已验证的 AgentReady.md 证书
签发于 sig: 5f9128674b8f29f0 验证 →

已分析URL

https://admintoolkit.io

测量于上周

分析另一个URL

AI-Ready评分

优秀

/ 100

Token节省量

HTML Token 31.384
Markdown Token 1324
节省 96%

评分详情

可访问性 88/100
AI可发现性 93/100
结构化数据 100/100
语义化HTML 100/100
内容效率 74/100

新兴协议

已检测到 3/6

AI代理查找的well-known端点。检测到意味着代理可以自动发现并连接到您的服务。

  • OAuth Protected Resource RFC 9728
    /.well-known/oauth-protected-resource
  • OAuth Discovery RFC 8414
    /.well-known/oauth-authorization-server
  • MCP Server Card SEP-1649 draft
    /.well-known/mcp/server-card.json
  • A2A Agent Card A2A v1.0
    /.well-known/agent-card.json
    • name: admintoolkit.io
    • v2026-07-01
    • 4 capabilities
    • 2 skill(s)
  • API Catalog RFC 9727
    /.well-known/api-catalog
    • 1 API(s)
  • Agent Skills index Discovery RFC v0.2.0 draft
    /.well-known/agent-skills/index.json
    • 4 skill(s)
    • check-mail-and-tls-readiness, markdown-negotiation, use-admintoolkit-tools, validate-agent-discovery

分数不会自己保持不变。 监控功能尚未上线——加入名单,上线时通知你。

您已加入名单!服务上线时我们会通知您。

我们测到的 Content ratio: 5.7% (6259 content chars / 109861 HTML bytes)

您的页面实际内容与总HTML的比率较低。页面重量的大部分是标记、脚本或样式而非内容。

如何实施

将CSS移至外部样式表,删除内联样式,最小化JavaScript,确保HTML专注于内容结构。

粘贴到编码智能体中让它完成修复
Markdown Token: 1324
## Essential Tools for Admins, Engineers and AI Agents

Network ToolsEmail SecurityBrowser-based

admintoolkit.io brings together essential browser tools for admins, engineers and AI agents: DNS, mail security, TLS, HTTP headers, public IP checks, CIDR, EDID, and agent-readable web metadata such as robots.txt, llms.txt, A2A Agent Cards, and WebMCP tool definitions. The tools are built for traceable diagnostics with local parsing where possible, explicit live lookups, and WebMCP support for AI agents.

Check RFC 9309 robots.txt matching for documented or custom crawler product tokens with merged groups, transport evidence, and registry provenance.

Web / SEO

Validate the required initial H1, optional summary and project details, and any H2 resource lists with link titles, URLs, optional descriptions, findings, and source-line evidence.

Web / SEO

Validate A2A Agent Card discovery JSON, skills, interfaces, capabilities, and deployment metadata.

Agentic Web

Inspect WebMCP declarative and imperative static source without executing JavaScript; runtime tools require actual browser observation.

Agentic Web

Query MX records through DNS-over-HTTPS, sort priorities, resolve first hosts, and spot Null MX or CNAME problems.

Email Security

Parse SPF, DMARC, and DKIM TXT records, highlight policy issues, and run DNS lookup only when needed.

Email Security

Parse full message headers locally, preserve raw Received order, and classify recorded Authentication-Results without claiming cryptographic or reverse-DNS verification.

Email Security

Check ARC instance structure, continuity, and recorded cv state without claiming cryptographic validation or sealer trust.

Email Security

Check BIMI records, DMARC readiness, logo and certificate URLs, and generate a conservative BIMI TXT draft.

Email Security

Assess MTA-STS TXT and HTTPS policy files, compare MX coverage, and return conformance findings with remediation warnings.

Email Security

Assess TLS-RPT TXT records, validate RUA destinations, flag external providers, and return conformance findings with remediation warnings.

Email Security

Review MX, STARTTLS, certificate match, MTA-STS, TLS-RPT, and optional DANE and FCrDNS readiness evidence.

Email Security

Review DS, DNSKEY, RRSIG structural inventory and the validating resolver's DNSSEC verdict for a domain.

DNS Security

Build valid TLSA records from certificate data and compare DANE fields directly with live DNS TLSA answers.

DNS Security

Validate DANE service owner names, TLSA RRsets, DNSSEC context, and implemented DANE-EE live comparisons.

DNS Security

Check and generate CAA issue, issuewild, iodef, ACME account bindings, validation methods, and issuemail tags.

DNS Security

Analyze pasted HTTP response headers locally, or fetch headers for a public URL through the restricted endpoint.

Web Security

Decode X.509 certificates in the browser, or fetch one public host certificate through the guarded TLS endpoint.

Web Security

Validate RFC 9116 vulnerability-disclosure contacts, expiry, canonical URL, policy, encryption, and hiring fields.

Web Security

Run separate exact-version TLS probes and summarize verified certificate identity, negotiated cipher/ALPN evidence, and HTTPS-only HSTS evidence.

Web Security

Check bounded redirect chains, final status, HTML and HTTP canonical hints, robots metadata, scoped X-Robots-Tag, hreflang, and separate sitemap reachability and membership.

Web / SEO

Shows the canonical public address, observed peer, trusted-proxy evidence, browser metadata, and forwarded headers; Geo-IP/ASN and map requests require separate clicks.

Network

Calculate exact IPv4 and IPv6 networks and BigInt address counts locally, including RFC 3021 /31, host /32, embedded IPv4, and capped split previews.

Network

Decode EDID hex or local files into display identity, timings, CTA blocks, audio data, HDR metadata, and checksum status.

Hardware / AV

Local parsers stay in the browser where possible. DNS, HTTP, TLS, Geo-IP and map calls are shown as live actions; the public-IP reflection is same-origin, while Geo-IP/ASN and map requests require separate clicks.

## Smart checks for real troubleshooting

admintoolkit.io is for the checks that come up while operating DNS, mail, TLS, web, network, and AV systems. It keeps each result close to the input: public IP context, MX routing, SPF/DMARC/DKIM/BIMI records, message headers, DNSSEC and DANE evidence, CAA policy, certificates, HTTP response headers, CIDR math, EDID data, and agentic web metadata such as llms.txt, robots.txt, A2A Agent Cards, and WebMCP tool definitions. Agent-ready diagnostics: admintoolkit.io exposes its 24 tools as read-only WebMCP runtime tools where supported by compatible agents. The pages are intentionally narrow. They give you one readable fact at a time, with the raw value still visible enough to compare against logs, tickets, DNS changes, firewall rules, or the device that produced the data.

## Local first, live when needed

Some tools are fully local, including header parsing, certificate decoding from pasted data, CIDR calculation, EDID decoding, and static validation of robots.txt, llms.txt, A2A, WebMCP, security.txt, ARC, and pasted DNS records. Live checks are separated by action and by tool: DNS uses browser DNS-over-HTTPS first with same-origin fallback when needed, public IP and selected host checks use same-origin helper endpoints, Geo-IP uses api.ip.sb, and the map loads only after its own opt-in. If a tool needs a current network answer, the lookup path is visible and limited to the data needed for that check.

## Built for first-pass evidence

The point is not to replace vendor consoles, packet captures, DNSViz, mail logs, or full audits. The point is to get a clear first-pass fact without losing time: which address is visible, which DNS record exists, whether DNSSEC, DANE, MTA-STS, TLS-RPT, or SMTP TLS evidence lines up, which certificate is served, which header is missing, which subnet contains an address, what an EDID block says, or whether emerging agentic web metadata is structurally ready before publication. That is usually enough to decide the next step without turning a quick report into a noisy investigation.
admintoolkit - Admin, Engineer & AI Tools                           [Skip to content](https://admintoolkit.io/#app "Skip to main content")

# Essential Tools for Admins, Engineers and AI Agents

Network ToolsEmail SecurityBrowser-based

admintoolkit.io brings together essential browser tools for admins, engineers and AI agents: DNS, mail security, TLS, HTTP headers, public IP checks, CIDR, EDID, and agent-readable web metadata such as robots.txt, llms.txt, A2A Agent Cards, and WebMCP tool definitions. The tools are built for traceable diagnostics with local parsing where possible, explicit live lookups, and WebMCP support for AI agents.

[AI Crawler robots.txt Checker](https://admintoolkit.io/ai-crawler-robots-checker/ "AI Crawler robots.txt Checker")

Check RFC 9309 robots.txt matching for documented or custom crawler product tokens with merged groups, transport evidence, and registry provenance.

Web / SEO

[llms.txt Validator](https://admintoolkit.io/llms-txt-validator/ "llms.txt Validator")

Validate the required initial H1, optional summary and project details, and any H2 resource lists with link titles, URLs, optional descriptions, findings, and source-line evidence.

Web / SEO

[A2A Agent Card Validator](https://admintoolkit.io/a2a-agent-card-validator/ "A2A Agent Card Validator")

Validate A2A Agent Card discovery JSON, skills, interfaces, capabilities, and deployment metadata.

Agentic Web

[WebMCP Tool Validator](https://admintoolkit.io/webmcp-tool-validator/ "WebMCP Tool Validator")

Inspect WebMCP declarative and imperative static source without executing JavaScript; runtime tools require actual browser observation.

Agentic Web

[MX Record Check](https://admintoolkit.io/mx-record-check/ "MX Record Check")

Query MX records through DNS-over-HTTPS, sort priorities, resolve first hosts, and spot Null MX or CNAME problems.

Email Security

[SPF/DMARC/DKIM Checker](https://admintoolkit.io/spf-dmarc-dkim-checker/ "SPF/DMARC/DKIM Checker")

Parse SPF, DMARC, and DKIM TXT records, highlight policy issues, and run DNS lookup only when needed.

Email Security

[Email Message Header Analyzer](https://admintoolkit.io/email-header-analyzer/ "Email Message Header Analyzer")

Parse full message headers locally, preserve raw Received order, and classify recorded Authentication-Results without claiming cryptographic or reverse-DNS verification.

Email Security

[ARC Chain Validator](https://admintoolkit.io/arc-chain-validator/ "ARC Chain Validator")

Check ARC instance structure, continuity, and recorded cv state without claiming cryptographic validation or sealer trust.

Email Security

[BIMI Checker/Generator](https://admintoolkit.io/bimi-checker-generator/ "BIMI Checker/Generator")

Check BIMI records, DMARC readiness, logo and certificate URLs, and generate a conservative BIMI TXT draft.

Email Security

[MTA-STS Checker/Generator](https://admintoolkit.io/mta-sts-checker-generator/ "MTA-STS Checker/Generator")

Assess MTA-STS TXT and HTTPS policy files, compare MX coverage, and return conformance findings with remediation warnings.

Email Security

[TLS-RPT Checker/Generator](https://admintoolkit.io/tls-rpt-checker-generator/ "TLS-RPT Checker/Generator")

Assess TLS-RPT TXT records, validate RUA destinations, flag external providers, and return conformance findings with remediation warnings.

Email Security

[SMTP TLS Handshake / Mail Domain Delivery Readiness](https://admintoolkit.io/smtp-tls-readiness-checker/ "SMTP TLS Handshake / Mail Domain Delivery Readiness")

Review MX, STARTTLS, certificate match, MTA-STS, TLS-RPT, and optional DANE and FCrDNS readiness evidence.

Email Security

[DNSSEC Validator](https://admintoolkit.io/dnssec-validator/ "DNSSEC Validator")

Review DS, DNSKEY, RRSIG structural inventory and the validating resolver's DNSSEC verdict for a domain.

DNS Security

[TLSA Record Checker/Generator](https://admintoolkit.io/tlsa-record-checker-generator/ "TLSA Record Checker/Generator")

Build valid TLSA records from certificate data and compare DANE fields directly with live DNS TLSA answers.

DNS Security

[DANE Validator](https://admintoolkit.io/dane-validator/ "DANE Validator")

Validate DANE service owner names, TLSA RRsets, DNSSEC context, and implemented DANE-EE live comparisons.

DNS Security

[CAA Record Checker/Generator](https://admintoolkit.io/caa-record-checker-generator/ "CAA Record Checker/Generator")

Check and generate CAA issue, issuewild, iodef, ACME account bindings, validation methods, and issuemail tags.

DNS Security

[HTTP Header Analyzer](https://admintoolkit.io/http-header-analyzer/ "HTTP Header Analyzer")

Analyze pasted HTTP response headers locally, or fetch headers for a public URL through the restricted endpoint.

Web Security

[SSL Certificate Decoder](https://admintoolkit.io/ssl-cert-decoder/ "SSL Certificate Decoder")

Decode X.509 certificates in the browser, or fetch one public host certificate through the guarded TLS endpoint.

Web Security

[security.txt Validator/Generator](https://admintoolkit.io/security-txt-validator-generator/ "security.txt Validator/Generator")

Validate RFC 9116 vulnerability-disclosure contacts, expiry, canonical URL, policy, encryption, and hiring fields.

Web Security

[TLS Configuration Checker](https://admintoolkit.io/tls-configuration-checker/ "TLS Configuration Checker")

Run separate exact-version TLS probes and summarize verified certificate identity, negotiated cipher/ALPN evidence, and HTTPS-only HSTS evidence.

Web Security

[Redirect / Canonical / Indexability Checker](https://admintoolkit.io/redirect-canonical-indexability-checker/ "Redirect / Canonical / Indexability Checker")

Check bounded redirect chains, final status, HTML and HTTP canonical hints, robots metadata, scoped X-Robots-Tag, hreflang, and separate sitemap reachability and membership.

Web / SEO

[What is my IP?](https://admintoolkit.io/what-is-my-ip/ "What is my IP?")

Shows the canonical public address, observed peer, trusted-proxy evidence, browser metadata, and forwarded headers; Geo-IP/ASN and map requests require separate clicks.

Network

[CIDR/Subnet Calculator](https://admintoolkit.io/cidr-subnet-calculator/ "CIDR/Subnet Calculator")

Calculate exact IPv4 and IPv6 networks and BigInt address counts locally, including RFC 3021 /31, host /32, embedded IPv4, and capped split previews.

Network

[HDMI EDID Decoder](https://admintoolkit.io/edid-decoder/ "HDMI EDID Decoder")

Decode EDID hex or local files into display identity, timings, CTA blocks, audio data, HDR metadata, and checksum status.

Hardware / AV

Local parsers stay in the browser where possible. DNS, HTTP, TLS, Geo-IP and map calls are shown as live actions; the public-IP reflection is same-origin, while Geo-IP/ASN and map requests require separate clicks.

## Root WebMCP tool contracts

The root page registers 24 directly executable, read-only WebMCP diagnostics. Each tool has a direct runtime handler and returns structured findings. Discovery endpoints include /tools.json, /.well-known/webmcp.json, /.well-known/mcp.json, /.well-known/tools.json, /mcp/tools, /.well-known/openapi.json, and /.well-known/api-catalog.

AI Crawler robots.txt Checker: Return a read-only RFC 9309 robots.txt access report for AI and search crawlers. Accepts robots.txt text or a public robots.txt URL plus an optional path. Includes merged matching groups, octet-normalized longest-match decisions, per-crawler evidence, transport status, crawler-registry provenance and policy snippets.

Url  Path  Content  Crawlers  Run AI Crawler robots.txt Checker

llms.txt Validator: Validate the required initial H1, optional summary and project details, and any H2 resource lists with link titles, URLs, optional descriptions, findings, and source-line evidence.

Url  Content  Run llms.txt Validator

A2A Agent Card Validator: Return a read-only version-aware A2A Agent Card validation report. Includes v0.2, v0.3 and v1.0 structure plus discovery-path evidence without claiming endpoint, authentication or signature conformance.

Url  Json  Run A2A Agent Card Validator

WebMCP Tool Validator: Return a read-only WebMCP report for pasted or fetched source. Includes declarative and imperative static-source evidence separately from caller-provided runtime observation; pasted JavaScript is never executed and active runtime tools are never inferred from source alone.

Url  Source  Run WebMCP Tool Validator

MX Record Check: Return a read-only MX routing report for a mail domain. Accepts a domain name. Includes exchanger hosts, preferences, Null MX, CNAME risk, address resolution and actionable mail-routing warnings.

Domain  Run MX Record Check

SPF/DMARC/DKIM Checker: Return a read-only SPF, DMARC and DKIM report for a mail domain. Accepts a domain plus optional pasted TXT values. Includes syntax, policy strength, alignment, DNS evidence and record-specific warnings.

Domain  Selector mode  Selector  Policy  Spf record  Dmarc record  Dkim record  Run SPF/DMARC/DKIM Checker

Email Message Header Analyzer: Return a read-only email message header report. Accepts pasted RFC 5322 headers. Includes raw Received order, recorded Authentication-Results and caller-configured authserv-id trust; it does not perform cryptographic authentication or reverse-DNS verification.

Headers  Trusted authserv ids  Run Email Message Header Analyzer

ARC Chain Validator: Return a read-only ARC structural validation report. Accepts pasted ARC-Seal, ARC-Message-Signature and ARC-Authentication-Results fields. Includes structural completeness, instance continuity and recorded cv state; cryptographic validation and sealer trust are not evaluated.

Headers  Run ARC Chain Validator

BIMI Checker/Generator: Return a read-only BIMI readiness report for a mail domain. Accepts a domain, selector and optional BIMI, DMARC, logo or certificate evidence. Includes TXT syntax, DMARC dependency, asset URL findings and a conservative BIMI draft.

Domain  Selector  Record  Dmarc  Logo url  Evidence url  Run BIMI Checker/Generator

MTA-STS Checker/Generator: Return a read-only MTA-STS deployment report for a mail domain. Accepts a domain plus optional TXT, policy, MX and TLS-RPT evidence. Includes mode, max-age, syntax, id consistency, MX coverage, conformance findings and remediation warnings.

Domain  Dns txt  Policy  Mode  Mx hosts  Tls rpt  Run MTA-STS Checker/Generator

TLS-RPT Checker/Generator: Return a read-only SMTP TLS Reporting report for a mail domain. Accepts a domain plus optional TLS-RPT TXT or RUA values. Includes version syntax, reporting destinations, external-provider use, conformance findings and remediation warnings.

Domain  Dns txt  Rua  Run TLS-RPT Checker/Generator

SMTP TLS Handshake / Mail Domain Delivery Readiness: Return a read-only SMTP TLS delivery readiness report for a mail domain. Accepts a domain and optional MTA-STS, TLS-RPT, DANE and FCrDNS checks. Includes MX, STARTTLS, certificate, policy-alignment and downgrade-risk findings.

Domain  Check mta sts  Check tls rpt  Check dane  Check fcrdns  Run SMTP TLS Handshake / Mail Domain Delivery Readiness

DNSSEC Validator: Return a read-only DNSSEC evidence report for a domain. Accepts a domain plus optional DS, DNSKEY, RRSIG and resolver-status data. Includes chain readiness, algorithms, missing records, validation findings and warnings.

Domain  Ds records  Dnskey records  Rrsig records  Status  Run DNSSEC Validator

TLSA Record Checker/Generator: Return a read-only DANE TLSA record report. Accepts host, port, protocol, usage, selector, matching type and optional certificate data. Includes owner name, digest, generated TLSA data and DNS comparison findings.

Host  Port  Protocol  Usage  Selector  Matching  Pem  File  Run TLSA Record Checker/Generator

DANE Validator: Return a read-only DANE service validation report. Accepts service host, port, protocol, TLSA records, DNSSEC status and optional certificate evidence. Includes owner names, TLSA syntax, DNSSEC dependency and certificate-match findings.

Host  Port  Protocol  Mode  Tlsa records  Dnssec  Run DANE Validator

CAA Record Checker/Generator: Return a read-only CAA certificate-authority policy report for a domain. Accepts a domain plus optional CAA records and issuer details. Includes issue, issuewild, iodef, ACME parameters, policy gaps and record-generation guidance.

Domain  Records  Ca  Iodef  Methods  Issuemail  Run CAA Record Checker/Generator

HTTP Header Analyzer: Return a read-only HTTP response-header report for a public endpoint. Accepts pasted headers or a public URL. Includes security, cache, framing, duplicate/conflicting header fields, prioritized findings and remediation notes.

Url  Headers  Run HTTP Header Analyzer

SSL Certificate Decoder: Return a read-only X.509 TLS certificate report. Accepts PEM text or public TLS host details. Includes subject, issuer, SANs, validity, fingerprints, key usage, extensions, hostname and certificate-health findings.

Host  Port  Protocol  Pem  Run SSL Certificate Decoder

security.txt Validator/Generator: Return a read-only RFC 9116 security.txt report. Accepts pasted content or a public security.txt URL plus optional contact fields. Includes contact, expiry, canonical, encryption, policy, language fields, findings and draft output.

Url  Content  Contact  Encryption  Policy  Pgp key  Run security.txt Validator/Generator

TLS Configuration Checker: Return a read-only public TLS configuration report for a host. Accepts host and port plus optional HSTS evidence. Includes separate exact-version probes, a distinct verified default handshake, SAN identity/trust evidence, negotiated cipher and ALPN evidence, and HTTPS-only HSTS checks; it does not claim cipher or ALPN enumeration.

Host  Port  Hsts  Run TLS Configuration Checker

Redirect / Canonical / Indexability Checker: Return a read-only redirect, canonical and indexability report for a public URL. Accepts a URL. Includes bounded per-hop status and SSRF evidence, final URL, HTML and HTTP canonical hints, robots meta and scoped X-Robots-Tag directives, hreflang, separate sitemap reachability and membership, and evidence completeness.

Url  Run Redirect / Canonical / Indexability Checker

What is my IP?: Return a read-only same-origin IP context report for the current request. Requires no input. Includes the canonical primary address, directly observed peer, trusted-proxy decision, preserved forwarded-header claims and observed address family; one request path does not prove dual-stack capability and no third-party Geo-IP lookup is performed.

 Run What is my IP?

CIDR/Subnet Calculator: Return a read-only local IPv4 or IPv6 CIDR report. Accepts a CIDR block plus optional split prefix and address family. Includes exact BigInt-derived boundaries and address counts, RFC 3021 /31 and host-route /32 semantics, no IPv6 broadcast claim, embedded-IPv4 parsing and a capped subnet preview.

Cidr  Target  Family  Run CIDR/Subnet Calculator

HDMI EDID Decoder: Return a read-only local EDID 1.3/1.4 and bounded CTA report. Includes identity, checksums, feature-qualified preferred timing, detailed timings, SVD/SAD and speaker data, selected CTA extended blocks, and lossless raw unknown blocks from hex or file content. It does not infer Atmos, DTS:X, dynamic HDR, Dolby Vision, HDR10+, FRL, DSC, VRR, ALLM, or QMS from unimplemented evidence.

File  Edid hex  Run HDMI EDID Decoder

## Smart checks for real troubleshooting

admintoolkit.io is for the checks that come up while operating DNS, mail, TLS, web, network, and AV systems. It keeps each result close to the input: public IP context, MX routing, SPF/DMARC/DKIM/BIMI records, message headers, DNSSEC and DANE evidence, CAA policy, certificates, HTTP response headers, CIDR math, EDID data, and agentic web metadata such as llms.txt, robots.txt, A2A Agent Cards, and WebMCP tool definitions. Agent-ready diagnostics: admintoolkit.io exposes its 24 tools as read-only WebMCP runtime tools where supported by compatible agents. The pages are intentionally narrow. They give you one readable fact at a time, with the raw value still visible enough to compare against logs, tickets, DNS changes, firewall rules, or the device that produced the data.

## Local first, live when needed

Some tools are fully local, including header parsing, certificate decoding from pasted data, CIDR calculation, EDID decoding, and static validation of robots.txt, llms.txt, A2A, WebMCP, security.txt, ARC, and pasted DNS records. Live checks are separated by action and by tool: DNS uses browser DNS-over-HTTPS first with same-origin fallback when needed, public IP and selected host checks use same-origin helper endpoints, Geo-IP uses api.ip.sb, and the map loads only after its own opt-in. If a tool needs a current network answer, the lookup path is visible and limited to the data needed for that check.

## Built for first-pass evidence

The point is not to replace vendor consoles, packet captures, DNSViz, mail logs, or full audits. The point is to get a clear first-pass fact without losing time: which address is visible, which DNS record exists, whether DNSSEC, DANE, MTA-STS, TLS-RPT, or SMTP TLS evidence lines up, which certificate is served, which header is missing, which subnet contains an address, what an EDID block says, or whether emerging agentic web metadata is structurally ready before publication. That is usually enough to decide the next step without turning a quick report into a noisy investigation.

将此文件上传到服务器的/index.md,以便AI代理可以访问页面的干净版本。您也可以配置Accept: text/markdown内容协商以自动提供。

我们的建议

下载llms.txt
# admintoolkit.io

> AdminToolkit exposes read-only DNS, mail, TLS, HTTP, IP, CIDR, EDID, and agentic web diagnostics as same-origin WebMCP-compatible tool contracts with direct runtime handlers, JSON-LD UseAction metadata, OpenAPI 3.1 schemas, /tools.json and /mcp/tools discovery, and document.modelContext.registerToo…

## Main
- [admintoolkit - Admin, Engineer & AI Tools](https://admintoolkit.io): admintoolkit.io gives admins browser-based DNS, mail authentication, TLS, HTTP, public IP, CIDR, and EDID checks with l…
- [Deutsch](https://admintoolkit.io/de/)
- [changelog](https://admintoolkit.io/changelog/)
- [guides](https://admintoolkit.io/guides/)
- [admintoolkit.io](https://admintoolkit.io/)

## Legal
- [privacy](https://admintoolkit.io/privacy/)
- [cookies](https://admintoolkit.io/cookies/)
- [terms](https://admintoolkit.io/terms/)
- [legal notice](https://admintoolkit.io/imprint/)

## Support
- [contact](https://admintoolkit.io/contact/)

完整llms.txt需要全域分析(即将推出)

将此文件上传到域名根目录的https://admintoolkit.io/llms.txt。ChatGPT、Claude和Perplexity等AI代理会检查此文件以了解您的网站结构。

该网站已有llms.txt文件。

格式有效
# admintoolkit.io

> admintoolkit.io provides 24 read-only browser diagnostics for IP, DNS, mail, HTTP headers, TLS certificates, subnets, EDID, and agent- and AI-web metadata.
admintoolkit.io provides practical diagnostics for administrators and technical users. Many tools run locally in the browser where possible; network lookups are explicit user actions.
Each tool page includes a human-readable workflow section, limits section, and FAQ references for interpreting the result and understanding which data stays local.

admintoolkit.io is a free, public suite of 24 browser-based, read-only diagnostic tools for DNS, email security, TLS, HTTP, networking, and agent-discovery metadata; it is not a monitoring, automatic-remediation, or configuration-management service. Each result is point-in-time diagnostic evidence for the exact target and input from the matching canonical tool page and published contract; limitations remain part of the result rather than a guarantee. Results exist only for checks the user explicitly ran; nothing is precomputed or inferred. Network-backed checks execute only on explicit user action and only against public targets the user is authorized to inspect. Tools require no secrets, credentials, private keys, access tokens, or confidential payloads. Local processing is used where suitable, with each tool page defining its privacy boundary. Reports identify the tool, target, observation, and important limitation. Consequential DNS, mail, TLS, routing, security, or publishing changes require verification against the authoritative service.

## Primary Pages
- [Admin, Engineer & AI Tools](https://admintoolkit.io/): English home and tool index.
- [Changelog](https://admintoolkit.io/changelog/): English release notes and recent public changes.

## Agent And WebMCP Discovery
- [MCP/WebMCP Tools](https://admintoolkit.io/mcp/tools): Machine-readable list of AdminToolkit read-only diagnostic tools with input schemas, output schemas, readOnly hints, and tool page URLs. Public agent-facing tools are read-only, same-origin, unauthenticated, and designed not to perform destructive actions.
- [Root Tools Manifest](https://admintoolkit.io/tools.json): Same-origin public tools manifest for browser agents and crawler-based tool discovery.
- [WebMCP Manifest](https://admintoolkit.io/.well-known/webmcp.json): WebMCP-compatible discovery metadata for browser agents.
- [MCP-style Tool Catalog Card](https://admintoolkit.io/.well-known/mcp.json): MCP-style tool catalog metadata for AdminToolkit discovery.
- [A2A Agent Card](https://admintoolkit.io/.well-known/agent-card.json): A2A-compatible agent card describing AdminToolkit's agent identity, skills, interfaces, and capabilities for agent-to-agent discovery.
- [OpenAPI Description](https://admintoolkit.io/.well-known/openapi.json): OpenAPI 3.1 description for public read-only endpoints and tool contracts.
- [API Catalog](https://admintoolkit.io/.well-known/api-catalog): Linkset catalog of public API and agent-discovery resources for AdminToolkit.
- [Web Bot Auth Key Directory](https://admintoolkit.io/.well-known/http-message-signatures-directory): Public Ed25519 JWKS key directory for HTTP Message Signatures / Web Bot Auth verification. Private signing keys are not published.
- [Authentication And Access Notes](https://admintoolkit.io/auth.md): Public authentication and access notes for unauthenticated read-only AdminToolkit agent discovery.
- [llms.txt](https://admintoolkit.io/llms.txt): This route inventory and AI-readable navigation file for AdminToolkit's public tools and documentation.
- [security.txt](https://admintoolkit.io/.well-known/security.txt): RFC 9116 security contact metadata for vulnerability disclosure and policy discovery.
- [Homepage Markdown Representation](https://admintoolkit.io/index.md): The English homepage returns its Markdown representation when requested with `Accept: text/markdown`.

## Tools
- [AI Crawler robots.txt Checker](https://admintoolkit.io/ai-crawler-robots-checker/): Accepts robots.txt text or a public robots.txt URL plus an optional path. Reports merged matching groups, octet-normalized longest-match decisions, per-crawler evidence, transport status, crawler-registry provenance and policy snippets — Web / SEO
- [llms.txt Validator](https://admintoolkit.io/llms-txt-validator/): Validate the required initial H1, optional summary and project details, and any H2 resource lists with link titles, URLs, optional descriptions, findings, and source-line evidence — Web / SEO
- [A2A Agent Card Validator](https://admintoolkit.io/a2a-agent-card-validator/): Reports v0.2, v0.3 and v1.0 structure plus discovery-path evidence without claiming endpoint, authentication or signature conformance — Agentic Web
- [WebMCP Tool Validator](https://admintoolkit.io/webmcp-tool-validator/): Reports declarative and imperative static-source evidence separately from caller-provided runtime observation; pasted JavaScript is never executed and active runtime tools are never inferred from source alone — Agentic Web
- [MX Record Check](https://admintoolkit.io/mx-record-check/): Accepts a domain name. Reports exchanger hosts, preferences, Null MX, CNAME risk, address resolution and actionable mail-routing warnings — Email Security
- [SPF/DMARC/DKIM Checker](https://admintoolkit.io/spf-dmarc-dkim-checker/): Accepts a domain plus optional pasted TXT values. Reports syntax, policy strength, alignment, DNS evidence and record-specific warnings — Email Security
- [Email Message Header Analyzer](https://admintoolkit.io/email-header-analyzer/): Accepts pasted RFC 5322 headers. Reports raw Received order, recorded Authentication-Results and caller-configured authserv-id trust; it does not perform cryptographic authentication or reverse-DNS verification — Email Security
- [ARC Chain Validator](https://admintoolkit.io/arc-chain-validator/): Accepts pasted ARC-Seal, ARC-Message-Signature and ARC-Authentication-Results fields. Reports structural completeness, instance continuity and recorded cv state; cryptographic validation and sealer trust are not evaluated — Email Security
- [BIMI Checker/Generator](https://admintoolkit.io/bimi-checker-generator/): Accepts a domain, selector and optional BIMI, DMARC, logo or certificate evidence. Reports TXT syntax, DMARC dependency, asset URL findings and a conservative BIMI draft — Email Security
- [MTA-STS Checker/Generator](https://admintoolkit.io/mta-sts-checker-generator/): Accepts a domain plus optional TXT, policy, MX and TLS-RPT evidence. Reports mode, max-age, syntax, id consistency, MX coverage, conformance findings and remediation warnings — Email Security
- [TLS-RPT Checker/Generator](https://admintoolkit.io/tls-rpt-checker-generator/): Accepts a domain plus optional TLS-RPT TXT or RUA values. Reports version syntax, reporting destinations, external-provider use, conformance findings and remediation warnings — Email Security
- [SMTP TLS Handshake / Mail Domain Delivery Readiness](https://admintoolkit.io/smtp-tls-readiness-checker/): Accepts a domain and optional MTA-STS, TLS-RPT, DANE and FCrDNS checks. Reports MX, STARTTLS, certificate, policy-alignment and downgrade-risk findings — Email Security
- [DNSSEC Validator](https://admintoolkit.io/dnssec-validator/): Accepts a domain plus optional DS, DNSKEY, RRSIG and resolver-status data. Reports chain readiness, algorithms, missing records, validation findings and warnings — DNS Security
- [TLSA Record Checker/Generator](https://admintoolkit.io/tlsa-record-checker-generator/): Accepts host, port, protocol, usage, selector, matching type and optional certificate data. Reports owner name, digest, generated TLSA data and DNS comparison findings — DNS Security
- [DANE Validator](https://admintoolkit.io/dane-validator/): Accepts service host, port, protocol, TLSA records, DNSSEC status and optional certificate evidence. Reports owner names, TLSA syntax, DNSSEC dependency and certificate-match findings — DNS Security
- [CAA Record Checker/Generator](https://admintoolkit.io/caa-record-checker-generator/): Accepts a domain plus optional CAA records and issuer details. Reports issue, issuewild, iodef, ACME parameters, policy gaps and record-generation guidance — DNS Security
- [HTTP Header Analyzer](https://admintoolkit.io/http-header-analyzer/): Accepts pasted headers or a public URL. Reports security, cache, framing, duplicate/conflicting header fields, prioritized findings and remediation notes — Web Security
- [SSL Certificate Decoder](https://admintoolkit.io/ssl-cert-decoder/): Accepts PEM text or public TLS host details. Reports subject, issuer, SANs, validity, fingerprints, key usage, extensions, hostname and certificate-health findings — Web Security
- [security.txt Validator/Generator](https://admintoolkit.io/security-txt-validator-generator/): Accepts pasted content or a public security.txt URL plus optional contact fields. Reports contact, expiry, canonical, encryption, policy, language fields, findings and draft output — Web Security
- [TLS Configuration Checker](https://admintoolkit.io/tls-configuration-checker/): Accepts host and port plus optional HSTS evidence. Reports separate exact-version probes, a distinct verified default handshake, SAN identity/trust evidence, negotiated cipher and ALPN evidence, and HTTPS-only HSTS checks; it does not claim cipher or ALPN enumeration — Web Security
- [Redirect / Canonical / Indexability Checker](https://admintoolkit.io/redirect-canonical-indexability-checker/): Accepts a URL. Reports bounded per-hop status and SSRF evidence, final URL, HTML and HTTP canonical hints, robots meta and scoped X-Robots-Tag directives, hreflang, separate sitemap reachability and membership, and evidence completeness — Web / SEO
- [What is my IP?](https://admintoolkit.io/what-is-my-ip/): Requires no input. Reports the canonical primary address, directly observed peer, trusted-proxy decision, preserved forwarded-header claims and observed address family; one request path does not prove dual-stack capability and no third-party Geo-IP lookup is performed — Network
- [CIDR/Subnet Calculator](https://admintoolkit.io/cidr-subnet-calculator/): Accepts a CIDR block plus optional split prefix and address family. Reports exact BigInt-derived boundaries and address counts, RFC 3021 /31 and host-route /32 semantics, no IPv6 broadcast claim, embedded-IPv4 parsing and a capped subnet preview — Network
- [HDMI EDID Decoder](https://admintoolkit.io/edid-decoder/): Reports identity, checksums, feature-qualified preferred timing, detailed timings, SVD/SAD and speaker data, selected CTA extended blocks, and lossless raw unknown blocks from hex or file content. It does not infer Atmos, DTS:X, dynamic HDR, Dolby Vision, HDR10+, FRL, DSC, VRR, ALLM, or QMS from unimplemented evidence — Hardware / AV

## Guides
- [Guides](https://admintoolkit.io/guides/): In-depth guidance for mail, DNS, TLS, web, network, AV, and agents.
- [From DNS Evidence to a Finding: AdminToolkit's DNS and Mail Security Methodology](https://admintoolkit.io/guides/dns-mail-security-methodology/): Use Methodology 1.2 to reproduce DNSSEC, DANE, mail-auth, and per-address dual-stack SMTP findings without crossing documented trust boundaries.
- [Deploying DANE and TLSA for SMTP Without Losing Mail](https://admintoolkit.io/guides/dane-tlsa-smtp-deployment/): Deploy DANE/TLSA for SMTP with safe records, rollovers, and failure handling.
- [A DMARC Rollout That Does Not Break Your Own Mail](https://admintoolkit.io/guides/dmarc-rollout-playbook/): Roll out DMARC safely from monitoring through enforcement.
- [Diagnosing DNSSEC Outages: From SERVFAIL to the Broken Link](https://admintoolkit.io/guides/dnssec-outage-diagnosis/): Trace DNSSEC SERVFAIL and chain breaks to their root cause.
- [MTA-STS, TLS-RPT, and DANE: Layering Mail Transport Security](https://admintoolkit.io/guides/mta-sts-tls-rpt-dane/): Layer MTA-STS, TLS-RPT, and DANE for mail transport security.
- [CAA Records in Practice: Controlling Certificate Issuance](https://admintoolkit.io/guides/caa-records-in-practice/): Control certificate issuance with practical CAA policy and validation.
- [Email Header Forensics: Reading a Message Like an Investigator](https://admintoolkit.io/guides/email-header-forensics/): Investigate Received lines, authentication results, forwarding, and ARC evidence.
- [Making Your Site Agent-Readable: robots.txt, llms.txt, Agent Cards, and WebMCP](https://admintoolkit.io/guides/agent-readable-website/): Publish honest robots.txt, llms.txt, Agent Cards, and WebMCP discovery.
- [TLS Troubleshooting From the Outside: Certificates, Names, and Handshakes](https://admintoolkit.io/guides/tls-certificate-troubleshooting/): Diagnose certificate, name, SNI, chain, protocol, and handshake failures.
- [SPF Record Design That Survives the 10-Lookup Limit](https://admintoolkit.io/guides/spf-record-design/): Design SPF records that stay within the ten-lookup limit.
- [DKIM Key Rotation Without Breaking Mail](https://admintoolkit.io/guides/dkim-key-rotation/): Rotate DKIM keys safely with overlap and clean selector retirement.
- [How ARC Helps Mail Survive Forwarding](https://admintoolkit.io/guides/arc-forwarding-survival/): Assess forwarded-mail authentication and ARC evidence without overstating trust.
- [BIMI Rollout: From Enforced DMARC to a Visible Logo](https://admintoolkit.io/guides/bimi-logo-rollout/): Build BIMI from enforced DMARC through deployable logo evidence.
- [Planning MX Architecture: Preference, Capacity, and Safe Migration](https://admintoolkit.io/guides/mx-architecture-planning/): Design resilient MX routing, capacity, failover, and migrations.
- [Auditing Mail Delivery Readiness End to End](https://admintoolkit.io/guides/mail-delivery-readiness-audit/): Audit MX, STARTTLS, policy enforcement, DANE, and reverse identity.
- [Reading TLS-RPT Reports in Practice](https://admintoolkit.io/guides/tls-rpt-report-reading/): Turn TLS-RPT aggregates into actionable transport-security evidence.
- [Security Headers That Actually Change Risk](https://admintoolkit.io/guides/security-headers-hardening/): Harden browser security with CSP, HSTS, cookies, isolation, and redirects.
- [security.txt and the Disclosure Process Behind It](https://admintoolkit.io/guides/security-txt-disclosure/): Build an operational vulnerability-disclosure process around security.txt.
- [Hardening TLS Without Guessing at Client Compatibility](https://admintoolkit.io/guides/tls-configuration-hardening/): Harden TLS with measured compatibility and expiring legacy exceptions.
- [Redirects, Canonicals, and Indexability as One System](https://admintoolkit.io/guides/redirect-canonical-indexability/): Align redirects, canonicals, robots, hreflang, sitemaps, and internal links.
- [Public IP, NAT, and Dual Stack: Which Address Is Really Yours?](https://admintoolkit.io/guides/public-ip-nat-dual-stack/): Understand public addressing across NAT, CGNAT, dual stack, and proxies.
- [IPv6 Subnet Planning That Scales](https://admintoolkit.io/guides/ipv6-subnet-planning/): Plan scalable IPv6 prefixes, aggregation, reserves, and documentation.
- [HDMI and EDID Troubleshooting in Real Signal Chains](https://admintoolkit.io/guides/hdmi-edid-troubleshooting/): Trace EDID capability loss through real HDMI signal chains.
- [llms.txt in Practice: Curating a Useful Entry Point](https://admintoolkit.io/guides/llms-txt-in-practice/): Curate a useful llms.txt map with consistent access and indexing signals.
- [Exposing Website Functions as WebMCP Tools](https://admintoolkit.io/guides/webmcp-tool-exposure/): Expose precise WebMCP tools with UI parity and runtime checks.

## Contact, Policies, And Data
- [Contact](https://admintoolkit.io/contact/): English contact form for tool requests, tool questions, bug reports, privacy or legal questions, and other messages.
- [Privacy Policy](https://admintoolkit.io/privacy/): English privacy policy for local processing, live lookups, analytics, logs, and contact details. User-entered tool values are not sent to analytics.
- [Cookies](https://admintoolkit.io/cookies/): English cookie and analytics controls; analytics requires consent and can be declined.
- [Terms of Use](https://admintoolkit.io/terms/): English terms of use. No public pricing page or paid plan is currently published.
- [Legal Notice & Contact](https://admintoolkit.io/imprint/): English legal notice and operator contact: [email protected].

## Optional
- [Full Tool Reference](https://admintoolkit.io/llms-full.txt): Optional English full-context reference for all 24 read-only tools, with inputs, result models, workflows, privacy notes, limits, examples, and FAQs.

可访问性

无需JavaScript即可获取内容 (100/100)

Content available without JavaScript

内容在HTML中位置靠前 (50/100)

Main content starts at 44% of HTML

合理的页面大小 (100/100)

Page size: 107KB

AI可发现性

robots.txt允许AI机器人 (100/100)

All major AI search bots allowed

Markdown for Agents支持 (85/100) Application
&#10003; Accept: text/markdown &#10003; .md URL &#10003; <link> tag &#10007; Link header
有sitemap.xml (100/100)

Sitemap found

有robots.txt文件 (100/100)

robots.txt exists

有llms.txt文件 (100/100)

llms.txt exists and is valid

有Content-Signal(robots.txt或HTTP标头) (60/100)
&#10003; robots.txt &#10007; HTTP header &#10007; Policy

结构化数据

有Schema.org / JSON-LD (100/100)

JSON-LD found: Organization, WebSite, BreadcrumbList, WebPage, WebApplication, ItemList

有Open Graph标签 (100/100)

All OG tags present

有meta描述 (100/100)

Meta description: 158 chars

有规范URL (100/100)

Canonical URL present

有lang属性 (100/100)

lang="en"

语义化HTML

正确的标题层级 (100/100)

Clean heading hierarchy

使用article或main元素 (100/100)

Has both <article> and <main>

使用语义化HTML元素 (100/100)

36 semantic elements, 27 divs (ratio: 57%)

有意义的图片alt属性 (100/100)

No informative images (2 decorative)

较低的div嵌套深度 (100/100)

Avg div depth: 0.0, max: 0

内容效率

良好的Token减少比率 (100/100)

96% token reduction (HTML→Markdown)

良好的内容与噪声比 (25/100)

Content ratio: 5.7% (6259 content chars / 109861 HTML bytes)

合理的页面重量 (80/100)

HTML size: 107KB

最少的内联样式 (100/100)

0/477 elements with inline styles (0.0%)

{
  "url": "https://admintoolkit.io",
  "timestamp": 1785269726353,
  "fetch": {
    "mode": "simple",
    "timeMs": 152,
    "htmlSizeBytes": 109861,
    "supportsMarkdown": true,
    "markdownAgents": {
      "contentNegotiation": true,
      "mdUrl": {
        "found": true,
        "url": "https://admintoolkit.io/index.md"
      },
      "linkTag": {
        "found": true,
        "url": "https://admintoolkit.io/index.md"
      },
      "linkHeader": {
        "found": false,
        "url": null
      },
      "responseHeaders": {
        "contentSignal": null,
        "xMarkdownTokens": null,
        "vary": "Accept,Accept-Encoding"
      },
      "frontmatter": {
        "present": false,
        "fields": [],
        "level": "none"
      },
      "level": "application",
      "contentNegotiationMediaType": "text/markdown",
      "properMediaType": true
    },
    "statusCode": 200
  },
  "extraction": {
    "title": "admintoolkit - Admin, Engineer & AI Tools",
    "excerpt": "admintoolkit.io gives admins browser-based DNS, mail authentication, TLS, HTTP, public IP, CIDR, and EDID checks with local parsing and explicit live lookups.",
    "byline": null,
    "siteName": "admintoolkit.io",
    "lang": "en",
    "contentLength": 6259,
    "metadata": {
      "description": "admintoolkit.io gives admins browser-based DNS, mail authentication, TLS, HTTP, public IP, CIDR, and EDID checks with local parsing and explicit live lookups.",
      "ogTitle": "admintoolkit - Admin, Engineer & AI Tools",
      "ogDescription": "admintoolkit.io gives admins browser-based DNS, mail authentication, TLS, HTTP, public IP, CIDR, and EDID checks with local parsing and explicit live lookups.",
      "ogImage": "https://admintoolkit.io/brand/admintoolkit/social/home.png",
      "ogType": "website",
      "canonical": "https://admintoolkit.io/",
      "lang": "en",
      "schemas": [
        {
          "@type": "Organization",
          "@id": "https://admintoolkit.io/#organization",
          "name": "admintoolkit.io",
          "url": "https://admintoolkit.io/"
        },
        {
          "@type": "WebSite",
          "@id": "https://admintoolkit.io/#website",
          "name": "admintoolkit.io",
          "url": "https://admintoolkit.io/",
          "publisher": {
            "@id": "https://admintoolkit.io/#organization"
          },
          "inLanguage": [
            "en",
            "de"
          ]
        },
        {
          "@type": "BreadcrumbList",
          "itemListElement": [
            {
              "@type": "ListItem",
              "position": 1,
              "name": "admintoolkit.io",
              "item": "https://admintoolkit.io/"
            }
          ]
        },
        {
          "@type": "WebPage",
          "@id": "https://admintoolkit.io/#webpage",
          "url": "https://admintoolkit.io/",
          "name": "Essential Tools for Admins, Engineers and AI Agents",
          "isPartOf": {
            "@id": "https://admintoolkit.io/#website"
          },
          "inLanguage": "en"
        },
        {
          "@type": "WebApplication",
          "@id": "https://admintoolkit.io/#application",
          "name": "admintoolkit.io",
          "url": "https://admintoolkit.io/",
          "applicationCategory": "UtilitiesApplication",
          "operatingSystem": "Any",
          "isAccessibleForFree": true,
          "description": "AdminToolkit exposes read-only DNS, mail, TLS, HTTP, IP, CIDR, EDID, and agentic web diagnostics as same-origin WebMCP-compatible tool contracts with direct runtime handlers, JSON-LD UseAction metadata, OpenAPI 3.1 schemas, /tools.json and /mcp/tools discovery, and document.modelContext.registerTool as the primary registration path; a distinct legacy navigator.modelContext is used only as a compatibility fallback where present.",
          "publisher": {
            "@id": "https://admintoolkit.io/#organization"
          },
          "potentialAction": [
            {
              "@type": "ViewAction",
              "name": "List AdminToolkit WebMCP tools",
              "description": "Read the same-origin AdminToolkit MCP/WebMCP tool manifest at /tools.json or /mcp/tools with tool names, inputSchema, outputSchema, readOnly flags, OpenAPI links, and tool page URLs.",
              "target": {
                "@type": "EntryPoint",
                "urlTemplate": "https://admintoolkit.io/mcp/tools",
                "httpMethod": "GET",
                "contentType": "application/json"
              }
            },
            {
              "@type": "UseAction",
              "name": "Open AdminToolkit report tool",
              "description": "Resolve a same-origin read-only AdminToolkit report route by slug. The route is described by JSON-LD UseAction metadata, OpenAPI schema links, and document.modelContext.registerTool as the primary registration path; a distinct legacy navigator.modelContext is only a compatibility fallback.",
              "target": {
                "@type": "EntryPoint",
                "urlTemplate": "https://admintoolkit.io/{tool}/",
                "httpMethod": "GET",
                "encodingType": "application/x-www-form-urlencoded",
                "contentType": "text/html"
              },
              "query-input": [
                {
                  "@type": "PropertyValueSpecification",
                  "name": "tool",
                  "valueName": "tool",
                  "description": "AdminToolkit tool route slug.",
                  "valueRequired": true
                }
              ]
            }
          ]
        },
        {
          "@type": "ItemList",
          "@id": "https://admintoolkit.io/#tool-list",
          "name": "AdminToolkit read-only report tools",
          "itemListElement": [
            {
              "@type": "ListItem",
              "position": 1,
              "name": "AI Crawler robots.txt Checker",
              "url": "https://admintoolkit.io/ai-crawler-robots-checker/"
            },
            {
              "@type": "ListItem",
              "position": 2,
              "name": "llms.txt Validator",
              "url": "https://admintoolkit.io/llms-txt-validator/"
            },
            {
              "@type": "ListItem",
              "position": 3,
              "name": "A2A Agent Card Validator",
              "url": "https://admintoolkit.io/a2a-agent-card-validator/"
            },
            {
              "@type": "ListItem",
              "position": 4,
              "name": "WebMCP Tool Validator",
              "url": "https://admintoolkit.io/webmcp-tool-validator/"
            },
            {
              "@type": "ListItem",
              "position": 5,
              "name": "MX Record Check",
              "url": "https://admintoolkit.io/mx-record-check/"
            },
            {
              "@type": "ListItem",
              "position": 6,
              "name": "SPF/DMARC/DKIM Checker",
              "url": "https://admintoolkit.io/spf-dmarc-dkim-checker/"
            },
            {
              "@type": "ListItem",
              "position": 7,
              "name": "Email Message Header Analyzer",
              "url": "https://admintoolkit.io/email-header-analyzer/"
            },
            {
              "@type": "ListItem",
              "position": 8,
              "name": "ARC Chain Validator",
              "url": "https://admintoolkit.io/arc-chain-validator/"
            },
            {
              "@type": "ListItem",
              "position": 9,
              "name": "BIMI Checker/Generator",
              "url": "https://admintoolkit.io/bimi-checker-generator/"
            },
            {
              "@type": "ListItem",
              "position": 10,
              "name": "MTA-STS Checker/Generator",
              "url": "https://admintoolkit.io/mta-sts-checker-generator/"
            },
            {
              "@type": "ListItem",
              "position": 11,
              "name": "TLS-RPT Checker/Generator",
              "url": "https://admintoolkit.io/tls-rpt-checker-generator/"
            },
            {
              "@type": "ListItem",
              "position": 12,
              "name": "SMTP TLS Handshake / Mail Domain Delivery Readiness",
              "url": "https://admintoolkit.io/smtp-tls-readiness-checker/"
            },
            {
              "@type": "ListItem",
              "position": 13,
              "name": "DNSSEC Validator",
              "url": "https://admintoolkit.io/dnssec-validator/"
            },
            {
              "@type": "ListItem",
              "position": 14,
              "name": "TLSA Record Checker/Generator",
              "url": "https://admintoolkit.io/tlsa-record-checker-generator/"
            },
            {
              "@type": "ListItem",
              "position": 15,
              "name": "DANE Validator",
              "url": "https://admintoolkit.io/dane-validator/"
            },
            {
              "@type": "ListItem",
              "position": 16,
              "name": "CAA Record Checker/Generator",
              "url": "https://admintoolkit.io/caa-record-checker-generator/"
            },
            {
              "@type": "ListItem",
              "position": 17,
              "name": "HTTP Header Analyzer",
              "url": "https://admintoolkit.io/http-header-analyzer/"
            },
            {
              "@type": "ListItem",
              "position": 18,
              "name": "SSL Certificate Decoder",
              "url": "https://admintoolkit.io/ssl-cert-decoder/"
            },
            {
              "@type": "ListItem",
              "position": 19,
              "name": "security.txt Validator/Generator",
              "url": "https://admintoolkit.io/security-txt-validator-generator/"
            },
            {
              "@type": "ListItem",
              "position": 20,
              "name": "TLS Configuration Checker",
              "url": "https://admintoolkit.io/tls-configuration-checker/"
            },
            {
              "@type": "ListItem",
              "position": 21,
              "name": "Redirect / Canonical / Indexability Checker",
              "url": "https://admintoolkit.io/redirect-canonical-indexability-checker/"
            },
            {
              "@type": "ListItem",
              "position": 22,
              "name": "What is my IP?",
              "url": "https://admintoolkit.io/what-is-my-ip/"
            },
            {
              "@type": "ListItem",
              "position": 23,
              "name": "CIDR/Subnet Calculator",
              "url": "https://admintoolkit.io/cidr-subnet-calculator/"
            },
            {
              "@type": "ListItem",
              "position": 24,
              "name": "HDMI EDID Decoder",
              "url": "https://admintoolkit.io/edid-decoder/"
            }
          ]
        }
      ],
      "robotsMeta": "index, follow",
      "author": null,
      "generator": null,
      "markdownAlternateHref": "https://admintoolkit.io/index.md"
    }
  },
  "markdown": "## Essential Tools for Admins, Engineers and AI Agents\n\nNetwork ToolsEmail SecurityBrowser-based\n\nadmintoolkit.io brings together essential browser tools for admins, engineers and AI agents: DNS, mail security, TLS, HTTP headers, public IP checks, CIDR, EDID, and agent-readable web metadata such as robots.txt, llms.txt, A2A Agent Cards, and WebMCP tool definitions. The tools are built for traceable diagnostics with local parsing where possible, explicit live lookups, and WebMCP support for AI agents.\n\nCheck RFC 9309 robots.txt matching for documented or custom crawler product tokens with merged groups, transport evidence, and registry provenance.\n\nWeb / SEO\n\nValidate the required initial H1, optional summary and project details, and any H2 resource lists with link titles, URLs, optional descriptions, findings, and source-line evidence.\n\nWeb / SEO\n\nValidate A2A Agent Card discovery JSON, skills, interfaces, capabilities, and deployment metadata.\n\nAgentic Web\n\nInspect WebMCP declarative and imperative static source without executing JavaScript; runtime tools require actual browser observation.\n\nAgentic Web\n\nQuery MX records through DNS-over-HTTPS, sort priorities, resolve first hosts, and spot Null MX or CNAME problems.\n\nEmail Security\n\nParse SPF, DMARC, and DKIM TXT records, highlight policy issues, and run DNS lookup only when needed.\n\nEmail Security\n\nParse full message headers locally, preserve raw Received order, and classify recorded Authentication-Results without claiming cryptographic or reverse-DNS verification.\n\nEmail Security\n\nCheck ARC instance structure, continuity, and recorded cv state without claiming cryptographic validation or sealer trust.\n\nEmail Security\n\nCheck BIMI records, DMARC readiness, logo and certificate URLs, and generate a conservative BIMI TXT draft.\n\nEmail Security\n\nAssess MTA-STS TXT and HTTPS policy files, compare MX coverage, and return conformance findings with remediation warnings.\n\nEmail Security\n\nAssess TLS-RPT TXT records, validate RUA destinations, flag external providers, and return conformance findings with remediation warnings.\n\nEmail Security\n\nReview MX, STARTTLS, certificate match, MTA-STS, TLS-RPT, and optional DANE and FCrDNS readiness evidence.\n\nEmail Security\n\nReview DS, DNSKEY, RRSIG structural inventory and the validating resolver's DNSSEC verdict for a domain.\n\nDNS Security\n\nBuild valid TLSA records from certificate data and compare DANE fields directly with live DNS TLSA answers.\n\nDNS Security\n\nValidate DANE service owner names, TLSA RRsets, DNSSEC context, and implemented DANE-EE live comparisons.\n\nDNS Security\n\nCheck and generate CAA issue, issuewild, iodef, ACME account bindings, validation methods, and issuemail tags.\n\nDNS Security\n\nAnalyze pasted HTTP response headers locally, or fetch headers for a public URL through the restricted endpoint.\n\nWeb Security\n\nDecode X.509 certificates in the browser, or fetch one public host certificate through the guarded TLS endpoint.\n\nWeb Security\n\nValidate RFC 9116 vulnerability-disclosure contacts, expiry, canonical URL, policy, encryption, and hiring fields.\n\nWeb Security\n\nRun separate exact-version TLS probes and summarize verified certificate identity, negotiated cipher/ALPN evidence, and HTTPS-only HSTS evidence.\n\nWeb Security\n\nCheck bounded redirect chains, final status, HTML and HTTP canonical hints, robots metadata, scoped X-Robots-Tag, hreflang, and separate sitemap reachability and membership.\n\nWeb / SEO\n\nShows the canonical public address, observed peer, trusted-proxy evidence, browser metadata, and forwarded headers; Geo-IP/ASN and map requests require separate clicks.\n\nNetwork\n\nCalculate exact IPv4 and IPv6 networks and BigInt address counts locally, including RFC 3021 /31, host /32, embedded IPv4, and capped split previews.\n\nNetwork\n\nDecode EDID hex or local files into display identity, timings, CTA blocks, audio data, HDR metadata, and checksum status.\n\nHardware / AV\n\nLocal parsers stay in the browser where possible. DNS, HTTP, TLS, Geo-IP and map calls are shown as live actions; the public-IP reflection is same-origin, while Geo-IP/ASN and map requests require separate clicks.\n\n## Smart checks for real troubleshooting\n\nadmintoolkit.io is for the checks that come up while operating DNS, mail, TLS, web, network, and AV systems. It keeps each result close to the input: public IP context, MX routing, SPF/DMARC/DKIM/BIMI records, message headers, DNSSEC and DANE evidence, CAA policy, certificates, HTTP response headers, CIDR math, EDID data, and agentic web metadata such as llms.txt, robots.txt, A2A Agent Cards, and WebMCP tool definitions. Agent-ready diagnostics: admintoolkit.io exposes its 24 tools as read-only WebMCP runtime tools where supported by compatible agents. The pages are intentionally narrow. They give you one readable fact at a time, with the raw value still visible enough to compare against logs, tickets, DNS changes, firewall rules, or the device that produced the data.\n\n## Local first, live when needed\n\nSome tools are fully local, including header parsing, certificate decoding from pasted data, CIDR calculation, EDID decoding, and static validation of robots.txt, llms.txt, A2A, WebMCP, security.txt, ARC, and pasted DNS records. Live checks are separated by action and by tool: DNS uses browser DNS-over-HTTPS first with same-origin fallback when needed, public IP and selected host checks use same-origin helper endpoints, Geo-IP uses api.ip.sb, and the map loads only after its own opt-in. If a tool needs a current network answer, the lookup path is visible and limited to the data needed for that check.\n\n## Built for first-pass evidence\n\nThe point is not to replace vendor consoles, packet captures, DNSViz, mail logs, or full audits. The point is to get a clear first-pass fact without losing time: which address is visible, which DNS record exists, whether DNSSEC, DANE, MTA-STS, TLS-RPT, or SMTP TLS evidence lines up, which certificate is served, which header is missing, which subnet contains an address, what an EDID block says, or whether emerging agentic web metadata is structurally ready before publication. That is usually enough to decide the next step without turning a quick report into a noisy investigation.\n",
  "fullPageMarkdown": "admintoolkit - Admin, Engineer & AI Tools                           [Skip to content](https://admintoolkit.io/#app \"Skip to main content\")\n\n# Essential Tools for Admins, Engineers and AI Agents\n\nNetwork ToolsEmail SecurityBrowser-based\n\nadmintoolkit.io brings together essential browser tools for admins, engineers and AI agents: DNS, mail security, TLS, HTTP headers, public IP checks, CIDR, EDID, and agent-readable web metadata such as robots.txt, llms.txt, A2A Agent Cards, and WebMCP tool definitions. The tools are built for traceable diagnostics with local parsing where possible, explicit live lookups, and WebMCP support for AI agents.\n\n[AI Crawler robots.txt Checker](https://admintoolkit.io/ai-crawler-robots-checker/ \"AI Crawler robots.txt Checker\")\n\nCheck RFC 9309 robots.txt matching for documented or custom crawler product tokens with merged groups, transport evidence, and registry provenance.\n\nWeb / SEO\n\n[llms.txt Validator](https://admintoolkit.io/llms-txt-validator/ \"llms.txt Validator\")\n\nValidate the required initial H1, optional summary and project details, and any H2 resource lists with link titles, URLs, optional descriptions, findings, and source-line evidence.\n\nWeb / SEO\n\n[A2A Agent Card Validator](https://admintoolkit.io/a2a-agent-card-validator/ \"A2A Agent Card Validator\")\n\nValidate A2A Agent Card discovery JSON, skills, interfaces, capabilities, and deployment metadata.\n\nAgentic Web\n\n[WebMCP Tool Validator](https://admintoolkit.io/webmcp-tool-validator/ \"WebMCP Tool Validator\")\n\nInspect WebMCP declarative and imperative static source without executing JavaScript; runtime tools require actual browser observation.\n\nAgentic Web\n\n[MX Record Check](https://admintoolkit.io/mx-record-check/ \"MX Record Check\")\n\nQuery MX records through DNS-over-HTTPS, sort priorities, resolve first hosts, and spot Null MX or CNAME problems.\n\nEmail Security\n\n[SPF/DMARC/DKIM Checker](https://admintoolkit.io/spf-dmarc-dkim-checker/ \"SPF/DMARC/DKIM Checker\")\n\nParse SPF, DMARC, and DKIM TXT records, highlight policy issues, and run DNS lookup only when needed.\n\nEmail Security\n\n[Email Message Header Analyzer](https://admintoolkit.io/email-header-analyzer/ \"Email Message Header Analyzer\")\n\nParse full message headers locally, preserve raw Received order, and classify recorded Authentication-Results without claiming cryptographic or reverse-DNS verification.\n\nEmail Security\n\n[ARC Chain Validator](https://admintoolkit.io/arc-chain-validator/ \"ARC Chain Validator\")\n\nCheck ARC instance structure, continuity, and recorded cv state without claiming cryptographic validation or sealer trust.\n\nEmail Security\n\n[BIMI Checker/Generator](https://admintoolkit.io/bimi-checker-generator/ \"BIMI Checker/Generator\")\n\nCheck BIMI records, DMARC readiness, logo and certificate URLs, and generate a conservative BIMI TXT draft.\n\nEmail Security\n\n[MTA-STS Checker/Generator](https://admintoolkit.io/mta-sts-checker-generator/ \"MTA-STS Checker/Generator\")\n\nAssess MTA-STS TXT and HTTPS policy files, compare MX coverage, and return conformance findings with remediation warnings.\n\nEmail Security\n\n[TLS-RPT Checker/Generator](https://admintoolkit.io/tls-rpt-checker-generator/ \"TLS-RPT Checker/Generator\")\n\nAssess TLS-RPT TXT records, validate RUA destinations, flag external providers, and return conformance findings with remediation warnings.\n\nEmail Security\n\n[SMTP TLS Handshake / Mail Domain Delivery Readiness](https://admintoolkit.io/smtp-tls-readiness-checker/ \"SMTP TLS Handshake / Mail Domain Delivery Readiness\")\n\nReview MX, STARTTLS, certificate match, MTA-STS, TLS-RPT, and optional DANE and FCrDNS readiness evidence.\n\nEmail Security\n\n[DNSSEC Validator](https://admintoolkit.io/dnssec-validator/ \"DNSSEC Validator\")\n\nReview DS, DNSKEY, RRSIG structural inventory and the validating resolver's DNSSEC verdict for a domain.\n\nDNS Security\n\n[TLSA Record Checker/Generator](https://admintoolkit.io/tlsa-record-checker-generator/ \"TLSA Record Checker/Generator\")\n\nBuild valid TLSA records from certificate data and compare DANE fields directly with live DNS TLSA answers.\n\nDNS Security\n\n[DANE Validator](https://admintoolkit.io/dane-validator/ \"DANE Validator\")\n\nValidate DANE service owner names, TLSA RRsets, DNSSEC context, and implemented DANE-EE live comparisons.\n\nDNS Security\n\n[CAA Record Checker/Generator](https://admintoolkit.io/caa-record-checker-generator/ \"CAA Record Checker/Generator\")\n\nCheck and generate CAA issue, issuewild, iodef, ACME account bindings, validation methods, and issuemail tags.\n\nDNS Security\n\n[HTTP Header Analyzer](https://admintoolkit.io/http-header-analyzer/ \"HTTP Header Analyzer\")\n\nAnalyze pasted HTTP response headers locally, or fetch headers for a public URL through the restricted endpoint.\n\nWeb Security\n\n[SSL Certificate Decoder](https://admintoolkit.io/ssl-cert-decoder/ \"SSL Certificate Decoder\")\n\nDecode X.509 certificates in the browser, or fetch one public host certificate through the guarded TLS endpoint.\n\nWeb Security\n\n[security.txt Validator/Generator](https://admintoolkit.io/security-txt-validator-generator/ \"security.txt Validator/Generator\")\n\nValidate RFC 9116 vulnerability-disclosure contacts, expiry, canonical URL, policy, encryption, and hiring fields.\n\nWeb Security\n\n[TLS Configuration Checker](https://admintoolkit.io/tls-configuration-checker/ \"TLS Configuration Checker\")\n\nRun separate exact-version TLS probes and summarize verified certificate identity, negotiated cipher/ALPN evidence, and HTTPS-only HSTS evidence.\n\nWeb Security\n\n[Redirect / Canonical / Indexability Checker](https://admintoolkit.io/redirect-canonical-indexability-checker/ \"Redirect / Canonical / Indexability Checker\")\n\nCheck bounded redirect chains, final status, HTML and HTTP canonical hints, robots metadata, scoped X-Robots-Tag, hreflang, and separate sitemap reachability and membership.\n\nWeb / SEO\n\n[What is my IP?](https://admintoolkit.io/what-is-my-ip/ \"What is my IP?\")\n\nShows the canonical public address, observed peer, trusted-proxy evidence, browser metadata, and forwarded headers; Geo-IP/ASN and map requests require separate clicks.\n\nNetwork\n\n[CIDR/Subnet Calculator](https://admintoolkit.io/cidr-subnet-calculator/ \"CIDR/Subnet Calculator\")\n\nCalculate exact IPv4 and IPv6 networks and BigInt address counts locally, including RFC 3021 /31, host /32, embedded IPv4, and capped split previews.\n\nNetwork\n\n[HDMI EDID Decoder](https://admintoolkit.io/edid-decoder/ \"HDMI EDID Decoder\")\n\nDecode EDID hex or local files into display identity, timings, CTA blocks, audio data, HDR metadata, and checksum status.\n\nHardware / AV\n\nLocal parsers stay in the browser where possible. DNS, HTTP, TLS, Geo-IP and map calls are shown as live actions; the public-IP reflection is same-origin, while Geo-IP/ASN and map requests require separate clicks.\n\n## Root WebMCP tool contracts\n\nThe root page registers 24 directly executable, read-only WebMCP diagnostics. Each tool has a direct runtime handler and returns structured findings. Discovery endpoints include /tools.json, /.well-known/webmcp.json, /.well-known/mcp.json, /.well-known/tools.json, /mcp/tools, /.well-known/openapi.json, and /.well-known/api-catalog.\n\nAI Crawler robots.txt Checker: Return a read-only RFC 9309 robots.txt access report for AI and search crawlers. Accepts robots.txt text or a public robots.txt URL plus an optional path. Includes merged matching groups, octet-normalized longest-match decisions, per-crawler evidence, transport status, crawler-registry provenance and policy snippets.\n\nUrl  Path  Content  Crawlers  Run AI Crawler robots.txt Checker\n\nllms.txt Validator: Validate the required initial H1, optional summary and project details, and any H2 resource lists with link titles, URLs, optional descriptions, findings, and source-line evidence.\n\nUrl  Content  Run llms.txt Validator\n\nA2A Agent Card Validator: Return a read-only version-aware A2A Agent Card validation report. Includes v0.2, v0.3 and v1.0 structure plus discovery-path evidence without claiming endpoint, authentication or signature conformance.\n\nUrl  Json  Run A2A Agent Card Validator\n\nWebMCP Tool Validator: Return a read-only WebMCP report for pasted or fetched source. Includes declarative and imperative static-source evidence separately from caller-provided runtime observation; pasted JavaScript is never executed and active runtime tools are never inferred from source alone.\n\nUrl  Source  Run WebMCP Tool Validator\n\nMX Record Check: Return a read-only MX routing report for a mail domain. Accepts a domain name. Includes exchanger hosts, preferences, Null MX, CNAME risk, address resolution and actionable mail-routing warnings.\n\nDomain  Run MX Record Check\n\nSPF/DMARC/DKIM Checker: Return a read-only SPF, DMARC and DKIM report for a mail domain. Accepts a domain plus optional pasted TXT values. Includes syntax, policy strength, alignment, DNS evidence and record-specific warnings.\n\nDomain  Selector mode  Selector  Policy  Spf record  Dmarc record  Dkim record  Run SPF/DMARC/DKIM Checker\n\nEmail Message Header Analyzer: Return a read-only email message header report. Accepts pasted RFC 5322 headers. Includes raw Received order, recorded Authentication-Results and caller-configured authserv-id trust; it does not perform cryptographic authentication or reverse-DNS verification.\n\nHeaders  Trusted authserv ids  Run Email Message Header Analyzer\n\nARC Chain Validator: Return a read-only ARC structural validation report. Accepts pasted ARC-Seal, ARC-Message-Signature and ARC-Authentication-Results fields. Includes structural completeness, instance continuity and recorded cv state; cryptographic validation and sealer trust are not evaluated.\n\nHeaders  Run ARC Chain Validator\n\nBIMI Checker/Generator: Return a read-only BIMI readiness report for a mail domain. Accepts a domain, selector and optional BIMI, DMARC, logo or certificate evidence. Includes TXT syntax, DMARC dependency, asset URL findings and a conservative BIMI draft.\n\nDomain  Selector  Record  Dmarc  Logo url  Evidence url  Run BIMI Checker/Generator\n\nMTA-STS Checker/Generator: Return a read-only MTA-STS deployment report for a mail domain. Accepts a domain plus optional TXT, policy, MX and TLS-RPT evidence. Includes mode, max-age, syntax, id consistency, MX coverage, conformance findings and remediation warnings.\n\nDomain  Dns txt  Policy  Mode  Mx hosts  Tls rpt  Run MTA-STS Checker/Generator\n\nTLS-RPT Checker/Generator: Return a read-only SMTP TLS Reporting report for a mail domain. Accepts a domain plus optional TLS-RPT TXT or RUA values. Includes version syntax, reporting destinations, external-provider use, conformance findings and remediation warnings.\n\nDomain  Dns txt  Rua  Run TLS-RPT Checker/Generator\n\nSMTP TLS Handshake / Mail Domain Delivery Readiness: Return a read-only SMTP TLS delivery readiness report for a mail domain. Accepts a domain and optional MTA-STS, TLS-RPT, DANE and FCrDNS checks. Includes MX, STARTTLS, certificate, policy-alignment and downgrade-risk findings.\n\nDomain  Check mta sts  Check tls rpt  Check dane  Check fcrdns  Run SMTP TLS Handshake / Mail Domain Delivery Readiness\n\nDNSSEC Validator: Return a read-only DNSSEC evidence report for a domain. Accepts a domain plus optional DS, DNSKEY, RRSIG and resolver-status data. Includes chain readiness, algorithms, missing records, validation findings and warnings.\n\nDomain  Ds records  Dnskey records  Rrsig records  Status  Run DNSSEC Validator\n\nTLSA Record Checker/Generator: Return a read-only DANE TLSA record report. Accepts host, port, protocol, usage, selector, matching type and optional certificate data. Includes owner name, digest, generated TLSA data and DNS comparison findings.\n\nHost  Port  Protocol  Usage  Selector  Matching  Pem  File  Run TLSA Record Checker/Generator\n\nDANE Validator: Return a read-only DANE service validation report. Accepts service host, port, protocol, TLSA records, DNSSEC status and optional certificate evidence. Includes owner names, TLSA syntax, DNSSEC dependency and certificate-match findings.\n\nHost  Port  Protocol  Mode  Tlsa records  Dnssec  Run DANE Validator\n\nCAA Record Checker/Generator: Return a read-only CAA certificate-authority policy report for a domain. Accepts a domain plus optional CAA records and issuer details. Includes issue, issuewild, iodef, ACME parameters, policy gaps and record-generation guidance.\n\nDomain  Records  Ca  Iodef  Methods  Issuemail  Run CAA Record Checker/Generator\n\nHTTP Header Analyzer: Return a read-only HTTP response-header report for a public endpoint. Accepts pasted headers or a public URL. Includes security, cache, framing, duplicate/conflicting header fields, prioritized findings and remediation notes.\n\nUrl  Headers  Run HTTP Header Analyzer\n\nSSL Certificate Decoder: Return a read-only X.509 TLS certificate report. Accepts PEM text or public TLS host details. Includes subject, issuer, SANs, validity, fingerprints, key usage, extensions, hostname and certificate-health findings.\n\nHost  Port  Protocol  Pem  Run SSL Certificate Decoder\n\nsecurity.txt Validator/Generator: Return a read-only RFC 9116 security.txt report. Accepts pasted content or a public security.txt URL plus optional contact fields. Includes contact, expiry, canonical, encryption, policy, language fields, findings and draft output.\n\nUrl  Content  Contact  Encryption  Policy  Pgp key  Run security.txt Validator/Generator\n\nTLS Configuration Checker: Return a read-only public TLS configuration report for a host. Accepts host and port plus optional HSTS evidence. Includes separate exact-version probes, a distinct verified default handshake, SAN identity/trust evidence, negotiated cipher and ALPN evidence, and HTTPS-only HSTS checks; it does not claim cipher or ALPN enumeration.\n\nHost  Port  Hsts  Run TLS Configuration Checker\n\nRedirect / Canonical / Indexability Checker: Return a read-only redirect, canonical and indexability report for a public URL. Accepts a URL. Includes bounded per-hop status and SSRF evidence, final URL, HTML and HTTP canonical hints, robots meta and scoped X-Robots-Tag directives, hreflang, separate sitemap reachability and membership, and evidence completeness.\n\nUrl  Run Redirect / Canonical / Indexability Checker\n\nWhat is my IP?: Return a read-only same-origin IP context report for the current request. Requires no input. Includes the canonical primary address, directly observed peer, trusted-proxy decision, preserved forwarded-header claims and observed address family; one request path does not prove dual-stack capability and no third-party Geo-IP lookup is performed.\n\n Run What is my IP?\n\nCIDR/Subnet Calculator: Return a read-only local IPv4 or IPv6 CIDR report. Accepts a CIDR block plus optional split prefix and address family. Includes exact BigInt-derived boundaries and address counts, RFC 3021 /31 and host-route /32 semantics, no IPv6 broadcast claim, embedded-IPv4 parsing and a capped subnet preview.\n\nCidr  Target  Family  Run CIDR/Subnet Calculator\n\nHDMI EDID Decoder: Return a read-only local EDID 1.3/1.4 and bounded CTA report. Includes identity, checksums, feature-qualified preferred timing, detailed timings, SVD/SAD and speaker data, selected CTA extended blocks, and lossless raw unknown blocks from hex or file content. It does not infer Atmos, DTS:X, dynamic HDR, Dolby Vision, HDR10+, FRL, DSC, VRR, ALLM, or QMS from unimplemented evidence.\n\nFile  Edid hex  Run HDMI EDID Decoder\n\n## Smart checks for real troubleshooting\n\nadmintoolkit.io is for the checks that come up while operating DNS, mail, TLS, web, network, and AV systems. It keeps each result close to the input: public IP context, MX routing, SPF/DMARC/DKIM/BIMI records, message headers, DNSSEC and DANE evidence, CAA policy, certificates, HTTP response headers, CIDR math, EDID data, and agentic web metadata such as llms.txt, robots.txt, A2A Agent Cards, and WebMCP tool definitions. Agent-ready diagnostics: admintoolkit.io exposes its 24 tools as read-only WebMCP runtime tools where supported by compatible agents. The pages are intentionally narrow. They give you one readable fact at a time, with the raw value still visible enough to compare against logs, tickets, DNS changes, firewall rules, or the device that produced the data.\n\n## Local first, live when needed\n\nSome tools are fully local, including header parsing, certificate decoding from pasted data, CIDR calculation, EDID decoding, and static validation of robots.txt, llms.txt, A2A, WebMCP, security.txt, ARC, and pasted DNS records. Live checks are separated by action and by tool: DNS uses browser DNS-over-HTTPS first with same-origin fallback when needed, public IP and selected host checks use same-origin helper endpoints, Geo-IP uses api.ip.sb, and the map loads only after its own opt-in. If a tool needs a current network answer, the lookup path is visible and limited to the data needed for that check.\n\n## Built for first-pass evidence\n\nThe point is not to replace vendor consoles, packet captures, DNSViz, mail logs, or full audits. The point is to get a clear first-pass fact without losing time: which address is visible, which DNS record exists, whether DNSSEC, DANE, MTA-STS, TLS-RPT, or SMTP TLS evidence lines up, which certificate is served, which header is missing, which subnet contains an address, what an EDID block says, or whether emerging agentic web metadata is structurally ready before publication. That is usually enough to decide the next step without turning a quick report into a noisy investigation.\n",
  "markdownStats": {
    "images": 0,
    "links": 0,
    "tables": 0,
    "codeBlocks": 0,
    "headings": 4
  },
  "tokens": {
    "htmlTokens": 31384,
    "markdownTokens": 1324,
    "reduction": 30060,
    "reductionPercent": 96
  },
  "score": {
    "score": 92,
    "grade": "A",
    "rubricVersion": 2,
    "dimensions": {
      "accessibility": {
        "score": 88,
        "weight": 30,
        "grade": "B",
        "checks": {
          "content_without_js": {
            "score": 100,
            "weight": 55,
            "evidence": "proven",
            "details": "Content available without JavaScript"
          },
          "fast_content_position": {
            "score": 50,
            "weight": 25,
            "evidence": "plausible",
            "details": "Main content starts at 44% of HTML"
          },
          "reasonable_page_size": {
            "score": 100,
            "weight": 20,
            "evidence": "plausible",
            "details": "Page size: 107KB"
          }
        }
      },
      "aiDiscoverability": {
        "score": 93,
        "weight": 25,
        "grade": "A",
        "checks": {
          "robots_allows_ai_bots": {
            "score": 100,
            "weight": 35,
            "evidence": "proven",
            "details": "All major AI search bots allowed"
          },
          "supports_markdown_negotiation": {
            "score": 85,
            "weight": 20,
            "evidence": "plausible",
            "details": "Application level — Content negotiation, .md URL (https://admintoolkit.io/index.md), <link> tag"
          },
          "has_sitemap": {
            "score": 100,
            "weight": 15,
            "evidence": "plausible",
            "details": "Sitemap found"
          },
          "has_robots_txt": {
            "score": 100,
            "weight": 10,
            "evidence": "plausible",
            "details": "robots.txt exists"
          },
          "has_llms_txt": {
            "score": 100,
            "weight": 10,
            "evidence": "speculative",
            "details": "llms.txt exists and is valid"
          },
          "has_content_signals": {
            "score": 60,
            "weight": 10,
            "evidence": "speculative",
            "details": "robots.txt: ai-train=no, search=yes, ai-input=yes"
          }
        }
      },
      "structuredData": {
        "score": 100,
        "weight": 20,
        "grade": "A",
        "checks": {
          "has_schema_org": {
            "score": 100,
            "weight": 35,
            "evidence": "proven",
            "details": "JSON-LD found: Organization, WebSite, BreadcrumbList, WebPage, WebApplication, ItemList"
          },
          "has_open_graph": {
            "score": 100,
            "weight": 20,
            "evidence": "plausible",
            "details": "All OG tags present"
          },
          "has_meta_description": {
            "score": 100,
            "weight": 20,
            "evidence": "plausible",
            "details": "Meta description: 158 chars"
          },
          "has_canonical_url": {
            "score": 100,
            "weight": 15,
            "evidence": "plausible",
            "details": "Canonical URL present"
          },
          "has_lang_attribute": {
            "score": 100,
            "weight": 10,
            "evidence": "plausible",
            "details": "lang=\"en\""
          }
        }
      },
      "semanticHtml": {
        "score": 100,
        "weight": 15,
        "grade": "A",
        "checks": {
          "proper_heading_hierarchy": {
            "score": 100,
            "weight": 30,
            "evidence": "plausible",
            "details": "Clean heading hierarchy"
          },
          "uses_article_or_main": {
            "score": 100,
            "weight": 25,
            "evidence": "plausible",
            "details": "Has both <article> and <main>"
          },
          "semantic_elements": {
            "score": 100,
            "weight": 20,
            "evidence": "plausible",
            "details": "36 semantic elements, 27 divs (ratio: 57%)"
          },
          "meaningful_alt_texts": {
            "score": 100,
            "weight": 15,
            "evidence": "plausible",
            "details": "No informative images (2 decorative)"
          },
          "low_div_nesting": {
            "score": 100,
            "weight": 10,
            "evidence": "speculative",
            "details": "Avg div depth: 0.0, max: 0"
          }
        }
      },
      "contentEfficiency": {
        "score": 74,
        "weight": 10,
        "grade": "C",
        "checks": {
          "token_reduction_ratio": {
            "score": 100,
            "weight": 40,
            "evidence": "speculative",
            "details": "96% token reduction (HTML→Markdown)"
          },
          "content_to_noise_ratio": {
            "score": 25,
            "weight": 30,
            "evidence": "speculative",
            "details": "Content ratio: 5.7% (6259 content chars / 109861 HTML bytes)"
          },
          "reasonable_page_weight": {
            "score": 80,
            "weight": 20,
            "evidence": "speculative",
            "details": "HTML size: 107KB"
          },
          "minimal_inline_styles": {
            "score": 100,
            "weight": 10,
            "evidence": "speculative",
            "details": "0/477 elements with inline styles (0.0%)"
          }
        }
      }
    }
  },
  "recommendations": [
    {
      "id": "improve_content_ratio",
      "priority": "medium",
      "category": "contentEfficiency",
      "titleKey": "rec.improve_content_ratio.title",
      "descriptionKey": "rec.improve_content_ratio.description",
      "howToKey": "rec.improve_content_ratio.howto",
      "effort": "moderate",
      "estimatedImpact": 2.3,
      "maxImpact": 3,
      "evidence": "speculative",
      "checkScore": 25,
      "checkDetails": "Content ratio: 5.7% (6259 content chars / 109861 HTML bytes)"
    }
  ],
  "llmsTxtPreview": "# admintoolkit.io\n\n> AdminToolkit exposes read-only DNS, mail, TLS, HTTP, IP, CIDR, EDID, and agentic web diagnostics as same-origin WebMCP-compatible tool contracts with direct runtime handlers, JSON-LD UseAction metadata, OpenAPI 3.1 schemas, /tools.json and /mcp/tools discovery, and document.modelContext.registerToo…\n\n## Main\n- [admintoolkit - Admin, Engineer & AI Tools](https://admintoolkit.io): admintoolkit.io gives admins browser-based DNS, mail authentication, TLS, HTTP, public IP, CIDR, and EDID checks with l…\n- [Deutsch](https://admintoolkit.io/de/)\n- [changelog](https://admintoolkit.io/changelog/)\n- [guides](https://admintoolkit.io/guides/)\n- [admintoolkit.io](https://admintoolkit.io/)\n\n## Legal\n- [privacy](https://admintoolkit.io/privacy/)\n- [cookies](https://admintoolkit.io/cookies/)\n- [terms](https://admintoolkit.io/terms/)\n- [legal notice](https://admintoolkit.io/imprint/)\n\n## Support\n- [contact](https://admintoolkit.io/contact/)\n\n",
  "llmsTxtExisting": "# admintoolkit.io\n\n> admintoolkit.io provides 24 read-only browser diagnostics for IP, DNS, mail, HTTP headers, TLS certificates, subnets, EDID, and agent- and AI-web metadata.\nadmintoolkit.io provides practical diagnostics for administrators and technical users. Many tools run locally in the browser where possible; network lookups are explicit user actions.\nEach tool page includes a human-readable workflow section, limits section, and FAQ references for interpreting the result and understanding which data stays local.\n\nadmintoolkit.io is a free, public suite of 24 browser-based, read-only diagnostic tools for DNS, email security, TLS, HTTP, networking, and agent-discovery metadata; it is not a monitoring, automatic-remediation, or configuration-management service. Each result is point-in-time diagnostic evidence for the exact target and input from the matching canonical tool page and published contract; limitations remain part of the result rather than a guarantee. Results exist only for checks the user explicitly ran; nothing is precomputed or inferred. Network-backed checks execute only on explicit user action and only against public targets the user is authorized to inspect. Tools require no secrets, credentials, private keys, access tokens, or confidential payloads. Local processing is used where suitable, with each tool page defining its privacy boundary. Reports identify the tool, target, observation, and important limitation. Consequential DNS, mail, TLS, routing, security, or publishing changes require verification against the authoritative service.\n\n## Primary Pages\n- [Admin, Engineer & AI Tools](https://admintoolkit.io/): English home and tool index.\n- [Changelog](https://admintoolkit.io/changelog/): English release notes and recent public changes.\n\n## Agent And WebMCP Discovery\n- [MCP/WebMCP Tools](https://admintoolkit.io/mcp/tools): Machine-readable list of AdminToolkit read-only diagnostic tools with input schemas, output schemas, readOnly hints, and tool page URLs. Public agent-facing tools are read-only, same-origin, unauthenticated, and designed not to perform destructive actions.\n- [Root Tools Manifest](https://admintoolkit.io/tools.json): Same-origin public tools manifest for browser agents and crawler-based tool discovery.\n- [WebMCP Manifest](https://admintoolkit.io/.well-known/webmcp.json): WebMCP-compatible discovery metadata for browser agents.\n- [MCP-style Tool Catalog Card](https://admintoolkit.io/.well-known/mcp.json): MCP-style tool catalog metadata for AdminToolkit discovery.\n- [A2A Agent Card](https://admintoolkit.io/.well-known/agent-card.json): A2A-compatible agent card describing AdminToolkit's agent identity, skills, interfaces, and capabilities for agent-to-agent discovery.\n- [OpenAPI Description](https://admintoolkit.io/.well-known/openapi.json): OpenAPI 3.1 description for public read-only endpoints and tool contracts.\n- [API Catalog](https://admintoolkit.io/.well-known/api-catalog): Linkset catalog of public API and agent-discovery resources for AdminToolkit.\n- [Web Bot Auth Key Directory](https://admintoolkit.io/.well-known/http-message-signatures-directory): Public Ed25519 JWKS key directory for HTTP Message Signatures / Web Bot Auth verification. Private signing keys are not published.\n- [Authentication And Access Notes](https://admintoolkit.io/auth.md): Public authentication and access notes for unauthenticated read-only AdminToolkit agent discovery.\n- [llms.txt](https://admintoolkit.io/llms.txt): This route inventory and AI-readable navigation file for AdminToolkit's public tools and documentation.\n- [security.txt](https://admintoolkit.io/.well-known/security.txt): RFC 9116 security contact metadata for vulnerability disclosure and policy discovery.\n- [Homepage Markdown Representation](https://admintoolkit.io/index.md): The English homepage returns its Markdown representation when requested with `Accept: text/markdown`.\n\n## Tools\n- [AI Crawler robots.txt Checker](https://admintoolkit.io/ai-crawler-robots-checker/): Accepts robots.txt text or a public robots.txt URL plus an optional path. Reports merged matching groups, octet-normalized longest-match decisions, per-crawler evidence, transport status, crawler-registry provenance and policy snippets — Web / SEO\n- [llms.txt Validator](https://admintoolkit.io/llms-txt-validator/): Validate the required initial H1, optional summary and project details, and any H2 resource lists with link titles, URLs, optional descriptions, findings, and source-line evidence — Web / SEO\n- [A2A Agent Card Validator](https://admintoolkit.io/a2a-agent-card-validator/): Reports v0.2, v0.3 and v1.0 structure plus discovery-path evidence without claiming endpoint, authentication or signature conformance — Agentic Web\n- [WebMCP Tool Validator](https://admintoolkit.io/webmcp-tool-validator/): Reports declarative and imperative static-source evidence separately from caller-provided runtime observation; pasted JavaScript is never executed and active runtime tools are never inferred from source alone — Agentic Web\n- [MX Record Check](https://admintoolkit.io/mx-record-check/): Accepts a domain name. Reports exchanger hosts, preferences, Null MX, CNAME risk, address resolution and actionable mail-routing warnings — Email Security\n- [SPF/DMARC/DKIM Checker](https://admintoolkit.io/spf-dmarc-dkim-checker/): Accepts a domain plus optional pasted TXT values. Reports syntax, policy strength, alignment, DNS evidence and record-specific warnings — Email Security\n- [Email Message Header Analyzer](https://admintoolkit.io/email-header-analyzer/): Accepts pasted RFC 5322 headers. Reports raw Received order, recorded Authentication-Results and caller-configured authserv-id trust; it does not perform cryptographic authentication or reverse-DNS verification — Email Security\n- [ARC Chain Validator](https://admintoolkit.io/arc-chain-validator/): Accepts pasted ARC-Seal, ARC-Message-Signature and ARC-Authentication-Results fields. Reports structural completeness, instance continuity and recorded cv state; cryptographic validation and sealer trust are not evaluated — Email Security\n- [BIMI Checker/Generator](https://admintoolkit.io/bimi-checker-generator/): Accepts a domain, selector and optional BIMI, DMARC, logo or certificate evidence. Reports TXT syntax, DMARC dependency, asset URL findings and a conservative BIMI draft — Email Security\n- [MTA-STS Checker/Generator](https://admintoolkit.io/mta-sts-checker-generator/): Accepts a domain plus optional TXT, policy, MX and TLS-RPT evidence. Reports mode, max-age, syntax, id consistency, MX coverage, conformance findings and remediation warnings — Email Security\n- [TLS-RPT Checker/Generator](https://admintoolkit.io/tls-rpt-checker-generator/): Accepts a domain plus optional TLS-RPT TXT or RUA values. Reports version syntax, reporting destinations, external-provider use, conformance findings and remediation warnings — Email Security\n- [SMTP TLS Handshake / Mail Domain Delivery Readiness](https://admintoolkit.io/smtp-tls-readiness-checker/): Accepts a domain and optional MTA-STS, TLS-RPT, DANE and FCrDNS checks. Reports MX, STARTTLS, certificate, policy-alignment and downgrade-risk findings — Email Security\n- [DNSSEC Validator](https://admintoolkit.io/dnssec-validator/): Accepts a domain plus optional DS, DNSKEY, RRSIG and resolver-status data. Reports chain readiness, algorithms, missing records, validation findings and warnings — DNS Security\n- [TLSA Record Checker/Generator](https://admintoolkit.io/tlsa-record-checker-generator/): Accepts host, port, protocol, usage, selector, matching type and optional certificate data. Reports owner name, digest, generated TLSA data and DNS comparison findings — DNS Security\n- [DANE Validator](https://admintoolkit.io/dane-validator/): Accepts service host, port, protocol, TLSA records, DNSSEC status and optional certificate evidence. Reports owner names, TLSA syntax, DNSSEC dependency and certificate-match findings — DNS Security\n- [CAA Record Checker/Generator](https://admintoolkit.io/caa-record-checker-generator/): Accepts a domain plus optional CAA records and issuer details. Reports issue, issuewild, iodef, ACME parameters, policy gaps and record-generation guidance — DNS Security\n- [HTTP Header Analyzer](https://admintoolkit.io/http-header-analyzer/): Accepts pasted headers or a public URL. Reports security, cache, framing, duplicate/conflicting header fields, prioritized findings and remediation notes — Web Security\n- [SSL Certificate Decoder](https://admintoolkit.io/ssl-cert-decoder/): Accepts PEM text or public TLS host details. Reports subject, issuer, SANs, validity, fingerprints, key usage, extensions, hostname and certificate-health findings — Web Security\n- [security.txt Validator/Generator](https://admintoolkit.io/security-txt-validator-generator/): Accepts pasted content or a public security.txt URL plus optional contact fields. Reports contact, expiry, canonical, encryption, policy, language fields, findings and draft output — Web Security\n- [TLS Configuration Checker](https://admintoolkit.io/tls-configuration-checker/): Accepts host and port plus optional HSTS evidence. Reports separate exact-version probes, a distinct verified default handshake, SAN identity/trust evidence, negotiated cipher and ALPN evidence, and HTTPS-only HSTS checks; it does not claim cipher or ALPN enumeration — Web Security\n- [Redirect / Canonical / Indexability Checker](https://admintoolkit.io/redirect-canonical-indexability-checker/): Accepts a URL. Reports bounded per-hop status and SSRF evidence, final URL, HTML and HTTP canonical hints, robots meta and scoped X-Robots-Tag directives, hreflang, separate sitemap reachability and membership, and evidence completeness — Web / SEO\n- [What is my IP?](https://admintoolkit.io/what-is-my-ip/): Requires no input. Reports the canonical primary address, directly observed peer, trusted-proxy decision, preserved forwarded-header claims and observed address family; one request path does not prove dual-stack capability and no third-party Geo-IP lookup is performed — Network\n- [CIDR/Subnet Calculator](https://admintoolkit.io/cidr-subnet-calculator/): Accepts a CIDR block plus optional split prefix and address family. Reports exact BigInt-derived boundaries and address counts, RFC 3021 /31 and host-route /32 semantics, no IPv6 broadcast claim, embedded-IPv4 parsing and a capped subnet preview — Network\n- [HDMI EDID Decoder](https://admintoolkit.io/edid-decoder/): Reports identity, checksums, feature-qualified preferred timing, detailed timings, SVD/SAD and speaker data, selected CTA extended blocks, and lossless raw unknown blocks from hex or file content. It does not infer Atmos, DTS:X, dynamic HDR, Dolby Vision, HDR10+, FRL, DSC, VRR, ALLM, or QMS from unimplemented evidence — Hardware / AV\n\n## Guides\n- [Guides](https://admintoolkit.io/guides/): In-depth guidance for mail, DNS, TLS, web, network, AV, and agents.\n- [From DNS Evidence to a Finding: AdminToolkit&#x27;s DNS and Mail Security Methodology](https://admintoolkit.io/guides/dns-mail-security-methodology/): Use Methodology 1.2 to reproduce DNSSEC, DANE, mail-auth, and per-address dual-stack SMTP findings without crossing documented trust boundaries.\n- [Deploying DANE and TLSA for SMTP Without Losing Mail](https://admintoolkit.io/guides/dane-tlsa-smtp-deployment/): Deploy DANE/TLSA for SMTP with safe records, rollovers, and failure handling.\n- [A DMARC Rollout That Does Not Break Your Own Mail](https://admintoolkit.io/guides/dmarc-rollout-playbook/): Roll out DMARC safely from monitoring through enforcement.\n- [Diagnosing DNSSEC Outages: From SERVFAIL to the Broken Link](https://admintoolkit.io/guides/dnssec-outage-diagnosis/): Trace DNSSEC SERVFAIL and chain breaks to their root cause.\n- [MTA-STS, TLS-RPT, and DANE: Layering Mail Transport Security](https://admintoolkit.io/guides/mta-sts-tls-rpt-dane/): Layer MTA-STS, TLS-RPT, and DANE for mail transport security.\n- [CAA Records in Practice: Controlling Certificate Issuance](https://admintoolkit.io/guides/caa-records-in-practice/): Control certificate issuance with practical CAA policy and validation.\n- [Email Header Forensics: Reading a Message Like an Investigator](https://admintoolkit.io/guides/email-header-forensics/): Investigate Received lines, authentication results, forwarding, and ARC evidence.\n- [Making Your Site Agent-Readable: robots.txt, llms.txt, Agent Cards, and WebMCP](https://admintoolkit.io/guides/agent-readable-website/): Publish honest robots.txt, llms.txt, Agent Cards, and WebMCP discovery.\n- [TLS Troubleshooting From the Outside: Certificates, Names, and Handshakes](https://admintoolkit.io/guides/tls-certificate-troubleshooting/): Diagnose certificate, name, SNI, chain, protocol, and handshake failures.\n- [SPF Record Design That Survives the 10-Lookup Limit](https://admintoolkit.io/guides/spf-record-design/): Design SPF records that stay within the ten-lookup limit.\n- [DKIM Key Rotation Without Breaking Mail](https://admintoolkit.io/guides/dkim-key-rotation/): Rotate DKIM keys safely with overlap and clean selector retirement.\n- [How ARC Helps Mail Survive Forwarding](https://admintoolkit.io/guides/arc-forwarding-survival/): Assess forwarded-mail authentication and ARC evidence without overstating trust.\n- [BIMI Rollout: From Enforced DMARC to a Visible Logo](https://admintoolkit.io/guides/bimi-logo-rollout/): Build BIMI from enforced DMARC through deployable logo evidence.\n- [Planning MX Architecture: Preference, Capacity, and Safe Migration](https://admintoolkit.io/guides/mx-architecture-planning/): Design resilient MX routing, capacity, failover, and migrations.\n- [Auditing Mail Delivery Readiness End to End](https://admintoolkit.io/guides/mail-delivery-readiness-audit/): Audit MX, STARTTLS, policy enforcement, DANE, and reverse identity.\n- [Reading TLS-RPT Reports in Practice](https://admintoolkit.io/guides/tls-rpt-report-reading/): Turn TLS-RPT aggregates into actionable transport-security evidence.\n- [Security Headers That Actually Change Risk](https://admintoolkit.io/guides/security-headers-hardening/): Harden browser security with CSP, HSTS, cookies, isolation, and redirects.\n- [security.txt and the Disclosure Process Behind It](https://admintoolkit.io/guides/security-txt-disclosure/): Build an operational vulnerability-disclosure process around security.txt.\n- [Hardening TLS Without Guessing at Client Compatibility](https://admintoolkit.io/guides/tls-configuration-hardening/): Harden TLS with measured compatibility and expiring legacy exceptions.\n- [Redirects, Canonicals, and Indexability as One System](https://admintoolkit.io/guides/redirect-canonical-indexability/): Align redirects, canonicals, robots, hreflang, sitemaps, and internal links.\n- [Public IP, NAT, and Dual Stack: Which Address Is Really Yours?](https://admintoolkit.io/guides/public-ip-nat-dual-stack/): Understand public addressing across NAT, CGNAT, dual stack, and proxies.\n- [IPv6 Subnet Planning That Scales](https://admintoolkit.io/guides/ipv6-subnet-planning/): Plan scalable IPv6 prefixes, aggregation, reserves, and documentation.\n- [HDMI and EDID Troubleshooting in Real Signal Chains](https://admintoolkit.io/guides/hdmi-edid-troubleshooting/): Trace EDID capability loss through real HDMI signal chains.\n- [llms.txt in Practice: Curating a Useful Entry Point](https://admintoolkit.io/guides/llms-txt-in-practice/): Curate a useful llms.txt map with consistent access and indexing signals.\n- [Exposing Website Functions as WebMCP Tools](https://admintoolkit.io/guides/webmcp-tool-exposure/): Expose precise WebMCP tools with UI parity and runtime checks.\n\n## Contact, Policies, And Data\n- [Contact](https://admintoolkit.io/contact/): English contact form for tool requests, tool questions, bug reports, privacy or legal questions, and other messages.\n- [Privacy Policy](https://admintoolkit.io/privacy/): English privacy policy for local processing, live lookups, analytics, logs, and contact details. User-entered tool values are not sent to analytics.\n- [Cookies](https://admintoolkit.io/cookies/): English cookie and analytics controls; analytics requires consent and can be declined.\n- [Terms of Use](https://admintoolkit.io/terms/): English terms of use. No public pricing page or paid plan is currently published.\n- [Legal Notice & Contact](https://admintoolkit.io/imprint/): English legal notice and operator contact: [email protected].\n\n## Optional\n- [Full Tool Reference](https://admintoolkit.io/llms-full.txt): Optional English full-context reference for all 24 read-only tools, with inputs, result models, workflows, privacy notes, limits, examples, and FAQs.",
  "emergingProtocols": {
    "oauthProtectedResource": {
      "exists": false,
      "url": "https://admintoolkit.io/.well-known/oauth-protected-resource"
    },
    "oauthDiscovery": {
      "exists": false,
      "url": "https://admintoolkit.io/.well-known/oauth-authorization-server"
    },
    "mcpServerCard": {
      "exists": false,
      "url": "https://admintoolkit.io/.well-known/mcp/server-card.json",
      "draft": true
    },
    "a2aAgentCard": {
      "exists": true,
      "url": "https://admintoolkit.io/.well-known/agent-card.json",
      "name": "admintoolkit.io",
      "version": "2026-07-01",
      "description": "admintoolkit.io exposes anonymous read-only diagnostics and discovery documents for DNS, mail, TLS, HTTP, IP, CIDR, EDID, and agent-facing web metadata.",
      "capabilities": 4,
      "skills": 2,
      "endpoint": null
    },
    "apiCatalog": {
      "exists": true,
      "url": "https://admintoolkit.io/.well-known/api-catalog",
      "contentType": "application/linkset+json; charset=UTF-8",
      "validMediaType": true,
      "apis": 1
    },
    "agentSkills": {
      "exists": true,
      "url": "https://admintoolkit.io/.well-known/agent-skills/index.json",
      "draft": true,
      "schema": "https://schemas.agentskills.io/discovery/0.2.0/schema.json",
      "skills": 4,
      "names": [
        "check-mail-and-tls-readiness",
        "markdown-negotiation",
        "use-admintoolkit-tools",
        "validate-agent-discovery"
      ]
    },
    "count": 3,
    "total": 6
  },
  "botAccess": {
    "probed": true,
    "bot": "OAI-SearchBot",
    "controlStatus": 200,
    "botStatus": 200,
    "discriminates": false,
    "refusedAsBot": false,
    "edge": "Cloudflare",
    "verifiable": false,
    "detail": "This origin answers OAI-SearchBot exactly as it answers any other client (200). No edge-level filtering of AI crawlers observed."
  },
  "snippets": []
}

使用我们的API以编程方式获取此内容(即将推出)

此JSON供内部使用 — 与Markdown和llms.txt文件不同,它不适合上传到您的网站。将其保存为基准值以跟踪评分变化,与开发团队共享,或集成到CI/CD流水线中。

想听听第二种意见?

Cloudflare 也提供免费扫描工具,但它问的是另一个问题。他们评分的是你的站点为智能体调用而发布的东西:MCP server card、Agent Skills、API 目录、DNS 记录。我们评分的是智能体能否访问、读取并理解你的内容。一个站点可能在其中一项表现很好、另一项很差,所以看到两个不同的分数很正常:它们是两个不同问题的答案,都值得了解。

用 Cloudflare 扫描 admintoolkit.io

嵌入您的徽章

将此徽章添加到您的网站。当您的 AI 就绪评分发生变化时,它会自动更新。

AgentReady.md score for admintoolkit.io
Script 推荐
<script src="https://agentready.md/badge.js" data-id="b2e5c679-b755-4e3a-ab70-833d44873b19" data-domain="admintoolkit.io"></script>
Markdown
[![AgentReady.md score for admintoolkit.io](https://agentready.md/badge/admintoolkit.io.svg)](https://agentready.md/zh/r/b2e5c679-b755-4e3a-ab70-833d44873b19)

即将推出:全域分析

爬取您的整个域名,生成llms.txt,并随时间监控您的AI就绪度评分。加入等候名单以获取通知。

您已加入名单!服务上线时我们会通知您。