Nextdns
for LuumenAI

Read NextDNS query analytics, then change blocking rules as approved steps

Connect NextDNS and your agent can read query analytics, blocking reasons, and the current allowlist for any profile without waiting on the dashboard. When a domain needs to be unblocked, denied, or rewritten, the change is proposed first and applied after you approve it. Authentication is by API key.

The Nextdns toolbox

68 tools: 28 read, 40 write. Reads answer instantly. Writes require approval by default. Everything is logged.

  • ReadDownload LogsRetrieves the download URL for exported DNS query logs from a NextDNS profile.
  • ReadGet AllowlistRetrieve the list of allowed domains for a NextDNS profile.
  • ReadGet Analytics DestinationsRetrieve destination analytics for a profile showing query destinations by country or GAFAM company.
  • ReadGet Analytics DevicesRetrieve device analytics for a profile showing identified devices with names, models, and query counts.
  • ReadGet Analytics DNSSECRetrieve DNSSEC validation analytics for a profile showing validated vs non-validated query counts.
  • ReadGet Analytics DomainsRetrieve analytics data for domains within a specific profile.
  • ReadGet Analytics EncryptionRetrieve encryption analytics for a profile showing encrypted vs unencrypted query counts.
  • ReadGet Analytics IPsRetrieve analytics aggregated by client IP addresses.
  • ReadGet Analytics IP VersionsRetrieve analytics grouped by IP version within a specific profile.
  • ReadGet Analytics ProtocolsRetrieve protocol analytics for a specific profile showing DNS protocol distribution (DNS-over-HTTPS, DNS-over-TLS, UDP).
  • ReadGet Analytics Query TypesRetrieve DNS query counts broken down by query type.
  • ReadGet Analytics Blocking ReasonsRetrieve blocking reasons analytics showing blocklists, native tracking protection, and other reasons for blocked queries.
  • ReadGet Analytics StatusRetrieve analytics status for a specific profile.
  • ReadGet LogsRetrieve logs for a specific NextDNS profile with optional filters.
  • ReadGet Parental Control SettingsGet parental control settings for a profile.
  • ReadGet Parental Control CategoriesGet the list of blocked/allowed content categories for parental control.
  • ReadGet Parental Control ServicesGet the list of blocked/allowed services for parental control.
  • ReadGet Performance SettingsGet performance settings for a profile including ECS, cache boost, and CNAME flattening configuration.
  • ReadGet Privacy SettingsGet privacy settings for a profile including blocklists, native tracking settings, disguised trackers, and affiliate settings.
  • ReadGet Profile DetailsRetrieves the details of a specific NextDNS profile.
  • ReadGet DNS RewritesRetrieve the list of DNS rewrites for a NextDNS profile.
  • ReadGet Security TLDsGet the list of blocked TLDs (top-level domains) for a profile's security settings.
  • ReadGet Profile SettingsGet all settings for a NextDNS profile including logs, block page, performance, and web3 settings.
  • ReadGet Block Page SettingsRetrieve the block page settings for a NextDNS profile.
  • ReadGet Logging SettingsRetrieve the logging settings for a NextDNS profile.
  • ReadList Denylist DomainsList domains in the denylist for a profile.
  • ReadList ProfilesList all NextDNS profiles for the authenticated user, returning profile IDs and configurations.
  • ReadList Security SettingsList current security options for a NextDNS configuration.
  • WriteAdd Allowlist EntryAdd a domain to the allowlist of a NextDNS profile. Approval by default
  • WriteAdd Blocked TLDAdd a top-level domain to the security blocklist for a NextDNS profile. Approval by default
  • WriteAdd Denylist DomainAdd a domain to the denylist of a NextDNS profile. Approval by default
  • WriteAdd Parental Control CategoryAdd a content category to the parental control categories list. Approval by default
  • WriteAdd Parental Control ServiceAdd a service to the parental control services list of a NextDNS profile. Approval by default
  • WriteAdd Privacy BlocklistAdd a blocklist to the privacy blocklists for a NextDNS profile. Approval by default
  • WriteAdd Privacy Native TrackerAdd a native tracking service to the blocked list for a NextDNS profile. Approval by default
  • WriteAdd DNS Rewrite RuleAdd a DNS rewrite rule to a NextDNS profile. Approval by default
  • WriteClear LogsClear DNS logs for a NextDNS profile. Approval by default
  • WriteCreate ProfileThis tool allows users to create a new NextDNS profile. Approval by default
  • WriteDelete Allowlist EntryRemove a domain from a NextDNS profile's allowlist. Approval by default
  • WriteDelete NextDNS ConfigurationDelete a NextDNS configuration profile. Approval by default
  • WriteDelete Parental Control CategoryRemove a category from parental control blocked categories. Approval by default
  • WriteDelete Parental Control ServiceRemove a service from parental control blocked services. Approval by default
  • WriteDelete Privacy BlocklistRemove a blocklist from the privacy blocklists for a NextDNS profile. Approval by default
  • WriteDelete Privacy Native TrackerRemove a native tracking entry from a NextDNS profile's privacy settings. Approval by default
  • WriteDelete DNS Rewrite RuleDelete a DNS rewrite rule from a NextDNS profile. Approval by default
  • WriteLog Client IPsEnable or disable logging of client IPs for a NextDNS configuration. Approval by default
  • WriteToggle Domain LoggingEnable or disable logging of domains for a NextDNS profile. Approval by default
  • WriteRemove Blocked TLDRemove a top-level domain from the security blocklist for a NextDNS profile. Approval by default
  • WriteRemove Denylist DomainRemoves a domain from a NextDNS profile's denylist (blocklist). Approval by default
  • WriteRename ConfigurationRename a NextDNS configuration (profile). Approval by default
  • WriteReplace AllowlistReplace the entire allowlist for a NextDNS profile. Approval by default
  • WriteReplace DenylistReplace the entire denylist (blocked domains) for a NextDNS profile. Approval by default
  • WriteReplace Parental Control CategoriesReplace the entire list of blocked/allowed content categories for parental control. Approval by default
  • WriteReplace Parental Control ServicesReplace the entire list of blocked/allowed services for parental control. Approval by default
  • WriteReplace Privacy BlocklistsReplace the entire list of privacy blocklists for a NextDNS profile. Approval by default
  • WriteReplace Privacy Native Tracking ServicesReplace the entire list of blocked native tracking services for a NextDNS profile. Approval by default
  • WriteReplace Security TLDsReplace the entire list of blocked TLDs (top-level domains) for a NextDNS profile's security settings. Approval by default
  • WriteUpdate Allowlist EntryUpdate a specific allowlist entry in a NextDNS profile. Approval by default
  • WriteUpdate Denylist EntryUpdates a specific denylist entry in a NextDNS profile, typically to toggle its active status. Approval by default
  • WriteUpdate linked IPUpdates the linked IP address for a NextDNS profile to the current caller's public IP. Approval by default
  • WriteUpdate Parental Control SettingsUpdate parental control settings for a NextDNS profile. Approval by default
  • WriteUpdate Parental Control CategoryUpdate a specific category entry in parental control settings. Approval by default
  • WriteUpdate Parental Control ServiceUpdate a specific service entry in parental control settings. Approval by default
  • WriteUpdate Performance SettingsUpdate performance settings of a NextDNS profile. Approval by default
  • WriteUpdate Privacy SettingsUpdate privacy settings for a profile. Approval by default
  • WriteUpdate Security SettingsUpdate security settings for a profile. Approval by default
  • WriteUpdate SettingsUpdate settings for a NextDNS profile including logs, block page, performance, and web3 settings. Approval by default
  • WriteUpdate Block Page SettingsUpdate block page settings for a NextDNS profile. Approval by default

One prompt, start to finish

What a governed Nextdns run looks like inside Luumen.

Questions

How does LuumenAI connect to Nextdns?

Authorize once with API token. Luumen lists the scopes each action needs before you approve the connection, and credentials never appear in the chat.

Can LuumenAI change things in Nextdns on its own?

Read actions answer immediately. Anything that writes — add allowlist entry, add blocked tld, add denylist domain, add parental control category, and more — is shown as a plan and requires approval by default, including the 12 actions classified as destructive. Administrators configure that per tool, so you decide exactly which actions can ever run unattended.

Who gets access to the integration?

You decide. Actions are granted per agent, skill, and team, and per environment — production is not staging. Read access can be broad while writes stay narrow.

Is there an audit trail?

Every call to Nextdns — read or write, approved or declined — is recorded with the actor, the input, and the result, and can be linked to the ticket or change record.

Put Nextdns to work with Luumen

Connect in minutes. Every action scoped, approved, and audited from day one.