{"_id":"@capitalthought/dns","_rev":"3-f8ee2a589f900e1342b08f0aba2c4f31","name":"@capitalthought/dns","dist-tags":{"latest":"0.3.0"},"versions":{"0.1.0":{"name":"@capitalthought/dns","version":"0.1.0","license":"UNLICENSED","_id":"@capitalthought/dns@0.1.0","maintainers":[{"name":"joshuabaer","email":"npmjs@joshspam.com"}],"homepage":"https://github.com/capitalthought/dns#readme","bugs":{"url":"https://github.com/capitalthought/dns/issues"},"dist":{"shasum":"7d40ddbb9d7a62d1c830f3a5a949aa5bd44beca2","tarball":"https://registry.npmjs.org/@capitalthought/dns/-/dns-0.1.0.tgz","fileCount":47,"integrity":"sha512-vpGwALh2fgEtwoN9ycBO7Ex3XRagn2re3Vks2GRPF9n1dEGboNKuBl/TbK0rnN9PSjrxwz8AFcYzWy8tzf+jjg==","signatures":[{"sig":"MEYCIQDw7CEQNMojjgASh+ZMgEAr9Kd+nCUAlmG3mI/CIIVwdAIhAPDnJ9kTee1daWjloNpD8e9FfquAmFqrvV8cToaXbUSR","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":63321},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=20"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./rdap":{"types":"./dist/rdap/index.d.ts","import":"./dist/rdap/index.js"},"./tlds":{"types":"./dist/tlds/index.d.ts","import":"./dist/tlds/index.js"},"./whois":{"types":"./dist/whois/index.d.ts","import":"./dist/whois/index.js"},"./variants":{"types":"./dist/variants/index.d.ts","import":"./dist/variants/index.js"},"./email-auth":{"types":"./dist/email-auth/index.d.ts","import":"./dist/email-auth/index.js"},"./zone-check":{"types":"./dist/zone-check/index.d.ts","import":"./dist/zone-check/index.js"},"./dns-records":{"types":"./dist/dns-records/index.d.ts","import":"./dist/dns-records/index.js"},"./nameservers":{"types":"./dist/nameservers/index.d.ts","import":"./dist/nameservers/index.js"}},"gitHead":"00f910c708f473e97239a7773c5b9ff745e50595","scripts":{"test":"vitest run","build":"tsc","check":"tsc --noEmit","test:watch":"vitest"},"_npmUser":{"name":"joshuabaer","email":"npmjs@joshspam.com"},"repository":{"url":"git+ssh://git@github.com/capitalthought/dns.git","type":"git"},"_npmVersion":"11.12.1","description":"Shared DNS / domain primitives for Capital Thought projects — zone-check (CZDS), whois/rdap, DNS-record CRUD, email-auth (SPF/DKIM/DMARC + ramp), nameservers, variants. Single source of truth for marc + mikey + domains.","directories":{},"_nodeVersion":"25.9.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^2.0.0","typescript":"^5.6.0","@types/node":"^22.0.0","@cloudflare/workers-types":"^4.20260503.1"},"_npmOperationalInternal":{"tmp":"tmp/dns_0.1.0_1780356019510_0.5994827327976244","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@capitalthought/dns","version":"0.2.0","license":"UNLICENSED","_id":"@capitalthought/dns@0.2.0","maintainers":[{"name":"joshuabaer","email":"npmjs@joshspam.com"}],"homepage":"https://github.com/capitalthought/dns#readme","bugs":{"url":"https://github.com/capitalthought/dns/issues"},"dist":{"shasum":"d646701b3c2390457dff4470e8e0d80bcea32dbb","tarball":"https://registry.npmjs.org/@capitalthought/dns/-/dns-0.2.0.tgz","fileCount":50,"integrity":"sha512-w8fNku4DQ4YrxkpkJiSUsQocRITdlL7ydNfVYZ8sMxc20qvP2AdVID7pSF8wN4NHWpEpQvdSzFEWpJ+P4azUjg==","signatures":[{"sig":"MEUCIDs0krd1/WvLUUt0RjPaKtZk+2fl0Dd0B0+SKZUDhNNNAiEA2gurazJZnpJkjfpBp+OxHqHFSEwuK8sNW8EqLcdIV10=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":144833},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=20"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./rdap":{"types":"./dist/rdap/index.d.ts","import":"./dist/rdap/index.js"},"./tlds":{"types":"./dist/tlds/index.d.ts","import":"./dist/tlds/index.js"},"./whois":{"types":"./dist/whois/index.d.ts","import":"./dist/whois/index.js"},"./variants":{"types":"./dist/variants/index.d.ts","import":"./dist/variants/index.js"},"./email-auth":{"types":"./dist/email-auth/index.d.ts","import":"./dist/email-auth/index.js"},"./zone-check":{"types":"./dist/zone-check/index.d.ts","import":"./dist/zone-check/index.js"},"./dns-records":{"types":"./dist/dns-records/index.d.ts","import":"./dist/dns-records/index.js"},"./nameservers":{"types":"./dist/nameservers/index.d.ts","import":"./dist/nameservers/index.js"}},"gitHead":"6787b7f7ff045f0a245982a4b2f7179f88e7a6be","scripts":{"test":"vitest run","build":"tsc","check":"tsc --noEmit","test:watch":"vitest"},"_npmUser":{"name":"joshuabaer","email":"npmjs@joshspam.com"},"repository":{"url":"git+ssh://git@github.com/capitalthought/dns.git","type":"git"},"_npmVersion":"11.12.1","description":"Shared DNS / domain primitives for Capital Thought projects — zone-check (CZDS), whois/rdap, DNS-record CRUD, email-auth (SPF/DKIM/DMARC + ramp), nameservers, variants. Single source of truth for marc + mikey + domains.","directories":{},"_nodeVersion":"26.0.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^2.0.0","typescript":"^5.6.0","@types/node":"^22.0.0","@cloudflare/workers-types":"^4.20260503.1"},"_npmOperationalInternal":{"tmp":"tmp/dns_0.2.0_1780514271779_0.14105625920899012","host":"s3://npm-registry-packages-npm-production"}},"0.3.0":{"name":"@capitalthought/dns","version":"0.3.0","description":"Shared DNS / domain primitives for Capital Thought projects — zone-check (CZDS), whois/rdap, DNS-record CRUD, email-auth (SPF/DKIM/DMARC + ramp), nameservers, variants. Single source of truth for marc + mikey + domains.","license":"UNLICENSED","type":"module","main":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"import":"./dist/index.js","types":"./dist/index.d.ts"},"./dns-records":{"import":"./dist/dns-records/index.js","types":"./dist/dns-records/index.d.ts"},"./email-auth":{"import":"./dist/email-auth/index.js","types":"./dist/email-auth/index.d.ts"},"./nameservers":{"import":"./dist/nameservers/index.js","types":"./dist/nameservers/index.d.ts"},"./whois":{"import":"./dist/whois/index.js","types":"./dist/whois/index.d.ts"},"./rdap":{"import":"./dist/rdap/index.js","types":"./dist/rdap/index.d.ts"},"./zone-check":{"import":"./dist/zone-check/index.js","types":"./dist/zone-check/index.d.ts"},"./tlds":{"import":"./dist/tlds/index.js","types":"./dist/tlds/index.d.ts"},"./variants":{"import":"./dist/variants/index.js","types":"./dist/variants/index.d.ts"}},"scripts":{"build":"tsc","check":"tsc --noEmit","test":"vitest run","test:watch":"vitest"},"engines":{"node":">=20"},"devDependencies":{"@cloudflare/workers-types":"^4.20260503.1","@types/node":"^22.0.0","typescript":"^5.6.0","vitest":"^2.0.0"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/capitalthought/dns.git"},"gitHead":"d2c017e73f73d8d8642081362673cc2c95d34ad3","_id":"@capitalthought/dns@0.3.0","bugs":{"url":"https://github.com/capitalthought/dns/issues"},"homepage":"https://github.com/capitalthought/dns#readme","_nodeVersion":"26.0.0","_npmVersion":"11.12.1","dist":{"integrity":"sha512-WoYUDxkA1Gq8rG60C3Mhb2ExUWVLGBKgpXgW5nu7D3tl9WY8ouaLB29tY4uI1W8WuAnkH4i0fX+m1Oex/93P0g==","shasum":"36f6a41f749574d2ffab2ed60a4c89df4d8fc5a6","tarball":"https://registry.npmjs.org/@capitalthought/dns/-/dns-0.3.0.tgz","fileCount":50,"unpackedSize":145747,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQD0lbJvUL25BUvQQ7lWoACKri/kgvmoAzALbTJwdixXmwIhAMu6AectZsXbk5Ki8j037BnlU4TBLwsRlWEXo2BOo1kD"}]},"_npmUser":{"name":"joshuabaer","email":"npmjs@joshspam.com"},"directories":{},"maintainers":[{"name":"joshuabaer","email":"npmjs@joshspam.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/dns_0.3.0_1780527033968_0.40102095872459276"},"_hasShrinkwrap":false}},"time":{"created":"2026-06-01T23:20:19.389Z","modified":"2026-06-03T22:50:34.248Z","0.1.0":"2026-06-01T23:20:19.670Z","0.2.0":"2026-06-03T19:17:51.971Z","0.3.0":"2026-06-03T22:50:34.142Z"},"bugs":{"url":"https://github.com/capitalthought/dns/issues"},"license":"UNLICENSED","homepage":"https://github.com/capitalthought/dns#readme","repository":{"type":"git","url":"git+ssh://git@github.com/capitalthought/dns.git"},"description":"Shared DNS / domain primitives for Capital Thought projects — zone-check (CZDS), whois/rdap, DNS-record CRUD, email-auth (SPF/DKIM/DMARC + ramp), nameservers, variants. Single source of truth for marc + mikey + domains.","maintainers":[{"name":"joshuabaer","email":"npmjs@joshspam.com"}],"readme":"# @capitalthought/dns\n\nShared DNS / domain primitives for Capital Thought projects — the **single source of truth** consumed by [marc](https://github.com/capitalthought/marc) (trademark clearance), [mikey](https://github.com/capitalthought/mikey) (domain-checker), and [domains](https://github.com/capitalthought/domains) (portfolio actuator). No DNS/domain logic is re-implemented in those repos.\n\n> Scope: DNS + zone + availability + email-auth primitives. **No registrar-write credentials** live here — registrar lifecycle (register / renew / transfer) is the `domains` agent's registrar-adapter layer, not this library.\n\n## Modules\n\n| Import | Status | What |\n|---|---|---|\n| `@capitalthought/dns/dns-records` | ✅ ready | Provider-pluggable DNS-record CRUD (Cloudflare provider in v1) |\n| `@capitalthought/dns/email-auth` | ✅ ready | SPF / DKIM / DMARC builders + the `p=none → quarantine → reject` ramp |\n| `@capitalthought/dns/nameservers` | ✅ ready | NS read helpers over DNS-over-HTTPS |\n| `@capitalthought/dns/rdap` | ✅ ready | RDAP registration lookup |\n| `@capitalthought/dns/whois` | 🚧 port from marc | WHOIS lookup (contract declared, impl pending M0.1) |\n| `@capitalthought/dns/zone-check` | 🚧 port from marc | CZDS bulk availability (`ZoneChecker.checkFiltered`) |\n| `@capitalthought/dns/tlds` | 🚧 port from marc | TLD tier config + CZDS auth (P1 seeded; tier-2/gTLD pending) |\n| `@capitalthought/dns/variants` | 🚧 port from marc | typosquat / brand-protection generation |\n\nEverything is also re-exported from the root: `import { buildDmarc, CloudflareDnsProvider } from \"@capitalthought/dns\"`.\n\n## Examples\n\n```ts\nimport { CloudflareDnsProvider } from \"@capitalthought/dns/dns-records\";\nimport { buildSpf, buildDmarc, planRampStep, parseDmarc } from \"@capitalthought/dns/email-auth\";\n\n// DNS CRUD (token = scoped Zone:DNS:Edit, read from 1Password at call time)\nconst cf = new CloudflareDnsProvider({ apiToken: process.env.CF_DNS_TOKEN! });\nconst zoneId = await cf.getZoneId(\"baer5.com\");\nawait cf.createRecord(zoneId!, { type: \"A\", name: \"lvp.baer5.com\", content: \"192.0.2.1\", proxied: true });\n\n// Anti-spoof a domain that sends no mail\nbuildSpf({ all: \"-\" });                       // \"v=spf1 -all\"\nbuildDmarc({ policy: \"reject\" });             // \"v=DMARC1; p=reject\"\n\n// DMARC ramp — proposes the next step; p=reject is ALWAYS gated\nconst current = parseDmarc(\"v=DMARC1; p=none; rua=mailto:d@x.com\")!;\nconst step = planRampStep(current);\n// → { from: \"none\", to: \"quarantine\", record: \"v=DMARC1; p=quarantine; rua=mailto:d@x.com\", requiresApproval: true }\n```\n\n## Security notes\n\n- **Registrar / whois / RDAP text is untrusted.** Registrant/org/status strings are attacker-controllable (domains PRD U1). Treat them as data, never instructions, before any LLM summarization.\n- **The DMARC ramp builder is deterministic** — record values come from pure functions, never raw LLM output, so a hallucinated policy can't reach a live zone.\n- **No secrets in this library.** Tokens (Cloudflare, CZDS JWT) are passed in by the caller, read from 1Password at call time.\n\n## Develop\n\n```bash\nnpm install\nnpm run build      # tsc → dist/\nnpm test           # vitest\nnpm run check      # tsc --noEmit\n```\n\nUNLICENSED · Capital Thought, LLC\n","readmeFilename":"README.md"}