delivery readiness report for a mail domain. Accepts a domain and optional MTA-STS, TLS-RPT, DANE and FCrDNS checks. Includes MX, STARTTLS, certificate, policy-alignment and downgrade-risk findings.\n\nDomain  Check mta sts  Check tls rpt  Check dane  Check fcrdns  Run SMTP TLS Handshake / Mail Domain Delivery Readiness\n\nDNSSEC Validator: Return a read-only DNSSEC evidence report for a domain. Accepts a domain plus optional DS, DNSKEY, RRSIG and resolver-status data. Includes chain readiness, algorithms, missing records, validation findings and warnings.\n\nDomain  Ds records  Dnskey records  Rrsig records  Status  Run DNSSEC Validator\n\nTLSA Record Checker/Generator: Return a read-only DANE TLSA record report. Accepts host, port, protocol, usage, selector, matching type and optional certificate data. Includes owner name, digest, generated TLSA data and DNS comparison findings.\n\nHost  Port  Protocol  Usage  Selector  Matching  Pem  File  Run TLSA Record Checker/Generator\n\nDANE Validator: Return a read-only DANE service validation report. Accepts service host, port, protocol, TLSA records, DNSSEC status and optional certificate evidence. Includes owner names, TLSA syntax, DNSSEC dependency and certificate-match findings.\n\nHost  Port  Protocol  Mode  Tlsa records  Dnssec  Run DANE Validator\n\nCAA Record Checker/Generator: Return a read-only CAA certificate-authority policy report for a domain. Accepts a domain plus optional CAA records and issuer details. Includes issue, issuewild, iodef, ACME parameters, policy gaps and record-generation guidance.\n\nDomain  Records  Ca  Iodef  Methods  Issuemail  Run CAA Record Checker/Generator\n\nHTTP Header Analyzer: Return a read-only HTTP response-header report for a public endpoint. Accepts pasted headers or a public URL. Includes security, cache, framing, duplicate/conflicting header fields, prioritized findings and remediation notes.\n\nUrl  Headers  Run HTTP Header Analyzer\n\nSSL Certificate Decoder: Return a read-only X.509 TLS certificate report. Accepts PEM text or public TLS host details. Includes subject, issuer, SANs, validity, fingerprints, key usage, extensions, hostname and certificate-health findings.\n\nHost  Port  Protocol  Pem  Run SSL Certificate Decoder\n\nsecurity.txt Validator/Generator: Return a read-only RFC 9116 security.txt report. Accepts pasted content or a public security.txt URL plus optional contact fields. Includes contact, expiry, canonical, encryption, policy, language fields, findings and draft output.\n\nUrl  Content  Contact  Encryption  Policy  Pgp key  Run security.txt Validator/Generator\n\nTLS Configuration Checker: Return a read-only public TLS configuration report for a host. Accepts host and port plus optional HSTS evidence. Includes separate exact-version probes, a distinct verified default handshake, SAN identity/trust evidence, negotiated cipher and ALPN evidence, and HTTPS-only HSTS checks; it does not claim cipher or ALPN enumeration.\n\nHost  Port  Hsts  Run TLS Configuration Checker\n\nRedirect / Canonical / Indexability Checker: Return a read-only redirect, canonical and indexability report for a public URL. Accepts a URL. Includes bounded per-hop status and SSRF evidence, final URL, HTML and HTTP canonical hints, robots meta and scoped X-Robots-Tag directives, hreflang, separate sitemap reachability and membership, and evidence completeness.\n\nUrl  Run Redirect / Canonical / Indexability Checker\n\nWhat is my IP?: Return a read-only same-origin IP context report for the current request. Requires no input. Includes the canonical primary address, directly observed peer, trusted-proxy decision, preserved forwarded-header claims and observed address family; one request path does not prove dual-stack capability and no third-party Geo-IP lookup is performed.\n\n Run What is my IP?\n\nCIDR/Subnet Calculator: Return a read-only local IPv4 or IPv6 CIDR report. Accepts a CIDR block plus optional split prefix and address family. Includes exact BigInt-derived boundaries and address counts, RFC 3021 /31 and host-route /32 semantics, no IPv6 broadcast claim, embedded-IPv4 parsing and a capped subnet preview.\n\nCidr  Target  Family  Run CIDR/Subnet Calculator\n\nHDMI EDID Decoder: Return a read-only local EDID 1.3/1.4 and bounded CTA report. Includes identity, checksums, feature-qualified preferred timing, detailed timings, SVD/SAD and speaker data, selected CTA extended blocks, and lossless raw unknown blocks from hex or file content. It does not infer Atmos, DTS:X, dynamic HDR, Dolby Vision, HDR10+, FRL, DSC, VRR, ALLM, or QMS from unimplemented evidence.\n\nFile  Edid hex  Run HDMI EDID Decoder\n\n## Smart checks for real troubleshooting\n\nadmintoolkit.io is for the checks that come up while operating DNS, mail, TLS, web, network, and AV systems. It keeps each result close to the input: public IP context, MX routing, SPF/DMARC/DKIM/BIMI records, message headers, DNSSEC and DANE evidence, CAA policy, certificates, HTTP response headers, CIDR math, EDID data, and agentic web metadata such as llms.txt, robots.txt, A2A Agent Cards, and WebMCP tool definitions. Agent-ready diagnostics: admintoolkit.io exposes its 24 tools as read-only WebMCP runtime tools where supported by compatible agents. The pages are intentionally narrow. They give you one readable fact at a time, with the raw value still visible enough to compare against logs, tickets, DNS changes, firewall rules, or the device that produced the data.\n\n## Local first, live when needed\n\nSome tools are fully local, including header parsing, certificate decoding from pasted data, CIDR calculation, EDID decoding, and static validation of robots.txt, llms.txt, A2A, WebMCP, security.txt, ARC, and pasted DNS records. Live checks are separated by action and by tool: DNS uses browser DNS-over-HTTPS first with same-origin fallback when needed, public IP and selected host checks use same-origin helper endpoints, Geo-IP uses api.ip.sb, and the map loads only after its own opt-in. If a tool needs a current network answer, the lookup path is visible and limited to the data needed for that check.\n\n## Built for first-pass evidence\n\nThe point is not to replace vendor consoles, packet captures, DNSViz, mail logs, or full audits. The point is to get a clear first-pass fact without losing time: which address is visible, which DNS record exists, whether DNSSEC, DANE, MTA-STS, TLS-RPT, or SMTP TLS evidence lines up, which certificate is served, which header is missing, which subnet contains an address, what an EDID block says, or whether emerging agentic web metadata is structurally ready before publication. That is usually enough to decide the next step without turning a quick report into a noisy investigation.\n",
  "markdownStats": {
    "images": 0,
    "links": 0,
    "tables": 0,
    "codeBlocks": 0,
    "headings": 4
  },
  "tokens": {
    "htmlTokens": 31384,
    "markdownTokens": 1324,
    "reduction": 30060,
    "reductionPercent": 96
  },
  "score": {
    "score": 92,
    "grade": "A",
    "rubricVersion": 2,
    "dimensions": {
      "accessibility": {
        "score": 88,
        "weight": 30,
        "grade": "B",
        "checks": {
          "content_without_js": {
            "score": 100,
            "weight": 55,
            "evidence": "proven",
            "details": "Content available without JavaScript"
          },
          "fast_content_position": {
            "score": 50,
            "weight": 25,
            "evidence": "plausible",
            "details": "Main content starts at 44% of HTML"
          },
          "reasonable_page_size": {
            "score": 100,
            "weight": 20,
            "evidence": "plausible",
            "details": "Page size: 107KB"
          }
        }
      },
      "aiDiscoverability": {
        "score": 93,
        "weight": 25,
        "grade": "A",
        "checks": {
          "robots_allows_ai_bots": {
            "score": 100,
            "weight": 35,
            "evidence": "proven",
            "details": "All major AI search bots allowed"
          },
          "supports_markdown_negotiation": {
            "score": 85,
            "weight": 20,
            "evidence": "plausible",
            "details": "Application level — Content negotiation, .md URL (https://admintoolkit.io/index.md), <link> tag"
          },
          "has_sitemap": {
            "score": 100,
            "weight": 15,
            "evidence": "plausible",
            "details": "Sitemap found"
          },
          "has_robots_txt": {
            "score": 100,
            "weight": 10,
            "evidence": "plausible",
            "details": "robots.txt exists"
          },
          "has_llms_txt": {
            "score": 100,
            "weight": 10,
            "evidence": "speculative",
            "details": "llms.txt exists and is valid"
          },
          "has_content_signals": {
            "score": 60,
            "weight": 10,
            "evidence": "speculative",
            "details": "robots.txt: ai-train=no, search=yes, ai-input=yes"
          }
        }
      },
      "structuredData": {
        "score": 100,
        "weight": 20,
        "grade": "A",
        "checks": {
          "has_schema_org": {
            "score": 100,
            "weight": 35,
            "evidence": "proven",
            "details": "JSON-LD found: Organization, WebSite, BreadcrumbList, WebPage, WebApplication, ItemList"
          },
          "has_open_graph": {
            "score": 100,
            "weight": 20,
            "evidence": "plausible",
            "details": "All OG tags present"
          },
          "has_meta_description": {
            "score": 100,
            "weight": 20,
            "evidence": "plausible",
            "details": "Meta description: 158 chars"
          },
          "has_canonical_url": {
            "score": 100,
            "weight": 15,
            "evidence": "plausible",
            "details": "Canonical URL present"
          },
          "has_lang_attribute": {
            "score": 100,
            "weight": 10,
            "evidence": "plausible",
            "details": "lang=\"en\""
          }
        }
      },
      "semanticHtml": {
        "score": 100,
        "weight": 15,
        "grade": "A",
        "checks": {
          "proper_heading_hierarchy": {
            "score": 100,
            "weight": 30,
            "evidence": "plausible",
            "details": "Clean heading hierarchy"
          },
          "uses_article_or_main": {
            "score": 100,
            "weight": 25,
            "evidence": "plausible",
            "details": "Has both <article> and <main>"
          },
          "semantic_elements": {
            "score": 100,
            "weight": 20,
            "evidence": "plausible",
            "details": "36 semantic elements, 27 divs (ratio: 57%)"
          },
          "meaningful_alt_texts": {
            "score": 100,
            "weight": 15,
            "evidence": "plausible",
            "details": "No informative images (2 decorative)"
          },
          "low_div_nesting": {
            "score": 100,
            "weight": 10,
            "evidence": "speculative",
            "details": "Avg div depth: 0.0, max: 0"
          }
        }
      },
      "contentEfficiency": {
        "score": 74,
        "weight": 10,
        "grade": "C",
        "checks": {
          "token_reduction_ratio": {
            "score": 100,
            "weight": 40,
            "evidence": "speculative",
            "details": "96% token reduction (HTML→Markdown)"
          },
          "content_to_noise_ratio": {
            "score": 25,
            "weight": 30,
            "evidence": "speculative",
            "details": "Content ratio: 5.7% (6259 content chars / 109861 HTML bytes)"
          },
          "reasonable_page_weight": {
            "score": 80,
            "weight": 20,
            "evidence": "speculative",
            "details": "HTML size: 107KB"
          },
          "minimal_inline_styles": {
            "score": 100,
            "weight": 10,
            "evidence": "speculative",
            "details": "0/477 elements with inline styles (0.0%)"
          }
        }
      }
    }
  },
  "recommendations": [
    {
      "id": "improve_content_ratio",
      "priority": "medium",
      "category": "contentEfficiency",
      "titleKey": "rec.improve_content_ratio.title",
      "descriptionKey": "rec.improve_content_ratio.description",
      "howToKey": "rec.improve_content_ratio.howto",
      "effort": "moderate",
      "estimatedImpact": 2.3,
      "maxImpact": 3,
      "evidence": "speculative",
      "checkScore": 25,
      "checkDetails": "Content ratio: 5.7% (6259 content chars / 109861 HTML bytes)"
    }
  ],
  "llmsTxtPreview": "# admintoolkit.io\n\n> AdminToolkit exposes read-only DNS, mail, TLS, HTTP, IP, CIDR, EDID, and agentic web diagnostics as same-origin WebMCP-compatible tool contracts with direct runtime handlers, JSON-LD UseAction metadata, OpenAPI 3.1 schemas, /tools.json and /mcp/tools discovery, and document.modelContext.registerToo…\n\n## Main\n- [admintoolkit - Admin, Engineer & AI Tools](https://admintoolkit.io): admintoolkit.io gives admins browser-based DNS, mail authentication, TLS, HTTP, public IP, CIDR, and EDID checks with l…\n- [Deutsch](https://admintoolkit.io/de/)\n- [changelog](https://admintoolkit.io/changelog/)\n- [guides](https://admintoolkit.io/guides/)\n- [admintoolkit.io](https://admintoolkit.io/)\n\n## Legal\n- [privacy](https://admintoolkit.io/privacy/)\n- [cookies](https://admintoolkit.io/cookies/)\n- [terms](https://admintoolkit.io/terms/)\n- [legal notice](https://admintoolkit.io/imprint/)\n\n## Support\n- [contact](https://admintoolkit.io/contact/)\n\n",
  "llmsTxtExisting": "# admintoolkit.io\n\n> admintoolkit.io provides 24 read-only browser diagnostics for IP, DNS, mail, HTTP headers, TLS certificates, subnets, EDID, and agent- and AI-web metadata.\nadmintoolkit.io provides practical diagnostics for administrators and technical users. Many tools run locally in the browser where possible; network lookups are explicit user actions.\nEach tool page includes a human-readable workflow section, limits section, and FAQ references for interpreting the result and understanding which data stays local.\n\nadmintoolkit.io is a free, public suite of 24 browser-based, read-only diagnostic tools for DNS, email security, TLS, HTTP, networking, and agent-discovery metadata; it is not a monitoring, automatic-remediation, or configuration-management service. Each result is point-in-time diagnostic evidence for the exact target and input from the matching canonical tool page and published contract; limitations remain part of the result rather than a guarantee. Results exist only for checks the user explicitly ran; nothing is precomputed or inferred. Network-backed checks execute only on explicit user action and only against public targets the user is authorized to inspect. Tools require no secrets, credentials, private keys, access tokens, or confidential payloads. Local processing is used where suitable, with each tool page defining its privacy boundary. Reports identify the tool, target, observation, and important limitation. Consequential DNS, mail, TLS, routing, security, or publishing changes require verification against the authoritative service.\n\n## Primary Pages\n- [Admin, Engineer & AI Tools](https://admintoolkit.io/): English home and tool index.\n- [Changelog](https://admintoolkit.io/changelog/): English release notes and recent public changes.\n\n## Agent And WebMCP Discovery\n- [MCP/WebMCP Tools](https://admintoolkit.io/mcp/tools): Machine-readable list of AdminToolkit read-only diagnostic tools with input schemas, output schemas, readOnly hints, and tool page URLs. Public agent-facing tools are read-only, same-origin, unauthenticated, and designed not to perform destructive actions.\n- [Root Tools Manifest](https://admintoolkit.io/tools.json): Same-origin public tools manifest for browser agents and crawler-based tool discovery.\n- [WebMCP Manifest](https://admintoolkit.io/.well-known/webmcp.json): WebMCP-compatible discovery metadata for browser agents.\n- [MCP-style Tool Catalog Card](https://admintoolkit.io/.well-known/mcp.json): MCP-style tool catalog metadata for AdminToolkit discovery.\n- [A2A Agent Card](https://admintoolkit.io/.well-known/agent-card.json): A2A-compatible agent card describing AdminToolkit's agent identity, skills, interfaces, and capabilities for agent-to-agent discovery.\n- [OpenAPI Description](https://admintoolkit.io/.well-known/openapi.json): OpenAPI 3.1 description for public read-only endpoints and tool contracts.\n- [API Catalog](https://admintoolkit.io/.well-known/api-catalog): Linkset catalog of public API and agent-discovery resources for AdminToolkit.\n- [Web Bot Auth Key Directory](https://admintoolkit.io/.well-known/http-message-signatures-directory): Public Ed25519 JWKS key directory for HTTP Message Signatures / Web Bot Auth verification. Private signing keys are not published.\n- [Authentication And Access Notes](https://admintoolkit.io/auth.md): Public authentication and access notes for unauthenticated read-only AdminToolkit agent discovery.\n- [llms.txt](https://admintoolkit.io/llms.txt): This route inventory and AI-readable navigation file for AdminToolkit's public tools and documentation.\n- [security.txt](https://admintoolkit.io/.well-known/security.txt): RFC 9116 security contact metadata for vulnerability disclosure and policy discovery.\n- [Homepage Markdown Representation](https://admintoolkit.io/index.md): The English homepage returns its Markdown representation when requested with `Accept: text/markdown`.\n\n## Tools\n- [AI Crawler robots.txt Checker](https://admintoolkit.io/ai-crawler-robots-checker/): Accepts robots.txt text or a public robots.txt URL plus an optional path. Reports merged matching groups, octet-normalized longest-match decisions, per-crawler evidence, transport status, crawler-registry provenance and policy snippets — Web / SEO\n- [llms.txt Validator](https://admintoolkit.io/llms-txt-validator/): Validate the required initial H1, optional summary and project details, and any H2 resource lists with link titles, URLs, optional descriptions, findings, and source-line evidence — Web / SEO\n- [A2A Agent Card Validator](https://admintoolkit.io/a2a-agent-card-validator/): Reports v0.2, v0.3 and v1.0 structure plus discovery-path evidence without claiming endpoint, authentication or signature conformance — Agentic Web\n- [WebMCP Tool Validator](https://admintoolkit.io/webmcp-tool-validator/): Reports declarative and imperative static-source evidence separately from caller-provided runtime observation; pasted JavaScript is never executed and active runtime tools are never inferred from source alone — Agentic Web\n- [MX Record Check](https://admintoolkit.io/mx-record-check/): Accepts a domain name. Reports exchanger hosts, preferences, Null MX, CNAME risk, address resolution and actionable mail-routing warnings — Email Security\n- [SPF/DMARC/DKIM Checker](https://admintoolkit.io/spf-dmarc-dkim-checker/): Accepts a domain plus optional pasted TXT values. Reports syntax, policy strength, alignment, DNS evidence and record-specific warnings — Email Security\n- [Email Message Header Analyzer](https://admintoolkit.io/email-header-analyzer/): Accepts pasted RFC 5322 headers. Reports raw Received order, recorded Authentication-Results and caller-configured authserv-id trust; it does not perform cryptographic authentication or reverse-DNS verification — Email Security\n- [ARC Chain Validator](https://admintoolkit.io/arc-chain-validator/): Accepts pasted ARC-Seal, ARC-Message-Signature and ARC-Authentication-Results fields. Reports structural completeness, instance continuity and recorded cv state; cryptographic validation and sealer trust are not evaluated — Email Security\n- [BIMI Checker/Generator](https://admintoolkit.io/bimi-checker-generator/): Accepts a domain, selector and optional BIMI, DMARC, logo or certificate evidence. Reports TXT syntax, DMARC dependency, asset URL findings and a conservative BIMI draft — Email Security\n- [MTA-STS Checker/Generator](https://admintoolkit.io/mta-sts-checker-generator/): Accepts a domain plus optional TXT, policy, MX and TLS-RPT evidence. Reports mode, max-age, syntax, id consistency, MX coverage, conformance findings and remediation warnings — Email Security\n- [TLS-RPT Checker/Generator](https://admintoolkit.io/tls-rpt-checker-generator/): Accepts a domain plus optional TLS-RPT TXT or RUA values. Reports version syntax, reporting destinations, external-provider use, conformance findings and remediation warnings — Email Security\n- [SMTP TLS Handshake / Mail Domain Delivery Readiness](https://admintoolkit.io/smtp-tls-readiness-checker/): Accepts a domain and optional MTA-STS, TLS-RPT, DANE and FCrDNS checks. Reports MX, STARTTLS, certificate, policy-alignment and downgrade-risk findings — Email Security\n- [DNSSEC Validator](https://admintoolkit.io/dnssec-validator/): Accepts a domain plus optional DS, DNSKEY, RRSIG and resolver-status data. Reports chain readiness, algorithms, missing records, validation findings and warnings — DNS Security\n- [TLSA Record Checker/Generator](https://admintoolkit.io/tlsa-record-checker-generator/): Accepts host, port, protocol, usage, selector, matching type and optional certificate data. Reports owner name, digest, generated TLSA data and DNS comparison findings — DNS Security\n- [DANE Validator](https://admintoolkit.io/dane-validator/): Accepts service host, port, protocol, TLSA records, DNSSEC status and optional certificate evidence. Reports owner names, TLSA syntax, DNSSEC dependency and certificate-match findings — DNS Security\n- [CAA Record Checker/Generator](https://admintoolkit.io/caa-record-checker-generator/): Accepts a domain plus optional CAA records and issuer details. Reports issue, issuewild, iodef, ACME parameters, policy gaps and record-generation guidance — DNS Security\n- [HTTP Header Analyzer](https://admintoolkit.io/http-header-analyzer/): Accepts pasted headers or a public URL. Reports security, cache, framing, duplicate/conflicting header fields, prioritized findings and remediation notes — Web Security\n- [SSL Certificate Decoder](https://admintoolkit.io/ssl-cert-decoder/): Accepts PEM text or public TLS host details. Reports subject, issuer, SANs, validity, fingerprints, key usage, extensions, hostname and certificate-health findings — Web Security\n- [security.txt Validator/Generator](https://admintoolkit.io/security-txt-validator-generator/): Accepts pasted content or a public security.txt URL plus optional contact fields. Reports contact, expiry, canonical, encryption, policy, language fields, findings and draft output — Web Security\n- [TLS Configuration Checker](https://admintoolkit.io/tls-configuration-checker/): Accepts host and port plus optional HSTS evidence. Reports separate exact-version probes, a distinct verified default handshake, SAN identity/trust evidence, negotiated cipher and ALPN evidence, and HTTPS-only HSTS checks; it does not claim cipher or ALPN enumeration — Web Security\n- [Redirect / Canonical / Indexability Checker](https://admintoolkit.io/redirect-canonical-indexability-checker/): Accepts a URL. Reports bounded per-hop status and SSRF evidence, final URL, HTML and HTTP canonical hints, robots meta and scoped X-Robots-Tag directives, hreflang, separate sitemap reachability and membership, and evidence completeness — Web / SEO\n- [What is my IP?](https://admintoolkit.io/what-is-my-ip/): Requires no input. Reports the canonical primary address, directly observed peer, trusted-proxy decision, preserved forwarded-header claims and observed address family; one request path does not prove dual-stack capability and no third-party Geo-IP lookup is performed — Network\n- [CIDR/Subnet Calculator](https://admintoolkit.io/cidr-subnet-calculator/): Accepts a CIDR block plus optional split prefix and address family. Reports exact BigInt-derived boundaries and address counts, RFC 3021 /31 and host-route /32 semantics, no IPv6 broadcast claim, embedded-IPv4 parsing and a capped subnet preview — Network\n- [HDMI EDID Decoder](https://admintoolkit.io/edid-decoder/): Reports identity, checksums, feature-qualified preferred timing, detailed timings, SVD/SAD and speaker data, selected CTA extended blocks, and lossless raw unknown blocks from hex or file content. It does not infer Atmos, DTS:X, dynamic HDR, Dolby Vision, HDR10+, FRL, DSC, VRR, ALLM, or QMS from unimplemented evidence — Hardware / AV\n\n## Guides\n- [Guides](https://admintoolkit.io/guides/): In-depth guidance for mail, DNS, TLS, web, network, AV, and agents.\n- [From DNS Evidence to a Finding: AdminToolkit&#x27;s DNS and Mail Security Methodology](https://admintoolkit.io/guides/dns-mail-security-methodology/): Use Methodology 1.2 to reproduce DNSSEC, DANE, mail-auth, and per-address dual-stack SMTP findings without crossing documented trust boundaries.\n- [Deploying DANE and TLSA for SMTP Without Losing Mail](https://admintoolkit.io/guides/dane-tlsa-smtp-deployment/): Deploy DANE/TLSA for SMTP with safe records, rollovers, and failure handling.\n- [A DMARC Rollout That Does Not Break Your Own Mail](https://admintoolkit.io/guides/dmarc-rollout-playbook/): Roll out DMARC safely from monitoring through enforcement.\n- [Diagnosing DNSSEC Outages: From SERVFAIL to the Broken Link](https://admintoolkit.io/guides/dnssec-outage-diagnosis/): Trace DNSSEC SERVFAIL and chain breaks to their root cause.\n- [MTA-STS, TLS-RPT, and DANE: Layering Mail Transport Security](https://admintoolkit.io/guides/mta-sts-tls-rpt-dane/): Layer MTA-STS, TLS-RPT, and DANE for mail transport security.\n- [CAA Records in Practice: Controlling Certificate Issuance](https://admintoolkit.io/guides/caa-records-in-practice/): Control certificate issuance with practical CAA policy and validation.\n- [Email Header Forensics: Reading a Message Like an Investigator](https://admintoolkit.io/guides/email-header-forensics/): Investigate Received lines, authentication results, forwarding, and ARC evidence.\n- [Making Your Site Agent-Readable: robots.txt, llms.txt, Agent Cards, and WebMCP](https://admintoolkit.io/guides/agent-readable-website/): Publish honest robots.txt, llms.txt, Agent Cards, and WebMCP discovery.\n- [TLS Troubleshooting From the Outside: Certificates, Names, and Handshakes](https://admintoolkit.io/guides/tls-certificate-troubleshooting/): Diagnose certificate, name, SNI, chain, protocol, and handshake failures.\n- [SPF Record Design That Survives the 10-Lookup Limit](https://admintoolkit.io/guides/spf-record-design/): Design SPF records that stay within the ten-lookup limit.\n- [DKIM Key Rotation Without Breaking Mail](https://admintoolkit.io/guides/dkim-key-rotation/): Rotate DKIM keys safely with overlap and clean selector retirement.\n- [How ARC Helps Mail Survive Forwarding](https://admintoolkit.io/guides/arc-forwarding-survival/): Assess forwarded-mail authentication and ARC evidence without overstating trust.\n- [BIMI Rollout: From Enforced DMARC to a Visible Logo](https://admintoolkit.io/guides/bimi-logo-rollout/): Build BIMI from enforced DMARC through deployable logo evidence.\n- [Planning MX Architecture: Preference, Capacity, and Safe Migration](https://admintoolkit.io/guides/mx-architecture-planning/): Design resilient MX routing, capacity, failover, and migrations.\n- [Auditing Mail Delivery Readiness End to End](https://admintoolkit.io/guides/mail-delivery-readiness-audit/): Audit MX, STARTTLS, policy enforcement, DANE, and reverse identity.\n- [Reading TLS-RPT Reports in Practice](https://admintoolkit.io/guides/tls-rpt-report-reading/): Turn TLS-RPT aggregates into actionable transport-security evidence.\n- [Security Headers That Actually Change Risk](https://admintoolkit.io/guides/security-headers-hardening/): Harden browser security with CSP, HSTS, cookies, isolation, and redirects.\n- [security.txt and the Disclosure Process Behind It](https://admintoolkit.io/guides/security-txt-disclosure/): Build an operational vulnerability-disclosure process around security.txt.\n- [Hardening TLS Without Guessing at Client Compatibility](https://admintoolkit.io/guides/tls-configuration-hardening/): Harden TLS with measured compatibility and expiring legacy exceptions.\n- [Redirects, Canonicals, and Indexability as One System](https://admintoolkit.io/guides/redirect-canonical-indexability/): Align redirects, canonicals, robots, hreflang, sitemaps, and internal links.\n- [Public IP, NAT, and Dual Stack: Which Address Is Really Yours?](https://admintoolkit.io/guides/public-ip-nat-dual-stack/): Understand public addressing across NAT, CGNAT, dual stack, and proxies.\n- [IPv6 Subnet Planning That Scales](https://admintoolkit.io/guides/ipv6-subnet-planning/): Plan scalable IPv6 prefixes, aggregation, reserves, and documentation.\n- [HDMI and EDID Troubleshooting in Real Signal Chains](https://admintoolkit.io/guides/hdmi-edid-troubleshooting/): Trace EDID capability loss through real HDMI signal chains.\n- [llms.txt in Practice: Curating a Useful Entry Point](https://admintoolkit.io/guides/llms-txt-in-practice/): Curate a useful llms.txt map with consistent access and indexing signals.\n- [Exposing Website Functions as WebMCP Tools](https://admintoolkit.io/guides/webmcp-tool-exposure/): Expose precise WebMCP tools with UI parity and runtime checks.\n\n## Contact, Policies, And Data\n- [Contact](https://admintoolkit.io/contact/): English contact form for tool requests, tool questions, bug reports, privacy or legal questions, and other messages.\n- [Privacy Policy](https://admintoolkit.io/privacy/): English privacy policy for local processing, live lookups, analytics, logs, and contact details. User-entered tool values are not sent to analytics.\n- [Cookies](https://admintoolkit.io/cookies/): English cookie and analytics controls; analytics requires consent and can be declined.\n- [Terms of Use](https://admintoolkit.io/terms/): English terms of use. No public pricing page or paid plan is currently published.\n- [Legal Notice & Contact](https://admintoolkit.io/imprint/): English legal notice and operator contact: [email protected].\n\n## Optional\n- [Full Tool Reference](https://admintoolkit.io/llms-full.txt): Optional English full-context reference for all 24 read-only tools, with inputs, result models, workflows, privacy notes, limits, examples, and FAQs.",
  "emergingProtocols": {
    "oauthProtectedResource": {
      "exists": false,
      "url": "https://admintoolkit.io/.well-known/oauth-protected-resource"
    },
    "oauthDiscovery": {
      "exists": false,
      "url": "https://admintoolkit.io/.well-known/oauth-authorization-server"
    },
    "mcpServerCard": {
      "exists": false,
      "url": "https://admintoolkit.io/.well-known/mcp/server-card.json",
      "draft": true
    },
    "a2aAgentCard": {
      "exists": true,
      "url": "https://admintoolkit.io/.well-known/agent-card.json",
      "name": "admintoolkit.io",
      "version": "2026-07-01",
      "description": "admintoolkit.io exposes anonymous read-only diagnostics and discovery documents for DNS, mail, TLS, HTTP, IP, CIDR, EDID, and agent-facing web metadata.",
      "capabilities": 4,
      "skills": 2,
      "endpoint": null
    },
    "apiCatalog": {
      "exists": true,
      "url": "https://admintoolkit.io/.well-known/api-catalog",
      "contentType": "application/linkset+json; charset=UTF-8",
      "validMediaType": true,
      "apis": 1
    },
    "agentSkills": {
      "exists": true,
      "url": "https://admintoolkit.io/.well-known/agent-skills/index.json",
      "draft": true,
      "schema": "https://schemas.agentskills.io/discovery/0.2.0/schema.json",
      "skills": 4,
      "names": [
        "check-mail-and-tls-readiness",
        "markdown-negotiation",
        "use-admintoolkit-tools",
        "validate-agent-discovery"
      ]
    },
    "count": 3,
    "total": 6
  },
  "botAccess": {
    "probed": true,
    "bot": "OAI-SearchBot",
    "controlStatus": 200,
    "botStatus": 200,
    "discriminates": false,
    "refusedAsBot": false,
    "edge": "Cloudflare",
    "verifiable": false,
    "detail": "This origin answers OAI-SearchBot exactly as it answers any other client (200). No edge-level filtering of AI crawlers observed."
  },
  "snippets": []
}

API를 사용하여 프로그래밍 방식으로 가져올 수 있습니다 (곧 출시)

이 JSON은 내부용입니다 — Markdown 및 llms.txt 파일과 달리 사이트에 업로드하기 위한 것이 아닙니다. 시간에 따른 점수 추적을 위한 기준값으로 저장하거나, 개발팀과 공유하거나, CI/CD 파이프라인에 통합하세요.

결과 공유

또는 AI에게 개선 방법을 물어보세요

다른 의견도 들어보시겠어요?

Cloudflare에도 무료 스캐너가 있는데, 던지는 질문이 다릅니다. 그쪽은 에이전트가 호출할 수 있도록 사이트가 게시한 것(MCP 서버 카드, Agent Skills, API 카탈로그, DNS 레코드)을 채점합니다. 저희는 에이전트가 콘텐츠에 도달해 읽고 이해할 수 있는지를 채점합니다. 한쪽은 좋고 다른 쪽은 나쁠 수 있으니 두 점수가 다른 것은 당연합니다. 서로 다른 질문에 대한 답이고, 둘 다 알아둘 가치가 있습니다.

Cloudflare로 admintoolkit.io 검사하기

배지 삽입

이 배지를 사이트에 추가하세요. AI 준비도 점수가 변경되면 자동으로 업데이트됩니다.

AgentReady.md score for admintoolkit.io
Script 권장
<script src="https://agentready.md/badge.js" data-id="b2e5c679-b755-4e3a-ab70-833d44873b19" data-domain="admintoolkit.io"></script>
Markdown
[![AgentReady.md score for admintoolkit.io](https://agentready.md/badge/admintoolkit.io.svg)](https://agentready.md/ko/r/b2e5c679-b755-4e3a-ab70-833d44873b19)

곧 출시: 전체 도메인 분석

전체 도메인을 크롤링하고, llms.txt를 생성하고, AI 준비도 점수를 시간에 따라 모니터링하세요. 대기자 명단에 등록하여 알림을 받으세요.

명단에 등록되었습니다! 서비스 출시 시 알려드리겠습니다.