scanned Apr 24, 2026

DNSid

dnsid.ai

DNSid provides a universal way to identify and verify ownership of AI agents across different environments and platforms.

8/100

Tier 1 · Agent-Unreadable

Content answers4/100
Protocol plumbing64/1007 of 11 checks pass

Scored by asking 15 questions a buyer of a ai-ml product asks, then grading this site’s own pages: answered, hedged (partial or vague), or silent (no page answers it). How scoring works

This report is public. Own dnsid.ai? Claiming is free: crawl every page, re-audit as you fix, and track your score over time.

Sign in to claim

The fix queue

92 points sit between dnsid.ai and 100: 15 open questions and 4 missing protocol checks, ordered by estimated payoff.

Point estimates are per fix under scoring v2. They are not additive to a promised total.

01getting-started · importance highGoes silent+7 content pts est.

We already have agents running with self-signed x509 certs — can we import those into DNSID to preserve continuity, or do we need to re-issue everything?

What the pages say

No page on the site addresses this.

The fix

Create a getting-started or migration guide that addresses common onboarding scenarios: importing existing x509 certificates, rotating from self-signed to DNSID-issued certs, hybrid operation during transition periods, and whether DNSID acts as a root CA or can chain to existing PKI infrastructure.

confidence high · grounding world-knowledge · weight 0.00 · Absent

02security · importance highGoes silent+7 content pts est.

If an agent's private key is compromised, what's the SLA for revocation propagation — and do you support OCSP stapling or only CRL distribution?

What the pages say

No page on the site addresses this.

The fix

Add a security/operations page documenting PKI certificate management practices, including revocation mechanisms (OCSP vs CRL), propagation SLAs, and stapling support. This is critical infrastructure detail for security-conscious buyers evaluating agent identity platforms.

confidence high · grounding world-knowledge · weight 0.00 · Absent

03security · importance highGoes silent+7 content pts est.

Your site mentions 'organizational boundaries' — if our legal team requires HSM-backed key escrow for agent identity keys, is that supported or do you hold all private material?

What the pages say

No page on the site addresses this.

The fix

Create a dedicated security architecture or key custody page that explains: (1) who holds private keys for agent identities, (2) whether HSM-backed key escrow or BYOK (bring your own key) options exist, (3) key generation and storage security controls, and (4) compliance with enterprise key management requirements.

confidence high · grounding world-knowledge · weight 0.00 · Absent

04technical · importance highGoes silent+7 content pts est.

When an AI agent gets decommissioned, does the birth certificate get revoked, archived, or does it persist forever with a 'terminated' status flag?

What the pages say

No page on the site addresses this.

The fix

Add documentation or FAQ section covering the complete lifecycle of a birth certificate including decommissioning, revocation, archival, and termination status handling.

confidence high · grounding world-knowledge · weight 0.00 · Absent

05pricing · importance highGoes silent+7 content pts est.

We're planning to register roughly 50,000 AI agents across three subsidiaries — do you have published volume tiers or is everything custom-quoted at that scale?

What the pages say

No page on the site addresses this.

The fix

Create a dedicated pricing page with published volume tiers or clear guidance on when custom quoting applies (e.g., thresholds like 10K/50K/100K agents).

confidence high · grounding world-knowledge · weight 0.00 · Page missing

06limits · importance mediumGoes silent+7 content pts est.

Is there a hard limit on agents registered per API call, or can we submit a 10,000-agent batch in one request? What's the timeout behavior if it takes too long?

What the pages say

No page on the site addresses this.

The fix

Create a developer documentation section with API reference including rate limits, batch size limits, timeout behavior, and request/response schemas. Consider adding a /docs or /developers page.

confidence high · grounding world-knowledge · weight 0.00 · Absent

07integration · importance mediumGoes silent+7 content pts est.

We need to feed agent verification events into our Splunk SIEM — do you offer a native Splunk connector or is it generic webhook/Syslog only?

What the pages say

No page on the site addresses this.

The fix

Create a dedicated integrations or API documentation page that lists available connectors (native Splunk, generic webhook, Syslog, etc.) with configuration details.

confidence high · grounding world-knowledge · weight 0.00 · Absent

08limits · importance mediumGoes silent+7 content pts est.

If two organizations both register agents with DNSID and later need to verify each other's agents, is there a rate limit on cross-organization certificate lookups?

What the pages say

No page on the site addresses this.

The fix

Add technical documentation covering rate limits, query quotas, and operational constraints for cross-organization certificate lookups, likely in a developer docs or API reference section.

confidence high · grounding world-knowledge · weight 0.00 · Absent

09operations · importance mediumGoes silent+7 content pts est.

For compliance purposes, how long do you retain the full audit trail of who modified an agent's birth certificate metadata — and can we export it to our own S3 bucket?

What the pages say

No page on the site addresses this.

The fix

Add a dedicated compliance/operations page covering data retention periods for audit trails and export/integration options including S3.

confidence high · grounding world-knowledge · weight 0.00 · Absent

10integration · importance lowGoes silent+7 content pts est.

We use Okta for workforce identity — does DNSID expose an OIDC bridge so our human admins can authenticate to the DNSID dashboard with existing SSO?

What the pages say

No page on the site addresses this.

The fix

Create a documentation page or FAQ section covering identity provider integrations for workforce SSO, specifically mentioning OIDC/SAML support for dashboard access.

confidence high · grounding world-knowledge · weight 0.00 · Absent

11migration · importance lowGoes silent+7 content pts est.

We're currently using SPIFFE/SPIRE for agent identity — does DNSID have a migration path that preserves SPIFFE IDs or do we abandon that namespace entirely?

What the pages say

No page on the site addresses this.

The fix

Create a migration guide or FAQ page addressing common identity systems including SPIFFE/SPIRE, with explicit guidance on whether SPIFFE IDs can be preserved, mapped, or must be abandoned when adopting DNSid.

confidence high · grounding synthesized · weight 0.00 · Absent

12operations · importance lowGoes silent+7 content pts est.

For disaster recovery, can we configure DNSID to replicate our agent registry to a secondary region we control, or is it strictly your SaaS infrastructure?

What the pages say

No page on the site addresses this.

The fix

Create a dedicated infrastructure/architecture page documenting deployment options, data residency, replication capabilities, and whether customers can configure secondary regions or if DNSid operates strictly as a managed SaaS service.

confidence high · grounding world-knowledge · weight 0.00 · Absent

13support · importance lowGoes silent+7 content pts est.

If we hit a P1 incident at 2am on a Sunday — like mass agent verification failures — is there a phone hotline or is it strictly ticket-based with defined severity SLAs?

What the pages say

No page on the site addresses this.

The fix

Create a dedicated support or contact page that specifies available support channels (phone, email, ticket portal), hours of operation, severity-based SLA commitments, and escalation procedures for P1 incidents.

confidence high · grounding world-knowledge · weight 0.00 · Absent

Hedged · 2 of 15 questions

A buyer gets something, then has to guess the rest. Expand any row for the evidence and the fix.

14You mention blockchain in your subcategories — which chain(s) do you actually anchor certificates to, and can we choose a private permissioned ledger instead of public?technicalHedges+7 pts est.

You mention blockchain in your subcategories — which chain(s) do you actually anchor certificates to, and can we choose a private permissioned ledger instead of public?

What the pages say

No page on the site addresses this.

The fix

Add a dedicated technical page specifying which blockchain(s) are used (e.g., Ethereum, Hyperledger Fabric, etc.) and whether customers can configure private permissioned ledger options.

Where we looked: dnsid.ai, dnsid.ai

confidence high · grounding stated · weight 0.00 · Vague

15Beyond proving 'who I am' to humans, can two DNSID-registered agents mutually authenticate each other directly using your certificates without calling your API?technicalHedges+3 pts est.

Beyond proving 'who I am' to humans, can two DNSID-registered agents mutually authenticate each other directly using your certificates without calling your API?

What the pages say

The chunks describe DNSid™ as using PKI/TLS/DANE for 'proof in the moment' and being 'resolvable by any party and any platform regardless of whether bilateral agreements are in place,' which suggests peer-to-peer verification is architecturally possible. However, the site does not explicitly state whether two DNSID-registered agents can mutually authenticate directly using certificates without calling DNSid's API. The technical implementation details of agent-to-agent authentication versus API-dependent verification are not specified.

The fix

Add explicit documentation on agent-to-agent authentication flows: clarify whether certificates can be validated offline using DANE/DNSSEC, what API calls (if any) are required for mutual authentication, and provide a technical architecture diagram showing the verification path between two agents.

Where we looked: dnsid.ai, dnsid.ai, dnsid.ai, dnsid.ai

confidence low · grounding synthesized · weight 0.55 · Vague

Protocol plumbing · 64/1007 of 11 checks pass · each fix +9 protocol pts est.

The other half of the score: 11 checks for the files and headers agents look for. The 4 below are installs, not judgment calls, and most are an afternoon. Expand any for the snippet and the standard it follows. They sit after the queue because none of them changes what your pages say.

Content signalAccess+9 pts est.
Install snippet
User-agent: *
Content-Signal: search=yes, ai-input=yes, ai-train=no
Allow: /

StandardCloudflare proposalVendor proposal

Markdown negotiationRendering+9 pts est.

StandardRFC 9110 + 7763IETF RFC

Server-rendered contentRendering+9 pts est.

StandardSitedex metricSitedex metric

WebMCP widgetInteraction+9 pts est.

Sitedex generates this file from your crawl. Grab it in Files from this audit below.

StandardW3C WebMCP draftW3C / WHATWG

Already passing 7 of 11: robots.txt, sitemap.xml, llms.txt, AI crawler access, Clean crawl, MCP card, OpenAPI spec.

Ask this site’s index

Sitedex already serves dnsid.ai as an MCP endpoint. Ask dnsid.ai anything an AI agent might ask, and see what its index returns. (To score your own site, use the form below.)

Snippets & configs

For developers and the engineer-on-call: copy these into your tools or your site.

Files from this audit

Built from this crawl. Download or copy each, then install it at the path noted.

llms.txt

Built from this crawl. Install at /llms.txt so agents start here.

organization.json

Organization JSON-LD, pre-filled from this crawl. Wrap in a ld+json script.

server-card.json

MCP server card built from this crawl. Host at /.well-known/mcp/server-card.json.

webmcp.json

WebMCP discovery manifest built from this crawl. Host at /.well-known/webmcp.json.

MCP endpoint

https://mcp.sitedex.dev/s/dnsid-ai/mcp

The URL anyone's agent points at. Read-only; safe to share.

Claude Code

claude mcp add dnsid --transport http https://mcp.sitedex.dev/s/dnsid-ai/mcp

One command, then the agent has it.

Cursor / Continue

{
  "mcpServers": {
    "dnsid": {
      "url": "https://mcp.sitedex.dev/s/dnsid-ai/mcp"
    }
  }
}

Drop into mcp.json.

WebMCP: two parts

WebMCP-capable browsers run the widget at runtime. Crawlers without JS rendering need the discovery manifest to find your tool surface. Install both.

1 · Widget script

<script async src="https://sitedex.dev/widget.js"></script>

Drop in <head>. WebMCP-capable browsers (Chrome 146+ Origin Trial) call navigator.modelContext.provideContext() via this script.

2 · Discovery manifest

{
  "$schema": "https://wellknownmcp.org/schemas/webmcp.json",
  "name": "dnsid.ai",
  "tools": [
    { "name": "search", "description": "Search dnsid.ai's indexed content." },
    { "name": "get_page", "description": "Fetch a page from dnsid.ai as markdown." }
  ]
}

Host alongside the script at /.well-known/webmcp.json. Crawlers that don't render JS rely on this.

Your turn

See which of these questions your site goes silent on.

Free, about 5 minutes. We crawl your site, test it against the buyer questions your category asks, and name what’s vague, contradictory, or missing, plus the files AI agents look for.

ComingEmbeddable grade badgeScore history and deltasOpt-in public board