Skip to main content
Glama

Typosquat Scanner

typosquat
Read-onlyIdempotent

Generate typosquat permutations for a domain and check which variants are registered. Produces omission, transposition, keyboard-adjacent replacement, insertion, repetition, hyphenation, vowel-swap, homoglyph, plural/singular, and TLD-swap variants. Each result includes the variant domain, mutation type, prefix TLD count (how many TLDs the prefix is registered under), and registration date if known.

Use for brand protection, phishing detection, and defensive registration planning.

Related tools: nrds, ns_reverse, dns, whois.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
domainYesDomain to scan (e.g. example.com)

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault
dataNo
totalNoNumber of permutations generated
domainNoThe input domain
successYes

Schema Changelog

Changes observed during successful MCP inspections.

  1. Added

TDQS

A4.1/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare readOnly, idempotent, non-destructive, and non-open-world behavior, so the safety profile is covered. The description adds real value beyond that by disclosing the mutation taxonomy and the exact per-result fields (variant domain, mutation type, prefix TLD count, registration date), plus the caveat that registration date is only known sometimes.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loads the core action, then result shape, then use cases, then related tools. Dense but every sentence carries information; no filler or restatement of the title.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With an output schema present and annotations covering safety, the description need not explain return values, and it still describes the result fields usefully. The only shortfall is that the listed related tools are not qualified with when each applies, leaving tool selection partly to inference.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Only one parameter, and the schema documents it at 100% coverage with its own example (example.com). The description adds no format or constraint details beyond what the schema already provides, so this is the baseline case where the schema does the work.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb (generate permutations) and resource (domain variants), then enumerates the ten mutation classes it produces. Distinctly different from siblings like dns, whois, or nrds, which are lookups rather than permutation generators.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Explicitly names three motivating scenarios (brand protection, phishing detection, defensive registration planning) and lists related tools. It stops short of saying when to prefer a sibling (e.g. nrds vs whois) or when not to use this tool, so it is clear context without real differentiation.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.