Nextdns

Nextdns MCP integration

Allowlists wrongly blocked domains, reads logs to explain a block, adjusts a profile's filtering policy, and manages DNS rewrite rules.

68actions available

Three actions you can hand over today

Every action runs live through MCP. Nothing to build, nothing to maintain.

  • Create profile

    Lyro creates a new NextDNS profile for DNS and security management. Support agents set up profiles for customers without requiring administrator intervention.

  • List profiles

    Lyro retrieves all NextDNS profiles available to the account. Support agents quickly see which profiles exist and select the right one for configuration.

  • Toggle domain logging

    Lyro enables or disables domain logging for a NextDNS profile. Support agents adjust logging preferences immediately without leaving the conversation.

See all 68 actions

How businesses use Nextdns + Lyro

Each card is one request a support team gets, and the Nextdns actions Lyro runs to close it.

  • Unblock a site a customer says is wrongly blocked

    Lyro checks what the profile already allows, adds the domain to the allowlist, and pulls it off the denylist if that is where it was caught, so the customer is back online in the same conversation.

    Get AllowlistAdd Allowlist EntryRemove Denylist Domain
  • Show why the query was blocked in the first place

    Lyro reads the query log for the device, reports which rule or blocklist caught the domain, and breaks down what else that profile has been blocking, so the fix addresses the cause.

    Get LogsGet Analytics Blocking ReasonsGet Analytics Domains
  • Set the filtering policy on a profile

    Lyro adjusts the security settings a profile enforces, adds the privacy blocklist the organisation has standardised on, and changes the parental control rules when a household's needs change.

    Update Security SettingsAdd Privacy BlocklistUpdate Parental Control Settings
  • Point a hostname somewhere else with a rewrite

    Lyro adds the DNS rewrite that sends an internal hostname to the right address, lists the rewrites already in place, and removes one that is sending traffic somewhere it should not.

    Add DNS Rewrite RuleGet DNS RewritesDelete DNS Rewrite Rule

How it works

Get started in 3 steps

Connect once, then just ask. There is no workflow builder to learn and nothing to maintain — Lyro reads the Nextdns actions it has and picks the ones a request needs.

  1. 01

    Connect Nextdns

    Authorize the Nextdns account your team already uses — one consent screen, no API keys, no mapping tables. Lyro can only do what you granted that account, and you can disconnect it at any time.

  2. 02

    Tell your agent what you need

    Describe the job the way you would hand it to a teammate. Lyro maps it to the Nextdns actions that close it and chains as many as the request needs.

  3. 03

    Watch it work

    The agent runs the actions inside the conversation the customer is already in, so nobody copies data between tabs and your team can take over at any point.

    Get started free
Nextdns · Lyro

Everything else about Nextdns

Setup, permissions, and the limits of what Lyro can do inside Nextdns.

  • The one Lyro is pointed at, which is worth confirming first. List Profiles enumerates the profiles on the account, Get Profile Details and Get Profile Settings return what a specific one enforces, and Create Profile adds a new one. Households and companies usually run several, so the profile is the difference between fixing one device and changing everybody's filtering.

Every action available in Nextdns

All 68 actions your agent can call on Nextdns, straight from the live MCP connection.

  • Add allowlist entry

    Add a domain to the allowlist of a NextDNS profile.

  • Add blocked tld

    Add a top-level domain to the security blocklist for a NextDNS profile.

  • Add denylist domain

    Add a domain to the denylist of a NextDNS profile.

  • Add parental control category

    Add a content category to the parental control categories list.

  • Add parental control service

    Add a service to the parental control services list of a NextDNS profile.

  • Add privacy blocklist

    Add a blocklist to the privacy blocklists for a NextDNS profile.

  • Add privacy native tracker

    Add a native tracking service to the blocked list for a NextDNS profile.

  • Add dns rewrite rule

    Add a DNS rewrite rule to a NextDNS profile.

  • Clear logs

    Clear DNS logs for a NextDNS profile.

  • Create profile

    This tool allows users to create a new NextDNS profile.

  • Delete allowlist entry

    Remove a domain from a NextDNS profile's allowlist.

  • Delete nextdns configuration

    Delete a NextDNS configuration profile.

  • Delete parental control category

    Remove a category from parental control blocked categories.

  • Delete parental control service

    Remove a service from parental control blocked services.

  • Delete privacy blocklist

    Remove a blocklist from the privacy blocklists for a NextDNS profile.

  • Delete privacy native tracker

    Remove a native tracking entry from a NextDNS profile's privacy settings.

  • Delete dns rewrite rule

    Delete a DNS rewrite rule from a NextDNS profile.

  • Download logs

    Retrieves the download URL for exported DNS query logs from a NextDNS profile.

  • Get allowlist

    Retrieve the list of allowed domains for a NextDNS profile.

  • Get analytics destinations

    Retrieve destination analytics for a profile showing query destinations by country or GAFAM company.

  • Get analytics devices

    Retrieve device analytics for a profile showing identified devices with names, models, and query counts.

  • Get analytics dnssec

    Retrieve DNSSEC validation analytics for a profile showing validated vs non-validated query counts.

  • Get analytics domains

    Retrieve analytics data for domains within a specific profile.

  • Get analytics encryption

    Retrieve encryption analytics for a profile showing encrypted vs unencrypted query counts.

  • Get analytics ips

    Retrieve analytics aggregated by client IP addresses.

  • Get analytics IP versions

    Retrieve analytics grouped by IP version within a specific profile.

  • Get analytics protocols

    Retrieve protocol analytics for a specific profile showing DNS protocol distribution (DNS-over-HTTPS, DNS-over-TLS, UDP).

  • Get analytics query types

    Retrieve DNS query counts broken down by query type.

  • Get analytics blocking reasons

    Retrieve blocking reasons analytics showing blocklists, native tracking protection, and other reasons for blocked queries.

  • Get analytics status

    Retrieve analytics status for a specific profile.

Ready to connect Nextdns?

Authorize the account and your agent has all 68 actions from the first conversation.

Support agent working at a laptop next to the Lyro mascot