{"id":50926202,"url":"https://github.com/kent-tokyo/shohei","last_synced_at":"2026-06-16T23:04:32.885Z","repository":{"id":363009909,"uuid":"1239773591","full_name":"kent-tokyo/shohei","owner":"kent-tokyo","description":"A next-generation Rust DNS diagnostic CLI that visualizes DNSSEC trust chains, iterative resolution paths, and DoH/DoT with an interactive TUI.","archived":false,"fork":false,"pushed_at":"2026-06-07T00:29:09.000Z","size":1337,"stargazers_count":1,"open_issues_count":0,"forks_count":0,"subscribers_count":1,"default_branch":"master","last_synced_at":"2026-06-07T03:29:23.059Z","etag":null,"topics":["cui","dig","dns","dnssec","rust","tui"],"latest_commit_sha":null,"homepage":"","language":"Rust","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/kent-tokyo.png","metadata":{"files":{"readme":"README.md","changelog":"CHANGELOG.md","contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2026-05-15T12:30:06.000Z","updated_at":"2026-06-07T00:29:12.000Z","dependencies_parsed_at":null,"dependency_job_id":null,"html_url":"https://github.com/kent-tokyo/shohei","commit_stats":null,"previous_names":["kent-tokyo/shohei"],"tags_count":null,"template":false,"template_full_name":null,"purl":"pkg:github/kent-tokyo/shohei","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/kent-tokyo%2Fshohei","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/kent-tokyo%2Fshohei/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/kent-tokyo%2Fshohei/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/kent-tokyo%2Fshohei/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/kent-tokyo","download_url":"https://codeload.github.com/kent-tokyo/shohei/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/kent-tokyo%2Fshohei/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":34426776,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-05-26T15:22:16.424Z","status":"online","status_checked_at":"2026-06-16T02:00:06.860Z","response_time":126,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["cui","dig","dns","dnssec","rust","tui"],"created_at":"2026-06-16T23:04:32.206Z","updated_at":"2026-06-16T23:04:32.880Z","avatar_url":"https://github.com/kent-tokyo.png","language":"Rust","funding_links":[],"categories":[],"sub_categories":[],"readme":"# shohei\n\n[![Crates.io](https://img.shields.io/crates/v/shohei.svg)](https://crates.io/crates/shohei)\n[![CI](https://github.com/kent-tokyo/shohei/actions/workflows/ci.yml/badge.svg)](https://github.com/kent-tokyo/shohei/actions/workflows/ci.yml)\n[![License: MIT](https://img.shields.io/badge/License-MIT-yellow.svg)](https://opensource.org/licenses/MIT)\n[![MSRV](https://img.shields.io/badge/rust-1.85%2B-blue.svg)](https://www.rust-lang.org)\n\n[日本語](README_ja.md) | [中文](README_zh.md)\n\n\u003e **SHOHEI** — **S**ecurity **H**ost **O**bservation \u0026 **H**ealthy **E**valuation **I**nstrument\n\n**shohei** v2.5.1 — **Rust infrastructure diagnostics library with 168 MCP tools across 62 modules**. Comprehensive security, OSINT, threat intelligence, and governance coverage. DNSSEC chain validation, DANE/TLSA, modern protocols, IPv6 dual-stack, security headers, technology fingerprinting, CVE lookup, typosquatting detection, and redirect analysis built in. **0 API keys required — all free/open APIs. Use in Rust projects or hand to Claude for autonomous diagnosis.**\n\n### Core Diagnostics (v1.0+)\n\n- **MCP server for Claude** — 168 diagnostic tools; ask \"Check example.com's TLS certificate, DNSBL status, IPv6 support, technology stack, CVE vulnerabilities, typosquatting variants, and redirect chain\" for autonomous analysis\n- **TLS certificate inspection** — DANE/TLSA validation (RFC 6698), chain analysis, OCSP responder detection, IPv6 support, OCSP stapling detection, TLS version probing (1.0–1.3), cipher suite enumeration\n- **Email security scoring** — MX records, SPF, DKIM, DMARC, BIMI, MTA-STS, TLS-RPT validation with 0–100 compliance score + issue linting\n- **IP reputation** — DNSBL checks against Spamhaus, Barracuda, SORBS; reverse DNS (PTR) + forward-confirmed reverse DNS (FCrDNS)\n- **CDN/WAF detection** — Identify Cloudflare, AWS CloudFront, Fastly, Akamai, Vercel, Netlify, Imperva via HTTP headers\n- **DNS delegation audit** — SOA serial consistency check, lame delegation detection across authoritative NS\n- **Domain health report** — Composite scoring across MX, SPF, DMARC, TLS, DNSSEC\n- **Security headers audit** — CSP, HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy with risk scoring\n\n### DNS \u0026 Network (v1.0+)\n\n- **DNS propagation checker** — Verify domain consistency across 6 global resolvers (Google, Cloudflare, Quad9, OpenDNS, 1.1.1.1, 8.8.8.8)\n- **DNSSEC chain tree** — see every DS, DNSKEY, and trust step from `.` to your domain; per-zone validation runs in parallel; add `-v` for key tags and algorithm names\n- **Iterative resolution trace** — watch queries travel from root servers to TLD to authoritative NS\n- **Latency benchmarking** — Multi-transport timing: System, DoH, DoT, DoQ across multiple rounds\n- **Reverse DNS** — PTR lookups for IPv4/IPv6 with FCrDNS validation\n- **Subdomain enumeration** — Check common subdomains (www, mail, api, staging, dev, etc.) with DNS resolution + HTTP status + TLS validity\n- **Port reachability** — TCP connectivity test for 15 common ports (SSH/22, HTTP/80, HTTPS/443, SMTP/25, MySQL/3306, etc.) with banner grab\n- **IPv6 dual-stack checker** — Verify AAAA records, IPv6 TCP/TLS/HTTP reachability, dual-stack completeness\n- **DNS amplification potential** — Measure UDP query/response size ratio, DDoS attack risk assessment\n- **Wildcard DNS detection** — Probe random subdomains to detect misconfigured `*.domain` records\n- **Traceroute / hop analysis** — Multi-platform hop-by-hop latency measurement (Linux/macOS/Windows)\n\n### Advanced Features (v1.0+)\n\n- **DoH, DoT, and DoQ** — DNS-over-HTTPS, DNS-over-TLS, and DNS-over-QUIC built in\n- **Zone transfer (AXFR)** — dump an entire zone from an authoritative server; detect critical misconfiguration\n- **N-way server comparison** — diff any number of resolvers simultaneously with `--compare`\n- **Multiple record types** — `--type a --type aaaa --type mx` queries all types concurrently in a single invocation\n- **Stdin and file batch mode** — pipe a list of domains or use `-f domains.txt`\n- **JSON output** — pipe-friendly for scripting and automation\n- **Watch mode** — auto-refresh at a set interval with `--watch`\n- **Interactive TUI** — browse records, DNSSEC chain, and trace in a single terminal window (`--features tui`)\n- **HTTP protocol detection** — Automatically detect HTTP/1.1, HTTP/2, HTTP/3 version in responses\n- **RPKI/ROA validation** — BGP origin authorization checks via Cloudflare API\n- **ARC authentication** — Email chain authentication record validation (DNS-level)\n- **TLS-RPT checking** — SMTP TLS Reporting Policy record discovery and parsing\n\n### Web Reconnaissance \u0026 Threat Intelligence (v1.3–1.4)\n\n- **Technology stack fingerprinting** — Identify web server, language runtime, CMS (WordPress/Drupal), frameworks from HTTP headers\n- **CVE lookup via NVD API** — Search for known vulnerabilities (no API key required); integrates with tech fingerprinting\n- **Typosquatting detection** — Generate 200+ domain variants (TLD swap, missing char, transposition, homoglyph, etc.); parallel DNS resolution to find live squats\n- **URL redirect chain tracing** — Follow HTTP redirects hop-by-hop; detect HTTPS→HTTP downgrades and redirect loops\n- **Parked domain detection** — Identify domains parked for sale via header signatures (Sedo, GoDaddy, Bodis, etc.)\n\n## Why shohei?\n\n### AI-First Infrastructure Diagnostics\n\nMost infrastructure tools are CLI-only. **shohei is built for AI agents:**\n\n- **MCP Server Ready**: Expose all diagnostics to Claude, ChatGPT, and custom AI agents without writing integration code\n- **Claude Desktop Integration**: Ask Claude \"Check example.com's TLS certificate\" → get automated diagnosis with full chain analysis\n- **Structured Async APIs**: Every function returns serializable types (`DnsCheckResult`, `TlsCheckResult`, `EmailSecurityResult`) — perfect for agents\n- **No CLI, No Python**: Pure Rust library + MCP server; scales from single checks to automated monitoring\n\n### Developer-Friendly\n\n- **Library-first design**: Import into Rust projects, CI/CD pipelines, or automation frameworks\n- **Trust chain validation**: The only open-source library that validates DNS → DNSSEC → TLS → DANE/TLSA in one call\n- **Modern protocols**: DoH, DoT, DoQ, DNSSEC, DANE/TLSA all built in\n- **Automation-friendly**: Concurrent queries, batching, multi-resolver checks, and programmatic APIs\n\n**Compared to alternatives** (`dig`, `dog`, `drill`): shohei is composable—use it in tests, monitoring, CI/CD, **or hand it to Claude for autonomous diagnosis.**\n\n| Feature | shohei | dig | dog | doggo | q | delv | drill |\n|---------|:------:|:---:|:---:|:-----:|:-:|:----:|:-----:|\n| Colored output | ✓ | | ✓ | ✓ | ✓ | | |\n| **DNSSEC chain-of-trust tree** | **✓** | | | | | | |\n| DNSSEC validation | ✓ | ✓ | | | | ✓ | ✓ |\n| **Iterative resolution trace (visual)** | **✓** | | | | | | |\n| Authority + Additional sections | ✓ | ✓ | | | | ✓ | ✓ |\n| N-way server comparison (`--compare`) | **✓** | | | | | | |\n| Zone transfer (AXFR) | **✓** | ✓ | | | | | ✓ |\n| Watch / auto-refresh (`--watch`) | **✓** | | | | | | |\n| Script-friendly output (`--short`) | **✓** | | | | | | |\n| **Multiple record types** (`--type a --type mx`) | **✓** | | | ✓ | | | |\n| **Reverse DNS shorthand** (`-x 1.2.3.4`) | **✓** | ✓ | | ✓ | | | |\n| Force TCP (`--tcp`) | ✓ | ✓ | | | | | ✓ |\n| Disable recursion (`--no-recurse`) | ✓ | ✓ | | | | ✓ | ✓ |\n| Query latency display | ✓ | ✓ | | ✓ | ✓ | | |\n| DNS-over-HTTPS (DoH) | ✓ | ✓ | ✓ | ✓ | ✓ | | |\n| DNS-over-TLS (DoT) | ✓ | ✓ | ✓ | ✓ | ✓ | | |\n| DNS-over-QUIC (DoQ) | **✓** | | | | ✓ | | |\n| JSON output | ✓ | ✓ | ✓ | ✓ | ✓ | | |\n| Interactive TUI | **✓** | | | | | | |\n| **Technology stack fingerprinting** | **✓** | | | | | | |\n| **CVE lookup (no API key)** | **✓** | | | | | | |\n| **Typosquatting detection** | **✓** | | | | | | |\n| **URL redirect chain tracing** | **✓** | | | | | | |\n| **Parked domain detection** | **✓** | | | | | | |\n\n\u003e dig = BIND utils 9.16+; q = [natesales/q](https://github.com/natesales/q); delv = BIND DNSSEC-validating resolver; drill = ldns-based\n\u003e\n\u003e **v2.4.0 additions**: 168 MCP tools across 62 modules, robots.txt/OAuth/OIDC/API exposure, unauthenticated DB/container detection, subdomain takeover (30+ services), DGA risk scoring, DKIM key strength, attack surface composite score, RIPE Stat passive DNS, Azure AD exposure.\n\u003e\n\u003e **v2.5.1 security patch**: 9 CRITICAL/HIGH SSRF fixes (VMC fetch, TCP port scan, MX connect, redirect-follow without per-hop validation across 8 modules), 15+ bug fixes (IPv6 DNSBL trailing-dot, Levenshtein panic on IDN, crypto stubs returning `valid=true`, hardcoded year comparisons, SPF `all` qualifier never populated, sequential awaits parallelised), 4× performance improvement on trust/threat scoring via `tokio::join!`.\n\n## MCP Security Servers Comparison\n\nshohei v2.5.1 stands out as the most comprehensive free, API-key-free MCP security server:\n\n| Feature | shohei | honeylabs | kastell | unphurl | cloud-audit | maigret |\n|---------|:------:|:---------:|:-------:|:-------:|:-----------:|:-------:|\n| **MCP Tools** | **168** | ~25 | ~30 | ~15 | ~20 | ~35 |\n| **Modules** | **62** | ~8 | ~10 | ~5 | ~7 | ~12 |\n| **DNS/DNSSEC** | ✓ | ✓ | ✓ | | | |\n| **TLS/Certificate** | ✓ | ✓ | ✓ | | | |\n| **Email Security** | ✓ | | | | | |\n| **OSINT/Recon** | ✓ | ✓ | | ✓ | | ✓ |\n| **Threat Intel** | ✓ | | | | | |\n| **WHOIS/Domain** | ✓ | | ✓ | | | |\n| **Port/Service** | ✓ | | | | | |\n| **IP Reputation** | ✓ | ✓ | | | | |\n| **Compliance/Governance** | ✓ | | | | ✓ | |\n| **Crypto/Blockchain** | ✓ | | | | | |\n| **Web Headers** | ✓ | ✓ | | ✓ | | |\n| **API Keys Required** | **0** | Multiple | Multiple | Some | Multiple | Multiple |\n| **Free/Open APIs Only** | **✓** | Partial | Partial | Partial | Partial | Partial |\n| **Active Maintenance** | ✓ | | | | | ✓ |\n| **Open Source** | ✓ (MIT) | | | | | ✓ |\n\n**Key Advantages:**\n- **168 MCP tools** — largest comprehensive security toolkit (v2.5.1)\n- **0 API keys** — all tools use free/open public APIs\n- **62 modules** — DNS, TLS, email, OSINT, threat intel, governance, crypto, web security, supply chain, compliance\n- **Zero setup cost** — no vendor API accounts or authentication required\n- **Pure library + MCP** — Rust library for CI/CD + MCP server for Claude Desktop/agents\n\n\n## Installation\n\n### As a library (Rust projects)\n\nAdd to your `Cargo.toml`:\n\n```toml\n[dependencies]\nshohei = \"2.4\"\n```\n\nThen import and use:\n\n```rust\nuse shohei::resolver::standard::query;\n\n#[tokio::main]\nasync fn main() {\n    let result = query(\"example.com\", \"A\").await;\n    println!(\"{:?}\", result);\n}\n```\n\nFor full API documentation: `cargo doc --open` or [docs.rs/shohei](https://docs.rs/shohei).\n\n### As a CLI (manual diagnosis)\n\n```bash\ncargo install shohei\n```\n\nOr download a pre-built binary from the [releases page](https://github.com/kent-tokyo/shohei/releases).\n\nFor the interactive TUI mode:\n\n```bash\ncargo install shohei --features tui\n```\n\n## Library Examples\n\nshohei is designed to be imported and composed in Rust projects. See the `examples/` directory:\n\n- **[propagation_check.rs](examples/propagation_check.rs)** — Check if a domain is propagated globally\n- **[tls_chain_verify.rs](examples/tls_chain_verify.rs)** — Validate TLS certificate chains (Phase 2)\n- **[email_security.rs](examples/email_security.rs)** — Check email security records (Phase 1)\n\nRun examples:\n```bash\ncargo run --example propagation_check -- example.com\ncargo run --example tls_chain_verify -- example.com\ncargo run --example email_security -- example.com\n```\n\n## CLI Usage\n\nThe CLI is a convenient wrapper around the library for manual inspection and testing.\n\n### DNS record query\n\n```bash\nshohei google.com              # A records (default)\nshohei google.com --type AAAA  # AAAA records\nshohei google.com --type NS    # Nameservers\nshohei gmail.com  --type MX    # Mail exchangers\n\n# Multiple record types in one command\nshohei google.com --type a --type aaaa --type mx\n```\n\n\n\n```bash\n# Security / DNSSEC-related record types\nshohei google.com --type caa       # Certificate Authority Authorization\nshohei github.com --type sshfp     # SSH fingerprints\nshohei _443._tcp.example.com --type tlsa  # DANE TLSA\n```\n\n\n### Reverse DNS\n\nResolve the PTR record for an IP address. IPv4 and IPv6 are both supported.\n\n```bash\nshohei -x 1.1.1.1              # → one.one.one.one\nshohei -x 2606:4700:4700::1111 # IPv6 reverse lookup\n```\n\n### DNSSEC chain of trust\n\nValidate the full DNSSEC chain from the root trust anchor down to the target domain.\nEach zone's DS and DNSKEY records are checked individually.\n\n```bash\nshohei cloudflare.com --dnssec\n\n# Verbose: show key tags, algorithm names, and KSK/ZSK roles\nshohei cloudflare.com --dnssec --verbose\n```\n\n\n### Iterative resolution trace\n\nStep through the full resolution path — root servers → TLD nameservers → authoritative nameservers.\n\n```bash\nshohei google.com --trace\n```\n\n\n### Modern transports\n\n```bash\n# DNS-over-HTTPS\nshohei google.com --doh https://dns.google/dns-query\n\n# DNS-over-TLS\nshohei google.com --dot 1.1.1.1:853\n\n# DNS-over-QUIC\nshohei google.com --doq 8.8.8.8\n\n# Custom resolver\nshohei google.com --server 8.8.8.8\n```\n\n### Authority and Additional sections\n\nWhen querying an authoritative server directly, shohei displays the **Authority Section** (NS referrals) and **Additional Section** (glue A/AAAA records) — matching `dig`'s default behavior.\n\n```bash\n# Query the .com TLD nameserver for google.com — shows NS referral + glue records\nshohei google.com -s 192.5.6.30 --no-recurse\n\n# Query an authoritative nameserver directly\nshohei example.com -s 199.43.135.53 --no-recurse --type ns\n```\n\n\n### Force TCP\n\nForce DNS queries over TCP instead of UDP. Useful for large responses that get truncated (TC bit set) or environments that block UDP/53.\n\n```bash\nshohei example.com -s 8.8.8.8 --tcp\n```\n\n### Short output\n\nStrip all decoration and return just the record data — one value per line. Ideal for shell scripting.\n\n```bash\nshohei gmail.com --type MX --short\n```\n\n\n### Compare resolvers\n\nQuery the same domain from multiple DNS servers simultaneously and diff the results. Useful for detecting CDN anycast differences or verifying a new resolver. Repeat `--compare` for N-way comparison.\n\n```bash\n# Show that both servers return the same NS records\nshohei cloudflare.com --type NS --server 8.8.8.8 --compare 1.1.1.1\n\n# Reveal CDN-induced A record differences\nshohei google.com --server 8.8.8.8 --compare 1.1.1.1\n\n# N-way comparison across three resolvers\nshohei google.com --server 8.8.8.8 --compare 1.1.1.1 --compare 9.9.9.9\n```\n\n\n\n### Zone transfer (AXFR)\n\nFetch the complete zone from an authoritative server. Requires `-s` to specify the authoritative nameserver.\n\n```bash\nshohei zonetransfer.me --axfr -s 81.4.108.41\n```\n\n\n### Batch / stdin mode\n\nPipe a newline-separated list of domains and shohei queries each one in sequence.\nLines starting with `#` are ignored as comments. You can also read targets from a file with `-f`.\n\n```bash\necho -e \"google.com\\nexample.com\\ncloudflare.com\" | shohei\ncat domains.txt | shohei --type mx --short\nshohei -f domains.txt --type mx --short\n```\n\n### Watch mode\n\nRepeat the query every N seconds and auto-refresh the display. Press Ctrl+C to stop.\n\n```bash\nshohei google.com --watch 5         # refresh every 5 seconds\nshohei google.com --type A --watch 10\n```\n\n### Output formats\n\n```bash\nshohei google.com --output json   # JSON for scripting\nshohei google.com --output plain  # No colors (CI-friendly)\n```\n\n### Interactive TUI (requires `--features tui`)\n\nPre-loads records, DNSSEC chain, and trace in parallel, then presents all three as navigable views.\n\n```bash\nshohei google.com --tui\n```\n\n```\n shohei — google.com\n┌─ Records ──────────────────────────────────────────────────────────┐\n│ Query: google.com (A IN)                                           │\n│                                                                    │\n│ NAME                                    TTL   TYPE   DATA          │\n│ ────────────────────────────────────────────────────────────────── │\n│ google.com.                             120   A      142.250.x.x   │\n│ ...                                                                │\n└────────────────────────────────────────────────────────────────────┘\n [r] Records  [d] DNSSEC  [t] Trace  [↑↓/jk] Scroll  [q] Quit\n```\n\n| Key | Action |\n|-----|--------|\n| `r` | Records view |\n| `d` | DNSSEC chain view |\n| `t` | Iterative trace view |\n| `↑` / `k` | Scroll up |\n| `↓` / `j` | Scroll down |\n| `q` / `Esc` | Quit |\n\n## Options\n\n| Flag | Short | Description |\n|------|-------|-------------|\n| `--type \u003cTYPE\u003e` | `-t` | Record type (repeatable): `a`, `aaaa`, `mx`, `ns`, `txt`, `cname`, `soa`, `ptr`, `srv`, `https`, `svcb`, `naptr`, `dnskey`, `ds`, `rrsig`, `caa`, `tlsa`, `sshfp`, `nsec`, `nsec3`, `any` |\n| `--reverse \u003cIP\u003e` | `-x` | Reverse DNS — auto-converts IP to PTR query (IPv4 and IPv6) |\n| `--file \u003cFILE\u003e` | `-f` | Read domains from a file (one per line), like `dig -f` |\n| `--dnssec` | `-d` | DNSSEC chain-of-trust validation tree |\n| `--verbose` | `-v` | Show verbose detail (key tags, algorithms) in DNSSEC chain |\n| `--trace` | | Iterative resolution path from root servers |\n| `--no-recurse` | | Clear RD bit — query authoritative servers directly; shows Authority + Additional sections |\n| `--axfr` | | Full zone transfer from the server specified with `-s` |\n| `--tcp` | | Force TCP instead of UDP (requires `-s`; useful for large/truncated responses) |\n| `--timeout \u003cSECS\u003e` | | DNS query timeout in seconds (default: 5, max: 60) |\n| `--short` | | Output data values only, one per line (script-friendly) |\n| `--watch \u003cSECS\u003e` | | Repeat query every N seconds; Ctrl+C to stop |\n| `--compare \u003cADDR\u003e` | | Query an additional server and diff; repeat for N-way comparison |\n| `--doh \u003cURL\u003e` | | DNS-over-HTTPS (e.g. `https://dns.google/dns-query`) |\n| `--dot \u003cIP:PORT\u003e` | | DNS-over-TLS (e.g. `1.1.1.1:853`) |\n| `--doq \u003cIP:PORT\u003e` | | DNS-over-QUIC (e.g. `8.8.8.8` or `8.8.8.8:853`) |\n| `--server \u003cADDR\u003e` | `-s` | Custom DNS server (`8.8.8.8` or `8.8.8.8:53`) |\n| `-4` | | Force queries over IPv4 transport |\n| `-6` | | Force queries over IPv6 transport |\n| `--output \u003cFORMAT\u003e` | `-o` | `colored` (default) · `plain` · `json` |\n| `--tui` | | Interactive TUI (requires `--features tui`) |\n\n## Trust States\n\n| Badge | Meaning |\n|-------|---------|\n| `✓ SECURE` | DNSSEC-validated, full chain of trust verified |\n| `⚠ INSECURE` | Zone unsigned, but parent has no DS delegation (expected) |\n| `✗ BOGUS` | Validation failed — signature mismatch or broken chain |\n| `? INDETERMINATE` | DNSSEC not requested, or result unclear |\n\n## MCP Server \u0026 Claude Integration\n\n### ✅ Live Now (v2.5.1+)\n\n**MCP (Model Context Protocol) Server** with 168 tools lets Claude Desktop and other AI agents call shohei diagnostics directly:\n\n```bash\n# 1. Install shohei\ncargo install shohei\n\n# 2. Register MCP server in Claude Desktop config:\n# ~/.config/Claude/claude_desktop_config.json\n{\n  \"mcpServers\": {\n    \"shohei\": {\n      \"command\": \"/path/to/shohei-mcp\"\n    }\n  }\n}\n\n# 3. Restart Claude Desktop\n# 4. Ask Claude: \"Check example.com's TLS certificate\"\n```\n\n**168 Tools Available to Claude (62 modules):**\n- **DNS \u0026 DNSSEC** (10+ tools) — Query records, DNSSEC validation, propagation checks, zone transfers, latency benchmarking\n- **TLS \u0026 Certificates** (8+ tools) — Chain inspection, DANE/TLSA validation, certificate transparency (CT) logs, OCSP checks, cipher suites\n- **Email Security** (6+ tools) — SPF, DKIM, DMARC, BIMI, MTA-STS, TLS-RPT validation with compliance scoring\n- **IP \u0026 Network** (10+ tools) — IP reputation, reverse DNS, ASN/GeoIP, port scanning, traceroute, IPv6 dual-stack checks\n- **Web Security** (12+ tools) — Security headers audit, WAF/CDN detection, technology fingerprinting, HTTP/2/3 detection, redirect analysis\n- **OSINT \u0026 Recon** (15+ tools) — WHOIS, domain age, subdomain enumeration, typosquatting detection, parked domain detection, brand name checker\n- **Threat Intelligence** (10+ tools) — CVE lookup, VirusTotal integration, URLhaus checking, Shodan queries, breach database lookups\n- **Governance \u0026 Compliance** (8+ tools) — BGP/RPKI validation, GDPR compliance checking, email authentication chain (ARC), DNS amplification risk\n- **Crypto \u0026 Blockchain** (10+ tools) — Ethereum address validation, cryptocurrency holder detection, blockchain WHOIS\n- **Advanced Analysis** (19+ tools) — Entity relationship graphs, brand detection, URL analysis, redirect domain age, compliance reports, HASSH fingerprinting, cloud exposure, network reputation\n- **URL Intelligence** (4 tools) — URL parsing, security intelligence, defacement detection, analytics\n- **Cloud Exposure** (4 tools) — Cloud provider asset detection, misconfiguration scanning, cloud infrastructure analysis\n- **OSINT Expansion** (4 tools) — Advanced recon techniques, infrastructure mapping, historical data queries\n- **Network Reputation** (3 tools) — ISP reputation, network behavior analysis, threat scoring\n- **Cloud Infrastructure** (4+ tools) — AWS/GCP/Azure resource exposure, misconfigured storage detection, IAM policy analysis\n- **Credential Security** (4+ tools) — Leaked credential checks, API key exposure scanning, secret detection in public resources\n- **Supply Chain Security** (4+ tools) — Dependency vulnerability analysis, package registry integrity checks, typosquatting in package names\n- **Web Intelligence** (5 tools) — robots.txt analysis, .well-known discovery, OAuth/OIDC audit, cert pinning, API debug endpoint exposure\n- **Service Exposure** (4 tools) — Unauthenticated database access (Redis/MongoDB/Elasticsearch), Docker/Kubernetes API exposure, service fingerprinting, DGA risk scoring\n- **Subdomain Takeover** (3 tools) — 30+ service signatures (GitHub Pages, Heroku, Netlify, Vercel, Azure, AWS, Shopify…), RIPE Stat passive DNS, Azure AD tenant exposure\n- **Email Advanced** (2 tools) — DKIM key strength (1024 vs 2048 vs Ed25519), MX server STARTTLS deep audit\n- **Attack Surface** (1 tool) — Composite CVSS-like score aggregating TLS + web headers + email + network exposure\n\n**Example:** Claude diagnoses a domain autonomously:\n\u003e \"Check if example.com's mail configuration is correct, and verify its TLS certificate chain\"\n\u003e → Claude calls check_email_security + check_tls_chain → returns full analysis\n\n![MCP shohei in Claude Desktop](images/use_mcp_shohei_01.png)\n\n### Other Integrations\n\n- **Rust Library**: `use shohei;` in your projects — structured async APIs\n- **CLI**: Manual inspection: `shohei example.com --dnssec --trace`\n- **JSON output**: Scripting and tooling: `shohei example.com --output json`\n\nSee [docs/INTEGRATIONS.md](docs/INTEGRATIONS.md) for full details.\n\n## Built with\n\n- [hickory-dns](https://hickory-dns.org/) — DNSSEC, DoH, DoT support\n- [clap](https://crates.io/crates/clap) — CLI argument parsing\n- [ratatui](https://ratatui.rs/) — TUI framework (optional `tui` feature)\n- [owo-colors](https://crates.io/crates/owo-colors) — Terminal colors\n- [comfy-table](https://crates.io/crates/comfy-table) — Record table rendering\n\n## License\n\nMIT — see [LICENSE](LICENSE)\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fkent-tokyo%2Fshohei","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fkent-tokyo%2Fshohei","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fkent-tokyo%2Fshohei/lists"}