01Configurable domain allowlists and denylists to protect critical domains
02Generates an audit trail for every tool call, without logging credentials
03Enforces server-side policy validation for RR-types, TTL caps, and CNAME rules
040 GitHub stars
05Least privilege and sandbox-only by default, with writes disabled out of the box
06Requires explicit confirmation strings for destructive operations (e.g., DELETE, RELOAD)